GDPR Goes Beyond Just Policies
While GDPR is often thought of as a privacy policy, cookie banner, or consent mechanism, a website can handle personal data and interact with external services in many ways.
Fonts, JavaScript, analytics, video players, forms, CDNs, external APIs, and other integrations can affect what data leaves a visitor’s browser and which services gain access to technical information.
That’s why we believe GDPR awareness should be embedded at a deeper level than just the visible website interface.
This is where WordPress and SiteAdmin differ significantly.
SiteAdmin Built with GDPR Awareness
SiteAdmin has been developed with privacy and control as core principles of its architecture. The goal is to eliminate the need for customers to manually assemble a long list of plugins and external services to achieve a solid foundation for their website.
SiteAdmin includes built-in cookie and consent management, forms, analytics, website analytics, privacy and cookie policies, and documentation about its suppliers and data processors.
SiteAdmin Cloud uses Swedish hosting infrastructure, and the platform is designed to maintain as much control as possible.
This doesn’t mean a website automatically becomes legally compliant just by using SiteAdmin. The customer remains responsible for their own operations and how the website is used. However, they start from a significantly more controlled technical foundation.
Cookies and Consent
SiteAdmin has its own cookie and consent management system where visitors can give consent and modify or withdraw it.
A key aspect is that SiteAdmin also considers which functions and modules are used on the website.
Each module can specify whether it requires cookie or consent management. If a feature requiring consent is activated, SiteAdmin automatically activates consent functionality and displays information on why it’s needed.
This ensures that consent cannot be manually disabled as long as the relevant feature requires it.
This is a deliberate security approach:
Better to have an extra consent than a doubtful one.
In this way, the customer doesn’t need to know all the technical details behind each module to understand how a feature might impact website privacy.
What Happens Behind the Scenes?
One of the most important parts of GDPR work involves things visitors never see.
A website may load external fonts, JavaScript, images, analytics tools, video players, or other resources from external servers. This can mean the visitor’s browser communicates directly with a third party.
This is common on WordPress websites because themes and plugins can add their own external resources and integrations. This doesn’t necessarily mean it’s wrong, but it means the person building and maintaining the website must have control over what is actually being loaded.
SiteAdmin, on the other hand, tries to keep as much as possible within its own platform. When an external service is needed, SiteAdmin, where possible, makes the request from the server, uses the server’s connection, and handles the result locally.
The visitor’s browser doesn’t need to contact the external service in the same way.
This is a key part of SiteAdmin’s GDPR-aware architecture: we don’t just control what the website shows—we also control what happens behind the scenes.
External CDNs and Resources
A well-built GDPR-compliant WordPress website is possible. A professional agency can configure privacy policy, cookie management, and consent mechanisms effectively.
However, it’s also important to look at the technical environment behind the website.
External CDNs, American cloud services, Google Fonts, external JavaScript libraries, analytics tools, and other third-party services can create communication that the website owner must be aware of and evaluate.
SiteAdmin tries to reduce this risk by maintaining control over the platform’s own code and the modules used.
If a SiteAdmin module uses an external resource, it can also declare this as part of the module’s functionality. The platform can then consider whether cookie or consent management is needed.
Privacy Policy as Part of the Platform
SiteAdmin doesn’t just have a general privacy policy for itself. Each customer’s website also has its own documents stored in the website’s database.
This allows the documentation to be based on SiteAdmin’s actual functions and the environment the customer uses.
This is a significant difference from having to search for a general GDPR template online and then figure out which parts apply to your specific website.
SiteAdmin also helps keep the customer’s documentation up-to-date as the platform evolves and new features are added.
We also have separate documentation for SiteAdmin itself, including information on privacy, suppliers, and data processors.
Suppliers and Data Processors
A modern platform often uses several technical suppliers. Therefore, it’s also important to be clear about which services are used and why.
SiteAdmin has separate documentation where suppliers and data processors can be listed with information about, for example, the service, geographic location, purpose, and categories of data that can be processed.
This makes it easier to understand which parts actually make up the platform’s technical chain.
This is especially important when new features and integrations are developed. GDPR work must keep up with the platform—not just documented once and then forgotten.
New Features Must Also Consider Privacy
SiteAdmin is continuously developed. New features and modules will therefore change what the platform can do.
Part of our approach is also to consider privacy issues when new features are built.
During development, AI can be used as support to identify and propose changes to documentation and GDPR-related information. Proposals are reviewed and approved before being implemented.
It’s not AI that itself decides what should be in the documentation. It acts as development support while the final decision is made by us.
At the module level, features can also declare whether they affect cookie and consent management. This ensures that privacy information follows the technical functionality.
SiteAdmin Analytics and Website Analytics
SiteAdmin has its own analytics function that is part of the platform. The customer therefore doesn’t automatically need to add Google Analytics just to get basic visitor statistics.
SiteAdmin also has website analytics that can check performance, Core Web Vitals, accessibility, SEO, best practices, and GDPR/cookie compliance.
The PageSpeed check runs from SiteAdmin’s server and not from the visitor’s browser. This means the PageSpeed check itself doesn’t need to be loaded as an external service on the public website.
This is another example of the principle that as much as possible should be handled within the platform itself rather than burdening the visitor’s browser with external services.
Forms and Personal Data
Forms are another area where personal data is often handled.
SiteAdmin has its own form builder where forms can include details such as name, email address, phone number, and other fields.
The forms can include a privacy or consent checkbox with a link to relevant information. Forms can also be managed in multiple languages.
Form data is stored in SiteAdmin until the website owner deletes it. This means the customer must have their own procedures for how long the information should be stored.
SiteAdmin also has spam control and AI-based checks before messages are sent.
Even here, the idea is that the customer gets a functional base without needing to assemble multiple external plugins.
WordPress Can Also Be GDPR-Compliant
It’s important to be fair to WordPress. WordPress can absolutely be used to build a very good and GDPR-compliant website.
WordPress has privacy features, and there are many plugins for cookies, consent, forms, analytics, and other privacy-related needs.
A skilled developer or agency can also configure WordPress very carefully, choosing local resources, the right hosting, and the right services.
The problem isn’t that WordPress cannot handle GDPR.
The problem is that WordPress leaves much of the work to the person building the website.
The Difference: Building vs. Starting from Scratch
This is where SiteAdmin stands out most clearly.
With WordPress, you can assemble a GDPR-compliant website yourself. You can choose a good theme, the right hosting, the right cookie plugin, the right form solution, the right analytics tool, and ensure external resources are handled correctly.
But then someone also needs to know that all this needs to be checked.
With SiteAdmin, much of the technical foundation is already in place.
Even if a customer builds their website themselves, they start with a platform where cookie management, privacy, forms, analytics, external resources, and documentation are already part of the whole.
You don’t need to be a GDPR expert to start from a GDPR-aware technical foundation.
Power Users and Custom Code
SiteAdmin also offers the ability to work with custom HTML, CSS, and tailored code for users who need more freedom.
But here, too, there’s a clear boundary.
What SiteAdmin itself controls can be taken responsibility for at the platform level. If a user adds an external service, a custom script, or other code themselves, the responsibility for the change lies with the user.
This is also a reason why Power User isn’t a function that should be enabled for all users. More technical freedom also means more responsibility.
SiteAdmin vs. WordPress: A Comparison
| WordPress | SiteAdmin | |
|---|---|---|
| Cookie Management | Built with plugins and external solutions | Built into the platform |
| Consent | Depends on configuration and chosen solutions | Integrated and can be automatically activated based on modules |
| External Resources | Depends on themes, plugins, and integrations | Controlled within the platform’s own functions and modules |
| Forms | Often plugin-based | Built-in |
| Analytics | Often an external service or plugin | SiteAdmin Analytics is built-in |
| Privacy Documentation | Features exist, but much needs to be configured | Documentation and templates are part of the platform |
| Suppliers | Depends on which services and plugins are used | Platform suppliers are documented centrally |
| New Features | Each plugin may have its own privacy requirements | Modules can declare their privacy and consent needs |
| Freedom | Very high | More controlled |
Who Has the Advantage?
If the question is which system offers the most freedom, the answer is still WordPress.
But if the question is which system gives a customer a controlled and GDPR-aware foundation from the start, the comparison looks different.
WordPress can be built very well. But the person building the website must themselves figure out and check many different aspects.
SiteAdmin tries to make GDPR awareness part of the platform itself.
This isn’t just about the finished website. It also applies to what happens when new modules are activated, external resources are used, and the platform is developed.
The main difference: WordPress gives you the tools to build a GDPR-compliant website. SiteAdmin tries to make GDPR awareness part of the platform itself.