FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. WordPress
W

WordPress

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does WordPress do?

WordPress is the world's most popular CMS, powering over 40% of all websites. For GDPR purposes, the core WordPress software has minimal privacy implications — it sets session cookies and comment author cookies that are strictly necessary. GDPR complexity comes from the plugin ecosystem: analytics plugins, contact form plugins, commenting systems, social share buttons, and advertising plugins each introduce their own data processing. Self-hosted WordPress GDPR compliance is the deployer's responsibility. WordPress.com (Automattic) is US-hosted requiring SCCs.

What is WordPress?

WordPress is an open-source content management system (CMS) powering over 43% of all websites globally. It comes in two forms: WordPress.org (self-hosted, free software you run on your own server) and WordPress.com (hosted by Automattic on US infrastructure). The core WordPress software provides a minimal privacy footprint. GDPR complexity comes almost entirely from the plugin ecosystem — WordPress has over 60,000 plugins, many of which add tracking, analytics, advertising, and communication features.

WordPress core cookies

WordPress core sets: wordpress_logged_in (authentication, session), wordpress_test_cookie (verifies cookies work, session), comment_author (remembers commenter name/email for 1 year). The first two are strictly necessary for site function. The comment_author cookie is a preference cookie that improves user experience. None require consent under most DPA interpretations, though some legal teams prefer to include them in cookie notices.

The plugin GDPR minefield

Every plugin that adds external functionality creates GDPR obligations. Common offenders: Google Analytics plugins (require consent, US transfer), contact form plugins storing submissions (data retention, erasure requests), social share buttons (third-party cookie loading), comment systems like Disqus (extensive tracking), live chat plugins (consent required), and page builder plugins loading Google Fonts CDN. Audit every plugin before installation.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

WordPress.com vs self-hosted

WordPress.com is hosted by Automattic (US). All site data, user data, and visitor data is processed on Automattic''s US infrastructure requiring SCCs. Self-hosted WordPress on a European server keeps all data in the EU with no third-country transfer required for the hosting itself. For EU organisations with strict data residency requirements, self-hosted WordPress on an EU server is the recommended configuration.

Practical compliance steps

Install a CMP plugin (Cookiebot, Axeptio, CookieYes). Audit all plugins for GDPR implications. Remove unnecessary plugins. Replace Google Analytics with a GDPR-compliant alternative or configure consent. Self-host Google Fonts. Use a GDPR-compliant contact form plugin with data retention controls. Add a comprehensive privacy policy. For WordPress.com, sign Automattic''s DPA.

GDPR consent category

Other

Websites using WordPress must obtain user consent under GDPR regulations.

Legal basisWordPress core sets strictly necessary cookies (wordpress_logged_in, comment_author) that do not require consent. Any additional tracking, analytics, or advertising plugins require appropriate legal bases and consent management. Legitimate interest may apply for security and anti-spam measures (Akismet).
Risk levellow
Applicable regulationsGDPR compliance depends on server location, plugins, and embedded services. WordPress.com requires SCCs for EU users. Self-hosted WordPress GDPR compliance is entirely the deployer's responsibility.

DPIA considerations

A DPIA is not required for standard WordPress websites. It may become relevant for membership sites processing extensive personal data, healthcare or sensitive data sites, or sites with large-scale behavioural tracking via advertising plugins.

Sample consent text

This website uses cookies. Essential cookies are required for basic site functions. We use additional cookies for analytics and functionality improvements. You can manage your cookie preferences below.

Technical details

Tracking methodCMS platform, PHP-based, first-party cookies for sessions and comments, plugin ecosystem adds third-party tracking
Server locationDeployer-controlled (self-hosted) or United States (WordPress.com/Automattic)
Cookieless tracking availableYes

Third-party domains contacted

wordpress.orgwordpress.comautomattic.com

Cookies placed

NameTypeDurationPurpose
wordpress_logged_insessionSessionWordPress authentication cookie for logged-in users — strictly necessary, no consent required
wp-settingspersistent1 yearWordPress interface preference cookie for logged-in users — strictly necessary, no consent required

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Is WordPress GDPR compliant?

WordPress core is minimal privacy risk. Compliance depends on plugins and hosting. Self-hosted on EU server with privacy-conscious plugins can be fully compliant. WordPress.com needs SCCs. The responsibility is yours as site operator.

What cookies does WordPress set by default?

wordpress_logged_in (authentication, session), wordpress_test_cookie (session), comment_author (1 year). No analytics or advertising cookies in core. The first two are strictly necessary.

Which WordPress plugins have GDPR issues?

Jetpack (US), Contact Form 7 (no retention controls by default), Google Site Kit (adds GA4), MonsterInsights, WooCommerce, social share plugins. Audit every plugin before installation.

Does WordPress.com require a DPA?

Yes. Sign Automattic's DPA at automattic.com/privacy. WordPress.com processes all site data on US infrastructure. The DPA includes SCCs for EU transfers.

How do I add a cookie consent banner to WordPress?

Install a CMP plugin: Cookiebot, CookieYes, Complianz, or Axeptio (all have free WordPress plugins). Integrate with Google Consent Mode v2 if using Google tools.

How do I handle GDPR requests in WordPress?

Access: Tools, Export Personal Data. Erasure: Tools, Erase Personal Data. For WooCommerce use the built-in customer data tools. Respond within 30 days.

Does WooCommerce need special GDPR configuration?

Yes. Enable: order anonymisation after set period, customer deletion, privacy policy at checkout, marketing opt-in checkbox. WooCommerce has built-in GDPR tools at WooCommerce, Settings, Privacy.

Is self-hosted WordPress better for GDPR than WordPress.com?

For EU organisations yes — no US transfers for hosting, full data sovereignty, no DPA with Automattic needed for hosting itself.