Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
NextGEN Gallery, by Imagely, is the most widely used photo gallery plugin for WordPress, used to create image galleries, albums and slideshows. It runs on your own WordPress server and typically sets only functional cookies, such as remembering a lightbox or gallery state. Because it processes little personal data in standard use, its privacy footprint is low, although the Pro ecommerce features and any embedded external resources need separate attention.
NextGEN Gallery is a long established WordPress plugin, developed by Imagely, for creating and managing photo galleries, albums, slideshows and image collections. It is one of the most popular gallery plugins, with a free version and a Pro version that adds ecommerce, proofing and additional display styles. It runs on your own WordPress server.
In standard use NextGEN Gallery sets only functional cookies, for example to remember a chosen gallery view or lightbox state, and it serves images from your own server. The plugin does not, by default, track visitors across sites. If you enable the Pro ecommerce features, customer and order data is processed, and any payment gateway you connect handles payment data.
The functional gallery cookies are generally treated as not requiring consent because they support a feature the visitor uses, although you should disclose them. The GDPR applies to any personal data the Pro ecommerce features collect, such as customer details for photo orders, which need a lawful basis and clear information.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The standard functional gallery cookies usually do not require prior consent, since they only support display preferences. If you embed external resources such as web fonts, a third party lightbox or social sharing, those may set non essential cookies or contact third parties and would then require consent. Review what the gallery actually loads.
NextGEN Gallery runs on your own server and serves images locally, so in standard use there is no transfer of visitor personal data to a third country. Licensing and update checks contact Imagely in the United States, but these do not involve visitor data. If you connect external services or a payment gateway, assess their transfers separately.
Confirm what NextGEN Gallery loads on your pages, disclose the functional gallery cookies in your privacy or cookie notice, and rely on legitimate interest for them. If you use the Pro ecommerce features, define a lawful basis and retention for customer and order data and assess any payment gateway transfers. Review the configuration when you add external resources.
Websites using NextGEN Gallery must obtain user consent under GDPR regulations.
DPIA considerations
In standard use NextGEN Gallery sets only functional cookies and serves images from your own server. Key DPIA considerations: (1) the functional gallery cookies generally do not require consent; (2) the plugin does not track visitors across sites by default; (3) the Pro ecommerce features process customer and order data; (4) embedded external resources may require consent. A full DPIA is generally not required for a standard gallery.
Sample consent text
We use NextGEN Gallery to display our photo galleries. In standard use the plugin sets only functional cookies that remember your display preferences and serves images from our server. You can find more details in our privacy notice.
Third-party domains contacted
imagely.complugins.imagely.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ngg_gallery_view | Functional | Session | Remembers the selected gallery view or page within a gallery during a visit. |
| ngg_lightbox | Functional | 30 days | Stores lightbox display preferences so images open consistently. |
NextGEN Gallery collects user analytics data — you legally need a consent banner. Try FlowConsent free.
In standard use NextGEN Gallery sets only functional cookies, such as remembering a gallery view or lightbox state. These support a feature the visitor uses and are generally not subject to consent, although you should still disclose them in your notices.
Usually not for the standard functional gallery cookies, because they only support display preferences and can rely on legitimate interest. If you embed external resources such as web fonts or social sharing that set non essential cookies, those would require consent.
The functional cookies rely on legitimate interest under Article 6(1)(f) GDPR, as they support a feature the visitor is using. The Pro ecommerce features process customer data on the basis of contract for the order, with clear information and retention.
In standard use NextGEN Gallery serves images from your own server, so there is no transfer of visitor data to a third country. Licensing and update checks contact Imagely in the United States but do not involve visitor data. Any payment gateway you connect for the Pro features should be assessed separately.
A DPIA is usually not required for a standard image gallery with a low privacy footprint. If you use the Pro ecommerce features at scale or process special category images, a short assessment of the customer data and any payment transfers is advisable.
Confirm what NextGEN Gallery loads, disclose the functional cookies in your notices, and rely on legitimate interest for them. If you embed external resources, gate those behind consent. For the Pro ecommerce features, define a lawful basis and retention for customer data and assess payment transfers.
Other WordPress gallery plugins include Envira Gallery, Modula, FooGallery and Photo Gallery by 10Web. They share the same low privacy profile for basic galleries, so the main considerations are any external resources they load and, for ecommerce, the handling of customer and payment data.
For standard functional gallery cookies a brief mention in your cookie or privacy notice is enough. If you enable external resources or the Pro ecommerce features, add the relevant cookies and describe the customer data processing and any transfers, and keep this aligned with your configuration.