Back to Blog

    Privacy Leadership Workshop · Part 2 of 5

    What It Actually Means to Be a DPO in Saudi Arabia

    Pyxos · 25 June 2026 · Riyadh Chamber of Commerce

    Panel 1 of the Privacy Leadership Workshop on the DPO role in Saudi Arabia

    Part 2 of our five-part series on the Privacy Leadership Workshop, hosted by Pyxos and the IAPP at the Riyadh Chamber of Commerce on June 22.

    The first panel of the day put the hardest job in the profession on stage. Hamza Saghir, Head of Privacy & AI Trust at KPMG Middle East, who served as deputy chief privacy officer at Saudi Aramco and as DPO for KPMG's UK firm when the GDPR came into force, moderated a lineup built to see the role from every side: Muneeb Imran Shaikh, data privacy expert and co-author of Data Privacy: A Practical Handbook for Governance and Operations; Richard Chudzynski, partner at Konexo, the legal consultancy arm of Eversheds Sutherland, with a decade of privacy work in the Kingdom; Husain Meleeh, Unit Head of Data Protection at Bank of Bahrain and Kuwait and an IAPP chapter chair who flew in from Bahrain for the day; and James Beriker, CEO and founder of Pyxos.

    Saghir opened with the question every DPO in the room has been asked in some form: given the size of the data sets in your custody, how do you sleep at night? Shaikh's answer redefined the job before it addressed the anxiety. "The DPO is meant to be the ambassador of the individual's rights and interests. It's not just about providing the safeguards to protect that data. An organization may do quite well in protecting the data, but is it being processed in a lawful manner, in a fair manner? Is it leading to an outcome that is fair to those individuals? Do they have any avenue to contest that processing?" The honest answer on sleep: "You will always have sleepless nights until you are able to create a culture where people transform these things into organizational values."

    Building that culture, Shaikh argued, requires a different message at every altitude of the organization, and he was specific about all three. At the C-suite, "if you do not have foresight on how the regulations are going to shape up and how they might impact the business, you're not going to get an audience"; executives respond to business consequences, not statutory citations. At middle management, the work is process engineering, because "within a process there are certain steps that actually violate the rights of individuals, or leave a channel open where personal data might be processed unlawfully or without the appropriate safeguards." And at the operational level, it is workshops and sensitization, because organizations resist change for a reason he named precisely: "Organizations are in a state of inertia, because inertia offers a sense of security to our minds. To break that inertia, you need to first sensitize the people."

    Chudzynski made the commercial case with the conviction of someone who has spent years making it to skeptical boards. The regional fines are not yet what moves executives, but reputational exposure is, and the neighborhood offers proof: he pointed to the DIFC and ADGM, where regulators have published enforcement details and issued hundreds of admonishments, and where naming produced immediate culture change. Saghir added the domestic signal: SDAIA investigated 48 organizations last year, without publishing names. Chudzynski's stronger argument, though, was upside: "I don't think people realize that when you put a proper privacy program in, when you can really utilize your data, know where it is, respond to rights, and do everything right, it really is a return on investment." And on organizations that want a tickbox engagement: "If a client wants to come and do a tick, I'm not interested, because it's running through my veins how important this is."

    Beriker brought the field data. Pyxos has spoken with hundreds of DPOs across the Kingdom, and the pattern is uniform: "They're constrained, resource-constrained, and stretched, and doing a lot of manual work." The deeper problem is structural. "It's very challenging to be a DPO in a country that until the PDPL never had a data privacy law. Data privacy isn't the job of one person; it's the job of the whole organization. But how do you get the organization to support a data privacy process when the people in sales, marketing, and HR who handle the personal data don't understand why it matters or what is required of them?" His answer to Saghir's technology question drew the sharpest line of the panel: "The existing platforms are workflow management tools. They're dashboards and templates, and they help you check boxes, but they don't do any of the work. What DPOs and teams need is help executing. They don't need any more dashboards and checkboxes and templates. They need technology platforms that can actually do the work."

    An audience member, a practicing privacy professional, pushed back on exactly the right point: the DPO's role is judgment, not rule lookup, so how can AI be trusted with assessments that turn on intangible, situational factors? Beriker's answer distinguished raw frontier models from expert-trained systems. "If you went to a general model and asked it about an assessment or a vendor contract, you're going to get a generalized answer, and it's likely to be wrong. The AI that works for lawyers and data protection officers isn't raw AI. It's a model trained on the nuances of your area of practice," the approach used by the leading legal AI platforms and by Pyxos, whose advisers are KSA lawyers, consultants, former regulators, and DPOs. And the boundary that governs all of it: "Everything is human in the loop. Nothing goes out without the DPO's review and consent. That is a core principle. AI can't run on its own in sensitive situations like data privacy."

    Meleeh offered the preview from a jurisdiction seven years into its law. In Bahrain, regulator pressure, mandatory training for data protection guardians, and licensing requirements are what moved DPOs from middle management into board-level committees, sector by sector, with financial services leading; he expects SAMA and SDAIA to drive the same trajectory here. His caution was about foundations: where data governance is immature, "more effort is required from the DPO, more discussions with all departments," because a DPO cannot protect an estate no one has mapped. His advice to those starting out was disarmingly practical: start incrementally with the compliance requirements, then integrate the privacy program into project management and procurement, "shifting the responsibilities from you as data privacy officer to the right team to handle the privacy requirement within their department. Even the budget concern can be resolved, because many of the budgeting requirements will move to the other departments."

    Shaikh closed with the career advice that landed hardest. Cross-functional understanding is non-negotiable, "because just knowing the law will not take you far; you need to see where the pathways of privacy converge or diverge with information security, risk management, IT, and the business." And the disposition that separates effective DPOs from feared ones: "You don't necessarily have to say no all the time. You can offer alternate solutions. If the business feels empowered that the DPO is offering alternate solutions, they will rely more on you rather than seeing you as a showstopper."

    Next in the series: the next generation of Saudi privacy leaders takes the stage. The DPO conversation also continues in the Pyxos masterclass series, which runs nearly every week. Visit pyxos.ai/masterclasses to join.

    Key takeaways for DPOs

    • Define the role as ambassador of individuals' rights, not custodian of data; protection without lawfulness and fairness is half the job.
    • Calibrate your message by audience: business foresight for the C-suite, process engineering with middle management, sensitization workshops for operations. One deck for all three fails all three.
    • Sell the program on reputational risk and return on investment, not fines; regional enforcement is already publishing names next door, and SDAIA's investigations are growing.
    • Push responsibility and budget into the business functions that own the processing; a privacy program run entirely from the DPO's office cannot scale and will not survive an audit.
    • Evaluate technology by whether it executes work, not whether it tracks it; dashboards and templates do not reduce the manual load that defines the role in the Kingdom.
    • Never say only no; pair every objection with an alternate route, and the organization will bring you in earlier rather than route around you.

    Our thanks to moderator Hamza Saghir (KPMG Middle East) and panelists Muneeb Imran Shaikh, Richard Chudzynski (Konexo · Eversheds Sutherland), Husain Meleeh (Bank of Bahrain and Kuwait), and James Beriker (Pyxos).

    In this series

    1. Part 1: "Innovation Can Move Fast, but Trust Is What Makes It Last": Inside the Privacy Leadership Workshop in Riyadh
    2. Part 2: What It Actually Means to Be a DPO in Saudi Arabia (current)
    3. Part 3: The Next Generation of Saudi Privacy Leaders Takes the Stage
    4. Part 4: Five Days: The Enforcement Reality Under the PDPL
    5. Part 5: When AI Starts Acting on Our Behalf

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.