Data Privacy Manager
Derayah Financial · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجJob PurposeThe Data Privacy Manager is responsible for leading the organization's data privacy program in alignment with the Personal Data Protection Law (PDPL) of Saudi Arabia and other applicable regulations. The role serves as the operational owner of the privacy framework and Data privacy platform , and ensuring that personal data processing activities across the organization meet regulatory requirements, contractual obligations, and internal privacy standards.Duties & ResponsibilitiesPrivacy Program & GovernanceOperate and maintain the organization-wide data privacy program in line with PDPL, SDAIA regulations, and applicable cross-border data transfer requirements.Develop, maintain, and review privacy policies, procedures, standards, and notices.Maintain the Record of Processing Activities (ROPA) and ensure it remains accurate across all business units.Manage data classification, retention, and minimization controls in coordination with the data management and information security functions.Track regulatory developments (PDPL, SDAIA, NDMO, sector-specific guidance) and translate them into actionable internal requirements.Privacy OperationsConduct and oversee Data Protection Impact Assessments (DPIA) and Privacy Impact Assessments (PIA) for new and existing processing activities.Manage the data subject rights (DSR) request lifecycle, including intake, validation, fulfilment, and reporting within regulatory timeframes.Lead the privacy incident response process, including breach assessment, notification to SDAIA and affected individuals, and post-incident remediation.Manage and operationalize Data Privacy technical platform .Education & ExperienceWorking knowledge of the Saudi PDPL, SDAIA regulations, NDMO data management policies, and applicable sector regulations.Familiarity with international privacy frameworks (GDPR, CCPA, ISO 27701, NIST Privacy Framework).Strong understanding of personal data lifecycles, lawful processing bases, cross-border data transfer mechanisms, and privacy-by-design principles.Practical knowledge of privacy-enhancing technologies (PETs), pseudonymization, anonymization, and data masking.Understanding of how privacy controls integrate with information security, IAM, DLP, and data governance functions.Strong analytical, drafting, and stakeholder management skills.Strong understanding or market Data privacy tooling and solutionsAbility to translate regulatory requirements into operational controls and platform configurations.Required SkillsHigh level of Arabic and English both written and oral.Knowledge of IT & CybersecurityHigh level of communication skillsExpert in Microsoft Office such as PowerPoint and ExcelSpecialized Knowledge and Certificates:One or more of the following is required: CIPM, CIPP/E, CIPP/US, CDPO, or equivalent.CIPT, CISM, CISSP, or ISO 27701 Lead Implementer/Auditor are an advantage.