Law / Oman

Personal Data Protection Law, breach notification

Royal Decree No. 6/2022, breach notification provision

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 February 2023.

A breach notification rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that suffers a breach leading to the destruction, alteration, disclosure, access, or illegal processing of an individual's personal data in Oman must notify the Ministry and the affected Data Subject, following the procedure the Executive Regulations set; no specific notification timeline is confirmed at primary source.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Royal Decree requires the Controller, in the event of a personal data breach leading to destruction, alteration, disclosure, access, or illegal processing, to notify the Ministry and the Data Subject of the breach, in accordance with the controls and procedures the Executive Regulations set.

As with cross-border transfer, the duty exists in the Decree itself but its timeline, not stated as a fixed number of hours or days in the primary text read, is deferred to the Executive Regulations (Ministerial Decision 34/2024), not read at primary source.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official consolidated Royal Decree text, decree.om

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app