DPO Radio

Free Website Privacy Check: Ensure Your Site's Compliant Now!

GDPR Compliance for Contact Form 7 in WordPress

GDPR Compliance for Contact Form 7 in WordPress

How to Make Contact Form 7 GDPR-Compliant in WordPress with AesirX CMP

Contact Form 7 (CF7) is a popular WordPress plugin for creating customizable contact forms. When users submit a form, personal data such as names, email addresses, and messages are collected. To meet GDPR and ePrivacy Directive (ePD) requirements, you must obtain user consent before collecting personal data.

This guide shows how to configure Contact Form 7 for GDPR and ePD compliance using AesirX Consent Management Platform (CMP). You'll set up consent settings, block tracking scripts until users give consent, and maintain compliance without affecting form functionality.

Prerequisite: WordPress and Contact Form 7 must be installed and activated before proceeding.

Make_Contact_Form_7.png

Step 1: Install AesirX CMP and Activate Your Trial

1. Download and Install AesirX CMP

  • Download the plugin: Get the latest release from AesirX CMP Plugin on GitHub.
  • Install the plugin:
    • Log in to your WordPress admin panel.
    • Go to Plugins > Add New.
    • Click Upload Plugin, select the downloaded file, and click Install Now.
    • Click Activate Plugin after installation.

2. Register Your Shield of Privacy (SoP)

  • After activation, you'll be prompted to register your Shield of Privacy (SoP) to start your 14-day free trial with full features. (Your SoP serves as your AesirX Account ID, granting access to all AesirX solutions and licenses.)
  • Steps:
    • Enter your details:
      • Email
      • Shield of Privacy ID
      • Domain
    • Accept Terms & Verify:
      • Check Accept Terms & Privacy Policy.
      • Click “Click to start verification" → Activate My Trial.
    • Your free license details will appear - copy your Client ID, Client Secret, and License Key.
    • Paste them into WordPress > Settings > AesirX Consent Management.

Screenshot_2025-02-06_at_09.31.42.png

3. Update Your License for Continued Access

Before your trial ends, upgrade your license to maintain full access:

  • Visit the AesirX Licenses page and click Manage License under AesirX CMP.
  • Under Action, select Upgrade License and choose your preferred plan.
  • Complete the upgrade process, and your license will be updated automatically.

Step 2: Use AesirX Privacy Scanner to Identify CF7 Third-Party Domains

With AesirX CMP installed, identify and block third-party domains in CF7 that track user data without consent. Use AesirX Privacy Scanner to find them.

1. Scan Your Site for Third-Party Domains:

  • Open AesirX Privacy Scanner.
  • Enter your website’s URL and click Scan.
  • The scanner will analyze your site and list all third-party domains collecting user data.

Screenshot_2025-02-06_at_09.32.07.png

2. Identify CF7’s Tracking Domains

Look for CF7-related domains in the scan results, such as:

  • www.google.com/recaptcha/ (if reCAPTCHA is enabled)
  • ajax.googleapis.com (if scripts are loaded via Google)
  • Any other third-party scripts related to CF7.

3. Copy Identified Domains:

Copy these domains for use in AesirX Consent Shield to CF7 tracking until users give consent.

Make_Contact_Form_7_Graphic_3.png

Step 3: Prevent CF7 Tracking Until Users Give Consent with AesirX Consent Shield

Stop CF7 from tracking users before they consent by configuring AesirX Consent Shield.

1. Block Third-Party Domains:

  • Go to WordPress > Settings > AesirX Consent Management.
  • Find AesirX Consent Shield for Domain/Path-Based Blocking.
  • Enter the copied domains (e.g., www.google.com/recaptcha/, ajax.googleapis.com) to prevent them from loading before consent.

2. Block Contact Form 7 Plugin

  • AesirX Consent Shield automatically detects and lists third-party plugins that collect user data.
  • Go to AesirX Consent Shield for Third-Party Plugins.
  • Find Contact Form 7 in the list and check the box to block it until users consent.

3. Adjust Script Blocking Settings:

  • Select "Only Third-Party Hosts" (default).
  • This blocks third-party scripts while keeping first-party scripts running normally.

4. Save your changes.

Click Save Settings to apply changes. CF7 and its third-party domains will remain blocked until users provide explicit consent. 

Screenshot_2025-02-03_at_16.36.19.png

Step 4: Set Up Explicit and Fully Informed Consent

AesirX enhances Google Consent Mode V2 with two improved compliance-focused consent modes:

  • Simple Consent Mode – Works like Google’s Basic Consent Mode but with stricter compliance. No data is collected or shared with third parties until users explicitly consent. Includes Reject and Consent options.
  • Default Template – Tags start with denied parameters, ensuring no data is collected, stored, or sent until consent is given. Unlike Google Consent Mode 2.0, AesirX prevents any tags from loading before consent, reducing compliance risks. Includes Reject, Consent, and Decentralized Consent, giving users full control over their personal data.

How to Update Consent Settings

  1. Go to Settings > AesirX Consent Management > Select Consent Mode.
  2. Choose a template and customize the consent text.
    • Update your privacy policy to explicitly state:
      • Who collects the data (your site or third-party services).
      • Why the data is collected (e.g., analytics, personalization).
      • What data is collected (cookies, form data).
    • Keep the consent message simple, clear, and informative so users understand what they’re agreeing to and why it matters.
  3. (Optional) Enter your Google Tag ID and Google Tag Manager ID.
  4. Click “Save Settings” to apply changes.

Screenshot_2025-02-04_at_09.08.43.png

You've successfully configured Contact Form 7 for GDPR, the ePrivacy Directive, and other data protection laws using AesirX CMP. CF7’s tracking scripts and third-party domains are blocked until users give explicit consent, maintaining full compliance.

Activate your 14-day free trial today and access powerful features like seamless consent management, customizable consent modes, and the unique Consent Shield for enhanced privacy protection. Take control of your site’s privacy and achieve compliance immediately!

Not sure if your site meets compliance standards? Test it now with AesirX Privacy Scanner to verify your data protection measures!

Enjoyed this read? Share the blog!