Title: xprttudio Local Consent for 152-FZ
Author: xpertstudio
Published: <strong>September 28, 2026</strong>
Last modified: September 28, 2026

---

Search plugins

![](https://ps.w.org/xprttudio-local-consent-152-fz/assets/banner-772x250.png?rev
=3717267)

![](https://ps.w.org/xprttudio-local-consent-152-fz/assets/icon-256x256.png?rev=
3717267)

# xprttudio Local Consent for 152-FZ

 By [xpertstudio](https://profiles.wordpress.org/xprttudio/)

[Download](https://downloads.wordpress.org/plugin/xprttudio-local-consent-152-fz.1.2.2.zip)

 * [Details](https://wordpress.org/plugins/xprttudio-local-consent-152-fz/#description)
 * [Reviews](https://wordpress.org/plugins/xprttudio-local-consent-152-fz/#reviews)
 *  [Installation](https://wordpress.org/plugins/xprttudio-local-consent-152-fz/#installation)
 * [Development](https://wordpress.org/plugins/xprttudio-local-consent-152-fz/#developers)

 [Support](https://wordpress.org/support/plugin/xprttudio-local-consent-152-fz/)

## Description

This plugin helps bring a site in line with the requirements of Russian Federal 
Law No. 152-FZ “On Personal Data”:

 * Shows a 152-FZ checklist on the settings page: which items the plugin already
   covers (based on current settings) and what needs to be done separately — a policy
   link in the footer, a Roskomnadzor notice, hosting the server in Russia.
 * Displays a cookie consent banner with three buttons — Accept, Reject, and Settings(
   expands an explanation and a link to the cookie policy).
 * Adds a required consent checkbox to the WordPress comment form.
 * Adds a required consent checkbox to the WooCommerce checkout page.
 * Can optionally auto-add a required checkbox to specific Contact Form 7 forms,
   via a whitelist of form IDs; disabled for all forms by default.
 * The Accept button color is customizable via the standard WordPress color picker.
 * Supports policy versioning: bumping the version in settings shows the banner 
   again to visitors who already consented to an earlier version.
 * Keeps a consent log (date, type, policy version, hashed IP) to help confirm that
   consent was given.
 * Lets you export the consent log to CSV.
 * Configurable log retention period, with automatic cleanup.

The plugin does not send any data to external servers. All data is stored in your
site’s own database.

#### Limitations

This plugin is a technical tool for collecting consent and does not replace legal
advice. The personal data processing policy and consent texts must be prepared separately
and must match your actual data processing practices.

The plugin author is not responsible for whether your site actually complies with
152-FZ. Achieving and maintaining compliance — including the accuracy of your policy
text, notifying Roskomnadzor, and the physical location of your hosting — is entirely
the responsibility of the site owner. The plugin is provided “as is”, without warranty
of any kind, as permitted by the GPL license it is distributed under.

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/`.
 2. Activate the plugin through the “Plugins” menu in WordPress.
 3. Go to “Settings  152-FZ: Consent” and configure the banner text and checkboxes,
    and select the policy page.

## FAQ

### Does the plugin replace a legal privacy policy?

No. The plugin is a technical tool for showing the banner and collecting consent.
The personal data processing policy text must be prepared separately and linked 
in the settings.

### Does the plugin send data to third-party services?

No, the plugin does not connect to any external services and does not share data
with third parties.

### Is the plugin author responsible for my site’s compliance with 152-FZ?

No. The plugin is a technical tool only, not a legal service. Whether your site 
actually complies with 152-FZ — including the wording of your policy, notifying 
Roskomnadzor, and where your data is hosted — is the responsibility of the site 
owner, not the plugin author.

### Can I add the checkbox to my own form (not comments, WooCommerce, or Contact Form 7)?

Not yet. The plugin intentionally supports only the forms where it can reliably 
block submission without the checkbox and log the consent: WordPress comments, WooCommerce
checkout, and whitelisted Contact Form 7 forms. There used to be a shortcode for
adding the checkbox to any form, but it only rendered a checkbox with the HTML `
required` attribute, without real server-side blocking or logging, which was misleading—
so it was removed in 1.2.0.

### What data is stored in the consent log?

Date and time, form type, the policy version in effect at the time of consent, a
hash of the IP address (not the IP address itself), and the browser user agent. 
This lets you confirm that consent was given without storing the IP address in plain
text.

### What does the “Reject” button in the cookie banner do?

It hides the banner and logs the rejection. 152-FZ does not formally require an 
opt-out button in the banner, but many sites add one for transparency. The plugin
does not control the loading of third-party scripts (analytics, ads, etc.) — if 
such scripts are added to the site outside of this plugin, rejecting in the banner
will not disable them.

### Can I export the consent log?

Yes, the settings page has an “Export log to CSV” button.

### Is this plugin affiliated with WooCommerce or Contact Form 7?

No. This plugin integrates with WooCommerce and Contact Form 7 if they are installed,
but it is not developed, owned, or endorsed by their respective teams.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“xprttudio Local Consent for 152-FZ” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ xpertstudio ](https://profiles.wordpress.org/xprttudio/)

[Translate “xprttudio Local Consent for 152-FZ” into your language.](https://translate.wordpress.org/projects/wp-plugins/xprttudio-local-consent-152-fz)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/xprttudio-local-consent-152-fz/),
check out the [SVN repository](https://plugins.svn.wordpress.org/xprttudio-local-consent-152-fz/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/xprttudio-local-consent-152-fz/)
by [RSS](https://plugins.trac.wordpress.org/log/xprttudio-local-consent-152-fz/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.2

 * Fixed: the WooCommerce checkout consent checkbox was wrapped in an extra wp_kses_post()
   call that silently stripped the `<input>` element (not in its default allow-list),
   so the checkbox never rendered while submission still required it. Replaced with
   wp_kses() using an explicit allow-list.
 * Changed: the settings page’s inline SVG icons are now escaped with wp_kses() 
   and an explicit allow-list on output, instead of a phpcs:ignore comment.

#### 1.2.1

 * Changed: renamed the plugin (display name and slug) to xprttudio Local Consent
   for 152-FZ / xprttudio-local-consent-152-fz, at the request of the WordPress.
   org Plugins Team during review.

#### 1.2.0

 * Changed: clarified in the readme, FAQ, and the settings page checklist that the
   plugin is a technical tool only — the site owner, not the plugin author, is responsible
   for the site’s actual compliance with 152-FZ.
 * Fixed (critical): banner text, the “Settings” button explanation, and the checkbox
   text — free-form admin input — were passed to sprintf() as a format string. On
   PHP 8.0+, sprintf() throws a ValueError on any string with a stray % character(
   e.g. “20% off”), crashing the banner render with a fatal error on every page.
   Replaced with str_replace(), which doesn’t parse the content as a format string
   and never fails.
 * Fixed: the banner cookie now gets the Secure attribute on HTTPS sites.
 * Fixed: the “Keep records for, days” setting did nothing — purge_old_records()
   existed but was never called. Added a daily WP-Cron job, unscheduled on deactivation.
 * Changed: the settings page redesigned as cards instead of a flat table — a dedicated
   stylesheet instead of default WordPress styling, toggles for boolean settings,
   clear selectable rows for forms, a grid-based log table with a colored badge 
   for the record type.
 * Fixed (important): consent checkbox validation for whitelisted Contact Form 7
   forms did not actually block submission — WPCF7_Validation::invalidate() silently
   does nothing when given a field name string that isn’t a real CF7 tag declared
   in the form editor. Now a properly built WPCF7_FormTag object is used, and submission
   without the checkbox is blocked server-side as intended. Updating is required
   if you use the CF7 integration.
 * Added: a 152-FZ checklist on the settings page — live status for items the plugin
   can verify (banner, checkbox, policy page), plus reminders for items outside 
   its scope (footer link, Roskomnadzor notice, hosting location).
 * Added: the cookie banner now has three buttons — Accept, Reject, and Settings(
   expands an explanation and policy link) — instead of a single “I agree” button.
 * Added: banner text supports the %s placeholder, replaced with a link to the selected
   policy page, same as the checkbox text.
 * Added: policy version (set under “Cookie banner  Policy version”). Bumping the
   version shows the banner again to visitors who already consented; the version
   is stored with every consent log record.
 * Added: export the consent log to CSV.
 * Changed: the consent log now stores the policy version in effect at the time 
   of consent.
 * Fixed: banner text, the “Settings” button explanation, and the checkbox text 
   were saved through sanitize_textarea_field(), which stripped all HTML — manually
   added `<a>` links disappeared after saving. These fields now save through wp_kses_post(),
   as intended.
 * Removed: the `[xprttudio_152fz_consent]` shortcode for arbitrary forms. It only
   rendered a checkbox with the `required` attribute but didn’t block submission
   server-side or log consent — it didn’t offer the same guarantees as the rest 
   of the plugin. Use your form builder’s own validation for forms this plugin doesn’t
   integrate with directly.

#### 1.1.0

 * Added a banner button color setting (background, hover background, text) via 
   the standard WordPress color picker.
 * Added optional auto-insertion of the checkbox into Contact Form 7 forms — strictly
   via a whitelist of form IDs; empty by default, so the checkbox doesn’t appear
   anywhere automatically.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.2.2**
 *  Last updated **3 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [152 ФЗ](https://wordpress.org/plugins/tags/152-%d1%84%d0%b7/)[152-FZ](https://wordpress.org/plugins/tags/152-fz/)
   [cookie consent](https://wordpress.org/plugins/tags/cookie-consent/)[GDPR](https://wordpress.org/plugins/tags/gdpr/)
   [Personal data](https://wordpress.org/plugins/tags/personal-data/)
 *  [Advanced View](https://wordpress.org/plugins/xprttudio-local-consent-152-fz/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/xprttudio-local-consent-152-fz/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/xprttudio-local-consent-152-fz/reviews/)

## Contributors

 *   [ xpertstudio ](https://profiles.wordpress.org/xprttudio/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/xprttudio-local-consent-152-fz/)