Innovation Analytics · Insights
Put privacy requirements into practice.
Turn agreed privacy requirements into working records, retention processes and request workflows. We implement the systems and evidence; your legal adviser determines the obligations and reviews legal wording.
General information, not legal advice.
Sources, review dates & scope
Royal Decree 68/2026 — Official Gazette 1664, in force 7 September 2026
This is general information about published Omani law. It is not legal advice. Innovation Analytics is not a law office or legal-consultancy office registered under Royal Decree 41/2024.
Accurate as at 7 September 2026, sourced from Royal Decree 68/2026, Official Gazette issue 1664, 7 September 2026.
Innovation Analytics does not hold a cloud computing or data centre permit from the Telecommunications Regulatory Authority and does not provide, resell or aggregate cloud services. We build and operate software within our clients' own cloud environments.
Privacy implementation
Practical controls in your existing systems
Start with the personal data your business holds, where it moves and who manages it. We agree the implementation priorities with your team, then build maintainable workflows with clear owners and handover documentation.

PDPL implementation
We do not give legal advice and we do not act as your data protection officer.
Published prices are an invitation to treat, not an offer capable of acceptance. Work is governed by a signed engagement letter.
Innovation Analytics is not an Oman Tax Authority accredited service provider.
What we build
- Data discovery and a processing inventory.
- The Records of Processing Activities, in your own tooling, maintainable rather than a PDF.
- A retention schedule keyed to Article 15.
- A transfer register carrying Executive Regulation Article 39's five heads.
- Consent capture, storage and withdrawal with proof-of-consent records — applying Article 10 bis correctly, as an exemption from consent only.
- DSAR intake and 45-day service-level tracking, free of charge to the data subject under Executive Regulation Article 16.
- Bilingual privacy notices.
- The Article 14 objection route, with audit log, review queue and a named human reviewer.
- A dual 72-hour breach runbook carrying Executive Regulation Article 30's five report elements and Article 32's three required contents, with bilingual templates, plus one tabletop exercise.
Scope boundaries
- Security remediation and specialist security operations require a separately agreed scope and appropriately qualified delivery support.
- No contract drafting. Reserved under Royal Decree 41/2024, Article 11(3). We publish clause topics as a checklist and refer drafting to a registered legal consultant — unpaid in both directions, because Article 80 makes a referral commission an offence carrying OMR 5,000–20,000.
- No statutory Data Protection Officer designation. Article 20 binds the controller.
- No 24/7 monitoring, security operations centre, on-call or forensics.
- No hosting of your data.
The three dates, kept straight
- 13 February 2023
- Royal Decree 6/2022 in force.
- 5 February 2026
- The Ministerial Decision 34/2024 alignment period ended.
- 7 September 2026
- Royal Decree 68/2026 in force, Official Gazette 1664 — with no transition period.
What changed on 7 September 2026
Article 3's exclusions fall from ten to six. The deleted head that matters most is "execution of a contract to which the data subject is a party" — the exclusion that kept most ordinary Omani commercial processing outside the law entirely. It reappears in new Article 10 bis, but only as an exemption from consent. Records, retention, erasure, security, the DPO duty, breach notification and transfer now all apply to processing that sat outside the law on 6 September 2026.
- Expressly extraterritorial
- The contract exclusion is deleted
- Processors are bound directly for the first time
- New Article 15 — erasure on purpose-end
- New Article 14 — automated-processing safeguards with a human element on review
Implementation needs to account for backups, logs, staging copies and working sets when applying the agreed retention and erasure requirements.
We publish the clause topics. We do not draft the clause: drafting contracts is reserved to registered advocates and legal consultants under Royal Decree 41/2024, Article 11(3).
Controller status: a question for legal review
Questions about how the amended definition of controller applies to a particular legal form should be resolved with your legal adviser and the Ministry before implementation.
What a processor has to build differently
- An erasure job with a purpose-end trigger that covers backups, logs, staging and working sets.
- A sub-processor register.
- A transfer register carrying the five heads in Executive Regulation Article 39.
- An automated-decision audit log, a review queue, and a named human reviewer with a service level.
- A dual 72-hour breach runbook with bilingual templates.
- Contract evidence as a topic checklist you hand to your lawyer.
- A Records of Processing Activities built to Executive Regulation Article 28's ten minimum contents — maintained, not a PDF.
The Data Protection Officer, and the three conditions that actually apply
Executive Regulation Article 34 sets three conditions and no more: qualified for the Article 35 tasks, knowledgeable about the Law, the Regulation and the practices in place, and professionally competent. There is no nationality condition, no residency condition and no employment condition. Article 36 obliges the controller to publish the officer's name and contact details, with a right for every data subject to contact them. Article 20 binds the controller, so a pure processor has no statutory DPO duty of its own.
The penalty ladder, whole
| Failure | Article | Penalty (OMR) |
|---|---|---|
| Processing without explicit consent, or a defective consent request | Article 25, as amended | 500 – 2,000 |
| Failing to appoint a Data Protection Officer (Article 20 duty); processor erasure duty (new Article 15) | Article 26 | 1,000 – 5,000 |
| Automated-processing safeguards (new Article 14) | Article 27, as amended | 5,000 – 10,000 |
| Special-category data, children's data, breach-notification failure, confidentiality | Article 28 | 15,000 – 20,000 |
| Unlawful cross-border transfer | Article 29 | 100,000 – 500,000 |
| Where the offender is a legal person | Article 30 | 5,000 – 100,000 |
| Administrative penalty, per violation and cumulative | Article 32 | up to 2,000 |
The exposure is large and the observed enforcement record is empty. MTCIT has published no fining decisions, no case log and no enforcement statistics, despite Article 7(h) of the Law obliging it to publish periodic reports. Both facts are true and we publish them together.
Figures that circulate, and what the text says
- OMR 15,000–20,000 for failing to appoint a Data Protection Officer
- Wrong. Article 20 imposes the duty; Article 26 penalises it at OMR 1,000–5,000. The 15,000–20,000 band is Article 28 and covers Articles 5, 6, 19 and 21 only.
- Up to OMR 10,000
- Real, but it is the ceiling of the amended Article 27 — not the law's maximum.
- Up to OMR 100,000
- Real. It is the Article 30 ceiling and the Article 29 floor, and it is defensible as a business-facing headline.
- A maximum of OMR 2,000
- Real, but it is the Article 32 administrative cap only — not the law's maximum.
Start a conversation
Discuss a project
PDPL implementation is quoted on application. We do not give legal advice and we do not act as your data protection officer.
- +968 7643 6295English
- +968 9964 1047العربية