Session Replay and Privacy: The Wiretap Risk

Summary
Session-replay tools record what a visitor does on your site, their clicks, scrolling, mouse movement, and often keystrokes and form entries, so you can play the session back. They also draw wiretap lawsuits. When a third-party replay vendor captures activity without consent, plaintiffs argue it is an unauthorized interception, the theory behind the California Invasion of Privacy Act pixel cases.
The privacy problem is not that replay exists. It is what replay can quietly capture: what someone typed into a form before submitting, a card number, a health detail, or a search, recorded and sent to an outside vendor.
The sections below explain why session replay is a privacy risk and how the wiretap theory applies to it. They finish with how to reduce your exposure and how to check your session-replay setup.
Why session replay is a privacy risk
Two things make replay riskier than an ordinary analytics tag.
It captures content, not just events. A page-view tag records that a page loaded. A replay tool can record the actual keystrokes and field entries on that page, which means it can pick up personal, financial, or health information a visitor typed, sometimes even data they entered and then deleted before submitting.
It involves a third party. Most replay tools are run by an outside vendor, and the recording is sent to that vendor’s systems. Under wiretap laws, that third-party involvement is the core of the claim: your site let someone else listen in on the visitor’s interaction without consent.
The wiretap theory applied to replay
Session replay is the clearest fit for the California Invasion of Privacy Act’s Section 631, which prohibits helping a third party read the contents of a communication without consent. A replay vendor recording a visitor’s activity in real time is exactly the “eavesdropping” the argument targets. CIPA does not require a plaintiff to show financial loss, though the interception must be willful or intentional, and it sets statutory damages per violation. Related state wiretap laws create similar exposure elsewhere, with limits: in 2025 the Ninth Circuit dismissed a session-replay wiretap suit (Popa v. Microsoft, under Pennsylvania’s wiretap law) because ordinary browsing data was not a concrete injury, while noting sensitive medical or financial data could be different.

For specific session-replay lawsuits and settlements, see our Enforcement Watch tracker.
How to reduce session-replay exposure
Three controls address the fact pattern.
Get consent before replay starts. A replay tool that waits for consent removes the “without permission” element the wiretap claim depends on.
Mask sensitive fields. Configure the tool so it never records form fields that carry personal, financial, or health data. Masking is the difference between a behavior recording and a data leak.
Verify what it actually captures. Masking is only as good as its configuration, and a form added later, or a field renamed, can slip through. The exposure lives in what the tool records, so it has to be checked.
How to check your session-replay setup
DataTrue loads your site in a real browser and records what the replay tool captures and sends, including whether it fires before consent and whether it is picking up form field contents it should be masking. Sensitive Data Detection inspects those payloads with fictitious personas, so you can see whether a card number, email, or health detail is reaching the replay vendor without ever using a real visitor. The result is a record of where your replay tool is capturing more than it should, and confirmation once the masking is fixed.
See how consent verification works
Questions
Is session replay legal?
As a tool, yes. The exposure comes from running it without consent and from capturing sensitive data. Session replay draws wiretap class actions under laws like CIPA because a third-party vendor records a visitor’s activity, which plaintiffs argue is an unauthorized interception when there is no consent.
Why is session replay a wiretap risk?
Because a replay tool records the contents of a visitor’s interaction and sends it to an outside vendor. Wiretap laws like CIPA’s Section 631 prohibit helping a third party read a communication without consent, and a replay recording fits that theory closely.
What data can session replay accidentally capture?
Keystrokes and form entries, which can include names, emails, card numbers, and health details, sometimes even data a visitor typed and deleted before submitting. Masking sensitive fields is meant to prevent this, but it has to be configured correctly and verified.
How do I make session replay compliant?
Get consent before it starts, mask fields that carry personal, financial, or health data, and verify with testing that it is not recording sensitive content or firing before consent. The exposure is in what it captures, so checking the actual recording is what proves it is safe.
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
