A cookie banner that is part of your privacy documentation.

heyData creates your GDPR-compliant cookie consent text as part of your existing privacy policy – tailored, categorized, and managed by a data protection expert.

book a free consultation
Certified and recognized.
Compliance that scales with you.

Stay compliant with ease – no matter the size.

2,500+
Companies that Trust heyData
28,000+
Completed Compliance Trainings
4.400+
Pre-filled Vendor Assessments
50+
Integrations for Your Existing Systems
The problem

A cookie banner alone doesn't make you compliant.

Incorrectly categorized

A technically necessary cookie that is classified as optional – or vice versa – makes the entire banner vulnerable.

Without a legal basis

A banner text that suggests consent but does not specifically meet the requirements of the GDPR and TTDSG.

Disconnected from documentation

A banner that does not match the privacy policy immediately raises questions during any audit.

Four components, one result: a banner that lasts.

01

Digital Audit

We conduct an annual review to identify which cookies are actually active on your website and categorize them correctly.

02

Categorization Support

If you are unsure about specific cookies, we will classify them for you and highlight any potential risks.

03

Banner Consulting

We guide the design and implementation of your cookie banner, including all legally required content.

04

Privacy Policy

Your cookie banner and your privacy policy speak the same language – because they come from a single source.

Request now
PROCESS

Set up once, monitored continuously.

1. Audit

We identify which cookies are actually active on your website.

2. Categorization

Every cookie is correctly classified according to its purpose and legal basis.

3. Text & Banner

Your cookie consent text is created to match your privacy policy, not in isolation from it.

4. Ongoing audit

We re-examine your cookies annually for any changes and update the documentation accordingly.

FAQ

FAQs

Can't find what you're looking for? Our team will get back to you within one business day.

Ask our team

What's the difference between the cookie text and the cookie policy?

The cookie text is the short notice in the banner. The cookie policy explains in detail how your company handles personal data.

Isn't a generic cookie banner generator enough?

A generator doesn't know the cookies you actually use. Without an audit, the categorization remains a guess — and that's exactly what gets questioned in an inspection.

How often does the cookie text need to be updated?

At least once a year, and whenever the tools or cookies you use change. We check this as part of the ongoing audit.

Does this also apply to third-party cookies?

Yes. Cookies from third-party services must also be disclosed and correctly categorized.

What happens if a cookie was categorized incorrectly?

We correct the classification, adjust the banner and privacy policy accordingly, and point out any risks arising from the previous categorization.

How do cookie banners and tracking tools need to be set up in e-commerce?

Tracking and analytics tools such as Google Analytics or marketing pixels may only be loaded after the website visitor has explicitly consented via a GDPR-compliant consent management system. A mere notice without a genuine option to decline, or with pre-selected checkboxes, doesn't meet the legal requirements and constitutes a data protection violation.

Is implied consent sufficient for cookies?

As a rule, no. For cookies that aren't technically necessary, active express consent is usually required.

Build once, cover many standards.

Your GDPR work directly translates to other regulations. See how much you have already covered with heyData.

datenschutz

GDPR

Risk assessments, TOMs, and policies from your GDPR work are integrated directly. No double work.

Learn more
infosec

ISO 27001 & ISMS

Risk assessments, technical and organizational measures, and policies from your GDPR work are integrated directly. No double work.

Learn more
infosec

NIS2 Compliance

Reporting obligations, incident response, and supply chain management build directly on your GDPR foundation.

Learn more
ai & governance

EU AI Act

Data protection impact assessments and documentation requirements draw directly on existing GDPR processes.

Learn more

Ready to get started?

No commitment. 15 minutes is all it takes.

Request now
View pricing

Book a demo, ask questions, compare prices – we are here to help.