[codicts-css-switcher id=”346″]

Global Law Experts Logo
omans personal data

Oman's Personal Data Protection Law, What Businesses Must Do to Comply

By Global Law Experts
– posted 2 hours ago

Oman’s Personal Data Protection Law (PDPL), issued by Royal Decree 6/2022 and supplemented by Executive Regulations issued in 2024, reaches directly into the compliance obligations of every organisation that processes the personal data of individuals in Oman. The framework addresses the law’s territorial scope, imposes obligations on both controllers and processors, sets rules on data retention and deletion, and governs automated processing and cross-border transfers. For corporate counsel, data protection officers and in-house compliance teams, the PDPL and its regulations demand ongoing review of data flows, contracts and retention practices. This explainer sets out the key requirements, why they matter, and the practical steps businesses should take.

Quick summary. Who is affected: controllers and processors operating in Oman, and (where applicable) those processing the personal data of individuals in Oman. What the law requires: a lawful basis for processing, defined retention and deletion practices, safeguards around automated processing, and controls on cross-border transfers. Immediate actions: map your data, update contracts and privacy notices, and build a delete-or-archive plan.

Oman’s PDPL, headline summary

Oman’s Personal Data Protection Law establishes a comprehensive framework for the processing of personal data and increases the compliance burden on organisations handling personal data connected to Oman. The law was issued by Royal Decree 6/2022, came into force in February 2023 (one year after publication), and is supplemented by Executive Regulations issued by the Ministry of Transport, Communications and Information Technology (MTCIT), which is the competent authority. The regulations clarify obligations that many organisations had previously treated as best practice rather than legal requirement.

The headline features of the framework are:

  • Lawful basis and consent. Processing generally requires the consent of the data subject unless another lawful basis applies, and consent must be freely given, specific and documented.
  • Retention and deletion obligations. Controllers and processors are expected to retain personal data only for as long as necessary for the purpose for which it was collected, subject to lawful retention exceptions.
  • Automated processing and profiling. The framework addresses how automated processing and profiling are treated, reinforcing transparency, oversight and risk-assessment expectations for organisations using algorithmic or data-driven systems.
  • Cross-border transfers. Transfers of personal data outside Oman are subject to conditions designed to protect data subjects.

Oman’s data protection regime sits within a broader period of legislative modernisation across the Gulf, with several GCC states having enacted or updated their own data protection laws in recent years. Organisations operating regionally should read the Omani requirements alongside those of the other jurisdictions in which they operate.

Territorial scope explained

The territorial reach of the PDPL is an important threshold question for any organisation. Businesses operating outside Oman but processing the personal data of people in Oman, for example, foreign e-commerce platforms, cloud service providers, or multinational groups serving Omani customers from abroad, should carefully assess whether and how the law and its regulations apply to their activities, and should seek local advice where the position is unclear.

In practical terms, organisations should not assume they sit outside the law’s reach simply because their servers or headquarters are located elsewhere. Local branches of international firms, and international firms with an Omani-facing customer base or workforce, should each assess their exposure and document the assessment that led them to their conclusion.

When application will be triggered

Application generally turns on the connection between the processing and people in Oman. The key factors to test against your operations include whether your organisation processes personal data in Oman, offers goods or services to individuals in Oman, and whether it monitors the behaviour of individuals located in Oman, for example through analytics, tracking, or profiling. Where the framework is engaged, controllers should document the assessment. Organisations that are uncertain should err towards compliance and take local advice rather than assume they fall outside scope, because the cost of remediation after an enforcement inquiry is materially higher than proactive alignment.

Jurisdictional conflicts and practical enforcement issues

Data protection laws inevitably raise questions of practical enforcement and overlap with other jurisdictions’ regimes. A multinational may find itself subject to Oman’s PDPL alongside the requirements of other GCC states and international frameworks, creating potential conflicts on issues such as lawful bases, data localisation and cross-border transfer conditions. Businesses should manage overlap by mapping their obligations jurisdiction by jurisdiction and applying the most protective standard where requirements diverge. Maintaining clear records will assist both compliance and any future dialogue with the competent authority.

Retention and deletion obligations, controllers and processors

One of the most operationally demanding features of the PDPL framework is the expectation that personal data is not kept longer than necessary. Personal data should generally be deleted or anonymised once the purpose for which it was collected has been fulfilled. This moves data minimisation and purpose limitation from aspirational principle towards enforceable duty, and it is relevant not only to controllers who determine why and how data is processed, but also to the processors acting on their instructions.

Retention is subject to lawful exceptions. Personal data may be retained where there is a continuing legal basis, for example, to comply with a statutory retention requirement, to establish, exercise or defend legal claims, or to serve a legitimate archiving or public-interest purpose. Crucially, the burden of justifying continued retention sits with the organisation. Where a business keeps data beyond the point at which the original purpose ends, it should be able to point to a specific, documented lawful basis for doing so.

For most organisations, meeting these expectations requires a systematic review of retention schedules. Data that has historically been kept indefinitely “just in case” now carries clear legal risk. A practical deletion programme should include the following elements:

  • Retention mapping. Identify every category of personal data, its purpose, and the point at which that purpose is fulfilled.
  • Retention schedules. Set defined retention periods for each data category, tied to a lawful basis, with a default deletion trigger when the purpose ends.
  • Secure erasure. Implement technical controls that ensure deletion is complete and irreversible across production systems, backups and third-party environments.
  • Exception handling. Document each instance of continued retention and the legal ground relied upon, with periodic review.
  • Processor flow-down. Ensure processors and subprocessors are contractually bound to delete or return data on the same terms.

Recordkeeping and documenting deletion decisions

Accountability runs through the PDPL framework, and deletion is no exception. Organisations should maintain records that demonstrate not only that data was deleted, but when, how, and on whose instruction. Where data is retained under an exception, the record should capture the specific lawful basis and the review date. For processors, erasure logs and deletion confirmations provided back to the controller create an evidential trail regulators may expect to see. Robust recordkeeping is one of the most effective ways to convert a legal obligation into a defensible compliance posture, and it should be embedded in standard operating procedures rather than treated as an afterthought.

Contractual changes with processors and subprocessors

Because obligations reach processors as well as controllers, existing data processing agreements will often need revision. Controllers should update contracts to specify deletion timelines, secure erasure standards, and the treatment of data at the end of the engagement. Processors, in turn, should ensure that these obligations flow down to any subprocessors they engage, so that requirements are honoured throughout the supply chain. Where legacy contracts are silent on deletion, or defer entirely to the controller without defined standards, they should be prioritised for amendment. Contract remediation is often the longest lead-time item in a compliance programme, so it should begin early.

Obligations under the PDPL, controllers vs processors

The table below summarises how key duties under the PDPL framework typically apply to controllers and processors respectively.

Duty / Topic Controllers Processors
Deletion when purpose fulfilled Responsibility to delete personal data no longer required and to ensure processors comply; should document justification for any retention exception Should delete data on controller instruction and when the purpose is fulfilled; should securely erase and provide proof to the controller
Recordkeeping Maintain records of processing activities and retention decisions Maintain processing records, erasure logs and deletion confirmations to controllers
Contractual requirements Should update contracts to include deletion timelines, security standards and subprocessor terms Should accept the controller’s deletion requirements and flow them down to subprocessors
Liability exposure Primary responsibility for lawful basis and retention decisions; may face administrative penalties Exposure for failing to delete or secure data; may face contractual and regulatory consequences
Impact assessments / automated processing Should assess high-risk profiling and ensure data-subject safeguards Should support the controller’s assessments and implement technical controls for automated processing

Automated processing and profiling, what to consider

A further pillar of the PDPL framework concerns automated processing. As organisations increasingly rely on algorithmic decision-making, machine learning and data-driven analytics, businesses should expect scrutiny around transparency, oversight and risk management. The direction of travel mirrors the wider global consensus that decisions made by automated systems, particularly those with a material effect on individuals, require additional safeguards.

In practice, businesses deploying automated processing should focus on three disciplines. First, transparency: individuals should be told, in clear terms, when automated processing is used and what it means for them. Second, risk assessment: high-risk processing should be evaluated through a data protection impact assessment (DPIA) that identifies risks to individuals and the measures taken to mitigate them. Third, human oversight: where automated decisions materially affect a person, there should be meaningful human involvement rather than a purely mechanical outcome, unless a specific lawful basis permits otherwise.

For teams building or procuring AI and machine-learning systems, the compliance work should begin at the design stage. Consider whether consent or another lawful basis supports the processing, document the choice, and revisit it as the system evolves. Vendors and internal development teams should be briefed on these requirements so that safeguards are engineered in rather than retrofitted.

When human intervention is required

Human intervention becomes important where an automated decision produces legal effects or similarly significant consequences for an individual, for example decisions affecting access to credit, employment, or essential services. In those cases, organisations should ensure a qualified person can review the decision, take account of additional information the individual provides, and, where appropriate, override the automated outcome. The intervention should be genuine rather than a rubber stamp; a reviewer who simply confirms the algorithm’s result without independent assessment is unlikely to satisfy the spirit of the law. Building a clear escalation pathway and training reviewers accordingly is the practical response.

Data subject rights in automated decisions

Individuals subject to automated processing should be able to understand how decisions about them are reached and to challenge outcomes they consider unfair. Practically, this means providing accessible explanations of the logic involved, offering a route to request human review, and responding to objections within reasonable timeframes. Organisations should update their privacy notices to describe automated processing in plain language and establish internal procedures for handling explanation and review requests. Treating these rights as operational workflows, with named owners and service standards, is far more effective than treating them as legal formalities that surface only when a complaint arrives.

Enforcement, penalties and practical risk management

Enforcement of the PDPL sits with the competent authority, the Ministry of Transport, Communications and Information Technology. The law provides for administrative penalties and, in certain cases, fines and other sanctions for non-compliance. Organisations should assume that the authority has the tools to investigate, issue corrective orders and impose penalties on those who fail to meet their obligations. Reputational exposure is also a real risk: enforcement action against data-handling failures tends to attract public attention, and the commercial cost of lost customer trust can exceed any financial penalty.

From a practical risk-management perspective, the most effective mitigations are proactive. Businesses that identify gaps and remediate them voluntarily, updating contracts, deleting data that should no longer be held, and documenting their decisions, are in a materially stronger position than those who wait for an inquiry. Where a compliance failure is identified internally, early self-assessment and prompt correction demonstrate good faith. Maintaining an incident response plan, so that any breach or non-compliance can be addressed quickly and transparently, is a core component of resilience. Businesses should verify the precise enforcement and penalty provisions in the published text of the PDPL and its Executive Regulations before finalising their risk assessments.

Practical compliance checklist, nine steps for businesses

The following nine steps translate the PDPL framework into an actionable programme. Each should be assigned an owner and a target date.

  1. Map processing activities. Build or refresh a record of all personal data you process, its purpose, its source and where it is stored.
  2. Update records of processing. Ensure your processing register reflects current activities, lawful bases and retention periods.
  3. Revise data retention schedules. Set defined retention periods tied to a lawful basis, with automatic deletion triggers when purposes end.
  4. Amend controller–processor contracts. Add deletion timelines, secure erasure standards, security requirements and subprocessor flow-down terms.
  5. Implement deletion protocols. Deploy secure erasure across production systems, backups and third-party environments, and log every deletion.
  6. Conduct DPIAs for automated systems. Assess high-risk automated processing and profiling, and document mitigations and oversight.
  7. Update privacy notices. Explain scope, retention, deletion rights and automated processing in clear language.
  8. Train staff and prepare incident response. Brief teams on the obligations and rehearse breach and non-compliance procedures.
  9. Assess cross-border transfers. Review data flows into and out of Oman and confirm they meet the law’s transfer requirements.

Interaction with other regulatory developments

Oman’s data protection framework should be read alongside the country’s wider regulatory environment, which has seen active modernisation across sectors including foreign investment, mining and infrastructure. Organisations active in sectors that generate significant data, such as banking, telecommunications, mining, and cross-border logistics and transport, should read the data protection requirements alongside the sector-specific rules that apply to their operations. Cross-border infrastructure projects, in particular, can generate substantial data-sharing that engages both transfer and territorial-scope considerations under the PDPL. Where a project spans more than one jurisdiction, businesses should coordinate their data protection compliance across each relevant regime.

Practical examples and short case studies

The following illustrative scenarios show how the framework reshapes obligations in different contexts.

A local bank. An Omani bank retains customer records long after accounts are closed. Under the retention and deletion expectations, it should identify when the purpose for holding each category of data ends, delete data that is no longer required, and document a lawful basis, such as statutory record-keeping, for anything it retains. Its automated credit-scoring system would benefit from a DPIA and a human-review pathway.

A multinational technology firm. A company headquartered abroad offers a consumer app to users in Oman. Because it processes the personal data of people in Oman, it should assess whether the PDPL applies to its activities, take local advice, align retention and deletion practices, and update its privacy notice to reflect Omani requirements.

A cross-border logistics operator. A logistics business sharing operational data across a cross-border route should map its transfers, ensure processor contracts include deletion and security terms, and confirm that any automated routing or analytics systems meet transparency and oversight expectations.

Conclusion and recommended next steps

Oman’s Personal Data Protection Law materially raises the bar for how organisations handle personal data connected to Oman. Its territorial reach means many foreign organisations should assess whether they fall within the law’s ambit; its retention and deletion expectations reinforce data minimisation as a practical duty for both controllers and processors; and its treatment of automated processing calls for transparency, oversight and structured risk assessment. The three most urgent actions for counsel and compliance teams are to map data flows and confirm whether the law applies, to build and implement a delete-or-archive programme with documented retention justifications, and to review contracts and automated systems against the law’s requirements.

Organisations that act proactively, rather than after an enforcement inquiry, will be best placed to manage risk and demonstrate accountability. Given that specific obligations are set out in the PDPL and its Executive Regulations, businesses should confirm the current text and take local legal advice before finalising their compliance programmes.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Ahmed Al Barwani at Al Barwani & Co, a member of the Global Law Experts network.

Sources

  1. Oman lawyers, corporate practice (Global Law Experts)

FAQs

What is Oman's Personal Data Protection Law and when did it take effect?
Oman’s Personal Data Protection Law was issued by Royal Decree 6/2022 and came into force in February 2023, one year after its publication. It is supplemented by Executive Regulations issued by the Ministry of Transport, Communications and Information Technology, which is the competent authority. The framework governs how personal data is processed, retained and transferred.
It can, depending on the connection between the processing and people in Oman. Organisations that process the personal data of individuals in Oman, or that offer goods or services to or monitor the behaviour of people in Oman, should assess their exposure and take local advice where the position is unclear.
Personal data should generally not be kept longer than necessary for the purpose for which it was collected, subject to lawful retention exceptions. Both controllers and processors have a role in ensuring data is deleted when no longer required, and businesses should document each deletion and record the specific legal basis for any data they continue to retain.
Organisations using automated processing should focus on transparency, risk assessment through DPIAs, and human oversight where automated decisions materially affect individuals, unless a specific lawful basis applies. Systems should be assessed at the design stage.
Map personal data flows, update retention policies, amend processor contracts, implement secure deletion protocols, conduct DPIAs on automated systems, and refresh privacy notices and staff training. Cross-border transfers should also be reassessed against the law’s requirements.
Yes. Enforcement sits with the Ministry of Transport, Communications and Information Technology, and the law provides for administrative penalties and, in certain cases, fines. Businesses should review the PDPL’s enforcement provisions and its Executive Regulations to confirm the applicable penalties and corrective powers.
By A&M Consulting Co.

posted 2 hours ago

By A&M Consulting Co.

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Oman's Personal Data Protection Law, What Businesses Must Do to Comply

Send welcome message

Custom Message