Law note · Oman
Personal Data Protection Law, biometric and sensitive data prior permit
What it requires
- An app must obtain a Ministry permit before processing biometric data, including a faceprint or voiceprint, about an individual in Oman; the Data Subject's consent alone is not a sufficient basis, and the permit's own conditions sit in Executive Regulations not yet confirmed at primary source in this document.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_models
- Excludes recording-derived identifiers
- No
What we found
Art. 1 defines biometric data as "personal data resulting from specific technical processing relating to the physical, psychological, or behavioural characteristics such as the facial image or the genetic fingerprint data," naming a facial image as a worked example.
Art. 5 prohibits processing genetic data, biometric data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions, or security-measures data, except after obtaining a Ministry permit under controls and procedures the Executive Regulations set out (not read in this pass).
This is a prior-permit model, structurally the same heightened gate found in Bahrain: a service cannot rely on the Data Subject's consent alone to process biometric data in Oman. No modality-specific voice provision exists beyond the general definition, which would still reach a voiceprint as a behavioural characteristic enabling identification. No retention-period ceiling or destruction duty specific to biometric data was found in the Royal Decree itself.