Skip to content

EP GDPR

EP GDPR is a complete GDPR compliance toolkit for PageMotor. Cookie consent banner, data subject request handling (access, rectification, erasure, portability), consent logging across forms and subscriptions, and integration with every EP Suite plugin that touches personal data.

Published by ElmsPark Studio.

Three pillars of GDPR that the plugin handles:

A customisable banner that asks visitors to accept or reject cookies. Supports granular categories (necessary, analytics, marketing) so visitors can accept some and reject others. Remembers the choice across sessions. Provides a “Revisit consent” link visitors can click at any time to change their mind.

Adds an opt-in consent checkbox above the submit button on every EP Email contact form. The checkbox text and required-or-optional behaviour are configurable. Independent of the cookie banner: a site that has no third-party tracking and therefore needs no banner can still enable form consent for the personal data captured by enquiry forms.

Four rights, handled through a single admin dashboard:

  • Access — “What data do you hold about me?” Generates a JSON or HTML export.
  • Rectification — “This data is wrong, change it.”
  • Erasure — “Delete all my data.” Coordinates with every EP plugin that holds data.
  • Portability — “Give me my data in a machine-readable format.” JSON export.

Each request is logged with timestamps for the full lifecycle (received, confirmed by the requester, under review, completed) so you have an audit trail.

Every form submission, newsletter signup, and booking that happens while EP GDPR is installed logs the consent state at that moment. If a visitor later requests data, you can show them exactly what they consented to and when.

  • PageMotor 0.8.2b or later
  • EP Suite base class

Coordinates with (optional):

  • EP Email — logs consent on form submissions.
  • EP Newsletter — logs consent on subscriptions.
  • EP Booking — logs consent on booking submissions.
  • EP Ecommerce — logs consent on purchases.
  • EP Bunny Fonts — reports compliance on font delivery.
  1. Download ep-gdpr.zip from the EP Suite downloads page.
  2. Upload via Plugins → Manage Plugins. Activate.
  3. Open Plugin Settings → EP GDPR and work through the configuration.
  • Banner text. Shown when the visitor first arrives. The default placeholder (“This website uses cookies to ensure you get the best experience…”) is neutral English; replace with your own wording in any language or variant you prefer.
  • Categories. Necessary (always on, informational), Analytics (EP Analytics doesn’t set cookies, but listed for completeness), Marketing. Add custom categories if a plugin needs them.
  • Position. Bottom banner, top banner, or centre modal.
  • Colours. Match your site styling.
  • Privacy policy link. Required — the banner must link to your privacy policy.
  • Change-your-choice link. Add [ep-cookie-settings], or any link to #cookie-settings, to your footer or privacy page. It reopens the banner with the visitor’s current choice ticked, so they can change or withdraw it.

Drop [ep-gdpr-request-form] on a dedicated page, typically /privacy-rights/ or similar, linked from your privacy policy.

The form collects:

  • Type of request (access, rectification, erasure, portability).
  • Name, email.
  • Description of the request.
  • Verification: the requester is emailed a link and must confirm the request is theirs. Until they do, the request cannot be exported or erased, and an unconfirmed request is deleted after 30 days.

Submissions land in the admin dashboard for processing.

From Plugin Settings → EP GDPR → Requests:

  1. Click the request to open it.
  2. Check it shows as confirmed (the requester opened the link in their email). A request that reached you another way, for example through EP Email Inbox’s privacy mailbox, needs Mark as confirmed once you have checked who sent it. For high-risk cases, ask for more.
  3. Click Gather data — the plugin queries every EP Suite plugin for records matching the email address, assembles them into a single export.
  4. Review the export for anything to redact.
  5. Send it to the requester (download and email, or use the plugin’s built-in send button).
  6. Mark the request completed.

For erasure:

  1. Click Gather data to see what will be deleted.
  2. Click Erase — every EP Suite plugin deletes or anonymises its records.
  3. The consent log entry for this email stays (audit requirement), but is flagged as “subject erased”.

Admin view shows:

  • Every consent event with timestamp, email, context (which form / plugin), and what they consented to.
  • Searchable by email.
  • Used as evidence when handling data subject requests.

When a plugin hooks into EP GDPR, it:

  • Logs consent on opt-in (form submit, subscription, booking).
  • Exposes data to the data subject request flow.
  • Responds to erasure by deleting or anonymising its records.

EP Email, EP Newsletter, EP Booking, EP Ecommerce, EP Comments, and EP Affiliate all integrate.

A single page shows your compliance status:

  • Cookie consent banner active.
  • Privacy policy linked.
  • Data subject request form configured.
  • Consent logging active on each integrated plugin.
  • Font delivery GDPR-compliant (via EP Bunny Fonts).

Red and green indicators. Green means that area is sorted.

Check Settings → EP GDPR → Cookie consent → Enabled. Also check the banner isn’t being hidden by an ad-blocker — some aggressive blockers hide consent dialogs.

“Erasure didn’t delete a record in plugin X”

Section titled ““Erasure didn’t delete a record in plugin X””

Not every plugin integrates with EP GDPR’s erasure flow. The dashboard shows which do. Manual deletion is required for non-integrated plugins. Log the gap in the review queue if you spot one.

“Data export contains fields that shouldn’t be there”

Section titled ““Data export contains fields that shouldn’t be there””

Plugins control what they expose. If a field shouldn’t be in the export, it’s either sensitive data that’s leaking (bug) or metadata the plugin considers user-facing (intentional). Log specifics in the review queue.

Retention is configurable. Default retains everything. Consider a 24-month retention for non-erasure consent events and indefinite for consents tied to existing active accounts.

“Visitors complain about the banner appearing on every page load”

Section titled ““Visitors complain about the banner appearing on every page load””

Check cookies are being set correctly. If the visitor’s browser blocks all cookies, the banner has no way to remember their choice and shows every time. Nothing to fix — their browser is actively preventing persistence.

For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.

For anything bigger — a bug report, a feature request, or a “how do I…” that needs a real reply — open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.

  • The cookie banner now appears on sites built from standalone HTML pages. On a site whose pages are standalone HTML documents rather than built through a theme, the banner never showed, even with it switched on. It now shows on every page.
  • Google Analytics now waits for consent. With the banner switched on, the Measurement ID you enter in PageMotor’s own Google Analytics settings is no longer loaded straight away. It loads only after a visitor accepts analytics cookies, and not at all if they reject them. Nothing to change on your side: your ID stays where it is.
  • When Google Analytics is set up, the banner always offers the Analytics choice, so visitors can consent to it.
  • Data requests from affiliates work again. On a site running EP Affiliate, an access or export request for someone who is an affiliate stopped with a database error, because EP GDPR asked for affiliate details under names EP Affiliate does not use. The export now includes their affiliate account (with their earnings and balances), referrals, commissions and payouts.
  • Erasure requests from affiliates work again. Erasing an affiliate failed for the same reason, part-way through. The affiliate account is now anonymised and suspended (kept for your financial records, as before), and its custom link, notes and portal access are cleared too.
  • Requests must now be confirmed by the owner of the email address. Anyone could type anyone’s address into the request form, and the request could then be erased or exported straight from your dashboard. Now the address gets an email with a confirmation link. Until the person opens it and presses Confirm, the request shows as “Awaiting email confirmation” and Erase Data and Export Data are not offered. You are notified, and the acknowledgement goes out, only once it is confirmed. Requests nobody confirms are deleted after 30 days. If you have checked someone’s identity another way (for example, they emailed you), use “Mark as confirmed”. Requests already on your list before this update count as confirmed.
  • The form can no longer be used to send messages to strangers. The confirmation email has fixed wording only; nothing the visitor types appears in it.
  • Erasure and export match the exact email address. Looking up [email protected] also matched [email protected] and [email protected] in the email log, so an erasure deleted other people’s records and an export included them. Only the exact address now matches, in the email log and in queued emails.
  • The newsletter send log is now included in exports and erasures (every newsletter or transactional email sent to the person).
  • Visitors can now change or withdraw their cookie choice. Once a choice was made the banner never came back. Add [ep-cookie-settings] (or any link to #cookie-settings) to your footer or privacy page and it reopens the banner with the current choice ticked. Withdrawing consent reloads the page, so blocked scripts stop running.
  • Cookie choices are now recorded. Each choice is saved in the consent log (no email address, just a random ID kept in the visitor’s cookie, what they chose and the banner wording shown), so you can show what was agreed and when.
  • The contact-form consent box now counts. When marked required, a message without it ticked is refused on the server too, not just in the browser. A ticked box is now saved in the consent log with the wording shown and the sender’s email address.
  • Names and messages typed into the request form are now shown as plain text in the emails sent to you and to the requester, never as formatting.
  • Malformed form posts (a field sent as a list instead of text) now get a normal error instead of crashing the request.
  • Request emails use your email provider. When EP Email sends through Mailgun, Brevo or SendGrid, the notice you receive about a new data protection request, and the acknowledgement the visitor receives, now go out through that provider. Before, they were handed to the server’s own mail function, which many hosts silently discard, so requests could arrive in your dashboard without anyone being told.
  • Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
  • Danish. Adds a Danish translation.
  • Section status. Each settings section shows whether that feature is switched on. On a site that also runs an older EP plugin, the section shows its plain title instead.
  • Fixes EP GDPR switching itself off for one admin page a day. Once a day, the first admin page to load ran the data-request deadline check, and on PageMotor 0.11 that check failed on its own saved list of reminders already sent. The failure stopped EP GDPR loading for that one page view, so its consent and privacy features were missing on that page, and the day’s reminder check never finished.
  • It only happened once at least one data request had been open long enough to earn a reminder. The check now reads that list correctly on every PageMotor version.
  • The daily housekeeping (old-data purge and deadline reminders) can no longer stop the plugin loading. If it ever fails again, it logs one line and the rest of EP GDPR carries on.
  • No reminders are sent twice: requests already reminded stay remembered.
  • Also brings the shared ElmsPark admin layout up to date: the brand-colour control has moved out of the page header into a Branding section in Settings. Nothing else about your settings changes.
  • Plainer punctuation in the words your visitors see. The consent categories, the data request form’s five rights, the retention and reminder choices in Settings, and every line of the generated privacy policy used a long dash to join a label to its explanation (“Right of access — obtain a copy…”). Those now read with a colon or brackets instead (“Right of access: obtain a copy…”, “Never (keep indefinitely)”). Nothing about what the form or the policy does has changed, and any wording you have overridden through the language file is left exactly as you set it.
  • Fixes a crash on the data request form when an older EP plugin is installed on the same site. Submitting the form returned an internal error and nothing was saved or sent. EP plugins share one common code library, and whichever copy loads first is the one every EP plugin on that site uses, so a single out-of-date plugin could leave this one calling a spam check its copy did not have. The check now carries its own fallback and no longer depends on another plugin being up to date.
  • No change on a site where this never happened: the same spam check runs, and nothing else changed.
  • Blocks a spam bot that was getting past the form honeypot. The scraper changed its network address on every single request, so blocking by address never caught it, but it always sent a malformed browser identifier that no real browser sends. Forms now reject anything carrying that signature, with the same silent response a caught bot already got.
  • It was not theoretical. One client site had taken 57 fake signups before this went in, and the same bot had hit 17 sites.