Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Vendor & Processor Management

    under Saudi PDPL

    Masterclass #126 February 2026Richard Chudzynsky and Skanda Reddy

    A recap of the Pyxos masterclass with Richard Chudzynsky and Skanda Reddy.

    Outsourcing a task does not outsource the accountability that comes with it. That was the premise Richard Chudzynsky and Skanda Reddy of Konexo, the consulting arm of Eversheds Sutherland, returned to throughout this opening masterclass of the year. Under the PDPL, when you hand personal data to a payroll provider, a cloud platform, or a professional advisor, you remain the accountable party, and that responsibility runs the length of the relationship rather than ending at signature.

    The most practical thread was classification. Before any contract language matters, you have to decide what each party actually is, controller, processor, or joint controller, and that turns on who decides the purpose and means of the processing, not on what the agreement happens to call them. Chudzynsky was candid that this is exactly where organizations slip, particularly with SaaS platforms, analytics tools, and anything involving AI, where the locus of decision-making is genuinely blurry. Get the classification wrong and every obligation that flows from it lands on the wrong party.

    Joint controllership drew some of the sharpest discussion. Where two parties genuinely share the purpose of processing, the relationship is joint, and the allocation of duties becomes a negotiation rather than a default. Chudzynsky's observation from practice was blunt: leverage tends to decide who carries what, the smaller party often absorbs more obligation, and that is precisely when you want good lawyers in the room so you do not take on duties you cannot actually discharge.

    The session was equally practical about how to vet a vendor in the first place. The advice was to run privacy due diligence as a defined step inside procurement, triaging vendors into high, medium, and low risk and applying controls proportionate to that tier rather than treating every supplier the same. Valid international certifications such as ISO 27701 can carry real weight in that assessment. And the presenters were frank that in the Kingdom this is often an education exercise, because some vendors have faced risk questionnaires before but never a privacy one. The red flags they flagged were telling: a vendor that denies it processes personal data at all, vague commitments on breach or data-subject support, and resistance to audit rights.

    A second recurring risk was scope creep. A vendor engaged as a processor that quietly starts using the data for its own purposes, model training being the obvious modern example, can become a controller for that secondary use, with all the obligations that role carries. The counsel was to watch what vendors actually do with the data, not only what the contract said they would.

    Underneath it all sat a simple discipline: vendor management is a lifecycle, not a procurement gate. Risk-based due diligence before onboarding, contractual controls that reflect the real relationship, monitoring proportionate to risk, and a clean offboarding that returns or deletes the data, all documented well enough to show a regulator. The session walked through that lifecycle and the contractual requirements in detail, which are best taken from the recording and the takeaways.

    The closing point is the one to keep. A local vendor is not a safe vendor by default. PDPL accountability does not depend on where the processor sits; inside the Kingdom or outside it, the controller answers for the personal data.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenters

    • Richard Chudzynsky

      Richard Chudzynsky

      Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

    • Skanda Reddy

      Skanda Reddy

      Skanda Reddy is a Senior Associate at Konexo (Eversheds Sutherland), focused on PDPL and data protection implementation across Saudi Arabia and the wider region.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.