أبلاي إيدج ابدأ البحث عن عمل

Data Privacy Consultant

Acuative Middle East · Jeddah, Makkah, Saudi Arabia

قدّم وتابع مع أبلاي إيدج
About the role:Acuative is hiring a Senior Data Privacy Consultant to be embedded within the Personal Data Protection (PDP) function of a leading research university in Saudi Arabia. You will act as a hands-on extension of the DPO's team, running the day-to-day privacy operations program and strengthening the organization's compliance posture under the Saudi Personal Data Protection Law (PDPL) and SDAIA regulations.This is an operational role, not an advisory-only role. You will facilitate workshops with business units, populate and validate compliance artifacts, run assessments, manage incidents, and coach internal privacy champions so the organization becomes self-sufficient over time.What you will do:Records of Processing Activities (RoPAs)Identify business units and processing activities without RoPAs and build them through stakeholder workshops.Validate and update existing RoPAs with process owners, and secure sign-off from BU Heads and the DPO.Data Protection Impact Assessments (DPIAs)Develop or apply a process gating methodology to screen all processing activities and flag high-risk ones.Conduct DPIAs on high-risk activities, identify privacy risks and controls, assign risk and control owners, and obtain sign-off.Record all identified risks in the GRC platform and track them to closure.Third-Party Privacy Risk ManagementIdentify data processors not yet subject to due diligence and build a High/Medium/Low risk tiering methodology.Assess high-risk processors, prescribe corrective actions and timelines, and coordinate with Procurement and the relevant BUs.Review vendor security controls in Data Processing Agreements (DPAs), perform transfer risk assessments, and embed required controls into DPAs and KSA Standard Contractual Clauses.Develop template security controls by contract type with Information Security, and update guidance for researchers on securing human subject research data.Data Breach ManagementSupport the DPO on privacy incidents end to end: containment, root cause analysis, mitigation, and coordination with Cyber Incident Response, Legal, Communications, and HR.Support regulatory breach notifications and responses to SDAIA inquiries.Privacy Hub and Spoke ModelRun workshops with BU Heads to appoint Privacy Champions across the organization.Define the Privacy Champion role (responsibilities, expectations) and secure management sign-off.Deliver 1-1 training to champions and manage a structured handover of privacy activities, with three months of SME support post-transition.Data Subject Rights (DSR)Handle DSR requests end to end: intake, register logging, validation, internal coordination, response, and closure.Identify and fix process bottlenecks in the DSR workflow.Data Minimization, Privacy Notices, and RetentionConduct data minimization reviews on intake forms, data sharing proposals, transfer risk assessments, and DPIAs.Review and update privacy notices based on RoPA and DPIA findings, changes in lawful basis, consent management, and legitimate interest procedures; draft new notices where needed.Review retention schedules against PDPL requirements and support process owners and technical stewards in setting compliant retention periods and technical SOPs for deletion.Privacy TrainingDevelop and deliver specialized on-site privacy training for units and build online training modules.Ad-hoc SupportAny other privacy tasks requested by the PDP function and the DPO.What we are looking for:Required:6+ years in data privacy, data protection, or GRC roles, with at least 2 years of hands-on operational privacy work (not purely policy or advisory).Deep working knowledge of the Saudi PDPL, its Implementing Regulations, the Data Transfer Regulations, and SDAIA guidance. Familiarity with GDPR is a strong plus.Proven experience building and maintaining RoPAs, conducting DPIAs, and running third-party privacy risk assessments.Experience managing personal data breaches, including regulatory notification.Experience handling Data Subject Rights requests and maintaining a DSR register.Strong workshop facilitation and stakeholder management skills across business, legal, IT, security, and procurement teams.Ability to draft clear compliance documentation: DPAs, SCCs, privacy notices, retention schedules, role definitions, and training material.Fluent English, written and spoken.Willingness to work on-site full-time in Thuwal, KSA.Preferred:CIPP/E, CIPM, CIPT, or equivalent privacy certification.Experience with GRC platforms (e.g., ServiceNow GRC, OneTrust, Archer) for risk logging and tracking.Background in higher education, research institutions, or other environments handling human subject research data.Arabic language proficiency.Experience with information security frameworks (ISO 27001, NCA ECC) and reviewing technical security controls in vendor contracts.