4.1. General Characteristics of Privacy Policies
As shown in
Figure 2, the majority of the websites (403 out of 500) provide privacy policy links. This practice demonstrates a growing awareness among website owners about the importance of transparency. This improvement can be attributed to the efforts of the Saudi Ministry of Commerce to promote the importance of privacy policies for online stores, and to increase the awareness of society about privacy and data protection issues. However, 19.40% of websites still lack privacy policies, which is a worrying issue, especially in light of the PDPL. Additionally, it was observed that of the seven websites offering plastic, cleaning supplies, and kitchenware services, two lack privacy policies, as shown in
Figure 2. This percentage is high compared to other fields. Such non-compliance with the regulations raises concerns regarding the commitment of website owners to user rights. It is worth noting that this general lack of privacy policy is not new. As previously highlighted, a significant percentage of websites across various sectors lack privacy policies [
12,
13,
14,
25]. More effort is still needed to ensure full compliance across all websites.
For the 403 websites that provide links to their privacy policies, the following characteristics were examined based on the presence and position of the link, regardless of the accessibility of its content. Firstly, when examining the location of privacy policy pages,
Table 4 shows that the majority of websites (356) place the privacy policy link in the footer. This place is considered to be a common and familiar place for users. However, it is worth noting that a small percentage of websites (0.50%) engage in the negative practice of hiding links across multiple pages, making it difficult for users to access this important information. On the other hand, 11.16% of websites display the privacy policy link in additional locations, such as at the top of the page or in drop-down menus, which can improve the visibility and accessibility of the link.
Additionally, as illustrated in
Figure 3, only 28.04% of the websites provide a link to the privacy policy during the registration process. Access to the policy at this stage is crucial, as it enables users to understand how the site handles their data before submission. However, studies show that users rarely read privacy policies before registering [
31,
45]; still, making the policy available is a necessary step that gives users the opportunity to review this information if they wish [
46].
Regarding the terminology used to describe the privacy policy pages,
Table 5 shows that “Privacy Policy” is the most common term. This terminology is widely used in the literature and in the guidelines of the Saudi Ministry of Commerce and the PDPL. However, the use of other titles, such as “Terms and Conditions” (used by 11 websites), may confuse users, especially if the title does not contain the word “Privacy.” Websites should adopt a unified terminology to facilitate user understanding and avoid confusion.
Through a more detailed analysis and examination of the general characteristics of the content and the links leading to these pages, it was observed that within 403 websites containing links to privacy policies, only four had non-functional links or links that led to empty pages. Accordingly, these sites were excluded from all following analyses, and 399 websites with privacy policies remained for the analysis.
Among the 399 websites providing privacy policies, 2.01% do not provide them in Arabic, as shown in
Figure 4. Writing these policies in non-Arabic languages may create a significant barrier for Saudi users in knowing their rights and obligations, especially since Arabic is the official language of Saudi Arabia. Failure to provide the text in Arabic is a clear violation of the Saudi PDPL and the SDAIA guidelines for preparing and developing a privacy policy. The law requires that the contents of the policy be written in a clear, non-misleading, easy-to-read, and easy-to-understand language, suitable for the level of understanding of all categories of personal data subjects (users).
By focusing on privacy policy update information, the results in
Figure 5 reveal that 358 out of the 391 websites that provide policies in Arabic do not provide any information about the last date their policies were updated. This absence may raise doubts about how the policies are updated and kept up to date with legislative or technological changes. This is a clear violation of the SDAIA guidelines for writing a privacy policy.
Regarding the formatting styles in the available Arabic policies, it was observed that 64.45% of websites use bold headings to divide their privacy policies, while 25.58% use non-bold headings with a single color. Additionally, 9.97% of websites present their policies as plain text without any formatting effects such as highlighting or bolding. Using a single font and a single level of writing can make it difficult for users to read and understand, especially if they have reading or vision disabilities. Only 6.91% of the websites use additional presentation techniques in their privacy policies, such as colors (n = 22), highlighted headings (n = 2), boxes (n = 1), and hyperlinks (n = 1). These techniques are considered to be a good attempt by these websites to improve the presentation of the privacy policies and make them more attractive to the reader, but there is still a lot of room for improvement.
4.2. Analyzing the Texts of Privacy Policies
As previously discussed, 391 of the 399 websites had accessible Arabic privacy policies, and in this phase, the texts of these policies were analyzed. By focusing on the text length, as can be observed in
Figure 6, the average privacy policy consisted of approximately 980.99 words and 114.52 sentences. The longest policy contained 6139 words and 648 sentences, while the shortest policy was only nine words in one sentence. Previous studies have confirmed that privacy policies of such length tend to be more complex and challenging for users to read and understand, which may reduce the effective awareness of data practices [
8,
15,
19,
20].
Before extracting the most frequently occurring words, the preprocessing stage resulted in the removal of 367 unique stop words. Among the words that were removed were common words such as ‘aw’ (11,657 occurrences), ‘alY’ (8494 occurrences), and ‘fI’ (8185 occurrences).
As shown in
Figure 7 and
Table 6, the results revealed that the most common words centered around the concepts of data and identity. The word “Information” emerged as the most frequently repeated word (appearing 5925 times in 379 documents), followed by the word “Personal” with 3626 repetitions in 371 documents, then the word “Data” with 3079 repetitions used in 283 documents. This repetition of the word “Information” may be due to its flexibility in describing different sets of data (such as contact and payment information). Additionally, this repetition highlights how policies tend to focus on describing what information is, rather than explaining how to manage it.
Furthermore, as shown in
Figure 7, terms referring to the owning entity, such as “Website”, “Store”, and “Our website”, are repeated significantly. This repetition shows how websites focus heavily on their identity. Additionally, it can be noted that the absence of words focuses mainly on the users and their rights. Words such as “Delete”, “Modify”, or “Withdraw” did not appear among the top ranks, suggesting a lack of a clear, direct explanation of user rights.
Focusing on the average frequency of each word in each document, the analysis in
Figure 8a shows that the word “Definition” has the highest frequency (an average of 9.89 times per document). This may be due to the existence of a complete section at the beginning of the policy called “Definitions,” and it being related to the term “Cookies”. This is confirmed by the repetition of the word “Files” (with an average repetition of 7.54). However, it should be noted that the frequency of the word “link” is relatively low, with an average of 1.90 repetitions.
Additionally, as illustrated in
Figure 8b, the box plot revealed many outliers (small circles) for terms such as “Your Information” and “Information”. Although the medians for these words are low (4.85 and 5.32, respectively), the outliers exceed 50 in some documents. These results confirm that there is significant inconsistency in the details of the policies. Several stores write very long, complex policies that use the same words repeatedly. Additionally, certain words, such as “Private/Specific”, “Mail”, and “Electronic”, appear infrequently, with low average frequencies (1.30, 1.52, 1.62). This indicates that these terms are used mainly for specific functional purposes, such as referencing email or electronic services, rather than being repeatedly used throughout the text.
When dividing texts into sentences based on punctuation (periods, semicolons, and question marks), the most frequently repeated sentences were identified. A total of 3637 common sentences were found.
Table 7 shows one of the most common sentences that appeared on 35 websites. These results confirm that many stores rely on ready-made templates to draft their privacy policies and terms of use agreements.
Additionally, for the text blocks (complete paragraphs that form independent thematic units), 542 common blocks that appeared identically on two or more websites were extracted (
Figure 9). Although the number of common blocks may seem lower than the number of sentences, the size of these blocks reveals the depth of the copying phenomenon. The longest shared text block was 3975 characters (670 words), which was a huge legal text related to “security measures” that was copied word for word between two websites.
Furthermore, the most common block was repeated across 35 websites (the same pattern observed in the sentence analysis), strongly indicating similarity. This means that stores are not just copying individual phrases but importing entire paragraphs, supporting the hypothesis that many websites rely on templates or generators to create their privacy policies, without any attempt to customize the content to reflect the actual practices of the store [
40].
To verify the reliance of websites using ready-made templates, as observed during the sentence and block analysis, this study performed a clustering analysis using the K-Means algorithm and TF-IDF. When dividing the data into 32 clusters (
) (
Figure 10), the results showed that the repetition previously observed in
Table 7 (the sentence that appeared in 35 locations) was not just random copying, but part of a complete structural pattern. Specifically, the algorithm discovered a cluster of 37 identical documents (Cluster 3). This cluster is the primary source of that repeated sentence. A close examination of the content of this cluster revealed that it did not contain just one sentence, but an entire legal sequence, including “Article 5”, “Article 6”, and “Membership Cancellation” sections. This suggests that these stores copied the entire “Terms of Use” document and used it as their privacy policy. Although clustering alone cannot confirm intentional copying, the presence of identical documents in the same cluster, and the repeated legal terminology, supports the use of templates rather than independently written policies. This also explains the use of strict legal terminology, such as “Article”, as illustrated in
Figure 11. While some standardization in legal language is acceptable and expected in privacy policies [
3], the pattern observed here represents complete duplication, with the store replacing its privacy policy entirely with its terms of use agreement [
6,
40].
These findings confirm that many e-commerce websites rely on repetitive and similar privacy policies. This is consistent with previous studies, which have found that many websites use copy-and-paste privacy policies without adapting them to their actual practices [
3,
40]. Additionally, researchers in [
40] found and confirmed that some of the available generators for creating privacy policies use inflexible templates that are unsuitable for all applications and produce incomplete policies that fail to meet legal requirements. These vulnerabilities explain the widespread similarity observed in this study, as stores rely on automated tools rather than creating tailored policies that reflect their actual data practices.
4.3. Readability of Privacy Policies
Focusing on readability,
Figure 12 shows that there is a similarity in the averages among the categories, ranging between 93 to 97 in the LIX index and 30 to 34 in the ARI index. For the LIX index, the results showed an average score of 95.34, with a high value of 119.05 and a low value of 82.20. As for the ARI index, the results showed an average score of 30.96, with a high value of 60.87 and a low value of 22.34. These results suggest that the policies presented to Saudi users are complex, and require a high level of education to comprehend them effectively. Specifically, an average user without higher education would find these policies extremely difficult to understand, as they are equivalent to technical or academic texts, which are far beyond the reading level of most everyday users. The complexity and difficulty of these policy texts are not new, and they are similar to those found in previous studies in other fields [
12,
16,
25]. A study evaluating the privacy policies of Middle Eastern banks and mobile money services also found them to be challenging to understand [
16].
Although sentence and word length may not directly correlate with readability, as illustrated in
Figure 13 (which suggests no strong relationship between text length and readability level), long and complex sentences can hinder understanding [
16]. This is especially true for Arabic, which has complex grammatical structures. Furthermore, the absence of diacritics is one factor that adds to this complexity [
29]. In Arabic, texts that do not use diacritics can be challenging to understand and make it difficult to determine their intended meaning, especially with words that are similar but have different meanings [
29]. The use of legal language and complex terminology has also made understanding these policies more challenging. Additionally, the reliance of websites on templates for privacy policies may be another contributing factor. While these templates make the process of creating policies easier, they may not always take into account the clarity and ease of understanding of the language for users.
4.4. PDPL Requirement Coverage of Privacy Policies
When assessing and analyzing the coverage of privacy policies regarding the requirements of SDAIA and PDPL, the results showed several interesting findings as illustrated in
Figure 14 and
Figure 15. The average compliance score was 45.50%, and the median was 41.67%. These scores indicate that the “average” website in Saudi Arabia only complies with less than half of the legal requirements. This average score points to a significant gap in full compliance. Nevertheless, it is worth noting that only four websites achieved a high coverage rate of 91.66%, and all of them belong to large, well-known companies. This high percentage reflects the strong commitment of these companies to the standards and laws of personal data protection.
However, the results differed greatly when analyzing the detailed elements of the privacy policies, as can be seen in
Figure 15. Here, 86.96% of websites provide information and details about the company, such as the company name, address, and website, which may explain the high repetition of words such as “Our site”. This is followed by information about data sharing, where it is worth noting that 84.65% of websites provide some information on data sharing using keywords such as “third parties” and “outside the Kingdom of Saudi Arabia”. These high percentages are consistent with the findings from previous studies, where third-party data sharing was among the most covered elements in privacy policies [
12,
25]. This is followed by contact information, the data to be collected, and data security (75.70%, 72.63%, and 68.29%, respectively).
Additionally, it can be noted that elements related to user rights and how data is collected and processed appear to be lower percentages: 27.11%, 24.81%, and 11.00%, respectively. This may explain why no information about user rights appears when searching for the most frequently used words. Finally, it can be noted that websites fail to provide information on how to file a complaint, which is a user right and a requirement under the SDAIA guidelines and PDPL. These results are consistent with those of [
25], who found that 50% of policies do not inform users about what data is being collected and stored. Similarly, Javed et al. [
12] found that user data accuracy and control (e.g., access, modification, and deletion rights) were among the least covered elements, with compliance rates as low as 34% in some regions. These gaps weaken the effectiveness of privacy policies and may reduce user confidence in the sites.
By focusing on the specific keywords and phrases used to express these basic required elements, the results show that terms expressing company information are repeated and used frequently and intensively (see
Figure A1 in
Appendix A). For example, outliers were recorded for the term “About Us”, which was repeated more than 50 times in a single policy. Similarly, the word “cookies” appeared more than 30 times in a single policy. This high frequency is mainly because cookies are mentioned both as a type of data and as a method for collecting data. However, the frequent use of the term does not necessarily indicate transparency or legal compliance. As reported in [
18], about 85% of websites that use cookies fail to display banners to their visitors, highlighting a significant gap between what is stated in privacy policies and actual transparency practices. Although many organizations refer to “cookies” in their policies, they often fail to explain how they use cookies or fail to notify users properly. This aligns with our finding that compliance with the “how data is collected” requirement remains low (24.81%).
4.5. Key Findings
In summary, this study uncovered the current diverse status of privacy policies in terms of availability, readability, and PDPL compliance (
Figure 16). The results revealed that the majority of e-commerce websites serving Saudi users provide privacy policies. However, 2.01% of them do not provide these policies in Arabic. Regarding the available Arabic policies, the readability analysis found that these policies remain complex and difficult for the average user to understand. This complexity violates the requirements of both the PDPL and SDAIA guidelines, which require policies to be simple and easy to understand. The use of legal language and the lack of diacritics in the Arabic text make the policies even harder to understand. Additionally, the analysis revealed a high degree of similarity between the policies. Several stores rely on ready-made templates when writing their own policies, which raises concerns about whether these policies accurately reflect the actual practices of the store.
By analyzing the content in more detail, the results revealed that, despite the acceptable coverage of the basic elements required by SDAIA guidelines and Article 12 of the PDPL, many key elements still require improvement and careful review by legal experts. For example, some policies in the dataset may use general and vague compliance statements without any details. One policy stated, “We care about protecting your data” without providing specific details about the methods and procedures used to ensure this protection. Similarly, some policies mention the collection of personal data, “e.g., we will collect your data”, without specifying exactly what types of data are collected, the methods of collection, or the specific purposes behind it. Therefore, these critical elements (e.g., user rights and data collection and processing) still require further investigation.