A recap of the Pyxos masterclass with Richard Chudzynsky and Joe Corina.
A privacy notice is the one part of a compliance program the whole world can read, which is exactly why it is so often the first thing a regulator checks. That was the framing Richard Chudzynsky of Konexo (Eversheds Sutherland) and Joe Corina, Head of Data Privacy Operations at Teya, brought to this masterclass on privacy notice and transparency management. The notice, they argued, is the organization's shop front, and increasingly a regulator's first read on how mature the program behind it really is.
The problem the session centred on is drift. A notice is accurate the day it is published and then slowly stops being true as processing activities change, new technologies are deployed, vendor relationships shift, and transfers move offshore. A notice that no longer matches the underlying record of processing is not a cosmetic issue; it is a breach of the transparency obligation. Chudzynsky and Corina made the dependency explicit: a notice update is downstream of a records update, so when the processing record changes, the notice is reviewed as a matter of course rather than on a separate schedule, and the sensible cadence is to batch learnings into periodic updates rather than editing the notice every other week.
On contents, the session grounded the requirements in Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations, the controller's identity, the lawful basis, the purposes and categories of data, the recipients, and the timing before collection and processing. The element they singled out as PDPL-distinctive, with no direct GDPR equivalent, is the statement of whether providing the data is mandatory or optional. They also flagged the obligation that catches people out: where data is collected from a source other than the individual, the controller has thirty days to inform them, including the categories and the source, subject to defined exceptions.
A genuinely modern point was how cheaply regulators can now detect a bad notice. With AI, a regulator, or an activist privacy group, can scan thousands of published notices in a day and surface the ones that are plainly wrong. The cost of an inaccurate notice has fallen for the people who enforce against it, which raises the stakes for getting it right.
The presenters were practical about the craft: draft in plain, layered language rather than legalese, using accordions and short front-end notices that link to detail; deliver just-in-time, at recruitment or at the point a new tool is introduced, rather than burying everything on one page; and log which version was served to whom so delivery can be evidenced. They were also clear that the notice rests on the rest of the program, the records, the impact assessments, the lawful-basis work, which makes it an inherently cross-functional deliverable rather than a legal team's solo document. The full content requirements and the notice lifecycle are best taken from the recording and the takeaways.
The closing thread, raised in the context of keeping notices consistent across a complex organization, was that this is precisely the kind of work where tools earn their place, holding consistency and reducing risk so teams can keep a notice honest without scaling headcount to do it.
π₯
About the presenters

Richard Chudzynsky
Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

Joe Corina
Joe Corina is Head of Data Privacy Operations at Teya.
