Blog · Oman Service Pulse · 21 September 2026 · 5 min read

Your Customer Data Rules Just Changed Again

Seven months after enforcement began, Oman's privacy law moved again, this time reaching into your call recordings, your consent forms and your AI systems.

On 7 September 2026, Oman's Personal Data Protection Law changed for the first time since it became fully enforceable seven months earlier. If your business keeps customer phone numbers, ID copies or call recordings on file, this is not background reading. The amendment adds a real cost to holding data you no longer need, and gives every customer a new right to challenge a decision your systems make about them without a person involved.

Seven months in, then a rewrite

The grace period under the data protection law ended on 5 February 2026. From that date the Ministry of Transport, Communications and Information Technology (MTCIT), the regulator for data protection, gained full power to investigate complaints, audit how businesses handle customer data and issue fines. Most service businesses treated that date as the finish line and moved on to other things.

Then, on 6 September 2026, a Royal Decree amended the law itself, and the changes took effect the next day. They touch exactly the parts that matter to a business running a call desk: what counts as valid consent, how long a recording can sit on a server, and what happens when a system, not a person, makes a decision about a customer.

What changed on 7 September

Five changes matter most for a customer-facing business:

  • Reach beyond Oman's borders. The law now covers processing of a customer's data even when that processing happens outside Oman, for example on an overseas vendor's server.
  • A right to a human decision. If a system flags, scores or routes a customer automatically, an IVR queue or an AI triage step, the customer can now object and ask a person to review it.
  • Delete data once the job is done. Personal data must be erased once the reason for holding it no longer applies, with narrow exceptions for an open dispute or a legal duty to keep it.
  • Marketing consent stays explicit. A written yes is still required before sending offers or promotional messages, separate from the consent a customer gave simply to be served.
  • Staff data got simpler. A business can now process its own employees' data, including fingerprints for time clocks, without applying for a ministry permit first.

Why your call desk is exposed

Most of this reads like a legal update until you map it onto an actual day at the desk. A hotel front office keeps call recordings for training. A polyclinic's call desk logs a caller's number and reason for calling before the call reaches a doctor. A dealership's service line records calls to settle disputes about what was promised. None of that is illegal on its own. What is now exposed is not being able to say why you're still holding a recording six months later, and not being able to show a person reviewed a decision your system made when a customer pushed back.

Keeping a customer's call recording after the reason for it has passed is now the violation, not the recording itself.

If part of your call handling already runs on an AI system, check whether it can hand off to a person the moment someone objects. CustomerCare.OM, for one, builds this into escalation rules that route a caller to a person on trigger words or on request, which is roughly the shape the new right takes in a real conversation.

The three fixes this week

  1. Put a number on retention. Decide how long call recordings, chat logs and enquiry forms stay before deletion, ninety days is a common starting point for service calls, write it down, and set your phone or call software to enforce it automatically.
  2. Build the human hand-off. If any part of intake is automated, routing, triage or an AI system, make sure a customer can ask for a person and actually get one, and keep a short note of what was reviewed.
  3. Separate marketing consent from service consent. A customer who gave a number to book a room or an appointment did not agree to receive offers. Keep that yes as its own dated, logged tickbox.

One service desk's numbers

Here is how those three fixes might look for a twenty-line dealership service desk. Use your own call volumes to redo the sums.

Three fixes, sized for a twenty-line service desk
FixTime and cost to do itRisk if skipped
Ninety-day auto-delete on call recordingsHalf a day with your phone or call platform provider, usually no extra costUp to OMR 2,000 in administrative fines if recordings are held with no stated reason
A 'get me a person' path on automated routingOne afternoon configuring escalation rulesA complaint upheld against the business, plus the fine tied to the underlying breach
Marketing consent logged apart from booking consentOne spreadsheet column or CRM field, same dayOMR 1,000 to OMR 5,000 for sending marketing without explicit consent
We used to keep every recording forever, just in case. Now that habit is the risk we're managing.
Sumaiya, call-desk coordinator, polyclinic group, Muscat · composite voice

What this means for you

If you already run a call desk, an IVR line or a front office, treat this amendment as a checklist, not a crisis. You are not starting from zero: you already collect consent to serve customers and you already record calls for a real reason. The gap is usually paperwork and defaults, not intent. Fix the three items above this week. For the fuller rulebook on consent and recording built for phone systems, the Oman AI calling guide is a useful next stop.

Clinics, insurers and any business handling health or financial data carry extra duties on top of the general law, so check your sector's own guidance as well.

Does this apply to a small clinic or a single branch, not just large groups?

Yes. The law applies by what data you hold and how you use it, not by company size.

Is there a new grace period for the September amendment?

None has been published. Treat the changes as already in force, because they are.

What about recordings kept from before September?

The erasure duty runs from when the reason for keeping data ends. Review older recordings against the same test: is there still a reason to keep this one?

The bottom line

The data protection law is no longer something you read once and file away. It changed twice within a year: once in February when enforcement began, and again on 7 September when the rules themselves moved. The businesses in the best shape are the ones that treat every update the same way, read what changed, fix what's exposed, and get back to the next call.

Sources checked for this article

Practical information, not legal advice. Rules and dates were checked on 21 September 2026; verify current official positions before acting.

personal data protection lawcall recordingscustomer data complianceMTCITdata retentionconsentOman Service Pulse

Put an end to hold music and IVR menus

Your first 100 minutes of customer conversations are free, and your customer data stays inside Oman.

Oman Personal Data Protection Law compliant · Data never leaves the Sultanate