Data Exfiltration by Hotjar Revisited
Libor Pol\v{c}\'ak, Alexandra Slez\'akov\'a

TL;DR
This paper revisits Hotjar's data collection practices, revealing persistent privacy issues despite policy changes, and discusses technical and legal improvements needed to better protect user privacy.
Contribution
It updates previous findings on Hotjar's data collection, highlighting ongoing privacy concerns and proposing technical and legal measures to enhance user privacy protections.
Findings
Hotjar records user behavior outside input elements despite policy changes.
Encrypted connections and Do Not Track signals are not fully effective in preventing data collection.
Legal obligations for data processors should be extended under GDPR.
Abstract
Session replay scripts allow website owners to record the interaction of each web site visitor and aggregate the interaction to reveal the interests and problems of the visitors. However, previous research identified such techniques as privacy intrusive. This position paper updates the information on data collection by Hotjar. It revisits the previous findings to detect and describe the changes. The default policy to gather inputs changed; the recording script gathers only information from explicitly allowed input elements. Nevertheless, Hotjar does record content reflecting users' behaviour outside input HTML elements. Even though we propose changes that would prevent the leakage of the reflected content, we argue that such changes will most likely not appear in practice. The paper discusses improvements in handling TLS. Not only do web page operators interact with Hotjar through…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Privacy, Security, and Data Protection · Advanced Malware Detection Techniques
