Saturday, April 27, 2024 | Shawwal 17, 1445 H
clear sky
weather
OMAN
27°C / 27°C
EDITOR IN CHIEF- ABDULLAH BIN SALIM AL SHUEILI

Oman strengthens personal data protection measures with new regulations

The new regulations emphasise the importance of obtaining consent before processing personal data, outline the rights of data subjects, and address specific scenarios such as the processing of personal data pertaining to children.
The new regulations emphasise the importance of obtaining consent before processing personal data, outline the rights of data subjects, and address specific scenarios such as the processing of personal data pertaining to children.
minus
plus

MUSCAT: In a positive stride towards safeguarding individuals' privacy and personal information, Oman’s Ministry of Transport, Communications, and Information Technology (MoTCIT) has recently issued new executive regulations for the Personal Data Protection Law (Royal Decree No 6/2022). These regulations aim to provide an improved framework for the protection of personal data and offer clarity on various provisions outlined in the law.


The executive regulations consist of nine chapters and forty-five articles, focusing on enhancing data privacy and establishing proper controls and procedures. They emphasise the importance of obtaining consent before processing personal data, outline the rights of data subjects, and address specific scenarios such as the processing of personal data pertaining to children.


One significant provision in the regulations is the requirement for entities to obtain a permit when processing personal data. This ensures that personal information is treated with care and respect. The regulations specify the process for obtaining permits, including the submission of a personal data protection policy and measures to address potential breaches. Permits are valid for up to five years, with provisions for renewal, amendment, or cancellation.


To safeguard the privacy of children, the regulations include a chapter dedicated to the processing of their personal data. This provides legal protection for children's privacy and requires explicit consent from their legal guardian or custodian before their data can be processed.


The regulations also outline the rights of data subjects, including the right to withdraw consent, request modifications or updates to their data, obtain copies of processed data, and request the deletion of their personal information, where applicable. In the event of a data breach, data subjects must be promptly notified and informed of the actions taken to address the breach.


Controllers and processors have specific obligations under the regulations, such as obtaining explicit consent before processing personal data and adhering to controls related to the processing of children's personal data.


In the event of a personal data breach, controllers are required to notify the Ministry within 72 hours. The Ministry will assess the actions taken by the controller and may direct them to take appropriate measures to mitigate the impact of the breach.


The regulations establish the role of the Data Protection Officer (DPO), responsible for overseeing data protection matters within an organisation. The DPO provides consultations and proposals to the controller and coordinates with the Ministry on data processing issues.


Regarding the transfer of personal data outside the country's borders, the regulations establish controls and conditions to ensure a balance between risks and the necessity of such transfers. This includes obtaining the data subject's consent and assessing the level of protection provided by the receiving party.


The regulations also include provisions for filing complaints and imposing penalties. Individuals can file complaints and reports, and the Minister has the authority to impose administrative penalties such as warnings, permit suspension, and fines not exceeding RO 2000. In extreme cases, permits may be canceled.


These new executive regulations demonstrate Oman's commitment to enhancing personal data protection and promoting trust in digital transactions. By implementing a robust framework and clarifying key provisions, Oman aims to create a secure environment that respects individuals' privacy rights and fosters responsible data handling.


SHARE ARTICLE
arrow up
home icon