Set up and correctly link the privacy policy in WordPress

Reading time approx.: 14 minutes

A privacy policy informs visitors about how personal data is processed on a website. WordPress provides some practical functions for this: You can use an existing page as Privacy Policy page define or create a new page for it directly.

WordPress can also provide information on certain data protection topics. However, the content management system does not automatically generate a complete and legally compliant privacy policy.

Which information is actually required depends on your website. A simple blog processes different data than a WooCommerce store with customer accounts, payment services, newsletters, contact forms, analysis tools, and externally embedded content.

In this guide, we will show you where to find WordPress's privacy features, how to set a privacy policy page, and how to link to it sensibly on your website.

Important: WordPress privacy features are technical tools and do not constitute legal advice. A page created in WordPress or designated as a privacy policy is not automatically complete or legally correct solely for that reason.

What is a privacy policy? #

A privacy policy describes what personal data is processed via a website, why this is done, and which other entities or services may be involved.

Depending on the website, data may be processed, for example, via:

  • Server log files
  • Contact forms
  • User accounts
  • Comments
  • Newsletter
  • Orders in an online shop
  • Payment service provider
  • Analysis and statistics services
  • embedded videos or maps
  • Social media features
  • Cookies and similar technologies
  • Spam and security services

Therefore, there is no single privacy policy that can be used unchanged for every WordPress website.

WordPress has its own privacy features #

WordPress provides its own privacy section in the admin area.

You can usually find him under:

Settings → Privacy

There you can specify in particular which WordPress page should be used as the privacy policy for your website.

Depending on the WordPress version, additional information and assistance on creating or reviewing a privacy policy may also be available there.

Create a privacy policy page in WordPress #

If a privacy policy does not yet exist as a WordPress page, you can first create a new page.

Create new privacy policy page #

  1. Log in to your WordPress admin area.
  2. Open Settings → Privacy.
  3. Check the option offered there to create a new privacy policy page.
  4. Create the page.
  5. Open the newly created page for editing.
  6. Add or replace the content according to your website's actual data processing.
  7. Do not publish the page until the content has been reviewed.

Alternatively, you can also under Pages → Create create a new page yourself. We explain how WordPress pages are generally created under Create new pages in WordPress.

Set existing page as privacy policy #

If a privacy policy already exists, you do not need to create a second page.

You can select the existing page in the WordPress privacy settings.

Select existing privacy policy #

  1. Open Settings → Privacy.
  2. Select the already existing privacy policy page.
  3. Confirm or save the selection.
  4. Then check whether the correct page is linked.

This tells WordPress which page on your installation is designated as the privacy policy.

Important: Setting a page under Settings → Privacy does not replace the visible link to the privacy policy for your visitors.

Does WordPress automatically create a ready-made privacy policy? #

No.

This is one of the most important points in this guide.

WordPress can create a page and provide information or suggestions regarding various privacy topics. However, WordPress does not automatically know the complete technical and legal situation of your website.

For example, WordPress cannot reliably decide:

  • which external services you actually use
  • what data a specific plugin processes
  • receive what third-party data
  • what contracts exist with service providers
  • what legal bases apply to your specific website
  • whether your privacy policy is complete

Therefore, a page prepared by WordPress must not be equated with an individually reviewed privacy policy.

Why plugins for the privacy policy are important #

Plugins extend WordPress with additional functions and can therefore also cause additional data processing.

A simple example is a contact form. Through it, names, email addresses, phone numbers, messages, and other information requested by the form can be processed.

Other plugins can, for example:

  • Generate visitor statistics
  • Detect spam
  • Transfer backups to external services
  • Process newsletter subscriptions
  • load external fonts or scripts
  • Embed social media content
  • Process payments
  • Log user activities

Therefore, when installing a new plugin, you should not only consider its features, but also check whether it changes your website's data processing.

We explain how to install WordPress extensions in our guide What is a WordPress plugin and how do you install a new plugin?.

Check plugin privacy information #

WordPress offers developers ways to provide information about which privacy-related operations their plugin performs.

Such information can be helpful when creating or updating a privacy policy.

However, you should not rely on that blindly.

For relevant plugins, also check the respective manufacturer's documentation and, in particular, which functions you actually have activated on your website.

The fact that a plugin technically supports a certain feature does not automatically mean that your specific installation is also using that feature.

What areas of a WordPress website should you check? #

Before you create or update a privacy policy, you should systematically review your website.

Check in particular:

  • WordPress itself
  • active theme
  • active plugins
  • Contact forms
  • Comments
  • User registration
  • Newsletter
  • WooCommerce and other shop systems
  • Payment service provider
  • Shipping service provider
  • Analysis and tracking services
  • external media
  • Spam and security features
  • embedded maps
  • Social media content
  • Cookie or consent solutions

This inventory is much more sensible than copying someone else's privacy policy and simply replacing the company name.

Consider contact forms #

Contact forms are among the most common places on a website where visitors enter personal data themselves.

Depending on the form, the following information may be processed, for example:

  • Name
  • Email address
  • Phone number
  • Companies
  • Subject
  • Message
  • uploaded files

In addition, you should check whether form entries are only sent by email or also saved within the WordPress database.

We cover how to generally set up a form separately under Create contact form in WordPress.

Consider comments #

If comments are enabled on your website, various information is processed in connection with the comment function.

What specific data is collected depends on WordPress, your settings, and any plugins you may be using.

If you do not need comments, you can restrict or disable the corresponding functions.

We explain the corresponding settings under Configure discussion settings in WordPress.

Consider user accounts and registered users #

If your website allows user registrations or if you operate an online shop, member area, or community, for example, additional personal data will be processed.

WordPress stores various account information for user accounts. Plugins can extend these user profiles with additional data.

You can check which users exist on your installation and what roles they have in the WordPress admin area.

You can find more about this at Managing users in WordPress: roles, capabilities, and user accounts.

WooCommerce requires special attention #

With a WooCommerce store, data processing is significantly more extensive than with a simple informational website.

In connection with orders, the following may be processed, for example:

  • Name
  • Billing address
  • Shipping address
  • Email address
  • Phone number
  • Order details
  • Payment information or payment status
  • Customer account

Additionally, external payment service providers, shipping service providers, accounting systems, or other services may be involved.

Therefore, a privacy policy for an online store should not simply be copied from a standard WordPress business website.

External content may transmit data #

A website can transmit data to third parties without a visitor consciously submitting a form.

This can be relevant, for example, with externally integrated resources or services.

Depending on the implementation, this may include:

  • Videos
  • Cards
  • Social media content
  • external fonts
  • Analysis scripts
  • Ad networks
  • external JavaScript services

What is crucial is not only what is visible on the website, but which technical connections are actually established when the page is loaded.

Cookie banner and privacy policy are not the same thing #

A common misconception is to equate a cookie or consent banner with a privacy policy.

Both fulfill different tasks.

The privacy policy provides information about the processing of personal data. A consent solution, on the other hand, can serve to obtain and manage necessary consents for specific technologies or processing activities.

A cookie banner therefore does not replace a privacy policy.

Conversely, the existence of a privacy policy does not automatically mean that no further consent is required for every technology used on the website.

Not every cookie is automatically a tracking cookie #

Cookies can be used for different purposes.

Some are technically required for certain functions, while others serve, for example, settings, statistics, marketing, or other purposes.

Therefore, in a data privacy audit, the question should not only be, Whether "ob" is an abbreviation for something specific or a typo in your source text, it translates to **whether** or **if** in English (from German, for example). If you intended a specific context, please provide the full sentence. cookies are present, but:

  • who sets them
  • what purpose they serve
  • what data is associated with it
  • how long they last
  • whether third parties are involved

Link the privacy policy visibly on the website #

After the privacy policy has been created and published, visitors also need to be able to find it.

On many websites, the corresponding link is located in the Footer.

Links such as the following are often summarized there:

  • Imprint
  • Privacy Policy
  • Terms and Conditions
  • Contact

We explain in detail how to include pages in a WordPress navigation at Creating and managing menus in WordPress.

Do not hide the privacy policy only in the main menu #

A privacy policy does not necessarily have to occupy a prominent place in the main navigation. However, it should be easily accessible for visitors.

Therefore, a permanently visible footer is a suitable place for the link on many websites.

Check the mobile display in particular. A link that is present on the desktop but accidentally hidden in the mobile footer doesn't help smartphone users.

What URL should the privacy policy have? #

Use a readable and permanent URL.

For example:

https://deine-domain.ch/datenschutz

or:

https://deine-domain.ch/datenschutzerklaerung

Both options are basically understandable. The decisive factor is above all that the URL is used permanently and linked correctly internally.

Do not unnecessarily change the URL of an existing privacy policy #

If your privacy policy is already published and linked, you should not change its slug without a reason.

When changing a URL, existing internal and, if applicable, external links must be taken into account.

If an existing URL needs to be changed, the old address should normally be redirected properly to the new address.

We explain how WordPress URLs are generally structured under Configure permalink settings in WordPress.

Check privacy policy after plugin changes #

A privacy policy is not a document that you create once and then basically never have to look at again.

When you integrate new features or external services into your website, you should check whether this changes the data processing.

This applies, for example, after the introduction of:

  • a new contact form
  • a newsletter system
  • to a statistical service
  • a new spam protection
  • Social media integrations
  • a booking system
  • WooCommerce
  • new payment services
  • external videos or maps

Even when removing a service, an adjustment can be useful so that the privacy policy continues to match the website actually in use.

Do not just deactivate plugins when they are no longer needed permanently #

If you find during a data privacy audit that a plugin is no longer needed at all, you should check whether it can be completely removed.

A permanently disabled plugin serves no function on the website and should not simply remain installed indefinitely.

We explain how to proceed correctly at Deactivate or delete WordPress plugins.

Review privacy policy after a website relaunch #

Following a relaunch, technically much more can have changed than is visible at first glance.

For example, a new theme or page builder might use different external resources. At the same time, plugins are frequently replaced, forms are recreated, or analytics tools are changed.

Therefore, the data protection audit is also one of the items that should be checked before publishing a fundamentally revised website.

Privacy policy after a hosting change #

Changes to the technical infrastructure can also make a review necessary.

When you change your hosting provider, for example, the technical service provider, the server location, or other general conditions may change.

Whether and which information in your privacy policy needs to be adjusted as a result depends on the specific situation and the applicable requirements.

WordPress Personal Data Tools #

WordPress also provides administrators with additional tools for handling personal data.

In the admin area you can find under Tools Functions for Export and Deletion of personal data.

These features are not to be confused with the normal import and export of WordPress content.

Export personal data #

Using the appropriate privacy tool, a request for the export of personal data can be processed for a specified email address.

WordPress and compatible plugins may include personal data provided by them in the export.

However, that does not automatically mean that all information from all external systems is contained within it.

For example, if an external newsletter, payment, or CRM service is used, there may be additional data stored there that WordPress itself does not manage.

Delete personal data #

WordPress also provides a tool for managing erasure requests.

This also applies here: The tool can only consider data that WordPress or correspondingly integrated components provide for this process.

External systems may need to be considered separately.

Important: The technical ability to delete data does not mean that all data may or must be deleted immediately in every situation. For example, there may be statutory retention obligations. Such legal questions must be assessed for the specific use case.

Do not confuse the normal WordPress export function with the privacy export #

Under Tools → Export data or rather, the data protection tools deal with personal data.

The standard WordPress export under Tools → Export data or rather Export may be named similarly depending on the interface, but fulfills a different purpose: It is used for exporting WordPress content such as posts, pages, or other content types.

We explain how this content export works at Export content from WordPress.

Do not simply copy someone else's privacy policy #

The privacy policy of another website is not a template for what data your own WordPress installation processes.

Two visually similar websites can have completely different technical structures.

Website A may use:

  • locally stored fonts
  • no statistical software
  • a simple contact form

Website B, on the other hand, uses:

  • external web fonts
  • Analytics and marketing services
  • embedded videos
  • Newsletter
  • Online bookings

An unaltered adoption of website A's privacy policy would consequently not reflect the technical situation of website B.

Do not have your privacy policy created blindly by AI #

AI tools can draft texts and help structure information. However, they do not automatically know all data flows of your specific WordPress installation.

If a system does not know which plugins, external services, contracts, data flows, and functions are actually present, it cannot reliably derive a complete privacy policy from them.

The same problem exists with general templates and text generators.

Therefore, the starting point should always be an inventory of the website actually in use.

Technical privacy audit of the website #

For more complex websites, an additional technical audit may be useful.

This involves, for example, examining:

  • which external domains are contacted
  • which cookies are set
  • which scripts are loaded
  • Which form data is transmitted
  • what external content is embedded
  • which plugins are active

This can be used to compare the actual technical configuration with the privacy policy and any consent solution in use.

Privacy policy and Swiss websites #

Operators of a Swiss website also have to deal with data protection requirements. Which specific regulations apply depends, among other things, on who operates the website, which individuals are targeted, and how or where personal data is processed.

For websites with users or customers outside of Switzerland, additional regulations may also become relevant.

Therefore, a technical WordPress guide cannot make a blanket statement as to which data protection law is fully applicable in every individual case.

Privacy Policy and GDPR #

The General Data Protection Regulation of the European Union can also be relevant for companies outside the EU if the corresponding requirements are met.

However, the mere fact that a website is powered by WordPress says nothing about that.

What matters are the specific activity, target group, and data processing.

If you are unsure which legal requirements apply to your company, you should consult a suitably qualified professional.

Typical errors in the WordPress privacy policy #

  • publish the page prepared by WordPress without review
  • copying a privacy policy from another website
  • ignore new plugins and services
  • Forgot contact forms
  • do not check external content
  • Ignore WooCommerce and payment gateways
  • Treating the cookie banner and the privacy policy as the same thing
  • create the privacy policy, but don't link it visibly anywhere
  • keep the old explanation unchanged after a relaunch
  • assuming that a generator automatically knows all data flows
  • focus only on WordPress and forget external systems

Note: WordPress helps you with the technical management of a privacy policy page. WordPress cannot automatically assess whether its content completely and legally correctly describes your actual data processing.

When should you seek professional help? #

The more complex a website's data processing becomes, the harder it is to accurately map all requirements using only general templates.

Professional support can be particularly useful for:

  • Online stores
  • extensive tracking or online marketing
  • international audiences
  • sensitive personal data
  • member or customer portals
  • numerous external service providers
  • complex data transmissions

For legal questions, you should consult a qualified professional.

When should you contact CURIAWEB support? #

As a CURIAWEB customer, you can contact our support if you have a technical problem with WordPress have, for example if you cannot select the privacy policy page or cannot find a specific WordPress feature.

Please let us know as much as possible:

  • the affected domain
  • which WordPress function is affected
  • which theme or plugin is involved
  • which error message is displayed

Please note that our technical WordPress support does not replace individual legal advice and does not constitute a legal review of your privacy policy.

Summary #

WordPress provides under Settings → Privacy Features are ready that allow you to create a page for your privacy policy or to designate an existing page for it. In addition, WordPress has tools for requests to export and erase personal data.

However, an automatically created WordPress page is not yet a guarantee for a complete privacy policy. The deciding factor is which data your specific website actually processes. In doing so, plugins, forms, comments, user accounts, shops, external services, and embedded content must be taken into account in particular.

Link the completed privacy policy so that it is easily accessible on your website, for example in the footer, and check it again if plugins, services, or other relevant components of your website change. We explain how to insert the corresponding link into your navigation under Creating and managing menus in WordPress.

Last updated August 27, 2026
Was this article helpful?
Content
Cookie Consent with Real Cookie Banner