The DPDP Audit Tool
Compliance for Using Customer Testimonials Under DPDP
🗣️

Using Customer Testimonials Under DPDP
Liability Check

📜

Using customer testimonials without explicit, purpose-specific consent is a direct violation of the DPDP Act, 2023. Every name, photo, and company mention in your testimonials is personal data, and processing it without a valid legal basis could cost you dearly.

Why Using Customer Testimonials Under DPDP is at Risk

Your glowing customer testimonials from Bangalore's tech park startups or legacy Mumbai businesses are marketing gold. But under DPDP, each testimonial, especially if it includes a person's name, photo, designation, or even company name, constitutes **personal data**. You can no longer assume implied consent from an old email or a casual LinkedIn post. DPDP mandates **explicit, informed, and purpose-specific consent** for *each* medium (website, social media, sales decks) and *each* duration. The Data Principal must know exactly how their data will be used and have an easy way to withdraw consent.

Common Violations

  • 1.Publishing customer testimonials on your website or social media without a specific, signed consent form from the individual.
  • 2.Using testimonials collected years ago under a general 'terms of service' without re-obtaining DPDP-compliant consent for specific uses.
  • 3.Failing to provide an easily accessible mechanism for a customer to request the removal or anonymization of their testimonial data.

The Immediate Fix

Immediately audit all existing testimonials to ensure you have specific, verifiable consent for their current use. For future testimonials, implement a clear, digital consent flow that outlines the exact platforms and duration of use, and provides an easy opt-out mechanism.

Get DPDP Updates for Using Customer Testimonials Under DPDP

We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.

Unbundled consent — the DPDP gold standard. Unsubscribe anytime. Privacy Policy

or
Start 30-Second Audit

Projected Compliance Deadline: Immediate

Next step after the audit

The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme