Our Expert in Oman
No results available
Oman’s data protection framework has reshaped two of the most sensitive areas of corporate data handling: employee records and surveillance-camera footage. The Sultanate’s Personal Data Protection Law (PDPL) was enacted by Royal Decree 6/2022 and came into force on 13 February 2023, with its Executive Regulations issued by the Ministry of Transport, Communications and Information Technology (MTCIT). Understanding who may process personal data, and on what lawful basis, is now a central corporate compliance question. For multinationals, HR departments and security operations teams, the practical consequences are immediate.
At a glance: This article explains how Oman’s PDPL regulates the processing of personal data, focusing on territorial scope and the lawful bases relevant to two common activities, processing of employee personal data and surveillance-camera (CCTV) data. It sets out what HR, compliance officers and multinational employers should check, how to update privacy notices and employment contracts, and how to audit security operations, with a step-by-step compliance roadmap and model notice wording. Because the detailed rules sit in the PDPL and its Executive Regulations, readers should confirm specific requirements against the current official texts and with local counsel.
Oman’s PDPL introduced, for the first time, a comprehensive statutory framework for personal data protection in the Sultanate. Three themes matter most to corporate counsel. First, the law applies to the processing of personal data and sets out the lawful bases on which processing may proceed. Second, employee personal data and surveillance-camera data are common, high-volume processing activities that require careful analysis of the correct lawful basis and of the supporting controls. Third, the MTCIT, through its Executive Regulations and guidance, sets the detailed obligations that controllers and processors must meet.
Under the PDPL, processing of personal data generally requires the data subject’s consent, subject to exceptions set out in the law and its Executive Regulations. Several routine business activities, including aspects of employment administration and security monitoring, may fall within recognised exceptions or alternative bases rather than depending on individual consent. Organisations that previously relied on consent mechanics for their Oman-facing workforce or their camera estates should re-examine both the lawful basis they invoke and whether they are caught by the law.
The operative detail sits in the statutory text and the Executive Regulations. Each relevant provision should be read against its exact wording; the summaries below are practical interpretations and should be confirmed against the current official texts and with local counsel.
| Issue | Position under the PDPL (Royal Decree 6/2022) and Executive Regulations |
|---|---|
| Territorial scope | Applies to processing of personal data in Oman; cross-border transfers are regulated separately |
| General lawful basis | Consent is the default basis, subject to statutory exceptions |
| Employee data | Employment-related processing should be mapped to a lawful basis and supported by notices and controls |
| CCTV / surveillance | Surveillance processing requires a lawful basis, signage, purpose limitation and access controls |
| Disclosure to third parties | Disclosure generally requires a lawful basis and, in many cases, the data subject’s consent |
| Cross-border transfers | Transfers abroad are subject to the PDPL’s transfer provisions and MTCIT requirements |
| Sensitive data | Categories such as health, genetic, biometric and other sensitive data attract heightened protection |
A threshold question for any organisation is whether its processing falls within the PDPL. The law regulates the processing of personal data within the Sultanate, and corporate groups should analyse their operations carefully rather than assuming they are outside scope. The detailed reach, including how the law treats processing connected to individuals in Oman by entities based abroad, should be confirmed against the PDPL text, the Executive Regulations and MTCIT guidance.
For corporate groups, the practical question is not only “do we have an Omani entity?” but also “do we process data about people in Oman, and where does that processing take place?” A payroll bureau in another Gulf state, a cloud platform hosting an HR system, or a recruitment portal that accepts applications from Oman-based candidates may each raise compliance considerations. The practical burden is to run the analysis deliberately rather than assume an outcome.
Work through the following points to help assess whether and how the PDPL may be relevant to your processing:
These points help scope the compliance effort and should be considered alongside local legal advice. The following three scenarios illustrate how the analysis plays out in practice.
Employee data processing is the area most HR teams consult first. Employers should identify a lawful basis for processing employee personal data for operational purposes such as payroll administration, performance management, workforce planning and leave records. Consent in the employment context is often difficult to rely on because the imbalance of power can make genuinely free consent problematic, so employers should consider whether a statutory exception or alternative basis is available under the PDPL and its Executive Regulations, and document their analysis.
Whatever basis is relied on, processing must remain within the PDPL’s broader protections, the principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and security continue to apply. A lawful basis does not switch off the rest of the statute. Disclosure of employee data to genuinely separate third parties generally requires a lawful basis and, in many cases, the employee’s consent.
Consent, frequently in writing, remains relevant in several situations:
Employers should refresh the documents and controls that underpin HR processing:
As model wording to adapt to local circumstances, an employee privacy notice paragraph might read: “We process your personal data for operational purposes connected to your employment, relying on the lawful basis set out in the Personal Data Protection Law and its Executive Regulations. We will not disclose your personal data to third parties without your consent, except where the law otherwise permits or requires.” This is illustrative only and should be reviewed by local counsel before use.
Operating CCTV in a workplace, retail environment or public-facing facility cannot realistically depend on the consent of every individual captured on camera. Organisations should identify the lawful basis on which security-driven monitoring proceeds under the PDPL and its Executive Regulations, which may include bases connected to legal or security obligations. Where a camera deployment cannot be tied to an appropriate basis, controllers should reconsider whether and how it operates.
Organisations should identify the specific requirement or basis they rely on, and where a security obligation is imposed by a competent authority, document that obligation. The precise contours of the applicable basis should be confirmed against the current statutory and regulatory texts and any guidance from the MTCIT or relevant security authorities.
Security and facilities teams should audit camera estates against the following:
Cross-border processing requires careful transfer analysis. Routing Oman-linked data offshore does not necessarily remove the relevance of the PDPL, and organisations should confirm the applicable requirements for international transfers under the law and its Executive Regulations.
This matters most where personal data is shared with external processors or transferred internationally. Treat transfers to external payroll bureaux, HR platforms or analytics providers as potential third-party disclosures, which may require the data subject’s consent unless another lawful basis or transfer mechanism applies. Where personal data is moved across borders, the PDPL’s transfer provisions govern, and organisations should confirm whether consent, contractual safeguards such as data processing agreements, or other recognised mechanisms are required. The OECD’s guidance on transborder data flows remains a useful policy-level reference, though the operative requirements are those of the PDPL.
Several Gulf states have adopted their own data protection frameworks, and some include extraterritorial features. For groups operating across the region, this can create overlapping obligations where the same dataset is subject to more than one national law. A practical response is a harmonised baseline that satisfies the strictest applicable requirement, combined with jurisdiction-specific layers where local law demands them. This is comparative framing only; each regime must be applied on its own terms with local advice.
Multinationals should treat PDPL compliance as a structured project rather than an open-ended review. The following roadmap sequences the work over roughly twelve weeks.
A simple prioritisation matrix helps allocate effort: treat the scoping analysis, privacy-notice updates and CCTV audit as high priority; processor contracts, transfer tools and training as medium; and recordkeeping refinements and board reporting as ongoing. The exact weighting will depend on how much Oman-linked data each organisation handles.
Relying on a lawful basis is only defensible if you can show your working. Maintain a record that demonstrates, for each processing activity, which basis you rely on and why. Recommended documentation includes:
Compliance attention is likely to focus on whether organisations have genuinely analysed their scope, whether privacy notices and contracts reflect the correct lawful bases, and whether cross-border arrangements are properly documented. Foreign controllers who historically assumed they were outside Omani law should review their position carefully. Organisations should avoid speculation about specific penalties and instead focus on demonstrable compliance: any administrative consequences or remedial orders will turn on the facts and the operative statutory language. The safest posture is to close obvious gaps, unupdated notices, undocumented lawful bases, unaudited camera estates, before any regulatory engagement arises.
Oman’s PDPL demands a deliberate response from every organisation touching the data of individuals in Oman. Three priority actions are clear: run the scoping analysis across your operations; update employee privacy notices and contracts to reflect the correct lawful basis and the consent requirements for third-party disclosures; and audit your CCTV estate against the PDPL’s requirements for signage, purpose limitation, retention and access. Because the framework is supported by Executive Regulations and MTCIT guidance that may evolve, treat the position as live and keep it under review. Confirm your analysis against the current official texts and take bespoke local advice before finalising your compliance posture.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Ahmed Al Barwani at Al Barwani & Co, a member of the Global Law Experts network.
posted 23 seconds ago
posted 20 minutes ago
posted 41 minutes ago
posted 44 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message