Data Protection Officer

6 days ago


الرياض, Saudi Arabia Tamara Full time

Data Protection Officer

**About Tamara**

Tamara is the leading shopping and payments platform in Saudi Arabia and the GCC region, with a mission to empower people in their daily lives and revolutionize how they shop, pay, and bank. The company was founded by serial entrepreneur Abdulmajeed Alsukhan along with his partners Turki Bin Zarah and Abdulmohsen Al Babtain. Tamara operates out of its headquarters in Riyadh, Saudi Arabia, and has offices in the UAE, Egypt, Germany, and Vietnam. Our large, dedicated team of professionals continues to grow as we expand our reach and impact.

**Role Overview**: The Data Protection Officer (DPO) is responsible for developing, implementing, and managing the organization's data protection strategy to ensure full compliance with the Saudi Personal Data Protection Law (PDPL) and other applicable data protection regulations. The DPO serves as the primary point of contact for all data privacy and protection matters, ensuring that personal data is processed legally, securely, and ethically throughout the organization.

**Key Responsibilities**:

- **Develop and Implement Data Protection Policies**:

- Establish and maintain comprehensive data protection policies, procedures, and guidelines in alignment with the Saudi PDPL and international best practices.
- Ensure all data processing activities comply with PDPL and integrate data protection principles into all organizational processes.
- Create a data governance framework that includes policies for data retention, data deletion, and data archiving, aligned with PDPL.
- **Monitor Compliance with PDPL and Other Regulations**:

- Conduct regular reviews and audits of data processing activities to ensure compliance with PDPL.
- Identify, assess, and mitigate potential compliance gaps and collaborate with relevant stakeholders to implement corrective measures.
- Maintain documentation to demonstrate compliance with PDPL requirements, including data processing activities, risk assessments, and decisions related to data protection.
- **Manage Data Protection Impact Assessments (DPIAs)**:

- Ensure that DPIAs are carried out in accordance with PDPL and that any identified risks are mitigated effectively.
- **Handle Data Subject Requests and Complaints**:

- Address complaints related to data protection from internal and external parties, ensuring swift resolution in compliance with PDPL.
- **Manage Data Breach Response**:

- Establish and maintain a data breach response plan compliant with PDPL requirements.
- Ensure thorough documentation of all breaches and corrective actions taken, meeting PDPL's notification and reporting obligations.
- **Serve as Point of Contact with Regulatory Authorities**:

- Act as the primary liaison between the organization and the Saudi Data and Artificial Intelligence Authority (SDAIA) or other relevant regulatory bodies.
- Coordinate and prepare responses to inquiries, audits, and investigations from regulatory authorities.
- Maintain a positive and cooperative relationship with regulators, providing necessary documentation and information promptly.
- **Provide Training and Awareness**:

- Develop and deliver comprehensive training programs to educate employees about their responsibilities under PDPL and the organization's data protection policies.
- Conduct regular awareness sessions and workshops to foster a culture of data protection and privacy compliance within the organization.
- **Advise on Data Protection Strategy and Governance**:

- Provide strategic advice to senior management on data protection matters, including risk management, data security, and regulatory compliance.
- Work closely with IT, Legal, HR, and other departments to integrate data protection into all organizational functions.
- Develop and implement a roadmap for ongoing data protection improvements, aligned with business objectives and PDPL requirements.
- **Maintain Records of Processing Activities (RoPA)**:

- Ensure the creation and maintenance of comprehensive records of all data processing activities conducted by the organization, in line with PDPL.
- Ensure these records are accurate, up to date, and readily available for inspection by regulatory authorities.
- **Stay Up to Date with Legal Developments**:

- Monitor and interpret changes in PDPL and other data protection regulations to provide proactive advice to the organization.
- Update internal policies and procedures as necessary to reflect new regulatory requirements or best practices.
- **Develop and Oversee Consent Management Processes**:

- Ensure clear and transparent communication about the purposes for data collection and processing, and manage consent withdrawal efficiently.
- **Ensure Compliance with Data Localization Requirements**:

- Ensure that all personal data collected or processed is stored in compliance with PDPL's data localization requirements, ensuring data is stored within Saudi Arabia unless specific conditions allow otherwise.
- Work with IT



  • الرياض, Saudi Arabia Right Team Full time

    This role requires a proactive approach to managing data privacy, providing expert advice, and driving compliance initiatives across the organization. **Key Accountabilities**: - **Primary Point of Contact**: Serve as the main point of contact within the organization for staff, regulators, and public bodies regarding data protection issues. -...


  • الرياض, Saudi Arabia Career Maker Full time

    What we are looking for - At least **one IAPP qualification** (such as the **CIPP/E, CIPP/US, CIPM, AIGP**) OR **PECB CDPO** & one other data protection (EXCLUDING any information security or One Trust) qualification At least 2 years of **core data protection**experience (not information security) Fluent Arabic and English We are looking for an associate...


  • الرياض, Saudi Arabia SWATX Full time

    **Expected Activities**: - Assisting with incident and problem management activities. - Participating in Root Cause Analysis reviews as applicable. - Monitoring backup activity for the in-scope environment. - Performing routine backup policy changes. - Participating in the planning, approval, and implementation of approved change management requests. -...

  • Data Privacy Manager

    2 weeks ago


    الرياض, Saudi Arabia SWATX Full time

    The Data Privacy Manager at the Data Management Office (DMO) is responsible for ensuring the organization's data management practices comply with relevant data protection regulations and Saudi’s Personal Data Protection laws. The role involves developing, implementing, and monitoring privacy policies, conducting privacy impact assessments, and working...


  • الرياض, Saudi Arabia NTT DATA Full time

    **Make an impact with NTT DATA** Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive. **Your day at NTT DATA** The...


  • الرياض, Saudi Arabia NTT DATA Full time

    **Make an impact with NTT DATA** Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive. **Your day at NTT DATA** This...


  • الرياض, Saudi Arabia DB Schenker Full time

    At DB Schenker, you are part of a global logistics network that connects the world. A network that allows you to shape your career by encouraging you to contribute and truly make a difference. With more than 72,000 colleagues worldwide, we welcome diversity and thrive on individual backgrounds, perspectives and skills. Together as one team, we are Here to...


  • الرياض, Saudi Arabia Devoteam Middle East Full time

    **Company Description** Devoteam is a leading consulting firm focused on digital strategy, tech platforms and cybersecurity. By combining creativity, tech and data insights, we empower our customers to transform their business and unlock the future. With 25 years’ experience and more than 8,500 employees across Europe, the Middle East and Africa, Devoteam...


  • الرياض, Saudi Arabia Riyadh Air Full time

    About the Company: Riyadh Air (RX), headquartered in the Saudi Capital, is the new national airline that’s shaping the future of flying. It seeks to lead the aviation industry by transforming Saudi Arabia into a global aviation and trade hub - a digitally native airline that will connect the kingdom to more than 100 destinations. About the Role: Are you...

  • Data Manager

    6 days ago


    الرياض, Saudi Arabia Comspark International Full time

    Key Responsibilities - Develop and maintain data privacy policies procedures, and guidelines in alignment with national and international data protection regulations. - conduct regular audits and assessments to ensure compliance with data privacy laws and regulations. - identify and potential privacy risks and work with relevant team to mitigate...