Past Masterclass June 4, 2026
From Privacy Reporting to Regulatory Evidence: PDPL Metrics and Dashboards
Privacy metrics are not operational reporting; they are evidence of accountability, control effectiveness, and regulatory defensibility under the Saudi PDPL. This masterclass examines the central discipline of shifting from activity-based reporting toward risk-based measurement, and the recurring test behind it: if a regulator asked tomorrow to prove the program operates effectively, what would you show rather than say. It addresses why the classic privacy artifacts are baselines rather than proof a program works, the difference between performance and risk indicators, why a green dashboard built on weak evidence is governance theater, and the 72-hour breach reporting timeline that makes internal escalation a control in its own right.
Presenters

Tahir Latif
IAPP Country Leader - UAE, KSA & Qatar | Co-Author, Data Privacy: Practical Handbook for Governance & Operations
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- Privacy metrics are evidence of accountability, control effectiveness, oversight, and defensibility, not activity counts. A metric that proves none of these is window dressing.
- The core discipline is the shift from activity reporting ("we completed 20 Data Protection Impact Assessments (DPIAs)") to risk-based measurement that answers whether risk actually fell and whether defensible evidence was created.
- The classic privacy artifacts, the notice, the Record of Processing Activities (RoPA), a DPIA template, a training module, are baselines, not proof the program works. Training completion does not prove behavior changed, and a current-looking RoPA does not prove records are accurate.
- The Saudi Personal Data Protection Law (PDPL) requires demonstrated accountability. The operative word is "demonstrate," and activity volume alone does not meet it.
- Move beyond performance indicators to early-warning indicators that show pressure building beneath a green surface; the key risk indicator (KRI) is the clearest example.
- A metric only governs when accountability is attached to it: a named owner and a threshold that forces a defined response, rather than a number reported without consequence.
- Privacy risk is not static. A RoPA accurate six months ago is likely inaccurate now, and controls degrade as systems, vendors, and AI use change.
- False confidence is more dangerous than no confidence. A green dashboard built on weak evidence is governance theater, what the session called the "traffic-light illusion."
- PDPL prescribes no fixed metric list. The organization selects metrics proportionate to its risk and maps each to a real obligation, applying a structured test of whether a metric is worth tracking before adopting it.
- Beware the denominator problem: "90 percent of critical vendors assessed" is meaningless if the true vendor population was never established.
- A single number says what happened; a trend says what is changing. Watch for repeat failures, aging items, and concentration, and for averages that hide outliers.
- Reporting must be layered. The board needs direction of travel, not 50 metrics; the regulator needs a defensibility pack.
- Reporting without action is theater. A serious metric drives root-cause analysis with an owner, a deadline, and evidence, not a reminder to "engage privacy earlier."
- Breaches must be reported to the Saudi Data and AI Authority (SDAIA) within 72 hours of awareness, so internal escalation is itself a control, not an operational detail.
- Maintain a standing PDPL evidence pack rather than assembling proof from scratch when a regulator asks. Metrics also give privacy the language to defend investment as part of the license to operate.
Frequently Asked Questions
Saudi PDPL prescribes no fixed list of metrics. The organization selects metrics proportionate to its processing activities and risk profile and maps each to a real obligation, covering core privacy operations such as DSAR handling, incidents, and vendor oversight. For each metric the test is the same: what obligation it supports, what evidence proves the control operates, what signals it weakening, and who acts when the threshold is breached.
A key performance indicator (KPI) shows whether performance is happening, for example whether data subject access requests (DSARs) are closing on time, while a key risk indicator (KRI) shows whether risk is increasing and acts as an early warning. A KPI can read green because requests are closing while a KRI reveals that complex requests are rising or one business unit is repeatedly delaying searches. Mature programs add control-focused and effectiveness-focused indicators on top of standard performance measures.
SDAIA expects demonstrated accountability, not asserted compliance; the operative word in the PDPL is "demonstrate." A defensible answer shows the process, how it operates, the metric and its threshold, the exceptions, the escalation, the remediation evidence, and the management oversight. Counting completed activities is not enough, so organizations should maintain a standing evidence pack that reconstructs what happened, what was decided, who approved it, and what was fixed.
A personal data breach must be reported to SDAIA within 72 hours of the organization becoming aware of it, alongside an assessment of harm, rights impact, and required mitigation. Internal escalation is therefore a control rather than an operational detail: if whether the privacy team learns of a breach depends on who happens to notice, the organization cannot meet the timeline reliably.
A green dashboard fails when the evidence beneath it is weak, what the session called the traffic-light illusion. It can show high training completion while staff repeat the same errors, or report that most critical vendors were assessed when the true vendor population was never established, the denominator problem. Red, amber, and green are only useful when the underlying data is authoritative, complete, current, and independently checked.
