On-demand library

    Saudi PDPL Masterclass Library

    A comprehensive on-demand library of Pyxos masterclasses covering the core domains of Saudi PDPL compliance — from DSARs, DPIAs, and RoPA through cross-border transfers, vendor management, AI governance, and SDAIA enforcement.

    Looking for the next live session? See upcoming masterclasses →

    Showing 18 of 18 masterclasses

    Past masterclasses

    #18 — Audit, Assurance and Regulatory Engagement under Saudi PDPL

    August 12, 2026
    Basmah Alsubaie
    Basmah Alsubaie

    PDPL audit readiness is the discipline this masterclass puts at the center of the DPO role: the ability to demonstrate compliance on request, with evidence that is complete, current, traceable to operations, and consistent with what the organization has already submitted. Basmah Alsubaie, CEO of Privacy Professionals and former CEO of National Data Governance at SDAIA, treated the session as a working hour rather than a recital of articles, moving from why audit work never ends, through what regulators actually scrutinize during inspections, to how to engage a regulator when the request arrives with a five-day window.

    Key Takeaways from the Masterclass

    • Accountability under the Saudi PDPL is not a passive obligation. It is the requirement to demonstrate compliance on request, which converts a policy exercise into an evidence exercise.
    • What separates a comfortable audit from a difficult one is rarely knowledge of the law. It is whether the organization can put evidence on the table quickly and whether that evidence holds up under questioning.
    • Audit work is a permanent fixture of the DPO office, not an occasional event. Scheduled internal audits, unannounced regulator inquiries, sharply increased board requests, post-incident reviews, and an emerging certification regime can each land in any given quarter, and inspections are accelerating across entities of every size, often with response windows as short as five business days.

    #17 — Personal Data Breach Notification & Incident Response under Saudi PDPL

    July 15, 2026
    Richard Chudzynsky
    Skanda Reddy
    Richard Chudzynsky & Skanda Reddy

    Personal data breach notification under the Saudi PDPL runs on a 72-hour clock that starts the moment an organization becomes aware of an incident, not when its privacy team is told. This masterclass, led by Richard Chudzynsky and Skanda Reddy of Konexo (Eversheds Sutherland), covered what the law counts as a personal data breach, when and how to notify the Saudi Data & AI Authority (SDAIA) and affected data subjects under Article 20 of the PDPL and Article 24 of the Implementing Regulations, and how to build an incident response posture that holds under regulatory scrutiny, from triage and risk assessment through documentation and post-incident improvement.

    Key Takeaways from the Masterclass

    • The Implementing Regulations define a personal data breach broadly: any incident leading to disclosure, destruction, or unauthorized access to personal data, whether intentional or accidental, automated or manual. Accidental exposure is a breach in law, not a lesser event.
    • A security incident and a personal data breach are not the same thing. If no personal data is affected, PDPL notification obligations are not triggered, so triage that distinguishes the two is the first capability an incident response posture needs.
    • Article 20 of the PDPL and Article 24 of the Implementing Regulations govern notification. SDAIA must be notified within 72 hours of the organization becoming aware of a breach that may potentially harm the personal data or the data subject; potential harm, not actual harm, is the trigger.

    #16 — Controller vs. Processor: Classification & Contract Governance under PDPL

    June 25, 2026
    Muneeb Imran
    Muneeb Imran

    Deciding whether a party is a controller or a processor under the Saudi Personal Data Protection Law (PDPL) is one of the most consequential, and most frequently rushed, judgments a privacy team makes. In this masterclass, Muneeb Imran argues that classification is a risk decision before it is a legal one: the label two organizations agree on in a contract does not change the operational reality of who decides why and how personal data is processed, and a regulator examines the reality, not the wording.

    Key Takeaways from the Masterclass

    • Classification drives every downstream duty. Whether a party is a controller, processor, joint controller or independent controller determines its legal obligations, regulatory exposure, contractual burden, data subject duties, breach responsibilities, cross-border obligations and audit rights.
    • Operational reality overrides the contractual label. Two privacy teams can reach full agreement on who is the controller and who is the processor and still be wrong; a regulator assesses actual decision-making and data flows, not the words in the agreement.
    • The defining test is choice. A controller decides why personal data is processed, which is the lawful basis, and how it is processed; a processor acts on documented instructions and cannot set the purpose on its own.

    #15 — Data Security & Technical Organizational Measures (TOMs) under Saudi PDPL

    June 11, 2026
    Aben Pagar
    Skanda Reddy
    Aben Pagar & Skanda Reddy

    Security controls do not satisfy Saudi PDPL obligations simply by existing on paper. They must be appropriate to the risk, implemented in practice, and capable of being evidenced, and organizations routinely discover during audits or after an incident that controls written into policy were never operationalized.

    Key Takeaways from the Masterclass

    • Technical and organizational measures do not satisfy PDPL obligations by existing on paper — they must be implemented in practice, proportionate to risk, and capable of being evidenced.
    • TOMs are not a one-off exercise; they evolve continuously as threats, systems, controls, and standards change, and require a named owner to keep them current.
    • Internal triggers for reassessing measures include incidents and suspected breaches, new vendor onboarding, and DPIA findings that require security controls as risk mitigants.

    #14 — Privacy Notice & Transparency Management under Saudi PDPL

    June 8, 2026
    Richard Chudzynsky
    Joe Corina
    Richard Chudzynsky & Joe Corina

    The privacy notice is an organization's outward-facing commitment about what it does with personal data, and increasingly a regulator's first read on program maturity under the Saudi PDPL. This masterclass examines the notice as an operational deliverable rather than a static legal text, one that drifts out of alignment as processing activities, technologies, and transfers change.

    Key Takeaways from the Masterclass

    • The privacy notice is the organization's public, outward-facing statement of what it does with personal data — a "shop front" and "paper shield," and often a regulator's first port of call for assessing program maturity.
    • The number one trigger for updating a notice is a change to processing activities or data types; other triggers include changes to DPO details, new data sharing or cross-border transfers, changes to storage/retention/destruction, and new technologies such as AI, agentic AI, and biometrics.
    • A notice update is downstream of a RoPA update — when the RoPA changes, the notice should be reviewed as a matter of course.

    #13 — From Privacy Reporting to Regulatory Evidence: Building Effective PDPL Metrics and Dashboards

    June 4, 2026
    Tahir Latif
    Tahir Latif

    Privacy metrics are not operational reporting; they are evidence of accountability, control effectiveness, and regulatory defensibility under the Saudi PDPL. This masterclass examines the central discipline of shifting from activity-based reporting toward risk-based measurement, and the recurring test behind it: if a regulator asked tomorrow to prove the program operates effectively, what would you show rather than say.

    Key Takeaways from the Masterclass

    • Metrics are evidence of accountability, control effectiveness, oversight, and defensibility — not activity counts. Metrics that prove none of these are window dressing.
    • The classic artifacts — notice, ROPA, DPIA template, training module, breach workflow, vendor questionnaire — are baselines, not proof the program works.
    • A notice doesn't prove transparency is accurate; a ROPA doesn't prove records are current; training completion doesn't prove behavior changed.

    #12 — Privacy Culture, Awareness & Training under Saudi PDPL

    May 21, 2026
    Muneeb Imran
    Muneeb Imran

    Privacy culture determines whether policies and controls hold in practice, because privacy is upheld by the people handling personal data, not by documents filed away. This masterclass examines how culture is built deliberately through role-based training and awareness treated as instruments rather than ends in themselves.

    Key Takeaways from the Masterclass

    • Privacy culture is an operational control, not an HR formality — policies and procedures do not themselves uphold privacy; the people working with personal data do.
    • The discourse around privacy needs to shift from protection alone toward rights, since individuals are defined by the data points that grant or remove their rights under PDPL.
    • Training and awareness are means to an end — creating a culture — not the end itself; conducting workshops is not the objective, changing behaviour is.

    #11 — Data Protection Officer (DPO): Role, Responsibilities & Accountability under Saudi PDPL

    May 14, 2026Delivered — No Recording Available
    Richard Chudzynsky
    Skanda Reddy
    Richard Chudzynsky & Skanda Reddy

    The Data Protection Officer is the central accountability mechanism under the Saudi PDPL and the operational link between the controller, SDAIA, and data subjects. This masterclass examines the DPO as an advisory and independent role rather than an administrative one, and why compliance depends not on appointing someone in name but on equipping them with the authority, mandate, resources, and reporting lines to operate effectively.

    Key Takeaways from the Masterclass

    • The DPO is an advisory and independent role, not an administrative one. The DPO guides the business on how to identify, manage, treat, accept, or transfer data protection risk — but the business owns the risk.
    • Mandatory appointment under Article 32 of the Implementing Regulations is triggered in three scenarios: a public entity providing services that involve large-scale processing of personal data; a controller whose core activity involves regular and systematic monitoring of data subjects; or a processor whose core activity involves processing sensitive personal data.
    • Sector-specific regulators — SAMA, CMA, CST, and the insurance regulator — may impose additional or stricter DPO obligations that sit alongside the baseline PDPL framework.

    #10 — Regulatory Signals: What We Are Hearing on Saudi PDPL

    May 13, 2026Delivered — No Recording Available for Roundtable Sessions
    Basmah Alsubaie
    Richard Chudzynsky
    Tahir Latif
    Basmah Alsubaie & Richard Chudzynsky & Tahir Latif

    Saudi PDPL enforcement has moved decisively from anticipation to action. This masterclass offers a ground-level account of how SDAIA and sectoral regulators are operating in practice, drawing on engagements with organizations under active investigation.

    Key Takeaways from the Masterclass

    • The "wishful thinking" phase is over. SDAIA and sectoral regulators are decisively in an active enforcement posture, and organizations treating PDPL as a future concern are materially behind the curve.
    • 48 formal enforcement decisions were issued in 2025 alone, spanning multiple sectors — not only critical infrastructure or technology — covering violations such as marketing without consent, inaccurate privacy notices, and missing lawful basis.
    • Saudi Arabia's accession to the Global Privacy Assembly has elevated SDAIA's regional and global profile and introduced enforcement standards it is now expected to meet.

    #9 — Privacy Governance & Operating Model Design under Saudi PDPL

    April 30, 2026
    Muneeb Imran
    Muneeb Imran

    Privacy governance is what transforms Saudi PDPL compliance from a set of documents into an operational reality. Without clear accountability, decision authority, and escalation pathways, even strong controls decay once the project that built them ends.

    Key Takeaways from the Masterclass

    • Policies, tools, and controls fail without accountability, decision-making authority, and escalation pathways—governance is what gives them legitimacy and longevity.
    • Without a robust operating model, privacy controls built by consultants or one-off projects gradually decay or collapse once external support leaves.
    • PDPL embeds accountability as a core principle, requiring controllers to implement organizational measures, appoint a DPO where applicable, maintain compliance records, and ensure effective oversight.

    #8 — Legal Basis & Legitimate Interest Assessments (LIA) under Saudi PDPL

    April 23, 2026
    Muneeb Imran
    Muneeb Imran

    Lawful basis is the first and most critical decision in any personal data processing under the Saudi PDPL: without a valid basis, processing is unlawful regardless of the security controls around it. This masterclass examines how to move beyond defaulting to consent toward a structured, defensible approach to selecting and documenting a lawful basis, and the role of the Legitimate Interest Assessment (LIA) in supporting compliant operations.

    Key Takeaways from the Masterclass

    • Lawful basis is the first and most critical decision in any data processing activity—without it, all processing is unlawful regardless of security controls.
    • Organizations must always answer: why is this data being collected and processed? before considering how it is protected.
    • Common business triggers for lawful basis decisions include new products, marketing campaigns, analytics, data monetization, and customer interactions.

    #7 — Data Inventory, Mapping & Records of Processing (RoPA) under Saudi PDPL

    April 16, 2026
    Richard Chudzynsky
    Aben Pagar
    Richard Chudzynsky & Aben Pagar

    The Record of Processing Activities (RoPA) is the operational backbone of a Saudi PDPL program: an organization cannot manage, protect, or govern personal data it has not first inventoried. This masterclass examines how to build and maintain a RoPA as a living system rather than a one-time compliance artifact, from identifying every processing activity across the business to validating and updating it as systems, vendors, and use cases change.

    Key Takeaways from the Masterclass

    • RoPA is the foundation of a privacy program—without it, effective compliance and governance are not possible.
    • Organizations must first understand what personal data they process before they can manage risk, respond to requests, or comply with PDPL.
    • Data mapping requires identifying every processing activity across all departments, not just high-level functions.

    #6 — AI & Automated Decision-Making Governance under Saudi PDPL

    April 9, 2026
    Aben Pagar
    Skanda Reddy
    Aben Pagar & Skanda Reddy

    Artificial intelligence and automated decision-making are becoming embedded across business operations in Saudi Arabia, and under the PDPL they are treated not as a separate regulatory category but as an extension of personal data processing, often with amplified risk. This masterclass examines how PDPL's technology-agnostic obligations apply to AI systems, how to distinguish decision-support analytics from automated decision-making that replaces human judgment, and when explicit consent and meaningful human oversight are required.

    Key Takeaways from the Masterclass

    • AI governance under PDPL is about managing personal data risk in AI systems, not regulating AI in isolation.
    • PDPL is technology-agnostic—the same obligations apply regardless of whether processing is manual, automated, or AI-driven.
    • AI introduces heightened risks around fairness, bias, transparency, and explainability, especially in automated decision-making.

    #5 — Data Retention, Minimization & Deletion Programs under Saudi PDPL

    April 2, 2026
    Anurag Sushant
    Anurag Sushant

    Data retention, minimization, and deletion are core operational requirements under the Saudi PDPL. Organizations are expected to keep personal data only as long as a defined purpose requires, then delete it in a structured and documented way.

    Key Takeaways from the Masterclass

    • Data deletion is not just a technical activity—it is a core compliance requirement under the PDPL.
    • Retention without a defined purpose creates privacy, security, operational, and regulatory risk.
    • Organizations often resist deletion because they hope data may be useful in the future, but "future value" is not itself a sufficient legal purpose.

    #4 — Cross-Border Personal Data Transfers under Saudi PDPL

    March 16, 2026
    Muneeb Imran
    Muneeb Imran

    Cross-border data transfers are one of the most legally complex areas of Saudi PDPL compliance, arising through SaaS platforms, cloud migrations, offshore support, and intra-group operations. The transfer rules exist to ensure personal data remains adequately protected once it leaves the Kingdom.

    Key Takeaways from the Masterclass

    • Cross-border transfers are not prohibited under the PDPL, but they are subject to strict procedural and legal requirements.
    • Article 29 must be read together with SDAIA's transfer regulations, rather than in isolation.
    • The purpose of the transfer rules is to ensure that personal data remains adequately protected even when it leaves the Kingdom.

    #3 — Data Subject Requests (DSARs) under Saudi PDPL

    March 9, 2026
    Joe Corina
    Richard Chudzynsky
    Joe Corina & Richard Chudzynsky

    Data subject requests are among the most operationally demanding aspects of Saudi PDPL compliance, requiring organizations to locate and disclose personal data across complex systems while meeting a strict statutory timeline. As public awareness of PDPL rights grows, these requests arrive more frequently and through informal channels.

    Key Takeaways from the Masterclass

    • Data subject rights are becoming an active compliance issue in Saudi Arabia. As awareness of PDPL increases and organizations publish clearer privacy notices, individuals are beginning to exercise their rights more frequently.
    • DSARs are both legal and operational events. Mishandling requests can trigger regulatory complaints, reputational damage, and increased scrutiny from SDAIA.
    • Organizations generally have 30 days to respond to a request, with a possible 30-day extension where additional effort is required. The response timeline begins when the organization receives the request—not when the privacy team becomes aware of it.

    #2 — Higher-Risk Personal Data Processing & DPIAs under Saudi PDPL

    March 5, 2026
    Tahir Latif
    Tahir Latif

    High-risk processing sits at the center of regulatory scrutiny under the Saudi PDPL, and the Data Protection Impact Assessment (DPIA) is the primary tool for identifying and mitigating risks to data subjects before that processing begins. Whether the trigger is sensitive data, new technology, large-scale analytics, or automated decision-making, Article 25 of the Implementing Regulations frames when an assessment is required.

    Key Takeaways from the Masterclass

    • DPIAs are the core accountability mechanism under PDPL. They are the primary tool for identifying and mitigating risks to data subjects before high-risk processing begins.
    • DPIAs must be treated as living documents. They are not a one-time gate before launch—if the data, technology, scope, or volume changes, the risk assessment must be updated.
    • High-risk processing is expanding rapidly in Saudi Arabia's digital economy. Under Vision 2030, rapid digital transformation creates "privacy debt" when privacy is not embedded at the design stage.

    #1 — Vendor & Processor Management under Saudi PDPL

    February 26, 2026
    Richard Chudzynsky
    Skanda Reddy
    Richard Chudzynsky & Skanda Reddy

    Third-party risk is one of the most persistent and underestimated exposure areas under the Saudi PDPL. From payroll and IT vendors to cloud platforms and professional advisors, the controller remains fully accountable even when processing is outsourced, and that accountability does not end at signature.

    Key Takeaways from the Masterclass

    • Vendor management is continuous, not one-and-done. Under KSA PDPL, controllers retain accountability across the full vendor lifecycle—from onboarding to offboarding.
    • Third parties are the "weak link" risk. Many breaches originate with processors/sub-processors, so strong due diligence and contract controls are designed to prevent incidents before they happen.
    • Controllers remain on the hook—even if the vendor is local. Accountability doesn't disappear just because the processor is inside KSA; controllers must maintain compliance across the value chain.