Skip to the content
Global Data RulesData governance rules, country by country

Oman

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Oman has a full privacy law, policed by a government ministry rather than by a separate privacy watchdog. Personal data may leave the country, but only with the person's clear permission, only if the destination protects the data at least as well as Oman does, and only after you have written a risk assessment. Data held for an Omani government body is different: it must stay inside Oman.

Data governance in Oman

The eight things that decide how you handle data about people in Oman. Same eight on every country page, so you can compare.

Who has to follow these rules

The law does not say. It states only that it applies to personal data that is processed. There is no sentence about companies based abroad, no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. If you have people, a branch or servers in Oman you are plainly covered. If you sell to Omanis purely from abroad, the position is genuinely unsettled, and no official guidance answering the question was found.

Medium confidenceNational rules

Where the data is allowed to live

Yes, data can leave Oman, and no country is banned. But four things must be true before it goes. The person must have given clear, specific permission. The transfer must not damage national security or the higher interests of the state. The organisation receiving the data must protect it at least as well as Oman's own rules do. And you must have written a risk assessment of the transfer, which the ministry can demand a copy of at any time.

Medium confidenceYes, with paperworkApproval each timeGovernmentTelecoms

Sending data out of the country

There is no list of approved countries and no list of banned ones, and no government form to file for an ordinary transfer. Oman puts the work on you: get clear permission from the person, satisfy yourself that the recipient protects the data as well as Oman does, and keep a written assessment on file. The exception is sensitive data such as health or biometric records, which you cannot process at all until the ministry grants you a permit, and the permit application has to name where the data will be stored or sent.

Medium confidenceApproval each timeExplicit consentGovernment sign-off neededPut a transfer safeguard in place

The regulator, and whether it actually acts

There is no separate privacy watchdog. The regulator is the Ministry of Transport, Communications and Information Technology, working through an in-house personal data protection department. It exists and it is doing things: it issued the detailed rules in 2024, it publishes an address for breach reports and complaints, and it put out a compliance self-check tool for companies in 2025. What we could not find is a single published decision, fine or enforcement report, even though the law tells the ministry to publish reports on its work. So the machinery is switched on, but its teeth have not been seen in public.

Medium confidenceWaking upRegulator

How long you must keep it — and when to delete it

Oman sets a firm floor and a soft ceiling. The floor: tax records, books and the documents behind them must be kept for at least ten years after the accounting period ends. The ceiling: there is no fixed maximum, but you must decide a retention period for every purpose, write down why, keep it proportionate, and delete when a person asks unless you have a legal reason to refuse. Where the two collide, the keeping duty wins, because complying with a legal obligation is one of the situations the privacy law does not cover.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep records of processingLet people delete their data

If something goes wrong

Two clocks, both seventy-two hours, and they start at different moments for different audiences. Tell the ministry's data protection department within seventy-two hours of learning about a breach if it could put people's rights at risk. Tell the affected people themselves within seventy-two hours of learning about it if the breach could cause them serious harm or high risk. The ministry can also order you to notify people when you had decided not to. Failing to report is a criminal offence, not just a paperwork slip.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: you need a government permit before you touch health, genetic, biometric, ethnic, sex life, political or religious, or criminal record data, and the ministry has forty-five days to answer, with silence counting as a no. Two: the fine for sending data abroad unlawfully runs from one hundred thousand to five hundred thousand Omani rials, about two hundred and sixty thousand to one and a third million United States dollars, which is a court fine, far above the two thousand rial administrative cap people quote. Three: the ministry can order you to hire an external auditor that it has licensed, and a copy of the audit report goes to the ministry. Four: there is no legitimate interest basis, so consent has to carry almost everything, in writing, and again separately before any marketing message. Five: the law's exemption list is enormous and includes performing a contract with the person, so both sides of an argument can point at it.

Medium confidenceRegister or notifyIndependent auditGet a parent's consent for childrenAppoint a data protection officerCriminal liability

What's changing next

Nothing new is scheduled to hit private companies in the next twelve months that we could find. The recent movement has all been in cyber and government rules: a brand new technology crimes law took effect on 2 June 2026, and a fresh cloud policy for government bodies landed on 28 June 2026. The bigger risk is not a bill but a switch already in the minister's hand: the ministry can order transfers to any country or international organisation to stop, and can suspend or cancel a processing permit, with no consultation and no notice period.

Medium confidenceIn forceGovernment

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Cloud and Hosting Services Standard

Government policy document · MTCIT Cloud and Hosting Services Standard version 1, effective 17 May 2018, read with Cloud Computing First Circular 10/2026 of 28 June 2026

In forceNo — it stays put

Anything hosted for an Omani government body must stay inside the country, backups included. This is the hardest data residency wall in Oman and it catches any cloud vendor or system integrator serving the public sector.

In force since 17 May 2018

Enforced by Ministry of Transport, Communications and Information Technology

Transfer model: Not allowed

High confidence
Telecoms

قانون تنظيم الاتصالات (Telecommunications Regulation Law)

Act of parliament · Royal Decree 30/2002 as amended, published 17 March 2002

In forceYes — store it anywhere

Telecommunications and internet companies in Oman are not told where to store data, but they are told who may see it. Subscriber data cannot be handed over to anyone, including a foreign parent company, without an order from an Omani court.

In force since 17 March 2002

Enforced by Telecommunications Regulatory Authority

Transfer model: Approval each time

Medium confidence

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

قانون حماية البيانات الشخصية (Personal Data Protection Law)

Act of parliament · Royal Decree 6/2022, Official Gazette No. 1429 of 13 February 2022

In forceYes, with paperwork

Oman's general privacy law. Consent-first, with a government permit needed before touching sensitive categories such as health or biometric data. Transfers abroad are allowed on conditions rather than banned, but the criminal fine for getting a transfer wrong is the heaviest penalty in the statute.

In force since 13 February 2023

Enforced by Ministry of Transport, Communications and Information Technology

Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed, Important public interest

Medium confidence

اللائحة التنفيذية لقانون حماية البيانات الشخصية (Executive Regulation of the Personal Data Protection Law)

Directly binding regulation · Ministerial Decision 34/2024, signed 28 January 2024, Official Gazette No. 1531 of 4 February 2024

In forceYes, with paperwork

The detailed rules under the privacy law. It creates the permit system, the cross-border transfer test, the seventy-two hour breach clocks, the data protection officer duty and the complaint procedure. Organisations were given one year from February 2024 to bring themselves into line, so it has bitten fully since February 2025.

In force since 5 February 2024But only enforceable from 5 February 2025

Enforced by Ministry of Transport, Communications and Information Technology

Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed

Medium confidence

قانون مكافحة جرائم تقنية المعلومات (Information Technology Crimes Law)

Act of parliament · Royal Decree 61/2026, published 1 June 2026, replacing the earlier technology crimes law

In forceYes — store it anywhere

A new criminal law on technology offences that took effect on 2 June 2026. It reaches acts committed outside Oman that harm Omani interests or people, and it lets the ministry obtain electronic data from bodies inside and outside the country on a prosecutor's or court order.

In force since 2 June 2026

Enforced by Ministry of Transport, Communications and Information Technology

Transfer model: Approval each time

Medium confidence

Who you would hear from

  • وزارة النقل والاتصالات وتقنية المعلومات

    Privacy law, permits for sensitive data processing, breach reports, complaints, government cloud and data governance policy

    Acts as the privacy regulator through an internal personal data protection department. It issued the detailed rules in February 2024, publishes breach and complaint channels, and released a compliance self-assessment tool in 2025. No published enforcement decision, fine or statutory activity report was found as of 18 August 2026, so enforcement is rated waking rather than active.

  • مركز الدفاع الإلكتروني

    Cyber defence; its powers are expressly preserved by both the privacy law and the 2026 technology crimes law

    Created by Royal Decree 64/2020 and named in the preamble of the privacy law. No public website, published decision, reporting channel or contact point was found on 18 August 2026. Treat its practical role as unknown rather than absent: it may operate entirely inside the security apparatus. The link given is the ministry site, because the centre has no verified site of its own.

  • هيئة تنظيم الاتصالات

    Telecommunications and postal regulation, licence conditions, subscriber data controls

    Site is live and its legal framework library carries current instruments, including a regulation running to 2026.

  • المركز الوطني للسلامة المعلوماتية

    National computer emergency response and cybersecurity industry programmes

    Site is live and publishing cybersecurity industry programme material dated 2025 and 2026. No published incident reporting obligation for private companies was found on it.

  • جهاز الضرائب

    Income tax, value added tax, record keeping duties

  • البنك المركزي العماني

    Banking, payments, outsourcing and cloud rules for licensed banks

    Not verified in this run. Every attempt to reach the Central Bank site on 18 August 2026 failed at the network level, so no banking data rule is asserted in this record in either direction.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether banks, insurers or investment firms face data localisation or cloud approval rules

    The Central Bank of Oman site and the Financial Services Authority site were unreachable throughout this research on 18 August 2026, so nothing could be verified from a government source. Gulf central banks commonly impose outsourcing and cloud conditions, so assume rules may exist until checked directly with the regulator.

  • The exact article numbers behind the money penalties, in particular that the fine of one hundred thousand to five hundred thousand Omani rials attaches to unlawful transfer abroad

    Oman publishes the law only as a scanned Arabic gazette with a legacy font that machines cannot read, so the text had to be read by optical character recognition. The words and the amounts are clear; Arabic numerals inside brackets are the least reliable part. The article sequence strongly supports the reading, but it should be confirmed against a certified translation before relying on it.

  • Whether the law reaches a company with no presence in Oman

    The scope provision is a single line about personal data that is processed. It says nothing about companies abroad, and no official guidance, decision or frequently asked questions page addressing the point was found.

  • The age at which a person stops being a child for consent purposes

    Neither the law nor its executive regulation states an age. The general Omani age of majority is the usual assumption, but this was not confirmed from a government source.

  • Whether a separate incident report must go to the Cyber Defence Centre, and on what deadline

    Both the privacy law and the 2026 technology crimes law expressly preserve the centre's powers, but no published reporting rule, form or contact channel for it could be located.

  • Any sector rule for health records, education, insurance broking, gambling or mapping and survey data

    No such rule was found on official Omani sources on 18 August 2026. Several relevant sites, including the Ministry of Justice and Legal Affairs, the Ministry of Commerce and the National Survey Authority, were unreachable, so this is an unchecked gap rather than a confirmed absence. Gambling is in any event not lawfully offered in Oman.

  • Whether the ministry has ever issued a fine, a public decision, or the periodic activity reports the law requires it to publish

    No such decision or report was found on the ministry's own site. Absence of publication is not proof that nothing has happened; enforcement in Oman is often handled privately.

  • Whether the telecommunications regulator imposes storage or localisation conditions through individual operator licences

    The regulator's document library is served through a search interface that could not be enumerated, so the forty-two licence documents it lists were not read individually.

Sixty-day cadence. Oman is not legislating constantly, but the minister holds switches that can flip without consultation, including an order halting transfers to a named country and suspension of processing permits, and the ministry issued three significant instruments between January 2025 and June 2026. The unverified financial sector is also a standing reason to re-check.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Oman versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.