WordPress Plugins for Privacy Policies and Processing Records

Open your privacy policy and search it for the name of your form plugin. Then your email marketing platform, your analytics tool, and whatever handles your live chat. If none of them appear, your policy is describing a website that is not yours, and a generated document that inventories the wrong processing is worse than a short honest one, because it is a written statement you cannot stand behind.
This is the failure mode of the entire generated-policy category. The tools are fine; the output is only as accurate as the inventory behind it, and most inventories are a checkbox exercise completed once, before three more plugins were installed. This article covers how to find what your site actually processes, who genuinely needs a formal processing record, and which tools keep a policy current rather than merely producing one.
Verified August 2026. This is a practical guide, not legal advice.
Why a generic policy is a liability
A privacy notice is a set of specific statements: what you collect, why, on what legal basis, who you share it with, where it goes, how long you keep it, and what rights the reader has. Every one of those is falsifiable against your actual site, and a regulator investigating a complaint reads the policy first because it is the cheapest way to establish whether you know what you are doing.
Generic templates fail in two directions and both are damaging. They omit real processing, so your analytics, your remarketing pixel, and your helpdesk go undisclosed. And they invent processing you do not do, because the template hedges by listing everything a website might conceivably do. A policy claiming you share data with advertising partners when you do not is a promise to a standard you never needed and an invitation to be asked about it.
The related failure is timing. Policies get written at launch and inherited by a site that has changed three times since. A policy accurate in 2023 and untouched since is not a document with a small error; it is evidence that nobody has looked.
The 6 options compared
1. Complianz
The strongest answer for WordPress specifically, at $59 a year for a single site, flat, and the reason is the inventory rather than the prose. Because it is built for WordPress it detects the plugins you have installed and generates policy text describing them, instead of asking you to describe your site to a form.
That inverts the failure mode. A hosted generator produces a document as accurate as your memory on the day you filled it in; a plugin that reads your installation produces one anchored to what is actually running. It also revisits the question when your site changes, which addresses the staleness problem that ruins most policies. It generates the surrounding documents too, cookie policy and the processing information, and keeps them alongside your consent records so an enquiry can be answered from one place.
- Price: From $59 a year, single site, flat
- Inventory: Detects installed plugins and writes from that
- Best for: WordPress sites wanting an accurate, self-updating policy
- Watch out for: External services it cannot see are still yours to add
2. iubenda
The best-known dedicated policy platform, with a free tier and paid plans from around €4.99 a month. Its distinguishing feature is a large library of pre-written service descriptions, so instead of describing what Mailchimp does with data you select Mailchimp and get accurate, maintained wording.
The maintenance is the real product. When a service changes what it does, or a legal requirement shifts, the wording updates without you noticing, which is exactly the work nobody does manually. The limitation is that selection is still yours: it will describe perfectly whatever you tell it you use, and say nothing about the plugin you forgot. Pair it with a genuine inventory rather than treating it as one, and read the pageview limits on the cheaper tiers.
- Price: Free tier; paid from around €4.99 a month
- Inventory: You select from a large maintained service library
- Best for: Sites using many well-known third-party services
- Watch out for: Accuracy depends entirely on your selections
3. Termly
US-oriented where most of this category is European, with a free tier and paid pricing around $0.67 per site per day, roughly $245 a year for one site. That orientation matters more for policies than for banners.
American state privacy laws impose their own notice content requirements, including specific disclosures about categories of data sold or shared, and a policy written to European conventions does not satisfy them by being stricter. It is a different list of required statements, not a subset. Termly’s templates assume that structure, and it pairs policy generation with the consent side so the two describe the same site. For a US business the daily per-site rate is worth weighing against a flat WordPress licence over a couple of years.
- Price: Free tier; paid around $0.67 per site per day
- Inventory: Guided, with US notice requirements built in
- Best for: US businesses across multiple state regimes
- Watch out for: Adds up for a single site against flat licences
4. WP AutoTerms
A WordPress plugin that generates a privacy policy, terms, and a disclaimer, with a free version that covers the basics and a paid upgrade. For a small site that currently has no policy at all, this is a fast route from nothing to something defensible.
Its honest position is as a starting point rather than a compliance programme. It produces standard documents and keeps them updated as templates change, which is more than a one-off generator does, but it works from what you tell it rather than from your installation. Treat the generated policy as a first draft, then walk your plugin list and add what is missing. That combination, template plus manual pass, produces a better result than most paid platforms used carelessly.
- Price: Free version; paid upgrade available
- Inventory: None, it works from your answers
- Best for: Small sites going from no policy to a real one
- Watch out for: Requires a manual pass to become accurate
5. A cookie scanner plus any generator
Not a product but the combination that fixes the actual problem, and worth choosing deliberately. Run a scanner across your site to discover what is really being set and contacted, then feed that inventory into whichever generator you prefer.
Cookiebot’s automatic scanning, at roughly €12 to €49 a month by page count, is the strongest discovery tool in the wider category and rescans on a schedule, so newly introduced trackers surface rather than accumulating silently. Even a single scan is valuable: almost every site turns up something the owner did not know about, usually from a plugin that quietly added a pixel. The discipline this creates is the point. A policy derived from a scan is anchored to evidence, and rescanning quarterly turns policy maintenance into a recurring task with a defined trigger instead of a good intention.
- Price: Scanner from ~€12/mo, plus your chosen generator
- Inventory: Evidence-based, from an actual crawl
- Best for: Anyone who suspects their policy is out of date
- Watch out for: Scanners see the front end, not your back office
6. Writing it yourself
Free, and better than every option above for a simple site, provided you write about your site rather than about websites in general. A policy that accurately describes a contact form, an email list, and one analytics tool in four hundred words beats three thousand words of hedged template.
The structure is fixed and short: what you collect, why, the legal basis, who receives it, whether it leaves your country, how long you keep it, the reader’s rights, and how to contact you. Work through your plugin list and your external accounts, write a line for each, and you have a document you can defend line by line. Where it stops being viable is complexity, special-category data, or anything with real consequences attached, and at that point the right purchase is an hour of a lawyer’s time rather than a subscription.
- Price: Free
- Inventory: Yours, and therefore correct if you do it properly
- Best for: Simple sites with a handful of tools
- Watch out for: No automatic updates when the law or your stack moves
Comparison table
| Option | Price | Finds your services | Stays current | Best fit |
|---|---|---|---|---|
| Complianz | From $59/yr flat | Yes, detects plugins | Yes | WordPress sites |
| iubenda | Free; from ~€4.99/mo | No, you select | Yes, wording maintained | Many known services |
| Termly | Free; ~$0.67/site/day | No, guided | Yes | US state law notices |
| WP AutoTerms | Free; paid upgrade | No | Templates update | Sites with no policy |
| Scanner plus generator | From ~€12/mo plus | Yes, by crawling | Yes, if you rescan | Stale policies |
| Writing it yourself | Free | You do | Only if you revisit | Simple sites |
Records of processing, and who actually needs one
A record of processing activities is an internal document, distinct from your public policy, listing each processing purpose, the categories of people and data involved, who receives the data, any transfers outside your jurisdiction, retention periods, and your security measures. It is not published. It exists to be produced on request.
Article 30 exempts organisations with fewer than 250 employees, and most site owners stop reading there. The exemption is narrower than it looks: it falls away if the processing is more than occasional, if it risks people’s rights and freedoms, or if it involves special-category or criminal-offence data. Running an email list, analytics, and a customer database is regular and systematic processing, not occasional, so most businesses doing ordinary online marketing are outside the exemption despite being small.
The good news is that it need not be elaborate. A spreadsheet with a row per processing activity satisfies the requirement and takes an afternoon. Rows for the contact form, the mailing list, the customer accounts, the analytics, and the payroll cover most small organisations completely. The tools above can generate a starting point, and Complianz’s version has the advantage of being anchored to your installed plugins, but the document is only useful if somebody keeps it honest.
Related guides
Frequently asked questions
Are generated policies legally valid?
There is no approval process for privacy policies. What matters is whether the statements are accurate and complete. An accurate generated policy is fine; an inaccurate bespoke one is not. Accuracy, not authorship, is the test.
How often should I update it?
Whenever your processing changes, which in practice means whenever you add a plugin or service that touches personal data. Set a calendar reminder to review it annually as a backstop, and treat any new marketing tool as a trigger.
Do I need separate policies for the EU and the US?
One document with clearly marked sections is usually cleaner than two, since the notice requirements overlap heavily but not entirely. The US state laws expect specific disclosures about data sold or shared that European conventions do not cover.
Does WordPress core help?
A little. Core includes a privacy policy page template with suggested text, and plugins can contribute their own suggested wording to it. It is a useful prompt for what to cover and no substitute for describing your own site.
What if my policy has been wrong for years?
Fix it now and note the revision date. A corrected policy with a recent date is a normal thing; an uncorrected one that somebody eventually notices is the problem. Nobody is penalised for improving a document.
Does a processing record need to be public?
No. It is internal and produced to a supervisory authority on request. Publishing it is unnecessary and would disclose more about your systems than anyone needs.
The verdict
For WordPress sites: Complianz at $59 a year, flat, because it builds the policy from the plugins you actually have rather than from what you remember, and revisits it when the site changes.
If you are US-based: Termly, whose templates assume the state-law notice structure rather than adapting European wording to it.
If your site is simple: write it yourself, for nothing, in four hundred accurate words. Work through your plugin list and your external accounts and write a line for each.
Whatever you choose, scan first. Run one crawl of your own site before writing a word, and treat the results as the inventory. Nearly every site finds something it did not know it was running, and that discovery is what separates a policy that describes your website from one that describes a website.



