Law / Oman

Oman

privacy

Oman's Personal Data Protection Law (Royal Decree No. 6/2022) was read in full at primary source, an untruncated consolidated English translation. Article 3 carves a list of processing activities entirely outside the Law's scope, not merely exempt from consent, including national security, state administrative functions, and publicly available data.

Article 5 requires a Ministry permit, not merely consent, before processing biometric data, genetic data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions, or security-measures data, structurally the same heightened prior-authorization gate found in Bahrain, distinct from a mere consent requirement.

Article 3(j)'s publicly-available scope exclusion is the most permissive such provision read across this batch, but it is qualified by a circularity clause ("in a manner not contrary to the provisions of this law") that plausibly still does not rescue an identifier a third party derives from an incidental public recording.

The Royal Decree defers its substantive cross-border transfer conditions and its breach-notification timeline entirely to the Executive Regulations (Ministerial Decision 34/2024), which were not read at primary source in this pass; both provisions' existence and duty are confirmed in the Decree's own text, but their operative detail is not.

Cross-border transfer violations carry by far the highest penalty tier in the Law (100,000 to 500,000 Rial Omani), a strong signal of seriousness even though the substantive rule itself is deferred.

12 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Personal Data Protection Law, biometric and sensitive data prior permit

cite Royal Decree No. 6/2022, Arts. 1, 5 stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

Art. 1 defines biometric data as "personal data resulting from specific technical processing relating to the physical, psychological, or behavioural characteristics such as the facial image or the genetic fingerprint data," naming a facial image as a worked example.

Art. 5 prohibits processing genetic data, biometric data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions, or security-measures data, except after obtaining a Ministry permit under controls and procedures the Executive Regulations set out (not read in this pass).

This is a prior-permit model, structurally the same heightened gate found in Bahrain: a service cannot rely on the Data Subject's consent alone to process biometric data in Oman. No modality-specific voice provision exists beyond the general definition, which would still reach a voiceprint as a behavioural characteristic enabling identification. No retention-period ceiling or destruction duty specific to biometric data was found in the Royal Decree itself.

Breach notification

Personal Data Protection Law, breach notification

cite Royal Decree No. 6/2022, breach notification provision stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

The Royal Decree requires the Controller, in the event of a personal data breach leading to destruction, alteration, disclosure, access, or illegal processing, to notify the Ministry and the Data Subject of the breach, in accordance with the controls and procedures the Executive Regulations set.

As with cross-border transfer, the duty exists in the Decree itself but its timeline, not stated as a fixed number of hours or days in the primary text read, is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source in this pass.

Comprehensive regime

Personal Data Protection Law, comprehensive regime and scope

cite Royal Decree No. 6/2022, Arts. 3-4, 7 stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

Art. 3 excludes a list of processing activities entirely from the Law's scope: national security and public interest, state administrative functions, legal-obligation compliance, state economic and financial interest protection, vital-interest protection, crime detection or prevention on formal written request, contract performance, personal or family-sphere processing, de-identified research or statistics, and publicly available data (Art. 3(j), see the jurisdiction summary).

Art. 4 sets a general coverage default for anything not excluded: "Personal data is deemed protected by virtue of the provisions of this law." The Ministry of Transport, Communications and Information Technology implements the Law under Art. 7, issuing controls, procedures, licences, and a controller and processor register.

Cross border transfer

Personal Data Protection Law, cross-border transfer

cite Royal Decree No. 6/2022, Art. 23 stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

Art. 23 permits a Controller to transfer personal data outside Oman "in accordance with the controls and procedures determined by the regulation," without prejudice to the Cyber Defence Centre's own competences. The Royal Decree itself states no adequacy test, no whitelist, and no enumerated conditions of its own; the entire substantive transfer regime is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source in this pass.

What the Decree does confirm is that a violation of Art. 23 carries by far the highest penalty tier in the whole Law (100,000 to 500,000 Rial Omani), a strong signal of seriousness even though the substantive rule is deferred.

This document does not code a jurisdiction-level cross_border_restriction finding from this instrument alone; the moderate value carried at jurisdiction level rests on the carried seed and the Bahrain and UAE comparators in this batch, not on Oman's own Executive Regulations text.

Data subject rights

Personal Data Protection Law, data subject rights

cite Royal Decree No. 6/2022, Art. 11 stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

Art. 11 gives the data subject six rights, read verbatim in full on review: (a) revoke consent to processing, without affecting processing that already took place, (b) request amendment, updating, or blocking of their personal data, (c) obtain a copy of their processed personal data, (d) transfer their personal data to another controller (portability), (e) request erasure, unless processing is necessary for national archiving and documentation, and (f) be notified of any breach or infringement of their personal data and the actions taken in response.

No separate right to object to processing was found in Art. 11; the closest analog is the consent-revocation right at (a), which is narrower since it presupposes the processing rested on consent. Art. 12 separately gives a right to complain to the Ministry. These rights apply to a data subject's personal data generally, biometric identifiers included, since Art. 11 is not limited to any particular data category.

Enforcement supervision

Personal Data Protection Law, enforcement and penalties

cite Royal Decree No. 6/2022, Art. 8, penalties provisions stage IN FORCE in force since 2023-02-13 binds public and private bodies source official consolidated Royal Decree text, decree.om
What it requires

Art. 8 gives the Ministry power to warn, order rectification or erasure, suspend processing (temporarily or permanently), and suspend cross-border transfer for a violation of the Law.

A five-tier fine structure by article violated (no imprisonment terms found in the sections read): 500-2,000 Rial Omani for Art. 14 violations; 1,000-5,000 for Arts. 15-18, 20, 22; 5,000-10,000 for Art. 13; 15,000-20,000 for Arts. 5, 6, 19, 21 (including the biometric or sensitive-data permit requirement and child-data processing); and 100,000-500,000, far the highest tier, for Art. 23 (cross-border transfer) violations.

A legal person is separately fined 5,000-100,000 Rial Omani where the violation is committed in its name, "without prejudice to the criminal liability of natural persons," though no imprisonment clause was independently located in the sections read. No private right of action was found; enforcement reads as Ministry-administrative with tiered fines.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.