Data Privacy Expert

TAWANTECHRiyadhgulftalentoffentliggjort 16.09.2026
Skal:SecuritySenior

Responsibilities

Develop and operationalize data privacy policies, processes/procedures, standards, principles, guidelines, and templates to comply with KSA PDPL and NDMO regulations (including but not limited to personal data breach procedures, DPIA, PIA, RoPA, etc.).

Advise the bank and employees on data processing requirements under the KSA PDPL and ensure compliance.

Provide guidance on data protection impact assessments (DPIA) for data collection and processing.

Ensure all bank records and systems containing personal data align with PDPL.

Develop a comprehensive risk register that encompasses all identified risks along with corresponding treatment plans, closure dates, and responsible stakeholders.

Define personal data protection standards to be followed by the information security team.

Conduct due diligence on vendors and monitor their adherence to privacy obligations.

Regularly review and update personal data privacy and protection practices.

Review and advise on controls implemented by the business to ensure compliance with data protection requirements and internal policies.

Collaborate with SAMA, Saudi Data and Artificial Intelligence Authority (SDAIA), and other relevant authorities on data protection matters.

Act as the point of contact for data subjects (e.g., customers) and regulatory authorities.

Collaborate with procurement and legal teams to evaluate privacy risks associated with third-party vendors and service providers.

Review and negotiate privacy terms in vendor contracts to ensure compliance with data protection requirements.

Provide regular reports to senior management and relevant stakeholders on privacy program effectiveness, compliance status, and emerging privacy risks.

Collaborate with legal to address privacy-related legal requirements, inquiries, and regulatory investigations.

Serve as a liaison between business and functional areas and technology to ensure data-related business requirements for protecting personal and sensitive data are clearly defined, communicated, and well understood.

Manage and advise the relevant stakeholders on data transfers across borders, including approvals and monitoring.

Establish processes to manage personal data transfers and data sharing agreements with external parties while maintaining privacy compliance.

Support the bank in prioritizing processing activities.

Conduct data flow mapping exercises to identify the journey of personal data from collection to destruction, covering data collection points, systems used for processing, storage, etc.

Conduct the RoPA exercise and maintain its repository for all personal data processing activities.

Conduct PIAs for all processing activities identified in the RoPAs to determine which require DPIAs.

Perform DPIAs based on the results of the PIAs.

Offer consultation in the event of a data breach or incident, report to senior management promptly, and take necessary actions.

Provide clear and transparent privacy notices to data subjects across all channels.

Respond to data subject rights requests (DSRs) and establish policies and procedures for handling DSRs.

Define performance metrics and ensure compliance with data protection and privacy policies, standards, roles, and responsibilities.

Requirements

Bachelor’s degree in engineering, information technology, cybersecurity, or a related field.

Fluent in spoken and written Arabic and English.

A minimum of 5+ years of experience in a dedicated data privacy or data protection role.

Fair experience in data management; CDMP is an additional advantage.

Demonstrable expertise in the Saudi Personal Data Protection Law (PDPL) and its implementing regulations.

Proven experience working with data governance, privacy, and cybersecurity frameworks specific to the Saudi financial sector (e.g., SAMA’s Cyber Security Framework, IT Governance Framework).

Strong understanding of privacy principles such as data minimization, purpose limitation, and accountability.

Excellent communication, interpersonal, and leadership skills, with the ability to influence stakeholders at all levels.

High level of integrity and professional ethics, with the ability to handle confidential information with discretion.

Skills

Excellent IT skills: full Microsoft Office suite.

In-depth knowledge of PDPL and other relevant data protection laws and regulations.

Sufficient knowledge of information technology and data management systems required.

Well-developed and professional interpersonal skills; ability to interact effectively with people at all organizational levels of the firm.

Experience of working in a large organization.

Detail-oriented approach needed to recommend and implement strategic improvements on a range of data privacy and data protection issues.