Back to blog
Websites2 August 20269 min read

What Your Website Legally Needs in Spain (2026)

Legal notice, privacy policy, a cookie banner that actually complies, and lawful forms. A plain-English checklist of what a business website needs in Spain.

What Your Website Legally Needs in Spain (2026)

Nobody starts a business because they were excited about cookie banners. But if you run a website that does any kind of commercial activity in Spain, there are a handful of legal boxes to tick, and most small business websites get at least one of them wrong.

The good news: it is a short list, it is mostly a one-off job, and none of it is complicated once someone explains it without the legalese. Here is what your website needs and how to check your own in about ten minutes.

This is general information to help you know what to look for, not legal advice. If you handle sensitive data or sell online at volume, get your setup reviewed properly.

1. A legal notice (aviso legal)

Spanish law on information society services, the LSSI-CE, requires any website carrying out economic activity to identify who is behind it. Not buried, not optional. It needs to be reachable from every page, normally a link in the footer, and it should state:

  • Your name or company name, and your NIF or CIF.
  • Your registered address.
  • A working contact route, normally an email address.
  • Commercial registry details if you are a company, and professional body registration if you are in a regulated profession.

This is the requirement most freelancers and sole traders skip, usually because they do not want their address online. It is still required if you are trading.

2. A privacy policy that matches what you actually do

The moment your site collects a name, an email, a phone number or an IP address for analytics, the GDPR and Spain's LOPDGDD apply. Your privacy policy has to tell people, in clear language:

  • Who is responsible for the data (you) and how to reach you.
  • What data you collect and why.
  • Your legal basis, for example consent for a newsletter, or performing a contract for a customer job.
  • Who else sees it. Be honest here: your hosting provider, your email tool, Google Analytics, your CRM.
  • How long you keep it.
  • Their rights: access, correction, erasure, objection, and the right to complain to the AEPD.

The common failure is not the absence of a policy but a copied template that describes a different business. If yours mentions services you do not offer, or omits the tools you actually use, it is not doing its job.

3. A cookie banner that genuinely complies

This is where most sites fall down, and the rules got stricter. The AEPD updated its cookie guidance with a compliance deadline of 11 January 2024, and the key points are:

  • Rejecting must be as easy as accepting. One click for each. If your banner has a big "Accept" button and rejection is hidden behind a settings menu, that is a breach.
  • Both options must be equally visible. Same prominence, same height, no making "Reject" small, faint or low contrast.
  • No non-essential cookies before consent. Analytics and advertising tags must not fire until the visitor agrees. This is the one that silently catches people: the banner looks right, but Google Analytics loaded on page one anyway.
  • Continuing to browse is not consent. Neither is scrolling.
  • People must be able to change their mind later, so keep a way to revisit cookie settings.

For scale, cookie and information breaches in Spain have commonly drawn sanctions from around 10,000 euros up to 150,000 euros for the more serious cases, and GDPR breaches carry much higher theoretical ceilings. Nobody is fining a village bakery out of existence, but it is a real regulatory area with a real enforcement record.

4. Forms that collect data lawfully

Your contact form needs three things: a clear statement of what you will do with the details, a link to your privacy policy, and, where you rely on consent, a tick box that is not pre-ticked. Silence is not consent. And if you plan to send marketing later, you need consent for that specifically, not just permission to reply to the enquiry.

If you sell online, there is more

Selling adds terms and conditions, clear pricing including tax and delivery, information about the 14-day right of withdrawal for consumers, and details of your payment and returns process. If that is your model, it is worth a proper review rather than a checklist.

Check your own site in ten minutes

  1. Open your site in a private browsing window and look at the footer. Are there links to a legal notice, a privacy policy and a cookie policy?
  2. Does the cookie banner offer a reject option that is as obvious and as quick as accept?
  3. Click reject, then check whether analytics still loads. If you are not sure, this is the item to ask about.
  4. Read your privacy policy as if you were a customer. Does it describe your actual business and actual tools?
  5. Look at your contact form. Is there a privacy link, and is any consent box unticked by default?

If you found problems, you are in the majority. Most of this is a single afternoon of work, and it is the sort of thing that should simply come as standard with a professional site. On the sites we build it does, along with the consent handling wired in properly rather than bolted on. While you are at it, the same care applies to how you message customers: there is more on that in our guide to using WhatsApp for business.

Frequently asked questions

Is a cookie banner mandatory?

If your site uses any non-essential cookies, which includes analytics and advertising, then yes, you need a compliant consent banner. A site with only strictly necessary cookies does not need a consent banner, but still needs to explain them.

Can I use a privacy policy template?

A template is a reasonable starting point, but it has to be adapted to your business, your data and your tools. An unedited template that describes a shop when you are a plumber is worse than useless, because it is a written record of you saying something inaccurate.

Do I need a legal notice if I do not sell online?

Yes. The obligation applies to websites engaged in economic activity, not just online shops. If your site promotes a business, it needs to identify who runs it.

What about Google Analytics?

Analytics is not an essential cookie, so it must only load after the visitor consents, and you should mention it in your privacy and cookie policies. Loading it on arrival is one of the most common compliance mistakes we see.

Can I really be fined as a sole trader?

The rules apply regardless of size, and the AEPD has sanctioned small businesses and individuals. In practice, complaints often come from a competitor or a disgruntled visitor rather than a random inspection, which is exactly why it is worth tidying up.

Getting this right is not about fear, it is about not having an avoidable problem sitting on your website. If you would like yours built with the legal basics handled properly from day one, take a look at our websites or get a free consultation.

Need Help With This?

We implement everything we write about. Let us handle the technical stuff for you.

Get a Free Consultation