Skip to content
Public Report · 2026

The KSA E-Commerce
Privacy Compliance Index

We scanned the top KSA ecom stores for PDPL + GDPR privacy compliance. Results are public, data is shareable, no email gate.

Stores scanned
1556
Median score
45/100
Worst score
14/100
Inconclusive scans
60
The takeaway, in one paragraph

Across the 1556 stores we scanned, the median compliance score is 45/100. Translation: the average Saudi e-commerce store today is roughly half-compliant with the PDPL — firing marketing pixels before consent, shipping no banner at all, and running on a privacy stack designed for the pre-PDPL era. The headline isn't that some stores are failing. It's that the entire market is.

89%
No consent banner
1379 of 1556 stores
68%
Pre-consent tracking
1065 of 1556 stores
88%
No Google Consent Mode v2
1371 of 1556 stores
The headline
97%

of the stores we scanned would fail a PDPL audit today.

That's 1507 out of 1556 stores. The pattern isn't isolated bad actors — it's a market that hasn't caught up with the law that came into full effect in September 2024.

Score distribution

How scores are distributed

23
1%
641
41%
337
22%
116
7%
379
24%
020406080100
0–19
23
20–39
641
40–59
337
60–79
116
80–100
379
Worst: 14Median: 45Best: 100
n = 1556

A market in healthy shape would cluster around 70–80. What we found instead: a long lower-middle tail. Roughly half the stores sit in the 40–60 "critical to failing" band. Only five stores cracked 80+. The good news: five stores DID — so the bar isn't impossibly high. The bad news: the gap between them and the rest is a 30-point chasm.

Curious where YOUR store falls in this distribution?
Free scan, 30 seconds, no signup.
Scan my store free
Top failures, unpacked

The three things hurting Saudi stores the most

Finding 168%

Marketing pixels fire before the visitor consents

68% of stores load Google Analytics, Meta Pixel, or both — before the visitor has had a chance to accept or reject. This is the single largest PDPL violation we observed across the index. The mechanism is usually Google Tag Manager firing on page-load with no consent gating. The fix is well-documented (Google Consent Mode v2 default-denied + a banner that flips the gate after interaction). That this much of the market hasn't done it tells you most stores don't know it's required.

Finding 289%

89% don't show any consent banner at all

Not a "bad banner" — no banner. The visitor lands, the trackers fire, the data flows. No pop-up, no choice, no record of consent. Under PDPL this isn't an aesthetic issue — it's a baseline violation. The "no banner" pattern correlates strongly with stores running on stock Salla / Shopify / WordPress without a CMP installed. Every platform we tested ships defaults with tracking enabled and no consent layer at all.

Finding 388%

88% are missing Google Consent Mode v2

GCM v2 is the modern way to signal consent state to Google's ad ecosystem (Ads, Analytics, Tag Manager). Without it, even stores that DO have a banner end up signaling "consent granted" for every visitor regardless of what they clicked — which Google now penalizes by withholding bid signals in the EEA. KSA isn't EEA, but Google Ads accounts spanning both get clipped globally. The fix is one config block in Tag Manager.

The complete list

Every common failure we found

PDPL / data-protection compliance risk
97%1507/1556
Trackers loading before consent
68%1065/1556
No server-side event forwarding
62%965/1556
No consent banner
60%935/1556
Google Consent Mode v2 missing
48%751/1556
Excessive non-essential cookies
45%694/1556
No privacy policy linked
37%580/1556
By platform

How compliance varies by platform

WordPress / WooCommerce
47/100
Median · 858 stores
Not detected
29/100
Median · 401 stores
Shopify
47/100
Median · 114 stores
Zid
29/100
Median · 89 stores
Salla
29/100
Median · 72 stores
Custom-built
42/100
Median · 22 stores
Top trackers detected

Trackers that show up on most stores

Google Analytics
59%920/1556
Facebook Pixel
29%452/1556
Hotjar
6%99/1556
Google Tag Manager
1%13/1556
Google
1%9/1556
Microsoft Clarity
0%7/1556
Intercom
0%4/1556
jsDelivr CDN
0%4/1556
Cloudflare
0%4/1556
Klaviyo
0%3/1556

Google Analytics on 59% of stores, Meta Pixel on 29% — that's the entire visible tracking surface for most Saudi e-commerce. What this list is missing isn't more trackers; it's the trackers we couldn't see. Server-side forwarding, custom-domain Meta CAPI endpoints, first-party analytics — these don't show up in a client-side scan, but they're where the modern stack is heading. The headline: 62% of stores have no server-side event forwarding at all.

Why this matters now

The grace period is over

Saudi Arabia's Personal Data Protection Law (PDPL) took full effect on September 14, 2024. SDAIA — the Saudi Data and Artificial Intelligence Authority — issued 48 enforcement decisions against violators during 2025 alone, officially announced February 2026. The two-year buildup of advisory communication is over; enforcement is the operating mode.

Up to SAR 5,000,000 per violation

Plus imprisonment up to 2 years for unauthorized disclosure of sensitive personal data. Penalties double on repeat offenses.

48 enforcement decisions in 2025

SDAIA's specialised committees issued 48 decisions against violators during 2025 — announced February 2026. Retail was explicitly named among the most-affected sectors.

PDPL + GDPR, simultaneously

Any KSA store reaching EU visitors must comply with BOTH. Most we scanned comply with neither cleanly.

The fix

What good looks like

The gap between 49/100 and 90/100 isn't expensive. It's three configuration changes most stores can ship in an afternoon.

Fire pixels AFTER consent, not before

Set Google Consent Mode v2 to default-denied. Configure your CMP to call gtag('consent','update', …) on banner interaction. Result: pixels only fire when the visitor agrees.

⏱ Time to fix: 20–40 min

Ship a PDPL-tuned consent banner

Bilingual (Arabic-first for KSA visitors), three choices (Accept / Reject / Customize), defaults to denied, logs the consent decision per visitor. Most CMPs ship this out of the box once configured for the KSA / GDPR-strict regime.

⏱ Time to fix: 1–2 hours

Publish a PDPL-localized privacy policy

Cover the seven mandatory disclosures: data collected, lawful basis, retention, sharing, data subject rights, contact info, transfer outside KSA. Link from the footer. A boilerplate template won't pass — it has to name your actual processors and lawful basis per data type.

⏱ Time to fix: 2–4 hours
Want the free PDPL banner shipped for you?
Arqam360's free tier gives you the banner forever — no signup, no card.
Get the free banner
Methodology

How we scanned these stores

  • • Real browser (Puppeteer) loads each store homepage
  • • We detect cookies, trackers, consent banner, GCM v2 status
  • • Score 0-100 against PDPL + GDPR criteria
  • • Inconclusive when a store blocks our scanner (CF/DataDome)
What this scan can't tell us
  • • Whether the store has proper backend protections (data-deletion workflows, DSAR pipelines, vendor agreements)
  • • What's collected once a visitor logs in or completes checkout
  • • Whether processor agreements (Shopify, Salla, Meta, etc.) meet PDPL standards
  • • The store's posture on cross-border data transfer

A store could score 100/100 on this scan and still be non-compliant in storage and processing. The reverse is also true.

Arqam360 ships on Shopify, Zid, WordPress, and custom sites today. Salla coming soon.

Scan your store

How does YOUR store compare?

Median in this index: 45/100. Scan your store free in 30 seconds and see where you stand.

Scan my store free

Last updated: 7 September 2026 · Region: KSA