Saudi Arabia's Personal Data Protection Law has been fully enforceable since September 2024, and its regulator, SDAIA, confirmed 48 enforcement decisions in its January 2026 announcement. Marketing sent without consent is one of the violation categories it named. The UAE has its own data protection law too.
So we asked a simple question: when you open a Gulf business website, does it ask before it tracks you?
How we measured
We loaded each homepage once in a real browser (Puppeteer) and recorded every cookie set and every third-party tracker loaded. For each site we checked three things:
- whether any tracker fired before the visitor made a choice,
- whether a consent banner appeared at all,
- whether Google tags sent a Google Consent Mode v2 signal.
Sites that blocked the scanner were marked inconclusive.
Saudi Arabia: 1,556 online stores (September 2026)
- 935 (60%) run trackers and show no consent banner at all. The visitor is simply never asked.
- 1,065 (68%) start tracking before the visitor makes any choice.
- 751 (48%) run Google Analytics or Tag Manager with no Consent Mode v2 signal.
- Google Analytics runs on 920 stores (59%), Meta Pixel on 452 (29%).
UAE: 547 business websites on .ae (October 2026)
- 279 (51%) run trackers with no consent banner.
- 287 (52%) track before any choice.
- 223 (41%) run Google tags with no Consent Mode signal.
The two samples are different populations (stores vs business websites, and the UAE list covers only part of the .ae namespace: every domain in it starts with a digit or the letter "a"), so we don't rank the countries. Each number stands on its own.
Why "no banner" is the headline
Most consent debates in Europe are about banner design: dark patterns, a missing "Reject all" button. In the Gulf the problem comes earlier. On most sites there is no banner to design. The visitor's first page view already sends data to Google and Meta.
Why it matters for the businesses themselves
Under Google Consent Mode v2, tags that run without a consent signal can lose measurement and ad features for traffic from regions where consent is required. Under the Saudi law, fines go up to SAR 5 million, SAR 10 million for repeat violations. A banner alone doesn't fix it either: the tags have to wait for the answer, and the business has to keep a record of the choice.
What the scan cannot see
Homepage only, client-side only: no checkout pages, no server-side processing, no contracts or internal procedures. A low score is a signal about consent at the storefront, not a legal finding. We name no site and publish no store-level results.
Check it yourself
Both datasets are open (CC BY 4.0) with DOIs:
- Saudi: 10.5281/zenodo.23053713 · report: arqam360.com/ksa-compliance-index
- UAE: 10.5281/zenodo.23109874 · report: arqam360.com/uae-compliance-index
Disclosure: I'm the founder of Arqam360, which makes consent software for Gulf businesses. That's why we built the scanner, and why we publish the data openly so anyone can check it. This article was written with an AI assistant from our data and method.
— Taha Farhane, Founder, Arqam360. Former lead auditor in technology, processes and data privacy.
Top comments (3)
the puppeteer methodology is what sells this for me. testing whether a tracker actually fires before the visitor chooses is way more honest than just counting banners.
the 48% running GA with no consent mode signal is the stat i would pin on a wall. google's own docs say those hits get degraded, so a lot of these sites are paying the privacy cost and quietly losing the measurement anyway.
one thing worth pushing on: homepage-only scans miss the worst of it. checkout and pricing pages usually add two or three more pixels nobody audited. your numbers are probably a floor, not a ceiling.
honest question: do you think enforcement comes from regulators first, or from google quietly degrading unconsented traffic until the data is not worth keeping? i built cloudline as cookieless analytics (one script tag, no cookies, so no banner needed) because i got tired of watching sites choose between compliance and knowing their numbers.
@omyvnss thanks, agreed on the floor point. Homepage only, one visit, no clicks, so checkout and thank-you pages (where purchase pixels usually sit) aren't counted. The real rates are likely higher.
On enforcement: for Gulf traffic I'd bet on the regulator first. Google's Consent Mode requirement is tied to EEA/UK users, so a Saudi store serving Saudi visitors doesn't feel that pressure today. SDAIA, on the other hand, confirmed 48 enforcement decisions in January 2026, and marketing without consent is one of the categories it named.
Cookieless analytics helps on the measurement side, but most of the stores we scanned also run ad pixels (Meta Pixel on 29% of the Saudi sample), and those still need a choice before they fire. That's the gap we look at.
the regulator-first argument is convincing. google's consent mode pressure doesn't reach saudi traffic, but SDAIA is local and already has 48 decisions out. and fair on the ad pixels, cookieless only fixes the measurement half. has SDAIA said what those decisions actually covered? knowing whether it was tracking pixels or just spammy marketing emails would tell you where the risk really sits.