codexier.

Design & UX

Heatmaps and Session Recordings Without GDPR Trouble

By CodexierPublished 5 min read

Heatmaps and session recordings are among the most useful tools in conversion work: they show where people click, how far they scroll and where they give up. They are also among the most privacy-sensitive, because a recording is a replay of a real person's visit, sometimes including what they typed. Used carelessly, they create a GDPR problem; configured properly, they are defensible and still valuable. This guide covers consent, masking, retention and how to get insight from fewer, better sessions.

What heatmaps and recordings show

Click heatmaps

Where people click and tap, including on things that are not links. Useful for spotting elements that look clickable but are not.

Scroll maps

How far down the page visitors get. Shows whether key content or the call to action is seen at all.

Session recordings

A replay of one visit: movement, clicks, scrolling and hesitation. The richest data, and the most sensitive.

Tools such as Hotjar, Microsoft Clarity, Mouseflow and the recording features in some analytics platforms all do broadly the same thing. The legal questions are the same for all of them.

Masking personal data

Consent does not make it acceptable to capture everything. Data minimisation still applies: record behaviour, not content. Most tools mask form inputs by default, but check it, and extend masking to any on-screen text that can contain personal data, such as names on account pages, order details or messages.

AreaWhat to doWhy
Form inputsMask all inputs, not just password and card fieldsPeople type personal data in unexpected fields
Account and order pagesMask text or exclude the pagesThey display names, addresses and purchase history
Checkout and paymentExclude entirelyPayment providers' fields must never be recorded
Health, finance and other sensitive servicesExclude or do not use recordings at allSensitive personal data needs a much stronger basis
URLs with parametersStrip email addresses and tokens from query stringsIdentifiers leak through links

Retention and access

Recordings lose most of their value within weeks, once the question they were meant to answer is answered. Set the shortest retention the tool allows that still covers your analysis cycle, often thirty to ninety days. Give access only to the people doing the analysis, use individual logins with two-factor authentication, and remove access when someone leaves the project. Document the setup in your record of processing activities, so you can show what you collect and why.

Getting insight from fewer sessions

  1. Start with a question from analytics, such as why visitors leave the pricing page or the second step of a form.
  2. Record only the pages involved, or filter recordings to sessions that reached them.
  3. Watch twenty to thirty relevant sessions and note each point of hesitation or error.
  4. Group the notes into patterns and rank them by how often they occur.
  5. Change one thing, then check the funnel in analytics rather than rewatching recordings.

This targeted approach is both better research and better privacy: less data collected, shorter retention, clearer purpose. It is also how we use recordings in a UX audit.

When you do not need recordings: with low traffic, five moderated user tests teach more than a month of recordings and involve no tracking. Recordings pay off when traffic is steady and analytics shows where people drop but not why. Our UX audit and conversion service sets up tools with consent and masking and turns the findings into a prioritised list; see pricing or book a call.

Frequently asked questions

Do heatmaps need consent if they do not record sessions?

Usually yes. Heatmap tools still store or read identifiers in the browser to group clicks by visit, and that requires consent under the Swedish rules unless the tool is configured to work without any device storage, which few are.

Is Microsoft Clarity free and therefore fine to use?

Free has nothing to do with legality. Clarity, like other tools, must load only after consent, be named in your policies and be configured with masking. Check its current terms on data use and where data is processed before you choose it.

Can we record logged-in users in our app?

It is possible with consent, masking and a clear purpose, but the risk is higher because sessions are directly linked to named people. Many teams use recordings only on the public site and rely on product analytics and user interviews inside the app.

How long should we keep recordings?

As short as your analysis cycle allows, typically thirty to ninety days. Delete them when the question they were collected for has been answered.

Get behaviour insight you can defend

Tell us which pages lose visitors and which tools you use today. In fifteen minutes we can tell you whether recordings are worth it and how to set them up with consent and masking.

Book a free 15-minute call