All Masterclasses
    Past Masterclass May 14, 2026

    Data Protection Officer (DPO) under Saudi PDPL: Role, Responsibilities and Accountability

    The Data Protection Officer is the central accountability mechanism under the Saudi PDPL and the operational link between the controller, SDAIA, and data subjects. This masterclass examines the DPO as an advisory and independent role rather than an administrative one, and why compliance depends not on appointing someone in name but on equipping them with the authority, mandate, resources, and reporting lines to operate effectively. It addresses when appointment becomes mandatory under Article 32 of the Implementing Regulations, the qualifications the role requires, why reporting into IT creates a structural conflict, and why outsourcing the function never transfers the controller's liability.

    Presenters

    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland
    Skanda Reddy
    Skanda Reddy
    Senior Associate, KONEXO/Eversheds Sutherland

    Recording

    No recording is available for this session.

    Key takeaways

    • The Data Protection Officer (DPO) is an advisory and independent role, not an administrative one. The DPO guides the business on how to identify, manage, treat, accept, or transfer data protection risk, but the business owns the risk.
    • Mandatory appointment is triggered under Article 32 of the Implementing Regulations in three defined scenarios tied to large-scale processing, systematic monitoring, or sensitive data processing.
    • Voluntary appointment is permitted and encouraged even where not mandated, and erring toward appointment is generally the more defensible position.
    • Sector-specific regulators, including SAMA, CMA, and CST, may impose additional or stricter DPO obligations alongside the baseline Saudi Personal Data Protection Law (PDPL) framework.
    • "Large-scale processing" is not numerically defined in the PDPL. Organizations must weigh factors such as the number of data subjects, data volume, sensitivity, and the presence of vulnerable populations, and document that judgment.
    • Getting the DPO function wrong carries real consequences: administrative sanctions including suspension of processing, financial penalties up to SAR 5 million (potentially doubled for severe or repeated breaches), criminal liability in certain instances, and reputational damage.
    • The DPO must meet defined qualification requirements spanning data-protection expertise, knowledge of risk and breach handling and of regulatory requirements, and demonstrable integrity. The role need not be a lawyer but requires a multidisciplinary skill set.
    • The DPO may be an internal employee or an external contractor under a written services agreement, and group DPO arrangements are permitted. Outsourcing the function does not transfer liability: the controller remains accountable.
    • The DPO must be appointed in writing, announced internally, and registered with the Saudi Data and AI Authority (SDAIA) via the National Register of Controllers, with contact details kept current.
    • Independence is structural, not declared. Reporting into IT, the first line of defense, creates a built-in conflict because IT objectives align with business outcomes; reporting into legal, risk, or compliance, the second line, is more defensible.
    • Dual-hatting the DPO with roles that determine the purpose and means of processing, such as Head of IT or CISO, creates conflicts SDAIA can be expected to identify. The most common audit finding is the inability to demonstrate independence.
    • The DPO cannot be dismissed or penalized for performing the role and must be adequately resourced, proportionate to the volume, sensitivity, and risk of processing, with direct access to senior leadership.
    • The DPO leads breach notification to SDAIA, which must occur within 72 hours of becoming aware, which requires enough technical literacy to assess what has actually happened and whether the threshold is met.
    • The DPO's responsibilities are operational as well as advisory, and depend on translating policy into standards and operating procedures, because procedures are where interpretation is removed and practice is defined.
    • Cross-functional integration is non-negotiable: the DPO must operate across every function that touches personal data, and standing up a program (which can take 12 to 18 months for a large organization) is a distinct phase from the ongoing work of operating it.

    Frequently Asked Questions