Data and digital law · Regulatory layer

Personal Data Protection Law

Sets rules for personal-data processing, individual rights, controller duties and cross-border transfers, together with the 2024 Executive Regulation.

Material typeRoyal Decree
Legal branchData and digital law
Legal layerRegulatory layer
Source languageOfficial Arabic text and government-published English translation
Review dateAugust 24, 2026
IssuedFebruary 9, 2022
EffectiveFebruary 13, 2023
Official Gazette1429 · February 13, 2022
Version checkedAugust 24, 2026

01

Document overview

Sets rules for personal-data processing, individual rights, controller duties and cross-border transfers, together with the 2024 Executive Regulation.

02

Scope and exclusions

03

On-site text

All 32 articles are published: official Arabic text, government-published English text and Smart Global Capital editorial Russian and Chinese translations.

The Arabic text is authoritative. The English text was published by a government authority; Russian and Chinese are Smart Global Capital editorial translations for information only.

Published articles32 / 32
Government-published English translation32 / 32

Article 1

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

For the purposes of this Law, the following words and expressions have the meanings assigned to them, unless the context requires otherwise: Ministry: Ministry of Transport, Communications and Information Technology. Minister: Minister of Transport, Communications and Information Technology. Personal Data: Data that identifies a natural person, or makes that person directly or indirectly identifiable, by reference to one or more identifiers such as a name, civil number, electronic identifier data or location data, or by reference to one or more factors specific to genetic, physical, mental, psychological, social, cultural or economic identity. Genetic Data: Personal Data relating to inherited or acquired genetic characteristics and resulting from analysis of a biological sample. Biometric Data: Personal Data resulting from specific technical processing relating to physical, psychological or behavioural characteristics, such as a facial image or genetic fingerprint data. Health Data: Personal Data relating to physical, mental and psychological health. Processing: An operation or set of operations performed on Personal Data, including collection, recording, analysis, organisation, storage, alteration, adaptation, retrieval, consultation, alignment, combination, blocking, erasure, destruction or disclosure by transmission, dissemination, transfer, conversion or otherwise making it available. Data Subject: The natural person identifiable through his or her Personal Data. Controller: The person who determines the purposes and means of Processing Personal Data and carries out the Processing or entrusts it to another person. Processor: The person who processes Personal Data on behalf of the Controller. Regulation: The Executive Regulation of this Law.

Article 2

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

This Law applies to Personal Data that is processed.

Article 3

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

This Law does not apply to Processing Personal Data in the following cases: (a) protecting national security or the public interest; (b) performance by units of the State Administrative Apparatus and other public legal persons of their legally prescribed functions; (c) performance of a legal obligation imposed on the Controller by any law, judgment or court decision; (d) protecting the State's economic and financial interests; (e) protecting a vital interest of the Data Subject; (f) detecting or preventing a criminal offence on the basis of a formal written request from an investigating authority; (g) performance of a contract to which the Data Subject is a party; (h) Processing within a personal or family context; (i) historical, statistical, scientific, literary or economic research by entities authorised to conduct such work, provided that published research and statistics use no indication or reference relating to the Data Subject, so that Personal Data cannot be attributed to an identified or identifiable natural person; (j) where the data is publicly available in a manner not contrary to this Law.

Article 4

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

Personal Data is protected under this Law.

Article 5

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

Processing Personal Data relating to Genetic Data, Biometric Data, Health Data, racial origin, sex life, political or religious opinions, beliefs, criminal convictions or security measures is prohibited unless a permit has first been obtained from the Ministry in accordance with the controls and procedures prescribed by the Regulation.

Article 6

Official English translation — Arabic text controlsPermanent link

Chapter One · Definitions and General Provisions

Processing a child's Personal Data is prohibited without the approval of the child's guardian, unless the Processing is in the child's best interests, in accordance with the controls and procedures prescribed by the Regulation.

Article 7

Official English translation — Arabic text controlsPermanent link

Chapter Two · Duties and Powers of the Ministry

Without prejudice to the powers assigned to the Cyber Defence Centre, the Ministry is responsible for implementing this Law and, in particular, shall: (a) prepare and approve controls and procedures for protecting Personal Data, including necessary safeguards and measures and codes of conduct; (b) issue controls and procedures required for Processing Personal Data and verify compliance by Controllers and Processors; (c) receive and decide reports and complaints filed by Data Subjects within the period prescribed by the Regulation; (d) cooperate with authorities responsible for Personal Data protection in other states; (e) provide advice, support and coordination to units of the State Administrative Apparatus and other public legal persons on Personal Data protection matters; (f) issue and revoke licences for service providers entrusted with assessing compliance by Controllers and Processors, in accordance with the Regulation; (g) prepare guidance forms for implementing this Law whenever required; (h) prepare periodic reports on its Personal Data protection activities and publish them on its website; (i) establish a register of Controllers and Processors that satisfy the prescribed requirements, as provided by the Regulation.

Article 8

Official English translation — Arabic text controlsPermanent link

Chapter Two · Duties and Powers of the Ministry

To protect the rights of Data Subjects, the Ministry may take any of the following measures: (a) warn a Controller or Processor of a violation of this Law; (b) order rectification and erasure of Personal Data processed in violation of this Law; (c) suspend Processing temporarily or permanently; (d) suspend the transfer of Personal Data to another state or an international organisation; (e) take any other measure it considers necessary to protect Personal Data, as prescribed by the Regulation.

Article 9

Official English translation — Arabic text controlsPermanent link

Chapter Two · Duties and Powers of the Ministry

Ministry employees designated by a decision of the competent authority in agreement with the Minister have judicial enforcement status for the implementation of this Law, the Regulation and decisions issued under it.

Article 10

Official English translation — Arabic text controlsPermanent link

Chapter Three · Rights of the Data Subject

Personal Data may be processed only transparently, fairly and with respect for human dignity, and after the Data Subject has given explicit consent. A request to process Personal Data must be written, clear, explicit and understandable. The Controller must be able to prove the Data Subject's written consent to the Processing.

Article 11

Official English translation — Arabic text controlsPermanent link

Chapter Three · Rights of the Data Subject

The Data Subject has the right to: (a) withdraw consent to Processing, without affecting Processing carried out before withdrawal; (b) request amendment, updating or blocking of Personal Data; (c) obtain a copy of processed Personal Data; (d) transfer Personal Data to another Controller; (e) request erasure of Personal Data unless Processing is necessary for national archiving and documentation; (f) be notified of any breach or infringement involving Personal Data and the measures taken in response. The Regulation prescribes the controls and procedures for exercising these rights.

Article 12

Official English translation — Arabic text controlsPermanent link

Chapter Three · Rights of the Data Subject

A Data Subject may submit a complaint to the Ministry if the Data Subject believes that the Processing of his or her Personal Data does not comply with this Law, in accordance with the controls and procedures prescribed by the Regulation.

Article 13

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller must establish controls and procedures to be followed when Processing Personal Data. They must include in particular: (a) identification of risks to which the Data Subject may be exposed as a result of Processing; (b) procedures and controls for transporting and transferring Personal Data; (c) technical and procedural measures ensuring that Processing is carried out in accordance with this Law; (d) any other controls or procedures prescribed by the Regulation.

Article 14

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

Before Processing any Personal Data, the Controller must notify the Data Subject in writing of: (a) the details of the Controller and Processor; (b) contact details of the Personal Data protection officer; (c) the purpose of Processing and the source from which the Personal Data was collected; (d) a comprehensive and accurate description of the Processing, its procedures and the levels of disclosure of Personal Data; (e) the Data Subject's rights, including access, rectification, transfer and updating; (f) any other information necessary to satisfy the conditions for Processing.

Article 15

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller and Processor must comply with the controls and procedures prescribed by the Ministry to ensure that Processing is carried out in accordance with this Law.

Article 16

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

At the Ministry's request, the Controller and Processor must appoint an external auditor to verify that Processing has been conducted in accordance with this Law and with the Controller's procedures and controls under Article 13. The Regulation prescribes the controls and procedures for appointing the external auditor. The Controller and Processor must provide the Ministry with a copy of the external auditor's report.

Article 17

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller and Processor must retain documentation of Processing operations for the periods and in accordance with the procedures prescribed by the Regulation.

Article 18

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller and Processor must cooperate with the Ministry and provide the data and documents it requests and considers necessary for exercising its powers under this Law, within the period prescribed by the Regulation.

Article 19

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

Where a Personal Data breach results in unlawful destruction, alteration, disclosure, access or Processing, the Controller must notify the Ministry and the Data Subject of the breach in accordance with the controls and procedures prescribed by the Regulation.

Article 20

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller must designate a Personal Data protection officer. The Regulation prescribes the criteria for selecting the officer and the officer's duties.

Article 21

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

The Controller must ensure the confidentiality of Personal Data and must not publish it without the Data Subject's prior consent, as prescribed by the Regulation.

Article 22

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

Before sending advertising or marketing material for commercial purposes, the Controller must obtain the Data Subject's written consent, as prescribed by the Regulation.

Article 23

Official English translation — Arabic text controlsPermanent link

Chapter Four · Obligations of the Controller and Processor

Without prejudice to the powers assigned to the Cyber Defence Centre, a Controller may transport Personal Data and permit its transfer outside the Sultanate of Oman in accordance with the controls and procedures prescribed by the Regulation. The Controller is prohibited from transporting Personal Data if it has been processed in violation of this Law or if the transport would harm the Data Subject.

Article 24

Official English translation — Arabic text controlsPermanent link

Chapter Five · Penalties

Without prejudice to any more severe penalty prescribed by the Penal Law or any other law, the offences specified in this Law are punishable by the penalties provided in it.

04

Publication status

Source and translation status

Ministry of Justice and Legal Affairs / MTCIT. All 32 articles are published: official Arabic text, government-published English text and Smart Global Capital editorial Russian and Chinese translations.

Legal review

The official source and citation were checked; the consolidated version and amendments require separate verification before use. · August 24, 2026

Republication status

Official documents are excluded from copyright protection by Article 4 of Oman's Copyright Law 65/2008. Source-site layout and editorial material are not reproduced.

Change history

24 August 2026: source located and initial record, scope and exclusions added to the index.

06

Official primary source

Royal Decree 6/2022 · Executive Regulation 34/2024 · Ministry of Justice and Legal Affairs / MTCIT

Official documents are excluded from copyright protection by Article 4 of Oman's Copyright Law 65/2008. Source-site layout and editorial material are not reproduced.

Official Arabic textGovernment English text
WAWhatsAppTGTelegram