Cybercrime Combat Law, unauthorized access to a website or information system
Royal Decree No. 61/2026, Art. 5
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not access, or remain on, a website, information system, or information-technology means in Oman without right, in excess of authorized access, or after becoming aware the access is unauthorized; a spurious raise costs a developer one read, so this is flagged even though the Law's text does not on its face require defeating a technical security measure to reach a public, unauthenticated page.
- Where such access alters, discloses, copies, or destroys data, or the data reached is personal data, the penalty escalates in two further tiers; treat any automated access that could plausibly change or expose data on the target system as carrying the higher exposure.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 5 sets three escalating tiers: imprisonment of one to six months and a fine of 100 to 1,000 Omani Rial for the base unauthorized-access offense; imprisonment of six months to one year and a fine of 1,000 to 3,000 Omani Rial where the access results in altering, disclosing, copying, destroying, or blocking data, harming users, or destroying the site; and imprisonment of one to three years and a fine of 2,000 to 5,000 Omani Rial where the data reached in that second tier is personal data.
Penalty structure
Three escalating tiers under Art. 5: 100-1,000 OMR (base unauthorized access, also imprisonment of one to six months); 1,000-3,000 OMR (access resulting in alteration, disclosure, copying, destruction, or blocking of data, or harm to users or the site, also imprisonment of six months to one year); 2,000-5,000 OMR (same aggravated outcome where the data is personal data, also imprisonment of one to three years). 5,000 OMR is the highest tier's cap.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- OMR
- Fixed cap
- 5,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 5 (Chapter Two, Encroachment on Data or Electronic Information and Information Systems) punishes whoever intentionally, without right, enters a website, an information system, or an information-technology means, or exceeds authorized access to it, or continues access once aware it is unauthorized, with imprisonment of one to six months and a fine of 100 to 1,000 Omani Rial, or either penalty.
Where that access results in the deletion, alteration, addition, modification, distortion, damage, copying, destruction, blocking, encryption, disclosure, or republication of data or electronic information, or in destroying the website, harming its users, or occupying its domain name or address, the penalty rises to imprisonment of six months to one year and a fine of 1,000 to 3,000 Omani Rial, or either penalty.
Where the data or electronic information reached under that second paragraph is personal data, the penalty rises again to imprisonment of one to three years and a fine of 2,000 to 5,000 Omani Rial, or either penalty. A guardian, custodian, curator, or caregiver who acted to protect the interest of a person lacking or having diminished legal capacity is exempted from punishment.
The Decree's own text states it takes effect the day after its Official Gazette publication and was issued on 15 Dhul Hijjah 1447H (1 June 2026), repealing the prior cybercrime law issued by Royal Decree No. 12/2011, but the Gazette's own publication date is not stated in the text read at primary source, so the specific commencement day is not confirmed here.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Law Combating Information Technology Crimes text
Ministry of Justice and Legal Affairs (mjla.gov.om) legislation library