We scanned the top KSA ecom stores for PDPL + GDPR privacy compliance. Results are public, data is shareable, no email gate.
Stores scanned
1556
Median score
45/100
Worst score
14/100
Inconclusive scans
60
The takeaway, in one paragraph
Across the 1556 stores we scanned, the median compliance score is 45/100. Translation: the average Saudi e-commerce store today is roughly half-compliant with the PDPL — firing marketing pixels before consent, shipping no banner at all, and running on a privacy stack designed for the pre-PDPL era. The headline isn't that some stores are failing. It's that the entire market is.
89%
No consent banner
1379 of 1556 stores
68%
Pre-consent tracking
1065 of 1556 stores
88%
No Google Consent Mode v2
1371 of 1556 stores
The headline
97%
of the stores we scanned would fail a PDPL audit today.
That's 1507 out of 1556 stores. The pattern isn't isolated bad actors — it's a market that hasn't caught up with the law that came into full effect in September 2024.
Score distribution
How scores are distributed
23
1%
641
41%
337
22%
116
7%
379
24%
020406080100
0–19
23
20–39
641
40–59
337
60–79
116
80–100
379
Worst: 14Median: 45Best: 100
n = 1556
A market in healthy shape would cluster around 70–80. What we found instead: a long lower-middle tail. Roughly half the stores sit in the 40–60 "critical to failing" band. Only five stores cracked 80+. The good news: five stores DID — so the bar isn't impossibly high. The bad news: the gap between them and the rest is a 30-point chasm.
Curious where YOUR store falls in this distribution?
68% of stores load Google Analytics, Meta Pixel, or both — before the visitor has had a chance to accept or reject. This is the single largest PDPL violation we observed across the index. The mechanism is usually Google Tag Manager firing on page-load with no consent gating. The fix is well-documented (Google Consent Mode v2 default-denied + a banner that flips the gate after interaction). That this much of the market hasn't done it tells you most stores don't know it's required.
Finding 289%
89% don't show any consent banner at all
Not a "bad banner" — no banner. The visitor lands, the trackers fire, the data flows. No pop-up, no choice, no record of consent. Under PDPL this isn't an aesthetic issue — it's a baseline violation. The "no banner" pattern correlates strongly with stores running on stock Salla / Shopify / WordPress without a CMP installed. Every platform we tested ships defaults with tracking enabled and no consent layer at all.
Finding 388%
88% are missing Google Consent Mode v2
GCM v2 is the modern way to signal consent state to Google's ad ecosystem (Ads, Analytics, Tag Manager). Without it, even stores that DO have a banner end up signaling "consent granted" for every visitor regardless of what they clicked — which Google now penalizes by withholding bid signals in the EEA. KSA isn't EEA, but Google Ads accounts spanning both get clipped globally. The fix is one config block in Tag Manager.
The complete list
Every common failure we found
PDPL / data-protection compliance risk
97%1507/1556
Trackers loading before consent
68%1065/1556
No server-side event forwarding
62%965/1556
No consent banner
60%935/1556
Google Consent Mode v2 missing
48%751/1556
Excessive non-essential cookies
45%694/1556
No privacy policy linked
37%580/1556
By platform
How compliance varies by platform
WordPress / WooCommerce
47/100
Median · 858 stores
Not detected
29/100
Median · 401 stores
Shopify
47/100
Median · 114 stores
Zid
29/100
Median · 89 stores
Salla
29/100
Median · 72 stores
Custom-built
42/100
Median · 22 stores
Top trackers detected
Trackers that show up on most stores
Google Analytics
59%920/1556
Facebook Pixel
29%452/1556
Hotjar
6%99/1556
Google Tag Manager
1%13/1556
Google
1%9/1556
Microsoft Clarity
0%7/1556
Intercom
0%4/1556
jsDelivr CDN
0%4/1556
Cloudflare
0%4/1556
Klaviyo
0%3/1556
Google Analytics on 59% of stores, Meta Pixel on 29% — that's the entire visible tracking surface for most Saudi e-commerce. What this list is missing isn't more trackers; it's the trackers we couldn't see. Server-side forwarding, custom-domain Meta CAPI endpoints, first-party analytics — these don't show up in a client-side scan, but they're where the modern stack is heading. The headline: 62% of stores have no server-side event forwarding at all.
Why this matters now
The grace period is over
Saudi Arabia's Personal Data Protection Law (PDPL) took full effect on September 14, 2024. SDAIA — the Saudi Data and Artificial Intelligence Authority — issued 48 enforcement decisions against violators during 2025 alone, officially announced February 2026. The two-year buildup of advisory communication is over; enforcement is the operating mode.
Up to SAR 5,000,000 per violation
Plus imprisonment up to 2 years for unauthorized disclosure of sensitive personal data. Penalties double on repeat offenses.
48 enforcement decisions in 2025
SDAIA's specialised committees issued 48 decisions against violators during 2025 — announced February 2026. Retail was explicitly named among the most-affected sectors.
PDPL + GDPR, simultaneously
Any KSA store reaching EU visitors must comply with BOTH. Most we scanned comply with neither cleanly.
The fix
What good looks like
The gap between 49/100 and 90/100 isn't expensive. It's three configuration changes most stores can ship in an afternoon.
Fire pixels AFTER consent, not before
Set Google Consent Mode v2 to default-denied. Configure your CMP to call gtag('consent','update', …) on banner interaction. Result: pixels only fire when the visitor agrees.
⏱ Time to fix: 20–40 min
Ship a PDPL-tuned consent banner
Bilingual (Arabic-first for KSA visitors), three choices (Accept / Reject / Customize), defaults to denied, logs the consent decision per visitor. Most CMPs ship this out of the box once configured for the KSA / GDPR-strict regime.
⏱ Time to fix: 1–2 hours
Publish a PDPL-localized privacy policy
Cover the seven mandatory disclosures: data collected, lawful basis, retention, sharing, data subject rights, contact info, transfer outside KSA. Link from the footer. A boilerplate template won't pass — it has to name your actual processors and lawful basis per data type.
⏱ Time to fix: 2–4 hours
Want the free PDPL banner shipped for you?
Arqam360's free tier gives you the banner forever — no signup, no card.