Prima — Data Protection & Privacy Policy · A4 · 16pp · Draft v0.1
DRAFT
Draft
Part ofPetroCompute
Data Protection & Privacy Policy
Personal data under
Omani law — what we
hold and what we owe

Prima's data protection policy, written against the Personal Data Protection Law of the Sultanate of Oman — Royal Decree 6/2022 and its Executive Regulations under Ministerial Decision 34/2024. Roles, lawful basis, the processing record, sensitive-data permits, data subject rights, cross-border transfers and breach notification.

Document
PRM-DPP-2026-001
Version
0.1 — Draft
Classification
Internal — controlled
Owner
CISO, with Legal
Regulator
MTCIT, Oman
45d
To answer a data
subject request
72h
To notify MTCIT
of a breach
1
Permit required —
biometric access
0
Customer datasets
in our custody
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled01 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 02 / 16
The three things to take from this document
Narrow exposure

Prima holds no customer workload data. Bare-metal capacity means the customer administers its own systems and Prima has no logical access to them. The personal data Prima does hold is its own — personnel, visitors, contractors, commercial contacts.

Verifiable architecturally
One hard permit

Biometric access control requires a permit from MTCIT before processing begins. Article 5 prohibits it otherwise. Forty-five days to decide, and silence counts as refusal. This is the single blocking item in the whole policy.

Section 06
Consent-first law

Oman's regime rests on explicit written consent far more heavily than European law, with a list of situations where the law does not apply at all rather than a menu of alternative bases. Section 03 sets out how Prima works within that.

Section 03
Standing of this documentThis is Prima's internal policy, drafted to align with the PDPL and its Executive Regulations. It is not legal advice and does not substitute for it. Review by Omani counsel is required before issue at version 1.0 — in particular on the lawful basis analysis at section 03, the permit application at section 06, and the interaction between the Article 3 exemptions and employment processing.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled02 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 03 / 16
01The law, the timing, and why this is not a future project

Oman's data protection regime is built from two instruments: the Personal Data Protection Law, issued under Royal Decree No. 6/2022 on 9 February 2022, and its Executive Regulations, issued under Ministerial Decision No. 34/2024 on 4 February 2024. The Regulations are where the operative detail sits — consent validity, permit procedure, transfer conditions, notification periods.

TimingThe extended transition period ended on 5 February 2026. The law is now fully enforceable and the Ministry of Transport, Communications and Information Technology is actively supervising compliance. There is no grace period remaining, and no basis for treating this as something to address alongside the facility opening.
1.1 What is required, in one table
ConsentExplicit, and valid only if given by a person of full capacity, clearly and without coercion, and recorded in writing or electronically. Executive Regulations, Article 4.
Privacy noticeGiven to the data subject in writing before processing begins — not at the point of complaint. PDPL Article 14.
Sensitive dataProcessing prohibited without a permit from MTCIT. PDPL Article 5.
Data subject rightsAccess, correction, deletion, withdrawal of consent, portability, and complaint to MTCIT. Response within 45 days.
RecordsDocumentation of processing operations retained for the period set by the Regulations. PDPL Article 17.
Data protection officerA DPO must be designated. PDPL Article 20.
Breach notificationNotify both MTCIT and the affected data subject. PDPL Article 19; qualifying breaches within 72 hours.
Cross-border transferPermitted under PDPL Article 23; the Regulations at Article 37 make the data subject's consent sufficient, without prior Ministry approval, provided the transfer does not prejudice national security or the higher interests of the State.
External auditAn auditor approved by MTCIT evaluates the controller's data protection arrangements. PDPL Article 16.
1.2 Two features that differ from European practice

Anyone arriving from a GDPR background will make two mistakes if these are not stated plainly.

  1. There is effectively one lawful basis, not six. The PDPL rests on the data subject's explicit consent. It does not offer legitimate interests, and it does not offer a general contractual-necessity basis in the way European law does. Instead it lists situations in which the law does not apply at all — Article 3. The analysis is therefore about whether an exemption applies, not which basis to select. Section 03.
  2. Consent alone can support a cross-border transfer. There is no adequacy list to work through and no standard contractual clauses regime to execute. The condition is consent, plus the overriding limits on national security and harm to the data subject. Section 09.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled03 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 04 / 16
02Roles — where Prima is a controller, and where it is nothing at all

Getting the role wrong is the most consequential error available in a data protection policy, because every obligation in the law attaches to a role. Prima occupies three different positions depending on the data, and the third is the one that matters commercially.

Controller

Prima decides why and how the data is processed. Applies to personnel, contractors, visitors, video, access records and commercial contacts — its own data about its own people and counterparties. Full obligations under the PDPL.

Sections 04 and 05
Processor

Prima processes on another party's instruction. A narrow position: contact details a customer supplies for its own named engineers so that access can be provisioned. Prima acts on the customer's determination, not its own.

Limited to access administration
Neither

Customer workload data. Prima is neither controller nor processor, because it has no access to it at all. It does not receive it, hold it, or have a technical path to it. There is no processing, so no role arises.

The commercially important one
2.1 Why the third position is not a disclaimer

Most infrastructure providers claim to be a mere processor of customer data. Prima's position is stronger and different: on bare-metal GPU capacity there is no processing relationship at all. The customer receives dedicated hardware, administers its own operating systems, and holds its own credentials. Prima's staff have no logical route into a customer's allocation — not a restricted route, not a logged route, none.

This is verifiable architecturally rather than by assurance, which is what makes it worth stating. An auditor or a customer's counsel can test the claim by examining the access model rather than accepting a representation. The consequence is that a compromise of Prima cannot expose customer workload data, because Prima does not have it.

2.2 Where the boundary is drawn, and by what
ContractualSet out in the Master Services Agreement and the Demarcation Matrix, PRM-DEM-2026-001, which draws the responsibility line element by element rather than in principle.
TechnicalTenant segregation in the fabric; no administrative credentials held by Prima for customer systems; sanitisation to NIST SP 800-88 before any hardware moves between customers.
PhysicalLayer 4 and Layer 5 of the access model. Prima staff entering a customer cage do so under the conditions in PRM-SEC-2026-001, logged and recorded, and for a defined purpose.
Colocation variantWhere a customer owns the equipment, the same conclusion applies with more force: Prima provides space, power and cooling and has no involvement with the systems at all.
The exception to stateIf Prima were ever to offer a managed service that touched customer systems, this analysis would change and the arrangement would need a processor agreement. No such service is offered today, and none should be offered without revisiting this section.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled04 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 05 / 16
03Lawful basis in a consent-first regime

The PDPL rests on the explicit consent of the data subject. It does not provide the menu of alternative bases familiar from European law. What it provides instead is Article 3 — a list of circumstances in which the law does not apply to the processing at all. The analysis for each activity is therefore a two-step one, and doing it in the wrong order produces consent requests that are unnecessary and, worse, misleading.

3.1 The two-step test Prima applies
  1. Does an Article 3 exemption cover this processing? The exemptions include performance of a legal obligation imposed on the controller by law, judgment or court decision; protection of national security or public interest; and data already available in open sources. Where an exemption applies, the processing proceeds on that footing.
  2. If not, is there valid explicit consent? Consent must come from a person of full capacity, be given clearly and without coercion, and be recorded in writing or electronically — Executive Regulations, Article 4. If neither step is satisfied, the processing does not happen.
Where this is delicate — employmentConsent given by an employee to their employer is weak everywhere, because the power imbalance undermines “without coercion”. Prima therefore relies on Article 3 exemptions for core employment processing — payroll, tax, social insurance, statutory records — and reserves consent for processing that is genuinely optional. This analysis is the first item for Omani counsel to confirm, and it is flagged rather than assumed.
3.2 Consent is never used as a cover for something else

Three rules follow, and they are stated because the failure mode is always the same — a consent form used to legitimise processing the subject cannot realistically refuse.

  • Consent must be refusable. If refusing would cost the person their job, their site access or their contract, consent is not the right basis and an exemption analysis must be done instead.
  • Consent is specific. One consent does not cover a second purpose. A visitor consenting to identity verification has not consented to their image being used for anything beyond site security.
  • Consent is withdrawable, and withdrawal has consequences that are explained in advance. A contractor who withdraws consent to biometric enrolment cannot be given unescorted access — that is a legitimate operational consequence, and it is disclosed at the point of enrolment rather than discovered afterwards.
3.3 What Prima does not do

Stated so that a reviewer does not have to look for it. Prima does not sell or share personal data for commercial purposes; does not send marketing without separate written consent, which the PDPL requires expressly; does not use personal data for automated decisions about individuals; does not process children's data; and does not use CCTV or access records for performance management of staff.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled05 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 06 / 16
04Record of processing — personnel and contractorsPDPL Art. 17

Article 17 requires documentation of processing operations. This and the following section are that record. Retention periods are the maximum held; data is deleted earlier where the purpose has ended.

Processing activityRoleLawful basis under the PDPLRetention
Recruitment and employment
Recruitment and selectionApplications, CVs, references, interview recordsControllerConsent of the candidate, taken at application. Unsuccessful candidates’ data deleted unless they consent to retention for future roles.12 months
Employment administrationContracts, payroll, tax, social insurance, leave, bankingControllerArticle 3 exemption — performance of legal obligations imposed on the employer under Omani labour, tax and social insurance law.Term + 7 years
Competence and certification recordsQualifications, certifications, training completions, drill participationControllerArticle 3 exemption — obligations arising under health and safety law, and contractual commitments to customers on competence. PRM-HR-2026-001.Term + 7 years
Personnel vettingIdentity, right to work, employment history, criminal record where lawfulControllerConsent, taken before screening begins, together with Article 3 where a check is legally required. Depth by tier under PRM-HR-2026-001.Outcome only,
term + 2 years
Occupational healthFitness for role, incident and injury recordsControllerArticle 3 exemption for statutory reporting. Health data is sensitive — see section 06; held by HR only, not by line management.Term + 7 years
Disciplinary and grievanceCase records, outcomesControllerArticle 3 exemption — legal obligation and defence of legal claims.Term + 3 years
Contractors and vendors
Contractor personnel administrationIdentity, employer, competence evidence, induction recordControllerConsent at induction, plus Article 3 for safety obligations. Held for the duration of the engagement.Engagement + 3 years
Vendor remote-access accountsNamed individual, credentials metadata, session recordsControllerConsent at account creation, disclosed in the vendor agreement. Session recording is disclosed before first use, never covert.Engagement + 2 years
Supplier and partner contactsName, role, business contact detailsControllerConsent, or Article 3 where the contact detail is already in open sources such as a company filing or a published directory.Relationship + 2 years
Note on session recordingRecording a vendor engineer’s administrative session is disclosed in the vendor agreement and again at the point of connection. Covert monitoring would be both unlawful and unnecessary — the control works precisely because the engineer knows the session is recorded.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled06 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 07 / 16
05Record of processing — site, security and commercial
Processing activityRoleLawful basis under the PDPLRetention
Site access and surveillance
Access control recordsIdentity, credential, time and place of every controlled transitionControllerConsent at enrolment, plus Article 3 — protection of the facility engages public-interest and legal-obligation grounds. Basis confirmed with counsel.12 months
Biometric enrolmentFingerprint or hand geometry template at Layer 3 and aboveControllerSensitive data. Requires an MTCIT permit under Article 5 — not yet held. Consent additionally required. See section 06 in full.Term, then destroyed
Video surveillanceRecorded image of every person at a controlled transitionControllerConsent through notice at the point of entry, plus Article 3 public-interest grounds. Retention set by the security commitment, not by convenience.90 days minimum
Visitor recordsName, organisation, host, purpose, times, identity verifiedControllerConsent at registration. Purpose limited to site security and cannot be reused for commercial contact.12 months
Access recertification recordsReviewer, decision, date per entitlementControllerArticle 3 — evidence required by contractual audit rights and by the certification regime.3 years
Investigation filesVideo, access logs, statements relating to a specific incidentControllerArticle 3 — legal obligation, defence of claims, and cooperation with lawful requests under PRM-SEC-2026-001 §11.Case + 3 years
Commercial and corporate
Customer contactsNamed individuals at customer and prospective customer organisationsControllerConsent, or Article 3 where taken from open sources. Marketing to these contacts requires separate written consent, which the PDPL requires expressly.Relationship + 2 years
Document request recordsEmail address supplied to receive a site brief or spec sheetControllerConsent, taken at the point of the request on the website. Used to send the document requested and to follow up on it; not sold, not shared.24 months
Corporate recordsDirectors, shareholders, beneficial owners, signatoriesControllerArticle 3 exemption — statutory and regulatory filing obligations, banking and know-your-customer requirements.Statutory periods
Export-control screeningNames screened against restricted-party lists, results, end-use statementsControllerArticle 3 — legal obligation under export control regimes. PC-ECP-001.7 years
The two rows that need actionBiometric enrolment cannot lawfully begin until the MTCIT permit is held — section 06. Video surveillance is lawful but requires a compliant notice at every entry point, which does not yet exist in the form the law requires — section 08.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled07 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 08 / 16
06Sensitive data and the MTCIT permitPDPL Art. 5

Article 5 of the PDPL prohibits the processing of sensitive personal data unless a permit has been obtained from MTCIT. This is a prohibition, not a condition — the processing is unlawful until the permit exists. It is the strongest single requirement in the law and the one that has direct consequences for Prima's security design.

6.1 What counts as sensitive

Article 5 names data relating to genetic and biometric characteristics, health, ethnic origin, sexual life, political or religious opinions and beliefs, criminal convictions, and related security measures.

Prima processes two of these

Biometric data — fingerprint or hand geometry templates used as an authentication factor at Layer 3 and above of the access model.

Health data — occupational health records, fitness-for-role assessments, and injury records arising under safety obligations.

Both engage Article 5
Prima processes none of the others

No genetic data. No data on ethnic origin, sexual life, political opinion or religious belief is collected in any process, and none is inferred. Criminal record checks are conducted only where lawful in the jurisdiction of the individual, and only the outcome is retained — never the underlying record.

Stated so it is not assumed
6.2 The permit — procedure and timing
ApplicationMade to MTCIT under the Executive Regulations, stating the classification of sensitive data, the purpose, the categories of subject, the security measures applied and the retention period.
Decision period45 days from application.
If the Ministry does not respondThe application is deemed rejected. Silence is refusal, not tacit approval — which makes tracking the deadline a governance duty rather than an administrative one.
AppealWithin 60 days of notification of rejection.
Penalty for processing without a permitA fine of not less than OMR 15,000 and not more than OMR 20,000, per offence, under the penalty provisions attaching to Article 5.
Action required — and its consequence for the security designThe biometric permit application must be filed no later than August 2026 to be decided before the resident team is enrolled and the facility reaches service in December. If the permit is refused or delayed, biometric factors cannot be used, and the multi-factor requirement at Layers 3 to 5 of PRM-SEC-2026-001 must be met by a different second factor. The security design therefore needs a documented fallback, not an assumption that the permit will arrive.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled08 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 09 / 16
06Sensitive data, continuedHandling and fallback
6.3 How biometric data is handled once permitted
  1. Template, not image. The reader stores a mathematical template from which the original biometric cannot be reconstructed. No fingerprint or hand image is retained anywhere in the estate.
  2. Held on the access platform only. Never copied into HR systems, never exported, never included in a report. The template exists in one place and is reachable only by the access-platform administrators named in PRM-SEC-2026-001.
  3. Consent in addition to the permit. The permit makes the processing lawful in principle; the individual's explicit written consent is still taken at enrolment, with the consequence of refusal explained in advance.
  4. Destroyed at departure. The template is deleted when the person leaves or their entitlement is withdrawn, verified at the next access recertification cycle rather than left to the leaver process alone.
  5. Never used for anything but authentication. Not for timekeeping, not for attendance, not for productivity. Any such reuse would be a new purpose requiring a new basis and a new permit.
6.4 The fallback if the permit is not held

Stated concretely, because a policy that identifies a blocking dependency without an alternative has only described the problem.

Requirement to be metTwo independent authentication factors at every controlled layer from Layer 3 inward — the commitment in PRM-SEC-2026-001.
Without biometricsCard credential plus PIN known only to the holder, with the PIN issued and reset through a controlled process. Two independent factors — something held and something known — and the requirement is satisfied.
What is lostResistance to credential sharing. A card and PIN can be handed to a colleague; a fingerprint cannot. This is a real reduction in control strength and is recorded as such rather than glossed over.
Compensating measuresAnti-passback and interlock at portals, video review of transitions at Layer 4 and above, and access recertification unchanged. Together these detect sharing after the fact even where they cannot prevent it.
Decision pointIf the permit is not granted by October 2026, the fallback becomes the design and the biometric readers are commissioned as card-and-PIN devices. The decision is the COO's and is recorded, not left to drift.
6.5 Health data

Occupational health records also fall within Article 5. Prima's position is to minimise rather than permit: line management receives a fitness-for-role outcome only — fit, fit with adjustment, or not fit — and never the underlying medical information, which is held by the occupational health provider. Injury records required by statutory reporting are handled under the Article 3 exemption for legal obligations. Where any processing beyond this becomes necessary, it requires its own permit and is not undertaken until one is held.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled09 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 10 / 16
07Data subject rights and the 45-day clock

The PDPL grants six rights. The response period is 45 days — longer than the thirty days of comparable regimes, which makes missing it harder to excuse rather than easier.

RightWhat Prima does on receiptLimits and refusals
AccessProvides a copy of the personal data held, the purposes, the recipients and the retention period.Redacted where disclosure would reveal another person's data or compromise a security investigation
CorrectionCorrects inaccurate data and notifies anyone it was disclosed to.Records of past events are annotated, not rewritten
Deletion and erasureDeletes where the purpose has ended and no retention obligation applies.Refused where a statutory retention period or a legal-hold applies; refusal is explained
Withdrawal of consentStops the processing that rested on consent, and explains the operational consequence.Does not undo lawful past processing; does not reach processing under an Article 3 exemption
PortabilityProvides the data in a structured, machine-readable form.Applies to data the subject provided, not to Prima's own records about them
Complaint to MTCITProvides the Ministry's contact route and does not obstruct or discourage it.None. The right is unconditional
7.1 How a request is handled
  1. Any route counts. A request to any Prima address, to any employee, verbally or in writing, is a valid request. There is no prescribed form and requiring one would be unlawful. Anyone receiving one forwards it to the DPO the same day.
  2. Identity verified proportionately. Enough to be confident, not enough to become a barrier. Requesting a document the subject does not have is a refusal dressed as a process.
  3. Logged on receipt, with the date the 45-day period expires calculated and visible from that moment. The DPO holds the register.
  4. Answered in full or refused with reasons. A partial answer that does not say what was withheld and why is treated as a failure to respond.
  5. Free of charge. No fee for a first request.
  6. Escalated at day 30 if not resolved, to the CISO and then the COO. Waiting until day 44 to discover a problem is the predictable failure and the escalation exists to prevent it.
Requests that will actually arriveRealistically: a former employee or contractor asking what access and video records are held about them, and a website visitor asking for their email address to be deleted from the document-request list. Both are straightforward, and both are answered inside a week rather than at day 44. The document-request list is the one an outsider is most likely to test, because it is the only place Prima collects personal data from the public.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled10 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 11 / 16
08Privacy notices and how consent is takenPDPL Art. 14

Article 14 requires the controller to notify the data subject in writing, before processing begins. A notice published after collection has started does not cure the collection, and a notice that exists only on a website does not reach someone walking through a gate.

8.1 What every notice must state
  • Who the controller is — Prima Artificial Intelligence LLC, CR 1575008, with the DPO contact route.
  • What data is collected, specifically. “Personal information” is not a category.
  • Why, and on what basis — consent, or the Article 3 exemption relied upon.
  • Who it is shared with, including whether it leaves Oman and to where.
  • How long it is kept.
  • The rights available, how to exercise them, and the right to complain to MTCIT.
  • The consequence of refusing, where consent is the basis.
8.2 The notices Prima needs, and where each has to appear
NoticeWhere it must appearStatus
Website privacy noticeLinked from every page of primacompute.com, and shown at the point the email address is requested for a document — not only in a footer.Outstanding
Surveillance noticePhysically, at every point of entry and at the perimeter — in Arabic and English, legible, stating that recording takes place, by whom, why, and for how long.Outstanding
Visitor noticeAt registration, before identity details are taken. Signed or acknowledged electronically as part of the registration record.Outstanding
Employee noticeIssued with the contract, before the effective date, and reissued on any material change to processing.Outstanding
Contractor noticeAt induction, alongside the safety and security briefing.Outstanding
Biometric enrolment noticeAt enrolment, stating the permit reference, that a template rather than an image is held, and the consequence of refusal.Depends on the permit
Vendor access noticeIn the vendor agreement, and again at the point of connection where session recording applies.Outstanding
The gap that is live todayPrima is already collecting personal data from the public — email addresses supplied on primacompute.com to receive a site brief or spec sheet — and the website carries no privacy notice. The law has been fully enforceable since 5 February 2026. This is the one item in the whole policy that is presently non-compliant and fixable this week: a website privacy notice, and a line at the point of the request stating what the address is used for and how to have it removed.
8.3 How consent is recorded

Consent is worthless without proof of it. Every consent is recorded with who consented, to what, when, and by what means — the wording shown to them at the time, retained so that it can be produced later. A tick recorded without the text it referred to cannot be evidenced and is treated as no consent at all.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled11 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 12 / 16
09Transfers outside OmanPDPL Art. 23

Article 23 permits transfer outside the Sultanate under conditions set by the Executive Regulations. Article 37 of the Regulations makes the data subject's consent sufficient, without prior approval from MTCIT, provided the transfer does not prejudice national security or the higher interests of the State. Two absolute prohibitions sit alongside: data may not be transferred if it was processed in breach of the law, or if the transfer would cause harm to the data subject.

9.1 What this means practically

There is no adequacy list to work through and no standard contractual clauses regime to execute. The obligation is simpler and, in one respect, stricter: consent must be informed as to destination. A consent that does not tell the person where their data is going is not consent to the transfer.

9.2 Prima's actual transfers
TransferDestinationBasis and controls
Corporate email and productivityProvider infrastructure outside OmanConsent, disclosed in the employee and contractor notices with the destination named. Encrypted in transit and at rest.
Website hosting and the document-request functionProvider infrastructure outside OmanConsent at the point of request, with the destination stated in the website notice — currently outstanding, see 8.2.
Autoresponder and transactional emailProvider infrastructure outside OmanConsent at the point of request. Address used to send the document requested and nothing else.
Consortium and investor correspondencePartner and adviser jurisdictionsBusiness contact details of named individuals, shared under NDA for a defined purpose. Consent or open-source origin.
Export-control screeningScreening provider, outside OmanArticle 3 exemption — legal obligation. Names submitted for restricted-party screening under PC-ECP-001.
Equipment vendor supportVendor jurisdictionsNamed engineer details for access provisioning. Consent at account creation, disclosed in the vendor agreement.
9.3 What is never transferred
  • Biometric templates. Held only on the on-site access platform. Never exported, never replicated to a cloud service, never included in a backup that leaves Oman.
  • Video recordings. Retained on site. Released only under the lawful-request procedure in PRM-SEC-2026-001 §11, and a request from a foreign authority is handled through the Omani legal route rather than answered directly.
  • Access logs and investigation files. On site, for the same reasons.
  • Occupational health records. Held by the provider within Oman.
Why this list is short and deliberateThe categories that never leave Oman are exactly the ones a sovereign customer or a regulator would ask about. Keeping surveillance, access and biometric data on-site is a design decision rather than an accident of architecture, and it is what allows Prima to answer the data-residency question in one sentence.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled12 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 13 / 16
10Breach notification — the 72-hour dutyPDPL Art. 19

Article 19 requires the controller to notify both MTCIT and the affected data subject of a breach leading to destruction, alteration, unlawful disclosure of, access to, or processing of personal data. Qualifying breaches are notified within 72 hours. Failure carries a fine of not less than OMR 15,000 and not more than OMR 20,000.

10.1 The duty is dual, and that is the part most often missed

Many regimes require notification to the regulator and leave notification to individuals to a harm test. The PDPL names both. Prima therefore plans for both notifications from the first hour, rather than deciding later whether individuals need to be told.

10.2 Sequence, against the clock
From detectionActionOwner
ImmediateContain. Stop the exposure before investigating it. Handled as a security incident under PRM-IRP-2026-001 at the severity the incident warrants.Shift Lead, then CISO
Within 4 hoursAssess whether personal data is involved and whether the 72-hour duty is engaged. The clock starts at detection, not at conclusion of the assessment.CISO with DPO
Within 12 hoursEstablish what data, whose, how much, and whether it left Prima's control. Preserve evidence before remediation destroys it.DPO
Within 24 hoursDraft both notifications. Inform the COO and, for anything material, the CEO and the board.DPO with Legal
Within 72 hoursNotify MTCIT and the affected data subjects. Notify on incomplete information rather than late — the law does not accept an ongoing investigation as a reason to miss the period.DPO, approved by COO
FollowingRoot-cause analysis, remediation tracked to closure, and a supplementary notification if the picture changes materially.CISO
10.3 What each notification contains
To MTCIT

Nature of the breach, categories and approximate number of subjects and records, likely consequences, measures taken and proposed, and the DPO's contact details. Filed by the DPO with the COO's approval.

Within 72 hours
To the data subject

What happened, what data of theirs was involved, what the likely consequence is for them, what Prima has done, what they should do, and how to contact the DPO or complain to MTCIT. In plain language, in Arabic and English.

Within 72 hours
Breach historyNo personal data breach has occurred. Prima has not yet commenced operations, holds no customer data, and has no history to disclose. This will be stated as a positive assertion in diligence rather than as an absence — and it stops being a useful statement the moment it is untrue, which is why the notification duty is rehearsed before it is needed.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled13 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 14 / 16
11Security, retention, the DPO and external audit
11.1 Security of processing

The PDPL requires appropriate measures without prescribing them. Prima's are the ones already documented elsewhere, applied to personal data specifically — this policy adds no new control set, which is deliberate: a second, parallel security regime for personal data would be maintained worse than the first.

AccessLeast privilege by role. Personnel records reachable by HR and the DPO; security records by the CISO and named investigators; biometric templates by access-platform administrators only.
ClassificationPersonnel, security and biometric data classified Restricted — the highest class — under PRM-ISM-2026-001 §04.
EncryptionIn transit for all administrative access and transfers; at rest on endpoints and backups.
LoggingAccess to Restricted records is logged. Who opened a personnel or investigation file is itself a record.
PhysicalRecords held on site sit at Layer 3 or above of the access model. Paper records in controlled storage, never in an open office.
DisposalClear, Purge or Destroy per media type against NIST SP 800-88, witnessed, with a certificate per item — PRM-SEC-2026-001 §10.
11.2 Retention and deletion

Retention periods are in the processing record at sections 04 and 05. Two rules govern how they are applied.

  • Deletion is scheduled, not incidental. A quarterly review identifies records past retention and deletes them. Data that outlives its purpose because nobody looked is the most common breach of this law, and the least dramatic.
  • Legal hold overrides retention. Where a dispute, investigation or regulatory request is live, the affected records are held until it closes — recorded as a hold with a reason and an owner, not left as an unexplained exception.
11.3 The Data Protection Officer
RequirementArticle 20 requires the controller to designate a DPO, on conditions set by the Executive Regulations.
Prima's designationThe CISO holds the DPO function, reporting to the COO on data protection matters and with direct access to the CEO and the board on any matter of non-compliance.
DutiesOwns this policy and the processing record; holds the rights-request register; files breach notifications; runs the permit application at section 06; advises on new processing before it begins; and reports to the board.
IndependenceThe DPO cannot be instructed to reach a particular conclusion, and cannot be penalised for advising that a proposed processing activity is unlawful. Stated because the protection is worthless if unwritten.
ContactA published route reaching the DPO directly — not a general enquiries address that a rights request could be lost in.
Conflict to watchThe CISO also owns security operations, which the DPO role must sometimes scrutinise. Acceptable at Prima's scale, and reviewed when headcount allows separation. The conflict is recorded rather than ignored.
11.4 External audit — Article 16

The PDPL contemplates evaluation of the controller's data protection arrangements by an auditor approved by MTCIT. Prima will appoint one once the policy set is in force and the processing record is populated — sequenced after the ISO 27001 stage 1 audit in November 2026, so that the same evidence base serves both and the two reviews do not contradict each other.

© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled14 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 15 / 16
12Penalties, gap position, governance and measures
12.1 What non-compliance costs

Stated because a policy that omits the consequence reads as advisory. The PDPL carries banded penalties, and the Ministry may separately impose administrative measures — warnings, suspension or cancellation of a processing permit, and administrative fines of up to OMR 2,000 per violation.

BandWhat it attaches toPrima's exposure
OMR 1,000 – 5,000Failure to designate a DPO, to document processing, to observe retention, or to obtain written consent for commercial marketing.Addressed by this policy and §11.3
OMR 5,000 – 10,000Failure to apply the required processing controls and procedures.Addressed by §11.1
OMR 15,000 – 20,000Processing sensitive data without a permit, children's data, breach notification failure, and breach of confidentiality.Live — biometric permit, §06
OMR 100,000 – 500,000Unlawful cross-border transfer under Article 23 causing damage to the data subject.Low — §09.3 keeps the sensitive categories in Oman
OMR 5,000 – 100,000Liability of the legal person where an offence is committed in its name by senior persons, including through approval, concealment or gross negligence.Addressed by DPO independence, §11.3
12.2 Gap position — what is outstanding, in order
ActionOwnerBy
Website privacy notice, and a statement at the point the email address is requestedPresently non-compliant — data is being collected today. Fixable this weekCISOImmediately
File the MTCIT permit application for biometric processing45-day decision, silence is refusal. Blocks enrolment of the resident teamCISO, LegalAug 2026
Omani counsel review — lawful basis analysis, employment exemptions, permit applicationLegalAug 2026
Issue this policy at v1.0, formally designate the DPO and publish the contact routeCISOSep 2026
Employee, contractor, visitor and vendor notices; consent wording and recordingCISO, HRSep 2026
Physical surveillance notices installed, Arabic and English, at every entry pointFacilitiesOct 2026
Rights-request register and the 45-day tracking in operationDPOOct 2026
Breach notification rehearsed as a tabletop, with both notifications drafted in templateDPO, CISONov 2026
Decision point on the biometric fallback if no permit is held§6.4 — card and PIN becomes the designCOOOct 2026
Appoint an MTCIT-approved auditor under Article 16CISOQ1 2027
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled15 / 16
DRAFT
PRIMA
Data Protection & Privacy PolicyPRM-DPP-2026-001 · 16 / 16
12Penalties, gap position, governance and measures, continuedGovernance
12.3 Governance
Policy ownerCISO, in the DPO capacity, with Legal. Owns this policy, the processing record and the rights register.
Accountable officerCOO. Approves breach notifications and any decision to accept a data protection risk. Reports to the board.
New processingAny new processing activity is assessed before it begins — basis, notice, retention, whether it engages Article 5, whether it involves a transfer. The assessment is recorded and the processing record updated. A new system procured without this assessment is a finding against the sponsor, not the DPO.
TrainingData protection included in induction for every person, and annually for anyone handling personnel, security or customer contact data. Recorded against the competence file under PRM-HR-2026-001.
ReviewAnnually, on any change to processing or to the law or its Regulations, and after any breach. Recorded even where nothing changes.
12.4 Measures
MeasureTargetReported
Rights requests answered within 45 days100%Quarterly
Rights requests answered within 14 days≥ 90%Quarterly
Notifiable breaches notified within 72 hours100%Per event
Processing activities with a current notice and recorded basis100%Quarterly
Sensitive processing covered by a current MTCIT permit100%Quarterly
Records deleted on schedule at the quarterly review100%Quarterly
New processing assessed before it commenced100%Quarterly
Staff with data protection training current100%Annually
Personal data breaches0Monthly
12.5 Summary position
  • Exposure is narrow by design. Prima holds no customer workload data and is neither controller nor processor of it. The personal data it holds is its own — personnel, contractors, visitors, video, access records, commercial contacts.
  • Two categories are sensitive under Article 5 — biometric and health. The biometric permit is the one blocking item, and the security design needs a documented fallback rather than an assumption that it will be granted.
  • One item is non-compliant today: personal data is being collected on primacompute.com without a privacy notice, and the law has been fully enforceable since 5 February 2026. It is fixable this week.
  • Everything else is drafting and installation — notices, consent wording, a rights register, and physical signage. All internal, none waiting on the facility.
RelatedPRM-ISM-2026-001 · PRM-SEC-2026-001 · PRM-IRP-2026-001 · PRM-HR-2026-001 · PC-ECP-001 · PRM-DEM-2026-001.
Data Protection Officer

To exercise a right, to ask what personal data Prima holds about you, or to raise a data protection concern. You may also complain directly to the Ministry of Transport, Communications and Information Technology.

info@primasecurity.ai
primacompute.com
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanInternal — controlled16 / 16