Are session replays GDPR compliant? A practical guide
Session replays are the fastest way to see why visitors leave. They also record behaviour on your site, which is exactly what privacy law cares about. Here's what to check before you press record.

Short answer: session replays can be used in line with the GDPR, but no tool is compliant on its own — your setup is. Mask what visitors type, don't tie recordings to identities, keep them only as long as you need, host them in the EU, and in most cases ask for consent before recording. This guide is practical information, not legal advice: check your setup with your data protection officer.
What the law actually looks at
A session replay is not a video. It's a reconstruction of the page from events: scrolls, clicks, taps, page changes. Two sets of rules can apply to it.
- The GDPR applies as soon as you process personal data, meaning anything that can identify a person directly or indirectly.1 A recording on its own may not identify anyone. A recording that captures a typed email address, a customer ID in the URL or a name on an account page does.
- The ePrivacy rules (the "cookie law") apply to storing or reading information on the visitor's device — cookies, but also local storage and similar techniques — whether or not the data is personal.2
So the two questions are: could this recording identify someone? and does the tool store or read anything on the device?
When you need consent
The ePrivacy rules require consent before storing or reading information on a device, except where it is strictly necessary for a service the user asked for. Understanding how visitors use your site is useful to you, but regulators don't usually treat it as strictly necessary for the visitor.
Some regulators carve out an exception for basic audience measurement. France's CNIL, for example, exempts analytics from consent when they are limited to anonymous statistics, strictly for the site owner, with no cross-site tracking and limited retention.3 Session replays go further than aggregate statistics: they follow one visit in detail. The safe default is to record sessions only for visitors who have given consent, and to confirm the specifics for your country with your DPO.
A 7-point checklist before recording
- Mask every input by default. Visitors' keystrokes — emails, addresses, card details, passwords — should never end up in a recording. Check how your tool masks fields and test it on your real forms.
- Exclude sensitive pages. Account areas, order history, anything showing health, financial or personal details: don't record them at all.
- Don't attach identities. Avoid sending names, emails or customer IDs to your replay tool. Anonymous sessions answer the conversion question just as well.
- Keep recordings for a limited time. Decide how long you actually need them to investigate a problem, and set retention to match.
- Host the data in the EU (or in a country with an adequacy decision), and sign a data processing agreement with your provider.4
- Ask for consent where required, and only load the recording script once it is given. Make refusing as easy as accepting.
- Say it in your privacy policy: what you record, why, for how long, and who processes it.
None of this makes replays less useful. To find why visitors leave your website, you need to see hesitation, repeated taps and where attention stops — not who the visitor is.
Lightweight analytics vs replays
A practical setup splits the two:
| Lightweight analytics | Session replays | |
|---|---|---|
| What it gives you | Traffic, sources, pages, goals | The detailed sequence of one visit |
| Stored on the device | Nothing (cookie-less) | Depends on the tool — check |
| Typical consent need | Often none, if anonymous | Consent in most EU setups |
| Who you measure | Every visitor | Visitors who accepted |
You keep complete numbers for everyone, and detailed recordings for the share of visitors who agreed — usually more than enough to spot a pattern. Numbers like bounce and exit rates tell you where to look; the recordings tell you why.
SessionInsight was built for this split. Its lightweight mode stores nothing on the visitor's device and collects no personal data, and you choose the mode per website. Data is hosted by PlanetHoster in France and Switzerland. When you turn on session replays, cover them in your consent flow.
FAQ
Do I need consent to record sessions?
In most EU setups, yes. Recording how a visitor moves, clicks and types goes beyond basic audience measurement, and it usually relies on storing or reading information on the visitor's device. Plan to ask for consent before recording, and confirm the details with your data protection officer.
Is a session replay personal data?
It can be. A recording linked to an identifier, an IP address or anything the visitor typed can identify a person, directly or indirectly. That is why masking inputs and avoiding identifiers matter so much.
Can I use analytics without a cookie banner?
Often, yes, for basic audience measurement that stores nothing on the device and collects no personal data. Some regulators, such as France's CNIL, also exempt certain audience measurement from consent under strict conditions. Session replays are a different matter and should be covered by consent.
Where is SessionInsight data hosted?
SessionInsight is hosted by PlanetHoster in data centres in France and Switzerland. Switzerland benefits from an EU adequacy decision, so data stays within a framework the EU recognises.
Sources
- GDPR, Regulation (EU) 2016/679, Article 4(1) — definition of personal data.
- ePrivacy Directive, Directive 2002/58/EC, Article 5(3).
- CNIL, Cookies : solutions pour les outils de mesure d'audience.
- European Commission, Adequacy decisions.