22 Breaches, 20 Complaints: Oman's Data Law Gets Real Numbers
For the first time, Oman's data protection regulator has put numbers behind its enforcement of the Personal Data Protection Law, logging 20 complaints and 22 breach notifications by May 2026 as tougher rules under Royal Decree 68/2026 take hold.
Oman's Personal Data Protection Law has moved from paper to practice. Officials at the Ministry of Transport, Communications and Information Technology (MTCIT) have disclosed that the ministry logged 20 complaints and 22 data breach notifications related to personal data by the end of May 2026, the first detailed enforcement figures published since the law's transition period ended earlier this year, according to Al Roya.
🔑 Key Takeaways
- MTCIT received 20 complaints and 22 data breach notifications tied to personal data protection through the end of May 2026, according to Al Roya.
- The ministry has run more than 15 awareness workshops for government and private-sector bodies since the law came into effect.
- Royal Decree 68/2026 raises penalties for serious breaches to between RO 5,000 and RO 10,000, up from a flat RO 2,000 ceiling under the original 2024 executive regulation.
- New rules require a human to review any AI-driven "automated decision" that affects a person's legal or financial standing.
- The amended law now reaches processing of Omani residents' data carried out outside the country, not just inside it.
📊 The First Real Enforcement Numbers
Since Oman's Personal Data Protection Law (originally issued under Royal Decree 6/2022) finished its transition period on 5 February 2026, compliance has largely been discussed in the abstract, workshops, guidance notes, and legal commentary. That changed this week when Fatima bint Hamad Al-Toby, head of personal data protection at MTCIT, confirmed to Al Roya that the ministry had processed 20 complaints and 22 data breach notifications by the end of May, spanning banking, healthcare, telecommunications, digital platforms, and commercial companies, per the report.
Under the executive regulation issued in 2024, controllers operating in Oman must already notify the ministry within 72 hours of discovering a breach that threatens data subjects' rights. The new figures suggest that rule is being tested in practice rather than sitting unused in a compliance binder.
"The ministry adopts an integrated approach to monitoring compliance, combining awareness, guidance and oversight, with enforcement action taken when violations occur."
- Fatima Al-Toby, Head of Personal Data Protection, Ministry of Transport, Communications and Information Technology
⚖️ What Royal Decree 68/2026 Actually Changed
The enforcement statistics arrive alongside a broader legal upgrade. Royal Decree 68/2026, which amended the original 2022 law, widened the statute's reach so it now also covers processing of Omani residents' personal data that takes place outside the Sultanate, tightened the rules on marketing communications so explicit consent is required before commercial messages go out, and mandated that data be deleted once its original purpose is fulfilled, subject to limited exceptions.
It also raised the financial stakes for non-compliance. Where the 2024 executive regulation capped administrative fines at RO 2,000 regardless of severity, the amended law introduces tiered penalties.
| Violation Type | Fine Under 2024 Regulation | Fine Under Decree 68/2026 |
|---|---|---|
| General processing violations | Up to RO 2,000 | RO 500 - RO 2,000 |
| Serious or major breaches | Not separately tiered | RO 5,000 - RO 10,000 |
Background on the original 2024 breach-notification and penalty framework is available from the ministry's own executive regulation announcement, which set the 72-hour breach-reporting window still in force today.
🤖 Automated Decisions Get a Human Check
Perhaps the most forward-looking change targets artificial intelligence directly. Khalifa bin Marhoon Al-Rahbi, vice chair of the Omani Bar Association, told Al Roya that the amendments require a human element whenever an automated decision is reviewed, so that a person affected by an AI-driven outcome retains the right to challenge it, according to the same report. That matters as more Omani institutions, from banks to government portals, adopt AI-assisted scoring and eligibility tools, and as sovereign AI providers like the one behind DeepAstra's partnership with Z.AI begin hosting AI models on Omani soil, where they too will need to answer to this human-review requirement.
Al-Rahbi also pointed to the law's new consent standard, which shifts the burden of proof onto data controllers and rules out vague, blanket approvals for using someone's personal data.
🏦 Where the Complaints Are Coming From
Al-Toby's account to Al Roya named banking, healthcare, telecommunications, digital platforms, and commercial firms as the sectors generating the complaints and breach reports logged so far, a spread that tracks closely with where Oman's digital transformation has moved fastest, and where personal data volumes have grown alongside it. The ministry says it has run more than 15 awareness workshops and training programmes since the law's enactment, aimed at helping both government bodies and private companies build compliance capacity rather than simply reacting to fines.
That capacity-building push echoes a wider staffing effort across Oman's cyber and data fields; a cohort of specialists highlighted in an earlier graduation of cyber leadership talent reflects the same push to grow a domestic workforce that can handle both cybersecurity and data governance obligations as the market expands.
🌍 Why This Matters for Oman
Laws are only as credible as the numbers behind them, and Oman has spent much of 2026 writing new digital rules, from AI standards to cybercrime penalties to this amended data protection law. The 20 complaints and 22 breach notifications disclosed this week are modest in absolute terms, but they are the first real evidence that MTCIT is actually receiving, processing, and presumably acting on reports rather than administering a law that exists only on the Official Gazette. For businesses in banking, healthcare, and telecom, higher fines and an expanded cross-border scope mean data protection compliance is no longer a box-ticking exercise tied to a single physical office in Muscat. For citizens, the human-review requirement for automated decisions offers a concrete check on how AI tools can be used against them as adoption accelerates. As Oman continues to publish national performance indicators across sectors, this kind of granular enforcement data, rather than sweeping decree language alone, is what will let residents and companies judge whether Vision 2040's digital trust ambitions are being delivered in practice.
Tags
Related Articles
Back to School 2025: How Oman's EdTech Revolution is Transforming Every Classroom
As 700,000 students return to school this August, they're walking into AI-powered classrooms, VR labs, and personalized learning systems. Inside Oman's $400 million education technology transformation.
Oman Unveils National AI Strategy 2025-2030: A Blueprint for Digital Sovereignty
The Ministry of Transport, Communications & IT launches Oman's comprehensive AI strategy, targeting 30,000 AI jobs, $5B economic impact, and positioning the Sultanate as the Gulf's AI innovation hub by 2030.
Oman–India Tech Partnership: Driving Innovation Beyond Borders
Discover how growing technology ties between Oman and India are creating new opportunities, from joint AI projects to IT talent exchange and beyond.