GovernanceX
Back

PDPL Is a Board Issue: Five Questions Directors Should Ask This Quarter

PDPL enforcement is maturing, and with it the personal exposure of organizations that treat data protection as an IT concern. Directors set the tone. These five questions surface the real posture in one meeting.

1. Do we know what personal data we hold, and why?

If there is no current record of processing activities, every other answer is speculative.

2. What is our lawful basis for each major processing activity?

Consent is not the only basis — but every activity needs one, documented.

3. Could we notify a breach inside the regulatory window?

Notification duties measure hours, not weeks. Ask when the runbook was last exercised.

4. How do we handle data leaving the Kingdom?

Cross-border transfers need assessed safeguards. Cloud regions, support desks and analytics vendors all count.

5. Who answers a data-subject request tomorrow morning?

A named owner, a tracked queue and tested templates — or a scramble. There is no third option.

GovernanceX builds PDPL programs that give boards defensible answers to all five — with evidence.