If you run an online store that serves customers in Saudi Arabia, having a privacy policy is no longer optional or just a legal page added to your website. It has become a core requirement for complying with the Personal Data Protection Law (PDPL). Since the law came into full force, every store that collects customer data such as names, phone numbers, addresses, and payment details must clearly explain how that data is collected, used, and protected, while giving customers clear rights to control their personal information.
This guide gives you a ready-to-use privacy policy template store owners can edit and publish directly on their online store, along with a breakdown of the key PDPL requirements. Together, these will help you put together a privacy policy that is clear, practical, and aligned with Saudi regulations.
What is the Personal Data Protection Law (PDPL)?
The Personal Data Protection Law (PDPL) is Saudi Arabia's first comprehensive legal framework governing the collection, processing, storage, and sharing of personal data. It was issued under Royal Decree No. (M/19) of 2021 and later updated by Royal Decree No. (M/148) of 2023, under the supervision of the Saudi Data and Artificial Intelligence Authority (SDAIA). The law came into full effect on 14 September 2024, after the grace period given to organisations to align their operations came to an end.
The law is designed to protect individual privacy, promote transparency, and make sure that any organisation handling personal data operates under clear rules that guarantee lawful and responsible use.
PDPL doesn't only apply to entities based inside Saudi Arabia. It also extends to any organisation that processes the personal data of residents in the Kingdom, even if its headquarters or servers are located abroad. In practice, that means any online store receiving orders from customers in Saudi Arabia is required to comply, no matter where it operates from.
Why every online store needs a PDPL-compliant privacy policy
A clear privacy policy isn't just about ticking a legal box. It also helps build customer trust and strengthens your store's credibility. When customers understand how their data is used and who can access it, they feel far more comfortable completing a purchase.
The law also requires online store owners to publish an easy-to-access privacy policy that clearly explains the following:
The personal data being collected.
Why the data is being collected.
How long it will be retained.
Who the data may be shared with.
The rights customers have over their personal data.
Failing to meet these requirements can lead to fines of up to five million Saudi riyals in serious cases, alongside real risks to your store's reputation and customer trust.
What your store privacy policy should include
Before using any template or publishing one on your store, make sure your actual practices match what the policy says. A privacy policy on its own isn't enough. It needs to reflect the way your store genuinely handles personal data.
1. A legal basis for processing data
PDPL requires a legal basis for every act of collecting or using personal data. For online stores, the most common bases include:
Obtaining customer consent to send marketing messages.
Processing data needed to fulfil orders and complete purchases.
Meeting regulatory requirements such as invoicing and tax records.
2. Transparency and plain language
The law requires the privacy policy to be written in simple, clear language that any user can understand, so customers don't need a legal background to grasp how their data is handled.
You also need to:
Display the privacy policy before collecting data.
Provide an Arabic version, as it is the primary language required by law.
Add an English version if you wish, but it cannot replace the Arabic one.
3. Explaining data subjects' rights
PDPL grants every individual a set of rights, and your privacy policy needs to explain how to exercise them. These include:
The right to know how their data is used.
The right to access their personal data.
The right to correct inaccurate data.
The right to request the destruction of data once it is no longer needed.
The right to obtain a copy of their data.
The right to withdraw consent for processing.
The right to object to certain processing activities.
You also need to provide a clear channel for receiving these requests and respond within 30 days at most. A single extension is allowed only when there is a valid regulatory reason.
4. Reporting data breaches
If your store suffers a breach or a security incident that could harm customers or their personal data, the law requires you to:
Notify the Saudi Data and Artificial Intelligence Authority within 72 hours.
Inform affected customers as quickly as possible.
Explain the steps taken to contain the incident and reduce its impact.
It's also good practice to mention this commitment within your privacy policy to show customers that you take the protection of their data seriously.
5. Transferring data outside Saudi Arabia
Most online stores rely on third-party services such as:
Payment gateways.
Cloud hosting providers.
Analytics and marketing tools.
In these cases, personal data may be transferred outside Saudi Arabia. Such transfers are subject to specific PDPL rules and require the safeguards approved by the Saudi Data and Artificial Intelligence Authority to ensure the data stays protected during transfer.
6. Setting data retention periods
Personal data cannot be kept indefinitely. It should only be retained for as long as is needed to fulfil the purpose it was collected for.
A good privacy policy sets a retention period for each type of data, for example:
Keeping order records for the periods required by commercial and tax regulations.
Deleting data or anonymising it once its legal purpose has ended.
Deleting marketing data as soon as the customer withdraws consent.
Ready-to-use privacy policy template for your online store
You can use the template below as the foundation for your online store's privacy policy. Simply replace the bracketed placeholders with your store's information before publishing.
Privacy PolicyLast updated: [Last update date] 1. IntroductionAt [Store Name], we are committed to protecting the privacy of every customer and visitor. We aim to handle personal data securely and transparently, in line with the Personal Data Protection Law (PDPL) and its implementing regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA). This policy explains how we collect, use, store, share, and protect your personal data when you use our online store. 2. Who we areThe entity responsible for processing your personal data is:
3. Personal data we collectWe may collect the following types of data: Identity data
Contact data
Order data
Payment data Payment data is processed by licensed payment service providers, and we do not store full bank card numbers. Account data
Technical data
Marketing data
4. How we collect your dataWe collect your personal data in several ways, including:
5. Why we use your dataWe use your personal data for the following purposes:
6. Who we share your data withYour data may be shared with:
7. Transferring data outside Saudi ArabiaSome personal data may be processed outside Saudi Arabia when we use cloud services or global service providers. In such cases, we apply the safeguards approved by the Saudi Data and Artificial Intelligence Authority to ensure an appropriate level of protection for your personal data. 8. Data retention periodWe only retain personal data for as long as needed to fulfil the purpose it was collected for. Examples include:
9. Your rights under the Personal Data Protection LawAs a user of the store within Saudi Arabia, you have the following rights:
You can exercise any of these rights by contacting us using the contact details provided in this policy. We will respond within 30 days, in line with the timeframe set by the law. 10. How we protect your dataWe apply a set of security measures to protect personal data, including:
In the event of a breach that may affect customer data, we commit to notifying the relevant authorities and customers within the timeframes set by law. 11. CookiesWe use cookies to:
You can manage cookies through your browser settings or through the cookie management window on the site. 12. Children’s privacyOur services are intended for individuals aged 18 or over. We do not knowingly collect data from children without the consent of a parent or legal guardian. If we become aware that we have collected such data without proper consent, we will delete it as soon as possible. 13. Updating this privacy policyWe may update this policy when changes occur to our services or to the regulations governing personal data protection. The updated version will be posted on this page along with the date of the latest update. We may also notify customers of significant changes by email or through notifications inside the store. 14. Contact and complaintsIf you have any questions or requests related to your personal data, you can contact us via:
You also have the right to file a complaint directly with the Saudi Data and Artificial Intelligence Authority if you believe your data has been processed in violation of the law. |
How to publish your store privacy policy on the MEEC platform
Once you have finished customising the template, we at the MEEC platform recommend the following steps before publishing:
Prepare two versions of the privacy policy, one in Arabic and one in English, with the Arabic version treated as the primary reference.
Create a dedicated privacy policy page within the store and link to it from the footer of every page.
Add a link to the policy at every point where data is collected, such as the registration page, the checkout page, and the newsletter signup form.
Provide a working communication channel to receive customer requests related to their personal data.
Review the privacy policy every 6 to 12 months to keep it aligned with any updates or new guidelines issued by the Saudi Data and Artificial Intelligence Authority.
Common mistakes to avoid
When drafting your store privacy policy, steer clear of the following mistakes:
Publishing the policy in English only without an Arabic version.
Pre-ticking the box for consent to marketing messages.
Copying a GDPR-compliant privacy policy without adapting it to PDPL.
Failing to provide a clear channel for personal data requests.
Leaving data retention periods vague instead of setting clear timeframes aligned with Saudi regulations.
Building a privacy policy that complies with the Saudi Personal Data Protection Law (PDPL) is more than a legal obligation. It is a key element in earning customer trust and strengthening the credibility of your online store. The clearer, more transparent, and more accurate your policy is in reflecting your actual data practices, the more your customers will trust you and the lower your legal risk will be.
Make it a habit to review your privacy policy regularly and update it whenever you add new services or change the way data is processed. Always refer to the official guidance issued by the Saudi Data and Artificial Intelligence Authority to make sure your privacy policy template store continues to meet the law.

Conversation
Comments
Be the first to comment.
Leave a comment