Somewhere in your business right now sits a list: booking names and phone numbers in a spreadsheet, guest notes in a shared inbox, medical history or vehicle details in a CRM nobody has opened in months. Since 5 February 2026, that list has stopped being just useful. It is regulated, and the grace period that let a messy version slide has ended.
What counts as your customer list
Oman's data protection law does not only cover fancy databases. It covers any name, phone number, email, national ID, health note, vehicle registration or call recording your business collects, stores or uses to serve customers. If you run an operator desk, a front office or a service line, you almost certainly hold this kind of information today, whether it lives in a proper CRM, a shared inbox, or a paper diary behind the counter. The law calls what you do with that information processing, and processing is now something the Ministry can ask you to explain.
The grace period is over
The Personal Data Protection Law has applied since February 2023, but the Ministry of Transport, Communications and Information Technology gave businesses time to get ready. That adjustment window closed on 5 February 2026. Since then the Ministry actively supervises compliance, takes complaints from customers, and can issue fines. For a hotel, a clinic group or a dealership that has been quietly collecting customer details for years, this is not a future compliance project. It is live exposure, starting with the list you already have.
The list nobody in your business has opened in months is exactly the list a regulator can now ask to see.
Five plain obligations
Strip away the legal language and the law asks for five things from any business holding a customer list. Check your own operation against each one.
- Ask before you collect. Get clear consent before you take someone's phone number or email, and get it in writing if you plan to use it for marketing texts or calls later.
- Say why you're keeping it. Tell the customer, even in one line on a form or a message, what you'll use their information for. A booking confirmation is a different purpose from a promotional blast.
- Guard it like cash. Limit who in your team can open the list, and if it's ever breached, you have 72 hours to tell the Ministry and the customers affected.
- Only use it for what you said. A phone number collected for an appointment reminder is not automatically fair game for a campaign six months later.
- Let them see it, fix it, or delete it. Customers can ask what you hold on them, ask you to correct it, or ask you to delete it, and someone in your business needs to own that request when it lands.
What a gap could cost
Here is what those obligations look like once they turn into fines, based on the ranges published under the law. Match your own list against each row before you assume the size of your business keeps you off the Ministry's radar.
| Gap in your customer list | What it breaks | Fine range (OMR) |
|---|---|---|
| Phone numbers collected for bookings, later used for marketing texts with no separate consent | Using data beyond what the customer agreed to | 1,000 to 5,000 per offence |
| Health notes, ID copies or biometric details stored with no extra permit | Handling sensitive data without authorisation | 15,000 to 20,000 per offence |
| Guest or patient list backed up to a server outside Oman with nobody checking | An unauthorised cross border transfer | 100,000 to 500,000 |
| No record of who consented to what, or when | Missing basic documentation | 500 to 2,000 |
Our booking sheet had every patient's number and no record of consent. That gap alone could have cost us thousands.
What this means for you
Start by finding your own list, wherever it actually lives, and walk through the five obligations against it this week, not next quarter. If a customer asks what you hold on them, you should already have a plain answer ready, the kind covered in What Can You Ask a Business About Your Data. If part of the gap is that nobody logs consent from every call or keeps that data outside Oman, an enterprise setup built for Oman, such as CustomerCare.OM's, keeps that call data and its consent trail inside the country automatically. Either way, the fix is a habit, not a one time form: review the list, its purpose and its home, every few months.
Does this apply to a small hotel or a single-branch clinic, not just big companies?
Yes. The law covers any business that collects personal data, regardless of size. What differs is the risk: a business with an operator desk handling hundreds of calls a week has more data, so more exposure if the list is a mess.
Do we need to hire a dedicated data protection officer?
The law expects someone in the business to be accountable for data protection decisions. For a smaller operation this can be an existing manager who takes on the role, not necessarily a new hire.
What counts as a breach we have to report?
Any loss, theft or unauthorised access to personal data that could put customers at risk, reported to the Ministry within 72 hours of your business becoming aware of it.
The bottom line
Your customer list was never just a business asset. Since February 2026 it is also a record the Ministry can ask to see. Five habits, consent, purpose, security, limited use and customer access, turn that list from a liability into something you can defend on paper, this week rather than after a complaint arrives.
Sources checked for this article
- MTCIT: Personal Data Protection (oman-official)
- MTCIT: Personal Data Protection Law (oman-official)
- MTCIT news: enforcement phase update (oman-official)
- Decree Blog: penalties under the Personal Data Protection Law (analysis)
Practical information, not legal advice. Rules and dates were checked on 26 August 2026; verify current official positions before acting.
