Glossario privacy e consenso
Definizioni brevi e chiare dei termini usati nel consenso ai cookie e nella compliance privacy.
Termini più cercati
Concetti chiave spiegati in una frase.
- CMP: software che raccoglie, conserva e applica il consenso dei visitatori per cookie e tracker.
- Google Consent Mode v2: standard di segnalazione che indica ai tag Google se lo storage analitico e pubblicitario è consentito.
- IAB TCF v2.2: framework del settore pubblicitario per trasmettere il consenso ai fornitori ad-tech.
- Titolare del trattamento: chi decide perché e come trattare i dati, di norma il proprietario del sito.
- Responsabile del trattamento: chi tratta i dati su istruzione del titolare, ad esempio Cookietrace.
- Log del consenso: prova con timestamp di cosa ha accettato il visitatore e quando.
Come funziona Cookietrace
Un solo script si installa in circa 3 minuti, direttamente o tramite Google Tag Manager. Analizza il sito alla ricerca di cookie, pixel e uso dello storage, classifica ogni tracker, mostra il banner nella lingua del visitatore e solo dopo consente i tag non essenziali. Le scansioni periodiche segnalano ogni nuovo tracker.
- Rilevamento automatico di cookie, pixel e fingerprinting con riscansioni programmate.
- Categorie granulari: necessari, funzionali, analitici, marketing, social.
- Segnali Google Consent Mode v2 e IAB TCF v2.2 inclusi.
- Blocco opzionale delle richieste dei tracker rifiutati nel browser.
- Log di consenso firmati e con marca temporale, conservati oltre 3 anni.
Normative coperte
GDPR ed ePrivacy per UE e Regno Unito, KVKK e la guida cookie 2022 per la Turchia, CCPA/CPRA per la California, oltre al supporto per l'informativa dell'articolo 50 dell'AI Act. Banner, conservazione e prova del consenso seguono le regole della giurisdizione del visitatore.
Piani e prezzi
Prezzo mensile in USD, in base al numero di domini: Pro: $39/mese · Premium: $79/mese · Enterprise: prezzo su misura. Tutti i piani mantengono le funzioni di compliance; la prova di 14 giorni non richiede carta.
Azienda
Cookietrace by Ezeratech Digital (EZERA DIGITAL TECHNOLOGIES FZCO), fondata nel 2024. Sedi: IFZA Business Park, Dubai Silicon Oasis, Dubai (AE) · İstanbul (TR) · London (GB). Interfaccia e supporto in inglese, turco, spagnolo e italiano. Contatti: [email protected] (vendite), [email protected] (supporto), [email protected] (privacy).
KVKK
Turkey's Personal Data Protection Law (Law No. 6698). Defines principles and procedures for processing personal data in Türkiye.
GDPR
General Data Protection Regulation (EU 2016/679). The EU's comprehensive data protection regulation governing personal data of EU citizens.
ePrivacy Direktifi
EU Directive 2002/58, known as the 'Cookie Law'. Regulates privacy in cookies and electronic communications.
CCPA
California Consumer Privacy Act. US state law granting California consumers control over their personal data.
CMP
Consent Management Platform. A system that displays banners, records user preferences and runs scripts conditionally on consent.
IAB TCF v2.2
IAB Transparency & Consent Framework v2.2. The standard consent signaling protocol for the EU advertising ecosystem.
DPO
Data Protection Officer. The independent corporate role responsible for GDPR/KVKK compliance.
VERBİS
Türkiye's Data Controllers Registry maintained by the KVKK Authority.
Açık Rıza (Explicit Consent)
Specific, informed and freely given consent for a defined purpose. The central requirement of KVKK.
Aydınlatma Yükümlülüğü
Türkiye's KVKK obligation to inform data subjects about purpose, scope and rights when collecting data.
Veri Sorumlusu
The natural or legal person who determines the purposes and means of processing personal data (GDPR 'controller').
Veri İşleyen
The party that processes personal data on behalf of the data controller (GDPR 'processor').
Birinci Taraf Çerez
A cookie set directly by the domain the user is visiting.
Üçüncü Taraf Çerez
A cookie set by a domain different from the one being visited (typically for advertising or analytics).
Zorunlu Çerez
Cookies strictly necessary for basic site functions. Do not require consent but require disclosure.
Performans Çerezi
Cookies collecting anonymous/aggregated analytics about site usage (e.g. Google Analytics).
Pazarlama Çerezi
Cookies used for ad targeting, retargeting and profile building. Explicit consent required.
Fonksiyonel Çerez
Cookies that remember user preferences such as language, region or theme.
Pixel / Tracking Pixel
A 1x1 image or code snippet embedded in a page to track user actions (Meta Pixel, TikTok Pixel, etc.).
Fingerprinting
Identifying users by combining browser/device attributes without cookies. Requires consent under KVKK/GDPR.
Server-side Tracking
Tracking approach where requests are sent via the server instead of the browser. A foundational technology for the cookieless era.
Privacy Sandbox
Google's set of privacy-preserving advertising APIs for a post-3rd-party-cookie world (Topics, FLEDGE, etc.).
Topics API
A Privacy Sandbox browser API enabling interest-based ads without tracking individual users.
Dark Pattern
Manipulative UI designs (e.g. hiding the 'Reject' button). Banned under KVKK and GDPR.
Prior Consent
The principle of obtaining user consent BEFORE placing cookies. A core rule of ePrivacy and KVKK.
Consent Logs
Timestamped records of when each user gave which choice on which banner version. Required for audits.
Cryptographic Proof of Consent
Hash/signature-based structure that mathematically proves consent records are tamper-free.
Cookie Wall
A barrier forcing users to accept cookies. Considered invalid by the EDPB.
Geo-targeting
Showing different banners/rules based on user country (e.g. GDPR for EU, KVKK for TR visitors).
Right to be Forgotten
GDPR Article 17. The right to request deletion of one's personal data. KVKK Article 7 contains a similar right.
DPIA
Data Protection Impact Assessment. Required for high-risk processing activities.
Data Subject
The natural person whose personal data is processed (KVKK 'data subject').
Lawful Basis
One of the six legal grounds defined in GDPR/KVKK for processing data (consent, contract, legitimate interest, etc.).
Sensitive Data
Special category personal data such as health, ethnicity, religion, biometrics. Subject to stricter protection.
Data Breach
Unauthorized access, alteration or disclosure of personal data. KVKK requires notification within 72 hours.
Cross-border Transfer
Transfer of personal data abroad. Requires additional safeguards and consent under KVKK.
Aydınlatma Metni
The disclosure document published by data controllers as required by KVKK Article 10.
EU AI Act
EU Artificial Intelligence Act (Regulation 2024/1689). The world's first comprehensive AI law, regulating AI systems by risk tier. Article 50 transparency obligations become enforceable on 2 August 2026.
Article 50 (AI Act)
The transparency article of the EU AI Act. Four obligations: (1) chatbot disclosure, (2) AI-generated content marking, (3) emotion-recognition notice, (4) deepfake labelling.
AI Disclosure
The mechanism that explicitly informs a user they are interacting with AI, or that a piece of content was AI-generated. Required by laws such as the EU AI Act and California SB 942.
Deepfake
AI-generated or manipulated video/audio/image content that appears authentic. EU AI Act Article 50(4) requires a visible label.
Watermark (AI)
A mark embedded in AI-generated content, detectable by humans or machines. Article 50(2) mandates a machine-readable version.
C2PA
Coalition for Content Provenance and Authenticity. Open metadata standard that proves the provenance of AI-generated media. The de facto standard for EU AI Act compliance.
Generative AI (GenAI)
AI models that generate text, image, video or audio (ChatGPT, Gemini, Claude, Midjourney etc.). Subject to special obligations under the EU AI Act.
Companion Chatbot
An AI chatbot designed for persistent, personal conversation with a user. Oregon SB 1546 and Washington HB 2225 require disclosure.
Emotion Recognition System
An AI system that infers a person's emotions or intentions from biometric data. EU AI Act Article 50(3) requires the exposed person to be informed.
California SB 942
California AI Transparency Act. Requires GenAI providers with 1M+ monthly users to offer watermarks, an AI detection tool and latent disclosure. Enforcement: 2 August 2026.
Colorado AI Act
SB 24-205. Requires risk management and consumer disclosure for high-risk AI systems making consequential decisions in education, employment, healthcare and more. Enforcement: 30 June 2026.
TRAIGA
Texas Responsible Artificial Intelligence Governance Act (HB 149). In force since 1 January 2026; covers anyone with Texas users.
Digital Omnibus
7 May 2026 EU agreement. Shortened the grace period for systems on the market before 2 August 2026 under EU AI Act Article 50 from 6 to 3 months; deadline 2 December 2026.
Territorial Scope
The principle defining which companies a law covers geographically. GDPR and the EU AI Act cover all companies with EU users, regardless of where they are established.