Skip to content

GDPR and WordPress: what the site collects and what to set up

A WordPress site collects personal data through comments, forms, accounts, orders, tags from other companies and its server logs. WordPress has a privacy policy page, an export tool and an erase tool. The rest is an inventory, a reason for each thing kept, consent and retention.

By
WP Ministry
Published

In short

  • This is the WordPress side of the job. What the law requires of your organization is a question for a lawyer or your data protection authority.
  • Start with an inventory of what the site collects, where it is stored and who else receives it.
  • WordPress has a privacy policy page with suggested text, an export tool and an erase tool. They reach WordPress and the plugins that take part, and nothing else.
  • The erase tool does not delete accounts or comments, and it does not touch backups.
  • A tag that needs consent stays out of the page until the visitor agrees. A notice shown while it loads anyway is not consent.
  • No plugin, banner or setting settles the question on its own.

A WordPress site collects personal data as soon as it has a comment form, a contact form, accounts, a store or a tag from an analytics service. The General Data Protection Regulation (GDPR) sets rules for that data. Since version 4.9.6, WordPress has had tools for part of the job: a privacy policy page with suggested text, a tool that exports one person's data and a tool that erases it.

No setting and no plugin does the rest. The work is an inventory of what the site collects, a written reason for each thing you keep, consent where consent is the reason, and a way to answer a person who asks for their data or wants it erased.

What the regulation says, in the articles a website meets

The GDPR is Regulation (EU) 2016/679. Its first articles set the terms.

  • Who it applies to. Article 3 says it applies to processing personal data in the context of the activities of an establishment of a controller or a processor in the European Union, wherever the processing takes place. It also applies to processing the personal data of people who are in the Union by a controller or processor outside it, where the processing relates to offering them goods or services, paid or not, or to monitoring their behavior within the Union.
  • Personal data. Article 4 defines it as any information relating to an identified or identifiable natural person, and names an online identifier as one way to identify someone. The European Commission's explanation lists an IP address and a cookie ID among its examples.
  • Controller and processor. The controller decides the purposes and means of the processing. A processor handles the data on the controller's behalf.
ArticleWhat the text says, in shortWhere a site meets it
5Data is limited to what its purpose needs and kept no longer than necessary. The controller must be able to demonstrate this.Inventory, retention
6Processing is lawful only if at least one of six grounds applies: consent, a contract, a legal obligation, vital interests, a public task or legitimate interests.The reason you record for each item
7Where consent is the ground, the controller must be able to demonstrate that it was given. Withdrawing it must be as easy as giving it.The consent banner
13When data is collected from a person, they are told who the controller is, the purposes and legal basis, who receives the data, how long it is kept and what their rights are.The privacy policy
12, 15, 17A person can ask whether you hold their data and get a copy, and can have it erased where a listed ground applies. The answer is due without undue delay and within one month, which can be extended in some cases.The export and erase tools
28Processing by a processor is governed by a contract or other legal act.Host, mail service, analytics
32Security appropriate to the risk, including the ability to restore access to the data after an incident.Updates, logins, backups
33, 34A personal data breach is notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people's rights and freedoms. Where the risk is high, the people affected are told too.The breach plan
44 to 46Personal data goes to a country outside the Union only under the conditions of Chapter V, such as an adequacy decision or appropriate safeguards.Where each service keeps data

Each row is a short reading. The articles carry conditions and exceptions that a table leaves out.

What a WordPress site collects

WordPress on its own, going by its documentation and the policy text it suggests:

  • Comments. The data in the comment form, plus the commenter's IP address and browser user agent string. With avatars on, a hash made from the email address may be sent to the Gravatar service.
  • Commenter cookies. Three cookies that hold the name, email address and website, and expire a little under a year later. They are set only for a commenter who opts in.
  • Accounts. The profile fields, and for each login session the IP address, the user agent and the time of login.
  • Login cookies. wordpress_[hash], wordpress_logged_in_[hash] and wp-settings-{time}-[UID] for a logged-in user, and a test cookie on the login page.
  • Embeds. WordPress's suggested text says an embed "behaves in the exact same way as if the visitor has visited the other website".

What you added:

  • Forms. WordPress does not include a contact form. The plugin decides whether an entry is mailed, stored or both. The Contact Form 7 listing, for example, says the plugin by itself does not write personal data to the database or use cookies, and that some of its integrations may send the submitter's data, including their IP address, to the service provider.
  • A store. Orders, addresses and customer accounts.
  • Tags, fonts, maps and videos from other companies. The visitor's browser requests each one from that company's server, so the company receives at least the visitor's IP address.

And outside WordPress:

  • The server's access log. Apache's combined log format and nginx's default format record the client's IP address, the time, the request and the user agent.
  • Backups. A copy of everything above.
  • The mailbox that form notifications arrive in.

The privacy tools built into WordPress

On a single site, administrators can use all of them.

The privacy policy page

Go to Settings, then Privacy. Create a new page there, or choose an existing one and select Use This Page. The Policy Guide tab holds suggested text from WordPress under headings such as "Comments", "Cookies" and "How long we retain your data", along with text suggested by your plugins and theme. A plugin adds its part with wp_add_privacy_policy_content(), so a plugin that does not call it suggests nothing.

The screen says that using this text correctly, and keeping the policy current and accurate, is your responsibility. WordPress links the page from the login and registration pages. A link in the footer is yours to add.

Under Settings, then Discussion, the setting is "Show comments cookies opt-in checkbox, allowing comment author cookies to be set". With it on, the comment form shows a checkbox labeled "Save my name, email, and website in this browser for the next time I comment."

Export Personal Data

Go to Tools, then Export Personal Data. Enter the person's username or email address and select Send Request. WordPress emails them a link to confirm, and the request shows as Pending until they use it. Once it shows as Confirmed, send them the file's link from the same row.

The file is a .zip holding one index.html. From WordPress it contains the user's profile information, comments and a list of media uploads. By default WordPress deletes the file after three days.

Erase Personal Data

Tools, then Erase Personal Data works the same way: a request, a confirmation by email, then a button that erases.

Know what it leaves:

  • The account. The tool does not delete a registered user. That is a separate step.
  • The comments. WordPress keeps the text. It changes the author to "Anonymous", empties the email, website and user agent, and anonymizes the IP address.
  • Backups. Nothing is removed from them. WordPress's documentation says erasure requests should still be respected when you restore one.

Why a plugin's data may be missing

Both tools work from an email address and ask each registered exporter or eraser for what it holds. A plugin joins through the wp_privacy_personal_data_exporters and wp_privacy_personal_data_erasers filters. One that does not is not asked, and its data stays where it is. WooCommerce is one that does: its documentation lists customer and order data among what it adds to the export.

An eraser can also report that it kept something, with a message to the administrator saying why.

The work, in order

  1. Step 1: List what the site collects and where it goes

    For each item, write down what the data is, where it is stored, who else receives it and how long it is kept. Go through comments, every form (and the mailbox it sends to), accounts, orders, analytics and advertising tags, embedded media and fonts, the host's logs and backups.

    To see what loads from other companies, open the site in a private window with the browser's developer tools open, and read the requests and cookies before you click anything.

  2. Step 2: Drop what you do not need

    Remove form fields nobody uses, tags for services you stopped using and plugins you no longer need. How to choose a WordPress plugin has the steps for removing one properly. Avatars can be switched off under Settings, then Discussion.

  3. Step 3: Write down the reason for each thing you keep

    Beside each row, note what the data is for and which of the six grounds in Article 6 you rely on. Choosing the ground is a legal decision, so take advice on it.

  4. Step 4: Ask for consent where consent is the reason

    The cookie rule is Article 5(3) of Directive 2002/58/EC. Storing information on a visitor's device, or reading information already stored there, is allowed only with consent given after clear information about the purposes. It has two exceptions: storage needed only to carry out a transmission, and storage strictly necessary for a service the visitor explicitly asked for. It is a directive, so each member state applies it through its own law.

    The European Data Protection Board's guidelines on consent add that consent comes before the processing starts, that pre-ticked boxes are invalid, that scrolling is not consent, and that blocking the site until a visitor accepts does not produce valid consent. In a 2023 report of the Board's cookie banner taskforce, a large majority of authorities held that a banner with a button to accept and no way to refuse on the same layer does not obtain valid consent.

    On the site, that means a tag that needs consent stays out of the page until the visitor agrees. A consent tool holds those scripts back, adds them after a yes and records the answer. Check it the same way, in a private window: before any click, and after refusing, there should be no requests to those services and none of their cookies. Put a link on every page that reopens the choice.

  5. Step 5: Write the privacy policy from the inventory

    Start from the Policy Guide. For each row, say what is collected, why and on which ground, who receives it and how long it is kept. Add who you are, how to reach you and the rights a person has.

  6. Step 6: Be ready for a request for access or erasure

    Decide who answers requests. Run an export for your own address to see what the tool finds. For every row the tools do not reach, such as the form mailbox, a newsletter service or a payment provider, write down how you would find and remove one person's data there.

  7. Step 7: Get agreements with the companies that process data for you

    That is the host, the mail service, backup storage, analytics and any newsletter service. Ask each for its data processing agreement, and note in which country it keeps the data.

  8. Step 8: Secure the site and plan for a breach

    WordPress security: what to do, in order of what matters most covers updates, logins and backups. For a breach, decide now who makes the call and which authority you would notify. Hacked WordPress site: a runbook for the first hour covers the first steps on the site itself, starting with a written record of what you see and when.

  9. Step 9: Set how long each thing is kept

    WordPress's suggested text says comments and their metadata are kept indefinitely. Delete old form entries and clear the form mailbox on a set day. Ask the host how long it keeps access logs. WooCommerce has retention settings for inactive accounts and for orders by status. For backups, how to schedule automatic WordPress backups covers how many to keep. Keep a note of completed erasure requests, so that you can run them again after restoring a backup.

What not to rely on

  • A plugin or a banner on its own. A consent tool does not know what your forms store, what your host logs or why you keep any of it.
  • A notice that only informs. "By using this site you accept cookies" asks for nothing. The Board's guidelines say that merely proceeding with a service is not an active indication of choice.
  • The two tools as the whole answer to a request. WordPress's documentation says they gather data only from WordPress and participating plugins.

When to get help

A lawyer or your data protection authority answers what the law requires of you: which ground applies, what a contract must say, whether a breach must be reported. The upkeep is a separate job. Our WordPress maintenance service is a monthly care plan that keeps one WordPress site updated, backed up, monitored and scanned.

Common questions

Does the GDPR apply to my site if my business is outside the EU?

Article 3 says the regulation applies to a controller or processor outside the Union when the processing relates to offering goods or services to people who are in the Union, paid or not, or to monitoring their behavior there. Whether your site falls under that is a question for a lawyer.

Does WordPress set cookies for someone who only reads a page?

WordPress's documentation describes cookies for commenters who opt in, for the login page and for logged-in users. Themes, plugins and tags from other companies can set their own. To know what your site sets, look in a private window at what the browser has stored after a page loads.

Do I need a cookie banner?

The rule asks for consent before storing or reading information on a visitor's device, with the two exceptions described above. So it depends on what your site stores. List it, then check your authority's guidance on which items need consent.

More on this subject

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.