To make a WordPress site better prepared for Brazil’s LGPD, first map what personal data the site and its connected services collect and use. Then align the privacy notice, cookie and tracking choices, data-request process, and security measures with that map. WordPress privacy tools and plugins can help implement parts of the work, but neither a banner nor a plugin establishes compliance by itself.
This is a practical implementation guide, not a site-specific legal determination. The obligations depend on the site’s actual data processing and circumstances.
1. Map the site’s personal-data flows
Start with the data, not the plugin. Inventory each form and service that may handle personal data, including WordPress core, themes, plugins, hosting, analytics, newsletters, payment services, embedded media, backups, and advertising or affiliate tools.
For each one, record:
- What data is collected or generated, and from whom.
- Why it is used and where it is stored.
- Which providers or other recipients can access it.
- How long it is retained, including in logs and backups.
- Who is responsible for reviewing requests about it.
WordPress’s privacy helper and personal-data request tools can surface information from WordPress and participating plugins, but they do not discover every external service or its practices. Use the WordPress Privacy documentation as a guide to the built-in features, not as a complete inventory of your site.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems2. Make the privacy notice match reality
In the WordPress administration area, open Settings → Privacy to access the privacy-policy helper. Use its suggested material as a starting point, then check every statement against your data-flow inventory and actual configuration.
#1 Best Overall
Add or correct information about the site’s purposes, data collected, sharing with providers, retention, and a contact route for privacy questions or requests. Include services that the helper cannot identify, and remove or revise text that does not describe what the site actually does. Keep the notice easy to find and understandable; generated suggestions alone are not a completed policy.
3. Review cookies and other tracking
List cookies and similar tracking technologies, what each is for, and what data they involve. Decide which technologies may run before a visitor makes a choice and which should wait, taking the applicable legal basis and the site’s circumstances into account. A banner that appears while non-essential tracking continues regardless of the visitor’s choice may not implement the choice the interface promises.
The ANPD’s 2024 cookie and personal-data guide, modified in 2025, addresses cookies and similar tracking technologies. It also makes clear that cookie guidance does not replace the rest of an organization’s LGPD responsibilities.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchFor the Gov.br portal, the ANPD’s 2022 recommendations called for a prominent way to reject all non-essential cookies, consent-based cookies disabled by default, categories, and specific consent by category. Those recommendations concern that portal; they are a useful design reference, not a universal pass/fail checklist for every WordPress site.
4. Make personal-data requests workable
WordPress provides two tools under Tools: Export Personal Data and Erase Personal Data. The documented workflow includes email validation and administrator review. Test it with the address that receives requests and make sure the person responsible knows how to assess and respond.
Rank #3
- Open Tools → Export Personal Data or Tools → Erase Personal Data.
- Enter the requester’s email address and initiate the request.
- Have the requester complete the email validation step.
- Review the validated request in WordPress and handle it according to the site’s process.
- Separately check connected providers and systems for data they hold, and document any action taken there.
The WordPress tools cover WordPress and participating plugins, not every external service. Erasure also is not necessarily absolute when information must be retained for legal or security reasons; the WordPress erasure tool does not remove data from backups or archives. Consider applicable retention obligations before acting. See the WordPress Privacy documentation for the tools’ scope and workflow.
5. Address security and responsibility
Security is a separate workstream from notices and consent. The ANPD’s security guide for small-scale processing agents describes administrative and technical measures and includes a checklist. Use it to shape controls that fit the site’s data, providers, and risks.
Small size alone is not a blanket indication that the LGPD does not apply. The ANPD’s Resolution CD/ANPD No. 2 sets out rules for small-scale processing agents; check the regulation and the site’s circumstances rather than assuming an exemption. The ANPD’s Frequently Asked Questions is another official place to consult for general questions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Decide whether a privacy plugin helps
A privacy plugin can support an implementation, but it cannot determine the site’s legal obligations or automatically discover every data flow. The WordPress.org listings describe features, not proof of legal adequacy. For example, LGPD Consent says it displays a consent notice and records choices. LGPD Framework describes consent, request, policy, and cookie functions, and expressly says its use does not guarantee compliance.
| Approach | What it can support | What still needs site-owner review |
|---|---|---|
| WordPress core privacy features | Policy-helper material and export/erasure workflows for WordPress and participating plugins, as described in the WordPress documentation. | External services, the accuracy of the notice, cookie behavior, retention, security, and the site’s overall process. |
| Add a privacy or consent plugin | Depending on the plugin, consent notices, choice records, or other listed policy and request functions; see the LGPD Consent and LGPD Framework listings. | Whether its functions cover the actual setup, how it stores or shares data, compatibility, maintenance, security, and legal adequacy. |
Before installing a plugin, check its current maintenance and compatibility, test its behavior with the site’s themes and services, and review what data it stores or sends outside the site. Confirm that its controls support the choices and request workflow you actually need. A feature list is not a substitute for those checks.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

