Article-by-article contents · Page 1 / 1

Executive Regulation of the Personal Data Protection Lawarticles 1–45

  1. Article 1

    For the purposes of this Regulation, words and expressions have the meanings assigned to them in the Personal Data Protection Law. Unless the context requires otherwise, the following also mean: 1. Law: the Personal Data

  2. Article 2

    The Controller or Processor, as applicable, must provide the Competent Department with any requested documents, data, information or other material within 30 days from the request.

  3. Article 3

    A Controller may contract with a Processor to process Personal Data. In dealings with third parties concerning those services, the Processor acts on behalf of the Controller for civil liability and administrative liabili

  4. Article 4

    Before Processing Personal Data, the Controller must obtain the Data Subject's explicit consent. Valid consent must: (1) be given by a person with full legal capacity; (2) be clear and freely given without coercion; and

  5. Article 5

    For article 5 of the Law, a Controller must obtain a Ministry Permit before Processing the specified categories of Personal Data, using the prescribed form and stating: the data protection officer's name, address and ema

  6. Article 6

    A Permit application must include the Controller's personal data protection policy and its approved precautionary measures for a Personal Data Breach.

  7. Article 7

    The Competent Department must decide a complete Permit application within 45 days. A refusal must give reasons; silence when the period expires is deemed refusal. The applicant may appeal to the Minister within 60 days o

  8. Article 8

    After payment of the prescribed fee, the Minister issues a Permit for no more than five years, identifying the permit holder. It may be renewed for one or more similar periods under the same procedures.

  9. Article 9

    The Controller must notify the Competent Department, on the prescribed form, of changes to Permit information within 15 days of the change.

  10. Article 10

    A Permit is cancelled: at the Controller's request; if the Controller violates the Law or Regulation; if Permit changes are not notified on time; or if the Permit was obtained by fraud, deception, forgery or false data o

  11. Article 11

    Before Processing a child's Personal Data, the Controller or Processor must obtain the guardian's explicit consent. It may request from the child the minimum guardian information needed to verify identity and obtain cons

  12. Article 12

    When Processing a child's Personal Data, the purpose must be clear, direct, safe and free from fraud or misleading practices, and Processing must be limited to the minimum data necessary for that purpose.

  13. Article 13

    The Controller or Processor must provide means for a child's guardian to access, update and amend the child's Personal Data.

  14. Article 14

    A child's Personal Data may not be disclosed or shared with third parties without the guardian's explicit consent.

  15. Article 15

    A guardian, tutor or custodian, as applicable, represents a person who lacks, has limited, or has lost legal capacity. This chapter applies to Processing that person's Personal Data.

  16. Article 16

    A Data Subject may submit a free written request to exercise the rights in article 11(a)-(e) of the Law. The Controller must decide within 45 days of receipt. The Data Subject may request suspension of Processing until a

  17. Article 17

    The Controller may reject a request wholly or partly if it is unjustifiably repetitive or requires extraordinary effort. A reasoned refusal must be notified within the article 16 period.

  18. Article 18

    A Data Subject may request erasure when the Processing purpose has ended, consent is withdrawn subject to article 17, or Processing violates the Law or Regulation. The Controller may refuse where retention is required by

  19. Article 19

    A Data Subject may request a readable, clear electronic or paper copy of processed Personal Data, provided it contains no Personal Data identifying another person.

  20. Article 20

    A Data Subject may transfer Personal Data to a new Controller, and the existing Controller must transfer it where legally required.

  21. Article 21

    The Controller or Processor must display a personal data protection policy where the Data Subject can review it before Processing. At minimum, it must explain the mechanism and procedures for exercising rights under the

  22. Article 22

    Before sending advertising, marketing or commercial material, the Controller must obtain written consent, tell the Data Subject how it will be sent, provide a free opt-out mechanism, and stop sending immediately upon an

  23. Article 23

    The Controller and Processor must appoint an external auditor who is accredited and licensed by the Ministry and independent of both. They must allow the auditor to inspect the records, Processing systems and data necess

  24. Article 24

    The Controller and Processor must provide the Competent Department with a copy of the external auditor's report within 60 days of the auditor's appointment.

  25. Article 25

    The Controller and Processor may not publish, share or disclose the Personal Data specified in article 5 of the Law except within legally permitted limits and cases or to execute a judgment or judicial decision.

  26. Article 26

    The Controller must ensure confidentiality by implementing electronic systems against unlawful access, leakage, tampering or misuse; maintaining recovery systems for physical or technical incidents; and testing the effec

  27. Article 27

    Subject to article 18, Processing records must be retained for a specific lawful reason, for a period proportionate to the Processing purpose, and under technical safeguards ensuring secure retention.

  28. Article 28

    The Controller or Processor must maintain a Processing activities register containing at least: DPO details; data categories and authorised persons; periods, restrictions and scope; erasure, amendment and Processing mech

  29. Article 29

    The Controller must continuously update the Processing activities register and provide it to the Competent Department on request.

  30. Article 30

    A Controller must notify the Competent Department within 72 hours of learning of a breach that may threaten Data Subjects' rights. The notice must describe the breached data and consequences; give Controller or contact-p

  31. Article 31

    After receiving an article 30 notice, the Competent Department may record it and: assess the Controller's measures and whether they address the harm; direct notification of the Data Subject without prejudice to article 3

  32. Article 32

    Where a breach may cause serious harm or high risk, the Controller must notify the Data Subject within 72 hours of becoming aware. The notice must state the type and nature of breach, details of affected Personal Data, a

  33. Article 33

    The Controller must document breaches, their causes and consequences, and corrective, technical or organisational measures, and retain that information for the period set by the Competent Department in the article 28 reg

  34. Article 34

    The Controller must designate a Data Protection Officer qualified for article 35 duties, knowledgeable about the Law, Regulation and the Controller's or Processor's practices, and professionally competent to handle all p

  35. Article 35

    The Data Protection Officer advises the Controller or Processor on obligations under the Law and Regulation, monitors implementation of data protection policies and legal obligations, and coordinates with the Competent D

  36. Article 36

    The Controller must publish the Data Protection Officer's name and contact details by any means. A Data Subject may contact the officer on any matter concerning Processing of that subject's Personal Data.

  37. Article 37

    Before transferring Personal Data outside Oman, the Controller must obtain explicit consent and ensure the transfer does not prejudice national security or the State's supreme interests. Consent is unnecessary to perform

  38. Article 38

    Before an overseas transfer, the Controller must ensure the foreign Processing entity provides adequate protection no lower than the level required by the Law and Regulation.

  39. Article 39

    The Controller must assess the foreign recipient's protection and transfer risks, including: nature, volume and sensitivity of data; purpose, scope and recipients; Processing duration and whether restricted, one-off, rep

  40. Article 40

    The Ministry may request a copy of the Controller's assessment report to verify adequate protection by the foreign Processing entity.

  41. Article 41

    A Data Subject or other interested person may file the prescribed complaint or report with the Competent Department within 30 days of certain knowledge of a violation of the Law, Regulation or implementing decisions. The

  42. Article 42

    The Controller may respond to a complaint or report within 14 days of notification.

  43. Article 43

    The Competent Department must decide the complaint or report within 60 days beginning after the article 42 response period expires. Silence is deemed rejection.

  44. Article 44

    For a violation of the Regulation, the Minister may impose a warning, suspend the Permit until the violation is remedied, impose an administrative fine up to OMR 2,000 per violation, or cancel the Permit.

  45. Article 45

    A person subject to an administrative sanction may appeal to the Minister within 60 days of notification or certain knowledge of the violation decision. The Minister must decide within 30 days of filing; silence is deeme

WAWhatsAppTGTelegram