Decree Blog https://blog.decree.om Thu, 24 Sep 2026 04:52:08 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1.2 https://i0.wp.com/blog.decree.om/wp-content/uploads/2021/12/favicon-decree.png?fit=32%2C32&ssl=1 Decree Blog https://blog.decree.om 32 32 197035704 Remote Work Under Omani Labour Law https://blog.decree.om/2026/remote-work-under-omani-labour-law/ Thu, 24 Sep 2026 04:50:16 +0000 https://blog.decree.om/?p=90204 Remote work is not new in Oman. The Labour Law issued by Royal Decree 53/2023 already recognised remote work, and employees have been working remotely in practice. Furthermore, Ministerial Decision 523/2023 regarding the governance of remote work provides specific rules on certain aspects of remote work that are not addressed in detail in the Labour Law itself. This blog post outlines the key provisions that govern remote work.

The Labour Law defines remote work as “a work system in which the worker performs his work or duties using information technology and communications within the Sultanate of Oman outside the premises of the establishment whether part-time or full-time”. A key aspect of this definition is that Oman only recognises remote work performed within the country. This is confirmed by Article 2 of Ministerial Decision 523/2023, which prohibits establishments from contracting with an employee outside Oman to perform remote work for the establishment.

In essence, remote work remains subject to all the provisions of the Labour Law, including those on working hours, leave, minimum wage, contract duration and annual increments. Being a remote employee does not deprive an employee of any of their rights under the Labour Law.

On the other hand, nothing in the Labour Law or Ministerial Decision 523/2023 requires an employer to allow employees to work from home, regardless of their personal or family circumstances.

However, Ministerial Decision 523/2023 sets out a few administrative matters that employers need to consider if they choose to allow their employees to work remotely. Employers may use electronic systems to supervise and evaluate remote employees, but they cannot use monitoring methods that violate privacy or use personal data collected for non-work purposes. In certain cases, an employee may disconnect from the employer’s electronic systems.

The decision also requires employers to have written agreements for full-time remote work that address matters such as working hours, technology, performance monitoring, information security, privacy, and occupational safety and health.

It also sets out the circumstances in which an employer can require a part-time remote employee to return to the workplace, such as cybersecurity risks or serious policy breaches.

As remote work becomes increasingly popular, employers and employees are strongly encouraged to familiarise themselves with Ministerial Decision 523/2023. You can read it in full in English at the link below:


]]>
90204
Overtime Work Under Oman’s Labour Law https://blog.decree.om/2026/overtime-work-under-omans-labour-law/ Wed, 16 Sep 2026 04:36:49 +0000 https://blog.decree.om/?p=90202 Overtime is one of the most common sources of dispute between employers and employees in Oman. The Labour Law promulgated by Royal Decree 53/2023 sets out exactly when a worker can be asked to work beyond normal hours, how much extra pay is owed, and the narrow circumstances in which consent isn’t required at all. Here’s what employers and employees both need to know.

Normal Working Hours

Before overtime can even be discussed, it helps to know the baseline. Under article 70, a worker may not be made to work more than 8 actual hours a day or 40 hours a week, excluding rest and meal breaks, and no continuous stretch of work may exceed 6 hours. During Ramadan, working hours for Muslims drop to 6 a day or 30 a week. Any time worked beyond this baseline is what the law treats as overtime.

Consent

Article 71 makes clear that overtime is, in principle, voluntary. The employer may only require additional hours “if the interest of the work so requires,” and the employee’s written consent is needed. The combined total of regular and overtime hours can never exceed 12 hours in a single day, regardless of an agreement between the employer and employee.

Overtime Pay

Where the employee agrees, article 71 sets clear minimum rates:

  • Daytime overtime: basic wage for the extra hours, plus at least 25%.
  • Night-time overtime: basic wage plus at least 50%.
  • Work on the weekly rest day or an official holiday: a cash amount equal to 100% of the employee’s daily basic wage, in addition to the pay for that day itself.

As an alternative to cash, the employer may instead grant time off in lieu, one day of compensatory leave for each day worked on a rest day or holiday.

When Consent Isn’t Needed

Article 72 carves out two narrow exceptions where an employer can require overtime without the employee’s consent:

  1. Routine business necessities: annual stocktaking, budget preparation, closing accounts, or discount sale preparation, but this is capped at 15 days a year unless the authorities approve more.
  2. Emergencies: preventing or repairing damage from an accident, avoiding the loss of perishable goods, or coping with an unusual surge in work, provided the employer notifies the relevant authority within 24 hours.

These exceptions revoke the employee of the right to refuse, so the trade-off is higher pay: 50% extra for daytime hours instead of 25%, 75% instead of 50% for night hours, and 200% of the basic wage plus the day’s own pay for rest days or holidays instead of 100% or two compensatory rest days per day worked rather than one.

Case Law in Practice

A useful clarification comes from Omani case law. In Supreme Court (Labour Circuit) Contestation 766/2017, an employee argued that his daily rest hour should count toward his overtime claim. The court disagreed, confirming that rest and meal periods are excluded from working hours by definition and cannot be counted as overtime.

You can read the Labour law in full in English at the link below:


]]>
90202
The Use of Decrees and Orders by the Basic Statute of the State https://blog.decree.om/2026/royal-decree-vs-royal-order/ Wed, 09 Sep 2026 08:40:47 +0000 https://blog.decree.om/?p=90178 Anyone who reads Omani legislation runs into two similar-sounding instruments: the royal decree and the royal order. Both are issued by the Sultan, but the Basic Statute of the State, in its current 2021 form, uses them for different purposes. The difference is not just naming convention.

According to the Basic Statute of the State, royal decrees are the instrument of lawmaking and institutional structure. They ratify and issue laws, establish or abolish specialised councils, govern local administration, appoint members of Majlis Al-Dawla, and set up the Supreme Judicial Council. Senior appointments, including deputy prime ministers, ministers, undersecretaries, senior judges, and senior military and security officers, are also made by decree, as is the appointment of a prime minister. Royal decrees are, with rare exception, published in the Official Gazette.

Royal orders, by contrast, deal with matters internal to the state rather than lawmaking. For example, article 61 leaves minister’s financial allocations, during and after their term, to a royal order. Furthermore, article 65 provides that the committee responsible for monitoring ministers’ performance is formed by royal order.

Some royal orders are published in the Official Gazette, like the granting of an award for special achievements. However, the majority are never published and remain internal to the state. This is not very effective for certain matters that the Basic Statute of the State reserves for royal orders. For example, the crown prince is appointed by royal order, as is the governance of the Royal Family Council. Due to the significance of the two matters it would have been more effective if they were governed by a public instrument like a royal decree.

In short, watch for decrees when the law changes or an institution is restructured, and orders for royal appointments or internal administration, some published and some not. Neither term is interchangeable with the other, and the gaps between them are worth keeping in mind when reading Omani legislation more broadly.

Everyone is recommended to read the Basic Statute of the State. It is available in full in English at the link below:


]]>
90178
Citizen Rights vs Human Rights in the Basic Statute of the State https://blog.decree.om/2026/citizen-rights-vs-human-rights-in-the-basic-statute-of-the-state/ Tue, 08 Sep 2026 11:34:50 +0000 https://blog.decree.om/?p=90180 The Basic Statute of the State protects both human and citizen rights. Although these two types of rights are connected, they apply to different groups, and this blog post will explain how and list some examples.

Human rights are rights that are available to everyone broadly because they are human. For example, article 18 of the Basic Statute of the State provides that life and dignity are rights of every human, while article 22 provides that every human has a right to security of life. Other human rights include personal freedom in article 23 which is within the provisions of the law. Article 25 also protects individuals from physical or mental torture, or degrading treatment.

On the other hand, citizen rights are rights connected to the Omani citizenship. For example, article 20 protects citizens from being deported, exiled, or prohibited from returning to Oman. Additionally, article 15 further guarantees healthcare for citizens, social security services and aid in emergency, illness, incapacity, and old age in the manner prescribed by the law. Article 16 also guarantees education as a right for every Omani citizen, aiming to develop their knowledge, abilities, and skills.

It is worth noting that non-citizens are not left out of the Basic Statute of the State. Under article 42 every person present in Oman lawfully is granted protection of their person and property under the law, in return for a duty to abide by Omani legislation, values, and respect its traditions.

Moreover, the Sultanate has also ratified the International Covenant on Economic, Social and Cultural Rights in 2020, which extends rights like health and education to everyone, not just citizens, although certain legal exceptions may exist. This causes some tension with articles 15 and 16 of the Basic Statute of the State, which frame healthcare, social security, and education specifically as citizen rights. Furthermore, article 9 of the ICESCR recognises the right of every human to social security. This is significant when considering article 15 of the Basic Statute of the State, which specifically refers to social security for Omani citizens.

Another tension could be seen regarding the right to education. Article 16 of the Basic Statute of the State recognises education as a right limited to citizens. However, Oman is a party to the Convention on the Rights of the Child, which recognises the right of every child to education despite citizenship. This creates an interesting legal question on whether the wording of the Basic Statute of the State truly reflects Oman’s international obligations.  

However, article 93 provides an important connection between domestic law and international treaties, as it gives ratified treaties the force of law. This means that Oman’s international obligations can work alongside the rights and protections provided under the Basic Statute of the State.

In conclusion, the distinction between human rights and citizen rights creates an interesting question, and this article demonstrated that the protection of human rights in Oman involves balancing national legislation with international obligations.

It is highly recommended for everyone to make themselves familiar with both categories of rights, and understand how they are protected in the Sultanate of Oman. You can read the Basic Statute of the State in full at the link below:


]]>
90180
New Amendments to the Personal Data Protection Law https://blog.decree.om/2026/new-amendments-to-the-personal-data-protection-law/ Mon, 07 Sep 2026 11:21:12 +0000 https://blog.decree.om/?p=90154 The Personal Data Protection Law originally issued under Royal Decree 6/2022 was amended for the first time last week by Royal Decree 68/2026. This blog post will highlight the key amendments made to the PDPL.

A key substantive change can be seen in article 5bis which allows a controller to process its own staff data, including biometric data such as fingerprints, without the need to obtain a permit from the ministry.

Article 14 grants data subjects a new right to object to decisions made through automated processing, for example, filtering of CVs for job applications, and to require the controller to bring in a human to review the decision.

Moreover, article 15 imposes a new obligation on controllers and processors to erase personal data as soon as its processing purpose ends, subject to narrow exceptions, like an existing dispute or a legal obligation.

Article 22 strengthens consent requirements by requiring explicit consent for marketing purposes, and article 10 provides a new list of specifications for the request for consent to process personal data.

The amendment includes several other substantive changes relating to definitions, territorial scope, consent, direct marketing, and fines.

This amendment has already entered into force. You can read it in full in English at the link below:


]]>
90154
Mineral Resources Law Amended https://blog.decree.om/2026/mineral-resources-law-amended/ Mon, 07 Sep 2026 10:35:51 +0000 https://blog.decree.om/?p=90151 This week’s issue of the Official Gazette included Royal Decree 69/2026 Amending Some Provisions of the Mineral Resources Law. The amendment includes changes to how licences are granted, the conditions for granting a concession, and the penalties for violating the law.

Under the previous law, auctions were only mandatory for concession agreements, and ordinary prospecting and exploitation licences could be granted after the ministry simply verified the applicant’s technical and financial standing. Now, prospecting and exploitation licences must not be granted except by way of auction, though the ministry retains a narrow exception allowing it to assign some mining sites directly.

The previous law required a concession to run for 20 to 30 years, cover at least 5 square kilometres, and be backed by both an economic feasibility study and an environmental impact assessment before it could be granted. The amended law drops all four of these requirements, leaving only the applicant’s technical competence and financial solvency, and the need to specify technical and financial supervision arrangements for the site.

Penalties for illegal extraction have also been simplified. Before, a licensee who deliberately mined outside their own licensed limits actually faced a tougher punishment than someone with no licence at all: imprisonment plus a fine of 50,000 to 150,000 Rial Omani, or just one of the two. Now both offences carry the same fine, 20,000 to 100,000 Rial Omani, but imprisonment of one to three years is compulsory.

These are only some of the key changes made by Royal Decree 69/2026, which enters into force today. You can read it in full in English at the link below:


]]>
90151
Introducing: Decree Graph https://blog.decree.om/2026/introducing-decree-graph/ Mon, 07 Sep 2026 03:35:43 +0000 https://blog.decree.om/?p=90143 We are launching today Decree Graph—a new feature on Decree that shows the status of every law, royal decree, and ministerial decision on Decree and how it connects to other legislation.

Using the Decree Graph, you can now easily determine if the legislation you are currently reading is repealed or valid, and quickly locate regulations issued pursuant to the legislation in question.

When viewing any legislation page on Decree, a status label will now be displayed on the Ask Lex button located in the corner of the page. Clicking this label opens the new Graph tab, which explains the status of the item, provides a link to the consolidated version of the law where one is available, and lists all the connections of the item. Decree Graph is also available on Arabic Decree and in the document menu of the Decree app on iOS and Android.

Decree Graph is available to Decree members whose subscription bundle includes Lex AI. You can try it by logging into Decree and viewing any law, such as the Personal Data Protection Law.

]]>
90143
Legal Requirements to Set Up and Run an LLC in Oman https://blog.decree.om/2026/legal-requirements-to-set-up-and-run-an-llc-in-oman/ Sun, 06 Sep 2026 03:28:13 +0000 https://blog.decree.om/?p=90128 The limited liability company (LLC) is the default vehicle for anyone starting a business in Oman, and for good reason, since the shareholders’ liability stops at the value of their shares. But that protection is not automatic. It comes from a body of rules in the Commercial Companies Law and its executive regulation. This post walks through what the law requires to set an LLC up, and what it requires to keep running one.

Who can form one, and with what

Under article 234 of the Commercial Companies Law, an LLC is formed by no fewer than two and no more than 50 persons, natural or legal, and each of them is liable for the company’s debts only up to the value of their shares. If there is only one owner, article 291 provides a separate but closely related vehicle, the one-person company, which is in substance an LLC with a single shareholder. A natural person may own only one of these, so a founder cannot spin up a separate one-person company for every venture.

Under the law, the name of the company can be the shareholder’s name or any word or phrase, provided it does not mislead as to the company’s objectives or the identity of its owners, and requires that wherever the name appears it is followed by “limited liability company” or “LLC”. Check availability with the Ministry of Commerce, Industry, and Investment Promotion before settling on anything, under article 40, a registered name cannot be used by another merchant in the same line of business, though two companies in genuinely different fields can carry similar names.

In terms of capital, it is divided into shares of equal value. Article 239 allows contributions in cash or in kind, but not in services or labour, because founders often plan for one partner to contribute effort rather than money. That works in a partnership. It does not work in an LLC. However, where a contribution is in kind, article 242 requires its type, location, and value to be set out in a report prepared by a valuation office or an auditor licensed in Oman, and if the value turns out to have been inflated, the contributing shareholder must pay the difference to the company in cash out of his own pocket.

Getting registered

Once the shareholders have settled the constitutive documents, they have 30 days to apply to register the company with the Registrar. The application goes through the Ministry’s electronic system, and article 87 of the Commercial Companies Regulation requires it to be accompanied by the constitutive contract, the minutes of the partners’ meeting where one of the partners is a legal person, and identity documents for the partners and managers. Any later amendment to the constitutive documents follows the same route within the same 30 days.

The constitutive contract must contain:

  • The name and principal place of business.
  • The capital and the breakdown between cash and in-kind shares.
  • The shareholders with their nationalities and shareholdings.
  • The company’s objectives, its date of establishment and duration.
  • The manager’s name and powers.
  • The start and end of the financial year.
  • The body that will resolve disputes between the shareholders.
  • The majorities needed to pass resolutions at the shareholders’ meeting.

These constitutive documents must all be written in Arabic; otherwise, they are considered void. The company then acquires legal personality only from the date of its registration, so anyone who does business in the company’s name before that point is personally liable for the obligations he creates.

If one of the shareholders is not Omani

Under the Foreign Capital Investment Law, no foreigner may carry out an investment activity in Oman except after obtaining a licence from the Ministry of Commerce, Industry, and Investment Promotion. Article 12bis of its executive regulation also requires the company to appoint at least one Omani worker no longer than a year from the start of its commercial activity, to register that worker with the Social Protection Fund, and to comply with the Omanisation percentages if set for its sector.

Running the company

For the company, the management is entrusted to one or more managers who must be natural persons, drawn from the shareholders or from outside, and appointed either in the constitutive documents or by a resolution of the shareholders. Removing a manager requires a resolution of shareholders owning three quarters of the capital, and that same resolution must appoint his replacement, so the shareholders cannot vote a manager out and leave the seat empty.

Ten per cent of the company’s net profits each year must be set aside by the managers, after tax, into a legal reserve, and to keep doing so until that reserve reaches one third of the capital. It cannot be paid out as dividends; it exists to absorb accumulated losses.

An auditor plays a huge role in an LLC, but not every LLC needs one. They are only needed when a company has more than seven shareholders, when its capital exceeds 50,000 Rial Omani, when the constitutive documents call for one, or when its shareholders representing at least a fifth of the capital ask for one. A small company starting out will often fall outside all four, though it will still need audited accounts for tax purposes.

Things to keep in mind for later

Shares in an LLC are not tradable, so bringing in a new partner means transferring existing shares, and the other shareholders have a right of pre-emption which they may exercise within 45 days by depositing the full price. Increasing or reducing the capital requires a unanimous shareholder resolution, and a reduction gives creditors 30 days to object. Once the first financial year closes, a reporting cycle begins. The managers have 90 days to prepare the financial statements, and 180 days from the year-end to circulate them to the shareholders with the notice of the meeting that approves them. Filing obligations also continue past incorporation since resolutions and records must reach the Ministry of Commerce, Industry, and Investment Promotion within seven days, and the company has seven working days to produce audited financial statements when the ministry asks for them.

In short

An LLC is not difficult to set up in Oman, but the protection it offers is conditional on doing a handful of things properly. When setting up a company, it is always good to check the Commercial Companies Law and understand all requirements that apply to you depending on your size or the type of establishment.

You can read the Commercial Companies Law in full in English at the link below:


]]>
90128
Does the Use of Copyrighted Content to Train AI Models Violate the Law? https://blog.decree.om/2026/does-the-use-of-copyrighted-content-to-train-ai-models-violate-the-law/ Sun, 06 Sep 2026 03:22:45 +0000 https://blog.decree.om/?p=90015 This is a guest blog post written by Nouf Al-Hoqani, Rayan Al-Hasni, Zahra Al-Balushi, and Zayd Al-Harrasi as part of their Decree Fellowship group project in July 2026.

Artificial intelligence has advanced significantly in recent years. AI systems can now generate text, compose music, and create images and other works. These advancements have also raised significant legal concerns, particularly regarding intellectual property rights. AI developers often use copyrighted materials to train AI models, raising the risk that these models will create counterfeit or derivative works belonging to other people. This issue has not yet been addressed under Omani law: there is no specific legal provision or regulation governing the relationship between AI and intellectual property. By contrast, jurisdictions such as the United Kingdom, the United States, and the European Union have already begun to grapple with the problem and to explore potential solutions. Oman should therefore begin addressing this issue, drawing on the experience of these jurisdictions to inform its own approach.

The connection between artificial intelligence and intellectual property arises from AI’s growing capacity to create works similar to those made by human artists, such as images and music. This capacity makes it easier to reproduce the works of well-known artists and imitate their distinctive styles, raising the question of whether such conduct amounts to intellectual property theft or should instead be regarded as merely drawing inspiration from existing works.

The Omani Legal Framework

When examining Omani law at the intersection of artificial intelligence and intellectual property, the most prominent issue is the infringement of intellectual property rights by AI, and how such infringement, though contrary to law and ethics, has become so simplified and widely accessible that it is now available to anyone with the click of a button. This section examines how Omani law treats AI activities that rely on imitating or using copyrighted materials, guided by a single question: does Omani law treat the training of AI systems on copyrighted material as a violation of the law, or as a permissible exception?

Training an AI system involves compiling a large database of the data on which the model is trained, including words, letters, shapes, patterns, and colours, drawn from sources such as websites, books, articles, images, videos, music, and other works. Once this data is collected, it is presented to the system, which learns to recognise statistical patterns in it, analyse them, and generate similar patterns or predict the most likely next one through repeated exposure. Since this process requires assembling a dedicated database, the developer must first identify the data to include, download or copy it, and then store that copy electronically for later use in generating derivative outputs.

These steps matter because the Copyright and Neighbouring Rights Law, reserves the economic rights in a work to its author. Article 6 grants the author the right to reproduce the work, one of the most significant rights the law protects, as well as the right to adapt it into other forms, create derivative works, and dispose of the work in both its original and copied forms. Article 1 defines reproduction broadly as making one or more copies identical to the original, whether directly or indirectly, “by any means such as printing, photocopying, recording, or permanent or temporary electronic storage.” This definition captures precisely what AI training involves: the electronic storage of copyrighted works, a step that is fundamental to building a training database but is reserved exclusively to the author unless the author grants that right to another party by agreement.

There are, in principle, two ways an AI developer might avoid infringing copyright in this process. The first is to obtain the author’s consent to use the work for training purposes; although the law does not address this scenario explicitly, such permission would, as in other contexts, allow the work to be used lawfully. The second is for the training process to fall within Chapter Five of the law, which sets out the free uses of works. Article 20 lists uses that do not require the author’s consent, including use for explanation or critique, educational and informational purposes, copying by archives or public libraries, and use to illustrate a concept in a study, provided that certain conditions relating to the quantity used, the manner of use, and the absence of any direct or indirect financial gain are met. Article 20 makes no mention of AI or its training on copyrighted material. We therefore conclude that training an AI system without the author’s permission, and without relying on works in the public domain, constitutes a clear violation of copyright under Omani law. This gap, the complete absence of any law or regulation addressing AI’s use of copyrighted material, creates considerable uncertainty about how Omani law will respond to these issues as the technology continues to advance.

Comparison with Other Jurisdictions

The European Union offers a significant comparative model for Oman, having been the first jurisdiction to establish a comprehensive legal framework for artificial intelligence through the Artificial Intelligence Act (Regulation (EU) 2024/1689). The Act creates a framework intended to build trust in AI technology while protecting human rights and safety. Although it permits text and data mining for the training of general-purpose AI (GPAI) systems, this mechanism is subject to strict conditions and does not give AI developers a free pass to use copyrighted data. The Act requires generative AI providers to comply with existing EU copyright law, imposes transparency obligations regarding the content used to train AI models, and gives rights holders the option to opt out of having their content used for training.

Because GPAI providers require large datasets that may contain copyrighted material, questions arise over whether such use might constitute infringement. The EU addresses this largely through Directive (EU) 2019/790 on Copyright in the Digital Single Market, which introduced text and data mining exceptions under Articles 3 and 4. Article 3 permits research organisations to use protected content lawfully but excludes commercial or industrial uses. Article 4 allows other institutions to reproduce and extract data, subject to an opt-out mechanism that allows rights holders to exclude their work by ‘machine-readable’ means. What qualifies as machine-readable has been contested, notably in the German case Kneschke v LAION, in which a non-profit organisation used Kneschke’s copyrighted content to build an AI training dataset. The court rejected the copyright claim on the basis that the use fell within the text and data mining exception for scientific research, and held that a reservation expressed only in ordinary language was not sufficiently machine-readable. An appeal is pending.

Article 53(1)(d) of the Act further requires generative AI providers to publish a sufficiently detailed summary of the content used to train their models, and Recital 107 explains that this transparency requirement is intended to support copyright holders in exercising their rights. Even so, uncertainty remains over how far the existing text and data mining exceptions extend to AI training, and EU member states continue to debate whether the current framework adequately addresses the scale and complexity of the practice.

Most member states nonetheless favour monitoring and clarifying the existing framework rather than introducing new legislation immediately, given the continued novelty of generative AI. This cautious approach is instructive for Oman, which may similarly benefit from clarifying and monitoring its existing copyright principles rather than enacting an entirely new framework at this stage.

The United States has not enacted a comprehensive federal AI statute; regulation instead derives from a mix of executive orders, existing sectoral laws applied to AI, and state legislation. In Thomson Reuters v Ross Intelligence (2025), the court rejected a fair use defence where Ross had engaged a third party, LegalEase, to produce training data that substantially copied headnotes from Thomson Reuters’ Westlaw platform. The court found that Ross had directly copied thousands of these headnotes and rejected fair use primarily because Ross intended to use the resulting AI tool to compete directly with Westlaw, a factor the court held weighed decisively against fair use.

By contrast, in Bartz v Anthropic (2025), Anthropic had trained its Claude models using a mix of purchased and pirated books to build a permanent digital library, arguing that the books were essential to training its models. The court found that Anthropic’s use of purchased books constituted fair use, but that its use of pirated copies did not.

The US approach is therefore highly fact-specific, with outcomes varying case by case, and indicates that fair use may apply, but only within certain limits. The EU, by contrast, takes a legislative approach through the text and data mining exception in Directive (EU) 2019/790.

Jurisdictions aside from the EU and the USA have taken different approaches. The United Kingdom, for example, has no broad copyright exception permitting commercial AI training on protected works, although proposals for a text and data mining exception remain under discussion.

These divergent approaches show that there is no settled international consensus on whether copyrighted content may be used to train AI systems. Oman therefore has no single international model to follow and should instead weigh the interests of copyright holders against the goal of supporting AI development in determining its own approach.

Recommendations

The existing exceptions under Article 20 are tied to non-commercial, educational, or family contexts. We recommend amending Article 20 to introduce a new AI training clause permitting commercial entities to use copyrighted content for AI training, provided they have lawful access to that content, whether through licensing, subscription, or other authorised means. This carve-out is necessary because AI development in Oman is largely a commercial activity; without it, a company would remain excluded from the exception even where it has lawful access to the content it seeks to use. At the same time, original creators may face heightened competitive risk, as AI-generated content trained on their work could saturate the market with similar output and reduce demand for their future work.

Oman may also wish to adopt a gradual approach to regulating AI training on copyrighted content, rather than introducing a comprehensive AI-IP framework immediately, given that the technology remains relatively new and not yet fully understood. Instead, Oman should clarify the existing copyright law to specify the circumstances under which AI training can use protected work without infringing copyright, potentially through a text and data mining exception modelled on the EU approach, paired with an effective opt-out mechanism allowing copyright holders to reserve their work from AI training. Oman should also impose transparency obligations requiring AI developers to disclose the sources and content used to develop their systems, strengthening copyright holders’ ability to identify and enforce their rights without imposing an outright prohibition on the use of their content for AI training. Given the rapid development of generative AI and the current uncertainty in copyright law, these recommendations would allow Oman to protect copyright holders’ interests while continuing to encourage technological innovation.

These reforms also carry risks. A broad text and data mining exception could weaken copyright protection by allowing developers to use large quantities of copyrighted material, reducing copyright holders’ control over their work and its economic value. An opt-out mechanism may be difficult to enforce where ownership is unclear or content originates outside the country. Strict transparency requirements could impose high compliance costs on AI providers, potentially discouraging international companies from operating in Oman. There is also a risk that legislating before international approaches have stabilised could produce requirements that quickly become outdated.

Conclusion

Despite the risks of reform, the absence of regulation carries the greater risk: legal uncertainty. Without clear governance over whether copyrighted content can be used to train AI, both copyright holders and system developers face uncertainty in determining whether their conduct is lawful, which in turn complicates innovation in Oman. A carefully defined text and data mining exception would not eliminate copyright protection; rather, it would establish predictable circumstances in which works may be used, while preserving authors’ right to opt out. The goal should not be to eliminate all risk, an unrealistic aim, but to regulate use and provide greater certainty while respecting copyright holders’ rights. This is particularly important if Oman seeks to attract AI investment and build a competitive digital economy.

Authors
Nouf Al-Hoqani
University of Manchester, United Kingdom

—

Rayan Al-Hasni
Sultan Qaboos University, Oman

—

Zahra Al-Balushi
Modern College of Business and Science, Oman

—

Zayd Al-Harrasi
Nottingham Trent University, United Kingdom

—

]]>
90015
Data Subject Rights Under Oman’s PDPL: Where the Law Falls Short, and How to Fix It https://blog.decree.om/2026/data-subject-rights-under-omans-pdpl-where-the-law-falls-short-and-how-to-fix-it/ Sun, 06 Sep 2026 03:18:51 +0000 https://blog.decree.om/?p=90024 This is a guest blog post written by Aatika Al-Hinai, Mais Al-Hajri, Malak Al-Kharusi, and Mohammed Al-Lawati as part of their Decree Fellowship group project in July 2026.

The Personal Data Protection Law (Royal Decree No. 6/2022) has been in force since February 2023. It is Oman’s first comprehensive data protection statute, and a clear step forward from the single chapter of the Electronic Transactions Law that previously governed the field. Across its 32 articles, the PDPL grants data subjects a genuine set of rights and places clear obligations on controllers, giving the Sultanate a solid foundation to build on.

This policy brief examines that framework through the lens of data subject rights and identifies three areas where targeted refinement would strengthen it. First, the right of access could be broadened so that a copy of one’s data comes with the context needed to judge how it is being used. Second, a limited set of lawful bases could sit alongside consent, freeing consent to do its real work of protecting higher-risk processing. Third, a personal route to compensation could run alongside the Ministry’s enforcement role. Drawing on comparators including the UK GDPR and the Saudi and UAE frameworks, each reform builds on what the PDPL already does rather than reworking it.

As Oman Vision 2040 drives the growth of digital government, e-commerce, and cloud-based enterprise, individuals are increasingly asked to share their data to reach everyday services. Robust data subject rights are what allow them to take part in that digital future with confidence rather than exposure, making the case for reform both timely and central to the Sultanate’s wider economic ambitions.

Introduction

We live in an era where individuals constantly hand over sensitive information to organisations, often without knowing how it will be used, by whom, or for how long. Personal data has become an economic input for countless organisations, and while this has driven real benefits, in the form of more efficient markets and more responsive public services, the risks that come with it cannot be ignored.

The Basic Statute of the Sultanate of Oman already recognises the importance of personal privacy, establishing the inviolability of private life in Article 36. The Omani legislator went further with the Personal Data Protection Law (PDPL), issued by Royal Decree 6/2022 on 9 February 2022 and entering into force a year later. It is Oman’s first comprehensive piece of legislation dedicated to personal data protection, repealing and replacing Chapter 7 of the Electronic Transactions Law (Royal Decree 69/2008), which had governed the subject only in limited terms.

The PDPL runs to 32 articles, the first of which defines the key terms used throughout. It grants a set of rights to the data subject, the natural person identifiable through their personal data, and imposes obligations on the controller, who processes personal data or entrusts a processor to do so on the controller’s behalf. The processor, in turn, carries its own obligations under the law. The PDPL is supplemented by Executive Regulations issued under Ministerial Decision 34/2024, which fill in the detail the primary legislation left for the regulations to specify.

This brief looks at Omani law through the lens of the data subject. The first section sets out the rights the PDPL grants to data subjects, the second looks at where Omani law falls short against leading international standards, and the third sets out reforms to close those gaps.

What Rights Does the PDPL Give Data Subjects?

The PDPL grants data subjects six core rights under Article 11, but their practical strength varies considerably: some are stated in absolute terms, others depend on procedural detail the law defers elsewhere, and at least one presupposes a right the law does not clearly grant. Assessing that variation, rather than simply listing the rights, is the task of this section and the critiques that follow.

The rights granted to data subjects sit at the centre of any data protection framework, and the PDPL builds its own around a single gatekeeping requirement: personal data can only be processed after the data subject has given explicit, written consent. The law treats that consent as the operative condition for everything else, so the rights that follow are largely conditioned on it.

Article 11(a) gives the data subject the right to withdraw consent, bringing the processing relationship to an end. Article 11(b) lets the data subject ask for their data to be updated, amended, or blocked. Article 11(c) establishes the right of access, which matters because, without it, a data subject has no way to check whether their data is accurate or whether the controller has processed it beyond its original purpose (the Executive Regulations add procedural detail here). Article 11(d) grants a right to data portability, the transfer of one’s data to another controller, putting Oman among a small number of jurisdictions to grant a right of this kind. Article 11(e) grants the right to request erasure, subject to one exception for data processed for national archiving purposes. Finally, Article 11(f) entitles a data subject to be notified of any breach affecting their data, along with the action taken in response. Article 11 itself does not set out the procedures for exercising these rights; that detail, again, is left to the Executive Regulations.

Beyond Article 11, Article 12 gives data subjects a route to complain to the Ministry (MTCIT) where they believe their data has been processed unlawfully. The PDPL also imposes obligations on controllers that indirectly reinforce these rights, even though they are not framed as data subject rights themselves: Article 21 requires controllers to keep personal data confidential, Article 22 requires separate written consent before data is used for commercial or marketing purposes, and Article 23 prohibits cross-border transfers that are unlawful or that would harm the data subject.

Where the PDPL Falls Short for Data Subjects

A Right of Access That Doesn’t Go Far Enough

The right of access matters because it lets data subjects work out whether their data is being processed lawfully, and whether they need to exercise any of their other rights. But Article 11(c) of the PDPL only gives data subjects the right to obtain a copy of the personal data being processed. Article 11 also gives rights to amendment, blocking, erasure, and portability, but none of these oblige a controller to explain the broader context in which the data is being processed; those procedures, too, are left to the Executive Regulations.

Compare this with Article 15 of the UK GDPR, which treats access as extending well beyond the data itself. A controller responding to a UK access request must also disclose the purpose of processing, the categories of data involved, the recipients the data has been shared with, the envisaged retention period, the source of the data where it wasn’t obtained from the individual directly, and information about any automated decision-making. These requirements give data subjects what they need to judge whether processing is lawful, understand how their data is being used and shared, and decide whether to exercise their other rights.

This gap matters because several data subject rights turn on information a copy of the data alone won’t reveal. That copy won’t show whether data has been kept longer than necessary, shared with third parties, or used for a purpose it was never collected for: exactly the kind of thing Article 15 of the UK GDPR is designed to expose, and which might justify seeking reassurance, restriction, or objection. Article 12 of the GDPR reinforces this by requiring controllers to make it easy for data subjects to exercise their rights, and to provide information in a concise, transparent, and accessible form. Together, Articles 12 and 15 turn access from a simple entitlement to information into a practical tool that individuals can use to scrutinise how their data is handled. Oman’s narrower approach gives data subjects considerably less transparency over processing, and leaves them with a heavier burden: without that wider picture, spotting non-compliance becomes much harder.

Consent as the Only Lawful Basis

Article 11 of the PDPL makes unambiguous consent the general requirement for processing personal data, and the Executive Regulations (Ministerial Decision 34/2024) set out what that means in practice: consent must be freely given, not forced, given by a person with full legal capacity, and recorded in a form the controller determines, whether in writing or electronically. The law does carve out a small number of situations where consent isn’t required, namely meeting a legal obligation, protecting vital interests, and performing a contract to which the data subject is a party. These are exceptions to the consent requirement rather than alternative lawful bases in their own right, and the distinction matters: a controller falling outside these narrow exceptions has no basis to process data at all, while a data subject has no equivalent right to object to processing that does fall within them.

The comparison with other jurisdictions is telling. The UK GDPR sets out six lawful bases in Article 6, of which consent is only one; it pairs legitimate interests with a mandatory balancing test and gives individuals a right to object under Article 21, so people retain some control even where consent was never sought or given. The UAE’s Federal Decree-Law 45/2021 also recognises grounds beyond consent, including contractual necessity, legal obligation, and the legitimate interests of the controller. Most instructive of all is Saudi Arabia, whose Personal Data Protection Law (PDPL) began life just as consent-centric as Oman’s, before it was amended in 2023 to add legitimate interest as a standalone lawful basis, specifically because the original, consent-only draft proved unworkable for ordinary commercial processing. A regional peer identified the same flaw in its own law, and fixed it through legislation.

Oman’s consent-only structure creates two problems, and both work against the data subject rather than for them. First, requiring consent even for low-risk, routine, and entirely expected processing pushes controllers towards obtaining broad, bundled consent at the very start of a relationship, consent that may be formally valid but is meaningless in substance. Consent given as the price of receiving a service isn’t meaningfully free, and a system that demands consent for everything ends up producing consent worth having for nothing. Second, because the law has no general right to object, the only real control a data subject has is to withdraw a consent that was never truly voluntary to begin with; withdrawing consent for a service you still need is not much of a choice at all.

No Right to Compensation

On paper, the PDPL protects data subjects well. But when a violation actually causes harm, the law sends the data subject to the regulator rather than to a remedy of their own. The Ministry of Transport, Communications and Information Technology (MTCIT) controls enforcement, with the power to fine a controller or pursue criminal sanctions, a deliberate design choice that gives the regulator clear, centralised authority. Where the law falls short is that it gives individuals no direct route to compensation. A data subject can complain to the Ministry under Article 12, but that is their only channel: they have no standing to bring a controller before a court, no independent adjudicator sitting above the regulator, and no way to have a judge rule on whether their rights have been breached. If the Ministry chooses not to act, or simply doesn’t respond, the data subject’s options run out there.

That gap is felt most sharply where the harm is non-material: the distress of losing control of your data, reputational damage, or the exposure of sensitive details. In those cases, a data subject can be left with no personal remedy even where the Ministry does fine the controller. A fine serves the public interest in compliance; it does nothing to make the injured individual whole, and the two are not the same thing. For a law built around protecting the individual, that is a gap worth closing, and not an unusual one to close either: the GDPR and Brazil’s LGPD (Article 42) both give data subjects a direct route to compensation, showing this is a broadly accepted standard rather than a regional one.

Under Article 82 of the GDPR, a person can claim compensation directly from a controller for both material and non-material damage, and Article 79 gives them an effective judicial remedy against that controller on top of any complaint to the regulator. The Court of Justice of the European Union confirmed that this right has real substance: in Case C-300/21 (2023), it held that non-material harm doesn’t need to cross any threshold of seriousness to qualify, though a claimant must still show real damage and a causal link, not merely a breach. Saudi Arabia’s own PDPL takes the same approach: Article 40 lets anyone who suffers damage apply to a competent court for proportionate compensation for material or moral harm, moral harm being exactly the emotional and reputational injury at issue here, and that claim runs independently of any penalty the regulator imposes. The value of the court route isn’t only the payout: it puts an independent judge, rather than the regulator alone, in charge of deciding whether a person’s rights were actually breached.

A recent breach shows why the type of remedy matters. In May 2026, the Canvas learning platform, operated by Instructure, was hacked, exposing the personal data of students across thousands of institutions. The incident was resolved through a private settlement between the company and the attackers, not through any payment to the people whose data was exposed. Cases like this raise a hard question: what remedy should a data subject have when the processor wasn’t obviously at fault? The answer depends on the model. The GDPR’s liability is fault-based: Article 82(3) lets a controller or processor escape compensation if it proves it bears no responsibility for the event that caused the harm, meaning a genuinely blameless processor might avoid paying regardless.

Closing the Gaps: Reforms Centred on the Data Subject

A Right of Access Worth Having

Oman should strengthen the right of access by amending Article 11(c), or the Executive Regulations made under it, so that a copy of personal data comes with the context needed to make that right meaningful. Alongside the data itself, controllers should have to disclose the purpose of processing, the specific recipients, the applicable retention period, the source of the data where it wasn’t obtained from the data subject, and information about any automated decision-making, bringing Oman in line with Article 15 of the UK GDPR.

This matters most in the context of automated decision-making, where people can’t meaningfully assess or challenge a decision without understanding how it was reached. According to the Business and Human Rights Centre, Uber and Ola drivers in the Netherlands couldn’t challenge algorithmic dismissals until the courts confirmed that Article 15(1)(h) of the GDPR entitled them to information about the logic behind decisions that had ended their employment. An Omani worker facing an equivalent automated dismissal would currently have no comparable right. The UAE PDPL recognises a right to object to automated processing, while Saudi Arabia’s PDPL separately requires controllers to inform data subjects of the purpose and legal basis of data collection under Article 4. Neither, however, requires disclosure of the logic underlying automated decisions, so adopting the GDPR’s broader disclosure requirements would place Oman ahead of both regional counterparts.

Importantly, this reform could be implemented through the Executive Regulations rather than the primary legislation, making it one of the more practical recommendations in this brief: amending regulations is generally quicker, and less politically demanding, than amending a statute.

A Right to Compensation and Judicial Remedy

Oman’s framework is a strong foundation, and the fixes needed here are refinements rather than an overhaul. Following Saudi Arabia’s Article 40, and reinforced by Articles 79 and 82 of the GDPR, the law should give data subjects an express right to claim compensation before a competent court for both material and moral harm. That right should run alongside the Ministry’s existing enforcement powers, not replace them. The advantage of this approach is that it builds on rights Oman already has, while keeping the Ministry’s role intact and adding a personal remedy on top. The trade-off is that a court route adds cost and litigation risk for controllers, and requires the slower process of legislative change to put in place.

Oman would also do well to adopt a fault-based system of liability, along the lines of Article 82(3) of the GDPR: if a controller can prove it is not responsible for a violation, it should not have to compensate those affected by it. This offers an answer to the Canvas problem. Where there is no clear evidence that a processor caused or contributed to a violation, the appropriate course is to test whether it was negligent, or otherwise responsible, through a judicial process. Finally, limiting the amount of compensation a controller must pay, as Saudi Arabia’s Article 40 requires, would guard against a “floodgate” situation: controllers would still face real liability, but it would be limited and quantifiable rather than unlimited and unquantifiable.

Beyond Consent: A Safer Lawful Basis

Oman’s reform here should follow the Saudi model. Adding legitimate interests and contractual necessity as affirmative lawful bases, subject to a documented balancing assessment, would take the pressure off consent and let it function as a genuine safeguard for processing that is actually high-risk. The advantages are practical: controllers could manage fraud detection, network security, internal administration, and debt recovery without needing consent that no data subject would meaningfully refuse anyway, freeing enforcement resources to focus on processing that genuinely threatens people’s interests.

The risks, though, are real. Legitimate interest is a flexible standard, assessed by controllers themselves, and European experience shows how far it can be stretched: Meta tried to justify behavioural advertising first as a contractual necessity and then as a legitimate interest, and both arguments were rejected by the European Data Protection Board and the Court of Justice of the European Union. That example is an argument for safeguards rather than against reform: an obligatory, documented legitimate interest assessment, of the kind the UK Information Commissioner’s Office requires and opens to regulatory review, paired with a general right to object under Article 21 of the UK GDPR, would let Oman widen its lawful bases without leaving the data subject any less protected.

Why This Matters for Oman’s Digital Future

Protecting data subject rights is not a footnote to Oman’s digital transformation; it is central to it. As Oman Vision 2040 pushes digital government services, e-commerce, and cloud-based enterprise, ordinary people are increasingly required to hand over personal information to access basic services, often with little visibility into how that data is stored, used, or shared. Meaningful data subject rights, access, correction, erasure, and the ability to withdraw consent, give people real control over that exposure, rather than leaving them dependent on the goodwill of controllers. Without those protections, the same digital economy that Vision 2040 is built on becomes a source of risk rather than opportunity, through data misuse, breaches, and unauthorised disclosure. Strong data subject rights are what let people take part in Oman’s digital future with confidence, rather than vulnerability.

Conclusion

This brief began from a simple proposition: the PDPL exists to balance the interests of individuals who disclose their personal information against those of the organisations that control how it is processed. Before 2022, personal data in Oman was governed by a single chapter of the Electronic Transactions Law; today, it has a dedicated law built around it.

The gaps set out above, around access, consent, and remedies, show where that law still falls short for data subjects. The reforms proposed here would close them, giving data subjects real, usable protection over their own personal data.

Oman has pursued the digital economy as a central plank of Oman Vision 2040, treating it as a key tool for economic diversification away from hydrocarbon revenues. That pursuit has brought with it an expansion of digital government services, telecommunications, and cloud-based enterprise, and, with it, a corresponding rise in the processing of personal data, along with the risks that come with it: misuse, breaches, and unauthorised disclosure by the organisations entrusted with sensitive information. Protecting data subject rights should not be treated as secondary to a thriving Omani economy; the two go hand in hand.

Authors
Aatika Al-Hinai
Queen Mary University of London, United Kingdom

—

Mais Al-Hajri
Sultan Qaboos University, Oman

—

Malak Al-Kharusi
Leeds Beckett University, United Kingdom

—

Mohammed Al-Lawati
University of Liverpool, United Kingdom

—

]]>
90024