Cookie Consent and Session Replay — How to Set It Up Correctly (and Why You See No Data)
How to connect your cookie banner to session replay and heatmaps—consent-required vs legitimate interest, wiring the consent call, popular CMPs, and fixing "installed but no sessions."
Here's the most common support question for any session replay tool: "I installed the script, but I see no sessions." In most cases, the script is working perfectly—it's waiting for consent that never arrives.
This guide explains how consent works for session replay and heatmaps, and how to wire it correctly.
Table of Contents
- Consent Modes Explained
- Wiring the Consent Call
- Popular Consent Platforms
- Testing Your Setup
- Consent Rate and Data Gaps
- Key Takeaways
Consent Modes Explained
| Mode | Behavior | When it's used |
|---|---|---|
| Consent-required (default) | Nothing is collected until a consent signal arrives | GDPR, DPDP, and other opt-in regimes |
| Legitimate interest | Records without waiting for a signal | Only where your legal basis supports it |
DeepSync projects default to consent-required. Whether legitimate interest is lawful for you depends on jurisdiction, your privacy notice, and what you capture—a decision for your legal counsel. See consent modes.
Wiring the Consent Call
When a visitor accepts analytics cookies, call:
deepsync("consent", true);When they withdraw:
deepsync("consent", false);Withdrawing stops recording immediately.
Remember returning visitors
Your banner usually doesn't reappear for visitors who already accepted. Make sure the consent call also fires on page load when stored consent exists—not only on the click.
Popular Consent Platforms
Most consent management platforms (CookieYes, Cookiebot, OneTrust, Complianz, and others) offer either:
- Callbacks / events when consent changes — call the consent function there.
- Script blocking by category — make sure DeepSync is assigned to the right category (e.g., analytics/statistics) so it loads after consent.
With Google Tag Manager, ensure the tag is allowed to fire under its consent category and add a consent tag or trigger. See heatmaps via GTM.
Testing Your Setup
- Open your site in a private window.
- Decline → browse → confirm no session appears.
- Open a new private window, accept → browse → confirm the session appears.
- Revisit in the same window → confirm recording continues without clicking the banner again.
- Withdraw → confirm recording stops.
If sessions still don't appear, see I installed the snippet but see no data.
Consent Rate and Data Gaps
With consent-required mode, your recordings represent visitors who accepted. That's fine for finding UX problems—friction affects everyone—but remember:
- Session counts will differ from server logs or other tools (why numbers differ).
- Banner design affects consent rates; a clear, honest banner performs better than dark patterns.
- Masking still applies to consenting visitors—inputs, passwords, and payment fields are masked by default.
Key Takeaways
- "Installed but no data" is usually a missing consent call.
- Wire consent on accept and on page load for returning visitors.
- Configure your CMP category so the script can load.
- Test decline, accept, revisit, and withdraw.
Conclusion
Get consent right once and your replay data will be both lawful and complete for the visitors who agreed. It's a ten-minute setup that saves days of confusion.
Frequently Asked Questions
Related articles
Stay in the loop
Get the latest insights on product analytics and user behavior delivered to your inbox.



