Cookie policy for a WordPress website
A cookie policy and consent configuration for a WordPress website, drafted for the site owner with the privacy notice, for a fixed fee of £595 in five working days.
Cookie policy for a WordPress website
Buy now, £595A WordPress site sets cookies from the moment it loads: the core software, the theme, the plugins, the analytics, the embedded video, the map, the fonts loaded from a third party, each adding something the law treats as requiring consent unless it is strictly necessary. The cookie policy has to list what the site sets, the consent banner has to stop the non-essential ones firing until the visitor agrees, the consent plugin has to be configured to do that rather than to look as if it does, and the business has to know what the 2025 Act's new exception for analytics does and does not allow. I draft the cookie notice and the privacy notice for the business, with guidance on configuring consent, for a fixed fee of £595, delivered in five working days.
Who this is for
Businesses in England and Wales running a WordPress website, with or without WooCommerce, whose cookie banner was installed by a developer and whose owner does not know what it does.
What matters in a WordPress cookie policy
What WordPress and its plugins set before anyone adds anything
WordPress itself sets cookies for logged-in users, comments and sessions, most of which are strictly necessary for those functions, but the theme and the plugins add more: WooCommerce sets cart and session cookies (necessary) and may add tracking, form plugins set cookies, security plugins set cookies, page builders and sliders may load third-party scripts, and the analytics, marketing and social sharing plugins set the cookies that need consent; the policy starts from an audit of what the site sets with each plugin active, because the owner rarely knows, and the cookie notice lists the result by category (strictly necessary, functional, analytics, marketing) with each cookie's name, purpose, provider and duration.
The consent the law requires and the banner that delivers it
Non-essential cookies and similar technologies need prior consent under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, with only those strictly necessary for a service the visitor requested exempt, and the Information Commissioner's guidance requires the consent to be a positive action with refusal no harder than acceptance (a reject button as prominent as the accept button on the first layer), no pre-ticked boxes, no cookie walls that block access, and the non-essential cookies not set until consent is given; a banner that says 'by continuing you consent' or that sets analytics before the visitor clicks anything is the configuration the regulator has written to site owners about, and the guidance explains how to avoid it.
The cookie notice and the audit that produces it
The cookie notice is the list the visitor can read of what the site sets, which requires an audit of the live site (a scan with the plugins active, in a logged-out browser, with consent refused and then accepted, to see what fires in each state), and the notice should be regenerated when plugins are added or removed, because a cookie notice that lists cookies the site no longer sets and omits the ones a new plugin added is inaccurate; the pack includes the notice built from the audit and the instructions for repeating it, and the privacy notice refers to the cookie notice rather than duplicating it.
Embedded content, fonts and the third parties on the page
Embedded videos, maps, social media feeds and share buttons load third-party scripts that set cookies and send the visitor's data to the provider before any consent, and fonts loaded from a third-party server send the visitor's address to that server (which a European court has treated as a transfer of personal data), so the policy should identify each embed and the guidance should explain the options: load the embed only after consent (which most consent plugins and privacy-enhanced embed modes support), use the provider's privacy-enhanced mode, or host the fonts locally; the cookie notice lists the third parties and the privacy notice covers the transfers under Article 46 of the UK GDPR.
The consent plugin, its configuration and the proof it keeps
The consent plugin should be configured to block all non-essential scripts until consent (by category, with the scripts tagged or the plugin's blocking rules set), to show a first-layer banner with accept, reject and manage options of equal prominence, to record each visitor's choice with a timestamp as the proof of consent the business may need, to offer a way to change the choice (a floating icon or a footer link), to re-ask after a stated period, and to respect the choice on every page; the guidance covers the configuration for the common plugins and the test that confirms nothing fires before consent, because a plugin installed with its defaults often does not block anything.
The 2025 Act's analytics exception and what it changes
The Data (Use and Access) Act 2025 amends the Regulations to allow some cookies to be set without consent on an opt-out basis, including those used solely for statistical purposes to improve the service, provided the visitor is given clear information and a clear means to object and the data is not shared or used for other purposes, and the policy should say whether the business relies on the exception for its analytics once the provision is in force and the conditions are met (which excludes analytics tools that share data with the provider for its own purposes); until then and for everything else, consent remains the rule, and the guidance explains how to configure the site for either position.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our developer installed a cookie plugin. Is that enough?
Only if it is configured to block non-essential scripts until consent, with reject no harder than accept, and records the choices. Most plugins installed with their defaults do not block anything. The guidance covers the configuration and the test.
Do embedded videos need consent?
They do, because they load third-party scripts and send data to the provider. Load them after consent, use the provider's privacy-enhanced mode, or both. The cookie notice lists the third parties.
Can we run analytics without consent now?
Under the 2025 Act's exception, once in force, for cookies used solely for statistics with clear information, a clear opt-out and no sharing with the provider for its own purposes. Most hosted analytics tools do not meet the last condition. The guidance explains both positions.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Cookie policy for a Shopify store
- Privacy notice for a tradesperson with a website
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.