Oman Privacy Guide

Personal data:
from inventory to breach response

PDPL is not just one policy on the site: you need a data card, consents, permits, agreements with processors, rights of subjects, DPO and control of international transfers.

Consentkey requirement
Permitfor Article 5 data
DPOaccording to the rules of the regime
72 hourssignificant leak

01

Law and executive rules

Personal Data Protection Law issued by Royal Decree 6/2022; Executive Regulations - Ministerial Decision 34/2024. The rules detail permits, children, rights, controller/processor responsibilities, breaches, DPO and transfers outside Oman.

02

Who defines the target and who processes

Controller
Defines goals, means and significant decisions
Processor
Processes data according to instructions and agreements
Data subject
The individual to whom the data relates
DPO
Coordinates the privacy program and interaction with MTCIT
Joint model
Roles are defined by functions, not by contract name

03

Consent must be demonstrable

The official summary of the rules emphasizes obtaining explicit consent prior to processing. Privacy notice explains controller, data, purposes, recipients, transfers, retention and rights. Where the law allows for a different regime, its basis is stated separately.

Do not mix

Agreement to the terms of the contract, marketing consent and permission for sensitive processing are different elements.

04

Data owner rights

Withdraw
Withdraw consent without canceling already lawful processing
Correct
Correct, update or block data
Access
Get a copy if you follow the rules
Portability
Transfer data to another controller
Erase
Delete unless legal exception applies
Breach notice
Be notified if there is serious harm or high risk

05

Article 5 data and permit

For the categories specified in Article 5, the controller or processor obtains an MTCIT permit according to the established procedure. Documents are attached to the application, including privacy policy and safeguards; The official service indicates a permit period of up to five years with renewal/amendment/cancellation controls.

06

Vendor and cloud do not relieve responsibility

Scope
Data, goals, instructions and duration
Security
Access, encryption, logging, backup and testing
Subprocessors
Approval and flow-down obligations
Requests
Help with rights and regulatory inquiries
Breach
Immediate communication to controller and evidence
Exit
Return/deletion and completion confirmation

07

Leakage: 72 hours at specified risk

Controller notifies MTCIT within 72 hours of knowledge if the breach threatens the rights of data subjects. During the same period, the subject is notified if serious harm or high risk is possible. Before an incident, classification, contacts, escalation and decision log are needed.

  1. 01
    Contain

    Stop the leak and save evidence.

  2. 02
    Assess

    Data, persons, consequences and risk.

  3. 03
    Notify

    MTCIT and subjects, if the threshold is reached.

  4. 04
    Remediate

    Reason, controls and documented follow-up.

08

Cross-border transfer

The rules link the transfer to consent, the absence of a threat to national security or higher interests, and sufficient protection from the external processor not lower than the level of the Omani regime. The contract, destination, onward transfers and technical measures are included in the transfer file.

09

Direct marketing

Email, SMS, messengers and profiling are checked by consent and special controls. The company stores proof of opt-in, gives simple opt-out, maintains a suppression list and does not use the database received for another purpose without verification.

10

Privacy-program

  1. 01

    Create data inventory and records of processing.

  2. 02

    Prepare notices, consent flows and rights procedures.

  3. 03

    Define Article 5 permits and DPO responsibilities.

  4. 04

    Update vendor, cloud and transfer agreements.

  5. 05

    Test the 72-hour breach plan.

Official base

MTCIT: rules and permit

01

MTCIT — Executive Regulation announcement

Official summary of Ministerial Decision 34/2024: rights, permit, DPO, breach and transfers.

Open source
02

MTCIT — PDPL Permits Service

Official service for obtaining permission to process data under Article 5.

Open source

Privacy program

We will build a working data protection system

Inventory, notices, permits, vendors, transfers and incident response.

Discuss the project
WAWhatsAppTGTelegram