Skip to navigation
Back to all guides
Data Protection and PrivacyOman Compliance Made Simple

The Customer List in Your Phone Could Become Your Biggest Privacy Risk

A customer asks you to delete her number while an employee medical note sits in a shared drive. Here is how a small Omani company can handle both without building a legal department.

At 9:12 on a Tuesday morning, Maha receives a WhatsApp message from a customer: "Please delete everything you have about me." Five minutes later, her office manager uploads an employee's medical certificate to a folder that the entire team can open. Nothing looks dramatic. Yet those two ordinary actions can reveal whether Maha's 12-person catering company treats privacy as a real operating rule or as a policy nobody reads.

One ordinary company, six copies of the same person

Maha's customer, Sara, appears in a phone contact, a WhatsApp thread, a quotation spreadsheet, an invoice, a delivery sheet and an email marketing list. Her employee, Ahmed, appears in payroll, attendance, a bank transfer file, a leave request and the shared medical certificate. The problem is not that Maha collected data. A business often needs data to quote, deliver, employ and get paid. The problem is that she cannot quickly say what exists, why it exists, who can see it or when it should go.

Personal data shall be deemed protected.
Article 4, Personal Data Protection Law

Oman's Personal Data Protection Law under Royal Decree 6/2022 defines personal data broadly and covers collecting, storing, changing, viewing, sharing and deleting it. The Executive Regulation under Ministerial Decision 34/2024 turns that principle into daily duties. It is written for controllers and processors, not only large companies.

What the rules mean in plain language

  1. Tell people what you are doing. Before processing, provide clear information about who controls the data, the purpose, the source, disclosures and the person's rights. Put a visible privacy policy where people can read it before they hand over data.
  2. Use the right legal route. Explicit approval is central, but consent is not a magic answer for everything. Article 3 also addresses processing needed to execute a contract or meet a legal obligation. Written consent is expressly required before commercial marketing, together with an easy, free opt-out.
  3. Collect less. If a quotation only needs a name, phone number and delivery area, do not ask for a civil ID, date of birth and family details just because your form has empty boxes.
  4. Restrict access. A driver may need the address for today's delivery. The driver does not need Sara's full purchase history, and the sales team does not need Ahmed's salary or medical certificate.
  5. Keep a living record. Article 28 of the Regulation calls for a processing activities register covering data categories, authorised access, purpose, retention, recipients, transfers, security measures and breaches.
  6. Make rights workable. A person can request access, correction, transfer, blocking or deletion in the situations the law allows. The Regulation gives the controller up to 45 days to respond to a written rights request.
  7. Prepare for the bad day. If a breach risks people's rights, the competent department must be notified within 72 hours of awareness. If serious harm or high risk may result, the affected person must also be notified within that period.

The two traps small firms miss

First, Ahmed's medical certificate contains health data. Article 5 prohibits processing specified sensitive categories, including health and biometric data, without a Ministry permit under the Regulation's procedure. Fingerprint attendance can therefore deserve more scrutiny than a normal clock-in. Do not assume that being small removes the issue. Map the data and obtain qualified legal advice on whether a permit is required.

Second, cloud storage can move data beyond Oman even when the screen is opened in Muscat. Articles 37 to 40 of the Regulation require explicit consent for a transfer unless a stated exception applies, adequate protection by the overseas processor and a documented assessment of the transfer risk. Oman hosting can reduce this workload, but email, analytics, backups and connected apps still need checking.

A seven day privacy cleanup you can actually finish

  • Day 1: list every place customer, employee, applicant and supplier contact data lives.
  • Day 2: write one honest purpose and one retention rule for each data group.
  • Day 3: remove shared passwords and give access by job role.
  • Day 4: publish a clear privacy notice and fix marketing consent and opt-out.
  • Day 5: create a request inbox, a 45-day response tracker and a simple identity check.
  • Day 6: write the 72-hour breach contact tree and test it with a lost phone scenario.
  • Day 7: review sensitive data, overseas processors and the privacy officer designation with competent counsel.

Which ERP makes this easiest in Oman?

Disclosure: Amaal publishes this blog and is included below. This is not a laboratory security audit or a declaration that any product makes its customer legally compliant. We reviewed public information on Amaal, Zoho, Odoo and ERPNext on 28 July 2026. Plans, hosting regions and controls can change.

Practical privacy fit for an Omani small business
PlatformWhat it does wellPrivacy friction to examineBest fit
AmaalOman-hosted small ERP with encryption, role-based access, audit trails and full administrator data exportSmaller ecosystem; your team must still set collection, retention, request and incident proceduresOmani service SME wanting local hosting, local support and one connected record
ZohoBroad suite with encryption, role controls, audit tools and established regional data centresNo Oman data centre is listed, so the Oman controller must map and assess cross-border processingTeam wanting a wide cloud suite and willing to govern several apps
OdooDeep ERP, granular access options and a choice between cloud and self-hostingCloud production and backups can span countries; self-hosting adds security, backup and upgrade workComplex company with an implementation budget and specialist support
ERPNextOpen source, detailed role permissions and the ability to run on infrastructure you controlOman hosting and privacy workflows must be arranged and maintained by you or a capable partnerTechnical team that values control and customisation

Why this is good for growth, not only compliance

The UAE's official portal describes its federal data law as an integrated framework for confidentiality and privacy. Saudi Arabia's official controller and processor guide connects regulated personal data use with a thriving digital economy. The useful lesson is not that a law creates trust overnight. It is that digital trade scales better when customers and workers know the rules around their information.

That also fits the direction explored in Oman's Digital Government Programme Hit 94 Percent. Vision 2040 depends on services and businesses exchanging data with confidence. A clean data register, accountable access and reliable records help a small supplier qualify for larger clients, answer due diligence faster and recover from incidents with less confusion.


Maha need not become a privacy lawyer. When she can find Sara's records, explain their purpose, remove marketing access and protect Ahmed's medical data, privacy becomes a business habit. This is general education, not legal advice. Check current MTCIT guidance and obtain qualified advice.

Comparison note: Amaal publishes this guide and is included in the comparison. The same criteria were applied to each provider using public material reviewed on 2026-07-28. Product details change, so confirm critical requirements directly with the vendor.

Sources checked for this guide
Oman Personal Data Protection LawOman PDPLsmall business Omancustomer data privacyemployee data protectionERP OmanAmaalOman Vision 2040