🇴🇲Oman

OM-PDPL

Personal Data Protection Law, 2022

Ministry of Transport, Communications and Information Technology

Oman overview

Oman's privacy framework is built around explicit approval and Ministry oversight

Oman's personal data protection regime is anchored by the Personal Data Protection Law, promulgated by Royal Decree No. 6/2022. The law protects personal data as a statutory right and places the Ministry of Transport, Communications and Information Technology at the centre of implementation, supervision and enforcement.

The Omani framework is not just a privacy notice regime. It requires explicit approval for processing, written transparency before processing begins, controls for sensitive data and children's data, a personal data protection officer, breach notification, transfer controls and penalties that become significant where personal data is transferred unlawfully outside Oman.

The three ideas to understand first

The Ministry is the regulator. The Ministry of Transport, Communications and Information Technology is responsible for applying the law, issuing controls and procedures, receiving complaints, cooperating with foreign data protection authorities, licensing compliance assessment service providers, maintaining a registry of controllers and processors, and taking protective measures against controllers and processors that violate the law.

Explicit approval is the operating baseline. Article 10 says personal data may not be processed except in a context of transparency, honesty and respect for human dignity, and after obtaining the explicit approval of the data subject. The processing request must be written in a clear, explicit and understandable manner, and the controller must be able to prove the data subject's written approval.

Special data and cross-border transfers carry the highest risk. Genetic data, biometric data, health data, ethnic origin, sexual life, political or religious opinions, criminal convictions and data related to security measures may not be processed unless a permit is obtained from the Ministry. Cross-border transfers are allowed only in accordance with the Regulation's controls and procedures, and unlawful transfers attract the highest fine range under the law.

How the law works in practice

The law defines personal data broadly as data that directly or indirectly identifies a natural person by reference to identifiers such as name, civil identity number, electronic identification data, spatial data, or factors relating to genetic, physical, mental, psychological, social, cultural or economic identity.

The law uses familiar roles. A controller determines the purposes and means of processing and may process the data itself or entrust processing to another person. A processor processes personal data on behalf of the controller. This means organisations must know whether they are deciding the purpose and means of processing or acting under another party's instructions.

The law also contains several exclusions. It does not apply where processing is for national security or public interest, public authority functions, legal obligations, protection of state economic and financial interests, vital interests, crime detection or prevention based on an official written request, execution of a contract with the data subject, personal or family purposes, certain research purposes, or data made public in a lawful manner.

What organisations should prioritise

Start with a processing map. Identify personal data, sensitive categories, child data, processors, transfer destinations and marketing use. Then separate processing that falls within an Article 3 exclusion from processing that requires the normal consent, notice and controller-obligation framework.

Next, design the written notice and consent layer. Before processing, the controller must notify the data subject in writing of controller and processor details, the personal data protection officer's contact information, purpose and source of processing, description of processing procedures and disclosure levels, and the data subject's rights.

Finally, build the governance layer. Controllers must set processing controls and procedures, appoint a personal data protection officer, maintain processing documents, cooperate with the Ministry, notify breaches, protect confidentiality, obtain written marketing consent and follow cross-border transfer controls. These are operational controls, not optional policy statements.

Key Oman Law

Royal Decree No. 6/2022 promulgating the Personal Data Protection Law - Oman's principal personal data protection law, issued on 9 February 2022 and brought into force one year after publication in the Official Gazette.

What this means for you

Oman compliance turns on evidence. You need written, understandable consent where required, documented processing controls, a clear notice before processing begins, a personal data protection officer, breach reporting procedures and transfer controls. The highest exposure sits around unlawful cross-border transfers, special-category processing and failure to manage controller obligations properly.