A recap of the Pyxos masterclass with Basmah Alsubaie, Richard Chudzynsky and Tahir Latif.
The wishful-thinking phase is over. That was the unambiguous message of this roundtable on how PDPL enforcement is actually unfolding, a conversation among Basmah Alsubaie, CEO of Privacy Professionals and former CEO of National Data Governance at SDAIA; Richard Chudzynsky of Konexo (Eversheds Sutherland); and Tahir Latif of the IAPP. Drawing on direct work with organizations under active investigation, the panel described a regulator that has moved decisively from awareness-building to action. As Latif put it, the early hope that the law would arrive without teeth is finished.
The reframing that ran through the discussion was that enforcement, in practice, is the evidence phase. Regulators are no longer satisfied with policies and frameworks; they expect documented proof that controls operate as described, and Latif's distinction was that the work has to shift from privacy paperwork to privacy proof, from understanding the law to demonstrating compliance with it. A privacy policy, he noted pointedly, can be drafted by a chatbot in minutes; what regulators now probe is the operational layer beneath it.
The concrete signals were striking. SDAIA's enforcement committees, chaired by legal experts and staffed with IT and technology specialists, hear cases, summon parties, require evidence, and issue binding resolutions, and they published 48 decisions in 2025 alone. Chudzynsky stressed that these spanned many sectors, not just tech or critical infrastructure, and covered ordinary failures: marketing without consent, inaccurate privacy notices, missing lawful basis. Alsubaie added that cases pass through a supervisory and audit phase before any judicial stage, and that the organizations which fare worst are those that ignore SDAIA's communications and requests for documentation, escalating a matter that engagement could have contained.
Sectoral regulators are maturing alongside SDAIA. Latif described the financial regulator's quarterly audits, now two years deep, as genuinely intrinsic, often producing twenty to thirty findings of varying severity, with other sectoral regulators building comparable capability. Healthcare and financial services appear to be priority sectors, reflecting the sensitivity of the data. And enforcement risk is increasingly driven by data subjects themselves: Alsubaie cited research showing younger residents are the most aware of their rights, and the panel confirmed that every individual complaint is investigated.
Two structural cautions recurred. The first was the under-empowered DPO, too low in the organization, excluded from early decisions, engaged only after processing has begun, which creates privacy debt that is expensive to remediate; the panel's view was that DPOs should report at C-suite level, and that reporting into IT or security is a conflict that would not survive in a mature jurisdiction. The second was over-reliance on tooling bought before governance, ownership, and human capability existed, which delivers little. Notably, Latif observed that some regulators now ask large enterprises how they can possibly run privacy manually at scale, signalling that thoughtful use of technology is expected, not discouraged, provided the human judgment sits behind it.
A shared warning closed the substance: treat any claim of total compliance with suspicion, since no mature program anywhere asserts it, and capacity constraints at the regulator are no reason to relax, because the complaint-driven trigger does not depend on the number of investigators. The specific triggers, sector priorities, and committee mechanics are best taken from the recording and the takeaways.
The most actionable takeaway was about posture. A proactive, transparent stance toward the regulator consistently de-escalates, while silence and contestation escalate, and the foundation under all of it remains an accurate, current record of processing, the first artifact a regulator asks to see.
About the presenters

Basmah Alsubaie
Basmah Alsubaie is CEO of Privacy Professionals and a former regulator, previously CEO of National Data Governance at SDAIA.

Richard Chudzynsky
Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

Tahir Latif
Tahir Latif is the IAPP Country Leader for the UAE, KSA and Qatar, and co-author of Data Privacy: A Practical Handbook for Governance and Operations.
