TRA's New Rule Curbs Spam Calls, Locks Down Your Telecom Data
Oman's Telecommunications Regulatory Authority has issued a formal regulation restricting promotional calls and SMS, banning unauthorised sharing of customer data, and fining violators up to RO 30,000, giving telcos six months to comply.
Oman's Telecommunications Regulatory Authority (TRA) has formally issued a new regulation governing promotional calls, service messages and value-added services, closing nearly two years of public consultation with a rulebook that puts customer data protection at its centre. The regulation, published this week, restricts when marketers can contact people, forces telecom operators to build fraud-detection systems, and bans the sharing of customer information without the regulator's approval.
📋 Key Takeaways
- The TRA issued Decision No. (1511/25/2/36/2026) on the Regulation on Promotional Calls, Service Messages and Value-Added Services, according to Times of Oman.
- Promotional calls and messages are now restricted to 8am-9pm Oman time, and every promotional or service call must show caller ID matching the sender's real commercial or legal name, as Muscat Daily reported.
- Operators cannot share customer data with local or international subscribers or intermediaries without prior TRA approval, and must deploy technical safeguards to protect that data.
- Licensees must build systems to detect and block suspected fraudulent or intrusive calls and messages, including traffic originating from outside Oman, and cooperate with other operators through shared databases.
- Penalties range from RO 500 to RO 30,000 depending on the violation, doubling for repeat offences within a year, according to The Arabian Stories.
- Telecom operators and businesses have six months from the issuance date to bring their systems and contracts into compliance.
🔒 What the Regulation Actually Changes
The rule, formally titled the Regulation on Promotional Calls, Service Messages and Value-Added Services, was first floated as a public consultation back in September 2024, when the TRA cited "the growing use of SMS for marketing and the rise in spam messages causing consumer inconvenience" as the driver behind the planned rules, according to details of that consultation. By February 2026, a senior official confirmed the framework was close to release, telling Oman Tech News that a "brand-new consumer protection regulation is in the works." That draft has now become binding law.
At its core, the regulation is a data protection instrument dressed up as an anti-spam rule. According to Times of Oman, telecommunications licensees are now barred from sharing customer information with local subscribers, international subscribers, or international intermediaries without the TRA's prior written approval, and must put in place "appropriate technical and organisational measures" to safeguard that data. That language echoes obligations already in force under Oman's Personal Data Protection Law, which became fully enforceable on February 5, 2026 when its transition period ended and the Ministry of Transport, Communications and Information Technology (MTCIT) assumed active supervisory powers, according to a compliance analysis published in February. The new TRA regulation effectively extends that data-protection logic specifically into the telecom marketing channel, where most Omani consumers actually experience unwanted contact and potential fraud.
📵 New Rules for Marketers and Operators
Under the regulation, as detailed by Muscat Daily:
- Promotional SMS sender IDs must display a commercial or legal name, and marketing content must be clearly distinguishable from other messages.
- Individual phone numbers can no longer be used to make promotional, service, or value-added calls, closing a loophole often used to dodge caller-ID rules.
- Local and international SMS providers must verify sender identities before messages reach Omani networks, targeting the spoofed sender IDs commonly used in phishing and smishing scams.
- Users must be given an accessible way to block promotional contact entirely, block specific sender IDs or short codes, and report anyone who keeps contacting them after an opt-out.
- A unified database of opt-out requests is required so operators cooperate rather than duplicate consumer complaints across networks.
The regulation also brings value-added services (the premium SMS subscriptions and content services that have drawn consumer complaints in the past) under tighter control, requiring TRA approval and restricting them to authorised purposes only, according to The Arabian Stories.
💰 Penalties and the Compliance Clock
Fines range from RO 500 to RO 30,000 depending on the severity of the breach, with penalties doubling for repeat violations within a single year, and some infractions calculated per sender ID or per day of continued non-compliance, Times of Oman reported. Telecom operators, marketing agencies, banks, and any business that runs SMS or call-based promotional campaigns in Oman now have six months from the regulation's issuance to update their contracts, technical systems, and consent-collection processes.
That timeline puts the practical compliance deadline in February 2027, which will land close to other 2027 regulatory milestones already on Omani businesses' calendars, including the country's phased shift toward mandatory e-invoicing. For compliance and IT teams already juggling data residency, invoicing, and data protection deadlines, this adds one more item: auditing every third-party marketing vendor and SMS gateway contract to confirm the TRA has approved any cross-border data sharing involved.
🇴🇲 Why This Matters for Oman
This regulation is a small but concrete piece of a much larger push. Oman's cybersecurity and data governance apparatus has been building out steadily this year, from the 30 cyber chiefs who graduated in June as the government eyed a $214 million domestic security market to the full enforcement of the Personal Data Protection Law in February. What makes the TRA's new rule notable is that it targets the single channel most ordinary residents actually encounter: the spam call or SMS trying to sell insurance, a loan, or a "prize," some of which double as social engineering attempts to harvest personal data or banking details.
By forcing telecom operators to verify sender identities, block suspicious traffic before it reaches users, and get explicit TRA sign-off before sharing customer data with intermediaries, the regulation closes a gap that sat between telecom licensing rules and data protection law. It also gives residents and businesses a clearer enforcement mechanism, and a six-month runway, to demand accountability the next time an unmarked number calls after 9pm. For a Sultanate building its digital economy toward Vision 2040's 10% GDP contribution target, tightening the basic hygiene of who can contact you, and with what data, is unglamorous but necessary groundwork for public trust in everything built on top of it, from mobile banking to AI-driven customer service.
Tags
Related Articles
Back to School 2025: How Oman's EdTech Revolution is Transforming Every Classroom
As 700,000 students return to school this August, they're walking into AI-powered classrooms, VR labs, and personalized learning systems. Inside Oman's $400 million education technology transformation.
Oman Unveils National AI Strategy 2025-2030: A Blueprint for Digital Sovereignty
The Ministry of Transport, Communications & IT launches Oman's comprehensive AI strategy, targeting 30,000 AI jobs, $5B economic impact, and positioning the Sultanate as the Gulf's AI innovation hub by 2030.
Oman–India Tech Partnership: Driving Innovation Beyond Borders
Discover how growing technology ties between Oman and India are creating new opportunities, from joint AI projects to IT talent exchange and beyond.