Skip to sign up

Job matched to your search

Data Privacy Consultant

Acuative Middle East · Jeddah

Jeddah · On-siteFull-TimePosted Sep 6, 2026

Free · Join 5,000+ job seekers using Qarera

How well do you match this role?

Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.

↑ tap the skills you have
Loading sign-in…
Free · no credit card · 30 seconds

Job description

About the role:

Acuative is hiring a Senior Data Privacy Consultant to be embedded within the Personal Data Protection (PDP) function of a leading research university in Saudi Arabia. You will act as a hands-on extension of the DPO's team, running the day-to-day privacy operations program and strengthening the organization's compliance posture under the Saudi Personal Data Protection Law (PDPL) and SDAIA regulations.

This is an operational role, not an advisory-only role. You will facilitate workshops with business units, populate and validate compliance artifacts, run assessments, manage incidents, and coach internal privacy champions so the organization becomes self-sufficient over time.

What you will do:

Records of Processing Activities (RoPAs)

  • Identify business units and processing activities without RoPAs and build them through stakeholder workshops.
  • Validate and update existing RoPAs with process owners, and secure sign-off from BU Heads and the DPO.

Data Protection Impact Assessments (DPIAs)

  • Develop or apply a process gating methodology to screen all processing activities and flag high-risk ones.
  • Conduct DPIAs on high-risk activities, identify privacy risks and controls, assign risk and control owners, and obtain sign-off.
  • Record all identified risks in the GRC platform and track them to closure.

Third-Party Privacy Risk Management

  • Identify data processors not yet subject to due diligence and build a High/Medium/Low risk tiering methodology.
  • Assess high-risk processors, prescribe corrective actions and timelines, and coordinate with Procurement and the relevant BUs.
  • Review vendor security controls in Data Processing Agreements (DPAs), perform transfer risk assessments, and embed required controls into DPAs and KSA Standard Contractual Clauses.
  • Develop template security controls by contract type with Information Security, and update guidance for researchers on securing human subject research data.

Data Breach Management

  • Support the DPO on privacy incidents end to end: containment, root cause analysis, mitigation, and coordination with Cyber Incident Response, Legal, Communications, and HR.
  • Support regulatory breach notifications and responses to SDAIA inquiries.

Privacy Hub and Spoke Model

  • Run workshops with BU Heads to appoint Privacy Champions across the organization.
  • Define the Privacy Champion role (responsibilities, expectations) and secure management sign-off.
  • Deliver 1-1 training to champions and manage a structured handover of privacy activities, with three months of SME support post-transition.

Data Subject Rights (DSR)

  • Handle DSR requests end to end: intake, register logging, validation, internal coordination, response, and closure.
  • Identify and fix process bottlenecks in the DSR workflow.

Data Minimization, Privacy Notices, and Retention

  • Conduct data minimization reviews on intake forms, data sharing proposals, transfer risk assessments, and DPIAs.
  • Review and update privacy notices based on RoPA and DPIA findings, changes in lawful basis, consent management, and legitimate interest procedures; draft new notices where needed.
  • Review retention schedules against PDPL requirements and support process owners and technical stewards in setting compliant retention periods and technical SOPs for deletion.

Privacy Training

  • Develop and deliver specialized on-site privacy training for units and build online training modules.

Ad-hoc Support

  • Any other privacy tasks requested by the PDP function and the DPO.

What we are looking for:

Required:

  • 6+ years in data privacy, data protection, or GRC roles, with at least 2 years of hands-on operational privacy work (not purely policy or advisory).
  • Deep working knowledge of the Saudi PDPL, its Implementing Regulations, the Data Transfer Regulations, and SDAIA guidance. Familiarity with GDPR is a strong plus.
  • Proven experience building and maintaining RoPAs, conducting DPIAs, and running third-party privacy risk assessments.
  • Experience managing personal data breaches, including regulatory notification.
  • Experience handling Data Subject Rights requests and maintaining a DSR register.
  • Strong workshop facilitation and stakeholder management skills across business, legal, IT, security, and procurement teams.
  • Ability to draft clear compliance documentation: DPAs, SCCs, privacy notices, retention schedules, role definitions, and training material.
  • Fluent English, written and spoken.
  • Willingness to work on-site full-time in Thuwal, KSA.

Preferred:

  • CIPP/E, CIPM, CIPT, or equivalent privacy certification.
  • Experience with GRC platforms (e.g., ServiceNow GRC, OneTrust, Archer) for risk logging and tracking.
  • Background in higher education, research institutions, or other environments handling human subject research data.
  • Arabic language proficiency.
  • Experience with information security frameworks (ISO 27001, NCA ECC) and reviewing technical security controls in vendor contracts.

Don’t just read the job — see if you’ll get it.

Get your match score, a resume tailored to this exact role, and jobs like it — free.

Check my fit for this job
Loading sign-in…
Apply →

Hiring for a role like this? Join the employer waitlist.