Abstract
In recent years, electronic commerce (e-commerce) platforms catering to Saudi users have experienced significant growth. Analyzing the privacy policies of these platforms is crucial to ensure data protection and transparency for Saudi users, especially in light of Saudi Arabia’s Vision 2030. However, existing studies on these platforms are limited in scope and fail to address key dimensions comprehensively. This study investigates the current state of privacy policies across 500 e-commerce websites serving Saudi users. The analysis focuses on policy availability, language, readability, and compliance with Saudi Arabia’s Personal Data Protection Law (PDPL). The findings reveal that 19.40% of websites lack privacy policies, and 2.01% fail to provide an Arabic version. On average, the privacy policies are lengthy, with approximately 981 words and 115 sentences, and are written in complex language that is difficult for users to understand. This study also identifies gaps in compliance with the PDPL, particularly in clarifying how data is collected and processed, and in explaining user rights. This study highlights the need for clearer, more accessible, and legally compliant privacy policies to enhance user trust and data protection.
1. Introduction
In recent years, Saudi Arabia has witnessed significant growth in electronic commerce stores [1,2]. These stores and platforms have become essential to the daily lives of Saudi consumers. According to the annual report issued by the Saudi Ministry of Commerce in 2024 (https://mc.gov.sa/ar/About/Statistics, accessed on 1 March 2026), approximately 40,913 e-commerce businesses were registered by the end of the year. With this growth, the ministry has paid close attention to protecting the users of these stores. The Ministry requires store owners to take security measures to protect user data. Providing a clear and detailed privacy policy is one of the most important requirements.
These privacy policies are legal documents that outline how online platforms collect, process, and protect user data [1,3,4,5,6,7]. With increasing privacy awareness in the digital world, these policies have become critical tools to help users understand their rights and obligations regarding their data. Clear and accessible policies help to build trust between users and online platforms and encourage these users to make more informed decisions.
These privacy policies have become a requirement not only in Saudi Arabia by law but also according to international regulations. In the European Union, the General Data Protection Regulation (GDPR) sets strict requirements for how platforms collect and process personal data [8,9]. In the United States, the California Consumer Privacy Act (CCPA) requires platforms to disclose their data practices to consumers [10,11].
Despite these regulatory efforts globally and locally, privacy policies are usually written differently across platforms and stores [3]. These differences are not limited to the length and complexity of the text, but also extend to how transparently platforms process user data and make their rights clear [12,13]. Studies across different domains and countries have shown that there are clear differences and shortcomings in their availability, readability, and compliance with specific regulations (e.g., GDPR) [12,14,15]. As a result, users find it difficult to fully understand their rights and obligations, especially when using multiple websites simultaneously.
Analyzing these policies can reveal the similarities and differences, and assess how clear and understandable they are to users. Through this analysis, gaps in these policies can be identified. This analysis may involve the language used, its transparency, and its compliance with local laws, such as the Saudi Personal Data Protection Law (PDPL).
While the literature has focused on analyzing privacy policies across domains such as e-government and banking [16,17], the field of e-commerce remains unexplored. Specifically, there is limited research investigating the privacy policies of e-commerce platforms serving Saudi users [18]. This is a significant gap given the rapid growth of e-commerce in Saudi Arabia under Vision 2030 and the increasing reliance on and widespread adoption of these platforms. Previous studies have identified policy availability, readability, and legal compliance as common challenges in privacy policies [14,15,19], yet these aspects remain unexamined for e-commerce platforms serving Saudi users. Therefore, this study aims to fill these gaps by answering the following research question:
RQ: What is the current state of privacy policies in e-commerce websites serving Saudi users in terms of availability, readability, and coverage of the requirements mandated by the Saudi Personal Data Protection Law?
To answer this question, the study begins by collecting 500 popular websites used by Saudi users, including both local and global platforms that serve the Saudi market. Then, it analyzes their privacy policies, focusing on several key factors, including availability, accessibility, presentation, and readability. Furthermore, it analyzes their coverage of the requirements outlined in the PDPL, particularly Article 12, which mandates platforms to adopt and publish a clear privacy policy.
By answering this research question, the study contributes to the existing literature by:
- Conducting a comprehensive analysis of privacy policies across 500 e-commerce websites serving Saudi users, a sector that has received limited academic attention compared to banking and e-government domains. By focusing on this rapidly growing industry under Vision 2030, the study provides a representative dataset that highlights the unique challenges and opportunities of the Saudi e-commerce landscape.
- Providing an in-depth analysis of Arabic privacy policies by evaluating their general characteristics (availability, location, language, updates, and formatting), textual patterns, readability, and compliance with PDPL.
- Identifying gaps and areas for improvement to support the development of clearer and more compliant privacy policies for e-commerce platforms serving Saudi users.
2. Background and Related Work
2.1. Definition of Privacy Policy
A privacy policy is a legal document that outlines how an organization or company gathers, processes, and shares the personal data of customers [1,3,4,5,6,7]. Several studies have shown the connection between privacy policies and other important factors in the current digital environment [20]. It has been observed that privacy policies are not just a legal requirement, but also a tool for building trust with customers [21]. Clear privacy policies can increase user trust.
2.2. Privacy Policies in Saudi Arabia
Privacy policies play a major role in informing users of their rights and obligations [3], and Saudi Arabia is well aware of this importance. This importance is highlighted by Article 12 of the Personal Data Protection Law (PDPL) (https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataProtectionLaw.pdf, accessed on 1 March 2026), which was released in 2021 and enforced in 2023. The PDPL is the main data protection law in Saudi Arabia and applies to any entity that processes the personal data of individuals residing in the Kingdom, regardless of its location. In its 12th article, it requires that the controller (the entity handling user data) adopt a privacy policy and make it available to the data subjects (users) before data collection is undertaken. This policy must explicitly detail the purpose of the data collection, the type of data collected, and the methods used to collect, process, store, and destroy such data, in addition to defining the rights of users and the mechanisms for exercising them.
By focusing on the field of e-commerce in accordance with the Saudi Ministry of Commerce guidelines (https://mc.gov.sa/ar/ECC, accessed on 1 March 2026), privacy policies must be prominently displayed and available on all e-commerce platforms. These policies are essential to protect customers, support Vision 2030 growth, and build customer trust.
2.3. Privacy Policy Research
Privacy policies have received significant attention from the research community and have been studied from many perspectives. This includes studies on user behavior, policy design, and linguistic complexity. Studies have also covered topics such as accessibility, readability, and compliance with relevant laws.
2.3.1. User Behavior and Design in Privacy Policies
Studies reveal that a high percentage of users do not read them due to their length, complexity, and the use of complex terminology [8,19,22,23]. A study conducted in 2020 [19] confirmed that a large percentage of European internet users do not read privacy policies for these reasons. Similar results have been reported in another study [8], which found that more than 50% of participants found it challenging to understand the policies due to the complex language and length of the documents. The results from a recent study further support these findings, showing that most users rarely or never read privacy policies, which leads to limited awareness of how their data is collected and used [22]. Additionally, in the field of e-commerce, a study of users in Indonesia found that most participants are only interested in privacy policies when the website handles money or sensitive personal data [23].
Despite these challenges, multiple studies have found that policies have become longer and more difficult to read over time [15,19]. The large number of words and sentences in these policies is a burden on users, making them difficult to read or overwhelming [20,24]. Several studies have suggested that shorter policies are more effective at attracting the attention of users, thereby encouraging them to read the entirety of the content [8,15,19].
2.3.2. Analysis of Privacy Policy Availability and Legal Compliance
Early studies found a significant lack of privacy policies worldwide. In 2017, researchers conducted a study of 600 companies, including those listed on stock exchanges, such as the New York Stock Exchange (NYSE), the National Association of Securities Dealers Automated Quotations (NASDAQ), and the American Stock Exchange (AMEX) [14]. They found that 30% of these companies lacked privacy policies. Similarly, a study in South Asian countries (India, Pakistan, and Bangladesh) discovered that 103 of 284 websites lacked privacy policies, and in addition, it noted weak compliance with privacy regulations in those countries [12].
In the mobile payment services field, a study that analyzed the privacy policies of 54 services found that 44% did not provide privacy policies [25]. It was also found that half of the policies reviewed did not explain how user data was collected or stored. In another study conducted in 2021, on banks and mobile money services in the Middle East, it was discovered that all banks covered provided privacy policies, and that 17% of mobile money services lacked privacy policies [16]. These results indicate that banks are more compliant with privacy regulations than mobile money services. Additionally, in Gulf countries, a study analyzed the privacy policies of 183 websites belonging to major companies and found that only 26.8% of these websites contained a privacy statement [13].
These studies reveal a clear compliance gap, where the availability of a privacy policy does not necessarily mean full compliance with the privacy requirements. There are also differences between sectors, with the financial sector appearing to be more compliant than websites and public services.
2.3.3. Analysis of Privacy Policy Readability
Readability refers to measuring the ease of understanding a text or part of it by an average person [21,26]. Studies have shown that privacy policies are often written in complex language, making them difficult for users to understand, reducing their usefulness [15,19]. Several measures have been developed to assess readability; the Flesch Reading Ease [27] is one of the most widely used and has been applied by several researchers, such as [16]. This metric determines the level of education required to understand a text. The cloze test [28] is another measure that has been presented as an alternative to traditional tests [21]. This metric requires the user to interact directly with the text. In this test, the user is presented with text that has words missing, and they have to fill in the missing words. If the text is filled in correctly at 57% or above, it is considered appropriate for an adult independent reading level.
However, these measures were primarily designed and applied for English texts and privacy policies, thus reducing their accuracy when applied to other languages, such as Arabic, due to language differences [16,29]. Researchers have attempted to adapt these metrics or develop new ones that are suitable for Arabic texts. One of the most notable efforts was made by the researchers in [29], who modified general metrics such as the Automated Readability Index (ARI) and the Lesbarhets Index (LIX) in order to better suit Arabic text.
2.3.4. Privacy Policy Research in Saudi Arabia
Regarding privacy policy studies conducted in Saudi Arabia, there is a noticeable lack of research compared to global studies, particularly in the field of e-commerce. The majority of these studies have focused on social media applications [30,31,32]. For instance, a study conducted on Snapchat users showed interesting results, where the knowledge of users of the privacy policy did not have a significant impact on their concerns about their privacy. Rather, it prompted them to take action to protect their privacy [30]. It also showed that social influence increases privacy concerns, but does not drive users to take proactive action. In another study, users had difficulty reading the privacy policies of apps like WhatsApp and Telegram; they suggested replacing legal texts with attractive icons, graphics, and colors, and offering the policy in both Arabic and English [33]. Furthermore, a study focused on students noted a significant lack of interest in reading terms and conditions among those who use social media, highlighting the need to promote awareness of the importance of reading and understanding privacy policies [31].
Additionally, studies focusing on analyzing privacy policies across websites and platforms are also limited compared to global studies. Researchers at [18] examined 723 popular websites in Saudi Arabia (6% of which were e-commerce sites) in order to assess their compliance with informing visitors about their use of cookies and clarifying their privacy policies. Their results showed that the majority of websites (85%) use cookies and do not provide policies or banners for visitors, and that 39% lack clear policies. Another study provided a dataset that contains the privacy policies of various organizations in Saudi Arabia [34]. This dataset contains multiple policies from different sectors; for each policy, only the first page was collected, which was then split into smaller text parts and labeled with the 10 principles of the PDPL. This represents an important step toward supporting quantitative analysis in this field.
This review shows that most of the previous studies have focused on the availability of privacy policies and formal compliance with laws. However, there is a clear lack of studies in Saudi Arabia that analyze Arabic-language privacy policies, especially in the e-commerce sector, and quantitatively assess their readability using specialized metrics.
3. Methodology
To answer the research question, this study followed a multi-phase methodology, as shown in Figure 1. These phases included data collection and extraction, data cleaning and validation, and data analysis. During this study, a non-probability purposive sampling approach was used, as the websites analyzed here were intentionally selected based on specific criteria (described in detail in Section 3.1).
Figure 1.
Methodology Framework of the Study.
This methodology was executed on a MacBook Air (Apple Inc., Cupertino, CA, USA) with an M1 chip and 8 GB RAM, running macOS Sequoia 15.2. Google Sheets was used for manual data collection, and the data were exported in CSV format for analysis. This manual extraction was necessary, as the extracted data required human judgment and contextual understanding that cannot be reliably automated. For automated text processing and analysis, Python (Version 3.12.2) was used in a Jupyter Notebook (Version 7.0.8) environment with libraries such as the Natural Language Toolkit (NLTK) and Scikit-learn. Additionally, the OSMAN (Open Source Metric for Measuring Arabic Narratives) tool (2020 release), proposed in [29], was used to calculate the readability of the privacy policies. OSMAN was selected here because it is specifically designed for Arabic text and provides readability metrics adjusted to this language, unlike traditional readability metrics and tools, which were developed for English and are not suitable for Arabic.
3.1. Phase 1: Data Collection and Extraction
The data for this study was collected from December 2024 to February 2025. This timing is crucial, as it comes more than a year after the official enforcement of the PDPL in 2023, as explained earlier. This provides sufficient time for websites to adapt to the regulatory requirements. To collect and extract the data, several steps were followed, starting with identifying the websites and then extracting the required data.
For the website identification and selection, the study targeted 500 e-commerce websites serving Saudi users, including both local and global platforms. However, the majority were local platforms, as reports reveal that 93.1% of Saudi online shoppers purchase from local stores [35]. This sample size was determined according to Roscoe’s rule of thumb [36], which suggests that sample sizes ranging from 30 to 500 are appropriate for most research. Therefore, the 500 websites were selected to ensure a large and representative sample. Each of the selected websites had to be an active e-commerce platform selling products or services, serve Saudi users, and have a website, rather than just operating through social media pages.
These websites were identified through Google search and social media platforms (X (formerly Twitter), Instagram, and TikTok), as these platforms are among the most widely used in Saudi Arabia [35]. Here, Arabic keywords related to various e-commerce categories were used to identify the websites and stores (e.g., dresses, electrical appliances). Websites appearing at the top of search results were prioritized, as higher-ranking results are generally more visible and more likely to be visited by Saudi users [37]. Additionally, popular stores recommended and discussed by Saudi users and Saudi-focused review accounts on social media were also included. These identified websites were then manually classified into nine main e-commerce categories based on the types of products or services they offer, as shown in Table 1. These categories reflect the most popular online shopping sectors in Saudi Arabia. For example, fashion and clothing represent the largest share (35.2%), followed by health, beauty, and personal care products (23.2%). This is consistent with the reports showing that clothing and shoes are the most purchased products online in the Kingdom at 89.5%, followed by cosmetics at 47.2% [35].
Table 1.
Distribution of E-commerce Websites by Category.
After identifying the websites, the dataset creation and data extraction process began. Each of the 500 selected sites was visited individually, and all relevant information was recorded in the Google Sheets spreadsheet created specifically for this study. Multiple fields were manually collected via direct site inspection, as shown in Table 2.
Table 2.
Description of Data Fields Extracted from E-commerce Websites.
3.2. Phase 2: Data Cleaning and Integrity Validation
To ensure the quality and reliability of the dataset and the extracted data, multiple validation and cleaning procedures were performed. First, the legal status of each e-commerce website was verified through the Saudi Business Center (https://business.sa/ar/eservices/details/3fd371e5-11de-4078-08cf-08dbf015747a, accessed on 1 March 2026), which is the official platform for commercial registration. This verification process required searching the platform database for the store name, URL, or commercial registration number (usually provided on the website itself). Any website that could not be verified was excluded and replaced by another one from the same category.
Second, the dataset was reviewed to identify any duplicate websites. When duplicates were discovered, only the website with the most complete information was retained. The removed duplicates were replaced with new websites from the same category (verified via the Saudi Business Center). Additionally, the full text of the privacy policies was reviewed to ensure that the entire policy text was extracted.
Furthermore, to validate the reliability of the extracted data, which consists of 500 websites and 14 fields (7000 data points), several techniques, such as logical rules, completeness analysis, and Natural Language Processing (NLP), were applied. The overall data completeness rate was 88.40%. Here, the empty cells were not caused by errors; however, since some websites did not provide a privacy policy, their related fields, such as URL, location, style, and full text, were naturally left empty. Additionally, to check whether the data was entered correctly, 14 logical rules (if-then rules) were tested. For example, if a website was recorded as having no privacy policy, then the fields URL, location, used term, and full text should be empty. Similarly, if a website was recorded as having a policy, then these fields should contain data. In addition, if the policy was marked as accessible, then the full text should be included, and if not, the field should be empty. Here, the overall consistency score was 99.7%. An NLP technique was used to verify that the extracted texts were actual privacy policies. Each text was compared with a set of common privacy policy keywords in both Arabic and English. Out of the 391 available texts, 99.7% matched the expected privacy policy content, which confirms that the extracted texts were actual privacy policies, rather than other content extracted by mistake or retrieved by entering the wrong page.
3.3. Phase 3: Data Analysis
The final dataset of the websites and their available privacy policies was investigated and analyzed through a multi-stage process. This process began with analyzing general characteristics (e.g., policy availability, location, terminology, update information, and presence of a link during registration), followed by text analysis and a readability assessment, and concluded with an evaluation of compliance with the PDPL requirements. These dimensions were selected as they are consistently identified in previous privacy policy studies as essential aspects for evaluating policy quality and accessibility [12,14,15,18,19,21,25].
3.3.1. Analysis of General Characteristics
For the general website characteristics, descriptive statistics were calculated. Specifically, percentages and frequencies were used to summarize the following:
- The overall privacy policy availability rate.
- The distribution of policy locations across websites.
- The availability of privacy policy links during registration.
- The frequency of different terminology usage.
- The Arabic language availability percentage.
- The presence of the last update information.
- The formatting used when writing the policies. This included checking the use of headings, colors, and other formatting elements, such as bullets or numbering.
3.3.2. Analysis of Privacy Policy Texts
The full texts of the available privacy policies were analyzed in this step. Here, an automated text analysis was performed using Python 3.12.2 and the OSMAN tool [29]. Initially, the OSMAN tool was used to count the words and sentences. During this step, each policy text was manually entered into the tool to calculate the required statistics. The results were then recorded and added to the dataset to be combined with the previous variables.
Following this step, Python was used with specialized libraries to identify and extract the most common words and sentences in the privacy policies. Specifically, the NLTK library was used for text preprocessing, tokenization, and stop word removal, and Scikit-learn was used for Term Frequency-Inverse Document Frequency (TF-IDF) vectorization and K-Means clustering. This was done to explore the primary focus of the policies and to identify any patterns of similarity.
First, before analyzing individual words, the texts underwent preprocessing steps following the procedures described by Del Alamo et al. [38] for automated policy analysis. The texts were cleaned by removing non-text characters and punctuation, and were split into tokens to enable analysis. Next, a normalization step was applied by removing the definite article “Al” from words containing five or more letters (e.g., normalizing “Al-byAnAt” to “byAnAt”). Afterward, stop words (e.g., ‘alY’ and fI) were excluded to retain only important words. This step was performed using the standard NLTK library list, combined with the Al-Refaie list [39], yielding an exclusion list of 902 words.
For the sentence and paragraph analysis, the focus was on identifying text shared across at least two different websites. This was done to determine whether the websites rely on duplicate policies and ready-made templates, or on unique policies designed specifically for them and their activities [3,40]. Unlike in word analysis, stop words were included here to maintain the context of the text. The policies were broken down into separate sentences based on punctuation marks (., ?, !, ;), and blocks of paragraphs separated by new lines were extracted.
Additionally, clustering analysis was performed to move beyond simple frequency counts and uncover the similarities within the policies. This process involved transforming the text data into numerical vectors using the TF-IDF technique. This method was selected as it has been proven to be one of the most effective for Arabic document clustering [41]. Afterward, the K-Means algorithm was applied to group the policies, as it is the most widely used method for document clustering [41]. The optimal number of clusters was determined here at based on the Silhouette Score metric. This approach enabled the identification of common templates across the different websites.
3.3.3. Analysis of Readability
As highlighted in the literature, privacy policies are often written in a complex and legal language that is difficult for users to understand. Therefore, measuring the readability of Arabic policies is essential to ensure that they are written in simple and easy language for the average Saudi user. In this phase, two language-independent metrics were used to measure the readability: the Lesbarhets Index (LIX) [42] and the Automated Readability Index (ARI) [43]. These metrics were implemented using the modified equations and the OSMAN tool proposed by [29].
- Laesbarheds Index (LIX): This index was used to assess the readability of texts based on the length of both sentences and words [42]. The score from this index indicates the difficulty of the text. The higher the LIX value, the more complex the text is to read. Texts with a value above 60 are considered complex and require a high level of education. This index was measured as follows:whereA: The total number of words in the text.B: The total number of sentences in the text (to determine sentence length).C: Number of long words (more than 6 letters).
- Automated Readability Index (ARI): This index is used to assess the readability of texts based on the number of characters (to estimate word complexity) and the number of words and sentences in the text [43]. The score from this index indicates the level of education required to understand the text. The higher the ARI value, the higher the level of education needed to comprehend the text. This index was measured as follows:whereE: Number of characters in the text.A: Number of words in the text.B: Number of sentences in the text.
To implement these metrics, the complete Arabic text of each privacy policy was entered individually into the OSMAN tool interface. After processing the text characteristics, the tool generated scores for both the LIX [42] and ARI [43] measures. These calculated values and results were then recorded and added to the dataset to be combined with the previous variables.
3.3.4. Analysis of PDPL Requirements Coverage
After assessing the readability of the privacy policies, this phase analyzed their coverage of the requirements of the PDPL, especially Article 12. As explained previously, Article 12 requires the controller to provide a clear privacy policy. This policy must include the purpose of the data collection, the content of the personal data to be collected, the methods of collection, storage, processing, and destruction, as well as the rights of users and how to exercise these rights.
A previous study [34] attempted to classify privacy policies based on 10 general PDPL principles. However, its classification had some limitations. It combined some concepts, such as data collection and processing, into a single category and only covered limited aspects of data subject rights. Furthermore, it overlooked some of the key Article 12 requirements, such as the purpose of data collection, company and contact information, and complaint submission mechanisms.
Therefore, to provide a more accurate assessment, the steps proposed and applied in the previous research were followed [12,16,25]. First, the guidelines for preparing and developing a privacy policy provided by the Saudi Data and Artificial Intelligence Authority (SDAIA) via the National Data Governance Platform (https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf, accessed on 1 March 2026) were reviewed. This guide outlines the basic elements to consider when developing privacy policies, based on the PDPL. The guide mentions 10 main elements. The elements include the name of the entity, its activity, and methods of communicating with them, the personal data that will be collected, the methods and purpose of collecting, processing, sharing, and storing data, the duration of retention and destruction of personal data, the rights of personal data owners, the mechanism for submitting complaints, and making the policy available and easy to access. Based on these guidelines and elements, 12 elements were identified. This was done by separating some of the elements that were combined in the guide. For example, the entity name and its contact information were treated as separate elements, and data collection, processing, sharing, storage, and destruction were also separated. This separation was necessary to simplify the search and analysis processes. For each element, a set of initial keywords and phrases reflecting its core concepts was identified [16], as shown in Table 3.
Table 3.
Initial Checklist of PDPL Required Elements.
These initial keywords and phrases were used to analyze the privacy policies. This process was automated using Python. Each privacy policy was scanned for the identified keywords. If any of the keywords or phrases were found in the text during the analysis, the policy was considered to cover that element. Additionally, we calculated the coverage percentage for each privacy policy. Finally, to ensure that the results were accurate and covered all keywords and phrases that can be used in privacy policies, the following steps were followed:
- 10% of the sites were randomly selected for a manual review of their privacy policies. This percentage falls within the recommended range of 10% to 20% for reliability subsamples in content analysis studies [44].
- During this manual review, additional terms and phrases were identified that were not in the initial list, such as “other party” and “how long we hold your personal information”.
- The new terms and phrases were added to the checklist to ensure complete coverage.
- After updating the checklist, the policies were re-analyzed for more accurate results.
4. Results and Discussion
4.1. General Characteristics of Privacy Policies
As shown in Figure 2, the majority of the websites (403 out of 500) provide privacy policy links. This practice demonstrates a growing awareness among website owners about the importance of transparency. This improvement can be attributed to the efforts of the Saudi Ministry of Commerce to promote the importance of privacy policies for online stores, and to increase the awareness of society about privacy and data protection issues. However, 19.40% of websites still lack privacy policies, which is a worrying issue, especially in light of the PDPL. Additionally, it was observed that of the seven websites offering plastic, cleaning supplies, and kitchenware services, two lack privacy policies, as shown in Figure 2. This percentage is high compared to other fields. Such non-compliance with the regulations raises concerns regarding the commitment of website owners to user rights. It is worth noting that this general lack of privacy policy is not new. As previously highlighted, a significant percentage of websites across various sectors lack privacy policies [12,13,14,25]. More effort is still needed to ensure full compliance across all websites.
Figure 2.
Availability of Privacy Policies. (a) Availability of Privacy Policies. (b) Availability of Privacy Policies by Category.
For the 403 websites that provide links to their privacy policies, the following characteristics were examined based on the presence and position of the link, regardless of the accessibility of its content. Firstly, when examining the location of privacy policy pages, Table 4 shows that the majority of websites (356) place the privacy policy link in the footer. This place is considered to be a common and familiar place for users. However, it is worth noting that a small percentage of websites (0.50%) engage in the negative practice of hiding links across multiple pages, making it difficult for users to access this important information. On the other hand, 11.16% of websites display the privacy policy link in additional locations, such as at the top of the page or in drop-down menus, which can improve the visibility and accessibility of the link.
Table 4.
Location of Privacy Policy Links (N = 403).
Additionally, as illustrated in Figure 3, only 28.04% of the websites provide a link to the privacy policy during the registration process. Access to the policy at this stage is crucial, as it enables users to understand how the site handles their data before submission. However, studies show that users rarely read privacy policies before registering [31,45]; still, making the policy available is a necessary step that gives users the opportunity to review this information if they wish [46].
Figure 3.
Availability of Privacy Policy Links During Registration (N = 403).
Regarding the terminology used to describe the privacy policy pages, Table 5 shows that “Privacy Policy” is the most common term. This terminology is widely used in the literature and in the guidelines of the Saudi Ministry of Commerce and the PDPL. However, the use of other titles, such as “Terms and Conditions” (used by 11 websites), may confuse users, especially if the title does not contain the word “Privacy.” Websites should adopt a unified terminology to facilitate user understanding and avoid confusion.
Table 5.
Most Commonly Used Titles for Privacy Policies (N = 403).
Through a more detailed analysis and examination of the general characteristics of the content and the links leading to these pages, it was observed that within 403 websites containing links to privacy policies, only four had non-functional links or links that led to empty pages. Accordingly, these sites were excluded from all following analyses, and 399 websites with privacy policies remained for the analysis.
Among the 399 websites providing privacy policies, 2.01% do not provide them in Arabic, as shown in Figure 4. Writing these policies in non-Arabic languages may create a significant barrier for Saudi users in knowing their rights and obligations, especially since Arabic is the official language of Saudi Arabia. Failure to provide the text in Arabic is a clear violation of the Saudi PDPL and the SDAIA guidelines for preparing and developing a privacy policy. The law requires that the contents of the policy be written in a clear, non-misleading, easy-to-read, and easy-to-understand language, suitable for the level of understanding of all categories of personal data subjects (users).
Figure 4.
Availability of Privacy Policies in Arabic (N = 399).
By focusing on privacy policy update information, the results in Figure 5 reveal that 358 out of the 391 websites that provide policies in Arabic do not provide any information about the last date their policies were updated. This absence may raise doubts about how the policies are updated and kept up to date with legislative or technological changes. This is a clear violation of the SDAIA guidelines for writing a privacy policy.
Figure 5.
Presence of Last Updated Information on Privacy Policies (N = 391).
Regarding the formatting styles in the available Arabic policies, it was observed that 64.45% of websites use bold headings to divide their privacy policies, while 25.58% use non-bold headings with a single color. Additionally, 9.97% of websites present their policies as plain text without any formatting effects such as highlighting or bolding. Using a single font and a single level of writing can make it difficult for users to read and understand, especially if they have reading or vision disabilities. Only 6.91% of the websites use additional presentation techniques in their privacy policies, such as colors (n = 22), highlighted headings (n = 2), boxes (n = 1), and hyperlinks (n = 1). These techniques are considered to be a good attempt by these websites to improve the presentation of the privacy policies and make them more attractive to the reader, but there is still a lot of room for improvement.
4.2. Analyzing the Texts of Privacy Policies
As previously discussed, 391 of the 399 websites had accessible Arabic privacy policies, and in this phase, the texts of these policies were analyzed. By focusing on the text length, as can be observed in Figure 6, the average privacy policy consisted of approximately 980.99 words and 114.52 sentences. The longest policy contained 6139 words and 648 sentences, while the shortest policy was only nine words in one sentence. Previous studies have confirmed that privacy policies of such length tend to be more complex and challenging for users to read and understand, which may reduce the effective awareness of data practices [8,15,19,20].
Figure 6.
Word and Sentence Statistics of Privacy Policies. (a) Distribution of Word Counts. (b) Average Number of Words per Domain. (c) Distribution of Sentence Counts. (d) Average Number of Sentences per Domain.
Before extracting the most frequently occurring words, the preprocessing stage resulted in the removal of 367 unique stop words. Among the words that were removed were common words such as ‘aw’ (11,657 occurrences), ‘alY’ (8494 occurrences), and ‘fI’ (8185 occurrences).
As shown in Figure 7 and Table 6, the results revealed that the most common words centered around the concepts of data and identity. The word “Information” emerged as the most frequently repeated word (appearing 5925 times in 379 documents), followed by the word “Personal” with 3626 repetitions in 371 documents, then the word “Data” with 3079 repetitions used in 283 documents. This repetition of the word “Information” may be due to its flexibility in describing different sets of data (such as contact and payment information). Additionally, this repetition highlights how policies tend to focus on describing what information is, rather than explaining how to manage it.
Figure 7.
Heatmap of the Top 20 Most Frequent Words across all Privacy Policies.
Table 6.
Top 20 Words by Document Frequency.
Furthermore, as shown in Figure 7, terms referring to the owning entity, such as “Website”, “Store”, and “Our website”, are repeated significantly. This repetition shows how websites focus heavily on their identity. Additionally, it can be noted that the absence of words focuses mainly on the users and their rights. Words such as “Delete”, “Modify”, or “Withdraw” did not appear among the top ranks, suggesting a lack of a clear, direct explanation of user rights.
Focusing on the average frequency of each word in each document, the analysis in Figure 8a shows that the word “Definition” has the highest frequency (an average of 9.89 times per document). This may be due to the existence of a complete section at the beginning of the policy called “Definitions,” and it being related to the term “Cookies”. This is confirmed by the repetition of the word “Files” (with an average repetition of 7.54). However, it should be noted that the frequency of the word “link” is relatively low, with an average of 1.90 repetitions.
Figure 8.
Word Frequency. (a) Average Word Frequency per Document. (b) Distribution of Word Occurrences Across Documents (Box Plot).
Additionally, as illustrated in Figure 8b, the box plot revealed many outliers (small circles) for terms such as “Your Information” and “Information”. Although the medians for these words are low (4.85 and 5.32, respectively), the outliers exceed 50 in some documents. These results confirm that there is significant inconsistency in the details of the policies. Several stores write very long, complex policies that use the same words repeatedly. Additionally, certain words, such as “Private/Specific”, “Mail”, and “Electronic”, appear infrequently, with low average frequencies (1.30, 1.52, 1.62). This indicates that these terms are used mainly for specific functional purposes, such as referencing email or electronic services, rather than being repeatedly used throughout the text.
When dividing texts into sentences based on punctuation (periods, semicolons, and question marks), the most frequently repeated sentences were identified. A total of 3637 common sentences were found. Table 7 shows one of the most common sentences that appeared on 35 websites. These results confirm that many stores rely on ready-made templates to draft their privacy policies and terms of use agreements.
Table 7.
The Most Frequent Sentence in Privacy Policies.
Additionally, for the text blocks (complete paragraphs that form independent thematic units), 542 common blocks that appeared identically on two or more websites were extracted (Figure 9). Although the number of common blocks may seem lower than the number of sentences, the size of these blocks reveals the depth of the copying phenomenon. The longest shared text block was 3975 characters (670 words), which was a huge legal text related to “security measures” that was copied word for word between two websites.
Figure 9.
Distribution of Text Block Reuse Across Websites.
Furthermore, the most common block was repeated across 35 websites (the same pattern observed in the sentence analysis), strongly indicating similarity. This means that stores are not just copying individual phrases but importing entire paragraphs, supporting the hypothesis that many websites rely on templates or generators to create their privacy policies, without any attempt to customize the content to reflect the actual practices of the store [40].
To verify the reliance of websites using ready-made templates, as observed during the sentence and block analysis, this study performed a clustering analysis using the K-Means algorithm and TF-IDF. When dividing the data into 32 clusters () (Figure 10), the results showed that the repetition previously observed in Table 7 (the sentence that appeared in 35 locations) was not just random copying, but part of a complete structural pattern. Specifically, the algorithm discovered a cluster of 37 identical documents (Cluster 3). This cluster is the primary source of that repeated sentence. A close examination of the content of this cluster revealed that it did not contain just one sentence, but an entire legal sequence, including “Article 5”, “Article 6”, and “Membership Cancellation” sections. This suggests that these stores copied the entire “Terms of Use” document and used it as their privacy policy. Although clustering alone cannot confirm intentional copying, the presence of identical documents in the same cluster, and the repeated legal terminology, supports the use of templates rather than independently written policies. This also explains the use of strict legal terminology, such as “Article”, as illustrated in Figure 11. While some standardization in legal language is acceptable and expected in privacy policies [3], the pattern observed here represents complete duplication, with the store replacing its privacy policy entirely with its terms of use agreement [6,40].
Figure 10.
Visual Distribution of Privacy Policy Clusters (K = 32).
Figure 11.
Top Keywords for the Contractual Model (Cluster 3).
These findings confirm that many e-commerce websites rely on repetitive and similar privacy policies. This is consistent with previous studies, which have found that many websites use copy-and-paste privacy policies without adapting them to their actual practices [3,40]. Additionally, researchers in [40] found and confirmed that some of the available generators for creating privacy policies use inflexible templates that are unsuitable for all applications and produce incomplete policies that fail to meet legal requirements. These vulnerabilities explain the widespread similarity observed in this study, as stores rely on automated tools rather than creating tailored policies that reflect their actual data practices.
4.3. Readability of Privacy Policies
Focusing on readability, Figure 12 shows that there is a similarity in the averages among the categories, ranging between 93 to 97 in the LIX index and 30 to 34 in the ARI index. For the LIX index, the results showed an average score of 95.34, with a high value of 119.05 and a low value of 82.20. As for the ARI index, the results showed an average score of 30.96, with a high value of 60.87 and a low value of 22.34. These results suggest that the policies presented to Saudi users are complex, and require a high level of education to comprehend them effectively. Specifically, an average user without higher education would find these policies extremely difficult to understand, as they are equivalent to technical or academic texts, which are far beyond the reading level of most everyday users. The complexity and difficulty of these policy texts are not new, and they are similar to those found in previous studies in other fields [12,16,25]. A study evaluating the privacy policies of Middle Eastern banks and mobile money services also found them to be challenging to understand [16].
Figure 12.
Average Readability by Domains.
Although sentence and word length may not directly correlate with readability, as illustrated in Figure 13 (which suggests no strong relationship between text length and readability level), long and complex sentences can hinder understanding [16]. This is especially true for Arabic, which has complex grammatical structures. Furthermore, the absence of diacritics is one factor that adds to this complexity [29]. In Arabic, texts that do not use diacritics can be challenging to understand and make it difficult to determine their intended meaning, especially with words that are similar but have different meanings [29]. The use of legal language and complex terminology has also made understanding these policies more challenging. Additionally, the reliance of websites on templates for privacy policies may be another contributing factor. While these templates make the process of creating policies easier, they may not always take into account the clarity and ease of understanding of the language for users.
Figure 13.
Relationship Between Policy Length and Readability (ARI & LIX).
4.4. PDPL Requirement Coverage of Privacy Policies
When assessing and analyzing the coverage of privacy policies regarding the requirements of SDAIA and PDPL, the results showed several interesting findings as illustrated in Figure 14 and Figure 15. The average compliance score was 45.50%, and the median was 41.67%. These scores indicate that the “average” website in Saudi Arabia only complies with less than half of the legal requirements. This average score points to a significant gap in full compliance. Nevertheless, it is worth noting that only four websites achieved a high coverage rate of 91.66%, and all of them belong to large, well-known companies. This high percentage reflects the strong commitment of these companies to the standards and laws of personal data protection.
Figure 14.
PDPL Requirement Coverage Percentage Distribution.
Figure 15.
Distribution of Compliance Percentage Across All Websites.
However, the results differed greatly when analyzing the detailed elements of the privacy policies, as can be seen in Figure 15. Here, 86.96% of websites provide information and details about the company, such as the company name, address, and website, which may explain the high repetition of words such as “Our site”. This is followed by information about data sharing, where it is worth noting that 84.65% of websites provide some information on data sharing using keywords such as “third parties” and “outside the Kingdom of Saudi Arabia”. These high percentages are consistent with the findings from previous studies, where third-party data sharing was among the most covered elements in privacy policies [12,25]. This is followed by contact information, the data to be collected, and data security (75.70%, 72.63%, and 68.29%, respectively).
Additionally, it can be noted that elements related to user rights and how data is collected and processed appear to be lower percentages: 27.11%, 24.81%, and 11.00%, respectively. This may explain why no information about user rights appears when searching for the most frequently used words. Finally, it can be noted that websites fail to provide information on how to file a complaint, which is a user right and a requirement under the SDAIA guidelines and PDPL. These results are consistent with those of [25], who found that 50% of policies do not inform users about what data is being collected and stored. Similarly, Javed et al. [12] found that user data accuracy and control (e.g., access, modification, and deletion rights) were among the least covered elements, with compliance rates as low as 34% in some regions. These gaps weaken the effectiveness of privacy policies and may reduce user confidence in the sites.
By focusing on the specific keywords and phrases used to express these basic required elements, the results show that terms expressing company information are repeated and used frequently and intensively (see Figure A1 in Appendix A). For example, outliers were recorded for the term “About Us”, which was repeated more than 50 times in a single policy. Similarly, the word “cookies” appeared more than 30 times in a single policy. This high frequency is mainly because cookies are mentioned both as a type of data and as a method for collecting data. However, the frequent use of the term does not necessarily indicate transparency or legal compliance. As reported in [18], about 85% of websites that use cookies fail to display banners to their visitors, highlighting a significant gap between what is stated in privacy policies and actual transparency practices. Although many organizations refer to “cookies” in their policies, they often fail to explain how they use cookies or fail to notify users properly. This aligns with our finding that compliance with the “how data is collected” requirement remains low (24.81%).
4.5. Key Findings
In summary, this study uncovered the current diverse status of privacy policies in terms of availability, readability, and PDPL compliance (Figure 16). The results revealed that the majority of e-commerce websites serving Saudi users provide privacy policies. However, 2.01% of them do not provide these policies in Arabic. Regarding the available Arabic policies, the readability analysis found that these policies remain complex and difficult for the average user to understand. This complexity violates the requirements of both the PDPL and SDAIA guidelines, which require policies to be simple and easy to understand. The use of legal language and the lack of diacritics in the Arabic text make the policies even harder to understand. Additionally, the analysis revealed a high degree of similarity between the policies. Several stores rely on ready-made templates when writing their own policies, which raises concerns about whether these policies accurately reflect the actual practices of the store.
Figure 16.
The Research Key Findings.
By analyzing the content in more detail, the results revealed that, despite the acceptable coverage of the basic elements required by SDAIA guidelines and Article 12 of the PDPL, many key elements still require improvement and careful review by legal experts. For example, some policies in the dataset may use general and vague compliance statements without any details. One policy stated, “We care about protecting your data” without providing specific details about the methods and procedures used to ensure this protection. Similarly, some policies mention the collection of personal data, “e.g., we will collect your data”, without specifying exactly what types of data are collected, the methods of collection, or the specific purposes behind it. Therefore, these critical elements (e.g., user rights and data collection and processing) still require further investigation.
4.6. Targeted Recommendations
Based on the research findings, several practical recommendations have been suggested as shown in Table 8. These recommendations can be widely applied to enhance privacy and increase the transparency of privacy policies within the e-commerce sector, both locally and globally.
Table 8.
Summary of Targeted Recommendations.
5. Conclusions
This study investigated the current status of privacy policies on e-commerce websites serving Saudi users by analyzing 500 websites. It focused on several critical areas, including availability, readability, and PDPL compliance. The results showed notable progress in the availability of privacy policies on these websites. However, there are still challenges to address regarding their availability, readability, and compliance with the PDPL and SDAIA guidelines. Although these policies are commonly available, they are often too complex for the average consumer to understand and do not cover the essential elements required.
These study findings indicate an urgent need to improve privacy policies. All e-commerce websites should ensure that their policies are available and clearly written in Arabic, and regularly updated to reflect any changes in regulations or company practices. Furthermore, efforts should be made to simplify the language of these documents. They should also be written with the actual practices of the website in mind, rather than relying on ready-made templates. Stores should be more transparent about how information is obtained, used, and stored, and clarify the rights of users.
Finally, despite the contributions of this study, certain limitations should be considered. First, although automated verification techniques were used to ensure data extraction accuracy, relying on human evaluation for certain qualitative aspects (such as formatting and accessibility) remains a potential limitation, which future studies could address by involving multiple reviewers. Additionally, this study used a non-probability purposive sampling approach, which may introduce selection bias, as the sample was collected through Google search results and social media, potentially overlooking less visible or emerging e-commerce stores. This may limit the generalizability of the findings. However, the large sample size of 500 websites, combined with the high degree of similarity and repeated content identified across the analyzed policies, suggests that the sampled websites reflect common practices in the e-commerce stores serving Saudi users. Future research could benefit from a stratified sampling approach to capture a broader spectrum of small-to-medium enterprises.
Author Contributions
N.D.A.: Conceptualization, Methodology, Formal analysis, Validation, Investigation, Writing—Original Draft, Visualization. M.A.: Conceptualization, Writing—Review and Editing, Supervision, Project administration. M.B.: Conceptualization, Writing—Review and Editing, Supervision, Project administration. All authors have read and agreed to the published version of the manuscript.
Funding
This research received no external funding.
Data Availability Statement
The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding author.
Conflicts of Interest
The authors declare no conflicts of interest.
Appendix A
Figure A1 presents the frequency distribution of the most commonly used terms across all PDPL coverage categories, providing additional detail to support the compliance analysis reported in Section 4.
Figure A1.
Most Frequently Used Terms Across All Categories. (a) Average Term Frequency per Document—Top 20 Terms. (b) Distribution of Term Occurrences Across Documents (Box Plot).
References
- Nokhbeh Zaeem, R.; Barber, K. Human and Privacy Rights; CRC Press: Boca Raton, FL, USA, 2025; pp. 460–475. [Google Scholar] [CrossRef] [Scilit]
- Hamli, S.S.A.; Sobaih, A.E.E. Factors Influencing Consumer Behavior towards Online Shopping in Saudi Arabia Amid COVID-19: Implications for E-Businesses Post Pandemic. J. Risk Financ. Manag. 2023, 16, 36. [Google Scholar] [CrossRef] [Scilit]
- Morel, V.; Pardo, R. Three Dimensions of Privacy Policies; Research Report RR-9287; Inria—Research Centre Grenoble—Rhône-Alpes; CITI—CITI Centre of Innovation in Telecommunications and Integration of Services: Montbonnot-Saint-Martin, France, 2019. [Google Scholar]
- Qamar, A.; Javed, T.; Beg, M.O. Detecting Compliance of Privacy Policies with Data Protection Laws. arXiv 2021, arXiv:2102.12362. [Google Scholar]
- Nivas, S.; Gokul, C.; Banahatti, V.; Lodha, S. Visuals Triumph in a Curious Case of Privacy Policy; Springer: Cham, Switzerland, 2021; pp. 732–741. [Google Scholar]
- Hosseini, M.B.; Heaps, J.; Slavin, R.; Niu, J.; Breaux, T. Ambiguity and Generality in Natural Language Privacy Policies. In Proceedings of the 2021 IEEE 29th International Requirements Engineering Conference (RE), Notre Dame, IN, USA, 20–24 September 2021; IEEE: New York, NY, USA, 2021; pp. 70–81. [Google Scholar]
- Andow, B.; Mahmud, S.Y.; Wang, W.; Whitaker, J.; Enck, W.; Reaves, B.; Singh, K.; Xie, T. PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19), Santa Clara, CA, USA, 14–16 August 2019; pp. 585–602. [Google Scholar]
- Ibdah, D.; Lachtar, N.; Raparthi, S.M.; Bacha, A. Why Should I Read the Privacy Policy, I Just Need the Service: A Study on Attitudes and Perceptions Toward Privacy Policies. IEEE Access 2021, 9, 166465–166487. [Google Scholar] [CrossRef] [Scilit]
- Habib, H.; Cranor, L.F. Evaluating the Usability of Privacy Choice Mechanisms. In Proceedings of the Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022), Boston, MA, USA, 8–9 August 2022; pp. 273–289. [Google Scholar]
- Goldman, E. An Introduction to the California Consumer Privacy Act (CCPA); Santa Clara University Legal Studies Research Paper; Santa Clara University: Santa Clara, CA, USA, 2020. [Google Scholar]
- Bou Chaaya, K. Privacy Management in Connected Environments. Ph.D. Thesis, Université de Pau et des Pays de l’Adour, Pau, France, 2021. [Google Scholar]
- Javed, Y.; Salehin, K.M.; Shehab, M. A Study of South Asian Websites on Privacy Compliance. IEEE Access 2020, 8, 156067–156083. [Google Scholar] [CrossRef] [Scilit]
- Shalhoub, Z.K. Content Analysis of Web Privacy Policies in the GCC Countries. Inf. Syst. Secur. 2006, 15, 36–45. [Google Scholar] [CrossRef] [Scilit]
- Zaeem, R.N.; Barber, K.S. A study of web privacy policies across industries. J. Inf. Priv. Secur. 2017, 13, 169–185. [Google Scholar] [CrossRef] [Scilit]
- Ebert, N.; Alexander Ackermann, K.; Scheppler, B.O. Bolder is Better: Raising User Awareness through Salient and Concise Privacy Notices. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems (CHI’21); Association for Computing Machinery: New York, NY, USA, 2021. [Google Scholar] [CrossRef] [Scilit]
- Javed, Y.; Al Qahtani, E.; Shehab, M. Privacy Policy Analysis of Banks and Mobile Money Services in the Middle East. Future Internet 2021, 13, 10. [Google Scholar] [CrossRef] [Scilit]
- Alhomod, S.M.; Shafi, M.M. Privacy Policy in E Government Websites: A Case Study of Saudi Arabia. Comput. Inf. Sci. 2012, 5, 88–93. [Google Scholar] [CrossRef] [Scilit]
- Alhazmi, A.; Daghistani, A. Privacy practices of popular websites in Saudi Arabia. J. Umm-Qura Univ. Eng. Archit. 2024, 16, 19–29. [Google Scholar] [CrossRef] [Scilit]
- Meier, Y.; Schäwel, J.; Krämer, N.C. The shorter the better? Effects of privacy policy length on online privacy decision-making. Media Commun. 2020, 8, 291–301. [Google Scholar] [CrossRef] [Scilit]
- Soumelidou, A.; Tsohou, A. Effects of privacy policy visualization on users’ information privacy awareness level: The case of Instagram. Inf. Technol. People 2019, 33, 502–534. [Google Scholar] [CrossRef] [Scilit]
- Ermakova, T.; Baumann, A.; Fabian, B.; Krasnova, H. Privacy Policies and Users’ Trust: Does Readability Matter? In Proceedings of the Americas Conference on Information Systems, Savannah, GA, USA, 7–9 August 2014. [Google Scholar]
- Raibulet, C.; Wang, K. Awareness of privacy and data collection: Exploring privacy policy effectiveness in Google Maps. Front. Comput. Sci. 2025, 7, 1568179. [Google Scholar] [CrossRef] [Scilit]
- Rusna, R. Privacy Concerns of Indonesian Internet Users: Investigating the Level of Concern Among Ecommerce Users; KTH Royal Institute of Technology: Stockholm, Sweden, 2022. [Google Scholar]
- McDonald, A.M.; Cranor, L.F. The cost of reading privacy policies. Isjlp 2008, 4, 543. [Google Scholar]
- Bowers, J.; Reaves, B.; Sherman, I.N.; Traynor, P.; Butler, K.R.B. Regulators, Mount Up! Analysis of Privacy Policies for Mobile Money Services. In Proceedings of the Symposium On Usable Privacy and Security, Santa Clara, CA, USA, 12–14 July 2017. [Google Scholar]
- Cătuneanu, V.M.; Mihalache, A.N. Chapter 7—Principles of Reliability. In Reliability Fundamentals; Cătuneanu, V.M., Mihalache, A.N., Eds.; Fundamental Studies in Engineering; Elsevier: Amsterdam, The Netherlands, 1989; Volume 10, pp. 231–237. [Google Scholar] [CrossRef] [Scilit]
- Farr, J.N.; Jenkins, J.J.; Paterson, D.G. Simplification of Flesch reading ease formula. J. Appl. Psychol. 1951, 35, 333. [Google Scholar] [CrossRef] [Scilit]
- Fanguy, R.; Kleen, B.A.; Soule, L.C. Privacy policies: Cloze test reveals readability concerns. Issues Inf. Syst. 2004, 5, 117–123. [Google Scholar]
- El-Haj, M.; Rayson, P. OSMAN—A Novel Arabic Readability Metric. In Proceedings of the International Conference on Language Resources and Evaluation; European Language Resources Association (ELRA): Reykjavik, Iceland, 2016. [Google Scholar]
- Al-Saqer, N.S.; Seliaman, M.E. The Impact of Privacy Policies Awareness on Snapchat Saudi users Discontinuous Usage Intention. In Proceedings of the 2018 21st Saudi Computer Society National Computer Conference (NCC), Riyadh, Saudi Arabia, 25–26 April 2018; IEEE: New York, NY, USA, 2018; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Alabdulatif, A.; Alturise, F. Awareness of data privacy on social networks by students at Qassim University. Int. J. Adv. Comput. Res. 2020, 10, 194. [Google Scholar] [CrossRef] [Scilit]
- Ali, M.N.Y.; Rahman, M.L.; Jahan, I. Security and privacy awareness: A survey for smartphone user. Editor. Pref. Desk Manag. Ed. 2019, 10, 483–488. [Google Scholar] [CrossRef] [Scilit]
- Aldalbahi, S.S.; Albesher, A.S. Young Saudis’ Evaluations and Perceptions of Privacy in Digital Communities: The Case of WhatsApp and Telegram. Sustainability 2023, 15, 11286. [Google Scholar] [CrossRef] [Scilit]
- Al-Khalifa, H.; Mashaabi, M.; Al-Yahya, G.; Alnashwan, R. The Saudi Privacy Policy Dataset. arXiv 2023, arXiv:2304.02757. [Google Scholar]
- Communications, Space and Technology Commission. Saudi Internet Report 2024; Communications, Space and Technology Commission: Riyadh, Saudi Arabia, 2024. [Google Scholar]
- Mann, D.S. Research Methods for Business: A Skill-Building Approach. Leadersh. Organ. Dev. J. 2013, 34, 700–701. [Google Scholar] [CrossRef] [Scilit]
- Ziakis, C.; Vlachopoulou, M.; Kyrkoudis, T.; Karagkiozidou, M. Important Factors for Improving Google Search Rank. Future Internet 2019, 11, 32. [Google Scholar] [CrossRef] [Scilit]
- Del Alamo, J.M.; Guaman, D.S.; García, B.; Diez, A. A systematic mapping study on automated analysis of privacy policies. Computing 2022, 104, 2053–2076. [Google Scholar] [CrossRef] [Scilit]
- Alrefaie, M.T. Arabic Stop Words. 2019. Available online: https://github.com/mohataher/arabic-stop-words (accessed on 15 February 2025).
- Sun, R.; Xue, M. Quality Assessment of Online Automated Privacy Policy Generators: An Empirical Study. In EASE ’20: Proceedings of the 24th International Conference on Evaluation and Assessment in Software Engineering; Association for Computing Machinery: New York, NY, USA, 2020; pp. 270–275. [Google Scholar] [CrossRef] [Scilit]
- Alhanjouri, M. Pre Processing Techniques for Arabic Documents Clustering. Int. J. Eng. Manag. Res. 2017, 7, 70–79. [Google Scholar]
- Björnsson, C.H. Läsbarhet; Pedagogiskt Utvecklingsarbete vid Stockholms Skolor. 6; Liber: Solna, Sweden, 1968; p. 269. [Google Scholar]
- Smith, E.A.; Senter, R. Automated Readability Index; Technical Report AMRL-TR-66-220; Aerospace Medical Research Laboratories, Aerospace Medical Division, Air Force Systems Command: Wright-Patterson Air Force Base, OH, USA, 1967. [Google Scholar]
- Krippendorff, K. Content Analysis: An Introduction to Its Methodology, 4th ed.; Sage Research Methods; SAGE Publications, Inc.: Thousand Oaks, CA, USA, 2019. [Google Scholar] [CrossRef] [Scilit]
- Obar, J.A.; Oeldorf-Hirsch, A. The biggest lie on the Internet: Ignoring the privacy policies and terms of service policies of social networking services. Inf. Commun. Soc. 2018, 23, 128–147. [Google Scholar] [CrossRef] [Scilit]
- Steinfeld, N. “I agree to the terms and conditions”: (How) do users read privacy policies online? An eye-tracking experiment. Comput. Hum. Behav. 2016, 55, 992–1000. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.













































