2- The authentication service provider may transfer part of his activity to another authentication service provider provided that: (a) He notifies the owners of the valid certificates of his intention to transfer the certificates to another provider at least one month prior to the expected date of transfer. (b) He notifies the owners of the certificates of their rights in refusing such transfer and the deadline for refusal and the method thereof. The certificates whose owners expressed their refusal shall be revoked in writing or electronically on the stated deadline. 3- In case of the death or bankruptcy or dissolution of the authentication service provider, his heirs or liquidators shall be subjected to sub-article (2) of this article provided that the whole activity shall be transferred within three months. 4- In all cases of stopping the activity, the personal informations that remain under the control of the authentication service provider shall be destroyed in the presence of the competent authority representative. Article (42) 1- In determining the accuracy and validity of the certificate or electronic signature no regard should be had to the place where the certificate is issued or the electronic signature is effected or the jurisdiction within which the place of business of the certificate issuer is located or the electronic signature is effected. 2- The certificates issued by foreign authentication service providers shall be the same as those issued by authentication service providers who act pursuant to this law if the practices of the foreign authentication service provider has got that level of credibility not less than the level required from the authentication service providers who have been subjected to the provisions of this law taking into consideration the recognized international practices. 3- The certificates issued by foreign authentication service provider shall not be recognized unless by a ministerial decision. 4- To decide the validity of a certificate or electronic signature, any agreement between the parties in respect of the transaction in which that signature is used or the certificate is issued, or in respect of the obligation of a specific authentication service provider or specific group of authentication service providers to use a specific type of certificates in relation to electronic messages or signatures introduced to them, shall be considered, provided that such agreement shall not be contrary to the laws of the Sultanate of Oman. Chapter Seven Protection of Private Data Article (43) Any government body or authentication service provider may collect personal data directly from the concerned person or from others after his explicit approval, only for the purpose of issuing a certificate or keeping it or facilitating such issuing or keeping. It is not permitted to collect or process or use such data for any other purpose without the explicit consent of the person from whom such data is collected. As an exception from the above paragraph, the collection or disclosing or providing or processing of personal data shall be legal in the following cases:14

Select target paragraph3