Cookie Consent Banner — PDPL, GDPR & Arabic RTL (Arqam360)

Cookie Consent Banner — PDPL, GDPR & Arabic RTL (Arqam360)

0/5 (0 ratings) — active installs Updated Sep 25, 2026

Free PDPL + GDPR cookie consent banner for Saudi, UAE, and GCC WordPress sites. Native Arabic RTL. Live in 60 seconds. No code, no developer, no credit card.

The free tier covers what most stores need: a compliant banner with PDPL, GDPR, and UAE PDPA detection, native Arabic, Google Consent Mode v2, GPC support, a bilingual cookie declaration page, 1 domain, and 10,000 pageviews per month — forever. Upgrade when you’re ready for the Cookie Scanner, DSAR portal, server-side event forwarding, audience activation, custom banner branding, or multi-domain support.

Key Features:

  • Google Consent Mode v2 — fires consent signals before any tag loads
  • 18 regulations covered — Saudi PDPL, UAE PDPA, GDPR, CCPA, plus Qatar, Bahrain, Oman, Egypt, Morocco, Tunisia, Algeria, Jordan, Lebanon, Brazil LGPD, Canada PIPEDA, UK GDPR, and more
  • 113-cookie classifier — including MENA-specific services (Tabby, Tamara, Mada, STC Pay, Salla, Zid) that global CMPs miss
  • Bilingual cookie declarations — every cookie ships with English + Arabic descriptions, on every plan
  • Native Arabic RTL — built for MENA merchants from day one
  • AI Cookie Scanner — discover every cookie and tracker (Pro plan)
  • Server-side event forwarding — Meta CAPI, GA4, sGTM, TikTok, Snap, LinkedIn, HubSpot, Mixpanel, BigQuery, Google Enhanced Conversions
  • Audience activation — segment your consented first-party data and sync to ad platforms (Pro/Agency plan)
  • 30+ Customization Options — colors, position, text, categories
  • Auto Regime Detection — detect visitor regulatory regime by IP location
  • Script + request quarantine — block trackers BEFORE they fire, not just after
  • GPC Support — respect Global Privacy Control browser signals

Works with WooCommerce and any WordPress site.

Tag manager placement

The plugin loads its script in the document <head>, before any other script
WordPress prints, so the Google Consent Mode v2 “denied” default is set before
your tags read it.

There is one case it cannot control. If your Google Tag Manager or GA4 snippet
is pasted directly into your theme’s header.php above the wp_head()
call, that snippet runs before anything WordPress outputs, including this
plugin — and it will read no consent state.

Two ways to be sure:

  • Move the GTM snippet below wp_head() in your theme, or
  • Install GTM through this plugin’s container guidance instead of hardcoding it.

If you manage tags entirely inside a GTM container loaded via a plugin or
wp_head, no action is needed.

Content Security Policy

Most sites have no CSP and need nothing here. If yours sends one — directly, or
through a security plugin — the widget needs three allowances, and it fails
silently without them: the browser blocks the script and no banner appears,
which looks like the plugin is broken rather than like a policy is doing its job.

  • script-src https://cdn.arqam360.com — the banner script itself.
  • connect-src https://api.arqam360.com — fetching your widget configuration
    and recording consent decisions.
  • style-src 'unsafe-inline' — the banner builds its stylesheet at runtime so
    it can carry your colours and position. If your policy cannot allow inline
    styles, tell us and we will work through the alternatives with you rather
    than have you weaken the policy site-wide.

The widget contacts no other host. It loads no external fonts and no
third-party resources.

If you embed the Arqam360 dashboard inside wp-admin, that page additionally
needs frame-src https://app.arqam360.com. That applies only to the wp-admin
screen, never to your public pages.

Credentials

The plugin uses two credentials from your Arqam360 dashboard, in the same way
Stripe uses a publishable key and a secret key:

  • Widget Key (ciq_live_...) — public. It appears in your page source and
    loads the consent banner. This is by design; it authorizes the banner and
    nothing else.
  • Site Token (ciq_sk_live_...) — secret. It opens your Arqam360 dashboard
    inside wp-admin and is never written to your pages. It is shown once, when
    you create it.

The two are not interchangeable and the settings page will refuse a credential
pasted into the wrong field.

External Services

This plugin connects to the Arqam360 service to function:

  1. Arqam360 CDN (cdn.arqam360.com) — The consent banner JavaScript is loaded from Arqam360’s CDN. This script renders the cookie consent banner on your site and handles consent collection. No personal visitor data is sent to the CDN; it only serves the static JavaScript file.

  2. Arqam360 API (api.arqam360.com) — When a Widget Key is configured, the plugin fetches your widget configuration (colors, text, position, compliance settings) from the Arqam360 API. Consent records are also sent to this API for storage and analytics. Your Widget Key authenticates these requests. If a Site Token is also configured, it is used only to open the dashboard inside wp-admin, and is sent from your server to api.arqam360.com over HTTPS — never to a visitor’s browser.

A free Arqam360 account is required (free forever for the consent banner, no credit card). Sign up at arqam360.com.

For agencies and developers

If you build WordPress or WooCommerce sites for clients, Arqam360 runs a partner
programme. Your client subscribes to Arqam360 directly and you earn 20% of what
they actually pay, for 12 months from their first paid invoice.

You install nothing extra and support nothing — we handle the consent side. A
client who stays on the free plan earns you nothing, so this is worth it where
you are already recommending a paid tool.

Terms, including how referrals are attributed and how payouts work:
https://arqam360.com/partners