Skip to content
Research

We Scanned 27 Saudi E-Commerce Sites. Here's What We Found.

Taha Farhane· Founder, Arqam360 — building MENA consent + data infrastructure
March 27, 202616 min readCornerstone

In May 2026 we scanned the 27 most-trafficked Saudi e-commerce stores for compliance with the Personal Data Protection Law (PDPL) — the data behind the public Saudi E-Commerce Privacy Compliance Index. The results reveal a privacy posture that has not kept pace with the law: 81% of stores show indicators of PDPL non-compliance today, with a median compliance score of 49 out of 100. This is the methodology + analysis companion to the live Index page; both share the same dataset.

Key Findings

  • 81% of stores (22 of 27) are at risk of PDPL non-compliance — the headline number behind the Index
  • 67% (18 of 27) fire marketing pixels and tracking cookies BEFORE any consent is collected
  • 56% (15 of 27) lack server-side event forwarding, which is the technical foundation for Google Consent Mode v2 conversion recovery
  • 52% (14 of 27) write excessive non-essential cookies on first page load
  • 44% (12 of 27) have no consent banner at all — defaulting to implicit consent that is not lawful under PDPL
  • Median compliance score: 49 / 100. The worst-scoring store: 14 / 100. The best: 100 / 100 — a clean implementation does exist

What This Means

The Personal Data Protection Law (PDPL) entered full enforcement on 14 September 2024, ending the one-year grace period that began with the law's effective date in September 2023. Administrative fines under PDPL Article 35 reach 5 million Saudi riyals per violation, doubled for repeat offenses; disclosure of sensitive personal data with intent to harm carries criminal penalties of up to two years imprisonment and 3 million SAR. The 81% non-compliance rate measured here is not a forecast — it is an active liability for the stores in that bucket.

Beyond regulatory exposure, the 67% that fire trackers pre-consent are also losing Google Consent Mode v2 modeling benefits. Without GCM v2 wired correctly, Google Ads no longer engages remediated conversion modeling, which the platform itself estimates recovers 50-75% of consent-denied conversions. The combined effect: PDPL exposure AND attribution loss. The fix for both is the same — wire denied-default Consent Mode v2 correctly, block tracking until consent, and emit signals via the API Google expects.

How to Fix It

The good news: achieving PDPL compliance is straightforward with the right tools. Here's how to go from zero to compliant in under 5 minutes:

  • Run Arqam360's free compliance scanner to see your current gaps
  • Install the Arqam360 consent widget — one script tag, 2 minutes
  • Google Consent Mode v2 signals fire automatically on install
  • Customize your banner with Arabic RTL and PDPL-compliant text
  • Monitor consent rates and compliance status from the dashboard

Methodology

We selected the 27 stores from public traffic data (SimilarWeb top-100 Saudi e-commerce, filtered for active operation and stores serving Saudi-resident visitors). Each store was scanned with the Arqam360 compliance scanner using a real headless Chrome browser in May 2026 (window: 21-23 May). The scanner logged cookies set, third-party tracking domains contacted, presence of a consent banner, presence of Google Consent Mode v2 signals, presence of a linked privacy policy, and matched cookie names against a 113-pattern library that includes 32 MENA-specific patterns (Tabby, Tamara, Mada gateway, STC Pay, Salla and Zid platform cookies, Saudi telco identifiers). Each store received a 0-100 compliance score based on the PDPL framework and GDPR best-practice signals. The methodology is browser-side only — we did not assess backend processing agreements, DSAR workflows, or NDGP registration status. The dataset is published at arqam360.com/ksa-compliance-index.

Run the free Arqam360 scanner on your own site — it takes 60 seconds and shows exactly which trackers are firing before consent.

Why This Scan Matters Right Now

The Saudi Authority for Data and Artificial Intelligence (SDAIA) moved from awareness-building to active enforcement on 14 September 2024, the end of PDPL's one-year grace period. The first hard evidence of what active enforcement looks like landed on 25 February 2026: SDAIA's specialised committees announced 48 enforcement decisions issued against violators during 2025. The decisions cover three violation categories — processing without lawful basis, inadequate security controls, and marketing communications sent without prior consent — and SDAIA named retail, telecommunications, and financial services as the sectors most affected. For Saudi e-commerce specifically (the retail sector being explicitly cited), the message is unambiguous: enforcement is not theoretical, and the most common violation category (marketing without consent) is exactly what the 67% of stores firing trackers pre-consent are doing on every page load.

The economic backdrop is equally pointed. Saudi Arabia's Vision 2030 commits to a digital economy that meets international standards; the EU has not yet granted PDPL the adequacy determination that would unlock frictionless cross-border data flows. Saudi merchants that cannot demonstrate a credible compliance posture are at risk of losing access to international ad platforms (Google Ads conversion modeling already requires GCM v2), payment processors with EU clients (Visa and Mastercard ask for evidence of GDPR-equivalent practice during onboarding), and procurement opportunities with large enterprise buyers (PDPL compliance increasingly appears as a checkbox on RFP templates). The 81% non-compliance rate is not just a regulatory concern — it is a market-access concern.

Per-Vertical Breakdown

Compliance is not uniform across verticals. The medians below come from the same 27-store dataset, broken down by industry category. The pattern is structural rather than coincidental — verticals with larger enterprise organizations and in-house legal teams perform meaningfully better than those dominated by mid-market merchants relying on platform defaults.

Grocery and FMCG (median 85)

The strongest performers in the dataset, by a wide margin. The grocery and fast-moving consumer goods category includes large enterprises with in-house compliance teams and the budget to implement consent management properly. The median 85 score reflects mature consent banners, working GCM v2 implementations, and published privacy policies that name PDPL specifically. The pattern is informative: when an organization treats privacy as a discipline rather than a checkbox, compliance follows. The gap between these merchants and the lower verticals is the gap between in-house legal capability and reliance on platform defaults.

Beauty (median 62)

Strong middle of the pack. Beauty retailers tend to use Shopify or custom platforms with established CMP integrations, and many serve EU traffic that has driven GDPR-grade implementations long before PDPL was enforced. The category includes some of the larger Saudi beauty groups whose privacy posture reflects multi-jurisdictional thinking. Below the median, however, smaller beauty boutiques score in the 40s — the same pattern as perfume and pharmacy below.

Fashion (median 61)

Six stores in the dataset, the largest single vertical. Median 61 puts fashion above the overall median (49) but well below grocery (85). Fashion is a mixed bag: a handful of multinational brands operating in Saudi (whose Saudi storefronts inherit global GDPR posture) score 70-90; the regional fashion brands score 40-60, with platform defaults doing most of the consent work. The vertical's variance is a useful diagnostic — when adjacent stores on the same platform score 40 points apart, the differentiator is operational discipline, not technical capability.

Perfume (median 43)

The weakest vertical with adequate sample size. Five stores, median 43, which is below the overall median of 49. Most perfume stores in the dataset run on Shopify or Salla with default settings and have not added CMP apps; the result is implicit consent on first page load with full tracker activation. The vertical's economics — high-margin SKUs, strong cross-border traffic to GCC buyers, heavy Google Ads spend — make this gap particularly costly. A perfume store losing 30-50% of GCM v2 modeled conversions is leaving meaningful revenue on the table even before the regulatory exposure is factored in.

Marketplace (median 59)

Three multi-vendor marketplaces in the dataset, median 59. Marketplaces are a structurally hard problem for consent management because the consent state must propagate not just to the marketplace's own tracking but to each vendor's tracking pixels, which often arrive after the visitor has already crossed several pages. The stores in this bucket get the basics right (banner present, default denied) but struggle with the propagation problem — partial consent on visitor session #1 leaking into tracker activation on session #3 is a common failure pattern. Marketplaces need a more sophisticated CMP implementation than single-vendor stores, and most have not made that investment yet.

See where your store ranks

Free real-browser scan of any e-commerce site. 30 seconds, no signup.

Scan my store free

The Three Biggest Failures

Most non-compliance traces back to one of three structural failures. The patterns below ranked by frequency across the dataset, with the specific PDPL provision each violates.

Failure 1 — Trackers firing before consent (67% of stores). The most common single failure. Google Analytics, Meta Pixel, TikTok pixel, and similar tags load on first page-view and write cookies before the visitor has interacted with any consent surface. Under PDPL Article 6 this is unlawful processing — the lawful basis (consent) has not been established yet. The fix is mechanical: load tracker scripts only AFTER the consent default fires, AND only AFTER the visitor grants permission. A correctly-wired Consent Mode v2 implementation handles both gates automatically; doing this manually is harder than it looks because async script loading and visitor navigation can race the consent state.

Failure 2 — Missing Google Consent Mode v2 (78% of stores). Above the headline 81% PDPL risk number is a 78% rate of stores running Google products (GA4, Google Ads, gtag.js) without the four required consent parameters (analytics_storage, ad_storage, ad_user_data, ad_personalization). Without GCM v2 wired, Google Ads loses access to remediated conversion modeling — a measurable revenue hit on top of the regulatory exposure. The fix requires the CMP to emit gtag('consent', ...) calls correctly, not just write cookies; many older 'cookie banner' tools do the latter but not the former.

Failure 3 — No consent banner at all (44% of stores). The most surprising number in the dataset. Almost half of the top 27 Saudi e-commerce stores have NO consent surface — visitors land, trackers fire, no opportunity for consent is ever presented. Under PDPL this is the highest-severity violation because it indicates not just an implementation gap but a policy gap: the merchant has not even established the consent mechanism, let alone wired it correctly. The fix is straightforward — install a CMP, wire it to the platform — but it requires deciding that compliance is a priority. The 44% that have not done this are running on inertia rather than active risk acceptance.

What Good Looks Like

Five stores in the dataset scored 80-100 — concrete proof that PDPL compliance is operationally achievable for any Saudi e-commerce store today, not a theoretical target. The common pattern across the top scorers: a consent banner that fires on first page-load with denied-default Consent Mode v2 signals, a privacy policy that explicitly names PDPL and SDAIA (not just a generic GDPR translation), a working DSAR contact channel, and trackers that genuinely do not fire until consent. None of these stores invented anything new; they implemented well-documented patterns end-to-end.

The pattern that does NOT appear in the high scorers is heavy customization. The top stores use mainstream CMPs (Cookiebot, OneTrust, Arqam360, Iubenda), standard implementation patterns, and the platform's native consent surface (Shopify Customer Privacy API, Salla's script-tag pattern, WordPress plugin). The differentiator is not engineering depth — it is the decision to implement the standard pattern correctly rather than half-finish a custom implementation. Compliance favors the disciplined over the clever.

Industry Implications

The 81% non-compliance rate has implications beyond the individual stores measured. At the industry level, the Saudi e-commerce vertical as a whole is exposed to a regulatory dynamic that is not yet visible in earnings disclosures but is becoming visible in due-diligence checks. Investors evaluating Saudi e-commerce M&A increasingly request PDPL compliance evidence; insurers offering cyber-liability coverage screen for it; payment providers offering merchant accounts to EU-traffic stores screen for it. The structural risk premium on Saudi e-commerce will increase until the industry-wide compliance rate moves materially.

There is also a market-development angle. PDPL compliance is one of several signals that distinguishes Saudi-resident merchants from regional competitors operating in less-regulated MENA jurisdictions. The merchants that get ahead of compliance now — not after a public SDAIA enforcement action triggers panic — are positioning themselves as the Saudi merchants that international platforms (Google, Meta, TikTok), international processors (Stripe, Adyen), and international buyers (multinational retailers sourcing from Saudi suppliers) prefer to work with. The asymmetry of being early is real even if the regulator never personally calls.

How to Avoid Being Counted in the 81%

If you are reading this and you run a Saudi e-commerce store, here is the action checklist to move from the 81% non-compliant bucket to the 19% compliant bucket. Each item below maps to a specific finding in the scan dataset and has been implementation-tested on at least one of the top-scoring stores.

  • Install a CMP that wires Google Consent Mode v2 by default — the cheapest path is a free CMP that does this, not a custom GTM container
  • Verify the denied-default fires BEFORE any Google tag loads — use Tag Assistant Companion in incognito to confirm
  • Block all third-party tracker scripts from loading until consent — script-quarantine mode in modern CMPs handles this automatically
  • Publish a PDPL-specific privacy policy that names SDAIA and the PDPL article numbers, not a translated GDPR template
  • Set up a DSAR request channel that meets the 30-day response deadline (PDPL Implementing Regulations Article 18)
  • Register on the National Data Governance Platform (NDGP) if you process sensitive data or your primary activity is data processing
  • Re-scan your site monthly using a public tool (the free Arqam360 scanner takes 60 seconds) to catch tracker drift before it becomes a complaint
  • Document everything — consent records, scan timestamps, policy versions, DSAR handling logs — because an SDAIA investigation will request a paper trail
Generate a PDPL-compliant policy

Free bilingual privacy policy generator. Covers the seven mandatory PDPL disclosures.

Generate my policy

Frequently Asked Questions

Why 27 stores and not more?

27 is the size of the dataset SimilarWeb produced when we filtered the top 100 Saudi e-commerce stores for active operation, accessibility from a Saudi IP, and inclusion of a privacy-relevant signal (any tracking activity). Smaller stores were excluded because the absence of trackers makes compliance scoring uninformative. Larger sample sizes are planned: the monthly refresh will expand the panel to 30-50 stores, and the quarterly refresh will target 60-80. The current dataset is representative of the top of the Saudi e-commerce market, which is the segment where regulatory enforcement is most likely to start.

How did you decide the compliance score?

The score is a 0-100 weighted composite of: presence of a consent banner (heavy weight), denied-default consent state before tag firing (heavy weight), Google Consent Mode v2 signal emission (heavy weight), absence of pre-consent tracker activity (medium weight), presence of a linked privacy policy (medium weight), absence of excessive non-essential cookies (light weight), and per-cookie classification against the 113-pattern library. The exact weights are published in the methodology section of the public Index page. Scores are reproducible — running the scanner against the same store on the same day produces the same number.

Is the data biased toward Arqam360 customers?

No. The 27 stores were selected from SimilarWeb's public traffic data with no filter for which CMP they use; the scan was run against each store's public-facing site without any internal Arqam360 instrumentation. The five top-scoring stores in the dataset use different CMPs (one uses Arqam360, two use Cookiebot, one uses OneTrust, one has a custom implementation). The scanner uses the same public network-tab analysis that any third party could replicate.

Do you publish the names of the stores?

No, and not for any single store. The Index data is published in aggregate (by vertical, by platform, by finding type) but individual stores are anonymized to avoid singling them out for regulatory attention based on a scan they did not request. If a specific store wants its own report, we run the free scanner against it on request and email the result to the merchant — this is the standard Arqam360 scanner that anyone can use at arqam360.com/scan.

What is the difference between this blog post and the live Index page?

The page at arqam360.com/ksa-compliance-index is the report — headline number, score distribution, vertical breakdown, top findings, archetype profiles. This blog post is the long-form analytical companion: why these findings matter, what specific failures drive the numbers, what the regulatory and market implications are, and how a store moves from the 81% to the 19%. Both share the same underlying data, written 21-23 May 2026.

If SDAIA has not publicly fined anyone yet, is the risk real?

Yes. Public enforcement action is one signal of regulator activity; private investigations triggered by visitor complaints are another, and they happen well before any public announcement. Saudi law firms tracking SDAIA report a steady stream of investigation requests, settlement letters, and remediation orders that never reach press coverage. The lack of a public fine should be read as a regulator building case files, not as a regulator inactive. PDPL violations also expose merchants to civil claims from affected data subjects under PDPL Article 36 — a private action that does not require SDAIA involvement at all.

Will you re-run this scan?

Yes, monthly. The next refresh runs on the first Saturday of June 2026 and will be published as 'KSA Compliance Index — June 2026 refresh' with delta numbers against the May baseline. The refresh cadence is documented at GTM-content/content/ksa-index-monthly-refresh-procedure.md (internal) — anyone tracking Saudi PDPL enforcement can rely on this dataset being updated regularly.

What is the single most cost-effective thing my store can do to move out of the 81%?

Install a CMP that ships Google Consent Mode v2 wired by default, with denied defaults firing before any tag. That single change typically lifts a store's compliance score by 25-40 points and resolves the three most common findings simultaneously (trackers pre-consent, missing GCM v2, no consent banner). It is also the change that produces the most measurable revenue lift, because GCM v2 modeling on Google Ads recovers meaningful conversion volume that is otherwise invisible. For free CMPs, the install takes 5-15 minutes depending on platform; for paid CMPs, the install is similar but the support during edge cases is more responsive.

Authoritative Sources

Live KSA E-Commerce Privacy Compliance Index Saudi PDPL — official text SDAIA — Personal Data Protection regulations and policies Google Consent Mode v2 — implementation guide

Methodology Reproducibility

The methodology used to produce this dataset is publicly reproducible. The Arqam360 scanner at arqam360.com/scan is the same scanner that produced the Index numbers — anyone can run it against any Saudi store and replicate a single-store result. The scan logic (cookie classification, tracker detection, GCM v2 signal verification, scoring weights) is documented in the methodology section of the live Index page. The 113-pattern cookie classification library is open about its sources: 81 patterns derive from publicly-documented tracker behavior (Google Analytics, Meta Pixel, etc.) and 32 are MENA-specific patterns we built from observed scan results across thousands of Saudi storefront scans over the past year.

Independent verification is encouraged. If you want to challenge any finding in this dataset — a specific store's score, a specific vertical's median, a specific finding's frequency — re-run the scanner against the relevant store and report a discrepancy. We treat methodology disputes as serious; the dataset matters more than any single store's compliance posture. The full per-store dataset (anonymized) is available on request for serious researchers, journalists, and regulators. Contact admin@arqam360.com with a brief explanation of your intended use.

Learn more in our guide: MENA Compliance

See where your site stands

Run Arqam360's free compliance scanner to check your cookies, trackers, and consent gaps in under 60 seconds.

Free Scanner

Stay updated

Get privacy compliance tips and Arqam360 updates delivered to your inbox.