A recent study by King Abdulaziz University revealed that a majority of Saudi e-commerce platforms fail to meet national data protection standards. The research, conducted by Iman Al-Ashouli and Abeer Al-Hadhli, analyzed the privacy policies of 100 active e-commerce websites in Saudi Arabia. According to a report by Okaz, only 31% of the examined websites fully complied with the regulatory requirements.
Analysis of Privacy Policies
The researchers evaluated the websites based on four primary criteria. These included disclosing data retention periods, allowing users to request data destruction, providing copies of personal data, and offering a clear complaints mechanism. The findings showed that 9% of the analyzed websites lacked any privacy policy. Meanwhile, 31% of the sites published policies that completely omitted all four required elements.
Additionally, 29% of the platforms met some requirements but failed to complete them. Only 31% of the websites successfully disclosed all four elements. Specifically, 45% of the policies disclosed how long they retain personal data, while 51% stated the user’s right to request data destruction. Furthermore, 34% mentioned the right to obtain a copy of the data, and 33% provided a complaints mechanism.
Compliance with Data Protection Standards
The study analyzed how 100 digital commerce sites align with Saudi data protection standards under the Personal Data Protection System. Notably, the websites with the highest search engine visibility recorded the highest rate of non-compliance at 60%. In comparison, mid-ranking websites showed a 22% non-compliance rate, while lower-ranked sites stood at 38%.
The research also highlighted significant issues among hosted platforms. Specifically, 70% of the websites hosted on local economy platforms were classified as non-compliant. None of the stores in this category achieved full compliance with the four examined elements. The researchers suggested that this trend stems from a lack of awareness, as some store owners mistakenly believe the hosting platform handles data security.
Platform Hosting and Procedural Gaps
The analysis identified severe procedural gaps even among websites that claimed to respect user rights. For instance, 82% of the policies did not specify a timeframe for responding to data destruction requests. Moreover, 86% did not clarify the time needed to provide data copies, and 89% failed to specify a duration for processing complaints. Additionally, 67% of the sites did not name the department responsible for handling these issues.
Artificial Intelligence in Policy Analysis
The study also tested the ability of artificial intelligence language models to analyze privacy policies. The technology achieved a 96% agreement rate with human analysis regarding data retention provisions. It reached 92% for data destruction rights and 81% for complaints mechanisms. However, the agreement rate dropped to 58% when evaluating the right to obtain data copies.
The researchers recommended providing simplified templates to help small businesses implement these data protection standards effectively. They emphasized that the store owner remains the primary data controller, while hosting platforms act as data processors. Finally, they noted that the study only measures policy clarity, not actual operational practices.





