العربية

Service · Data protection officer

Four Gulf laws require an officer. They require different things.

The GCC has no common data protection regime, no adequacy mechanism and no mutual recognition. Where a data protection officer is mandatory, what qualifies someone to hold the role, and whether an external appointment is permitted at all, are answered differently in every market — and in two of them the answer constrains who you can appoint.

Where the mandate actually bites

In order of how hard the obligation is.

Oman

Personal Data Protection Law

RD 6/2022MD 34/2024

The strongest DPO mandate in the GCC, and unconditional — there is no size, sector or risk threshold to fall below. Enforceable since 5 February 2026, which is the single most important date on the Omani register. A ministerial permit is required before processing genetic, biometric, health, racial origin, sexual life, political or religious belief and criminal record data. Fines are low by regional standards, up to OMR 2,000 for most breaches, which is precisely why some groups have not taken the obligation seriously.

ConstraintThe regulator prefers the officer to be physically located in Oman. An externally appointed officer outside the country is therefore a position to be taken deliberately and documented, not an obvious fit — we will say so before you appoint rather than after.
Bahrain

Personal Data Protection Law

Law 30/2018

The clearest statutory basis in the GCC for an external officer: the law contemplates external appointment and sets qualification criteria for it. A DPO is mandatory for all licensed financial institutions and optional elsewhere. Penalties under this law are criminal, up to a year's imprisonment, which changes how seriously the appointment should be taken.

ConstraintOfficers must be accredited and appear on the Authority's register, administered by the Ministry of Justice under Royal Decree 78/2019. We are not currently on that register. For a Bahraini appointment we would either have to be accredited first or you appoint someone who already is — we will name firms rather than stall the engagement.
Saudi Arabia

Personal Data Protection Law

RD M/19, amended M/148

Fully enforceable since September 2024, and enforcement here is real rather than theoretical — 48 enforcement decisions had been announced by mid-January 2026, with publication of final penalties and fines to SAR 5 million, doubled for repeat violations. A DPO is mandatory for public bodies, for large-scale systematic monitoring, and for large-scale special-category processing, under qualification rules issued in August 2024. Controllers register on the National Data Governance Platform.

ConstraintWhether the role can be held from outside the Kingdom is a question to settle alongside the wider services licensing position, not in isolation.
DIFC and ADGM

Free-zone regimes, separate from the federal law

DIFC Law 5/2020, am. 1/2025ADGM 2021, cons. 2024

DIFC requires an annual assessment of whether a DPO is needed, and failing to complete that assessment attracts a fine of up to USD 25,000 whether or not an officer was actually required — an obligation regularly missed because it is about the assessment, not the appointment. The July 2025 amendment also created a private right of action: data subjects may sue controllers and processors directly in the DIFC Courts, for financial loss and for distress, without going to the Commissioner first. ADGM requires every registered entity processing personal data to register as a controller and renew annually, with a maximum fine of USD 28 million.

ConstraintFederal Decree-Law 45/2021 reaches processors outside the UAE handling residents' data, but its Executive Regulations have still not been issued, so the penalty regime and transfer mechanics are not operable. DIFC, ADGM, government, health and banking data are carved out to their own regimes in any case.

What the role is, and what it is not

A data protection officer is an accountable named individual, not a retainer. The role carries statutory duties toward the regulator and toward data subjects that sit alongside, and sometimes against, the interests of the organisation paying for it. That tension is the point of the role; an officer who never disagrees with the business is not doing the job.

Which is also why the officer should not be the person who built the processing, or who sold you the system, or who would be paid to fix what they find. The same boundary that runs through every other service line runs through this one, and here it has statutory force rather than being a matter of preference.

What the appointment covers

A standing role rather than a project, priced annually.

01

Named officer of record

Registered with the authority where registration exists, reachable by data subjects, and answerable at board level. One named person, with a named deputy — not a shared inbox.

NamedDeputy named
02

Impact assessment and prior authorisation

DPIAs where the processing warrants one, and the ministerial permit or prior authorisation applications that Oman and Qatar require for special-category data before processing begins rather than after.

DPIAPrior authorisation
03

Breach clock management

The notification obligations differ sharply — Oman runs to 72 hours; Bahrain's financial-sector rules put the central bank on a one-hour phone call. Knowing which clock is running, before it starts, is most of what the role is worth on the worst day.

72h Oman1h CBB
04

Records, requests and the annual assessment

Processing records, data subject requests inside the statutory window — 45 days in Oman — and the DIFC annual DPO-requirement assessment, which is fineable in its own right whether or not you conclude an officer is needed.

45 daysAnnual DIFC assessment

Two markets where we would tell you to appoint someone else

Bahrain gates the role behind an accreditation register we are not on. Oman's regulator prefers an officer physically present in the country. Neither is a reason to leave the obligation unmet, and neither is something you should discover after signing — so if your exposure is principally in those two markets, the honest answer is that our value is in the assessment and the appointment specification rather than in holding the role ourselves. We would rather say that at the scoping call than bill for a year of it.

Start with a scoping call

Tell us which countries your personal data is processed in and whether anyone currently holds the role. The mandate question is usually answerable inside the call.