Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Regulatory Enforcement Roundtable II: From Understanding Enforcement to Demonstrating Compliance

    Masterclass #199 September 2026Basmah Alsubaie, Richard Chudzynsky and Tahir Latif

    A recap of the Pyxos masterclass with Basmah Alsubaie, Richard Chudzynsky and Tahir Latif.

    A clinic with thirty patients has been told to appoint a Data Protection Officer within a fixed deadline or face a legal case. That detail, offered by Basmah Alsubaie, former CEO of National Data Governance at SDAIA, said more about where Saudi PDPL enforcement stands than any published statistic could, and it set the tone for this second roundtable with Alsubaie, Richard Chudzynsky of Konexo (Eversheds Sutherland), and Tahir Latif of the IAPP. Enforcement is no longer selective by size or sector. It is general.

    The panel described a regulator that has moved from awareness campaigns to audits, evidence requests, corrective action notices, and in some cases the freezing of non-compliant features inside live applications. Chudzynsky recalled the 48 enforcement decisions published in January and a further round of penalties in June that arrived without a communique, but with the scope visibly widened to organizations with no DPO, unreported breaches, and unanswered data subject requests. Alsubaie added that cross-border transfers and data inventory have drawn particular scrutiny since May: where the data sits, and what safeguards protect it.

    What an audit now looks like was the most practical part of the discussion. Eighteen months ago the approach was a questionnaire and a gap assessment. Today, Latif said, his financial-sector clients face unannounced visits and periodic audits every three to six months, not one of which has produced a clean bill of health. Findings are documented, deadlines are set, and the regulator returns to check that the corrective actions were actually taken. The examiners have also become skilled: they ask where a SaaS platform is hosted, where the backups sit, and whether the organization knows its data is travelling to North America. Increasingly they ask how personal data is being used in AI models.

    Three structural shifts framed the outlook. SDAIA does not yet publish the names of sanctioned organizations, but the panel expects it to follow the pattern the Ministry of Commerce set with e-commerce enforcement and begin naming repeat violators once its practice matures. Private litigation for breaches is nascent, though Chudzynsky sees it growing along the path the UK took, where access requests now drive a large share of privacy litigation. And extraterritorial reach is being actively pursued against foreign entities processing the data of Saudi residents. The penalty ceiling remains the frame for all of it: under Article 36 of the PDPL, fines reach SAR 5 million, doubled for repeat violations, and Article 35 carries imprisonment and fines up to SAR 3 million for unlawful disclosure of sensitive data.

    The reputational lever may already be moving faster than the legal one. Alsubaie pointed to a recent case in which an individual promoted a service built with AI that plainly violated the PDPL; the replies on X ran into the hundreds, many tagging SDAIA directly. Latif described a CEO alerted near midnight to a social media campaign about the company's privacy program and calling an emergency meeting the next morning. That, the panel agreed, is what finally moves budgets. Sector regulators are maturing in parallel, with a marked uptick from the healthcare regulators, and a breach can now require notifying several authorities at once.

    On resourcing, the panel was candid that the tipping point has arrived but the budgets have not. Chudzynsky sees AI adoption forcing privacy, data governance, and AI governance into one conversation. Latif put the economics bluntly: retraining a model that ingested personal data it should not have costs more than any compliance program, and SAMA audits now score organizations lower if they have no privacy technology platform in place. The first thing SDAIA asks for is the RoPA and the data inventory; a complaint or incident changes the entire set of questions, and every valid complaint is investigated. The panel's closing advice to DPOs is best taken from the key takeaways.

    The panel reconvenes in January. The wishful-thinking phase ended a year ago; the evidence phase is now the whole job.

    About the presenters

    • Basmah Alsubaie

      Basmah Alsubaie

      Basmah Alsubaie is CEO of Privacy Professionals and a former regulator, previously CEO of National Data Governance at SDAIA.

    • Richard Chudzynsky

      Richard Chudzynsky

      Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

    • Tahir Latif

      Tahir Latif

      Tahir Latif is the IAPP Country Leader for the UAE, KSA and Qatar, and co-author of Data Privacy: A Practical Handbook for Governance and Operations.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.

    Read more articles