All Masterclasses
    Past Masterclass February 26, 2026

    Vendor and Processor Management under Saudi PDPL

    Third-party risk is one of the most persistent and underestimated exposure areas under the Saudi PDPL. From payroll and IT vendors to cloud platforms and professional advisors, the controller remains fully accountable even when processing is outsourced, and that accountability does not end at signature. This masterclass examines vendor and processor management as a continuous discipline spanning role classification, lawful basis, risk-based due diligence, the Data Processing Agreement required under Article 17 of the Implementing Regulations, and ongoing oversight through to offboarding. It addresses why misclassification and weak contractual controls are such common sources of exposure, and how defensible oversight is evidenced across the vendor lifecycle.

    Presenters

    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland. Former Head of Data Protection & Privacy, PwC Middle East
    Skanda Reddy
    Skanda Reddy
    Senior Associate, KONEXO/Eversheds Sutherland. Former Technology Consultant, PwC Middle East

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Vendor management is continuous, not one-and-done. The controller retains accountability across the full vendor lifecycle, from onboarding through monitoring to offboarding.
    • Correct role classification at the outset, controller, processor, or joint controller, determines each party's obligations and is the foundation on which the rest of the lifecycle rests.
    • Third parties are a primary breach vector, so due diligence and contractual controls exist to prevent incidents before they occur, not to apportion blame afterward.
    • Controller accountability does not depend on the vendor's location. It persists even where the processor operates inside the Kingdom, and outsourcing processing never transfers accountability for lawful processing across the value chain.
    • The Saudi Personal Data Protection Law (PDPL) may require a lawful basis both for processing personal data and for disclosing it to a third party, alongside purpose limitation.
    • Scope creep is a key risk: where a vendor reuses data for its own purposes such as product improvement or model training, it may become a controller for that secondary processing and must then meet controller obligations.
    • Vendor due diligence should be risk-based, applying stronger controls to high-risk vendors such as those involving AI, cloud, biometrics, sensitive data, or large-scale processing, and lighter review to low-risk ones.
    • Privacy due diligence belongs in procurement and assesses the vendor's governance, transparency, security posture, retention and destruction controls, and recognized assurance such as ISO/IEC 27701.
    • Controller-processor contracts are mandatory and prescriptive under the PDPL Implementing Regulations, specifically Article 17, which sets detailed Data Processing Agreement (DPA) requirements that serve as a baseline to be supplemented with sector or jurisdiction clauses.
    • Certain vendor behaviors are recognizable red flags, such as a vendor denying it processes personal data or resisting PDPL-specific contractual obligations.
    • Vendors are monitored on a cadence aligned to risk, with meaningful audit rights for high-risk vendors central to demonstrating accountability.
    • Offboarding matters as much as onboarding: ensure return or deletion of data at termination, obtain confirmations, and retain evidence, because protections can lapse once the contract ends.
    • Documentation is the safety net: a maintained evidence base linking vendor records to the Record of Processing Activities (RoPA), with the discipline shared across business owners, procurement, information security, and legal.
    • Cross-border vendor arrangements are uniquely demanding under the PDPL, and existing Standard Contractual Clauses or other-jurisdiction templates may not automatically satisfy Kingdom of Saudi Arabia requirements.
    • Caution is warranted in relying on general-purpose large language models for critical compliance execution; purpose-built, domain-trained systems are better suited to auditable, consistent outcomes.

    Frequently Asked Questions