GDPR module

Cookie consent that actually blocks the scripts.

A polished consent banner, real script & iframe blocking, Google Consent Mode v2 and an audit-ready log of every choice — all from the WPStack panel you already use. No third-party consent service.

Included in every plan Nothing loads before consent
We value your privacy

We use cookies to enhance your experience and analyse traffic. Choose which cookies you allow.

Preferences Reject all Accept all
Analytics blocked
Consent recorded
Included in every planNo add-on or subscription
Prior-consent blockingNothing loads before opt-in
Google Consent Mode v2GA4 & Ads respect the choice
Everything for compliance

Consent, blocking and proof — in one module

From the banner on the first visit to the record you can hand an auditor, GDPR covers the whole consent lifecycle without a single extra plugin.

Consent banner & categories

A clean bar or floating box with Accept all, Reject all (equal prominence) and a granular Preferences dialog — functional, preferences, statistics and marketing.

Script & iframe blocking

Known trackers (GA, GTM, Pixel, Hotjar, YouTube, Maps…) are blocked server-side until consent — with click-to-load placeholders for embeds. First-party scripts are never touched.

Google Consent Mode v2

Fires gtag consent “default (denied)” before any tag, then “update” on consent, so GA4 and Google Ads behave correctly out of the box.

Consent proof logging

Every choice is recorded — categories, policy version and a hashed IP (no raw PII) — with a CSV export and retention controls for your audit trail.

Cookie-policy shortcode

Drop in an auto-grouped cookie table and a “Manage consent” link with two shortcodes — no manual list to maintain.

Re-open & revoke

A floating “Manage consent” button lets visitors change or withdraw their choice at any time, from any page.

Five languages, one click

Fill the whole banner — title, message, buttons and category descriptions — in English, Dutch, French, German or Spanish from the Content tab, then tweak any wording.

How it works

Compliant in minutes

No external consent platform, no per-visitor fees. Turn it on, pick what to block, and you’re covered the same day.

01

Switch it on

Enable GDPR from the WPStack modules panel. The banner and Consent Mode signals go live immediately with sensible EU defaults.

02

Choose what to block

Keep the built-in tracker list or add your own services by URL. Pick the banner layout, colours and category descriptions.

03

Publish — and prove it

Visitors consent; matching scripts unblock instantly. Every choice is logged for your records, and they can revoke it anytime.

Real blocking

Trackers stay off until they’re allowed

GDPR neutralises known scripts and embeds in the page itself, so consent means something. When a visitor accepts a category, only those scripts come to life — and blocked YouTube or Maps embeds show a friendly click-to-load placeholder.

  • Server-side blocking — cache-safe
  • Allow-list of known trackers; first-party untouched
  • Click-to-load placeholders for embeds
  • Add any custom service by URL fragment
WPStackPreferencesEU
FunctionalRequired for the site to work
PreferencesRemember your choices
StatisticsAnonymous analytics
MarketingAds & retargeting

YouTube embed blocked — accept marketing to view.

Consent Mode v2

Google tags that behave, automatically

Before any gtag loads, GDPR sets every Consent Mode signal to denied. The moment a visitor consents, it fires an update mapping their choice to the right signals — so GA4 and Google Ads stay compliant without you touching a line of tag code.

  • gtag consent “default” denied on every page
  • consent “update” on accept / change
  • Maps categories → ad & analytics signals
  • A dataLayer event for your own GTM triggers
WPStackConsent ModeGA
analytics_storagegranted on statistics consent
ad_storagedenied until marketing consent
security_storagealways granted
Audit-ready

Proof of every consent, on your own site

Each choice is written to a consent-records log with the categories accepted, the policy version in force and a hashed IP — no raw personal data. Bump the policy version to re-ask everyone, export the full log as CSV, and prune on a schedule.

  • Categories, policy version & timestamp
  • Hashed IP — never the raw address
  • One-click CSV export
  • Retention window with auto-prune
WPStackConsent recordsEU
9a38d30b · statistics, marketingv1
8c73e953 · functional onlyv1
41d0…e2 · all categoriesv1
Keep records for 12 months
Place it anywhere

Two shortcodes, and you’re documented

Beyond the banner (which is automatic once enabled), two shortcodes cover your policy page and re-consent — and they inherit your theme’s styling.

Cookie-policy table

An always-current table of the cookies you use, grouped by consent category — perfect for your privacy/cookie policy page.

[wpstack_gdpr_cookies]

Manage-consent link

A button that reopens the preferences dialog so visitors can change or withdraw consent. Place it in your footer or menu.

[wpstack_gdpr_manage]
Automatic bannerRenders site-wide the moment the module is switched on.
Floating widgetA “Manage consent” button so visitors can change their choice.
One settings panelBanner, blocking, records and policy — all under WPStack → GDPR.
Works with the stack

Better with the rest of WPStack

GDPR gates the tools you already run, so consent is respected everywhere on your site.

Analytics & AdsConsent Mode v2 keeps GA4 and Google Ads compliant.
ChatThe chat bubble only loads once functional consent is given.
FormsEmbedded third-party form scripts wait for consent.
WordPress6.0+ (6.5+ recommended)
PHP7.4+ (8.1+ recommended)
Region modelGDPR prior opt-in
ThemesWorks with any theme

Optional: Google Consent Mode v2 for GA4 / Ads · a cookie-policy page for the shortcode. No external accounts required.

FAQ

GDPR, answered

It blocks. Known trackers and embeds are neutralised in the page HTML server-side, so nothing runs before consent. A lightweight script then unblocks only the categories the visitor accepts — which keeps it compatible with page caching.

Yes — correctly. GDPR fires Google Consent Mode v2: consent defaults to denied, then updates to granted for the categories the visitor allows. GA4 and Google Ads adjust their behaviour accordingly, and the GA tag itself only loads once statistics consent is given.

GA/gtag, Google Tag Manager, Google Ads, Meta/Facebook Pixel, Hotjar, Microsoft Clarity, LinkedIn, X/Twitter, TikTok, plus YouTube, Vimeo and Google Maps embeds and reCAPTCHA. You can add any other script or embed by a URL fragment.

Yes. Every choice is written to a consent-records log with the accepted categories, policy version, timestamp and a hashed IP (never the raw address). You can export the full log as CSV and set how long records are kept.

Always. A floating “Manage consent” button reopens the preferences dialog on any page, and the [wpstack_gdpr_manage] shortcode does the same anywhere you place it. Changing a choice re-blocks or unblocks scripts immediately.

Yes. The Content tab has a “Fill all content” dropdown — pick English, Dutch, French, German or Spanish and it fills the title, message, every button label and all four category descriptions in that language, then saves. You can still edit any field afterwards.

Yes — like every WPStack module, GDPR is included in every plan. Switch it on per project from the modules panel whenever you need it.

Stop juggling plugins. Start with WPStack.

One system for consent, forms, bookings, logins and everything in between. Activate what you need today.

No credit card to explore the demo · Cancel anytime