Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Privacy Governance & Operating Model Design

    under Saudi PDPL

    Masterclass #930 April 2026Muneeb Imran

    A recap of the Pyxos masterclass with Muneeb Imran.

    Strong controls decay the moment the project that built them ends, unless something holds them in place. That something is governance, and it was the subject of this masterclass led by Muneeb Imran, DPO at the Saudi Credit Bureau, whose framing was that governance is what turns PDPL compliance from a set of documents into the way an organization actually operates.

    Imran's argument was that policies, tools, and controls have no longevity without three things behind them: clear accountability, real decision-making authority, and defined escalation paths. Without those, a privacy program built by consultants or assembled in a one-off push gradually erodes once the external support leaves. The session set out the operating-model choices and their trade-offs: centralized, consistent but less agile and suited to smaller or highly regulated entities; federated, where business units own execution under central oversight, more agile but dependent on a clear RACI; and hybrid, which combines centralized governance with distributed execution and often suits complex multi-entity groups in the Kingdom. The point was that the model should follow the organization's structure and risk, not be adopted by default.

    Where the DPO sits within that model drew careful attention, and Imran kept the focus on independence as a structural property rather than a stated one. Wherever the function is placed, it has to remain independent of the business activities it monitors and retain a direct line to senior leadership, and a documented RACI is what makes that real by naming who is responsible, accountable, consulted, and informed across the core processes, the records, impact assessments, data-subject requests, vendor reviews, and incident handling. The recurring failure he described is the privacy obligation with no named owner.

    A governance committee is what gives the model teeth, and Imran was specific that it needs genuine cross-functional and senior business representation, legal, IT, security, HR, business units, and enterprise risk, not a room of technical staff. Escalation thresholds have to be written down so that the right risk reaches the right level: a breach to the DPO, legal, and executive leadership; a high-residual-risk assessment to the risk committee or board; a regulator inquiry to legal and the C-suite. A committee without documented decision rights and escalation paths is a standing meeting, not an accountability mechanism.

    A useful exchange in the Q&A concerned the DPO's qualifications, where Imran recalled the requirements as threefold: genuine expertise across privacy, data management, and risk; an ethical dimension, meaning a clean record without misconduct; and freedom from conflicts of interest. The point underneath was that a credible governance model depends on a credible person in the role, not merely a title.

    The session also pressed that governance is not a one-time setup. It has to be revisited on defined triggers, restructuring, acquisitions, new jurisdictions, regulatory audits, major breaches, new AI deployments, because each of those changes the risk the model is meant to manage. The committee design and the full operating-model comparison are best taken from the recording and the takeaways.

    The throughline was that governance is the connective tissue. It is what lets privacy integrate with enterprise risk, security, internal audit, and the board, and it is the difference between a program that holds and one that quietly comes apart when attention moves elsewhere.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenter

    • Muneeb Imran

      Muneeb Imran

      Muneeb Imran is a Data Privacy and AI Governance expert and co-author of Data Privacy: A Practical Handbook for Governance and Operations.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.