
Prima's data protection policy, written against the Personal Data Protection Law of the Sultanate of Oman — Royal Decree 6/2022 and its Executive Regulations under Ministerial Decision 34/2024. Roles, lawful basis, the processing record, sensitive-data permits, data subject rights, cross-border transfers and breach notification.

Prima holds no customer workload data. Bare-metal capacity means the customer administers its own systems and Prima has no logical access to them. The personal data Prima does hold is its own — personnel, visitors, contractors, commercial contacts.
Biometric access control requires a permit from MTCIT before processing begins. Article 5 prohibits it otherwise. Forty-five days to decide, and silence counts as refusal. This is the single blocking item in the whole policy.
Oman's regime rests on explicit written consent far more heavily than European law, with a list of situations where the law does not apply at all rather than a menu of alternative bases. Section 03 sets out how Prima works within that.

Oman's data protection regime is built from two instruments: the Personal Data Protection Law, issued under Royal Decree No. 6/2022 on 9 February 2022, and its Executive Regulations, issued under Ministerial Decision No. 34/2024 on 4 February 2024. The Regulations are where the operative detail sits — consent validity, permit procedure, transfer conditions, notification periods.
| Consent | Explicit, and valid only if given by a person of full capacity, clearly and without coercion, and recorded in writing or electronically. Executive Regulations, Article 4. |
|---|---|
| Privacy notice | Given to the data subject in writing before processing begins — not at the point of complaint. PDPL Article 14. |
| Sensitive data | Processing prohibited without a permit from MTCIT. PDPL Article 5. |
| Data subject rights | Access, correction, deletion, withdrawal of consent, portability, and complaint to MTCIT. Response within 45 days. |
| Records | Documentation of processing operations retained for the period set by the Regulations. PDPL Article 17. |
| Data protection officer | A DPO must be designated. PDPL Article 20. |
| Breach notification | Notify both MTCIT and the affected data subject. PDPL Article 19; qualifying breaches within 72 hours. |
| Cross-border transfer | Permitted under PDPL Article 23; the Regulations at Article 37 make the data subject's consent sufficient, without prior Ministry approval, provided the transfer does not prejudice national security or the higher interests of the State. |
| External audit | An auditor approved by MTCIT evaluates the controller's data protection arrangements. PDPL Article 16. |
Anyone arriving from a GDPR background will make two mistakes if these are not stated plainly.

Getting the role wrong is the most consequential error available in a data protection policy, because every obligation in the law attaches to a role. Prima occupies three different positions depending on the data, and the third is the one that matters commercially.
Prima decides why and how the data is processed. Applies to personnel, contractors, visitors, video, access records and commercial contacts — its own data about its own people and counterparties. Full obligations under the PDPL.
Prima processes on another party's instruction. A narrow position: contact details a customer supplies for its own named engineers so that access can be provisioned. Prima acts on the customer's determination, not its own.
Customer workload data. Prima is neither controller nor processor, because it has no access to it at all. It does not receive it, hold it, or have a technical path to it. There is no processing, so no role arises.
Most infrastructure providers claim to be a mere processor of customer data. Prima's position is stronger and different: on bare-metal GPU capacity there is no processing relationship at all. The customer receives dedicated hardware, administers its own operating systems, and holds its own credentials. Prima's staff have no logical route into a customer's allocation — not a restricted route, not a logged route, none.
This is verifiable architecturally rather than by assurance, which is what makes it worth stating. An auditor or a customer's counsel can test the claim by examining the access model rather than accepting a representation. The consequence is that a compromise of Prima cannot expose customer workload data, because Prima does not have it.
| Contractual | Set out in the Master Services Agreement and the Demarcation Matrix, PRM-DEM-2026-001, which draws the responsibility line element by element rather than in principle. |
|---|---|
| Technical | Tenant segregation in the fabric; no administrative credentials held by Prima for customer systems; sanitisation to NIST SP 800-88 before any hardware moves between customers. |
| Physical | Layer 4 and Layer 5 of the access model. Prima staff entering a customer cage do so under the conditions in PRM-SEC-2026-001, logged and recorded, and for a defined purpose. |
| Colocation variant | Where a customer owns the equipment, the same conclusion applies with more force: Prima provides space, power and cooling and has no involvement with the systems at all. |
| The exception to state | If Prima were ever to offer a managed service that touched customer systems, this analysis would change and the arrangement would need a processor agreement. No such service is offered today, and none should be offered without revisiting this section. |

The PDPL rests on the explicit consent of the data subject. It does not provide the menu of alternative bases familiar from European law. What it provides instead is Article 3 — a list of circumstances in which the law does not apply to the processing at all. The analysis for each activity is therefore a two-step one, and doing it in the wrong order produces consent requests that are unnecessary and, worse, misleading.
Three rules follow, and they are stated because the failure mode is always the same — a consent form used to legitimise processing the subject cannot realistically refuse.
Stated so that a reviewer does not have to look for it. Prima does not sell or share personal data for commercial purposes; does not send marketing without separate written consent, which the PDPL requires expressly; does not use personal data for automated decisions about individuals; does not process children's data; and does not use CCTV or access records for performance management of staff.

Article 17 requires documentation of processing operations. This and the following section are that record. Retention periods are the maximum held; data is deleted earlier where the purpose has ended.
| Processing activity | Role | Lawful basis under the PDPL | Retention |
|---|---|---|---|
| Recruitment and employment | |||
| Recruitment and selectionApplications, CVs, references, interview records | Controller | Consent of the candidate, taken at application. Unsuccessful candidates’ data deleted unless they consent to retention for future roles. | 12 months |
| Employment administrationContracts, payroll, tax, social insurance, leave, banking | Controller | Article 3 exemption — performance of legal obligations imposed on the employer under Omani labour, tax and social insurance law. | Term + 7 years |
| Competence and certification recordsQualifications, certifications, training completions, drill participation | Controller | Article 3 exemption — obligations arising under health and safety law, and contractual commitments to customers on competence. PRM-HR-2026-001. | Term + 7 years |
| Personnel vettingIdentity, right to work, employment history, criminal record where lawful | Controller | Consent, taken before screening begins, together with Article 3 where a check is legally required. Depth by tier under PRM-HR-2026-001. | Outcome only, term + 2 years |
| Occupational healthFitness for role, incident and injury records | Controller | Article 3 exemption for statutory reporting. Health data is sensitive — see section 06; held by HR only, not by line management. | Term + 7 years |
| Disciplinary and grievanceCase records, outcomes | Controller | Article 3 exemption — legal obligation and defence of legal claims. | Term + 3 years |
| Contractors and vendors | |||
| Contractor personnel administrationIdentity, employer, competence evidence, induction record | Controller | Consent at induction, plus Article 3 for safety obligations. Held for the duration of the engagement. | Engagement + 3 years |
| Vendor remote-access accountsNamed individual, credentials metadata, session records | Controller | Consent at account creation, disclosed in the vendor agreement. Session recording is disclosed before first use, never covert. | Engagement + 2 years |
| Supplier and partner contactsName, role, business contact details | Controller | Consent, or Article 3 where the contact detail is already in open sources such as a company filing or a published directory. | Relationship + 2 years |

| Processing activity | Role | Lawful basis under the PDPL | Retention |
|---|---|---|---|
| Site access and surveillance | |||
| Access control recordsIdentity, credential, time and place of every controlled transition | Controller | Consent at enrolment, plus Article 3 — protection of the facility engages public-interest and legal-obligation grounds. Basis confirmed with counsel. | 12 months |
| Biometric enrolmentFingerprint or hand geometry template at Layer 3 and above | Controller | Sensitive data. Requires an MTCIT permit under Article 5 — not yet held. Consent additionally required. See section 06 in full. | Term, then destroyed |
| Video surveillanceRecorded image of every person at a controlled transition | Controller | Consent through notice at the point of entry, plus Article 3 public-interest grounds. Retention set by the security commitment, not by convenience. | 90 days minimum |
| Visitor recordsName, organisation, host, purpose, times, identity verified | Controller | Consent at registration. Purpose limited to site security and cannot be reused for commercial contact. | 12 months |
| Access recertification recordsReviewer, decision, date per entitlement | Controller | Article 3 — evidence required by contractual audit rights and by the certification regime. | 3 years |
| Investigation filesVideo, access logs, statements relating to a specific incident | Controller | Article 3 — legal obligation, defence of claims, and cooperation with lawful requests under PRM-SEC-2026-001 §11. | Case + 3 years |
| Commercial and corporate | |||
| Customer contactsNamed individuals at customer and prospective customer organisations | Controller | Consent, or Article 3 where taken from open sources. Marketing to these contacts requires separate written consent, which the PDPL requires expressly. | Relationship + 2 years |
| Document request recordsEmail address supplied to receive a site brief or spec sheet | Controller | Consent, taken at the point of the request on the website. Used to send the document requested and to follow up on it; not sold, not shared. | 24 months |
| Corporate recordsDirectors, shareholders, beneficial owners, signatories | Controller | Article 3 exemption — statutory and regulatory filing obligations, banking and know-your-customer requirements. | Statutory periods |
| Export-control screeningNames screened against restricted-party lists, results, end-use statements | Controller | Article 3 — legal obligation under export control regimes. PC-ECP-001. | 7 years |

Article 5 of the PDPL prohibits the processing of sensitive personal data unless a permit has been obtained from MTCIT. This is a prohibition, not a condition — the processing is unlawful until the permit exists. It is the strongest single requirement in the law and the one that has direct consequences for Prima's security design.
Article 5 names data relating to genetic and biometric characteristics, health, ethnic origin, sexual life, political or religious opinions and beliefs, criminal convictions, and related security measures.
Biometric data — fingerprint or hand geometry templates used as an authentication factor at Layer 3 and above of the access model.
Health data — occupational health records, fitness-for-role assessments, and injury records arising under safety obligations.
No genetic data. No data on ethnic origin, sexual life, political opinion or religious belief is collected in any process, and none is inferred. Criminal record checks are conducted only where lawful in the jurisdiction of the individual, and only the outcome is retained — never the underlying record.
| Application | Made to MTCIT under the Executive Regulations, stating the classification of sensitive data, the purpose, the categories of subject, the security measures applied and the retention period. |
|---|---|
| Decision period | 45 days from application. |
| If the Ministry does not respond | The application is deemed rejected. Silence is refusal, not tacit approval — which makes tracking the deadline a governance duty rather than an administrative one. |
| Appeal | Within 60 days of notification of rejection. |
| Penalty for processing without a permit | A fine of not less than OMR 15,000 and not more than OMR 20,000, per offence, under the penalty provisions attaching to Article 5. |

Stated concretely, because a policy that identifies a blocking dependency without an alternative has only described the problem.
| Requirement to be met | Two independent authentication factors at every controlled layer from Layer 3 inward — the commitment in PRM-SEC-2026-001. |
|---|---|
| Without biometrics | Card credential plus PIN known only to the holder, with the PIN issued and reset through a controlled process. Two independent factors — something held and something known — and the requirement is satisfied. |
| What is lost | Resistance to credential sharing. A card and PIN can be handed to a colleague; a fingerprint cannot. This is a real reduction in control strength and is recorded as such rather than glossed over. |
| Compensating measures | Anti-passback and interlock at portals, video review of transitions at Layer 4 and above, and access recertification unchanged. Together these detect sharing after the fact even where they cannot prevent it. |
| Decision point | If the permit is not granted by October 2026, the fallback becomes the design and the biometric readers are commissioned as card-and-PIN devices. The decision is the COO's and is recorded, not left to drift. |
Occupational health records also fall within Article 5. Prima's position is to minimise rather than permit: line management receives a fitness-for-role outcome only — fit, fit with adjustment, or not fit — and never the underlying medical information, which is held by the occupational health provider. Injury records required by statutory reporting are handled under the Article 3 exemption for legal obligations. Where any processing beyond this becomes necessary, it requires its own permit and is not undertaken until one is held.

The PDPL grants six rights. The response period is 45 days — longer than the thirty days of comparable regimes, which makes missing it harder to excuse rather than easier.
| Right | What Prima does on receipt | Limits and refusals |
|---|---|---|
| Access | Provides a copy of the personal data held, the purposes, the recipients and the retention period. | Redacted where disclosure would reveal another person's data or compromise a security investigation |
| Correction | Corrects inaccurate data and notifies anyone it was disclosed to. | Records of past events are annotated, not rewritten |
| Deletion and erasure | Deletes where the purpose has ended and no retention obligation applies. | Refused where a statutory retention period or a legal-hold applies; refusal is explained |
| Withdrawal of consent | Stops the processing that rested on consent, and explains the operational consequence. | Does not undo lawful past processing; does not reach processing under an Article 3 exemption |
| Portability | Provides the data in a structured, machine-readable form. | Applies to data the subject provided, not to Prima's own records about them |
| Complaint to MTCIT | Provides the Ministry's contact route and does not obstruct or discourage it. | None. The right is unconditional |

Article 14 requires the controller to notify the data subject in writing, before processing begins. A notice published after collection has started does not cure the collection, and a notice that exists only on a website does not reach someone walking through a gate.
| Notice | Where it must appear | Status |
|---|---|---|
| Website privacy notice | Linked from every page of primacompute.com, and shown at the point the email address is requested for a document — not only in a footer. | Outstanding |
| Surveillance notice | Physically, at every point of entry and at the perimeter — in Arabic and English, legible, stating that recording takes place, by whom, why, and for how long. | Outstanding |
| Visitor notice | At registration, before identity details are taken. Signed or acknowledged electronically as part of the registration record. | Outstanding |
| Employee notice | Issued with the contract, before the effective date, and reissued on any material change to processing. | Outstanding |
| Contractor notice | At induction, alongside the safety and security briefing. | Outstanding |
| Biometric enrolment notice | At enrolment, stating the permit reference, that a template rather than an image is held, and the consequence of refusal. | Depends on the permit |
| Vendor access notice | In the vendor agreement, and again at the point of connection where session recording applies. | Outstanding |
Consent is worthless without proof of it. Every consent is recorded with who consented, to what, when, and by what means — the wording shown to them at the time, retained so that it can be produced later. A tick recorded without the text it referred to cannot be evidenced and is treated as no consent at all.

Article 23 permits transfer outside the Sultanate under conditions set by the Executive Regulations. Article 37 of the Regulations makes the data subject's consent sufficient, without prior approval from MTCIT, provided the transfer does not prejudice national security or the higher interests of the State. Two absolute prohibitions sit alongside: data may not be transferred if it was processed in breach of the law, or if the transfer would cause harm to the data subject.
There is no adequacy list to work through and no standard contractual clauses regime to execute. The obligation is simpler and, in one respect, stricter: consent must be informed as to destination. A consent that does not tell the person where their data is going is not consent to the transfer.
| Transfer | Destination | Basis and controls |
|---|---|---|
| Corporate email and productivity | Provider infrastructure outside Oman | Consent, disclosed in the employee and contractor notices with the destination named. Encrypted in transit and at rest. |
| Website hosting and the document-request function | Provider infrastructure outside Oman | Consent at the point of request, with the destination stated in the website notice — currently outstanding, see 8.2. |
| Autoresponder and transactional email | Provider infrastructure outside Oman | Consent at the point of request. Address used to send the document requested and nothing else. |
| Consortium and investor correspondence | Partner and adviser jurisdictions | Business contact details of named individuals, shared under NDA for a defined purpose. Consent or open-source origin. |
| Export-control screening | Screening provider, outside Oman | Article 3 exemption — legal obligation. Names submitted for restricted-party screening under PC-ECP-001. |
| Equipment vendor support | Vendor jurisdictions | Named engineer details for access provisioning. Consent at account creation, disclosed in the vendor agreement. |

Article 19 requires the controller to notify both MTCIT and the affected data subject of a breach leading to destruction, alteration, unlawful disclosure of, access to, or processing of personal data. Qualifying breaches are notified within 72 hours. Failure carries a fine of not less than OMR 15,000 and not more than OMR 20,000.
Many regimes require notification to the regulator and leave notification to individuals to a harm test. The PDPL names both. Prima therefore plans for both notifications from the first hour, rather than deciding later whether individuals need to be told.
| From detection | Action | Owner |
|---|---|---|
| Immediate | Contain. Stop the exposure before investigating it. Handled as a security incident under PRM-IRP-2026-001 at the severity the incident warrants. | Shift Lead, then CISO |
| Within 4 hours | Assess whether personal data is involved and whether the 72-hour duty is engaged. The clock starts at detection, not at conclusion of the assessment. | CISO with DPO |
| Within 12 hours | Establish what data, whose, how much, and whether it left Prima's control. Preserve evidence before remediation destroys it. | DPO |
| Within 24 hours | Draft both notifications. Inform the COO and, for anything material, the CEO and the board. | DPO with Legal |
| Within 72 hours | Notify MTCIT and the affected data subjects. Notify on incomplete information rather than late — the law does not accept an ongoing investigation as a reason to miss the period. | DPO, approved by COO |
| Following | Root-cause analysis, remediation tracked to closure, and a supplementary notification if the picture changes materially. | CISO |
Nature of the breach, categories and approximate number of subjects and records, likely consequences, measures taken and proposed, and the DPO's contact details. Filed by the DPO with the COO's approval.
What happened, what data of theirs was involved, what the likely consequence is for them, what Prima has done, what they should do, and how to contact the DPO or complain to MTCIT. In plain language, in Arabic and English.

The PDPL requires appropriate measures without prescribing them. Prima's are the ones already documented elsewhere, applied to personal data specifically — this policy adds no new control set, which is deliberate: a second, parallel security regime for personal data would be maintained worse than the first.
| Access | Least privilege by role. Personnel records reachable by HR and the DPO; security records by the CISO and named investigators; biometric templates by access-platform administrators only. |
|---|---|
| Classification | Personnel, security and biometric data classified Restricted — the highest class — under PRM-ISM-2026-001 §04. |
| Encryption | In transit for all administrative access and transfers; at rest on endpoints and backups. |
| Logging | Access to Restricted records is logged. Who opened a personnel or investigation file is itself a record. |
| Physical | Records held on site sit at Layer 3 or above of the access model. Paper records in controlled storage, never in an open office. |
| Disposal | Clear, Purge or Destroy per media type against NIST SP 800-88, witnessed, with a certificate per item — PRM-SEC-2026-001 §10. |
Retention periods are in the processing record at sections 04 and 05. Two rules govern how they are applied.
| Requirement | Article 20 requires the controller to designate a DPO, on conditions set by the Executive Regulations. |
|---|---|
| Prima's designation | The CISO holds the DPO function, reporting to the COO on data protection matters and with direct access to the CEO and the board on any matter of non-compliance. |
| Duties | Owns this policy and the processing record; holds the rights-request register; files breach notifications; runs the permit application at section 06; advises on new processing before it begins; and reports to the board. |
| Independence | The DPO cannot be instructed to reach a particular conclusion, and cannot be penalised for advising that a proposed processing activity is unlawful. Stated because the protection is worthless if unwritten. |
| Contact | A published route reaching the DPO directly — not a general enquiries address that a rights request could be lost in. |
| Conflict to watch | The CISO also owns security operations, which the DPO role must sometimes scrutinise. Acceptable at Prima's scale, and reviewed when headcount allows separation. The conflict is recorded rather than ignored. |
The PDPL contemplates evaluation of the controller's data protection arrangements by an auditor approved by MTCIT. Prima will appoint one once the policy set is in force and the processing record is populated — sequenced after the ISO 27001 stage 1 audit in November 2026, so that the same evidence base serves both and the two reviews do not contradict each other.

Stated because a policy that omits the consequence reads as advisory. The PDPL carries banded penalties, and the Ministry may separately impose administrative measures — warnings, suspension or cancellation of a processing permit, and administrative fines of up to OMR 2,000 per violation.
| Band | What it attaches to | Prima's exposure |
|---|---|---|
| OMR 1,000 – 5,000 | Failure to designate a DPO, to document processing, to observe retention, or to obtain written consent for commercial marketing. | Addressed by this policy and §11.3 |
| OMR 5,000 – 10,000 | Failure to apply the required processing controls and procedures. | Addressed by §11.1 |
| OMR 15,000 – 20,000 | Processing sensitive data without a permit, children's data, breach notification failure, and breach of confidentiality. | Live — biometric permit, §06 |
| OMR 100,000 – 500,000 | Unlawful cross-border transfer under Article 23 causing damage to the data subject. | Low — §09.3 keeps the sensitive categories in Oman |
| OMR 5,000 – 100,000 | Liability of the legal person where an offence is committed in its name by senior persons, including through approval, concealment or gross negligence. | Addressed by DPO independence, §11.3 |
| Action | Owner | By |
|---|---|---|
| Website privacy notice, and a statement at the point the email address is requestedPresently non-compliant — data is being collected today. Fixable this week | CISO | Immediately |
| File the MTCIT permit application for biometric processing45-day decision, silence is refusal. Blocks enrolment of the resident team | CISO, Legal | Aug 2026 |
| Omani counsel review — lawful basis analysis, employment exemptions, permit application | Legal | Aug 2026 |
| Issue this policy at v1.0, formally designate the DPO and publish the contact route | CISO | Sep 2026 |
| Employee, contractor, visitor and vendor notices; consent wording and recording | CISO, HR | Sep 2026 |
| Physical surveillance notices installed, Arabic and English, at every entry point | Facilities | Oct 2026 |
| Rights-request register and the 45-day tracking in operation | DPO | Oct 2026 |
| Breach notification rehearsed as a tabletop, with both notifications drafted in template | DPO, CISO | Nov 2026 |
| Decision point on the biometric fallback if no permit is held§6.4 — card and PIN becomes the design | COO | Oct 2026 |
| Appoint an MTCIT-approved auditor under Article 16 | CISO | Q1 2027 |

| Policy owner | CISO, in the DPO capacity, with Legal. Owns this policy, the processing record and the rights register. |
|---|---|
| Accountable officer | COO. Approves breach notifications and any decision to accept a data protection risk. Reports to the board. |
| New processing | Any new processing activity is assessed before it begins — basis, notice, retention, whether it engages Article 5, whether it involves a transfer. The assessment is recorded and the processing record updated. A new system procured without this assessment is a finding against the sponsor, not the DPO. |
| Training | Data protection included in induction for every person, and annually for anyone handling personnel, security or customer contact data. Recorded against the competence file under PRM-HR-2026-001. |
| Review | Annually, on any change to processing or to the law or its Regulations, and after any breach. Recorded even where nothing changes. |
| Measure | Target | Reported |
|---|---|---|
| Rights requests answered within 45 days | 100% | Quarterly |
| Rights requests answered within 14 days | ≥ 90% | Quarterly |
| Notifiable breaches notified within 72 hours | 100% | Per event |
| Processing activities with a current notice and recorded basis | 100% | Quarterly |
| Sensitive processing covered by a current MTCIT permit | 100% | Quarterly |
| Records deleted on schedule at the quarterly review | 100% | Quarterly |
| New processing assessed before it commenced | 100% | Quarterly |
| Staff with data protection training current | 100% | Annually |
| Personal data breaches | 0 | Monthly |
To exercise a right, to ask what personal data Prima holds about you, or to raise a data protection concern. You may also complain directly to the Ministry of Transport, Communications and Information Technology.