If you run an online store that serves customers in Saudi Arabia, having a privacy policy is no longer optional or just a legal page added to your website. It has become a core requirement for complying with the Personal Data Protection Law (PDPL). Since the law came into full force, every store that collects customer data such as names, phone numbers, addresses, and payment details must clearly explain how that data is collected, used, and protected, while giving customers clear rights to control their personal information.

This guide gives you a ready-to-use privacy policy template store owners can edit and publish directly on their online store, along with a breakdown of the key PDPL requirements. Together, these will help you put together a privacy policy that is clear, practical, and aligned with Saudi regulations.

What is the Personal Data Protection Law (PDPL)?

The Personal Data Protection Law (PDPL) is Saudi Arabia's first comprehensive legal framework governing the collection, processing, storage, and sharing of personal data. It was issued under Royal Decree No. (M/19) of 2021 and later updated by Royal Decree No. (M/148) of 2023, under the supervision of the Saudi Data and Artificial Intelligence Authority (SDAIA). The law came into full effect on 14 September 2024, after the grace period given to organisations to align their operations came to an end.

The law is designed to protect individual privacy, promote transparency, and make sure that any organisation handling personal data operates under clear rules that guarantee lawful and responsible use.

PDPL doesn't only apply to entities based inside Saudi Arabia. It also extends to any organisation that processes the personal data of residents in the Kingdom, even if its headquarters or servers are located abroad. In practice, that means any online store receiving orders from customers in Saudi Arabia is required to comply, no matter where it operates from.

Why every online store needs a PDPL-compliant privacy policy

A clear privacy policy isn't just about ticking a legal box. It also helps build customer trust and strengthens your store's credibility. When customers understand how their data is used and who can access it, they feel far more comfortable completing a purchase.

The law also requires online store owners to publish an easy-to-access privacy policy that clearly explains the following:

  • The personal data being collected.

  • Why the data is being collected.

  • How long it will be retained.

  • Who the data may be shared with.

  • The rights customers have over their personal data.

Failing to meet these requirements can lead to fines of up to five million Saudi riyals in serious cases, alongside real risks to your store's reputation and customer trust.

What your store privacy policy should include

Before using any template or publishing one on your store, make sure your actual practices match what the policy says. A privacy policy on its own isn't enough. It needs to reflect the way your store genuinely handles personal data.

PDPL requires a legal basis for every act of collecting or using personal data. For online stores, the most common bases include:

  • Obtaining customer consent to send marketing messages.

  • Processing data needed to fulfil orders and complete purchases.

  • Meeting regulatory requirements such as invoicing and tax records.

2. Transparency and plain language

The law requires the privacy policy to be written in simple, clear language that any user can understand, so customers don't need a legal background to grasp how their data is handled.

You also need to:

  • Display the privacy policy before collecting data.

  • Provide an Arabic version, as it is the primary language required by law.

  • Add an English version if you wish, but it cannot replace the Arabic one.

3. Explaining data subjects' rights

PDPL grants every individual a set of rights, and your privacy policy needs to explain how to exercise them. These include:

  • The right to know how their data is used.

  • The right to access their personal data.

  • The right to correct inaccurate data.

  • The right to request the destruction of data once it is no longer needed.

  • The right to obtain a copy of their data.

  • The right to withdraw consent for processing.

  • The right to object to certain processing activities.

You also need to provide a clear channel for receiving these requests and respond within 30 days at most. A single extension is allowed only when there is a valid regulatory reason.

4. Reporting data breaches

If your store suffers a breach or a security incident that could harm customers or their personal data, the law requires you to:

  • Notify the Saudi Data and Artificial Intelligence Authority within 72 hours.

  • Inform affected customers as quickly as possible.

  • Explain the steps taken to contain the incident and reduce its impact.

It's also good practice to mention this commitment within your privacy policy to show customers that you take the protection of their data seriously.

5. Transferring data outside Saudi Arabia

Most online stores rely on third-party services such as:

  • Payment gateways.

  • Cloud hosting providers.

  • Analytics and marketing tools.

In these cases, personal data may be transferred outside Saudi Arabia. Such transfers are subject to specific PDPL rules and require the safeguards approved by the Saudi Data and Artificial Intelligence Authority to ensure the data stays protected during transfer.

6. Setting data retention periods

Personal data cannot be kept indefinitely. It should only be retained for as long as is needed to fulfil the purpose it was collected for.

A good privacy policy sets a retention period for each type of data, for example:

  • Keeping order records for the periods required by commercial and tax regulations.

  • Deleting data or anonymising it once its legal purpose has ended.

  • Deleting marketing data as soon as the customer withdraws consent.

Ready-to-use privacy policy template for your online store

You can use the template below as the foundation for your online store's privacy policy. Simply replace the bracketed placeholders with your store's information before publishing.

Privacy Policy

Last updated: [Last update date]

1. Introduction

At [Store Name], we are committed to protecting the privacy of every customer and visitor. We aim to handle personal data securely and transparently, in line with the Personal Data Protection Law (PDPL) and its implementing regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA).

This policy explains how we collect, use, store, share, and protect your personal data when you use our online store.

2. Who we are

The entity responsible for processing your personal data is:

  • Business name: [Business Name]

  • Commercial registration number: [CR Number]

  • Address: [Full Address]

  • Data protection officer email: [Email Address]

  • Phone number: [Phone Number]

3. Personal data we collect

We may collect the following types of data:

Identity data

  • Full name.

  • National ID or residency number when required.

Contact data

  • Phone number.

  • Email address.

  • Shipping and billing address.

Order data

  • Products purchased.

  • Order value.

  • Order and return history.

Payment data

Payment data is processed by licensed payment service providers, and we do not store full bank card numbers.

Account data

  • Username.

  • Password (in encrypted form).

  • Preferences and wishlist.

Technical data

  • IP address.

  • Device type.

  • Browser type.

  • Cookies.

Marketing data

  • Preferences for receiving marketing messages.

  • Interaction with advertising campaigns.

4. How we collect your data

We collect your personal data in several ways, including:

  • Creating a new account.

  • Completing a purchase.

  • Subscribing to newsletters.

  • Contacting customer service.

  • Using cookies.

  • Data received from payment or shipping companies.

5. Why we use your data

We use your personal data for the following purposes:

  • Fulfilling orders and completing purchases.

  • Processing payments.

  • Providing technical support and customer service.

  • Sending marketing offers after obtaining your consent.

  • Meeting tax and regulatory requirements.

  • Detecting fraud and strengthening the security of the store.

6. Who we share your data with

Your data may be shared with:

  • The MEEC platform hosting the store.

  • Payment service providers.

  • Shipping and delivery companies.

  • Hosting and analytics providers.

  • Relevant government authorities when required by law.

7. Transferring data outside Saudi Arabia

Some personal data may be processed outside Saudi Arabia when we use cloud services or global service providers.

In such cases, we apply the safeguards approved by the Saudi Data and Artificial Intelligence Authority to ensure an appropriate level of protection for your personal data.

8. Data retention period

We only retain personal data for as long as needed to fulfil the purpose it was collected for. Examples include:

  • Keeping order records and invoices for the periods required under Saudi regulations.

  • Keeping account data for as long as the account remains active.

  • Deleting marketing data when a subscription is cancelled.

  • Deleting or anonymising data once it is no longer legally needed.

9. Your rights under the Personal Data Protection Law

As a user of the store within Saudi Arabia, you have the following rights:

  • The right to know how your data is processed.

  • The right to access your personal data.

  • The right to correct inaccurate data.

  • The right to request the deletion of data once it is no longer needed.

  • The right to obtain a copy of your data.

  • The right to withdraw consent for processing at any time.

  • The right to file a complaint with the Saudi Data and Artificial Intelligence Authority if your rights are violated.

You can exercise any of these rights by contacting us using the contact details provided in this policy. We will respond within 30 days, in line with the timeframe set by the law.

10. How we protect your data

We apply a set of security measures to protect personal data, including:

  • Encrypting data during transfer.

  • Restricting access to authorised staff only.

  • Using secure hosting.

  • Regularly reviewing access permissions.

  • Training staff on data protection.

In the event of a breach that may affect customer data, we commit to notifying the relevant authorities and customers within the timeframes set by law.

11. Cookies

We use cookies to:

  • Keep you logged in.

  • Remember the contents of your shopping cart.

  • Analyse store performance.

  • Personalise marketing offers with your consent.

You can manage cookies through your browser settings or through the cookie management window on the site.

12. Children’s privacy

Our services are intended for individuals aged 18 or over. We do not knowingly collect data from children without the consent of a parent or legal guardian. If we become aware that we have collected such data without proper consent, we will delete it as soon as possible.

13. Updating this privacy policy

We may update this policy when changes occur to our services or to the regulations governing personal data protection. The updated version will be posted on this page along with the date of the latest update. We may also notify customers of significant changes by email or through notifications inside the store.

14. Contact and complaints

If you have any questions or requests related to your personal data, you can contact us via:

  • Email: [Email Address]

  • Phone: [Phone Number]

You also have the right to file a complaint directly with the Saudi Data and Artificial Intelligence Authority if you believe your data has been processed in violation of the law.


How to publish your store privacy policy on the MEEC platform

Once you have finished customising the template, we at the MEEC platform recommend the following steps before publishing:

  • Prepare two versions of the privacy policy, one in Arabic and one in English, with the Arabic version treated as the primary reference.

  • Create a dedicated privacy policy page within the store and link to it from the footer of every page.

  • Add a link to the policy at every point where data is collected, such as the registration page, the checkout page, and the newsletter signup form.

  • Provide a working communication channel to receive customer requests related to their personal data.

  • Review the privacy policy every 6 to 12 months to keep it aligned with any updates or new guidelines issued by the Saudi Data and Artificial Intelligence Authority.

Common mistakes to avoid

When drafting your store privacy policy, steer clear of the following mistakes:

  • Publishing the policy in English only without an Arabic version.

  • Pre-ticking the box for consent to marketing messages.

  • Copying a GDPR-compliant privacy policy without adapting it to PDPL.

  • Failing to provide a clear channel for personal data requests.

  • Leaving data retention periods vague instead of setting clear timeframes aligned with Saudi regulations.

Building a privacy policy that complies with the Saudi Personal Data Protection Law (PDPL) is more than a legal obligation. It is a key element in earning customer trust and strengthening the credibility of your online store. The clearer, more transparent, and more accurate your policy is in reflecting your actual data practices, the more your customers will trust you and the lower your legal risk will be.

Make it a habit to review your privacy policy regularly and update it whenever you add new services or change the way data is processed. Always refer to the official guidance issued by the Saudi Data and Artificial Intelligence Authority to make sure your privacy policy template store continues to meet the law.