Job Openings
PDPL LEAD - DATA PRIVACY, DATA GOVERNANCE
About the job PDPL LEAD - DATA PRIVACY, DATA GOVERNANCE
POSITION SUMMARY
The PDPL Lead ensures the bank's compliance with KSA Personal Data Protection Law (PDPL). Responsible for implementing privacy policies, managing data protection compliance activities, conducting privacy assessments, and supporting regulatory requirements across the organization.
CORE RESPONSIBILITIES
- Ensure ongoing PDPL compliance and regulatory alignment across the organization
- Conduct and manage Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs)
- Lead data mapping initiatives and maintain data processing documentation
- Manage individual rights requests (access, deletion, correction, portability)
- Coordinate data breach response and incident management
- Oversee third-party/vendor data processing agreements and compliance
- Develop and deliver privacy training and awareness programs
- Manage consent workflows and lawful basis documentation
- Support regulatory examinations and SAMA/SDAIA inquiries
- Maintain privacy risk register and compliance tracking
REQUIRED QUALIFICATIONS
Experience
- Minimum 6–8 years data protection/privacy/compliance experience
- Minimum 4–5 years in banking or regulated financial services
- Experience implementing PDPL or equivalent data protection frameworks
- Proven experience conducting privacy assessments and audits
Certifications (Required)
- CDPO, CIPM, CIPP, or equivalent data protection certification
- ISO 27001 or DAMA DMBOK Data Governance certification
Knowledge & Skills
- Deep understanding of KSA PDPL framework and requirements
- Knowledge of SAMA regulatory expectations and SDAIA guidance
- Privacy Impact Assessment and Data Protection Impact Assessment expertise
- Data mapping and privacy documentation capabilities
- Consent management and individual rights request handling
- Risk analysis and compliance tracking
PREFERRED QUALIFICATIONS
- Prior Saudi Arabia or GCC banking experience
- IAPP CIPL or CISM certification
- Privacy management platform experience (OneTrust, Collibra, Cisco Hyperscale)
- SQL or database query skills for data auditing
- International privacy framework experience (GDPR, CCPA)
KEY COMPETENCIES
- Strong regulatory compliance focus and attention to detail
- Clear communication of complex privacy concepts to diverse audiences
- Technical capability and data flow understanding
- Cross-functional collaboration and stakeholder management
- Professional independence and ethical judgment
- Proactive problem-solving and documentation skills