By country

Refund Policy Generator Spain

GDPR through the LOPDGDD, cookies under Article 22.2 LSSI, and the AEPD’s own cookie guide.

Generate your refund policy Read the refund policy guide

Spain gives consumers a three-year conformity guarantee on goods, longer than the EU minimum most refund templates assume, and a six-month window in which a defect is presumed to have existed at delivery. Both belong in the policy explicitly.

Spain implements GDPR through the LOPDGDD, which adds national rules on digital rights, the age of consent set at fourteen, and specific obligations around whistleblowing and video surveillance. The AEPD is one of the most active regulators in Europe by volume of decisions.

Cookies sit under Article 22.2 of the LSSI-CE, and the AEPD publishes a detailed cookie guide that sets its expectations: a first-layer reject option, no pre-ticked boxes, no consent by scrolling, and a recommended consent lifetime of no more than twenty-four months.

Spanish e-commerce also carries LSSI information duties: identity, tax number, contact details and, where applicable, professional registration must be published in a way that is permanent, easy and free to access.

What a refund policy in Spain has to cover

How Spain actually moves personal data

Checkout and NIF collection

Spanish invoicing often involves collecting a tax identification number, which is directly identifying and needs a stated purpose and retention period.

Cookie consent under the AEPD guide

Consent must be granular, refusable on the first layer, and renewed periodically rather than stored indefinitely.

Video surveillance

The LOPDGDD sets specific rules for CCTV including signage, a maximum thirty-day retention in most cases, and restrictions on workplace monitoring.

Whistleblowing channels

Spanish law requires internal reporting channels for many organisations, with confidentiality obligations and a defined retention period.

Marketing consent

Electronic commercial communications require prior consent, with a narrow exemption for existing customers and similar products.

Third parties the draft will ask you about

Redsys · Stripe · Bizum · Correos or SEUR · Holded · AWS eu-south-2 · Mailchimp

The rules that apply

GDPR + LOPDGDD

Digital rights provisions, the age of digital consent set at fourteen, and specific rules on video surveillance and whistleblowing channels.

Article 22.2 LSSI-CE

Consent for storing and retrieving data on terminal equipment, enforced by the AEPD under its published cookie guide.

AEPD cookie guide

Reject on the first layer, no pre-ticked boxes, no consent by scrolling, and consent renewed at least every twenty-four months.

LSSI information duties

Company identity, NIF, address, contact and registry data published permanently and accessibly.

Consumer protection law

Fourteen-day withdrawal, a three-year conformity guarantee on goods, and mandatory pre-contractual information.

What the generated refund policy contains

Spanish compliance essentials

  1. Publish an aviso legal

    Identity, NIF, address, contact and any professional registry data.

  2. Rebuild the banner to the AEPD guide

    First-layer reject, granular categories, no pre-ticked boxes.

  3. Set consent renewal at twenty-four months or less

    And record the version of the banner that captured it.

  4. Apply the CCTV rules if you have cameras

    Signage, thirty-day retention and restricted access.

  5. Set the age of digital consent to fourteen

    With parental consent below it.

Where this usually goes wrong

No reject option on the first banner layer

The AEPD guide is explicit, and it is the most common finding on Spanish sites.

Cookie consent stored indefinitely

The AEPD expects renewal at least every twenty-four months.

Missing aviso legal

The LSSI identity information is a separate requirement from the privacy policy and is easy to check.

Age-gating at sixteen

Spain sets the digital age of consent at fourteen, which is lower than several neighbours.

CCTV retained beyond thirty days

The LOPDGDD limits retention in most circumstances and requires clear signage.

Frequently asked questions

What does the AEPD require of a cookie banner?

A reject option on the same layer as accept, granular consent by category, no pre-ticked boxes, no consent inferred from scrolling, and consent renewed at least every twenty-four months.

What is an aviso legal?

The LSSI legal notice identifying the business: name, tax number, registered address, contact details and professional registration where relevant. It is separate from the privacy and cookie policies.

What is the age of digital consent in Spain?

Fourteen under the LOPDGDD, which is lower than in several other member states.

Can I run a no-refunds policy?

Not against statutory rights. In the UK and EU a consumer’s cancellation and faulty-goods rights apply regardless of what your policy says, and advertising "no refunds" is itself treated as a misleading practice.

Do digital products have to be refundable?

The cancellation right can be waived for digital content, but only if the customer gave express consent to immediate delivery and acknowledged losing the right. That acknowledgement has to be captured at checkout, not assumed.

How long do I have to issue a refund?

In the UK and EU, within 14 days of receiving the goods back or of the customer proving they returned them. Card scheme rules and marketplace policies often impose something tighter.

Refund Policy Generator Spain

Answer a short questionnaire and get a draft written for Spain. Free to start, no card required.

Generate your refund policy

Other documents for Spain

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.