Webflow is a solid platform, and it takes care of a lot: hosting, SSL, a Data Processing Agreement. What it does not do is decide which trackers run on your site, or when. That part is on you.
This guide covers what Webflow handles, what it leaves to you, and the short list of things you need to fix to make a Webflow site GDPR compliant.
Is Webflow GDPR compliant?
Webflow as a platform can be used in a GDPR compliant way, but that does not make your site compliant. Webflow is the processor. You are the controller. Every tracker, pixel and embed you add to the site needs a legal basis, and for non-essential cookies that basis is consent collected before they run.
Think of it like renting an office. The landlord handles the locks and the fire alarm. What you do inside the office is your responsibility. Webflow gives you secure hosting. It does not stop you from pasting a Meta Pixel into the site head.
This matters because regulators look at the site, not the platform. The EDPB cookie banner taskforce reviewed real websites and their banners. Nobody asked which site builder they used.
What does Webflow handle for you?
Webflow handles the infrastructure layer: hosting, SSL certificates, uptime and the security of the Designer. It also offers a Data Processing Agreement, which you should accept if you run a business on the platform. It does not add a cookie banner, and it does not block third-party scripts before consent.
That split is easy to miss. The Webflow dashboard makes publishing feel finished. But a published site with GA4 in the custom code runs GA4 on every visit, consent or not.
What is left for you to do?
Here is the practical list. Most Webflow sites need all five:
- A cookie banner that actually blocks. Not a notice. Scripts must wait until the visitor says yes.
- Control over Webflow's own tracking. Analyze and Optimize track visitors too (more on this below).
- A way to withdraw consent. A link or button, usually in the footer or on the privacy page.
- A privacy policy that matches reality. It should list the cookies and tools you actually use.
- Embeds under control. YouTube, Vimeo, Calendly and Google Maps all set cookies the moment they load.
Not sure what your site runs today? Start with a free GDPR scan. It loads your Webflow site like a visitor would and lists every cookie and third-party request it finds.
Do Webflow Analyze and Optimize need consent?
Yes, if you use them on a site with EU visitors. Analyze and Optimize are Webflow's own analytics and testing features, and they track visitors. Webflow gives you a "Site tracking" setting and a small JavaScript API so a consent tool can switch that tracking on or off per visitor.
According to Webflow's help center, you should set the tracking default to Don't track by default (or let visitors opt out) before you connect a consent solution. For EU traffic, "don't track by default" is the safe choice, because opt-out is not valid consent under GDPR.
The Webflow consent API has three functions: wf.getUserTrackingChoice(), wf.allowUserTracking() and wf.denyUserTracking(). They only affect Analyze and Optimize. Your GA4, Meta Pixel and Hotjar are not touched by them.
How to connect them to Consentify
On the Scale plan you can add a custom integration in the analytics category with a one line script:
wf.ready(() => wf.allowUserTracking());
Consentify only injects that script once the visitor accepts analytics. Until then, Webflow's default ("don't track") stays in place. If you do not use Analyze or Optimize, skip this step entirely.
How do you block Google Analytics on Webflow until consent?
Remove the GA4 tag from Webflow's custom code and from the Google Analytics field in Project Settings. Then add your Measurement ID to Consentify instead. Consentify injects GA4 only after the visitor accepts analytics, so there is nothing to block because nothing loads early.
This is the part people get wrong most often. They add a cookie banner, but leave GA4 in the site head. The banner shows up, the visitor clicks "Reject", and GA4 has already fired. A banner that does not control the scripts is decoration.
The same goes for Meta Pixel, TikTok Pixel, LinkedIn Insight Tag and Hotjar. Take them out of Webflow, add their IDs to Consentify, and let the consent decision decide whether they load. If you want the full picture on GA, we wrote a separate guide on making Google Analytics GDPR compliant.
What about Google Tag Manager?
Same idea. Remove your own GTM snippet and give Consentify the container ID. We load GTM after consent and send Google Consent Mode signals to the Google tags inside it. Non-Google tags in the container should use the consentify_consent dataLayer event as their trigger. The Consent Mode v2 page explains basic and advanced mode.
Adding the cookie banner to Webflow
The setup itself is short. Create your domain in the Consentify dashboard, add your integrations, then paste one script tag into Project Settings, Custom Code, Footer Code:
<script src="https://consentify.app/api/gateway?token=YOUR_TOKEN"></script>
Publish, and the banner is live on every page. It renders in a shadow DOM, so your Webflow styles and Interactions do not clash with it. For a click by click walkthrough with screenshots of each Webflow panel, see our Webflow cookie consent guide or the Webflow integration page.
Add the revoke button
GDPR says withdrawing consent must be as easy as giving it. In Webflow, add a link or button to your footer, open the element settings and set its ID to revoke-consent-btn. Consentify finds it and reopens the consent panel when clicked. No extra code.
Do Webflow forms need consent?
No, not for the cookie part. A Webflow form does not need cookie consent just to exist. But the data people submit is personal data, so you still need a legal basis, a clear purpose and a privacy policy that says where submissions go.
Practical tips for forms:
- Only ask for what you need. A contact form rarely needs a phone number.
- If you send submissions to a CRM or Zapier, name those tools in your privacy policy.
- If you add a newsletter checkbox, leave it unticked. Pre-ticked boxes are not valid consent.
- If you use reCAPTCHA on the form, remember it is a Google service that loads its own scripts.
What about embeds, fonts and other third parties?
Embeds are the sneaky part of Webflow GDPR. A YouTube video pasted into a Rich Text block or an Embed element starts talking to Google the moment the page loads. Calendly, Vimeo, Google Maps and Spotify do the same.
Consentify handles these in the browser. It swaps the embed for a placeholder until the visitor accepts the right category, then loads the real thing. You keep your embed code as it is. Our post on YouTube embeds and cookie consent goes deeper on this.
Fonts are a smaller issue. Webflow serves Google Fonts through its own setup in most cases, but if you have added a Google Fonts link manually in custom code, the visitor's IP goes to Google. Upload the font files to Webflow instead and the problem goes away.
How do I check that my Webflow site is compliant?
Run a scan after you publish. Open your site in a private window, do not click the banner, and check what loads. Nothing in the analytics or marketing category should appear before you accept. A scanner does the same check faster and catches things you would miss by eye.
Our GDPR scanner flags trackers that fire before consent and cookies set on first load. If it finds GA4 or a pixel before consent, it usually means an old tag is still sitting in Webflow's custom code or in a page-level embed. Remove it, republish, and scan again.
We see the same pattern on most Webflow sites we scan: the banner is installed, but one tag from an old campaign still lives in a page setting nobody remembers. Page-level custom code is the first place to look.
Webflow GDPR checklist
- Accept Webflow's Data Processing Agreement.
- Scan the site to see what runs today.
- Remove GA4, GTM and pixels from Webflow custom code and add their IDs to Consentify.
- Set Site tracking to "Don't track by default" if you use Analyze or Optimize.
- Paste the Consentify script tag into the footer code and publish.
- Add a
revoke-consent-btnelement to the footer. - Update your privacy policy with the tools you actually use.
- Scan again and confirm nothing fires before consent.
That is a one hour job for most sites. If you build Webflow sites for clients, do it once as a template and reuse it. Agencies on the Scale plan manage every client site from one dashboard.
Want to get your Webflow site sorted today? Start with Consentify for free, or pick the Scale plan if you need custom integrations, multiple languages or more than one site.