Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
GDPR Cookie Consent by WebToffee is one of the most installed cookie consent plugins for WordPress. It adds a configurable banner, a preference centre, a cookie scanner and a consent log, and can automatically block analytics and advertising scripts until the visitor opts in. Because it runs inside your own WordPress site, the banner logic and the consent records stay on your server rather than on a third party platform, which simplifies the international transfer question for the consent data itself.
GDPR Cookie Consent, published by WebToffee, is one of the most installed cookie consent plugins for WordPress, with millions of active installations. It runs entirely inside your WordPress site and adds a configurable cookie banner, a consent preference centre, a built in cookie scanner, and a consent log. Because it is self hosted, the banner logic and the consent records stay on your own server rather than on a vendor platform.
The plugin stores a visitor decision in first party cookies such as viewed_cookie_policy and CookieLawInfoConsent, plus one cookielawinfo-checkbox cookie per category covering necessary, functional, analytics, performance and advertisement. These cookies hold yes or no flags and the categories accepted, typically for one year. When consent logging is enabled, the plugin saves a record in your WordPress database with a pseudonymous identifier, the date, the banner version and the categories chosen, which you control entirely.
The consent cookies are strictly necessary to remember the visitor choice, so they benefit from the exemption in article 5(3) of the ePrivacy Directive and do not require consent themselves. The plugin helps you meet the GDPR requirement that analytics and advertising scripts must not run before consent, and the accountability duty of article 5(2) to keep proof of consent. Its value depends on enabling the script blocker so that tags such as Google Analytics or Meta Pixel are genuinely held back.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Use the auto blocking or the shortcode based blocking to ensure non essential scripts only load after the matching category is accepted, and verify this with the browser developer tools. Because GDPR Cookie Consent is self hosted, it does not by itself transfer personal data to a third country: the consent data lives in your WordPress database in your chosen hosting location. Remember that the trackers it controls, such as US analytics or advertising tags, may still create their own transfers once consent is given.
Run the cookie scanner, map each discovered cookie to a category and a clear description, and keep that list in sync with your privacy and cookie policy. Make the reject option as visible as accept, expose a persistent link to reopen the preference centre, and set a sensible consent expiry. Enable the consent log and export it when a supervisory authority asks for evidence, and re test the banner after every plugin or theme change.
Websites using GDPR Cookie Consent by WebToffee must obtain user consent under GDPR regulations.
DPIA considerations
The plugin records consent rather than profiling visitors, so it does not by itself require a DPIA. Assess the trackers it governs instead: a DPIA may be needed for the analytics or advertising tools that fire after consent, especially when they involve profiling or transfers to the United States. Document the script blocker configuration, the consent retention period and where your WordPress database is hosted.
Sample consent text
This website uses the WebToffee GDPR Cookie Consent plugin to manage your cookie choices. It stores strictly necessary cookies such as viewed_cookie_policy and cookielawinfo-checkbox cookies that remember your preferences for up to one year, all kept on our own servers. No analytics or advertising cookie is set until you accept the corresponding category, and you can change or withdraw your consent at any time from the cookie settings link.
Third-party domains contacted
webtoffee.comstore.webtoffee.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| viewed_cookie_policy | First party, persistent | 1 year | Records that the visitor has seen the banner and stores the overall consent decision. |
| CookieLawInfoConsent | First party, persistent | 1 year | Stores a summary of the categories the visitor accepted or rejected. |
| cookielawinfo-checkbox-necessary | First party, persistent | 1 year | Stores consent for the strictly necessary cookie category. |
| cookielawinfo-checkbox-analytics | First party, persistent | 1 year | Stores consent for the analytics cookie category. |
| cookielawinfo-checkbox-advertisement | First party, persistent | 1 year | Stores consent for the advertisement cookie category. |
GDPR Cookie Consent by WebToffee is an essential service, but transparency matters. Manage all your consent with FlowConsent.
It sets first party cookies that record your choice: viewed_cookie_policy and CookieLawInfoConsent store whether you consented and which categories you accepted, and a cookielawinfo-checkbox cookie is set per category such as necessary, analytics and advertisement. They typically last one year and contain preference flags, not your name.
No. The cookies the plugin uses to remember a choice are strictly necessary and exempt under article 5(3) of the ePrivacy Directive. The plugin is the mechanism that collects consent for other trackers, so enable its script blocker to keep analytics and advertising from running before the visitor accepts.
The consent cookies rely on the ePrivacy exemption for strictly necessary cookies, while keeping the consent log relies on your accountability and consent obligations under GDPR articles 5(2) and 7. The analytics and advertising scripts that the plugin gates need consent under GDPR article 6(1)(a) and ePrivacy article 5(3).
Not on its own. Because it is self hosted, the consent data stays in your WordPress database at your hosting location. Transfers come from the third party scripts the plugin controls, for example a US analytics or advertising tag, once consent is given, so document those tools separately.
The plugin itself does not require a DPIA because it logs consent rather than profiling people. Assess the trackers it governs: a DPIA may be needed for large scale analytics or advertising that profiles users or transfers data to the US, under GDPR article 35.
Enable the automatic or shortcode script blocker, run the cookie scanner and categorise every cookie, make reject as easy as accept, and add a persistent settings link so visitors can withdraw consent. Keep the cookie table aligned with your cookie policy and turn on the consent log.
Other WordPress and SaaS options include CookieYes, Complianz, Cookiebot, Axeptio, Didomi and the open source Klaro. Self hosted plugins such as this one and Complianz keep consent data on your own server, while SaaS platforms add hosted scanning and IAB TCF support.
Re run the cookie scanner regularly, review the detected cookies, and publish the generated cookie table in your policy through the plugin shortcode. After adding any new tag, re scan, categorise the new cookie and confirm the blocker rule before publishing.