Ninja Forms
This plugin is a service of Data443. Data443 is a Data Security and Compliance company traded on the OTCMarkets as ATDS. We have been providing leading GDPR compliance products such as Global Privacy Manager (Data443™ Global Privacy Manager), Blockchain privacy, and enterprise cloud eDiscovery tools. This plugin adds new privacy features to Ninja Forms. Your visitors can download or delete their form submissions automatically or submit a request for the site admin to do so. Until WordPress releases their own GDPR compliance update, this plugin requires The GDPR Framework to function (it’s free!) Make sure to also read the guide! You don’t need to drown your customers in pointless acceptance checkboxes if you know what you’re doing! Disclaimer Using Ninja Forms: GDPR Add-On does NOT guarantee compliance to GDPR. This plugin gives you general information and tools, but is NOT meant to serve as complete compliance package. Compliance to GDPR is risk-based ongoing process that involves your whole business. Data443 is not eligible for any claim or action based on any information or functionality provided by this plugin. Documentation How to use this plugin (the legal stuff explained): Legal grounds for processing data Full documentation: The WordPress Site Owner’s Guide to GDPR For developers: Developer Docs Knowledge Base: Knowledge Base Features ☑ Allow both users and visitors without an account to view, export and delete their form submissions or request the site admin to do so; ☑ Configure forms to be excluded from viewing, exporting or deleting. ☑ Support for anonymization: allow admin to select which fields must be anonymized; ☑ Track, manage and withdraw consent.
Top keywords
- gdpr7×2.63%
- compliance6×2.26%
- data4434×1.50%
- privacy4×1.50%
- admin3×1.13%
- forms3×1.13%
- site3×1.13%
- allow2×0.75%
- base2×0.75%
- compliance to gdpr2×0.75%
- data2×0.75%
- delete2×0.75%
Registration
Registration Email Blocker decides which email domains are acceptable on your site. Run it as a blocklist to refuse the providers you name, or as an allowlist to accept only the ones you approve. The check is applied everywhere an address can be set, not only on the registration form: the WordPress registration form the profile screen and “Add New User” in wp-admin the WordPress REST API WooCommerce registration the WooCommerce checkout, both the classic shortcode and the newer block based checkout the “Account details” page of the WooCommerce My Account area Checking email changes matters as much as checking registration. If only the registration form is guarded, an account can be created with an accepted address and switched to any other one a minute later. That option is on by default and can be turned off. What it does Two modes. Blocklist refuses the domains you list; allowlist accepts only the domains you list. Subdomains are matched in both directions, so listing example.com also covers mail.example.com. Two levels of strictness. Refuse the address outright, or allow it and record the attempt. Internationalized domains. Names such as почта.рф are converted to their punycode form when saved, so they match real addresses. Entries that are not valid domain names are reported back to you rather than silently dropped. Administrators are exempt by default, so a mistake in a domain list cannot lock you out of your own site. Report on existing accounts. See which accounts use a rejected domain, grouped by domain, and export the list as CSV. Batched notifications. Ask affected users to change their address. Mail is sent in small batches with a progress bar and a stop button, and anyone notified recently is skipped, so a timeout cannot restart the run from the beginning. A log you can live with. Attempts are recorded with a configurable level of detail, kept only as long as you choose, and trimmed automatically once a day. Repeated attempts from the same IP address within a minute are recorded once, so a bot cycling through addresses cannot inflate the table. Editable defaults. Both domain lists ship pre-filled and can be changed freely; a button restores them to the versions shipped with the plugin whenever you want the newest entries. Privacy The plugin stores registration attempts in a table in your own database. Nothing is sent anywhere else, and no external service is contacted. You decide how much is kept: email addresses in full, partially masked, reduced to the domain, or not stored at all IP addresses in full, anonymized, or not stored at all a retention period after which entries are deleted automatically The plugin registers a personal data exporter and eraser, so log entries are included in the export and erasure requests WordPress produces under Tools → Export/Erase Personal Data, and it suggests text for your privacy policy. The connection address is used by default; forwarded headers such as X-Forwarded-For are trusted only if you state that the site is behind a reverse proxy, because a visitor can otherwise put any value there. A note on what a blocklist can do A blocklist only refuses the domains you thought of. Somebody who wants an account will find a provider that is not on the list. When the set of acceptable providers is actually known, the allowlist is the mode that holds. The plugin is a technical control over email domains. It does not by itself make a site compliant with any particular legislation, and the site owner remains responsible for their own legal obligations. Russian Federal Law 406-FZ The plugin was originally written for Russian site owners working towards Federal Law No. 406-FZ, which requires authorization through a phone number, ESIA, a biometric system or another Russian-controlled system. This plugin implements none of those. It only controls the email domain used at registration, which the law does not address directly. Treat it as one piece of housekeeping, not as a compliance solution, and take legal advice about your own obligations. Support Questions and bug reports are welcome on the plugin’s support forum on WordPress.org. Developer: Studio Playner — https://profiles.wordpress.org/altcreative/ Support Development This plugin is free and will stay free. If it saves you time, you can support its development through YooKassa. Contributions go towards new features, compatibility with new WordPress and WooCommerce releases, and answering support questions. License This plugin is licensed under the GPL v2 or later. Copyright (C) 2026 Studio Playner This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.