Skip to content
Integration

How to Install a PDPL-Compliant Consent Banner on Zid (Saudi 2026 Step-by-Step)

Taha Farhane· Founder, Arqam360 — building MENA consent + data infrastructure
September 5, 202613 min read
Read the full guide: How to Set Up Google Consent Mode v2 (Step-by-Step)

Zid is one of Saudi Arabia's leading native e-commerce platforms, particularly strong for merchants doing higher GMV with sophisticated payment integrations (Mada, Apple Pay, Tabby, Tamara). After SDAIA's 48 enforcement decisions in 2025 (with retail explicitly named and "marketing pixels firing before consent" cited as the most common violation), every Zid merchant running Google Ads, Meta Pixel, or TikTok analytics needs a PDPL-compliant consent banner. Zid's architecture is unique among MENA marketplaces: the platform splits app integration from storefront script injection into two separate systems. The Arqam360 Zid app handles both — once installed and approved, the banner auto-injects across your storefront via Zid's official Snippet system. This guide walks the exact steps.

What Saudi PDPL Requires on a Cookie Banner

Saudi PDPL Article 6 requires explicit, informed, prior consent before processing personal data for non-essential purposes. In practical terms for a Zid store: trackers cannot fire and cookies cannot be written until the visitor has actively granted permission. Opt-out consent is not lawful — the visitor must take an affirmative action (clicking "Accept" on a banner) before Google Analytics, Meta Pixel, TikTok pixel, or any other non-essential cookie/tag activates. The PDPL Implementing Regulations add: consent recorded with timestamp + scope, withdrawal as easy as granting, and clear naming of data categories collected. SDAIA enforcement decisions in 2025 included multiple cases against Saudi retailers whose banners existed but failed these specific criteria.

  • Banner appears on first page load, before any non-essential tracker fires
  • Visitor takes an affirmative action (Accept / Reject / Customize) — implicit consent is not lawful
  • Visitor can withdraw consent as easily as granted (one-click via settings link)
  • Banner copy names the data categories (Analytics / Marketing / Preferences) and purposes
  • If visitor rejects, no non-essential trackers fire on subsequent page loads
  • Consent records stored with timestamp + scope + visitor identifier for audit
  • Banner available in Arabic with RTL layout for Saudi visitors

Step-by-Step: Install Arqam360 on Your Zid Store

This walkthrough assumes you have a Saudi Zid store and want a PDPL-compliant banner live in 3 clicks. Zid's architecture splits app integration (the merchant admin iframe) from snippet injection (the storefront script). The Arqam360 Zid app handles both layers — once approved by Zid, the snippet auto-injects across your storefront with zero extra steps. This is different from Shopify (single integration) and Salla (Easy Mode SDK) but produces the same outcome: a working banner on your storefront within minutes of install.

Step 1: Find Arqam360 in the Zid App Store

Open your Zid merchant admin → التطبيقات (Apps) → متجر التطبيقات (App Store). Search "Arqam360" or browse the privacy/compliance category. The listing shows the free tier (banner forever, no card required) and paid plans (Starter, Pro, Managed). For a single Saudi store with up to 10,000 monthly pageviews, the Free plan is sufficient for PDPL compliance. Click «تفعيل» (Activate).

Step 2: Approve OAuth + Grant Scopes

Zid redirects you through OAuth to authorize the app. The scopes the app requests: read your store information (for banner detection of language and currency), receive snippet-injection permission (the banner script). Approve. Zid uses code-exchange OAuth only (no Easy Mode shortcut like Salla), so you'll briefly see Zid's OAuth screen. After approval, Zid returns you to your store admin where the Arqam360 app is now active.

Step 3: Configure the Banner

Click the Arqam360 app icon in your Zid admin. The Arqam360 dashboard loads inside the Zid admin iframe. First-screen defaults: language is Arabic-RTL (auto-detected from your Zid store locale), position is bottom-right (recommended for thumb access on mobile), color scheme inherits your Zid theme's accent color. Adjust if desired, click «حفظ» (Save). The banner queues for storefront injection via Zid's official Snippet system.

Step 4: Verify on Your Storefront

Open your Zid storefront URL in an incognito browser. The banner should appear within 1-2 seconds. If it doesn't appear immediately after Step 3, wait 1-2 minutes — Zid's Snippet auto-injection has a brief propagation delay. If still no banner after 5 minutes, check your Zid admin → Apps → Arqam360 for any "Connection issue" warnings; re-authorize if needed. Click "Accept" on the banner — banner disappears. Refresh — banner stays gone (consent stored). New incognito window — banner reappears (fresh visitor).

Step 5: Verify Google Consent Mode v2 (Critical)

This is the step SDAIA enforcement decisions focus on. Install the Google Tag Assistant Companion (free Chrome extension). With it active, refresh your Zid storefront in incognito. The extension should show gtag('consent', 'default') firing FIRST with all four parameters (analytics_storage, ad_storage, ad_user_data, ad_personalization) set to 'denied'. Click "Accept" on the banner. You should now see gtag('consent', 'update') fire with parameters set to 'granted'. If the default doesn't fire before any GA4 tag, the load order is broken — but Arqam360's Zid integration uses Zid's official Snippet position which guarantees early-page injection.

See where your store ranks

Free real-browser scan of any e-commerce site. 30 seconds, no signup.

Scan my store free

Five Zid-Specific Gotchas

Zid's App-vs-Snippet architecture introduces some platform-specific edge cases. Each is solvable; run through this checklist after Steps 1-5.

Gotcha 1 — Token expiration breaks the integration silently. Zid uses two tokens for API access (access_token + manager_token / X-Manager-Token, both required for every call). If either expires and your store admin hasn't logged in for a while, the Arqam360 backend can't reach Zid to fetch store info — the banner keeps working (snippet is independent), but the dashboard shows stale data. The fix is automatic: log into your Zid admin once a week to refresh tokens. Most active merchants never notice this.

Gotcha 2 — Mada / Tabby / Tamara cookies must be classified correctly. Zid stores commonly use Mada (Saudi national debit network), Tabby, Tamara, and Apple Pay integrations. Each writes cookies during checkout. Arqam360's 113-pattern classifier includes all four explicitly; verify in your banner's «إدارة التفضيلات» (Manage Preferences) modal that these appear under "Essential" (required for payment to work). If they appear under "Marketing" or "Analytics", contact Arqam360 support to update the classification for your specific theme.

Gotcha 3 — Zid theme cache propagation. When you change banner configuration in the Arqam360 dashboard, Zid's storefront cache can delay the visible change by 5-10 minutes. Hard-refresh (Cmd+Shift+R) usually bypasses this. If your store has Cloudflare in front (some larger Zid merchants do), purge Cloudflare cache for your domain too.

Gotcha 4 — Snippet propagation depends on Zid app status. If Zid temporarily de-lists the Arqam360 app for any reason (rare, but possible during marketplace re-reviews), the snippet auto-injection pauses. Your banner stays functional on already-loaded pages but new visitors see the storefront without the banner. Monitor Zid → Apps for any status-change alerts; contact Arqam360 support if you see them.

Gotcha 5 — Multi-currency stores need explicit verification. Zid supports multi-currency for cross-GCC merchants. The Arqam360 banner detects the visitor's currency-language combination correctly, but multi-currency stores should test both: visit with SAR context (Saudi IP) → Arabic banner; visit with AED context (UAE IP) → Arabic banner with UAE-PDPA framing if enabled. Both regimes use Consent Mode v2; the difference is in the banner copy framing.

PDPL Compliance Checklist for Your Zid Store

Beyond the banner, full PDPL compliance requires several more pieces. Tick each box; gaps are audit exposure.

  • PDPL-compliant consent banner installed and verified across Steps 1-5
  • Privacy policy published explicitly naming PDPL and SDAIA — Zid provides a policy template you can customize under الإعدادات (Settings) → الصفحات (Pages)
  • DSAR (Data Subject Access Request) channel published with 30-day response commitment
  • Data Protection Officer (DPO) appointed if processing sensitive data at scale or systematically monitoring visitors
  • Registered on SDAIA's National Data Governance Platform (NDGP) if public entity, processing sensitive data, or primary business is data processing
  • Cross-border data transfer documented if any vendor (Zid itself, Meta, Google, Tabby, Tamara, Mada) processes Saudi-resident data outside Saudi Arabia
  • Consent records stored with timestamp + scope for audit (Arqam360 stores 90-day rolling logs)
  • Visible link to withdraw-consent UI in your Zid store footer
Generate a PDPL-compliant policy

Free bilingual privacy policy generator. Covers the seven mandatory PDPL disclosures.

Generate my policy

Frequently Asked Questions

Does Zid have a built-in cookie banner that satisfies PDPL?

Zid offers a basic cookie notice option but it's opt-out and doesn't fire Google Consent Mode v2 signals. For Saudi PDPL compliance you need a Google-certified CMP that wires GCM v2 explicitly + maintains an audit trail. Most Saudi Zid merchants overestimate what the built-in notice does.

Why does Zid have a separate Snippet system instead of just installing scripts via the app?

Zid's architecture separates app integration (merchant admin) from storefront script injection (Snippets) for security and quality reasons — they review snippets separately to ensure they don't introduce performance regressions or security issues across the merchant base. The Arqam360 Zid app went through both reviews; on approval, the snippet auto-injects across all stores that install the app, with zero merchant intervention required.

How long after install does the banner appear on the storefront?

Typically 1-2 minutes from clicking «Save» in Step 3. Zid's Snippet system propagates the snippet to your store's CDN. If you don't see it after 5 minutes, check the Arqam360 dashboard for any "Connection issue" warnings (rare; usually a transient OAuth token refresh).

Does the app work with Zid's multi-language stores (Arabic + English)?

Yes. The banner auto-detects the visitor's language and serves Arabic-RTL or English accordingly. The Arqam360 Zid integration reads your store's primary language setting and respects per-visitor language overrides.

Does the app work with Tabby / Tamara / Mada / Apple Pay integrations?

Yes — Arqam360's 113-pattern cookie classifier includes Tabby, Tamara, Mada (Saudi national debit), and Apple Pay cookies explicitly. These are classified as "Essential" (required for payment) and fire without requiring consent — correct under PDPL Article 6's essential-purpose exception.

Will the banner slow down my Zid store?

No measurable impact. The Arqam360 widget loads asynchronously after page render — Zid's storefront performance benchmarks are unaffected. Total weight is under 30KB gzipped.

What happens if I uninstall the Zid app?

The snippet stops injecting on your storefront immediately (Zid's Snippet system de-registers the script when the app is uninstalled). Visitors no longer see the banner on subsequent visits. Existing consent records in Arqam360 are retained for 90 days for audit purposes per PDPL Implementing Regulations. If you reinstall, the banner reappears within minutes.

How do I know my install is audit-ready for SDAIA?

Three checks: (1) Tag Assistant shows GCM v2 firing correctly with denied-default before any tag; (2) DevTools Network tab on fresh incognito visit shows zero tracker requests before banner-click; (3) Arqam360 dashboard shows consent records accumulating. If all three pass, an SDAIA auditor reviewing your store's network log against a visitor complaint sees what they need: no tracker activity before consent.

Authoritative Sources

Zid — official developer documentation Google: Consent Mode v2 implementation guide Saudi PDPL — official text (consent provisions, Article 6) SDAIA — Personal Data Protection regulations and policies

Next Steps

Once your Zid store has a verified PDPL banner running, two compounding follow-ups. First: run the free Arqam360 scanner against your storefront to confirm no trackers fire pre-consent and to surface any Saudi-payment cookies the classifier might handle differently than your specific store setup. Second: read the Cluster A cornerstone "Saudi PDPL: The Complete Merchant Guide 2026" to understand the broader compliance picture beyond the banner — DSAR workflow, DPO appointment criteria, and NDGP registration. The banner is the technical foundation; everything else is operational discipline. Zid merchants tend to be higher-GMV operators with sophisticated payment integrations; that operational sophistication is exactly the discipline PDPL compliance rewards.

Arqam360 is a Google-certified CMP and IAB TCF 2.2-registered — both signals SDAIA-grade compliance + ad-tech ecosystem interoperability that survive technical audit.
Learn more in our guide: Integrations

Set up in minutes, not days

Arqam360 integrates with Google Consent Mode v2, GTM, GA4, and Meta/TikTok/Snap pixels automatically.

Start Free Trial

Stay updated

Get privacy compliance tips and Arqam360 updates delivered to your inbox.