Privacy & Compliance
-
A PII Masking Checklist for Session Replay
A field-by-field checklist for masking PII in session replay: inputs, text nodes, URLs, network bodies, third-party widgets, plus a verification step.
-
Is Session Replay Legal? Jurisdiction by Jurisdiction
Session replay is legal in most places with the right setup. Where US wiretap suits and EU consent rules bite, and which configuration choices matter.
-
Session Recording Under GDPR: Lawful, but Only If You Do the Work
Session recording can comply with GDPR: pick a defensible lawful basis, mask PII at capture, set real retention limits, and sort out the vendor DPA.
-
Wiring Session Replay Into Your Consent Banner Correctly
How to gate session replay on consent: start-after-consent pattern with code, buffering tradeoffs, CMP integration, and testing the reject path.
-
How Long to Keep Session Replays (a Retention Policy That Holds Up)
A session replay retention policy that balances support lookback, GDPR storage limitation, and disk cost — with a tiered template and audit notes.
-
Session Replay and HIPAA: Proceed Only With Extreme Care
Why session replay on healthcare apps is high-risk under HIPAA: PHI leaks through DOM capture, most vendors won't sign a BAA, and what's defensible.