Cookie Policy Generator Spain
GDPR through the LOPDGDD, cookies under Article 22.2 LSSI, and the AEPD’s own cookie guide.
Spain has one of the most prescriptive cookie regimes in the EU because the AEPD publishes a guide setting out exactly what a banner must do. The cookie policy should describe a banner built to that guide, including the consent renewal cycle.
Spain implements GDPR through the LOPDGDD, which adds national rules on digital rights, the age of consent set at fourteen, and specific obligations around whistleblowing and video surveillance. The AEPD is one of the most active regulators in Europe by volume of decisions.
Cookies sit under Article 22.2 of the LSSI-CE, and the AEPD publishes a detailed cookie guide that sets its expectations: a first-layer reject option, no pre-ticked boxes, no consent by scrolling, and a recommended consent lifetime of no more than twenty-four months.
Spanish e-commerce also carries LSSI information duties: identity, tax number, contact details and, where applicable, professional registration must be published in a way that is permanent, easy and free to access.
What a cookie policy in Spain has to cover
A per-cookie table with titular, finalidad, categoría and duración
Article 22.2 LSSI-CE as the basis for the consent requirement
First-layer reject with equal prominence and granular category choices
Consent renewed at least every twenty-four months
Third-party cookies from embeds, social plugins and advertising partners
How Spain actually moves personal data
Checkout and NIF collection
Spanish invoicing often involves collecting a tax identification number, which is directly identifying and needs a stated purpose and retention period.
Cookie consent under the AEPD guide
Consent must be granular, refusable on the first layer, and renewed periodically rather than stored indefinitely.
Video surveillance
The LOPDGDD sets specific rules for CCTV including signage, a maximum thirty-day retention in most cases, and restrictions on workplace monitoring.
Whistleblowing channels
Spanish law requires internal reporting channels for many organisations, with confidentiality obligations and a defined retention period.
Marketing consent
Electronic commercial communications require prior consent, with a narrow exemption for existing customers and similar products.
Third parties the draft will ask you about
Redsys · Stripe · Bizum · Correos or SEUR · Holded · AWS eu-south-2 · Mailchimp
The rules that apply
GDPR + LOPDGDD
Digital rights provisions, the age of digital consent set at fourteen, and specific rules on video surveillance and whistleblowing channels.
Article 22.2 LSSI-CE
Consent for storing and retrieving data on terminal equipment, enforced by the AEPD under its published cookie guide.
AEPD cookie guide
Reject on the first layer, no pre-ticked boxes, no consent by scrolling, and consent renewed at least every twenty-four months.
LSSI information duties
Company identity, NIF, address, contact and registry data published permanently and accessibly.
Consumer protection law
Fourteen-day withdrawal, a three-year conformity guarantee on goods, and mandatory pre-contractual information.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Spanish compliance essentials
Publish an aviso legal
Identity, NIF, address, contact and any professional registry data.
Rebuild the banner to the AEPD guide
First-layer reject, granular categories, no pre-ticked boxes.
Set consent renewal at twenty-four months or less
And record the version of the banner that captured it.
Apply the CCTV rules if you have cameras
Signage, thirty-day retention and restricted access.
Set the age of digital consent to fourteen
With parental consent below it.
Where this usually goes wrong
No reject option on the first banner layer
The AEPD guide is explicit, and it is the most common finding on Spanish sites.
Cookie consent stored indefinitely
The AEPD expects renewal at least every twenty-four months.
Missing aviso legal
The LSSI identity information is a separate requirement from the privacy policy and is easy to check.
Age-gating at sixteen
Spain sets the digital age of consent at fourteen, which is lower than several neighbours.
CCTV retained beyond thirty days
The LOPDGDD limits retention in most circumstances and requires clear signage.
Frequently asked questions
What does the AEPD require of a cookie banner?
A reject option on the same layer as accept, granular consent by category, no pre-ticked boxes, no consent inferred from scrolling, and consent renewed at least every twenty-four months.
What is an aviso legal?
The LSSI legal notice identifying the business: name, tax number, registered address, contact details and professional registration where relevant. It is separate from the privacy and cookie policies.
What is the age of digital consent in Spain?
Fourteen under the LOPDGDD, which is lower than in several other member states.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator Spain
Answer a short questionnaire and get a draft written for Spain. Free to start, no card required.
Generate your cookie policyOther documents for Spain
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.