A recap of the Pyxos masterclass with Muneeb Imran.
Policies do not protect personal data; the people handling it do. That was the premise of this masterclass on privacy culture, awareness, and training, led by Muneeb Imran, DPO at the Saudi Credit Bureau, and it reframes culture from an HR formality into an operational control. Pyxos has spoken with well over fifty DPOs in the Kingdom over the past year, and as James Beriker noted in opening the session, this question, how do I get the whole organization to understand and support the law, comes up every single time.
Imran's argument was that culture is built deliberately, through role-based training and awareness treated as instruments toward a goal rather than as the goal itself. Running a workshop is not the objective; changing behavior is. And the single biggest cause of low training effectiveness, he argued, is generic content disconnected from the work people actually do. A legal-heavyweight course overwhelms a customer-care agent, while basic awareness wastes an executive's time. The fix is differentiation: the functions with the most exposure to personal data warrant their own curricula rather than a shared module.
That led to one of the session's sharper points, that privacy risk concentrates in particular roles, and they are not always the obvious ones. HR, IT administrators, security operations, customer care, marketing, procurement, and data and AI teams all sit close to personal data. Imran was especially pointed about IT administrators: authorized access to a system is not authorization to look at any data within it, and an administrator browsing payroll records is performing unauthorized processing. The high-risk behaviours to train against are concrete, informal sharing over chat and email, mishandled spreadsheets and unauthorized exports, delayed breach reporting, and the quiet adoption of Shadow AI or Shadow IT without review.
The session was clear that the PDPL prescribes neither a curriculum nor a frequency. It requires organizational measures and expects accountability proportionate to risk, which puts the judgment, and the burden of evidencing it, on the organization. That makes how you measure effectiveness the crucial question, and Imran's answer was that it has to be behavioral rather than administrative. Completion rates say nothing about whether behavior changed; in fact, signals have to be read with care, since a fall in incidents or a rise in reporting can each point in more than one direction. The clearest diagnostic he offered is full completion alongside recurring incidents, which is the unmistakable sign of a program that is performative rather than effective.
A recurring practical theme was that training needs surface through symptoms rather than on a calendar, security incidents and near-misses, misrouted requests, complaints that reveal frontline misunderstanding of rights, and onboarding waves after hiring surges or acquisitions. Reading those signals is what tells you the program needs reinforcement, not the passage of twelve months. The training lifecycle and the documentation that evidences accountability are best taken from the recording and the takeaways.
The point Imran left the audience with is that undocumented training is treated, in an audit, as no training at all, which is why a culture you cannot evidence offers little protection when it matters most. And the instinct to reach for a software tool to fix what is fundamentally a behavioral problem usually disappoints, because the administrative groundwork has to come first.
π₯
About the presenter

Muneeb Imran
Muneeb Imran is a Data Privacy and AI Governance expert, Data Protection Officer, and co-author of Data Privacy: A Practical Handbook for Governance and Operations.
