Most GDPR advice for WordPress is either a scary wall of legal text or a plugin that promises to make you “compliant” with one click. Neither is honest. Compliance is mostly a set of practical habits, and a WordPress site owner can get the large majority of them right without a lawyer. This is a working checklist you can run through in an afternoon. It will not cover every edge case, but it will get an ordinary site into good shape and show you where you genuinely need professional advice.
Know what you collect and why
Everything starts with knowing your own data. Walk through your site as a visitor and write down every point where personal data is captured. Contact and comment forms, newsletter signups, WooCommerce orders and accounts, server logs that record IP addresses, and any analytics or embedded content that phones home. For each one, note what is collected, why you need it, and how long you keep it. This short inventory is the backbone of GDPR. If you cannot say why you hold a piece of data, that is usually a sign you should stop holding it.
- List every form, plugin and integration that touches personal data.
- For each, record the purpose, the legal basis, and the retention period.
- Delete data you no longer have a reason to keep.
Get consent right, especially for cookies
Consent under the GDPR has to be a genuine, freely given choice. In practice, on a WordPress site, this mostly shows up as cookie and tracking behaviour. Non-essential scripts, such as analytics and marketing tags, should not run until the visitor has actively agreed. A pre-ticked box or a banner that only offers “accept” is not valid consent. Use a consent tool that blocks non-essential scripts by default and records the choice. The cleaner approach is to need less consent in the first place: privacy-friendly, EU-based analytics and self-hosted assets reduce how much you have to ask for.
Stop leaking data through the front end
This is the step most sites miss. Many WordPress themes and plugins load resources from third parties, and each one can receive your visitor’s IP address before any consent is given. The classic example is web fonts loaded from a third-party host, which a German court has treated as an unlawful transfer of personal data. The fix is straightforward: self-host your fonts, and audit what else loads from outside your domain.
- Self-host web fonts instead of loading them from a third party.
- Open your browser’s network panel and see which external domains a page contacts.
- Replace or remove embeds, maps and players that transmit visitor data before consent.
- Prefer analytics that anonymise IP addresses and are hosted in the EU.
Publish an honest privacy policy
Your privacy policy should describe what you actually do, not what a generic template assumes. It needs to tell visitors what you collect, why, how long you keep it, who you share it with, and how they can exercise their rights. If you use a payment processor, an email service or analytics, name the categories of recipients. Keep it in plain language. A policy nobody can understand does not satisfy the spirit of the rules, and it does not build trust. Our own privacy policy is written to be read, and it is a reasonable model for the level of specificity to aim for.
Be ready for data subject requests
People have the right to ask what data you hold about them, to get a copy, and to have it deleted. You do not need an elaborate system, but you do need a plan. WordPress has built-in tools under Tools, Export Personal Data and Erase Personal Data, that handle core data and many well-behaved plugins. Know where those tools are, know which of your plugins store data outside them, and decide who in your organisation answers these requests. Being able to respond calmly within a reasonable time is most of what is required.
GDPR is less about paperwork and more about knowing your own data: what you hold, why, where it lives, and who can reach it.
Sort out processors and where data lives
Anyone who processes personal data on your behalf is a processor, and you should have a Data Processing Agreement with them. Your host is the big one, since it holds your database and backups. Read its DPA, check its sub-processor list, and confirm where your data is actually processed and which company controls it. This is where sovereignty and GDPR meet: keeping the hosting path inside the EU, under EU control, removes the hardest transfer questions before they arise. If your host cannot produce a DPA and a sub-processor list, that is a gap worth closing.
Write down the decisions you make along the way, because the regulation expects you to be able to demonstrate compliance, not just achieve it. You do not need a formal management system for a small site. A single document that records what you collect, your legal basis for each, your retention periods, and the processors you rely on is enough to show a regulator, or a nervous client, that you have thought this through. Update it when you add a plugin or change a tool, and revisit it once a year so it does not drift out of date.
Keep the basics secure
Security is part of GDPR, not separate from it. The regulation expects appropriate technical measures, and for a WordPress site the basics carry most of the weight: keep core, plugins and themes updated, enforce strong admin passwords, serve everything over HTTPS, and take regular backups you have actually tested. A breach caused by an unpatched plugin is both a security failure and a compliance failure. Staying current is the least glamorous and most effective control you have.
Where a managed platform helps
A good chunk of this checklist is ongoing work rather than a one-time task, and that is where hosting choices matter. On Celestio the hosting path is Swedish by construction: sites run on our own infrastructure in Falkenberg, with customer data processed inside the EU and no US cloud in the path, which settles the location and control questions above. Updates and tested backups are handled for you, so the security basics do not depend on someone remembering. Our managed WordPress service is built around exactly these habits, and the sovereignty page and legal hub lay out the specifics. The checklist is still yours to own, but the foundation stops fighting you.
This is practical guidance, not legal advice. For a full compliance assessment of your specific site, consult your DPO or legal counsel.
