
Hotjar and GDPR: Is Session Recording Legal and How to Configure It Correctly
Session recording tools like Hotjar are powerful for understanding user behavior. They're also one of the more sensitive categories of tracking under GDPR. Here's what makes them legally complex and how to use Hotjar without creating a compliance problem. Why Session Recording Is Uniquely Sensitive Under GDPR Session recording captures everything a user does: mouse movements, clicks, scrolling, form input. Unlike a page view or a click event, a recording is a continuous behavioral trace — a replay of exactly what a real person did on your site. That's powerful for UX research. It's also one of the more invasive forms of data collection on the web. The sensitivity comes from what session recordings can inadvertently capture. If a user starts filling in a form — even partially, even if they abandon it — that data may be captured in the recording. This can include names, email addresses, search queries, and in worst-case misconfigurations, passwords or payment details. GDPR treats behavio
Continue reading on Dev.to Webdev
Opens in a new tab
