Jurisdiction Guides / Middle East
Oman Privacy & Data Protection Laws
Every regime below can apply to a business handling Oman residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Royal Decree 6/2022 replaced the data-protection provisions previously embedded in Oman's Electronic Transactions Law with a standalone regime, in force since February 2023 and given operative detail by the Executive Regulations issued under Ministerial Decision 34/2024, which opened a one-year window for controllers to align. It applies to the processing of personal data in Oman; there is no clearly expressed GDPR-style targeting clause reaching a foreign controller with no Omani footprint, so the trigger below is modeled on established presence only. Notable features: consent is the default basis with limited exceptions, permits from the Ministry of Transport, Communications and Information Technology are required for certain processing (including sensitive data such as genetic, biometric, health, ethnic and religious data), breach notification duties apply, and violations carry both administrative fines and criminal penalties.
Cross-Border Data Transfer · 1
Oman stacks a consent requirement on top of an adequacy requirement, which makes it stricter in practice than most regimes here. Transferring personal data outside Oman requires the EXPRESS CONSENT of the data subject unless the data is anonymised, AND the external processing party must maintain a level of protection not less than the PDPL's own, AND the transfer must not prejudice national security or higher national interests. Consent-based transfer at scale is fragile — consent can be withdrawn — so a business routing Omani personal data to an overseas parent or cloud region should treat this as a design constraint rather than a paperwork step. With the transition period closed on February 5, 2026, the regime is now fully enforceable. Marked 'check': the operative texts are Arabic-language originals and the interaction between the consent limb and the adequacy limb was triangulated across independent sources.
Data Security & Breach Notification · 1
Controllers must notify the Ministry of Transport, Communications and Information Technology within 72 hours of a personal data breach that may pose a risk to data subjects' rights, stating the nature and impact of the breach and the mitigation measures taken, and must notify affected data subjects where the breach is likely to cause them serious harm. The date that matters commercially is February 5, 2026: the transition period introduced by the Royal Decree and its Executive Regulation ended then, so the PDPL is now fully enforceable rather than in a grace period. Marked 'check': the operative texts are Arabic-language originals and the deadlines were triangulated across independent legal-reference sources.
Other Middle East jurisdictions