About the role:
Acuative is hiring a Senior Data Privacy Consultant to be embedded within the Personal Data Protection (PDP) function of a leading research university in Saudi Arabia. You will act as a hands-on extension of the DPO's team, running the day-to-day privacy operations program and strengthening the organization's compliance posture under the Saudi Personal Data Protection Law (PDPL) and SDAIA regulations.
This is an operational role, not an advisory-only role. You will facilitate workshops with business units, populate and validate compliance artifacts, run assessments, manage incidents, and coach internal privacy champions so the organization becomes self-sufficient over time.
What you will do:
Records of Processing Activities (RoPAs)
- Identify business units and processing activities without RoPAs and build them through stakeholder workshops.
- Validate and update existing RoPAs with process owners, and secure sign-off from BU Heads and the DPO.
Data Protection Impact Assessments (DPIAs)
- Develop or apply a process gating methodology to screen all processing activities and flag high-risk ones.
- Conduct DPIAs on high-risk activities, identify privacy risks and controls, assign risk and control owners, and obtain sign-off.
- Record all identified risks in the GRC platform and track them to closure.
Third-Party Privacy Risk Management
- Identify data processors not yet subject to due diligence and build a High/Medium/Low risk tiering methodology.
- Assess high-risk processors, prescribe corrective actions and timelines, and coordinate with Procurement and the relevant BUs.
- Review vendor security controls in Data Processing Agreements (DPAs), perform transfer risk assessments, and embed required controls into DPAs and KSA Standard Contractual Clauses.
- Develop template security controls by contract type with Information Security, and update guidance for researchers on securing human subject research data.
Data Breach Management
- Support the DPO on privacy incidents end to end: containment, root cause analysis, mitigation, and coordination with Cyber Incident Response, Legal, Communications, and HR.
- Support regulatory breach notifications and responses to SDAIA inquiries.
Privacy Hub and Spoke Model
- Run workshops with BU Heads to appoint Privacy Champions across the organization.
- Define the Privacy Champion role (responsibilities, expectations) and secure management sign-off.
- Deliver 1-1 training to champions and manage a structured handover of privacy activities, with three months of SME support post-transition.
Data Subject Rights (DSR)
- Handle DSR requests end to end: intake, register logging, validation, internal coordination, response, and closure.
- Identify and fix process bottlenecks in the DSR workflow.
Data Minimization, Privacy Notices, and Retention
- Conduct data minimization reviews on intake forms, data sharing proposals, transfer risk assessments, and DPIAs.
- Review and update privacy notices based on RoPA and DPIA findings, changes in lawful basis, consent management, and legitimate interest procedures; draft new notices where needed.
- Review retention schedules against PDPL requirements and support process owners and technical stewards in setting compliant retention periods and technical SOPs for deletion.
Privacy Training
- Develop and deliver specialized on-site privacy training for units and build online training modules.
Ad-hoc Support
- Any other privacy tasks requested by the PDP function and the DPO.
What we are looking for:
Required:
- 6+ years in data privacy, data protection, or GRC roles, with at least 2 years of hands-on operational privacy work (not purely policy or advisory).
- Deep working knowledge of the Saudi PDPL, its Implementing Regulations, the Data Transfer Regulations, and SDAIA guidance. Familiarity with GDPR is a strong plus.
- Proven experience building and maintaining RoPAs, conducting DPIAs, and running third-party privacy risk assessments.
- Experience managing personal data breaches, including regulatory notification.
- Experience handling Data Subject Rights requests and maintaining a DSR register.
- Strong workshop facilitation and stakeholder management skills across business, legal, IT, security, and procurement teams.
- Ability to draft clear compliance documentation: DPAs, SCCs, privacy notices, retention schedules, role definitions, and training material.
- Fluent English, written and spoken.
- Willingness to work on-site full-time in Thuwal, KSA.
Preferred:
- CIPP/E, CIPM, CIPT, or equivalent privacy certification.
- Experience with GRC platforms (e.g., ServiceNow GRC, OneTrust, Archer) for risk logging and tracking.
- Background in higher education, research institutions, or other environments handling human subject research data.
- Arabic language proficiency.
- Experience with information security frameworks (ISO 27001, NCA ECC) and reviewing technical security controls in vendor contracts.