A cookie banner that is part of your privacy documentation.

heyData creates your GDPR-compliant cookie consent text as part of your existing privacy policy – tailored, categorized, and managed by a data protection expert.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
book a free consultation
Dashboard mit Datenschutzstatus, Dokumenten, Anbietern, Schulungen und Auditdiagramm.
Certified and recognized.
OMR Reviews Auszeichnung als führend in Datenschutzmanagement für Q1 2026.
Capterra Logo mit 4,9 von 5 Sternen Bewertung.
Compliance that scales with you.

Stay compliant with ease – no matter the size.

2,500+
Companies that Trust heyData
28,000+
Completed Compliance Trainings
4.400+
Pre-filled Vendor Assessments
50+
Integrations for Your Existing Systems
The problem

A cookie banner alone doesn't make you compliant.

Incorrectly categorized

A technically necessary cookie that is classified as optional – or vice versa – makes the entire banner vulnerable.

Without a legal basis

A banner text that suggests consent but does not specifically meet the requirements of the GDPR and TTDSG.

Disconnected from documentation

A banner that does not match the privacy policy immediately raises questions during any audit.

Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

Four components, one result: a banner that lasts.

01

Digital Audit

We conduct an annual review to identify which cookies are actually active on your website and categorize them correctly.

02

Categorization Support

If you are unsure about specific cookies, we will classify them for you and highlight any potential risks.

03

Banner Consulting

We guide the design and implementation of your cookie banner, including all legally required content.

04

Privacy Policy

Your cookie banner and your privacy policy speak the same language – because they come from a single source.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Request now
PROCESS

Set up once, monitored continuously.

1. Audit

We identify which cookies are actually active on your website.

2. Categorization

Every cookie is correctly classified according to its purpose and legal basis.

3. Text & Banner

Your cookie consent text is created to match your privacy policy, not in isolation from it.

4. Ongoing audit

We re-examine your cookies annually for any changes and update the documentation accordingly.

FAQ

FAQs

Can't find what you're looking for? Our team will get back to you within one business day.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Ask our team

What's the difference between the cookie text and the cookie policy?

The cookie text is the short notice in the banner. The cookie policy explains in detail how your company handles personal data.

Isn't a generic cookie banner generator enough?

A generator doesn't know the cookies you actually use. Without an audit, the categorization remains a guess — and that's exactly what gets questioned in an inspection.

How often does the cookie text need to be updated?

At least once a year, and whenever the tools or cookies you use change. We check this as part of the ongoing audit.

Does this also apply to third-party cookies?

Yes. Cookies from third-party services must also be disclosed and correctly categorized.

What happens if a cookie was categorized incorrectly?

We correct the classification, adjust the banner and privacy policy accordingly, and point out any risks arising from the previous categorization.

How do cookie banners and tracking tools need to be set up in e-commerce?

Tracking and analytics tools such as Google Analytics or marketing pixels may only be loaded after the website visitor has explicitly consented via a GDPR-compliant consent management system. A mere notice without a genuine option to decline, or with pre-selected checkboxes, doesn't meet the legal requirements and constitutes a data protection violation.

Is implied consent sufficient for cookies?

As a rule, no. For cookies that aren't technically necessary, active express consent is usually required.

Build once, cover many standards.

Your GDPR work directly translates to other regulations. See how much you have already covered with heyData.

datenschutz
Verlauf von blau zu grün mit weichem, gebogenen Design.
Kreisdiagramm mit grünem Fortschrittsbalken, der 78 Prozent anzeigt.

GDPR

Risk assessments, TOMs, and policies from your GDPR work are integrated directly. No double work.

Learn more
infosec
Blauer und grüner Farbverlauf mit geschwungener Wellenform unten auf schwarzem Hintergrund.
Kreisdiagramm mit 54% grün hervorgehobenem Fortschritt.

ISO 27001 & ISMS

Risk assessments, technical and organizational measures, and policies from your GDPR work are integrated directly. No double work.

Learn more
infosec
Blauer und grüner Farbverlauf mit unregelmäßiger Wellenlinie in der Mitte.
Kreisdiagramm zeigt 38% in grün und 62% in grau.

NIS2 Compliance

Reporting obligations, incident response, and supply chain management build directly on your GDPR foundation.

Learn more
ai & governance
Kreisdiagramm mit grünem Abschnitt, der 22 Prozent anzeigt.

EU AI Act

Data protection impact assessments and documentation requirements draw directly on existing GDPR processes.

Learn more
Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

Ready to get started?

No commitment. 15 minutes is all it takes.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Request now
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
View pricing

Book a demo, ask questions, compare prices – we are here to help.