Webflow GDPR: What Your Site Needs to Be Compliant in 2026

TL;DR Webflow GDPR compliance is shared: Webflow secures hosting, but the tracking on your site is your job. You need a cookie banner that blocks GA4 and pixels before consent, a handle on Webflow Analyze and Optimize, and a privacy policy that lists what you actually run. Here is the full checklist.

Webflow is a solid platform, and it takes care of a lot: hosting, SSL, a Data Processing Agreement. What it does not do is decide which trackers run on your site, or when. That part is on you.

This guide covers what Webflow handles, what it leaves to you, and the short list of things you need to fix to make a Webflow site GDPR compliant.

Is Webflow GDPR compliant?

Webflow as a platform can be used in a GDPR compliant way, but that does not make your site compliant. Webflow is the processor. You are the controller. Every tracker, pixel and embed you add to the site needs a legal basis, and for non-essential cookies that basis is consent collected before they run.

Think of it like renting an office. The landlord handles the locks and the fire alarm. What you do inside the office is your responsibility. Webflow gives you secure hosting. It does not stop you from pasting a Meta Pixel into the site head.

This matters because regulators look at the site, not the platform. The EDPB cookie banner taskforce reviewed real websites and their banners. Nobody asked which site builder they used.

What does Webflow handle for you?

Webflow handles the infrastructure layer: hosting, SSL certificates, uptime and the security of the Designer. It also offers a Data Processing Agreement, which you should accept if you run a business on the platform. It does not add a cookie banner, and it does not block third-party scripts before consent.

That split is easy to miss. The Webflow dashboard makes publishing feel finished. But a published site with GA4 in the custom code runs GA4 on every visit, consent or not.

What is left for you to do?

Here is the practical list. Most Webflow sites need all five:

  • A cookie banner that actually blocks. Not a notice. Scripts must wait until the visitor says yes.
  • Control over Webflow's own tracking. Analyze and Optimize track visitors too (more on this below).
  • A way to withdraw consent. A link or button, usually in the footer or on the privacy page.
  • A privacy policy that matches reality. It should list the cookies and tools you actually use.
  • Embeds under control. YouTube, Vimeo, Calendly and Google Maps all set cookies the moment they load.

Not sure what your site runs today? Start with a free GDPR scan. It loads your Webflow site like a visitor would and lists every cookie and third-party request it finds.

Do Webflow Analyze and Optimize need consent?

Yes, if you use them on a site with EU visitors. Analyze and Optimize are Webflow's own analytics and testing features, and they track visitors. Webflow gives you a "Site tracking" setting and a small JavaScript API so a consent tool can switch that tracking on or off per visitor.

According to Webflow's help center, you should set the tracking default to Don't track by default (or let visitors opt out) before you connect a consent solution. For EU traffic, "don't track by default" is the safe choice, because opt-out is not valid consent under GDPR.

The Webflow consent API has three functions: wf.getUserTrackingChoice(), wf.allowUserTracking() and wf.denyUserTracking(). They only affect Analyze and Optimize. Your GA4, Meta Pixel and Hotjar are not touched by them.

How to connect them to Consentify

On the Scale plan you can add a custom integration in the analytics category with a one line script:

wf.ready(() => wf.allowUserTracking());

Consentify only injects that script once the visitor accepts analytics. Until then, Webflow's default ("don't track") stays in place. If you do not use Analyze or Optimize, skip this step entirely.

How do you block Google Analytics on Webflow until consent?

Remove the GA4 tag from Webflow's custom code and from the Google Analytics field in Project Settings. Then add your Measurement ID to Consentify instead. Consentify injects GA4 only after the visitor accepts analytics, so there is nothing to block because nothing loads early.

This is the part people get wrong most often. They add a cookie banner, but leave GA4 in the site head. The banner shows up, the visitor clicks "Reject", and GA4 has already fired. A banner that does not control the scripts is decoration.

The same goes for Meta Pixel, TikTok Pixel, LinkedIn Insight Tag and Hotjar. Take them out of Webflow, add their IDs to Consentify, and let the consent decision decide whether they load. If you want the full picture on GA, we wrote a separate guide on making Google Analytics GDPR compliant.

What about Google Tag Manager?

Same idea. Remove your own GTM snippet and give Consentify the container ID. We load GTM after consent and send Google Consent Mode signals to the Google tags inside it. Non-Google tags in the container should use the consentify_consent dataLayer event as their trigger. The Consent Mode v2 page explains basic and advanced mode.

Adding the cookie banner to Webflow

The setup itself is short. Create your domain in the Consentify dashboard, add your integrations, then paste one script tag into Project Settings, Custom Code, Footer Code:

<script src="https://consentify.app/api/gateway?token=YOUR_TOKEN"></script>

Publish, and the banner is live on every page. It renders in a shadow DOM, so your Webflow styles and Interactions do not clash with it. For a click by click walkthrough with screenshots of each Webflow panel, see our Webflow cookie consent guide or the Webflow integration page.

Add the revoke button

GDPR says withdrawing consent must be as easy as giving it. In Webflow, add a link or button to your footer, open the element settings and set its ID to revoke-consent-btn. Consentify finds it and reopens the consent panel when clicked. No extra code.

Do Webflow forms need consent?

No, not for the cookie part. A Webflow form does not need cookie consent just to exist. But the data people submit is personal data, so you still need a legal basis, a clear purpose and a privacy policy that says where submissions go.

Practical tips for forms:

  • Only ask for what you need. A contact form rarely needs a phone number.
  • If you send submissions to a CRM or Zapier, name those tools in your privacy policy.
  • If you add a newsletter checkbox, leave it unticked. Pre-ticked boxes are not valid consent.
  • If you use reCAPTCHA on the form, remember it is a Google service that loads its own scripts.

What about embeds, fonts and other third parties?

Embeds are the sneaky part of Webflow GDPR. A YouTube video pasted into a Rich Text block or an Embed element starts talking to Google the moment the page loads. Calendly, Vimeo, Google Maps and Spotify do the same.

Consentify handles these in the browser. It swaps the embed for a placeholder until the visitor accepts the right category, then loads the real thing. You keep your embed code as it is. Our post on YouTube embeds and cookie consent goes deeper on this.

Fonts are a smaller issue. Webflow serves Google Fonts through its own setup in most cases, but if you have added a Google Fonts link manually in custom code, the visitor's IP goes to Google. Upload the font files to Webflow instead and the problem goes away.

How do I check that my Webflow site is compliant?

Run a scan after you publish. Open your site in a private window, do not click the banner, and check what loads. Nothing in the analytics or marketing category should appear before you accept. A scanner does the same check faster and catches things you would miss by eye.

Our GDPR scanner flags trackers that fire before consent and cookies set on first load. If it finds GA4 or a pixel before consent, it usually means an old tag is still sitting in Webflow's custom code or in a page-level embed. Remove it, republish, and scan again.

We see the same pattern on most Webflow sites we scan: the banner is installed, but one tag from an old campaign still lives in a page setting nobody remembers. Page-level custom code is the first place to look.

Webflow GDPR checklist

  • Accept Webflow's Data Processing Agreement.
  • Scan the site to see what runs today.
  • Remove GA4, GTM and pixels from Webflow custom code and add their IDs to Consentify.
  • Set Site tracking to "Don't track by default" if you use Analyze or Optimize.
  • Paste the Consentify script tag into the footer code and publish.
  • Add a revoke-consent-btn element to the footer.
  • Update your privacy policy with the tools you actually use.
  • Scan again and confirm nothing fires before consent.

That is a one hour job for most sites. If you build Webflow sites for clients, do it once as a template and reuse it. Agencies on the Scale plan manage every client site from one dashboard.

Want to get your Webflow site sorted today? Start with Consentify for free, or pick the Scale plan if you need custom integrations, multiple languages or more than one site.
Free scan, no account

Does any of this apply to your site?

Find out in ten seconds. The scan shows which trackers fire before your visitors have agreed to anything.

  • Results in about 10 seconds
  • No account needed
  • Shareable report link

Frequently asked questions

Does Webflow have a built-in cookie banner?

No. Webflow has a consent API for its own Analyze and Optimize features, but it does not ship a cookie banner that blocks third-party scripts like Google Analytics or Meta Pixel. You need a consent management platform for that.

Is Webflow GDPR compliant?

Webflow can be used in a GDPR compliant way and offers a Data Processing Agreement. Your site is only compliant if you collect consent before non-essential trackers run, give visitors a way to withdraw consent and publish an accurate privacy policy.

Do Webflow Analyze and Optimize need cookie consent?

Yes, for EU visitors. Set Site tracking to 'Don't track by default' and enable tracking only after the visitor accepts analytics, using Webflow's wf.allowUserTracking() function.

Where do I paste the cookie banner script in Webflow?

In Project Settings, Custom Code, Footer Code. Paste the Consentify script tag there, save and publish. The banner then appears on every page of the site.

Do I need consent for Webflow forms?

Not cookie consent. Forms collect personal data, so you need a clear purpose and a privacy policy that explains where submissions go. Any marketing opt-in checkbox must be unticked by default.

Free forever, no credit card

Get your cookie banner live in 5 minutes

Paste one script tag into your site and you're covered. No plugin to install, no code to write, nothing to pay.

  • 1 domain
  • 5,000 pageviews/mo
  • All integrations
  • GDPR, CCPA and ePrivacy
Start for free

No credit card. Free forever.

Compare plans
Written by Consentify
Helping you stay GDPR compliant, one banner at a time.