CookieAz – Ley 21.719 Cookie Consent para Chile

Description

CookieAz gets your WordPress site ready for Chile’s Ley 21.719. A cookie banner that blocks third-party scripts until the visitor accepts, and a Wizard that generates your Cookie Policy and your Personal Data Processing Policy.

Key features

  • Cookie consent banner, with two color templates to choose from
  • Automatic blocking of third-party scripts until the visitor accepts
  • Google Consent Mode v2 (optional, off by default): instead of blocking them, it loads Google Analytics, Tag Manager and Ads without cookies until the visitor accepts. With low traffic, visitors who reject don’t show up in your Google reports
  • Guided 6-step legal Wizard that generates your Cookie Policy and your Personal Data Processing Policy, and finishes with a compliance check of the site
  • Automatic creation of the legal pages on your site, or insertion via shortcode if you already have your own text
  • ARCOP rights page: explains to your visitors how to exercise their rights over their data (access, rectification, erasure, objection and portability) by writing to your email
  • Consent log with SHA-256 hash chaining, exportable to CSV
  • Comprobador de Ley: a running checklist with a traffic-light view of your site’s legal and technical status, including detection of known vulnerabilities in WordPress core, active plugins and the active theme. What the plugin can’t solve, the cookieAz by MacLucan team can: security audit and monthly maintenance for your WordPress

Why choose CookieAz

Built around Ley 21.719
It’s not a generic template: the Wizard follows the structure required by article 14 ter of the Chilean law and asks only what that law requires (data controller, purposes, ARCOP rights, international transfers, retention periods).

Guided legal Wizard
The Wizard walks you step by step through your company details and generates the documents for you.

Know what’s missing
The Comprobador de Ley checks 15 legal and technical points on your site and shows you with a traffic light what’s in order and what isn’t, with the reason it matters under the law.

Consent log
Every time a visitor accepts, rejects or customizes their preferences, a record is stored with the date, policy version, anonymized IP (hash) and chained hash. It serves as backup that your site requested and recorded consent; it doesn’t identify individual visitors. It’s yours: you can export it to CSV at any time.

About the generated legal texts

The Wizard doesn’t provide legal advice. It generates both policies from the answers you give, following the structure required by article 14 ter. The pages carry a shortcode, not fixed text: the content is built from your answers and updates when you change them in the Wizard. Since its accuracy depends on your answers matching what your site actually does, review the published result, and consult a lawyer if you handle sensitive data, make automated decisions, or aren’t sure of your legal basis. Before the Data Protection Agency, the data controller is the site owner, not CookieAz or whoever installed it.

External services

This plugin connects to the following third-party services:

  1. ipify.org — detects your own server’s public IP address to suggest the hosting country (international transfers section of the Data Processing Policy). It only runs when an administrator clicks “Auto-detect” in step 2 of the legal Wizard. No visitor data is sent.
    Service: https://www.ipify.org — Privacy policy: https://www.ipify.org/ (see site footer).

  2. ipapi.co — turns that IP into a country. It runs on the same “Auto-detect” click. Only the server’s own public IP is sent.
    Service: https://ipapi.co — Privacy policy: https://ipapi.co/privacy/.

  3. Supabase (CookieAz’s own backend) — (a) Only if you enable “Share usage data with CookieAz” in Settings (off by default): once a week, your site URL and the plugin/WordPress/PHP versions are sent. (b) Only if you ask for help in the Comprobador de Ley and confirm in the dialog, which shows what will be sent: in addition, your checklist results and a technical inventory (active plugins and theme, their versions and known vulnerabilities), so the cookieAz by MacLucan team can contact you. No visitor data is ever sent.
    Service: https://supabase.com — Privacy policy: https://supabase.com/privacy.

  4. WPVulnerability.net — checks whether your WordPress version, active plugins or theme have known vulnerabilities. It runs when an administrator opens the Comprobador de Ley, at most once every 10 minutes. Only the WordPress version and the slugs of your active plugins and theme are sent: no site URL and no visitor data.
    Service: https://www.wpvulnerability.net — Privacy policy: https://www.wpvulnerability.com/privacy/.

Screenshots

Installation

  1. Go to Plugins > Add New in your WordPress admin panel
  2. Search for “CookieAz” and install the plugin
  3. Activate the plugin
  4. Go to the new CookieAz tab in your admin panel and follow the legal Wizard (6 steps): legal pages, company details, other data (security, data origin, decisions and legitimate interest), services, summary, and a compliance check of the site
  5. Choose whether you want CookieAz to automatically create the Cookie Policy and Data Processing Policy pages, use pages you already have, or insert them via shortcode
  6. Save, and you’re done — the banner is now active on your site

FAQ

Is a cookie banner mandatory in Chile?

If your site uses cookies that aren’t strictly necessary (analytics, advertising, social networks) and they process personal data, Ley 21.719 requires a legal basis to do so. The usual one is the visitor’s prior consent, and the banner is how you ask for it and record it.

I already have a cookie banner, do I still need CookieAz?

Probably yes. A banner solves only part of the problem: Chilean law also requires informing data subjects (article 14 ter), and that policy is the hardest part to write. CookieAz’s legal Wizard asks you simple questions about your company, generates your Data Processing Policy and your Cookie Policy, and keeps them up to date when you change your answers. It also blocks Google Analytics, Meta Pixel and other scripts until the visitor decides (a banner that only notifies doesn’t ask for consent before processing data), records every consent, and checks your site with the Comprobador de Ley.

Is CookieAz compatible with Google Consent Mode v2?

Yes, it’s optional and off by default.

Off (recommended): Google Tag Manager, Google Analytics and Google Ads stay blocked until the visitor accepts, like any other service. Visitors who reject don’t appear in your Google reports.

On: Google Tag Manager, Google Analytics and Google Ads will always load, even without consent, but without cookies or personalized advertising until the visitor accepts. Google can estimate part of the data from those who reject, only if your site has enough traffic (Google requires minimum thresholds). On low-traffic sites, visitors who reject won’t appear in your reports. More information from Google

If inside your Google Tag Manager container you load Meta Pixel, TikTok or other services not blocked by this plugin, those WILL fire without waiting for consent, unless you manually configure their consent checks inside your own Google Tag Manager (“Consent Overview”). More information from Google

Do I need to know about law or coding to use it?

No. The legal Wizard asks you simple questions about your company (name, tax ID, what data you handle) and generates the documents and the banner for you.

What happens to Google Analytics, Meta Pixel, or other scripts I already have installed?

CookieAz detects them and blocks them until the visitor gives consent, without you having to touch your site’s code.

What happens if my site doesn’t comply with Ley 21.719?

Sanctions range from warnings for minor infractions to fines of up to 20,000 UTM in the most serious cases, plus being listed in the National Registry of Sanctions and Compliance for 5 years.

Is it compatible with my WordPress theme?

Yes, CookieAz works regardless of the theme you use.

Can I use my own legal text instead of having CookieAz generate it?

Yes. In step 1 of the legal Wizard (Legal pages) you can choose between creating the page automatically, using a page you already have, or inserting the content via shortcode.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“CookieAz – Ley 21.719 Cookie Consent para Chile” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.4

New
* Comprobador de Ley: a 15-point legal and technical checklist with a traffic light, which detects known vulnerabilities in WordPress, active plugins and the theme. It’s step 6 of the legal Wizard and has its own tab, with a pending-items counter in the menu.
* If any point on your site isn’t up to date, you can ask the cookieAz by MacLucan team for help from the Comprobador itself.
* Editable category and provider suggestion for detected domains that haven’t been classified.
* Notice when an active service stops being detected in the weekly scan.

Improved
* Redesigned legal Wizard: from 9 to 6 steps, with a new design, required fields marked with an asterisk, and switches instead of checkboxes.
* The ARCOP email is asked in step 1, “Data origin” is a switch, and if your site is hosted outside Chile the safeguard for the international transfer is required.
* Fields that article 14 ter doesn’t require were removed from the Wizard (postal address and name of the ARCOP contact person).
* The Services step shows only the services detected on your site. Services detected for the first time are enabled automatically; if you uncheck them, they aren’t re-enabled.
* “Share usage data” (optional) now sends only the site URL and the plugin, WordPress and PHP versions.
* Consent log: clearer texts and access through the “View consents” link.
* Comprobador de Ley: risk texts aligned with article 14 quinquies, without asserting non-compliance, and better performance.

Fixed
* Google Tag Manager detection.
* Unchecked services that could reappear.
* Error when deleting already classified or ignored domains.
* Wizard notice that was displayed when it shouldn’t have been.

Security
* Hardening: internal queries, quote escaping, edit permission when inserting the shortcode into an existing page, and consent log protected against simultaneous submissions.

1.0.3

  • Internal maintenance adjustments.

1.0.2

  • New look for the banner and the panel, with CookieAz’s blue and black palette. Previously saved color schemes keep working.
  • Seals and preferences icon updated.

1.0.1

  • First public release: cookie banner with real script blocking (optional Google Consent Mode v2 compatibility), a legal Wizard to generate your legal pages, and a consent log with chained hashes, exportable to CSV.