Back to blog
Testimonial Consent and GDPR: A Founder's Guide
June 17, 20267 min readEdvin Åslund

Testimonial Consent and GDPR: A Founder's Guide

GDPR and testimonial consent trip up more founders than you'd think. Here's exactly what you need to cover legally — without killing your social proof strategy.

E

Edvin Åslund

Founder of Aboast

You've got a happy customer. They just told you the product changed how their team works. You want to put that on your landing page. So you screenshot the Slack message, paste it on your site, and move on. Sound familiar? That's a GDPR violation waiting to happen.

Testimonial consent and GDPR is one of those topics that founders either ignore completely or massively overcomplicate. Neither is good. The rules aren't that hard once you understand what they're actually protecting — and getting this right means you can collect and display social proof confidently, without a legal grenade under your marketing.

Why Testimonials Are Personal Data Under GDPR

A testimonial almost always contains personal data. A name, a job title, a company, a photo, a video — any of these can identify a natural person, which puts them squarely under GDPR if you're operating in or selling to the EU.

That means the moment you publish "— Sarah M., Head of Growth, Berlin" on your homepage, you're processing personal data. You need a lawful basis to do it. For testimonials, that basis is almost always explicit, informed consent — not a vague "they seemed fine with it" assumption.

Legitimate interest — the other common lawful basis — is a stretch here. Regulators and courts have consistently held that using someone's identity for your commercial marketing doesn't easily qualify. Stick with consent.

What Valid Testimonial Consent Actually Looks Like

GDPR consent has to be freely given, specific, informed, and unambiguous. For testimonials, that translates into a few concrete requirements:

  • The person must know exactly what they're consenting to — that their name, role, and words will appear publicly on your website and/or marketing materials.
  • Consent must be an active opt-in — a checkbox they tick, a form they submit, a written reply. Silence or inaction doesn't count.
  • You must tell them they can withdraw consent at any time — and actually have a process to remove their testimonial if they do.
  • You need to keep a record of the consent — who gave it, when, and what they agreed to. If a regulator asks, "they sent me a nice email" won't hold up.
  • Consent can't be bundled with your terms of service — it has to be a separate, standalone agreement specifically about the testimonial.

The screenshot-from-Slack approach fails on almost every one of these. The customer wasn't told their words would be published. There was no active opt-in. There's no withdrawal mechanism. This is why so many SaaS homepages are technically non-compliant right now.

Testimonial Consent GDPR: Building a Clean Collection Workflow

The good news: if you build consent into your collection process from the start, compliance costs you almost nothing extra. It's retrofitting that's painful.

Here's how a clean workflow looks in practice. With a tool like aboast, you send customers a branded collection form right after a key moment — trial-to-paid conversion, a support ticket resolved, a milestone hit inside the product. The form itself contains a clear consent statement: something like "By submitting this testimonial, you agree that [Company] may publish your name, role, and feedback on our website and marketing materials. You can withdraw this consent at any time by emailing us."

When the customer submits, the timestamp and consent text are logged automatically. You don't have to chase down email threads to prove consent happened. It's all in the dashboard, attached to that specific testimonial.

From what we've seen at aboast, adding a clear consent statement to the collection form doesn't meaningfully reduce submission rates — customers who are happy to give a testimonial are happy to consent to it being used. Our forms still see response rates between 45–65% when sent within 48 hours of a positive moment.

Video Testimonials Need Extra Attention

Video is biometric data territory. A person's face and voice are special category data in some EU member states, and even where they're not, video testimonials carry higher risk than text because the data is richer and harder to anonymise.

For video, your consent language needs to be even more explicit. Spell out:

  1. That their likeness and voice will be recorded and stored
  2. Where the video will be hosted (your site, YouTube, embedded widgets)
  3. How long you intend to keep and use it
  4. The process for requesting deletion

If a customer withdraws consent for a video testimonial, you need to delete it from every place it lives — your dashboard, your CDN, your embedded player, any social posts where you shared it. That's why keeping a clear record of where each testimonial is published matters from day one.

What to Do With Testimonials You Already Have

If you've already got testimonials on your site that were collected without proper consent, you have two options. Neither is fun, but one is worse than the other.

Option one: go back and get retroactive consent. Reach out to each customer, explain you'd like to keep their testimonial live, and send them a proper consent form. Most happy customers will say yes — and it's a good excuse to re-engage them and ask for an updated quote while you're at it.

Option two: take them down until you have consent. Painful if you've built your homepage around them, but the risk of a complaint to a data protection authority is real — especially if a customer relationship goes sour and they decide to make a point of it.

There's a third path some founders take: anonymise the testimonial. Remove the name, photo, and any identifying details. "A SaaS founder in Berlin" instead of "Sarah M., Head of Growth." It's not ideal for conversion — named testimonials with photos outperform anonymous ones significantly — but it's compliant without needing consent.

See also: how to ask customers for testimonials without being awkward — getting the timing right is what makes retroactive outreach actually work.

Common Mistakes Founders Make (and How to Avoid Them)

After talking to a lot of early-stage founders about this, the same mistakes come up repeatedly:

  • Screenshotting public tweets or LinkedIn posts. Public doesn't mean consented-to-commercial-use. You still need permission.
  • Burying consent in the terms of service. GDPR requires it to be separate and specific. "You agreed to our ToS" won't fly.
  • Not having a withdrawal process. If a customer asks you to remove their testimonial, you need to act promptly — within 30 days is the GDPR standard for data requests.
  • Storing testimonials without a data retention policy. You can't keep personal data indefinitely. Decide how long testimonials stay active and communicate that.
  • Assuming B2B is exempt. GDPR protects natural persons, not companies. "Sarah at Acme Corp" is still a natural person. B2B doesn't get you off the hook.
The goal isn't to make testimonial collection harder. It's to make consent so frictionless and automatic that compliance is just part of how you collect — not a separate legal exercise you do once a year.

For more on structuring your social proof strategy, read how to turn a Wall of Love into a conversion asset — the design choices matter as much as the legal ones.

A Note on Cross-Border Complexity

If you're a US-based SaaS with EU customers, GDPR still applies to you. Full stop. The regulation applies based on where your data subjects are located, not where you're incorporated.

UK founders also need to remember that post-Brexit, the UK GDPR runs in parallel — it's nearly identical in practice, but it's a separate legal framework. Complying with EU GDPR will cover you for UK GDPR in almost all testimonial scenarios, but worth knowing they're technically distinct.

California's CCPA adds another layer for US customers — it gives consumers the right to opt out of having their data used for commercial purposes. The consent-first approach that works for GDPR also satisfies the spirit of CCPA, so building consent into your collection flow once covers you across most jurisdictions.

Also worth reading: why video testimonials convert better than text for SaaS — especially relevant if you're deciding whether the added compliance overhead is worth it (it usually is).

The Right Mindset: Consent as Trust, Not Friction

Here's the reframe that makes all of this easier: asking for consent isn't a legal hurdle — it's a signal of respect. Customers who feel respected are more likely to give you a strong testimonial, more likely to update it when their results improve, and more likely to stay customers.

The founders who treat testimonial consent as a checkbox exercise miss this. The ones who build a clean, transparent process find that customers appreciate being asked properly. It reflects well on your brand.

Practically speaking, aboast is built around this model — consent language is embedded in every collection form, submissions are timestamped and logged, and if a customer asks to be removed, you can action that in seconds from the dashboard. Testimonial consent and GDPR compliance shouldn't be an afterthought you bolt on — and with the right collection tool, it doesn't have to be. You get the social proof, you stay compliant, and your customers stay happy. That's the whole game.

Try aboast

Collect testimonials in five minutes.

Free forever plan, no credit card required. Get a branded collection link and start shipping social proof today.

Start free