Dental website user behaviour analysis: what visitors do, and what you may record
Last reviewed against the regulators’ own text, linked in the sources below.
This is general information, not legal advice.
On this page
Dental website user behaviour analysis means looking at what visitors actually do on your site: which pages they read, where they leave, how far they scroll and what they tap. It shows you where the site loses people, but not why. On a dental site one of its tools, session recording, can capture data about a patient's health, so it needs a data protection decision before anyone switches it on.
Behaviour data is how you check whether you have a site that carries the strategy. Below is what each source shows, and my position on recording.
What behaviour data can and cannot tell you
Behaviour data is the record of actions on the page: page views, clicks, scrolls, form starts. It's good at "where" and poor at "why". It also stops at the edge of the website, so it never sees the phone call to reception the next morning.
| Question | Can behaviour data answer it? | Where the answer lives |
|---|---|---|
| Which page do visitors leave from? | Yes | GA4 paths and funnels |
| Do they reach the fees section? | Yes | Scroll depth, heatmaps |
| Do they tap the phone number? | Yes, if the tap is tracked as an event | GA4 events |
| Why did they leave? | No | Reception notes, patient questions, enquiry calls |
| Did the visit lead to a booked treatment? | No, not on its own | Your practice management system (PMS) |
Behaviour data tells you where to look. Bookings tell you whether a change worked.
Paths and drop-off in GA4
GA4 is Google Analytics 4, Google's free analytics tool. Two of its reports do most of the work.
A path exploration shows the sequence of pages or events visitors follow, forwards from a starting page or backwards from an ending point1. Working back from the booking confirmation shows which treatment pages feed it.
A funnel exploration shows the steps towards a goal and how many visitors fall out at each. GA4 allows up to 10 steps, and a visitor who misses a step isn't counted in later ones2.
Drop-off is the share of visitors who leave between one step and the next. The biggest drop is the first page to look at. Building these reports is covered in explorations and funnels in GA4.
Two limits apply. GA4 only sees visitors your cookie setup lets it see; how consent affects what analytics can see covers that. And Google's policy is that nothing it could recognise as personally identifiable reaches it, with its help page warning that page URLs and titles are where this often slips through3. A confirmation URL carrying a patient's email address is one way. Check yours.
Heatmaps and scroll depth
A heatmap is an image of a page coloured by where visitors clicked, tapped or scrolled, added up across many visits. Scroll depth is how far down a page a visitor got.
GA4's enhanced measurement scroll event fires once, when a visitor reaches 90 per cent of the page height4. That shows who reached the bottom, nothing about the middle. Google Tag Manager's scroll depth trigger fires at percentages you choose5, enough to see whether visitors reach the fees on an implant page.
Heatmaps need a separate tool, such as Microsoft Clarity or Hotjar. In both, heatmaps and recordings come from the same script67, so the consent question below applies to heatmaps too.
| On a treatment page, check | Report | What it can reveal |
|---|---|---|
| Do visitors reach the price? | Scroll depth, scroll map | Fees placed too low on the page |
| Do they tap things that are not links? | Click map | Text that looks like a button, such as "finance options" |
| Do they tap the phone number or the booking button? | Click map, GA4 events | Which route patients prefer on that page |
| Where does attention stop on a phone? | Scroll map on mobile | A long introduction pushing the answer out of view |
Session recordings and patient data
A session recording is a replay of one visitor's visit: pages, scrolling, taps and mouse movement, rebuilt so you can watch it like a video. It's the most detailed behaviour data there is, which is the problem on a dental site.
My position: I do not switch on session recording until the practice has made a written data protection decision, and I never record a visitor who has not agreed to it.
PECR. The Privacy and Electronic Communications Regulations cover any technology that stores or reads information on a visitor's device. The ICO's guidance, updated 29 April 20268, names scripts, cookies and local storage among them9. The analytics exemption is narrow: the sole purpose must be statistics about how the site is used, to improve it10, and visitors must be told and given a simple, free way to object. In my reading, watching one visit back isn't statistics, so recording needs consent.
UK GDPR special category data. Health data is personal data about physical or mental health, "including the provision of health care services", that reveals someone's health status. The ICO's examples include appointment details11. A recording of someone on your booking page, or typing into a "tell us about your problem" box, sits very close to that line. Special category data needs a lawful basis under Article 6 and a separate condition under Article 9. The ICO says explicit consent must be a clear statement, specify the nature of the data, and be separate from other consents12. An "accept all" cookie click is a weak fit. Whether another Article 9 condition applies is for your data protection adviser, not me.
Risk assessment. The ICO's list of processing likely to result in high risk includes tracking behaviour online, with web tracking as an example13. A data protection impact assessment (DPIA), the written risk assessment UK GDPR expects in such cases, is where this decision belongs.
What the tools do today
Checked against vendor documentation on 1 October 2026.
| Microsoft Clarity | Hotjar | |
|---|---|---|
| Default masking | Balanced mode: numbers and email addresses masked, other page text shown14 | User input suppressed; on-page numbers and email addresses suppressed; other text shown unless you turn on text suppression7 |
| Form fields | Input boxes and drop-downs masked in all modes14 | Keystrokes suppressed by default7 |
| Page addresses | URL parameter masking on request to support; referrer and clicked URLs not masked6 | Unverified |
| Without consent | Consent signals enforced for UK visitors from 31 October 2025. With no consent, no cookies, but page views and basic interactions are still collected156 | Help pages point you to stopping the tracking code loading until a visitor accepts16 |
| Recording retention | 30 days; favourites and a random sample up to 9 months6 | 365 days17 |
Two rows matter most. Clarity's default shows the words on the page, and the page address (a dentures page, say) says something about the visitor. And Clarity's consent mode controls cookies, not collection. PECR covers reading from a device as well as storing on it, so I stop the script loading at all until the visitor agrees. Banner and tag setup is on the cookie consent page.
Turning what you see into fixes
A finding is a guess until a change proves it. I make one change at a time and judge it against booked consultations, not clicks.
| What you see | Possible cause to test | Change to try |
|---|---|---|
| Few visitors reach the fees section | Price buried under long introduction | Short price summary near the top |
| Taps on "finance options" text | Visitors expected a link | Link it to finance details |
| Funnel drop between booking page and confirmation | Booking widget hard to use on a phone | Test the booking on a phone yourself |
| Paths loop between two treatment pages | Visitors cannot tell the treatments apart | A comparison section on both pages |
| High exits from the contact page | Form asks too much too early | Fewer required fields |
Testing changes like these without fooling yourself is covered in conversion rate optimisation for a practice site. Behaviour analysis is one part of what an engagement includes, alongside tracking that joins visits to bookings.
If you want to know how your site's paths, funnels and recording setup hold up, email me at Fayez@imfayez.com with your web address. The first look is free: I go through your site's key paths from the outside and reply with what I find. You can read how I work first.
Sources
-
Google Analytics Help: Path exploration, accessed 1 October 2026. ↩
-
Google Analytics Help: Funnel exploration, accessed 1 October 2026. ↩
-
Google Analytics Help: Best practices to avoid sending personally identifiable information, accessed 1 October 2026. ↩
-
Google Analytics Help: Enhanced measurement events, accessed 1 October 2026. ↩
-
Tag Manager Help: Scroll depth trigger, accessed 1 October 2026. ↩
-
Microsoft Learn: Clarity, frequently asked questions, accessed 1 October 2026. ↩ ↩2 ↩3 ↩4
-
Hotjar Help: How to suppress text, images, videos and user input from collected data, accessed 1 October 2026. ↩ ↩2 ↩3
-
ICO: Guidance on the use of storage and access technologies, last updated 29 April 2026, accessed 1 October 2026. ↩
-
ICO: What are storage and access technologies?, accessed 1 October 2026. ↩
-
ICO: What are the exceptions?, accessed 1 October 2026. ↩
-
ICO: What is special category data?, last updated 9 April 2024, accessed 1 October 2026. ↩
-
ICO: What are the conditions for processing?, last updated 18 December 2023, accessed 1 October 2026. ↩
-
ICO: Examples of processing likely to result in high risk, accessed 1 October 2026. ↩
-
Microsoft Learn: Clarity, masking content, accessed 1 October 2026. ↩ ↩2
-
Microsoft Learn: Clarity, Consent Mode, accessed 1 October 2026. ↩
-
Hotjar Help: Cookies set by the Hotjar tracking code, accessed 1 October 2026. ↩
-
Hotjar Help: Privacy FAQs, accessed 1 October 2026. ↩