Blog · Your Data, Your Rights · 26 August 2026 · 5 min read

Five Rules for the Customer List You Already Have

Your booking spreadsheet, shared inbox and CRM are all covered by Oman's data protection law now that the grace period has ended. Five plain obligations, and a two minute check.

Somewhere in your business right now sits a list: booking names and phone numbers in a spreadsheet, guest notes in a shared inbox, medical history or vehicle details in a CRM nobody has opened in months. Since 5 February 2026, that list has stopped being just useful. It is regulated, and the grace period that let a messy version slide has ended.

What counts as your customer list

Oman's data protection law does not only cover fancy databases. It covers any name, phone number, email, national ID, health note, vehicle registration or call recording your business collects, stores or uses to serve customers. If you run an operator desk, a front office or a service line, you almost certainly hold this kind of information today, whether it lives in a proper CRM, a shared inbox, or a paper diary behind the counter. The law calls what you do with that information processing, and processing is now something the Ministry can ask you to explain.

The grace period is over

The Personal Data Protection Law has applied since February 2023, but the Ministry of Transport, Communications and Information Technology gave businesses time to get ready. That adjustment window closed on 5 February 2026. Since then the Ministry actively supervises compliance, takes complaints from customers, and can issue fines. For a hotel, a clinic group or a dealership that has been quietly collecting customer details for years, this is not a future compliance project. It is live exposure, starting with the list you already have.

The list nobody in your business has opened in months is exactly the list a regulator can now ask to see.

Five plain obligations

Strip away the legal language and the law asks for five things from any business holding a customer list. Check your own operation against each one.

  1. Ask before you collect. Get clear consent before you take someone's phone number or email, and get it in writing if you plan to use it for marketing texts or calls later.
  2. Say why you're keeping it. Tell the customer, even in one line on a form or a message, what you'll use their information for. A booking confirmation is a different purpose from a promotional blast.
  3. Guard it like cash. Limit who in your team can open the list, and if it's ever breached, you have 72 hours to tell the Ministry and the customers affected.
  4. Only use it for what you said. A phone number collected for an appointment reminder is not automatically fair game for a campaign six months later.
  5. Let them see it, fix it, or delete it. Customers can ask what you hold on them, ask you to correct it, or ask you to delete it, and someone in your business needs to own that request when it lands.

What a gap could cost

Here is what those obligations look like once they turn into fines, based on the ranges published under the law. Match your own list against each row before you assume the size of your business keeps you off the Ministry's radar.

Gap in your customer listWhat it breaksFine range (OMR)
Phone numbers collected for bookings, later used for marketing texts with no separate consentUsing data beyond what the customer agreed to1,000 to 5,000 per offence
Health notes, ID copies or biometric details stored with no extra permitHandling sensitive data without authorisation15,000 to 20,000 per offence
Guest or patient list backed up to a server outside Oman with nobody checkingAn unauthorised cross border transfer100,000 to 500,000
No record of who consented to what, or whenMissing basic documentation500 to 2,000
Our booking sheet had every patient's number and no record of consent. That gap alone could have cost us thousands.
Yaqoub, operations manager, Seeb polyclinic · composite voice

What this means for you

Start by finding your own list, wherever it actually lives, and walk through the five obligations against it this week, not next quarter. If a customer asks what you hold on them, you should already have a plain answer ready, the kind covered in What Can You Ask a Business About Your Data. If part of the gap is that nobody logs consent from every call or keeps that data outside Oman, an enterprise setup built for Oman, such as CustomerCare.OM's, keeps that call data and its consent trail inside the country automatically. Either way, the fix is a habit, not a one time form: review the list, its purpose and its home, every few months.

Does this apply to a small hotel or a single-branch clinic, not just big companies?

Yes. The law covers any business that collects personal data, regardless of size. What differs is the risk: a business with an operator desk handling hundreds of calls a week has more data, so more exposure if the list is a mess.

Do we need to hire a dedicated data protection officer?

The law expects someone in the business to be accountable for data protection decisions. For a smaller operation this can be an existing manager who takes on the role, not necessarily a new hire.

What counts as a breach we have to report?

Any loss, theft or unauthorised access to personal data that could put customers at risk, reported to the Ministry within 72 hours of your business becoming aware of it.

The bottom line

Your customer list was never just a business asset. Since February 2026 it is also a record the Ministry can ask to see. Five habits, consent, purpose, security, limited use and customer access, turn that list from a liability into something you can defend on paper, this week rather than after a complaint arrives.

Sources checked for this article

Practical information, not legal advice. Rules and dates were checked on 26 August 2026; verify current official positions before acting.

personal data protection lawcustomer dataconsumer privacyMTCIT compliancedata consentcustomer list audit

Put an end to hold music and IVR menus

Your first 100 minutes of customer conversations are free, and your customer data stays inside Oman.

Oman Personal Data Protection Law compliant · Data never leaves the Sultanate