Session Replay GDPR Compliance: Hotjar, Clarity & FullStory Under EU Law
Session replay tools record what your visitors do — every click, scroll, and keystroke — and that makes session replay GDPR compliance a real obligation, not a checkbox. The tools themselves are perfectly legal. What gets sites in trouble is when the recording starts. This guide covers exactly what the EU requires for Hotjar, Microsoft Clarity and FullStory, where each one stands, and the US wiretapping risk that most GDPR guides never mention.
Key takeaways
- The tools are legal; the timing is the risk. Hotjar, Clarity and FullStory are lawful — liability comes from recording before a visitor consents.
- GDPR treats session replay as personal data. That means an explicit opt-in before the script loads, a DPIA, input masking, a data-processing agreement, and disclosure of the vendor in your privacy policy.
- No tool is "GDPR compliant" out of the box. Vendor "GDPR-ready" language is a marketing claim — your consent gating and configuration are what actually determine compliance.
- The common failure is a banner-vs-network mismatch. Your banner says replay is off until consent; the script loads anyway. It's a tag-order problem, not a tool problem.
- US sites face a second, bigger risk: CIPA. Session replay is the number-one target of California's wiretapping lawsuits, with $5,000-per-violation exposure under Cal. Penal Code §637.2 — and clearing GDPR doesn't clear that.
What this guide covers
Is session replay legal under GDPR?
Short answer: yes — session replay is legal, but recording a visitor before they consent generally is not. This distinction is the whole ballgame, and it's the thing most panicked "is Hotjar illegal?" searches get wrong. Hotjar, Microsoft Clarity and FullStory are legitimate, widely-used products. What determines whether your deployment is lawful is how and when you run them — specifically, whether the recording starts before or after the visitor makes a choice.
To see why GDPR applies at all, look at what these tools actually capture. A session replay script sits on your page and records the visitor's behavior as a video-like reconstruction — and the raw material is unmistakably personal data.
Mouse movements, scroll patterns, keystrokes and form interactions, tied to a session and often reconstructable into an identifiable behavioral profile — under GDPR, that's personal data. Recording it therefore needs a lawful basis, and for this kind of pervasive behavioral capture, that basis is consent. Which brings us to what the regulation specifically demands.
What GDPR actually requires for session replay
Getting session replay right under EU law comes down to five concrete obligations. Miss any one and your "compliant" setup has a hole in it.
Notice that four of those five are about setup and paperwork — but the first, consent before the script fires, is the one that's both most important and most often broken. It's also the one that connects directly to the litigation risk later in this guide.
Hotjar, Clarity and FullStory compared
All three are capable session replay tools, and all three put the same GDPR obligations on you. Where they differ is defaults, infrastructure, and the extras that matter for sensitive sites. One honest headline up front: none of them is "GDPR compliant" simply by installing it — the vendor gives you the controls, but consent gating and configuration are yours.
Hotjar (now part of Contentsquare)
Hotjar was the tool that popularized session replay for small and mid-sized sites. Worth knowing in 2026: Hotjar was acquired by Contentsquare in 2021 and fully merged into Contentsquare on 1 July 2025, so it's now a Contentsquare product line — which matters for your DPA and sub-processor records. It offers an EU data region and input masking, but, like the others, it will happily record on page load if you don't gate it.
Microsoft Clarity
Clarity is free, has no session limits, and by volume is the most widely deployed session replay tool — found on a large share of top sites precisely because it costs nothing. Two things to be clear-eyed about. First, it processes on Microsoft's US Azure infrastructure, so EU use needs a transfer mechanism (SCCs). Second, Microsoft's "GDPR and CCPA ready" language is a vendor compliance claim, not a regulator's certification — your banner and configuration still decide whether your deployment is lawful. Being free does not make Clarity's obligations any lighter: it triggers the same consent and DPIA duties as the paid tools.
FullStory
FullStory is the enterprise option — the most feature-rich, used heavily by large e-commerce. For regulated sites it has one meaningful advantage: it offers a HIPAA Business Associate Agreement, which Clarity and Hotjar do not — meaning Clarity and Hotjar should not run on any page that renders health information. That doesn't lower FullStory's GDPR bar, though; consent, DPIA, masking and transfer safeguards all still apply.
| Hotjar (Contentsquare) | Microsoft Clarity | FullStory | |
|---|---|---|---|
| Segment | SMB / product teams | Free, all sizes | Enterprise |
| Cost | Free tier + paid | Free, no limits | Paid (enterprise) |
| EU data region | ✅ Available | US (Azure) — needs SCCs | ✅ Available |
| Input masking | ✅ Configurable | ✅ Configurable | ✅ Strong |
| HIPAA BAA | ✗ No | ✗ No | ✅ Yes |
| Consent gating is… | …your responsibility — on every one of them | ||
| "Compliant" out of the box? | No — the vendor supplies controls; you must configure and gate them | ||
The practical read: pick on features, price and residency, but treat the compliance work — consent, masking, DPIA, disclosure — as identical and non-negotiable across all three. Your choice of vendor barely changes your obligations.
The failure that actually gets sites in trouble
Here's the gap between "we have a consent banner" and "we're actually compliant," and it's the most useful thing in this guide. The problem is almost never the tool. It's a mismatch between what your banner says and what your network actually does.
Your consent management platform lists session replay under "analytics," your privacy policy describes opt-out rights, and your banner looks perfect. But if the replay script still loads before consent — or keeps firing after a visitor clicks Reject — then your behavior contradicts your UI. That's the same problem as a misconfigured ad pixel: policy and interface say one thing, the network tab says another.
This mismatch doesn't depend on whether you chose Hotjar, Clarity or FullStory. It depends on tag order, how your CMP categorizes the script, whether a rescan re-enabled it, and whether someone in marketing added the snippet outside your tag manager. Which is exactly why you can't assume — you have to verify what fires, on the live site, in both the pre-consent and post-Reject states.
Does your replay script wait for consent? Find out.
The only way to know whether Hotjar, Clarity or FullStory is recording before consent is to test the live site. See which trackers fire before consent on your site, in about 10 seconds — no account.
Scan your site free →The bigger risk US sites miss: CIPA
If your visitors include Americans, GDPR is only half the story — and the half most guides stop at. In the United States, session replay is the single biggest target of a wave of wiretapping lawsuits, and clearing GDPR does nothing to clear it.
The vehicle is the California Invasion of Privacy Act (CIPA), a 1967 anti-wiretapping law. Plaintiffs' firms argue that when a session replay tool captures a visitor's keystrokes and interactions and transmits them to a third-party vendor before consent, it's an unlawful "interception" — a wiretap. The tools named throughout these complaints are exactly the ones in this guide: Hotjar, FullStory, Microsoft Clarity, Mouseflow and others. Crucially, the tools aren't the defendant — the website running them before consent is. The statute carries a private right of action and statutory damages of $5,000 per violation under Cal. Penal Code §637.2.
Two clarifications keep this accurate rather than alarmist. First, the tools are legal — recording with prior consent is a defensible position; the lawsuits target "record first, ask second." Second, California's SB 690, which passed the legislature in August 2026 and awaits the Governor's signature, would narrow one theory (the pen-register claim under §638.51) but explicitly leaves the core §631 wiretapping theory intact — so session-replay claims continue regardless. Beyond California, similar wiretap statutes in Pennsylvania and Florida, plus the federal Wiretap Act, extend the exposure. You can watch these cases develop on our CIPA Lawsuit Tracker, and we go deeper on the tool-specific angle in is Hotjar illegal? and the complete CIPA compliance guide.
How to use session replay compliantly
The good news is that because GDPR and CIPA converge on the same requirement, the compliance recipe is a single checklist rather than two. If you want to keep the insight session replay gives you without the exposure, this is the shape of it.
That last point — verify, don't assume — is where a prevention-first consent layer earns its place. This is exactly what ConsentPixel — Privacy · Verified is built to do: it blocks session replay tools like Hotjar, Clarity and FullStory until a visitor consents, keeps them working normally for visitors who do agree, logs each consent event with a timestamp, and lets you see what really fires on the live site. You keep the analytics you rely on; the recording just waits for permission. This is information, not legal advice — but "recording with prior consent" is the defensible position, and prevention is how you get there.
What it means for your website
Session replay is genuinely useful — it shows you why visitors hesitate, misclick and abandon in a way plain analytics can't. You don't have to give that up. What you have to change is the order of operations: let visitors choose first, record second.
Boiled down, session replay GDPR compliance — and CIPA safety alongside it — comes to one behavior you can verify rather than hope for: no recording until consent, proven on the live site. Everything else (DPIA, masking, DPAs, disclosure) is important supporting paperwork, but the recording-before-consent question is the one that turns into fines and lawsuits. Get that right for Hotjar, Clarity or FullStory and you're aligned with EU law and defended against the US wiretapping wave at the same time. This is general information, not legal advice; consult qualified counsel for your specific setup.
Frequently asked questions
Is session replay legal under GDPR?
Yes, session replay is legal under GDPR — but recording a visitor before they consent generally is not. Tools like Hotjar, Microsoft Clarity and FullStory are lawful products; what determines whether your deployment complies is how and when you run them. Because session replay captures behavioral data (clicks, scrolls, keystrokes, form inputs) that constitutes personal data, GDPR requires a lawful basis, which for this kind of pervasive recording means explicit opt-in consent before the script fires — plus a DPIA, input masking, a data-processing agreement, and disclosure in your privacy policy. This is general information, not legal advice.
Is Microsoft Clarity GDPR compliant?
Clarity gives you the controls to be compliant, but it is not automatically GDPR compliant just because you install it — and being free doesn't change that. Microsoft describes Clarity as "GDPR and CCPA ready," but that's a vendor compliance claim, not a regulator's certification; your consent banner and configuration still decide the outcome. Clarity records individual sessions (triggering the same consent and Article 35 DPIA obligations as paid tools) and processes data on US Azure infrastructure, so EU use also needs a transfer mechanism such as Standard Contractual Clauses. You must gate the script behind opt-in consent and mask sensitive fields.
Do I need consent for Hotjar or FullStory in the EU?
Yes. For visitors in the EEA, UK and Switzerland, session replay tools like Hotjar and FullStory require explicit opt-in consent before the recording script loads. Session replay captures personal data, and legitimate interest is generally not considered a sufficient lawful basis for recording this intrusive. In practice that means gating the script through your consent management platform so it stays silent until the visitor accepts, and confirming it stops on reject and Global Privacy Control. Bundling replay silently under "analytics" or letting it run on page load does not meet the consent requirement.
Does session replay require a DPIA?
Generally yes. Recording individual user sessions at scale is considered "large-scale systematic monitoring," which is a specific trigger for a Data Protection Impact Assessment under GDPR Article 35. This obligation applies regardless of which tool you use and regardless of price — Microsoft Clarity triggers the same DPIA duty as Hotjar or FullStory despite being free. A DPIA documents what you record, why, the risks to individuals, and the safeguards (like masking and consent gating) you've put in place. It's both a compliance requirement and a useful exercise for spotting gaps before a regulator or plaintiff does.
Can session replay tools get me sued in the US?
They can be the basis of a lawsuit if you record before consent. Session replay is the leading target of website wiretapping litigation under California's Invasion of Privacy Act (CIPA), which carries a private right of action and statutory damages of $5,000 per violation under Cal. Penal Code §637.2. Plaintiff firms use automated tools to find sites running Hotjar, Clarity or FullStory and send demand letters. The key point: the tools are legal, and the claim targets the website that ran them before getting consent — not the vendor. Recording with prior consent is a defensible position. This is general information, not legal advice.
How do I use session replay without the legal risk?
Make one behavior true and verifiable: nothing records until the visitor consents. Concretely — load your consent banner first and keep the replay script silent until opt-in; genuinely gate the script (not just categorize it) so it stops on reject and Global Privacy Control; mask passwords, payment and PII fields on your real forms; complete a DPIA and sign the vendor's data-processing agreement with transfer safeguards for US-hosted tools; disclose the vendor in your privacy policy; and keep timestamped consent logs while periodically verifying what actually fires on your live site. Because GDPR and CIPA both require consent before recording, this single recipe addresses both.
The bottom line
Session replay isn't the villain, and you don't have to abandon Hotjar, Clarity or FullStory to stay on the right side of the law. The entire question of session replay GDPR compliance — and the US wiretapping risk that rides alongside it — reduces to one thing: does the recording wait for consent?
Everything else is supporting cast. The DPIA, the masking, the DPAs and the privacy-policy disclosure all matter, but the recording-before-consent question is what turns into GDPR enforcement and CIPA lawsuits. And it's not a legal question you have to guess at — it's a technical fact about your site you can test.
Let visitors choose first and record second, prove it on the live site, and you've solved for the EU and the US at the same time.
See when your replay script fires
ConsentPixel — Privacy · Verified blocks session replay tools until consent, keeps them working for visitors who agree, and logs every event. Start by seeing what fires before consent on your site — then a 14-day trial.
Scan your site free →Information, not legal advice. This guide explains session replay under the GDPR and related US law for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Session replay tools — including Hotjar, Microsoft Clarity and FullStory — are lawful products; legal risk arises from how and when they are deployed, and specific obligations depend on your configuration, your visitors and your jurisdictions. Vendor "GDPR-ready" statements are the vendors' own claims, not regulatory certifications. Facts, dates and case references reflect publicly reported information as of September 2026 and may change — including the status of California's SB 690, which awaited the Governor's signature at the time of writing. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Consult qualified counsel for your situation. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law.