Skip to content

Evidence request lists

Oman Personal Data Protection Law (Royal Decree 6/2022)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Automated Decisions, Children, Marketing

OMANPDPL-7
Automated Decision-Making, Profiling, Children, Direct Marketing

Adhere to Oman PDPL Articles 25-28 covering automated decision-making + profiling + children + direct marketing. Automated decision-making and profiling per Article 25 requires (a) restriction of solely-automated decisions producing legal or similarly significant effects on individuals to specified lawful bases + (b) human review capability + explanation of decision logic + ability to contest + (c) safeguards for protected categories. Children and vulnerable data subjects per Article 26 requires (a) age verification + parental consent for processing of child data (typically under 18 in Oman per default + check sectoral specifics), (b) child-appropriate notices + privacy-preserving design, (c) heightened protections for sensitive contexts (health + education + safeguarding). Direct marketing per Article 27 requires (a) opt-in consent for marketing communications + (b) clear unsubscribe me

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-7
Where this commonly fails
  • compliance nominal not operational

Breach + RoPA + Processors

OMANPDPL-5
Breach Notification (72 hours), Records of Processing, Processor Engagement

Operate breach notification + records of processing + processor engagement per Oman PDPL Articles 21 + 22 + 23. Breach notification must (a) notify the MTCIT regulator (or designated supervisory authority) within 72 hours of becoming aware of personal data breach likely to result in risk to rights and freedoms per Article 21, (b) notify affected individuals without undue delay when likely to result in high risk + (c) maintain breach register with full incident details + timeline + impact + remediation + lessons learned. Records of Processing Activities (RoPA) must (a) maintain inventory of processing activities per Article 22 with content covering controller identity + purposes + categories of data + recipients + cross-border + retention + security measures, (b) update RoPA on material change + (c) make available to supervisory authority on request. Processor engagement must (a) bind pro

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-5
Where this commonly fails
  • compliance nominal not operational

International Transfers

OMANPDPL-6
International Data Transfers and Cross-Border Controls

Operate international data transfers per Oman PDPL Article 24. Cross-border transfer of personal data outside Oman requires (a) prior approval from the supervisory authority (MTCIT) for transfers outside Oman per Article 24, (b) maintenance of safeguards including standard contractual clauses + binding corporate rules + or equivalent + (c) documented adequacy assessment of recipient jurisdiction + (d) consideration of data subject consent where appropriate. Cloud computing arrangements with non-Oman processors require particular attention to transfer obligations + with data localisation requirements applicable to specific sectors (banking + telecom + health + government) per sectoral regulation. Maintain transfer register + supervisory authority correspondence + adequacy assessments + with periodic review.

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-6
Where this commonly fails
  • compliance nominal not operational

Minimisation and Retention

OMANPDPL-3
Data Minimisation, Purpose Limitation, Retention, Secure Deletion

Apply data minimisation + purpose limitation + retention + secure deletion per Oman PDPL Articles 7 + 9 + 10. Data minimisation requires collecting only personal data necessary for the documented lawful purpose + with periodic review of necessity. Purpose limitation requires using personal data only for the original purpose for which it was collected unless compatible purpose or subsequent lawful basis exists. Retention requires (a) defining retention periods per data category per processing purpose + (b) implementing automated retention enforcement where possible + (c) maintaining retention schedule documented and reviewed periodically. Secure deletion requires applying NIST SP 800-88 or equivalent sanitisation methods per media type + maintaining deletion logs + with cryptographic erase + degaussing + or physical destruction as appropriate.

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-3
Where this commonly fails
  • compliance nominal not operational

Notice and Rights

OMANPDPL-2
Privacy Notice, Transparency, Data Subject Rights

Provide privacy notice + honor data subject rights per Oman PDPL Articles 11-18. Notice must (a) be provided at collection covering identity of controller + purpose + lawful basis + retention + recipients + cross-border transfers + data subject rights + complaint mechanism per Article 11, (b) be in plain Arabic and English where applicable + accessible to vulnerable populations + (c) be updated when material changes occur. Data subject rights include (a) access per Article 13, (b) rectification per Article 14, (c) erasure per Article 15, (d) restriction per Article 16, (e) objection per Article 17, (f) portability per Article 18, (g) right not to be subject to automated decision-making per Article 19. Handle rights requests within statutory timeframes (typically 30 days extendable + free of charge with exceptions) + maintain audit trail.

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-2
Where this commonly fails
  • compliance nominal not operational

Scope and Lawful Processing

OMANPDPL-1
Scope, Lawful Basis, Consent, and Sensitive Data Protection

Adhere to Oman Personal Data Protection Law (Royal Decree 6/2022) issued 9 February 2022 + effective 13 February 2023 Sections covering scope (applies to processing of personal data of identified or identifiable natural persons in Oman + or by controllers/processors established in Oman) + lawful basis (consent + contract + legal obligation + vital interests + public task + legitimate interests per Article 5) + consent requirements (informed + specific + freely given + revocable + maintained per Article 6) + sensitive personal data protections (genetic + biometric + health + criminal records + ethnicity + religious belief + political opinion + trade union membership + sex life + child data require explicit consent + heightened protections per Article 8). Maintain documented lawful basis per processing activity + consent records per Article 6 + sensitive data inventory + special handling p

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-1
Where this commonly fails
  • compliance nominal not operational

Security and Privacy by Design

OMANPDPL-4
Security of Processing, Privacy by Design, Impact Assessment

Implement security of processing + privacy by design + DPIA per Oman PDPL Articles 19 + 20. Security must (a) implement appropriate technical and organisational measures considering state of the art + cost + nature/scope/purpose of processing + risk to data subjects + (b) include encryption + pseudonymisation + access control + integrity + availability + resilience + regular testing + (c) integrate with broader cybersecurity programme aligned with Oman National Cybersecurity Framework. Privacy by Design requires (a) embedding privacy considerations into system design + procurement + change management, (b) maintaining privacy default settings, (c) maintaining data minimisation by design. DPIA (Data Protection Impact Assessment) must be conducted for high-risk processing per Article 20 + criteria similar to GDPR Article 35 (large-scale processing of sensitive data + systematic monitoring +

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-4
Where this commonly fails
  • compliance nominal not operational

Supervision and Enforcement

OMANPDPL-8
Supervision, Enforcement, Penalties, and DPO Designation

Operate supervision + enforcement + penalties + DPO designation per Oman PDPL Articles 29-32. Supervisory authority (MTCIT) exercises powers including investigation + audit + corrective measures + administrative fines + suspension of processing + criminal referral for serious violations per Article 29. Enforcement and penalties include (a) administrative fines up to OMR 500,000 for serious violations + (b) criminal penalties for specified violations per Article 31 including imprisonment up to 5 years + (c) civil compensation rights for affected individuals. DPO designation per Article 30 is required for (a) public authorities + (b) controllers whose core activities consist of regular and systematic monitoring of data subjects on a large scale + (c) controllers whose core activities consist of processing of sensitive personal data on a large scale + with DPO independence + reporting line

Artefacts an auditor will ask for
  • Oman PDPL compliance evidence for OMANPDPL-8
Where this commonly fails
  • compliance nominal not operational
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.