Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Art. 1 defines biometric data as "personal data resulting from specific technical processing relating to the physical, psychological, or behavioural characteristics such as the facial image or the genetic fingerprint data," naming a facial image as a worked example.
Art. 5 prohibits processing genetic data, biometric data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions, or security-measures data, except after obtaining a Ministry permit under controls and procedures the Executive Regulations set out (not read in this pass).
This is a prior-permit model, structurally the same heightened gate found in Bahrain: a service cannot rely on the Data Subject's consent alone to process biometric data in Oman. No modality-specific voice provision exists beyond the general definition, which would still reach a voiceprint as a behavioural characteristic enabling identification. No retention-period ceiling or destruction duty specific to biometric data was found in the Royal Decree itself.
Breach notification
What it requires →
The Royal Decree requires the Controller, in the event of a personal data breach leading to destruction, alteration, disclosure, access, or illegal processing, to notify the Ministry and the Data Subject of the breach, in accordance with the controls and procedures the Executive Regulations set.
As with cross-border transfer, the duty exists in the Decree itself but its timeline, not stated as a fixed number of hours or days in the primary text read, is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source in this pass.
Comprehensive regime
What it requires →
Art. 3 excludes a list of processing activities entirely from the Law's scope: national security and public interest, state administrative functions, legal-obligation compliance, state economic and financial interest protection, vital-interest protection, crime detection or prevention on formal written request, contract performance, personal or family-sphere processing, de-identified research or statistics, and publicly available data (Art. 3(j), see the jurisdiction summary).
Art. 4 sets a general coverage default for anything not excluded: "Personal data is deemed protected by virtue of the provisions of this law." The Ministry of Transport, Communications and Information Technology implements the Law under Art. 7, issuing controls, procedures, licences, and a controller and processor register.
Cross border transfer
cite Royal Decree No. 6/2022, Art. 23
stage IN FORCE in force since 2023-02-13
binds public and private bodies
source official consolidated Royal Decree text, decree.om
What it requires →
Art. 23 permits a Controller to transfer personal data outside Oman "in accordance with the controls and procedures determined by the regulation," without prejudice to the Cyber Defence Centre's own competences. The Royal Decree itself states no adequacy test, no whitelist, and no enumerated conditions of its own; the entire substantive transfer regime is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source in this pass.
What the Decree does confirm is that a violation of Art. 23 carries by far the highest penalty tier in the whole Law (100,000 to 500,000 Rial Omani), a strong signal of seriousness even though the substantive rule is deferred.
This document does not code a jurisdiction-level cross_border_restriction finding from this instrument alone; the moderate value carried at jurisdiction level rests on the carried seed and the Bahrain and UAE comparators in this batch, not on Oman's own Executive Regulations text.
Data subject rights
cite Royal Decree No. 6/2022, Art. 11
stage IN FORCE in force since 2023-02-13
binds public and private bodies
source official consolidated Royal Decree text, decree.om
What it requires →
Art. 11 gives the data subject six rights, read verbatim in full on review: (a) revoke consent to processing, without affecting processing that already took place, (b) request amendment, updating, or blocking of their personal data, (c) obtain a copy of their processed personal data, (d) transfer their personal data to another controller (portability), (e) request erasure, unless processing is necessary for national archiving and documentation, and (f) be notified of any breach or infringement of their personal data and the actions taken in response.
No separate right to object to processing was found in Art. 11; the closest analog is the consent-revocation right at (a), which is narrower since it presupposes the processing rested on consent. Art. 12 separately gives a right to complain to the Ministry. These rights apply to a data subject's personal data generally, biometric identifiers included, since Art. 11 is not limited to any particular data category.
Enforcement supervision
What it requires →
Art. 8 gives the Ministry power to warn, order rectification or erasure, suspend processing (temporarily or permanently), and suspend cross-border transfer for a violation of the Law.
A five-tier fine structure by article violated (no imprisonment terms found in the sections read): 500-2,000 Rial Omani for Art. 14 violations; 1,000-5,000 for Arts. 15-18, 20, 22; 5,000-10,000 for Art. 13; 15,000-20,000 for Arts. 5, 6, 19, 21 (including the biometric or sensitive-data permit requirement and child-data processing); and 100,000-500,000, far the highest tier, for Art. 23 (cross-border transfer) violations.
A legal person is separately fined 5,000-100,000 Rial Omani where the violation is committed in its name, "without prejudice to the criminal liability of natural persons," though no imprisonment clause was independently located in the sections read. No private right of action was found; enforcement reads as Ministry-administrative with tiered fines.