Law note · Oman

Personal Data Protection Law, biometric and sensitive data prior permit

cite Royal Decree No. 6/2022, Arts. 1, 5 stage IN FORCE in force since 2023-02-13 kind Biometric privacy binds public and private bodies reviewed 2026-08-29

What it requires

  • An app must obtain a Ministry permit before processing biometric data, including a faceprint or voiceprint, about an individual in Oman; the Data Subject's consent alone is not a sufficient basis, and the permit's own conditions sit in Executive Regulations not yet confirmed at primary source in this document.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models
Excludes recording-derived identifiers
No

What we found

Art. 1 defines biometric data as "personal data resulting from specific technical processing relating to the physical, psychological, or behavioural characteristics such as the facial image or the genetic fingerprint data," naming a facial image as a worked example.

Art. 5 prohibits processing genetic data, biometric data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions, or security-measures data, except after obtaining a Ministry permit under controls and procedures the Executive Regulations set out (not read in this pass).

This is a prior-permit model, structurally the same heightened gate found in Bahrain: a service cannot rely on the Data Subject's consent alone to process biometric data in Oman. No modality-specific voice provision exists beyond the general definition, which would still reach a voiceprint as a behavioural characteristic enabling identification. No retention-period ceiling or destruction duty specific to biometric data was found in the Royal Decree itself.

← Back to the example  ·  Lint your app →