Preprint
Article

This version is not peer-reviewed.

Readiness of Government Institutions in Oman to Adopt Data Governance

A peer-reviewed version of this preprint was published in:
Information 2026, 17(7), 665. https://doi.org/10.3390/info17070665

Submitted:

09 June 2026

Posted:

10 June 2026

You are already at the latest version

Abstract
The study aimed to assess the readiness of government institutions in the Sultanate of Oman to adopt data governance by identifying the strategic and legislative foundations of data governance in the Sultanate of Oman, as well as the human resources and infrastructure necessary for governance within government institutions. The study relied on a qualitative approach to achieve its objectives and used semi-structured interviews to collect data from a sample comprising seven government institutions and one government company in the Sultanate. The results of the study showed Oman's interest in regulating the legislative framework for data governance by issuing a set of laws governing data handling in government institutions. It also pointed to disparities in the level of readiness of government institutions in Oman for data governance. In addition to a shortage of specialized data governance expertise in Oman, there is a clear need for university and postgraduate graduates in this field. The study recommended developing a strategic plan for implementing data governance to be followed by government institutions and companies in the Sultanate of Oman, and establishing an office to monitor data governance across all government institutions and companies in the Sultanate of Oman. This office would be responsible for monitoring the implementation of strategies and policies and ensuring compliance, and would submit performance reports to the Ministry of Transport, Communications, and Information Technology.
Keywords: 
;  ;  

1. Introduction

Data and information are considered vital assets for organizations and their most valuable assets. Data is now referred to as the "new oil", and this interest has become clear with the emergence of the big data economy and initiatives to shift towards data-driven business models. This organizations are using data analysis tools to leverage data, and this interest became clear when international data protection legislation, including the General Data Protection Regulation, was introduced, addressing growing concerns about data quality, privacy violations, and issues arising from poor data production and sharing management [1,2].
The application of data governance has become a necessity in our time, as reliance on data analysis and processing for decision-making across various fields has increased [3]. Data governance is defined as the organization and implementation of policies, procedures, structures, roles, and responsibilities to promote proper data usage behaviors, decision-making rights, and accountability for the effective management of data assets within an organization [4]. Governance initiatives help improve data quality by treating it as an asset and supporting strategies for its management, funding, and monitoring [3]. Data governance also focuses on creating a strategy for organizations that aligns their objectives with their data management efforts, supports regulatory compliance, and manages data-related risks [2,5,6].

2. Problem of the Study

Some organizations find it difficult to leverage data for decision-making, as the data often lacks the necessary quality levels, and there are concerns about relevant legal areas and issues related to privacy, social norms, and values. These uncertainties constitute a barrier to the acceptance and use of data due to the potential for financial risks and negative impact on the organization's reputation [7,8].
Previous studies reveal deficiencies in data governance practices, indicating that few organizations have achieved an adequate level of maturity in this domain. There is a prevailing belief that planning and understanding data governance relationships are difficult and complex due to constantly changing data standards, rules, and governance requirements, as well as factors specific to the organization's nature [1,9]. Therefore, this study aims to reveal the readiness of government institutions in the Sultanate of Oman to adopt data governance.

3. Study Objectives

The current study aimed to identify the readiness of government institutions in the Sultanate of Oman to adopt data governance by:
-
Identifying the strategic and legislative foundations of data governance in the Sultanate of Oman
-
Identifying the human requirements for data governance in Omani government institutions
-
Identifying the infrastructure for data governance in Omani government institutions

4. Importance of the Study

The importance of the study lies in its focus on the readiness of government institutions for data governance, a topic that has garnered widespread attention amid the growing recognition of data as an asset and strategic resource. A review of the literature has revealed a knowledge gap in Arabic studies on data governance. It is therefore hoped that this study will contribute to the literature in this field and open new horizons for further research. It is also aimed that the study will provide a clear picture of data governance applications in the Sultanate of Oman, the results achieved from its adoption, and its role in improving service quality.

5. Literature Review

Data governance has garnered significant attention across multiple domains, including academia, economics, and business, as data is perceived as an asset when its value is acknowledged, and appropriate investment is made [10].
Studies describe data governance practices as regulatory measures that clarify how data is managed and utilized in a regulated and beneficial manner. However, there is no unified approach to data governance that suits all sectors. Some institutions have faced difficulties in applying governance to their data [11,12].
To identify the most important aspects of data governance practices in organizations, the following section reviews the key requirements and pillars organizations must have to achieve effective data governance.

5.1. Data governance policies and strategies:

Data governance focuses on data as a strategic asset for the organization, requiring the design of standards and processes in line with its strategy and objectives. Therefore, the most important requirements for successful data governance implementation in any organization are to define a clear action plan and a strategic scope that suit its needs, enabling easy implementation. This facilitates the identification of the core tasks of the governance plan, along with its inputs and outputs, and helps define employees' responsibilities and roles [13,14]. The results of a study by Alhassan et al.(2019a) [15], which aimed to identify the success factors for adopting data governance in the telecommunications sector in Saudi Arabia, showed that the presence of data integration strategies aligned with organizational objectives was the most effective factor for data governance success. The sample study also indicated that the success of the data governance program within their organization was closely linked to decisions regarding data integration initiatives that led to an appropriate data governance program.
The study by Mulder (2019) [16], noted that the Council of Europe (CoE) was one of the first legislators to seek to protect personal data since the 1970s. During the period 1973–1974, the Council issued decisions concerning the protection of individuals’ privacy regarding electronic data used in both the public and private sectors. These decisions focused on processing data related to individuals’ personal lives and on the regulations governing its handling. They also require that sensitive information be neither collected nor disclosed, that its use comply with applicable legal frameworks, and that the purpose and duration of data retention be clearly defined.
The study by Bernier et al.(2022) [17] highlighted the European Union’s commitment to enacting international data protection legislation, noting that it is an active actor in international data governance and that data protection laws constitute an integral part of individual legal systems. International organizations, including the Council of Europe (CoE), the Organization for Economic Co-operation and Development (OECD), and the European Union, have shown sustained commitment to developing and enforcing comprehensive regulatory frameworks. These frameworks encompass mandatory disclosure requirements, data localization obligations, and regulations governing cross-border data transfers, all intended to ensure regulatory compliance. The study by Polat (2021) [18] indicated that the General Data Protection Regulation (GDPR) has been adopted as a law applicable across the European Union, encompassing institutions, companies, and citizens worldwide. It regulates the processing of personal data, ensures its protection, and imposes penalties for non-compliance. Mounia and Habiba (2015) [19] underscored the Moroccan Personal Data Protection Law (Law 09-08), which establishes a legal framework for protecting individuals’ personal and sensitive data, ensuring confidentiality and safeguarding against unauthorized disclosure or misuse during processing. The National Commission for the Control of Personal Data Protection in Morocco is responsible for monitoring institutional compliance with the law, ensuring that the processing of personal data is lawful and does not infringe upon the privacy or rights of the individuals concerned. The study also addressed the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), which establishes regulations for the collection, use, and disclosure of personal data. It further grants individuals the right to be informed about the purposes for which organizations collect, use, or disclose their personal information. It further grants individuals the right to be informed about the purposes for which organizations collect, use, or disclose their personal information. The findings of Parveen (2018) [20] indicated that the majority of the study sample agreed on the urgent need for legislation addressing data security and privacy issues in the Kingdom of Saudi Arabia. Participants highlighted the absence of laws and regulations that define data management strategies and ensure data protection from misuse. They further noted that cloud computing technologies offer significant opportunities for educational institutions to share data with stakeholders; however, these technologies require stringent regulations to safeguard data confidentiality, security, and institutional privacy.

5.2. Human Requirements:

A successful data governance program places the human element at its core, emphasizing the clear assignment of data ownership, roles, and responsibilities, as well as the enforcement of standards and policies. Central to governance is a management team and steering committee responsible for policy approval, implementation oversight, and conflict resolution among organizational units [21,22,23]. Arisandi & Khudri (2021) [29] similarly highlighted the need for a change management team to address data-related challenges and develop supporting tools for governance programs.
Effective implementation requires collaboration across all managerial levels. Executive leaders must recognize data’s strategic value and support governance initiatives, while financial managers can contribute due to their expertise in regulatory and financial data [21,24]. Appointing a Chief Data Officer (CDO) is critical, as the CDO oversees policy enforcement, program funding, and personnel assignments [22]. In some cases, a dedicated data governance office coordinates activities, organizes training, and ensures compliance.
Specialized personnel in IT and information security are essential for maintaining data quality, security, and compliance, and for facilitating safe inter-organizational data sharing [8,13,25]. Organizations must ensure that employees are capable and prepared to utilize high-quality data to support operations, policy-making, and service delivery. This requires investment in technical capacity, resources, and human capital [26].
Training is crucial for mitigating human error, enhancing cybersecurity awareness, and ensuring compliance with security and privacy policies. Such programs may include international certifications (e.g., IAPP) or training through initiatives like the Open Data Institute [24,26]. Zhang et al. (2022) [14] noted gaps in IT and big data skills, leading to reliance on specialized external firms for advanced infrastructure, such as cloud platforms.

5.3. Technical Requirements:

Effective data governance requires organizations to assess their foundational evidence and readiness, recognizing the critical role of technology and digital tools in processing, enhancing, and ensuring data quality. High-quality data must be accurate, reliable, and suitable for effective processing and utilization [14,27].
A strong technological infrastructure supports the preparation and utilization of organizational data through processes such as data integration, a continuous procedure aimed at improving core data attributes, including quality, accessibility, and consistency, and is considered a key step toward effective data governance [28]. This process begins by identifying reliable primary data sources, extracting information from systems, databases, communication platforms (e.g., websites and emails), and other relevant documents. Data then undergoes cleansing and validation, including error correction, verification, handling of missing values, duplicate removal, and compliance with established standards.
Fragmented datasets are subsequently integrated and standardized to align with organizational systems and delivered in appropriate formats to end users, whether employees, systems, or beneficiaries. Continuous evaluation and monitoring, along with reporting, are essential for identifying areas for improvement and capitalizing on organizational strengths [15,21].
Brous et al. (2020) [29] highlighted that the quality of data entering organizational systems and comprehensive compliance monitoring are critical factors for leveraging data science. Their study of the Directorate-General for Public Works and Water Management in the Netherlands emphasized the need for centralized, unified solutions for managing data privacy and security. Data governance should not be perceived as a one-time initiative; rather, it requires continuous development and iterative evaluation to achieve long-term objectives [29].
A review of prior studies on governmental data governance implementation indicates a focus on governance policies, their components, and their role in effective implementation within public institutions. These studies also underscore the emergence of new functional roles, such as data officers, and the need to establish robust technological and infrastructural foundations to support governance initiatives.

6. Study Methodology

The study adopted a qualitative methodology to achieve its research objectives, employing semi-structured interviews as the primary data collection tool. The study population consisted of governmental institutions and companies in the Sultanate of Oman that have implemented data governance initiatives and demonstrated significant progress, as well as organizations responsible for developing regulatory and legislative frameworks and supervising the implementation of governance across Omani institutions. A purposive sampling approach was used, resulting in a sample of eight organizations, including seven governmental institutions: Sultan Qaboos University, the Ministry of Transport, Communications and Information Technology, the Royal Oman Police, the National Center for Statistics and Information, the Oman Center for Governance and Sustainability, the Ministry of Higher Education, Research and Innovation, and the Cyber Defense Center. In addition, one government-owned company, Oman Telecommunications Company (Omantel), was included. Table 1 presents the number of interviews conducted for each organization.

7. Results and Discussion

This section addresses the infrastructure and resources available to the institutions in the study sample as they implement data governance. It is organized into three main subsections, which are shown in the following figure:
Figure 1. Map of the thematic analysis of the first section.
Figure 1. Map of the thematic analysis of the first section.
Preprints 217730 g001

7.1. Foundations and Strategies of Data Governance in Omani Government Institutions

This section explores the current status of Omani government institutions with respect to data governance, the maturity of the legislative framework, and relevant legal controls in the Sultanate of Oman. The analysis is structured around three primary pillars, further divided into specific sub-themes: the strategic and legislative foundations of data governance in Oman; human resource readiness for data governance; and the infrastructural preparedness of Omani government institutions.

7.1.1. Strategic and Legislative Foundations of Data Governance in Oman

Based on the study sample, this section reviews the strategies and legislation governing data management within Omani government institutions. These foundations are categorized into three levels: international standards and legislation, national strategies and laws, and institutional-level policies.

7.1.2. International Standards and Legislation

The study findings indicate a keen interest among Omani government institutions in staying abreast of international data-related laws, adhering to global standards, and ensuring compliance when sharing or publishing data. The results confirm an institutional awareness of the importance of adopting the best international practices and legal requirements to ensure comprehensive coverage of data governance, protection, and utilization.
Specifically, the findings reveal that several Omani government entities adhere to the International Standard Industrial Classification of All Economic Activities (ISIC Rev.4) issued by the United Nations Economic and Social Council. Furthermore, there is a clear commitment to global benchmarks through the pursuit of ISO certifications, specifically ISO/IEC 27001 (Information Security Management) and ISO/IEC 27701 (Privacy Information Management).
The results also highlight the adoption of the International Monetary Fund’s (IMF) Special Data Dissemination Standard (SDDS) for data sharing and publication. This standard defines four dimensions for the dissemination of economic data: data coverage, periodicity and timeliness; public access; integrity; and quality. The IMF encourages member states to publish additional economic and financial indicators to enhance transparency, reflecting the program’s commitment to rigorous data collection and dissemination [30].
These findings align with the work of Bernier et al. (2022) [17], Rosa (2021) [31], Monge et al. (2022) [32], and Polat (2021) [18], all of whom emphasize the role of international legislation in regulating data publication in accordance with standards set by global organizations. It is evident that global frameworks, such as those established by the ISO and the IMF, are vital to data governance systems. They facilitate data handling by unifying global classification and organization, enabling international benchmarking, fostering the exchange of expertise, and ensuring the standardization of indicators and concepts.

7.1.3. National Strategies and Legislation

The study highlights Oman’s commitment to regulating the legislative landscape of data governance through a series of laws governing data operations within government institutions. The study sample identified Royal Decree No. 118/2011 (The Law on the Classification of State Documents and the Regulation of Protected Places) as the cornerstone for data classification policies in the Sultanate. Additionally, reference was made to the Statistics and Information Law (Royal Decree No. 55/2019), which defines data ownership, regulates sharing and accessibility, and outlines penalties for breaches of data confidentiality and privacy. Article 11 of this law mandates that all personal data shall remain confidential and may only be disclosed in aggregated form, explicitly prohibiting access by any individual or entity, whether governmental or private, for purposes other than statistical analysis.
Participants also confirmed that the Personal Data Protection Law (Royal Decree No. 6/2022) reinforced existing legislation. Government institutions rely on this law to establish controls on data accessibility and sharing and are currently redrafting internal policies to ensure compliance with its mandates for protecting personal data from breaches. Article 5 of this law prohibits the processing of sensitive personal data such as genetic, biometric, or health data, as well as data regarding ethnic origin, religious or political beliefs, or criminal records, without prior authorization from the Ministry of Transport, Communications and Information Technology (MTCIT). Furthermore, Article 10 mandates that data processing be conducted with transparency, integrity, and respect for human dignity, and requires the explicit written consent of the data subject.
These results are consistent with Mounia & Habiba (2015) [19] regarding the Moroccan Personal Data Protection Law (Law 09-08) and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), both of which focus on protecting individual data and regulating its processing. Conversely, Parveen (2018) noted historical weaknesses in data protection laws in Saudi Arabia, where entities previously relied on broader cybercrime laws to address privacy issues.
Furthermore, the study highlights the MTCIT's efforts to organize the legislative framework for data governance in Oman. The Ministry’s Policies and Governance Department is responsible for developing and disseminating data governance policies and standards, while the Compliance Department monitors institutional performance. The MTCIT has issued various guidelines and manuals, including the Data Circulation and Sharing Policy and the Data Classification Standards Guide (issued by the National Records and Archives Authority), as well as IT risk management plans.
Regarding national strategies, Article 5 of the Statistics and Information Law (55/2019) mandates the National Center for Statistics and Information (NCSI) to prepare a National Data Strategy in coordination with relevant authorities. Article 6 stipulates that this strategy must specify data types, collection objectives, ownership, and integration strategies across both the public and private sectors. It further addresses the full data lifecycle—including creation, storage, and disposal—as well as mechanisms for quality assurance and confidentiality protection. Participants noted that the responsibility for the National Data Strategy was subsequently transferred to the Royal Oman Police (ROP), as the primary data owner and custodian in the Sultanate, and that the strategy is in its final stages for imminent publication.
Comparatively, Memish et al. (2021) [33] noted that the Saudi Data and AI Authority (SDAIA) launched the National Strategy for Data & AI (NSDAI) in 2020 to support Vision 2030. Similarly, the United Arab Emirates enacted the Dubai Data Law in 2015, followed by the establishment of the Digital Dubai Authority in 2016 to oversee data sharing and dissemination.
Finally, the MTCIT has begun issuing a dedicated Data Governance Policy for adoption by all government entities. This policy covers data classification, sharing, open data, and personal data protection. The classification component aligns with Royal Decree 118/2011, while the sharing and open data components follow Ministry Circular No. 8/2020. This comprehensive approach ensures that all government "controllers" and "processors" comply with the Personal Data Protection Law (6/2022).
This reflects similar developments in Saudi Arabia, where the National Data Management Office (NDMO) issued a national data governance standard encompassing comparable sub-policies (SDAIA, 2022). Additionally, AlFalasi (2019) [34] highlighted the Dubai Data Initiative, which fosters a culture of data exchange grounded in 13 principles across three pillars: dissemination, use, and privacy. Similarly, Shen (2022) [35] observed that China’s data governance policy aims to create a regulated data market to stimulate the digital economy while strengthening security and privacy regulations.

7.2. Institutional-Level Policies

The findings indicate that some governmental institutions in the Sultanate of Oman have made considerable progress in data governance and have established policies, standards, and operational plans to regulate data handling and governance practices. Conversely, certain institutions continue to lack coherent policies governing data strategies across their multiple departments; nevertheless, they have initiated efforts to establish centralized policies and harmonized procedures, guided by the regulatory frameworks promulgated by the Ministry of Transport, Communications, and Information Technology.
The National Center for Statistics and Information represents one of the most advanced governmental institutions in Oman in terms of data governance. The study findings reveal that the Center developed an Information Security Strategic Plan (2022–2024) that emphasizes the adoption of data governance programs. This strategy defines roles and responsibilities and adopts relevant governance policies. The Center’s data security policy also includes subsidiary policies on data classification, data sharing, and open data. In addition, the Center implemented a Geographic Data Governance Project, through which institutional relationships were regulated, roles and responsibilities were clearly defined, data ownership was specified due to the overlap of authorities responsible for geographic data, and data formats and required datasets were standardized.
These findings are consistent with previous studies [21,23,36], which emphasize that successful data governance programs depend on developing strategic institutional plans and comprehensive policies that address data-related aspects, including quality, security, privacy, and data-sharing mechanisms. Such policies define rules for data access, processing, storage, and privacy protection, as well as decision rights and accountability structures within organizations.
The results also show that some governmental institutions have adopted data classification policies derived from the State Documents Classification and Protected Areas Law No. 118/2011. Study participants confirmed that data should be accessible by default unless classified by law, and that access is restricted according to classification levels and authorized permissions. This aligns with Wang et al. (2019) [37] and Thompson et al. (2015) [23], who argue that data governance strategies must define access levels and authorization mechanisms to prevent misuse and security breaches. Kroll (2018) [38] similarly emphasized the importance of appropriate access control strategies to protect sensitive data.
Moreover, several institutions have established policies governing data sharing and transfer, both internally and externally, whether manual or electronic, to ensure data protection at both the organizational and user levels. These findings are consistent with Brous and Janssen (2020) [11], Tallon (2013) [12], and Koch and Corban (2020) [24], who emphasized the need to incorporate secure data-sharing procedures into governance strategies, including anonymization, backup and recovery practices, and data protection levels based on sensitivity.
Regarding open data, the findings indicate that most governmental institutions in Oman are developing internal policies aligned with the Government Open Data Policy issued by the Ministry of Transport, Communications, and Information Technology (Circular No. 8/2020). Several institutions have already made progress in publishing open data and reports while ensuring individual data protection and compliance with classification levels.

7.3. Human Readiness for Data Governance in Omani Governmental Institutions

This section examines the readiness of human competencies for adopting data governance programs across three dimensions: qualifications and competencies, awareness, and training.

7.3.1. Qualifications and Human Competencies

The findings highlight the critical role of human competencies in data governance, as personnel are responsible for implementation, regulation, and compliance. The results emphasize the need to clearly define roles and responsibilities, including data owners, data stewards, and data users, alongside appropriate training to ensure data security and confidentiality. This supports the findings of Stedman & Vaughan (2020) [22], who identified human resources as a cornerstone of successful data governance.
Most governmental institutions in Oman possess qualified personnel who support data governance initiatives. Their expertise contributed to the success of the geographic data governance experience at the National Center for Statistics and Information despite the absence of prior governance frameworks. Several institutions highlighted the role of technical staff in securing databases, using open-source software, and assigning data access rights in accordance with institutional policies. These findings align with Al-Ruithe & Benkhelifa (2020) [13], Janssen et al. (2020) [8], and Gregory (2011) [25], who stressed the need for specialized IT and information security professionals in data governance.
However, some institutions reported a significant shortage of specialized data governance professionals and a clear need for graduates and postgraduates in the field. The World Bank (2021) [26] emphasized that institutions adopting data governance must invest in technical capabilities and human capital development to support data-driven operations and policymaking.

7.3.2. Awareness of Human Competencies

The findings show that senior management in Omani governmental institutions demonstrates a good level of awareness of data governance, reflecting the government’s current orientation towards governance and data utilization for public benefit. Decision-makers recognize the importance of data in policymaking and the effective use of interactive dashboards and statistical indicators. This finding is consistent with Koch & Corban (2020) [24], who discussed the role of executive awareness in supporting data governance initiatives.
Nevertheless, the results reveal limited awareness among some employees regarding data governance practices. Institutions have responded by issuing awareness messages and security guidelines on data sharing and protection. The implementation of the 2020 electronic census also helped raise awareness and encourage institutions to organize their data to support digital transformation.

7.3.3. Training and Capacity Building

The study findings indicate strong institutional commitment to training and capacity building through workshops and training programs at national, regional, and international levels. Participants emphasized the role of the Ministry of Transport, Communications, and Information Technology in delivering training on data security and protection for decision-makers, senior management, and employees. Some institutions also benefited from international training programs, such as those offered by the United Nations Statistics Division.
Koch & Corban (2020) [24] note that limited awareness continues to pose a significant security risk, with many breaches stemming from human error or negligence. Addressing this vulnerability requires more focused training to strengthen cybersecurity awareness and improve staff capacity to recognize and mitigate potential threats. To address skill shortages, some institutions engage international consultancy firms, particularly for advanced economic data analysis. This finding is consistent with Zhang et al. (2022) [14], who reported that organizations often rely on specialized firms due to insufficient internal expertise in IT and big data.

7.4. Technological Infrastructure for Data Governance

The technological infrastructure constitutes a fundamental pillar of data governance initiatives and a decisive factor in their success or failure. The findings indicate that a strong ICT infrastructure directly facilitates the implementation of data governance by supporting organizational strategies and objectives. Essential requirements include reliable hardware, data processing and analytics software, and robust security measures.

7.4.1. Technical Departments

Participants commended the Omani government’s efforts to establish an advanced technological infrastructure capable of accommodating rapid technological developments. This infrastructure enhances the efficiency of data storage, processing, and utilization, consistent with Arisandi & Khudri (2021) [29] and Koch & Corban (2020) [24].
The governance and compliance sector within the Ministry of Transport, Communications, and Information Technology plays a central role in developing policies, monitoring compliance, and providing consultancy services in infrastructure, information security, software, and databases. At the National Center for Statistics and Information, the Information Security Department oversees daily data protection practices, while the Data Dissemination Department manages data sharing through electronic portals, social media, and official publications.
Gregory (2011) [25] emphasized the role of information systems departments in data processing, software development, and cybersecurity protection. With increasing data volumes and the growing reliance on artificial intelligence and machine learning, institutions must ensure the availability of accurate, high-quality data to support evidence-based decision-making.

7.4.2. Electronic Systems

The study’s findings reveal that several government institutions in the Sultanate of Oman are actively transitioning to automation and adopting modern electronic systems to ensure compliance with data security standards and safeguard against data loss. For instance, the electronic correspondence system implemented in one of the sampled institutions enforces employees’ adherence to security protocols and precautionary guidelines. It further protects data confidentiality by defining permissions for access, sharing, and modification, thereby preventing unauthorized access and potential breaches.
These observations align with Cheong and Chang (2007) [27], who emphasized that organizations are responsible for ensuring that data are accurate, reliable, and accessible in a comprehensible format to support effective decision-making. Achieving this requires adopting advanced technological systems that integrate data processing, analysis, and reporting while protecting information from misuse and unauthorized access.
Regarding the standardization of data management strategies and the unification of storage and processing systems, the study indicates that the Ministry of Transport, Communications, and Information Technology has issued directives encouraging government institutions to adopt cloud computing solutions. This strategy aims to reduce maintenance and storage costs while ensuring data availability and minimizing the risk of loss. Moreover, many institutions have established platforms to publish open data and statistical indicators derived from processed and analyzed datasets, in alignment with good governance directives emphasizing the strategic value of data utilization.
The Government Cloud Project stands out as one of Oman’s most significant infrastructure initiatives. It offers a comprehensive suite of technical support services, including software, security, and infrastructure solutions, provided by the Ministry of Transport, Communications, and Information Technology. Government institutions can leverage the full range of services on this platform, aligning with global trends in digital transformation and the development of robust data infrastructures.

7.5. Data Security Practices

In the absence of formal data governance strategies and policies in some government institutions in the Sultanate of Oman, the study’s findings revealed practical practices and implementations across various aspects of data governance within these institutions. These include data classification practices, data-sharing practices, and practices ensuring data security and confidentiality.

7.5.1. Data Classification Practices

The study’s findings indicate that some government institutions in the Sultanate of Oman are keen to establish internal policies to regulate data management strategies, both within the institution and when sharing it with external entities. These policies aim to ensure compliance with security standards and to safeguard data privacy and confidentiality. Data classification practices in government institutions are guided by the State Documents Classification and Protected Areas Regulation No. 118/2011, which defines four primary levels of data classification: Confidential, Highly Confidential, Restricted, and Limited. Compliance with these legally mandated classifications helps preserve data security by identifying potential risks, protecting data privacy, and ensuring appropriate security levels, thereby maintaining data availability, integrity, and confidentiality.
Previous studies have emphasized the role of data governance in guiding institutions in establishing controls and standards for handling data, defining tasks, and granting appropriate permissions, while ensuring adherence to security measures to prevent data loss [23,25]. This contributes to employee compliance with internal governance policies and external regulations, preserving data privacy and enhancing data accuracy, quality, and usability for decision-making.
One of the data security practices implemented by government institutions in Oman involves establishing a system for assigning access and modification privileges based on functional levels. This ensures alignment with the organization’s data classification policy, thereby safeguarding data confidentiality and preventing unauthorized disclosure. Additionally, some institutions have defined specific levels for data dissemination: certain periodic reports are made publicly available, while monthly reports are restricted to decision-makers, including ministers, deputy ministers, heads of authorities and councils, and select senior officials. These reports often include analyses of economic, social, and demographic variables in the Sultanate. Furthermore, confidential reports are issued for senior government authorities and key decision-makers.
Brous et al. (2020) [29] emphasized the necessity for institutions to adhere to data security and privacy policies and to ensure that all personally identifiable information is removed when data is shared or used for any purpose. The study also highlighted that institutions must possess sufficient awareness of the legal and social responsibilities associated with data, as well as the risks and threats specifically related to data privacy.

7.5.2. Data Security and Confidentiality Practices

The study’s findings indicate that some government institutions in the Sultanate of Oman, even in the absence of formal data governance policies, are committed to ensuring data security and confidentiality by adopting specific security practices and procedures. In terms of obtaining accurate and high-quality data, most institutions have moved toward adopting electronic linkage technologies with the systems and records of other government institutions in Oman, such as the Civil Status Department under the Royal Oman Police, the Ministry of Labor, the Ministry of Education, the Ministry of Health, and others, to acquire data directly from their primary sources. The study also revealed that data received through electronic systems undergo auditing and verification by specialized departments and personnel to ensure accuracy and to prevent duplication or unauthorized modification.
Several precautionary measures are observed by government institutions in Oman to protect data from breaches and violations and to maintain its confidentiality and security. Some institutions reported using storage services provided by Oman Data Park to safeguard their data against unauthorized access and cyber threats. Additionally, security guidelines are disseminated to employees to prevent the sharing or transfer of individual data, including prohibitions on storing sensitive data on personal devices or using external storage media, restrictions on file sharing to senior management only, requirements to change passwords every 3 months, and ensuring that each employee uses a dedicated work device.
Some institutions also attach warning notices to email communications indicating the data classification level, authorized users, and instructions for secure handling and protection to ensure data security and privacy. Furthermore, certain institutions emphasize assigning access privileges to preserve data security. Granting individuals or institutions access to view or modify data is governed by regulations designed to prevent privacy violations and maintain confidentiality. Employee access and modification privileges vary according to administrative positions and the responsibilities of departments and units; data is provided strictly based on individual needs and areas of responsibility.

7.5.3. Data Sharing Practices

The study’s findings indicate that data sharing within government institutions in the Sultanate of Oman occurs through various channels and methods, depending on the institution’s mandate and the data's necessity. The process of sharing and transferring data is conducted in accordance with specific procedures that must be adhered to by the institution or by individuals requesting access. Government electronic linkage between the National Center for Statistics and Information (NCSI) and certain government institutions facilitates data access through a shared electronic portal or via specialized electronic platforms provided by the Center.
The study also revealed that some institutions continue to employ traditional methods of data sharing, requiring an official written request signed by authorized decision-makers within the institution. The institution verifies the requester’s authority to access the requested data and ensures adherence to administrative protocols for information requests. Requests must typically be submitted to a senior management position, such as the Director-General or an authorized deputy. Employees must also have the appropriate privileges to access the requested data and ensure that such access complies with relevant laws and regulations and does not violate data privacy.
This aligns with Kroll’s (2018) [38] study, which emphasized the necessity of encrypting data during storage and transfer and of establishing appropriate access strategies to prevent unauthorized access to sensitive data, limiting access only to legitimate needs. It also highlighted the importance of verifying the requester’s authority, whether at the institutional or individual level, and assessing the necessity of their access. Furthermore, some government institutions require the execution of Non-Disclosure Agreements (NDAs) with collaborating entities, which define data handling rules and specify confidentiality levels to protect sensitive information and prevent violations.

8. Key Findings:

-
Some government institutions in the Sultanate of Oman are committed to reviewing international data-related regulations, adhering to established standards, and aligning with global benchmarks when sharing or publishing data. They are also aware of the importance of consulting best international practices, legal frameworks, and regulatory requirements for data governance to ensure comprehensive coverage of all aspects related to data management, protection, and utilization.
-
Oman has demonstrated a commitment to regulating the legislative framework related to data governance through the enactment of several laws governing data management in government institutions, including: the State Documents Classification and Protected Areas Regulation (118/2011), the Statistics and Information Law (55/2019), and the Personal Data Protection Law (6/2022).
-
The Ministry of Transport, Communications and Information Technology (MTCIT) has initiated the organization of data governance legislation in Oman, developed policies, and provided strategic guidance for government institutions seeking to adopt data governance initiatives and programs.
-
There is variation in the level of readiness among government institutions in Oman to implement data governance. While some institutions have made significant progress, others still lack sufficient awareness of the importance and effectiveness of data governance.
-
Most government institutions in Oman possess qualified personnel who support data governance efforts, including the National Center for Statistics and Information and the Royal Oman Police. Technical staff play a key role in protecting databases, securing data, and utilizing open-source software for data management and preservation.
-
There is a shortage of specialized competencies in data governance in Oman, highlighting a clear need for professionals with university degrees or postgraduate qualifications in the field.
-
The MTCIT is actively working to raise awareness within government institutions in Oman by organizing training programs for decision-makers, senior management, and staff on data security and protection, both nationally and in collaboration with regional and international organizations.
-
Government institutions possess strong technical infrastructure capable of accommodating rapid technological developments and modern tools, thereby enhancing the efficiency and effectiveness of strategies for data management, storage, and utilization.
-
The Governance and Compliance sector within the MTCIT provides advisory services to government entities to promote best practices in the technical sector, including infrastructure, information security, software, and database management. It also develops, reviews, issues, and disseminates policies, standards, work plans, and guidelines for government institutions.
-
Some government institutions have proactively adopted practical practices and implementations of data governance to compensate for the absence of formal policies. These practices include data classification, data sharing, and maintaining data security and confidentiality.

8. Recommendations

-
Developing a strategic plan for implementing data governance, which should be followed by all government institutions and organizations in Oman and monitored by the Ministry of Transport, Communications, and Information Technology.
-
Establishing a dedicated office for monitoring data governance within all government institutions and organizations in Oman. This office would oversee the implementation of strategies and policies, ensure compliance, and submit performance reports to the MTCIT.
-
Intensifying training programs and workshops organized by the MTCIT for government institutions in Oman to raise awareness among staff and senior management about the importance and effectiveness of implementing data governance.

References

  1. Ender, L. A. Data Governance in Digital Platforms: A Case Analysis in the Building Sector; UMEA UNIVERSITY, 2021. [Google Scholar]
  2. Putro, B. L.; Surendro, K.; Herbert, H. Leadership and culture of data governance for the achievement of higher education goals (Case study: Indonesia University of Education). In AIP Conference Proceedings; 2016; pp. 1–14. [Google Scholar] [CrossRef]
  3. McCaig, M.; Rezania, D. A Scoping Review on Data Governance. In 2nd International Conference on IoT Based Control Networks and Intelligent Systems (ICICNIS 2021); 2021; pp. 1–8. [Google Scholar] [CrossRef]
  4. Otto, B. Organizing Data Governance: Findings from the telecommunications industry and consequences for large service providers. Commun. Assoc. Inf. Syst. 2011, 29(1), 45–66. [Google Scholar] [CrossRef]
  5. Al-Ruithe, M.; Benkhelifa, E.; Hameed, K. A systematic literature review of data governance and cloud data governance. Personal. Ubiquitous Comput. 2019, 23(5–6), 839–859. [Google Scholar] [CrossRef]
  6. Nielsen, O. B. A comprehensive review of data governance literature. Sel. Pap. IRIS 2017, 8, 120–133. Available online: http://aisel.aisnet.org/iris2017.
  7. Alhassan, I.; Sammon, D.; Daly, M. Data governance activities: a comparison between scientific and practice-oriented literature. J. Enterp. Inf. Manag. 2018, 31(2), 300–316. [Google Scholar] [CrossRef]
  8. Janssen, M.; Brous, P.; Estevez, E.; Barbosa, L. S.; Janowski, T. Data governance: Organizing data for trustworthy Artificial Intelligence. Gov. Inf. Q. 2020, 37, 1–8. [Google Scholar] [CrossRef]
  9. Abraham, R.; Schneider, J.; vom Brocke, J. Data governance: A conceptual framework, structured review, and research agenda. Int. J. Inf. Manag. 2019, 49, 424–438. [Google Scholar] [CrossRef]
  10. Alhassan, I.; Sammon, D.; Daly, M. Critical Success Factors for Data Governance: A Theory Building Approach. Inf. Syst. Manag. 2019b, 36(2), 98–110. [Google Scholar] [CrossRef]
  11. Brous, P.; Janssen, M. Trusted Decision-Making: Data Governance for Creating Trust in Data Science Decision Outcomes. Adm. Sci. 2020, 10, 1–19. [Google Scholar] [CrossRef]
  12. Tallon, P. P. Corporate governance of big data: Perspectives on value, risk, and cost. Computer 2013, 46(6), 32–38. [Google Scholar] [CrossRef]
  13. Al-Ruithe, M.; Benkhelifa, E. Determining the enabling factors for implementing cloud data governance in the Saudi public sector by structural equation modelling. Future Gener. Comput. Syst. 2020, 107, 1061–1076. [Google Scholar] [CrossRef]
  14. Zhang, Q.; Sun, X.; Zhang, M. Data Matters: A Strategic Action Framework for Data Governance. Inf. Manag. 2022, 59(4), 103642. [Google Scholar] [CrossRef]
  15. Alhassan, I.; Sammon, D.; Daly, M. Critical success factors for data governance: a telecommunications case study. J. Decis. Syst. 2019a, 28(1), 41–61. [Google Scholar] [CrossRef]
  16. Mulder, T. The protection of data concerning health in Europe. Eur. Data Prot. Law. Rev. 2019, 5(2), 209–220. [Google Scholar] [CrossRef]
  17. Bernier, A.; Molnár-Gábor, F.; Knoppers, B. M. The international data governance landscape. J. Law. Biosci. 2022, 1–45. [Google Scholar] [CrossRef]
  18. Polat, A. Effects of GDPR on the financial services sector in the Kingdom of Saudi Arabia. J. Data Prot. Priv. 2021, 4(3), 273–282. [Google Scholar] [CrossRef]
  19. Mounia, B.; Habiba, C. Big data privacy in healthcare moroccan context. Procedia Comput. Sci. 2015, 63, 575–580. [Google Scholar] [CrossRef]
  20. Parveen, R. Challenges in Cloud Computing Adoption � An Empirical Study of Educational Sectors of Saudi Arabia. Indian J. Sci. Technol. 2018, 11(48), 1–11. [Google Scholar] [CrossRef]
  21. Panian, Z. Some practical experiences in data governance. World Acad. Sci. Eng. Technol. 2010, 62, 939–946. [Google Scholar]
  22. Stedman, C.; Vaughan, J. What is data governance and why does it matter? SearchDataManagement.Com. 2020. Available online: https://searchdatamanagement.techtarget.com/definition/data-governance.
  23. Thompson, N.; Ravindran, R.; Nicosia, S. Government data does not mean data governance: Lessons learned from a public sector application audit. Gov. Inf. Q. 2015, 32, 316–322. [Google Scholar] [CrossRef]
  24. Koch, R.; Corban, T. DATA GOVERNANCE IN DIGITAL TRANSFORMATION. In STRATEGIC FINANCE; 2020; pp. 60–61. Available online: http://search.proquest.com.upc.remotexs.xyz/docview/2439671625/abstract/DC9B2E0BBCF547ABPQ/1?accountid=43860.
  25. Gregory, A. Data governance Protecting and unleashing the value of your customer data assets: Stage 1: Understanding data governance and your current data management capability. J. Direct Data Digit. Mark. Pract. 2011, 12(3), 230–248. [Google Scholar] [CrossRef]
  26. World Bank. Institutions for data governance: Building trust through collective action. World Dev. Rep. 2021 Data Better Lives 2021, 265–296. [Google Scholar] [CrossRef]
  27. Cheong, L. K.; Chang, V. The need for data governance: A case study. 18th Australasian Conference on Information Systems, 2007; pp. 999–1008. [Google Scholar]
  28. Khatri, V.; Brown, C. V. Designing data governance. Commun. ACM 2010, 53(1), 148–152. [Google Scholar] [CrossRef]
  29. Brous, P.; Janssen, M.; Krans, R. Data Governance as Success Factor for Data Science. In IFIP International Federation for Information Processing; 2020; Volume 2020, pp. 431–442. [Google Scholar] [CrossRef]
  30. Vadlamannati, K. C.; Cooray, A.; Brazys, S. Nothing to hide: Commitment to, compliance with, and impact of the special data dissemination standard. Econ. Politics 2018, 30, 55–77. [Google Scholar] [CrossRef]
  31. Rosa, I. R. Relation of Data Visualization Techniques with the phases of Cybersecurity Incidents Response process; Kriativ.Tech, 2021; p. 9. [Google Scholar] [CrossRef]
  32. Monge, F.; Barns, S.; Kattel, R.; Bria, F. A new data deal: the case of Barcelona (No. WP 2022/02; Working Paper Series). 2022. Available online: https://www.ucl.ac.uk/bartlett/public-.
  33. Memish, Z. A.; Altuwaijri, M. M.; Almoeen, A. H.; Enani, S. M. The Saudi data & artificial intelligence authority (SDAIA) vision: Leading the Kingdom’s journey toward global leadership. J. Epidemiol. Glob. Health 2021, 11(2), 140–142. [Google Scholar] [CrossRef]
  34. AlFalasi, R. Personal Data Monetisation Strategy: Systematic Review and a Case Study of UAE ‫ (Issue July); The British University in Dubai, 2019. [Google Scholar]
  35. Shen, Y. Data governance in China’s platform economy. China Econ. J. 2022, 15(2), 202–215. [Google Scholar] [CrossRef]
  36. Benfeldt, O.; Persson, J. S.; Madsen, S. Data Governance as a Collective Action Problem. Inf. Syst. Front. 2019, 22, 299–313. [Google Scholar] [CrossRef]
  37. Wang, C. S.; Lin, S. L.; Chou, T. H.; Li, B. Y. An integrated data analytics process to optimize data governance of non-profit organization. Comput. Hum. Behav. 2019, 101, 495–505. [Google Scholar] [CrossRef]
  38. Kroll, J. A. Data Science Data Governance. IEEE Secur. Priv. 2018, 16(6), 61–70. Available online: https://www.data-science.ruhr/about_us/. [CrossRef]
  39. Arisandi, D.; Khudri, T. M. Y. Analysis and Design of Data Governance at the Financial Services Authority. InFestasi 2021, 17(1), 55–64. [Google Scholar] [CrossRef]
Table 1. Number of interviews per institution. 
Table 1. Number of interviews per institution. 
Institution Number of interviews
Sultan Qaboos University 4
Oman Center for Governance and Sustainability 1
Cyber Defense Center 1
Ministry of Transport, Communications and Information Technology 3
Royal Oman Police 1
National Center for Statistics and Information 3
Ministry of Higher Education, Scientific Research and Innovation 4
Oman Telecommunications Company (Omantel) 2
Total 19
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2026 MDPI (Basel, Switzerland) unless otherwise stated

Accessibility

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings