Authors
Oman has introduced its first significant update to the Personal Data Protection Law (the PDPL) since it was enacted in 2022. Royal Decree 68/2026, issued by his Majesty Sultan Haitham bin Tarik, amends a number of key provisions of the PDPL, including its territorial scope, processing grounds, automated decision-making rules and retention requirements. The amendments were published in Official Gazette No. 1664 on 6 September 2026 and took effect the following day, on 7 September 2026.
We have set out below a summary of the key changes and their practical implications for organisations doing business in Oman:
1. Expanded territorial scope
The amendments expand the territorial scope of the PDPL. Amended Article 2 now provides that the law applies to the processing of personal data of individuals in Oman, regardless of whether that processing takes place inside or outside the Sultanate. As a result, any organisation processing personal data of individuals in Oman may fall within the scope of the PDPL, even if it is has no physical presence in Oman.
This is broader than the GDPR's approach to extraterritoriality, which only applies to overseas organisations in certain circumstances, such as where they offer goods or services to individuals or monitor their behaviour.
Organisations processing personal data of customers, employees or other individuals based in Oman should therefore assess whether their activities fall within the PDPL’s scope and, if so, ensure that their data processing practices comply with its requirements.
2. Processing without consent: a move away from broad exclusions
One of the most significant changes introduced by the amendments is the PDPL’s revised approach to processing without consent.
Under the original PDPL, a number of common processing activities, including processing necessary to comply with a legal obligation, protect a vital interest, perform a contract or use publicly available data, appear in Article 3 as exemptions from the law’s scope. The amendments remove these concepts from Article 3 and instead introduce them as specific grounds for processing without the data subject’s explicit consent under new Articles 5 bis and 10 bis.
The amendments now permit personal data to be processed without consent in a number of circumstances, including:
- Employee data for internal purposes: processing employee personal data for internal operational purposes, provided the processing complies with the PDPL and data is not disclosed to third parties without written consent.
- Surveillance and CCTV: processing carried out through surveillance devices and cameras used to fulfil security requirements issued by the competent entities.
- Legal obligations:where processing is necessary to comply with a legal obligation imposed on the controller by law, court judgment, order, or court decision.
- Contractual necessity: where processing is necessary to perform a contract with the data subject, provided the contract includes evidence that data processing is carried out in accordance with the PDPL.
- Publicly available data: where the data is publicly available in a manner that does contravene the PDPL.
- Vital interests: where processing is necessary to protect a vital interest of the data subject who cannot be contacted.
These new legal bases bring the PDPL closer to many other international data protection laws by providing organisations with alternatives to consent.
The amended Article 3 continues to exclude certain activities from the scope of the PDPL, including processing relating to national security or the public interest, the exercise of functions by government entities, the protection of the state’s economic and financial interests, crime prevention and detection, personal or family activities (unless published), and specified research activities carried out by authorised entities.
For organisations, the key takeaway is that legal obligations, contractual necessity, vital interests and publicly available data are not longer treated as exclusions from the PDPL. Instead, they operate as grounds for processing under the PDPL. Organisations should therefore identify and document the legal basis relied upon for each processing activity and ensure that the PDPL’s other requirements continue to be met.
Unlike many other modern data protection laws, the amendments do not introduce a general legitimate interest basis for processing. However, Article 5 bis allows additional processing grounds to be introduced through future ministerial decisions, making this an area to watch.
3. Automated processing: new obligations for AI and digital systems
The amendments introduce a new definition of “automated processing”, which is broadly defined as processing carried out by an electronic programme or system operating either entirely without human involvement or with only limited human supervision. This means the concept is likely to capture a wide range of technologies, including AI tools, algorithmic decision-making systems, profiling tools and automated workflows.
Against this new definition, the amended Article 14 imposes new obligations on controllers and processors using automated processing. Organisations must implement appropriate measures to protect the privacy and confidentiality of personal data and avoid causing harm to data subjects. In addition, individuals now have a right to object to decisions resulting from automated processing. Where an objection is raised, the organisation must ensure that the decision is reviewed with human involvement, in accordance with any further requirements introduced by the regulation.
Organisations using AI or other automated systems should asses whether those tools influence or determine decisions affecting individuals and, if so, consider how objections will be handled in practice. This may require documenting the role of automated systems in decision-making identifying where human review is required, and requiring that appropriate governance processes are in place. The changes are likely to be particularly relevant for organisations using automated tools in areas such as recruitment, employee management, customer screening, credit assessment, insurance underwriting and fraud detection.
4. Retention and erasure
The amendments introduce a stricter approach to data retention. Controllers and processors must now delete personal data immediately once the purpose for which it was collected has been fulfilled, unless one of the limited exceptions applies. Personal data may only be retained where:
- there is an ongoing dispute between the organisation and the data subject; or
- retention is required by law or pursuant to a judgment, court order or other legal obligation.
Organisations should review their data retention policies and schedules to ensure that personal data is only retained only for as long as there is a clear and documented reason for doing so and deleted once that reason no longer exists. The amendments narrow the circumstances in which data may be retained after the original purpose has been fulfilled, meaning organisations will need to move away from “just in case”, indefinite retention practices and ensure that any extended retention period can be justified by an ongoing dispute or a specific legal requirement.
5. Consent for direct marketing
The amendment confirms that controllers must obtain the data subject’s explicit consent before sending any commercial advertising or marketing materials. It also provides that the manner in which such consent must be obtained will be determined by the regulation, potentially signalling further regulatory guidance or amendments in this area.
6. Increased regulatory oversight and compliance audits
The amendment expands the role of the Ministry of Transport, Communications and Information Technology (the Regulator) and expressly empowers it to approve external auditors responsible for evaluating the compliance of controllers and processors with the PDPL.
Organisations should anticipate the introduction of compliance audit requirements and begin preparing by ensuring that their data protection policies, procedures, and records of processing activities are up to date and audit-ready.
Preparing for the changes
The amendments also strengthen the enforcement framework. Breaches of the consent requirements under Article 10 may result in fines of up to OMR 2,000 (approx. USD 5,200), while breaches relating to processing controls and automated processing may result in fines of up to OMR 10,000 (approx. USD 26,000).
In light of these changes, organisations that process personal data of individuals in Oman (whether based in the Oman or abroad) should consider taking the following steps:
- assess whether the expanded territorial scope brings any additional business activities or systems within the scope of the PDPL;
- review and document the legal basis relied upon for each processing activity, particularly where processing is carried out pursuant to a contract, legal obligation or other newly recognised processing ground;
- review consent mechanisms, privacy notices and records of processing activities to ensure they reflect the amended requirements;
- evaluate the use of AI tools, automated workflows and other automated decision-making systems and, where relevant, implement processes for objections and human review;
- review retention schedules and deletion practices to ensure personal data is not retained longer than permitted under the amended law; and
- ensure that policies, procedures and compliance documentation are up to date and capable of withstanding regulatory scrutiny or an external audit.
The amendments represent an important development in Oman's data protection framework and will require organisations to revisit existing compliance practices. As the PDPL has only been enforceable since 5 February 2026, it remains to be seen how these amendments will be implemented and enforced in practice, and whether further guidance or regulations will be issued by the Regulator.
We will continue to monitor regulatory developments in this area. If you would like to discuss how these amendments affect your organisation, please get in touch.
Related Experts