TL;DR

Poland's data protection authority fined a company over PLN 201,000 in 2019 solely because its consent-withdrawal process forced people to state a reason. GDPR fines for unlawful processing can reach €20 million or 4% of global turnover. The FTC's Consumer Review Rule, finalized August 2024, allows civil penalties up to $51,744 per violation, and the agency issued its first warning letters under it in December 2025. A privacy-safe customer story requires exactly three things: documented, specific consent before collection; clear disclosure of any material connection (e.g., a free product); and a working withdrawal mechanism as easy as giving consent.

Everything else—redaction, storage, legal sign-off—supports those three but doesn't replace them. A customer story that meets only that narrow bar is compliant; anything less is a real enforcement risk.

A customer story workflow is "privacy-safe" when three specific things are true: the person and company being featured gave documented, purpose-specific consent before you collected anything; every claim and any material connection (a discount, free product, or other benefit given in exchange for participating) is disclosed and truthful; and there's a working mechanism for the customer to review, correct, or withdraw before and after publication. Everything else — redaction habits, storage hygiene, legal sign-off — supports those three things. None of it substitutes for them.

That's a narrower bar than most "customer marketing best practices" posts imply. It also isn't legal advice — see the limitations section below before you build a process around this article.

What "privacy-safe" actually means, precisely

Direct answer: A few terms get used loosely in this space. Precision matters because the wrong one changes what you're legally required to do:

  • Consent (GDPR sense): Under the GDPR, consent is only valid if it is freely given, specific, informed, and unambiguous — a data subject has to know exactly what they're agreeing to, for what purpose, and indicate agreement through a clear affirmative action. This is defined in GDPR Article 6 and detailed further in the EDPB's Guidelines 05/2020 on consent. A signed NDA or a general marketing opt-in does not cover "we will publish your name, title, and quote on our website" — that needs its own specific ask.
  • Withdrawal: GDPR Article 7(3) requires that withdrawing consent be "as easy" as giving it, at any time, without a reason required. If someone can consent with one click but has to email three people and wait two weeks to withdraw, that's a compliance gap, not a process quirk.
  • Material connection: Under the FTC's Endorsement Guides (16 CFR Part 255), any business, family, or financial relationship between you and the person giving the testimonial — including a discount or free product given in exchange for participating — that a reasonable audience wouldn't expect must be disclosed clearly and conspicuously. This is spelled out in 16 CFR § 255.5.
  • Right of publicity: Separate from privacy law, most U.S. states give individuals a property-like right over the commercial use of their name, photo, or likeness. California's version, Civil Code § 3344, prohibits using someone's name, voice, signature, photo, or likeness for advertising without prior consent — and it applies to ordinary people, not just celebrities. This is a distinct legal theory from GDPR/CCPA and needs its own consent language.
  • PII vs. sensitive business information (SBI): GDPR's "personal data" only covers information about identifiable individuals. A customer's internal revenue figures, proprietary process names, or unreleased roadmap details aren't personal data — but they're often the details customers are most protective of, and they need a separate confidentiality check, not a privacy check.

What the actual regulations require (and don't)

Direct answer: Skip the paraphrased "GDPR says be careful with data" version. Here's what the source material actually says about customer stories specifically:

GDPR treats a testimonial as a specific, non-essential use of personal data, which means consent (Article 6(1)(a)) — not "legitimate interest" (Article 6(1)(f)) — is the appropriate legal basis in almost every case. Legitimate interest requires passing a three-part balancing test, and using someone's name and quote in a case study is exactly the kind of specific, foreseeable, non-necessary processing that test is designed to catch. Getting the legal basis wrong isn't cosmetic: Article 83(5)(a) puts unlawful processing in the highest fine tier — up to €20 million or 4% of global annual turnover. As one enforcement data point, Poland's data protection authority fined a company over PLN 201,000 in 2019 specifically because its consent-withdrawal process was needlessly complicated — the EDPB's own case summary notes the regulator objected to forcing people to state a reason for withdrawing.

CCPA/CPRA works differently — it's opt-out, not opt-in, for most processing. California's framework, administered by the state Attorney General, generally doesn't require consent before you collect or use personal information; instead it requires disclosure at collection and an honored opt-out right, including recognition of the Global Privacy Control browser signal. The 2022 Sephora settlement — a $1.2 million fine, California's first public CCPA enforcement action — turned specifically on failing to honor opt-out signals and misrepresenting data practices, not on a testimonial. The practical read for customer stories: CCPA doesn't force you into a GDPR-style consent form, but you still need clear disclosure of use, and you still need to honor a later request to stop.

The FTC doesn't regulate consent to be quoted — it regulates truthfulness and disclosure of the quote itself. The updated Endorsement Guides, effective July 2023, require that any performance claim in a testimonial be substantiated and that the testimonial reflect the endorser's honest, current opinion. In August 2024 the FTC finalized its Consumer Review Rule, which bans fabricated or edited-to-misrepresent testimonials and gives the agency authority to seek civil penalties of up to $51,744 per violation. Enforcement is recent and real: the FTC issued its first round of warning letters under the rule in December 2025. If a customer's quote was edited to say something they didn't say, or a metric wasn't verified, that's the exposure — not the consent paperwork.

Right of publicity is the piece GDPR/CCPA discussions usually skip. It's a separate legal claim available to the individual (not the company), it exists in roughly half of U.S. states in some form, and it applies regardless of whether the customer's employer already agreed to the case study. A consent form signed by "the company" doesn't automatically cover an individual employee's name-and-likeness rights unless the form says so explicitly.

Use this before any interview, not after a draft exists.

ItemWhat it needs to sayLegal hook
PurposeExactly what's being published (case study, quote, logo use, video) and where (site, ads, sales decks, social)GDPR Art. 6/7 — specific and unambiguous
Individual vs. company scopeWhether the named person's likeness/quote is covered separately from the company's name/logoState right-of-publicity law (e.g., Cal. Civ. Code §3344)
Data pointsWhich specific facts, quotes, and metrics are approved for publicationGDPR data minimization
Material connectionAny discount, free product, payment, or other benefit given for participating, and how it will be disclosedFTC 16 CFR §255.5
SubstantiationBackup evidence for any stated metric (screenshot, internal report, named approver)FTC Endorsement Guides — truthful, substantiated claims
Withdrawal mechanismA named, low-friction way to revoke consent, stated up frontGDPR Art. 7(3) — as easy to withdraw as to give
Retention/expirationHow long the story will run before consent is re-confirmedGDPR storage limitation
Record of consentWho consented, when, to what — kept as a retrievable record, not a verbal understandingGDPR Art. 7(1) — burden of proof sits with you

The workflow

  1. Scope and ask before you collect anything. Define the specific channels, data points, and duration in writing, and get affirmative, purpose-specific consent — not a blanket marketing opt-in — before the interview happens. If any incentive (discount, swag, extended trial) is being offered for participation, decide now how it will be disclosed later.
  2. Interview inside the agreed scope. Ask about team- and company-level outcomes rather than personal struggles you haven't gotten separate consent to publish. Request supporting evidence for every number you plan to quote — an internal report, a dashboard screenshot, a named approver — and keep that evidence on file, because the substantiation obligation is yours, not the customer's.
  3. Draft, then redact against the consent form, not against instinct. Strip anything not explicitly covered: other employees' names, exact financials, internal project codenames, proprietary process detail. If the piece includes a metric, confirm the wording matches what the evidence actually supports — the FTC's rule is about accurate representation, not just permission.
  4. Route through legal/compliance review before customer sign-off. Someone should check three things in one pass: does the draft match the consent scope, is any material connection disclosed, and does the wording avoid overstated or unverifiable claims.
  5. Get explicit, dated final approval from the customer — the actual individual quoted, not just their marketing contact — before publishing. State plainly how they can request changes or pull the story later.
  6. Store the consent record and set an expiration. Keep the original consent form, evidence, and final approved copy together, tagged with a review or expiration date. When you revisit an old story for a new use (a paid ad campaign that wasn't in the original scope, for instance), that's a new purpose — go back and ask again rather than assuming the old consent stretches to cover it.

Limitations

This is not legal advice, and treating it as a complete compliance program would be a mistake. Requirements vary by jurisdiction (GDPR, UK GDPR under the ICO's consent guidance, CCPA/CPRA, and dozens of other state and national frameworks not covered here), by the customer's own industry (healthcare, finance, and public-sector customers often carry additional confidentiality or procurement restrictions on top of privacy law), and by whether the featured individual is an employee, a contractor, or the business owner. Right-of-publicity law in particular is state-specific in the U.S. and largely absent as a distinct concept elsewhere. If a customer story involves EU residents, regulated industries, minors, or any cross-border data transfer, get counsel involved before you templatize a process around this article.

Where nqzai fits

nqzai is built for B2B outbound and SEO/GEO content at volume, and customer story production runs through the same content and outreach machinery — drafting the initial ask to a customer, generating a first-pass narrative from interview notes, and slotting the approved story into a content calendar alongside the rest of a site's published work. What it doesn't do is replace the consent form, the legal review, or the judgment call about whether a specific claim is substantiated enough to publish — those stay human decisions, made against the checklist above, before anything nqzai touches goes live. If your team is producing customer stories at a pace where tracking consent status and expiration dates by hand is starting to fail, that's a signal to fix the workflow first and use tooling to execute it faster, not the other way around.

FAQ

Direct answer: Is a verbal "sure, go ahead" from a customer enough consent to publish? No. It's not verifiable, and GDPR Article 7(1) puts the burden of proving consent was given on you, not the customer. Use a dated, written (digital is fine) form that states the specific scope.

A customer asks us to take their story down two years after publication — what are we obligated to do? Remove it from active public channels and stop using the associated personal data in current marketing, per GDPR Article 7(3)'s "as easy to withdraw as to give" standard. Keep an internal record that the withdrawal happened and when, for your own audit trail, but don't keep using the story after the request.

We gave the customer a discount for agreeing to be featured — does that need to be disclosed? Yes, under the FTC's material connection rule (16 CFR §255.5), a discount, free product, or payment given in exchange for participation must be disclosed clearly if it's not something the audience would already expect.

Can we publish "a leading SaaS company grew revenue 30%" without naming the customer, and skip the consent process? If it's genuinely de-identified — no name, no identifying detail, nothing that lets someone infer who it is — it falls outside most PII-specific rules, but full anonymization defeats the purpose of most customer stories and courts/regulators read "obviously identifiable" claims skeptically. If the point of the story is that a specific, recognizable company said this, you're not actually anonymizing it — get consent.

Does the featured employee's consent cover the company, or do we need both? Get both, explicitly. A company-level agreement (from procurement or the account owner) doesn't automatically waive an individual's right-of-publicity or GDPR consent for their own name, photo, or quote, and vice versa.

Do these rules apply the same way to international customers? No — GDPR, CCPA, and the FTC's rules aren't a unified standard, and other jurisdictions have their own frameworks entirely. Design your consent form around the strictest regime your customer base touches, and confirm with counsel for any customer outside the U.S. and EU/UK, where the applicable law may differ from both.