Oman's Personal Data Protection Law was issued by Royal Decree 6/2022, and its Executive Regulation followed as Ministerial Decision 34/2024. On 5 February 2026 the transition period ended and the regime entered full enforcement. A startup that collects names, emails, phone numbers or behavioural data about people in Oman is a controller under this law, and the regulator, the Ministry of Transport, Communications and Information Technology, can now act on non-compliance with fines of up to OMR 2,000 per violation.
Most Omani startups we speak to fall into one of two camps: those who assume the law does not apply to companies their size, and those who copied a GDPR privacy policy and assumed the job was done. Both are exposed. The PDPL is its own regime, with its own deadlines, and several of them are shorter than the market expects.
The framework
| RD 6/2022 | The Personal Data Protection Law: consent, data subject rights, controller obligations |
| MD 34/2024 | The Executive Regulation: request timelines, permits, transfer conditions |
| 5 Feb 2026 | End of the transition period; full enforcement |
Consent is the default basis, and it has to be provable
The PDPL requires explicit, informed consent before processing personal data, unless a statutory exception applies. Consent must be freely given, unambiguous and, critically, capable of being verified. A pre-ticked box fails all three tests. For a product team this means consent has to be captured as an event: who agreed, to what, when, and through which interface. If you cannot produce that record, you cannot prove the basis on which your database exists.
The clock that matters most: 45 days
A data subject may ask for a copy of their data, ask for corrections, ask for deletion, ask for transfer, or withdraw consent. Under the Executive Regulation, the controller must respond in writing within 45 days. Refusal is permitted only on narrow grounds: the request is unjustifiably repetitive, or fulfilling it would demand extraordinary effort, and reasons must be given. If the response never comes, or the answer is refusal, the individual may complain to MTCIT within 60 days.
A published privacy policy with no internal process behind it is a promise your company has already broken. The 45-day clock starts whether or not anyone is watching it.
Seventy-two hours after a breach
If personal data is breached in a way that poses a risk to the people it describes, the regulator must be notified within 72 hours, covering the nature of the breach, its impact and the mitigation under way. Where the breach is likely to cause serious harm, the affected individuals must be told within the same window. Seventy-two hours is not long enough to design a response from scratch, which is why the procedure has to exist before the breach does.
Sensitive data needs a permit, not a policy
Processing sensitive personal data, health and biometric data among the categories, requires a permit from MTCIT under the Executive Regulation before the processing begins. The Ministry has 45 days to decide, and silence counts as rejection. A health-tech or fintech product that touches these categories has a regulatory step in its critical path, not merely a compliance document to write.
Data leaving Oman
Cross-border transfers do not require prior approval from MTCIT, and no whitelist or blacklist of countries applies. But two conditions attach: the data subject's consent, and a level of protection at the destination not less than that prescribed by Omani law. Transfers must not prejudice national security or the higher interests of the Sultanate. For a startup on foreign cloud infrastructure, this is a contract question: what does your hosting agreement actually commit your provider to?
The appointment most startups have not made
The law requires a Data Protection Officer whose contact details are publicly available, and the regulator prefers the DPO to be located in Oman. In an early-stage company this need not be a dedicated hire, but it must be a named, reachable person, published where your users can find them.
The startup checklist
- Capture consent as a verifiable event: who, what, when, where.
- Build the 45-day data subject request procedure before the first request arrives.
- Write the 72-hour breach playbook now; name who calls the regulator.
- Check whether anything you process is sensitive data. If so, the MTCIT permit comes first.
- Read your cloud contracts against the Omani-law protection standard.
- Appoint and publish a Data Protection Officer.