01
Law and executive rules
Personal Data Protection Law issued by Royal Decree 6/2022; Executive Regulations - Ministerial Decision 34/2024. The rules detail permits, children, rights, controller/processor responsibilities, breaches, DPO and transfers outside Oman.
02
Who defines the target and who processes
- Controller
- Defines goals, means and significant decisions
- Processor
- Processes data according to instructions and agreements
- Data subject
- The individual to whom the data relates
- DPO
- Coordinates the privacy program and interaction with MTCIT
- Joint model
- Roles are defined by functions, not by contract name
03
Consent must be demonstrable
The official summary of the rules emphasizes obtaining explicit consent prior to processing. Privacy notice explains controller, data, purposes, recipients, transfers, retention and rights. Where the law allows for a different regime, its basis is stated separately.
Agreement to the terms of the contract, marketing consent and permission for sensitive processing are different elements.
04
Data owner rights
- Withdraw
- Withdraw consent without canceling already lawful processing
- Correct
- Correct, update or block data
- Access
- Get a copy if you follow the rules
- Portability
- Transfer data to another controller
- Erase
- Delete unless legal exception applies
- Breach notice
- Be notified if there is serious harm or high risk
05
Article 5 data and permit
For the categories specified in Article 5, the controller or processor obtains an MTCIT permit according to the established procedure. Documents are attached to the application, including privacy policy and safeguards; The official service indicates a permit period of up to five years with renewal/amendment/cancellation controls.
06
Vendor and cloud do not relieve responsibility
- Scope
- Data, goals, instructions and duration
- Security
- Access, encryption, logging, backup and testing
- Subprocessors
- Approval and flow-down obligations
- Requests
- Help with rights and regulatory inquiries
- Breach
- Immediate communication to controller and evidence
- Exit
- Return/deletion and completion confirmation
07
Leakage: 72 hours at specified risk
Controller notifies MTCIT within 72 hours of knowledge if the breach threatens the rights of data subjects. During the same period, the subject is notified if serious harm or high risk is possible. Before an incident, classification, contacts, escalation and decision log are needed.
- 01Contain
Stop the leak and save evidence.
- 02Assess
Data, persons, consequences and risk.
- 03Notify
MTCIT and subjects, if the threshold is reached.
- 04Remediate
Reason, controls and documented follow-up.
08
Cross-border transfer
The rules link the transfer to consent, the absence of a threat to national security or higher interests, and sufficient protection from the external processor not lower than the level of the Omani regime. The contract, destination, onward transfers and technical measures are included in the transfer file.
09
Direct marketing
Email, SMS, messengers and profiling are checked by consent and special controls. The company stores proof of opt-in, gives simple opt-out, maintains a suppression list and does not use the database received for another purpose without verification.
10
Privacy-program
- 01
Create data inventory and records of processing.
- 02
Prepare notices, consent flows and rights procedures.
- 03
Define Article 5 permits and DPO responsibilities.
- 04
Update vendor, cloud and transfer agreements.
- 05
Test the 72-hour breach plan.
+7 (495) 221 31 46