← Sottava, jobs the hour they open
15 h agofound 2 h ago
Data Protection Officer (DPO) - PayLink
Posted by Salla on 8 October 2026. Still on their Workable board when we checked 11 min ago.
What the posting is about
Lead and oversee PayLink's data privacy and protection framework. Ensure compliance with Saudi Arabia's Personal Data Protection Law and applicable regulations. Advise stakeholders on data protection obligations and manage privacy risks.
Read out of the posting
Levelmid
Experience asked5+ years
EmploymentFull time
LocationMakkah, Saudi Arabia
RemoteNot stated
Visa sponsorshipNot stated
SalaryNot published, and most postings do not
Posted2026-10-08
Found viaworkable, direct from their system
We saw it 13 hours after it went up.
The posting, as the company wrote it
Employment: Full-time
Experience: Mid-Senior level
Education: Bachelor's Degree
Job Summary
We are seeking an experienced Data Protection Officer (DPO) to lead and oversee PayLink's data privacy and protection framework, ensuring compliance with Saudi Arabia's Personal Data Protection Law (PDPL), its Implementing Regulations, and applicable regulatory requirements.
The ideal candidate will have hands-on experience implementing data protection programs, conducting Privacy Impact Assessments (PIAs/DPIAs), managing privacy risks, and advising stakeholders on data protection obligations, preferably within FinTech, banking, payments, or other regulated financial services environments.
Key Responsibilities
Data Protection & Regulatory Compliance
Develop, implement, and maintain the organization's data protection and privacy compliance framework in accordance with Saudi PDPL, its Implementing Regulations, and applicable SAMA requirements.
Monitor regulatory developments and ensure ongoing compliance with applicable data protection laws and standards.
Serve as the primary point of contact for relevant regulatory authorities on data protection matters.
Advise senior management on privacy risks, regulatory obligations, and compliance improvements.
Privacy Governance & Risk Management
Develop, review, and maintain privacy policies, procedures, data retention schedules, and internal guidelines.
Conduct and oversee Privacy Impact Assessments (PIAs/DPIAs) for new products, systems, and business processes.
Identify, assess, and mitigate privacy risks associated with personal data processing, third-party vendors, and cross-border data transfers.
Embed Privacy by Design and Privacy by Default principles into business operations.
Data Subject Rights & Incident Management
Establish and manage processes for handling Data Subject Access Requests (DSARs) and other rights under Saudi PDPL.
Establish and manage processes for handling Data Subject Access Requests (DSARs) and other data subject rights under Saudi PDPL, in coordination with Information Security, Legal, and IT teams to ensure timely and compliant responses.
Monitor compliance with data protection requirements and maintain appropriate documentation and audit evidence.
Training & Stakeholder Engagement
Develop and deliver employee privacy awareness and data protection training programs.
Collaborate with Legal, Compliance, Cybersecurity, IT, Product, and business teams to ensure effective privacy controls.
Requirements
Bachelor's degree in Law, Information Security, Cybersecurity, Compliance, Information Technology , or a related field.
Professional privacy certifications such as CIPP/E, CIPM, CIPP/A are preferred.
Demonstrated hands-on experience in Data Protection, Data Privacy, Privacy Compliance, or Regulatory Compliance .
Strong knowledge of Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
Understanding of SAMA regulatory requirements and their application to financial institutions, payment service providers, or FinTech companies.
Proven experience developing and implementing privacy policies, data protection frameworks, and compliance procedures.
Practical experience conducting Privacy Impact Assessments (PIAs/DPIAs) , privacy risk assessments, and maintaining Records of Processing Activities (RoPA).
Experience managing Data Subject Rights Requests (DSARs) , personal data breaches, and privacy incident response.
Ability to collaborate with cross-functional teams and communicate regulatory requirements to technical and non-technical stakeholders.
Strong analytical, documentation, communication, and stakeholder management skills.
Professional proficiency in English; Arabic proficiency is highly preferred
Also open at Salla
Why this page exists
We read companies’ own hiring systems every hour, 1,287 of them, and show a job the hour it opens instead of when a job board gets around to indexing it. We saw it 13 hours after it went up.
The feed is free. No card, no trial to expire.
Apply at SallaA free account first, no card