A cookie banner that is part of your privacy documentation.
heyData creates your GDPR-compliant cookie consent text as part of your existing privacy policy – tailored, categorized, and managed by a data protection expert.


.avif)
Stay compliant with ease – no matter the size.
A cookie banner alone doesn't make you compliant.
Incorrectly categorized
A technically necessary cookie that is classified as optional – or vice versa – makes the entire banner vulnerable.
Without a legal basis
A banner text that suggests consent but does not specifically meet the requirements of the GDPR and TTDSG.
Disconnected from documentation
A banner that does not match the privacy policy immediately raises questions during any audit.

Four components, one result: a banner that lasts.
Digital Audit
We conduct an annual review to identify which cookies are actually active on your website and categorize them correctly.
Categorization Support
If you are unsure about specific cookies, we will classify them for you and highlight any potential risks.
Banner Consulting
We guide the design and implementation of your cookie banner, including all legally required content.
Privacy Policy
Your cookie banner and your privacy policy speak the same language – because they come from a single source.
Set up once, monitored continuously.
We identify which cookies are actually active on your website.
Every cookie is correctly classified according to its purpose and legal basis.
Your cookie consent text is created to match your privacy policy, not in isolation from it.
We re-examine your cookies annually for any changes and update the documentation accordingly.
FAQs
Can't find what you're looking for? Our team will get back to you within one business day.
What's the difference between the cookie text and the cookie policy?
What's the difference between the cookie text and the cookie policy?
The cookie text is the short notice in the banner. The cookie policy explains in detail how your company handles personal data.
Isn't a generic cookie banner generator enough?
Isn't a generic cookie banner generator enough?
A generator doesn't know the cookies you actually use. Without an audit, the categorization remains a guess — and that's exactly what gets questioned in an inspection.
How often does the cookie text need to be updated?
How often does the cookie text need to be updated?
At least once a year, and whenever the tools or cookies you use change. We check this as part of the ongoing audit.
Does this also apply to third-party cookies?
Does this also apply to third-party cookies?
Yes. Cookies from third-party services must also be disclosed and correctly categorized.
What happens if a cookie was categorized incorrectly?
What happens if a cookie was categorized incorrectly?
We correct the classification, adjust the banner and privacy policy accordingly, and point out any risks arising from the previous categorization.
How do cookie banners and tracking tools need to be set up in e-commerce?
How do cookie banners and tracking tools need to be set up in e-commerce?
Tracking and analytics tools such as Google Analytics or marketing pixels may only be loaded after the website visitor has explicitly consented via a GDPR-compliant consent management system. A mere notice without a genuine option to decline, or with pre-selected checkboxes, doesn't meet the legal requirements and constitutes a data protection violation.
Is implied consent sufficient for cookies?
Is implied consent sufficient for cookies?
As a rule, no. For cookies that aren't technically necessary, active express consent is usually required.
Build once, cover many standards.
Your GDPR work directly translates to other regulations. See how much you have already covered with heyData.


GDPR
Risk assessments, TOMs, and policies from your GDPR work are integrated directly. No double work.


ISO 27001 & ISMS
Risk assessments, technical and organizational measures, and policies from your GDPR work are integrated directly. No double work.


NIS2 Compliance
Reporting obligations, incident response, and supply chain management build directly on your GDPR foundation.


EU AI Act
Data protection impact assessments and documentation requirements draw directly on existing GDPR processes.

Ready to get started?
No commitment. 15 minutes is all it takes.
Book a demo, ask questions, compare prices – we are here to help.

