WordPress

WordPress GDPR Compliance: Everything You Need to Know

Your WordPress site almost certainly processes personal data. This guide walks you through every step of making it GDPR compliant — from auditing your plugins and blocking cookies to configuring consent banners and using WordPress’s built-in privacy tools.

The problem

Why WordPress sites need GDPR compliance.

WordPress powers over 43% of all websites on the internet. That scale creates a unique compliance challenge.

WordPress is the most popular content management system in the world, powering more than 43% of all websites on the internet. That includes personal blogs, corporate sites, online stores, news publications, membership platforms, and everything in between. The sheer ubiquity of WordPress means that millions of site owners need to think about GDPR compliance — and most of them have not done so adequately.

The challenge begins with WordPress itself. Even a completely default WordPress installation sets cookies. When a user logs in, WordPress creates authentication cookies like wordpress_logged_in_[hash] to maintain the session. When a visitor leaves a comment, WordPress can set cookies to remember their name, email, and website URL for future comments. These are functional cookies, and while they may qualify as strictly necessary in some contexts, they still need to be disclosed in your privacy policy and handled properly under GDPR.

But the real compliance risk comes from plugins. The average WordPress site runs 20 to 30 plugins, and many of the most popular plugins set cookies, load third-party scripts, or collect personal data in ways that trigger GDPR obligations. Installing Google Analytics through Site Kit or MonsterInsights adds tracking cookies. Adding WooCommerce creates session and cart cookies alongside a full customer database. Using Jetpack introduces WordPress.com tracking. Even plugins that seem harmless, like contact forms or spam filters, process personal data that falls under GDPR scope.

The result is that virtually every WordPress site with any kind of functionality — analytics, e-commerce, email marketing, contact forms, social sharing, advertising, or security — is processing personal data of European visitors and is therefore subject to GDPR. The regulation applies regardless of where the site owner is based. If your WordPress site is accessible to visitors in the European Union, GDPR applies to you.

Key risk

Most WordPress sites set tracking cookies the moment a page loads, before any consent is given. Under GDPR and the ePrivacy Directive, this is a violation that can result in fines of up to €20 million or 4% of annual global turnover, whichever is greater. Regulators are actively scanning websites and issuing enforcement actions for exactly this kind of non-compliance.

Plugin audit

Common WordPress plugins that set cookies.

These are the most widely used WordPress plugins and integrations that create GDPR obligations. Check whether any are active on your site.

Google Analytics

Whether installed via Site Kit, MonsterInsights, Insert Headers and Footers, or a manual code snippet, Google Analytics sets multiple tracking cookies on every page load. These cookies track individual visitors across sessions and pages, building a behavioral profile that constitutes personal data under GDPR. Without a consent mechanism, these cookies fire immediately on page load — a clear violation.

WooCommerce

WooCommerce is the most popular WordPress e-commerce plugin, and it sets several cookies for cart management and session handling. Beyond cookies, WooCommerce collects and stores extensive customer personal data including names, email addresses, billing addresses, order history, and payment information. This data is stored in your WordPress database and subject to GDPR data retention, access, and erasure requirements.

Jetpack

Jetpack connects your WordPress site to WordPress.com infrastructure and enables features like site stats, social sharing, related posts, and CDN image serving. The site stats module sets tracking cookies that monitor visitor behavior across your site and report data back to WordPress.com servers. The social sharing and related posts features may also load third-party scripts that set their own cookies.

Contact Form 7 / WPForms

Contact form plugins collect personal data submitted by visitors — typically names, email addresses, phone numbers, and message content. While these plugins may not set cookies themselves, the personal data they collect is stored in your database or sent via email and must be handled according to GDPR requirements. You need a legal basis for processing this data, a retention policy, and the ability to fulfill data subject access and erasure requests.

Yoast SEO

Yoast SEO itself does not set cookies or collect personal visitor data. However, it is almost always installed alongside Google Analytics, Google Search Console, and other tracking tools. Yoast also integrates with social media platforms through its open graph and Twitter card settings. The plugin is safe from a cookie perspective, but the broader analytics ecosystem it encourages makes a consent mechanism essential.

Akismet

Akismet is the default spam filtering plugin bundled with WordPress. It processes comment data by sending it to Akismet’s external servers for spam analysis. The data sent includes the commenter’s IP address, email address, name, user agent, and comment content. This constitutes a transfer of personal data to a third-party processor and must be disclosed in your privacy policy. Akismet is operated by Automattic, headquartered in the United States, which raises additional considerations around international data transfers.

Facebook Pixel / Meta

The Meta (Facebook) Pixel is widely used for advertising retargeting and conversion tracking. It sets persistent tracking cookies that follow visitors across the web and builds detailed advertising profiles. The Meta Pixel fires JavaScript that communicates directly with Facebook’s servers, transmitting page URLs, user actions, and visitor identifiers. Under GDPR, loading the Meta Pixel before obtaining explicit consent is one of the most common and most heavily penalized violations.

Google Ads / Conversion Tracking

Google Ads conversion tracking and remarketing tags set cookies that track visitor behavior for advertising purposes. These cookies enable Google to build cross-site advertising profiles and serve targeted ads based on pages visited on your site. Like Google Analytics, these scripts typically fire immediately on page load and must be blocked until the visitor provides explicit consent for marketing cookies.

Wordfence

Wordfence is the most popular WordPress security plugin. It sets cookies for rate limiting, bot detection, and administrator authentication verification. Most Wordfence cookies serve a legitimate security purpose and can be classified as strictly necessary. However, Wordfence also processes and logs IP addresses of all visitors, which constitutes personal data under GDPR. This processing should be disclosed in your privacy policy.

Mailchimp / Email Marketing

Mailchimp integrations, whether through the official Mailchimp for WordPress plugin or third-party connectors, collect email addresses and often set tracking cookies when embedded signup forms are loaded. Mailchimp’s tracking features monitor email opens and link clicks, which constitutes personal data processing. Subscriber data is stored on Mailchimp’s US-based servers, requiring appropriate transfer mechanisms under GDPR.

Action plan

What WordPress site owners need to do.

Follow these eight steps to bring your WordPress site into GDPR compliance. Each step addresses a specific legal requirement.

  1. Audit your plugins for cookies and data collection

    Go through every active plugin on your WordPress site and determine whether it sets cookies, loads third-party scripts, or collects personal data. Check the plugin documentation and privacy disclosures. Do not rely on assumptions — many plugins set cookies that are not obvious from their feature descriptions. Document every cookie and data collection point you find. This audit is the foundation for everything that follows, because you cannot write an accurate privacy policy or configure a consent banner without knowing exactly what your site does with visitor data. Pay special attention to analytics, advertising, social media, e-commerce, and form plugins, as these are the most common sources of GDPR-relevant data processing.

  2. Install a cookie consent banner

    GDPR and the ePrivacy Directive require that you obtain explicit, informed consent from visitors before setting any non-essential cookies. This means you need a consent banner that appears on the first visit, before any tracking scripts fire. The banner must offer a genuine choice — accept and reject buttons with equal visual prominence, no pre-checked boxes, and no dark patterns that nudge visitors toward accepting. It must also allow visitors to manage consent by category, distinguishing between strictly necessary cookies, analytics cookies, marketing cookies, and preference cookies. The FixGDPR WordPress plugin handles all of this automatically, including script blocking, category management, and consent storage.

  3. Block non-essential scripts until consent

    Having a consent banner is not enough if your tracking scripts still fire before the visitor makes a choice. You must ensure that Google Analytics, Facebook Pixel, Google Ads, and any other non-essential scripts are completely blocked until the visitor explicitly clicks accept. This is the most technically challenging part of GDPR compliance for WordPress sites, because many plugins inject their scripts directly into the page head without any consent awareness. A proper consent management solution will intercept these scripts and defer their execution until appropriate consent has been recorded. Without script blocking, your consent banner is purely decorative and offers no legal protection.

  4. Create or update your privacy policy

    GDPR Articles 13 and 14 require a comprehensive privacy policy that discloses the identity of the data controller, the purposes and legal basis for each type of data processing, the categories of personal data collected, data retention periods, third-party data sharing including specific recipients, information about international data transfers, and a full description of data subject rights. Your privacy policy must accurately reflect what your WordPress site actually does — including all the cookies and data processing you identified in your audit. A generic, template privacy policy that does not mention your specific plugins, analytics tools, and third-party services will not satisfy GDPR requirements.

  5. Add a privacy policy link to your footer

    Your privacy policy must be easily accessible from every page on your site. The standard practice is to include a link in your site footer. WordPress makes this straightforward — add a Privacy Policy page via Pages → Add New, then include it in your footer menu or widget area. The link should also be visible in your consent banner and in any forms that collect personal data, such as contact forms, comment forms, newsletter signup forms, and checkout pages. Visitors should never have to search for your privacy policy. It should be one click away from anywhere on your site.

  6. Configure WordPress’s built-in privacy tools

    Since WordPress 4.9.6, the platform includes built-in privacy features that many site owners overlook. Navigate to Settings → Privacy in your WordPress admin to designate your privacy policy page. This setting ensures WordPress links to your privacy policy from the login and registration pages. It also enables the privacy policy page to be recognized by plugins that need to reference it. Setting this up takes less than a minute and is an important part of your overall GDPR compliance posture, because it integrates your privacy disclosures with core WordPress functionality.

  7. Set up data export and erasure tools

    GDPR grants data subjects the right to access their personal data and the right to have it erased. WordPress provides built-in tools for both of these at Tools → Export Personal Data and Tools → Erase Personal Data. These tools allow you to search for a user by email address, generate a data export package containing all their personal data, or process an erasure request that removes their data from WordPress. Well-coded plugins hook into these tools and include their data in exports and erasures automatically. Check that your active plugins, especially WooCommerce and contact form plugins, properly integrate with these data handling tools.

  8. Review third-party integrations

    Any service that receives personal data from your WordPress site is a data processor under GDPR, and you need a Data Processing Agreement (DPA) with each one. This includes your hosting provider, email service, analytics platform, advertising networks, payment processors, CDN providers, and any SaaS tools connected to your site. Review each integration to understand what data is shared, where it is stored geographically, and what transfer mechanisms are in place for data leaving the EU. Most major services like Google, Mailchimp, and Stripe offer GDPR-compliant DPAs that you can sign online — but you need to actually sign them. Having unsecured data processing relationships is a compliance gap that regulators specifically look for.

Site audit

How to audit your WordPress site for cookies.

Before you can fix compliance issues, you need to know exactly what cookies and trackers your site loads.

The fastest and most thorough way to audit your WordPress site is to use FixGDPR’s free compliance scanner. Enter your URL and the scanner will load your site in a headless browser, simulating a first-time visitor with no existing cookies or cached consent. Within approximately 30 seconds, you receive a complete report listing every cookie set, every third-party script loaded, whether a consent banner is present and functional, and a compliance score from 0 to 100. Each issue comes with specific fix instructions. This is exactly how a regulatory auditor would evaluate your site, and it catches things that manual inspection often misses.

If you prefer to audit manually, open your WordPress site in a fresh browser profile or incognito window and use the browser’s developer tools. In Chrome, open DevTools with F12 or Ctrl+Shift+I, navigate to the Application tab, and look under Cookies in the left sidebar. You will see every cookie set by your domain and by third-party domains. Pay attention to cookies that appear immediately on page load, before you interact with any consent mechanism — these are your most urgent compliance issues. Also check the Network tab for outgoing requests to third-party domains like google-analytics.com, facebook.net, doubleclick.net, and similar tracking services.

For a comprehensive audit, you should also review your WordPress admin. Navigate to Plugins → Installed Plugins and go through each active plugin. Check its documentation or settings page for any mention of cookies, tracking, analytics, or data collection. Look at your theme’s settings as well — some WordPress themes embed Google Fonts, social media widgets, or analytics code directly in the theme options. Do not forget to check Appearance → Widgets and Appearance → Customize for any embedded third-party content like YouTube videos, Google Maps, or social media feeds that may set cookies.

Document everything you find in a spreadsheet with columns for the cookie or tracker name, its purpose, the plugin or integration that creates it, whether it is first-party or third-party, its expiration time, and whether it should be classified as strictly necessary, analytics, marketing, or preferences. This document becomes your cookie inventory — a critical GDPR compliance artifact that informs your privacy policy, consent banner configuration, and data processing records.

FixGDPR tip

The FixGDPR scanner does all of this automatically. It identifies every cookie, categorizes it, flags pre-consent violations, and generates the documentation you need. Run a free scan to get your complete cookie inventory in under a minute.

Implementation

Implementing consent with FixGDPR.

The FixGDPR WordPress plugin handles cookie consent, script blocking, and compliance monitoring from your WordPress admin.

The FixGDPR WordPress plugin is purpose-built to solve the GDPR compliance challenges that WordPress site owners face. Rather than requiring you to manually edit script tags, write custom JavaScript, or configure complex tag management rules, the FixGDPR plugin handles consent management, script blocking, and compliance monitoring automatically. It integrates directly into your WordPress admin panel, so everything can be configured from Settings → FixGDPR without touching a line of code.

Setup takes under two minutes. Download the plugin from the FixGDPR WordPress page, upload it via Plugins → Add New → Upload Plugin in your WordPress admin, and activate it. Then log into your FixGDPR dashboard, add your domain, and copy your Site ID. Paste the Site ID into the FixGDPR settings page in WordPress and save. That is it. The consent banner will appear on your site immediately, and all non-essential scripts will be blocked until the visitor grants consent.

The plugin is built with performance in mind. The entire consent banner script is under 20 KB gzipped. It has no jQuery dependency, causes no layout shift, and has zero measurable impact on Core Web Vitals or PageSpeed scores. Your site speed will not be affected.

  • ✓ Automatic script blocking — Third-party scripts from Google Analytics, Facebook, Google Ads, and other services are automatically intercepted and blocked until the visitor provides explicit consent. No manual script editing or tag manager configuration required.
  • ✓ Category-based consent — Visitors can accept or reject cookies by category: strictly necessary, analytics, marketing, and preferences. The banner provides clear descriptions of each category so visitors can make an informed choice.
  • ✓ Google Consent Mode v2 — Built-in support for Google Consent Mode v2 means consent signals are automatically forwarded to Google Analytics 4, Google Ads, and Google Tag Manager. This ensures your Google integrations respect visitor consent choices without any additional configuration.
  • ✓ Consent storage and proof — Every consent decision is recorded with a timestamp, the visitor’s choices by category, and a unique consent receipt ID. This creates an auditable consent log that demonstrates compliance if you are ever questioned by a regulator.
  • ✓ WCAG 2.1 AA accessible — The consent banner is fully keyboard navigable, screen-reader compatible, and meets WCAG 2.1 AA contrast and interaction standards out of the box.
  • ✓ Lightweight and fast — Under 20 KB gzipped with no dependencies. No impact on Core Web Vitals, Lighthouse scores, or page load time. The banner renders asynchronously and never blocks the main thread.

Built-in tools

WordPress’s built-in privacy features.

Since version 4.9.6, WordPress includes native privacy tools that every site owner should configure.

Privacy Policy Page Setting

Settings → Privacy

WordPress allows you to designate an official privacy policy page from the Settings menu. Once set, WordPress automatically links to this page from the login screen, the registration page, and the comment form. This setting also enables plugins to programmatically reference your privacy policy URL, ensuring consistent linking across your entire site. WordPress ships with a privacy policy template that covers many standard GDPR sections and can be customized to match your specific data processing activities.

When you create or select your privacy policy page, WordPress generates a suggested policy text that includes sections for what personal data you collect and why, who you share data with, how long you retain data, what rights visitors have over their data, and where you send visitor data. This template is a strong starting point, but you must customize it to accurately reflect your actual plugins, integrations, and data processing practices. A generic, unmodified template does not satisfy GDPR requirements.

Personal Data Export Tool

Tools → Export Personal Data

GDPR Article 15 gives data subjects the right to access their personal data, and Article 20 gives them the right to data portability. WordPress’s Personal Data Export tool fulfills both requirements. When you receive a data access request, enter the person’s email address into the export tool. WordPress will send a verification email to confirm the request, then generate a downloadable ZIP file containing all the personal data associated with that email address. The export includes user profile information, comments, media uploads, and data registered by compatible plugins.

Well-built plugins register their data with WordPress’s privacy system so it is automatically included in exports. WooCommerce, for example, includes order history, billing details, and shipping addresses in the export. Contact Form 7 and WPForms can include submitted form entries. If a plugin does not register its data with the export system, you may need to manually compile that data from the plugin’s own database tables when responding to access requests. Test the export tool with a known email address to see what is included and identify any gaps.

Personal Data Erasure Tool

Tools → Erase Personal Data

GDPR Article 17 establishes the right to erasure, commonly known as the “right to be forgotten.” WordPress’s Personal Data Erasure tool enables you to process these requests. Like the export tool, it works by email address. Enter the email, WordPress sends a confirmation request to the data subject, and upon confirmation, the tool either deletes or anonymizes all personal data associated with that email address.

The erasure tool distinguishes between data that can be fully deleted and data that must be anonymized rather than removed. For example, comments may be anonymized by removing the commenter’s name, email, and IP address while retaining the comment text for content integrity. Plugins that properly integrate with this system handle their own data cleanup — WooCommerce can anonymize order records while retaining the transaction data needed for tax and accounting compliance. As with the export tool, verify that your most important plugins participate in the erasure system, and have a manual process in place for plugins that do not.

Important note

WordPress’s built-in privacy tools handle data subject rights, but they do not address cookie consent, script blocking, or consent management. You still need a consent banner solution like FixGDPR to handle the front-end compliance requirements that visitors encounter when they first arrive on your site. Think of WordPress’s privacy tools as the back-end compliance layer, and FixGDPR as the front-end compliance layer. Together, they cover the full scope of GDPR requirements for your WordPress site.

Get started

Make your WordPress site GDPR compliant today.

The FixGDPR WordPress plugin handles cookie consent, script blocking, Google Consent Mode v2, and compliance monitoring — all from your WordPress admin. Install it in under two minutes and stop worrying about GDPR violations.

Related Resources

Continue learning about GDPR compliance.

FixGDPR WordPress Plugin

Download the FixGDPR plugin for WordPress. Cookie consent banner, automatic script blocking, Google Consent Mode v2, and compliance scanning from your WP admin.

GDPR Cookie Consent Guide

Everything you need to know about implementing cookie consent that meets GDPR requirements, including banner design, consent storage, and user choice management.

Free Cookie Checker

Scan your website for cookies and tracking scripts. Get a detailed compliance report with every cookie identified, categorized, and accompanied by fix instructions.

GDPR Compliance Checklist

A practical, step-by-step checklist for making your website GDPR compliant, from cookies and consent to privacy policies and data subject rights.