A PDPL-Compliant Privacy Policy for Your Online Store
What your privacy policy must disclose, and how to get it right before you collect a single customer's data.
Every online store in the Kingdom collects personal data: name, mobile number, email, address, order history, and payment details. Since the Personal Data Protection Law, issued by Royal Decree M/19 and its amendments, came into force, any entity that controls such data must tell its customers what it collects, why, and how it protects it. The instrument for doing this is the privacy policy published on your store.
The authority overseeing the law is the Saudi Data and Artificial Intelligence Authority (SDAIA). It issues the implementing regulations, monitors compliance, and handles violations. A good privacy policy is not a formality. It is a legal document that proves you are a compliant controller, shields your store from liability, and builds customer trust.
This guide explains what your store's privacy policy must disclose, the penalties for non-compliance, and gives you a ready bilingual snippet to build on. Sighaty's D-03 template (Privacy Policy) provides the full certified document.
Get the D-03 Privacy Policy templateThe law and the regulator
The Personal Data Protection Law, issued by Royal Decree M/19 and its amendments, is the framework that governs the collection, processing, and storage of individuals' data in the Kingdom. It applies to any processing of data of persons residing in the Kingdom, including processing carried out from abroad. The law distinguishes between the controller, who determines the purposes and means of processing, and the processor, who processes data on the controller's behalf.
As an online store owner, you are most often a controller, because you decide what data is collected and how it is used. This places the primary compliance responsibility on you before SDAIA, the Saudi Data and Artificial Intelligence Authority charged with overseeing the law, issuing its implementing regulations, and monitoring compliance.
What your privacy policy must disclose
A PDPL-compliant privacy policy must be clear and easily accessible, and must cover at least the following elements:
- Controller identity: the legal name of the store or company and official contact details.
- Data collected: name, mobile number, email, address, order history, and payment details.
- Purposes of processing and their legal basis: fulfilling the order, providing the service, improving the experience, or a legal obligation.
- Sharing disclosure: with whom data is shared (shipping companies, payment gateways, service providers).
- Retention period: how long data is kept and how it is destroyed once the purpose ends.
- Transfers outside the Kingdom: whether data is transferred or stored abroad and the controls applied.
- Security measures: the technical and organizational steps protecting data from leakage or unauthorized access.
- Data-subject rights: the rights to be informed, to access, to obtain a copy, to correct, and to erase.
- Contact and complaint channel: a clear way for the customer to exercise rights or file a complaint.
The data subject's rights
The law grants every customer a set of rights, and you must enable their actual exercise, not merely list them. Make your policy explain how the customer exercises each right and within what timeframe you respond.
- The right to know the legal basis and purpose for collecting their data.
- The right to access their data and obtain a copy in a readable format.
- The right to correct, update, or complete inaccurate data.
- The right to request erasure of their data once the purpose for processing it has ended.
- The right to withdraw consent at any time where processing is based on it.
Penalties for non-compliance
The law is not advisory. Violations carry substantial financial penalties set by SDAIA according to the gravity of the breach. Enforcement may begin with a warning, and financial penalties can reach high amounts in serious cases.
- A fine of up to 5 million riyals for offenses involving disclosure of sensitive data, with possible doubling on repetition.
- A fine of up to 3 million riyals for other violations of the law.
- A warning may suffice for less serious violations before a fine is imposed.
Beyond the fine, any leak or misuse incident damages your store's reputation and customer trust, a loss that may exceed the financial penalty itself.
Steps to publish a compliant privacy policy
- Inventory every piece of personal data your store actually collects, from sign-up through post-delivery.
- For each data type, define the purpose of collection, its legal basis, and its retention period.
- List the parties you share data with and confirm protective controls are in place with them.
- Draft the privacy policy covering every required disclosure element, or use the certified D-03 template.
- Publish the policy in a visible, easily accessible place on the store, and link it to the checkout and sign-up pages.
- Review the policy periodically and update it whenever your data, services, or SDAIA regulations change.
The data-subject rights sentence
لك الحق في العلم بمعالجة بياناتك والوصول إليها والحصول على نسخة منها وتصحيحها وطلب إتلافها وسحب موافقتك.
You have the right to be informed of the processing of your data, to access it, to obtain a copy, to correct it, to request its erasure, and to withdraw your consent.
This is the rights sentence alone, for illustration. The full policy, with the controller, purposes, sharing, retention, transfers and marketing sections, is in template D-03.
Frequently asked questions
Is a privacy policy mandatory for every online store?
Yes. As long as your store collects any personal data of persons residing in the Kingdom, you are a controller subject to the PDPL and must tell customers what you collect and why. The absence of a clear privacy policy is a violation exposing you to SDAIA enforcement.
What is the difference between a controller and a processor?
The controller is the party that determines the purposes and means of processing data, and as a store owner you usually fall into this category. The processor is the party that processes data on your behalf, such as a hosting provider or payment gateway. Primary compliance responsibility rests with the controller.
What is the penalty if sensitive data leaks from my store?
The fine for offenses involving disclosure of sensitive data reaches up to 5 million riyals, with possible doubling on repetition, while penalties for other violations reach up to 3 million riyals. SDAIA may suffice with a warning in less serious cases. To this is added the harm to your reputation and customer trust.
Is it enough to copy a ready privacy policy from another store?
No. A privacy policy must accurately reflect the data your specific store collects, the purposes of processing, and the parties you share it with. Copying a policy that does not match your actual activity can make it misleading and legally invalid. Use the certified D-03 template and adjust its fields to match your store.
This guide was prepared and reviewed by a lawyer licensed in the Kingdom. The content is general guidance, not legal advice; consult a licensed lawyer for your specific case. Where an Arabic and an English text exist, the Arabic text prevails.