Oman Personal Data Protection Law (Royal Decree 6/2022)
Oman's Personal Data Protection Law (Royal Decree 6/2022), effective February 2023, establishes a comprehensive data protection framework. The Ministry of Transport, Communications, and Information Technology (MTCIT) oversees enforcement. The law covers processing principles, consent requirements, data subject rights, cross-border transfers, breach notification, and data protection officer requirements. Applies to processing of personal data by controllers and processors in Oman. Data localisation requirements for certain categories of data. One of the most comprehensive data protection laws in the Gulf region.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Accountability
| Code | Title |
|---|---|
| PDPL-OM-13 | Records of Processing Activities |
Automated Decisions
| Code | Title |
|---|---|
| PDPL-OM-15 | Automated Decision-Making and Profiling |
Chapter Five — Punishments
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 32 | Entry into Force |
Chapter Four — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 23 | Transitional Provisions |
Chapter One — Definitions and General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
Chapter Three — Rights of the Data Subject
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
Chapter Two — Ministry Duties and Powers
| Code | Title |
|---|---|
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Consent
| Code | Title |
|---|---|
| PDPL-OM-03 | Consent Requirements |
Cross-Border
| Code | Title |
|---|---|
| PDPL-OM-12 | International Data Transfers |
Foundation
| Code | Title |
|---|---|
| PDPL-OM-01 | Scope, Definitions and Applicability |
Incident Response
| Code | Title |
|---|---|
| PDPL-OM-10 | Breach Notification (72 hours) |
Individual Rights
| Code | Title |
|---|---|
| PDPL-OM-06 | Data Subject Rights |
Lawful Basis
| Code | Title |
|---|---|
| PDPL-OM-02 | Lawful Bases for Processing |
Lifecycle
| Code | Title |
|---|---|
| PDPL-OM-08 | Retention and Erasure |
Marketing
| Code | Title |
|---|---|
| PDPL-OM-17 | Direct Marketing and Profiling |
Principles
| Code | Title |
|---|---|
| PDPL-OM-07 | Data Minimisation and Purpose Limitation |
Regulatory
| Code | Title |
|---|---|
| PDPL-OM-18 | Supervision, Enforcement and Penalties |
Risk Management
| Code | Title |
|---|---|
| PDPL-OM-14 | Privacy by Design and Impact Assessment |
Security
| Code | Title |
|---|---|
| PDPL-OM-09 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| PDPL-OM-04 | Sensitive Personal Data Protections |
Special Categories
| Code | Title |
|---|---|
| PDPL-OM-16 | Children and Vulnerable Data Subjects |
Transparency
| Code | Title |
|---|---|
| PDPL-OM-05 | Privacy Notice and Transparency |
Vendor Management
| Code | Title |
|---|---|
| PDPL-OM-11 | Processor Engagements and Contracts |
Your Compliance Coverage
If you comply with Oman Personal Data Protection Law (Royal Decree 6/2022), you already cover:
EU AI Act
33%
15 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
30%
14 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
30%
14 controls mapped
Compare →+ 628 more: South Korea PIPA (28%), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (28%)
See all 631 mapped frameworks ↓Maps to 631 other frameworks
Frequently Asked Questions
What is Oman Personal Data Protection Law (Royal Decree 6/2022)?
Oman Personal Data Protection Law (Royal Decree 6/2022) is a compliance framework from Oman with 23 domains and 46 controls. Oman's Personal Data Protection Law (Royal Decree 6/2022), effective February 2023, establishes a comprehensive data protection framework. The Ministry of Transport, Communications, and Information Technology (MTCIT) oversees enforcement. The law covers processing principles, consent requirements, data subject rights, cross-border transfers, breach notification, and data protection officer requirements. Applies to processing of personal data by controllers and processors in Oman. Data localisation requirements for certain categories of data. One of the most comprehensive data protection laws in the Gulf region. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Oman Personal Data Protection Law (Royal Decree 6/2022) have?
Oman Personal Data Protection Law (Royal Decree 6/2022) has 46 controls organised across 23 domains. The largest domains are Chapter Four — Controller and Processor Obligations (11 controls), Chapter One — Definitions and General Provisions (6 controls), Chapter Five — Punishments (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Oman Personal Data Protection Law (Royal Decree 6/2022) map to?
Oman Personal Data Protection Law (Royal Decree 6/2022) maps to 631 other compliance frameworks. The top mapping partners are EU AI Act (33% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (30% coverage), BS 65000:2014 — Guidance on Organizational Resilience (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Oman Personal Data Protection Law (Royal Decree 6/2022) compliance?
Start your Oman Personal Data Protection Law (Royal Decree 6/2022) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Oman Personal Data Protection Law (Royal Decree 6/2022) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 46 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required