D
Data Privacy Manager
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
The Data Privacy Manager leads and oversees the organization's data privacy initiatives to ensure compliance with the Saudi Arabian Personal Data Protection Law (PDPL) and related regulations. This role acts as the key operational head for maintaining the privacy framework and data privacy platform, ensuring that all personal data processing adheres to legal, contractual, and internal privacy requirements.
Key Responsibilities
- Manage and sustain the enterprise-wide data privacy program aligned with PDPL, SDAIA regulations, and cross-border data transfer mandates.
- Develop, update, and review privacy-related policies, procedures, standards, and communications.
- Maintain an accurate Record of Processing Activities (ROPA) across all business sectors.
- Coordinate data classification, retention, and minimization efforts in collaboration with data management and information security teams.
- Monitor evolving regulatory frameworks (PDPL, SDAIA, NDMO, and sector-specific guidance) and translate them into internal actionable policies.
- Conduct and supervise Data Protection Impact Assessments (DPIA) and Privacy Impact Assessments (PIA) for new and ongoing processing operations.
- Handle the complete data subject rights (DSR) request process including intake, verification, fulfillment, and compliance within stipulated timelines.
- Lead privacy incident response activities encompassing breach evaluation, notifications to SDAIA and affected parties, and implementing remedial measures.
- Manage and optimize the technical data privacy platform for operational efficiency.
Expertise & Experience
- Proficient knowledge of Saudi PDPL, SDAIA regulations, NDMO data management policies, and related sector-specific laws.
- Familiar with global privacy frameworks such as GDPR, CCPA, ISO 27701, and the NIST Privacy Framework.
- Deep understanding of personal data lifecycle processes, lawful bases for processing, mechanisms for cross-border data transfers, and privacy-by-design concepts.
- Hands-on knowledge of privacy-enhancing technologies including pseudonymization, anonymization, and data masking.
- Insight into how privacy controls fit within broader information security, Identity Access Management (IAM), Data Loss Prevention (DLP), and data governance functions.
- Strong analytical capability, excellent drafting skills, and effective stakeholder engagement.
- Well-versed in market-leading data privacy technologies and solutions.
- Capability to convert regulatory demands into practical control measures and platform settings.
Skills & Qualifications
- Fluent in Arabic and English with high proficiency in written and verbal communication.
- Good foundation in Information Technology and Cybersecurity.
- Advanced communication and interpersonal skills.
- Expertise in Microsoft Office applications, particularly PowerPoint and Excel.
Certifications
- Mandatory: Possession of at least one certification among CIPM, CIPP/E, CIPP/US, CDPO, or an equivalent credential.
- Optional but advantageous: Certifications such as CIPT, CISM, CISSP, or ISO 27701 Lead Implementer/Auditor.
Skills
Tools & software
Microsoft Office
Microsoft Office
required
How they work
Communication
Problem Solving
Attention to Detail
Relationship Building
Languages
Arabic
English