Hotjar made heatmaps and session recordings accessible to small businesses: you see where visitors click, how far they scroll and where they give up. For a shop or a lead-generation site, that is often more actionable than a traffic dashboard. So the question “is Hotjar GDPR compliant?” deserves a straight answer rather than a scare.
Hotjar is one of the easier behaviour-analytics tools to use lawfully in Europe, because its data is stored in the EU. But it still needs prior consent, and that part is entirely your responsibility.
What has changed about Hotjar
A bit of context first, because many guides are out of date:
- Hotjar was acquired by Contentsquare in 2021, and Contentsquare says it integrated all of Hotjar’s tools into the Contentsquare platform in 2024. It also states plainly that you can no longer sign up for Hotjar.
- Existing Hotjar installs still run the classic tracking code, which loads from
static.hotjar.com. Newer Contentsquare installs use a different tag, loaded fromt.contentsquare.netaccording to Contentsquare’s documentation. Look at your own snippet before following any guide, including this one.
What Hotjar does well for GDPR
Credit where it is due. Hotjar’s help centre states that the user and usage data it collects is stored in Ireland, on Amazon Web Services’ eu-west-1 data centres. For a small European business, that removes most of the international transfer headache that comes with US-hosted analytics. Hotjar also notes that some of its sub-processors are located outside the EU, so read its data processing agreement and list them in your privacy policy.
Hotjar acts as your processor: you decide what is recorded and why. That makes you responsible for two things no storage location can solve, consent and what ends up in the recordings.
Why Hotjar still needs consent
Hotjar’s tracking code writes first-party cookies whose names begin with _hj, including an identifier that recognises a returning visitor on your site and a session cookie that groups page views, and it keeps data in the browser’s local storage. That is “storing information in the terminal equipment” of the visitor.
Article 5(3) of the ePrivacy Directive makes this conditional on consent given beforehand, with an exception only for what is strictly necessary to provide the service the visitor asked for. A heatmap helps you improve your site; the visitor did not ask for it. In practice: Hotjar must not load until the visitor has accepted, and a banner that appears while Hotjar is already recording is in breach from the first page view.
- Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing.
— ePrivacy Directive, Article 5(3)
Could Hotjar qualify for an analytics exemption? Some regulators exempt audience measurement under strict conditions. The French CNIL’s conditions limit the purpose to audience measurement and A/B testing, require the tracker to serve a single publisher, the last byte of the IP address to be truncated and cookies to last at most 13 months, and the CNIL notes that most large audience measurement offerings fall outside the exemption whatever their configuration. Do not build your compliance on an exemption Hotjar does not claim. Ask for consent.
How the WebLegal cookie banner handles Hotjar
Our free cookie consent banner (CCB) ships with Hotjar in its catalogue, in the analytics category. Here is exactly what it does:
- Detection. Two signatures:
[./]hotjar\.com(?![\w-]), which catches any request tohotjar.comand its subdomains, and[./]static\.hotjar\., which catches the script host. A request to a lookalike domain such ashotjar.com-somethingis not matched, because of the boundary at the end. - Blocking before consent. The Hotjar script is held until the visitor accepts analytics. Nothing is recorded for a visitor who refuses or ignores the banner.
- Withdrawal. If a visitor withdraws consent, the banner deletes the
_hjcookies on your domain and the_hjkeys in local and session storage. Deleting the cookie alone would leave Hotjar’s identifier alive in storage.
One honest limitation. The Contentsquare tag (t.contentsquare.net) is not in our automatic catalogue yet. If that is what your site loads, neutralise it so the browser cannot fetch it before consent, and let the banner release it on acceptance:
<script type="text/plain"
data-wl-src="https://t.contentsquare.net/uxa/YOUR_TAG_ID.js"
data-wl-category="analytics"></script>
A tag with a non-executable type is never downloaded by the browser; the banner restores it, in place, once the visitor accepts the category you declared. Keep the configuration lines of your original snippet (the window._uxa queue) in a normal inline script: they set no cookie and contact no server on their own.
Whatever the tag, the banner itself must be the first script in your <head>, without defer or async, and never injected by a tag manager. It can only block what has not been requested yet.
Recordings: the part consent does not fix
Consent covers the cookies. It does not make it acceptable to record everything a visitor types. Before you switch recordings on, check that form fields with personal data (names, emails, addresses, anything health- or payment-related) are masked in your Hotjar or Contentsquare settings, and keep recordings only as long as you actually use them.
Check your site
- Open your site in a fresh browser profile, DevTools open, before clicking the banner.
- Network tab: any request to
hotjar.comorcontentsquare.netat this point is a request sent without consent. - Application tab: no
_hjcookie and no_hjlocal storage key should exist yet.
Or run our free GDPR compliance checker: it loads your page as a first-time visitor and lists the trackers that fire before consent.
Declare it properly
Hotjar must be listed in your cookie policy (purpose, provider, cookies, retention) and in your privacy policy (processor, data stored in the EU, sub-processors). Every WebLegal pack includes both documents, from the Essential pack at €19.90.
Hotjar rarely travels alone. If you also use Microsoft’s free alternative, read Microsoft Clarity and GDPR; for the full list of services a banner must hold back, see the 37 trackers your cookie banner must block.