Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Trusted Shops is a European trustmark, customer reviews and buyer protection provider that lets online shops embed the Trustbadge to display the trustmark and review stars and invite customers to leave reviews.
Trusted Shops is a European trustmark, customer reviews and buyer protection provider based in Cologne, Germany. Online shops embed a small element called the Trustbadge, which displays the Trusted Shops trustmark and review stars and invites customers to leave reviews. Because the Trustbadge loads from Trusted Shops servers, sets cookies and processes order and customer data, shops that use it need to understand its privacy implications.
Trusted Shops combines three services for online retailers. It provides a trustmark that signals the shop has been reviewed, it collects and publishes verified customer reviews, and it offers buyer protection that can reimburse customers in certain cases. The Trustbadge is the visible widget that ties these services together on a shop page, showing the rating and giving visitors a way to read and submit reviews.
The Trustbadge loads JavaScript from Trusted Shops servers and can set cookies to remember the badge state and to support review and buyer protection features. To send review invitations, the shop transmits order data such as the customer email address and order details to Trusted Shops, which then contacts the customer to request a review. The published reviews and the buyer protection records also involve processing of customer information.
Embedding the Trustbadge and sending order data to Trusted Shops are acts of personal data processing under the GDPR, while the cookies the Trustbadge sets fall under the ePrivacy Directive and national rules on storing information on a device. In many integrations the shop and Trusted Shops act as joint controllers for the review and trustmark functions, which means the relationship and the respective duties should be documented. Each purpose, from displaying the badge to sending invitations, needs a clear lawful basis.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Non essential cookies set by the Trustbadge and the sending of review invitations by email generally rely on the visitor and customer consent under Article 6(1)(a) of the GDPR, obtained before the cookies are set or the invitation is sent. Buyer protection and fraud prevention may instead rely on legitimate interest under Article 6(1)(f), subject to a balancing test. A consent banner should therefore load the Trustbadge only after the user has agreed, and the review invitation opt in should be clear and separate.
Trusted Shops is established in Germany and processes data within the European Union, which keeps the core processing inside the EU and avoids the main complications of third country transfers. Where any sub processor or recipient sits outside the EU, Trusted Shops relies on safeguards such as Standard Contractual Clauses. You should still confirm the current details in the Trusted Shops data processing documentation for your contract.
List the Trustbadge cookies and the Trusted Shops domains in your cookie policy, and gate the Trustbadge behind your consent manager so it loads only after consent. Collect a clear opt in for review invitations and keep a record of it, sign the joint controller and data processing terms offered by Trusted Shops, and update your privacy policy to describe the reviews, trustmark and buyer protection processing. Review these arrangements periodically as the integration evolves.
Websites using Trusted Shops must obtain user consent under GDPR regulations.
DPIA considerations
Trusted Shops processes order and customer data such as email addresses and order details to send review invitations and provide buyer protection, so a data protection impact assessment is usually not mandatory for a typical shop integration. However, you should document the joint controllership arrangement, the lawful basis for each purpose and the cookies the Trustbadge sets. Review the scope of data shared and the retention of review records as part of your records of processing activities.
Sample consent text
We use the Trusted Shops Trustbadge to display our trustmark and reviews and, with your consent, to send you an invitation to review your order.
Third-party domains contacted
trustedshops.comwidgets.trustedshops.comapi.trustedshops.comcdn1.trustedshops.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| tsCheckedProducts | Functional | Session | Stores products the visitor has interacted with in the Trustbadge so the badge and review prompts behave consistently during the visit. |
| ts_session | Functional | Session | Maintains the Trustbadge session state so the widget loads correctly and ties review and buyer protection interactions to the current visit. |
| tsAlreadyRated | Functional | 1 year | Records that a customer has already submitted a review so the Trustbadge does not repeatedly prompt the same person. |
| tsBuyerProtectionV2 | Functional | 1 year | Supports the buyer protection feature by remembering the protection state associated with the visitor and order. |
Trusted Shops uses cookies for user preferences — inform visitors with a consent banner.
The Trustbadge sets cookies to remember the badge and review state and to support the buyer protection and review features. These are typically functional cookies for the widget plus identifiers used when a customer interacts with reviews or buyer protection. List the exact cookies and their durations from the Trusted Shops documentation in your cookie policy, as the set can change between versions.
Yes, in most cases. Non essential Trustbadge cookies and the email review invitation rely on user consent under Article 6(1)(a) of the GDPR, so you should load the Trustbadge only after the visitor agrees and collect a clear opt in for invitations. Strictly necessary elements and buyer protection may rest on other bases, but the safe default is to gate the widget behind your consent manager.
Non essential cookies and review invitations generally rely on consent under Article 6(1)(a) of the GDPR. Buyer protection and fraud prevention may rely on legitimate interest under Article 6(1)(f), subject to a balancing test. For the review and trustmark functions the shop and Trusted Shops often act as joint controllers, so document the basis for each purpose.
Trusted Shops is based in Germany and processes data within the European Union, so the core processing stays in the EU and there is normally no routine transfer to the United States. Where a sub processor or recipient sits outside the EU, Trusted Shops relies on safeguards such as Standard Contractual Clauses. Confirm the current transfer details in your data processing agreement.
A full data protection impact assessment is usually not mandatory for a standard Trusted Shops integration, because the processing of order data and reviews is limited in scope and not high risk. You should still document the joint controllership, the lawful basis for each purpose and the cookies in your records of processing. Carry out a DPIA if you combine it with large scale profiling or other high risk processing.
Load the Trustbadge only after consent through your consent manager, and list its cookies and the Trusted Shops domains in your cookie policy. Collect a clear and separate opt in for review invitations and keep a record of it, sign the joint controller and data processing terms offered by Trusted Shops, and describe the reviews, trustmark and buyer protection in your privacy policy.
Other customer review and trustmark providers include eKomi, Trustpilot and Bazaarvoice. Each has its own data processing model, server locations and consent behaviour, so compare where they host data, whether they offer buyer protection and how their widgets handle cookies. Choose the one that fits your market and your privacy requirements.
Add an entry for the Trustbadge that names the cookies it sets, their purpose and duration, and the Trusted Shops domains the widget loads from. Explain that the badge is loaded only after consent and that review invitations require a separate opt in. Keep the entry in step with the version of the Trustbadge you deploy.