EP GDPR
EP GDPR is a complete GDPR compliance toolkit for PageMotor. Cookie consent banner, data subject request handling (access, rectification, erasure, portability), consent logging across forms and subscriptions, and integration with every EP Suite plugin that touches personal data.
Published by ElmsPark Studio.
Overview
Section titled “Overview”Three pillars of GDPR that the plugin handles:
Cookie consent
Section titled “Cookie consent”A customisable banner that asks visitors to accept or reject cookies. Supports granular categories (necessary, analytics, marketing) so visitors can accept some and reject others. Remembers the choice across sessions. Provides a “Revisit consent” link visitors can click at any time to change their mind.
Form consent
Section titled “Form consent”Adds an opt-in consent checkbox above the submit button on every EP Email contact form. The checkbox text and required-or-optional behaviour are configurable. Independent of the cookie banner: a site that has no third-party tracking and therefore needs no banner can still enable form consent for the personal data captured by enquiry forms.
Data subject requests
Section titled “Data subject requests”Four rights, handled through a single admin dashboard:
- Access — “What data do you hold about me?” Generates a JSON or HTML export.
- Rectification — “This data is wrong, change it.”
- Erasure — “Delete all my data.” Coordinates with every EP plugin that holds data.
- Portability — “Give me my data in a machine-readable format.” JSON export.
Each request is logged with timestamps for the full lifecycle (received, confirmed by the requester, under review, completed) so you have an audit trail.
Consent logging
Section titled “Consent logging”Every form submission, newsletter signup, and booking that happens while EP GDPR is installed logs the consent state at that moment. If a visitor later requests data, you can show them exactly what they consented to and when.
Requirements
Section titled “Requirements”- PageMotor 0.8.2b or later
- EP Suite base class
Coordinates with (optional):
- EP Email — logs consent on form submissions.
- EP Newsletter — logs consent on subscriptions.
- EP Booking — logs consent on booking submissions.
- EP Ecommerce — logs consent on purchases.
- EP Bunny Fonts — reports compliance on font delivery.
Installation
Section titled “Installation”- Download
ep-gdpr.zipfrom the EP Suite downloads page. - Upload via Plugins → Manage Plugins. Activate.
- Open Plugin Settings → EP GDPR and work through the configuration.
Cookie consent configuration
Section titled “Cookie consent configuration”- Banner text. Shown when the visitor first arrives. The default placeholder (“This website uses cookies to ensure you get the best experience…”) is neutral English; replace with your own wording in any language or variant you prefer.
- Categories. Necessary (always on, informational), Analytics (EP Analytics doesn’t set cookies, but listed for completeness), Marketing. Add custom categories if a plugin needs them.
- Position. Bottom banner, top banner, or centre modal.
- Colours. Match your site styling.
- Privacy policy link. Required — the banner must link to your privacy policy.
- Change-your-choice link. Add
[ep-cookie-settings], or any link to#cookie-settings, to your footer or privacy page. It reopens the banner with the visitor’s current choice ticked, so they can change or withdraw it.
Data subject request form
Section titled “Data subject request form”Drop [ep-gdpr-request-form] on a dedicated page, typically /privacy-rights/ or similar, linked from your privacy policy.
The form collects:
- Type of request (access, rectification, erasure, portability).
- Name, email.
- Description of the request.
- Verification: the requester is emailed a link and must confirm the request is theirs. Until they do, the request cannot be exported or erased, and an unconfirmed request is deleted after 30 days.
Submissions land in the admin dashboard for processing.
Handling a data subject request
Section titled “Handling a data subject request”From Plugin Settings → EP GDPR → Requests:
- Click the request to open it.
- Check it shows as confirmed (the requester opened the link in their email). A request that reached you another way, for example through EP Email Inbox’s privacy mailbox, needs Mark as confirmed once you have checked who sent it. For high-risk cases, ask for more.
- Click Gather data — the plugin queries every EP Suite plugin for records matching the email address, assembles them into a single export.
- Review the export for anything to redact.
- Send it to the requester (download and email, or use the plugin’s built-in send button).
- Mark the request completed.
For erasure:
- Click Gather data to see what will be deleted.
- Click Erase — every EP Suite plugin deletes or anonymises its records.
- The consent log entry for this email stays (audit requirement), but is flagged as “subject erased”.
Consent log
Section titled “Consent log”Admin view shows:
- Every consent event with timestamp, email, context (which form / plugin), and what they consented to.
- Searchable by email.
- Used as evidence when handling data subject requests.
Cross-plugin integration
Section titled “Cross-plugin integration”When a plugin hooks into EP GDPR, it:
- Logs consent on opt-in (form submit, subscription, booking).
- Exposes data to the data subject request flow.
- Responds to erasure by deleting or anonymising its records.
EP Email, EP Newsletter, EP Booking, EP Ecommerce, EP Comments, and EP Affiliate all integrate.
Compliance dashboard
Section titled “Compliance dashboard”A single page shows your compliance status:
- Cookie consent banner active.
- Privacy policy linked.
- Data subject request form configured.
- Consent logging active on each integrated plugin.
- Font delivery GDPR-compliant (via EP Bunny Fonts).
Red and green indicators. Green means that area is sorted.
Troubleshooting
Section titled “Troubleshooting”“Banner doesn’t appear”
Section titled ““Banner doesn’t appear””Check Settings → EP GDPR → Cookie consent → Enabled. Also check the banner isn’t being hidden by an ad-blocker — some aggressive blockers hide consent dialogs.
“Erasure didn’t delete a record in plugin X”
Section titled ““Erasure didn’t delete a record in plugin X””Not every plugin integrates with EP GDPR’s erasure flow. The dashboard shows which do. Manual deletion is required for non-integrated plugins. Log the gap in the review queue if you spot one.
“Data export contains fields that shouldn’t be there”
Section titled ““Data export contains fields that shouldn’t be there””Plugins control what they expose. If a field shouldn’t be in the export, it’s either sensitive data that’s leaking (bug) or metadata the plugin considers user-facing (intentional). Log specifics in the review queue.
“Consent log is huge”
Section titled ““Consent log is huge””Retention is configurable. Default retains everything. Consider a 24-month retention for non-erasure consent events and indefinite for consents tied to existing active accounts.
“Visitors complain about the banner appearing on every page load”
Section titled ““Visitors complain about the banner appearing on every page load””Check cookies are being set correctly. If the visitor’s browser blocks all cookies, the banner has no way to remember their choice and shows every time. Nothing to fix — their browser is actively preventing persistence.
Feedback and corrections
Section titled “Feedback and corrections”For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.
For anything bigger — a bug report, a feature request, or a “how do I…” that needs a real reply — open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.
Changelog
Section titled “Changelog”1.1.51
Section titled “1.1.51”- The cookie banner now appears on sites built from standalone HTML pages. On a site whose pages are standalone HTML documents rather than built through a theme, the banner never showed, even with it switched on. It now shows on every page.
- Google Analytics now waits for consent. With the banner switched on, the Measurement ID you enter in PageMotor’s own Google Analytics settings is no longer loaded straight away. It loads only after a visitor accepts analytics cookies, and not at all if they reject them. Nothing to change on your side: your ID stays where it is.
- When Google Analytics is set up, the banner always offers the Analytics choice, so visitors can consent to it.
1.1.50
Section titled “1.1.50”- Data requests from affiliates work again. On a site running EP Affiliate, an access or export request for someone who is an affiliate stopped with a database error, because EP GDPR asked for affiliate details under names EP Affiliate does not use. The export now includes their affiliate account (with their earnings and balances), referrals, commissions and payouts.
- Erasure requests from affiliates work again. Erasing an affiliate failed for the same reason, part-way through. The affiliate account is now anonymised and suspended (kept for your financial records, as before), and its custom link, notes and portal access are cleared too.
1.1.49
Section titled “1.1.49”- Requests must now be confirmed by the owner of the email address. Anyone could type anyone’s address into the request form, and the request could then be erased or exported straight from your dashboard. Now the address gets an email with a confirmation link. Until the person opens it and presses Confirm, the request shows as “Awaiting email confirmation” and Erase Data and Export Data are not offered. You are notified, and the acknowledgement goes out, only once it is confirmed. Requests nobody confirms are deleted after 30 days. If you have checked someone’s identity another way (for example, they emailed you), use “Mark as confirmed”. Requests already on your list before this update count as confirmed.
- The form can no longer be used to send messages to strangers. The confirmation email has fixed wording only; nothing the visitor types appears in it.
- Erasure and export match the exact email address. Looking up [email protected] also matched [email protected] and [email protected] in the email log, so an erasure deleted other people’s records and an export included them. Only the exact address now matches, in the email log and in queued emails.
- The newsletter send log is now included in exports and erasures (every newsletter or transactional email sent to the person).
- Visitors can now change or withdraw their cookie choice. Once a choice was made the banner never came back. Add
[ep-cookie-settings](or any link to#cookie-settings) to your footer or privacy page and it reopens the banner with the current choice ticked. Withdrawing consent reloads the page, so blocked scripts stop running. - Cookie choices are now recorded. Each choice is saved in the consent log (no email address, just a random ID kept in the visitor’s cookie, what they chose and the banner wording shown), so you can show what was agreed and when.
- The contact-form consent box now counts. When marked required, a message without it ticked is refused on the server too, not just in the browser. A ticked box is now saved in the consent log with the wording shown and the sender’s email address.
- Names and messages typed into the request form are now shown as plain text in the emails sent to you and to the requester, never as formatting.
- Malformed form posts (a field sent as a list instead of text) now get a normal error instead of crashing the request.
1.1.48
Section titled “1.1.48”- Request emails use your email provider. When EP Email sends through Mailgun, Brevo or SendGrid, the notice you receive about a new data protection request, and the acknowledgement the visitor receives, now go out through that provider. Before, they were handed to the server’s own mail function, which many hosts silently discard, so requests could arrive in your dashboard without anyone being told.
1.1.47
Section titled “1.1.47”- Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
- Danish. Adds a Danish translation.
- Section status. Each settings section shows whether that feature is switched on. On a site that also runs an older EP plugin, the section shows its plain title instead.
1.1.46
Section titled “1.1.46”- Fixes EP GDPR switching itself off for one admin page a day. Once a day, the first admin page to load ran the data-request deadline check, and on PageMotor 0.11 that check failed on its own saved list of reminders already sent. The failure stopped EP GDPR loading for that one page view, so its consent and privacy features were missing on that page, and the day’s reminder check never finished.
- It only happened once at least one data request had been open long enough to earn a reminder. The check now reads that list correctly on every PageMotor version.
- The daily housekeeping (old-data purge and deadline reminders) can no longer stop the plugin loading. If it ever fails again, it logs one line and the rest of EP GDPR carries on.
- No reminders are sent twice: requests already reminded stay remembered.
- Also brings the shared ElmsPark admin layout up to date: the brand-colour control has moved out of the page header into a Branding section in Settings. Nothing else about your settings changes.
1.1.45
Section titled “1.1.45”- Plainer punctuation in the words your visitors see. The consent categories, the data request form’s five rights, the retention and reminder choices in Settings, and every line of the generated privacy policy used a long dash to join a label to its explanation (“Right of access — obtain a copy…”). Those now read with a colon or brackets instead (“Right of access: obtain a copy…”, “Never (keep indefinitely)”). Nothing about what the form or the policy does has changed, and any wording you have overridden through the language file is left exactly as you set it.
1.1.44
Section titled “1.1.44”- Fixes a crash on the data request form when an older EP plugin is installed on the same site. Submitting the form returned an internal error and nothing was saved or sent. EP plugins share one common code library, and whichever copy loads first is the one every EP plugin on that site uses, so a single out-of-date plugin could leave this one calling a spam check its copy did not have. The check now carries its own fallback and no longer depends on another plugin being up to date.
- No change on a site where this never happened: the same spam check runs, and nothing else changed.
1.1.43
Section titled “1.1.43”- Blocks a spam bot that was getting past the form honeypot. The scraper changed its network address on every single request, so blocking by address never caught it, but it always sent a malformed browser identifier that no real browser sends. Forms now reject anything carrying that signature, with the same silent response a caught bot already got.
- It was not theoretical. One client site had taken 57 fake signups before this went in, and the same bot had hit 17 sites.