SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tabby is seeking a Data Protection Officer to report to the Head of Information Security and lead the organization's compliance with Saudi Arabia's Personal Data Protection Law (PDPL) and international data protection standards.
Key responsibilities include developing and implementing comprehensive data protection policies, procedures, and guidelines aligned with PDPL and international best practices. The role requires ensuring all data processing activities comply with PDPL requirements and integrating data protection principles across organizational processes. You will establish a robust data governance framework covering data retention, deletion, and archiving in accordance with regulatory requirements.
The Data Protection Officer will conduct regular reviews and audits of data activities to identify compliance gaps and implement corrective actions. This includes maintaining detailed documentation to demonstrate compliance, including risk assessments and data protection impact assessments (DPIAs). You will manage data subject access requests (DSARs) and complaints, ensuring timely and appropriate responses.
Additional responsibilities include developing and maintaining a comprehensive data breach response plan, leading breach investigations, and coordinating notifications with the Saudi Data and Artificial Intelligence Authority (SDAIA) as required. The role serves as the primary liaison with regulators, coordinating audits and inquiries while maintaining strong regulatory relationships.
You will drive employee training and awareness programs on data protection responsibilities, fostering a compliance-focused culture throughout the organization. The position requires advising senior management on data protection strategy and collaborating with departments to embed privacy and data protection practices into business operations. You will ensure compliance with data localization and minimization principles through regular reviews of processing activities and maintain clear, accessible privacy notices that reflect regulatory changes.