Consent management
The consent management module adds consent versioning, audit trail, data export and GDPR integration. It tracks customer consent history and responds to changes in terms and conditions content.
Consent versioning
Section titled “Consent versioning”Automatic change detection
Section titled “Automatic change detection”The plugin monitors the content of legal checkbox labels. Each time settings are saved, it calculates a hash (SHA-256) of the label content. If the hash has changed - the plugin automatically creates a new consent version.
Each consent version contains:
- version number (auto-increment)
- label content hash
- full label content
- version creation date
- ID of the user who made the change
Version history
Section titled “Version history”In the legal checkbox settings, a Version history button is available next to each checkbox. It displays a list of all versions with dates and content preview.
Re-consent
Section titled “Re-consent”When consent content changes (new version), the plugin can require customers to give their consent again. Configuration:
| Setting | Description |
|---|---|
| Require re-consent | Enables a prompt for re-consent after content change |
| Display prompt | On checkout page / In My Account panel / Both |
| Message content | Text informing the customer about the terms change |
The customer sees a message about the content change and must check the checkbox again. The previous consent remains in the history with a version label.
Audit trail
Section titled “Audit trail”Recorded events
Section titled “Recorded events”The plugin records all consent-related operations:
| Event | Data |
|---|---|
| Consent granted | User ID, consent ID, version, date, IP, user agent |
| Consent revoked | User ID, consent ID, date, source (customer/admin) |
| Consent content changed | Consent ID, old version, new version, date, admin ID |
| Re-consent prompt | User ID, consent ID, date |
| Re-consent given | User ID, consent ID, new version, date |
Browsing history
Section titled “Browsing history”There is no audit trail screen in wp-admin. The PRO plugin exposes the log through REST only, and every route requires the manage_woocommerce capability:
GET /wp-json/polski-pro/v1/consents?user_id=123GET /wp-json/polski-pro/v1/consents?session_id=abcGET /wp-json/polski-pro/v1/consents/versionsuser_id or session_id is required; there is no unfiltered listing, no event-type filter and no date-range filter.
The free plugin does have a screen for cookie banner decisions, at Polski > Reports and Tools > Consent records.
Data export
Section titled “Data export”Export runs through REST and returns JSON by default:
GET /wp-json/polski-pro/v1/consents/export?user_id=123One user per call. Add &format=csv for a CSV download, since PRO 1.26.3.
My Account panel integration
Section titled “My Account panel integration”Revoking consent
Section titled “Revoking consent”In the customer’s My Account panel, a “My consents” section appears with a list of granted consents. The customer can:
- browse currently granted consents
- see the date each consent was granted
- revoke consent with the “Revoke” button
Consent revocation is recorded in the audit trail. The administrator receives an email notification about the revocation (configurable).
Re-consent prompt
Section titled “Re-consent prompt”If the consent content has changed, the customer sees a message in the My Account panel asking them to review the new version and give their consent again.
GDPR integration
Section titled “GDPR integration”Personal data export
Section titled “Personal data export”The plugin integrates with the WordPress personal data export mechanism (wp_privacy_personal_data_exporters). When a customer data export is requested, the plugin includes:
- list of granted consents with dates and versions
- full consent change history (grants, revocations, re-consents)
- IP addresses and dates associated with each consent
/** * Rejestracja eksportera danych osobowych. */add_filter('wp_privacy_personal_data_exporters', function (array $exporters): array { $exporters['polski-pro-consents'] = [ 'exporter_friendly_name' => 'Polski PRO - Zgody', 'callback' => [PolskiPro\Privacy\Exporter::class, 'export'], ]; return $exporters;});Personal data erasure
Section titled “Personal data erasure”The plugin integrates with the WordPress data erasure mechanism (wp_privacy_personal_data_erasers). When a data deletion is requested:
- personal data in the audit trail is anonymized (IP, user agent)
- consent entries are marked as deleted
- the fact of granting/revoking consent itself remains (without identifying data) for accountability purposes
/** * Rejestracja erasera danych osobowych. */add_filter('wp_privacy_personal_data_erasers', function (array $erasers): array { $erasers['polski-pro-consents'] = [ 'eraser_friendly_name' => 'Polski PRO - Zgody', 'callback' => [PolskiPro\Privacy\Eraser::class, 'erase'], ]; return $erasers;});REST API
Section titled “REST API”Three read-only routes, all requiring the manage_woocommerce capability.
Consents for one user or session
Section titled “Consents for one user or session”GET /wp-json/polski-pro/v1/consents?user_id={id}GET /wp-json/polski-pro/v1/consents?session_id={id}One of the two is required; without either the route answers 400 with “Provide user_id or session_id.” A user lookup returns the newest 200 records, a session lookup returns that session’s records. There is no event-type or date filter and no paging.
Export for one user
Section titled “Export for one user”GET /wp-json/polski-pro/v1/consents/export?user_id={id}GET /wp-json/polski-pro/v1/consents/export?user_id={id}&format=csvuser_id is required. Returns up to 1000 records. The default is JSON, wrapped with user_id, exported_at and records_count. Pass format=csv for a text/csv download with the columns checkbox_id, context, consented, ip_address, created_at, where consented reads yes or no. Any other value falls back to JSON.
Before PRO 1.26.3 the format argument was declared and ignored, so a request for CSV received JSON with no error.
Consent versions
Section titled “Consent versions”GET /wp-json/polski-pro/v1/consents/versionsReturns the stored version map. Takes no arguments.
There is no /consents/audit route, and no route accepts consent_id, event_type, date_from, date_to or per_page.
The consent module registers no actions or filters of its own. Read the log through the routes above, or through ConsentLog directly. For GDPR requests, the module registers a WordPress personal-data exporter and eraser, which is the supported way to reach this data from outside the plugin.
Common issues
Section titled “Common issues”Re-consent prompt not displaying
Section titled “Re-consent prompt not displaying”- Check if the “Require re-consent” option is enabled
- Verify that the consent content has actually changed (check version history)
- Clear the checkout page and My Account panel cache
GDPR export does not contain consent data
Section titled “GDPR export does not contain consent data”- Make sure the consent management module is active
- Check if the
polski-pro-consentsexporter is registered in Tools > Export Personal Data - Verify logs for PHP errors
Audit trail growing too fast
Section titled “Audit trail growing too fast”The plugin stores consent history in a separate database table. With a large number of customers, the table can grow. Consider:
- regularly exporting and archiving older entries
- setting up automatic cleanup of entries older than a specified number of months (option in settings)