Director - Data Privacy
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Education
- Bachelor’s degree in Information Technology, Law, Business or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
Lead Tawuniya's Data Privacy division, steering the organization’s data protection strategy and ensuring compliance with all relevant privacy laws and corporate policies. Manage the continuous advancement of privacy frameworks and governance, working collaboratively across departments.
Key Responsibilities
- Shape and enhance the data protection strategy alongside leadership teams including Legal.
- Oversee the creation, periodic review, and improvement of privacy policies in line with regulations and industry standards.
- Monitor and report quarterly on privacy compliance, risks, and necessary focus areas to senior management.
- Manage communications with regulatory bodies and individuals regarding personal data, overseeing data subject rights.
- Supervise Data Protection Impact Assessments and ensure effective risk mitigation across functions.
- Identify and manage privacy risks by implementing appropriate controls and monitoring mechanisms.
- Coordinate with departments such as Procurement to guarantee third-party compliance with privacy obligations.
- Lead privacy education and awareness initiatives to empower employees on data protection responsibilities.
- Collaborate with Legal and HR to enforce privacy compliance and apply necessary sanctions for breaches.
- Develop and maintain a privacy audit program in partnership with Internal Audit to ensure regulatory adherence.
- Engage cross-functionally to integrate data protection measures across the organization.
- Lead and develop the Data Privacy team, ensuring clear responsibilities and performance excellence.
Qualifications and Experience
- Bachelor’s degree in Information Technology, Law, Business, or related disciplines.
- Over 10 years of overall professional experience, including minimum 5 years in data privacy or related roles.
- Preferred background in risk management or data security.
- Certifications such as CIPM, CIPP/E, or CIPT are advantageous.
- Comprehensive understanding of data protection laws including PDPL and GDPR.
- Strong knowledge of organizational policies, information security principles, and data classification.
- Proven capability in establishing and managing data protection programs.
Main Stakeholder Interactions
- Internal: Senior Management, Legal, Human Resources, Procurement, Internal Audit, and various business units.
- External: Regulatory authorities, data subjects, third parties, and data processors.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Teamwork & Collaboration
Attention to Detail
Leadership
Strategic Thinking
Accountability