GDPR Suite for WHMCS Print

  • 0

GDPR Suite provides WHMCS tools for data exports, deletion requests, consent records, DPA acceptance and retention workflows. These tools support your privacy procedures; installing the module does not establish GDPR compliance.

Installation

  1. Back up your WHMCS files and database. Use a module package compatible with your WHMCS and PHP versions.
  2. Upload gdpr_suite to /modules/addons/.
  3. Open System Settings > Addon Modules, activate GDPR Suite and enter your license key.
  4. Set administrator access and open Addons > GDPR Suite.
  5. Review Module Configuration and test the customer pages before enabling automated data changes.

The repository documents WHMCS 8.x and 9.x and the Six, Twenty-One and Lagom client templates. Check your installed theme and release package rather than treating that list as a test of every customisation.

Data exports

Clients can open Billing > Data Privacy and select data to export as CSV or JSON. Administrators can use the Data Export tab for a selected client.

Available categories include profile, invoices, services, domains, tickets, emails, activity, consent, contacts and transactions. Store exports securely: they can contain personal and financial information. Review the output when responding to a data-access request; data held by other integrations or processors may need separate handling.

Deletion requests and anonymisation

The client page lets customers submit a deletion request and view its status. Administrators review requests in the Requests tab and can approve or reject them with notes. Settings control administrator approval, confirmation email and creation of a WHMCS To-Do item.

Approval can trigger irreversible changes. Review legal holds, required accounting records and all related services before processing a request. Keep administrator approval enabled unless you have tested and approved another process.

The implemented routine replaces selected client and contact identifiers, closes the client account, changes ticket sender details, redacts client reply messages and clears client-associated activity-log IP addresses. It retains invoice records and an anonymisation mapping.

Do not describe this as deletion of all personal data. Original ticket bodies, attachments, staff replies, other integrations and backup copies need separate review. Closing a client account is also not proof that every associated WHMCS user identity or session has been disabled.

Consent records and audit history

Auto-Log Consent records registration and accepted-order events with the available request information. The module can also create an initial record for an existing account when the client next uses the client area. These records are not a substitute for collecting valid consent where it is required.

Use Consent History to review records and Audit Log to filter recorded actions. Audit Log Retention controls cleanup by the daily WHMCS cron; an explicit value of 0 keeps those records indefinitely. When cleanup is enabled, the code also removes consent records older than twice the configured audit-retention period. Choose retention periods deliberately.

Cookie notice

The cookie-banner controls provide styling and a policy-page link. The current notice is acknowledgement-only: OK stores an acknowledgement cookie; Close hides the notice for the current page view without storing that acknowledgement.

This is not a consent manager that blocks or releases optional scripts. It does not provide category-based analytics or advertising consent. Review the supplied wording and cookie policy against your own site, and use a separate consent mechanism if your scripts require one.

Client DPA setup

  1. Enable Client DPA in module settings.
  2. Set a version identifier for your agreement.
  3. Open the Client DPA tab and add the public PDF URL for each language you offer.
  4. Test the customer view, checkbox and acceptance action.
  5. Review acceptance statistics or export acceptance records from the admin tab.

The client sees the document matching their language, with English as fallback. If no PDF is configured, the module can show built-in content. Review that content before use; it is not automatically an agreement suitable for your business.

Clients who have not accepted the current version see a dashboard warning. Changing the version makes acceptance due again for that version. This tracking and warning should not be described as a blanket block on using services.

Processor register and breach records

DPA Management records third-party processors, agreement dates, DPA status and transfer information, and can export the register to CSV. Recording a processor does not verify its contract or international-transfer arrangements.

Breach Notification provides a place to document affected data and remediation. Use your own incident procedure to decide whether, when and how to notify authorities or affected people.

Automatic retention workflow

Automatic anonymisation is optional. Its settings include the inactivity period, warning period and exclusion of accounts with positive credit. The Data Retention tab shows the queue, lets administrators cancel scheduled entries and maintains manual exclusions with reasons.

The daily process looks for Closed or Inactive clients, checks client and linked-user login history, excludes active, pending or suspended hosting services, and checks recent activity. It sends a warning before processing a due entry. A later login or a newly detected relevant hosting service can cancel the scheduled action.

These checks do not establish that every domain, invoice, dispute or external service is safe to remove. Do not enable automatic anonymisation until you have tested the workflow and defined exclusions for your own records and legal holds.

Invoice Retention and Backup Retention settings describe retention information used by the module. They are not evidence of a scheduled invoice purge or deletion from your backup system. Manage those systems separately.

Maintenance and support

Module tables are preserved on deactivation. Keep your WHMCS daily cron running for cleanup and retention tasks, and inspect failures in the Activity Log. Before updating, back up files and database and test the customer export, request and DPA pages.

For support, provide the module, WHMCS and PHP versions, theme, the affected workflow and a redacted error. Do not attach a customer's full export or personal documents unless specifically needed through an appropriate support channel.


Was this answer helpful?

« Back

WHOIS Information

×
Loading WHOIS information...