E-Commerce Regulations in the GCC: Compliance Guide
E-commerce in the GCC is governed by a patchwork of national laws that regulate online transactions, consumer protection, data privacy, electronic payments and digital signatures. Each member state – Bahrain, Saudi Arabia, the UAE, Qatar, Kuwait and Oman – has enacted its own e-commerce legislation, creating compliance obligations for any business that sells goods or services online to GCC consumers. This guide covers the key regulatory requirements across all six countries and provides a practical compliance roadmap for e-commerce operators.
Published: July 2026 | Last updated: July 2026 | Author: Bitrixme Compliance Team
E-Commerce Laws by Country
Each GCC member state has enacted a primary e-commerce or electronic transactions law that establishes the legal framework for online commerce. Additional consumer protection and data privacy laws impose further obligations on e-commerce businesses.
| Country | Primary E-Commerce Law | Regulatory Authority | Licensing Requirement |
|---|---|---|---|
| Bahrain | Legislative Decree No. 28 of 2002 (Electronic Transactions) | iGA (Information & eGovernment Authority) | Class 2 or 3 eCommerce licence from iGA |
| Saudi Arabia | E-Commerce Law (Council of Ministers Resolution 141/1440) | Ministry of Commerce (MC) | No separate e-commerce licence (commercial registration required) |
| UAE | Federal Decree-Law No. 46 of 2021 (Electronic Transactions and Trust Services) | Telecommunications and Digital Government Regulatory Authority (TDRA) | Trade licence with e-commerce activity from relevant economic department |
| Qatar | Law No. 16 of 2010 (Electronic Commerce and Transactions) | Ministry of Communications and Information Technology (MCIT) | E-commerce licence from MCIT |
| Kuwait | Law No. 20 of 2014 (Electronic Transactions) | Communications and Information Technology Regulatory Authority (CITRA) | E-commerce registration with Ministry of Commerce and Industry |
| Oman | Royal Decree No. 69/2008 (Electronic Transactions Law) | Information Technology Authority (ITA) / Ministry of Transport and Communications | E-commerce permit from Ministry of Commerce, Industry and Investment Promotion |
Consumer Protection Requirements
GCC consumer protection laws impose specific obligations on e-commerce businesses, including the right to clear product information, transparent pricing, delivery terms and return policies. In Saudi Arabia, the E-Commerce Law requires traders to disclose their identity, contact details, full price (including taxes and delivery fees), product specifications and the right of withdrawal within 15 days for most products. The UAE Consumer Protection Law (Federal Decree-Law No. 5 of 2023) requires e-commerce platforms to provide accurate product descriptions, issue electronic receipts, respect delivery timelines and implement a clear return and refund policy. Bahrain’s Consumer Protection Law (Law No. 35 of 2012) requires sellers to provide accurate information and honour warranties; consumers have the right to return defective products within 14 days. Qatar, Kuwait and Oman have similar provisions that mandate transparent pricing, accurate product descriptions and a defined returns period.
Data Privacy Obligations
Data privacy requirements for e-commerce businesses vary across the GCC. Bahrain has the most comprehensive framework under the Personal Data Protection Law (PDPL) of 2018 (Law No. 30 of 2018), which requires informed consent, data processing registration, data breach notification and appointment of a data protection officer for certain businesses. Saudi Arabia’s Personal Data Protection Law (PDPL) of 2021, amended in 2023, applies to the processing of personal data of Saudi residents and requires consent, data minimisation and cross-border data transfer restrictions. The UAE’s Federal Decree-Law No. 45 of 2021 on Personal Data Protection applies to all sectors except free zones, which have their own data protection regulations (notably Dubai’s DIFC Law No. 5 of 2020 and ADGM’s Data Protection Regulations 2021). Qatar’s Law No. 13 of 2016 on Personal Data Privacy applies to electronically processed data. Kuwait and Oman are in the process of enacting comprehensive data protection laws, with draft legislation under review.
| Country | Data Protection Law | Consent Required | Data Breach Notification | Cross-Border Transfer Restriction |
|---|---|---|---|---|
| Bahrain | PDPL 2018 (Law No. 30) | Yes | Yes, 72 hours | Yes, adequacy standard |
| Saudi Arabia | PDPL 2021 (amended 2023) | Yes | Yes | Yes, restricted |
| UAE (federal) | Federal Decree-Law No. 45 of 2021 | Yes | Yes, 72 hours | Yes, adequacy standard |
| Qatar | Law No. 13 of 2016 | Yes | Yes | Yes, restricted |
| Kuwait | Draft law (not yet enacted) | Pending | Pending | Pending |
| Oman | Draft PDPL (not yet enacted) | Pending | Pending | Pending |
Payment Gateway Compliance
E-commerce businesses that process online payments must comply with payment card industry standards and national payment system regulations. All GCC countries require payment service providers to be licensed by the central bank or financial regulatory authority. Businesses that accept credit or debit cards must comply with PCI DSS (Payment Card Industry Data Security Standard). In Saudi Arabia, the Saudi Central Bank (SAMA) regulates payment service providers and requires compliance with its payment system rules. The UAE Central Bank issues licences for payment service providers under its Stored Value Facilities regulations. Bahrain’s Central Bank of Bahrain (CBB) regulates payment service providers under Volume 5 of its rulebook and requires compliance with CBB payment systems rules. Qatar Central Bank, the Central Bank of Kuwait and the Central Bank of Oman each maintain their own licensing and oversight regimes for payment services.
Key compliance requirements include implementing strong customer authentication (SCA) for online transactions, maintaining transaction records for a minimum of five years, reporting suspicious transactions to the financial intelligence unit, and ensuring that payment data is encrypted both in transit and at rest. E-commerce businesses that operate across multiple GCC countries should engage with a regional payment gateway that is licensed in each target market.
Digital Signatures and Records
All GCC member states recognise electronic signatures and electronic records as legally equivalent to their paper counterparts, subject to certain conditions. Each country has an electronic transactions law that defines the legal validity of electronic signatures, contracts and records. In practice, this means that e-commerce businesses can form valid contracts online, issue electronic invoices and maintain digital records without requiring paper backups. However, certain types of transactions – such as real estate conveyances, wills and marriage contracts – are typically excluded from electronic transactions laws and must still be executed in writing or before a notary.
Each country maintains a register of approved trust service providers who issue qualified digital certificates. E-commerce businesses that require high-assurance digital signatures (for example, for signing contracts above a certain value or for government filings) should use certificates from these approved providers. For standard e-commerce transactions such as checkout acceptance and terms of service agreement, a simple electronic signature (such as a checkbox click) is sufficient under all GCC laws.
Cross-Border E-Commerce in the GCC
Selling to consumers in another GCC country or importing goods for sale online introduces additional compliance layers. Cross-border e-commerce operators must consider customs duties, VAT, product conformity assessments and licensing recognition.
| Consideration | Requirement | Authority |
|---|---|---|
| VAT registration | Register for VAT if supplies exceed mandatory threshold in each GCC country (SAR 375,000 Saudi; AED 375,000 UAE; BHD 37,500 Bahrain) | ZATCA (Saudi), FTA (UAE), NBR (Bahrain), GTA (Qatar) |
| Customs duties | GCC unified customs tariff of 5% on most imported goods | GCC customs authorities |
| Product conformity | Products must meet GSO standards and country-specific labelling requirements | GSO (GCC Standardization Organization), SASO (Saudi), ESMA (UAE) |
| Consumer protection | Must comply with consumer law of the consumer’s country of residence | Consumer protection agencies in each country |
| Data residency | Certain countries (Saudi, Qatar) require local data storage for sensitive data | NCA (Saudi), MCIT (Qatar) |
Penalties for Non-Compliance
Penalties for non-compliance with GCC e-commerce regulations vary by country and by the nature of the violation. Fines are the most common sanction, but regulators can also suspend operations, block websites or revoke licences. In Saudi Arabia, violations of the E-Commerce Law carry fines of up to SAR 1,000,000 (approximately USD 267,000) and potential imprisonment. In the UAE, fines for consumer protection violations can reach AED 1,000,000 (approximately USD 272,000). Bahrain imposes fines of up to BHD 10,000 (approximately USD 26,500) for e-commerce licensing violations and up to BHD 50,000 (approximately USD 132,500) for data protection breaches. Data privacy violations in Saudi Arabia carry fines of up to SAR 5,000,000 (approximately USD 1,333,000) for serious breaches. Regulators across the GCC are increasing enforcement activity, with dedicated e-commerce compliance teams conducting online monitoring sweeps.
FAQ
Do I need a separate e-commerce licence in every GCC country?
Yes, unless you operate from a free zone that provides multi-country licensing capabilities. Each GCC member state requires businesses selling to local consumers to hold a valid trade licence with e-commerce activities or a dedicated e-commerce licence.
Are digital signatures valid for e-commerce contracts in the GCC?
Yes. All GCC member states recognise electronic signatures as legally equivalent to handwritten signatures under their electronic transactions laws. For high-assurance transactions, use a qualified digital certificate from an approved trust service provider.
What are the return policy requirements in the GCC?
Requirements vary by country. Saudi Arabia mandates a 15-day right of withdrawal for most products. Bahrain requires a 14-day return period for defective goods. The UAE requires sellers to honour their published return policies. All countries require clear disclosure of return and refund terms at the point of sale.
Do I need to store customer data locally in the GCC?
Requirements vary. Saudi Arabia and Qatar have explicit data localisation requirements for certain categories of personal data. Bahrain and the UAE permit cross-border data transfers subject to adequacy requirements. Kuwait and Oman do not yet have enacted data protection laws. Consult local legal advice for your specific data processing activities.
What happens if I do not register for VAT as an e-commerce seller?
Failure to register for VAT where required can result in penalties including fines of up to SAR 50,000 in Saudi Arabia, AED 20,000 in the UAE and BHD 5,000 in Bahrain, plus back-tax assessments and interest on unpaid VAT.
Which authority enforces e-commerce compliance in the GCC?
Enforcement is distributed. The Ministry of Commerce or equivalent body handles consumer protection and e-commerce licensing. The central bank or financial regulator oversees payment services. The data protection authority (where established) handles privacy compliance. Customs authorities enforce import and tariff obligations.
Ready to launch or expand your GCC e-commerce operation? Contact our compliance team for a comprehensive regulatory assessment, or message us directly on WhatsApp.