Employee data is sensitive and you have a relationship with the person. Visitor data is less sensitive and you have almost nothing — which makes it the harder problem.
Oman's Personal Data Protection Law, issued by Royal Decree 6/2022 and fully enforceable since February 2026, applies to a name written at a reception desk exactly as it applies to a payroll record. What differs is the ground you are standing on when you process it.
Visitor records under the PDPL
The asymmetry, side by side
| Employee | Visitor | |
|---|---|---|
| Basis for processing | Contract and legal obligation | Consent, or a legitimate security purpose you must articulate |
| Can they refuse? | Rarely meaningfully | Yes — and then what? You still need a record |
| Privacy notice | Given at onboarding, with time to read | Must land in seconds, at a door, in the right language |
| Exercising their rights | Knows who to ask; has an HR contact | Visited once, has no login, may not recall which entity holds it |
| Retention driver | Labour and tax law set defined periods | Nothing sets a period, so records accumulate forever |
Read down the right-hand column and the shape of the problem appears. Every structural convenience you have with employees is absent, and the last row is where most organisations are quietly non-compliant: there is no statutory reason to keep a visitor record for seven years, and no process that deletes it either.
The consent trap at the door
Leaning on consent for visitor data creates the same problem it creates for employees, for a different reason. A visitor asked to consent at a turnstile, with a host waiting and a meeting starting, is not making a considered decision. And consent is withdrawable — so a visitor may later ask you to delete the record of a visit that your security obligations require you to retain.
The more defensible position is to separate the two purposes clearly. The security record of who was on site is not there because the visitor agreed to it; it exists because a building has to know who is inside it, and that purpose stands on its own. Marketing follow-up, adding someone to a mailing list, or keeping their details for future convenience are entirely different purposes, and those genuinely do need consent that can be declined without consequence.
Conflating them is the common error: one tick box covering both, which means the security record inherits the revocability of the marketing permission.
A notice nobody will read, in the language they use
The PDPL expects clear information about processing. At a reception desk you have a few seconds and a small screen, and a visitor who is already late. A five-screen policy scrolled past is compliance theatre; it satisfies nobody and demonstrates nothing.
What works is short and layered: one sentence on why the record exists and how long it is kept, in Arabic or English at the visitor's choice, with the full notice one tap away for anyone who wants it. The language point is not decoration. A notice presented only in English to a visitor who reads Arabic has not informed them, whatever it says.
What you are not collecting is an advantage
It is worth noticing which design choices reduce your obligations rather than manage them. Verifying a visitor by one-time code to their own phone establishes that the contact detail is real while holding only a phone number. Capturing a facial image or fingerprint instead would establish identity more strongly — and would move the whole system into the biometric category, which under Article 5 of the PDPL is prohibited without a Ministry permit, as biometric attendance systems have to deal with.
For a reception desk that is a poor trade, and avoiding it is a deliberate design decision rather than a limitation. The same logic applies to photographing ID documents: it feels rigorous, and it means you now hold a copy of a passport for every visitor, with a retention question and a breach exposure attached to each one.
The 72-hour clock, and the question it asks
Breaches that threaten data subjects' rights must be notified to the Ministry within 72 hours, and affected individuals within the same window where serious harm results. For a visitor system that raises a specific difficulty: notifying employees is straightforward because you know how to reach them, and notifying four thousand people who visited once over three years is a different exercise entirely — you hold a phone number and nothing else, and some of those numbers are stale. That is the strongest practical argument for a retention period that actually deletes: the smaller the historical record, the smaller the notification problem you are one incident away from.
The honest summary
Visitor data is low-sensitivity and high-awkwardness. Get three things right and most of it resolves: a stated purpose that does not depend on consent for the security record, a retention period that runs automatically, and a notice a rushed person can absorb in their own language. This describes what the law asks of a system, not what it means for your organisation — read the primary text and take advice. For what the record has to prove operationally, see the questions a visitor book cannot answer.
Muscat Tech Solutions builds a visitor management system verified by one-time code in Arabic or English, hosted and supported in Oman. To review your own visitor records, get in touch.
Related posts
-
Employee Data Under the PDPL: The Questions HR Now Has to Answer
The transition period ended in February 2026. Payroll holds most of the data the law is about.
24 March 2026 -
Designing a Statement OCR Pilot Whose Result Actually Transfers
A pilot that passes and a production system that disappoints usually differ in the sample, not the software.
10 March 2026 -
From a Mulkiya Photo to a Motor Quote
Reading the card is the easy stage. The drop-off happens on either side of it.
24 February 2026


