[codicts-css-switcher id=”346″]

Global Law Experts Logo
omans royal decree 68 2026 amends

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Oman: Royal Decree 68/2026 Amends the Personal Data Protection Law, What Businesses Must Do

By Global Law Experts
– posted 51 minutes ago

Who this article is for: legal and compliance teams, in-house counsel, data protection officers, CIOs, and HR and marketing leads of businesses operating in or with Oman.

What you’ll get: an authoritative summary of the RD68/2026 amendments, a side-by-side comparison with the prior law, a practical compliance checklist, sample retention and deletion policy language, and a business-focused FAQ.

Lede and executive summary

Oman’s Royal Decree 68/2026 amends the Personal Data Protection Law and, in doing so, reshapes the compliance obligations of every organisation that touches personal data connected to Oman. Issued on 3 September 2026 as part of a wider legislative package, the decree modifies the framework first established under Royal Decree 6/2022. The headline changes reported include a clarified territorial scope, an obligation to delete personal data once the purpose of processing has been fulfilled, and clarified treatment of automated processing, together with amendments touching consent for direct marketing and permitted exceptions. For businesses inside and outside the Sultanate, the practical effect is immediate, retention schedules, cross-border arrangements and automated decision-making systems should all be reviewed against the amended text.

This analysis explains what the decree does in general terms, sets out the relevant statutory context, and provides a prioritised compliance roadmap. Where the amended law leaves room for interpretation, we flag those points as practical interpretations rather than settled conclusions, so your legal and compliance teams can plan on a conservative footing. The core message is straightforward: Oman’s Royal Decree 68/2026 amends a law that already carried substantial obligations, and it tightens them in ways that demand documented, auditable action. Because the operative wording governs, businesses should verify each point against the official decree text.

Organisations should treat the amendments as a trigger for a full data-protection review. The territorial reach means that companies without a physical presence in Oman may nonetheless fall within scope, while the deletion duty raises the operational bar for record-keeping and lifecycle management. The sections below translate the statutory changes into concrete steps.

Background: the PDPL and the 3 September 2026 Royal Decrees package

To understand why Oman’s Royal Decree 68/2026 amends the framework the way it does, it helps to place the decree in its legislative context. The Personal Data Protection Law was introduced by Royal Decree 6/2022, establishing Oman’s comprehensive statutory regime for the processing of personal data. That law set out core concepts familiar from international data-protection regimes, lawful bases for processing, obligations on those who determine the purposes of processing (controllers) and those who process on their behalf (processors), and rights for individuals whose data is processed. Executive Regulations issued under the law (by Ministerial Decision) provide operational detail.

Timeline of the PDPL and key milestones

The trajectory of Oman’s data-protection law can be summarised as follows:

  • Royal Decree 6/2022. The Personal Data Protection Law is promulgated, creating the primary statutory framework for personal data in Oman.
  • Implementation and grace period. Following enactment, businesses were expected to align their practices with the statutory requirements. The compliance grace period, initially set to end in early 2025, was extended by ministerial decision, with attention focused on notices, consent and processing records.
  • Royal Decree 68/2026. Issued on 3 September 2026, this decree amends provisions of the Personal Data Protection Law following review by the Council of Oman.

The amendment does not replace the original law; it modifies specific provisions. That means the definitions, principles and enforcement architecture established under Royal Decree 6/2022 continue to apply, read together with the changes made by the 2026 decree.

The 3 September 2026 package and which decrees matter commercially

Royal Decree 68/2026 was one of a group of decrees issued on the same date. While several of those decrees address distinct subject areas, RD68/2026 is the one of direct concern to privacy and data-protection compliance. For businesses monitoring the broader regulatory environment, it is prudent to review the full package to identify any sectoral measures that may intersect with data handling, but the data-protection compliance obligations flow specifically from the decree that amends the Personal Data Protection Law. Companies should confirm the precise scope and numbering of any related decrees against the official portal rather than relying on secondary summaries.

Key amendments introduced by Royal Decree 68/2026

The heart of this article is what Oman’s Royal Decree 68/2026 amends in operational terms. The decree makes several targeted changes to the Personal Data Protection Law. Below we explain each in plain English, note its likely legal effect, and set out the immediate compliance action it demands. Because statutory wording governs, businesses should always verify the exact text against the official decree before finalising policy language.

Territorial scope

A consequential area of change concerns the reach of the law. As amended, the Personal Data Protection Law is reported to address the personal data of natural persons whether they are located inside or outside Oman, where the law’s territorial triggers are met. In practical terms, this reduces any argument that the regime is confined to processing carried out solely within the Sultanate’s borders. Businesses should confirm the precise wording and any qualifying conditions against the official text.

Legal effect. Organisations established outside Oman that process personal data with a relevant connection to Oman, for example, data relating to individuals in Oman, may fall within the statute’s obligations. This mirrors the direction of travel in other modern data-protection regimes, where physical presence is no longer the sole determinant of applicability.

Immediate compliance action. Map where personal data connected to Oman is collected and processed, including by group entities and vendors located abroad. Identify any processing that previously sat outside your Oman compliance perimeter and reassess it against the amended scope.

Deletion obligation for controllers and processors

Royal Decree 68/2026 is reported to introduce or clarify an obligation to delete personal data once the purpose for which it was collected has been fulfilled. Where this duty is directed at both controllers and processors, organisations should not assume that responsibility for erasure rests solely with the party that determined the purpose of processing.

Legal effect. Any deletion duty is subject to legal exceptions and retention requirements, for example, where other laws require records to be kept for a defined period. The default position is that data should not be retained indefinitely once its processing purpose is spent, converting what many organisations treated as good practice into a compliance obligation.

Immediate compliance action. Establish or refresh a retention schedule that ties each category of personal data to a defined purpose and a defined retention period. Implement documented deletion procedures and maintain deletion logs so you can demonstrate compliance. Where a legal retention requirement applies, record the legal basis for continued storage.

Sample deletion policy language to adapt: “Personal data will be securely deleted, anonymised or destroyed once the purpose for which it was collected has been fulfilled, unless a specific legal or regulatory obligation requires its retention for a defined period. Where retention is required, the legal basis and retention period will be recorded, and the data will be deleted promptly upon expiry of that period. Deletion actions will be logged to provide an auditable record.”

Consent for direct marketing

Reporting on the amendment indicates a strengthened requirement that controllers obtain the data subject’s explicit consent before sending commercial advertising or marketing communications. The amended framework also preserves specific legal exceptions, including data processed for media and press purposes.

Immediate compliance action. Review your marketing consent capture and record-keeping to ensure explicit, demonstrable consent is obtained before direct marketing, and provide a clear mechanism to withdraw consent.

Automated processing: definitions and treatment

The decree is reported to clarify how automated processing is treated under the Personal Data Protection Law. As organisations increasingly deploy automated profiling and decision-making, from credit and eligibility scoring to marketing segmentation, clear rules on transparency and risk assessment become essential.

Legal effect. Entities relying on automated processing should expect obligations around transparency and, as a matter of prudent practice, the assessment of risks arising from such processing.

Immediate compliance action. Inventory systems that carry out automated profiling or automated decision-making affecting individuals. Assess the risks these systems present, ensure the required disclosures are made to data subjects, and build a defensible record of how each system operates and what safeguards are in place. Where automated processing could produce significant effects on individuals, a data protection impact assessment (DPIA) is a sensible control.

Miscellaneous technical amendments

Alongside the headline changes, Royal Decree 68/2026 amends the Personal Data Protection Law with technical adjustments that support the substantive reforms, for instance, refinements that align definitions and operational provisions with the clarified scope and lifecycle obligations. Businesses should read the amended text in full to identify any definitional shifts that affect how their processing is classified, and confirm the effective date stated in the decree so that internal deadlines are calibrated correctly.

Practical compliance steps for businesses

Understanding what Oman’s Royal Decree 68/2026 amends is only the starting point; the value lies in converting the changes into a prioritised, auditable programme of work. The checklist below is organised by timeframe. Adjust the sequencing to your organisation’s risk profile and processing footprint.

Immediate actions (0–30 days)

  • Legal and gap review. Commission a focused legal review of the amended Personal Data Protection Law against your current practices, prioritising the headline changes.
  • Data-flow mapping for territorial footprint. Map all personal data connected to Oman, including data processed by overseas group entities and third-party vendors, to determine what falls within scope.
  • Retention schedule triage. Identify categories of personal data held beyond their purpose and flag them for deletion or documented retention.
  • Confirm the effective date. Verify the effective date in the decree and set internal deadlines accordingly.

Short term (30–90 days)

  • Update privacy notices. Revise notices to reflect the clarified scope, retention and deletion practices, marketing consent, and any automated processing disclosures.
  • Update contracts and data processing agreements. Amend agreements with processors to reflect the deletion obligation, and to allocate responsibility for erasure clearly.
  • Implement deletion procedures. Operationalise deletion so that data is removed when its purpose is fulfilled, with proof-of-deletion records.

Sample DPA deletion clause to adapt: “Upon fulfilment of the processing purpose, or upon termination of this Agreement, the Processor shall, at the Controller’s option, delete or return all personal data processed on the Controller’s behalf, and shall delete existing copies unless retention is required by applicable law. The Processor shall provide the Controller with written confirmation of deletion and shall maintain a log evidencing the deletion actions taken.”

Medium term (90–180 days)

  • DPIAs for automated processing. Conduct impact assessments for systems that carry out automated profiling or decision-making with significant effects on individuals.
  • Strengthen security and access controls. Review technical and organisational measures, including access controls, to protect personal data throughout its lifecycle.
  • Staff training. Train teams in HR, marketing, IT and operations on the amended obligations, particularly deletion duties, marketing consent and automated-processing transparency.

Documentation and audit trail

Demonstrable compliance depends on records. Maintain the following as living documents:

  • Retention and deletion logs. Evidence of what was retained, on what legal basis, and when data was deleted.
  • Consent and lawful-basis records. A clear record of the basis relied upon for each processing activity, including marketing consent.
  • Cross-border transfer records. Documentation of transfers, the safeguards applied, and the assessments undertaken.
  • Automated processing register. A description of each automated system, its purpose, the disclosures made, and the safeguards in place.

Sample automated-processing transparency clause to adapt: “Where personal data is subject to automated processing, including profiling, the Controller will inform data subjects of the existence of such processing, its purpose and the categories of data involved, and will assess and document the risks arising from that processing before deployment.”

Cross-border data transfers and territorial application

Because Oman’s Royal Decree 68/2026 amends the law in ways that touch personal data of natural persons inside and outside the Sultanate, cross-border processing sits at the centre of the compliance analysis. Controllers and processors located outside Oman that handle personal data connected to Oman should not assume they are beyond the law’s reach.

When does territorial reach apply?

The practical question for any overseas organisation is whether a territorial nexus to Oman exists, for example, whether it processes the personal data of individuals in Oman. Where such a connection is present and the statutory triggers are met, the amended law’s obligations may apply. Organisations should carry out a documented assessment of their processing activities to determine whether they fall within scope, rather than relying on the absence of a physical presence in Oman.

Transfer mechanisms and safeguards

The Personal Data Protection Law and its Executive Regulations govern the transfer of personal data outside Oman, and detailed conditions may be set by the competent authority. A conservative approach is to rely on contractual safeguards and structured risk assessments, verified against the current regulations. Practical interim measures include:

  • Contractual measures. Incorporate robust data-protection clauses into agreements governing international transfers, addressing security, purpose limitation, deletion and onward transfer.
  • Technical measures. Apply encryption, access controls and pseudonymisation where appropriate to reduce transfer risk.
  • Risk assessment. Document the risk assessment underpinning each transfer, including the recipient’s ability to meet the required standards.

Recordkeeping for international transfers

Maintain a register of cross-border transfers that records the data categories, recipients, destination jurisdictions, safeguards applied and the legal basis relied upon. This register is both a compliance control and a readiness measure for any regulatory enquiry.

For multinational groups already aligned to regimes such as the GDPR, much of this infrastructure will feel familiar. However, GDPR compliance does not automatically satisfy Oman’s requirements; organisations must map their existing controls onto the specific obligations of the amended Personal Data Protection Law rather than assuming equivalence.

Comparison table: prior PDPL versus the amended law

The table below offers a scannable summary of how the amendments compare with the position under the original law. Use it as a starting point for an audit, then verify each item against the official statutory text before making policy decisions.

Feature Prior PDPL (Royal Decree 6/2022) Amended PDPL (Royal Decree 68/2026)
Territorial scope Framework focused on processing connected to Oman Reported to address personal data of natural persons inside and outside Oman where triggers are met
Deletion of personal data Lifecycle management largely a matter of good practice Obligation to delete personal data once the purpose is fulfilled, subject to exceptions
Direct marketing Consent-based framework under the original law Explicit consent required before commercial advertising or marketing
Automated processing Addressed under general processing provisions Clarified treatment, with expectations around transparency and risk assessment
Foundation Original enactment of the Personal Data Protection Law Amends, rather than replaces, the original framework

To use the table for auditing, work through each row and ask: does our current documentation reflect the amended position, and can we evidence it? Any row where the answer is uncertain should become an action item in the compliance plan above.

How Oman’s Royal Decree 68/2026 amends the regulatory timeline and enforcement outlook

Beyond the substantive changes, businesses need a view of what comes next. The decree states its own effective date, which should be confirmed against the official text and used to anchor internal deadlines.

Watchlist: expected secondary legislation

It is common for statutory amendments of this kind to be followed by updates to executive regulations or regulator guidance that fill in operational detail. Further guidance may be issued to clarify matters such as transfer mechanisms and the precise contours of the deletion duty. Organisations should monitor official government channels and update their policies once any such regulations are published.

Enforcement indicators and penalties

The Personal Data Protection Law carries an enforcement architecture, including administrative and criminal penalties set out in the law, and the amendments strengthen the substantive obligations against which compliance will be measured. Enforcement attention is likely to concentrate on the most visible new duties, retention and deletion, marketing consent, and the transparency of automated processing. A sensible monitoring cadence is to review official sources periodically and to reassess your compliance posture whenever new guidance appears.

Conclusion and recommended next steps

Oman’s Royal Decree 68/2026 amends the Personal Data Protection Law in ways that reach beyond a technical refresh. The clarified territorial scope brings overseas organisations into the frame, the deletion duty converts good practice into a documented obligation, the tightened marketing-consent requirement affects everyday commercial communications, and the clarified treatment of automated processing raises the bar for transparency and risk assessment. Businesses operating in or with Oman should act now: map their data, update notices and contracts, implement deletion procedures with audit trails, refresh marketing consent processes, and assess their automated systems. Where interpretation is required, adopt a conservative position and monitor for further regulations and guidance.

Engaging local counsel to review your specific processing activities is the surest route to demonstrable compliance under the amended law.

Sources

  1. Official Royal Decrees Portal, Royal Decree 68/2026
  2. Ministry of Transport, Communications and Information Technology, Personal Data Protection Law (Royal Decree 6/2022)
  3. Official Royal Decrees Portal, 2026 Royal Decrees
  4. Ministry of Transport, Communications and Information Technology

FAQs

What does Royal Decree 68/2026 change in Oman's Personal Data Protection Law?
Oman’s Royal Decree 68/2026 amends the Personal Data Protection Law. Reported changes include clarifying the law’s territorial reach to cover personal data of natural persons inside and outside Oman, an obligation to delete personal data once the processing purpose is fulfilled, a requirement for explicit consent before direct marketing, and clarified treatment of automated processing. It amends, rather than replaces, the framework created by Royal Decree 6/2022. Verify each point against the official decree text.
The amendment is reported to address the personal data of natural persons both inside and outside Oman where the law’s territorial triggers are met. Businesses processing data connected to Oman should assess whether they fall within scope, even without a physical presence in the Sultanate, and should confirm the exact conditions in the amended text.
The amendment is reported to require deletion of personal data once the purpose of processing has been fulfilled, subject to legal exceptions and retention requirements, with the duty capable of extending to processors as well as controllers. Organisations should maintain retention schedules and deletion logs to evidence compliance and record the legal basis for any continued retention.
The amended law is reported to require the data subject’s explicit consent before sending commercial advertising or marketing communications, while preserving certain exceptions such as processing for media and press purposes. Review your consent capture and withdrawal mechanisms accordingly.
The decree is reported to clarify how automated processing is treated, signalling expectations around transparency and, as a matter of prudent practice, risk assessment. Organisations using automated profiling or decision-making should inventory those systems, make the required disclosures, and consider conducting a data protection impact assessment where processing could significantly affect individuals.
Conduct a gap analysis and data-flow map for your Oman footprint, update privacy notices and data processing agreements, implement deletion procedures with proof-of-deletion records, refresh marketing consent processes, carry out impact assessments for automated processing, and monitor for further regulations and guidance. Engaging local counsel to confirm interpretations of ambiguous provisions is strongly recommended.
The official text is published on Oman’s Royal Decrees portal at the page for Royal Decree 68/2026. Compliance decisions should be based on the verbatim statutory text and its stated effective date, verified directly from the official source.
Further executive regulations or guidance may follow. Businesses should monitor the Ministry of Transport, Communications and Information Technology and the official decrees portal, and update their policies and procedures once any such regulations are published.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Oman: Royal Decree 68/2026 Amends the Personal Data Protection Law, What Businesses Must Do

Send welcome message

Custom Message