Consent banner & categories
A clean bar or floating box with Accept all, Reject all (equal prominence) and a granular Preferences dialog — functional, preferences, statistics and marketing.
A polished consent banner, real script & iframe blocking, Google Consent Mode v2 and an audit-ready log of every choice — all from the WPStack panel you already use. No third-party consent service.
From the banner on the first visit to the record you can hand an auditor, GDPR covers the whole consent lifecycle without a single extra plugin.
A clean bar or floating box with Accept all, Reject all (equal prominence) and a granular Preferences dialog — functional, preferences, statistics and marketing.
Known trackers (GA, GTM, Pixel, Hotjar, YouTube, Maps…) are blocked server-side until consent — with click-to-load placeholders for embeds. First-party scripts are never touched.
Fires gtag consent “default (denied)” before any tag, then “update” on consent, so GA4 and Google Ads behave correctly out of the box.
Every choice is recorded — categories, policy version and a hashed IP (no raw PII) — with a CSV export and retention controls for your audit trail.
Drop in an auto-grouped cookie table and a “Manage consent” link with two shortcodes — no manual list to maintain.
A floating “Manage consent” button lets visitors change or withdraw their choice at any time, from any page.
Fill the whole banner — title, message, buttons and category descriptions — in English, Dutch, French, German or Spanish from the Content tab, then tweak any wording.
No external consent platform, no per-visitor fees. Turn it on, pick what to block, and you’re covered the same day.
Enable GDPR from the WPStack modules panel. The banner and Consent Mode signals go live immediately with sensible EU defaults.
Keep the built-in tracker list or add your own services by URL. Pick the banner layout, colours and category descriptions.
Visitors consent; matching scripts unblock instantly. Every choice is logged for your records, and they can revoke it anytime.
GDPR neutralises known scripts and embeds in the page itself, so consent means something. When a visitor accepts a category, only those scripts come to life — and blocked YouTube or Maps embeds show a friendly click-to-load placeholder.
YouTube embed blocked — accept marketing to view.
Before any gtag loads, GDPR sets every Consent Mode signal to denied. The moment a visitor consents, it fires an update mapping their choice to the right signals — so GA4 and Google Ads stay compliant without you touching a line of tag code.
Each choice is written to a consent-records log with the categories accepted, the policy version in force and a hashed IP — no raw personal data. Bump the policy version to re-ask everyone, export the full log as CSV, and prune on a schedule.
Beyond the banner (which is automatic once enabled), two shortcodes cover your policy page and re-consent — and they inherit your theme’s styling.
An always-current table of the cookies you use, grouped by consent category — perfect for your privacy/cookie policy page.
[wpstack_gdpr_cookies]
A button that reopens the preferences dialog so visitors can change or withdraw consent. Place it in your footer or menu.
[wpstack_gdpr_manage]
GDPR gates the tools you already run, so consent is respected everywhere on your site.
Optional: Google Consent Mode v2 for GA4 / Ads · a cookie-policy page for the shortcode. No external accounts required.
It blocks. Known trackers and embeds are neutralised in the page HTML server-side, so nothing runs before consent. A lightweight script then unblocks only the categories the visitor accepts — which keeps it compatible with page caching.
Yes — correctly. GDPR fires Google Consent Mode v2: consent defaults to denied, then updates to granted for the categories the visitor allows. GA4 and Google Ads adjust their behaviour accordingly, and the GA tag itself only loads once statistics consent is given.
GA/gtag, Google Tag Manager, Google Ads, Meta/Facebook Pixel, Hotjar, Microsoft Clarity, LinkedIn, X/Twitter, TikTok, plus YouTube, Vimeo and Google Maps embeds and reCAPTCHA. You can add any other script or embed by a URL fragment.
Yes. Every choice is written to a consent-records log with the accepted categories, policy version, timestamp and a hashed IP (never the raw address). You can export the full log as CSV and set how long records are kept.
Always. A floating “Manage consent” button reopens the preferences dialog on any page, and the [wpstack_gdpr_manage] shortcode does the same anywhere you place it. Changing a choice re-blocks or unblocks scripts immediately.
Yes. The Content tab has a “Fill all content” dropdown — pick English, Dutch, French, German or Spanish and it fills the title, message, every button label and all four category descriptions in that language, then saves. You can still edit any field afterwards.
Yes — like every WPStack module, GDPR is included in every plan. Switch it on per project from the modules panel whenever you need it.
One system for consent, forms, bookings, logins and everything in between. Activate what you need today.
No credit card to explore the demo · Cancel anytime