GDPR
May 25th 2018 brought a major change in the data protection legislation in the UK. If you manage a website that deals with collecting any personal information (which is any site with so much as a contact form) – you need to learn about these changes and update your privacy policy pages accordingly. We are not experts on this subject and have merely collected a few links to the relevant information from the ico. and the gov.uk websites for guidance and reference.
The Data Protection Act 1998 is now superseded by the GDPR (General Data Protection Regulation) this year and deals with the protection of personal data. Personal data is defined as any information which can be used to identify a person. Larger companies and those dealing with data from CCTV will need to register with the ICO and implement required changes. Smaller companies still have to comply with the GDPR though might be exempt from the registration requirement.
GDPR official info
The Information Commissioner’s Office (ico.) is the authority which deals with the GDPR and offers specific information, tools and guidance on compliance.

- Guide to the General Data Protection Regulation (GDPR)
- Registration self-assessment – online questionnaire to assess whether registration is required
In summary, the GDPR defines six principles to focus on.

further reading
- What does GDPR mean to me and my business?, smallbusiness.co.uk
- What every SME in the UK needs to know about GDPR, brookscity.com
- The EU General Data Protection Regulation (GDPR), itgovernance.co.uk
- […] overview of the GDPR’s new Subject Access Request regime, burges-salmon.com
Handling GDPR in WP
To comply with the legislation, your WP site will have to ask for active consent for the use of cookies, show details of cookies set and clearly link to the policy page. The consent form can be done as top/bottom pop-up or as overlay (strongly advise against this option as it is too obtrusive). Importantly, it has to be shown when someone views your page for the first time. Once accepted, the cookie will then prevent the popup to be shown again until it expires. Read this article for more specific info.
Any new installation of WordPress now includes a placeholder page with prompts for points to cover for the privacy policy and cookie handling info. This includes useful prompts which you can edit to suit, or remove to write your own. Generally, you’ll want to complete your site setup, including all functions and forms etc, and as final step, you’ll update the details for all related data.
To get the cookie consent set up – there are now a number of plugins. Always check on reviews and latest updates and experiment to find which will suit your site best. The following video shows how to setup and configure the Cookie Notice & Compliance for GDPR / CCPA plugin. The cookie notice has to allow acceptance or rejection of cookies and link to the provicay policy page.