GDPR is eight years old, yet the majority of SME WordPress sites remain partially non-compliant. Not out of bad faith — out of technical ignorance. A cookie banner thrown together hastily, a Contact Form 7 sending data without a framework, third-party plugins tracking without your knowledge: so many legal risks sleeping under the hood. This guide tours the GDPR compliance of a WordPress site in 2026, without useless jargon.
Let’s be clear about the stakes: the CNIL and its European counterparts have tightened controls, and sanctions no longer target only the giants. An SME can be flagged for a non-compliant cookie banner or a data leak via a neglected plugin. The good news: bringing a WordPress site into compliance is entirely achievable with a method. Target audience: SME owners, DPOs and IT managers.
What has changed since 2018
GDPR itself hasn’t changed, but its application has tightened and sharpened. Three major developments weigh in 2026:
- Cookie consent has become strict. No more “by continuing, you accept” banner. Consent must be explicit, granular (by purpose), as easy to refuse as to accept, and revocable. A site that drops tracking cookies before consent is in breach.
- Data transfers outside the EU are scrutinised. After the invalidation then replacement of transatlantic transfer frameworks, using a US service (analytics, fonts, CDN) without appropriate safeguards is a major watch point.
- Liability extends to processors. You’re responsible for the plugins and third-party services that process your visitors’ data. “It’s the plugin that does it” is not a defence.
Cookies and trackers: the end of implicit consent
This is the most visible and most often mishandled point. The 2026 rule: no non-essential cookie should be dropped before the user’s explicit consent. This implies:
- A genuine consent management platform (CMP), not a mere cosmetic banner.
- The effective blocking of tracking scripts (Google Analytics, ad pixels, embedded videos) as long as consent isn’t given.
- Granular choices: the user accepts statistics but refuses advertising, for example.
- A refusal as simple as acceptance — a “reject all” button at the same level as “accept all”.
- Consent logging (proof you collected it properly).
Many WordPress sites have a banner that informs but blocks nothing: that’s precisely the case that exposes you to a sanction.
Contact forms: what Contact Form 7 doesn’t do on its own
A form collects personal data (name, email, sometimes more). Contact Form 7, very widespread, doesn’t natively integrate compliance: you have to add it. Concretely:
- An explicit consent checkbox (not pre-ticked) with a statement of purpose and a link to the privacy policy.
- A defined retention period: messages stored indefinitely (via Flamingo for example) are a risk. Plan automatic purging.
- Securing transmission: form data must not travel in clear text.
- Minimisation: only ask for data that is genuinely necessary.
Third-party plugins: the risk zone
Every plugin that loads an external resource or processes data is a potential processor. The frequent culprits: Google fonts loaded from Google’s servers (to host locally), maps, social media widgets, chat tools, marketing pixels. Auditing plugins is essential: for each, identify what data it processes, where it goes, and whether consent is required. An abandoned or unmaintained plugin is a double risk — GDPR and security.
Backups and data localisation
Your backups contain personal data. Where are they stored? If it’s on a non-EU cloud without safeguards, that’s a non-compliance point. Likewise the site’s hosting: an EU host considerably simplifies compliance. Data localisation — site, backups, logs, emails — is an integral part of the GDPR audit.
Right to erasure in practice
A user can request the erasure of their data. In practice on WordPress, this means being able to find and delete their data everywhere: accounts, orders (within legal accounting limits), form messages, comments, and data in third-party plugins. WordPress offers native tools for exporting and erasing personal data (since version 4.9.6) — but you still have to have configured and tested them. A right to erasure you can’t technically execute is a non-compliance.
Checklist: 12-point WordPress GDPR audit
- CMP installed and actually blocking non-essential cookies before consent.
- “Reject all” button at the same level as “accept all”.
- Google Analytics (or equivalent) anonymised and conditioned on consent.
- External fonts and resources hosted locally where possible.
- Forms with an explicit, non-pre-ticked consent checkbox.
- Defined retention period and automatic message purging.
- Privacy policy up to date, clear and accessible.
- Processing register maintained and up to date.
- Audit of third-party plugins and their data flows.
- Hosting and backups localised in the EU (or appropriate safeguards).
- Right-to-erasure procedure tested and operational.
- Security updates current (a hacked site = data leak).
In practice
GDPR compliance of a WordPress site isn’t a box to tick once and for all: it’s a state to maintain, crossing the legal, the technical and security. Most non-compliances come from invisible technical details — a script that loads too early, a plugin that tracks, a poorly localised backup. A methodical audit brings them to light.
At Seganiko, we conduct WordPress GDPR compliance audits as part of our maintenance and WordPress development services. We run your site through the 12 points above and deliver a prioritised compliance plan. The first audit is free.
Need to improve your SEO?
We audit your site and implement a measurable SEO strategy.
See our SEO service →