Oman Personal Data Protection Law (Royal Decree 6/2022)
Oman's Personal Data Protection Law (Royal Decree 6/2022), effective February 2023, establishes a comprehensive data protection framework. The Ministry of Transport, Communications, and Information Technology (MTCIT) oversees enforcement. The law covers processing principles, consent requirements, data subject rights, cross-border transfers, breach notification, and data protection officer requirements. Applies to processing of personal data by controllers and processors in Oman. Data localisation requirements for certain categories of data. One of the most comprehensive data protection laws in the Gulf region.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Chapter Five — Punishments
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Outsourcing of Personal Information Processing |
| Art. 27 | Penalties for Cross-Border Transfer Violations |
| Art. 32 | Entry into Force |
Chapter Four — Controller and Processor Obligations
| Code | Title |
|---|---|
| Art. 13 | Data Security and Privacy |
| Art. 14 | Direct Data Flows |
| Art. 15 | Cybersecurity Requirements |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 22 | Suspension and Revocation |
| Art. 23 | Transitional Provisions |
Chapter One — Definitions and General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art. 6 | Writing |
Chapter Three — Rights of the Data Subject
| Code | Title |
|---|---|
| Art. 10 | Consent Requirements |
| Art. 11 | Consent Revocation |
| Art. 12 | Data Ownership |
Chapter Two — Ministry Duties and Powers
| Code | Title |
|---|---|
| Art. 7 | Minimum Standards |
| Art. 8 | Data Categories |
| Art. 9 | Free Data Sharing |
Maps to 605 other frameworks
Frequently Asked Questions
What is Oman Personal Data Protection Law (Royal Decree 6/2022)?
Oman Personal Data Protection Law (Royal Decree 6/2022) is a compliance framework from Oman with 5 domains and 28 controls. Oman's Personal Data Protection Law (Royal Decree 6/2022), effective February 2023, establishes a comprehensive data protection framework. The Ministry of Transport, Communications, and Information Technology (MTCIT) oversees enforcement. The law covers processing principles, consent requirements, data subject rights, cross-border transfers, breach notification, and data protection officer requirements. Applies to processing of personal data by controllers and processors in Oman. Data localisation requirements for certain categories of data. One of the most comprehensive data protection laws in the Gulf region. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Oman Personal Data Protection Law (Royal Decree 6/2022) have?
Oman Personal Data Protection Law (Royal Decree 6/2022) has 28 controls organised across 5 domains. The largest domains are Chapter Four — Controller and Processor Obligations (11 controls), Chapter One — Definitions and General Provisions (6 controls), Chapter Five — Punishments (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Oman Personal Data Protection Law (Royal Decree 6/2022) map to?
Oman Personal Data Protection Law (Royal Decree 6/2022) maps to 605 other compliance frameworks. The top mapping partners are BS 65000:2014 — Guidance on Organizational Resilience (50% coverage), South Korea PIPA (46% coverage), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (46% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Oman Personal Data Protection Law (Royal Decree 6/2022) compliance?
Start your Oman Personal Data Protection Law (Royal Decree 6/2022) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Oman Personal Data Protection Law (Royal Decree 6/2022) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required