By country

Cookie Policy Generator Spain

GDPR through the LOPDGDD, cookies under Article 22.2 LSSI, and the AEPD’s own cookie guide.

Generate your cookie policy Read the cookie policy guide

Spain has one of the most prescriptive cookie regimes in the EU because the AEPD publishes a guide setting out exactly what a banner must do. The cookie policy should describe a banner built to that guide, including the consent renewal cycle.

Spain implements GDPR through the LOPDGDD, which adds national rules on digital rights, the age of consent set at fourteen, and specific obligations around whistleblowing and video surveillance. The AEPD is one of the most active regulators in Europe by volume of decisions.

Cookies sit under Article 22.2 of the LSSI-CE, and the AEPD publishes a detailed cookie guide that sets its expectations: a first-layer reject option, no pre-ticked boxes, no consent by scrolling, and a recommended consent lifetime of no more than twenty-four months.

Spanish e-commerce also carries LSSI information duties: identity, tax number, contact details and, where applicable, professional registration must be published in a way that is permanent, easy and free to access.

What a cookie policy in Spain has to cover

How Spain actually moves personal data

Checkout and NIF collection

Spanish invoicing often involves collecting a tax identification number, which is directly identifying and needs a stated purpose and retention period.

Cookie consent under the AEPD guide

Consent must be granular, refusable on the first layer, and renewed periodically rather than stored indefinitely.

Video surveillance

The LOPDGDD sets specific rules for CCTV including signage, a maximum thirty-day retention in most cases, and restrictions on workplace monitoring.

Whistleblowing channels

Spanish law requires internal reporting channels for many organisations, with confidentiality obligations and a defined retention period.

Marketing consent

Electronic commercial communications require prior consent, with a narrow exemption for existing customers and similar products.

Third parties the draft will ask you about

Redsys · Stripe · Bizum · Correos or SEUR · Holded · AWS eu-south-2 · Mailchimp

The rules that apply

GDPR + LOPDGDD

Digital rights provisions, the age of digital consent set at fourteen, and specific rules on video surveillance and whistleblowing channels.

Article 22.2 LSSI-CE

Consent for storing and retrieving data on terminal equipment, enforced by the AEPD under its published cookie guide.

AEPD cookie guide

Reject on the first layer, no pre-ticked boxes, no consent by scrolling, and consent renewed at least every twenty-four months.

LSSI information duties

Company identity, NIF, address, contact and registry data published permanently and accessibly.

Consumer protection law

Fourteen-day withdrawal, a three-year conformity guarantee on goods, and mandatory pre-contractual information.

What the generated cookie policy contains

Spanish compliance essentials

  1. Publish an aviso legal

    Identity, NIF, address, contact and any professional registry data.

  2. Rebuild the banner to the AEPD guide

    First-layer reject, granular categories, no pre-ticked boxes.

  3. Set consent renewal at twenty-four months or less

    And record the version of the banner that captured it.

  4. Apply the CCTV rules if you have cameras

    Signage, thirty-day retention and restricted access.

  5. Set the age of digital consent to fourteen

    With parental consent below it.

Where this usually goes wrong

No reject option on the first banner layer

The AEPD guide is explicit, and it is the most common finding on Spanish sites.

Cookie consent stored indefinitely

The AEPD expects renewal at least every twenty-four months.

Missing aviso legal

The LSSI identity information is a separate requirement from the privacy policy and is easy to check.

Age-gating at sixteen

Spain sets the digital age of consent at fourteen, which is lower than several neighbours.

CCTV retained beyond thirty days

The LOPDGDD limits retention in most circumstances and requires clear signage.

Frequently asked questions

What does the AEPD require of a cookie banner?

A reject option on the same layer as accept, granular consent by category, no pre-ticked boxes, no consent inferred from scrolling, and consent renewed at least every twenty-four months.

What is an aviso legal?

The LSSI legal notice identifying the business: name, tax number, registered address, contact details and professional registration where relevant. It is separate from the privacy and cookie policies.

What is the age of digital consent in Spain?

Fourteen under the LOPDGDD, which is lower than in several other member states.

Do I need a cookie policy as well as a privacy policy?

In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.

Do analytics cookies need consent?

In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.

Does a cookie policy need updating when I add a tool?

Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.

What about cookies set by embedded video and maps?

They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.

Cookie Policy Generator Spain

Answer a short questionnaire and get a draft written for Spain. Free to start, no card required.

Generate your cookie policy

Other documents for Spain

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.