GDPR subject access requests for WordPress

They want everything you hold on them. You have one month.

WP SAR Responder searches one email address across the whole site: the user account, comments, orders, form entries, and the plugin tables nobody remembers installing. Export it, erase it, anonymise it, and log that you did.

FROM $49/YEAR · LIFETIME OPTION · 14-DAY GUARANTEE

One search, every system — users, comments, orders, entries Export as JSON, CSV & HTML in one zip Anonymise instead of delete — the books stay straight Compliance log of every action taken
“They asked for everything we hold on them. We found the Woo order in ten minutes, then spent two days wondering what else was in there.”
— Every agency, the first time it happens

The hard part of a subject access request was never the answering. It is knowing you found all of it, on a site with forty plugins, half of which you did not install. WP SAR Responder searches every one of those places from a single box, and tells you what it could not reach.

How it works

Type the address. Read the answer.

Four passes run against one email address, each covering what the last one misses. Then you export, erase or anonymise from the same screen, and the log writes itself.

CORE

The obvious places, properly

The user account and every meta field hanging off it, the content they wrote, and their comments, including ones left while logged out under a different address. Login sessions are left out on purpose: those are credentials, not disclosable personal data.

PLUGINS

Every plugin that plays by the rules

WordPress has a privacy exporter API, and the serious plugins register with it. WP SAR Responder runs every registered exporter and folds the results in: WooCommerce orders and addresses, WPForms, Gravity Forms, Fluent Forms, Flamingo, Jetpack. Nothing to configure, and a new plugin is covered the day it is installed.

META

The plugins that do not

Plenty of plugins store an email address in post or user meta and never registered anything. The meta scan finds the address wherever it sits, including inside serialised data, and names the record it belongs to so you can judge whether it is personal data or a stray log line.

TABLES

The custom tables nobody remembers

Form entries, leads, bookings and orders usually live in their own tables. The scan finds tables with an email column, plus those whose names say they hold people, and searches inside serialised entry blobs. It never sweeps every column of every table, because that is how you take a database down on a Friday afternoon.

EXPORT

Three formats, one zip

JSON for portability, CSV for the client, and a readable HTML document for the file. Nothing is written into the uploads folder, so a subject access bundle can never be guessed at a URL and downloaded by a stranger. CSV values starting with a formula character are neutralised, because a form field is somebody else's spreadsheet payload.

ERASE

Erase, or take the person out

Anonymising keeps the record and removes the human: the order still counts towards last year, the comment thread still reads sensibly, the customer is gone. Dry run first to see the numbers, then type the subject address to confirm. The plugin will not action your own account, will not delete the last administrator, and will not delete any user who can administer the site.

LOG

Proof you handled it

Every search, export, erasure and retention run lands in a log with the subject, the action, the record count, the admin who ran it, and your note on how you verified their identity. Article 5(2) says you must be able to demonstrate compliance. Exports to CSV, and survives an uninstall.

DOCUMENT

The response, on your letterhead — Pro

Your logo, your colours, the reference block, the statutory rights wording, a summary of what you hold, and the full data as an appendix. A PDF you can send as it is, or a print-ready page if you would rather post it through your own system.

RETENTION

Stop hoarding it — Pro

Rules that clear records past their useful life on a daily schedule: old form entries, comments beyond your retention period, rows in a table you inherited. Dry-run any rule before you arm it, and every run writes to the same compliance log as a manual erasure.

Who it's for

Anyone holding other people's data in WordPress.

The agency with 40 client sites

A request lands on a site you built four years ago. One search tells you what is in there, including the plugins the client installed themselves, and the log proves you dealt with it properly.

The WooCommerce store

A customer wants deleting and the finance director wants last year's numbers intact. Anonymise: the orders survive, the customer does not.

The site with six form plugins

Contact forms, a quote builder, an event booking, a newsletter. Entries in all of them, found from one box, whether or not the plugin ever registered an exporter.

The site you just inherited

You have no idea what the last agency installed. Run a search on a known customer address and the result doubles as a map of where personal data lives on the site.

?The client asking “are we compliant?”

Point at the retention rules clearing old entries on a schedule, and at the log showing every request answered inside the deadline. Compliance you can show, not claim.

The membership or charity site

Members, donors and volunteers, spread across a user table, a CRM plugin and three years of form entries. One address, one answer, one document to send back.

The response

Anatomy of one answered request.

AThe time

Two days of asking colleagues what each plugin stores, against four minutes of reading one screen. The month the law gives you is for verifying identity and taking advice, not for archaeology.

BThe five systems

Account, comments, WooCommerce, two form plugins, and an old CRM table that never registered a privacy exporter. That last row is the one missed by hand, every time.

CThe erasure

Same screen, same address. Anonymised rather than deleted: 41 records keep their totals and their threads, and stop being about a person.

DThe log line

Who ran it, when, how many records, and your note on how you checked they were who they claimed to be. This is the part a regulator asks for, and the part nobody has.

Honest comparison

How we compare to the alternatives.

The realistic options are the privacy tools already in WordPress, or a spreadsheet and a lost afternoon. Here is what changes against the stronger of the two.

WP SAR Responder (us)WordPress core privacy tools
Runs registered privacy exporters✓ All of them, results shown to you✓ This is what core does well
Searches post, user & comment meta✓ Finds plugins that never registered✗ Invisible to core
Searches custom plugin tables✓ Entries, leads, bookings, orders✗ Invisible to core
You see the data before it is sent✓ On screen, grouped by source✗ Emails a link to the subject
Anonymise as well as delete✓ Keeps orders and threads intact✗ Erase only
Dry run before anything changes✓ Counts what would be touched✗ No preview
Compliance log of every action✓ Actor, counts, notes, CSV export◐ Request status only
Tells you what it could not search✓ Scope notes on every result✗ Silent about the gaps
Branded response document✓ Your letterhead, as a PDF, in Pro✗ A zip of HTML files
Retention rules on a schedule✓ Daily, dry-runnable, in Pro✗ Not a core concept
Free to run✗ Pro from $49/yr (the free edition does the whole search, export and erase)✓ In every WordPress install

Core's privacy tools are genuinely useful, and this plugin stands on them by running every exporter they know about. The difference is everything they cannot see, and the evidence trail afterwards. Full comparison →

Pricing

Simple prices. One is forever.

Every plan includes every Pro feature: the branded response document and automatic retention rules. You are only choosing how many sites.

10 Sites
$49/yr

Up to 10 sites

  • All features included
  • Updates & support for a year
  • 14-day guarantee
Choose 10 Sites
Agency
$99/yr

25 sites · for agencies

  • All features included
  • Updates & support for a year
  • 14-day guarantee
Choose Agency
100 Sites
$149/yr

Up to 100 sites

  • All features included
  • Updates & support for a year
  • 14-day guarantee
Choose 100 Sites
Lifetime
$599 once

Up to 100 sites, forever

  • All features, all future updates
  • Never renew, never re-buy
  • 14-day guarantee
Own it forever

Prices in USD. Licence keys are domain-based, with no accounts and no phoning home. Nothing about your clients' data leaves their own server. VAT invoices available.

Questions

Asked and answered.

Does WordPress not already do this?

Partly, and this plugin uses the good part. Core has an export and erase tool, but it only sees plugins that registered a privacy exporter, it emails a download link to the subject rather than handing you the data, and it tells you nothing about the plugin tables that never registered anything. WP SAR Responder runs those same core exporters, then goes further: it searches the user account and its meta, comments, authored content, post and user meta, and the custom tables where form entries, leads, bookings and orders actually live. You see the results yourself, in one place, before anything leaves the building.

Will it find data in a plugin you have never heard of?

Usually. There are two routes in. If the plugin registered a privacy exporter with WordPress, it is covered outright, and most of the big ones do: WooCommerce, WPForms, Gravity Forms, Fluent Forms, Flamingo and Jetpack among them. If it did not, the meta scan and the custom table scan look for the address in the data itself, including inside serialised form entries. Anything the search could not reach is listed as a scope note on the result, so you always know what you are signing off.

What is the difference between erasing and anonymising?

Erasing removes the record. Anonymising keeps the record and takes the person out of it, so the comment thread still reads sensibly and the order still counts towards last year's revenue. For most erasure requests anonymising is the right answer, because you usually have a legal reason to keep the transaction even when you have no reason to keep the customer. Both are one click, both can be dry-run first, and both are written to the compliance log.

Is it safe to run an erasure on a live client site?

Run a dry run first: it counts exactly what would change and touches nothing. A real erasure then needs the subject's email address typed in to confirm. Beyond that there are rails you cannot switch off: it never actions the account you are logged in as, never deletes the last remaining administrator, and never deletes any user who can administer the site, because staff accounts take their content with them when they go. Deleting a WordPress user account at all is a separate tick box, not the default.

What does the compliance log actually record?

Every search, export, response document, anonymisation, erasure and retention run: the subject address, what was done, how many records were affected, which admin did it, a truncated IP, and a free-text note where you record how you verified the person's identity. Article 5(2) of the UK GDPR says you have to be able to demonstrate compliance, and a log you can hand to a regulator is what demonstrating looks like. It exports to CSV, and it deliberately survives uninstalling the plugin.

How long does a search take on a big site?

Seconds on a normal site. Every pass is capped so one enormous table cannot stall the request, and the deep scan of plugin tables is limited to tables whose names suggest they hold people, such as entries, leads, orders and bookings. Searching every text column of every table is how you take a database down, so the plugin does not do it. On a very large store you can switch the deep scans off in settings, and the result will say plainly that they were switched off.

What is in the branded response document?

The thing you actually send back. A covering letter on your letterhead with your logo and colours, the reference block naming the subject and the date, the statutory rights wording, a summary table of what you hold, and the full data as an appendix. It renders as a PDF, or as a print-ready page if you would rather send it through your own system. Agencies tend to send it to the client to forward on; some send it straight to the data subject.

What are retention rules for?

Not holding the data in the first place is the other half of the job. A retention rule says records of a certain kind, past a certain age, get deleted or anonymised, and it runs once a day on its own: old contact form entries, comments beyond your retention period, rows in a plugin table you inherited. Every rule can be dry-run to see what it would touch before you arm it, and every run writes to the same compliance log as a manual erasure.

What is in the free edition, and what does Pro add?

Free is the whole working process: the four-pass search, the export in JSON, CSV and HTML, erasure and anonymisation with the dry run and the safety rails, and the compliance log. That is enough to answer a subject access request properly. Pro adds the two things agencies charge for: the branded response document on your letterhead, and automatic retention rules on a daily schedule.

How is the licence delivered?

Order through the form and your licence key and invoice arrive by email, usually within the hour. Keys are long codes starting VPC1. so paste the whole thing into the licence box rather than typing it. Domain-based, no account, no phoning home, no lock-in.

What if it is not for me?

14-day money-back guarantee, no questions. Email us and we refund you.

Get started

The next request will arrive on a Friday.

Order below and your licence key and invoice arrive by email, usually within the hour. Install it, run one search on a customer address, and you will know within a minute what your site has been quietly holding.

14-DAY MONEY-BACK GUARANTEE · SUPPORT BY ACTUAL HUMANS

You'll receive an invoice by email — pay by card or bank transfer. Nothing is charged on this page.