Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
WordPress Default describes the cookies a plain core WordPress install sets, which are strictly necessary functional cookies for logged in users and commenters that generally do not require consent.
WordPress core is the open source content management system in its default, self hosted form, without any additional plugins or third party services bolted on. It powers a very large share of the web and gives operators full control over where the site is hosted and what runs on it. Because it is self hosted and first party, the privacy footprint of a plain WordPress install is much smaller than many assume, and most of its data behaviour is decided by the choices the operator makes afterwards.
By default core WordPress sets first party cookies only for logged in users and for people who leave comments, using cookies such as wordpress_logged_in, wp-settings and comment_author. Anonymous visitors who simply read pages normally receive no cookies at all, which means a default WordPress site can be largely cookieless for the general public. This makes the baseline behaviour very privacy friendly compared with platforms that track every visitor from the first page view.
Self hosted WordPress runs on infrastructure the operator chooses, so data location is entirely under their control and core WordPress does not send data to any third country by itself. The software source is published at wordpress.org, but the running site serves content from the operator first party domain with no third party tracking by default. International transfers only appear if the operator selects overseas hosting or adds plugins and services that route data abroad.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The login and comment cookies are strictly necessary for the functions the user is asking for, so they do not require prior consent and rest on necessity and legitimate interest. Consent only becomes relevant once the operator adds analytics, advertising, social embeds or other plugins that place non essential cookies or process data for additional purposes. In a clean default install there is usually nothing to consent to for anonymous visitors.
The compliance risk of core WordPress is low, because the default cookies are first party, necessary and limited to authenticated users and commenters. The real risk in any WordPress project comes from what is added later, so the practical task is to keep an inventory of plugins and themes and to assess each addition that introduces tracking or transfers. Treating the core platform as the low risk baseline and watching the additions is the most accurate way to manage the project.
To keep a WordPress site compliant, start from the cookieless default and add only what you need, documenting every plugin, embed or analytics tool that changes the cookie or data picture. Where you add non essential cookies, place them behind a consent banner and update the cookie policy to reflect them, and choose hosting that keeps data in the region you intend. By preserving the lean default and controlling additions, you keep the platform simple, fast and easy to explain to visitors.
Websites using WordPress (Core, Self Hosted) must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is normally not needed for a plain core WordPress install because it only sets strictly necessary functional cookies for logged in users and commenters. The assessment focus shifts as soon as plugins, analytics, embeds or advertising are added, since those introduce tracking and possible third country transfers. Evaluate the full plugin stack and any external embeds rather than core WordPress alone.
Sample consent text
This site runs on WordPress and uses strictly necessary cookies to keep logged in users signed in and to remember your details when you leave a comment. These functional cookies do not require consent. If we add analytics or marketing tools we will ask for your consent separately.
Third-party domains contacted
api.wordpress.orgwordpress.orgsecure.gravatar.coms.w.orgCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| wordpress_test_cookie | Functional | Session | Checks whether the visitor browser accepts cookies so the login process can work |
| wordpress_logged_in_[hash] | Functional | Session or 14 days | Identifies that a user is logged in and keeps the authenticated session active |
| wordpress_sec_[hash] | Functional | Session or 14 days | Secures the authenticated session within the admin area and protected pages |
| wp-settings-[UID] | Functional | 1 year | Stores personal admin and interface preferences for a logged in user |
| comment_author_[hash] | Functional | 347 days | Remembers the name and website of a commenter to prefill the comment form |
| comment_author_email_[hash] | Functional | 347 days | Remembers the email address of a commenter to prefill the comment form |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
A plain WordPress install sets only first party functional cookies. The wordpress_test_cookie checks cookie support, wordpress_logged_in and wordpress_sec keep authenticated users signed in, wp-settings stores admin preferences and the comment_author cookies prefill the comment form. Anonymous readers who do not log in or comment usually receive no persistent cookies.
Generally no. The core cookies are strictly necessary functional cookies that fall under the exemption in Article 5(3) of the ePrivacy Directive, so they do not require consent. Comment cookies are set only after the user actively chooses to comment and can be declined. Consent becomes necessary only when plugins or external services add non essential tracking.
The limited core processing relies on contract performance and legitimate interest under Article 6(1)(b) and (f) of the GDPR, because the cookies are needed to deliver the login and commenting functions the user requested. No consent based marketing processing happens in a default install. The basis changes if you add analytics or advertising.
Core WordPress does not transfer personal data to third countries on its own. Where your data lives depends entirely on the hosting provider you choose, so a European host keeps data within the European Economic Area. Third country transfers normally appear only through external services such as a content delivery network, Gravatar or analytics that you add.
A data protection impact assessment is normally not required for a plain core install, because it only sets strictly necessary functional cookies with low privacy impact. The need for a DPIA arises when you add plugins, profiling, analytics or advertising that introduce tracking and possible transfers. Assess the full plugin stack rather than core WordPress alone.
Document the core functional cookies in your privacy and cookie policy and state that they are strictly necessary. You do not need a consent banner for core cookies alone, but keep an inventory and update it whenever you install a plugin or embed. Choose a hosting region that suits your users and keep WordPress updated for security.
Alternatives include other content management systems such as Ghost, Joomla, Drupal or static site generators, each with its own cookie behavior. For privacy minded sites a static generator sets almost no cookies, while hosted platforms may add their own tracking. The key difference is usually the plugins and external services rather than the core platform.
Re scan your site whenever you install or update a plugin, theme or embed, because those are what usually introduce new cookies and third party requests. Keep the core functional cookies documented and add any non essential cookies that plugins bring, along with a consent banner if needed. Review the policy after every significant change to the site.