Apply Edge Start your job search

Data Privacy Specialist

Hastraa Arabia Limited · Riyadh, Saudi Arabia

Apply & track with Apply Edge

Data Privacy ExpertLocationSaudi ArabiaExperience5–10 YearsNotice PeriodImmediate to 30 Days MaximumEmployment TypeFull-TimeJob SummaryWe are looking for an experienced Data Privacy Expert to lead and support the organization's data privacy and protection program in compliance with the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, NDMO requirements, SAMA regulations, and other applicable Saudi data protection and cybersecurity frameworks.The successful candidate will be responsible for developing and operationalizing privacy policies, conducting PIAs/DPIAs, maintaining the Record of Processing Activities (RoPA), managing data privacy risks, overseeing third-party privacy compliance, supporting data subject rights, managing cross-border data transfers, and advising business and technology stakeholders on privacy requirements.The role requires strong knowledge of the Saudi regulatory environment, particularly within the banking/financial services sector, along with the ability to engage effectively with senior management, regulators, legal teams, technology teams, vendors, and business stakeholders.Key ResponsibilitiesData Privacy Governance & ComplianceDevelop, implement, and continuously improve Data Privacy Policies, Processes, Procedures, Standards, Principles, Guidelines, and Templates in accordance with KSA PDPL, Implementing Regulations, NDMO requirements, and applicable regulatory requirements.Advise the organization and employees on personal data processing, collection, use, storage, sharing, retention, and disposal requirements.Ensure business processes, records, applications, systems, and technologies containing personal data comply with applicable privacy requirements.Establish and maintain a comprehensive Data Privacy Compliance Framework.Define privacy standards and requirements to be followed by Information Security, IT, Data Management, and business teams.Regularly review and enhance privacy practices to address regulatory, business, and technology changes.PIA, DPIA & RoPALead Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) activities across the organization.Conduct and maintain the Record of Processing Activities (RoPA) repository for all relevant personal data processing activities.Identify processing activities requiring DPIAs based on PIA results and applicable regulatory requirements.Conduct DPIAs and recommend appropriate technical and organizational controls to mitigate identified privacy risks.Conduct data flow mapping to document the lifecycle of personal data from collection through processing, storage, sharing, archival, and destruction.Support the business in identifying and prioritizing critical and high-risk personal data processing activities.Privacy Risk ManagementDevelop and maintain a comprehensive Data Privacy Risk Register covering identified risks, risk owners, treatment plans, target closure dates, and remediation status.Assess privacy risks associated with new and existing business processes, applications, systems, products, and services.Review privacy controls implemented by business and technology teams and recommend improvements where required.Define privacy performance metrics and KPIs/KRIs and provide regular reporting to senior management.Monitor emerging privacy risks and regulatory developments and recommend appropriate corrective actions.Third-Party & Vendor Privacy ManagementConduct privacy due diligence and assessments of third-party vendors, suppliers, and service providers.Collaborate with Procurement, Legal, Information Security, and Business teams to assess third-party privacy risks.Review and advise on privacy requirements in vendor contracts, agreements, and statements of work.Support negotiation of Data Processing Agreements (DPAs), privacy clauses, data sharing agreements, and other relevant contractual provisions.Monitor third-party compliance with applicable privacy obligations throughout the vendor lifecycle.Data Subject Rights & Privacy NoticesEstablish and maintain processes, policies, and procedures for managing Data Subject Rights (DSRs).Manage and respond to data subject requests in accordance with applicable PDPL requirements and organizational procedures.Coordinate with relevant business, legal, technology, and customer service teams to ensure timely resolution of DSRs.Develop and maintain clear, transparent, and compliant Privacy Notices across customer, employee, digital, and other relevant channels.Data Breach & Incident ManagementProvide privacy consultation and guidance during personal data breaches, cybersecurity incidents, and privacy-related incidents.Support incident investigation, assessment, escalation, documentation, and regulatory reporting where applicable.Advise senior management and relevant stakeholders on privacy implications and required remediation actions.Ensure appropriate procedures are established for managing and responding to Personal Data Breaches.Cross-Border Data Transfers & Data SharingAdvise stakeholders on cross-border personal data transfers and applicable regulatory requirements.Establish and maintain processes for assessing, approving, documenting, and monitoring cross-border data transfers.Review and support the implementation of Data Sharing Agreements with external parties.Ensure data sharing and transfer arrangements comply with applicable Saudi privacy and regulatory requirements.Regulatory & Stakeholder EngagementAct as a key point of contact for privacy-related matters involving customers, employees, business stakeholders, vendors, and regulatory authorities.Collaborate with SAMA, SDAIA, NDMO, and other relevant authorities on data protection and privacy matters.Support regulatory inspections, assessments, inquiries, investigations, and information requests.Work closely with Legal on privacy-related legal requirements, regulatory inquiries, investigations, and contractual matters.Serve as a liaison between Business, Data, Legal, Information Security, IT, and Technology teams to ensure personal and sensitive data protection requirements are clearly understood and implemented.Reporting & Continuous ImprovementQualifications & ExperienceBachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, Data Management, Law, or a related field.5–10 years of relevant professional experience, with at least 5 years in a dedicated Data Privacy, Data Protection, Privacy Governance, or Data Compliance role.Strong hands-on experience with Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.Strong understanding of NDMO requirements and Saudi data governance and privacy requirements.Experience working with SAMA regulations/frameworks, preferably within the banking or financial services sector.Experience with privacy and cybersecurity frameworks applicable to the Saudi financial sector, including SAMA Cyber Security Framework (CSF) and relevant IT governance requirements.Practical experience in RoPA, PIA, DPIA, data mapping, privacy risk assessments, DSRs, privacy notices, breach management, and data transfer assessments.Experience in data governance and data management is highly desirable.CDMP certification or relevant data management certification will be an advantage.Experience working in a large, complex organization, preferably within banking, financial services, fintech, telecommunications, or other highly regulated industries.Fluent in both Arabic and English, written and spoken.Required SkillsIn-depth knowledge of KSA PDPL and applicable data protection regulations.Strong understanding of privacy principles including:Data minimizationPurpose limitationTransparencyAccountabilityData accuracyStorage limitationConfidentiality and integrityStrong understanding of data privacy governance, risk, and compliance.Knowledge of data management, data governance, information security, and IT environments.Strong understanding of personal and sensitive data protection requirements.Ability to conduct and document PIAs, DPIAs, RoPA, data flow mapping, and privacy risk assessments.Strong third-party/vendor privacy assessment and contract review skills.Excellent analytical, problem-solving, and decision-making capabilities.Strong stakeholder management and influencing skills.Excellent written and verbal communication skills in Arabic and English.Strong attention to detail and ability to handle confidential and sensitive information with a high degree of integrity.Proficiency in Microsoft Office Suite, including Word, Excel, PowerPoint, and related reporting tools.Preferred CertificationsCandidates with one or more of the following certifications will be preferred:CIPP/E, CIPP/MENA, CIPM, CIPTCDMPISO/IEC 27701ISO/IEC 27001CISA / CISM / CISSPOther recognized Data Privacy, Data Protection, Data Governance, or Information Security certifications.Key Candidate Criteria:Experience: 5–10 yearsRelevant Privacy Experience: Minimum 5 years

Location: Saudi ArabiaLanguage: Arabic & English – FluentIndustry: Banking / Financial Services preferredPDPL: Strong hands-on expertise requiredSAMA: Relevant experience requiredNotice Period: Immediate to 30 days maximumData Privacy: Strong practical experience in RoPA, PIA, DPIA, DSR, data mapping, breach management, vendor privacy, and cross-border transfersIf interested pls reply with updated cv to balaguru@hastraa.comWRBalaguru