There is a conversation I have had many times over the last few years, with plenty of people, and I am fairly sure you have had it too. The client has seen a colourful picture somewhere, reds and yellows spread over a homepage, liked it, and asks me to “put one of those on so I can see what visitors do”. And they are right to ask, because the question is a good one. What they do not know is that the expectation usually is not! And on top of that, since last year there is a legal piece to it that changed without anyone noticing.

Let us take it in order, because this stretches across three layers: what you actually see, what that is worth, and what you need in place to see it lawfully.

What these tools really are

Two things, and they may well confuse you. A heatmap is aggregate: it takes thousands of visits and shows you where the clicks landed, how far people scrolled, where the pointer lingered. A session recording is individual: it is video of one specific visit, watched as if you were sitting over someone’s shoulder.

That difference is not a technical footnote, it is the whole matter. The first shows you a pattern. The second shows you a person. And along with the person, whatever they typed, corrected, hesitated over, deleted before sending. Which is why the two are not judged by the same standard, technically or legally.

The number you would like does not exist

Let me say something that does not serve my interests: there is no independent study at all showing that heatmaps or session recordings improve results by any particular percentage. I looked. What circulates, and plenty of it circulates, comes from the vendors of the tools themselves, who have the obvious incentive to convince us.

That does not mean they are useful nowhere. It makes them diagnostic tools, not treatment. They show you where it hurts. They do not perform the operation and they do not promise an outcome. Anyone who quotes you an uplift percentage because they will install a script is selling something that has never been seriously measured.

The five-users myth, and why it is not about you

You will have heard it: “five users reveal 85% of the problems.” It is true, and it is not yours.

The line is Jakob Nielsen’s, from March 2000, and what he describes is that after a first study with five participants you will have found 85% of the usability problems. The critical part is what he means by “study”: a moderated usability test, where you give the user a defined task, watch them, and above all ask them. He does not mean five videos watched passively one afternoon.

In a test you ask. In a recording you guess. The Nielsen Norman Group puts it plainly themselves: analytics tell you what customers are doing, not why they are doing it. And the “why” is precisely what you are paying to find out.

Now the part that changed, unnoticed

On 31 October 2025 Microsoft began enforcing a consent signal requirement in Clarity for visits originating from the EEA, the UK and Switzerland. This is not a lawyer’s reading, it is the product documentation itself: consent mode is enabled by default for users from those regions.

What does that mean in practice? Without explicit consent the tool’s cookies are not used. Page views and basic interactions are still counted, but sessions become fragmented and you lose full replays and journey continuity. Which is to say, exactly what you installed the thing for.

And here is the point worth thinking about for a moment. If you have had Clarity on your site since last year and no consent banner, you are not looking at wrong data. You are looking at less data, without knowing it, and drawing conclusions from it.

Controller or processor? The answer may surprise you

There is a difference between the two most popular tools that almost nobody mentions, and it matters.

Microsoft states that Clarity is GDPR-compliant as a data controller. Hotjar, by contrast, writes in its Data Processing Agreement that you are the Controller and Hotjar the Processor, and that collecting consent, managing its withdrawal and enabling the right of access are your obligations.

Two tools doing apparently the same job, with responsibility allocated differently. That is not a matter of preference, it is a matter of what you are signing and what you are taking on.

In the same spirit, a Hotjar detail that costs people: keystroke data is suppressed by default on all input fields, and suppressed inside the user’s own browser, so it never reaches Hotjar’s servers. Good. But the same documentation states that changing suppression settings does not apply retroactively. What was collected, was collected. So the setting is made before, not when somebody remembers.

What France is preparing, and why it reaches us

The French data protection authority took up these tools specifically. It opened a consultation with the industry in April 2025, then published a draft recommendation on session replay tools, with a public consultation that closed on 22 April 2026.

Note the wording, because it matters: it remains a draft. No final text has been issued to date. So I am not going to tell you that “the CNIL has banned” anything, because it has banned nothing.

What it says is still worth knowing, because it shows the direction of travel. The CNIL points to the large volume of navigation data collected, sometimes without the user’s knowledge, and to the possibility of inferring information about private life from it: habits, interests, in some cases sensitive data. It takes the view that prior consent is required, since these tools neither serve the sole purpose of carrying out the communication nor are strictly necessary for the service. And its draft proposes masking sensitive fields by default, different retention periods per purpose, and separate consent for each purpose.

Let me be honest about one more thing: no decision or fine by any European authority specifically against a session recording tool could be found. The CNIL’s move is so far the only targeted regulatory initiative, and it has not concluded yet.

What applies here

The rule for Greece is not new and it is not the GDPR. It is Article 4(5) of Law 3471/2006, which the Greek authority itself puts as follows: storing and accessing information stored on a user’s terminal equipment is permitted only if the subscriber or user has given consent. The exemption covers only what has the sole purpose of carrying out the transmission of a communication.

A tool that films your session so you can improve a page is not the transmission of a communication. You know it, I know it. And the authority, in its Recommendations 1/2020 of 25 February 2020, has already said that placing a tracker on a terminal device requires, in principle, the user’s consent.

At European level, the EDPB Guidelines 2/2023 on the technical scope of Article 5(3), in version 2.0 adopted on 7 October 2024, expressly cover tracking pixels and JavaScript executed in the browser. I owe you the caveat that they do not name session recording as a separate case. The conclusion that it falls within scope is mine, based on the general principle of the text, and I write it as a conclusion rather than as a quotation.

How we do it, when we do it

I am not against these tools. Used properly they answer questions no chart will answer. They just come with three conditions, and all three are boring: they stay frozen until consent is given, suppression is configured before the first byte is collected, and a retention period is set that bears some relation to why we installed them.

Freezing is not theory, we do it on our own site: our analytics do not load at all until the visitor says yes. It is the same work we do for clients with MS-Consent, and the natural continuation of what we wrote about cookies and the GDPR.

And so we come back again to that colourful picture at the start. It is nice, and it does say something. It just does not say “why”, it has never been shown to sell anything, and it does not go on without asking your visitor first. If you want to see what is actually happening on your site, with the tools set up properly and consent in order, get in touch.