See it liveHow it worksPacksQuestionnairesTrustYour recordPricingFree toolsBlogSign inStart free
All posts

Hotjar and UK GDPR: session recording, consent, and your obligations

7 September 20267 min read

Being asked about your Hotjar setup by a customer?

That question is usually one row of a security questionnaire. Paste or upload the one they sent and see every row classified, free, no account. Check the questionnaire

If you have Hotjar running on your website and a customer has just asked for your data protection documents, there is a good chance you have a gap. Session recording is not a grey area under UK law. It requires consent before the script fires, a signed data processing agreement, and entries in your record of processing. Most small businesses have none of these.

Here is what the rules actually say, what a sophisticated buyer will check, and what you need to fix before the deal stalls.

---

What Hotjar actually does with your visitors' data

Hotjar records mouse movements, clicks, scrolls, and navigation paths for every visitor it captures. According to Hotjar's own documentation, when you use Hotjar to record and collect data from your site, Hotjar takes on the role of the Data Processor, which means you are the owner and Controller of the data.

That distinction matters. Hotjar processes data on your behalf. The legal obligations for getting consent, managing withdrawal, and enabling access requests sit with you, not with Hotjar.

Hotjar sets persistent identification cookies and records detailed user sessions including mouse movements and clicks, transmitting that behavioural data to external servers. That puts it firmly in the analytics consent category. It is not strictly necessary for your site to function, which means it cannot load until a visitor has actively consented.

Hotjar does anonymise IP addresses by removing the last octet, and keyboard input on form fields is suppressed by default. But the session recording itself, the visual replay of what a visitor did on your page, still captures behavioural data tied to a persistent cookie identifier. That is personal data under UK GDPR Article 4(1).

---

The two laws you are dealing with: PECR and UK GDPR

In the UK, session recording tools like Hotjar are caught by two overlapping laws.

PECR (Privacy and Electronic Communications Regulations 2003), Regulation 6 is the first hurdle. PECR prohibits storing or accessing information on a user's device unless you have given them clear and comprehensive information about your purposes and obtained their consent. Hotjar sets cookies. That means PECR applies before you even get to UK GDPR.

UK GDPR then governs what you do with the personal data those cookies help collect. Once personal data is collected through those technologies, UK GDPR governs how that data is processed and protected. The ICO's position is that if you need PECR consent to place the cookie, consent is also the appropriate lawful basis under UK GDPR for the associated processing. Trying to apply another lawful basis such as legitimate interests when you already have GDPR-compliant consent would cause confusion for your users.

The practical upshot: you cannot run Hotjar on a legitimate interests basis. You need opt-in consent, obtained before the script loads.

Valid consent must be freely given, specific, informed, and unambiguous, with no implied consent or pre-ticked options. The "strictly necessary" exception is narrow: analytics, A/B testing, personalisation, and advertising tracking almost always need opt-in consent. Session recording sits squarely in that category.

---

The DPA: what Hotjar provides and what you need to know

A Data Processing Agreement (DPA) is the contract between you (the controller) and Hotjar (the processor) that UK GDPR Article 28 requires you to have in place. Without it, your processing of visitor data via Hotjar has no contractual foundation.

Hotjar's DPA is incorporated by reference into its Terms of Service. The DPA is incorporated by reference into Hotjar's Terms of Service and forms part of your agreement with Hotjar. You do not sign a separate document. Accepting Hotjar's Terms of Service is deemed acceptance of the DPA.

Hotjar is now part of Contentsquare. Hotjar's legal overview points the data processing agreement at Contentsquare's privacy centre, and that published document is the governing one. The DPA works by incorporation rather than signature: entering the agreement is deemed to be signing the incorporated Standard Contractual Clauses.

For UK businesses, the transfer mechanism matters too. Hotjar processes data on servers within the EEA, but its sub-processors include US-based infrastructure providers. If you are situated in the United Kingdom, Module 4 of the Standard Contractual Clauses shall apply together with the UK Addendum to the Standard Contractual Clauses in relation to the transfer of personal data from the United Kingdom. This is the correct mechanism: the UK Addendum works alongside the European Commission's Standard Contractual Clauses, adapting them so they can also support transfers governed by UK data protection law.

The sub-processor list. Hotjar is now part of Contentsquare, and the list of sub-processors applicable to Hotjar features has been consolidated into the unified Contentsquare sub-processors list, available at contentsquare.com/privacy-center/subprocessors/. In the case of a change in sub-processors, Hotjar will inform customers of the new sub-processor in writing ten days in advance of the change. You should check that list, record the sub-processors in your own record of processing, and note the transfer mechanism for any that sit outside the UK or EEA.

---

What a buyer's due diligence will actually ask

When a larger business asks for your GDPR documents, the questions about Hotjar tend to cluster around three things.

First, your lawful basis for session recording. They want to see that you have consent, not legitimate interests. If your privacy notice says "we use Hotjar on the basis of legitimate interests", that is a red flag to any privacy-aware procurement team. It signals that you have not engaged with PECR at all.

Second, the DPA with Hotjar. They will ask whether you have a signed DPA with every vendor that processes personal data on your behalf. The answer for Hotjar is: yes, it is incorporated into the Terms of Service, the governing document is the Contentsquare DPA, and the URL is contentsquare.com/privacy-center/data-processing-agreement/. You need to be able to say that clearly, not fumble around looking for a PDF.

Third, the transfer mechanism. If your buyer has a UK GDPR-aware legal team, they will ask how data transfers to Hotjar's sub-processors are covered. The answer is the EU SCCs with UK Addendum, as set out in the Contentsquare DPA. If you cannot name the mechanism, they will assume you have not checked.

Your record of processing (the Article 30 record, sometimes called an RoPA) should list Hotjar as a processor, record the categories of data (behavioural data, device data, cookie identifiers), the lawful basis (consent), and the transfer mechanism. If that record does not exist, or if Hotjar is not in it, that is the gap a buyer will find.

---

What the common failure looks like

Here is the pattern that comes up repeatedly with small businesses using Hotjar.

The script was installed by a developer two or three years ago. It went live the same day. There was no cookie banner, or the cookie banner was already ticked by default, or Hotjar was lumped under "analytics" with no explanation of what session recording means. The privacy policy mentions Hotjar in a list of third-party tools but does not explain the lawful basis or the transfer mechanism.

When a customer sends a security questionnaire, the operations lead goes to the Hotjar settings page, sees that the DPA is "included in the Terms of Service", and writes "yes, DPA in place" on the questionnaire. That answer is technically defensible but incomplete. It does not address the consent question, the sub-processor list, the transfer mechanism, or whether Hotjar is in the record of processing.

The buyer's legal team then asks a follow-up: "Can you provide the URL of the DPA, confirm the lawful basis for session recording, and list the sub-processors and their transfer mechanisms?" At that point, the operations lead is stuck. The deal waits three weeks while someone figures out what to say.

The other failure is consent implementation. You cannot set non-essential cookies on your website's homepage before the user has consented to them. If Hotjar fires on page load before the cookie banner is accepted, the consent is invalid regardless of what your privacy policy says. To achieve PECR compliance, you must block non-essential tags until consent is given. That means your consent management platform (CMP) must be configured to gate Hotjar behind an explicit accept action.

---

What to do about it

Work through this in order.

1. Check whether Hotjar fires before consent. Open your site in a private browser window. Before accepting any cookie banner, open your browser's developer tools and look at the network requests. If you see requests to static.hotjar.com or script.hotjar.com before you have clicked accept, your CMP is misconfigured. Fix that first.

2. Check your consent banner. The reject option must be as prominent as the accept option. A buried "manage preferences" link does not satisfy the freely-given standard. A cookie banner with a clear accept button but a buried reject option does not provide valid consent.

3. Update your privacy notice. It should name Hotjar, describe session recording in plain English ("we record mouse movements and clicks to understand how visitors use our site"), state that the lawful basis is consent, name the transfer mechanism (EU SCCs with UK Addendum), and link to the Contentsquare sub-processor list.

4. Add Hotjar to your record of processing. Your Article 30 record should include: the processing activity (session recording and heatmaps), the categories of data subjects (website visitors), the categories of personal data (behavioural data, device data, cookie identifiers), the processor (Contentsquare / Hotjar), the DPA reference (Contentsquare DPA, June 2026), the transfer mechanism (EU SCCs with UK Addendum), and the retention period (Hotjar retains recordings data for 365 days from date of capture).

5. Know your DPA URL. The governing document is at contentsquare.com/privacy-center/data-processing-agreement/. The sub-processor list is at contentsquare.com/privacy-center/subprocessors/. Write these down somewhere you can find them when a questionnaire lands.

6. Check suppression settings. Session recordings may inadvertently capture sensitive information displayed on screen, including personal details, financial data, and health information. Review Hotjar's suppression configuration to make sure form fields containing personal data are masked.

If a customer has already sent you a questionnaire asking about this, you need answers that are specific, not vague. "We use Hotjar under consent" is not an answer. "We obtain opt-in consent via [CMP name] before Hotjar fires, the DPA is the Contentsquare DPA at [URL], the transfer mechanism is EU SCCs with UK Addendum, and Hotjar is recorded in our Article 30 record" is an answer.

If you need to pull all of this together into a supplier pack or into drafted answers for the questionnaire you have been sent, Rowpa reads your website, drafts your record of processing, and turns it into the pack or the questionnaire answers the other side wants. You can also use it to answer a security questionnaire directly in the other side's own layout. Build your whole record free, no card. Pay only when you send something.

---

Sources

---

This post is for information only and does not constitute legal advice.

Further reading