What are the GDPR Considerations for Testimonials?

10 minuti di lettura

Obtaining valid consent from the individual whose data you wish to use is, by far, the most critical step in the entire process when it comes to GDPR compliance for testimonials.

The reason is that testimonials are data about a person, which frequently includes a person’s name, a photo, and their statements. Therefore, they are considered personal data, and using them requires a lawful basis under the GDPR, with consent being the most common.

To be on the safe side, you can implement a double opt-in method for consent. Once a user submits their testimonial, send them a confirmation email requesting them to click a link to verify their consent. It furnishes an audit trail and proof of their authorization.

Punti chiave:
  • Valid consent is the most important
  • Always get explicit, specific consent before using a testimonial.

  • Include a straightforward opt-out process; individuals should retain the ability to reverse their consent whenever desired
  • Regarding sharing reviews from third parties, it is important to secure consent before using them
Logo piccolo di Hocoos Risposte Testimonianze dei clienti

What specific personal data is typically involved in testimonials?

A testimonial may include personal data, such as the name of the person, a picture (e.g., a photo or video), and a description of the person’s job or company. Even the testimonial itself, which can be the speaker’s opinion or experience, is considered personal data and is covered by the GDPR.

Approfondimento:
Focus on data minimization. Only collect the personal data necessary for the testimonial (e.g., first name and city, rather than full name and address) to reduce your compliance burden.

How do you obtain valid consent from a person to use their testimonial?

Obtaining valid consent is the cornerstone of GDPR compliance for testimonials.

·   The existence of a genuine alternative is necessary, and consent should remain separate from the provision of a service.

·   The precise data collected should be disclosed along with the intended purpose.

·   The individual should have a transparent understanding of their testimonial usage.

·   The method by which consent is obtained should be characterized by a definite, positive action, as, for example, the signing of the document.

Approfondimento:
Use a dedicated testimonial consent form. A centralized location is available for recording necessary information and consent evidence, and may influence management and auditing.

What should be included in a consent form for testimonials?

Without a doubt, the consent form must be a straightforward document that explains how the testimonial will be used. It should include:

·   Data collected about the individual (e.g., name, photo, company).

·   The reason for its use (e.g., on the website, in the promotional materials).

·   The duration for which the material will be used.

·   The process of setting out how an individual may revoke the consent given at any time.

How can individuals withdraw their consent, and what is your obligation once they do?

Individuals have the right to revoke their consent at any time. You should facilitate the withdrawal process as simply as giving consent, maybe through a straightforward email link or a form on your website. The use and display of feedback on published platforms is subject to change based on consent status. It is the “right to be forgotten” under the GDPR.

Consiglio da professionista:
Establish a clear procedure for withdrawals. Include a “withdraw consent” link in your website’s footer or privacy policy, and set up an automated system to alert the right team members when a request is made.

How do you handle testimonials from third-party review sites?

Testimonials from sources such as Google Reviews or Trustpilot require a separate approach. While linking to a review may be allowed, you must not copy and paste the testimonial on your site without new consent. The application of data to a distinct purpose requires acquiring further authorization, regardless of its public accessibility on another site. Search the terms of service of the third-party platform and get unique consent from the individual to use their testimonial on your platforms.

Consiglio da professionista:
Consider a streamlined consent workflow. After a user leaves a review on a third-party site, send them a personalized email thanking them and asking for their explicit permission to use their testimonial on your own platforms.

What are the consequences of non-compliance?

GDPR compliance is associated with specific business outcomes. Observing the regulation reduces potential fines of up to €20 million or 4% of annual global turnover, and there may be a relationship with reputation and customer trust. Compliance reflects certain operational aspects like responsibility, transparency, and data handling, which could relate to credibility and market position.

Pros and Cons of using testimonials under GDPR

+
May foster trust and credibility with customers.Requires a formal consent process.
Social proof is utilized as a marketing tool.The process can involve administrative steps.
It has the potential to affect conversion rates and sales figures.Fines are a financial consideration related to instances of non-compliance.
Delivers customer feedback to new customers.A defined process for withdrawal is required.

Conclusione

Utilizing testimonials as a business tool may align with GDPR requirements, but valid consent should be the primary goal of your work, along with complete transparency and clear procedures for consent withdrawal. This process intends to mitigate legal vulnerabilities and has the potential to influence customer trust perceptions. Furthermore, marketing efforts may see changes in effectiveness and perceived ethical standards.

Indice

PRONTO A DARE IL VIA AL TUO PERCORSO CON LA TUA PICCOLA IMPRESA?

Considerazione importante: Le informazioni fornite dal nostro team di esperti sono pensate per offrirti una comprensione generale del processo di creazione di un sito web e delle funzionalità a tua disposizione. È importante notare che queste informazioni non sostituiscono la consulenza professionale personalizzata in base alle tue esigenze e ai tuoi obiettivi specifici.
Leggi la nostra standard editoriali per i contenuti di Answers.
Il nostro obiettivo è quello di consentirti di creare un sito web straordinario. Se hai domande o necessiti di una guida durante il processo di creazione, non esitare a Contattaci. Saremo lieti di fornirti assistenza e indicarti la giusta direzione.