Frequently asked questions
Answers on data protection, compliance, and our service – straight to the point.
Search
About heyData
Which systems can I connect to heyData?
Which systems can I connect to heyData?
heyData offers more than 50 integrations for HR systems, cloud infrastructures, and code repositories. These include Personio, Workday, BambooHR, Google Workspace, AWS, GitHub, and GitLab.
How does heyData stay up to date?
How does heyData stay up to date?
Our team monitors relevant developments around information security, data protection and AI. Changes flow into templates, workflows, and content so your compliance process doesn't become outdated after the initial setup.
Data Protection
What happens in the event of a data security breach?
What happens in the event of a data security breach?
You must assess and document the incident and inform the FDPIC if there's a high risk for the individuals affected. A clear incident response process helps you react quickly and cleanly.
Are standard templates sufficient for TOMs?
Are standard templates sufficient for TOMs?
In most cases, no. Security measures must fit your company's actual processes, the systems in use, and its individual risk.
Does every company need technical and organizational measures (TOMs)?
Does every company need technical and organizational measures (TOMs)?
Yes. As soon as personal data is processed, companies must define suitable technical and organizational measures to protect data appropriately and meet regulatory requirements.
Does heyData also review existing DPAs?
Does heyData also review existing DPAs?
Yes. Our data protection experts review existing contracts for completeness, potential weaknesses, and any need for adjustment in light of current regulatory requirements.
When do I need a Data Processing Agreement (DPA)?
When do I need a Data Processing Agreement (DPA)?
A DPA is always required when external service providers process personal data on your behalf — for example, with cloud tools, CRM systems, hosting providers, or external IT service providers.
What sets heyData apart from a law firm or a freelance DPO?
What sets heyData apart from a law firm or a freelance DPO?
Law firms and freelance DPOs provide ad-hoc advice — expensive, manual, and hard to scale. heyData is a platform with a team of experts: automation for day-to-day operations, human expertise for exceptional cases. You get both — without paying a law firm's hourly rate for routine tasks.
Can I combine GDPR management with ISO 27001 or NIS2 later?
Can I combine GDPR management with ISO 27001 or NIS2 later?
Yes — that's the core of our modular approach. Work you invest in GDPR automatically flows into ISO 27001 and NIS2. You start with what's pressing today. You build a foundation that lasts.
What happens if the GDPR or relevant court rulings change?
What happens if the GDPR or relevant court rulings change?
Nothing you'd have to do yourself. Our legal team continuously monitors legislation and regulatory practice. Relevant changes flow into your platform as guided updates. You'll be informed — and only need to confirm, not rebuild.
Does heyData also act as an external data protection officer?
Does heyData also act as an external data protection officer?
Yes. heyData can take on the role of external data protection officer for your company.
You get not just software but also an experienced data protection team at your side. We support you with ongoing GDPR obligations, data subject requests, documentation, vendor reviews, and Data Protection Impact Assessments.
The platform provides structure. Our team of experts provides professional guidance.
Whistleblowing
Can I book the tool as a standalone product?
Can I book the tool as a standalone product?
Yes, the whistleblowing solution can also be booked independently of the rest of the compliance suite.
Is the report really anonymous?
Is the report really anonymous?
Yes. No login or personal details are required; whistleblowers receive an individual access key for anonymous follow-up contact.
Which companies are required to set up a whistleblowing tool?
Which companies are required to set up a whistleblowing tool?
Companies with 50 or more employees are required to provide an internal, secure reporting channel.
What is a whistleblowing tool?
What is a whistleblowing tool?
A whistleblowing tool helps employees securely report observed legal violations to a trusted person within the company — required by law under the German Whistleblower Protection Act.
ISO 27001
Can we connect heyData to our existing tools?
Can we connect heyData to our existing tools?
Yes. heyData offers integrations with numerous tools such as AWS Cloud, Microsoft 365, Google Workspace, Jira, Slack, and more. This way, relevant information flows directly into your ISMS.
What happens after certification?
What happens after certification?
ISO 27001 isn't a one-off project. Your ISMS needs to be maintained, monitored, and continuously improved. heyData supports you with tasks, reminders, monitoring, and structured documentation for follow-up audits.
Is heyData only for ISO 27001, or also for NIS2?
Is heyData only for ISO 27001, or also for NIS2?
heyData combines ISO 27001, NIS2, and GDPR on one platform. Thanks to multi-framework mapping, you reuse your work multiple times instead of creating the same evidence over and over.
Do I need my own InfoSec staff?
Do I need my own InfoSec staff?
No. That's exactly why heyData combines software with experts. You need an internal point of contact and the capacity to implement recommendations, but no security team. We support you with structure, documentation, measures, and audit preparation.
How long does ISO 27001 certification take with heyData?
How long does ISO 27001 certification take with heyData?
That depends on your scope, company size, and existing security structure. With heyData, you're audit-ready faster because tasks, evidence, and responsibilities come together in one place instead of being scattered across different tools and Excel files. In the quick check, we'll give you a realistic assessment of your starting position.
NIS2 Compliance
Does heyData support reporting obligations under NIS2?
Does heyData support reporting obligations under NIS2?
Yes. heyData helps you prepare reporting channels, responsibilities, and documentation for security incidents. For significant security incidents, NIS2 requires, among other things, early reports and follow-up reports, so having a prepared process is crucial.
Does heyData also cover supplier risks?
Does heyData also cover supplier risks?
Yes. heyData includes vendor management with questionnaires, risk assessments, tracking, and a database with information on 4,000+ service providers. This lets you document which service providers are relevant, which risks exist, and which measures have been agreed.
Do we also need a law firm or external consultants?
Do we also need a law firm or external consultants?
For many operational steps, what you mainly need is structure: workflows, content created by experts, responsibilities, evidence — and specialists who support you with implementation. heyData brings both, including its own in-house lawyers.
How quickly can we get started with heyData?
How quickly can we get started with heyData?
A structured start is possible at any time: connect your tools, let the software identify gaps, prioritize measures, and define responsibilities. Full NIS2 compliance isn't a one-time checkbox, but an ongoing process — heyData helps you set it up cleanly and manage it verifiably.
What happens if we don't implement NIS2?
What happens if we don't implement NIS2?
The risk isn't just a fine. Management is liable for implementation — with their personal assets. Without demonstrable measures, clear responsibilities, reporting channels, and documentation are also missing when it matters most. For essential entities, NIS2 provides for fines of up to €10 million or 2% of global annual turnover; for important entities, at least up to €7 million or 1.4%.
Does NIS2 really apply to our company if we're not a critical infrastructure operator?
Does NIS2 really apply to our company if we're not a critical infrastructure operator?
Yes, that may well be the case. NIS2 is considerably broader than earlier critical infrastructure rules. Key factors include your industry, company size, and the type of services you provide. SaaS, cloud, IT, and digital service providers in particular should carefully check whether they're affected.
AI Compliance
Can we start with AI compliance and add GDPR, ISO 27001, or NIS2 later?
Can we start with AI compliance and add GDPR, ISO 27001, or NIS2 later?
Yes. heyData is built as a compliance suite. You can start with your most urgent topic and connect additional compliance areas later.
How does heyData differ from traditional consulting?
How does heyData differ from traditional consulting?
Consulting can be very helpful on a case-by-case basis. heyData complements this approach with a platform where you can permanently manage AI systems, assessments, measures, and documentation.
Do all AI systems need to be extensively documented?
Do all AI systems need to be extensively documented?
No. The scope depends on risk category, area of use, and role. heyData helps you capture these differences cleanly and derive suitable next steps.
Does heyData also help if we don't yet know which AI tools are being used in the company?
Does heyData also help if we don't yet know which AI tools are being used in the company?
Yes. That's exactly what the AI inventory is for as a first step. You identify which systems are already in use, who's responsible, and where a closer look is needed.
What's the difference between a provider and a deployer?
What's the difference between a provider and a deployer?
A provider develops an AI system or places it on the market. A deployer uses an AI system under its own responsibility. Different obligations may apply depending on the role.
We only use AI through third-party tools. Are we still affected?
We only use AI through third-party tools. Are we still affected?
Yes, that's possible. Even companies that don't develop AI systems themselves can have certain obligations as deployers. What matters is what the AI system is used for and in what context.
When does the EU AI Act apply?
When does the EU AI Act apply?
The EU AI Act takes effect in stages. The first rules, such as those on prohibited AI practices and AI literacy, have applied since February 2, 2025. Further obligations follow depending on role, system type, and risk category until the act applies in full. That's why it pays to start early with an AI inventory, role clarification, and risk assessment.
Still have questions?
Our team will answer your questions directly – personally and to the point.
No commitment. 15 minutes is all it takes.