🎉 Get 20% OFF the first C-DPO cohort! Code:
20KSACDPO
ChatGPT Summarize Button

Privacy notices for transparency: a study of Riyadh and London

A tale of two cities, two metro systems, and two very different approaches to privacy. Comparing Riyadh Metro and Transport for London reveals something more important than legal technicalities — it shows what transparency actually looks like in practice, and what organisations in Saudi Arabia can learn before regulators and the public start demanding answers.

Table of Contents

Introduction

Privacy notices may not seem like headline material, but they speak volumes about how seriously organizations take data protection. When you compare Riyadh Metro with Transport for London, the differences are more than just legal technicalities. They reflect different cultures, levels of regulatory pressure, and expectations around transparency.

This article is not a criticism of either approach. It is a reflection on what is said, what is unsaid, and what this means for organizations working in or across both regions.

Transport for London: A Mature Privacy Framework

TfL operates within the well-established framework of the UK GDPR and the Data Protection Act. Over the past seven years, organizations in the UK have been under sustained pressure from regulators, the media, and the public to get their house in order when it comes to privacy. The result is a landscape where privacy notices are detailed, layered, and clearly tied to legal obligations. You know what your rights are. You know how to use them. And people do.

Riyadh Metro: A great start

Riyadh Metro, by contrast, sits under Saudi Arabia’s Personal Data Protection Law, a relatively new regime that only entered enforcement in 2024. The notice they provide is more detailed than many in the region. It clearly describes what types of data are collected, from registration details to location and device data. It also outlines why the data is used, whether for ticketing, customer support, or improving the app.

Riyadh Metro has done a great job – the privacy notice is much better than most examples we have had a look at.

What is missing, though, is the lawful basis for each activity. PDPL, like the GDPR, requires organizations to have a clear legal reason for processing personal data. But in Riyadh Metro’s notice, these reasons are implied rather than stated. There is no breakdown of which uses are based on consent, contract, or other grounds.

This matters because it affects how people understand their rights. And although the notice touches on the right to access and delete personal data, other rights under PDPL are absent or unclear. There is no mention of how to object, request corrections, or escalate a complaint beyond the Royal Commission for Riyadh City itself.

Don’t Mistake Silence for Simplicity

If you are working in Saudi Arabia, do not assume privacy is unimportant just because you are not under daily pressure from regulators or customers. That pressure is coming. Expectations are shifting. Regulators, global partners, and the public are watching closely.

Right now is the time to define your own best practice. If you wait until enforcement ramps up or public awareness surges, you may find yourself reacting instead of leading.

Even if your operations are local, understanding how other jurisdictions like the UK handle transparency and user rights can help futureproof your approach.

Transparency Beyond the Policy

Riyadh Metro’s privacy notice does a reasonable job of covering app permissions, cookies, analytics, crash logs, and device data. The privacy notice explains how cookies work and what data they collect, but when I visited the website, I was not presented with a cookie banner or any options to manage my settings. That matters, especially when the policy mentions third-party analytics.

Transparency is not just about writing a policy. It’s about what people see and experience when they land on your page. These are areas where even UK and EU organizations often fall short. But again, the notice is more descriptive than legal. It does not explain whether these tracking tools require consent or how long the data is retained in a way that connects clearly to user rights.

TfL, by contrast, splits out its notices into focused sections, one for CCTV, another for Wi-Fi tracking, another for contactless payments. It sets out retention periods, third-party sharing details, and the lawful basis for each processing activity. This makes it easier to hold the organization accountable. And just as importantly, it makes it easier for users to understand what is happening.

The Challenge of Clarity

TfL, for all its strengths, is not perfect. Its privacy notices are detailed, yes, but also long and written in a way that arguably makes it harder than it should be to understand what applies to you as a user. So, while it ticks the boxes of lawful basis, data rights, and sharing, I’m not entirely sure it always delivers the clarity that the transparency principle was meant to protect.

This Is Not a Finger-Pointing Exercise

Let me be clear: Riyadh Metro’s privacy notice is better than many I’ve seen under the PDPL so far. It is even better than a lot published under the GDPR! It goes beyond vague statements. It tries to explain what data is collected and why, and that alone puts it ahead of the curve. But it still reflects the challenge we all face in this space: turning legal frameworks into something clear, meaningful, and human. And while TfL’s notice is far more detailed, it’s not exactly easy to navigate. It’s thorough, yes. But it’s also long, split across multiple pages, and in places more of a legal archive than a user guide. Strictly speaking, I’m not sure it always lives up to the intent behind the transparency principle.

Privacy Notices as Working Tools

Which brings me to this: privacy notices are not set-and-forget documents. They’re working tools. They should evolve. They should be read, not just by compliance teams or regulators, but by actual people. I always tell clients: read your privacy notice as if you were the customer. Not the data controller. Not the IT lead. But the commuter. The patient. The parent. The client.

Does your friend understand what a “controller” is? Does your mother know what a “data processor” does? If they don’t, how do you expect the public to?

And that’s the real issue. Most people still don’t know their rights. But they will. And when they do, you’ll want your house in order. Because privacy isn’t just about staying compliant. It’s about building trust before you’re forced to explain yourself. It’s about the humans.

Conclusion

So where does this leave us?

TfL’s notices reflect a system that has had time to mature, where transparency is expected and rights are routinely exercised. Riyadh Metro is part of a system still finding its feet. That’s not a criticism. It’s an opportunity. Organizations in the Kingdom have the chance to shape what privacy looks like in practice, before it is shaped for them.

If you work in privacy or compliance in Saudi Arabia, use this moment to build trust, not just tick boxes. Think about what your users need to know. Think about how easy it is for them to act on their rights. Think about what your notice says, not just about the law, but about your values.

Because the people reading it might not know the legal terms. But they will know whether they’re being respected.

This newsletter isn’t about pointing fingers. It’s about cutting through the noise, clearing up confusion, and encouraging everyone to do better when it comes to protecting people’s rights and their data.