Skip to the content
Global Data RulesData governance rules, country by country

Oman

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Oman — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Oman has a full privacy law. A government ministry polices it, not a separate privacy watchdog. Personal data may leave the country, but three things must be true. The person must give clear permission. The destination must protect the data at least as well as Oman does. And you must have written a risk assessment. Data held for an Omani government body is different. It must stay inside Oman.

Data governance in Oman

The eight things that decide how you handle data about people in Oman. Same eight on every country page, so you can compare.

Who has to follow these rules

The law does not say. It states only that it applies to personal data that is used or stored. There is no sentence about companies based abroad. There is no revenue or headcount threshold to fall below. There is no requirement to appoint a local representative. If you have people, a branch or servers in Oman, you are plainly covered. If you sell to Omanis purely from abroad, the position is unsettled. We found no official guidance answering the question.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, data can leave Oman, and no country is banned. But four things must be true before it goes. The person must have given clear, specific permission. The transfer must not damage national security or the higher interests of the state. The organisation receiving the data must protect it at least as well as Oman's own rules do. And you must have written a risk assessment of the transfer. The ministry can demand a copy of it at any time.

What to do: Get the paperwork for one of the routes below signed before any data leaves Oman.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

There is no list of approved countries and no list of banned ones. There is no government form to file for an ordinary transfer. Oman puts the work on you. Get clear permission from the person. Satisfy yourself that the recipient protects the data as well as Oman does. Keep a written assessment on file. The exception is sensitive data, such as health or biometric records. You may not touch that at all until the ministry grants you a permit. The permit application has to name where the data will be stored or sent.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Explicit consent · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

There is no separate privacy watchdog. The regulator is the Ministry of Transport, Communications and Information Technology, working through an in-house personal data protection department. It exists and it is doing things. It issued the detailed rules in 2024. It publishes an address for breach reports and complaints. It put out a compliance self-check tool for companies in 2025. What we could not find is a single published decision, fine or enforcement report. The law tells the ministry to publish reports on its work. So the machinery is switched on, but nobody has seen it used in public.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Oman sets a firm floor and a soft ceiling. The floor: tax records, books and the documents behind them must be kept for at least ten years after the accounting period ends. The ceiling: there is no fixed maximum. But you must set a keeping period for every purpose and write down why. Keep it proportionate. Delete when a person asks, unless you have a legal reason to refuse. Where the two collide, the duty to keep wins. Complying with a legal duty is one of the situations the privacy law does not cover.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Two clocks, both seventy-two hours. They start at different moments and go to different audiences. Tell the ministry's data protection department within seventy-two hours of learning about a breach, if it could put people's rights at risk. Tell the affected people within seventy-two hours of learning about it, if the breach could cause them serious harm or high risk. The ministry can also order you to notify people when you had decided not to. Failing to report is a crime, not just a paperwork slip.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. One: you need a government permit before you touch health, genetic, biometric, ethnic, sex life, political or religious, or criminal record data. The ministry has forty-five days to answer, and silence counts as a no. Two: the fine for sending data abroad unlawfully runs from one hundred thousand to five hundred thousand Omani rials. That is about two hundred and sixty thousand to one and a third million United States dollars. It is a court fine, far above the two thousand rial administrative cap people quote. Three: the ministry can order you to hire an external auditor that it has licensed, and a copy of the audit report goes to the ministry. Four: there is no legitimate interest basis, so consent has to carry almost everything. It must be in writing, and again separately before any marketing message. Five: the law's exemption list is enormous. It includes carrying out a contract with the person, so both sides of an argument can point at it.

What you have to do here:
Independent audit · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

Nothing new is scheduled to hit private companies in the next twelve months that we could find. The recent movement has all been in cyber and government rules. A brand new technology crimes law took effect on 2 June 2026. A fresh cloud policy for government bodies landed on 28 June 2026. The bigger risk is not a bill. It is a power the minister already holds. The ministry can order transfers to any country or international organisation to stop. It can suspend or cancel a permit. It needs no consultation and no notice period.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Cloud and Hosting Services Standard · MTCIT Cloud and Hosting Services Standard version 1, effective 17 May 2018, read with Cloud Computing First Circular 10/2026 of 28 June 2026 · Government policy document

In forceNo — it stays put

Anything hosted for an Omani government body must stay inside the country, backups included. This is the strictest location rule in Oman. It catches any cloud vendor or system integrator serving the public sector.

In force since 17 May 2018

Enforced by Ministry of Transport, Communications and Information Technology

How this country controls where data goes: Not allowed

Telecoms

Telecoms rules

Official name: قانون تنظيم الاتصالات (Telecommunications Regulation Law) · Royal Decree 30/2002 as amended, published 17 March 2002 · Act of parliament

In forceYes — store it anywhere

Telecommunications and internet companies in Oman are not told where to store data, but they are told who may see it. Subscriber data cannot be handed over to anyone, including a foreign parent company, without an order from an Omani court.

In force since 17 March 2002

Enforced by Telecommunications Regulatory Authority

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Health data rules

Official name: قانون حماية البيانات الشخصية (Personal Data Protection Law) · Royal Decree 6/2022, Official Gazette No. 1429 of 13 February 2022 · Act of parliament

In forceYes, with paperwork

Oman's general privacy law. Consent comes first. You need a government permit before you touch sensitive categories such as health or biometric data. Sending data abroad is allowed on conditions rather than banned. But the criminal fine for getting a transfer wrong is the heaviest penalty in the statute.

In force since 13 February 2023

Enforced by Ministry of Transport, Communications and Information Technology

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed, Important public interest

Not fully verified — see “What we're not sure about” below.

Breach reporting rules

Official name: اللائحة التنفيذية لقانون حماية البيانات الشخصية (Executive Regulation of the Personal Data Protection Law) · Ministerial Decision 34/2024, signed 28 January 2024, Official Gazette No. 1531 of 4 February 2024 · Directly binding regulation

In forceYes, with paperwork

The detailed rules under the privacy law. They create the permit system, the test for sending data abroad, the seventy-two hour breach clocks, the data protection officer duty and the complaint procedure. Organisations were given one year from February 2024 to comply. So the rules have applied in full since February 2025.

In force since 5 February 2024Enforced from 5 February 2025

Enforced by Ministry of Transport, Communications and Information Technology

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Data rules

Official name: قانون مكافحة جرائم تقنية المعلومات (Information Technology Crimes Law) · Royal Decree 61/2026, published 1 June 2026, replacing the earlier technology crimes law · Act of parliament

In forceYes — store it anywhere

A new criminal law on technology offences that took effect on 2 June 2026. It reaches acts committed outside Oman that harm Omani interests or people. It also lets the ministry obtain electronic data from bodies inside and outside the country, on a prosecutor's or court order.

In force since 2 June 2026

Enforced by Ministry of Transport, Communications and Information Technology

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • وزارة النقل والاتصالات وتقنية المعلومات

    Privacy law, permits for sensitive data processing, breach reports, complaints, government cloud and data governance policy

    Acts as the privacy regulator through an internal personal data protection department. It issued the detailed rules in February 2024, publishes breach and complaint channels, and released a compliance self-assessment tool in 2025. No published enforcement decision, fine or statutory activity report was found as of 18 August 2026, so enforcement is rated waking rather than active.

  • مركز الدفاع الإلكتروني

    Cyber defence; its powers are expressly preserved by both the privacy law and the 2026 technology crimes law

    Created by Royal Decree 64/2020 and named in the preamble of the privacy law. No public website, published decision, reporting channel or contact point was found on 18 August 2026. Treat its practical role as unknown rather than absent: it may operate entirely inside the security apparatus. The link given is the ministry site, because the centre has no verified site of its own.

  • هيئة تنظيم الاتصالات

    Telecommunications and postal regulation, licence conditions, subscriber data controls

    Site is live. Its legal library carries current rules, including a regulation running to 2026.

  • المركز الوطني للسلامة المعلوماتية

    National computer emergency response and cybersecurity industry programmes

    Site is live and publishing cybersecurity industry programme material dated 2025 and 2026. We found no published incident reporting duty for private companies on it.

  • جهاز الضرائب

    Income tax, value added tax, record keeping duties

  • البنك المركزي العماني

    Banking, payments, outsourcing and cloud rules for licensed banks

    Not verified. Every attempt to reach the Central Bank site on 18 August 2026 failed at the network level. So this record asserts no banking data rule, in either direction.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether banks, insurers or investment firms face keeping data in the country or cloud approval rules

    We could not confirm whether banks, insurers and investment firms have extra rules. The Central Bank of Oman site and the Financial Services Authority site were unreachable on 18 August 2026. Gulf central banks commonly impose outsourcing and cloud conditions. Assume rules may exist, and check directly with the regulator.

  • The exact article numbers behind the money penalties, in particular that the fine of one hundred thousand to five hundred thousand Omani rials attaches to unlawful transfer abroad

    We could not confirm the exact wording against a certified text. Oman publishes the law only as a scanned Arabic gazette, in a legacy font that machines cannot read, so we read it by optical character recognition. The words and the amounts are clear. Arabic numerals inside brackets are the least reliable part. The order of the articles strongly supports our reading, but confirm it against a certified translation before you rely on it.

  • Whether the law reaches a company with no presence in Oman

    We could not confirm whether the law reaches companies with no office in Oman. The scope wording is a single line about personal data that is used or stored. It says nothing about companies abroad. We found no official guidance, decision or frequently asked questions page on the point.

  • The age at which a person stops being a child for consent purposes

    We could not confirm the age at which someone stops being a child. Neither the law nor its executive regulation states an age. People usually assume the general Omani age of majority, but we could not confirm that from a government source.

  • Whether a separate incident report must go to the Cyber Defence Centre, and on what deadline

    We could not confirm whether you must also report incidents to the Cyber Defence Centre. Both the privacy law and the 2026 technology crimes law expressly preserve the centre's powers. We found no published reporting rule, form or contact channel for it.

  • Any sector rule for health records, education, insurance broking, gambling or mapping and survey data

    We found no such rule on official Omani sources on 18 August 2026. Several relevant sites were unreachable, including the Ministry of Justice and Legal Affairs, the Ministry of Commerce and the National Survey Authority. So this is an unchecked gap rather than a confirmed absence. Gambling is in any event not lawfully offered in Oman.

  • Whether the ministry has ever issued a fine, a public decision, or the periodic activity reports the law requires it to publish

    We found no decision or report on the ministry's own site. That does not prove nothing has happened. Enforcement in Oman is often handled privately.

  • Whether the telecommunications regulator imposes storage or localisation conditions through individual operator licences

    We could not read the regulator's document library. It is served through a search interface we could not enumerate, so we did not read the forty-two licence documents it lists individually.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.