العربية

Market · Sultanate of Oman

Meet Oman's data law, and choose the rest deliberately

Oman has the most unconditional data protection officer requirement in the Gulf, enforceable since February 2026. It also has no national private-sector cyber security control set — which is not what a good deal of vendor material will tell you.

There is no Omani equivalent of the Saudi ECC or the Qatar NIA

We looked for one. The Ministry of Transport, Communications and Information Technology publishes a cyber security governance guideline, a security assessment services standard, basic controls guidance, a social media security guide and an information classification guide — all addressed to government entities. We found no single named, mandatory national cyber security framework binding the Omani private sector. If a proposal tells you otherwise, ask which instrument, issued by whom, and on what date. Saying this plainly costs us a service line and is worth more than the service line.

What binds you

Almost all of the enforceable weight in Oman sits in the data protection regime rather than in cyber security controls.

MTCIT

Personal Data Protection Law

Royal Decree 6/2022MD 34/2024RD 68/2026

Enforceable since 5 February 2026, following the transition period set by Ministerial Decision 6/2025 — the single most important Omani date. Amended by Royal Decree 68/2026, in force since 7 September 2026, which extends the law to processing of data about people in Oman wherever it takes place, adds cases where consent is not needed, and gives individuals a right to object to solely automated decisions and ask for human review. Otherwise requires explicit consent before processing, written data protection policies and records of processing, breach notification to the ministry within 72 hours, and answers to data subject requests within 45 days. Privacy notices are customarily in Arabic.

Who signsMinistry oversight. MTCIT publishes self-assessment tools and guidance forms.
MTCIT

The data protection officer mandate

Unconditional

Appointing a DPO and publishing their contact details is required outright, with no size, sector or risk threshold to fall under — which makes it the strongest DPO obligation in the Gulf. The regulator prefers the officer to be physically located in Oman. For a foreign group with a small Omani footprint this is usually the first obligation that actually costs something.

Who signsA named officer, contact details published. Oman residence preferred.
MTCIT

Sensitive categories and cross-border transfer

Ministerial permit

A ministerial permit is required to process genetic, biometric and health data, racial origin, sexual life, political or religious belief, and criminal records. Since Royal Decree 68/2026, no permit is needed for an employer’s processing of its own staff’s data, including biometrics, or for security-camera footage required by the competent authorities. For transfers, non-sensitive data needs data subject consent; sensitive data needs Cyber Defence Centre approval, the recipient jurisdiction must offer equivalent protection, and the transfer must not harm national security.

Who signsMinisterial permit for sensitive categories; Cyber Defence Centre approval for their transfer.
MTCIT

General Policy for the Safe and Ethical Use of AI Systems

1 April 2025

A framework policy tied to Oman Vision 2040, setting operational expectations for state entities and regulated sectors. It is a policy instrument, not legislation, and preceded by a 2024 consultation that included a draft national charter for AI ethics.

Who signsSelf-assessed. Voluntary.

Modest administrative fines, real leverage

Administrative penalties run to OMR 2,000 per violation, which is modest by regional standards and leads some organisations to under-weight the regime. That reads the wrong lever. The law itself carries fines of up to OMR 500,000 for its most serious offences, and the enforcement power that matters day to day is suspension or cancellation of processing permits — and for anything touching the sensitive categories above, a suspended permit stops the activity outright. Also unresolved: a new Cybercrime Law, Royal Decree 61/2026, was issued on 1 June 2026 repealing the 2011 decree. Its full text is not freely available, so its obligations for organisations have not been confirmed.

How to approach it

Sensible first steps

  • Establish whether you process any sensitive category, because the permit is a lead time and not a formality.
  • Appoint the DPO. There is no threshold to argue your way under.
  • Map transfers before you map controls — the transfer rules are where foreign groups actually get caught.
  • Build the 72-hour breach path and test it once.

What not to buy

  • Certification against an Omani national cyber framework. There isn't one for the private sector.
  • A control-set gap assessment sold as a regulatory requirement. It may still be good practice — but it is not compliance, and it should not be priced as though it were.
  • Anything premised on the new Cybercrime Law until its obligations are actually established.

Start with a scoping call

Tell us what you process and where it goes. In Oman that conversation usually resolves the whole question faster than a framework would.