
As organisations are increasingly relying on digital systems, automated tools and personal data, data protection has become an important part of day to day business operation.
On 3 September 2026, Oman issued Royal Decree No. 68/2026, introducing important amendments to the Personal Data Protection Law (PDPL) promulgated by Royal Decree No. 6/2022. The changes strengthen individual rights, clarify processing obligations, and impose additional compliance requirements on Organisations that collect or process personal data.
In this article, we highlight the key changes, how they impact organisations and at the end we point out to organisations who are affected by the changes.
1. Expanded Territorial Scope
The amended Article 2 expressly provides that the PDPL applies to the processing of personal data of natural persons in Oman, whether the processing takes place inside or outside Oman.
→ Impact: Organisations located outside Oman that process personal data relating to individuals in Oman should assess whether their processing activities fall within the scope of the PDPL.
2. Stronger Consent Requirements
The amended Article 10 reinforces the requirement for express consent before personal data is processed, unless a statutory exception applies. Controllers must also be able to demonstrate that consent was obtained and must clearly identify the controller, processor (if any), processing purposes, and relevant contact details.
→ Impact: Organisations should review consent forms, websites, applications, and registration processes to ensure consent is explicit, documented, and auditable.
3. New Lawful Bases for Processing
Article 10 bis introduces circumstances where processing may occur without consent, including where processing:
→ Impact: Organisations should review and document the legal basis relied upon for each processing activity rather than relying on consent alone.
4. Employee Data and CCTV Processing
New Article 5 bis permits:
→ Impact: Employers and Companies should review HR practices, employee privacy documentation, workplace monitoring arrangements, and CCTV governance procedures.
5. Automated Processing
The amendments introduce a formal definition of automated processing and strengthen protections where decisions are made through automated systems. This is important given the adoption of Artificial Intelligence (AI) models as working systems. Individuals may object to decisions resulting from automated processing, and Organisations must provide human review of challenged decisions.
→ Impact: Organisations using AI, automated decision-making, recruitment screening, admissions systems, profiling, or financial scoring tools should assess governance and review mechanisms.
6. Expanded Definition of Health Data
Health data now expressly includes information relating to an individual's physical, mental, or psychological health, as well as healthcare services provided to that individual.
→ Impact: Healthcare providers, insurers, educational institutions, and employers should reassess how health-related information is classified and protected.
7. Data Retention and Deletion
Article 15 now requires personal data to be deleted immediately once the purpose of processing ends, unless retention is required because of a legal obligation or ongoing dispute.
→ Impact: Organisations should review retention schedules, establish deletion triggers, and identify lawful retention exceptions.
8. Direct Marketing Restrictions
Article 22 requires express consent before sending advertising or marketing communications for commercial purposes.
→ Impact: Businesses engaged in email marketing, SMS campaigns, lead generation, or digital advertising should review their marketing consent mechanisms and records.
Which Organisations Are Most Affected?
The amendments are particularly relevant to:
Compliance Checklist
Organisations should consider the following immediate actions:
- Review consent mechanisms and records.
- Identify lawful bases for processing under Article 10 bis.
- Update privacy notices and internal policies.
- Review employee-data processing and HR procedures.
- Assess CCTV and monitoring arrangements.
- Evaluate AI and automated-processing activities.
- Review health-data handling practices.
- Update data retention and deletion schedules.
- Audit direct marketing and advertising activities.
- Train relevant personnel on the new requirements.
Conclusion
Royal Decree No. 68/2026 represents the most significant update to Oman’s data protection framework since the PDPL was introduced in 2022. While the amendments provide greater flexibility through new lawful processing grounds, they also impose stricter obligations regarding consent, automated decision-making, direct marketing, and data retention.
Organisations should undertake a targeted compliance review to assess the impact of the amendments and implement any necessary updates to policies, processes, contracts, and governance frameworks.
How We Can Help
We assist Organisations with:
Authors:
Shahab Al Bulushi, Managing Partner, GRATA International Oman