11 September 2026 Compliance By Vedhagiri Prakasam

eKYC Under Oman's PDPL: The Face Match Needs a Permit

An eKYC journey handles two different kinds of data, and Oman's data protection law treats them very differently.

The details on an ID card are personal data. The comparison between a selfie and that card's photograph is biometric processing. Under Oman's Personal Data Protection Law, issued by Royal Decree 6/2022 and fully enforceable since 5 February 2026, the first needs a purpose, a retention period and controlled access. The second is prohibited except after obtaining a permit from the Ministry.

Abstract illustration of concentric arcs radiating outward

Two categories of data in one journey

What each artefact is

Artefact Category What it needs
Extracted ID fieldsPersonal dataA stated purpose, a retention period, controlled access
ID card imagePersonal dataThe same, and a reason if it is kept as evidence
Selfie or videoPersonal data, captured for a biometric comparisonThe same, plus everything below, because of what it is used for
Face comparison and its resultBiometric processingA Ministry permit under Article 5 before any processing
Liveness analysisPerformed on the same face captureTreat it as part of the same biometric processing unless your own legal advice says otherwise

Reading a document is not biometric processing; comparing a face to it is. The two are often specified in the same sentence, which is how the permit gets missed.

The permit comes first

The sequence is not "get consent, then deploy". It is "obtain the permit, then deploy, with consent handled properly as well". The obligation to hold the permit falls on the controller — the institution verifying its customers — not on the software vendor.

That has a direct effect on the plan: a pilot on real customers' faces cannot start while the application is still pending. Put the permit on the timeline before the pilot, exactly as the same rule requires for facial attendance.

Hold as little as the process allows

Decide retention per artefact rather than for "the eKYC record" as a whole. The extracted fields, the card image, the selfie, the match result and the audit log serve different purposes and justify different periods. Write down each period with its reason, and confirm the periods with your own regulator rather than adopting a vendor default — the approach set out in what ID capture obliges you to keep and delete.

Protect the data in transit from the first moment. ekyciq's capture encrypts the ID image before it leaves the customer's device, so the document is never sent in the clear.

Share the result, not the raw data

When verified data moves on to the service that asked for it, it should carry what that service needs: the verified details and the outcome of the checks. It should not carry the selfie or the facial comparison data by default. Every copy of biometric data is one more copy to account for.

This is not legal advice, and it does not enumerate every obligation in the PDPL; read the primary text, and take advice on your own processing.

ekyciq is built with encryption and data privacy by design. See how ekyciq works, or talk to us about fitting identity verification to your data protection position.

You may also like

Related posts