High-priority exposures
Internal breach target
Merchant deployments
Shared control framework
Executive summary
Crystal Retail Suite can support lawful retail operations, but it also concentrates identifiable customer, employee, supplier and transaction information across a large merchant network. In the usual deployment, each merchant decides why and how its shop data is used and is therefore the controller; MDW operates or supports the software on its behalf and is commonly a processor/service provider.
The label follows facts, not the contract. MDW may become a controller for its own HR, billing, account management, security administration or product analytics where it determines purpose and essential means. A merchant can also remain responsible where staff export data into spreadsheets, messaging apps or third-party tools outside Crystal.
Role mapping and accountability
Merchant — normally controller
- Chooses purposes, required fields, users, retention and integrations.
- Provides notices, handles consent where required and answers data-subject requests.
- Assesses risk, appoints the required privacy contact/officer and reports qualifying breaches.
- Ensures staff use Crystal and exports lawfully.
MDW — normally processor / service provider
- Processes shop data only on documented merchant instructions.
- Implements agreed technical and organisational safeguards.
- Controls support access and approved sub-processors.
- Assists with rights, audits, incidents, return and deletion.
Data-flow view
Customers • employees • applicants • supplier contacts
POS • back office • HR/payroll • local devices • exports
Database • support • hosting • backups • logs
Prefer token/reference; avoid storing full card data
WhatsApp/SMS • email • campaign consent/suppression
Cloud • monitoring • crash reports • remote support
For every arrow, record data categories, purpose, role, location, transfer mechanism, retention, security owner and deletion route.
Key merchant data categories
| Category | Retail examples | Control focus |
|---|---|---|
| Customer & loyalty | Name, mobile, email, address, purchase and returns history, loyalty balance | Notice, purpose limitation, marketing choice, correction/deletion workflow |
| Transaction | Invoices, product basket, timestamps, branch/cashier, payment reference | Accounting retention, restricted exports, fraud controls |
| Employee / HR | Civil ID, contact details, salary, attendance, roster, performance data | Strict role access, HR retention, special-data permit check |
| Supplier contacts | Contact person, phone/email, bank and purchasing records | Business-purpose notice and financial controls |
| Technical & security | User IDs, IP/device data, audit logs, support session recordings | Security purpose, access limitation, log retention |
| Potentially sensitive | Biometric attendance, health notes, criminal/security-measure data | Do not enable by default. Assess permit/approval requirements under Article 5 before processing |
Risk heatmap and dashboard
Shared admin or cashier accounts
No individual accountability; excessive access and weak investigation evidence.
Untracked Excel/PDF exports
Personal data spreads to desktops, USB drives, email and consumer cloud storage.
Overseas hosting / vendors
Unknown locations or onward transfers can defeat risk and contract controls.
Indefinite backups
Deleted records remain recoverable without a defined expiry or restoration procedure.
Marketing integrations
Transactional contacts may be repurposed without clear choice or suppression.
Centralized platform
Standard roles, logging, patches and contracts can lift all shops together.
| Likelihood ↓ / Impact → | Low | Medium | High |
|---|---|---|---|
| Likely | Monitor | Treat now | Escalate now |
| Possible | Manage | Planned treatment | Priority treatment |
| Unlikely | Accept/review | Monitor | Contingency |
Operational control set
Hosting, residency and cross-border transfers
- Maintain a current hosting diagram listing production, replicas, backups, monitoring and support-access locations.
- Do not assume Oman-only hosting is universally mandatory; assess overseas transfer conditions, risks and safeguards under the Regulation before transfer.
- Contractually prohibit unapproved location changes and onward transfers. Maintain a sub-processor register.
- Encrypt data in transit and at rest; keep keys, privileged access and restore operations controlled and evidenced.
Third-party integrations
| Integration | Required posture |
|---|---|
| Payments | Use approved gateway/tokenization; minimize card data; define PCI responsibilities; never log sensitive authentication data. |
| WhatsApp / SMS | Separate service messages from marketing; record instructions/consent where applicable; manage opt-outs; disclose provider and transfer implications. |
| Restrict bulk exports and recipient mistakes; use approved platform; authenticate domains; suppress opt-outs. | |
| Analytics | Prefer aggregated or pseudonymized events; avoid names, phone numbers and receipt details; document purpose and retention. |
Access control, audit and support
- Unique user accounts; role templates for cashier, supervisor, finance, HR, auditor and MDW support.
- MFA for administrators, remote support and cloud consoles; quarterly access review and immediate leaver removal.
- Time-bound, approved support access with ticket reference; prevent routine access to merchant content.
- Log authentication, privilege change, personal-data view/export, deletion, configuration change and support activity. Protect logs from alteration and synchronize time.
Backups, disaster recovery and retention
- Define encrypted backup frequency, location, owner, expiry and tested restore objectives. Record quarterly restore evidence.
- Create a retention schedule by record class and legal/business need; automatically delete or anonymize where feasible.
- Deletion in production should flow into backup expiry. If restoration reintroduces deleted records, reapply the deletion queue.
- Document legal holds; avoid “keep everything forever.”
Breach response and the 72-hour consideration
Oman PDPL Article 19 requires the controller to notify the Ministry and affected data subject of a qualifying breach according to the Regulation. Treat 72 hours from awareness as MDW’s conservative internal investigation and escalation target, not as an unqualified statement that every event has the same legal deadline. The controller should obtain Oman counsel/competent-authority guidance on notification threshold, recipients, timing and content for the actual facts.
- Contain without destroying evidence; open an incident record and preserve logs.
- MDW alerts the affected merchant immediately under the DPA—ideally within hours—with known facts and updates.
- Assess people, data, systems, quantity, consequences, geography and safeguards.
- Merchant decides and documents authority/data-subject notifications; MDW supplies facts and remediation support.
- Track lessons, corrective action and closure across any other exposed shops.
Onboarding, offboarding and data-subject rights
- Onboard only after signed DPA, shop inventory, named owners, approved users/integrations, notice configuration and secure migration.
- Route access, copy, correction, portability, restriction/blocking, withdrawal and erasure requests to the merchant; authenticate the requester and log deadlines/actions.
- At offboarding: freeze access, export securely to the authorized recipient, revoke tokens/users, obtain return/deletion instruction, remove production data, allow backup expiry and issue evidence.
DPA and vendor contract essentials
- Subject matter, duration, purpose and documented instructions
- Data and data-subject categories
- Confidentiality and personnel controls
- Security measures and control responsibility matrix
- Sub-processor approval and current list
- Hosting locations and cross-border safeguards
- Incident alert, cooperation and evidence deadlines
- Support for rights requests and risk assessments
- Audit rights, certifications and remediation
- Retention, return, deletion and backup treatment
- Change control, service exit and portability
- Liability, insurance, precedence and survival clauses
Avoid promising impossible absolute security or immediate deletion from immutable backups. State measurable safeguards, response times and the actual backup lifecycle.
Practical retail scenarios
Loyalty signup
Collect mobile number and minimum profile fields with a concise notice. Keep promotional choice separate from membership and record it. A receipt is not blanket marketing consent.
MDW remote support
Merchant opens ticket; manager approves time-limited session; named engineer uses MFA; access is logged; screenshots avoid unrelated data; ticket records closure.
Employee leaves
Disable access the same day, preserve records required for payroll/legal needs, delete unnecessary copies and review any exported reports or shared devices.
Lost store laptop
Shop informs MDW immediately. Revoke sessions, establish encryption status and affected data, preserve logs and start the breach assessment clock.
New analytics vendor
Do not send the full customer table. Define events, strip direct identifiers, check location/sub-processors, set expiry and update the data map and contract.
Merchant cancellation
Verify authorized export recipient, transfer securely, revoke access, delete according to instruction and issue a closure record describing backup expiry.
Action-priority matrix
| When | MDW / Crystal action | Merchant action | Evidence |
|---|---|---|---|
| IMMEDIATE | Stop shared privileged accounts; map hosting/vendors; appoint incident lead; freeze unreviewed sensitive-data and analytics features. | Name accountable owner; inventory users/exports/integrations; publish incident contact; remove former users. | User list, system/data-flow map, incident roster, decision log |
| 0–30 DAYS | Issue DPA and security schedule; configure role templates/MFA/logging; publish sub-processor list; draft breach and rights playbooks. | Sign DPA; approve access matrix; update notices/marketing choices; set initial retention rules. | Signed DPA, access approval, notices, playbook test |
| 60–90 DAYS | Automate retention/export monitoring; test restore and incident tabletop; close vendor gaps; launch compliance dashboard. | Complete shop review; sample rights request; validate deletion and offboarding; train staff. | Restore report, tabletop minutes, training and exception register |
Per-shop checklist
- Accountable shop owner and privacy contact are named
- Current staff/users and roles are approved
- No shared admin accounts; leavers disabled promptly
- Customer and employee notices are available
- Marketing choice and opt-out are recorded
- Only necessary fields are mandatory
- Sensitive/biometric processing has been specifically reviewed
- Exports, USB use and local spreadsheets are controlled
- Integrations and their business purpose are listed
- Retention periods are assigned to key record types
- Rights requests route to a named owner
- Incidents are reported to MDW immediately
- Store devices are patched, locked and encrypted where supported
- Quarterly review is dated and signed
Central MDW checklist
- Controller/processor role register covers every processing purpose
- One executed DPA and security schedule per merchant
- Data, system, hosting and sub-processor maps are current
- Security baseline is deployed across all supported versions
- Named support accounts, MFA and ticket-linked access
- Export, deletion, privilege and admin events are logged
- Log review and exception escalation are assigned
- Secure SDLC, testing, patch and vulnerability processes operate
- Backup restore and deletion-after-restore are tested
- Breach playbook and merchant contact tree are exercised
- Rights-request assistance workflow is measured
- Retention and offboarding are productized and evidenced
- Vendor due diligence and transfer review are complete
- Staff confidentiality and annual training are recorded
- Quarterly merchant compliance dashboard is issued
- Legal/regulatory change review is scheduled
Suggested compliance dashboard
| Measure | Target | Escalate when |
|---|---|---|
| Named merchant privacy owner | 100% shops | Any shop missing owner/contact |
| Unique admin accounts + MFA | 100% | Any shared or non-MFA privileged account |
| Quarterly access review | ≥95% on time | Overdue >15 days |
| Critical support access linked to ticket | 100% | Any unexplained access |
| Incident acknowledgement | <1 hour | Potential personal-data event exceeds target |
| Restore test | Quarterly | Failure or unverified recovery objective |
| Offboarding closure evidence | 100% | Access/data remains beyond agreed window |
Legal basis and disclaimer
This operational guide is informed by Oman’s Personal Data Protection Law issued under Royal Decree 6/2022 and its Executive Regulation issued under Ministerial Decision 34/2024. The Law defines controllers and processors, requires written transparency information, safeguards, processing records, cooperation, breach notification and a personal-data protection officer, and regulates transfers outside Oman. The Regulation provides further procedures and controls.
Disclaimer: This is a practical readiness document, not legal advice or a certification of compliance. Exact duties depend on MDW’s architecture, contracts, actual processing, sector rules and regulatory guidance. MDW and each merchant should obtain qualified Oman legal advice—particularly for sensitive data permits, children’s data, cross-border transfers, officer requirements, exemptions, notification thresholds/deadlines and retention laws.
Primary references: Ministry of Justice and Legal Affairs — Royal Decree 6/2022 • MTCIT — Ministerial Decision 34/2024 • Official English Regulation PDF