Back to Blog
testimonials
subprocessors
privacy
compliance
security-review
page-layout
social-proof

Where to Place Testimonials on a Subprocessor List Page

ProofShow Team··7 min read

Nobody browses a subprocessor list. People arrive on it for one of three reasons: a privacy team is filling in a DPA review, a security questionnaire asked where customer data goes, or a customer got your change notification and wants to know what just changed.

All three readers are doing compliance work under time pressure, and all three are looking for a specific name in a table. That makes this the most hostile page on your site for a testimonial — and also one of the few where a single, narrowly-scoped quote is genuinely load-bearing.

The distinction comes down to what the quote is evidence of. On this page, praise is noise. Process is signal.

The rule that governs this page

A quote earns its place here only if it describes surviving a review that used this page.

Not a customer who likes your product. Not a customer who trusts you with their data in the abstract. Someone whose privacy or procurement team read this exact list, ran it through their own assessment, and approved it — and who can say what that process involved.

Anything else is a vendor putting marketing copy in the middle of a legal disclosure, which is the fastest way to make a reviewer distrust the disclosure.

Slot 1: never above the table

The top of the page belongs to four things, in this order: the effective date of the list, the scope (which products it covers), the table itself, and the link to your DPA. No quote, no logo band, no testimonial carousel goes above that.

A privacy analyst who has to scroll past a customer quote to find whether you use a US-region storage provider will note it as friction, and some of them will note it in writing. This page is graded on how fast it answers a question, and anything between the reader and the table costs you.

The table needs the columns reviewers actually check — subprocessor name, purpose, data categories, and processing location — and it needs them before any narrative at all.

Slot 2: after the change-notification policy, as evidence the process works

This is the one slot where a testimonial does real work.

Your change-notification section makes a promise: we will tell you before we add a subprocessor, with this much notice, through this channel, and here is your objection right. Every vendor makes some version of that promise. A reader has no way to know whether yours is operational or aspirational.

A customer who has been through one notification cycle does:

"We got the notice about the new CDN provider 32 days before the change, with the region and the data categories already filled in. Our DPO had two questions, we sent them Tuesday and had answers Thursday. We did not have to chase anyone." — DPO, European insurance group

Why this works where other quotes fail:

  • It confirms a specific commitment. Thirty-two days against a stated thirty-day notice period is verifiable against the sentence directly above it.
  • It describes a process, not a feeling. No adjectives about your company. The reader is assessing operational reliability, and that is what the quote reports on.
  • It names the reviewer's own role. A DPO quoting a DPO is peer evidence. A VP of Marketing saying the same thing would be worthless here.

One quote in this slot. Two if you operate under materially different regimes and have a quote from each — one EU, one US healthcare, for instance — clearly attributed by sector.

Slot 3: next to the objection or termination right, usually nothing

Most subprocessor policies grant a right to object to a new subprocessor, with some escalation path if the objection cannot be resolved.

Resist putting a quote here. Every available quote comes from a customer who did not object, which reads as "nobody has ever used this right" — and a reviewer will hear that as "this right is theoretical." You have accidentally undermined the clause you were trying to reassure them about.

If you have genuinely handled an objection well, the place for that story is a security review FAQ or a conversation with a prospect's privacy team, not the disclosure page.

State the right. State the escalation path. Give a contact address that is monitored. Nothing else.

Slot 4: the audit and certification section, one line only

If you list your own certifications — SOC 2, ISO 27001, whatever applies — one inline sentence from a customer about how their assessment went is defensible, provided it is about the assessment and not about you.

"Their SOC 2 report answered eleven of the fourteen items on our vendor checklist without a follow-up call." — Security review lead, fintech

Inline. No portrait, no quote card, no company logo. On a compliance page, visual treatment is what converts a data point into an advertisement, and the conversion is not in your favor.

The placements that make things worse

  • A logo wall of enterprise customers. On a subprocessor page this argues "big companies accepted this," which a reviewer correctly reads as pressure rather than evidence. Their job is to assess your processing, not to benchmark their risk appetite against someone else's.
  • Quotes about product quality. Nobody on this page is evaluating whether your product is good. Introducing that topic signals that you do not understand who is reading.
  • Anything with "trust" as an adjective. "We trust them completely" is the exact claim a reviewer is being paid not to take on faith.
  • A carousel. A reader is extracting facts into a questionnaire. Moving content is an obstacle, and in some review workflows it breaks the PDF capture they are taking as evidence.
  • Quotes that predate your current list. If you added or removed a subprocessor since the quote was given, the quote describes a different arrangement than the one on the page.
  • Testimonials from customers in a different regulatory regime than the reader. A US customer's comfort is not relevant to an EU reviewer's transfer analysis, and putting it there looks like you think it is.

A layout that holds up

  1. Effective date and scope — which products and which entities this list covers.
  2. The subprocessor table — name, purpose, data categories, processing location.
  3. Transfer mechanism section — SCCs, adequacy, or whatever applies.
  4. Change-notification policy — notice period, channel, subscription link.
  5. One process quote, from someone who has been through a notification cycle.
  6. Objection and escalation rights — no quotes.
  7. Certifications and audit reports — optionally one inline assessment quote.
  8. Contact for privacy inquiries, with a real response-time commitment.

Two quotes maximum. One is usually right.

How to collect these

The window is narrow and it is not the one most teams use. Asking a customer to praise your privacy posture produces a useless quote, because the honest answer is "I have no way to evaluate that."

Ask instead right after a subprocessor change notification has gone out and been resolved. The request is specific: you received our notice about X — how did that land with your privacy team, how much notice did you actually need, and did you have to chase us for anything? That question is answerable, and the answer contains the numbers that make the quote worth publishing.

The same logic — evidence of process rather than expressions of confidence — governs the neighboring pages: where to place testimonials on a security page covers the broader trust surface, and where to place testimonials on an enterprise page handles the page your procurement reader lands on next.

Ready to get started?

Start collecting and showcasing testimonials in under 5 minutes.

Start Free