Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
OnePress Social Locker is a WordPress plugin that hides content until a visitor likes or shares on social networks; it loads Facebook, Twitter and LinkedIn widgets that set third party cookies and send data to those providers.
OnePress Social Locker is a WordPress plugin that hides a piece of content until the visitor performs a social action such as a like, a share or a tweet. To offer those actions it embeds widgets and software development kits from social networks like Facebook, Twitter and LinkedIn. The plugin itself runs on the website server, but the social widgets it loads are operated by large platforms based mainly in the United States. This makes it far more than a layout tool from a privacy perspective.
When the social widgets load, the networks receive the visitor IP address, the page URL and device information, and they set their own cookies in the browser. These cookies are typically used for advertising and cross site tracking, not just for the share button. The plugin also stores a local marker, through a cookie or local storage, to remember that a visitor has already unlocked the content. The combination means several third party tracking cookies can be placed as soon as the locker appears.
Loading the third party widgets writes and reads cookies that are not strictly necessary, so Art. 5(3) of the ePrivacy Directive requires prior consent. The data sent to the social networks is personal data, and because the platforms often act as independent or joint controllers, the website operator must clarify the roles. The lawful basis for the processing is consent under Art. 6(1)(a) of the GDPR. A particular concern is whether consent is freely given when access to content is conditioned on a social action.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
No social widget should load and no cookie should be set before the visitor gives explicit consent. The widgets must therefore be blocked by your consent management platform until opt in, and the banner should name the networks involved and the United States transfer. Because the GDPR requires consent to be freely given, you should make sure visitors are not unfairly coerced, for example by offering an alternative path to the content. Visitors must be able to refuse and to withdraw consent without detriment.
The embedded networks are operated from the United States, so loading them transfers personal data to a third country. Meta, X, Microsoft and Google each receive data when their widget runs, and you must rely on a valid mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses with a transfer impact assessment. You should verify the current certification status of each provider and document supplementary measures where needed. Until consent is given and a safeguard is in place, the widgets should stay blocked.
Block the Social Locker widgets behind a consent management platform so they load only after explicit opt in, and provide an alternative way to access valuable content so consent stays freely given. List every social network, its cookies and the United States transfer in your cookie policy and privacy notice. Keep records of consent and of the transfer safeguards, and review them regularly. If the risk remains high, consider replacing the locker with simple share buttons that load only on click.
Websites using OnePress Social Locker must obtain user consent under GDPR regulations.
DPIA considerations
Because Social Locker forces visitors to interact with third party social networks to unlock content, and because those networks set tracking cookies and receive data in the United States, a data protection impact assessment is strongly advisable. The assessment should examine whether conditioning access to content on a social action is compatible with the requirement that consent be freely given, and it should document the cross border transfers. The risk is heightened where the locked content is necessary or valuable, since visitors may feel pressured to accept.
Sample consent text
This content is locked behind social sharing features provided by Facebook, Twitter and LinkedIn. With your consent these networks load and may set cookies and receive your IP address and page data, including transfers to the United States. You can decline and reach the content another way, and you can withdraw your consent at any time.
Third-party domains contacted
connect.facebook.netfacebook.complatform.twitter.complatform.linkedin.comapis.google.comonepress-media.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| bizpanda_unlocked | first party | 1 year | Marker set by the plugin to remember that the visitor has already unlocked the gated content |
| fr | third party | 3 months | Set by Facebook to deliver advertising and to track and measure visitors across sites |
| _fbp | third party | 3 months | Set by Facebook to identify browsers for advertising and analytics purposes |
| personalization_id | third party | 2 years | Set by Twitter to enable cross site personalisation and advertising |
| bcookie | third party | 1 year | Set by LinkedIn as a browser identifier for advertising and tracking |
| lidc | third party | 1 day | Set by LinkedIn to route requests and support its embedded widgets |
OnePress Social Locker collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The plugin itself stores a small marker, through a cookie or local storage, to remember that a visitor has already unlocked the content. The more significant cookies come from the embedded social networks, for example Facebook, Twitter and LinkedIn, which set advertising and tracking cookies when their widgets load. These third party cookies are not strictly necessary and are subject to consent.
Yes. The social widgets set non essential third party cookies and send data abroad, so prior consent is required under Art. 5(3) of the ePrivacy Directive before they load. The widgets must stay blocked until the visitor opts in, and you must also ensure the consent is freely given despite the content being locked.
The lawful basis is consent under Art. 6(1)(a) GDPR, because loading third party social trackers is not necessary to deliver the website. Legitimate interest is not appropriate here given the advertising cookies and the cross border transfers. Where the platforms act as joint controllers, you may also need a joint controller arrangement.
Yes. The embedded networks such as Meta, X, Microsoft and Google are operated from the United States, so loading their widgets transfers personal data to a third country. You need a valid mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses with a transfer impact assessment, and the widgets should not load before consent.
A data protection impact assessment is strongly advisable because of the third party tracking, the United States transfers and the pressure that locking content can place on the freedom of consent. The assessment should test whether the locker is compatible with freely given consent and should document the transfers and safeguards. Treat this tool as high risk by default.
Block every social widget behind a consent management platform so nothing loads before explicit opt in, and offer an alternative route to the content so consent remains freely given. Name each network, its cookies and the United States transfer in your cookie and privacy notices, and keep consent and transfer records. Review the setup regularly and remove networks you do not need.
Yes. Replace the locker with click to load social share buttons that only contact the networks after the visitor clicks, or use a self hosted sharing solution such as Shariff that avoids loading trackers by default. Offering content freely and inviting voluntary shares is both lower risk and more compatible with the rules on freely given consent.
List the local unlock marker set by the plugin and, more importantly, the cookies set by each embedded network with their purpose and duration. Identify Facebook, Twitter, LinkedIn and any other platform as third party processors or controllers, and describe the United States transfer and its safeguard. Update the policy whenever you add or remove a social network from the locker.