How to Use WordPress Built-in Privacy Tools

WordPress has a set of privacy tools built into every standard installation, and this guide shows you how to use them to handle the data-subject requests that data protection law expects a website owner to answer. You will set up a privacy policy page, respond to a request from someone who wants a copy of their personal data, and respond to a request from someone who wants their personal data deleted. All three tasks are done from the WordPress admin area with no extra plugin, because the features are part of WordPress core. This guide is written for Noiz clients who run their own WordPress site, and it explains not only which buttons to press but the two things the official documentation understates: exactly what these tools do and do not reach, and the practical hosting details that decide whether the whole process actually works.

Last reviewed: 27 July 2026, against WordPress 7.0.2 (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.

Official Documentation Reference

Prerequisites

  • You can log in to your WordPress admin dashboard as an administrator. These tools are only visible to administrator accounts.
  • Your site can send email reliably. The export and erase tools work by sending a confirmation link to the person making the request, so if your site cannot deliver email, the process stalls at the first step. This is the single most common reason these tools appear "broken", and it is covered in Troubleshooting below.
  • A recent, restorable backup of your site, before you action any erasure. An erasure permanently removes data from your database and cannot be undone.

What These Tools Do, and What They Do Not

Before touching any button, it is worth being clear about the boundary of what WordPress can do for you here, because misunderstanding it is how site owners end up thinking they have complied when they have not.

The built-in tools gather and remove personal data from WordPress itself and from plugins that participate in the privacy system. From WordPress core that means account details, the content and metadata of comments a person has left, media they uploaded, and session information. Many well-behaved plugins, for example contact form, e-commerce, membership and newsletter plugins, register their own data with these same tools, so a single export or erasure can sweep up form submissions or order records too. That is the good news, and it is genuinely useful.

The important limit is everything the tools cannot see. They do not reach data held in third-party services you send information to, such as an email marketing platform, a payment processor, an analytics service or a support desk. They do not touch server-level logs, and they deliberately do not alter your backups. A plugin that has not been written to participate in the privacy system will keep its data untouched and give you no warning that it has done so. So treat these tools as the WordPress-shaped part of a larger job, not as a complete answer to a legal request.

Why This Matters for a South African Site

If your site collects any personal information from visitors, for example through a contact form, a comment box, an account signup or a shop checkout, then data protection law gives the people that information belongs to certain rights over it. For a South African site the relevant law is the Protection of Personal Information Act (POPIA), which among other things lets a person ask what personal information you hold about them and ask you to correct or delete it. If your site also serves visitors in the European Union or United Kingdom, the General Data Protection Regulation (GDPR) gives comparable rights of access and erasure. The WordPress export and erase tools exist precisely to help you answer those two kinds of request in a consistent, repeatable way.

One honest caveat. Neither WordPress nor this guide is legal advice, and using these tools does not by itself make your site compliant with POPIA, GDPR or any other law. What content your privacy policy must contain, how quickly you must respond to a request, and how you verify who is really asking are legal questions for you or your advisor to answer. What follows is the mechanical how-to for the WordPress side.

Setting Up Your Privacy Policy Page

A privacy policy tells visitors what personal information your site collects and what you do with it, and having one is a baseline expectation under both POPIA and GDPR. WordPress helps you start one from a built-in template.

Create or Nominate the Page

Go to Settings > Privacy in your admin area. You have two choices here:

  • Click Create New Page to have WordPress generate a fresh draft page titled Privacy Policy, pre-filled with template text.
  • Or, if you already have a privacy policy page, choose it from the Select a Privacy Policy page dropdown and click Use This Page. This tells WordPress which page is your official policy so it can link to it in the right places.

Use the Policy Guide, Do Not Just Publish the Template

This is where most people go wrong. The page WordPress creates is a starting template with placeholder guidance, not a finished policy, and publishing it as-is leaves you with a document full of prompts that do not describe your actual site. On the Settings > Privacy screen, switch to the Policy Guide tab, which WordPress also links to from the draft policy page it generates. The guide assembles suggested wording drawn from WordPress and from every participating plugin you have installed, so a site running a shop or a form builder will see extra suggested sections that reflect the data those plugins collect. Copy the parts that apply, adapt the wording to describe what your site really does, delete the rest, and only then publish. It remains your responsibility to keep the policy accurate as your site changes.

Make Sure Visitors Can Find It

Once a policy page is nominated, WordPress automatically links to it from your login and registration pages, and most modern themes offer a way to place the policy link in the site footer so it appears on every page. Check your theme's footer or menu settings and add the link if it is not already there, since a policy nobody can find serves little purpose.

Handling a Request to Export Someone's Data

When a person asks for a copy of the personal data your site holds about them (an access request under POPIA, or a subject access request under GDPR), the Export Personal Data tool produces a downloadable file you can hand over.

Start the Request

Go to Tools > Export Personal Data. Enter the person's username or email address and click Send Request. The request now appears in the table below with a Status of Pending, and WordPress emails the person a confirmation link with the subject line "Confirm Action: Export Personal Data".

Wait for Confirmation, Then Send the Data

The confirmation step is a deliberate safeguard: it means data is only released to someone who can prove they control that email address, which protects you from handing a stranger somebody else's information. When the person clicks the link, the request status changes to Confirmed and a Email Data button appears under Next steps. Click it, and WordPress builds a .zip archive and emails the person a private download link. The status then moves to Completed. The download link is time-limited and the file is deleted automatically after three days by default, so the person should download it promptly.

The export itself is a .zip containing an index.html file that opens in any web browser and lays the data out in readable sections covering the site, the user's account information, their comments and their media, plus anything contributed by participating plugins.

When You Need to Skip the Email

If you would rather download the file yourself, for example to review it or to send it through a channel you consider more secure, hover over the requester's email address in the table and click Download Personal Data. This works even while a request is still Pending, so use it with care: it bypasses the email confirmation, and the responsibility for confirming the person's identity by some other means then falls to you.

Handling a Request to Erase Someone's Data

When a person asks you to delete the personal data your site holds about them (a deletion request under POPIA, or the right to erasure under GDPR), the Erase Personal Data tool removes it. Because this is permanent, take that backup first.

Start and Confirm the Request

Go to Tools > Erase Personal Data, enter the username or email address, and click Send Request. As with exports, the person receives a confirmation email, this time headed "Confirm Action: Erase Personal Data", and the request sits at Pending until they click the link, at which point it becomes Confirmed.

Perform the Erasure

With the request confirmed, an Erase Personal Data button appears under Next steps. Be aware that there is no second confirmation prompt: the moment you click that button the data is erased from your database, permanently, and the action cannot be reversed. The status then changes to Completed. As with the export tool, if you need to act without the email round trip you can hover over the requester's address and choose Force Erase Personal Data, which again places the burden of verifying identity on you.

Understand What "Erase" Actually Removes

Two details here catch people out and are worth stating plainly. First, comments are anonymised rather than deleted: the comment text usually remains on your site, but the personal details attached to it, such as the author's name, email and IP address, are stripped and the author is shown as "Anonymous". This keeps the shape of a discussion intact while removing the personal data from it. Second, erasing a person's data does not delete their WordPress user account. If the request is that the account itself be removed, you still need to do that separately under Users, choosing what to do with any content they authored. The erase tool clears the personal data; it does not close the account.

Finally, remember the boundary from the start of this guide. Erasure removes data from WordPress and participating plugins only. It does not remove the person's information from your backups, and it cannot reach data you have already copied to third-party services. If you later restore your site from a backup taken before the erasure, that person's data will come back, and you would need to honour the erasure again.

Keeping a Record

Every request you raise stays listed in the table on the Export or Erase screen, with its status and dates, until you remove it. This list is a useful informal audit trail, evidence that you received a request and acted on it, so consider leaving completed requests in place for a while rather than clearing them immediately. When you do want to tidy up, tick the request and choose Remove from the Bulk actions dropdown. Removing a request from this table only deletes the record of the request; on the export side it does not touch the person's data, and on the erase side the data is already gone.

Troubleshooting

  • Symptom: a request is stuck at Pending and the person says no confirmation email arrived. This is almost always email delivery, not the privacy tool. WordPress sends these confirmations as ordinary site email, so if that email is not being delivered the process cannot proceed. Ask the person to check their spam folder first. If the mail genuinely is not arriving, your site's email delivery needs attention, and the Noiz support team can help you get reliable email sending in place. In the meantime you can use Download Personal Data or Force Erase Personal Data to proceed manually, provided you have verified the person's identity another way.
  • Symptom: you cannot see Tools > Export Personal Data or the Privacy settings at all. These screens are only available to administrator accounts. Confirm you are logged in as an administrator rather than an editor or author.
  • Symptom: the export file seems to be missing data you know a plugin collected. That plugin has most likely not been written to participate in the WordPress privacy system, so its data is invisible to the tool. You will need to export or delete that data through the plugin's own tools, or by asking its developer how their data is handled.
  • Symptom: the download link in the export email has stopped working. Export files are deleted automatically after a few days for security. Simply raise the request again, or use the Download Personal Data option to generate a fresh copy.
  • Symptom: you erased someone's data but it reappeared. You have almost certainly restored the site from a backup made before the erasure. The privacy tools never alter backups, so an erasure must be repeated after any such restore.

If you are unsure how to respond to a data-subject request, or you want help making sure your WordPress site can send the confirmation emails these tools depend on, open a support ticket with the Noiz support team. Include your domain and a short description of the request you have received. For the wider picture of locking down your site, it is also worth working through the Noiz WordPress Security Checklist.

  • 0 Users Found This Useful
  • wordpress, privacy
Was this answer helpful?

Related Articles

WordPress Security Checklist

WordPress powers a large share of the web, which makes it a constant target for automated...

How to Set Up Two-Factor Authentication (2FA) in WordPress with All-In-One Security (AIOS)

Two-factor authentication (2FA) adds a second layer of protection to your WordPress login. Even...

How to Stop Comment and Form Spam in WordPress

This guide shows you how to cut comment and form spam on your WordPress site down to a trickle,...

Debunking Common WordPress Security Myths

This guide separates WordPress security fact from fiction. A handful of persistent myths lead...

WordPress Cookies and Consent: Staying Privacy-Compliant

This guide explains what cookies and trackers your WordPress site really sets, how to find them,...