A session-recording script captures behaviour inside the page: mouse movement, scrolling, clicks and often keystrokes in form fields, replayable afterwards as a film of the visit.
Why it is a separate entry
This is a different order of collection from counting page views. What someone typed and then deleted, where they hesitated, which field they returned to: none of that is needed to run a website, and all of it is revealing.
How it arises
recording script loaded outside the consent gate
field masking left off, so entered text is captured too
Not to be confused with
Ordinary page-view analytics is not this entry. The distinguishing feature is capture of in-page behaviour.
How to establish it
A request to a session-recording endpoint of a recording vendor, carrying a site identifier, at page load.
method network-with-identifierQoD 95
Requirements on the measurement
clean profile
no interaction
note whether field masking is active; unmasked input raises the stakes considerably
What would refute it
by handThe vendor processes only aggregated data without session capture.finding falls
automatedRecording starts only after consent is granted.finding falls
by handAll input fields are masked at source.weakens
Where this plugs into existing processes
The one question that surfaces itIs anything recording mouse movement or keystrokes, and from what moment?
In a DPIA, verify this
Verify whether in-page behaviour is captured and whether input fields are masked, rather than treating it as analytics.
As a procurement clause
No session recording is active before consent, and where used, input masking is enabled and demonstrated.
With a complaint, hand over
A capture showing the recording endpoint contacted at load, and whether field masking was active.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
repro/web/check.mjs · script · the run reports DPE-2026-0005 as present, with the detail behind it
Third parties that can confirm it: blacklight, urlscan.io
Legal framing
eu-gdpr-6-1-a
nl-tw-11-7a
Objections, and the answer
“The recording servers are in the EU.”
Where the recording is stored says nothing about whether it should have been made. Location is a separate question from lawfulness of collection.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0005: Session recording. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0005
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0005, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.