Our Expert in Oman
No results available
Oman’s Personal Data Protection Law (PDPL), issued by Royal Decree 6/2022 and supplemented by Executive Regulations issued in 2024, reaches directly into the compliance obligations of every organisation that processes the personal data of individuals in Oman. The framework addresses the law’s territorial scope, imposes obligations on both controllers and processors, sets rules on data retention and deletion, and governs automated processing and cross-border transfers. For corporate counsel, data protection officers and in-house compliance teams, the PDPL and its regulations demand ongoing review of data flows, contracts and retention practices. This explainer sets out the key requirements, why they matter, and the practical steps businesses should take.
Quick summary. Who is affected: controllers and processors operating in Oman, and (where applicable) those processing the personal data of individuals in Oman. What the law requires: a lawful basis for processing, defined retention and deletion practices, safeguards around automated processing, and controls on cross-border transfers. Immediate actions: map your data, update contracts and privacy notices, and build a delete-or-archive plan.
Oman’s Personal Data Protection Law establishes a comprehensive framework for the processing of personal data and increases the compliance burden on organisations handling personal data connected to Oman. The law was issued by Royal Decree 6/2022, came into force in February 2023 (one year after publication), and is supplemented by Executive Regulations issued by the Ministry of Transport, Communications and Information Technology (MTCIT), which is the competent authority. The regulations clarify obligations that many organisations had previously treated as best practice rather than legal requirement.
The headline features of the framework are:
Oman’s data protection regime sits within a broader period of legislative modernisation across the Gulf, with several GCC states having enacted or updated their own data protection laws in recent years. Organisations operating regionally should read the Omani requirements alongside those of the other jurisdictions in which they operate.
The territorial reach of the PDPL is an important threshold question for any organisation. Businesses operating outside Oman but processing the personal data of people in Oman, for example, foreign e-commerce platforms, cloud service providers, or multinational groups serving Omani customers from abroad, should carefully assess whether and how the law and its regulations apply to their activities, and should seek local advice where the position is unclear.
In practical terms, organisations should not assume they sit outside the law’s reach simply because their servers or headquarters are located elsewhere. Local branches of international firms, and international firms with an Omani-facing customer base or workforce, should each assess their exposure and document the assessment that led them to their conclusion.
Application generally turns on the connection between the processing and people in Oman. The key factors to test against your operations include whether your organisation processes personal data in Oman, offers goods or services to individuals in Oman, and whether it monitors the behaviour of individuals located in Oman, for example through analytics, tracking, or profiling. Where the framework is engaged, controllers should document the assessment. Organisations that are uncertain should err towards compliance and take local advice rather than assume they fall outside scope, because the cost of remediation after an enforcement inquiry is materially higher than proactive alignment.
Data protection laws inevitably raise questions of practical enforcement and overlap with other jurisdictions’ regimes. A multinational may find itself subject to Oman’s PDPL alongside the requirements of other GCC states and international frameworks, creating potential conflicts on issues such as lawful bases, data localisation and cross-border transfer conditions. Businesses should manage overlap by mapping their obligations jurisdiction by jurisdiction and applying the most protective standard where requirements diverge. Maintaining clear records will assist both compliance and any future dialogue with the competent authority.
One of the most operationally demanding features of the PDPL framework is the expectation that personal data is not kept longer than necessary. Personal data should generally be deleted or anonymised once the purpose for which it was collected has been fulfilled. This moves data minimisation and purpose limitation from aspirational principle towards enforceable duty, and it is relevant not only to controllers who determine why and how data is processed, but also to the processors acting on their instructions.
Retention is subject to lawful exceptions. Personal data may be retained where there is a continuing legal basis, for example, to comply with a statutory retention requirement, to establish, exercise or defend legal claims, or to serve a legitimate archiving or public-interest purpose. Crucially, the burden of justifying continued retention sits with the organisation. Where a business keeps data beyond the point at which the original purpose ends, it should be able to point to a specific, documented lawful basis for doing so.
For most organisations, meeting these expectations requires a systematic review of retention schedules. Data that has historically been kept indefinitely “just in case” now carries clear legal risk. A practical deletion programme should include the following elements:
Accountability runs through the PDPL framework, and deletion is no exception. Organisations should maintain records that demonstrate not only that data was deleted, but when, how, and on whose instruction. Where data is retained under an exception, the record should capture the specific lawful basis and the review date. For processors, erasure logs and deletion confirmations provided back to the controller create an evidential trail regulators may expect to see. Robust recordkeeping is one of the most effective ways to convert a legal obligation into a defensible compliance posture, and it should be embedded in standard operating procedures rather than treated as an afterthought.
Because obligations reach processors as well as controllers, existing data processing agreements will often need revision. Controllers should update contracts to specify deletion timelines, secure erasure standards, and the treatment of data at the end of the engagement. Processors, in turn, should ensure that these obligations flow down to any subprocessors they engage, so that requirements are honoured throughout the supply chain. Where legacy contracts are silent on deletion, or defer entirely to the controller without defined standards, they should be prioritised for amendment. Contract remediation is often the longest lead-time item in a compliance programme, so it should begin early.
The table below summarises how key duties under the PDPL framework typically apply to controllers and processors respectively.
| Duty / Topic | Controllers | Processors |
|---|---|---|
| Deletion when purpose fulfilled | Responsibility to delete personal data no longer required and to ensure processors comply; should document justification for any retention exception | Should delete data on controller instruction and when the purpose is fulfilled; should securely erase and provide proof to the controller |
| Recordkeeping | Maintain records of processing activities and retention decisions | Maintain processing records, erasure logs and deletion confirmations to controllers |
| Contractual requirements | Should update contracts to include deletion timelines, security standards and subprocessor terms | Should accept the controller’s deletion requirements and flow them down to subprocessors |
| Liability exposure | Primary responsibility for lawful basis and retention decisions; may face administrative penalties | Exposure for failing to delete or secure data; may face contractual and regulatory consequences |
| Impact assessments / automated processing | Should assess high-risk profiling and ensure data-subject safeguards | Should support the controller’s assessments and implement technical controls for automated processing |
A further pillar of the PDPL framework concerns automated processing. As organisations increasingly rely on algorithmic decision-making, machine learning and data-driven analytics, businesses should expect scrutiny around transparency, oversight and risk management. The direction of travel mirrors the wider global consensus that decisions made by automated systems, particularly those with a material effect on individuals, require additional safeguards.
In practice, businesses deploying automated processing should focus on three disciplines. First, transparency: individuals should be told, in clear terms, when automated processing is used and what it means for them. Second, risk assessment: high-risk processing should be evaluated through a data protection impact assessment (DPIA) that identifies risks to individuals and the measures taken to mitigate them. Third, human oversight: where automated decisions materially affect a person, there should be meaningful human involvement rather than a purely mechanical outcome, unless a specific lawful basis permits otherwise.
For teams building or procuring AI and machine-learning systems, the compliance work should begin at the design stage. Consider whether consent or another lawful basis supports the processing, document the choice, and revisit it as the system evolves. Vendors and internal development teams should be briefed on these requirements so that safeguards are engineered in rather than retrofitted.
Human intervention becomes important where an automated decision produces legal effects or similarly significant consequences for an individual, for example decisions affecting access to credit, employment, or essential services. In those cases, organisations should ensure a qualified person can review the decision, take account of additional information the individual provides, and, where appropriate, override the automated outcome. The intervention should be genuine rather than a rubber stamp; a reviewer who simply confirms the algorithm’s result without independent assessment is unlikely to satisfy the spirit of the law. Building a clear escalation pathway and training reviewers accordingly is the practical response.
Individuals subject to automated processing should be able to understand how decisions about them are reached and to challenge outcomes they consider unfair. Practically, this means providing accessible explanations of the logic involved, offering a route to request human review, and responding to objections within reasonable timeframes. Organisations should update their privacy notices to describe automated processing in plain language and establish internal procedures for handling explanation and review requests. Treating these rights as operational workflows, with named owners and service standards, is far more effective than treating them as legal formalities that surface only when a complaint arrives.
Enforcement of the PDPL sits with the competent authority, the Ministry of Transport, Communications and Information Technology. The law provides for administrative penalties and, in certain cases, fines and other sanctions for non-compliance. Organisations should assume that the authority has the tools to investigate, issue corrective orders and impose penalties on those who fail to meet their obligations. Reputational exposure is also a real risk: enforcement action against data-handling failures tends to attract public attention, and the commercial cost of lost customer trust can exceed any financial penalty.
From a practical risk-management perspective, the most effective mitigations are proactive. Businesses that identify gaps and remediate them voluntarily, updating contracts, deleting data that should no longer be held, and documenting their decisions, are in a materially stronger position than those who wait for an inquiry. Where a compliance failure is identified internally, early self-assessment and prompt correction demonstrate good faith. Maintaining an incident response plan, so that any breach or non-compliance can be addressed quickly and transparently, is a core component of resilience. Businesses should verify the precise enforcement and penalty provisions in the published text of the PDPL and its Executive Regulations before finalising their risk assessments.
The following nine steps translate the PDPL framework into an actionable programme. Each should be assigned an owner and a target date.
Oman’s data protection framework should be read alongside the country’s wider regulatory environment, which has seen active modernisation across sectors including foreign investment, mining and infrastructure. Organisations active in sectors that generate significant data, such as banking, telecommunications, mining, and cross-border logistics and transport, should read the data protection requirements alongside the sector-specific rules that apply to their operations. Cross-border infrastructure projects, in particular, can generate substantial data-sharing that engages both transfer and territorial-scope considerations under the PDPL. Where a project spans more than one jurisdiction, businesses should coordinate their data protection compliance across each relevant regime.
The following illustrative scenarios show how the framework reshapes obligations in different contexts.
A local bank. An Omani bank retains customer records long after accounts are closed. Under the retention and deletion expectations, it should identify when the purpose for holding each category of data ends, delete data that is no longer required, and document a lawful basis, such as statutory record-keeping, for anything it retains. Its automated credit-scoring system would benefit from a DPIA and a human-review pathway.
A multinational technology firm. A company headquartered abroad offers a consumer app to users in Oman. Because it processes the personal data of people in Oman, it should assess whether the PDPL applies to its activities, take local advice, align retention and deletion practices, and update its privacy notice to reflect Omani requirements.
A cross-border logistics operator. A logistics business sharing operational data across a cross-border route should map its transfers, ensure processor contracts include deletion and security terms, and confirm that any automated routing or analytics systems meet transparency and oversight expectations.
Oman’s Personal Data Protection Law materially raises the bar for how organisations handle personal data connected to Oman. Its territorial reach means many foreign organisations should assess whether they fall within the law’s ambit; its retention and deletion expectations reinforce data minimisation as a practical duty for both controllers and processors; and its treatment of automated processing calls for transparency, oversight and structured risk assessment. The three most urgent actions for counsel and compliance teams are to map data flows and confirm whether the law applies, to build and implement a delete-or-archive programme with documented retention justifications, and to review contracts and automated systems against the law’s requirements.
Organisations that act proactively, rather than after an enforcement inquiry, will be best placed to manage risk and demonstrate accountability. Given that specific obligations are set out in the PDPL and its Executive Regulations, businesses should confirm the current text and take local legal advice before finalising their compliance programmes.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Ahmed Al Barwani at Al Barwani & Co, a member of the Global Law Experts network.
posted 44 minutes ago
posted 44 minutes ago
posted 45 minutes ago
posted 45 minutes ago
posted 47 minutes ago
posted 50 minutes ago
posted 51 minutes ago
posted 51 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message