WordPress Training
ElementorWordPress

Setting Up Elementor in a GDPR-Compliant Way: Fonts, Maps, Videos, Forms

Elementor itself is unremarkable in data protection terms. It gets critical with four components that almost every website uses — and which, on their default settings, transmit data to third parties before the visitor has agreed to anything.

First, because it belongs here: I am not a lawyer. What follows is the technical implementation from practice. For a binding assessment of your specific website, ask somebody qualified to give one.

1. Fonts: the most common single case

When Elementor embeds Google Fonts, your visitor's browser loads the font from a Google server. Their IP address is transmitted in the process — without consent and without them noticing. That is exactly what the well-known German court decision on the matter was about, and the reasoning carries over to Austria.

The solution: host the fonts yourself. You download the font files and embed them via your own domain. Elementor supports custom fonts under Elementor → Custom Fonts; alternatively there are plugins that switch this over automatically.

Afterwards, check that no connection really goes out any more. In your browser's developer tools, under “Network”, you can see all loaded resources — filter for googleapis and gstatic. Making the switch is not enough on its own; often the theme loads fonts of its own on top.

Side effect: self-hosted fonts usually load faster and avoid layout shifts, see Elementor and Core Web Vitals.

2. Google Maps

The map widget embeds Google Maps directly — with data transmission on page load, before anyone has even touched the map.

The clean approach is a two-click solution: at first only a placeholder appears, with a note that data will be transmitted to Google on loading. Only after an active click is the map loaded. A consent tool that blocks embeds like this will handle it.

For many websites the simpler variant is enough anyway: a screenshot of the map plus a “Get directions” link. No tracking, a faster page, the same function for the visitor.

3. YouTube and Vimeo

An embedded video sets cookies on loading and transmits data — here too before any interaction.

The video widget has a privacy mode option (for YouTube the “nocookie” variant). That reduces tracking but does not eliminate it completely. Do not rely on it alone.

The dependable route here too is: show a preview image, load the video only on click. That is also good for loading time, because the video script is not loaded along with the page.

4. Forms

With forms it is less about embedding and more about how the data is handled.

Data minimisation. Ask only for what you actually need. A required “phone number” field for a written enquiry is hard to justify — and it costs you enquiries as well.

A reference to the privacy policy. One sentence at the form pointing to what the data will be used for.

A consent checkbox, but done properly. It must not be pre-ticked, and it has to be worded comprehensibly. For a plain contact enquiry a checkbox is often not legally necessary at all; for adding someone to a newsletter it is — and then separately from the contact purpose.

Retention period. Elementor Pro stores form submissions in the database if you want it to. Convenient, but you are thereby collecting personal data on your server. Either switch it off or delete regularly.

Spam protection. If you use Google's reCAPTCHA, the same applies as for Maps: it transmits data. There are European alternatives, and for many small websites a simple honeypot field is enough.

What belongs in the privacy policy

For each of these services: which provider, what data, for what purpose, on what legal basis. If you host fonts yourself, replace Maps with a screenshot and only load videos on click, the text gets considerably shorter — that too is an argument for these solutions.

Also check whether your host offers a data processing agreement. With Austrian and German providers that is standard.

A word on the cookie banner

A banner that does not actually block scripts is decoration. If Google Maps and YouTube load on page view anyway, the consent prompt changes nothing about the transmission.

And: an Elementor popup is not a consent tool. It documents no consent and blocks nothing — see creating a popup in Elementor.

Elementor Pro: custom fonts and the privacy mode in the video widget are part of Pro. Forms as well — including the retention setting, which you should then set deliberately. View Elementor Pro

In brief

Host fonts yourself. Load maps and videos only after a click. Keep forms sparing and do not store submissions forever. Then check in the browser that no unwanted connections are actually being made any more.

These four points cover what I most frequently encounter in client projects. If you want to go through this on your own site together, it is a regular topic in my Elementor training.

Tags

DatenschutzDSGVOElementorRechtWordPress