Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Google Customer Reviews is a free Google programme that collects post purchase ratings from customers via email survey, feeding seller ratings into Google Search and Shopping. It requires sharing customer email and order data with Google and loading Google scripts, making consent and GDPR compliance essential.
Google Customer Reviews is a free programme from Google that lets merchants collect verified post purchase ratings from their customers. After a completed order, Google sends the buyer an email invitation to rate their shopping experience. The aggregated ratings appear as seller ratings in Google Search results and Google Shopping, increasing trust and click through rates for the merchant. To activate the survey, the merchant must add a JavaScript badge and survey module to their site and transmit the customer email address, order identifier, estimated delivery date and country code to Google at checkout.
The integration transmits personal data directly to Google: the customer email address, the order identifier, the estimated delivery date and the customer country. On the browser side, loading the Google badge and survey scripts from Google domains causes Google to set cookies on the visitor device, including NID (a preferences and advertising identifier valid for 6 months), OGPC and OGP (Google services state cookies) and CONSENT (a 2 year cookie that stores the visitor's Google consent state). These cookies are set under the google.com domain and can track the visitor across other Google properties.
Two separate GDPR obligations arise. First, sharing the customer email and order data with Google constitutes a disclosure of personal data to a third party data controller, which requires a legal basis under Article 6 GDPR and must be disclosed to the data subject under Articles 13 and 14. Second, the badge and survey scripts set cookies and read device storage, triggering Article 5(3) of the ePrivacy Directive, which requires prior informed consent regardless of the cookie purpose. The merchant acts as controller for the data it sends to Google; Google acts as an independent controller for how it uses that data to send the survey and display ratings.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required on two levels. The cookie consent banner must cover the Google scripts before they load on any page where the badge appears. Additionally, before sending the customer email to Google for the post purchase survey, the merchant must have a valid legal basis: in practice this means obtaining explicit opt in consent from the customer at checkout, separate from the purchase terms. Legitimate interest is unlikely to cover sharing contact details with Google for Google's own marketing or ratings product. The consent must be freely given, specific, informed and unambiguous, and customers must be able to decline without losing access to the purchase flow.
Customer email addresses and order data are transferred to Google LLC, which is established in the United States. This is an international data transfer under Chapter V of the GDPR. Google relies on the EU US Data Privacy Framework adequacy decision and standard contractual clauses as the legal transfer mechanism. Merchants must reference these transfer mechanisms in their privacy policy and ensure that Google's Data Processing Terms are in place. Visitors whose data is transferred must be informed of this transfer and the associated safeguards.
To implement Google Customer Reviews in a GDPR compliant manner: (1) Block the badge and survey scripts in your consent management platform and only load them after the visitor has given cookie consent. (2) Add a clearly worded opt in checkbox at checkout asking the customer to agree to share their details with Google for the review survey. (3) Sign Google's Data Processing Terms and reference the EU US Data Privacy Framework in your privacy policy. (4) Update your cookie policy to list NID, OGPC, OGP and CONSENT cookies with their purposes and durations. (5) Consider whether a DPIA is required given the volume of customer emails shared. (6) Provide a contact for withdrawal of consent for the survey invitation.
Websites using Google Customer Reviews must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered given the transfer of customer email addresses and order data to Google LLC in the United States. Key risk areas include: (1) sharing personal contact data with a third party for Google's own survey processing; (2) international data transfer under Article 46 GDPR requiring reliance on the EU US Data Privacy Framework or standard contractual clauses; (3) the loading of Google scripts that may set advertising related cookies such as NID without granular user control. The controller must assess whether the survey mechanism and badge scripts go beyond the original purchase transaction purpose and whether customers are adequately informed.
Sample consent text
We would like to share your email address and order details with Google to invite you to rate your experience. Google may use this information to display seller ratings on Google Search and Shopping. You can withdraw your consent at any time. [Accept] [Decline]
Third-party domains contacted
www.google.comapis.google.comwww.gstatic.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| NID | Advertising / Preferences | 6 months | Google identifier storing user preferences and used for advertising personalisation across Google properties |
| CONSENT | Preference | 2 years | Stores the visitor Google consent state across Google domains |
| OGPC | Functional | Session | Stores Google services operational state for the current session |
Google Customer Reviews uses cookies for user preferences — inform visitors with a consent banner.
Google Customer Reviews loads scripts from Google domains that set several cookies on the visitor device. The main cookies are NID (a preferences and advertising identifier lasting 6 months), OGPC and OGP (which store Google services state), and CONSENT (a 2 year cookie recording the visitor Google consent status). These are set under google.com and can persist across browsing sessions and other Google properties.
Yes, consent is required on two levels. First, the badge and survey scripts must be blocked by your consent management platform until the visitor gives cookie consent. Second, before sending the customer email and order data to Google for the post purchase survey, you need a separate opt in consent from the customer at checkout. Legitimate interest is not a valid legal basis for sharing personal contact data with Google for its own ratings product.
The appropriate legal basis is consent under Article 6(1)(a) GDPR for both the loading of the Google scripts (which triggers ePrivacy Article 5(3)) and for the transfer of the customer email and order data to Google. Consent must be freely given, specific, informed and unambiguous. Merchants cannot rely on performance of a contract or legitimate interests for the data sharing with Google because the processing benefits Google as a third party rather than being strictly necessary for the purchase.
Yes. Customer email addresses, order identifiers, delivery estimates and country codes are transferred to Google LLC in the United States. This is an international data transfer under GDPR Chapter V. Google relies on the EU US Data Privacy Framework adequacy decision and standard contractual clauses as the legal transfer mechanism. You must reference these safeguards in your privacy policy and ensure Google Data Processing Terms are executed.
A DPIA is likely warranted if you share large volumes of customer email addresses with Google, given the international transfer involved and Google's role as an independent controller. Key factors triggering a DPIA include: systematic sharing of personal contact data with a third party, international transfer to the US, and the use of advertising cookies. You should consult with your Data Protection Officer and assess whether the processing is listed in your supervisory authority's DPIA trigger list.
To implement compliantly: (1) Integrate the badge and survey scripts through your consent management platform so they only load after cookie consent is given. (2) Add a clearly labelled opt in checkbox at checkout asking the customer to agree to share their details with Google for the review programme. (3) Accept Google Data Processing Terms and reference the EU US Data Privacy Framework in your privacy policy. (4) List all Google cookies in your cookie policy with durations and purposes. (5) Conduct or review a DPIA if warranted. (6) Ensure customers can easily withdraw consent for the survey invitation.
If you want to avoid sharing customer emails with Google and loading Google third party scripts, consider: (1) Self hosted review platforms such as Trustpilot Business (with a direct data processing agreement), Feefo or Reviews.io which keep data under your control. (2) Post purchase email surveys operated directly by your own email platform without involving third party data controllers. (3) On site review widgets that store data in your own database without transmitting personal data to external parties. Each alternative should be evaluated against your own GDPR obligations.
Your cookie policy must list each cookie set by the Google Customer Reviews integration. Add entries for: NID (google.com, 6 months, preferences and advertising identifier), OGPC and OGP (google.com, session or short term, Google services state), and CONSENT (google.com, 2 years, Google consent state). For each cookie include the name, provider, purpose, duration and category. Categorise NID and CONSENT under advertising or analytics. Ensure the cookie policy is linked from your consent banner and is updated whenever you add or remove third party integrations.