Innovation Analytics · Insights

Put privacy requirements into practice.

Turn agreed privacy requirements into working records, retention processes and request workflows. We implement the systems and evidence; your legal adviser determines the obligations and reviews legal wording.

General information, not legal advice.

Sources, review dates & scope
Published 7 September 2026Reviewed 7 September 202610 min read

Royal Decree 68/2026 — Official Gazette 1664, in force 7 September 2026

This is general information about published Omani law. It is not legal advice. Innovation Analytics is not a law office or legal-consultancy office registered under Royal Decree 41/2024.

Accurate as at 7 September 2026, sourced from Royal Decree 68/2026, Official Gazette issue 1664, 7 September 2026.

Innovation Analytics does not hold a cloud computing or data centre permit from the Telecommunications Regulatory Authority and does not provide, resell or aggregate cloud services. We build and operate software within our clients' own cloud environments.

Privacy implementation

Practical controls in your existing systems

Start with the personal data your business holds, where it moves and who manages it. We agree the implementation priorities with your team, then build maintainable workflows with clear owners and handover documentation.

PDPL implementation

Price on application

We do not give legal advice and we do not act as your data protection officer.

Published prices are an invitation to treat, not an offer capable of acceptance. Work is governed by a signed engagement letter.

Innovation Analytics is not an Oman Tax Authority accredited service provider.

What we build

  • Data discovery and a processing inventory.
  • The Records of Processing Activities, in your own tooling, maintainable rather than a PDF.
  • A retention schedule keyed to Article 15.
  • A transfer register carrying Executive Regulation Article 39's five heads.
  • Consent capture, storage and withdrawal with proof-of-consent records — applying Article 10 bis correctly, as an exemption from consent only.
  • DSAR intake and 45-day service-level tracking, free of charge to the data subject under Executive Regulation Article 16.
  • Bilingual privacy notices.
  • The Article 14 objection route, with audit log, review queue and a named human reviewer.
  • A dual 72-hour breach runbook carrying Executive Regulation Article 30's five report elements and Article 32's three required contents, with bilingual templates, plus one tabletop exercise.

Scope boundaries

  • Security remediation and specialist security operations require a separately agreed scope and appropriately qualified delivery support.
  • No contract drafting. Reserved under Royal Decree 41/2024, Article 11(3). We publish clause topics as a checklist and refer drafting to a registered legal consultant — unpaid in both directions, because Article 80 makes a referral commission an offence carrying OMR 5,000–20,000.
  • No statutory Data Protection Officer designation. Article 20 binds the controller.
  • No 24/7 monitoring, security operations centre, on-call or forensics.
  • No hosting of your data.

The three dates, kept straight

13 February 2023
Royal Decree 6/2022 in force.
5 February 2026
The Ministerial Decision 34/2024 alignment period ended.
7 September 2026
Royal Decree 68/2026 in force, Official Gazette 1664 — with no transition period.

What changed on 7 September 2026

Article 3's exclusions fall from ten to six. The deleted head that matters most is "execution of a contract to which the data subject is a party" — the exclusion that kept most ordinary Omani commercial processing outside the law entirely. It reappears in new Article 10 bis, but only as an exemption from consent. Records, retention, erasure, security, the DPO duty, breach notification and transfer now all apply to processing that sat outside the law on 6 September 2026.

  • Expressly extraterritorial
  • The contract exclusion is deleted
  • Processors are bound directly for the first time
  • New Article 15 — erasure on purpose-end
  • New Article 14 — automated-processing safeguards with a human element on review

Implementation needs to account for backups, logs, staging copies and working sets when applying the agreed retention and erasure requirements.

We publish the clause topics. We do not draft the clause: drafting contracts is reserved to registered advocates and legal consultants under Royal Decree 41/2024, Article 11(3).

Controller status: a question for legal review

Questions about how the amended definition of controller applies to a particular legal form should be resolved with your legal adviser and the Ministry before implementation.

What a processor has to build differently

  • An erasure job with a purpose-end trigger that covers backups, logs, staging and working sets.
  • A sub-processor register.
  • A transfer register carrying the five heads in Executive Regulation Article 39.
  • An automated-decision audit log, a review queue, and a named human reviewer with a service level.
  • A dual 72-hour breach runbook with bilingual templates.
  • Contract evidence as a topic checklist you hand to your lawyer.
  • A Records of Processing Activities built to Executive Regulation Article 28's ten minimum contents — maintained, not a PDF.

The Data Protection Officer, and the three conditions that actually apply

Executive Regulation Article 34 sets three conditions and no more: qualified for the Article 35 tasks, knowledgeable about the Law, the Regulation and the practices in place, and professionally competent. There is no nationality condition, no residency condition and no employment condition. Article 36 obliges the controller to publish the officer's name and contact details, with a right for every data subject to contact them. Article 20 binds the controller, so a pure processor has no statutory DPO duty of its own.

The penalty ladder, whole

The penalty ladder under the Personal Data Protection Law, in OMR.
FailureArticlePenalty (OMR)
Processing without explicit consent, or a defective consent requestArticle 25, as amended500 – 2,000
Failing to appoint a Data Protection Officer (Article 20 duty); processor erasure duty (new Article 15)Article 261,000 – 5,000
Automated-processing safeguards (new Article 14)Article 27, as amended5,000 – 10,000
Special-category data, children's data, breach-notification failure, confidentialityArticle 2815,000 – 20,000
Unlawful cross-border transferArticle 29100,000 – 500,000
Where the offender is a legal personArticle 305,000 – 100,000
Administrative penalty, per violation and cumulativeArticle 32up to 2,000

The exposure is large and the observed enforcement record is empty. MTCIT has published no fining decisions, no case log and no enforcement statistics, despite Article 7(h) of the Law obliging it to publish periodic reports. Both facts are true and we publish them together.

Figures that circulate, and what the text says

OMR 15,000–20,000 for failing to appoint a Data Protection Officer
Wrong. Article 20 imposes the duty; Article 26 penalises it at OMR 1,000–5,000. The 15,000–20,000 band is Article 28 and covers Articles 5, 6, 19 and 21 only.
Up to OMR 10,000
Real, but it is the ceiling of the amended Article 27 — not the law's maximum.
Up to OMR 100,000
Real. It is the Article 30 ceiling and the Article 29 floor, and it is defensible as a business-facing headline.
A maximum of OMR 2,000
Real, but it is the Article 32 administrative cap only — not the law's maximum.

Start a conversation

Discuss a project

PDPL implementation is quoted on application. We do not give legal advice and we do not act as your data protection officer.

CR 1363386Innovation Analytics · تحليلات الابتكارMuscat, OmanVerify our company