Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Higher-Risk Processing & DPIAs

    under Saudi PDPL

    Masterclass #25 March 2026Tahir Latif

    A recap of the Pyxos masterclass with Tahir Latif.

    A dataset that looks harmless on its own can become sensitive the moment it is combined with another. That idea sat at the centre of this masterclass on higher-risk processing and Data Protection Impact Assessments, led by Tahir Latif, IAPP Country Leader for the UAE, KSA and Qatar. His argument was that the DPIA is not a launch-day formality but the primary instrument for finding and reducing risk to people before high-risk processing begins, and that it has to stay alive as the processing changes.

    The framing that landed hardest was about what actually makes processing high-risk. It is not only the obvious categories. Latif pressed the point that aggregation creates hidden exposure: combining datasets that each look benign can reveal health status, religious affiliation, or personal habits that no single source disclosed. Three quick tests help surface when a DPIA is owed: are you processing sensitive or inferred-sensitive data, are you monitoring people in public or semi-public spaces, and are algorithms making or shaping decisions about people.

    He was also clear that risk under the PDPL is not measured in financial terms alone. In the Saudi legal and cultural context, dignity, stigma, and psychological harm can be the more significant risks, and an assessment that weighs only monetary loss is incomplete. That is a meaningful difference from how impact assessments are often run elsewhere, and it changes what a defensible DPIA has to consider.

    The most operationally useful part of the session was about where DPIAs actually live. Latif's argument was that an assessment triggered by luck is no control at all, so the DPIA has to be wired into the workflows where high-risk processing originates: project-management approval gates, the software development lifecycle, change management, and procurement sign-off for new tools. He was equally direct about the growing problem of Shadow IT and Shadow AI, where a department adopts a high-risk technology with no review at all, which is why continuous discovery, not just a one-time inventory, is part of the job.

    A point that recurs across enforcement-era privacy work came through here too: who owns the risk. The DPIA is advised by the privacy function, but the business unit that runs the processing accepts the residual risk and signs off. Where that residual risk stays high after mitigation, it does not sit with a project team; it escalates to senior leadership or a risk committee. And the mitigations a DPIA identifies, encryption, retention limits, audit rights, have to make their way into the vendor contracts that govern the processing, or they are not really mitigations at all.

    Article 25 of the Implementing Regulations frames when an assessment is mandatory, and the session set out the triggers and the audit-ready documentation a regulator would expect to see for each high-risk activity. Those specifics are best taken from the recording and the takeaways.

    The closing message was that a DPIA is a living document. When the data, the technology, the scope, or the volume changes, the assessment is reopened, not archived. Treated that way, it is the spine of a defensible program rather than a one-time gate, and the organizations that can trace a dataset end to end, from the processing record through the DPIA to the vendor contract and ongoing monitoring, are the ones that withstand scrutiny.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenter

    • Tahir Latif

      Tahir Latif

      Tahir Latif is the IAPP Country Leader for the UAE, KSA and Qatar, and co-author of Data Privacy: A Practical Handbook for Governance and Operations.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.