Most discussion of Oman's data protection law is about customers. The largest and most sensitive collection of personal data in a typical company is its payroll.
The Personal Data Protection Law, issued by Royal Decree 6/2022, has been fully enforceable since 5 February 2026, when the transition period that followed the Executive Regulations expired. The grace period is the part that has ended; the obligations themselves have been public for years.
An HR and payroll system holds identity documents, bank details, salary, dependants, medical absence, disciplinary records and performance notes. If any system in the business is going to be asked to demonstrate compliance, it is this one — and the questions below are the ones it has to be able to answer without a project.
HR records under the PDPL
"On what basis are you processing this?"
The PDPL requires express consent before processing personal data, unless an excluded circumstance applies — among them performing a contract to which the data subject is a party, and complying with a legal obligation. Employment is exactly that situation, which is why consent is the wrong instrument to lean on for most payroll data.
This matters practically rather than academically. Consent can be withdrawn. If you have told an employee that you process their bank details on the basis of their consent, you have implied a right to withdraw it that you cannot honour, because you are obliged to pay wages through a regulated institution and record it. The defensible position is to identify which processing is contractual, which is a legal obligation, and which genuinely does rest on consent — and to treat only the last category as revocable.
The processing that really is consent-based tends to be the optional extras: a photograph on an internal directory, a wellbeing programme, biometric convenience features. Those need a real choice, and a real choice means the employee who declines is not disadvantaged.
"Who can see this record, and who did?"
Access control in HR systems is frequently coarse: a role called "HR" can see everything about everyone. That is administratively convenient and hard to defend, because most of those people have no need to read most of that data.
The harder question is the second one. Access control determines who can look; a log determines who did. Without the second, an allegation that a manager read a colleague's salary or medical absence cannot be investigated, only denied. A system that records reads as well as writes turns that from a dispute into a lookup.
"How long do you keep it, and why that long?"
Retention is where HR practice and data protection most often conflict, because both have a legitimate case. Labour and tax obligations require records to be kept for defined periods; the PDPL expects data not to be kept indefinitely without reason. Both are satisfiable, but only by writing the reason down per category rather than keeping everything forever because deleting feels risky.
The category that usually has no defence is recruitment. CVs and interview notes for candidates who were not hired sit in mailboxes and shared drives for years with no retention decision attached to them at all. That is the cheapest thing to fix on this list and the most commonly left undone.
"Where is it processed, and who is your DPO?"
The PDPL controls cross-border transfers, which makes the location of your payroll processing a compliance attribute rather than an implementation detail. If an HR platform processes or stores data outside Oman, that is a question to have an answer to before it is asked, not a reason for alarm.
Appointing a Data Protection Officer is mandatory for all entities under the PDPL — notably stricter than the risk-based test in the GDPR, which catches organisations whose advisers have assumed the European position applies. If nobody in your organisation holds that role by name, that is a gap that requires no investigation to confirm.
"It is Thursday evening and payroll data has leaked. What happens?"
Breaches that threaten the rights of data subjects must be notified to the Ministry within 72 hours, and affected individuals within the same window where serious harm results. Seventy-two hours is not long enough to design a process, so the process has to exist beforehand: who decides that something is notifiable, who writes the notification, who tells the employees, and who can answer what data was involved and whose. That last question is the one that consumes the time, and it is answerable in advance only if you know what your systems hold and who has touched it. Everything earlier in this article is what makes the 72-hour clock survivable.
The honest summary
None of this is exotic, and none of it is satisfied by a policy document. It is answerable only by systems that record what they hold, who reached it, on what basis and for how long. Read the primary text rather than a summary of it, including this one, and take legal advice on your own circumstances — this article describes what the law asks of a system, not what it means for your organisation.
inayaHR is built by Muscat Tech Solutions around Oman's labour law, PDPL and CBO wage protection, hosted and supported locally. For the mechanics of paying people correctly, see the SIF file and end-of-service gratuity. To talk through your own records, get in touch.
Related posts
-
Designing a Statement OCR Pilot Whose Result Actually Transfers
A pilot that passes and a production system that disappoints usually differ in the sample, not the software.
10 March 2026 -
From a Mulkiya Photo to a Motor Quote
Reading the card is the easy stage. The drop-off happens on either side of it.
24 February 2026 -
Face Recognition for Attendance: The Permit Most Buyers Do Not Know About
Employee consent is not the binding constraint. Article 5 of the PDPL is.
10 February 2026


