A review widget GDPR check should establish which servers receive requests from each visitor's browser, where copied reviews are stored and which companies process the data. ReviewMix imports Google reviews through Google's API, caches them in an EU database and serves the widget without making the visitor's browser contact Google.
What does a review widget GDPR data journey look like?
A Google review can pass through six distinct stops before appearing to a website visitor. The important distinction is between the original review, the vendor's stored copy and the network requests made by the visitor's browser.
- The customer writes a review, often using a phone or another personal device.
- Google receives and stores the original review.
- The widget vendor fetches a copy, either in advance or when somebody opens the website.
- The fetched copy lives on infrastructure chosen by the widget vendor.
- The vendor or Google serves review content and widget files to the business's page.
- The visitor sees the review, while the browser may disclose connection data to each server it contacts.
The visitor does not send the review itself. However, a browser request normally exposes technical information needed to deliver a response, such as the visitor's IP address, requested page information, browser details and request time.
The data route therefore matters even when the widget shows public material. Public review text and visitor connection data are separate categories, with different reasons for being processed.
What happens when a Google review widget loads on my page?
A Google review widget loads code or prepared HTML, obtains review content and renders that content inside the page. The exact route depends on whether the widget fetches reviews during each visit or serves a copy collected earlier.
A live fetching design can create external requests whenever somebody opens the page. A cached design lets the vendor retrieve reviews on a schedule, store the copy and serve that copy without involving the original source during every visit.
ReviewMix uses the cached approach. Google reviews are imported once per scheduled refresh through Google's API and stored in ReviewMix's EU database, with Google listed as a sub-processor for that import.
The visitor then receives the widget from ReviewMix. The browser does not need to ask Google for the review content, and updates arrive automatically after the next scheduled refresh.
Does the visitor's browser contact Google or a US server?
A visitor's browser may contact Google or a server outside the EU when a widget embeds third-party code, fonts, images or live review content. Many widgets make such requests on every page load, but the actual behaviour must be verified for the specific embed.
ReviewMix serves its widget loader from cdn.reviewmix.eu and review content from ReviewMix infrastructure. The browser talks to ReviewMix rather than Google, while the earlier import remains a separate server-to-server operation through Google's API.
ReviewMix delivers the loader and the review response through Cloudflare, a network provider headquartered in the US that serves them from EU edge nodes and briefly processes the visitor's IP address for routing and security. Cloudflare is named on ReviewMix's sub-processor list, alongside Google for the import.
EU hosting does not remove the need to document processing. A business still needs to understand the purpose, lawful basis, retention, access and sub-processors involved. The data location guide explains the ReviewMix route in more detail.
A low monthly widget price can become expensive if an undisclosed external request forces consent-banner changes, legal review or rework across many client sites. Test the real embed before rolling it out, because a vendor's general privacy page may not describe every request made by the browser.
How can I check what my widget does in the browser?
The browser's developer tools can show every domain contacted while a widget loads. Test with optional cookies declined so that the result reflects the experience of a visitor who has not granted marketing consent.
Open a private browsing window, visit the test page and open Developer Tools. Select the Network panel, clear existing entries and reload the page.
- Filter requests by the widget vendor's name or domain.
- Look for requests to Google, analytics services, font hosts, image hosts and content delivery networks.
- Open each request and inspect its full URL, method, response and initiator.
- Repeat the test after declining the cookie banner.
- Disable JavaScript and check what remains visible.
- Record the results for the client or data protection officer.
The initiator field is particularly useful because it identifies which script triggered a request. A request can come from the widget, the website theme, a tag manager or another integration, so domain names alone do not prove the source.
For a stricter setup, compare the standard embed with a server-rendered no-JavaScript embed. ReviewMix includes that option on every plan, giving the page prepared HTML without running the widget loader in the visitor's browser.
What should I ask a widget vendor if my client has a DPO?
A widget vendor should give the client's data protection officer a concrete map of storage, browser requests and external processors. Broad claims such as European compliance are not enough to explain the actual flow.
Ask the vendor:
- Where is the copied review content stored?
- Which domains and endpoints does the visitor's browser contact?
- Does any request leave the EU?
- Which sub-processors receive review data or visitor connection data?
- Does the embed respect Consent Mode v2 and the site's consent state?
- Is a server-rendered or no-JavaScript embed available?
- How often are source reviews imported and cached?
- What changes when optional cookies are declined?
- Can the vendor provide a downloadable data processing agreement?
A worked example shows why the answers need operational detail. Suppose an agency tests one client page and sees three domains after declining optional cookies: the client's site, ReviewMix and an unrelated analytics host. ReviewMix can account for its loader and cached review response, while the agency should trace the analytics request through the Network panel's initiator field before approving deployment.
The agency should keep that evidence with its vendor assessment and repeat the check after material embed changes. The guide to embedding reviews without breaking a consent banner covers the wider consent setup.



