Glosario de privacidad y consentimiento
Definiciones breves y claras de los términos del consentimiento de cookies y el cumplimiento en privacidad.
Términos más buscados
Conceptos clave explicados en una frase.
- CMP: software que recoge, almacena y aplica el consentimiento del visitante para cookies y rastreadores.
- Google Consent Mode v2: estándar de señalización que indica a las etiquetas de Google si se permite el almacenamiento analítico y publicitario.
- IAB TCF v2.2: marco del sector publicitario para transmitir el consentimiento a proveedores ad-tech.
- Responsable del tratamiento: quien decide por qué y cómo se tratan los datos, normalmente el titular del sitio.
- Encargado del tratamiento: quien trata los datos siguiendo instrucciones del responsable, por ejemplo Cookietrace.
- Registro de consentimiento: prueba con marca de tiempo de qué aceptó el visitante y cuándo.
Cómo funciona Cookietrace
Un único script se instala en unos 3 minutos, directamente o mediante Google Tag Manager. Escanea el sitio en busca de cookies, píxeles y uso de almacenamiento, clasifica cada rastreador, muestra el banner en el idioma del visitante y solo después permite las etiquetas no esenciales. Los reescaneos periódicos avisan cuando aparece un rastreador nuevo.
- Descubrimiento automático de cookies, píxeles y fingerprinting con reescaneos programados.
- Categorías granulares: necesarias, funcionales, analíticas, marketing y sociales.
- Señales de Google Consent Mode v2 e IAB TCF v2.2 incluidas.
- Bloqueo opcional de solicitudes de rastreadores rechazados en el navegador.
- Registros de consentimiento firmados y con sello de tiempo, conservados más de 3 años.
Normativas cubiertas
RGPD y ePrivacy para la UE y Reino Unido, KVKK y la guía de cookies de 2022 para Turquía, CCPA/CPRA para California, además del soporte de divulgación del artículo 50 de la Ley de IA. El banner, la retención y la prueba de consentimiento siguen la norma de la jurisdicción del visitante.
Planes y precios
Precio mensual en USD, según el número de dominios: Pro: $39/mes · Premium: $79/mes · Enterprise: precio a medida. Todos los planes mantienen las funciones de cumplimiento; la prueba de 14 días no requiere tarjeta.
Empresa
Cookietrace by Ezeratech Digital (EZERA DIGITAL TECHNOLOGIES FZCO), fundada en 2024. Oficinas: IFZA Business Park, Dubai Silicon Oasis, Dubai (AE) · İstanbul (TR) · London (GB). Interfaz y soporte en inglés, turco, español e italiano. Contacto: [email protected] (ventas), [email protected] (soporte), [email protected] (privacidad).
KVKK
Turkey's Personal Data Protection Law (Law No. 6698). Defines principles and procedures for processing personal data in Türkiye.
GDPR
General Data Protection Regulation (EU 2016/679). The EU's comprehensive data protection regulation governing personal data of EU citizens.
ePrivacy Direktifi
EU Directive 2002/58, known as the 'Cookie Law'. Regulates privacy in cookies and electronic communications.
CCPA
California Consumer Privacy Act. US state law granting California consumers control over their personal data.
CMP
Consent Management Platform. A system that displays banners, records user preferences and runs scripts conditionally on consent.
IAB TCF v2.2
IAB Transparency & Consent Framework v2.2. The standard consent signaling protocol for the EU advertising ecosystem.
DPO
Data Protection Officer. The independent corporate role responsible for GDPR/KVKK compliance.
VERBİS
Türkiye's Data Controllers Registry maintained by the KVKK Authority.
Açık Rıza (Explicit Consent)
Specific, informed and freely given consent for a defined purpose. The central requirement of KVKK.
Aydınlatma Yükümlülüğü
Türkiye's KVKK obligation to inform data subjects about purpose, scope and rights when collecting data.
Veri Sorumlusu
The natural or legal person who determines the purposes and means of processing personal data (GDPR 'controller').
Veri İşleyen
The party that processes personal data on behalf of the data controller (GDPR 'processor').
Birinci Taraf Çerez
A cookie set directly by the domain the user is visiting.
Üçüncü Taraf Çerez
A cookie set by a domain different from the one being visited (typically for advertising or analytics).
Zorunlu Çerez
Cookies strictly necessary for basic site functions. Do not require consent but require disclosure.
Performans Çerezi
Cookies collecting anonymous/aggregated analytics about site usage (e.g. Google Analytics).
Pazarlama Çerezi
Cookies used for ad targeting, retargeting and profile building. Explicit consent required.
Fonksiyonel Çerez
Cookies that remember user preferences such as language, region or theme.
Pixel / Tracking Pixel
A 1x1 image or code snippet embedded in a page to track user actions (Meta Pixel, TikTok Pixel, etc.).
Fingerprinting
Identifying users by combining browser/device attributes without cookies. Requires consent under KVKK/GDPR.
Server-side Tracking
Tracking approach where requests are sent via the server instead of the browser. A foundational technology for the cookieless era.
Privacy Sandbox
Google's set of privacy-preserving advertising APIs for a post-3rd-party-cookie world (Topics, FLEDGE, etc.).
Topics API
A Privacy Sandbox browser API enabling interest-based ads without tracking individual users.
Dark Pattern
Manipulative UI designs (e.g. hiding the 'Reject' button). Banned under KVKK and GDPR.
Prior Consent
The principle of obtaining user consent BEFORE placing cookies. A core rule of ePrivacy and KVKK.
Consent Logs
Timestamped records of when each user gave which choice on which banner version. Required for audits.
Cryptographic Proof of Consent
Hash/signature-based structure that mathematically proves consent records are tamper-free.
Cookie Wall
A barrier forcing users to accept cookies. Considered invalid by the EDPB.
Geo-targeting
Showing different banners/rules based on user country (e.g. GDPR for EU, KVKK for TR visitors).
Right to be Forgotten
GDPR Article 17. The right to request deletion of one's personal data. KVKK Article 7 contains a similar right.
DPIA
Data Protection Impact Assessment. Required for high-risk processing activities.
Data Subject
The natural person whose personal data is processed (KVKK 'data subject').
Lawful Basis
One of the six legal grounds defined in GDPR/KVKK for processing data (consent, contract, legitimate interest, etc.).
Sensitive Data
Special category personal data such as health, ethnicity, religion, biometrics. Subject to stricter protection.
Data Breach
Unauthorized access, alteration or disclosure of personal data. KVKK requires notification within 72 hours.
Cross-border Transfer
Transfer of personal data abroad. Requires additional safeguards and consent under KVKK.
Aydınlatma Metni
The disclosure document published by data controllers as required by KVKK Article 10.
EU AI Act
EU Artificial Intelligence Act (Regulation 2024/1689). The world's first comprehensive AI law, regulating AI systems by risk tier. Article 50 transparency obligations become enforceable on 2 August 2026.
Article 50 (AI Act)
The transparency article of the EU AI Act. Four obligations: (1) chatbot disclosure, (2) AI-generated content marking, (3) emotion-recognition notice, (4) deepfake labelling.
AI Disclosure
The mechanism that explicitly informs a user they are interacting with AI, or that a piece of content was AI-generated. Required by laws such as the EU AI Act and California SB 942.
Deepfake
AI-generated or manipulated video/audio/image content that appears authentic. EU AI Act Article 50(4) requires a visible label.
Watermark (AI)
A mark embedded in AI-generated content, detectable by humans or machines. Article 50(2) mandates a machine-readable version.
C2PA
Coalition for Content Provenance and Authenticity. Open metadata standard that proves the provenance of AI-generated media. The de facto standard for EU AI Act compliance.
Generative AI (GenAI)
AI models that generate text, image, video or audio (ChatGPT, Gemini, Claude, Midjourney etc.). Subject to special obligations under the EU AI Act.
Companion Chatbot
An AI chatbot designed for persistent, personal conversation with a user. Oregon SB 1546 and Washington HB 2225 require disclosure.
Emotion Recognition System
An AI system that infers a person's emotions or intentions from biometric data. EU AI Act Article 50(3) requires the exposed person to be informed.
California SB 942
California AI Transparency Act. Requires GenAI providers with 1M+ monthly users to offer watermarks, an AI detection tool and latent disclosure. Enforcement: 2 August 2026.
Colorado AI Act
SB 24-205. Requires risk management and consumer disclosure for high-risk AI systems making consequential decisions in education, employment, healthcare and more. Enforcement: 30 June 2026.
TRAIGA
Texas Responsible Artificial Intelligence Governance Act (HB 149). In force since 1 January 2026; covers anyone with Texas users.
Digital Omnibus
7 May 2026 EU agreement. Shortened the grace period for systems on the market before 2 August 2026 under EU AI Act Article 50 from 6 to 3 months; deadline 2 December 2026.
Territorial Scope
The principle defining which companies a law covers geographically. GDPR and the EU AI Act cover all companies with EU users, regardless of where they are established.