GCC
PDPL
PDPL (Royal Decree 6/2022) (Oman)
29 controls · 8 domains
Mandatory for: Data-protection law
About this framework
Oman's Personal Data Protection Law (Royal Decree 6/2022) sets the rules for handling personal data, including consent, security, and the rights of individuals over their information.
Who needs this
For organisations handling the personal data of people in Oman.
Cross-framework coverage
Controls in PDPL also cover:
ADHICS 12 shared
GDPR (EU) 12 shared
PDPL 12 shared
Data-protection rules 12 shared
PDPPL 12 shared
See how PDPL connects to the rest → the Security Universe
Control domains
DP1 · Governance & Accountability 5
DP1.1
Accountability & compliance ownership
Assign clear ownership and demonstrate compliance with the data-protection law through documented policies, decisions, and evidence of personal-data processing being managed lawfully.
DP1.2
Data protection officer / responsible person
Designate a data protection officer or equivalent responsible person where required, with defined responsibilities for advising on and monitoring data-protection compliance.
DP1.3
Records of processing activities
Maintain records of personal-data processing activities, including purposes, categories of data and data subjects, recipients, and retention periods.
DP1.4
Data protection by design and by default
Embed data-protection requirements into the design of systems and processes, defaulting to the minimum personal data necessary for each purpose.
DP1.5
Data protection impact assessment
Assess and document the privacy risks of high-risk processing before it begins, and apply measures to mitigate identified risks to data subjects.
DP2 · Lawful Basis & Consent 3
DP2.1
Lawful basis for processing
Establish and record a valid lawful basis for each processing activity (e.g. consent, contract, legal obligation, or legitimate interest as recognised by the applicable law).
DP2.2
Consent management
Where processing relies on consent, obtain it freely, specifically, and unambiguously, keep records of consent, and provide an accessible means to withdraw it.
DP2.3
Processing of sensitive personal data
Apply the additional conditions and safeguards required for sensitive / special categories of personal data before processing them.
DP3 · Data Subject Rights 4
DP3.1
Right of access
Provide data subjects with a means to obtain confirmation of, and access to, the personal data held about them within the statutory timeframe.
DP3.2
Rights to rectification and erasure
Enable data subjects to have inaccurate personal data corrected and, where applicable, to have their personal data erased.
DP3.3
Rights to object, restrict and port
Support data subjects' rights to object to or restrict processing and, where provided by the law, to receive or transfer their data in a portable format.
DP3.4
Safeguards for automated decision-making
Provide safeguards, including human review where required, for decisions based solely on automated processing or profiling that significantly affect data subjects.
DP4 · Transparency & Data Minimisation 2
DP4.1
Privacy notice and transparency
Inform data subjects clearly about who processes their data, for what purposes, on what basis, and how to exercise their rights, at or before the point of collection.
DP4.2
Purpose limitation and data minimisation
Collect personal data only for specified, legitimate purposes and limit it to what is adequate, relevant, and necessary for those purposes.
DP5 · Data Security Measures 6
DP5.1
Technical and organisational security measures
Implement appropriate technical and organisational measures to protect personal data, proportionate to the risk to data subjects.
DP5.2
Access control to personal data
Restrict access to personal data to authorised personnel on a least-privilege, need-to-know basis, with access reviewed periodically.
DP5.3
Encryption and pseudonymisation
Apply encryption and/or pseudonymisation to personal data in transit and at rest, proportionate to its sensitivity and the risk to data subjects.
DP5.4
Data classification and handling
Classify personal data by sensitivity and apply handling, retention, and disposal rules consistent with its classification.
DP5.5
Logging and monitoring of processing
Log and monitor access to and processing of personal data to detect and investigate unauthorised or unlawful activity.
DP5.6
Confidentiality, integrity, availability and resilience
Maintain the confidentiality, integrity, availability, and resilience of processing systems and restore access to personal data after an incident.
DP6 · Personal Data Breach Management 3
DP6.1
Breach detection and response
Establish processes to detect, assess, contain, and respond to personal data breaches.
DP6.2
Breach notification to the regulator
Notify the competent regulator of qualifying personal data breaches within the timeframe and in the manner required by the applicable law.
DP6.3
Breach communication to data subjects
Communicate high-risk personal data breaches to affected data subjects where required, with clear information and recommended actions.
DP7 · Cross-Border Transfer 3
DP7.1
Conditions for cross-border transfer
Transfer personal data outside the jurisdiction only where the conditions set by the applicable law are met.
DP7.2
Transfer safeguards and adequacy
Apply appropriate safeguards (e.g. adequacy findings, contractual clauses, or approved mechanisms) to international transfers of personal data.
DP7.3
Data localisation requirements
Identify and meet any data-localisation or in-country storage requirements applicable to specific categories of personal data.
DP8 · Processor & Third-Party Management 3
DP8.1
Processor obligations and contracts
Engage processors only under binding agreements that set out the subject matter, scope, and data-protection obligations of the processing.
DP8.2
Sub-processor management
Authorise and control the use of sub-processors, ensuring equivalent data-protection obligations flow down the supply chain.
DP8.3
Due diligence and oversight of processors
Conduct due diligence on processors before engagement and monitor their compliance with data-protection obligations throughout the relationship.
Ready to assess against PDPL?
Start free trial →