Data and digital law · Regulatory layer

Executive Regulation of the Personal Data Protection Law

Details permits for sensitive data, Data Subject rights, audits, Processing registers, breach notices, DPOs, cross-border transfers, complaints and administrative sanctions.

Material typeMinisterial Decision
Legal branchData and digital law
Legal layerRegulatory layer
Source languageOfficial Arabic text
Review dateAugust 24, 2026
IssuedJanuary 28, 2024
EffectiveFebruary 5, 2024
Official Gazette1531 · February 4, 2024
Version checkedAugust 24, 2026

01

Document overview

Details permits for sensitive data, Data Subject rights, audits, Processing registers, breach notices, DPOs, cross-border transfers, complaints and administrative sanctions.

02

Scope and exclusions

03

On-site text

All 45 articles are published: official Arabic and Smart Global Capital editorial English, Russian and Chinese translations. The 6/2025 amendment to the transition period is reflected.

The Arabic text is authoritative. English, Russian and Chinese are Smart Global Capital editorial translations for information only.

Published articles45 / 45
Government-published English translation45 / 45

Article 1

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

For the purposes of this Regulation, words and expressions have the meanings assigned to them in the Personal Data Protection Law. Unless the context requires otherwise, the following also mean: 1. Law: the Personal Data Protection Law. 2. Competent Department: the administrative division of the Ministry responsible for personal data protection. 3. Permit: the Ministry's approval for a Controller to process Personal Data. 4. Disclosure: enabling a third party, by any means and for any purpose, to access, view, obtain or use Personal Data. 5. Personal Data Breach: unlawful access to Personal Data resulting in its destruction, alteration, disclosure, access or unlawful Processing.

Article 2

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

The Controller or Processor, as applicable, must provide the Competent Department with any requested documents, data, information or other material within 30 days from the request.

Article 3

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

A Controller may contract with a Processor to process Personal Data. In dealings with third parties concerning those services, the Processor acts on behalf of the Controller for civil liability and administrative liability before the Ministry, without prejudice to the Processor's criminal liability for violations of the Law or this Regulation.

Article 4

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

Before Processing Personal Data, the Controller must obtain the Data Subject's explicit consent. Valid consent must: (1) be given by a person with full legal capacity; (2) be clear and freely given without coercion; and (3) be written, electronic or given by another means specified by the Controller.

Article 5

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

For article 5 of the Law, a Controller must obtain a Ministry Permit before Processing the specified categories of Personal Data, using the prescribed form and stating: the data protection officer's name, address and email; the purpose; the categories of data; any Processor; recipients or third parties; locations of transfer or storage; data management and protection systems; and any other information requested by the Ministry.

Article 6

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

A Permit application must include the Controller's personal data protection policy and its approved precautionary measures for a Personal Data Breach.

Article 7

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

The Competent Department must decide a complete Permit application within 45 days. A refusal must give reasons; silence when the period expires is deemed refusal. The applicant may appeal to the Minister within 60 days of notice or certain knowledge of refusal. No response to the appeal within 30 days is deemed refusal.

Article 8

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

After payment of the prescribed fee, the Minister issues a Permit for no more than five years, identifying the permit holder. It may be renewed for one or more similar periods under the same procedures.

Article 9

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

The Controller must notify the Competent Department, on the prescribed form, of changes to Permit information within 15 days of the change.

Article 10

Official English translation — Arabic text controlsPermanent link

Chapter Two · Permit Procedures

A Permit is cancelled: at the Controller's request; if the Controller violates the Law or Regulation; if Permit changes are not notified on time; or if the Permit was obtained by fraud, deception, forgery or false data or information.

Article 11

Official English translation — Arabic text controlsPermanent link

Chapter Three · Processing Children's Data

Before Processing a child's Personal Data, the Controller or Processor must obtain the guardian's explicit consent. It may request from the child the minimum guardian information needed to verify identity and obtain consent.

Article 12

Official English translation — Arabic text controlsPermanent link

Chapter Three · Processing Children's Data

When Processing a child's Personal Data, the purpose must be clear, direct, safe and free from fraud or misleading practices, and Processing must be limited to the minimum data necessary for that purpose.

Article 13

Official English translation — Arabic text controlsPermanent link

Chapter Three · Processing Children's Data

The Controller or Processor must provide means for a child's guardian to access, update and amend the child's Personal Data.

Article 14

Official English translation — Arabic text controlsPermanent link

Chapter Three · Processing Children's Data

A child's Personal Data may not be disclosed or shared with third parties without the guardian's explicit consent.

Article 15

Official English translation — Arabic text controlsPermanent link

Chapter Three · Processing Children's Data

A guardian, tutor or custodian, as applicable, represents a person who lacks, has limited, or has lost legal capacity. This chapter applies to Processing that person's Personal Data.

Article 16

Official English translation — Arabic text controlsPermanent link

Chapter Four · Data Subject Rights

A Data Subject may submit a free written request to exercise the rights in article 11(a)-(e) of the Law. The Controller must decide within 45 days of receipt. The Data Subject may request suspension of Processing until a decision is made.

Article 17

Official English translation — Arabic text controlsPermanent link

Chapter Four · Data Subject Rights

The Controller may reject a request wholly or partly if it is unjustifiably repetitive or requires extraordinary effort. A reasoned refusal must be notified within the article 16 period.

Article 18

Official English translation — Arabic text controlsPermanent link

Chapter Four · Data Subject Rights

A Data Subject may request erasure when the Processing purpose has ended, consent is withdrawn subject to article 17, or Processing violates the Law or Regulation. The Controller may refuse where retention is required by a legal obligation, judgment or judicial decision, or where a dispute exists between the Controller and Data Subject.

Article 19

Official English translation — Arabic text controlsPermanent link

Chapter Four · Data Subject Rights

A Data Subject may request a readable, clear electronic or paper copy of processed Personal Data, provided it contains no Personal Data identifying another person.

Article 20

Official English translation — Arabic text controlsPermanent link

Chapter Four · Data Subject Rights

A Data Subject may transfer Personal Data to a new Controller, and the existing Controller must transfer it where legally required.

Article 21

Official English translation — Arabic text controlsPermanent link

Chapter Five · Controller and Processor Obligations

The Controller or Processor must display a personal data protection policy where the Data Subject can review it before Processing. At minimum, it must explain the mechanism and procedures for exercising rights under the Law and Regulation.

Article 22

Official English translation — Arabic text controlsPermanent link

Chapter Five · Controller and Processor Obligations

Before sending advertising, marketing or commercial material, the Controller must obtain written consent, tell the Data Subject how it will be sent, provide a free opt-out mechanism, and stop sending immediately upon an opt-out request.

Article 23

Official English translation — Arabic text controlsPermanent link

Chapter Five · Controller and Processor Obligations

The Controller and Processor must appoint an external auditor who is accredited and licensed by the Ministry and independent of both. They must allow the auditor to inspect the records, Processing systems and data necessary for the audit.

Article 24

Official English translation — Arabic text controlsPermanent link

Chapter Five · Controller and Processor Obligations

The Controller and Processor must provide the Competent Department with a copy of the external auditor's report within 60 days of the auditor's appointment.

04

Publication status

Source and translation status

Ministry of Justice and Legal Affairs / MTCIT. All 45 articles are published: official Arabic and Smart Global Capital editorial English, Russian and Chinese translations. The 6/2025 amendment to the transition period is reflected.

Legal review

The official source and citation were checked; the consolidated version and amendments require separate verification before use. · August 24, 2026

Republication status

Official documents are excluded from copyright protection by Article 4 of Oman's Copyright Law 65/2008. Translations are Smart Global Capital editorial work; third-party layout and commentary were not copied.

Change history

24 August 2026: source located and initial record, scope and exclusions added to the index.

06

Official primary source

Ministerial Decision 34/2024 · amended by 6/2025 · Ministry of Justice and Legal Affairs / MTCIT

Official documents are excluded from copyright protection by Article 4 of Oman's Copyright Law 65/2008. Translations are Smart Global Capital editorial work; third-party layout and commentary were not copied.

Official Arabic textTransition-period amendment
WAWhatsAppTGTelegram