People have rights concerning their personal data.
They can ask whether an organisation processes their data, request access to it, receive a copy, correct inaccurate information, object to certain processing or — in specific circumstances — request deletion.
The GDPR establishes these rights, but it does not automatically give every website a practical way to receive such requests.
For many WordPress sites, the available options are still:
- Send an ordinary email
- Use a generic contact form
- Download and complete a PDF
- Search the privacy policy for the correct address
That works, but it places the entire burden on the visitor.
atec Privacy Request Form adds a clear, dedicated process directly to WordPress.
One Form for Different Privacy Requests
The visitor begins by selecting what the request concerns:
- Access to personal data
- A copy of personal data
- Correction of personal data
- Deletion of personal data
- Restriction of processing
- Objection to processing
- Withdrawal of consent
- Another privacy-related request
The form then collects the information needed to understand and route the request.
After submission:
- The complete request is sent to the website administrator.
- The visitor receives an immediate acknowledgement by email.
- Both emails contain a reference number for further communication.
The form can be added to any WordPress page using a shortcode. It works without WooCommerce and does not depend on an external service.
Why It Does Not Delete Data Automatically
A privacy request is not the same as a WordPress user account.
Personal information associated with one person may exist in many places:
- WordPress users and form entries
- Email inboxes
- Newsletter platforms
- Accounting software
- Customer relationship or support systems
- Payment providers
- Server and security logs
- Backups
- Custom databases
WordPress cannot know about all of these systems.
There may also be legitimate reasons why particular information cannot be deleted immediately — for example, legal retention requirements or the need to establish or defend a legal claim.
A button promising to “delete everything” would therefore be misleading and potentially dangerous.
atec Privacy Request Form receives and forwards the request. It does not automatically disclose, correct or delete personal data.
No Additional Request Archive in WordPress
Many request-management solutions create a dashboard containing every submitted case.
That can be useful for large organisations, but it also creates another database of names, email addresses and potentially sensitive messages.
atec Privacy Request Form follows the same lightweight principle as atec Withdrawal Form:
Form → email notification → acknowledgement → no request log
The request is delivered by email and is not stored in a separate plugin archive inside WordPress.
This does not mean that email systems or server logs retain no information. Those systems remain under the control of the website operator and its hosting or mail providers. The plugin simply avoids creating an additional permanent request database of its own.
Receipt Is Not Identity Verification
An acknowledgement email confirms that a request was received. It does not prove that the sender is entitled to receive, change or delete the requested information.
Before disclosing personal data or taking another significant action, the website operator must verify the requester in an appropriate and proportionate way.
The plugin makes this boundary explicit:
- It receives the request.
- It sends the acknowledgement.
- It does not claim that identity has been verified.
- It does not perform an automatic action on stored data.
That distinction protects both the requester and the website operator.
Privacy Rights Need a Practical Contact Point
The GDPR includes rights of access, rectification, erasure, restriction, objection and portability, among others. Organisations need procedures for responding to these requests, and electronic requests should generally receive an electronic response where appropriate. EU overview of GDPR rights, European Data Protection Board guidance
A WordPress plugin cannot fulfil the organisation’s complete legal responsibility.
It can, however, make the first step much clearer:
Give visitors an accessible place to submit the request and give the website operator the information needed to begin handling it.
That is exactly what atec Privacy Request Form is designed to do.
Focused, Local and Independent
atec Privacy Request Form is built for website owners who want one clearly defined tool rather than a large compliance platform.
The plugin is part of the atec Plugins suite and is presented alongside other focused tools at Site Compliance.
The plugin supports the technical intake of privacy requests. It does not provide legal advice or guarantee GDPR compliance.
Top comments (0)