Operate data protection + cryptography + privacy alignment per Oman framework + Oman Personal Data Protection Law (Royal Decree 6/2022 effective 13 February 2023). Implement encryption at rest + in transit + with cryptographic key management lifecycle + HSM where appropriate + FIPS 140-2 / 140-3 validated modules. Apply data minimisation + purpose limitation + retention + secure deletion per PDPL. Implement DLP + classification-based protection + cross-border transfer mechanism per PDPL Article 36 (regulator approval required for transfer + adequacy / safeguards / consent). Maintain data subject rights handling + breach notification per PDPL Article 35 (72 hour notification to MTCIT regulator + affected individuals).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.