Reference

Which Omani rules apply to your sector

A starting map. The Personal Data Protection Law applies across every sector; sector authorities add their own requirements on top.

Sector by sector

Banks, insurers and financial institutions

CBO-licensed institutions carry the central bank's cyber requirements alongside the data protection law. The Financial Services Authority regulates the capital market and the insurance sector.

Regulators: Central Bank of Oman · Financial Services Authority · Ministry of Transport, Communications and Information Technology

What applies

  • The CBO Cyber Security and Resilience Framework, Circular BM 1194, for banks, finance and leasing companies, money exchange companies and payment service providers.
  • The Financial Services Authority, which replaced the Capital Market Authority under Royal Decree 20/2024, for capital market firms and insurers.
  • Insurers that process health data need an MTCIT permit under Article 5.
  • The Personal Data Protection Law for customer and employee data, including explicit consent and the 72 hours breach rules.
  • PCI DSS wherever cardholder data is stored, processed or transmitted.

Healthcare providers

The Ministry of Health licenses healthcare providers. For data protection, health data needs an MTCIT permit, and the 2026 amendment widened what counts as health data.

Regulators: Ministry of Transport, Communications and Information Technology · Ministry of Health

What applies

  • A permit before processing health data, under Article 5. See the permits guide.
  • The new definition covers data about the provision of health care that reveals health status.
  • Breach notices within 72 hours, and a data protection officer for every controller.

Government entities

Units of the state's administrative apparatus and other public legal persons implementing the competences prescribed to them by law are excluded from the data protection law for that processing, but national cybersecurity expectations apply.

Regulators: Ministry of Transport, Communications and Information Technology · Cyber Defence Centre

What applies

  • Article 3 excludes processing by units of the state's administrative apparatus and other public legal persons implementing the competences prescribed to them by law.
  • The Cyber Defence Centre, established by Royal Decree 64/2020, is the national reference for cybersecurity and the place to report a cyber incident.
  • Affiliated companies and contractors should check whether their own processing falls outside that exclusion.

Telecommunications

Operators answer to the TRA for licensing and to the data protection law for subscriber data.

Regulators: Telecommunications Regulatory Authority · Ministry of Transport, Communications and Information Technology

What applies

  • TRA licensing and regulatory requirements for operators.
  • The Personal Data Protection Law for subscriber data, including breach notices within 72 hours.

Technology, cloud and AI providers

Providers often act as processors for their clients and increasingly make automated decisions about people.

Regulators: Ministry of Transport, Communications and Information Technology · Cyber Defence Centre

What applies

  • Processor obligations under the Personal Data Protection Law when you handle client data.
  • Article 14: privacy safeguards for automated processing and human review of automated decisions on objection.
  • Transfers outside Oman only under the controls in the Executive Regulations, including the data subject's explicit consent under Article 37 of the regulations, and Cyber Defence Centre approval before sensitive personal data goes abroad.

Retail and e-commerce

The main obligations come from customer personal data, marketing and card payments.

Regulators: Ministry of Transport, Communications and Information Technology

What applies

  • Explicit consent before commercial marketing, under Article 22.
  • Consent requests that meet the new Article 10, and erasure when the purpose ends.
  • PCI DSS for cardholder data.

Foreign companies serving people in Oman

Since 7 September 2026, the law reaches processing of personal data of people in Oman wherever it takes place.

Regulators: Ministry of Transport, Communications and Information Technology · Cyber Defence Centre

What applies

  • Article 2 brings you into scope even without an Omani entity.
  • Transfers out of Oman need the data subject's explicit consent under Article 37 of the Executive Regulations, unless an international agreement obligation applies or the data is anonymised, and sensitive personal data needs Cyber Defence Centre approval first.
  • Name a data protection officer, meet the consent rules and prepare for the 72 hours breach notices.
  • Read what changed in 2026.

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.