The Middle East is quickly emerging as one of the top digital economies of the world. With the increased pace of innovation, use of artificial intelligence, and delivery of digital services, data is becoming one of the most important assets of the organization. The development has also made privacy, trust, and good governance of data the core of business strategies. Current leaders must ensure regulatory compliance while fostering trust among their customers.
Pulkit Vohra, Senior Data Privacy Manager at a leading UAE bank, has built his career by helping organizations address these challenges with clarity and confidence. Instead of treating privacy as a mere formality, he sees it as a powerful business strategy that promotes innovation and fosters trust with customers. His vast experience in dealing with privacy in globally operating companies and in various jurisdictions has enabled him to establish himself as an accomplished privacy professional who combines technology, business, and governance to enable innovation.
Privacy as a Business Strategy
Pulkit’s journey began with a defining realization during his MSc in Cyber Security and Management at the University of Warwick. He recognized that the most important conversations in technology had shifted beyond securing systems. They had become focused on ownership, accountability, and maintaining trust in an increasingly digital world. That perspective has shaped his leadership ever since.
Over the past decade, through leadership roles at Intel, BT Group, PwC, Deloitte, and now the banking sector, Pulkit has helped organizations transform privacy from a regulatory obligation into a strategic business capability. Working across global organizations and multiple jurisdictions, he has advised executive leadership on embedding privacy into business strategy, digital transformation, and enterprise governance. His experience has reinforced a simple belief: organizations that earn trust through responsible data practices are better positioned to innovate, grow, and build lasting customer relationships.
These experiences have shaped a leadership style that is evidence-based, business-focused, and people-centric. Pulkit acts as a bridge between technical, legal, and business teams. He can explain technical controls to auditors, translate product strategies for legal teams, and present strong business cases to board members with clarity and confidence.
Compliance as a Competitive Advantage
Many organizations treat privacy as a final step in the product development process. Pulkit takes a different approach. He shifts the conversation from asking, “Can we do this?” to asking, “How can we do this responsibly and more effectively?” In his current role, he integrates privacy compliance into the product design stage instead of waiting until just before launch. This approach allows innovation teams to move faster because potential risks are identified and addressed from the beginning.
With over a decade of experience leading enterprise privacy programs, Pulkit is known for translating complex regulatory requirements into practical business strategies. Rather than focusing solely on compliance, he works closely with business leaders, technology teams, and product owners to ensure privacy enables growth, strengthens customer trust, and supports responsible innovation. His approach is driven by measurable outcomes, improving regulatory readiness, strengthening governance, accelerating strategic initiatives, and embedding privacy into everyday decision-making. As organizations increasingly embrace AI and digital transformation, Pulkit advocates for integrating privacy, AI governance, and security into the foundation of enterprise architecture. For Pulkit, privacy is not a barrier to innovation; it is a competitive advantage that helps organizations innovate responsibly while earning lasting customer and stakeholder trust.
Strengthening Business Alignment
Large privacy programs rarely fail because of weak policies. They often fail because legal, technology, security, and business teams are not aligned. Throughout his career, Pulkit has relied on three principles to build strong collaboration across these functions.
The first principle is fluency over authority. He does not expect technology teams to accept control simply because it is required. Instead, he takes time to understand their architecture, development cycles, and operational challenges. He communicates in terms that are relevant to their work. He follows the same approach with legal and commercial teams. He considers that credibility comes from understanding the priorities and constraints of others and addressing them effectively.
The second principle is shared accountability instead of shared blame. Pulkit designs operating models where business functions own their privacy risks, while his team provides guidance and support. This approach replaces a culture of resistance with one of collaboration and shared responsibility.
The third principle is transparency. Pulkit believes people are more likely to support decisions when they understand the reason behind them. He explains the purpose before discussing the actions, whether he is resolving an audit finding or reviewing a product design. This collaborative leadership style has strengthened regulatory readiness, accelerated issue resolution, and improved engagement across business functions. In his current role, it has contributed to the successful closure of multiple internal and external audit findings while significantly improving overall compliance maturity.
Building Regulatory Agility
Privacy regulations across the Middle East and other regions continue to evolve rapidly. Pulkit believes regulatory agility is a capability that must be developed continuously rather than addressed through occasional updates. Drawing on experience across major privacy frameworks, including GDPR, the UAE PDPL, Saudi Arabia’s PDPL, India’s DPDP Act, Canada’s PIPEDA, and California’s CCPA, he focuses on embedding adaptable governance that evolves alongside changing regulatory expectations. Rather than treating compliance as an annual exercise, his approach emphasizes continuous assessment, proactive risk management, and timely implementation. Pulkit also believes that resilient privacy programs are built by investing in people. He encourages continuous learning, professional certifications, and cross-functional experience, enabling his team to develop expertise across areas such as privacy impact assessments, incident response, third-party risk management, and regulatory engagement. This creates versatile professionals who can confidently navigate emerging challenges while reducing dependence on individual specialists.
Equally important is simplifying the routine so teams can focus on what matters most. By standardizing processes and leveraging technology to automate repetitive activities, Pulkit enables his team to spend less time on administration and more time providing strategic guidance to the business. For him, agility is not about moving faster, it is about helping organizations respond to change with confidence, consistency, and purpose.
Driving Operational Excellence
An early challenge at Intel became a defining moment in shaping Pulkit’s leadership philosophy. He inherited a global Records of Processing Activities (RoPA) program that required nearly two months to complete each update. This pace could not keep up with the company’s fast product development cycle. By the time leadership reviewed the information, much of the data was already outdated, making it difficult to support informed governance decisions.
Instead of adding more resources, Pulkit redesigned the operating model. He established clear data ownership, integrated RoPA updates into existing product and engineering workflows, implemented OneTrust modules to streamline data collection, and created a global Privacy Champions network. This approach encouraged frontline teams to become active contributors rather than passive participants. As a result, the program’s refresh cycle was reduced from two months to just 15 days.
This experience became an important leadership lesson. Pulkit believes that many privacy challenges are not caused by compliance issues alone. They are often the result of ineffective operating models. Whenever he faces a complex problem, he first examines the underlying processes, ownership structures, and incentives before changing the controls.
Leading Responsible AI
Pulkit believes artificial intelligence will define the next decade of privacy leadership. He sees AI as bringing together many of the traditional privacy challenges, including lawful basis, purpose limitation, data minimization, transparency, and fairness, within a single decision-making system.
His approach begins with looking beyond the data itself to understand how AI systems make decisions, who may be affected by those decisions, and how those outcomes can be explained and governed. He believes effective AI governance must incorporate principles such as transparency, fairness, accountability, and meaningful human oversight from the earliest stages of design. Pulkit also draws a clear distinction between automating processes and automating judgment. While technology can streamline activities such as privacy assessments, consent management, and data governance, decisions with ethical, regulatory, or significant business impact should remain subject to human accountability. He believes technology should improve efficiency, while leaders remain accountable for the outcomes.
Ultimately, Pulkit believes customer trust is the foundation of successful AI adoption. If an organization cannot clearly explain how an AI system uses data or reaches important decisions, it is not yet ready for deployment. For him, responsible AI is not simply about meeting regulatory expectations; it is about building technology that people can trust with confidence.
Trust Through Transparency
For Pulkit, trust is built through consistent actions over time rather than through public announcements. He strengthens stakeholder confidence by focusing on regulators, customers, and business leaders.
When working with regulators, he emphasizes openness and transparency. He engages early, acknowledges gaps honestly, and presents practical plans to address them. This approach has supported his work with the Central Bank of the UAE, DIFC DP Commissioner., Saudi Arabia’s SDAIA, and the UK’s Information Commissioner’s Office.
With customers, Pulkit promotes clear communication, transparent privacy practices, and simple processes for exercising data privacy rights. He ensures that data subject request processes are easy to use and provide a positive customer experience rather than simply meeting legal requirements.
When engaging with the board, Pulkit presents a balanced view of performance. He shares achievements while also discussing challenges and areas that require attention. This approach helps build credibility, supports informed decision-making, and strengthens long-term trust across the organization.
Developing the Next Generation
For Pulkit, one of the most rewarding aspects of leadership is developing future privacy professionals. He believes the best way to build expertise is by giving people meaningful ownership, supported by guidance and trust. Rather than limiting team members to routine compliance activities, he encourages them to engage directly with business stakeholders, solve complex problems, and take responsibility for outcomes.
Continuous learning is central to his leadership philosophy. He promotes professional certifications, cross-functional exposure, and hands-on experience across areas such as privacy impact assessments, third-party risk management, incident response, and AI governance. His goal is to develop well-rounded professionals who can adapt confidently as technology and regulations continue to evolve.
Above all, Pulkit believes great teams are built on psychological safety. He encourages curiosity, open discussion, and learning from mistakes, recognizing that sound judgment develops through experience. For him, the true measure of leadership is not only delivering results today, but also preparing the next generation of professionals to lead with confidence tomorrow.
Future-Focused Leadership
Pulkit sees five major trends that will shape the role of privacy leaders over the next five years. He expects AI governance to move beyond guiding principles and become subject to stronger regulations, bringing privacy and AI accountability closer together. He also anticipates greater challenges around cross-border data flows as the UAE, Saudi Arabia, India, and the European Union strengthen their digital sovereignty.
The rise of quantum computing will require organizations to rethink their encryption strategies. At the same time, synthetic and inferred data will challenge traditional definitions of personal data. He also expects customer expectations for transparency to continue growing faster than regulatory requirements.
To prepare for these changes, Pulkit focuses on both personal and organizational readiness. He continues to expand his knowledge in areas such as AI ethics, post-quantum security, and comparative privacy regulations across the GCC, Europe, and Asia. Within his organization, he is building privacy operations that can adapt quickly to changing regulations. This includes developing modular controls, creating jurisdiction-specific playbooks, and establishing an operating model that can incorporate new regulatory requirements without major disruption.
Leading with Legacy
Pulkit measures his legacy not by the frameworks he has implemented or the certifications he has earned. Instead, he hopes to inspire a new generation of privacy leaders across the Middle East and beyond who view privacy as a meaningful profession rather than simply a compliance function. He considers his career successful if the professionals he has mentored go on to advise boards, influence national regulations, and mentor future leaders.
His advice to professionals entering the field is straightforward. First, develop strong technical expertise. Privacy is a discipline that requires a deep understanding of regulations, technologies, and data protection practices. Technical knowledge builds credibility and creates opportunities to contribute at the highest levels.
Second, develop strong business acumen. The most effective privacy leaders understand business strategy and commercial priorities as well as legal and regulatory requirements. They can connect privacy objectives with organizational goals and create value for both the business and its stakeholders.