On June 22, more than 100 privacy professionals, practitioners, and business leaders filled the Riyadh Chamber of Commerce for the Privacy Leadership Workshop, a half-day event co-sponsored by Pyxos and the IAPP and moderated by Tahir Latif, IAPP Country Leader for the UAE, KSA, and Qatar. The day marked the fourth year of IAPP events in the Kingdom, and the arc of those four years was visible in the room itself. As Latif reminded the audience in his welcome, the community began as "a handful of professionals, the vast majority from overseas, bringing knowledge of GDPR and data privacy regulations from across the globe." The commitment he and IAPP KSA chapter chair Basmah Alsubaie made at the time was "to uplift the Kingdom, to share our knowledge, to train more privacy professionals here." On June 22, that commitment filled an auditorium.
This post opens a five-part series covering the workshop. The keynote is below; over the coming days we will publish a recap of each of the four panels: what it actually means to be a DPO in Saudi Arabia; the next generation of Saudi privacy leaders; the enforcement reality under the PDPL; and what happens when AI starts acting on our behalf. Each recap carries the arguments, the disagreements, and the practical guidance the panelists put on the record, along with takeaways you can act on.
The keynote fell to Basmah Alsubaie of Privacy Professionals, and she opened by dismantling the frame most organizations still use. "Privacy is often described as a legal requirement, sometimes as a compliance burden, and sometimes, unfortunately, as a box to tick," she told the room. "But that is not what privacy is. Privacy is the way a society decides whether it can trust the systems it is building."
That question, she argued, is no longer abstract in Saudi Arabia, because the Kingdom is not merely adopting digital transformation but leading it, across government, healthcare, finance, smart cities, and artificial intelligence. "Data is becoming the fuel of national ambition," she said. And every act of scale compounds the stakes: "Every time we collect more data, we automate more decisions, we connect more systems, one question becomes unavoidable: will people trust what we are building?"
Her reading of the regulatory moment was precise. The PDPL has moved the discussion "from intention to execution, from policy to practice, and from aspiration to accountability." Privacy in Saudi Arabia, she said, "is no longer a future topic. It is a present responsibility." But she refused to let the room mistake documentation for capability, and this was the passage practitioners quoted back to each other through the day: "The real challenge is not writing the rules. The real challenge is living them, because compliance on paper does not automatically create maturity in practice. A policy can exist and fail. A control can be documented and still not work. A team can be aware of the law and still not know how to apply it under pressure."
That is why the event was built around people rather than paperwork. The question before the profession, she argued, is not whether privacy matters; it is "whether we are building privacy as a habit, as a discipline, and as a leadership capability." The foundation is the PDPL, governance, and accountability; the execution is data handling, security, AI, and real-world implementation; but the deciding layer is human: "the DPOs, leaders, practitioners, and future professionals who will shape what privacy becomes in the Kingdom. Because systems do not build trust. People do. And people build trust when they lead with clarity, consistency, and courage." Those three C's became the day's refrain, cited on stage in every panel that followed.
She closed with an invitation rather than a conclusion. "Do not come here only to listen. Come here to challenge assumptions, to ask the hard questions, and to compare experiences. Because the future of privacy in Saudi Arabia will not be decided by one regulation or one organization or one workshop. It will be decided by whether we choose to treat privacy as a constraint or as a competitive advantage. I believe it is the second." And then the line the room carried out the door: "Innovation can move fast, but trust is what makes it last."
Latif added the personal test that made the keynote operational, urging the audience to take one habit home: "Always think, what if this is my data? How would I use it? Would I process it in this manner? Would I share it with others in this way?" It is a one-sentence privacy impact assessment, and it costs nothing to run.
The four panel recaps follow in this series. The Privacy Leadership Workshop was the second event Pyxos has hosted at the Riyadh Chamber of Commerce, alongside a masterclass series that runs nearly every week with the Kingdom's leading practitioners. To join the next session, or to be in the room for the next Riyadh event, visit pyxos.ai/masterclasses.
Key takeaways for DPOs
- Reframe your internal pitch: privacy is not a compliance cost but the mechanism by which your organization earns the trust its digital ambitions depend on.
- Audit for the gap Alsubaie named: a documented control that does not work under pressure is a liability dressed as an asset. Test controls, not just policies.
- Build privacy as a habit and a discipline across the organization, not as a project owned by one office; maturity is behavioral, not documentary.
- Lead with the three C's: clarity in what the law requires, consistency in how you apply it, and courage to say so when the business pushes back.
- Apply the personal test to any contested processing decision: would you accept this handling if it were your own data?
- Position compliance as competitive advantage in board conversations; the organizations that treat it as a constraint will do the minimum and it will show.
Our thanks to Basmah Alsubaie (Privacy Professionals) for the keynote, to Tahir Latif (IAPP) for moderating the day, and to the Riyadh Chamber of Commerce for hosting.
In this series
- Part 1: "Innovation Can Move Fast, but Trust Is What Makes It Last": Inside the Privacy Leadership Workshop in Riyadh (current)
- Part 2: What It Actually Means to Be a DPO in Saudi Arabia
- Part 3: The Next Generation of Saudi Privacy Leaders Takes the Stage
- Part 4: Five Days: The Enforcement Reality Under the PDPL
- Part 5: When AI Starts Acting on Our Behalf

