Skip to content

Consent management

The consent management module adds consent versioning, audit trail, data export and GDPR integration. It tracks customer consent history and responds to changes in terms and conditions content.

The plugin monitors the content of legal checkbox labels. Each time settings are saved, it calculates a hash (SHA-256) of the label content. If the hash has changed - the plugin automatically creates a new consent version.

Each consent version contains:

  • version number (auto-increment)
  • label content hash
  • full label content
  • version creation date
  • ID of the user who made the change

In the legal checkbox settings, a Version history button is available next to each checkbox. It displays a list of all versions with dates and content preview.

When consent content changes (new version), the plugin can require customers to give their consent again. Configuration:

Setting Description
Require re-consent Enables a prompt for re-consent after content change
Display prompt On checkout page / In My Account panel / Both
Message content Text informing the customer about the terms change

The customer sees a message about the content change and must check the checkbox again. The previous consent remains in the history with a version label.

The plugin records all consent-related operations:

Event Data
Consent granted User ID, consent ID, version, date, IP, user agent
Consent revoked User ID, consent ID, date, source (customer/admin)
Consent content changed Consent ID, old version, new version, date, admin ID
Re-consent prompt User ID, consent ID, date
Re-consent given User ID, consent ID, new version, date

There is no audit trail screen in wp-admin. The PRO plugin exposes the log through REST only, and every route requires the manage_woocommerce capability:

GET /wp-json/polski-pro/v1/consents?user_id=123
GET /wp-json/polski-pro/v1/consents?session_id=abc
GET /wp-json/polski-pro/v1/consents/versions

user_id or session_id is required; there is no unfiltered listing, no event-type filter and no date-range filter.

The free plugin does have a screen for cookie banner decisions, at Polski > Reports and Tools > Consent records.

Export runs through REST and returns JSON by default:

GET /wp-json/polski-pro/v1/consents/export?user_id=123

One user per call. Add &format=csv for a CSV download, since PRO 1.26.3.

In the customer’s My Account panel, a “My consents” section appears with a list of granted consents. The customer can:

  • browse currently granted consents
  • see the date each consent was granted
  • revoke consent with the “Revoke” button

Consent revocation is recorded in the audit trail. The administrator receives an email notification about the revocation (configurable).

If the consent content has changed, the customer sees a message in the My Account panel asking them to review the new version and give their consent again.

The plugin integrates with the WordPress personal data export mechanism (wp_privacy_personal_data_exporters). When a customer data export is requested, the plugin includes:

  • list of granted consents with dates and versions
  • full consent change history (grants, revocations, re-consents)
  • IP addresses and dates associated with each consent
/**
* Rejestracja eksportera danych osobowych.
*/
add_filter('wp_privacy_personal_data_exporters', function (array $exporters): array {
$exporters['polski-pro-consents'] = [
'exporter_friendly_name' => 'Polski PRO - Zgody',
'callback' => [PolskiPro\Privacy\Exporter::class, 'export'],
];
return $exporters;
});

The plugin integrates with the WordPress data erasure mechanism (wp_privacy_personal_data_erasers). When a data deletion is requested:

  • personal data in the audit trail is anonymized (IP, user agent)
  • consent entries are marked as deleted
  • the fact of granting/revoking consent itself remains (without identifying data) for accountability purposes
/**
* Rejestracja erasera danych osobowych.
*/
add_filter('wp_privacy_personal_data_erasers', function (array $erasers): array {
$erasers['polski-pro-consents'] = [
'eraser_friendly_name' => 'Polski PRO - Zgody',
'callback' => [PolskiPro\Privacy\Eraser::class, 'erase'],
];
return $erasers;
});

Three read-only routes, all requiring the manage_woocommerce capability.

GET /wp-json/polski-pro/v1/consents?user_id={id}
GET /wp-json/polski-pro/v1/consents?session_id={id}

One of the two is required; without either the route answers 400 with “Provide user_id or session_id.” A user lookup returns the newest 200 records, a session lookup returns that session’s records. There is no event-type or date filter and no paging.

GET /wp-json/polski-pro/v1/consents/export?user_id={id}
GET /wp-json/polski-pro/v1/consents/export?user_id={id}&format=csv

user_id is required. Returns up to 1000 records. The default is JSON, wrapped with user_id, exported_at and records_count. Pass format=csv for a text/csv download with the columns checkbox_id, context, consented, ip_address, created_at, where consented reads yes or no. Any other value falls back to JSON.

Before PRO 1.26.3 the format argument was declared and ignored, so a request for CSV received JSON with no error.

GET /wp-json/polski-pro/v1/consents/versions

Returns the stored version map. Takes no arguments.

There is no /consents/audit route, and no route accepts consent_id, event_type, date_from, date_to or per_page.

The consent module registers no actions or filters of its own. Read the log through the routes above, or through ConsentLog directly. For GDPR requests, the module registers a WordPress personal-data exporter and eraser, which is the supported way to reach this data from outside the plugin.

  1. Check if the “Require re-consent” option is enabled
  2. Verify that the consent content has actually changed (check version history)
  3. Clear the checkout page and My Account panel cache
  1. Make sure the consent management module is active
  2. Check if the polski-pro-consents exporter is registered in Tools > Export Personal Data
  3. Verify logs for PHP errors

The plugin stores consent history in a separate database table. With a large number of customers, the table can grow. Consider:

  • regularly exporting and archiving older entries
  • setting up automatic cleanup of entries older than a specified number of months (option in settings)
This page is for informational purposes only and does not constitute legal advice. Consult a lawyer before implementation. Polski for WooCommerce is open source software (GPLv2) provided without warranty.