All Blog Posts

WooCommerce and the GDPR: How to Support Privacy Compliance for Your Website

Close
Read time
7 mins
Published
Aug 3, 2026
Share

  • WooCommerce collects personal data by default, including names, email addresses, billing details, and order history, all of which fall under the GDPR.
  • The GDPR applies to any WooCommerce store with EU customers, regardless of where the business is registered.
  • You're legally responsible for every tool running on your store, including third-party plugins and ad pixels, even if a vendor built and maintains them.
  • Analytics and marketing cookies require opt-in consent before they fire. WooCommerce's own functional cookies are generally exempt, but plugin and ad tracking aren't.
  • Sending customer data to a third-party advertising platform may qualify as a "sale" of personal information under the CPRA, even when no money changes hands.

By their own numbers, as of the beginning of 2025, WooCommerce was powering over a third of all e-commerce stores globally. Behind every one of those stores is a checkout collecting names, addresses, payment records, and order histories, along with whatever analytics tools, ad pixels, and plugins the store happens to be running.

All of that data collection comes with legal obligations under the GDPR, CCPA, and other global privacy regulations, and they fall on the store operator, not on WooCommerce, plugin developers, or payment processors.

What Data Does WooCommerce Collect from Customers?

WooCommerce collects several types of personal data during the checkout process, including names, email addresses, phone numbers, and shipping details, and builds order histories.

For registered customers, that information is linked to an account profile and retained in the site's database. Payment card details are handled by the payment processor, but WooCommerce still stores transaction records along with customer names, addresses, and purchase information.

The amount of personal data being processed often extends beyond WooCommerce itself. Third-party tools such as Google Analytics, Meta Pixel, and abandoned cart plugins may begin collecting information as soon as they load. 

However, under regulations like the General Data Protection Regulation (GDPR), store owners are responsible for the personal data collected by these third-party tools, not just the data WooCommerce processes natively.

Cookie consent is one of the most visible parts of WooCommerce GDPR compliance, and the rules differ depending on what each type of cookie actually does.

WooCommerce sets several cookies by default to keep the store functioning. These are strictly necessary and don't require consent under the GDPR:

  • woocommerce_cart_hash: tracks cart contents and helps the browser cache that data
  • woocommerce_items_in_cart: indicates whether the cart contains items
  • wp_woocommerce_session: stores session data for the current visit

Cookies set by third-party tools are treated differently and require explicit opt-in consent before they can fire. These include:

  • Analytics cookies, such as those set by Google Analytics, which track visitor behavior across sessions
  • Advertising cookies, such as those set by Google Ads and Meta Pixel, which build profiles for ad targeting
  • Personalization cookies that track browsing history to tailor the shopping experience

A WooCommerce consent banner that appears after these scripts have already loaded isn't GDPR compliant. Consent has to come first, and non-essential scripts need to stay blocked until a visitor actively opts in.

Does the GDPR Apply to Your WooCommerce Store?

Yes, the GDPR most likely applies to your WooCommerce store, even if your business is not registered in Europe.

The GDPR applies based on where your customers are located, not where the business is registered. So a store with visitors browsing from Germany, or shipping to France, is subject to the GDPR for those customers, even if it’s run from Chicago, Sydney, or elsewhere. Because most WooCommerce stores don't restrict access from the EU, the regulation applies to many businesses worldwide.

If a WooCommerce store falls under the GDPR requirements, the store owner is responsible for how visitors are notified, and how customer data is collected, used, and shared, including through third-party plugins and services. In GDPR terms, this means the business acts as the data controller.

That responsibility comes with several requirements:

  • A lawful basis for each type of data processing. Contract fulfillment provides the basis for processing orders, while marketing and behavioral tracking generally require consent.
  • A privacy policy that explains what personal data is collected, which tools and processors handle it, how long data is retained, and how customers can exercise their rights.
  • Cookie consent before non-essential scripts are activated.
  • Data processing agreements (DPAs) with third-party vendors that handle customer data.
  • A way for customers to request access to, correction, or deletion of their personal data.

WooCommerce includes some built-in features that support these requirements. Under Settings > Accounts & Privacy, store owners can configure retention periods for inactive accounts and old orders. WordPress also provides personal data export and erasure tools under Tools

However, it’s worth noting that these features are not configured by default, and any retention periods used in the store should match the periods described in the privacy policy.

Does the CPRA Apply to Your WooCommerce Store?

For stores with U.S. customers, the California Privacy Rights Act (CPRA), which expanded and largely replaced the CCPA, creates a separate set of compliance obligations alongside the GDPR. The law applies to for-profit businesses that meet at least one of the following thresholds:

  • Annual gross revenue of at least USD 25 million (periodically adjusted for the Consumer Price Index)
  • Receiving, buying, selling, or sharing personal information of 100,000 or more consumers or households
  • Earn more than 50 percent of their annual revenue from the sale of California residents’ personal information

For many WooCommerce stores, the second threshold is the most relevant. The count includes tracking data, even when no purchase takes place. This means that a store using analytics and advertising pixels can reach 100,000 consumers much sooner than revenue figures alone would suggest.

Once the CPRA applies, sharing visitor data with advertising and analytics platforms can qualify as a "sale" or "sharing" of personal information, even when no money changes hands. Businesses must provide a "Do Not Sell or Share My Personal Information" opt-out option and honor those requests across the technologies running on the site.

How to Set Up a GDPR-Compliant Checkout in WooCommerce?

The checkout process is where WooCommerce collects the majority of customer data, making it a key part of GDPR compliance. Alongside cookie consent, stores need to configure checkout settings, privacy disclosures, and data retention policies appropriately.

Configuring privacy settings correctly helps customers understand how their information is used and can make informed consent choices, to help your store meet key GDPR requirements.

Configure the Privacy Policy and Terms Checkboxes

The checkout page is one of the main points where WooCommerce collects customer data. Making your store's privacy policy available at this moment of the customer journey helps improve transparency and is widely considered a best practice.

WooCommerce includes a built-in privacy policy checkbox for this purpose. Under WooCommerce > Settings > Accounts & Privacy, enable the checkbox and link it to the store's privacy policy page. See WooCommerce's Accounts & Privacy documentation for details. 

While the GDPR does not specifically require a checkbox at checkout, providing privacy information at the point of data collection helps customers understand how their personal data will be used before they complete a purchase.

Update Your WooCommerce Privacy Policy

The privacy policy should explain how customer data is handled throughout the store. This includes WooCommerce itself, payment providers, email marketing platforms, analytics tools, and advertising services.

For each service, your privacy policy should describe: 

  • What data is collected and for what purposes
  • The legal basis for processing 
  • How long the data is retained 
  • What third parties (vendors) will have access to the data
  • Whether the data is transferred outside the EU

Sign Data Processing Agreements

Every third-party service handling customer data on the store's behalf needs a signed DPA. Most major providers, including Stripe, PayPal, Mailchimp, and Google, offer these, but they require active acceptance from the store operator. Check each vendor's documentation and complete the process where it's available.

Configure Data Retention Settings

To help your WooCommerce store meet GDPR requirements, data should not be kept indefinitely. The regulation doesn’t specify storage periods, but operates on the principle of storage limitation, set out in Art. 5(1)(e) GDPR.

WooCommerce allows store owners to configure retention periods for inactive accounts and order data under WooCommerce > Settings > Accounts & Privacy.

Those settings should align with the retention periods described in the privacy policy. For example, if the policy states that order data is retained for two years, the WooCommerce settings should reflect the same period.

How to Install Cookiebot for WooCommerce: Step-by-Step Instructions

The checkout settings and privacy policy handle what happens once a customer engages. But cookies fire before any of that. Keeping track of which ones need consent is something that shifts every time a plugin updates or a new script is added.

That's where a consent management platform (CMP) like Cookiebot™ comes in. A CMP scans your website, categorizes every cookie it finds, and blocks non-essential scripts until a visitor has opted in. 

Cookiebot CMP has a dedicated WordPress plugin that integrates directly with WooCommerce, making it possible to manage cookie consent across the store without having to manually track every script that runs on it. Here’s how to set it up.

Step 1: Set Up Your Cookiebot Account and Domain

Create an account on cookiebot.com and add your WooCommerce store URL under the Domains tab. This triggers an automated backend scan that identifies every cookie your store sets and categorizes them into necessary, preferences, statistics, or marketing.

Step 2: Install the Plugin

In your WordPress dashboard, go to Plugins > Add Plugin and search for Cookiebot. Install and activate the Cookiebot CMP plugin.

Step 3: Connect Your Account

Go to the Cookiebot settings page in your WordPress dashboard. Enter your unique Domain Group ID, found in your Cookiebot Admin Interface. This syncs your site and pulls your specific banner configuration and consent logic.

Step 4: Enable Auto-Blocking

Turn on auto-blocking in the plugin settings (General Settings tab > Cookie-blocking mode: Automatic). Non-essential scripts won't fire until a visitor responds to the consent banner. WooCommerce's strictly necessary cookies continue to load normally.

If your store runs Google Ads or Google Analytics, enable the Google Consent Mode integration directly within the WordPress plugin settings. The plugin will automatically pass real-time consent signals to Google's tools so your conversion tracking and analytics respect each visitor's choices without breaking data continuity.

Frequently asked questions

Yes, the GDPR applies based on where customers are located, not where the business is registered. Any store with EU customers is subject to its requirements.

No, WooCommerce is not GDPR-compliant by default. It includes a privacy checkbox at checkout and basic data tools, but it doesn't manage cookie consent or block third-party tracking scripts. Those require additional configuration and a consent management platform.

Yes, if you have EU-based customers, every plugin installed on your e-commerce site is your company’s responsibility under the GDPR. So before installing a plugin that collects or processes visitor data, check whether the developer offers a data processing agreement and documents what data the plugin handles.

It should name every tool and processor handling customer data: payment gateway, analytics platform, email provider, and ad pixels. For each one, state what's collected, the legal basis, how long data is kept, and how customers can request deletion.

The CCPA defines "sale" broadly. Sharing visitor data with a third-party advertising or analytics platform can qualify, even without money changing hands. If a store passes behavioral data to Google Ads or Meta Pixel, that may trigger opt-out requirements under the law.