Oman
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Oman has a full privacy law, policed by a government ministry rather than by a separate privacy watchdog. Personal data may leave the country, but only with the person's clear permission, only if the destination protects the data at least as well as Oman does, and only after you have written a risk assessment. Data held for an Omani government body is different: it must stay inside Oman.
Data governance in Oman
The eight things that decide how you handle data about people in Oman. Same eight on every country page, so you can compare.
Who has to follow these rules
The law does not say. It states only that it applies to personal data that is processed. There is no sentence about companies based abroad, no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. If you have people, a branch or servers in Oman you are plainly covered. If you sell to Omanis purely from abroad, the position is genuinely unsettled, and no official guidance answering the question was found.
The Personal Data Protection Law issued by Royal Decree 6/2022 opens with a one-line scope provision covering personal data that is processed, then sets out a long list of processing that falls outside the law altogether: protecting national security or the public interest, state bodies carrying out their legal functions, complying with a legal obligation or a court ruling, protecting the state's economic and financial interests, protecting a vital interest of the person, detecting or preventing a crime on a written official request from investigators, performing a contract to which the person is a party, purely personal or family activity, historical, statistical, scientific, literary or economic research by authorised bodies where the output is anonymised, and data already lawfully public. The contract exemption is drafted very widely and no official interpretation of it was found. By contrast, the new Information Technology Crimes Law issued by Royal Decree 61/2026 is expressly extraterritorial: it reaches offences committed wholly or partly outside Oman where they harm Oman's interests or people, or where the criminal result happened or was meant to happen in Oman. Anyone relying on the argument that Omani law stops at the border should read that provision first.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022, Official Gazette No. 1429 - scope and exemptions
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law - ministry page, published 13 February 2022
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026 - extraterritorial reach
mtcit.gov.om
Link checked 18 August 2026
Where the data is allowed to live
Yes, data can leave Oman, and no country is banned. But four things must be true before it goes. The person must have given clear, specific permission. The transfer must not damage national security or the higher interests of the state. The organisation receiving the data must protect it at least as well as Oman's own rules do. And you must have written a risk assessment of the transfer, which the ministry can demand a copy of at any time.
The general rule sits in the Personal Data Protection Law and is filled out by the Executive Regulation issued as Ministerial Decision 34/2024. Consent is not needed in two narrow cases: where the transfer carries out an international treaty obligation Oman has signed, and where the data has been stripped of identity so completely that nobody can link it back to the person. The written assessment must cover the nature, volume and sensitivity of the data, the purpose and scope of processing and who else will see it, how long processing lasts and whether it is one-off or routine, the stages of the journey including every country the data passes through and its final destination, and the effects and risks for the person. Sector picture, in order of how hard the wall is. Government: hardest. The ministry's Cloud and Hosting Services Standard tells government agencies that government data and information may only be hosted, transacted or processed inside Oman's geographical boundaries, primary storage and backup or disaster recovery included, and a June 2026 circular now also requires government bodies to classify data before it is put into any cloud. Sensitive personal data: health, genetic, biometric, ethnic origin, sex life, political or religious opinions, beliefs and criminal convictions may not be processed at all without a permit from the ministry, and the permit application must list the places where the data will be stored or transferred, so storage location becomes a licensed matter rather than a private choice. Telecommunications: no storage rule was found, but an internet service provider may not disclose subscriber data to anyone except on an order from the competent court, which blocks routine group-wide sharing with a foreign parent. Banking, insurance and securities: not verified, see the unconfirmed list. Health, education, gambling and mapping: no separate storage rule found on official sources, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024, Official Gazette No. 1531 - chapter on transfer outside the borders
mtcit.gov.om
“يلتزم المتحكم قبل نقل أو تحويل البيانات الشخصية إلى خارج حدود سلطنة عمان بالحصول على الموافقة الصريحة لصاحب البيانات الشخصية، وألا يترتب على نقل البيانات أو تحويلها مساس بالأمن الوطني أو المصالح العليا للدولة”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard, section on sensitive information storage and processing
mtcit.gov.om
“Government data and/or information must only be hosted/transacted/processed with in the geo boundaries of Sultanate of Oman. This includes the primary storage as well as the backup or disaster recovery arrangements.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law, Royal Decree 30/2002 as amended - confidentiality of subscriber data
mtcit.gov.om
Link checked 18 August 2026
Sending data out of the country
There is no list of approved countries and no list of banned ones, and no government form to file for an ordinary transfer. Oman puts the work on you: get clear permission from the person, satisfy yourself that the recipient protects the data as well as Oman does, and keep a written assessment on file. The exception is sensitive data such as health or biometric records, which you cannot process at all until the ministry grants you a permit, and the permit application has to name where the data will be stored or sent.
The permit route works like this. You apply to the ministry with the name and contact details of your data protection officer, the purpose of processing, a description and classification of the data, the processor you will use, any third party you will disclose to, the places where the data will be transferred or stored, and your data management and protection systems, and you attach your privacy policy and your plan for handling a breach. The competent department has forty-five days to decide from the date your file is complete; silence for forty-five days counts as a refusal. A refusal must give reasons and can be appealed to the Minister within sixty days, and silence on that appeal for thirty days is again a refusal. The permit is issued by the Minister for up to five years against payment of a fee, and is renewable. You must report any change to the permit details within fifteen days. The permit can be cancelled if you break the law or the regulation, if you miss that fifteen-day deadline, or if it turns out the permit was obtained by fraud or false information. Note also the reverse power: the ministry can order the transfer of personal data to a named country or international organisation to stop.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024 - permit procedure and transfer assessment
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulations of the Personal Data Protection Law - ministry page, issued 4 February 2024
mtcit.gov.om
“The Executive Regulations of the Personal Data Protection Law were issued pursuant to Ministerial Decision No. 34/2024. The regulations provide detailed provisions for several articles of the Personal Data Protection Law, most importantly: the procedures for obtaining a permit to process personal data as outlined in Article (5) of the law”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - ministry powers including halting transfers abroad
mtcit.gov.om
Link checked 18 August 2026
The regulator, and whether it actually acts
There is no separate privacy watchdog. The regulator is the Ministry of Transport, Communications and Information Technology, working through an in-house personal data protection department. It exists and it is doing things: it issued the detailed rules in 2024, it publishes an address for breach reports and complaints, and it put out a compliance self-check tool for companies in 2025. What we could not find is a single published decision, fine or enforcement report, even though the law tells the ministry to publish reports on its work. So the machinery is switched on, but its teeth have not been seen in public.
The law names the ministry as the body responsible for applying it, expressly without prejudice to the powers of the Cyber Defence Centre, which was created by Royal Decree 64/2020. The regulation defines the competent department as the ministry's own personal data protection administration. Officials designated by decision can be given the status of judicial enforcement officers, which is what allows evidence gathering rather than mere correspondence. The ministry can warn an organisation, order data corrected or erased, suspend processing temporarily or permanently, halt transfers to a country or international organisation, suspend or cancel a permit, and impose administrative fines of up to two thousand Omani rials, roughly five thousand two hundred United States dollars, per violation. Larger money penalties are criminal court fines under the law itself, not administrative ones. Complaints run to fixed clocks: a complaint must be brought within thirty days of the complainant learning of the violation, the department passes it to the organisation within seven days, the organisation has fourteen days to answer, and the department then has sixty days to decide, with silence counting as a rejection. The Cyber Defence Centre is a separate matter: its powers are expressly preserved by both the privacy law and the 2026 technology crimes law, but no public website, published decision or contact channel for it was found, so its practical role is unknown rather than absent. The telecommunications regulator and the tax authority are visibly operational and publish current material.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection reporting channels - violation reports and breach reports to the ministry
mtcit.gov.om
“regarding the implementation of the controller's obligation to inform the competent department at the Ministry of any breach of personal data within a period not exceeding 72 hours of his knowledge of the breach”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologySelf-assessment tool for controllers and processors, 2025
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - ministry duties, enforcement measures and judicial officer status
mtcit.gov.om
Link checked 18 August 2026
How long you must keep it — and when to delete it
Oman sets a firm floor and a soft ceiling. The floor: tax records, books and the documents behind them must be kept for at least ten years after the accounting period ends. The ceiling: there is no fixed maximum, but you must decide a retention period for every purpose, write down why, keep it proportionate, and delete when a person asks unless you have a legal reason to refuse. Where the two collide, the keeping duty wins, because complying with a legal obligation is one of the situations the privacy law does not cover.
The privacy regulation says the reason for keeping processing records must be specific and lawful, the period must match the purpose of processing, and the records must be technically protected while held. Records of processing activities must be kept continuously and handed to the competent department on request, and they must include the categories of data, who may access it, processing periods and limits, deletion and correction methods, who the data is disclosed to and why, details of anyone the data is transferred to, anything about movement of data across the border, the security measures in place, and every breach with its circumstances, effects and the remedy applied. Breach records must be kept for whatever period the competent department sets. On the deletion side, a person may demand erasure where the purpose has ended, where they have withdrawn consent, or where processing broke the rules, and the organisation may refuse only to comply with a law, a court ruling or judgment, or where there is a live dispute with that person. The law also carves out data needed for national preservation and documentation purposes from the erasure right. Requests must be answered within forty-five days.
Sources
- Official sourceTax Authority of OmanIncome Tax Law, English version - ten year record keeping duty
tms.taxoman.gov.om
“Every taxpayer shall preserve for at least ten years from the end of the accounting period for which the income is chargeable to tax, all registers, books of accounts and the documents proving their contents”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - retention of processing documents, record of processing activities, erasure
mtcit.gov.om
Link checked 18 August 2026
If something goes wrong
Two clocks, both seventy-two hours, and they start at different moments for different audiences. Tell the ministry's data protection department within seventy-two hours of learning about a breach if it could put people's rights at risk. Tell the affected people themselves within seventy-two hours of learning about it if the breach could cause them serious harm or high risk. The ministry can also order you to notify people when you had decided not to. Failing to report is a criminal offence, not just a paperwork slip.
The report to the ministry must describe the nature of the data involved and the consequences, give contact details for follow-up, describe the likely effects, set out the corrective, technical and organisational steps you will take including anything proposed to soften the impact, and state what you already did between discovering the breach and reporting it. Reports go to the personal data protection address published by the ministry. After a report the department may log it, assess whether your response actually meets the harm, direct you to notify the affected people, and offer guidance or support. The notice to individuals must state the type and nature of the breach, which of their data was hit, and recommendations for limiting the damage. Separately you must keep an internal breach file with causes, consequences and remedies, held for as long as the department requires. A breach is defined as unlawful access to personal data leading to its destruction, alteration, disclosure, access or unlawful processing. Breaking the breach reporting duty carries a court fine of fifteen thousand to twenty thousand Omani rials, roughly thirty-nine thousand to fifty-two thousand United States dollars. A second, separate reporting duty may exist towards the Cyber Defence Centre, whose powers the law preserves, but no published incident reporting rule for it was found.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal data breach reporting to the competent department within 72 hours
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - breach chapter, contents of the report and notice to individuals
mtcit.gov.om
“يجب على المتحكم إبلاغ الإدارة المختصة خلال مدة لا تتجاوز (72) اثنتين وسبعين ساعة من وقت علمه بالاختراق إذا كان من شأنه أن يؤدي إلى خطر يهدد حقوق أصحاب البيانات الشخصية”
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: you need a government permit before you touch health, genetic, biometric, ethnic, sex life, political or religious, or criminal record data, and the ministry has forty-five days to answer, with silence counting as a no. Two: the fine for sending data abroad unlawfully runs from one hundred thousand to five hundred thousand Omani rials, about two hundred and sixty thousand to one and a third million United States dollars, which is a court fine, far above the two thousand rial administrative cap people quote. Three: the ministry can order you to hire an external auditor that it has licensed, and a copy of the audit report goes to the ministry. Four: there is no legitimate interest basis, so consent has to carry almost everything, in writing, and again separately before any marketing message. Five: the law's exemption list is enormous and includes performing a contract with the person, so both sides of an argument can point at it.
More detail on each. The permit is granted by the Minister for up to five years and you must report changes within fifteen days or risk losing it. The heavy transfer fine sits in the law's criminal chapter, alongside fifteen thousand to twenty thousand rials for breaking the sensitive data, children, breach reporting or confidentiality duties, five thousand to ten thousand rials for other listed duties, and five hundred to two thousand rials at the bottom of the scale. A company can be fined five thousand to one hundred thousand rials, about thirteen thousand to two hundred and sixty thousand United States dollars, where an offence was committed in its name by a chairman, board member, manager or other officer with their consent, cover-up or gross negligence, and this does not displace the personal liability of the individuals. A court may also confiscate the equipment used. On children, the guardian's clear consent is required and no disclosure or sharing of a child's data is allowed without it, but the law does not define the age at which someone stops being a child, so the general Omani age of majority has to be assumed. On operations, expect a forty-five day clock for answering individual rights requests, a thirty day clock for handing documents to the ministry when asked, and sixty days from appointing an external auditor to file the report. Finally, an internet service provider in Oman may not hand over subscriber data except on an order of the competent court, which catches groups that expect their Omani subsidiary to answer a parent company request.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022 - permit for sensitive data, children, penalties chapter
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law - permit procedure, external auditor, marketing consent, children
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law - internet service provider confidentiality and court order gate
mtcit.gov.om
Link checked 18 August 2026
What's changing next
Nothing new is scheduled to hit private companies in the next twelve months that we could find. The recent movement has all been in cyber and government rules: a brand new technology crimes law took effect on 2 June 2026, and a fresh cloud policy for government bodies landed on 28 June 2026. The bigger risk is not a bill but a switch already in the minister's hand: the ministry can order transfers to any country or international organisation to stop, and can suspend or cancel a processing permit, with no consultation and no notice period.
Recent and current instruments, most recent first. Cloud Computing First Circular 10/2026, dated 28 June 2026, updates the cloud-first policy for government digital projects, requires cloud providers to hold approved certifications before contracting, and requires government bodies to classify data before storing or processing it in a cloud. The Information Technology Crimes Law issued by Royal Decree 61/2026 was published on 1 June 2026, replaced the previous technology crimes law, and took effect the day after publication; it allows the ministry, coordinating with other authorities and on an order from the public prosecution or the competent court, to obtain electronic data from government and non-government bodies inside Oman and outside it. A ministerial circular of 14 January 2025 put in place a regulatory framework for national data governance and management across government bodies. A new Electronic Transactions Law was issued by Royal Decree 39/2025 in April 2025. Dormant switches to watch, each usable without warning: the power to stop transfers to a named country or international organisation, the power to suspend or cancel a processing permit, the power to order an external audit by a ministry-licensed auditor, and the ability to rewrite the executive regulation by ministerial decision without new legislation.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud Computing First Circular 10/2026, dated 28 June 2026
mtcit.gov.om
“Mandating government entities to classify data before storing or processing it in cloud environments, in accordance with national data management standards.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026, published 1 June 2026
mtcit.gov.om
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyMinisterial Circular 113/2025 on the regulatory framework for national data governance and management, 14 January 2025
mtcit.gov.om
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and Hosting Services Standard
Government policy document · MTCIT Cloud and Hosting Services Standard version 1, effective 17 May 2018, read with Cloud Computing First Circular 10/2026 of 28 June 2026
Anything hosted for an Omani government body must stay inside the country, backups included. This is the hardest data residency wall in Oman and it catches any cloud vendor or system integrator serving the public sector.
Enforced by Ministry of Transport, Communications and Information Technology
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryPrimary storage and backup or disaster recovery must all sit inside Oman.
- Hold a security certificateCloud providers must hold recognised security certifications and pass third party assessments before a government body contracts with them.
- Independent auditGovernment agencies may run their own vulnerability scans of the provider, and continuous monitoring and reporting to the ministry is required.
- Prove the data stays under local control — from 28 June 2026Since the 2026 circular, government bodies must classify data before it is stored or processed in any cloud.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard - sensitive information storage and processing
mtcit.gov.om
“Government data and/or information must only be hosted/transacted/processed with in the geo boundaries of Sultanate of Oman. This includes the primary storage as well as the backup or disaster recovery arrangements.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud and Hosting Services Standard - ministry page, data sovereignty summary
mtcit.gov.om
“Data Sovereignty: All data must remain within Oman's borders, including backups.”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCloud Computing First Circular 10/2026
mtcit.gov.om
Link checked 18 August 2026
قانون تنظيم الاتصالات (Telecommunications Regulation Law)
Act of parliament · Royal Decree 30/2002 as amended, published 17 March 2002
Telecommunications and internet companies in Oman are not told where to store data, but they are told who may see it. Subscriber data cannot be handed over to anyone, including a foreign parent company, without an order from an Omani court.
Enforced by Telecommunications Regulatory Authority
Transfer model: Approval each time
What it makes you do
- Extra vendor secrecy termsAn internet service provider must keep its services confidential and may not disclose any subscriber data except on an order of the competent court.
- Secure the dataThe telecommunications regulator is empowered to set the controls that protect subscriber data and guarantee its confidentiality and privacy.
What it costs if you get it wrong
- Criminal liabilityDisclosing the confidentiality of message content, sender or recipient data, or tampering with subscriber data. Imprisonment and fines, doubled on repeat.
- Loss of your licenceBreach of licence conditions set by the telecommunications regulator
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyTelecommunications Regulation Law, Royal Decree 30/2002 as amended - service provider confidentiality
mtcit.gov.om
“يلتزم موفر الخدمات على شبكة الإنترنت بسرية الخدمات التي يؤديها إلى المنتفعين وعدم العبث بها أو الكشف عنها أو عن أية بيانات عن المنتفع إلا بناء على أمر يصدر من المحكمة المختصة”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTelecommunications Regulatory Authority - legal framework library
tra.gov.om
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
قانون حماية البيانات الشخصية (Personal Data Protection Law)
Act of parliament · Royal Decree 6/2022, Official Gazette No. 1429 of 13 February 2022
Oman's general privacy law. Consent-first, with a government permit needed before touching sensitive categories such as health or biometric data. Transfers abroad are allowed on conditions rather than banned, but the criminal fine for getting a transfer wrong is the heaviest penalty in the statute.
Enforced by Ministry of Transport, Communications and Information Technology
Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed, Important public interest
What it makes you do
- Get consentExplicit, written or electronic consent is the main basis. There is no legitimate interest route.
- Tell people what you doWritten notice before processing starts, covering controller and processor details, data protection officer contact, purpose and source, a full description of the processing and disclosure levels, and the person's rights.
- Register or notify — applies at: Genetic, biometric, health, ethnic origin, sex life, political or religious opinions, beliefs, criminal convictions or security measures dataMinistry permit required before any processing of these categories.
- Let people see their data
- Let people correct their data
- Let people delete their dataRefusable where processing is needed for national preservation and documentation purposes.
- Let people take their data elsewhere
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Appoint a data protection officer
- Independent auditOnly where the ministry requires it; the auditor must be licensed by the ministry.
- Get a parent's consent for childrenGuardian consent required unless processing is in the child's best interest. The law does not state an age.
- Put a transfer safeguard in place
- Extra vendor secrecy terms
What it costs if you get it wrong
- Criminal liability: OMR 500,000 — about $1 millionUnlawful transfer of personal data outside Oman; minimum OMR 100,000
- Criminal liability: OMR 20,000 — about $52 thousandProcessing sensitive data without a permit, breaching children's data rules, failing to report a breach, or breaching confidentiality; minimum OMR 15,000
- Criminal liability: OMR 100,000 — about $260 thousandCompany liability where the offence was committed in its name by an officer with consent, cover-up or gross negligence; minimum OMR 5,000
- Fixed maximum fine: OMR 2,000 — about $5 thousandAdministrative fine imposed by the ministry, per violation
- Order to stopTemporary or permanent suspension of processing, or an order halting transfers to a country or international organisation
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law, Royal Decree 6/2022, Official Gazette No. 1429
mtcit.gov.om
“ينشر هذا المرسوم في الجريدة الرسمية، ويعمل به بعد انقضاء سنة من تاريخ نشره”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyPersonal Data Protection Law - ministry summary page
mtcit.gov.om
Link checked 18 August 2026
اللائحة التنفيذية لقانون حماية البيانات الشخصية (Executive Regulation of the Personal Data Protection Law)
Directly binding regulation · Ministerial Decision 34/2024, signed 28 January 2024, Official Gazette No. 1531 of 4 February 2024
The detailed rules under the privacy law. It creates the permit system, the cross-border transfer test, the seventy-two hour breach clocks, the data protection officer duty and the complaint procedure. Organisations were given one year from February 2024 to bring themselves into line, so it has bitten fully since February 2025.
Enforced by Ministry of Transport, Communications and Information Technology
Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeBefore any transfer abroad: explicit consent, no harm to national security or the higher interests of the state, proof that the receiving party protects the data at least as well as Omani law, and a written assessment the ministry can demand.
- Register or notifyPermit application must list the places where personal data will be transferred or stored. Decision in 45 days, silence is a refusal, permit valid up to 5 years, changes reported within 15 days.
- Keep records of processingRecord of processing activities must include cross-border data movements and every breach.
- Delete data after a periodRetention period must be specific, lawful and proportionate to the purpose.
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hoursRequired where the breach could cause serious harm or high risk to the person.
- Appoint a data protection officerName and contact details of the data protection officer must be published.
- Independent auditExternal auditor must be licensed by the ministry and independent; report to the ministry within 60 days of appointment.
- Let people see their dataRights requests answered free of charge within 45 days.
- Get a parent's consent for children
- Tell people what you doPrivacy policy must be displayed where the person can read it before processing.
What it costs if you get it wrong
- Fixed maximum fine: OMR 2,000 — about $5 thousandAdministrative fine per violation of the regulation
- Order to stopWarning, suspension of the permit until the violation is cured, or cancellation of the permit
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulation of the Personal Data Protection Law, Ministerial Decision 34/2024, Official Gazette No. 1531
mtcit.gov.om
“يجب على المخاطبين بأحكام اللائحة المرفقة توفيق أوضاعهم طبقا لأحكامها خلال مدة لا تزيد على عام من تاريخ العمل بها”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyExecutive Regulations of the Personal Data Protection Law - ministry page
mtcit.gov.om
Link checked 18 August 2026
قانون مكافحة جرائم تقنية المعلومات (Information Technology Crimes Law)
Act of parliament · Royal Decree 61/2026, published 1 June 2026, replacing the earlier technology crimes law
A new criminal law on technology offences that took effect on 2 June 2026. It reaches acts committed outside Oman that harm Omani interests or people, and it lets the ministry obtain electronic data from bodies inside and outside the country on a prosecutor's or court order.
Enforced by Ministry of Transport, Communications and Information Technology
Transfer model: Approval each time
What it makes you do
- Do not hand data to foreign authorities on demandData can be demanded from bodies inside and outside Oman, but only on an order from the public prosecution or the competent court.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityUnauthorised access to a system, and altering, copying, destroying, disclosing or blocking stored electronic data. Prison terms plus fines.
Sources
- Official sourceMinistry of Transport, Communications and Information TechnologyInformation Technology Crimes Law, Royal Decree 61/2026, Official Gazette
mtcit.gov.om
“تسري أحكام هذا القانون على الجرائم المنصوص عليها فيه ولو ارتكبت كليا أو جزئيا خارج سلطنة عمان متى ما أضرت بمصالحها أو أشخاصها”
Link checked 18 August 2026
- Official sourceMinistry of Transport, Communications and Information TechnologyCybercrime Combat Law - ministry page confirming Royal Decree 61/2026 and publication on 1 June 2026
mtcit.gov.om
Link checked 18 August 2026
قانون ضريبة الدخل (Income Tax Law)
Act of parliament · Income Tax Law, Royal Decree 28/2009 as amended
The retention floor. Tax records and the documents behind them must be kept for at least ten years after the accounting period ends, which overrides any shorter deletion promise in a privacy notice.
Enforced by Tax Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 10 yearsRegisters, books of account and supporting documents, counted from the end of the accounting period. Books may be kept in a foreign currency only with authorisation; no rule was found requiring them to be kept inside Oman.
Sources
- Official sourceTax Authority of OmanIncome Tax Law, English version published by the Tax Authority
tms.taxoman.gov.om
“Every taxpayer shall preserve for at least ten years from the end of the accounting period for which the income is chargeable to tax, all registers, books of accounts and the documents proving their contents”
Link checked 18 August 2026
- Official sourceTax Authority of OmanTax Authority - income tax law and regulations library
tms.taxoman.gov.om
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether banks, insurers or investment firms face data localisation or cloud approval rules
The Central Bank of Oman site and the Financial Services Authority site were unreachable throughout this research on 18 August 2026, so nothing could be verified from a government source. Gulf central banks commonly impose outsourcing and cloud conditions, so assume rules may exist until checked directly with the regulator.
The exact article numbers behind the money penalties, in particular that the fine of one hundred thousand to five hundred thousand Omani rials attaches to unlawful transfer abroad
Oman publishes the law only as a scanned Arabic gazette with a legacy font that machines cannot read, so the text had to be read by optical character recognition. The words and the amounts are clear; Arabic numerals inside brackets are the least reliable part. The article sequence strongly supports the reading, but it should be confirmed against a certified translation before relying on it.
Whether the law reaches a company with no presence in Oman
The scope provision is a single line about personal data that is processed. It says nothing about companies abroad, and no official guidance, decision or frequently asked questions page addressing the point was found.
The age at which a person stops being a child for consent purposes
Neither the law nor its executive regulation states an age. The general Omani age of majority is the usual assumption, but this was not confirmed from a government source.
Whether a separate incident report must go to the Cyber Defence Centre, and on what deadline
Both the privacy law and the 2026 technology crimes law expressly preserve the centre's powers, but no published reporting rule, form or contact channel for it could be located.
Any sector rule for health records, education, insurance broking, gambling or mapping and survey data
No such rule was found on official Omani sources on 18 August 2026. Several relevant sites, including the Ministry of Justice and Legal Affairs, the Ministry of Commerce and the National Survey Authority, were unreachable, so this is an unchecked gap rather than a confirmed absence. Gambling is in any event not lawfully offered in Oman.
Whether the ministry has ever issued a fine, a public decision, or the periodic activity reports the law requires it to publish
No such decision or report was found on the ministry's own site. Absence of publication is not proof that nothing has happened; enforcement in Oman is often handled privately.
Whether the telecommunications regulator imposes storage or localisation conditions through individual operator licences
The regulator's document library is served through a search interface that could not be enumerated, so the forty-two licence documents it lists were not read individually.
Sixty-day cadence. Oman is not legislating constantly, but the minister holds switches that can flip without consultation, including an order halting transfers to a named country and suspension of processing permits, and the ministry issued three significant instruments between January 2025 and June 2026. The unverified financial sector is also a standing reason to re-check.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Oman versus
Compare