Past Masterclass May 14, 2026
Data Protection Officer (DPO) under Saudi PDPL: Role, Responsibilities and Accountability
The Data Protection Officer is the central accountability mechanism under the Saudi PDPL and the operational link between the controller, SDAIA, and data subjects. This masterclass examines the DPO as an advisory and independent role rather than an administrative one, and why compliance depends not on appointing someone in name but on equipping them with the authority, mandate, resources, and reporting lines to operate effectively. It addresses when appointment becomes mandatory under Article 32 of the Implementing Regulations, the qualifications the role requires, why reporting into IT creates a structural conflict, and why outsourcing the function never transfers the controller's liability.
Presenters

Richard Chudzynsky
Partner, KONEXO/Eversheds Sutherland

Skanda Reddy
Senior Associate, KONEXO/Eversheds Sutherland
Recording
No recording is available for this session.
Key takeaways
- The Data Protection Officer (DPO) is an advisory and independent role, not an administrative one. The DPO guides the business on how to identify, manage, treat, accept, or transfer data protection risk, but the business owns the risk.
- Mandatory appointment is triggered under Article 32 of the Implementing Regulations in three defined scenarios tied to large-scale processing, systematic monitoring, or sensitive data processing.
- Voluntary appointment is permitted and encouraged even where not mandated, and erring toward appointment is generally the more defensible position.
- Sector-specific regulators, including SAMA, CMA, and CST, may impose additional or stricter DPO obligations alongside the baseline Saudi Personal Data Protection Law (PDPL) framework.
- "Large-scale processing" is not numerically defined in the PDPL. Organizations must weigh factors such as the number of data subjects, data volume, sensitivity, and the presence of vulnerable populations, and document that judgment.
- Getting the DPO function wrong carries real consequences: administrative sanctions including suspension of processing, financial penalties up to SAR 5 million (potentially doubled for severe or repeated breaches), criminal liability in certain instances, and reputational damage.
- The DPO must meet defined qualification requirements spanning data-protection expertise, knowledge of risk and breach handling and of regulatory requirements, and demonstrable integrity. The role need not be a lawyer but requires a multidisciplinary skill set.
- The DPO may be an internal employee or an external contractor under a written services agreement, and group DPO arrangements are permitted. Outsourcing the function does not transfer liability: the controller remains accountable.
- The DPO must be appointed in writing, announced internally, and registered with the Saudi Data and AI Authority (SDAIA) via the National Register of Controllers, with contact details kept current.
- Independence is structural, not declared. Reporting into IT, the first line of defense, creates a built-in conflict because IT objectives align with business outcomes; reporting into legal, risk, or compliance, the second line, is more defensible.
- Dual-hatting the DPO with roles that determine the purpose and means of processing, such as Head of IT or CISO, creates conflicts SDAIA can be expected to identify. The most common audit finding is the inability to demonstrate independence.
- The DPO cannot be dismissed or penalized for performing the role and must be adequately resourced, proportionate to the volume, sensitivity, and risk of processing, with direct access to senior leadership.
- The DPO leads breach notification to SDAIA, which must occur within 72 hours of becoming aware, which requires enough technical literacy to assess what has actually happened and whether the threshold is met.
- The DPO's responsibilities are operational as well as advisory, and depend on translating policy into standards and operating procedures, because procedures are where interpretation is removed and practice is defined.
- Cross-functional integration is non-negotiable: the DPO must operate across every function that touches personal data, and standing up a program (which can take 12 to 18 months for a large organization) is a distinct phase from the ongoing work of operating it.
Frequently Asked Questions
Article 32 of the Implementing Regulations mandates appointment in three scenarios: a public entity whose services involve large-scale processing of personal data; a controller whose core activity involves regular and systematic monitoring of data subjects; and a processor whose core activity involves processing sensitive personal data. Voluntary appointment is also permitted and encouraged where not mandated.
The DPO must hold appropriate qualifications and experience in personal data protection, sufficient knowledge of risk management and breach handling, sufficient knowledge of regulatory requirements, and demonstrable honesty and integrity with no record of offences involving dishonesty or breach of trust. The role requires a multidisciplinary skill set rather than a legal qualification specifically.
Reporting into IT or the CISO creates a structural conflict of interest, because those functions' objectives align with the business outcomes the DPO must independently monitor. Reporting into the second line of defense, legal, risk, or compliance, is significantly more defensible and consistent with SDAIA's independence expectations.
Yes. The DPO may be an internal employee or an external contractor under a written services agreement, and group DPO arrangements are permitted. Outsourcing does not transfer liability: the controller remains accountable and must verify that an external DPO has the experience and capacity to discharge the role in practice.
The PDPL does not explicitly require Saudi nationality or residency. However, the DPO must be accessible to SDAIA and to data subjects, understand the local regulatory and cultural context, and be able to discharge the role in practice, so for KSA-centric operations a local presence strengthens the accountability posture.
There is no dedicated penalty for failing to appoint a DPO, but doing so where required is a PDPL violation that attracts the general penalty regime: administrative measures, including warnings, and financial penalties up to SAR 5 million, doubled for repeat violations. Criminal liability and reputational damage may also follow in severe cases.
