A community post on dev.to reports the results of a browser-based scan of 2,103 Gulf business websites, concluding that most of the sampled homepages set third-party trackers before a visitor makes any privacy choice. The author is Taha Farhane, who states he is the founder of Arqam360, a company that sells consent software for Gulf businesses, and who describes himself as a former lead auditor in technology, processes and data privacy. The findings are the author's own claims about his own scan, not an independently verified study, and the post itself discloses the commercial interest behind it.

As the post explains, Puppeteer drove a real browser to load each homepage a single time, with the scanner logging all cookies placed and all third-party trackers that loaded. Three items were examined per site, according to the author: did a tracker activate before the visitor chose anything, did any consent banner show up, and did Google tags emit a Google Consent Mode v2 signal. Domains that shut out the scanner were labeled inconclusive — a point that matters, since it means the listed domains are not captured as a clean census.

The Saudi sample is described as 1,556 online stores, dated September 2026 in the post. Within that group the author reports that 935 stores, or 60%, run trackers and show no consent banner at all; 1,065, or 68%, begin tracking before the visitor makes any choice; and 751, or 48%, run Google Analytics or Tag Manager without a Consent Mode v2 signal. Google Analytics appears on 920 stores (59%) and Meta Pixel on 452 (29%), according to the same post.

The UAE sample is smaller and differently constituted: 547 business websites on .ae, dated October 2026. There the author reports 279 sites (51%) running trackers with no consent banner, 287 (52%) tracking before any choice, and 223 (41%) running Google tags without a Consent Mode signal. The post explicitly warns against ranking the two countries, noting that the samples are different populations — stores versus business websites — and that the UAE list covers only part of the .ae namespace, specifically every domain starting with a digit or the letter "a". Each number, the author writes, stands on its own.

Turning to regulation, the post notes that September 2024 marked the point when Saudi Arabia's Personal Data Protection Law became fully enforceable, and that SDAIA, its regulator, confirmed 48 enforcement decisions in a January 2026 announcement. Marketing sent without consent, the author says, was among the violation categories named in that announcement, and the UAE maintains its own data protection law. These amount to the author's characterizations of the legal backdrop; the regulator's text is not reproduced in the post, and in the supplied excerpts the enforcement figure appears without a linked primary document.

Earlier in the chain than the European debate is where the author locates the Gulf consent problem, and this is his central argument. Most discussion in Europe, he writes, centers on banner design — dark patterns, a "Reject all" button that is missing. On most sites in the Gulf, he claims, there is no banner to design at all, since data already reaches Google and Meta on the visitor's first page view. That framing is an interpretation drawn from the scan's three checks, not a separate measurement.

Two distinct technical failures, rather than one, are what the post highlights for developers and freelancers who build or audit sites for Gulf clients. No consent interface at all is the first. The ordering problem is the second: tags firing on first paint whether or not a banner exists. On the author's account, placing a banner on top of tags that already fired does not fix the second failure, because the tags must await the answer and the business must retain a record of the choice.

A practical consequence for measurement and advertising is also raised by the post. Under Google Consent Mode v2, it states, tags that run with no consent signal may forfeit measurement and ad features for traffic originating in regions where consent is required. Fines under the Saudi law, it further states, reach SAR 5 million, rising to SAR 10 million for repeat violations. Both statements come from the author, offered as context for why the scan's numbers matter to the businesses scanned.

Unusually specific are the limitations the author states, and they deserve preserving. Homepages only, client-side only — checkout pages, server-side processing, contracts and internal procedures were all outside the scan's scope. A low score, the author writes, signals something about consent at the storefront rather than constituting a legal finding; no site is named, and no store-level results are published. Anything behind a block was also invisible to the scanner, since blocked sites were marked inconclusive instead of being counted as compliant or non-compliant.

The datasets are described as open under CC BY 4.0 with DOIs: 10.5281/zenodo.23053713 for the Saudi data, with a report at arqam360.com/ksa-compliance-index, and 10.5281/zenodo.23109874 for the UAE data, with a report at arqam360.com/uae-compliance-index. The post states the article was written with an AI assistant from the company's data and method. None of these linked resources is reproduced in the supplied evidence, so their contents cannot be checked here.

The disclosure is the most important caveat for anyone weighing these numbers. The author sells consent software to exactly the businesses the scan finds wanting, and says so directly: that commercial interest is why the scanner was built, and why the data is published openly so anyone can check it. Open data and a stated method are meaningful mitigants, but they do not make the findings independent, and the post's headline framing — "most never ask before they track" — is the vendor's own summary of his own instrument's output.

For this audience, the actionable reading is procedural rather than statistical. If you maintain a site with Gulf traffic, the scan's three checks are cheap to replicate on your own pages: load the homepage in a clean browser profile, watch the network panel for third-party requests before any interaction, confirm whether a consent interface exists, and check whether Google tags emit a Consent Mode v2 signal. That is a self-audit you can run without trusting the vendor's numbers, and it tests the same ordering question the post is built around.

What remains unknown is substantial. There is no independent replication, no per-site data, no breakdown of which trackers fired in which order, and no information about how many sites were excluded as inconclusive — a figure that would materially affect the percentages. The two samples are not comparable to each other by the author's own admission, and neither is described as a random or complete sample of Gulf websites. The legal consequences cited are context, not findings of the scan, and the scan explicitly cannot see server-side processing or contractual arrangements.

The honest conclusion is that this is a well-documented vendor scan with a clear method, an explicit disclosure and open data, reporting a consistent pattern across two differently-built samples: trackers firing before any choice, and in many cases no choice being offered at all. Treat the percentages as the author's measurements of his own instrument on his own lists, treat the regulatory framing as his characterization, and treat the underlying datasets as the thing worth checking before citing any of it to a client.