Oman
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Oman — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Oman has a full privacy law. A government ministry polices it, not a separate privacy watchdog. Personal data may leave the country, but three things must be true. The person must give clear permission. The destination must protect the data at least as well as Oman does. And you must have written a risk assessment. Data held for an Omani government body is different. It must stay inside Oman.
Data governance in Oman
The eight things that decide how you handle data about people in Oman. Same eight on every country page, so you can compare.
Who has to follow these rules
The law does not say. It states only that it applies to personal data that is used or stored. There is no sentence about companies based abroad. There is no revenue or headcount threshold to fall below. There is no requirement to appoint a local representative. If you have people, a branch or servers in Oman, you are plainly covered. If you sell to Omanis purely from abroad, the position is unsettled. We found no official guidance answering the question.
The Personal Data Protection Law was issued by Royal Decree 6/2022. It opens with a one-line statement of scope, covering personal data that is used or stored. It then lists a long set of activities that fall outside the law altogether. Those are protecting national security or the public interest. State bodies carrying out their legal functions. Complying with a legal duty or a court ruling. Protecting the state's economic and financial interests. Protecting a vital interest of the person. Detecting or preventing a crime, on a written official request from investigators. Carrying out a contract to which the person is a party. Purely personal or family activity. Historical, statistical, scientific, literary or economic research by authorised bodies, where the output is anonymised. And data that is already lawfully public. The contract exemption is drafted very widely, and we found no official interpretation of it. By contrast, the new Information Technology Crimes Law, issued by Royal Decree 61/2026, applies even if you have no office in Oman. It reaches offences committed wholly or partly outside Oman where they harm Oman's interests or people. It also reaches offences where the criminal result happened, or was meant to happen, in Oman. If you plan to argue that Omani law stops at the border, read that part first.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022, Official Gazette No. 1429 - scope and exemptions
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law - ministry page, published 13 February 2022
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026 - extraterritorial reach
mtcit.gov.om
Link checked 18 August 2026
Where the data is allowed to live
Yes, data can leave Oman, and no country is banned. But four things must be true before it goes. The person must have given clear, specific permission. The transfer must not damage national security or the higher interests of the state. The organisation receiving the data must protect it at least as well as Oman's own rules do. And you must have written a risk assessment of the transfer. The ministry can demand a copy of it at any time.
The general rule sits in the Personal Data Protection Law. The Executive Regulation, issued as Ministerial Decision 34/2024, fills it out. Consent is not needed in two narrow cases. One is where the transfer carries out an international treaty duty Oman has signed. The other is where the data has been stripped of identity so completely that nobody can link it back to the person. The written assessment must cover several things. The nature, volume and sensitivity of the data. The purpose and scope of the work, and who else will see the data. How long the work lasts, and whether it is one-off or routine. The stages of the journey, including every country the data passes through and its final destination. And the effects and risks for the person. Here is the position sector by sector, hardest rule first. Government: hardest. The ministry's Cloud and Hosting Services Standard tells government agencies that government data and information may only be hosted, transacted or handled inside Oman's geographical boundaries. That includes primary storage and backup or disaster recovery. A June 2026 circular now also requires government bodies to classify data before it is put into any cloud. Sensitive personal data: you may not touch health, genetic, biometric, ethnic origin, sex life, political or religious opinions, beliefs or criminal convictions without a permit from the ministry. The permit application must list the places where the data will be stored or transferred. So storage location becomes a licensed matter rather than a private choice. Telecommunications: we found no storage rule. But an internet service provider may not disclose subscriber data to anyone except on an order from the competent court. That blocks routine group-wide sharing with a foreign parent. Banking, insurance and securities: not verified, see the unconfirmed list. Health, education, gambling and mapping: we found no separate storage rule on official sources, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024, Official Gazette No. 1531 - chapter on transfer outside the borders
mtcit.gov.om
“يلتزم المتحكم قبل نقل أو تحويل البيانات الشخصية إلى خارج حدود سلطنة عمان بالحصول على الموافقة الصريحة لصاحب البيانات الشخصية، وألا يترتب على نقل البيانات أو تحويلها مساس بالأمن الوطني أو المصالح العليا للدولة”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard, section on sensitive information storage and processing
mtcit.gov.om
“Government data and/or information must only be hosted/transacted/processed with in the geo boundaries of Sultanate of Oman. This includes the primary storage as well as the backup or disaster recovery arrangements.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law, Royal Decree 30/2002 as amended - confidentiality of subscriber data
mtcit.gov.om
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Oman.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
There is no list of approved countries and no list of banned ones. There is no government form to file for an ordinary transfer. Oman puts the work on you. Get clear permission from the person. Satisfy yourself that the recipient protects the data as well as Oman does. Keep a written assessment on file. The exception is sensitive data, such as health or biometric records. You may not touch that at all until the ministry grants you a permit. The permit application has to name where the data will be stored or sent.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Explicit consent · Government sign-off needed
The permit route works like this. You apply to the ministry with the name and contact details of your data protection officer. You give the purpose of your work with the data, and a description and classification of the data. You name the supplier who will handle it for you, and any third party you will disclose it to. You list the places where the data will be transferred or stored. You describe your data management and protection systems. You attach your privacy policy and your plan for handling a breach. The competent department has forty-five days to decide, counted from the date your file is complete. Silence for forty-five days counts as a refusal. A refusal must give reasons. You can appeal to the Minister within sixty days, and silence on that appeal for thirty days is again a refusal. The Minister issues the permit for up to five years against payment of a fee, and it is renewable. You must report any change to the permit details within fifteen days. The permit can be cancelled for three reasons. You break the law or the regulation. You miss that fifteen-day deadline. Or it turns out the permit was obtained by fraud or false information. Note also the reverse power. The ministry can order you to stop transferring personal data to a named country or international organisation.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024 - permit procedure and transfer assessment
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulations of the Personal Data Protection Law - ministry page, issued 4 February 2024
mtcit.gov.om
“The Executive Regulations of the Personal Data Protection Law were issued pursuant to Ministerial Decision No. 34/2024. The regulations provide detailed provisions for several articles of the Personal Data Protection Law, most importantly: the procedures for obtaining a permit to process personal data as outlined in Article (5) of the law”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - ministry powers including halting transfers abroad
mtcit.gov.om
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
There is no separate privacy watchdog. The regulator is the Ministry of Transport, Communications and Information Technology, working through an in-house personal data protection department. It exists and it is doing things. It issued the detailed rules in 2024. It publishes an address for breach reports and complaints. It put out a compliance self-check tool for companies in 2025. What we could not find is a single published decision, fine or enforcement report. The law tells the ministry to publish reports on its work. So the machinery is switched on, but nobody has seen it used in public.
The law names the ministry as the body responsible for applying it. It says this is without prejudice to the powers of the Cyber Defence Centre, which was created by Royal Decree 64/2020. The regulation defines the competent department as the ministry's own personal data protection administration. Officials named by decision can be given the status of judicial enforcement officers. That is what allows evidence gathering rather than mere correspondence. The ministry has a range of powers. It can warn an organisation. It can order data corrected or erased. It can suspend the use of data temporarily or permanently. It can halt transfers to a country or international organisation. It can suspend or cancel a permit. And it can impose administrative fines of up to two thousand Omani rials, roughly five thousand two hundred United States dollars, per violation. Larger money penalties are criminal court fines under the law itself, not administrative ones. Complaints run to fixed clocks. A complaint must be brought within thirty days of the complainant learning of the violation. The department passes it to the organisation within seven days. The organisation has fourteen days to answer. The department then has sixty days to decide, and silence counts as a rejection. The Cyber Defence Centre is a separate matter. Both the privacy law and the 2026 technology crimes law expressly preserve its powers. But we found no public website, published decision or contact channel for it, so its real role is unknown rather than absent. The telecommunications regulator and the tax authority are visibly working and publish current material.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection reporting channels - violation reports and breach reports to the ministry
mtcit.gov.om
“regarding the implementation of the controller's obligation to inform the competent department at the Ministry of any breach of personal data within a period not exceeding 72 hours of his knowledge of the breach”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologySelf-assessment tool for controllers and processors, 2025
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - ministry duties, enforcement measures and judicial officer status
mtcit.gov.om
Link checked 18 August 2026
How long you must keep it — and when to delete it
Oman sets a firm floor and a soft ceiling. The floor: tax records, books and the documents behind them must be kept for at least ten years after the accounting period ends. The ceiling: there is no fixed maximum. But you must set a keeping period for every purpose and write down why. Keep it proportionate. Delete when a person asks, unless you have a legal reason to refuse. Where the two collide, the duty to keep wins. Complying with a legal duty is one of the situations the privacy law does not cover.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data · Let people delete their data
The privacy regulation says the reason for keeping records must be specific and lawful. The keeping period must match the purpose. The records must be technically protected while held. You must keep records of what you do with personal data, continuously, and hand them to the competent department on request. Those records must include the categories of data, who may access it, the periods and limits for using it, and how it is deleted and corrected. They must also include who the data is disclosed to and why. They must cover details of anyone the data is transferred to, and anything about movement of data across the border. They must cover the security measures in place. And they must cover every breach, with its circumstances, effects and the remedy applied. Breach records must be kept for whatever period the competent department sets. On the deletion side, a person may demand erasure where the purpose has ended, where they have withdrawn consent, or where you broke the rules. You may refuse only to comply with a law, a court ruling or judgment, or where there is a live dispute with that person. The law also excludes data needed for national preservation and documentation purposes from the erasure right. You must answer requests within forty-five days.
Sources
- Official sourceTax Authority of OmanIncome Tax Law, English version - ten year record keeping duty
tms.taxoman.gov.om
“Every taxpayer shall preserve for at least ten years from the end of the accounting period for which the income is chargeable to tax, all registers, books of accounts and the documents proving their contents”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - retention of processing documents, record of processing activities, erasure
mtcit.gov.om
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Two clocks, both seventy-two hours. They start at different moments and go to different audiences. Tell the ministry's data protection department within seventy-two hours of learning about a breach, if it could put people's rights at risk. Tell the affected people within seventy-two hours of learning about it, if the breach could cause them serious harm or high risk. The ministry can also order you to notify people when you had decided not to. Failing to report is a crime, not just a paperwork slip.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The report to the ministry must describe the nature of the data involved and the consequences. It must give contact details for follow-up. It must describe the likely effects. It must set out the corrective, technical and organisational steps you will take, including anything proposed to soften the impact. And it must state what you already did between discovering the breach and reporting it. Reports go to the personal data protection address published by the ministry. After a report the department may log it. It may assess whether your response actually meets the harm. It may direct you to notify the affected people, and offer guidance or support. The notice to individuals must state the type and nature of the breach, which of their data was hit, and recommendations for limiting the damage. Separately you must keep an internal breach file with causes, consequences and remedies, held for as long as the department requires. A breach is defined as unlawful access to personal data leading to its destruction, alteration, disclosure, access or unlawful use. Breaking the breach reporting duty carries a court fine of fifteen thousand to twenty thousand Omani rials, roughly thirty-nine thousand to fifty-two thousand United States dollars. A second, separate reporting duty may exist towards the Cyber Defence Centre, whose powers the law preserves. We found no published incident reporting rule for it.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal data breach reporting to the competent department within 72 hours
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - breach chapter, contents of the report and notice to individuals
mtcit.gov.om
“يجب على المتحكم إبلاغ الإدارة المختصة خلال مدة لا تتجاوز (72) اثنتين وسبعين ساعة من وقت علمه بالاختراق إذا كان من شأنه أن يؤدي إلى خطر يهدد حقوق أصحاب البيانات الشخصية”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things. One: you need a government permit before you touch health, genetic, biometric, ethnic, sex life, political or religious, or criminal record data. The ministry has forty-five days to answer, and silence counts as a no. Two: the fine for sending data abroad unlawfully runs from one hundred thousand to five hundred thousand Omani rials. That is about two hundred and sixty thousand to one and a third million United States dollars. It is a court fine, far above the two thousand rial administrative cap people quote. Three: the ministry can order you to hire an external auditor that it has licensed, and a copy of the audit report goes to the ministry. Four: there is no legitimate interest basis, so consent has to carry almost everything. It must be in writing, and again separately before any marketing message. Five: the law's exemption list is enormous. It includes carrying out a contract with the person, so both sides of an argument can point at it.
- What you have to do here:
- Independent audit · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
More detail on each. The Minister grants the permit for up to five years, and you must report changes within fifteen days or risk losing it. The heavy transfer fine sits in the law's criminal chapter. Alongside it sit fifteen thousand to twenty thousand rials for breaking the sensitive data, children, breach reporting or confidentiality duties. Then five thousand to ten thousand rials for other listed duties, and five hundred to two thousand rials at the bottom of the scale. A company can be fined five thousand to one hundred thousand rials, about thirteen thousand to two hundred and sixty thousand United States dollars. That applies where an offence was committed in its name by a chairman, board member, manager or other officer, with their consent, cover-up or gross negligence. It does not displace the personal liability of those individuals. A court may also confiscate the equipment used. On children, the guardian's clear consent is required, and no disclosure or sharing of a child's data is allowed without it. The law does not define the age at which someone stops being a child, so you have to assume the general Omani age of majority. On day-to-day work, expect three clocks. Forty-five days for answering individual rights requests. Thirty days for handing documents to the ministry when asked. And sixty days from appointing an external auditor to file the report. Finally, an internet service provider in Oman may not hand over subscriber data except on an order of the competent court. That catches groups who expect their Omani subsidiary to answer a parent company request.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - permit for sensitive data, children, penalties chapter
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - permit procedure, external auditor, marketing consent, children
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law - internet service provider confidentiality and court order gate
mtcit.gov.om
Link checked 18 August 2026
What's changing next
Nothing new is scheduled to hit private companies in the next twelve months that we could find. The recent movement has all been in cyber and government rules. A brand new technology crimes law took effect on 2 June 2026. A fresh cloud policy for government bodies landed on 28 June 2026. The bigger risk is not a bill. It is a power the minister already holds. The ministry can order transfers to any country or international organisation to stop. It can suspend or cancel a permit. It needs no consultation and no notice period.
Recent and current rules, most recent first. Cloud Computing First Circular 10/2026, dated 28 June 2026, updates the cloud-first policy for government digital projects. It requires cloud providers to hold approved certifications before contracting. It requires government bodies to classify data before storing or using it in a cloud. The Information Technology Crimes Law, issued by Royal Decree 61/2026, was published on 1 June 2026. It replaced the previous technology crimes law and took effect the day after publication. It allows the ministry to obtain electronic data from government and non-government bodies inside Oman and outside it. The ministry must coordinate with other authorities, and must have an order from the public prosecution or the competent court. A ministerial circular of 14 January 2025 set up national rules for data governance and management across government bodies. A new Electronic Transactions Law was issued by Royal Decree 39/2025 in April 2025. Some powers can be used without warning. The ministry can stop transfers to a named country or international organisation. It can suspend or cancel a permit. It can order an external audit by a ministry-licensed auditor. And it can rewrite the executive regulation by ministerial decision, with no new legislation.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud Computing First Circular 10/2026, dated 28 June 2026
mtcit.gov.om
“Mandating government entities to classify data before storing or processing it in cloud environments, in accordance with national data management standards.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026, published 1 June 2026
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyMinisterial Circular 113/2025 on the regulatory framework for national data governance and management, 14 January 2025
mtcit.gov.om
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Cloud and Hosting Services Standard · MTCIT Cloud and Hosting Services Standard version 1, effective 17 May 2018, read with Cloud Computing First Circular 10/2026 of 28 June 2026 · Government policy document
Anything hosted for an Omani government body must stay inside the country, backups included. This is the strictest location rule in Oman. It catches any cloud vendor or system integrator serving the public sector.
Enforced by Ministry of Transport, Communications and Information Technology
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryPrimary storage and backup or disaster recovery must all sit inside Oman.
- Hold a security certificateCloud providers must hold recognised security certifications and pass third party assessments before a government body contracts with them.
- Independent auditGovernment agencies may run their own vulnerability scans of the provider, and continuous monitoring and reporting to the ministry is required.
- Prove the data stays under local control — from 28 June 2026Since the 2026 circular, government bodies must classify data before it is stored or used in any cloud.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard - sensitive information storage and processing
mtcit.gov.om
“Government data and/or information must only be hosted/transacted/processed with in the geo boundaries of Sultanate of Oman. This includes the primary storage as well as the backup or disaster recovery arrangements.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard - ministry page, data sovereignty summary
mtcit.gov.om
“Data Sovereignty: All data must remain within Oman's borders, including backups.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud Computing First Circular 10/2026
mtcit.gov.om
Link checked 18 August 2026
Telecoms rules
Official name: قانون تنظيم الاتصالات (Telecommunications Regulation Law) · Royal Decree 30/2002 as amended, published 17 March 2002 · Act of parliament
Telecommunications and internet companies in Oman are not told where to store data, but they are told who may see it. Subscriber data cannot be handed over to anyone, including a foreign parent company, without an order from an Omani court.
Enforced by Telecommunications Regulatory Authority
How this country controls where data goes: Approval each time
What you have to do
- Extra vendor secrecy termsAn internet service provider must keep its services confidential and may not disclose any subscriber data except on an order of the competent court.
- Secure the dataThe telecommunications regulator is empowered to set the controls that protect subscriber data and guarantee its confidentiality and privacy.
What it costs if you get it wrong
- Criminal liabilityDisclosing the confidentiality of message content, sender or recipient data, or tampering with subscriber data. Imprisonment and fines, doubled on repeat.
- Loss of your licenceBreach of licence conditions set by the telecommunications regulator
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law, Royal Decree 30/2002 as amended - service provider confidentiality
mtcit.gov.om
“يلتزم موفر الخدمات على شبكة الإنترنت بسرية الخدمات التي يؤديها إلى المنتفعين وعدم العبث بها أو الكشف عنها أو عن أية بيانات عن المنتفع إلا بناء على أمر يصدر من المحكمة المختصة”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTelecommunications Regulatory Authority - legal framework library
tra.gov.om
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Health data rules
Official name: قانون حماية البيانات الشخصية (Personal Data Protection Law) · Royal Decree 6/2022, Official Gazette No. 1429 of 13 February 2022 · Act of parliament
Oman's general privacy law. Consent comes first. You need a government permit before you touch sensitive categories such as health or biometric data. Sending data abroad is allowed on conditions rather than banned. But the criminal fine for getting a transfer wrong is the heaviest penalty in the statute.
Enforced by Ministry of Transport, Communications and Information Technology
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed, Important public interest
What you have to do
- Get consentExplicit, written or electronic consent is the main basis. There is no legitimate interest route.
- Tell people what you doWritten notice before you start using the data. It must cover who decides how the data is used, who handles it for them, and the data protection officer's contact details. It must give the purpose and the source. It must fully describe what you do with the data, and who you disclose it to. And it must set out the person's rights.
- Register or notify — applies at: Genetic, biometric, health, ethnic origin, sex life, political or religious opinions, beliefs, criminal convictions or security measures dataYou need a ministry permit before you touch these categories.
- Let people see their data
- Let people correct their data
- Let people delete their dataYou can refuse where the data is needed for national preservation and documentation purposes.
- Let people take their data elsewhere
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Appoint a data protection officer
- Independent auditOnly where the ministry requires it; the auditor must be licensed by the ministry.
- Get a parent's consent for childrenGuardian consent is required, unless using the data is in the child's best interest. The law does not state an age.
- Put a transfer safeguard in place
- Extra vendor secrecy terms
What it costs if you get it wrong
- Criminal liability: OMR 500,000 — about $1 millionUnlawful transfer of personal data outside Oman; minimum OMR 100,000
- Criminal liability: OMR 20,000 — about $52 thousandProcessing sensitive data without a permit, breaching children's data rules, failing to report a breach, or breaching confidentiality; minimum OMR 15,000
- Criminal liability: OMR 100,000 — about $260 thousandCompany liability where the offence was committed in its name by an officer with consent, cover-up or gross negligence; minimum OMR 5,000
- Fixed maximum fine: OMR 2,000 — about $5 thousandAdministrative fine imposed by the ministry, per violation
- Order to stopTemporary or permanent suspension of processing, or an order halting transfers to a country or international organisation
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022, Official Gazette No. 1429
mtcit.gov.om
“ينشر هذا المرسوم في الجريدة الرسمية، ويعمل به بعد انقضاء سنة من تاريخ نشره”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law - ministry summary page
mtcit.gov.om
Link checked 18 August 2026
Breach reporting rules
Official name: اللائحة التنفيذية لقانون حماية البيانات الشخصية (Executive Regulation of the Personal Data Protection Law) · Ministerial Decision 34/2024, signed 28 January 2024, Official Gazette No. 1531 of 4 February 2024 · Directly binding regulation
The detailed rules under the privacy law. They create the permit system, the test for sending data abroad, the seventy-two hour breach clocks, the data protection officer duty and the complaint procedure. Organisations were given one year from February 2024 to comply. So the rules have applied in full since February 2025.
Enforced by Ministry of Transport, Communications and Information Technology
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What you have to do
- Put a transfer safeguard in placeFour things are needed before any transfer abroad. Explicit consent. No harm to national security or the higher interests of the state. Proof that the receiving party protects the data at least as well as Omani law does. And a written assessment that the ministry can demand.
- Register or notifyPermit application must list the places where personal data will be transferred or stored. Decision in 45 days, silence is a refusal, permit valid up to 5 years, changes reported within 15 days.
- Keep records of how you use dataYour record of what you do with personal data must include cross-border movements and every breach.
- Delete data after a periodThe keeping period must be specific, lawful and proportionate to the purpose.
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hoursRequired where the breach could cause serious harm or high risk to the person.
- Appoint a data protection officerName and contact details of the data protection officer must be published.
- Independent auditExternal auditor must be licensed by the ministry and independent; report to the ministry within 60 days of appointment.
- Let people see their dataRights requests answered free of charge within 45 days.
- Get a parent's consent for children
- Tell people what you doYour privacy policy must be displayed where the person can read it before you start using their data.
What it costs if you get it wrong
- Fixed maximum fine: OMR 2,000 — about $5 thousandAdministrative fine per violation of the regulation
- Order to stopWarning, suspension of the permit until the violation is cured, or cancellation of the permit
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024, Official Gazette No. 1531
mtcit.gov.om
“يجب على المخاطبين بأحكام اللائحة المرفقة توفيق أوضاعهم طبقا لأحكامها خلال مدة لا تزيد على عام من تاريخ العمل بها”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulations of the Personal Data Protection Law - ministry page
mtcit.gov.om
Link checked 18 August 2026
Data rules
Official name: قانون مكافحة جرائم تقنية المعلومات (Information Technology Crimes Law) · Royal Decree 61/2026, published 1 June 2026, replacing the earlier technology crimes law · Act of parliament
A new criminal law on technology offences that took effect on 2 June 2026. It reaches acts committed outside Oman that harm Omani interests or people. It also lets the ministry obtain electronic data from bodies inside and outside the country, on a prosecutor's or court order.
Enforced by Ministry of Transport, Communications and Information Technology
How this country controls where data goes: Approval each time
What you have to do
- Do not hand data to foreign authorities on demandData can be demanded from bodies inside and outside Oman, but only on an order from the public prosecution or the competent court.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityUnauthorised access to a system, and altering, copying, destroying, disclosing or blocking stored electronic data. Prison terms plus fines.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026, Official Gazette
mtcit.gov.om
“تسري أحكام هذا القانون على الجرائم المنصوص عليها فيه ولو ارتكبت كليا أو جزئيا خارج سلطنة عمان متى ما أضرت بمصالحها أو أشخاصها”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCybercrime Combat Law - ministry page confirming Royal Decree 61/2026 and publication on 1 June 2026
mtcit.gov.om
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: قانون ضريبة الدخل (Income Tax Law) · Income Tax Law, Royal Decree 28/2009 as amended · Act of parliament
The retention floor. Tax records and the documents behind them must be kept for at least ten years after the accounting period ends. That overrides any shorter deletion promise in a privacy notice.
Enforced by Tax Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 10 yearsRegisters, books of account and supporting documents, counted from the end of the accounting period. Books may be kept in a foreign currency only with authorisation; no rule was found requiring them to be kept inside Oman.
Sources
- Official sourceTax Authority of OmanIncome Tax Law, English version published by the Tax Authority
tms.taxoman.gov.om
“Every taxpayer shall preserve for at least ten years from the end of the accounting period for which the income is chargeable to tax, all registers, books of accounts and the documents proving their contents”
Link checked 18 August 2026
- Official sourceTax Authority of OmanTax Authority - income tax law and regulations library
tms.taxoman.gov.om
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether banks, insurers or investment firms face keeping data in the country or cloud approval rules
We could not confirm whether banks, insurers and investment firms have extra rules. The Central Bank of Oman site and the Financial Services Authority site were unreachable on 18 August 2026. Gulf central banks commonly impose outsourcing and cloud conditions. Assume rules may exist, and check directly with the regulator.
The exact article numbers behind the money penalties, in particular that the fine of one hundred thousand to five hundred thousand Omani rials attaches to unlawful transfer abroad
We could not confirm the exact wording against a certified text. Oman publishes the law only as a scanned Arabic gazette, in a legacy font that machines cannot read, so we read it by optical character recognition. The words and the amounts are clear. Arabic numerals inside brackets are the least reliable part. The order of the articles strongly supports our reading, but confirm it against a certified translation before you rely on it.
Whether the law reaches a company with no presence in Oman
We could not confirm whether the law reaches companies with no office in Oman. The scope wording is a single line about personal data that is used or stored. It says nothing about companies abroad. We found no official guidance, decision or frequently asked questions page on the point.
The age at which a person stops being a child for consent purposes
We could not confirm the age at which someone stops being a child. Neither the law nor its executive regulation states an age. People usually assume the general Omani age of majority, but we could not confirm that from a government source.
Whether a separate incident report must go to the Cyber Defence Centre, and on what deadline
We could not confirm whether you must also report incidents to the Cyber Defence Centre. Both the privacy law and the 2026 technology crimes law expressly preserve the centre's powers. We found no published reporting rule, form or contact channel for it.
Any sector rule for health records, education, insurance broking, gambling or mapping and survey data
We found no such rule on official Omani sources on 18 August 2026. Several relevant sites were unreachable, including the Ministry of Justice and Legal Affairs, the Ministry of Commerce and the National Survey Authority. So this is an unchecked gap rather than a confirmed absence. Gambling is in any event not lawfully offered in Oman.
Whether the ministry has ever issued a fine, a public decision, or the periodic activity reports the law requires it to publish
We found no decision or report on the ministry's own site. That does not prove nothing has happened. Enforcement in Oman is often handled privately.
Whether the telecommunications regulator imposes storage or localisation conditions through individual operator licences
We could not read the regulator's document library. It is served through a search interface we could not enumerate, so we did not read the forty-two licence documents it lists individually.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.