Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA
This is Cookie Compliance for WordPress — the WordPress component of Cookie Compliance, the consent management platform by Hu-manity.co. (Previously published as “Compliance by Hu-manity.co”, and before that “Cookie Notice”.) One product: this plugin runs the consent banner on your WordPress site, and the Cookie Compliance dashboard is where you configure it, manage every domain you own, and keep your consent records. Cookie Compliance is a fully featured Consent Management Platform (CMP) that provides automated compliance features and enhanced design controls in a state-of-the-art web application. Cookie Compliance enables websites to take a proactive approach to data protection and consent laws. It is the first solution to offer Intentional Consent, a new consent framework that incorporates the latest guidelines from over 100+ countries, and emerging standards from leading international organizations like the IEEE and European Center for Digital Rights (noyb.eu). Cookie Compliance provides a beautiful, multi-level experience and includes new choices and controls for site visitors to better understand and engage in data privacy decisions. You can run this plugin two ways. In Banner Only mode it works on its own, with no account, and gives you the consent banner and its settings. In Connected mode — free or paid — you sign in to Cookie Compliance from inside WordPress and the plugin unlocks the platform features listed below: automatic script blocking, purpose categories, consent records, Google, Microsoft and Facebook consent modes, multilingual banners and multi-domain management. The two lists below say exactly which features belong to which mode. Our Cookie Compliance web application introduces a more ethical, proactive way to capture and manage consent. This early version of the emerging Intentional Consent framework is a result of Hu-manity.co’s ongoing work with top Fortune 500 companies, governments, and standards organizations, who believe that the imbalanced relationship between consumers and corporations is unsustainable when it comes to data privacy and consent online. We are making it available for all website owners and operators who share this belief and support our mission to eliminate the dark patterns in online consent. Matt Sinderbrand – Chief Platform Officer, Hu-manity.co Banner Only mode (this plugin on its own, no account) Cookie Compliance for WordPress provides a simple, customizable website banner to help your website comply with certain cookie consent requirements. Banner features: Customizable notice message Consent on click, scroll or close Multiple cookie expiry options Link to Privacy Policy page WordPress Privacy Policy page synchronization WPML and Polylang compatible SEO friendly Connected mode (this plugin + the Cookie Compliance dashboard) Signed in to Cookie Compliance, on a free or paid plan, you get access to the most up-to-date formatting guidelines and technical compliance requirements for over 100 countries and legal jurisdictions. Banner features: Intentional Consent provides 3 equal buttons to give site visitors the ability to accept none, some, or all cookies through packaged choices called Data Access Levels. Data Access Levels improve consent conversion and eliminate the dark pattern of deceptive, non-equal choices in the first layer. Complies with equal choice principle prescribed under GDPR and other data protection laws. Consent duration selector gives visitor control over how long their consent remains valid for your site. Enables your site to align with recent guidelines from EU Data Protection Authorities, which state that cookie consent should be valid for no longer than a period of 6 months. Cookie purpose categories make it easy for website visitors to customize their consent by category. Complies with affirmative, opt-in consent requirements prescribed under GDPR and other data protection laws. Consent metrics displays the visitor’s consent record and a list of blocked / allowed 3rd parties directly in the expanded level of the banner. Complies with latest guidance from EU Data Protection Authorities like CNIL (France) and ICO (UK). Customizable Privacy Paper provides helpful information to improve visitor comprehension and understanding of the data sharing risks and benefits. Allows you to summarize core components of your sites privacy notice and aligns with the informed principle prescribed by GDPR rules for valid consent capture. Configurable Privacy Contact allows you to provide contact information for a business’ data privacy admin, as well as helpful links to data subject request forms and other data privacy resources. Aligns with the informed principle prescribed by GDPR rules for valid consent capture. Cookie Compliance dashboard features: Consent analytics dashboard shows event data for number of visits and provides a “trust score” to help you track how site visitors are setting their consent. Make adjustments to your banner to improve your cookie acceptance rate and monitor progress via the consent activity graph. Default configurations for GDPR, CCPA and more help to remove dark patterns and allow for quick and easy deployment of the consent banner without any guesswork. Customize the design of any default configuration to match the look and feel of your site. Automatic script blocking blocks all non-essential cookie scripts and iFrames by default and complies with valid consent rules under GDPR and other data protection laws; in order to be compliant, your site must record visitor consent before setting or sending cookies. Google Consent Mode v2 ensures that your website can still gather valuable insights and perform effectively while respecting users’ privacy preferences by dynamically adjusting the behavior of Google services (ad_storage, analytics_storage, ad_user_data, ad_personalization) according to user consent. Facebook Consent Mode allows your website to measure the impact of your ads on Facebook, track website activities and conversions and automatically deliver ads to Facebook if the user has agreed to. Consent record storage automatically stores a record of each consent and makes these records available for export. Complies with proof-of-consent requirements prescribed under GDPR and other data protection laws. Multilingual support automatically translates all banner text strings and allows you to provide custom translations for every text field to ensure visitors get a consistent consent experience. Multidomain management allows you to manage additional Free or Professional domains under a single account and enables you to customize banner configuration and design for each domain independently. Cookie Compliance proactive approach: For all businesses, the resources required to stay ahead of the latest regulations increases with the passage of each new law. With enforcement of compliance violations increasing daily, we believe it is critical for us as a trusted consent vendor to do everything in our power to help you stay ahead of these laws and remove the risk to your business Cookie Compliance covers all current and upcoming regulations: GDPR (EU) ePrivacy Directive (EU) ePrivacy Regulation (EU) PECR (UK) LGPD (Brazil) PIPEDA (Canada) PDPB (India) CCPA (California, US) VCDPA (Virginia, US) Colorado Privacy Act (US) CPRA (California, US) Cookie Compliance incorporates all recent formatting guidance: European Data Protection Supervisor (EDPS) ICO (United Kingdom) CNIL (France) GPDP (Italy) BfDl (Germany) AEPD (Spain) European Center for Digital Rights (noyb.eu) Cookie Compliance targets dark patterns Dark Patterns are user interface (UI) techniques that push site visitors to make decisions (such as agreeing to the installation of cookies on their devices) that they might not otherwise make. The most common Dark Pattern is the lack of an equal “reject all” button on the first layer of the consent notice. Dark Patterns are explicitly banned under GDPR and other data protection laws. As a part of our proactive approach, Cookie Compliance is configured by default to prevent Dark Patterns through our unique Intentional Consent design. Privacy Cookie Compliance for WordPress is a Consent Management Platform client. Depending on how you use it, the plugin may send data to Hu-manity.co services on your behalf. This section describes what data leaves your WordPress server and when. It is kept up to date as the plugin evolves; material changes are noted in the changelog. Plugin-only mode (Banner Only) If you install the plugin and choose “Banner Only” in the Welcome screen — or never open the Welcome screen at all — the plugin operates entirely on your WordPress site. No account is created and the plugin does not initiate calls to Hu-manity.co services. Connected mode (Free or Professional) If you create a Cookie Compliance account from the Welcome screen (or log into an existing one), the plugin connects your site to the Hu-manity.co platform. While connected, the plugin sends data over HTTPS to Hu-manity.co’s platform services (hosted under *-api.hu-manity.co) for the following purposes: Account sign-up and sign-in, and registering your site as an application. Fetching and updating your banner configuration. Fetching consent analytics and individual consent records shown in the Audit Trail. Processing subscription payments (Professional plans only). The data sent depends on the feature you are using and typically includes: Account-identifying data such as the email address and password used for sign-up or sign-in. Site-identifying data such as your site’s URL, title, description, and language. Application credentials (App ID and Secret Key) issued to your site at registration, included with subsequent platform requests. Subscription and billing data for Professional plans, such as the selected plan identifier and a one-time payment token described below. Integration telemetry such as the plugin version, the admin interface and language you use, which of the plugin’s own options are switched on, basic diagnostics about how it is running, and which of the caching or JavaScript-optimisation plugins it needs to stay compatible with are active on your site, and whether a Google, Meta or Microsoft tracking plugin is active, sent as HTTP headers so we can understand integration adoption and support the plugin. Operational metadata such as the timestamp and locale of a request, as is normal for HTTPS API calls. As the plugin evolves, additional non-personal fields of the same categories listed above may be sent to support new features. Material changes are noted in the changelog. Payments (Professional plans only) Payment card details are collected by Braintree’s hosted-fields SDK running in your browser and are tokenized there. The plugin and Hu-manity.co servers do not receive raw card data. A one-time, non-replayable Braintree token is sent to Hu-manity.co’s platform to create the subscription. Deactivation feedback If you deactivate the plugin and fill in the optional deactivation feedback form, the reason you select, any free-text comment you type, and your site URL are sent once to Hu-manity.co so we can improve the product. Submitting the form is optional; clicking “Skip” sends nothing. This applies to both Plugin-only and Connected modes. The banner shown to your site visitors The consent banner shown to your site visitors is served from cdn.hu-manity.co/hu-banner.min.js. When a visitor interacts with the banner, the banner script (running in the visitor’s browser, not the plugin) communicates directly with Hu-manity.co services to record the consent decision — this is what makes consent records available to you in the Audit Trail. This data flow is between the visitor’s browser and Hu-manity.co and does not pass through your WordPress server. Because these requests originate in the visitor’s browser, the visitor’s IP address is visible to Hu-manity.co as part of standard HTTPS network handling. Local state set by the plugin The plugin stores operational state in three places. None of this is transmitted to Hu-manity.co: On your WordPress server (options and transients) — for example, a welcome-modal dismissal timestamp (cookie_notice_welcome_dismissed) and short-lived caches of API tokens and configuration. In the admin user’s browser (localStorage) — for example, first-run setup flags such as cn_setup_wizard_complete_* and cn_has_platform_config_*. In visitor browsers (a short-lived hu-form cookie, 5 minutes) — set when forms with consent integration are submitted. Used locally by the form-consent flow. As the plugin evolves, additional keys may be stored in any of these locations. They remain local state on your site or in the user’s browser — not data sent to Hu-manity.co. Material changes to this pattern would be noted in the changelog. Data the plugin does not send The plugin does not transmit visitor IP addresses, cookies, page URLs, or page content as data fields. IP addresses are, as with any HTTPS request, visible to the receiving server as part of standard network handling. The plugin does not transmit the content of your posts, pages, users, or WordPress database. The plugin does not send data to third parties other than Hu-manity.co and, for Professional plan payments, Braintree (a PayPal service). Service providers Hu-manity.co / Cookie Compliance — primary service provider. Terms of Service: https://cookie-compliance.co/terms-of-service/ Privacy contact: https://cookie-compliance.co/documentation/privacy-contact/ Braintree (a PayPal service) — processes Professional plan signups initiated from the plugin (not invoked for Banner Only or Free). When you manage your subscription from the Cookie Compliance web application, additional payment gateway providers may process your billing information. Hu-manity.co’s email subscription service — receives your account email address and name to manage newsletter and operational email preferences. You can unsubscribe at any time via the email footer or by deleting your account. Account and consent data is processed in the European Union (AWS Ireland region). Hu-manity.co’s public marketing websites (hu-manity.co, cookie-compliance.co) are hosted separately in the United States. How long we retain your data Plugin-side caches on your WordPress server (API tokens, subscription data, configuration) are short-lived, with TTLs typically up to 24 hours. The visitor hu-form cookie expires after 5 minutes. On the Hu-manity.co platform, account information and consent records are retained as long as your Cookie Compliance account is active, and are removed when the account is deleted or via an erasure request. What rights you have over your data Stop further sends. Deactivate the plugin from the Plugins screen — no further plugin-initiated API calls will be made. Export consent records. Site owners can export cookie-consent and privacy-consent logs as CSV from the Cookie Compliance web application. Delete your account and all associated data. The Cookie Compliance web application has an account-deletion flow. Triggering it cancels active subscriptions, deletes your apps and banner configuration, removes your consent records from the platform, and nullifies free-text personal data before deleting the account. Erasure of visitor data (GDPR Article 17 / CCPA Delete). To request erasure of a specific visitor’s records (by email, session ID, IP, or consent ID), contact Hu-manity.co via the privacy contact page above. Hu-manity.co processes the request and erases the matching records from its storage systems within 30 days, in line with GDPR Article 12. Manage consent (visitors). Site visitors can adjust their consent at any time through the consent banner.
Top keywords
- consent57×2.37%
- data39×1.62%
- cookie34×1.41%
- co29×1.20%
- compliance28×1.16%
- hu-manity26×1.08%
- hu-manity co26×1.08%
- cookie compliance24×1.00%
- banner22×0.91%
- site21×0.87%
- account14×0.58%
- privacy14×0.58%
SureCookie – GDPR Cookie Consent Banner, Cookie Scanner & Script Blocking
SureCookie is a WordPress cookie consent plugin that helps you scan cookies, display a customizable cookie banner, block non-essential scripts before consent, and store consent logs inside your WordPress database. It is built for site owners, E-commerce stores, agencies, bloggers, and WordPress professionals who want more than a basic cookie notice. SureCookie helps you understand what cookies and third-party services are running on your site, lets visitors manage their choices, and gives you a practical consent workflow without visitor-based pricing. 👉 Try the live demo of SureCookie. Not Just a Cookie Banner A cookie notice can tell visitors that your site uses cookies, but that alone does not manage consent. If analytics scripts, marketing pixels, video embeds, maps, or tag manager scripts run before visitors choose, the banner is only cosmetic. SureCookie connects the banner to the rest of the workflow: scan the site, review detected cookies, block non-essential scripts before consent, store consent logs locally, and keep your cookie policy easier to maintain. How SureCookie Works SureCookie follows a simple WordPress cookie consent workflow: Scan selected pages with the real browser cookie scanner. Review detected cookies, scripts, resources, and third-party domains. Organize cookies into consent categories such as Essential, Functional, Analytics, and Marketing. Enable script blocking so non-essential scripts wait for consent. Show the cookie consent banner and preference modal to visitors. Store consent logs locally in WordPress for review and export. Generate or connect a cookie policy page that reflects your cookie setup. This makes SureCookie more than a WordPress cookie banner. Many cookie plugins focus only on the visitor-facing notice, while SureCookie focuses on what happens before and after it: cookie detection, script blocking, consent records, and policy support. Free Features Included The WordPress.org version of SureCookie includes the core consent workflow: Cookie consent banner: Show a clean banner or notice for visitors. Preference modal: Let visitors review and manage cookie categories. Accept, Accept All, Decline, and Preferences buttons: Control the button text and order. Real browser cookie scanner: Scan selected pages using a browser-based scanning service. Cookie categories: Use Essential, Functional, Analytics, Marketing, and Uncategorized categories. See managing cookie categories. Custom cookies: Add and manage cookies manually when needed. Script blocking: Block non-essential scripts before consent is given. Resource blocking: Manage scripts, iframes, embeds, and objects found during scans. Consent logs: Store visitor choices inside your WordPress database. Consent log filters: Search and filter logs by action, country, IP, and session ID. Consent PDF export: Export individual consent records for documentation. Consent retention settings: Control how long consent logs are kept. Monthly automatic scanning: Schedule recurring scans on the free plan. Scan history and change detection: See what changed between scans, including newly detected cookies and domains. Rule-based category suggestions: Get suggested categories for newly detected cookies. Cookie policy page: Generate a page with dynamic cookie tables. Re-consent controls: Add a Cookie Preferences link through a shortcode or menu item. Re-request consent: Ask all visitors to review choices again when needed. Google Consent Mode support: Send consent states to supported Google services. WP Consent API support: Share consent state with compatible WordPress plugins. Multilingual support: Work with WPML and Polylang for banner and admin text. RTL support: Display frontend cookie policy content correctly for RTL languages. MCP and WordPress Abilities support: Enable AI assistant access to SureCookie management actions when supported. No visitor-based limits: SureCookie does not charge by traffic or monthly visitors. Free vs Pro Clarity Everything listed above is in the free plugin. Advanced workflows are reserved for SureCookie Pro: weekly automatic scans, email scan digests, auto-apply behavior, compliance guard workflows, geographic targeting (which applies CCPA-style opt-out rules per region), and consent forwarding. Compare on the features page or see plans and pricing. Real Browser Cookie Scanner SureCookie uses a browser-based scanning service at https://library.surecookie.com/ to inspect selected pages. See how the cookie scanner works. Instead of only reading static HTML, the scanner loads your pages in a real browser environment. This helps detect cookies and resources that appear after page load, through tag managers, or through third-party scripts. The scanner can help identify: Analytics, marketing, advertising, functional, and preference cookies WooCommerce and WordPress session cookies Third-party domains and resources Tag manager loaded and dynamically injected scripts Monthly Automatic Scanning When enabled, SureCookie runs scheduled monthly scans through WP-Cron. The scan uses the same scanner engine, respects the configured scan scope, and records the latest scan history. Full setup is in the automatic scheduled scanning guide. The scan history can show: Newly detected cookies Removed cookies Recategorized cookies Newly detected third-party domains Whether the scan was manual or automatic The last scan date and cookie count Script Blocking Before Consent SureCookie can block non-essential scripts before the visitor gives consent. When blocking is enabled, SureCookie processes the frontend HTML and converts matching resources so they do not execute until the relevant cookie category is allowed. It can handle scripts as well as embedded content such as iframes, embeds, and objects. This matters because a banner alone does not stop tracking. SureCookie is designed to connect consent choices with technical enforcement. The script blocker also includes safeguards so it skips admin pages, REST requests, AJAX requests, feeds, JSON responses, XML responses, and scanner bypass requests. The resource and script blocking guide covers how scripts, iframes and embeds are matched. Customizable Banner and Preferences SureCookie gives you control over the visitor-facing consent experience. You can customize: Banner message and description Rich text banner content Accept, Accept All, Decline, and Preferences button labels Button order Banner position and width Banner logo Banner animation Background overlay Preference modal heading and description Cookie category labels and descriptions Custom CSS Visitors can accept all cookies, decline non-essential cookies, or open the preferences modal and choose specific categories. See customizing banner content and banner layout for every option, and custom CSS for banner styling if you need finer control. Consent Logs Stored Locally SureCookie stores consent records inside your WordPress database. This is different from many SaaS consent management platforms where consent records live on an external platform. With SureCookie, your consent logs stay on your WordPress site and can be reviewed from the admin area. Consent logs can include: User session ID Consent action, such as accepted, declined, or partially accepted Cookie category preferences Masked IP address Timestamp Country Admins can view, search, filter, delete, and export logs from WordPress. SureCookie also includes retention settings so you can control how long logs are kept. See understanding consent logs and exporting consent logs to PDF or CSV. Cookie Policy Page and Generator SureCookie includes a cookie policy generator that can create a Cookie Policy page for your website. The generated page uses native WordPress blocks and includes a dynamic shortcode that displays cookie tables grouped by category and provider. The cookie policy content can include: Cookie categories Cookie names Purpose or description Duration Domain Last updated timestamp A table of contents when multiple categories are available You can edit the generated policy page in the WordPress editor and keep the dynamic cookie table connected to your scanned and manually added cookies. Walkthrough: how to generate a cookie policy page. Re-Consent and Re-Request Consent Visitors should be able to change their choices later. SureCookie includes a re-consent shortcode: [surecookie_reconsent_button] You can use it to add a Cookie Preferences button on your site. SureCookie can also add a virtual Cookie Preferences item to a selected WordPress navigation menu. Admins can also re-request consent from all visitors. This is useful after updating your cookie policy, adding new tracking tools, changing categories, or making a major consent workflow change. See the re-consent guide. Google Consent Mode When enabled, SureCookie sends consent states for supported Google services and updates them when visitors change their preferences. Setup steps: setting up Google Consent Mode v2. It maps SureCookie categories to Google consent signals, detects Google services from enqueued scripts or the page HTML, and hides block toggles that Google Consent Mode already manages. WP Consent API SureCookie reads its consent cookie and syncs the visitor’s consent state so compatible WordPress plugins can check consent using the standardized WP Consent API flow. Default category mapping includes: Essential to functional Functional to preferences Analytics to statistics Marketing to marketing Developers can customize mappings through filters. Multilingual and RTL Support SureCookie includes multilingual compatibility for WPML and Polylang. It can register and translate banner text, button labels, preference modal text, category labels, and related frontend strings. It also includes RTL support for cookie policy layouts. MCP and WordPress Abilities When enabled, AI assistants and compatible tools can use structured SureCookie abilities to manage settings, cookie categories, consent logs, cookie management, and site scanner actions. Scanner start actions still require care because they contact an external scanning service. Who Should Use SureCookie? SureCookie is a good fit for: WordPress site owners and agencies who need a cookie consent banner across client sites E-commerce stores and publishers using analytics, ads, pixels, embeds, or marketing tools Businesses running tag managers, heatmaps, video embeds, maps, forms, or CRM and conversion tracking Developers who want a WordPress-native consent workflow with hooks and APIs, and consent logs kept inside WordPress Important Legal Note SureCookie provides technical tools for cookie scanning, script blocking, consent collection, consent logging, and cookie policy management. No WordPress plugin can guarantee legal compliance on its own. Privacy and cookie requirements depend on your website, visitors, region, policies, data processing practices, and legal obligations. For legal advice, consult a qualified legal professional. External Services SureCookie uses external services for cookie scanning, site verification, and geolocation. Cookie Scanning SureCookie connects to https://library.surecookie.com/ to provide real browser-based cookie scanning and smart categorization. When you run a scan, SureCookie sends the selected page URLs to the scanning service. A browser-based scanner visits those pages and detects cookies, scripts, resources, and third-party domains. Scanner Registration and Authentication Before the first scan, SureCookie performs a one-time registration handshake with library.surecookie.com/api/register. The request sends: Site URL WordPress admin email SureCookie version A temporary installation nonce (one-time, random) The scanning service verifies the site through a temporary REST endpoint, then returns site-specific credentials and a verification token. These credentials are stored locally in a non-autoloaded WordPress option and are used for authenticated scan requests. Consent IP Logs and Region Detection For consent logging and country detection, visitor IP addresses may be processed through MaxMind-backed region detection through SureCookie’s service. This helps SureCookie record the country in the consent log. IP addresses are masked before being stored in your WordPress database. MaxMind attribution: https://www.maxmind.com Service URLs SureCookie scanning and geolocation service: https://library.surecookie.com/ SureCookie privacy policy: https://surecookie.com/privacy-policy/ MaxMind: https://www.maxmind.com Data Stored Locally SureCookie stores plugin settings and consent data in your WordPress database. This can include: Banner and preference modal settings Cookie categories Custom cookies Scanned cookies Scanned resources Scan history Consent logs Cookie policy page ID Automatic scan settings Scanner credentials Consent logs and scan results can be viewed, exported, or deleted from the WordPress admin. Privacy and Data Processing SureCookie processes data through its API service at library.surecookie.com for cookie scanning, scanner authentication, and region-aware consent logging. Here is what happens and why. What We Send to SureCookie Services During the one-time scanner registration and site verification flow, SureCookie sends the site URL, the WordPress administrator email, the SureCookie version, and a temporary installation nonce. The scanning service uses these to verify your site and issue credentials, then returns a verification token that SureCookie exposes at a temporary REST endpoint for domain verification. After registration, scan requests use site-specific credentials stored locally in WordPress and do not resend the admin email. When a scan runs, SureCookie sends selected page URLs to the scanning service so a real browser can detect cookies, scripts, resources, and third-party domains. What Is Processed and Why Cookie scanning: Selected page URLs are scanned in a real browser environment to detect cookies, scripts, resources, and third-party domains. Cookie categorization: Detected cookie details, such as names, domains, and durations, are used to help categorize cookies. Region detection: Visitor IP addresses may be processed through MaxMind-backed region detection to determine country-level location for consent logs. IP addresses are masked before being stored in your WordPress database. Consent records: Consent choices, timestamps, category preferences, and session details are logged locally in your WordPress database. Where Data Lives Consent logs, scan results, settings, and scanner credentials are stored in your WordPress database. Data sent to library.surecookie.com for scanning and geolocation may be temporarily processed for those features. SureCookie does not sell this data or use it for advertising. Data Retention and Control Consent logs and scan results can be viewed, exported, or deleted from your WordPress admin. Consent log retention periods are configurable in plugin settings. Scanner credentials are stored locally in a non-autoloaded WordPress option. Security API communication uses HTTPS. Scan requests use authenticated site credentials after the registration flow. Site credentials are used to sign later scan requests. Because visitor data and selected page URLs can be processed through SureCookie services, you should mention this in your site’s privacy policy where appropriate. Full details: https://surecookie.com/privacy-policy/ For questions about data processing, visit https://surecookie.com/support/. Useful Links SureCookie Website Documentation Support Forum Privacy Policy Live Demo About Brainstorm Force SureCookie is built by Brainstorm Force, the team behind Astra and other widely used WordPress products.