كشفت دراسة بحثية حديثة لباحثتين من جامعة الملك عبدالعزيز أن 31% فقط من مواقع التجارة الإلكترونية العاملة في السعودية استوفت المتطلبات الأربعة التي تناولتها الدراسة ضمن نظام حماية البيانات الشخصية، فيما تراوحت بقية المواقع بين الامتثال الجزئي وعدم الامتثال.
وحللت الدراسة، التي أعدتها الباحثتان إيمان العشولي وعبير الهذلي، سياسات الخصوصية في 100 موقع للتجارة الإلكترونية، استناداً إلى أربعة عناصر رئيسية؛ هي الإفصاح عن مدة الاحتفاظ بالبيانات الشخصية، وحق المستخدم في طلب إتلاف بياناته، وحقه في الحصول على نسخة منها، إلى جانب توفير آلية لتقديم الشكاوى المتعلقة بمعالجة البيانات.
وأظهرت النتائج أن 9% من المواقع لم توفر سياسة خصوصية من الأساس، بينما قدمت 31% سياسات لم تتضمن أياً من العناصر الأربعة، وأعلنت 29% بعض المتطلبات دون استكمالها، في حين أعلنت 31% جميع العناصر محل الدراسة.
وأوضحت الدراسة أن 45% من سياسات الخصوصية أفصحت عن مدة الاحتفاظ بالبيانات، فيما نصت 51% على حق المستخدم في طلب إتلاف بياناته، وذكرت 34% صراحة حق الحصول على نسخة من البيانات، مقابل 33% فقط وفرت آلية لتقديم الشكاوى.
ورصدت الدراسة قصوراً في التفاصيل الإجرائية حتى لدى المواقع التي أعلنت هذه الحقوق؛ إذ لم تحدد 82% من السياسات مدة للرد على طلبات إتلاف البيانات، ولم توضح 86% المدة اللازمة لتلبية طلب الحصول على نسخة منها، كما أغفلت 89% تحديد مدة لمعالجة الشكاوى، ولم تسمِّ 67% الإدارة أو المسؤول المختص باستقبالها.
وسجلت المواقع الأعلى ظهوراً في نتائج البحث النسبة الأكبر من عدم الامتثال، بواقع 60%، مقارنة بـ22% للمواقع متوسطة الترتيب و38% للمواقع الأقل ترتيباً. كما أظهرت النتائج أن 70% من المواقع المستضافة على منصات تجارة إلكترونية محلية صُنفت غير ممتثلة، ولم يحقق أي موقع ضمن هذه الفئة الامتثال الكامل للعناصر الأربعة التي فحصتها الدراسة.
ورجحت الباحثتان أن ارتفاع عدم الامتثال لدى المتاجر المستضافة على المنصات المحلية قد يرتبط بنقص الوعي أو باعتقاد بعض أصحاب المتاجر أن منصة الاستضافة تتحمل مسؤولية حماية بيانات العملاء، مؤكدة أن مالك المتجر يظل المسؤول الأساسي بوصفه المتحكم في البيانات، فيما تعمل منصة الاستضافة عادة بصفة معالج للبيانات نيابة عنه.
واختبرت الدراسة كذلك قدرة نماذج الذكاء الاصطناعي اللغوية على تحليل سياسات الخصوصية، وسجلت نسبة اتفاق مع التحليل البشري بلغت 96% في أحكام الاحتفاظ بالبيانات، و92% في حق الإتلاف، و81% في آلية الشكاوى، لكنها انخفضت إلى 58% في حق الحصول على نسخة من البيانات.
وأشارت إلى أن الذكاء الاصطناعي يستطيع اكتشاف معلومات قد يغفل عنها المحلل البشري في السياسات الطويلة أو غير المنظمة، إلا أنه قد يخلط بين حق الوصول إلى البيانات وحق الحصول على نسخة منها، أو يتعامل مع معلومات رأس الصفحة وتذييلها على أنها جزء من سياسة الخصوصية، فضلاً عن احتمال تأثره بنصوص مستمدة من أنظمة أجنبية لا تنطبق على النظام السعودي.
ودعت الدراسة إلى تعزيز الرقابة المستمرة، وتوفير أدلة ونماذج مبسطة للمنشآت الصغيرة والمتوسطة، ورفع وعي أصحاب المتاجر والمستخدمين بحقوق حماية البيانات وآليات ممارستها، إلى جانب حث منصات التجارة الإلكترونية على مساعدة المتاجر في إعداد سياسات خصوصية متوافقة مع النظام.
ونبهت الباحثتان إلى أن نتائج الدراسة تقيس مدى وضوح المتطلبات في سياسات الخصوصية المعلنة، ولا تختبر الممارسات الفعلية للمواقع في جمع بيانات العملاء أو معالجتها وإتلافها؛ ما يعني أن التصنيف الوارد فيها لا يمثل حكماً قانونياً نهائياً على كل متجر.
A recent research study conducted by two researchers from King Abdulaziz University revealed that only 31% of e-commerce sites operating in Saudi Arabia met the four requirements addressed in the study under the personal data protection system, while the remaining sites ranged between partial compliance and non-compliance.
The study, prepared by researchers Iman Al-Ashouli and Abeer Al-Hadhli, analyzed the privacy policies of 100 e-commerce sites based on four main elements: the disclosure of the duration for retaining personal data, the user's right to request the destruction of their data, their right to obtain a copy of it, in addition to providing a mechanism for submitting complaints related to data processing.
The results showed that 9% of the sites did not provide a privacy policy at all, while 31% offered policies that did not include any of the four elements, and 29% announced some requirements without completing them, whereas 31% announced all the elements under study.
The study indicated that 45% of the privacy policies disclosed the duration for retaining data, while 51% stipulated the user's right to request the destruction of their data, and 34% explicitly mentioned the right to obtain a copy of the data, compared to only 33% that provided a mechanism for submitting complaints.
The study noted a lack of procedural details even among the sites that announced these rights; 82% of the policies did not specify a duration for responding to requests for data destruction, 86% did not clarify the time needed to fulfill a request for a copy of the data, 89% neglected to specify a duration for processing complaints, and 67% did not name the administration or responsible person for receiving them.
The sites that appeared most frequently in search results recorded the highest rate of non-compliance, at 60%, compared to 22% for mid-ranking sites and 38% for lower-ranking sites. The results also showed that 70% of the sites hosted on local e-commerce platforms were classified as non-compliant, with no site in this category achieving full compliance with the four elements examined in the study.
The researchers suggested that the high rate of non-compliance among stores hosted on local platforms might be related to a lack of awareness or the belief among some store owners that the hosting platform bears the responsibility for protecting customer data, emphasizing that the store owner remains the primary responsible party as the data controller, while the hosting platform typically acts as a data processor on their behalf.
The study also tested the ability of language-based artificial intelligence models to analyze privacy policies, recording an agreement rate with human analysis of 96% in data retention provisions, 92% in the right to destruction, and 81% in the complaints mechanism, but it dropped to 58% in the right to obtain a copy of the data.
It pointed out that artificial intelligence can detect information that a human analyst might overlook in lengthy or unorganized policies, but it may confuse the right to access data with the right to obtain a copy of it, or treat header and footer information as part of the privacy policy, in addition to the possibility of being influenced by texts derived from foreign regulations that do not apply to the Saudi system.
The study called for enhancing continuous oversight, providing simplified guides and templates for small and medium enterprises, raising awareness among store owners and users about data protection rights and mechanisms for exercising them, as well as urging e-commerce platforms to assist stores in preparing privacy policies that comply with the system.
The researchers warned that the results of the study measure the clarity of the requirements in the announced privacy policies and do not test the actual practices of the sites in collecting, processing, or destroying customer data; this means that the classification included does not represent a final legal judgment on every store.