Skip to content
Building a clothing brand

What tracking pixels collect, and what Saudi law asks

Saudi Arabia has no cookie law. I searched the Personal Data Protection Law and its Implementing Regulation for the word, found nothing, and found the obligation somewhere else entirely.

Tamm Team10 min read

What tracking pixels collect, and what Saudi law asks

Every English guide to selling online in Saudi Arabia that touches privacy says the same thing, and says it with the same confidence: add a cookie banner, Saudi law requires one. Not one of them cites an article number. A seller in Jeddah sent me a screenshot of the grey strip at the bottom of his store, copied from a British site by the agency that built it, and asked whether it satisfied the rule. He was not really asking about the strip. He was asking which article it answered, and I could not have told him.

The instruments are short enough to read in one sitting. I opened the Personal Data Protection Law, issued by Royal Decree M/19, and its Implementing Regulation as published in Umm al-Qura, and started searching.

The article that is not there

I searched for cookie. Then tracking. Then pixel. Then profiling, and then the Arabic equivalents of all four, because a Saudi instrument will sometimes carry the Arabic term and put the foreign one in brackets beside it. Zero occurrences, in the Law and in the Regulation alike.

Before doubting the text I doubted my method, which is what anyone looking for an absence rather than a presence owes the reader. An encoding fault or a hamza typed in the wrong shape will manufacture a zero out of nothing. So I ran a control: the phrase "personal data" appears 241 times in the Regulation alone. The search works. The word is simply not in the document.

What I had assumed, along with most of what has been written on this in either language, was that somewhere behind the banners sat a Saudi counterpart to the European directive. An article saying when the strip appears, what it has to say, and how long the visitor's answer is kept. There is no cookie-specific legislation in Saudi Arabia and no article anywhere that names a pixel. Anyone who writes that Saudi law mandates a cookie banner is writing a sentence with nothing underneath it.

That gap is not a permission, and it is the thing worth taking away from all this. The law does not have to name an instrument in order to govern what the instrument does. A pixel collects personal data about people in Saudi Arabia, sends it to a company outside the Kingdom, and produces lists that are then used to send those people advertising. Three facts, and each one has a door of its own in the very text that never says the word.

What the pixel actually records

A pixel is a line of code that runs in the visitor's browser rather than on your server, and its job is to tell an ad platform what that visitor did on your pages: opened a product, added a piece to the cart, started checkout, completed the purchase. Riding along with each event are identifiers strong enough to recognise the same person on a later visit, and those identifiers are exactly the personal data the whole legal question turns on.

Out of those events the platform builds custom audiences: lists of everyone who saw a particular page, or added to cart and never came back. This is where one number gets copied wrong almost everywhere. Retention is not 30 days. The advertiser chooses it, the longest duration Meta will accept for a website custom audience is 365 days, and after that a member drops out unless they return to the site and match the rule again. The 30 days comes from a worked example in Meta's own documentation, where a visitor who arrives on 1 June leaves the audience on 30 June.

The distance between 30 days and 365 days is not a field on a form. It is the difference between a list that forgets the customer who browsed during Ramadan before Eid arrives, and a list that still remembers him the following Ramadan. Copying the 30 from one guide to the next costs a seller eleven months of memory that was already available, and the sales that memory would have carried.

A desk with a laptop and a phone showing an audiences and retargeting dashboard in warm light
A desk with a laptop and a phone showing an audiences and retargeting dashboard in warm light

Where the obligation comes from instead

It starts with consent. Article 5 of the Law bars the processing of personal data without the consent of the person it belongs to, except in the cases the Law itself provides, and Article 11 of the Implementing Regulation describes the consent that counts: freely given, not obtained by misleading methods, and tied to a purpose that is clear and specific. Read the second condition again while looking at a banner with a bright accept button and a washed-out grey decline in the corner.

The second fact is that the data does not stay in the Kingdom. Meta, Google, TikTok and Snap all process it elsewhere, which puts a pixel squarely inside the cross-border regime: Article 29 of the Law, substantially rewritten by Royal Decree M/148, together with the separate Regulation on the transfer of personal data outside the Kingdom, which is its own instrument with its own conditions. No cookie banner opens that door and none closes it.

The third is that nobody collects an audience for its own sake. A list exists to be messaged, and Article 25 prohibits using a person's own contact channels, postal and email addresses among them, to send promotional material without their consent and without a clear mechanism to stop it. The line there is drawn by channel rather than by technology, which is what makes email marketing a compliance subject as much as a marketing one.

One practical question survives all of this: if the word is not in the text, does the regulator care at all? It does. SDAIA's guideline on preparing privacy policies names cookies explicitly, as an indirect collection method a policy is expected to disclose. So the accurate sentence is the whole sentence: no cookie-specific law, no cookie term in the Law or its Implementing Regulation, and regulator guidance that expects cookies to be disclosed in your privacy policy. Article 36, for its part, exposes a breach to a warning or a fine of up to SAR 5,000,000, doubled where the breach is repeated.

Names that changed while the copy did not

Half of what is written about measurement still names tools that were renamed or switched off years ago. The product is now the Google tag: one tag with one tag ID feeding several Google destinations, Google Ads and Google Analytics among them. gtag.js is the library the tag is deployed with rather than the product itself, and the Latin name survives because it is the name of a file in the page source. Google Tag Manager is not a rival to it either, but the container in which tags are configured and published, a distinction most explainers drop and leave the reader choosing between two things that were never alternatives.

Universal Analytics, meanwhile, is not a side of any comparison. Standard properties stopped processing hits on 1 July 2023, and access to current and historical UA data ended starting the week of 1 July 2024. Any page still written in the future tense about the shutdown is describing something that finished more than two years ago, which is a shelf life attached to the article rather than to the tool.

In the other direction sits a name that was widely assumed to have changed and did not. The Meta Pixel is still the Meta Pixel in Meta's own documentation. And the story that the Conversions API arrived to replace it has it backwards: Meta's published best practice is to use the Conversions API in addition to the pixel, sending the same events through both, with deduplication so a single event is not counted twice. Each one catches what the other misses. That is why they run together, not why one retires the other.

The same shape repeats across the rest. TikTok has a pixel and an Events API, and recommends running both with deduplication. Snap has the Snap Pixel, which is its actual name rather than the Snapchat Pixel, and a Conversions API beside it, now on version 3 after version 2 was deprecated in early 2025. Three independent platforms landing on the same recommendation is worth noticing: the server-side layer is not a replacement you buy instead of the first one, it is a second support underneath it for the events a browser no longer passes through.

The pixel belongs to whoever owns the page

For all of that, a pixel does not get installed where many sellers imagine. It runs in the page the visitor opens, so it belongs with whoever owns that page, which is the platform you already sell on. The ID comes out of an ad account you open in your own name, it goes into your own store, and the data arrives at the ad platform attributed to you. There is no point in that chain where a factory sits.

Which is worth saying plainly before anyone asks: Tamm does not give you a tracking pixel, a retargeting audience, or a number about how your ads performed. All of that comes out of your ad account and the platform you sell on, and all of it stays yours even if you stopped printing with us tomorrow. I think that is a feature rather than a gap, because whoever holds the list of your customers holds a piece of your brand, and here the list is not in anyone's hands but yours.

Advertising that is not measured is spending blind, but anyone running a pixel today is running it on their own account in every sense: consent asked for in language the visitor understands before they click, a privacy policy that says what is collected and why and where it goes, and a working way to stop it for anyone who changes their mind. Get that right alongside a properly configured ad account and Google Ads becomes something you can judge with a number instead of a feeling.

Where Tamm fits

Tamm is a factory and a warehouse in Saudi Arabia, and the print-on-demand service provider behind your store. You keep selling on the platform you already use; when an order arrives we print the piece on our own line and ship it to your customer under your brand. It is not a store platform and it does not compete with Salla, Zid or Shopify. Browse the catalog

What the law does not name, it still governs

I went back to the seller in Jeddah with an answer he did not like at first: there is no article to point you at, and no banner text you can paste and then forget. The text that governs him is not about the strip at all. It is about three questions that can be asked on any ordinary day. Did he get consent that the person giving it understood. Did he say where the data goes. Can someone who changes their mind actually get out. A banner copied from a British store answers the first in form and leaves the third unanswered in substance. What I took from that evening is a habit I now apply to everything I read about tracking, and it transfers cleanly: open the text and search for the word yourself.

Frequently asked questions

Does Saudi Arabia have a cookie law?
No. The Personal Data Protection Law and its Implementing Regulation contain no occurrence of cookie, tracking, pixel or profiling, in Arabic or in Latin script. The obligation on a store comes from the general rules instead: consent, direct marketing, and transfer of personal data outside the Kingdom.
Do I need the visitor's consent before running a pixel?
Yes, where the pixel processes personal data. Article 5 of the Law bars processing without the data subject's consent except in the cases the Law provides, and Article 11 of the Implementing Regulation sets the conditions: freely given, not obtained by misleading methods, and for a clear and specific purpose.
Has the Conversions API replaced the browser pixel?
No. Meta's own best-practice guidance is to use the Conversions API in addition to the Meta Pixel and send the same events through both, with deduplication so nothing is counted twice. TikTok and Snap say the same about their own server-side interfaces.
How long does a retargeting audience keep its members?
The advertiser sets the retention. For a Meta website custom audience the longest duration that can be set is 365 days, after which a member drops out unless they revisit and match the rule again. The 30 days repeated across most guides is a worked example in Meta's documentation, not a cap.
Does Tamm supply a tracking pixel or a retargeting audience?
No. Tamm is a factory and a warehouse in Saudi Arabia and the print-on-demand service provider behind your store. The pixel comes from your own ad account and is installed on the platform you sell on, and the data and the audiences stay yours alone.

You might also want