Law note · Oman

Personal Data Protection Law, cross-border transfer

cite Royal Decree No. 6/2022, Art. 23 stage IN FORCE in force since 2023-02-13 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Oman outside the country must follow the controls and procedures the Executive Regulations set, whose substantive text was not confirmed at primary source in this document; a violation of this provision carries by far the highest penalty tier in Oman's Personal Data Protection Law.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

Art. 23 permits a Controller to transfer personal data outside Oman "in accordance with the controls and procedures determined by the regulation," without prejudice to the Cyber Defence Centre's own competences. The Royal Decree itself states no adequacy test, no whitelist, and no enumerated conditions of its own; the entire substantive transfer regime is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source in this pass.

What the Decree does confirm is that a violation of Art. 23 carries by far the highest penalty tier in the whole Law (100,000 to 500,000 Rial Omani), a strong signal of seriousness even though the substantive rule is deferred.

This document does not code a jurisdiction-level cross_border_restriction finding from this instrument alone; the moderate value carried at jurisdiction level rests on the carried seed and the Bahrain and UAE comparators in this batch, not on Oman's own Executive Regulations text.

← Back to the example  ·  Lint your app →