2- The authentication service provider may transfer part of his activity to another
authentication service provider provided that:
(a)
He notifies the owners of the valid certificates of his intention to
transfer the certificates to another provider at least one month prior to
the expected date of transfer.
(b)
He notifies the owners of the certificates of their rights in refusing such
transfer and the deadline for refusal and the method thereof. The
certificates whose owners expressed their refusal shall be revoked in
writing or electronically on the stated deadline.
3- In case of the death or bankruptcy or dissolution of the authentication service provider,
his heirs or liquidators shall be subjected to sub-article (2) of this article provided that
the whole activity shall be transferred within three months.
4- In all cases of stopping the activity, the personal informations that remain under the
control of the authentication service provider shall be destroyed in the presence of the
competent authority representative.
Article (42)
1- In determining the accuracy and validity of the certificate or electronic signature no
regard should be had to the place where the certificate is issued or the electronic
signature is effected or the jurisdiction within which the place of business of the
certificate issuer is located or the electronic signature is effected.
2- The certificates issued by foreign authentication service providers shall be the same as
those issued by authentication service providers who act pursuant to this law if the
practices of the foreign authentication service provider has got that level of credibility
not less than the level required from the authentication service providers who have
been subjected to the provisions of this law taking into consideration the recognized
international practices.
3- The certificates issued by foreign authentication service provider shall not be
recognized unless by a ministerial decision.
4- To decide the validity of a certificate or electronic signature, any agreement between
the parties in respect of the transaction in which that signature is used or the certificate
is issued, or in respect of the obligation of a specific authentication service provider or
specific group of authentication service providers to use a specific type of certificates
in relation to electronic messages or signatures introduced to them, shall be
considered, provided that such agreement shall not be contrary to the laws of the
Sultanate of Oman.
Chapter Seven
Protection of Private Data
Article (43)
Any government body or authentication service provider may collect personal data directly
from the concerned person or from others after his explicit approval, only for the purpose of
issuing a certificate or keeping it or facilitating such issuing or keeping. It is not permitted to
collect or process or use such data for any other purpose without the explicit consent of the
person from whom such data is collected.
As an exception from the above paragraph, the collection or disclosing or providing or
processing of personal data shall be legal in the following cases:14