Home/Guides/Online business
Online business

Oman's data protection law — what changed on 7 September 2026

Most summaries tell you the maximum fine under this law is OMR 2,000 and that it is a large-company problem. Both are wrong, and the September 2026 amendments made them more wrong.

Published 2026-09-17 ✓ Figures verified 2026-09-17 20 min read

On 7 September 2026 Oman's Personal Data Protection Law stopped being a domestic law. Royal Decree 68/2026 — published in Official Gazette issue 1664 on 6 September 2026 and effective the following day — amends Article 2 so that the law applies to the processing of the personal data of individuals in Oman whether the processing takes place inside or outside the Sultanate. If you hold a customer list with Omani residents on it, the question of which country your server sits in has stopped mattering. There was no transition period: the amendments are in force now, and the grace period that used to be the reason to wait ended on 5 February 2026.

7 September 2026
The amended law took effect
OMR 500,000
Top of the Article 29 fine band
72 hours
To notify MTCIT of a breach
5 February 2026
The grace period ended

What changed on 7 September 2026

Royal Decree 68/2026 was issued by Sultan Haitham bin Tarik, published in Official Gazette issue 1664 on 6 September 2026 and took effect on 7 September 2026. It is not a new law and it replaces nothing: it rewrites particular articles of the Personal Data Protection Law promulgated by Royal Decree 6/2022. Six of those changes matter to an ordinary business.

  • Article 2 — territorial scope. The law now covers the processing of the personal data of individuals in Oman regardless of whether the processing takes place inside or outside the Sultanate. The previous wording was narrower.
  • Article 5 bis, new. Sets out specific legal bases for processing in place of the previous exemptions: employee data, surveillance and CCTV, legal obligations, contractual necessity, publicly available data, and protection of vital interests.
  • Article 10 amended, and Article 10 bis, new. Specifications for how consent must be requested — the mechanics, not merely the requirement.
  • Article 14 amended. Automated processing is defined as processing carried out by an electronic programme or system operating entirely without human involvement or with only limited human supervision, and data subjects gain the right to object to an automated decision and to require the controller to bring in a human to review it.
  • Article 15 amended. Personal data must be deleted as soon as the purpose it was collected for has been fulfilled, unless there is an ongoing dispute or a legal obligation to keep it.
  • Article 22 amended. Explicit consent is required before sending commercial advertising. The consent mechanism itself is left to regulation.

No transition period was stated and no compliance deadline was set. The amendments are in force now — they arrived in September 2026 — and there is nothing left to wait for. That is worth saying plainly, because the history of this law until now has been a history of waiting.

The grace period ended on 5 February 2026, and there is no new one

The sequence, because you have probably seen two different dates. Royal Decree 6/2022 was issued on 9 February 2022, published in Official Gazette issue 1429 on 13 February 2022, and came into force one year after issuance, on 9 February 2023. Ministerial Decision 34/2024, the Executive Regulation, was published on 28 January 2024 and took effect on 29 January 2024, giving controllers one year to regularise — which is why Trowers & Hamlins, writing in February 2024, put the deadline at approximately 29 January 2025.

Ministerial Decision 6/2025, gazetted in the week of 19 January 2025, extended that period by one further year. CMS and Trowers both give the end date as 5 February 2026. Both of the dates you may have read are correct at their own moment; the later one reflects the extension.

So the grace period is finished, and the September 2026 amendments arrived without one of their own. If you are starting from nothing today, you are starting late rather than early.

Being outside Oman no longer puts you outside the law

This is the change most likely to catch a business that has never given the PDPL a thought. The amended Article 2 applies the law to the processing of the personal data of individuals in Oman, and says the processing is caught whether it takes place inside or outside the Sultanate. The test is where the person is — not where the server is, not where the company is registered, not where the processing happens.

Work through what that covers. A Gulf e-commerce site incorporated elsewhere that ships to Muscat and keeps the delivery addresses. A software company whose customers include Omani businesses whose staff log in. A clinic abroad taking appointments from patients in Oman. A marketing agency running a mailing list with Omani subscribers on it. A parent company whose HR system in another country holds the records of employees working here. None of these had an obvious argument that Omani law applied to them before 7 September 2026; all of them are inside Article 2 now. If you are selling online from inside Oman, our guide to e-commerce licensing covers the other half of the problem. What we cannot trace in any published source is how MTCIT intends to reach a controller with no presence in Oman: the text states the scope, it does not describe an enforcement mechanism against a foreign entity.

The “maximum fine is OMR 2,000” reading is a partial one

A large part of the advisory commentary summarises the PDPL as carrying a maximum fine of OMR 2,000 per violation. The figure is real and it is in the law. It is Article 32, which sets the ceiling for administrative penalties. It is not the ceiling of the law.

Article 29 reaches OMR 500,000

The penalty articles of Royal Decree 6/2022 run in bands, and which band applies to you depends on which obligation you broke. Article 29 — the data transfer restrictions — carries a fine of OMR 100,000 to OMR 500,000. That is two hundred and fifty times the figure most summaries quote.

The mistake is easy to make, because Article 32 genuinely does cap administrative penalties at OMR 2,000, and it is the line that summarises most neatly. But Article 32 sits alongside the law's penalty articles, not above them, and it does not limit them. A business that reads “maximum OMR 2,000” and concludes the law is cheap to ignore has been misled by a partial reading of it.

The practical consequence: the single most expensive thing you can get wrong under this law is moving personal data out of Oman without the explicit consent of the people it belongs to. Everything else in the table below is an order of magnitude cheaper.

ArticleConductFine
25Notification requirementsOMR 500 to OMR 2,000
26Compliance and procedural articlesOMR 1,000 to OMR 5,000
27Control proceduresOMR 5,000 to OMR 10,000
28Sensitive data and breach notificationOMR 15,000 to OMR 20,000
29Cross-border transfer restrictionsOMR 100,000 to OMR 500,000
30Legal entity liabilityOMR 5,000 to OMR 100,000
32Administrative penaltiesMaximum OMR 2,000

Two things to read alongside that table. First, MTCIT's other administrative sanctions are not financial: a warning, and suspension or cancellation of the processing permit. For a business whose product depends on processing health or biometric data, cancellation is the penalty that ends the business, not the fine. Second, on the amended articles, CMS reports fines of up to OMR 2,000 for consent breaches under Article 10 and up to OMR 10,000 for processing-control and automated-processing breaches. That is a law firm's reading of the amended text, so treat those two figures as secondary; the banded figures in the table come from the text of Royal Decree 6/2022 itself.

Who enforces this

The regulator is the Ministry of Transport, Communications and Information Technology (MTCIT) — وزارة النقل والاتصالات وتقنية المعلومات. There is no separate Omani data protection authority and no commissioner. MTCIT receives breach notifications, decides sensitive-data permit applications, hears complaints from data subjects whose requests were refused or ignored, and issues the executive regulation. The regulation in force is Ministerial Decision 34/2024, as amended by Ministerial Decision 6/2025.

MTCIT publishes the law and a plain-language summary of data subject rights on its own site. It does not publish, on that page, the executive regulation's decision number, the permit procedure, the fees or the deadlines. You will find the regulation itself in the ministry's legislation library and on Oman Open Data, but the operational detail a controller actually needs — how to apply, to whom, with what, and for how much — is not assembled anywhere on a government page. Worth knowing before you spend an afternoon looking for it.

Consent, marketing, and the legal bases that replaced the exemptions

Consent must be explicit and informed, and must come before processing begins. Article 10 was amended and a new Article 10 bis added, both dealing with how consent is to be requested — the specifications, not merely the principle. If your consent flow is a pre-ticked box, a buried line in terms of service, or one bundled agreement covering marketing, analytics and service delivery together, it is the part of your operation most likely to be wrong.

Article 22, as amended, requires explicit consent before you send commercial advertising. This is the provision that catches the largest number of otherwise careful businesses, because a list you bought, a list you scraped, and a list of people who once bought something from you are none of them consent to advertise to those people. The mechanism by which that consent is obtained and recorded is left to regulation, and the regulation has not yet specified it.

The new Article 5 bis works in the opposite direction, and is the one piece of genuinely good news in the decree. It sets out specific legal bases for processing in place of the previous exemptions: employee data, surveillance and CCTV, legal obligations, contractual necessity, publicly available data, and the protection of vital interests. On decree.om's own reading of the amendment, this lets an employer process employee data including biometric data such as fingerprints without a ministry permit — which matters to every Omani business with a fingerprint reader at the door.

Article 15, amended, is short and has teeth: personal data must be deleted as soon as the purpose it was collected for has been fulfilled, unless a dispute is ongoing or a legal obligation requires you to keep it. There is no fallback retention period stated. If you keep every CV you have ever received, every delivery address you have ever taken and every abandoned sign-up, the law's default position is that you should not have them.

You need a data protection officer, whatever your size

Organisations must designate a Personal Data Protection Officer and make that person's contact details publicly available. The obligation applies regardless of the size of the organisation. There is no small-business exemption, no employee-count threshold and no turnover threshold in the law or in Ministerial Decision 34/2024 — a five-person company in Al Ghubra carries the same obligation as a bank.

What “designate” means in practice

The word in the obligation is designate, not employ. It does not require you to hire anyone. An existing employee may hold the role alongside their other duties, and in a small company that is the ordinary way of meeting it.

What it does require is that the designation is real and that the contact details are actually published: an address on your site that reaches a named person who knows they hold the role. A generic inbox nobody has been told about is the version of this that fails.

The clocks: 72 hours, 45 days, 60 days

You have 72 hours to notify MTCIT of a personal data breach, running from the controller's knowledge of it rather than from the breach itself. Where the breach is likely to cause serious harm or presents a high risk to the people affected, you must notify them as well. Seventy-two hours is short, and it is short in the way that decides the outcome: it is not enough time to first work out who is responsible, then find the ministry's contact route, then draft a position. The organisations that meet this deadline are the ones that decided in advance who makes the call.

In the other direction, a data subject who asks you to erase, retrieve or transfer their data must be answered within 45 days. If you refuse or simply do not answer, they may complain to MTCIT, which then has 60 days to decide. Silence from the ministry is deemed a rejection of the complaint. That cuts both ways: it protects a controller from an indefinitely open file, and it denies a complainant a decision they can argue with.

ClockWhat it isIf it runs out
72 hoursNotify MTCIT of a breach, from when you know of itArticle 28: OMR 15,000 to OMR 20,000
45 daysAnswer an erasure, retrieval or transfer requestThe data subject may complain to MTCIT
60 daysMTCIT's time to decide that complaintSilence is deemed rejection
45 daysMTCIT's time to decide a sensitive-data permitNo response means the application is refused
60 daysThe minister's time to decide an appealNo response means the appeal is refused

The sensitive-data permit, and the fee nobody publishes

Processing sensitive personal data — health data, biometric data and similar categories — requires a permit from MTCIT before you begin. The ministry has 45 days to decide, and no response means the application is rejected. You may appeal to the minister, who has 60 days, and again no response means the appeal is rejected. Both silences are refusals, which means an application that disappears is an application that failed. Diarise the forty-fifth day.

The application must set out the precautionary measures adopted in the event of a breach — your incident plan has to exist before the permit is granted, not after the first incident. Note the interaction with the new Article 5 bis: on decree.om's reading, employee biometric data processed by an employer no longer needs a ministry permit. Biometric data about anyone else — customers, patients, visitors — still does.

No permit fee is published anywhere

Neither MTCIT nor any gazette source publishes a fee for the sensitive-data processing permit. We looked in the ministry's legislation library, in the executive regulation, and in the practitioner write-ups of it. None of them states a figure, and the practitioner write-ups do not state one either. This is a gap in the official and the secondary sources alike — not a number we are declining to give.

We are not going to write that fees vary, and we are not going to quote a range from another country's regime. If a consultant quotes you an Omani permit fee, ask them which instrument publishes it, because we could not find one that does.

Moving data out of Oman

Cross-border transfer requires the data subject's explicit consent, and the transfer must not compromise national security. There is no adequacy list, no standard contractual clauses regime and no published mechanism equivalent to either — the consent of the individual is the gate.

Read that against Article 29 and it becomes the most commercially serious paragraph on this page. Every ordinary modern arrangement is a transfer: a CRM hosted in Europe, a payroll bureau in India, an email platform in the United States, a group HR system at head office, a cloud backup. If the personal data of people in Oman sits in any of them and those individuals did not explicitly consent to the transfer, that is the conduct Article 29 prices at OMR 100,000 to OMR 500,000. Combine it with the amended Article 2 and the position is stark: a foreign controller processing Omani residents' data abroad is now inside the law's scope and, by the fact of holding that data outside the Sultanate, inside the reach of its most expensive penalty article unless the explicit consent exists and can be shown.

Automated decisions, AI, and the right to ask for a human

The amended Article 14 defines automated processing as processing carried out by an electronic programme or system operating entirely without human involvement, or with only limited human supervision. Note the second half: limited supervision still counts. Somebody who glances at the output and clicks approve does not take the decision outside the article. Data subjects gain the right to object to an automated decision and to require the controller to bring in a human to review it — so if you run a model that screens applicants, prices a policy, blocks a transaction or ranks a CV, you need a route by which a person in Oman can ask for a human, and a human who can actually be brought in.

Two adjacent developments put this in context, neither of them a binding data protection rule. MTCIT issued its Public Policy for the Safe and Ethical Use of Artificial Intelligence on 1 April 2025 — guidance for the public and private sectors built on internationally recognised governance principles, not law. And Royal Decree 50/2026, of 30 April 2026, establishes an Artificial Intelligence Special Zone, extending incentives such as tax breaks and customs exemptions to AI projects. The combination is what to notice: Oman is inviting AI businesses in with one instrument while, with another, making the amended Article 2 apply to any tool that makes decisions about people in Oman no matter where it runs. An AI company taking the incentives is not taking an exemption from the PDPL.

What the official sources do not say

  • No permit fee is published. Not by MTCIT, not in the Gazette, and not in any practitioner write-up we could find.
  • No enforcement action has been reported. As at September 2026 we could not find a single published Omani enforcement decision or fine under the PDPL. The law is in force and enforceable; what MTCIT does with it in practice is not yet on the record.
  • MTCIT's own PDPL page stops short of the operational detail. It publishes the law and a summary of rights, but not the executive regulation's decision number, the permit procedure, the fees or the deadlines.
  • Royal Decree 68/2026 sets no compliance deadline. No transition period was given for bringing existing practices into line with the amendments.

The second of those is the one people misread, so handle it carefully. An absence of reported enforcement is not evidence that the law will not be enforced. It tells you there is no published record yet of how MTCIT weighs a first offence, whether it warns before it fines, where in the Article 29 band it starts, or how it treats a foreign controller. It also means nobody knows those things — including any consultant pricing your risk for you. Anyone describing Omani enforcement practice in September 2026 is describing something that has not happened yet.

Where to start, in order

  1. Write down what personal data you hold and where it physically sits. Every list, every system, every backup, every spreadsheet on a laptop. This is the step people skip, and everything else depends on it.
  2. Mark the cross-border items. Anything hosted or accessible outside Oman is your Article 29 exposure. Deal with these first, because they are the expensive ones.
  3. Designate your data protection officer and publish the contact details. It can be an existing employee. It cannot be nobody.
  4. Write the 72-hour breach procedure, naming who decides and who contacts MTCIT, and make sure the people who would notice a breach at nine on a Thursday evening know it exists.
  5. Fix the consent flows, marketing first — Article 22 now requires explicit consent for commercial advertising, and a list you bought is not consent.
  6. If you process health or biometric data about anyone other than your own employees, apply for the permit, and diarise 45 days from the application, because silence is a refusal.
Does Oman's data protection law apply to my company if we are based outside Oman?
Yes, if you process the personal data of people who are in Oman. Article 2 of the Personal Data Protection Law, as amended by Royal Decree 68/2026 with effect from 7 September 2026, applies the law to the processing of the personal data of individuals in Oman whether the processing takes place inside or outside the Sultanate. The test is where the person is, not where the company or the server is. That brings in a foreign-registered online shop that ships to Muscat, a software platform with Omani users, and a head-office HR system holding the records of employees working here. What no published source explains is how MTCIT would reach a controller with no presence in Oman.
What is the maximum fine under Oman's Personal Data Protection Law?
It is not OMR 2,000, which is the most common error on this subject. OMR 2,000 is the ceiling of Article 32 alone, the administrative penalties article. The penalty articles of Royal Decree 6/2022 go considerably further: Article 29, on cross-border data transfer restrictions, carries OMR 100,000 to OMR 500,000; Article 30, on legal entity liability, carries OMR 5,000 to OMR 100,000; and Article 28, on sensitive data and breach notification, carries OMR 15,000 to OMR 20,000. Alongside the fines, MTCIT may issue a warning or suspend or cancel the processing permit.
Has the deadline for complying with Oman's data protection law passed?
Yes. The law came into force on 9 February 2023. The Executive Regulation issued by Ministerial Decision 34/2024 then gave controllers one year from 29 January 2024 to regularise, and Ministerial Decision 6/2025 extended that by a further year, ending on 5 February 2026 according to both CMS and Trowers & Hamlins. Older articles put the deadline at approximately 29 January 2025, which was correct when written but predates the extension. The September 2026 amendments came with no transition period and no compliance date at all — they have been in force since 7 September 2026.
Does a small business in Oman need a data protection officer?
Yes. Organisations must designate a Personal Data Protection Officer and make the contact details publicly available, and the obligation applies regardless of the size of the organisation. There is no small-business exemption, no employee-count threshold and no turnover threshold. The word used is designate rather than employ, which means an existing employee can hold the role alongside their other duties. What is required is that the designation is real and that the published contact details reach a named person who knows they hold it.
How long do I have to report a data breach in Oman?
Seventy-two hours from when you become aware of the breach, not from when it happened, and the notification goes to the Ministry of Transport, Communications and Information Technology. Where the breach is likely to cause serious harm or presents a high risk to the people affected, you must notify them as well. Article 28 of the law, which covers breach notification, carries a fine of OMR 15,000 to OMR 20,000. In practice the deadline is short enough that the organisations meeting it are the ones that decided in advance who makes the decision and who contacts the ministry.
How much does the sensitive data processing permit cost in Oman?
No fee is published. Neither the Ministry of Transport, Communications and Information Technology nor any gazette source publishes a fee for the sensitive-data processing permit, and the practitioner write-ups do not state one either. That is a genuine gap in both the official and the secondary sources rather than a figure being withheld. The deadlines, by contrast, are published: MTCIT has 45 days to decide the application and no response means refusal, and the minister has 60 days to decide an appeal, where again no response means refusal.

If you would rather have this dealt with than read about: the paperwork parts of it — the sensitive-data permit application, the correspondence with the ministry, a privacy notice in Arabic that will stand up at a counter — are ordinary work, and our office in Al Ghubra can handle them. The part that is not paperwork, chiefly working out what data you hold and where it sits, only you can do, and it is where the law bites.

Sources

  1. OFFICIALRoyal Decree 6/2022 issuing the Personal Data Protection Law — Decree
  2. OFFICIALRoyal Decree 6/2022 — Ministry of Justice and Legal Affairs
  3. OFFICIALPersonal Data Protection Law — MTCIT
  4. OFFICIALExecutive Regulations of the Personal Data Protection Law — MTCIT
  5. OFFICIALMinisterial Decision 6/2025 amending Ministerial Decision 34/2024 — Decree
  6. OFFICIALOfficial Gazette 1429 — Promulgating the Personal Data Protection Law (PDF)
  7. OFFICIALExecutive Regulation of the Personal Data Protection Law — Oman Open Data
  8. SECONDARYNew Amendments to the Personal Data Protection Law — Decree Blog
  9. SECONDARYOman Personal Data Protection Law: Key 2026 Amendments — CMS
  10. SECONDARYOman personal data protection law: entering the enforcement phase — CMS
  11. SECONDARYExtension of the Grace Period to Comply with Data Protection Regulation — Decree Blog
  12. SECONDARYOman's Data Protection law — new regulations — Trowers & Hamlins
  13. SECONDARYPersonal data and artificial intelligence: recent regulatory developments in Oman — Trowers & Hamlins
  14. SECONDARYExecutive Regulations on the Oman Personal Data Protection Law — Dentons

Need help with your transaction?

Our Sanad office in Al Ghubra, Muscat handles government transactions on your behalf — clear pricing, direct follow-up.

Message us on WhatsApp

This guide is for information only and is not legal or tax advice. Fees and rules in Oman change; always confirm with the relevant government authority before acting. The verification date is shown at the top of this page.