Who this article is for: legal and compliance teams, in-house counsel, data protection officers, CIOs, and HR and marketing leads of businesses operating in or with Oman.
What you’ll get: an authoritative summary of the RD68/2026 amendments, a side-by-side comparison with the prior law, a practical compliance checklist, sample retention and deletion policy language, and a business-focused FAQ.
Oman’s Royal Decree 68/2026 amends the Personal Data Protection Law and, in doing so, reshapes the compliance obligations of every organisation that touches personal data connected to Oman. Issued on 3 September 2026 as part of a wider legislative package, the decree modifies the framework first established under Royal Decree 6/2022. The headline changes reported include a clarified territorial scope, an obligation to delete personal data once the purpose of processing has been fulfilled, and clarified treatment of automated processing, together with amendments touching consent for direct marketing and permitted exceptions. For businesses inside and outside the Sultanate, the practical effect is immediate, retention schedules, cross-border arrangements and automated decision-making systems should all be reviewed against the amended text.
This analysis explains what the decree does in general terms, sets out the relevant statutory context, and provides a prioritised compliance roadmap. Where the amended law leaves room for interpretation, we flag those points as practical interpretations rather than settled conclusions, so your legal and compliance teams can plan on a conservative footing. The core message is straightforward: Oman’s Royal Decree 68/2026 amends a law that already carried substantial obligations, and it tightens them in ways that demand documented, auditable action. Because the operative wording governs, businesses should verify each point against the official decree text.
Organisations should treat the amendments as a trigger for a full data-protection review. The territorial reach means that companies without a physical presence in Oman may nonetheless fall within scope, while the deletion duty raises the operational bar for record-keeping and lifecycle management. The sections below translate the statutory changes into concrete steps.
To understand why Oman’s Royal Decree 68/2026 amends the framework the way it does, it helps to place the decree in its legislative context. The Personal Data Protection Law was introduced by Royal Decree 6/2022, establishing Oman’s comprehensive statutory regime for the processing of personal data. That law set out core concepts familiar from international data-protection regimes, lawful bases for processing, obligations on those who determine the purposes of processing (controllers) and those who process on their behalf (processors), and rights for individuals whose data is processed. Executive Regulations issued under the law (by Ministerial Decision) provide operational detail.
The trajectory of Oman’s data-protection law can be summarised as follows:
The amendment does not replace the original law; it modifies specific provisions. That means the definitions, principles and enforcement architecture established under Royal Decree 6/2022 continue to apply, read together with the changes made by the 2026 decree.
Royal Decree 68/2026 was one of a group of decrees issued on the same date. While several of those decrees address distinct subject areas, RD68/2026 is the one of direct concern to privacy and data-protection compliance. For businesses monitoring the broader regulatory environment, it is prudent to review the full package to identify any sectoral measures that may intersect with data handling, but the data-protection compliance obligations flow specifically from the decree that amends the Personal Data Protection Law. Companies should confirm the precise scope and numbering of any related decrees against the official portal rather than relying on secondary summaries.
The heart of this article is what Oman’s Royal Decree 68/2026 amends in operational terms. The decree makes several targeted changes to the Personal Data Protection Law. Below we explain each in plain English, note its likely legal effect, and set out the immediate compliance action it demands. Because statutory wording governs, businesses should always verify the exact text against the official decree before finalising policy language.
A consequential area of change concerns the reach of the law. As amended, the Personal Data Protection Law is reported to address the personal data of natural persons whether they are located inside or outside Oman, where the law’s territorial triggers are met. In practical terms, this reduces any argument that the regime is confined to processing carried out solely within the Sultanate’s borders. Businesses should confirm the precise wording and any qualifying conditions against the official text.
Legal effect. Organisations established outside Oman that process personal data with a relevant connection to Oman, for example, data relating to individuals in Oman, may fall within the statute’s obligations. This mirrors the direction of travel in other modern data-protection regimes, where physical presence is no longer the sole determinant of applicability.
Immediate compliance action. Map where personal data connected to Oman is collected and processed, including by group entities and vendors located abroad. Identify any processing that previously sat outside your Oman compliance perimeter and reassess it against the amended scope.
Royal Decree 68/2026 is reported to introduce or clarify an obligation to delete personal data once the purpose for which it was collected has been fulfilled. Where this duty is directed at both controllers and processors, organisations should not assume that responsibility for erasure rests solely with the party that determined the purpose of processing.
Legal effect. Any deletion duty is subject to legal exceptions and retention requirements, for example, where other laws require records to be kept for a defined period. The default position is that data should not be retained indefinitely once its processing purpose is spent, converting what many organisations treated as good practice into a compliance obligation.
Immediate compliance action. Establish or refresh a retention schedule that ties each category of personal data to a defined purpose and a defined retention period. Implement documented deletion procedures and maintain deletion logs so you can demonstrate compliance. Where a legal retention requirement applies, record the legal basis for continued storage.
Sample deletion policy language to adapt: “Personal data will be securely deleted, anonymised or destroyed once the purpose for which it was collected has been fulfilled, unless a specific legal or regulatory obligation requires its retention for a defined period. Where retention is required, the legal basis and retention period will be recorded, and the data will be deleted promptly upon expiry of that period. Deletion actions will be logged to provide an auditable record.”
Reporting on the amendment indicates a strengthened requirement that controllers obtain the data subject’s explicit consent before sending commercial advertising or marketing communications. The amended framework also preserves specific legal exceptions, including data processed for media and press purposes.
Immediate compliance action. Review your marketing consent capture and record-keeping to ensure explicit, demonstrable consent is obtained before direct marketing, and provide a clear mechanism to withdraw consent.
The decree is reported to clarify how automated processing is treated under the Personal Data Protection Law. As organisations increasingly deploy automated profiling and decision-making, from credit and eligibility scoring to marketing segmentation, clear rules on transparency and risk assessment become essential.
Legal effect. Entities relying on automated processing should expect obligations around transparency and, as a matter of prudent practice, the assessment of risks arising from such processing.
Immediate compliance action. Inventory systems that carry out automated profiling or automated decision-making affecting individuals. Assess the risks these systems present, ensure the required disclosures are made to data subjects, and build a defensible record of how each system operates and what safeguards are in place. Where automated processing could produce significant effects on individuals, a data protection impact assessment (DPIA) is a sensible control.
Alongside the headline changes, Royal Decree 68/2026 amends the Personal Data Protection Law with technical adjustments that support the substantive reforms, for instance, refinements that align definitions and operational provisions with the clarified scope and lifecycle obligations. Businesses should read the amended text in full to identify any definitional shifts that affect how their processing is classified, and confirm the effective date stated in the decree so that internal deadlines are calibrated correctly.
Understanding what Oman’s Royal Decree 68/2026 amends is only the starting point; the value lies in converting the changes into a prioritised, auditable programme of work. The checklist below is organised by timeframe. Adjust the sequencing to your organisation’s risk profile and processing footprint.
Sample DPA deletion clause to adapt: “Upon fulfilment of the processing purpose, or upon termination of this Agreement, the Processor shall, at the Controller’s option, delete or return all personal data processed on the Controller’s behalf, and shall delete existing copies unless retention is required by applicable law. The Processor shall provide the Controller with written confirmation of deletion and shall maintain a log evidencing the deletion actions taken.”
Demonstrable compliance depends on records. Maintain the following as living documents:
Sample automated-processing transparency clause to adapt: “Where personal data is subject to automated processing, including profiling, the Controller will inform data subjects of the existence of such processing, its purpose and the categories of data involved, and will assess and document the risks arising from that processing before deployment.”
Because Oman’s Royal Decree 68/2026 amends the law in ways that touch personal data of natural persons inside and outside the Sultanate, cross-border processing sits at the centre of the compliance analysis. Controllers and processors located outside Oman that handle personal data connected to Oman should not assume they are beyond the law’s reach.
The practical question for any overseas organisation is whether a territorial nexus to Oman exists, for example, whether it processes the personal data of individuals in Oman. Where such a connection is present and the statutory triggers are met, the amended law’s obligations may apply. Organisations should carry out a documented assessment of their processing activities to determine whether they fall within scope, rather than relying on the absence of a physical presence in Oman.
The Personal Data Protection Law and its Executive Regulations govern the transfer of personal data outside Oman, and detailed conditions may be set by the competent authority. A conservative approach is to rely on contractual safeguards and structured risk assessments, verified against the current regulations. Practical interim measures include:
Maintain a register of cross-border transfers that records the data categories, recipients, destination jurisdictions, safeguards applied and the legal basis relied upon. This register is both a compliance control and a readiness measure for any regulatory enquiry.
For multinational groups already aligned to regimes such as the GDPR, much of this infrastructure will feel familiar. However, GDPR compliance does not automatically satisfy Oman’s requirements; organisations must map their existing controls onto the specific obligations of the amended Personal Data Protection Law rather than assuming equivalence.
The table below offers a scannable summary of how the amendments compare with the position under the original law. Use it as a starting point for an audit, then verify each item against the official statutory text before making policy decisions.
| Feature | Prior PDPL (Royal Decree 6/2022) | Amended PDPL (Royal Decree 68/2026) |
|---|---|---|
| Territorial scope | Framework focused on processing connected to Oman | Reported to address personal data of natural persons inside and outside Oman where triggers are met |
| Deletion of personal data | Lifecycle management largely a matter of good practice | Obligation to delete personal data once the purpose is fulfilled, subject to exceptions |
| Direct marketing | Consent-based framework under the original law | Explicit consent required before commercial advertising or marketing |
| Automated processing | Addressed under general processing provisions | Clarified treatment, with expectations around transparency and risk assessment |
| Foundation | Original enactment of the Personal Data Protection Law | Amends, rather than replaces, the original framework |
To use the table for auditing, work through each row and ask: does our current documentation reflect the amended position, and can we evidence it? Any row where the answer is uncertain should become an action item in the compliance plan above.
Beyond the substantive changes, businesses need a view of what comes next. The decree states its own effective date, which should be confirmed against the official text and used to anchor internal deadlines.
It is common for statutory amendments of this kind to be followed by updates to executive regulations or regulator guidance that fill in operational detail. Further guidance may be issued to clarify matters such as transfer mechanisms and the precise contours of the deletion duty. Organisations should monitor official government channels and update their policies once any such regulations are published.
The Personal Data Protection Law carries an enforcement architecture, including administrative and criminal penalties set out in the law, and the amendments strengthen the substantive obligations against which compliance will be measured. Enforcement attention is likely to concentrate on the most visible new duties, retention and deletion, marketing consent, and the transparency of automated processing. A sensible monitoring cadence is to review official sources periodically and to reassess your compliance posture whenever new guidance appears.
Oman’s Royal Decree 68/2026 amends the Personal Data Protection Law in ways that reach beyond a technical refresh. The clarified territorial scope brings overseas organisations into the frame, the deletion duty converts good practice into a documented obligation, the tightened marketing-consent requirement affects everyday commercial communications, and the clarified treatment of automated processing raises the bar for transparency and risk assessment. Businesses operating in or with Oman should act now: map their data, update notices and contracts, implement deletion procedures with audit trails, refresh marketing consent processes, and assess their automated systems. Where interpretation is required, adopt a conservative position and monitor for further regulations and guidance.
Engaging local counsel to review your specific processing activities is the surest route to demonstrable compliance under the amended law.
posted 9 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 18 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message