Are fake reviews illegal in the EU? Yes, categorically. Since 28 May 2022 the UCPD blacklist has banned submitting or commissioning false consumer reviews, misrepresenting reviews to promote products, and claiming reviews come from real purchasers without taking reasonable steps to verify it. Blacklist entries need no case-by-case balancing: the practice is unfair per se. And yet, when the European Commission and national authorities swept 223 major websites, they assessed at least 55% as likely breaching EU consumer law on reviews, with roughly two-thirds raising doubts about whether their reviews could be trusted at all.
For most of this series, the margin illusion sits in a cost line. This one sits somewhere more uncomfortable: in the evidence itself. Customer reviews are the closest thing e-commerce diligence has to a neutral witness. They are what this firm’s own outside-in method leans on, and what every acquirer’s team quietly consults whether or not it appears in the workplan. A target that has manufactured its review base has not just inflated its conversion rate. It has pre-poisoned the well that both sides drink from.
The Mechanism
A review base can be manufactured at every point in its life cycle, and most manufactured bases mix several methods:
- Purchased and commissioned reviews. Bought outright from review farms, or commissioned through agencies and “product testing” communities. This is the crude end, and the per-se banned one.
- Incentivised reviews without disclosure. Discounts, refunds, or free products in exchange for a review. Lawful in some forms if disclosed as such; presented as organic, it misrepresents the review’s origin.
- Review gating. Only customers flagged as satisfied get the review invitation; complainants get a private feedback form instead. Every published review is real, and the aggregate is still synthetic: the average describes the filter, not the product. Where exactly gating crosses into a misleading practice is a live enforcement question rather than settled text, and one for counsel per market, but the diligence implication doesn’t wait for that answer: a gated 4.8 does not mean what an ungated 4.8 means.
- Inherited and migrated reviews. Listings merged so that a new product wears an older product’s review history, or imported review widgets carrying scores generated somewhere else, under other rules. The rating is real; its connection to the product being sold is not.
None of this requires touching the product. Like the reference price, the review score is a number printed next to the product that does conversion work the product didn’t earn.
Where This Sits in EU Law: Two Blacklist Entries and a Disclosure Duty
The Omnibus Directive wrote reviews into the Unfair Commercial Practices Directive in two places, applicable across the EU since 28 May 2022.
First, Annex I, the blacklist of practices unfair in all circumstances, gained two entries: stating that reviews come from consumers who actually used or purchased the product without taking reasonable and proportionate steps to check that they do; and submitting, or commissioning others to submit, false consumer reviews or endorsements, or misrepresenting reviews or social endorsements, to promote products. Blacklisted practices need no proof of consumer harm in the individual case.
Second, Article 7(6) made review governance a required disclosure: a trader that provides access to consumer reviews must state whether and how it ensures those reviews come from actual purchasers. Displaying a review section while staying silent on verification is a misleading omission, not a neutral default. The Commission’s UCPD guidance walks through both provisions in detail.
The enforcement posture is the same as elsewhere in the Omnibus family: national authorities enforce, coordinated sweeps surface targets, and for widespread infringements member states must provide fines whose maximum is at least 4% of the trader’s annual turnover in the markets concerned. The sweep numbers above say how much low-hanging fruit that machinery has to work with.
The Fake GM3 Problem: The Deal Gets Sold Twice
The first sale is at the checkout, and it works exactly like the anchor in the Permanent Sale: the star rating lifts conversion, the conversion suppresses CAC, and the P&L books the lift as marketing efficiency and brand strength. A manufactured review base is rented trust, and GM3 pays the rent invisibly. The normalisation mechanics are familiar too. Marketplaces and review platforms purge fake and incentivised reviews on their own schedules, with the same suspension-first reflexes mapped in the DSA piece; a target one purge away from its true rating is carrying a conversion reset with an unknown trigger date.
The second sale is the one unique to this topic: it happens in the diligence process itself. Reviews are the informal evidence layer of every e-commerce acquisition. Associates read them. Commercial DD samples them. Confirmatory calls quote them. A QoE model never cites them, and the partners’ conviction quietly rests on them anyway. A manufactured review base therefore doesn’t just inflate the target’s numbers; it corrupts the buyer’s independent check on those numbers. The seller’s curated data room is expected. A curated outside world is the sharper trick, and it is exactly what a fake review base buys.
There is also an asset-quality footnote for marketplace-heavy targets: the review history attached to listings is often treated as part of what’s being acquired, the moat that makes the ASIN defensible. To the extent that history is manufactured, the moat is a compliance liability wearing an asset’s clothes.
Why This Slips Through Due Diligence
Nothing in a standard process owns review authenticity. The data room contains no review-provenance schedule. Financial diligence has no line where purchased reviews appear; if they were ever paid for, the cost sits in marketing spend under labels nobody queries. Legal diligence reviews the target’s own terms, not its solicitation practices or its agencies’ methods, and a seller’s compliance representation is only as good as its knowledge of what a growth agency did three years ago. Commercial diligence reads the rating and the top reviews, which is precisely the surface manufacturing is designed to decorate. The practice is visible only in the patterns underneath, and those are outside the data room entirely.
What Outside-In Analysis Can Detect Before the Data Room
- Timing structure: review velocity mapped against launch dates, ranking milestones, and promotion windows; organic bases accumulate unevenly but not in synchronised bursts
- Distribution shape: authentic bases show characteristic spreads; a wall of five-star reviews with a thin scatter beneath, or a distribution that shifts abruptly at a date boundary, is a pattern with a small number of explanations
- Verified-purchase ratios and reviewer histories: the share of reviews from confirmed buyers, and whether the same reviewer accounts recur across the target’s catalogue or across unrelated brands from the same sourcing ecosystem
- Cross-platform divergence: the target’s own-site widget saying 4.9 while its marketplace listings, Trustpilot, and app-store pages say something materially different; independent surfaces are harder to curate in sync
- Article 7(6) compliance on the target’s own store: whether any statement exists on how reviews are verified, whether incentivised reviews are flagged, and whether negative reviews appear at all
- Listing archaeology: review histories older than the product, reviews describing a different item, or merged-listing scars visible in earliest-review dates
None of this proves manufacturing on its own; these are indications of how much weight the review base can bear, and they scope a formal DD request that rarely gets made: solicitation policy, agency contracts touching reviews, incentive programmes, and platform enforcement history.
The Pre-LOI Question Every PE Fund Should Ask
The rating is the number everyone can see, and the least informative one on the page. The question is: would the target’s conversion rate, and the buyer’s own conviction, survive the review base being reduced to its verified, organically solicited core?
A target whose reviews hold up under that reduction owns its trust, and its GM3 with it. A target whose reviews don’t is borrowing conversion from a blacklisted practice, and lending the borrowed evidence onward, to the very diligence process that’s supposed to catch it.
This analysis is part of Tronvik’s GP3 Waterfall methodology, focused on GM3 marketing-efficiency mapping. Nothing in this article constitutes legal advice. To initiate an outside-in review-authenticity screen on a specific acquisition target, contact info@tronvik.com.