Free installation badge Product image of GDPR
Standard
User Guide
Professional
User Guide
Magento Edition *
Version * Compare versions
Add Subscription * Up to -20%
  • 1 year support
  • 2 years support
  • 3 years support
FREE installation Tooltip
Ending in:
0
days
:
0
hrs
:
0
mins
:
0
secs
$79
icon logo magento 2.4.4 - 2.4.9
Tooltip
Hyva logo Theme
Tooltip

The Most Popular GDPR for Magento 2

Magento 2 GDPR extension helps your online store comply with the latest EU regulations and protect customers' data and privacy. This module ensure your website can tranparently collect all necessary user consents to avoid severe penalties. Shoppers give granular cookie consent by accepting or rejecting cookies per category, and every decision is recorded with the policy version behind it.
tick icon
Compatible with Hyva theme
tick icon
Compatible with Magento 2.4.9
tick icon
Compatible with API/GraphQL
tick icon
Enable delete accounts and corresponding data
tick icon
Let shoppers accept or reject cookies per category
tick icon
Allow customers to access their personal data easily
tick icon
Safeguard customer identities with robust data anonymization features
tick icon
Notify users of their account deletion
tick icon
Show transparent Terms & Conditions
Free Installation
60 days money back guarantee

Protect Customer Data Privacy — Unlock New Opportunities

Protect Customer Data Privacy — Unlock New Opportunities

Automatically delete inactive accounts Pro

Mageplaza's GDPR module for Magento 2 makes it easy to identify and automatically delete inactive customer accounts. Simply set the period of inactivity — whether it's 1 month, 2 months, or even a year — and the module will handle the rest. Once an account is deleted, all associated personal data will be securely removed to ensure full GDPR compliance.
Show more

Collect granular cookie consent, and log every decision Pro

Instead of one all-or-nothing banner, shoppers open a preferences popup and accept or reject each cookie category on its own, with the cookies in each category listed for them to see. Every decision is written to a consent log together with the version of the cookie policy it was given under — and the shopper's IP only as a hash, so proving consent never means storing more personal data.
Show more

Allow customers to download their data Pro

Our GDPR extension also lets customers to effortlessly download their personal data in CSV or XML formats. This feature gives users complete access on what information has been collected and how it’s being used. When shoppers know exactly what's going on, they're more likely to trust your brand.
Show more

Enable account anonymization Pro

To enhance users' privacy, eCommerce store owners can anonymize certain sentitive information, like billing address and shipping address in the order, invoice, shipment, and credit memo after customers delete the account. This ensures that once an account is removed, no one, including admins, can access the customer’s personal data.
Show more

Send account deletion alerts Pro

All information about the customer account status will be automatically updated by configuring email notifications. Thanks to this feature, admins can catch up with sudden changes like when customers delete their accounts. Simultaneously, shoppers will also get notifications reminding them that their accounts have been inactive for too long and can be deleted.
Show more

All features

Delete customer account

Mageplaza’s Magento 2 GDPR plugin gives you two flexible ways to handle customer account deletions:
check
Self-deletion by customers (Standard): Customers can delete their own accounts directly from their profile.
check
Scheduled deletion by admin (Pro): Admins can automatically remove inactive customer accounts after a specific period that is configured in the backend.
Whenever an account is deleted, all associated personal data, even in their abandoned carts, is permanently erased, ensuring no sensitive information remains vulnerable. Additionally, for completed orders stored in your backend, customer details are securely anonymized to maintain GDPR compliance and protect user privacy.

Request terms agreement Pro

When customers sign up, our module asks them clearly and directly to agree to your store's Terms & Conditions. They can't continue without checking the consent box, prompting them to read and understand your policies. This straightforward process provides clear proof of consent and helps merchants avoid complicated situations with customers in the future.

Evaluate password safety

Magento 2 GDPR plugin also automatically checks how secure a customer’s password is when they create an account. It instantly tells users if their password is strong enough to protect their account from unauthorized access. This simple but highly efficient feature boosts account security and protects personal data.

Configure Cookie restriction Pro

Choose how your store asks for cookie consent: a classic banner for markets that only need a single accept, or granular cookie consent, where every cookie category carries its own toggle, so a shopper can allow analytics, refuse advertising, and reject as easily as accept.
Each category comes with its own cookie inventory. The cookies it actually covers, what each one is for, and how long each one lasts, shown right where the shopper is making the decision. Shoppers can reopen the popup and change their mind at any time, and the newer decision replaces the older one.

Consent log Pro

Every consent decision your store collects lands in the Cookie Consent Log: which cookie categories were granted, the version of your cookie policy in force at that moment, the store view, the source, the user agent, and the time it happened.
check
Policy Version on every record: Update your cookie policy and older records keep the version they were collected under, so you can show what a shopper was actually shown.
check
IP kept as a SHA-256 hash: Match a record against a claim, without turning your consent log into another pile of personal data you now have to protect.
Filter, sort and export any slice of the grid. A daily cron clears records once they pass the retention period you set.

Download personal data Pro

Allowing customers to download their data is a crucial aspect of GDPR compliance for online stores because it fulfills the customer's right to data portability and access. This right means customers can request a copy of their personal data held by the store and transmit it to another entity.
With solid understanding in eCommerce, Mageplaza team developed GDPR for Magento 2 extension to meet that requirement perfectly by letting customers download their personal data as CSV or Excel XML files. Stored data includes: Account ID, name, email, address, creation time, last update time, ability to change customer group status, etc.

Delete customer address

Address is a sensitive data and many shoppers wish to keep it as a secret. In fact, EU regulation mandates that individuals have the right to have their personal data erased if there is no legitimate reason to retain it. Understanding this, our plugin is designed to let customers easily delete their default address.

Enhance security Pro

To delete accounts, users must enter their password to verify identity. This safety measure guarantees that only authorized account owners can delete accounts. As a result, we can prevent accidental or malicious removals.

Anonymize customer info Pro

Allowing customers to anonymize their data is crucial for online stores to comply with GDPR because it makes sure individuals have control over their personal information and protects them from unauthorized access or misuse. Thanks to this feature, Magento stores can minimize the risk of exposing sensitive data for their clients.
We enable admins to anonymize critical data like names, emails, and addresses in billing documents, orders, invoices, and shipments.

Send email notification Pro

Our GDPR module is a useful tool for keeping both shoppers and store owners informed of account changes. We provide an auto-email sending feature to ensure:
check
Admins receive alerts when customers delete their accounts.
check
Customers get confirmation emails when they want to delete their accounts.
check
Customers also receive timely reminders if their accounts are inactive for too long and when their accounts are deleted.

Management grid Pro

The Magento 2 GDPR extension by Mageplaza provides two comprehensive management grids for recording:
check
Customer data download requests: Provide the information of users who downloaded their personal data, including fields like Name, Email, File Type, Customer Group, etc. Clicking the "View" button on each case will redirect admins to the customer page for further details.
check
Account deletions: Record the list of shoppers who deleted their accounts to track the number of inactive users and their spending on your website (e.g. Email, Order Count, Grand Total, Refunded, etc.) With this information, store owners can identify VIP clients trying to delete their accounts and convince them to stay.

What customers say about us

Product reviews: 35
Overall rating: 5.0
5
4
3
2
1
How much do you like this product?
Leave your email to get reward points for reviews
Submit a relevant review of 30+ words to earn 5 reward points (one-time per extension)
AndrewT
06 May 2026
Verified purchase
Maylay
10 January 2024
Verified purchase
Leo Nguyen
13 October 2022
Verified purchase
Cheryl
29 April 2022
Verified purchase
Ky Nguyen
21 April 2022
Verified purchase

Release notes

  • v4.3.0 (Magento v2.4.x)

    21 August 2026

    Standard:

    • Bug Fix: We added missing translation entries.
    • Compatibility: The extension is now compatible with PHP 8.5.

    Professional:

    • New Feature: Granular cookie consent. Shoppers can accept or reject cookies per category in a preferences popup, with a cookie inventory for each category. Enable it under Cookie Restriction > Consent Mode.
    • New Feature: Consent log. Every consent decision is recorded and shown in a new admin grid, cleaned up by a daily retention cron.
    • New Update: Enforce mode blocks tagged scripts and removes cookies of categories the shopper did not accept.
    • New Update: Hyvä - the consent banner and preferences popup now work on Hyvä storefronts.
    • Bug Fix: We fixed dismissing the preferences popup overwriting an already saved consent choice.
    • Bug Fix: We fixed the Personal Data Download Logs and Delete Your Account grids failing to load.
  • v4.2.9 (Magento v2.4.x)

    13 July 2026

    Standard:

    • Compatibility: Added compatibility with Magento v2.4.9.

    Professional:

    • Compatibility: Added compatibility with Magento v2.4.9.
  • v4.2.8 (Magento v2.4.x)

    28 April 2026

    Standard:

    • Compatibility: Support for PHP 8.4 environments.

    Professional:

    • Compatibility: Support for PHP 8.4 environments.
  • v4.2.7 (Magento v2.4.x)

    08 January 2026

    Standard:

    • Bug Fix: Button “Delete Address” not showing on Hyva theme
  • v4.2.6 (Magento v2.4.x)

    29 September 2025

    Standard:

    • Bug Fix: Fixed a syntax error.
  • v4.2.5 (Magento v2.4.x)

    21 April 2025

    • Compatibility: Now compatible with Hyva theme
    • Compatibility: Now compatible with Magento 2.4.8
  • v4.2.4 (Magento v2.4.x)

    22 June 2023

    • Compatible with Magento v2.4.6
    • Fixed some minor bugs
  • v4.2.3 (Magento v2.4.x)

    05 April 2023

    • Fix some minor bugs
  • v4.2.2 (Magento v2.4.x)

    28 February 2023

    • Fix some minor bugs
  • v4.2.1 (Magento v2.4.x)

    30 August 2022

    • Compatible with Magento v2.4.4
  • v4.2.0 (Magento v2.4.x)

    07 April 2022

    • Supported Rest API & GraphQL
  • 1.4.0 (Magento v2.3.x)

    21 March 2022

    • Supported Rest API & GraphQL
  • v4.1.0 (Magento v2.4.x)

    27 October 2021

    • Compatible Magento 2.4.2
    • Fix some minor bugs
  • v1.3.0 (Magento v2.3.x)

    27 October 2021

    • Compatible Magento 2.3.7
    • Fix some minor bugs
  • v4.0.0 (Magento v2.4.x)

    10 November 2020

    • Supported Magento v2.4
  • 1.2.4 (Magento v2.3.x)

    19 June 2020

    • Compatible with Magento v2.3.5
  • v1.2.3 (Magento v2.3.x)

    26 August 2019

    • Improved code style & performance

    GDPR Pro

    • New feature: download customer data
    • New feature: auto delete customer
  • v1.2.2 (Magento v2.3.x)

    11 June 2019

    • Compatible with Magento 2.3.1
  • v1.2.1 (Magento v2.3.x)

    22 January 2019

    • Compatible with Magento 2.3.0
  • v1.2.0 (Magento v2.3.x)

    14 June 2018

    GDPR Pro

    • Added confirm the password before deleting the account
    • Added confirm the email before deleting the account
    • Added Terms and Conditions on the Create Account page
    • Fixed bug google analytic still works when the user has not allowed the cookie
  • v1.1.0 (Magento v2.3.x)

    28 May 2018

    GDPR Pro

    • Delete customers abandoned carts information
    • Delete billing information appearing on order, invoice, credit memo, shipment
    • Delete customers subscription information
    • Ability to customize cookie’s message
    • Cookie restriction allows admins to display the message in chosen areas
  • v1.0.0 (Magento v2.3.x)

    17 May 2018

    Release v1.0.0

Load More

Frequently Asked Questions

Magento 2 GDPR extension is a tool that helps e-commerce stores comply with the EU General Data Protection Regulation by managing customers' personal data privacy and handling data access and erasure requests.

To allow the Mageplaza GDPR extension, follow these steps: From the Admin Panel, go to Store > Settings > Configuration > Mageplaza Extensions > GDPR > General configuration and turn the Enable to Yes. Follow our standard guide and pro guide for more details.

Yes. Turn on the cookie preferences popup and shoppers accept or reject each cookie category on its own, with the cookies in each category listed so they can see exactly what they are agreeing to.

Yes. You can show a classic consent banner, or switch on the cookie preferences popup, where shoppers accept or reject each cookie category on its own and can see exactly which cookies sit in each one.

Yes. The preferences popup can be reopened at any time, and the newer decision replaces the older one — with both kept in the consent log.

Each entry in the Cookie Consent Log holds the categories granted, the version of your cookie policy at that moment, the store view, the source, the user agent, the time, and the shopper's IP as a SHA-256 hash, never the raw address. Filter and export any slice of the grid; a daily cron clears records once they pass your retention period.

Filter the log by date, store view or policy version and export the result. Each record shows which categories were granted under which version of your policy, so you can demonstrate what was asked and what was agreed — without holding raw personal data in order to do it.

The GDPR extension collects and stores the consent decision. To pass that signal to GA4 and Google Ads through Google Consent Mode v2, use it alongside Google Tag Manager for Magento 2.

The answer is no. To prevent data misuse issues, customers are able to permanently delete their accounts with all their personal information, like names, addresses, phone numbers, ID card numbers, credit card information, and so on.

To optimize the effectiveness of GDPR, we highly recommend well-compatible modules such as SMTP and Store Credit.

Yes, the module includes Apply For Countries feature which allow users to apply the GDPR regulations on targeted groups of customer. There are 3 options: All Allowed Countries, All EU Countries, and Specific Countries.

Yes, GDPR is compatible with Hyva theme. However, the checkout only supports hyva-themes/magento2-theme-fallback. To learn how to enable checkout on Hyva, please follow this guide.

Mageplaza provides FREE Hyva Checkout Compatibility for all of our extensions upon requests. You can request by contacting us via email, live chat, or support ticket. Our team will respond within 24 hours and ask for details such as Order ID, extension name, Magento & Hyva versions, and any special requirements. To qualify, your module subscription must be active. If your subscription has expired, renewal is required as some older modules do not support Hyva. Additional customization requests may incur extra costs, and our team will inform you before proceeding. For assistance, feel free to reach out - we're here to help!

Magento Edition *
Version * Compare versions
Add Subscription * Up to -20%
  • 1 year support
  • 2 years support
  • 3 years support
FREE installation Tooltip
Ending in:
0
days
:
0
hrs
:
0
mins
:
0
secs
$79
icon logo magento 2.4.4 - 2.4.9
Tooltip
Hyva logo Theme
Tooltip

Pricing

Choose your suitable edition.

Standard

$79 first year
Includes support & updates for 1 year Tooltip
60 days money back guarantee
Read our policies
Features:
check
Account Deletion
check
Password Verification
check
Terms and Conditions Display
check
Data Anonymization

Professional

$129 first year
Includes support & updates for 1 year Tooltip
60 days money back guarantee
Read our policies
Everything in Standard, plus:
check
Account Automatic Deletion
check
Customer Information Download
check
Cookie Restriction Mode
check
Per-category cookie consent
check
Cookie Consent Log
check
Cookie Accept Request
check
CMS Cookie Policy Page
check
Automatic Email
check
Countries Application
check
CSS Customization
Can't see the feature you're looking for?
Describe it and we will customize this extension to suit your needs!
Request customization
feature looking icon