Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Legal Basis & Legitimate Interest Assessments

    under Saudi PDPL

    Masterclass #823 April 2026Muneeb Imran

    A recap of the Pyxos masterclass with Muneeb Imran.

    Every processing activity has to answer one question before any other: why are we allowed to do this at all. That was the foundation Muneeb Imran, DPO at the Saudi Credit Bureau, built this masterclass on. Lawful basis, he argued, is the first and most consequential decision in any processing, because without a valid basis the processing is unlawful no matter how well it is later secured.

    The habit Imran spent most time correcting was the reflex to reach for consent. The PDPL recognizes a range of bases, consent, contractual necessity, legal obligation, legitimate interest, public interest, actual interest, and vital interest, and consent is only the default many organizations assume rather than the one that usually fits. Over-reliance on it creates real operational fragility, because a consent that can be withdrawn can leave a necessary process with no ground to stand on. The work is to select the basis that genuinely matches the processing, which is a fact-specific judgment rather than a checkbox.

    The distinction he drew most firmly was the firewall between consent and legal obligation. Where a law or regulator mandates the processing, the basis is legal obligation, and asking for consent in that situation is not just unnecessary but misleading, because withdrawing consent cannot stop processing the organization is legally required to perform. He was equally clear that sensitive personal data cannot rest on legitimate interest, and that legitimate interest, where used, has to be supported by a documented assessment, a three-part test of purpose, necessity, and the balance against the individual's rights, that is signed and revisited when purposes change.

    The most memorable practical moment came in the Q&A, on how to capture consent for an in-person customer. Imran's answer was to design systems around the touchpoint: the moment an individual establishes a channel with you, walking into a store, for example, is the moment to obtain consent and, crucially, to secure the consent record for audit. A lawful basis you cannot evidence is, in practice, a lawful basis you may not have.

    A recurring caution was that marketing and service communications are easy to conflate and carry different requirements. Direct marketing generally requires consent under Article 25, which restricts the use of personal channels such as post, email, and phone for advertising, whereas a service communication tied to an existing contract may rest on another basis. Misclassifying one as the other is a common and avoidable compliance failure.

    Imran was clear that the lawful-basis decision is not the privacy team's to make alone. The business defines the purpose of the processing; the DPO ensures the basis selected is sound and documented. And the decision has to be recorded in the records of processing and supported by evidence, the signed assessments and the logs, so it can be defended later. The full set of bases and the assessment framework are best taken from the recording and the takeaways.

    The closing thought reframed the whole topic. Lawful basis is not a box to tick at the start; it is the control layer that determines whether processing is valid at all, and it has to be revisited whenever the purpose of the processing changes or a new use is added, because a basis that fit the original purpose may not survive the expansion.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenter

    • Muneeb Imran

      Muneeb Imran

      Muneeb Imran is a Data Privacy and AI Governance expert and co-author of Data Privacy: A Practical Handbook for Governance and Operations.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.