Data Privacy Consultant
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Bachelor's Degree
- Eligibility
- This position is open exclusively to Saudi Nationals.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
The Data Privacy Consultant will spearhead the management, support, and continuous improvement of the company's data privacy initiatives to ensure full adherence to relevant privacy laws, regulatory frameworks, and industry standards. The consultant will play an integral role in evolving the organization's privacy governance, risk mitigation strategies, and privacy-by-design models while ensuring the protection of personal data throughout all operations.
Key Responsibilities
- Create, enforce, and update data privacy protocols, standards, procedures, and governance frameworks within the organization.
- Lead and conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to evaluate privacy risks.
- Guarantee compliance with data protection regulations such as Saudi PDPL, European GDPR, NDMO guidelines, and other related laws.
- Maintain comprehensive personal data catalogues, perform detailed data flow analyses, and carry out data classification processes.
- Oversee the handling of Data Subject Access Requests (DSARs) ensuring legal compliance and timely response.
- Evaluate third-party vendors through privacy risk assessments and review their privacy practices.
- Implement ongoing privacy risk evaluations and compliance audits to monitor organizational adherence.
- Assist with managing privacy incidents, including investigations, documentation, reporting, and resolution efforts.
- Participate in reviewing new projects, systems, and applications by incorporating privacy-by-design principles to protect personal data from the outset.
- Collaborate cross-functionally with legal, compliance, cybersecurity, and IT teams to reinforce data protection measures.
- Develop educational resources and support organization-wide privacy awareness and training programs.
- Keep abreast of changes in privacy laws and advise on necessary modifications to policies and controls.
Qualifications and Experience
- A Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, or closely related field is required.
- Possession of certificates such as CIPP, CIPM, ISO 27701, DAMA, or related credentials is highly desirable.
- Applicants must be Saudi Nationals.
- At least five years of relevant experience in Data Privacy, Data Governance, Information Security, Compliance, or Risk Management is mandatory.
- Demonstrated expertise in leading privacy compliance programs, assessments, and initiatives is preferred.
Competencies and Skills
- Expertise in managing comprehensive data privacy programs.
- Proficient with conducting Privacy and Data Protection Impact Assessments.
- Strong competence in personal data inventory maintenance and data mapping procedures.
- Experienced in managing Data Subject Rights requests effectively.
- Skilled at performing and evaluating third-party privacy risks.
- Knowledgeable about privacy risk management and continuous compliance monitoring techniques.
- Capable of managing privacy incidents including investigation and remediation.
- In-depth understanding of privacy-by-design frameworks.
- Familiarity with major privacy regulations including PDPL, GDPR, NDMO, and SAMA rules.
- Ability to develop and maintain privacy policies, standards, and processes.
- Strong background in data governance and managing information lifecycles.
- Experience in stakeholder liaison and regulatory communications.
- Excellent analytical, documentation, and reporting skills.
- Outstanding communication and stakeholder engagement abilities.
Minimum education
Bachelor's Degree