Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsThe tracking landscape and privacy law · Lesson 2 of 14

Privacy laws for marketers: EU, UK, US, KSA and UAE

Article · 8 min · 9 min lecture

Video lecture

Privacy laws for marketers: EU, UK, US, KSA and UAE

14 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 14

Privacy laws for marketers

  • EU and UK
  • United States
  • Saudi Arabia
  • UAE and free zones
  • Your tag-to-law register

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Why marketers must know the law

Tracking decisions are legal decisions. Which tags fire, what data is sent to which vendor, how long it is kept, and whether a user agreed — these determine whether your measurement is lawful. This lesson gives a practical map, not legal advice. Laws change; confirm with counsel and the regulator's current guidance for your situation.

Two layers of rules in Europe and the UK

  1. Device access rules — the EU ePrivacy Directive (Article 5(3)) and the UK's PECR require consent to store or access information on a user's device unless it is strictly necessary for a service the user requested. This covers cookies, local storage, pixels and fingerprinting.
  2. Data protection rules — the GDPR (EU) and UK GDPR govern processing personal data: lawful basis, transparency, minimization, purpose limitation, retention, security, international transfers, data subject rights.

For advertising and most analytics, consent is the expected basis under the device-access rules in the EU.

UK update: the Data (Use and Access) Act 2025 introduced new exemptions from cookie consent for certain low-risk purposes, including analytics used solely for statistical purposes to improve a service, provided users get clear information and an easy way to object. Its provisions have been commencing in stages through 2026; advertising and cross-site tracking still require consent. Check current ICO guidance before relying on the exemption.

The United States: a state patchwork

There is no single federal privacy law. Around twenty states have comprehensive privacy laws (California's CCPA/CPRA, Virginia, Colorado, Connecticut, Texas, Oregon and others; Indiana, Kentucky and Rhode Island took effect on 1 January 2026). Common features:

  • Opt-out model for "sale" of personal data, "sharing" for cross-context behavioral advertising (California) and "targeted advertising".
  • Universal opt-out signals: several states require honoring browser signals like Global Privacy Control (GPC).
  • Sensitive data (health, precise location, etc.) often requires opt-in consent.
  • Sector laws (HIPAA for health, COPPA for children) and enforcement by the FTC and state attorneys general on tracking pixels that leak sensitive data.

Saudi Arabia: PDPL

The Personal Data Protection Law (PDPL) is regulated by SDAIA and has been enforceable since September 2024. Key points for marketers: a legal basis is required (consent is central for marketing), privacy notices, data subject rights, restrictions on transfers outside the Kingdom (updated Transfer Regulation, 2024: adequacy or appropriate safeguards such as standard contractual clauses), registration and record-keeping duties for some controllers, and breach notification. SDAIA's violation committees have issued enforcement decisions.

UAE: PDPL and free zones

The UAE Federal Decree-Law No. 45 of 2021 (PDPL) establishes consent and other lawful bases, rights and transfer rules, overseen by the UAE Data Office. Check the current status of its executive regulations before relying on specific details. Financial free zones have their own regimes: DIFC Data Protection Law and ADGM Data Protection Regulations, both modeled closely on GDPR, with active regulators.

Pakistan

Pakistan has had a draft Personal Data Protection Bill under discussion for several years; check whether it has been enacted. Meanwhile, if you target EU, UK, Gulf or US users from Pakistan, their laws apply to your processing.

A practical compliance map

QuestionEU/UKUS statesKSAUAE
Consent before ad cookies/pixels?YesGenerally opt-out, honor GPC; opt-in for sensitiveConsent-based approach recommendedConsent-based approach recommended
Analytics without consent?EU: generally no; UK: possible under DUAA exemption conditionsUsually yes with notice/opt-outAssess legal basisAssess legal basis
Cross-border transfer rules?Yes (adequacy/SCCs)LimitedYes (Transfer Regulation)Yes

Worked example: a Riyadh-based marketplace advertising in KSA, UAE and UK

The marketplace maps each tag to a purpose, lawful basis and vendor location. It configures a CMP with region-specific behavior: opt-in for UK and EU visitors; consent collection with clear notices in KSA and UAE; GPC honored for US visitors. Server-side events forward only fields needed for each purpose; transfers of personal data outside KSA rely on documented safeguards.

Hands-on: a tag-to-law register

tag,vendor,purpose,data_sent,cookies_or_device_access,lawful_basis_eu_uk,us_optout_applies,ksa_basis,vendor_location,transfer_mechanism,retention
GA4,Google,analytics,page_url;event;client_id,_ga,consent (EU) / DUAA exemption? (UK - verify),no,consent,US/EU,SCCs/DPF,14 months
Meta Pixel + CAPI,Meta,advertising,event;hashed_email;fbp,_fbp,consent,yes (sharing/targeted ads),consent,US/IE,SCCs/DPF,per vendor

Pitfalls

  • Copying a US opt-out banner into EU/UK traffic.
  • Sending health, financial or children's data to ad platforms through URLs or events.
  • Ignoring cross-border transfer rules for Gulf data.
  • Treating the CMP as "compliance done" without checking what actually fires.

How to measure success

A current tag register signed off by legal, region-specific consent behavior verified in testing, and documented transfer mechanisms.

Key takeaways

  • EU/UK rules have two layers: device-access consent (ePrivacy/PECR) and data protection (GDPR/UK GDPR).
  • The UK's Data (Use and Access) Act 2025 adds limited cookie-consent exemptions (e.g., certain analytics) — advertising still needs consent.
  • US states use opt-out models for targeted advertising, and several require honoring Global Privacy Control.
  • KSA PDPL (SDAIA) and UAE PDPL impose consent, rights and cross-border transfer rules; DIFC and ADGM have their own laws.
  • Maintain a tag-to-law register and verify what actually fires.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Under EU ePrivacy rules, what generally requires consent?
  2. A US visitor's browser sends a Global Privacy Control signal. What should a business subject to laws that recognize GPC do?
  3. Which regulator oversees Saudi Arabia's PDPL?

Put it into practice

Create a tag-to-law register for your site: every tag, vendor, purpose, data sent, cookies, lawful basis per region and transfer mechanism.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.