Oman Privacy Guide

Personal data:
from inventory to breach response

PDPL is not just one policy on the site: you need a data card, consents, permits, agreements with processors, rights of subjects, DPO and control of international transfers.

Consentkey requirement
Permitfor Article 5 data
DPOaccording to the rules of the regime
72 hourssignificant leak

01

Law and executive rules

Personal Data Protection Law issued by Royal Decree 6/2022; Executive Regulations - Ministerial Decision 34/2024. The rules detail permits, children, rights, controller/processor responsibilities, breaches, DPO and transfers outside Oman.

02

Who defines the target and who processes

Controller
Defines goals, means and significant decisions
Processor
Processes data according to instructions and agreements
Data subject
The individual to whom the data relates
DPO
Coordinates the privacy program and interaction with MTCIT
Joint model
Roles are defined by functions, not by contract name

03

Consent must be demonstrable

The official summary of the rules emphasizes obtaining explicit consent prior to processing. Privacy notice explains controller, data, purposes, recipients, transfers, retention and rights. Where the law allows for a different regime, its basis is stated separately.

Do not mix

Agreement to the terms of the contract, marketing consent and permission for sensitive processing are different elements.

04

Data-subject rights

Withdraw
Withdraw consent without invalidating processing that was already lawful
Correct
Correct, update or block data
Access
Obtain a copy in accordance with the applicable rules
Portability
Transfer data to another controller
Erase
Request deletion unless a legal exception applies
Breach notice
Be notified where serious harm or high risk may arise

05

Article 5 data and permit

For the categories specified in Article 5, the controller or processor obtains an MTCIT permit according to the established procedure. Documents are attached to the application, including privacy policy and safeguards; The official service indicates a permit period of up to five years with renewal/amendment/cancellation controls.

06

Vendor and cloud do not relieve responsibility

Scope
Data, goals, instructions and duration
Security
Access, encryption, logging, backup and testing
Subprocessors
Approval and flow-down obligations
Requests
Help with rights and regulatory inquiries
Breach
Immediate communication to controller and evidence
Exit
Return/deletion and completion confirmation

07

Data breach: 72 hours where the risk threshold is met

The controller notifies MTCIT within 72 hours of becoming aware of a breach if it threatens the rights of data subjects. During the same period, the data subject is notified if serious harm or high risk is possible. Before an incident, classification, contacts, escalation and a decision log are needed.

  1. 01
    Contain

    Contain the breach and preserve evidence.

  2. 02
    Assess

    Data, persons, consequences and risk.

  3. 03
    Notify

    MTCIT and data subjects if the threshold is met.

  4. 04
    Remediate

    Root cause, controls and documented follow-up.

08

Cross-border transfer

The rules link the transfer to consent, the absence of a threat to national security or higher interests, and sufficient protection from the external processor not lower than the level of the Omani regime. The contract, destination, onward transfers and technical measures are included in the transfer file.

09

Direct marketing

Email, SMS, messengers and profiling are checked by consent and special controls. The company stores proof of opt-in, gives simple opt-out, maintains a suppression list and does not use the database received for another purpose without verification.

10

Privacy-program

  1. 01

    Create data inventory and records of processing.

  2. 02

    Prepare notices, consent flows and rights procedures.

  3. 03

    Define Article 5 permits and DPO responsibilities.

  4. 04

    Update vendor, cloud and transfer agreements.

  5. 05

    Test the 72-hour breach plan.

Official base

MTCIT: rules and permit

01

MTCIT — Executive Regulation announcement

Official summary of Ministerial Decision 34/2024: rights, permit, DPO, breach and transfers.

Open source
02

MTCIT — PDPL Permits Service

Official service for obtaining permission to process data under Article 5.

Open source

Privacy program

We will build a working data protection system

Inventory, notices, permits, vendors, transfers and incident response.

Discuss the project
WAWhatsAppTGTelegram