What is the _pk_hsr cookie?
_pk_hsr is a first-party cookie set by the Matomo Tag Manager script or matomo.js when the Heatmap & Session Recording feature is enabled for a site. The cookie's full name includes a numeric or alphanumeric suffix identifying the specific Matomo site/instance in use (hence the "prefix" in its base name).
It typically appears on the visitor's first interaction with the page, provided the site owner has enabled heatmap or session recording collection for that domain — whether through Matomo Cloud or a self-hosted Matomo instance.
What data it stores
The cookie stores a short identifier tied to the current heatmap/session-recording session, used to link successive interactions (mouse movements, clicks, scrolling) to the same visitor session without duplicating them across multiple recordings.
The exact value format can vary depending on the Matomo version in use. The interaction data collected during the session is sent to the Matomo server — either Matomo Cloud's infrastructure or the site's own server, if it runs a self-hosted installation.
What it is used for
The cookie's purpose is strictly technical: it lets Matomo's Heatmap & Session Recording module correctly reconstruct a single browsing session, avoiding double-counting or misattributing interactions to the wrong session.
For site owners, this data helps understand actual visitor behavior — where they click, how far they scroll, where they hesitate — information used to optimize page layout and conversions.
Does it require consent?
Under CookieFix's classification, _pk_hsr falls under the statistics (analytics) category. Because it records individual visitor behavior (heatmap and, potentially, session playback), it does not qualify for the strictly-necessary exemption under the ePrivacy Directive (transposed in Romania via Law 506/2004) and requires prior user consent under GDPR and ANSPDCP requirements.
- Site owners must disclose the cookie in their cookie policy under the "statistics" category.
- The Matomo script (including the Heatmap & Session Recording module) must only load after explicit consent is obtained.
- It's also worth checking the Matomo configuration (IP anonymization, Do Not Track support), which affects the overall compliance assessment.
How to block or delete _pk_hsr
A visitor can delete the _pk_hsr cookie via browser settings (site data/cookies) or decline the "statistics" category in the consent banner, if the site offers that option. Tracker-blocking browser extensions and private/incognito mode also prevent it from being set.
For site owners, the safest approach is to technically block the Matomo script until consent is given, rather than just hiding the feature visually. A CMP platform like CookieFix can do this automatically, preventing the Matomo/Heatmap script from loading before the visitor accepts the statistics category.
Frequently asked questions
It's a cookie set by Matomo for the Heatmap & Session Recording feature, used to identify the visitor's current browsing session.
Yes, as an analytics/statistics cookie that records visitor behavior, it requires prior consent under ePrivacy and GDPR.
It typically lasts 30 minutes, aligned with the duration of a browsing session.
The most effective way is to use a CMP that blocks the Matomo Heatmap & Session Recording script from loading until the visitor accepts the statistics category.