This is a guest blog post written by Aatika Al-Hinai, Mais Al-Hajri, Malak Al-Kharusi, and Mohammed Al-Lawati as part of their Decree Fellowship group project in July 2026.
The Personal Data Protection Law (Royal Decree No. 6/2022) has been in force since February 2023. It is Oman’s first comprehensive data protection statute, and a clear step forward from the single chapter of the Electronic Transactions Law that previously governed the field. Across its 32 articles, the PDPL grants data subjects a genuine set of rights and places clear obligations on controllers, giving the Sultanate a solid foundation to build on.
This policy brief examines that framework through the lens of data subject rights and identifies three areas where targeted refinement would strengthen it. First, the right of access could be broadened so that a copy of one’s data comes with the context needed to judge how it is being used. Second, a limited set of lawful bases could sit alongside consent, freeing consent to do its real work of protecting higher-risk processing. Third, a personal route to compensation could run alongside the Ministry’s enforcement role. Drawing on comparators including the UK GDPR and the Saudi and UAE frameworks, each reform builds on what the PDPL already does rather than reworking it.
As Oman Vision 2040 drives the growth of digital government, e-commerce, and cloud-based enterprise, individuals are increasingly asked to share their data to reach everyday services. Robust data subject rights are what allow them to take part in that digital future with confidence rather than exposure, making the case for reform both timely and central to the Sultanate’s wider economic ambitions.
Introduction
We live in an era where individuals constantly hand over sensitive information to organisations, often without knowing how it will be used, by whom, or for how long. Personal data has become an economic input for countless organisations, and while this has driven real benefits, in the form of more efficient markets and more responsive public services, the risks that come with it cannot be ignored.
The Basic Statute of the Sultanate of Oman already recognises the importance of personal privacy, establishing the inviolability of private life in Article 36. The Omani legislator went further with the Personal Data Protection Law (PDPL), issued by Royal Decree 6/2022 on 9 February 2022 and entering into force a year later. It is Oman’s first comprehensive piece of legislation dedicated to personal data protection, repealing and replacing Chapter 7 of the Electronic Transactions Law (Royal Decree 69/2008), which had governed the subject only in limited terms.
The PDPL runs to 32 articles, the first of which defines the key terms used throughout. It grants a set of rights to the data subject, the natural person identifiable through their personal data, and imposes obligations on the controller, who processes personal data or entrusts a processor to do so on the controller’s behalf. The processor, in turn, carries its own obligations under the law. The PDPL is supplemented by Executive Regulations issued under Ministerial Decision 34/2024, which fill in the detail the primary legislation left for the regulations to specify.
This brief looks at Omani law through the lens of the data subject. The first section sets out the rights the PDPL grants to data subjects, the second looks at where Omani law falls short against leading international standards, and the third sets out reforms to close those gaps.
What Rights Does the PDPL Give Data Subjects?
The PDPL grants data subjects six core rights under Article 11, but their practical strength varies considerably: some are stated in absolute terms, others depend on procedural detail the law defers elsewhere, and at least one presupposes a right the law does not clearly grant. Assessing that variation, rather than simply listing the rights, is the task of this section and the critiques that follow.
The rights granted to data subjects sit at the centre of any data protection framework, and the PDPL builds its own around a single gatekeeping requirement: personal data can only be processed after the data subject has given explicit, written consent. The law treats that consent as the operative condition for everything else, so the rights that follow are largely conditioned on it.
Article 11(a) gives the data subject the right to withdraw consent, bringing the processing relationship to an end. Article 11(b) lets the data subject ask for their data to be updated, amended, or blocked. Article 11(c) establishes the right of access, which matters because, without it, a data subject has no way to check whether their data is accurate or whether the controller has processed it beyond its original purpose (the Executive Regulations add procedural detail here). Article 11(d) grants a right to data portability, the transfer of one’s data to another controller, putting Oman among a small number of jurisdictions to grant a right of this kind. Article 11(e) grants the right to request erasure, subject to one exception for data processed for national archiving purposes. Finally, Article 11(f) entitles a data subject to be notified of any breach affecting their data, along with the action taken in response. Article 11 itself does not set out the procedures for exercising these rights; that detail, again, is left to the Executive Regulations.
Beyond Article 11, Article 12 gives data subjects a route to complain to the Ministry (MTCIT) where they believe their data has been processed unlawfully. The PDPL also imposes obligations on controllers that indirectly reinforce these rights, even though they are not framed as data subject rights themselves: Article 21 requires controllers to keep personal data confidential, Article 22 requires separate written consent before data is used for commercial or marketing purposes, and Article 23 prohibits cross-border transfers that are unlawful or that would harm the data subject.
Where the PDPL Falls Short for Data Subjects
A Right of Access That Doesn’t Go Far Enough
The right of access matters because it lets data subjects work out whether their data is being processed lawfully, and whether they need to exercise any of their other rights. But Article 11(c) of the PDPL only gives data subjects the right to obtain a copy of the personal data being processed. Article 11 also gives rights to amendment, blocking, erasure, and portability, but none of these oblige a controller to explain the broader context in which the data is being processed; those procedures, too, are left to the Executive Regulations.
Compare this with Article 15 of the UK GDPR, which treats access as extending well beyond the data itself. A controller responding to a UK access request must also disclose the purpose of processing, the categories of data involved, the recipients the data has been shared with, the envisaged retention period, the source of the data where it wasn’t obtained from the individual directly, and information about any automated decision-making. These requirements give data subjects what they need to judge whether processing is lawful, understand how their data is being used and shared, and decide whether to exercise their other rights.
This gap matters because several data subject rights turn on information a copy of the data alone won’t reveal. That copy won’t show whether data has been kept longer than necessary, shared with third parties, or used for a purpose it was never collected for: exactly the kind of thing Article 15 of the UK GDPR is designed to expose, and which might justify seeking reassurance, restriction, or objection. Article 12 of the GDPR reinforces this by requiring controllers to make it easy for data subjects to exercise their rights, and to provide information in a concise, transparent, and accessible form. Together, Articles 12 and 15 turn access from a simple entitlement to information into a practical tool that individuals can use to scrutinise how their data is handled. Oman’s narrower approach gives data subjects considerably less transparency over processing, and leaves them with a heavier burden: without that wider picture, spotting non-compliance becomes much harder.
Consent as the Only Lawful Basis
Article 11 of the PDPL makes unambiguous consent the general requirement for processing personal data, and the Executive Regulations (Ministerial Decision 34/2024) set out what that means in practice: consent must be freely given, not forced, given by a person with full legal capacity, and recorded in a form the controller determines, whether in writing or electronically. The law does carve out a small number of situations where consent isn’t required, namely meeting a legal obligation, protecting vital interests, and performing a contract to which the data subject is a party. These are exceptions to the consent requirement rather than alternative lawful bases in their own right, and the distinction matters: a controller falling outside these narrow exceptions has no basis to process data at all, while a data subject has no equivalent right to object to processing that does fall within them.
The comparison with other jurisdictions is telling. The UK GDPR sets out six lawful bases in Article 6, of which consent is only one; it pairs legitimate interests with a mandatory balancing test and gives individuals a right to object under Article 21, so people retain some control even where consent was never sought or given. The UAE’s Federal Decree-Law 45/2021 also recognises grounds beyond consent, including contractual necessity, legal obligation, and the legitimate interests of the controller. Most instructive of all is Saudi Arabia, whose Personal Data Protection Law (PDPL) began life just as consent-centric as Oman’s, before it was amended in 2023 to add legitimate interest as a standalone lawful basis, specifically because the original, consent-only draft proved unworkable for ordinary commercial processing. A regional peer identified the same flaw in its own law, and fixed it through legislation.
Oman’s consent-only structure creates two problems, and both work against the data subject rather than for them. First, requiring consent even for low-risk, routine, and entirely expected processing pushes controllers towards obtaining broad, bundled consent at the very start of a relationship, consent that may be formally valid but is meaningless in substance. Consent given as the price of receiving a service isn’t meaningfully free, and a system that demands consent for everything ends up producing consent worth having for nothing. Second, because the law has no general right to object, the only real control a data subject has is to withdraw a consent that was never truly voluntary to begin with; withdrawing consent for a service you still need is not much of a choice at all.
No Right to Compensation
On paper, the PDPL protects data subjects well. But when a violation actually causes harm, the law sends the data subject to the regulator rather than to a remedy of their own. The Ministry of Transport, Communications and Information Technology (MTCIT) controls enforcement, with the power to fine a controller or pursue criminal sanctions, a deliberate design choice that gives the regulator clear, centralised authority. Where the law falls short is that it gives individuals no direct route to compensation. A data subject can complain to the Ministry under Article 12, but that is their only channel: they have no standing to bring a controller before a court, no independent adjudicator sitting above the regulator, and no way to have a judge rule on whether their rights have been breached. If the Ministry chooses not to act, or simply doesn’t respond, the data subject’s options run out there.
That gap is felt most sharply where the harm is non-material: the distress of losing control of your data, reputational damage, or the exposure of sensitive details. In those cases, a data subject can be left with no personal remedy even where the Ministry does fine the controller. A fine serves the public interest in compliance; it does nothing to make the injured individual whole, and the two are not the same thing. For a law built around protecting the individual, that is a gap worth closing, and not an unusual one to close either: the GDPR and Brazil’s LGPD (Article 42) both give data subjects a direct route to compensation, showing this is a broadly accepted standard rather than a regional one.
Under Article 82 of the GDPR, a person can claim compensation directly from a controller for both material and non-material damage, and Article 79 gives them an effective judicial remedy against that controller on top of any complaint to the regulator. The Court of Justice of the European Union confirmed that this right has real substance: in Case C-300/21 (2023), it held that non-material harm doesn’t need to cross any threshold of seriousness to qualify, though a claimant must still show real damage and a causal link, not merely a breach. Saudi Arabia’s own PDPL takes the same approach: Article 40 lets anyone who suffers damage apply to a competent court for proportionate compensation for material or moral harm, moral harm being exactly the emotional and reputational injury at issue here, and that claim runs independently of any penalty the regulator imposes. The value of the court route isn’t only the payout: it puts an independent judge, rather than the regulator alone, in charge of deciding whether a person’s rights were actually breached.
A recent breach shows why the type of remedy matters. In May 2026, the Canvas learning platform, operated by Instructure, was hacked, exposing the personal data of students across thousands of institutions. The incident was resolved through a private settlement between the company and the attackers, not through any payment to the people whose data was exposed. Cases like this raise a hard question: what remedy should a data subject have when the processor wasn’t obviously at fault? The answer depends on the model. The GDPR’s liability is fault-based: Article 82(3) lets a controller or processor escape compensation if it proves it bears no responsibility for the event that caused the harm, meaning a genuinely blameless processor might avoid paying regardless.
Closing the Gaps: Reforms Centred on the Data Subject
A Right of Access Worth Having
Oman should strengthen the right of access by amending Article 11(c), or the Executive Regulations made under it, so that a copy of personal data comes with the context needed to make that right meaningful. Alongside the data itself, controllers should have to disclose the purpose of processing, the specific recipients, the applicable retention period, the source of the data where it wasn’t obtained from the data subject, and information about any automated decision-making, bringing Oman in line with Article 15 of the UK GDPR.
This matters most in the context of automated decision-making, where people can’t meaningfully assess or challenge a decision without understanding how it was reached. According to the Business and Human Rights Centre, Uber and Ola drivers in the Netherlands couldn’t challenge algorithmic dismissals until the courts confirmed that Article 15(1)(h) of the GDPR entitled them to information about the logic behind decisions that had ended their employment. An Omani worker facing an equivalent automated dismissal would currently have no comparable right. The UAE PDPL recognises a right to object to automated processing, while Saudi Arabia’s PDPL separately requires controllers to inform data subjects of the purpose and legal basis of data collection under Article 4. Neither, however, requires disclosure of the logic underlying automated decisions, so adopting the GDPR’s broader disclosure requirements would place Oman ahead of both regional counterparts.
Importantly, this reform could be implemented through the Executive Regulations rather than the primary legislation, making it one of the more practical recommendations in this brief: amending regulations is generally quicker, and less politically demanding, than amending a statute.
A Right to Compensation and Judicial Remedy
Oman’s framework is a strong foundation, and the fixes needed here are refinements rather than an overhaul. Following Saudi Arabia’s Article 40, and reinforced by Articles 79 and 82 of the GDPR, the law should give data subjects an express right to claim compensation before a competent court for both material and moral harm. That right should run alongside the Ministry’s existing enforcement powers, not replace them. The advantage of this approach is that it builds on rights Oman already has, while keeping the Ministry’s role intact and adding a personal remedy on top. The trade-off is that a court route adds cost and litigation risk for controllers, and requires the slower process of legislative change to put in place.
Oman would also do well to adopt a fault-based system of liability, along the lines of Article 82(3) of the GDPR: if a controller can prove it is not responsible for a violation, it should not have to compensate those affected by it. This offers an answer to the Canvas problem. Where there is no clear evidence that a processor caused or contributed to a violation, the appropriate course is to test whether it was negligent, or otherwise responsible, through a judicial process. Finally, limiting the amount of compensation a controller must pay, as Saudi Arabia’s Article 40 requires, would guard against a “floodgate” situation: controllers would still face real liability, but it would be limited and quantifiable rather than unlimited and unquantifiable.
Beyond Consent: A Safer Lawful Basis
Oman’s reform here should follow the Saudi model. Adding legitimate interests and contractual necessity as affirmative lawful bases, subject to a documented balancing assessment, would take the pressure off consent and let it function as a genuine safeguard for processing that is actually high-risk. The advantages are practical: controllers could manage fraud detection, network security, internal administration, and debt recovery without needing consent that no data subject would meaningfully refuse anyway, freeing enforcement resources to focus on processing that genuinely threatens people’s interests.
The risks, though, are real. Legitimate interest is a flexible standard, assessed by controllers themselves, and European experience shows how far it can be stretched: Meta tried to justify behavioural advertising first as a contractual necessity and then as a legitimate interest, and both arguments were rejected by the European Data Protection Board and the Court of Justice of the European Union. That example is an argument for safeguards rather than against reform: an obligatory, documented legitimate interest assessment, of the kind the UK Information Commissioner’s Office requires and opens to regulatory review, paired with a general right to object under Article 21 of the UK GDPR, would let Oman widen its lawful bases without leaving the data subject any less protected.
Why This Matters for Oman’s Digital Future
Protecting data subject rights is not a footnote to Oman’s digital transformation; it is central to it. As Oman Vision 2040 pushes digital government services, e-commerce, and cloud-based enterprise, ordinary people are increasingly required to hand over personal information to access basic services, often with little visibility into how that data is stored, used, or shared. Meaningful data subject rights, access, correction, erasure, and the ability to withdraw consent, give people real control over that exposure, rather than leaving them dependent on the goodwill of controllers. Without those protections, the same digital economy that Vision 2040 is built on becomes a source of risk rather than opportunity, through data misuse, breaches, and unauthorised disclosure. Strong data subject rights are what let people take part in Oman’s digital future with confidence, rather than vulnerability.
Conclusion
This brief began from a simple proposition: the PDPL exists to balance the interests of individuals who disclose their personal information against those of the organisations that control how it is processed. Before 2022, personal data in Oman was governed by a single chapter of the Electronic Transactions Law; today, it has a dedicated law built around it.
The gaps set out above, around access, consent, and remedies, show where that law still falls short for data subjects. The reforms proposed here would close them, giving data subjects real, usable protection over their own personal data.
Oman has pursued the digital economy as a central plank of Oman Vision 2040, treating it as a key tool for economic diversification away from hydrocarbon revenues. That pursuit has brought with it an expansion of digital government services, telecommunications, and cloud-based enterprise, and, with it, a corresponding rise in the processing of personal data, along with the risks that come with it: misuse, breaches, and unauthorised disclosure by the organisations entrusted with sensitive information. Protecting data subject rights should not be treated as secondary to a thriving Omani economy; the two go hand in hand.
Authors

Aatika Al-Hinai
Queen Mary University of London, United Kingdom
—

Mais Al-Hajri
Sultan Qaboos University, Oman
—

Malak Al-Kharusi
Leeds Beckett University, United Kingdom
—

Mohammed Al-Lawati
University of Liverpool, United Kingdom
—
