[codicts-css-switcher id=”346″]

Global Law Experts Logo
omans personal data

Our Expert in Oman

  • GOLD

Oman's Personal Data Protection Law: Who Can Process Personal Data Without Consent

By Global Law Experts
– posted 3 hours ago

Oman’s data protection framework has reshaped two of the most sensitive areas of corporate data handling: employee records and surveillance-camera footage. The Sultanate’s Personal Data Protection Law (PDPL) was enacted by Royal Decree 6/2022 and came into force on 13 February 2023, with its Executive Regulations issued by the Ministry of Transport, Communications and Information Technology (MTCIT). Understanding who may process personal data, and on what lawful basis, is now a central corporate compliance question. For multinationals, HR departments and security operations teams, the practical consequences are immediate.

At a glance: This article explains how Oman’s PDPL regulates the processing of personal data, focusing on territorial scope and the lawful bases relevant to two common activities, processing of employee personal data and surveillance-camera (CCTV) data. It sets out what HR, compliance officers and multinational employers should check, how to update privacy notices and employment contracts, and how to audit security operations, with a step-by-step compliance roadmap and model notice wording. Because the detailed rules sit in the PDPL and its Executive Regulations, readers should confirm specific requirements against the current official texts and with local counsel.

What the PDPL changes, the headline points

Oman’s PDPL introduced, for the first time, a comprehensive statutory framework for personal data protection in the Sultanate. Three themes matter most to corporate counsel. First, the law applies to the processing of personal data and sets out the lawful bases on which processing may proceed. Second, employee personal data and surveillance-camera data are common, high-volume processing activities that require careful analysis of the correct lawful basis and of the supporting controls. Third, the MTCIT, through its Executive Regulations and guidance, sets the detailed obligations that controllers and processors must meet.

Under the PDPL, processing of personal data generally requires the data subject’s consent, subject to exceptions set out in the law and its Executive Regulations. Several routine business activities, including aspects of employment administration and security monitoring, may fall within recognised exceptions or alternative bases rather than depending on individual consent. Organisations that previously relied on consent mechanics for their Oman-facing workforce or their camera estates should re-examine both the lawful basis they invoke and whether they are caught by the law.

The operative detail sits in the statutory text and the Executive Regulations. Each relevant provision should be read against its exact wording; the summaries below are practical interpretations and should be confirmed against the current official texts and with local counsel.

Snapshot: key compliance areas under the PDPL

Issue Position under the PDPL (Royal Decree 6/2022) and Executive Regulations
Territorial scope Applies to processing of personal data in Oman; cross-border transfers are regulated separately
General lawful basis Consent is the default basis, subject to statutory exceptions
Employee data Employment-related processing should be mapped to a lawful basis and supported by notices and controls
CCTV / surveillance Surveillance processing requires a lawful basis, signage, purpose limitation and access controls
Disclosure to third parties Disclosure generally requires a lawful basis and, in many cases, the data subject’s consent
Cross-border transfers Transfers abroad are subject to the PDPL’s transfer provisions and MTCIT requirements
Sensitive data Categories such as health, genetic, biometric and other sensitive data attract heightened protection

Who and what is in scope, the territorial test explained

A threshold question for any organisation is whether its processing falls within the PDPL. The law regulates the processing of personal data within the Sultanate, and corporate groups should analyse their operations carefully rather than assuming they are outside scope. The detailed reach, including how the law treats processing connected to individuals in Oman by entities based abroad, should be confirmed against the PDPL text, the Executive Regulations and MTCIT guidance.

For corporate groups, the practical question is not only “do we have an Omani entity?” but also “do we process data about people in Oman, and where does that processing take place?” A payroll bureau in another Gulf state, a cloud platform hosting an HR system, or a recruitment portal that accepts applications from Oman-based candidates may each raise compliance considerations. The practical burden is to run the analysis deliberately rather than assume an outcome.

Practical scoping checklist for controllers and processors

Work through the following points to help assess whether and how the PDPL may be relevant to your processing:

  • Data subjects. Do you process personal data about identifiable individuals who are in Oman, whether employees, customers or applicants?
  • Targeted services. Do you direct services, platforms or communications towards people located in Oman?
  • Offering goods or services. Do you offer goods or services to individuals in Oman, including in Arabic or priced in Omani rials?
  • Monitoring behaviour. Do you track, profile or monitor the behaviour of individuals while they are in Oman?
  • Geolocation and IP indicators. Do analytics, logs or device signals show users connecting from Oman?
  • Contractual data flows. Do your contracts contemplate the receipt of personal data originating from Oman-based individuals?
  • Hosting locations. Where is the data hosted, and does any onward processing involve data subjects in Oman?
  • Transfer mechanisms. Are there existing transfer tools, data processing agreements or similar arrangements that route Oman-linked data to you?

These points help scope the compliance effort and should be considered alongside local legal advice. The following three scenarios illustrate how the analysis plays out in practice.

Three worked scenarios

  • Cloud provider. A software-as-a-service vendor hosts an Omani employer’s HR platform on servers outside Oman. Because the records relate to individuals in Oman, the vendor is likely a processor whose arrangements should reflect PDPL obligations in its data processing agreement.
  • Regional shared-services centre. A group’s shared-services hub in another Gulf state administers payroll and benefits for Omani staff. Even where processing takes place abroad, the centre should assess PDPL applicability and align its internal controls and transfer arrangements accordingly.
  • Remote HR provider. An offshore outsourced HR function manages recruitment and onboarding for Oman-based hires. Collecting and processing applicant data should prompt a review of notices, lawful-basis documentation and transfer safeguards.

Employee data processing, what employers must know

Employee data processing is the area most HR teams consult first. Employers should identify a lawful basis for processing employee personal data for operational purposes such as payroll administration, performance management, workforce planning and leave records. Consent in the employment context is often difficult to rely on because the imbalance of power can make genuinely free consent problematic, so employers should consider whether a statutory exception or alternative basis is available under the PDPL and its Executive Regulations, and document their analysis.

Whatever basis is relied on, processing must remain within the PDPL’s broader protections, the principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and security continue to apply. A lawful basis does not switch off the rest of the statute. Disclosure of employee data to genuinely separate third parties generally requires a lawful basis and, in many cases, the employee’s consent.

Where consent is still required

Consent, frequently in writing, remains relevant in several situations:

  • Disclosure to third parties. Sharing employee data with external organisations outside the employer’s internal operations generally requires consent unless another lawful basis or mechanism applies.
  • Sensitive data. Categories of data attracting heightened protection under the PDPL continue to require careful handling and, in many cases, explicit grounds.
  • International transfers. Moving employee data outside Oman engages the PDPL’s transfer provisions and may require consent or an appropriate transfer mechanism.

Practical drafting changes for employers

Employers should refresh the documents and controls that underpin HR processing:

  • Privacy notices. Update the employee privacy notice to state the lawful basis for operational processing under the PDPL, and to explain when and how third-party disclosures occur.
  • Employment contract clauses. Revise data-handling clauses to reflect the lawful basis relied on, while preserving a mechanism to capture written consent where disclosures are contemplated.
  • Consent capture. Build a clear, auditable process for obtaining consent specifically for third-party disclosures and transfers.
  • Minimisation and retention. Confirm that HR systems collect only what is needed and apply defensible retention periods.
  • Internal access controls. Restrict access to employee records on a need-to-know basis and log access to demonstrate compliance.

As model wording to adapt to local circumstances, an employee privacy notice paragraph might read: “We process your personal data for operational purposes connected to your employment, relying on the lawful basis set out in the Personal Data Protection Law and its Executive Regulations. We will not disclose your personal data to third parties without your consent, except where the law otherwise permits or requires.” This is illustrative only and should be reviewed by local counsel before use.

CCTV and security processing, scope and limits

Operating CCTV in a workplace, retail environment or public-facing facility cannot realistically depend on the consent of every individual captured on camera. Organisations should identify the lawful basis on which security-driven monitoring proceeds under the PDPL and its Executive Regulations, which may include bases connected to legal or security obligations. Where a camera deployment cannot be tied to an appropriate basis, controllers should reconsider whether and how it operates.

Organisations should identify the specific requirement or basis they rely on, and where a security obligation is imposed by a competent authority, document that obligation. The precise contours of the applicable basis should be confirmed against the current statutory and regulatory texts and any guidance from the MTCIT or relevant security authorities.

CCTV audit checklist

Security and facilities teams should audit camera estates against the following:

  • Location. Map every camera and confirm each placement is justified by the purpose relied upon.
  • Signage. Display clear notices informing individuals that surveillance is in operation and the purpose.
  • Purpose limitation. Use footage only for the identified purpose; avoid repurposing for unrelated monitoring.
  • Retention. Apply and document a defensible retention period, deleting footage once the purpose is spent.
  • Access. Restrict who can view and export footage, and log access.
  • Third-party processors. Where monitoring is outsourced, ensure the provider is bound by appropriate PDPL-aligned terms.

Examples across different environments

  • Mall security. A shopping centre operating cameras for security purposes should document its lawful basis and ensure signage, retention and access controls are in place.
  • Corporate office. An employer monitoring entrances and server rooms for security should tie each camera to a clear security purpose and avoid drifting into general employee monitoring.
  • Cross-border monitoring. Where footage of individuals in Oman is reviewed from a security operations centre abroad, the organisation should assess PDPL applicability and transfer requirements.

Cross-border implications and transfers, how data moves

Cross-border processing requires careful transfer analysis. Routing Oman-linked data offshore does not necessarily remove the relevance of the PDPL, and organisations should confirm the applicable requirements for international transfers under the law and its Executive Regulations.

This matters most where personal data is shared with external processors or transferred internationally. Treat transfers to external payroll bureaux, HR platforms or analytics providers as potential third-party disclosures, which may require the data subject’s consent unless another lawful basis or transfer mechanism applies. Where personal data is moved across borders, the PDPL’s transfer provisions govern, and organisations should confirm whether consent, contractual safeguards such as data processing agreements, or other recognised mechanisms are required. The OECD’s guidance on transborder data flows remains a useful policy-level reference, though the operative requirements are those of the PDPL.

Interaction with other Gulf regimes

Several Gulf states have adopted their own data protection frameworks, and some include extraterritorial features. For groups operating across the region, this can create overlapping obligations where the same dataset is subject to more than one national law. A practical response is a harmonised baseline that satisfies the strictest applicable requirement, combined with jurisdiction-specific layers where local law demands them. This is comparative framing only; each regime must be applied on its own terms with local advice.

Practical compliance steps, a 12-week implementation roadmap

Multinationals should treat PDPL compliance as a structured project rather than an open-ended review. The following roadmap sequences the work over roughly twelve weeks.

  1. Run the scoping analysis. Apply the checklist across every business unit to determine PDPL applicability.
  2. Map data flows. Inventory where Oman-linked data subjects’ information is collected, stored and processed.
  3. Update employee privacy notices and contracts. Reflect the lawful basis relied on and the consent requirement for third-party disclosures.
  4. Audit CCTV and security operations. Apply the camera checklist and tie each deployment to a clear purpose and basis.
  5. Update processor contracts. Ensure external processors are bound by PDPL-aligned terms.
  6. Update data transfer tools. Confirm consent, agreements or mechanisms for international transfers.
  7. Train staff. Brief HR, security and management on the lawful bases and their limits.
  8. Keep records and run impact assessments where required. Document lawful bases and assess higher-risk processing.
  9. Appoint a point of accountability. Consider whether a data protection function or local contact is needed.
  10. Maintain a regulatory watchlist. Monitor MTCIT guidance and any amendments to the framework.
  11. Implement breach response. Establish detection, assessment and notification processes consistent with the PDPL.
  12. Report to the board. Provide leadership with a clear view of residual risk.

A simple prioritisation matrix helps allocate effort: treat the scoping analysis, privacy-notice updates and CCTV audit as high priority; processor contracts, transfer tools and training as medium; and recordkeeping refinements and board reporting as ongoing. The exact weighting will depend on how much Oman-linked data each organisation handles.

How to document lawful bases and evidence for auditors or the regulator

Relying on a lawful basis is only defensible if you can show your working. Maintain a record that demonstrates, for each processing activity, which basis you rely on and why. Recommended documentation includes:

  • Lawful-basis entries. A register recording the lawful basis for each relevant activity under the PDPL.
  • Data protection impact assessments. For higher-risk processing, documented assessments of risk and mitigation.
  • Retention justification. Written rationale for retention periods, particularly for CCTV footage.
  • Access logs. Records showing who accessed employee data or surveillance footage and when.
  • Consent records. Evidence of consent captured for third-party disclosures and transfers.

Practical examples and short case studies

  • Multinational payroll provider. A group payroll team abroad processes Omani staff records. After running the scoping analysis, it confirms PDPL relevance, documents the lawful basis for operational processing, and captures consent before sharing data with an external benefits administrator.
  • Regional security monitoring firm. A contractor monitors cameras at Omani sites from an offshore operations centre. It documents the lawful basis, implements retention limits and access logs, and updates its service agreement to reflect PDPL obligations and transfer requirements.
  • Remote recruitment platform. An offshore recruitment portal receiving Oman-based applications updates its applicant privacy notice, restricts internal access, and treats any sharing with hiring clients as a third-party disclosure requiring an appropriate basis.

Key risks and enforcement considerations

Compliance attention is likely to focus on whether organisations have genuinely analysed their scope, whether privacy notices and contracts reflect the correct lawful bases, and whether cross-border arrangements are properly documented. Foreign controllers who historically assumed they were outside Omani law should review their position carefully. Organisations should avoid speculation about specific penalties and instead focus on demonstrable compliance: any administrative consequences or remedial orders will turn on the facts and the operative statutory language. The safest posture is to close obvious gaps, unupdated notices, undocumented lawful bases, unaudited camera estates, before any regulatory engagement arises.

Conclusion, what to do next

Oman’s PDPL demands a deliberate response from every organisation touching the data of individuals in Oman. Three priority actions are clear: run the scoping analysis across your operations; update employee privacy notices and contracts to reflect the correct lawful basis and the consent requirements for third-party disclosures; and audit your CCTV estate against the PDPL’s requirements for signage, purpose limitation, retention and access. Because the framework is supported by Executive Regulations and MTCIT guidance that may evolve, treat the position as live and keep it under review. Confirm your analysis against the current official texts and take bespoke local advice before finalising your compliance posture.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Ahmed Al Barwani at Al Barwani & Co, a member of the Global Law Experts network.

Sources

  1. Sultanate of Oman, Official Government Portal
  2. Ministry of Transport, Communications and Information Technology (MTCIT)
  3. European Union, General Data Protection Regulation (GDPR)
  4. OECD, Guidelines on the Protection of Privacy and Transborder Flows of Personal Data

FAQs

Does Oman's PDPL apply to companies outside Oman?
It can be relevant to processing connected to individuals in Oman, depending on the circumstances. Foreign controllers and processors should run the scoping analysis using the checklist above and confirm their position against the PDPL, its Executive Regulations and MTCIT guidance with local counsel.
Employers should identify a lawful basis for employment-related processing. In some cases a statutory exception or alternative basis may apply rather than consent, but processing must remain within the PDPL’s protections, and disclosure to third parties generally requires consent or another lawful basis.
Surveillance-camera processing must rest on an appropriate lawful basis under the PDPL, which may include bases connected to security obligations. Core compliance steps, signage, purpose limitation, retention controls and access restrictions, remain essential, and the applicable basis should be confirmed against the current texts.
Possibly. If the transfer amounts to disclosure to a third party, consent may be required unless another lawful basis or transfer mechanism applies. Treat transfers to external processors as potential third-party disclosures and review them against the PDPL’s transfer provisions.
Monitor publications from the MTCIT and the Official Gazette, and treat regulatory developments and guidance as a standing watch item in your compliance programme.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Oman's Personal Data Protection Law: Who Can Process Personal Data Without Consent

Send welcome message

Custom Message