OmanPersonal Data Protection Law
RD 6/2022MD 34/2024
The strongest DPO mandate in the GCC, and unconditional — there is no size, sector or risk threshold to fall below. Enforceable since 5 February 2026, which is the single most important date on the Omani register. A ministerial permit is required before processing genetic, biometric, health, racial origin, sexual life, political or religious belief and criminal record data. Fines are low by regional standards, up to OMR 2,000 for most breaches, which is precisely why some groups have not taken the obligation seriously.
ConstraintThe regulator prefers the officer to be physically located in Oman. An externally appointed officer outside the country is therefore a position to be taken deliberately and documented, not an obvious fit — we will say so before you appoint rather than after.
BahrainPersonal Data Protection Law
Law 30/2018
The clearest statutory basis in the GCC for an external officer: the law contemplates external appointment and sets qualification criteria for it. A DPO is mandatory for all licensed financial institutions and optional elsewhere. Penalties under this law are criminal, up to a year's imprisonment, which changes how seriously the appointment should be taken.
ConstraintOfficers must be accredited and appear on the Authority's register, administered by the Ministry of Justice under Royal Decree 78/2019. We are not currently on that register. For a Bahraini appointment we would either have to be accredited first or you appoint someone who already is — we will name firms rather than stall the engagement.
Saudi ArabiaPersonal Data Protection Law
RD M/19, amended M/148
Fully enforceable since September 2024, and enforcement here is real rather than theoretical — 48 enforcement decisions had been announced by mid-January 2026, with publication of final penalties and fines to SAR 5 million, doubled for repeat violations. A DPO is mandatory for public bodies, for large-scale systematic monitoring, and for large-scale special-category processing, under qualification rules issued in August 2024. Controllers register on the National Data Governance Platform.
ConstraintWhether the role can be held from outside the Kingdom is a question to settle alongside the wider services licensing position, not in isolation.
DIFC and ADGMFree-zone regimes, separate from the federal law
DIFC Law 5/2020, am. 1/2025ADGM 2021, cons. 2024
DIFC requires an annual assessment of whether a DPO is needed, and failing to complete that assessment attracts a fine of up to USD 25,000 whether or not an officer was actually required — an obligation regularly missed because it is about the assessment, not the appointment. The July 2025 amendment also created a private right of action: data subjects may sue controllers and processors directly in the DIFC Courts, for financial loss and for distress, without going to the Commissioner first. ADGM requires every registered entity processing personal data to register as a controller and renew annually, with a maximum fine of USD 28 million.
ConstraintFederal Decree-Law 45/2021 reaches processors outside the UAE handling residents' data, but its Executive Regulations have still not been issued, so the penalty regime and transfer mechanics are not operable. DIFC, ADGM, government, health and banking data are carved out to their own regimes in any case.