Add a page titled "Privacy Policy," write or paste your policy text into the block editor, publish it, and link it in your footer menu. You don't need a plugin for this. WordPress has included a built-in privacy page tool for years, and for most sites that's enough.
A plugin only earns its place if you need cookie consent banners, automatic scanning for tracking scripts, or a policy generator that fills in clauses for you. Otherwise, the block editor handles it fine, and one less plugin means one less thing that can break your site or slow it down.
Using the built-in privacy tool
WordPress can create and flag a privacy policy page for you:
- In wp-admin, go to Settings → Privacy.
- Click Create New Page, or select an existing page from the dropdown if you already have one drafted.
- WordPress opens the page in the block editor with a starter template: sections for what data you collect, comments, embedded content, cookies, and who you share data with.
- Replace the placeholder text with your actual practices. Be specific: what you collect (forms, comments, analytics), what you use it for, whether you share it with third parties, and how visitors can contact you about their data.
- Publish the page.
- Back in Settings → Privacy, confirm this page is set as your site's official Privacy Policy page. WordPress marks it internally so themes and plugins that check for a privacy policy link (many comment forms and contact forms do) can find it.
Write the content the same way you'd write any other page: wp-admin → Pages → Add New, using paragraph, heading, and list blocks. No special formatting needed. Keep the language plain.
Add it to your navigation
Once published, add the page to your footer menu so it's reachable from every page. Go to Appearance → Menus, select your footer menu, and add the Privacy Policy page to it. Most themes put legal links in the footer rather than the main nav, which keeps the primary menu focused on products and content.
What actually belongs in the policy
The content is a legal and business decision, not a technical one, so this article won't tell you what clauses you need. What's worth knowing on the technical side:
- If you run contact forms, comments, or an email signup, list what those forms collect and where it goes.
- If you run analytics (Google Analytics, etc.), disclose it and link to the provider's own privacy policy.
- If you run WooCommerce, your policy needs to cover order data, payment processing, and shipping information. See Running a WooCommerce store for the operational side of running a store.
- If cookie law applies to your audience (GDPR, CCPA, etc.), a static policy page usually isn't sufficient on its own. You'll likely need a consent banner too. That's a legal question specific to your business and audience; talk to someone qualified rather than copying a template.
When a plugin makes sense
Skip the plugin route unless you specifically need one of these:
- Cookie consent banners that block scripts until a visitor accepts. The block editor can't do this; it requires JavaScript that intercepts other scripts before they load.
- Automated policy generators that ask you questions and assemble legal language. Useful if you don't have a lawyer-reviewed policy to start from, but treat the output as a draft, not a final document.
- Cookie scanning that audits your site for third-party scripts and trackers you may have forgotten about.
If you do add one, treat it like any other new plugin: test it before it touches your live site. Spin up a copy with WordPress staging, install and configure the plugin there, confirm the banner or generated policy looks right, then push it live. Consent banners in particular can conflict with themes or other plugins and break page rendering if something goes wrong; staging catches that before visitors see it.
See WordPress staging for a safe-change workflow.