G
Privacy & Legal Free WordPress.org

GDPR

4.3 (58 reviews)
· 10K+ active installs · By Trew Knowledge
Active Installs
10K+
Rating
4.3 / 5
Version
v2.1.2
Last Updated
Jun 2026
Share

Plugin Review

AI-Researched

What is GDPR?

The GDPR plugin, developed by Trew Knowledge, has been a fixture in the WordPress ecosystem for 8 years. It aims to assist Controllers, Data Processors, and Data Protection Officers (DPOs) in meeting obligations under the General Data Protection Regulation. Currently at version 2.1.2, it holds 10K+ active installs. The plugin carries a 4.3/5 rating from 58 reviews, with 76% of those being five-star. This longevity suggests a stable tool for gdpr compliance wordpress efforts, though its 12% one-star rate indicates some users face issues.

The plugin addresses core GDPR requirements like consent logs, data access requests, and breach notifications. It is tested up to WordPress 6.9.4, ensuring compatibility with recent core updates. The developer maintains an active GitHub repository for collaboration and documentation, which is a positive sign for transparency.

Key Features of GDPR

  • Consent Management with Re-Consent – Logs user consent to Privacy Policy changes and flags admins to seek re-consent on policy updates.
  • Cookie Preference UI – A front-end interface for users to opt in or out of cookies, supporting "Always Active," "Toggled," and "Opt-Out Link" formats.
  • Right to Erasure with Double Opt-In – Processes data deletion requests with a confirmation email, plus pseudonymization or reassignment of user data.
  • Data Access & Portability Exports – Admins or Data Subjects can export user data in XML or JSON formats via email lookup or front-end requests.
  • Encrypted Audit Logs – Maintains encrypted logs of compliance activity for the lifetime of each Data Subject.
  • Data Breach Notification System – Logs breaches and sends batch email notifications to affected Data Subjects with hourly send limits.
  • Telemetry Tracker – Visualizes installed plugins and website data to help assess data processing scope.
  • Data Processor Settings – Publishes contact information for Data Processors, aiding gdpr data processor obligations wordpress compliance.

Who Should Use GDPR?

This plugin suits site owners who need a structured approach to how to make wordpress gdpr compliant. Its feature set targets those with moderate technical skill—users comfortable configuring settings pages and understanding consent flows. The plugin handles obligations for Controllers and Data Processors, making it relevant for EU-based businesses, charities, or any site collecting EU resident data. With 10K+ installs, it is used by a niche but active audience.

Ideal use cases include membership sites, e-commerce stores, or blogs with comment systems that store personal data. The plugin requires PHP 5.6+ and WordPress 4.7+, so it works on older hosting setups. However, its 0% support resolution rate in the last 2 months (0 open threads, 0 resolved) suggests self-reliance is necessary. Beginners may struggle without the GitHub wiki documentation.

Installation & Setup

Installation follows the standard WordPress process: upload the plugin folder to /wp-content/plugins/, activate it, then fill out all settings page sections. The setup is not beginner-friendly due to the need to configure Privacy Policy pages, cookie categories, and email limits. The plugin provides shortcodes and helper functions documented on GitHub, which developers can use to customize consent banners and data request forms.

Support & Community

Support data shows a concerning trend. In the last 2 months, the plugin had 0 open threads and 0 resolved threads, resulting in a 0% resolution rate. This likely contributes to the 12% one-star ratings, as users may encounter bugs without recourse. The developer does maintain a GitHub repository for pull requests and issue tracking, which provides an alternative support channel. For a plugin handling legal compliance, this support gap is a notable risk.

The rating distribution (76% five-star) indicates many users find the features effective when they work. The 8-year development history suggests the plugin is mature, but the lack of recent support activity raises questions about long-term maintenance. For gdpr compliance for wordpress site needs, this plugin offers depth but requires technical comfort and a fallback plan for troubleshooting.

Pros & Cons

What's Good
  • With 10K+ active installs and a 4.3 rating from 58 reviews, it is a moderately trusted tool for GDPR compliance tasks.
  • It offers a complete consent lifecycle, including front-end cookie preference UI, privacy policy version control, and mandatory re-consent on policy updates.
  • It supports Data Subject rights like erasure with double opt-in confirmation, data access via email lookup, and portability exports in XML or JSON formats.
  • Encrypted audit logs and a two-factor decryption token provide a verifiable record of compliance activity for the lifetime of each data subject.
  • The plugin includes data breach notification logs and batch email capabilities, helping administrators respond to incidents directly from the dashboard.
Drawbacks
  • Despite a 76% 12% one-star reviews suggest notable user dissatisfaction, potentially due to complexity or bugs.
  • The plugin has zero resolved support threads out of zero total, indicating either a lack of community support or that the support forum is not actively monitored.
  • Its reliance on a login-based consent gate (users cannot log in without consenting) may conflict with sites that require guest access or have non-logged-in user flows.

Technical Details

Requires WordPress
4.7+
Requires PHP
5.6+
Tested up to WP
6.9.4
First Released
2018 (8+ years)
Support (last 2 months)
0 threads

Feature Tags

compliance gdpr general-data-protection-regulation law privacy

Frequently Asked Questions