By country

Privacy Policy Generator Spain

GDPR through the LOPDGDD, cookies under Article 22.2 LSSI, and the AEPD’s own cookie guide.

Generate your privacy policy Read the privacy policy guide

A Spanish política de privacidad is read alongside two other mandatory documents: the aviso legal required by the LSSI, and the cookie policy required by Article 22.2. Publishing only the privacy policy leaves two statutory gaps that anyone can check in a minute.

Spain implements GDPR through the LOPDGDD, which adds national rules on digital rights, the age of consent set at fourteen, and specific obligations around whistleblowing and video surveillance. The AEPD is one of the most active regulators in Europe by volume of decisions.

Cookies sit under Article 22.2 of the LSSI-CE, and the AEPD publishes a detailed cookie guide that sets its expectations: a first-layer reject option, no pre-ticked boxes, no consent by scrolling, and a recommended consent lifetime of no more than twenty-four months.

Spanish e-commerce also carries LSSI information duties: identity, tax number, contact details and, where applicable, professional registration must be published in a way that is permanent, easy and free to access.

What a privacy policy in Spain has to cover

How Spain actually moves personal data

Checkout and NIF collection

Spanish invoicing often involves collecting a tax identification number, which is directly identifying and needs a stated purpose and retention period.

Cookie consent under the AEPD guide

Consent must be granular, refusable on the first layer, and renewed periodically rather than stored indefinitely.

Video surveillance

The LOPDGDD sets specific rules for CCTV including signage, a maximum thirty-day retention in most cases, and restrictions on workplace monitoring.

Whistleblowing channels

Spanish law requires internal reporting channels for many organisations, with confidentiality obligations and a defined retention period.

Marketing consent

Electronic commercial communications require prior consent, with a narrow exemption for existing customers and similar products.

Third parties the draft will ask you about

Redsys · Stripe · Bizum · Correos or SEUR · Holded · AWS eu-south-2 · Mailchimp

The rules that apply

GDPR + LOPDGDD

Digital rights provisions, the age of digital consent set at fourteen, and specific rules on video surveillance and whistleblowing channels.

Article 22.2 LSSI-CE

Consent for storing and retrieving data on terminal equipment, enforced by the AEPD under its published cookie guide.

AEPD cookie guide

Reject on the first layer, no pre-ticked boxes, no consent by scrolling, and consent renewed at least every twenty-four months.

LSSI information duties

Company identity, NIF, address, contact and registry data published permanently and accessibly.

Consumer protection law

Fourteen-day withdrawal, a three-year conformity guarantee on goods, and mandatory pre-contractual information.

What the generated privacy policy contains

Spanish compliance essentials

  1. Publish an aviso legal

    Identity, NIF, address, contact and any professional registry data.

  2. Rebuild the banner to the AEPD guide

    First-layer reject, granular categories, no pre-ticked boxes.

  3. Set consent renewal at twenty-four months or less

    And record the version of the banner that captured it.

  4. Apply the CCTV rules if you have cameras

    Signage, thirty-day retention and restricted access.

  5. Set the age of digital consent to fourteen

    With parental consent below it.

Where this usually goes wrong

No reject option on the first banner layer

The AEPD guide is explicit, and it is the most common finding on Spanish sites.

Cookie consent stored indefinitely

The AEPD expects renewal at least every twenty-four months.

Missing aviso legal

The LSSI identity information is a separate requirement from the privacy policy and is easy to check.

Age-gating at sixteen

Spain sets the digital age of consent at fourteen, which is lower than several neighbours.

CCTV retained beyond thirty days

The LOPDGDD limits retention in most circumstances and requires clear signage.

Frequently asked questions

What does the AEPD require of a cookie banner?

A reject option on the same layer as accept, granular consent by category, no pre-ticked boxes, no consent inferred from scrolling, and consent renewed at least every twenty-four months.

What is an aviso legal?

The LSSI legal notice identifying the business: name, tax number, registered address, contact details and professional registration where relevant. It is separate from the privacy and cookie policies.

What is the age of digital consent in Spain?

Fourteen under the LOPDGDD, which is lower than in several other member states.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator Spain

Answer a short questionnaire and get a draft written for Spain. Free to start, no card required.

Generate your privacy policy

Other documents for Spain

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.