GDPR and WordPress management: where does your client's data live?
If you maintain sites for clients, you are a processor. That comes with obligations most agencies have never written down.
Robin
Every agency that manages WordPress sites for clients processes personal data on their behalf: form submissions, order details, user accounts, IP addresses in logs. Under the GDPR that makes you a processor and the client a controller, whether or not anyone has signed anything.
The first practical consequence is the data processing agreement. You need one with each client, and each tool you use needs one with you. Hosting, backup storage, monitoring, an email service, a management dashboard: every one of them touches data and belongs in your register.
The second is knowing where the data physically sits. Backups in particular have a habit of ending up in a storage bucket on another continent without anyone deciding that on purpose. For European clients, and especially for public sector and healthcare clients, EU hosting is often a hard requirement rather than a preference.
The third is access. The GDPR expects you to limit who can reach personal data to those who need it. In practice that means named accounts instead of a shared login, roles instead of everyone being an administrator, and removing access when someone leaves the project.
Then there is retention. Contact form entries stored forever in the WordPress database are a liability, not an archive. Agree a retention period with the client, apply it, and write it down. The same applies to backup retention: thirty days of daily backups is a defensible choice, five years of them is not.
Logging deserves specific attention. Uptime checks, error logs and security scans routinely capture IP addresses. That is legitimate for security purposes, but it needs to be in the processing agreement and it needs a retention limit.
A breach has a clock on it. As a processor you must notify the controller without undue delay, and the controller has seventy-two hours to notify the regulator. That means you need to be able to determine quickly what happened, which files changed, and which data was reachable. Integrity scanning and a clear activity log turn a panicked weekend into a documented incident.
The management tool itself is part of the picture. If your dashboard stores connection keys, it should store them encrypted and outside the WordPress installations it manages. If it is hosted, ask where. If it is self-hosted, remember that you are now the party responsible for securing it.
None of this requires a legal department. It requires a short list per client: which tools touch the data, where each stores it, what the retention period is, and who has access. Review it once a year and when you change tooling.
The agencies that handle this well do not treat it as compliance paperwork. They treat it as part of the maintenance product, and they say so in the proposal, because a client in a regulated sector will choose the agency that already has the answer.