img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Hastraa Arabia is seeking an experienced Data Privacy Expert to lead and support the organization's data privacy and protection program. This full-time role involves ensuring compliance with the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, NDMO requirements, SAMA regulations, and other applicable Saudi data protection and cybersecurity frameworks. The successful candidate will be responsible for developing privacy policies, conducting PIAs/DPIAs, managing data privacy risks, and advising stakeholders on privacy requirements.

Key Responsibilities

  • Develop and implement Data Privacy Policies, Processes, Procedures, Standards, Principles, Guidelines, and Templates in accordance with KSA PDPL and other regulatory requirements.
  • Advise the organization on personal data processing, collection, use, storage, sharing, retention, and disposal requirements.
  • Lead Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) activities and maintain the Record of Processing Activities (RoPA).
  • Develop and maintain a comprehensive Data Privacy Risk Register, assessing privacy risks for new and existing processes, applications, and services.
  • Conduct privacy due diligence and assessments of third-party vendors, suppliers, and service providers, and advise on privacy requirements in vendor contracts.
  • Establish and maintain processes for managing Data Subject Rights (DSRs) and develop clear, transparent, and compliant Privacy Notices.
  • Provide privacy consultation and guidance during personal data breaches and cybersecurity incidents, supporting investigation, assessment, and regulatory reporting.
  • Advise stakeholders on cross-border personal data transfers and ensure compliance with Saudi privacy and regulatory requirements.
  • Act as a key point of contact for privacy-related matters involving customers, employees, business stakeholders, vendors, and regulatory authorities.

Qualifications and Experience

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, Data Management, Law, or a related field.
  • 5–10 years of relevant professional experience, with at least 5 years in a dedicated Data Privacy, Data Protection, Privacy Governance, or Data Compliance role.
  • Strong hands-on experience with Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
  • Understanding of NDMO requirements and Saudi data governance and privacy requirements.
  • Experience working with SAMA regulations/frameworks, preferably within the banking or financial services sector.
  • Practical experience in RoPA, PIA, DPIA, data mapping, privacy risk assessments, DSRs, privacy notices, breach management, and data transfer assessments.
  • Experience in data governance and data management is highly desirable.

Required Skills

  • In-depth knowledge of KSA PDPL and applicable data protection regulations.
  • Strong understanding of privacy principles, including data minimization, purpose limitation, transparency, and accountability.
  • Knowledge of data management, data governance, information security, and IT environments.
  • Ability to conduct and document PIAs, DPIAs, RoPA, data flow mapping, and privacy risk assessments.
  • Strong third-party/vendor privacy assessment and contract review skills.
  • Excellent analytical, problem-solving, and decision-making capabilities.
  • Strong stakeholder management and influencing skills.
  • Proficiency in Microsoft Office Suite.

Preferred Certifications

  • CIPP/E, CIPP/MENA, CIPM, CIPT
  • CDMP
  • ISO/IEC 27701, ISO/IEC 27001
  • CISA / CISM / CISSP
  • Other recognized Data Privacy, Data Protection, Data Governance, or Information Security certifications.

Requirements

  • Requires 5-10 Years experience

Similar Jobs