Price

From €49/year

Buy
v1.1.8
[B] Easy RGPD & Cookies (España)

[B] Easy RGPD & Cookies (España)

Complete RGPD, LOPDGDD & LSSI-CE compliance — built for Spain, runs on your server.

  • AEPD 2024-compliant cookie banner with equal-hierarchy Accept / Reject / Configure buttons and granular category toggles
  • Five mandatory legal pages auto-created from your company data and fully editable — restore defaults in one click
  • Third-party script blocker prevents Google Analytics, Meta Pixel, Hotjar, GTM, and more from firing before consent
4.9
(38 reviews)

About the plugin

Every Spanish website that collects personal data is legally required to comply with the RGPD, the LOPDGDD, and the LSSI-CE — and the AEPD is actively sanctioning sites that fall short. Yet most WordPress site owners are still relying on a patchwork of free cookie banners, manually drafted legal pages that go stale, and zero documentation of what users actually consented to. When an inspection arrives or a user exercises their data rights, that patchwork unravels fast. The cost is not just a fine — it is the time, stress, and reputational damage of scrambling to prove compliance you never properly built.

[B] Easy RGPD & Cookies (España) is the only all-in-one WordPress plugin built specifically for the Spanish legal framework. It auto-creates your five mandatory legal pages from your company data, deploys an AEPD 2024-compliant cookie banner with granular category toggles and equal-hierarchy buttons, blocks third-party scripts before consent is given, scans your site for third-party cookies automatically, and records a cryptographically verifiable audit trail of every consent action — all without a single external SaaS subscription. Everything runs on your own server, under your own control, with no monthly fees for the compliance infrastructure itself.

Freelancers and agencies building sites for Spanish SMEs, law firms, e-commerce stores, healthcare providers, and public-sector clients will find this plugin covers the full compliance stack in one activation. WooCommerce stores using Google Analytics, Meta Pixel, or Stripe get script blocking and consent gating out of the box. Content sites embedding YouTube or Vimeo get placeholder replacements until the visitor grants marketing consent. Membership sites and lead-generation funnels get a structured ARCO+ rights form that accepts identity verification documents, stores them securely, and auto-deletes them when the request is closed — exactly as RGPD data minimization requires.

The plugin is built on WordPress 6.0+ and PHP 8.1+, tested up to WordPress 6.8, and designed to coexist peacefully with caching plugins, Elementor, Divi, and other page builders. The consent decision is evaluated client-side from a first-party cookie, so full-page caching never breaks the banner logic. The secure document upload zone uses .htaccess and web.config deny-all rules plus nonce-protected admin download links — no identity document is ever exposed via a public URL. IP addresses are stored only as a salted SHA-256 hash, satisfying the AEPD’s pseudonymization requirements while still proving consent uniqueness.

Managing compliance at scale stops being a burden when the audit trail does the work for you. Every consent action — accept, reject, customize, revoke — is logged with a canonical JSON snapshot of the exact banner the user saw: button text, category labels, accent color, locale, and a SHA-256 integrity hash. If the AEPD asks what banner version user X encountered on date Y, you can export a print-ready PDF of that specific consent record in seconds. The same PDF export covers individual ARCO+ rights requests with space for a signed response, and full consent logs by date range with action totals. No external dependencies, no third-party PDF service — pure semantic HTML rendered via @media print.

The automatic cookie scanner crawls your public URLs, cross-references a built-in catalog of over a dozen major third-party services — Google Analytics, Meta Pixel, Hotjar, Microsoft Clarity, LinkedIn Insight Tag, TikTok Pixel, YouTube, Vimeo, Cloudflare, Stripe, PayPal, and more — and proposes inventory rows and block-list entries without overwriting anything you have configured manually. Consent logs older than the configured retention period (default 24 months, the AEPD maximum) are purged automatically by a background cron job. You stay lean, compliant, and audit-ready without lifting a finger.

Compliance is not a one-time checkbox — it is an ongoing operational commitment. [B] Easy RGPD & Cookies gives you the infrastructure to meet that commitment confidently: structured processes for handling rights requests, documented proof of every consent, legally current page content you can restore in one click, and a plugin that is actively maintained against the latest AEPD guidance. Stop patching compliance together from free tools that were never designed for the Spanish legal framework. Deploy one plugin, cover the full obligation, and get back to building your business.

Screenshots

Benefits

Audit-Ready Consent Proof

Every consent action is logged with a cryptographic snapshot of the exact banner the user saw — exportable to PDF in seconds if the AEPD comes knocking. You stop hoping your compliance holds up and start knowing it does.

Hours Saved on Every Site Launch

Legal pages, cookie inventory, script blocking, and the rights form are all configured from a single panel. What used to take a lawyer, a developer, and a SaaS subscription now takes under ten minutes per site.

No External SaaS, No Data Leaving Your Server

Unlike cookie consent platforms that phone home to their own infrastructure, this plugin runs entirely on your WordPress server. Your visitors' consent data stays under your control — no third-party processors, no additional DPA agreements required for the consent layer itself.

ARCO+ Rights Requests Handled Properly

A structured, legally compliant workflow for access, rectification, erasure, portability, and objection requests — with secure identity verification, an internal resolution tracker, and auto-deletion of sensitive documents. Handling a rights request no longer means a panicked email chain.

Know What Cookies Your Site Actually Sets

The automatic scanner cross-references your live pages against a curated catalog of third-party services and surfaces what you are loading — so your cookie policy reflects reality, not wishful thinking. Fewer surprises during audits; fewer embarrassing gaps in your disclosure.

One Flat Annual Fee — No Per-Site SaaS Charges

Agencies managing multiple client sites pay once per license tier, not per pageview or per consent. At €199/year for 25 sites, the cost per site is less than a single hour of legal consultation — and the compliance infrastructure is always on, always running.

Stays Current as Regulations Evolve

The AEPD updates its guidance; the plugin is actively maintained to track those changes. Active license holders receive automatic updates with no manual intervention — so the banner logic, block list, and scanner catalog stay aligned with current requirements without you having to monitor regulatory news.

Available plans

Personal

49.00 / /year

1 site

Buy

Professional

149.00 / /year

5 sites

Buy

Agency

199.00 / /year

25 sites

Buy

Unlimited

349.00 / /year

Unlimited sites

Buy

Why [B] Easy RGPD Instead of the Alternatives?

Free plugins and generic cookie banners leave dangerous gaps in Spanish legal compliance. Here is exactly where they fall short.

Feature [B] Easy RGPD & Cookies (España) Other solutions
AEPD 2024 equal-hierarchy button requirement Fully implemented — Accept, Reject, and Configure at identical visual weight Most free banners still use a prominent Accept button and a hidden or smaller Reject option, which the AEPD has explicitly sanctioned
Consent audit log with banner snapshot Every record stores a canonical JSON snapshot of the exact banner shown, with SHA-256 hash for tamper detection Generic plugins log a timestamp at best — no record of what the user actually saw or agreed to
ARCO+ rights request form with identity verification Built-in form covering all Art. 15–22 RGPD types, secure document upload, admin workflow, and auto-delete on closure Not included in any comparable free plugin; requires a separate form plugin, manual process, and no document security
Pre-consent script blocking (not just cookie deletion) Scripts are prevented from executing before consent — tags never fire, no data is sent Many tools delete cookies after the fact but cannot stop scripts from running and transmitting data on page load
PDF export for AEPD submissions Print-ready PDFs for individual consents, individual rights requests, and date-range log exports — no external service No PDF export capability in free alternatives; SaaS platforms charge extra or require manual screenshot workflows
Automatic cookie scanner with third-party service catalog Crawls live URLs, detects 12+ major services, proposes inventory rows without overwriting manual entries Free plugins require fully manual cookie inventory — no detection, no catalog, no proposed entries
No external SaaS dependency or per-consent pricing Flat annual license — everything runs on your server, no data leaves your WordPress installation Major consent platforms (Cookiebot, OneTrust, Axeptio) charge per domain or per pageview and process consent data on their own servers

How it works

1

Install and Activate

Upload the plugin folder to /wp-content/plugins/ or install directly from your WordPress admin. Activate it — the plugin immediately creates your five legal pages and registers the database tables for consent logging and rights requests.

2

Enter Your Company Data

Go to RGPD → Settings and fill in your company name, CIF/NIF, registered address, contact email, and Data Protection Officer details if applicable. This information populates all five legal pages automatically — no copy-pasting into page editors.

3

Review Legal Pages and Cookie Inventory

Visit RGPD → Legal Pages to review the auto-generated content and make any site-specific edits. Then go to RGPD → Cookie Scanner, run a scan of your public URLs, and review the proposed cookie inventory entries before publishing them to your Cookie Policy page.

4

Configure the Banner and Script Blocker

In RGPD → Cookie Settings, set your accent color, confirm the categories you use, and review the pre-populated block list. Visit your site as a new visitor to verify the banner appears correctly and that blocked scripts are not firing in the browser console before consent is given.

5

Place the Rights Form Shortcode

Add [beasy_rgpd_rights_form] to your Rights Exercise page (already created and linked in the Privacy Policy). Test a submission end-to-end: submit a request, upload a test document, then process it from RGPD → Rights Requests in the admin panel and confirm the document auto-deletes on closure.

6

Activate Your License for Updates

Go to RGPD → License, enter your license key, and activate your domain. You will immediately receive automatic update notifications through the standard WordPress updates panel, and premium features — cookie scanner and PDF export — will be fully unlocked.

Detailed features

Full Documentation

Step-by-step guides covering every feature: banner configuration, scanner usage, ARCO+ workflow, PDF export, shortcode reference, and security hardening notes. Available at https://baqueiro.es/docs/b-easy-rgpd

Video Walkthrough

A complete screen-recorded setup walkthrough covering installation through first live banner — under 12 minutes. Ideal for agencies onboarding new client sites. Watch at https://youtube.com/watch?v=xxxxx

Live Demo Site

Explore the plugin in a fully configured WordPress environment: test the cookie banner, submit a sample ARCO+ request, and browse the consent audit log. No account required. Visit https://demo.baqueiro.es/b-easy-rgpd

AEPD 2024 Cookie Guide — Summary for Developers

A concise reference document summarizing the AEPD's January 2024 updated cookie guidance: what changed, what the equal-hierarchy requirement means in practice, and how [B] Easy RGPD implements each point. Available in the documentation portal.

Priority Support

Licensed customers receive email and ticket support from the development team (Mon–Fri, 9–18h CET). Average first response under 4 business hours. Submit tickets via the customer portal at https://baqueiro.es/support

Built to boost your project

Use cases where this plugin delivers the most value.

WooCommerce Store with Analytics and Ads

A Spanish e-commerce site running Google Analytics 4, Meta Pixel, and Google Ads conversion tracking needs to block all three before consent and fire them only when the visitor grants Analytics or Marketing consent. The plugin handles all three out of the box — no custom GTM triggers, no manual script wrapping, no risk of data being sent before the user decides.

Agency Managing Multiple Client Sites

A web agency with 15 client sites needs a repeatable, defensible compliance workflow without paying per-domain SaaS fees. The Agency license covers all 15 sites under one annual fee. Each site gets its own legal pages, its own consent log, and its own ARCO+ inbox — fully isolated, fully auditable, managed from each client's own WordPress admin.

Healthcare or Legal Professional Website

A clinic or law firm collecting appointment requests and contact form submissions faces heightened scrutiny under the LOPDGDD due to the sensitivity of the data. The plugin's structured rights request workflow, secure identity document handling, and verifiable consent audit trail provide the documented processes these sectors need to demonstrate accountability to regulators and clients alike.

Educational Platform or Membership Site

A membership site with registered users needs to handle access, portability, and erasure requests formally — not via ad-hoc email. The ARCO+ form gives members a self-service channel for all Art. 15–22 rights, the admin panel gives the site operator a structured queue to process them, and the PDF export provides a signed-response template that satisfies the one-month response requirement under RGPD Art. 12.

Content Publisher with Embedded Media

A news or blog site embedding YouTube videos and Vimeo clips throughout its content cannot legally load those embeds — which set third-party cookies — without prior marketing consent. The plugin automatically replaces all embeds with a branded placeholder until the visitor grants consent, then loads the actual embed on click. No shortcode changes, no manual template edits — it works with standard WordPress embed blocks.

Public-Sector or NGO Website

Public institutions and nonprofits operating under Spanish law face the same RGPD obligations as commercial entities, often with less technical resource. The auto-created legal pages with one-click content restore, the structured rights form, and the zero-configuration cron-based retention purge mean compliance stays current without requiring ongoing developer involvement after initial setup.

Frequently asked questions

Version history

1.1.7 2025-05-10 Current
  • Added: Integration with [B] License Manager SDK v1.1.0 — domain activation/deactivation, expiration warnings, and automatic plugin updates via the WordPress updates panel.
  • Added: License management page under RGPD menu — activate/deactivate license key, view status and days remaining.
  • Added: Premium feature gating — cookie scanner and PDF export require an active license; disabled buttons show an explanatory tooltip when unlicensed.
  • Added: Admin notice on the Plugins page when no active license is detected.
  • Added: Helper function beasy_rgpd_is_licensed() for license status checks throughout the codebase.
1.1.6 2025-04-22
  • UX: Added close (×) button to the cookie preferences modal for easier dismissal on desktop and mobile.
  • UX: Rights form now repopulates fields automatically after a validation failure using a transient flash — no data exposed in the URL.
  • UX: Attachment error messages now distinguish between file size exceeded and invalid file type.
  • UX: Internal resolution field capped at 2,000 characters with a live character counter.
  • UX: Scanner AJAX panel now shows a Reload button instead of static text on completion.
  • UX: Cookie Policy link in the banner now opens in a new tab to preserve the user's navigation context.
1.1.5 2025-04-08
  • Security: Removed dangerous copy() fallback in file upload handler; upload directory permissions set to 0600.
  • Security: Fixed race condition in rate limiting for rights form and consent AJAX by switching to timestamp-array transients.
  • Security: Hardened mail header sanitization to strip control characters and restrict display-name charset.
  • Security: Isolated scanner apply_findings nonce from AJAX scan nonce to prevent CSRF replay attacks.
  • Security: YouTube and Vimeo embed unblocker now correctly requires explicit Marketing consent (was incorrectly unblocking on Analytics consent).
  • Fixed: Request code generation now checks database uniqueness with a retry loop to prevent collisions.
  • Fixed: PDF DPO email field now renders as a proper mailto: link instead of plain text.
  • Fixed: Admin notices isolated per user ID via transient suffix to prevent cross-user display.
  • Fixed: Uninstall routine now clears wp_page_for_privacy_policy option only when the referenced page was created by this plugin.

Reviews

38 reviews

There are no approved reviews for this plugin yet.

Reviews are collected by e-mail and published by the team.

Submit your review

Your feedback helps other buyers and can be edited later.

Sign in with the purchasing account to submit your review.

System requirements

PHP 8.1+
WP 6.0+

Required plugins

  • none

Other plugins you might like

Take your project to the next level

Get started right now with [B] Easy RGPD & Cookies (España).

I want to buy now

30-day full refund guarantee.