GDPR and Social Proof Notifications: What You Can and Cannot Show
July 18, 2025 | 11,298 views | 13 min. read time
Can you legally show “Sarah from Amsterdam just bought this” on your website? If you sell to anyone in Europe, that question is a GDPR question, and the answer is more nuanced than a simple yes or no. This guide explains what counts as personal data in a social proof notification, when you need consent, and how to configure your widgets so they stay on the right side of the rules.
1. Why GDPR applies to a purchase popup
The General Data Protection Regulation governs the processing of personal data of people in the EU and EEA. “Processing” includes displaying data, and “personal data” is any information relating to an identifiable person. A recent-purchase notification can easily contain both: a first name, a town, a product, and a time. On its own, “Sarah” is not very identifying. Combined with a small town, a specific product, and a precise timestamp, it can become enough to single someone out — and that is exactly what GDPR is designed to control.
This does not mean social proof is forbidden in Europe. It means you have to think about whose data you are showing, how much of it, and on what legal basis. Most stores can run compliant notifications with a few sensible configuration choices. The mistake is assuming a widget is invisible to the law because it is “just a bit of UI.” If it displays information about a real customer, it is processing personal data, and the usual GDPR principles apply.
2. What counts as personal data in a notification
Think of the fields in a typical recent-purchase card. A full name is clearly personal data. A first name plus a city is often enough to be personal data in combination, especially in a small location. A precise timestamp narrows things further. A product name is not personal data by itself, but tied to an identifiable buyer it becomes part of a personal profile. Even an IP-derived location can be considered personal data.
The practical takeaway is that the more precise and complete your notification is, the more likely it is to identify a real person — and the more careful you need to be. The safest notifications are deliberately vague about the individual and specific about the action. “Someone in the Netherlands just bought the Trail Runner 2” carries almost no identification risk. “Sarah Jansen from Edam bought the Trail Runner 2 at 14:32” carries a great deal. You get almost all of the persuasive benefit from the first version, and almost all of the legal risk from the second.
3. Consent, legitimate interest, and minimisation
GDPR requires a lawful basis for processing. For social proof, the two most relevant bases are consent and legitimate interest. Relying on consent means you would need the displayed customer to have agreed to have their purchase shown to other visitors — which is rarely practical at the moment of checkout. Relying on legitimate interest means you have judged that showing the data is a reasonable business practice that does not override the individual’s rights — which is more workable, but only if you minimise the data and respect objections.
This is where the principle of data minimisation does the heavy lifting. If you show only a first name (or no name at all), a region rather than a precise address, and a rounded time rather than an exact one, you dramatically reduce both the identification risk and the strength of any privacy objection. Minimisation is not just a compliance checkbox; it is the single most effective way to make notifications safe. The less identifying the data, the easier every other part of the analysis becomes.
4. Cookies, tracking, and the ePrivacy angle
GDPR is not the only rule in play. The ePrivacy Directive — the “cookie law” — governs storing or reading information on a visitor’s device. Some social proof tools drop cookies to track visitors across sessions, count returning users, or personalise notifications. If yours does, that tracking generally requires prior consent through your cookie banner, and it should be switched off until the visitor agrees.
A cleaner approach is to favour tools and configurations that do not rely on invasive tracking to function. A live visitor counter can be driven by aggregate, anonymous session data rather than by profiling individuals. A recent-purchase feed can be driven by order events without building a cross-site advertising profile of the buyer. The fewer identifiers you set on the device, the simpler your consent story becomes — and the fewer things can go wrong during an audit. When you evaluate a widget, ask specifically what it stores on the visitor’s device and whether that is essential to the feature or just convenient for the vendor.
5. Rights: access, objection, and erasure
Under GDPR, the people whose data you process have rights, and those rights extend to social proof. A customer can ask what data of theirs you display, can object to it being shown, and can request erasure. In practice this means you need to be able to stop showing a specific person’s purchase if they ask, and you should not be caching customer details in a widget for longer than you need them.
This is far easier to honour when you have minimised in the first place. If your notifications only ever show “someone in France,” there is effectively nothing for an individual to object to, because no one is identifiable. If you show full names, you need a real process to remove a named person on request. Designing for minimal identification up front means you rarely have to handle these requests at all — a good example of privacy-by-design saving you operational work later, not just reducing legal risk.
6. A safe configuration you can copy
Here is a configuration that keeps most stores comfortably compliant while preserving the persuasive power of social proof. Show a first name only, or drop the name entirely in favour of “a customer” or “someone.” Show a region or country rather than a precise town or postcode. Round timestamps to “recently” or the hour rather than the exact minute. Avoid combining several precise fields that together single someone out. Turn off any cross-site tracking cookies unless the visitor has consented. Keep an easy way to suppress a specific record on request.
None of these choices weaken the message much. “Someone in Germany just booked a demo” still triggers the same herd instinct as a fully named version, because what persuades is the action and the recency, not the surname. You lose a little specificity and gain a lot of legal comfort — a trade almost every store should take.
7. Doing this with Proofly
Proofly is built by an EU-based team, so privacy-friendly defaults are part of the design rather than an afterthought. You control exactly which fields appear in a notification, so you can choose to show a first name and a region instead of a full identity, and you can present real activity — recent purchases, form submissions, live visitor counts — without building an invasive profile of each individual. That makes it straightforward to run notifications that respect data minimisation while still looking convincing. If you want to set up GDPR-conscious social proof, you can create a free Proofly account and configure the fields to match your risk appetite.
The broader point is that compliance and effectiveness pull in the same direction here. Minimised, honest notifications are both safer under GDPR and more trusted by shoppers, who are increasingly wary of sites that seem to know and broadcast too much about other customers. Showing less about the individual and more about the action is the sweet spot.
8. This is guidance, not legal advice
GDPR is principle-based and fact-specific, and this article is a general explainer rather than tailored legal advice. Your obligations depend on what data you actually display, your lawful basis, your market, and your own risk assessment. If you handle sensitive categories of data, operate at large scale, or are unsure whether your configuration is defensible, consult a qualified data-protection professional. As a working default, minimise what you show, avoid unnecessary tracking, and keep the ability to remove a record on request — and most social proof stays comfortably inside the rules.
Need more customers/visitors?
Use Proofly to add high-converting widgets for your website to boost conversion. No creditcard required.
Get started now!Always be up-to-date with Proofly.
The amount of people using your website on mobile devices rapidly increases. Make sure your websites are fully responsive!
58.111%
Mobile devices
This might be useful for you too:
How to Implement FOMO on Your Website
Knowing that the fear of missing out drives action is one thing; putting it to work on your website is another. Done right, FOMO gently nudges hesitant visitors to act on opportunities they genuinely want. Done wron...
2022-03-08
Read more
The Truth About Social Proof: What Works and What Backfires
Social proof is one of the most talked-about tactics in marketing, and one of the most misunderstood. Used well, it is a genuine force multiplier for trust and sales. Used carelessly — or dishonestly — i...
2021-12-04
Read more
How to Use Social Proof in Marketing: 12 Tactics That Convert
Collecting reviews is only half the job. Social proof only lifts sales when it appears in the right place, at the right moment, in the right format. A five-star rating hidden on a testimonials page does nothing; th...
2022-06-09
Read moreReady to use social-proof too?
You can use Proofly within 5 minutes on your own website absolutely free!
Set-up in 5 minutes Over 25,000 satisfied customers No monthly subscription
4.7/5 customer satisfaction
Get started now!
a few thousand others...