Part 4 of our five-part series on the Privacy Leadership Workshop, hosted by Pyxos and the IAPP at the Riyadh Chamber of Commerce on June 22.
By the afternoon the room had grown beyond its morning numbers, and the subject had turned to the one that concentrates minds: enforcement. Skanda Reddy of Konexo moderated a panel deliberately built to cover the legal, in-house, and consulting lenses: Hamza Saghir, Head of Privacy & AI Trust at KPMG Middle East; Mahmoud Shafik Youssef, Group General Counsel at Foodics; Ali Abbas, Senior Associate at Al Tamimi & Company; and Yasir Bin Dabl, Director of Cybersecurity & Data Privacy at BSF Capital.
Reddy anchored the session in a single number. "Five days. That's the amount of time you have to respond once an enforcement notification lands on your desk." The organizing question followed directly: "What can your organization actually prove?" Then he asked the room for a show of hands: how many DPOs present were confident they could produce their record of processing activities within five minutes? The response, or the absence of one, made his point for him.
Abbas, who has moved with his clients from front-end compliance into live enforcement actions over three years of TMT and data practice, delivered the operational detail that visibly registered across the room. SDAIA is a technology-forward regulator that runs its processes through dedicated platforms: one for controller registration, and a separate one for enforcement, through which the claims against you are accessed. "A lot of companies that meet the requirement to register have not done so, and then when they need to report a breach, the first question is: are you registered with the platform? If you haven't signed up, it's a race against time, because you can't see what the claims against you are until you log on." On the reporting threshold itself, his guidance removed a common excuse for delay: the PDPL's threshold is low, SDAIA takes a conservative view of it, and interim notification is always available. "There's nothing stopping you from sending an interim notification: this has happened, we don't know all the facts yet, we will update you. What you don't want is to be debating internally whether the threshold is met while fifteen other companies using the same processor have already reported." And after filing, do not relax: "SDAIA is very proactive. They're reaching out, asking follow-up questions, often on a daily basis. Teams think, we've notified, we can relax. No. You have to continue working internally and be ready."
Saghir supplied the sequencing that experienced teams know. The 72-hour obligation runs to the regulator; the duty to notify data subjects is "deliberately left different: without undue delay," which exists precisely so that organizations can establish the facts before alarming the people affected. "What you don't want is to have notified the regulator and the data subjects, and it turns out there was no infiltration. You've caused panic and reputational harm." He also imported a remediation practice from the UK financial sector that he expects to reach the Kingdom: breach notifications that arrive with a credit-monitoring subscription code, so affected individuals can protect themselves immediately. The economics, he noted, are lopsided: a monitoring license costs a few pounds per person at volume, while litigated claims can run to tens of thousands per case. Being able to offer it within days of an incident means the process and budget were approved as part of business continuity long before anything went wrong.
Bin Dabl made the case for stress-testing everything before the crisis does it for you: tabletop exercises borrowed from business continuity, walking the DPO, general counsel, and the crisis team through a simulated breach to discover whether the templates, accesses, and escalation groups actually exist. "Documentation will slip away someday," he warned; only rehearsal reveals it. His counsel to DPOs was blunt about self-protection as well as compliance: "Most DPOs are superheroes, working multiple functions. But document things. Documentation is your actual evidence, because at the end you will be challenged, from the board, from the committees. If you haven't shared your struggles and challenges with management and board-level committees, then what do you expect? Have a very simple roadmap that leads you gradually to compliance, and always seek support." Saghir added the incentive: a tabletop exercise is also "a great way to ask for a pay rise," because it is the moment executives see the pressure concentrated on the DPO, whose personal details sit on the SDAIA registration.
Saghir's framing for the program as a whole was the phrase practitioners left repeating: the defensible compliance position. "This is not a technical or a legal term. It's what you are comfortable taking to the regulator. If you've got nothing to show, you're not going to be comfortable. If you've got something that says: this is the plan, these are the resources we've been given, this is what we're working on month one, month two, month three, get your artifacts ready." His sequencing advice was concrete: split design from implementation, because design moves fast, starting with the outward-facing basics of the website and external privacy notice; expect 50 to 60 percent compliance in a realistic first year; prioritize RoPAs and impact assessments where the sensitive data concentrates, typically HR and customer CRM; and if resourcing is inadequate, say so formally: "If you're not giving me the resources required to be audit-ready, it is not me who is responsible. You are the controller, and the regulator is going to hold you accountable."
Youssef grounded the evidence question in the business itself. A defensible lawful basis "should always be in relation to the service that you provide," supported by retention and deletion policies, and he widened the defense beyond privacy law: statutory retention obligations under tax and labor regulations can justify keeping data, with masking and anonymization applied to what is no longer needed. Deleting what you do not need, he added, is also a budget argument: fewer servers, lower cost, "a win-win for the board and for the operation." He flagged the cultural shift his team is living through: deletion requests from Saudi nationals, once unheard of, are now arriving, even for something as small as a CV, and Foodics built an HR process and information sessions to handle them. And he described the multi-jurisdiction reality for regional groups: the era of one GDPR-modeled RoPA for the whole group is over. "Now we have one general RoPA and we localize it for each jurisdiction," while regulators increasingly talk to each other, and boards debate a question no one anticipated: can one DPO based in KSA serve as the DPO in Egypt or the UAE?
Bin Dabl closed the loop on legacy risk that predates the law: historic vendor agreements without data processing terms are exactly what regulators now request in enforcement actions, and "we don't have a data processing agreement because it wasn't a requirement" will not hold. As Abbas put it, the regulator expects compliance obligations to be kept current, "because personal data is dynamic, not static."
Next in the series: the finale on agentic AI, the panel that had the room out of its seats. Enforcement readiness is also a recurring subject of the Pyxos masterclass series. Visit pyxos.ai/masterclasses to join.
Key takeaways for DPOs
- Register on SDAIA's controller and enforcement platforms now; in a live action, the claims against you are visible only there, and the five-day clock does not wait for your registration.
- Notify the regulator within 72 hours, use interim notifications when facts are incomplete, and notify data subjects without undue delay once the picture is clear, never before you know whether harm occurred.
- Run a tabletop breach exercise this quarter with the DPO, CISO, general counsel, and crisis team; procedures that exist only on paper fall away under pressure, and the exercise doubles as your resourcing argument to the board.
- Build a defensible compliance position: a documented, risk-prioritized, month-by-month plan you would be comfortable showing SDAIA, starting where sensitive data concentrates (HR, customer CRM).
- Audit legacy vendor agreements that predate the PDPL and bring data processing terms current; historic contracts are now a standard enforcement request.
- Document your resource constraints formally to management; accountability sits with the controller, and the record of what you asked for is your protection.
Our thanks to moderator Skanda Reddy (Konexo) and panelists Hamza Saghir (KPMG Middle East), Mahmoud Shafik Youssef (Foodics), Ali Abbas (Al Tamimi & Company), and Yasir Bin Dabl (BSF Capital).
In this series
- Part 1: "Innovation Can Move Fast, but Trust Is What Makes It Last": Inside the Privacy Leadership Workshop in Riyadh
- Part 2: What It Actually Means to Be a DPO in Saudi Arabia
- Part 3: The Next Generation of Saudi Privacy Leaders Takes the Stage
- Part 4: Five Days: The Enforcement Reality Under the PDPL (current)
- Part 5: When AI Starts Acting on Our Behalf

