GDPR & Cookie Consent for WordPress Sites: What Changed in 2026

GDPR & Cookie Consent for WordPress Sites: What Changed in 2026 — HD Web Mobile

If your site serves visitors in the EU, including dealer sites syncing inventory from mobile.de, GDPR compliance isn’t optional, and enforcement has only gotten stricter. Here’s what a WordPress site actually needs, without the legal jargon.

What GDPR Requires, in Plain Terms

Consent before non-essential cookies load. Analytics, ad tracking, and embedded video such as YouTube or social widgets all set cookies, and none of them should fire until the visitor actively consents. Implied consent from continued browsing is not sufficient.

A genuine choice to decline. A consent banner with only an Accept button and no equally easy way to reject is a common compliance failure, not a technicality. Regulators have fined sites specifically over this pattern.

Clear information about what you collect and why, in a privacy policy that’s actually accurate for your site, not a generic template that lists tools you don’t use.

A way for people to request their data or ask you to delete it. You need a process, even a simple one such as an email address that gets acted on, for handling these requests.

What This Means for a Dealer or Business Site

Contact forms, WhatsApp click-to-chat, live chat widgets, and CRM integrations all collect personal data such as name, phone number, and message content. Each of these needs to be covered in your privacy policy, and any that set cookies before consent is given need to sit behind your consent banner.

Practical Setup for WordPress

1. Use a proper consent management plugin such as CookieYes or Complianz, configured to actually block scripts pre-consent, not just display a banner cosmetically. This distinction is the most common compliance gap we see: the banner shows, but the tracking scripts fire anyway.

2. Audit what’s actually setting cookies. Analytics, embedded maps, social share buttons, and chat widgets are the usual list. Anything not strictly necessary for the page to function needs to sit behind consent.

3. Update your privacy policy to match reality, listing the actual plugins and services you use, such as Google Analytics, WPForms, or WhatsApp Business, not a boilerplate list.

4. Set a process for data requests. Even a simple documented workflow, such as someone checking a dedicated inbox weekly and being able to locate or delete a contact’s data, satisfies the requirement for most small business sites.

Getting This Wrong Is Expensive

Non-compliance isn’t just a legal risk in the abstract. Regulators across the EU have issued real fines to small businesses over consent banners that don’t actually block tracking. For a dealer site with visitors across Germany and the EU, this is worth getting right once rather than fixing under pressure later.

CookieYes vs Complianz: Which One Fits

Plugin Strongest for
CookieYes Simple setup, automatic cookie scanning, generous free tier for small sites
Complianz Deeper regional rule handling (GDPR, CCPA, and others together), better fit for sites with EU + non-EU traffic

For a single-market dealer site targeting EU visitors, CookieYes is usually the faster setup. For a business serving multiple regions with different privacy laws, Complianz’s rule-matrix approach is worth the extra configuration time.

Frequently Asked Questions

Does a cookie banner alone make a site GDPR compliant?

No — a banner that displays but doesn’t actually block scripts until consent is given is one of the most common compliance failures regulators have fined over. The scripts have to be technically blocked, not just visually deferred.

Do I need consent for Google Analytics specifically?

Yes, standard Google Analytics sets tracking cookies and requires prior consent under GDPR — it should sit behind your consent banner like any other non-essential tracking script.

What happens if a visitor never responds to the consent banner?

No consent means no non-essential cookies fire — the safe default is to treat silence as “not consented,” not as implied permission.

HD Web Mobile sets up GDPR-compliant consent and privacy configuration as part of every WordPress build. Ask us for a compliance check.


Ready to start your project?

Share your brief and we’ll propose the right approach — a full site, a landing page, or a custom plugin.