Privacy Policy Generator Spain
GDPR through the LOPDGDD, cookies under Article 22.2 LSSI, and the AEPD’s own cookie guide.
A Spanish política de privacidad is read alongside two other mandatory documents: the aviso legal required by the LSSI, and the cookie policy required by Article 22.2. Publishing only the privacy policy leaves two statutory gaps that anyone can check in a minute.
Spain implements GDPR through the LOPDGDD, which adds national rules on digital rights, the age of consent set at fourteen, and specific obligations around whistleblowing and video surveillance. The AEPD is one of the most active regulators in Europe by volume of decisions.
Cookies sit under Article 22.2 of the LSSI-CE, and the AEPD publishes a detailed cookie guide that sets its expectations: a first-layer reject option, no pre-ticked boxes, no consent by scrolling, and a recommended consent lifetime of no more than twenty-four months.
Spanish e-commerce also carries LSSI information duties: identity, tax number, contact details and, where applicable, professional registration must be published in a way that is permanent, easy and free to access.
What a privacy policy in Spain has to cover
Controller identity consistent with the aviso legal, including the NIF
The AEPD named as supervisory authority with the complaint route
Purposes and lawful bases, with the age of digital consent set at fourteen
Video surveillance where you operate it, with signage and retention
Marketing consent and the narrow existing-customer exemption
How Spain actually moves personal data
Checkout and NIF collection
Spanish invoicing often involves collecting a tax identification number, which is directly identifying and needs a stated purpose and retention period.
Cookie consent under the AEPD guide
Consent must be granular, refusable on the first layer, and renewed periodically rather than stored indefinitely.
Video surveillance
The LOPDGDD sets specific rules for CCTV including signage, a maximum thirty-day retention in most cases, and restrictions on workplace monitoring.
Whistleblowing channels
Spanish law requires internal reporting channels for many organisations, with confidentiality obligations and a defined retention period.
Marketing consent
Electronic commercial communications require prior consent, with a narrow exemption for existing customers and similar products.
Third parties the draft will ask you about
Redsys · Stripe · Bizum · Correos or SEUR · Holded · AWS eu-south-2 · Mailchimp
The rules that apply
GDPR + LOPDGDD
Digital rights provisions, the age of digital consent set at fourteen, and specific rules on video surveillance and whistleblowing channels.
Article 22.2 LSSI-CE
Consent for storing and retrieving data on terminal equipment, enforced by the AEPD under its published cookie guide.
AEPD cookie guide
Reject on the first layer, no pre-ticked boxes, no consent by scrolling, and consent renewed at least every twenty-four months.
LSSI information duties
Company identity, NIF, address, contact and registry data published permanently and accessibly.
Consumer protection law
Fourteen-day withdrawal, a three-year conformity guarantee on goods, and mandatory pre-contractual information.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Spanish compliance essentials
Publish an aviso legal
Identity, NIF, address, contact and any professional registry data.
Rebuild the banner to the AEPD guide
First-layer reject, granular categories, no pre-ticked boxes.
Set consent renewal at twenty-four months or less
And record the version of the banner that captured it.
Apply the CCTV rules if you have cameras
Signage, thirty-day retention and restricted access.
Set the age of digital consent to fourteen
With parental consent below it.
Where this usually goes wrong
No reject option on the first banner layer
The AEPD guide is explicit, and it is the most common finding on Spanish sites.
Cookie consent stored indefinitely
The AEPD expects renewal at least every twenty-four months.
Missing aviso legal
The LSSI identity information is a separate requirement from the privacy policy and is easy to check.
Age-gating at sixteen
Spain sets the digital age of consent at fourteen, which is lower than several neighbours.
CCTV retained beyond thirty days
The LOPDGDD limits retention in most circumstances and requires clear signage.
Frequently asked questions
What does the AEPD require of a cookie banner?
A reject option on the same layer as accept, granular consent by category, no pre-ticked boxes, no consent inferred from scrolling, and consent renewed at least every twenty-four months.
What is an aviso legal?
The LSSI legal notice identifying the business: name, tax number, registered address, contact details and professional registration where relevant. It is separate from the privacy and cookie policies.
What is the age of digital consent in Spain?
Fourteen under the LOPDGDD, which is lower than in several other member states.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator Spain
Answer a short questionnaire and get a draft written for Spain. Free to start, no card required.
Generate your privacy policyOther documents for Spain
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.