Saudi e-commerce privacy study reveals limited compliance
A recent study by researchers at King Abdulaziz University found that only 31% of Saudi e-commerce sites met four core requirements examined under the country’s Personal Data Protection Law, highlighting widespread gaps in Saudi e-commerce privacy disclosures. The analysis reviewed privacy policies on 100 online retail sites to assess how clearly businesses communicate user rights and data handling practices.
Conducted by Iman Al-Ashouli and Abeer Al-Hadhli, the study evaluated publicly posted privacy policies against four specific elements: disclosure of data retention periods, the user’s right to request deletion, the right to obtain a copy of personal data, and the availability of a complaints mechanism. The report measured the presence of these requirements and the procedural detail provided to users.
Key findings on privacy policies and compliance
The researchers found that 9% of the sampled sites did not publish any privacy policy at all, while 31% had policies that omitted all four assessed elements. Another 29% included some but not all requirements, and 31% of sites disclosed all four elements in their policies. Therefore, a minority of sites fully met the clarity criteria used in the study.
Breakdowns for individual elements showed specific weaknesses: 45% of sites disclosed a data retention period, 51% stated the user’s right to request deletion, 34% explicitly acknowledged the right to obtain a copy of personal data, and only 33% provided a complaints channel. These figures indicate uneven adoption of key privacy policy components across the market.
Procedural gaps and platform-hosted store issues
Even where rights were mentioned, the study recorded major procedural gaps. Among policies that recognized user rights, 82% did not set a response timeframe for deletion requests, 86% omitted a timeline for fulfilling access (copy) requests, and 89% failed to specify how long complaint handling would take. Additionally, 67% of policies did not name an officer or department responsible for receiving complaints.
Search ranking and hosting arrangements also correlated with compliance. Sites that appeared higher in search results showed the largest share of noncompliance at 60%, compared with 22% for mid-ranked sites and 38% for lower-ranked ones. Notably, 70% of stores hosted on local e-commerce platforms were classified as noncompliant, and none of those platform-hosted stores achieved full compliance on the four measured elements.
The researchers suggest that the elevated noncompliance among platform-hosted stores may reflect limited awareness among merchants or a misconception that hosting platforms assume full responsibility for customer data protection. According to the study, the store owner typically remains the data controller, while the hosting platform generally acts as a data processor on the owner’s behalf.
AI privacy analysis: strengths and limitations
The study also explored how language models perform when analyzing privacy policies. Automatic analysis agreed with human reviewers at rates of 96% for data retention disclosures, 92% for deletion rights, 81% for complaints mechanisms, and 58% for the right to obtain a copy of data. These results indicate strong alignment for some items but notable divergence on access/copy rights.
Researchers noted that artificial intelligence tools can detect elements that might be missed by human reviewers in long or poorly structured policies. However, the models sometimes conflated related rights—for example, access versus receiving a copy—or misinterpreted header and footer text as policy content. The models could also be influenced by foreign-law language that does not apply under Saudi rules, so human oversight remains important.
Implications for personal data protection and recommendations
The findings have implications for personal data protection and for how regulators, platforms, and merchants prioritize compliance. The study calls for continuous monitoring of privacy policies, provision of simplified templates for small and medium-sized enterprises, and awareness campaigns to inform store owners and consumers about rights under the law.
Researchers urged local e-commerce platforms to support merchants by offering compliant privacy policy templates and clearer guidance. They also recommended that authorities encourage or require platforms to assist hosted stores in meeting disclosure standards, particularly by specifying response times and naming responsible officers to improve procedural transparency.
Importantly, the study measures the clarity of published policies rather than verifying actual data-handling practices. The authors cautioned that policy disclosures do not necessarily reflect on-the-ground processing, deletion, or access behaviors, so the classifications in the report are not legal determinations of overall compliance.
What to watch next
Stakeholders should watch for regulatory follow-up, platform policy updates, and broader adoption of standardized privacy templates in the months ahead. Meanwhile, merchants are advised to review and update their privacy policies to include clear retention periods, deletion and access procedures, complaint channels, and named points of contact.
For consumers, the immediate takeaway is to review a retailer’s published privacy policy before sharing personal information and to use available complaint mechanisms when rights are unclear. For policymakers and researchers, further studies that combine policy analysis with audits of actual practices would help paint a fuller picture of data protection performance in the sector.

