01
Law and executive rules
Personal Data Protection Law issued by Royal Decree 6/2022; Executive Regulations - Ministerial Decision 34/2024. The rules detail permits, children, rights, controller/processor responsibilities, breaches, DPO and transfers outside Oman.
02
Who defines the target and who processes
- Controller
- Defines goals, means and significant decisions
- Processor
- Processes data according to instructions and agreements
- Data subject
- The individual to whom the data relates
- DPO
- Coordinates the privacy program and interaction with MTCIT
- Joint model
- Roles are defined by functions, not by contract name
03
Consent must be demonstrable
The official summary of the rules emphasizes obtaining explicit consent prior to processing. Privacy notice explains controller, data, purposes, recipients, transfers, retention and rights. Where the law allows for a different regime, its basis is stated separately.
Agreement to the terms of the contract, marketing consent and permission for sensitive processing are different elements.
04
Data-subject rights
- Withdraw
- Withdraw consent without invalidating processing that was already lawful
- Correct
- Correct, update or block data
- Access
- Obtain a copy in accordance with the applicable rules
- Portability
- Transfer data to another controller
- Erase
- Request deletion unless a legal exception applies
- Breach notice
- Be notified where serious harm or high risk may arise
05
Article 5 data and permit
For the categories specified in Article 5, the controller or processor obtains an MTCIT permit according to the established procedure. Documents are attached to the application, including privacy policy and safeguards; The official service indicates a permit period of up to five years with renewal/amendment/cancellation controls.
06
Vendor and cloud do not relieve responsibility
- Scope
- Data, goals, instructions and duration
- Security
- Access, encryption, logging, backup and testing
- Subprocessors
- Approval and flow-down obligations
- Requests
- Help with rights and regulatory inquiries
- Breach
- Immediate communication to controller and evidence
- Exit
- Return/deletion and completion confirmation
07
Data breach: 72 hours where the risk threshold is met
The controller notifies MTCIT within 72 hours of becoming aware of a breach if it threatens the rights of data subjects. During the same period, the data subject is notified if serious harm or high risk is possible. Before an incident, classification, contacts, escalation and a decision log are needed.
- 01Contain
Contain the breach and preserve evidence.
- 02Assess
Data, persons, consequences and risk.
- 03Notify
MTCIT and data subjects if the threshold is met.
- 04Remediate
Root cause, controls and documented follow-up.
08
Cross-border transfer
The rules link the transfer to consent, the absence of a threat to national security or higher interests, and sufficient protection from the external processor not lower than the level of the Omani regime. The contract, destination, onward transfers and technical measures are included in the transfer file.
09
Direct marketing
Email, SMS, messengers and profiling are checked by consent and special controls. The company stores proof of opt-in, gives simple opt-out, maintains a suppression list and does not use the database received for another purpose without verification.
10
Privacy-program
- 01
Create data inventory and records of processing.
- 02
Prepare notices, consent flows and rights procedures.
- 03
Define Article 5 permits and DPO responsibilities.
- 04
Update vendor, cloud and transfer agreements.
- 05
Test the 72-hour breach plan.
