
Data Protection Officer (DPO) - PayLink
At a Glance
- Category
- 🏦 Finance & Banking
- Level
- Mid-Level
- Type
- Full-time
Quick CV Check
- Get your free CV score for Salla in 30 seconds
- Get every weak line rewritten
- Download a CV written for the Gulf
Free check in 60 seconds. Fixes $5.88 one-time, only if you want them.
Job Summary
We are seeking an experienced Data Protection Officer (DPO) to lead and oversee PayLink's data privacy and protection framework, ensuring compliance with Saudi Arabia's Personal Data Protection Law (PDPL), its Implementing Regulations, and applicable regulatory requirements.
The ideal candidate will have hands-on experience implementing data protection programs, conducting Privacy Impact Assessments (PIAs/DPIAs), managing privacy risks, and advising stakeholders on data protection obligations, preferably within FinTech, banking, payments, or other regulated financial services environments.
Key Responsibilities
Data Protection & Regulatory Compliance
- Develop, implement, and maintain the organization's data protection and privacy compliance framework in accordance with Saudi PDPL, its Implementing Regulations, and applicable SAMA requirements.
- Monitor regulatory developments and ensure ongoing compliance with applicable data protection laws and standards.
- Serve as the primary point of contact for relevant regulatory authorities on data protection matters.
- Advise senior management on privacy risks, regulatory obligations, and compliance improvements.Privacy Governance & Risk Management
- Develop, review, and maintain privacy policies, procedures, data retention schedules, and internal guidelines.
- Conduct and oversee Privacy Impact Assessments (PIAs/DPIAs) for new products, systems, and business processes.
- Identify, assess, and mitigate privacy risks associated with personal data processing, third-party vendors, and cross-border data transfers.
- Embed Privacy by Design and Privacy by Default principles into business operations.Data Subject Rights & Incident Management
- Establish and manage processes for handling Data Subject Access Requests (DSARs) and other rights under Saudi PDPL.
- Establish and manage processes for handling Data Subject Access Requests (DSARs) and other data subject rights under Saudi PDPL, in coordination with Information Security, Legal, and IT teams to ensure timely and compliant responses.
- Monitor compliance with data protection requirements and maintain appropriate documentation and audit evidence.Training & Stakeholder Engagement
- Develop and deliver employee privacy awareness and data protection training programs.
- Collaborate with Legal, Compliance, Cybersecurity, IT, Product, and business teams to ensure effective privacy controls.
- Bachelor's degree in Law, Information Security, Cybersecurity, Compliance, Information Technology, or a related field.
- Professional privacy certifications such as CIPP/E, CIPM, CIPP/A are preferred.
- Demonstrated hands-on experience in Data Protection, Data Privacy, Privacy Compliance, or Regulatory Compliance.
- Strong knowledge of Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
- Understanding of SAMA regulatory requirements and their application to financial institutions, payment service providers, or FinTech companies.
- Proven experience developing and implementing privacy policies, data protection frameworks, and compliance procedures.
- Practical experience conducting Privacy Impact Assessments (PIAs/DPIAs), privacy risk assessments, and maintaining Records of Processing Activities (RoPA).
- Experience managing Data Subject Rights Requests (DSARs), personal data breaches, and privacy incident response.
- Ability to collaborate with cross-functional teams and communicate regulatory requirements to technical and non-technical stakeholders.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Professional proficiency in English; Arabic proficiency is highly preferred
Requirements
- •Bachelor's degree in Law, Information Security, Cybersecurity, Compliance, Information Technology, or a related field
- •Demonstrated hands-on experience in Data Protection, Data Privacy, Privacy Compliance, or Regulatory Compliance
- •Strong knowledge of Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations
- •Understanding of SAMA regulatory requirements for financial institutions or FinTech
Nice to Have
- •Professional privacy certifications such as CIPP/E, CIPM, CIPP/A
- •Experience within FinTech, banking, payments, or other regulated financial services
Responsibilities
- •Develop, implement, and maintain the organization's data protection and privacy compliance framework
- •Monitor regulatory developments and ensure ongoing compliance with data protection laws
- •Serve as the primary point of contact for relevant regulatory authorities
- •Advise senior management on privacy risks and regulatory obligations
- •Develop, review, and maintain privacy policies, procedures, and data retention schedules
- •Conduct and oversee Privacy Impact Assessments (PIAs/DPIAs)
- •Identify, assess, and mitigate privacy risks associated with personal data processing
- •Establish and manage processes for handling Data Subject Access Requests (DSARs)
Related Jobs4 similar jobs
Browse Similar
Guides for this role
- Get your free CV score for Salla in 30 seconds
- Get every weak line rewritten
- Download a CV written for the Gulf
Free check in 60 seconds. Fixes $5.88 one-time, only if you want them.
Salla is an e-commerce platform that enables businesses to create and manage online stores. It provides tools for selling products online in Saudi Arabia.