An eKYC journey handles two different kinds of data, and Oman's data protection law treats them very differently.
The details on an ID card are personal data. The comparison between a selfie and that card's photograph is biometric processing. Under Oman's Personal Data Protection Law, issued by Royal Decree 6/2022 and fully enforceable since 5 February 2026, the first needs a purpose, a retention period and controlled access. The second is prohibited except after obtaining a permit from the Ministry.
Two categories of data in one journey
What each artefact is
| Artefact | Category | What it needs |
|---|---|---|
| Extracted ID fields | Personal data | A stated purpose, a retention period, controlled access |
| ID card image | Personal data | The same, and a reason if it is kept as evidence |
| Selfie or video | Personal data, captured for a biometric comparison | The same, plus everything below, because of what it is used for |
| Face comparison and its result | Biometric processing | A Ministry permit under Article 5 before any processing |
| Liveness analysis | Performed on the same face capture | Treat it as part of the same biometric processing unless your own legal advice says otherwise |
Reading a document is not biometric processing; comparing a face to it is. The two are often specified in the same sentence, which is how the permit gets missed.
The permit comes first
The sequence is not "get consent, then deploy". It is "obtain the permit, then deploy, with consent handled properly as well". The obligation to hold the permit falls on the controller — the institution verifying its customers — not on the software vendor.
That has a direct effect on the plan: a pilot on real customers' faces cannot start while the application is still pending. Put the permit on the timeline before the pilot, exactly as the same rule requires for facial attendance.
Hold as little as the process allows
Decide retention per artefact rather than for "the eKYC record" as a whole. The extracted fields, the card image, the selfie, the match result and the audit log serve different purposes and justify different periods. Write down each period with its reason, and confirm the periods with your own regulator rather than adopting a vendor default — the approach set out in what ID capture obliges you to keep and delete.
Protect the data in transit from the first moment. ekyciq's capture encrypts the ID image before it leaves the customer's device, so the document is never sent in the clear.
Share the result, not the raw data
When verified data moves on to the service that asked for it, it should carry what that service needs: the verified details and the outcome of the checks. It should not carry the selfie or the facial comparison data by default. Every copy of biometric data is one more copy to account for.
This is not legal advice, and it does not enumerate every obligation in the PDPL; read the primary text, and take advice on your own processing.
ekyciq is built with encryption and data privacy by design. See how ekyciq works, or talk to us about fitting identity verification to your data protection position.
Related posts
-
Fawtara: What Oman's E-Invoicing Mandate Requires, and When
The pilot is live, Phase 1 lands in April 2027, and the thresholds decide when you are in scope.
11 August 2026 -
Getting Your ERP Ready for Fawtara: The Work Before the Connector
The integration takes weeks. The customer master takes longer, and nobody budgets for it.
07 July 2026 -
Peppol, UBL and PINT: The Standards Behind Omani E-Invoicing
What the five-corner model changes, and why the schema is the easy half.
16 June 2026


