كشفت دراسة بحثية حديثة لباحثتين من جامعة الملك عبدالعزيز، أن 31% فقط من مواقع التجارة الإلكترونية العاملة في السعودية استوفت المتطلبات الأربعة التي تناولتها الدراسة ضمن نظام حماية البيانات الشخصية، فيما تراوحت بقية المواقع بين الامتثال الجزئي وعدم الامتثال.
وحللت الدراسة، التي أعدتها الباحثتان إيمان العشولي وعبير الهذلي، سياسات الخصوصية في 100 موقع للتجارة الإلكترونية، استناداً إلى أربعة عناصر رئيسية؛ هي الإفصاح عن مدة الاحتفاظ بالبيانات الشخصية، وحق المستخدم في طلب إتلاف بياناته، وحقه في الحصول على نسخة منها، إلى جانب توفير آلية لتقديم الشكاوى المتعلقة بمعالجة البيانات.
وأظهرت النتائج، أن 9% من المواقع لم توفر سياسة خصوصية من الأساس، بينما قدمت 31% سياسات لم تتضمن أياً من العناصر الأربعة، وأعلنت 29% بعض المتطلبات دون استكمالها، في حين أعلنت 31% جميع العناصر محل الدراسة.
وأوضحت الدراسة، أن 45% من سياسات الخصوصية أفصحت عن مدة الاحتفاظ بالبيانات، فيما نصت 51% على حق المستخدم في طلب إتلاف بياناته، وذكرت 34% صراحة حق الحصول على نسخة من البيانات، مقابل 33% فقط وفرت آلية لتقديم الشكاوى.
ورصدت الدراسة قصوراً في التفاصيل الإجرائية حتى لدى المواقع التي أعلنت هذه الحقوق؛ إذ لم تحدد 82% من السياسات مدة للرد على طلبات إتلاف البيانات، ولم توضح 86% المدة اللازمة لتلبية طلب الحصول على نسخة منها، كما أغفلت 89% تحديد مدة لمعالجة الشكاوى، ولم تسمِّ 67% الإدارة أو المسؤول المختص باستقبالها.
وسجلت المواقع الأعلى ظهوراً في نتائج البحث النسبة الأكبر من عدم الامتثال، بواقع 60%، مقارنة بـ22% للمواقع متوسطة الترتيب و38% للمواقع الأقل ترتيباً. كما أظهرت النتائج أن 70% من المواقع المستضافة على منصات تجارة إلكترونية محلية صُنفت غير ممتثلة، ولم يحقق أي موقع ضمن هذه الفئة الامتثال الكامل للعناصر الأربعة التي فحصتها الدراسة.
ورجحت الباحثتان، أن ارتفاع عدم الامتثال لدى المتاجر المستضافة على المنصات المحلية قد يرتبط بنقص الوعي أو باعتقاد بعض أصحاب المتاجر أن منصة الاستضافة تتحمل مسؤولية حماية بيانات العملاء، مؤكدة أن مالك المتجر يظل المسؤول الأساسي بوصفه المتحكم في البيانات، فيما تعمل منصة الاستضافة عادة بصفة معالج للبيانات نيابة عنه.
الذكاء الاصطناعي واللغة
ختبرت الدراسة قدرة نماذج الذكاء الاصطناعي اللغوية على تحليل سياسات الخصوصية، وسجلت نسبة اتفاق مع التحليل البشري بلغت 96% في أحكام الاحتفاظ بالبيانات، و92% في حق الإتلاف، و81% في آلية الشكاوى، لكنها انخفضت إلى 58% في حق الحصول على نسخة من البيانات.
وأشارت إلى أن الذكاء الاصطناعي يستطيع اكتشاف معلومات قد يغفل عنها المحلل البشري في السياسات الطويلة أو غير المنظمة، إلا أنه قد يخلط بين حق الوصول إلى البيانات وحق الحصول على نسخة منها، أو يتعامل مع معلومات رأس الصفحة وتذييلها على أنها جزء من سياسة الخصوصية، فضلاً عن احتمال تأثره بنصوص مستمدة من أنظمة أجنبية لا تنطبق على النظام السعودي.
ودعت الدراسة إلى تعزيز الرقابة المستمرة، وتوفير أدلة ونماذج مبسطة للمنشآت الصغيرة والمتوسطة، ورفع وعي أصحاب المتاجر والمستخدمين بحقوق حماية البيانات وآليات ممارستها، إلى جانب حث منصات التجارة الإلكترونية على مساعدة المتاجر في إعداد سياسات خصوصية متوافقة مع النظام.
ونبهت الباحثتان إلى أن نتائج الدراسة تقيس مدى وضوح المتطلبات في سياسات الخصوصية المعلنة، ولا تختبر الممارسات الفعلية للمواقع في جمع بيانات العملاء أو معالجتها وإتلافها؛ ما يعني أن التصنيف الوارد فيها لا يمثل حكماً قانونياً نهائياً على كل متجر.
A recent research study by two researchers from King Abdulaziz University revealed that only 31% of e-commerce sites operating in Saudi Arabia met the four requirements addressed in the study under the Personal Data Protection System, while the remaining sites ranged from partial compliance to non-compliance.
The study, prepared by researchers Iman Al-Ashouli and Abeer Al-Hudaili, analyzed the privacy policies of 100 e-commerce sites based on four main elements: the disclosure of the duration for retaining personal data, the user's right to request the deletion of their data, their right to obtain a copy of it, in addition to providing a mechanism for filing complaints related to data processing.
The results showed that 9% of the sites did not provide a privacy policy at all, while 31% offered policies that did not include any of the four elements. Additionally, 29% announced some requirements without completing them, while 31% declared all the elements under study.
The study indicated that 45% of the privacy policies disclosed the duration for retaining data, while 51% stipulated the user's right to request the deletion of their data, and 34% explicitly mentioned the right to obtain a copy of the data. In contrast, only 33% provided a mechanism for filing complaints.
The study noted a lack of procedural details even among the sites that announced these rights; 82% of the policies did not specify a timeframe for responding to requests for data deletion, 86% did not clarify the time required to fulfill requests for obtaining a copy, 89% neglected to specify a duration for processing complaints, and 67% did not name the department or responsible person to receive them.
The sites that appeared most frequently in search results recorded the highest rate of non-compliance at 60%, compared to 22% for moderately ranked sites and 38% for lower-ranked sites. The results also showed that 70% of the sites hosted on local e-commerce platforms were classified as non-compliant, and no site within this category achieved full compliance with the four elements examined in the study.
The researchers suggested that the high rate of non-compliance among stores hosted on local platforms may be related to a lack of awareness or the belief among some store owners that the hosting platform bears the responsibility for protecting customer data. They emphasized that the store owner remains the primary responsible party as the data controller, while the hosting platform typically acts as a data processor on their behalf.
Artificial Intelligence and Language
The study tested the ability of linguistic artificial intelligence models to analyze privacy policies and recorded an agreement rate with human analysis of 96% in data retention provisions, 92% in the right to deletion, and 81% in the complaints mechanism, but it dropped to 58% in the right to obtain a copy of the data.
It pointed out that artificial intelligence can detect information that a human analyst might overlook in lengthy or unorganized policies; however, it may confuse the right to access data with the right to obtain a copy of it or treat header and footer information as part of the privacy policy. Additionally, it may be influenced by texts derived from foreign regulations that do not apply to the Saudi system.
The study called for enhancing ongoing oversight, providing guides and simplified models for small and medium enterprises, raising awareness among store owners and users about data protection rights and how to exercise them, and urging e-commerce platforms to assist stores in preparing privacy policies that comply with the system.
The researchers warned that the study's results measure the clarity of the requirements in the announced privacy policies and do not test the actual practices of the sites in collecting, processing, or deleting customer data; this means that the classification mentioned does not represent a final legal judgment on every store.