Blog · Your Data, Your Rights · 30 September 2026 · 5 min read

The First 72 Hours After a Data Leak

A leaked spreadsheet, a hacked vendor, a lost laptop: you have 72 hours to report it before the fine does the talking.

A spreadsheet emailed to the wrong address, a laptop left in a taxi, a vendor's server that got hacked: however it happens, the moment your business learns customer data has leaked, Oman's data protection law gives you 72 hours to report it to the regulator, with fines of OMR 15,000 to OMR 20,000 for missing that window. What you do inside those three days decides whether this stays a quiet fix or becomes a ministry file with your business's name on it.

The clock starts the moment you know

Oman's Personal Data Protection Law calls this the notification duty. A personal data breach is any event where customer information such as names, phone numbers, ID scans or booking details is destroyed, altered, leaked or accessed by someone who should not see it. The regulator here is the Ministry of Transport, Communications and Information Technology, known as MTCIT, which runs a dedicated Personal Data Protection Department for exactly this. The 72 hour clock does not start when the breach actually happened. It starts the moment someone on your team realises it happened, even if that is three days later.

Step one: contain it

Before you write a single report, stop the bleeding. This is the part your front office team, call desk or IT lead should already know how to do without waiting for a meeting.

  • Cut access first: disable the shared link, reset the password, pull the laptop off the network.
  • Freeze, do not delete: keep a copy of logs and files for the investigation. Deleting anything now looks like a cover up later.
  • Name one person in charge, usually the operations manager or IT lead, so instructions do not come from five directions at once.
  • Write down the exact time you found out. That timestamp is where your 72 hours begins.

Step two: work out what actually got out

Contain first, then assess. Pull together which records were touched, how many customers are affected, and whether the data included anything sensitive such as passport numbers, health details or payment information. A leaked marketing list of first names is a very different conversation than nine hundred guest passport scans. This is also where a call log that shows exactly who your team spoke with, and when, turns a guessing exercise into a short, workable list.

The 72 hours is not a suggestion. It is the difference between a fixable mistake and a fine that starts at OMR 15,000.

Step three: tell the regulator, and maybe the customer too

Once you know roughly what happened, notify MTCIT's Personal Data Protection Department by email at PDPC@mtcit.gov.om before the deadline passes. If the breach could cause serious harm, such as identity theft from a leaked ID scan, you must also tell the affected customers directly, within the same 72 hours, in plain language they can act on.

  1. What happened, and exactly when you found out.
  2. What data was exposed, and how many customers it touches.
  3. What you have already done to stop it.
  4. What you are doing next, and who to contact with questions.

Hours 0 to 72: a worked example

Khalfan runs front office for a mid-size hotel near Qurum. His team found that a shared booking folder had been open to anyone with the link for six weeks, exposing guest names, phone numbers and passport scans. Here is roughly how his 72 hours played out, in numbers any operations lead can redo with their own.

Hour windowWhat happensWho owns itRough cost (OMR)
0 to 2 hoursIT disables the shared folder and resets accessOps manager, IT lead0, in house
2 to 6 hoursTeam confirms 940 guest records exposed: names, phone numbers, passport scansOps manager with outside counsel150, one legal consult
6 to 24 hoursDraft report to MTCIT, update the internal breach registerData protection contact0
24 to 48 hoursPassport scans meet the serious harm threshold, so a customer notice is draftedOps manager, marketing40, SMS and email
48 to 72 hoursMTCIT notification submitted and guest notices sent before the deadlineOps managerDeadline met
After 72 hoursMinistry may ask follow up questions; internal review scheduled for the next weekOwner, ops managerOngoing
The hardest call is the one to the customer. But a rehearsed script makes it feel less awful for everyone.
Buthaina, call desk coordinator, polyclinic group, Muscat · composite voice

Step four: learn so it does not happen twice

Once the deadline is met, the job is not done. Update the breach register you are required to keep, note what let this happen, and close that specific gap. Most breaches this size trace back to one habit, not one villain: a shared password, an old spreadsheet nobody archived, an ex staff account nobody switched off.

The businesses that get through a leak calmly decided who does what before the phone ever rang.

What this means for you

If you already run a call desk, a front office or a service team, you are already collecting the data this law protects: phone numbers, ID copies, booking histories, health details. You do not need a breach to start acting. Write down, today, who in your business is the person who takes that call at 2am, and where the MTCIT report contact is saved so nobody is searching for it during hour one of the 72. The grace period for getting compliant ended in February 2026, so this is no longer homework you can put off.

Do I have to report every data breach to MTCIT?

Only breaches that threaten a customer's rights or could cause harm. A locked cabinet that was jimmied but nothing taken is different from a database dump. When in doubt, report it. The fine for staying quiet is steeper than the fine for over reporting.

What counts as serious harm that requires telling the customer directly?

Anything that could lead to identity theft, financial loss or personal danger: passport or ID numbers, bank details, health records, or a home address tied to a name. A leaked list of first names alone usually does not meet that bar.

Does the 72 hours include weekends?

The law counts hours, not business days, so yes. This is exactly why naming one responsible person in advance matters more than the report template itself.

The bottom line

A data leak is not the end of the story if you move fast and honestly. Contain it, work out what actually happened, tell MTCIT and any customer who needs to know within 72 hours, then fix the habit that let it happen. The businesses that get through this calmly are the ones who decided who does what before the phone ever rang.

Sources checked for this article

Practical information, not legal advice. Rules and dates were checked on 30 September 2026; verify current official positions before acting.

data breachpersonal data protection lawMTCITcustomer datacompliance checklistprivacy Omandata protection rights

Put an end to hold music and IVR menus

Your first 100 minutes of customer conversations are free, and your customer data stays inside Oman.

Oman Personal Data Protection Law compliant · Data never leaves the Sultanate