Privacy

Cookie Consent and Session Replay — How to Set It Up Correctly (and Why You See No Data)

How to connect your cookie banner to session replay and heatmaps—consent-required vs legitimate interest, wiring the consent call, popular CMPs, and fixing "installed but no sessions."

Purushottam Kumar Suman
Purushottam Kumar SumanSeptember 19, 20269 min read
Founder & CEO, DeepSync
Cookie consent banner connected to session replay

Here's the most common support question for any session replay tool: "I installed the script, but I see no sessions." In most cases, the script is working perfectly—it's waiting for consent that never arrives.

This guide explains how consent works for session replay and heatmaps, and how to wire it correctly.

Table of Contents

  1. Consent Modes Explained
  2. Wiring the Consent Call
  3. Popular Consent Platforms
  4. Testing Your Setup
  5. Consent Rate and Data Gaps
  6. Key Takeaways
ModeBehaviorWhen it's used
Consent-required (default)Nothing is collected until a consent signal arrivesGDPR, DPDP, and other opt-in regimes
Legitimate interestRecords without waiting for a signalOnly where your legal basis supports it

DeepSync projects default to consent-required. Whether legitimate interest is lawful for you depends on jurisdiction, your privacy notice, and what you capture—a decision for your legal counsel. See consent modes.

When a visitor accepts analytics cookies, call:

deepsync("consent", true);

When they withdraw:

deepsync("consent", false);

Withdrawing stops recording immediately.

Remember returning visitors

Your banner usually doesn't reappear for visitors who already accepted. Make sure the consent call also fires on page load when stored consent exists—not only on the click.

Most consent management platforms (CookieYes, Cookiebot, OneTrust, Complianz, and others) offer either:

  • Callbacks / events when consent changes — call the consent function there.
  • Script blocking by category — make sure DeepSync is assigned to the right category (e.g., analytics/statistics) so it loads after consent.

With Google Tag Manager, ensure the tag is allowed to fire under its consent category and add a consent tag or trigger. See heatmaps via GTM.

Testing Your Setup

  1. Open your site in a private window.
  2. Decline → browse → confirm no session appears.
  3. Open a new private window, accept → browse → confirm the session appears.
  4. Revisit in the same window → confirm recording continues without clicking the banner again.
  5. Withdraw → confirm recording stops.

If sessions still don't appear, see I installed the snippet but see no data.

With consent-required mode, your recordings represent visitors who accepted. That's fine for finding UX problems—friction affects everyone—but remember:

  • Session counts will differ from server logs or other tools (why numbers differ).
  • Banner design affects consent rates; a clear, honest banner performs better than dark patterns.
  • Masking still applies to consenting visitors—inputs, passwords, and payment fields are masked by default.

Key Takeaways

  • "Installed but no data" is usually a missing consent call.
  • Wire consent on accept and on page load for returning visitors.
  • Configure your CMP category so the script can load.
  • Test decline, accept, revisit, and withdraw.

Conclusion

Get consent right once and your replay data will be both lawful and complete for the visitors who agreed. It's a ten-minute setup that saves days of confusion.

Start free.

Frequently Asked Questions

Was this article helpful?

Ready to understand
users like never before?

Join thousands of teams who use DeepSync to uncover insights,improve experiences, and build better products—faster.

Quick & easy onboarding
See results in real time
Enterprise-grade security