Get started

Guide • 2025-12-06

GDPR and customer reviews: best practices for local businesses

Google reviews and GDPR: what personal data reviews contain, what never to write in a reply, and how to handle access, retention and customer requests.

GDPR and customer reviews: best practices

A customer review looks harmless: a few lines and a rating. Yet it contains personal data, and the way you reply to it, store it or share it internally falls under the GDPR, the European data protection regulation.

This guide sums up the simple habits to adopt. It is not legal advice: for a specific situation, talk to a professional or check your data protection authority’s resources.

Why GDPR applies to reviews

Personal data is any information that identifies a person, directly or indirectly. A review often contains:

  • The author’s name or nickname, and sometimes their profile picture.
  • The date of their visit or purchase.
  • Details about their order, appointment or situation.
  • Sometimes sensitive information, for example about their health in the case of a medical practice.

As long as the review stays on the platform where it was posted, the platform is responsible for it. As soon as you copy it, store it, analyze it or cross-reference it with your own customer files, you are also processing personal data.

The golden rule: nothing private in a public reply

This is the most concrete and most frequent risk. A reply to a review is public and stays online. Never mention:

  • The customer’s full name if they did not display it themselves.
  • Details of their order, file or invoice.
  • Health information, even to dispute a review about care.
  • Their address, phone number, email or any other contact detail.
  • Information from your customer database, for example “you came three times this month”.

Even to set the record straight on an unfair review, stay general in public and offer to continue privately. Our guide on how to respond to Google reviews gives examples of safe wording.

The principles to apply

The GDPR rests on a few principles (Article 5). Applied to reviews, they look like this.

Data minimization

Keep only what is useful. To track and reply to reviews, you need the text, the rating, the date and the location concerned. Avoid building files that link review authors to your customer data without a clear reason.

Purpose limitation

Use reviews for what they are for: replying, improving your service, monitoring your reputation. Do not use them for anything else, such as marketing to their authors.

Storage limitation

Decide how long you keep reviews and replies in your own tools, and delete what is no longer useful. A duration aligned with your tracking needs (for example a few years of history) is easier to justify than unlimited retention.

Security and access

Limit access to the people who need it, with individual accounts rather than a shared login. Remove access when someone leaves the team.

Organizing access internally

  • One account per person, never a shared password.
  • Clear roles: who reads, who replies, who administers.
  • A history of published replies: who replied, when, with what text.
  • Access removed on an employee’s last day, including on your Google profile.

These rules protect data and also prevent someone who has left from still replying on the business’s behalf.

Customer requests

The GDPR gives people rights: access to their data (Article 15), erasure (Article 17), objection (Article 21), among others. For reviews, two cases come up often.

A customer asks you to delete their review

The review is published on the platform, not with you: you cannot delete it yourself. Tell them they can edit or delete it from their account, or contact the platform. Do delete any copies you keep in your own tools if the request covers them.

A customer asks what data you hold about them

Reply within the deadline set by the GDPR (one month in principle), including, where relevant, the reviews and replies you keep in your tools.

Review management tools

If you use software to track your reviews, it processes this data on your behalf. Check:

  • What data it stores and for how long.
  • Security measures: encrypted communications, access control, logging.
  • How it connects to Google: an official authorization you can revoke is preferable.
  • Contract terms and the list of subprocessors, available on request.
  • Whether you can export or delete your data when you leave.

See also our checklist for choosing review management software.

CloutAlert connects to Google Business Profile through an authorization you can revoke at any time from Google, applies data minimization, encrypts communications (HTTPS/TLS) and strictly controls access. Hosting and subprocessor details are available on request. See the security page and the privacy policy.

Checklist

  • No private data in your public replies
  • Individual accounts and defined roles
  • Access removed when someone leaves
  • Reply history kept
  • Defined retention period for your copies of reviews
  • A simple process to handle customer requests
  • Review management tool checked (data, security, subprocessors)

A question about how your data is handled in CloutAlert? Contact us.

Back to the guides list.