Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Personal Data Breach Notification & Incident Response

    Masterclass #1715 July 2026Richard Chudzynsky and Skanda Reddy

    A recap of the Pyxos masterclass with Richard Chudzynsky and Skanda Reddy.

    The 72-hour clock does not start when the data protection officer finds out. It starts the moment anyone in the organization becomes aware of the incident. That point, repeated throughout, set the tone for this masterclass on personal data breach notification and incident response, led by Richard Chudzynsky and Skanda Reddy of Konexo, the consulting arm of Eversheds Sutherland: breach response rewards the prepared and punishes the improvising.

    The session began with the definition, because it is wider than most assume. The Implementing Regulations treat any incident leading to the disclosure, destruction, or unauthorized access to personal data as a breach, intentional or accidental, automated or manual. A misdirected email qualifies just as a ransomware event does. Yet not every security incident is a personal data breach: where no personal data is involved, the PDPL's notification machinery is not engaged, which makes triage the first capability to build.

    The legal spine is Article 20 of the PDPL and Article 24 of the Implementing Regulations. Where a breach may potentially cause harm to the personal data or the data subject, SDAIA must be notified within 72 hours of the organization becoming aware, and the notification carries two distinct timestamps: when the breach occurred and when it was discovered. The deadline can be extended, but only after an initial notification justifying the delay, which is why Chudzynsky's counsel was early engagement with the regulator, supplying detail as it firms up. Data subjects are notified without undue delay where the breach may damage their data or conflict with their rights or interests, harm SDAIA's guidance frames as impaired rights, physical danger, or economic loss such as fraud and identity theft. The notification itself comes from the DPO through the national data governance platform.

    On where breaches originate, the presenters were blunt. They cited industry research finding that 86 percent of Saudi organizations experience at least three identity-related breaches a year, and put the share beginning with employees at 60 to 80 percent, with the misdirected email as the everyday example. Third parties drew equal weight, since the weakest link in a supply chain is the one an attacker finds, and novel technologies, AI among them, expand the attack surface faster than the security and technical measures around them mature.

    The most practical moment returned to a familiar artifact. With a complete record of processing, a breached system can be traced in hours to the data it holds, the people it concerns, and where that data was shared or transferred. Without one, Chudzynsky observed, you are scrambling for days while the 72-hour clock runs, and the defensible narrative to the regulator becomes very hard to write. Preparation, both presenters kept repeating, is the real control.

    The aftermath received equally candid treatment. A large customer-facing breach drives a spike in data subject requests, each on its own statutory clock. Dually regulated organizations, a bank under SAMA or a hospital under the Ministry of Health, answer to more than one notification regime, which is why regulatory mapping is the first step of any breach plan, and communications discipline protects a reputation already at risk. The Jaguar Land Rover attack, cited at a reported cost near 200 million pounds, showed the scale mishandling can compound.

    The staged response lifecycle and the documentation toolkit the session set out are best taken from the recording and the takeaways.

    The closing question, what exactly makes an incident reportable, drew an honest answer: detailed guidance is still thin, and the judgment is informed by the organization's own risk appetite, with the safer posture being engagement over silence. The controller stays accountable throughout, whatever a processor contract says about who notifies. The framing that lingers is the oldest in security: there are two kinds of companies, those that have been breached and those that will be. The difference that matters is whether the plan existed before the incident did.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenters

    • Richard Chudzynsky

      Richard Chudzynsky

      Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

    • Skanda Reddy

      Skanda Reddy

      Skanda Reddy is a Senior Associate at Konexo (Eversheds Sutherland), focused on PDPL and data protection implementation across Saudi Arabia and the wider region.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.