Heatmaps and Session Recordings Without GDPR Trouble
By CodexierPublished 5 min read
Heatmaps and session recordings are among the most useful tools in conversion work: they show where people click, how far they scroll and where they give up. They are also among the most privacy-sensitive, because a recording is a replay of a real person's visit, sometimes including what they typed. Used carelessly, they create a GDPR problem; configured properly, they are defensible and still valuable. This guide covers consent, masking, retention and how to get insight from fewer, better sessions.
What heatmaps and recordings show
Click heatmaps
Where people click and tap, including on things that are not links. Useful for spotting elements that look clickable but are not.
Scroll maps
How far down the page visitors get. Shows whether key content or the call to action is seen at all.
Session recordings
A replay of one visit: movement, clicks, scrolling and hesitation. The richest data, and the most sensitive.
Tools such as Hotjar, Microsoft Clarity, Mouseflow and the recording features in some analytics platforms all do broadly the same thing. The legal questions are the same for all of them.
Consent requirements
Under the Swedish Electronic Communications Act, storing or reading information on a visitor's device requires consent unless it is strictly necessary for a service the visitor asked for. Behaviour analytics is not strictly necessary, so the script must not load until the visitor has accepted the relevant cookie category. On top of that, GDPR applies to the recordings themselves, since they can be linked to a person. The Swedish Authority for Privacy Protection (IMY) has made clear that analytics tools are not exempt from these rules. See our guide to cookie banner rules in Sweden for the banner side.
- Place behaviour tools in a statistics or analytics category that is off by default.
- Load the script only after consent, and verify it with the browser's developer tools.
- Name the tool and its purpose in the cookie policy and the privacy notice.
- Sign the vendor's data processing agreement and check where data is stored.
- Some vendors now require a consent signal before they record visitors in the EU; configure it rather than working around it.
Masking personal data
Consent does not make it acceptable to capture everything. Data minimisation still applies: record behaviour, not content. Most tools mask form inputs by default, but check it, and extend masking to any on-screen text that can contain personal data, such as names on account pages, order details or messages.
| Area | What to do | Why |
|---|---|---|
| Form inputs | Mask all inputs, not just password and card fields | People type personal data in unexpected fields |
| Account and order pages | Mask text or exclude the pages | They display names, addresses and purchase history |
| Checkout and payment | Exclude entirely | Payment providers' fields must never be recorded |
| Health, finance and other sensitive services | Exclude or do not use recordings at all | Sensitive personal data needs a much stronger basis |
| URLs with parameters | Strip email addresses and tokens from query strings | Identifiers leak through links |
Retention and access
Recordings lose most of their value within weeks, once the question they were meant to answer is answered. Set the shortest retention the tool allows that still covers your analysis cycle, often thirty to ninety days. Give access only to the people doing the analysis, use individual logins with two-factor authentication, and remove access when someone leaves the project. Document the setup in your record of processing activities, so you can show what you collect and why.
Getting insight from fewer sessions
- Start with a question from analytics, such as why visitors leave the pricing page or the second step of a form.
- Record only the pages involved, or filter recordings to sessions that reached them.
- Watch twenty to thirty relevant sessions and note each point of hesitation or error.
- Group the notes into patterns and rank them by how often they occur.
- Change one thing, then check the funnel in analytics rather than rewatching recordings.
This targeted approach is both better research and better privacy: less data collected, shorter retention, clearer purpose. It is also how we use recordings in a UX audit.
When you do not need recordings: with low traffic, five moderated user tests teach more than a month of recordings and involve no tracking. Recordings pay off when traffic is steady and analytics shows where people drop but not why. Our UX audit and conversion service sets up tools with consent and masking and turns the findings into a prioritised list; see pricing or book a call.
Frequently asked questions
Do heatmaps need consent if they do not record sessions?
Usually yes. Heatmap tools still store or read identifiers in the browser to group clicks by visit, and that requires consent under the Swedish rules unless the tool is configured to work without any device storage, which few are.
Is Microsoft Clarity free and therefore fine to use?
Free has nothing to do with legality. Clarity, like other tools, must load only after consent, be named in your policies and be configured with masking. Check its current terms on data use and where data is processed before you choose it.
Can we record logged-in users in our app?
It is possible with consent, masking and a clear purpose, but the risk is higher because sessions are directly linked to named people. Many teams use recordings only on the public site and rely on product analytics and user interviews inside the app.
How long should we keep recordings?
As short as your analysis cycle allows, typically thirty to ninety days. Delete them when the question they were collected for has been answered.
Get behaviour insight you can defend
Tell us which pages lose visitors and which tools you use today. In fifteen minutes we can tell you whether recordings are worth it and how to set them up with consent and masking.
Book a free 15-minute call