Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Google Tag Manager for WordPress is a popular plugin that injects the Google Tag Manager container so you can deploy analytics and marketing tags without editing code.
Google Tag Manager for WordPress, originally by DuracellTomi, is a widely used plugin that injects the Google Tag Manager container into your WordPress pages. It lets marketers add and manage analytics, advertising and other tags from the GTM interface without editing site code, and it can pass rich data layer information about pages, users and ecommerce events.
The plugin and the GTM container themselves do not set tracking cookies. However, the container loads the tags you configure, such as Google Analytics or advertising pixels, and those tags set cookies and collect personal data. The data layer can also expose user and order details to those tags.
Because Google Tag Manager is the delivery mechanism for non essential tags, your consent obligations depend on what you deploy through it. The container is also fetched from Google servers in the United States, which exposes the visitor IP address. Misconfigured containers commonly fire analytics and advertising tags before consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Configure the container so that tags requiring consent only fire after the visitor opts in, ideally using Google Consent Mode and your consent platform. The plugin should not be used to bypass the banner; treat every analytics and marketing tag as requiring prior consent.
The plugin runs on your WordPress host, but the GTM library is delivered from Google in the United States, and many tags transfer data there too. Put a transfer mechanism in place for those flows and disclose Google as a recipient in your privacy policy.
Map every tag in your container and classify it by purpose. Block consent dependent tags until opt in, enable Consent Mode, and use the data layer carefully so you do not leak personal data to tags. Keep your tag inventory, cookie policy and records of processing aligned.
Websites using Google Tag Manager for WordPress must obtain user consent under GDPR regulations.
DPIA considerations
The plugin itself sets no tracking cookies, but it deploys tags that often do. Assess each tag you add through it; a DPIA may be needed where those tags involve large scale analytics, advertising or profiling.
Sample consent text
We use Google Tag Manager to load website tags. Tags that set analytics or marketing cookies run only after you give consent through our cookie banner.
Third-party domains contacted
googletagmanager.comwww.googletagmanager.comGoogle Tag Manager for WordPress collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The plugin and the GTM container do not set tracking cookies themselves. The tags you deploy through it, such as analytics and advertising tags, are what set cookies and collect data.
Using GTM does not by itself require consent, but the tags it loads usually do. Configure the container so non essential tags fire only after the visitor consents.
For the tags deployed through GTM the legal basis is normally consent (Art. 6(1)(a) GDPR). GTM is only the delivery layer, so the basis depends on each tag purpose.
Yes. The GTM container is loaded from Google in the United States, exposing the visitor IP, and many tags send data there. Use a transfer mechanism and disclose Google as a recipient.
Possibly. The plugin alone is low risk, but assess the tags you deploy; large scale analytics, advertising or profiling delivered through GTM can require a DPIA.
Use Google Consent Mode and your consent platform to gate tags, keep a tag inventory, and avoid pushing personal data into the data layer unnecessarily. Test that no consent dependent tag fires before opt in.
Alternatives include Matomo Tag Manager, server side GTM, or adding tags manually. Matomo Tag Manager can be self hosted in the EU for a lower transfer profile.
List the cookies set by the tags you deploy through GTM, not GTM itself, and update the policy whenever you add or remove tags. A scanner can help detect the cookies each tag creates.