Every business or professional firm website in Spain needs a legal notice with your details and privacy information next to each form. If it uses cookies that are not technical, such as those from Analytics or from a YouTube video, it also needs a cookie notice. And that notice must make rejecting them as easy as accepting them. If you sell online, add terms and conditions and withdrawal information, and possibly accessibility information.
Below you will find which texts each website needs and what each one must say. Plus a 20-minute audit using your browser and a 20-point checklist, each point with its article.
This guide does not replace whoever drafts your texts: it helps you review the ones you have and commission the ones that are missing. When something is our interpretation and not the wording of a rule, we mark it as a cautious approach.
Which texts you need depends on what your website does, not on its size
Each text comes from a different rule and is triggered by something specific: identifying yourself, collecting data, using cookies, selling or running promotions.
| Text | Mandatory for | Rule | Where it goes |
|---|---|---|---|
| Legal notice | Any website of a business or a professional, whether it sells or not | LSSI, art. 10 and annex | Its own page, linked in the footer of every page |
| Privacy information | Anyone who collects personal data: form, newsletter, bookings, chat | GDPR, art. 13; LOPDGDD, art. 11 | A summary next to each form and a full policy |
| Cookie notice and policy | Anyone who uses cookies or similar technologies that are not technical | LSSI, art. 22.2; cookie guide of the Spanish Data Protection Agency (AEPD) | Banner on the first visit and a policy page |
| Terms and conditions of sale | Anyone who sells, takes booking payments or enters into service contracts on the website | LSSI, art. 27; Consumer Protection Law (Ley de Consumidores), arts. 97 to 108 | Before payment, in a format the customer can save |
| Accessibility information | Anyone bound by Law 11/2023 on accessibility (Ley 11/2023), above all online sales to consumers | Law 11/2023, art. 13.2 | In the general terms and conditions or on a linked page |
| Promotion rules | Anyone running prize draws, competitions or discounts on the website or by email | LSSI, art. 20.2 | A rules page linked from the promotion |
The legal notice is the only one that any business website needs. The Information Society Services Law (LSSI) also applies to services that are free for the user if they are an economic activity for whoever provides them, including supplying information (annex, point a). A professional firm’s or an SME’s website counts, even if it sells nothing.
Terms of use are something else: we have not found any rule that requires them on an informational website without a client area.
Example
Let’s say we have a tax and accounting firm in Castellón with an informational website, a contact form, a Google map and Analytics. It needs a legal notice, privacy information next to the form and a full policy. It needs a cookie notice and policy because of Analytics and, if it installs cookies, because of the map. It does not need terms and conditions of sale: clients do not buy or sign up for anything on its website.
What each text must say, point by point
Legal notice: who you are, with details that can be checked
Art. 10.1 of the LSSI requires these details to be accessible “permanently, easily, directly and free of charge”:
- Name or company name, address, email and any other detail that allows you to be contacted directly (point a).
- Tax ID (NIF) (point e) and, if you are registered, the details of the Commercial Register (Registro Mercantil) or another public register (point b).
- The prior authorisation, if your activity requires one, and the body that supervises you (point c). The case of clinics is covered in healthcare advertising.
- Professional association, number, qualification, State that issued it and professional rules, if you practise a regulated profession (point d). What each profession adds is in advertising for lawyers and in an insurance brokerage’s website.
- Whether prices include taxes and delivery costs (point f), and the codes of conduct you have signed up to (point g).
If you sell to consumers, add your phone number (Consumer Protection Law, art. 97.1.c). The owner is your company, not the agency that built the website. Cautious approach: link to the notice from the footer of every page.
Privacy: the information starts next to the submit button
When you collect someone’s data, you must inform them at that moment (GDPR, art. 13), in clear and plain language (art. 12.1). The LOPDGDD, Spain’s data protection law, allows you to do this in two layers (art. 11):
- Next to the form: who the controller is, what the data will be used for and how to exercise rights, with a link to the rest. If you profile users, say so too.
- In the full policy: contact details of the controller and, if there is one, of the data protection officer. Each purpose with its legal basis, recipients, international transfers, retention periods, rights and the right to complain to the AEPD.
Cautious approach on the “I accept the privacy policy” checkbox. To answer an enquiry you do not need consent: at the data subject’s request, you are taking pre-contractual steps (art. 6.1.b). If you add a checkbox, make it for confirming that the information has been read. Consent is needed to send the newsletter to someone who is not a client, with its own checkbox, optional and unticked (arts. 6.1.a and 7.2).
Three points that are often forgotten:
- The data protection officer at clinics. Healthcare centres that are required to keep clinical records need one, except professionals who practise individually (LOPDGDD, art. 34.1.l). Their contact details go in the policy.
- The suppliers who process data for you. Your hosting, email, CRM or online booking providers need a processor contract (GDPR, art. 28.3). It is usually an annex to their terms, like Calendly’s.
- Commercial emails. Only to those who authorised them or to clients, about products similar to those they bought, and always with a simple, free way to unsubscribe (LSSI, art. 21).
Cookies: a notice that makes rejecting as easy as accepting
To install or read cookies, or similar technologies, you need the user’s consent after informing them clearly and fully (LSSI, art. 22.2). Cookies that are strictly necessary for the service the user requests are excluded.
The AEPD’s Guide on the use of cookies sets out how to do it. It is the May 2024 version, the current one on the AEPD website as of 2 October 2026. The banner, or first layer, must include (section 3.1.2.2):
- What the cookies are used for and whether they are your own or also third-party cookies.
- What type of data is collected, if profiles are created.
- A button to accept, a similar one to reject and another to configure by purpose. Cautious approach: if you only use one purpose, such as analytics, accept and reject already cover configuration.
- A visible link to the cookie policy, and who you are if this cannot be inferred from the website.
The option to reject goes in the same layer, at the same level and with a mechanism similar to accepting (section 3.2.1). You cannot nudge people into accepting or use misleading colours, such as a “Reject” that can barely be read. Continuing to browse is not consent.
The exempt ones. Among others, session, authentication, security, load balancing, user interface customisation and player session cookies do not need consent (section 1). The guide recommends giving general information about them. If your website only uses these, you do not need a banner.
Analytics, in general, is not exempt. The AEPD only accepts exempting audience measurement if it meets strict conditions (January 2024 guide):
- Anonymous statistics, for the publisher’s exclusive use.
- No combining or transferring data to third parties, and no cross-site tracking.
- Cookies with a limited lifespan, for example 13 months, and data kept for 25 months at most.
- Information in the privacy policy and a processor contract with the supplier.
The same guide warns that several products on the market reuse the data for other purposes and fall outside the exemption. Cautious approach: with Google Analytics, ask for consent.
Google offers two ways to do this (consent mode). In basic mode, its tags are blocked until the user accepts. In advanced mode, they load before the banner and send “cookieless pings” if the user rejects. Basic mode is the one that leaves no doubt. What to measure and how is covered in how to measure your website’s enquiries.
After the click. The AEPD considers it good practice to renew consent at intervals of no more than 24 months (section 3.2.8). Withdrawing it must be as easy as giving it, with permanent access to the settings (section 3.2.9; GDPR, art. 7.3). A cookie wall is only acceptable with a genuinely equivalent alternative (section 3.2.10): on the website of a professional firm or an SME, the cautious approach is not to use one.
The cookie policy explains which types you use and what for, who uses them, how to accept, reject and revoke, transfers and retention periods (section 3.1.1).
If you sell online: terms before payment and 14 days to withdraw
If people buy, pay a booking deposit or contract a service on your website, three more obligations apply:
- Before contracting, explain the steps, whether you will store the contract, how to correct errors and in which languages. And offer the general terms and conditions in a format the customer can save (LSSI, art. 27).
- For consumers, the pre-contractual information: identity, address, phone number, email, total price including taxes and costs, payment, delivery, legal guarantee and withdrawal with its form (Consumer Protection Law, art. 97). The final button says “order with obligation to pay” or something equally clear (art. 98.2).
- Withdrawal: 14 calendar days without giving reasons (art. 102), from the contract for services and from delivery for products (art. 104). If you do not inform the customer, the period is extended by 12 months (art. 105). You refund the money within 14 days at most (art. 107).
What changes in 2026. Directive (EU) 2023/2673 requires a withdrawal function labelled “withdraw from contract here” or an equivalent wording. Member States had to apply it from 19 June 2026 to contracts concluded on a website or an app (new art. 11 bis of Directive 2011/83/EU).
We have not found the Spanish rule that transposes it in the BOE: the consolidated Consumer Protection Law, updated on 28 February 2026, does not include it. Cautious approach: if you sell online, prepare it now.
And remove a link. The link to the European online dispute resolution platform is no longer required. The Regulation that required it was repealed with effect from 20 July 2025 and the platform has been discontinued (Regulation (EU) 2024/3228).
Accessibility: a page that explains how you comply
If Law 11/2023 applies to you, your general terms and conditions, or an equivalent document, must explain how your service meets the accessibility requirements (art. 13.2). It mainly affects you if you sell online to consumers, unless you are a micro-enterprise that provides services (art. 3.3).
If you serve the public without selling on the website, Royal Decree 193/2023 (Real Decreto 193/2023) will require a website at level AA from 2029 or, at the latest, before 2030. The details are in mandatory web accessibility, and the accessibility test tells you in up to 7 questions whether it affects you.
Seven typical mistakes, and three the AEPD has already fined
- Copied texts or unfilled templates. In procedure PS/00458/2023, the AEPD fined an estate agency €3,000 because its policy named “XXXXX” as controller (decision). Other clues: details of another company or of your agency, or references to the 1999 LOPD, repealed in 2018 (LOPDGDD, sole repealing provision).
- A banner without “Reject”. If rejecting means going into “More options”, it does not comply with the AEPD guide.
- Analytics before the user decides. In PS/00079/2023, the AEPD proposed a €2,000 fine for the owner of a small news website, who paid €1,600 (decision). Google Analytics cookies were installed as soon as the visitor arrived, and the banner only offered “more options” and “I accept”. In their defence, the owner cited what their provider had told them. The penalty still fell on the owner.
- A “Reject” that does not reject. In PS/00040/2024, the company that owned a motoring website paid €6,000 out of an initial €10,000 penalty (decision). Its YouTube videos installed cookies before any action and also after clicking “Reject all”.
- Forms without information. The LOPDGDD classifies failing to comply with the duty to inform as very serious (art. 72.1.h), and giving incomplete information as minor (art. 74.a).
- Pre-ticked checkboxes or everything in one checkbox. Pre-ticked boxes are not consent (recital 32 of the GDPR). And the request for consent must be clearly distinguishable from other matters (art. 7.2).
- A cookie policy that does not match what is installed. Each new plugin can add cookies, and the AEPD recommends reviewing them periodically (section 3 of its guide).
All three procedures began with a complaint from a user.
20-minute audit with your browser
It is the same method described in the AEPD’s decisions: visit with a clean browser and without touching anything. You need Chrome on a computer and your cookie policy to hand.
- Prepare the browser (minutes 0 to 2). Open an incognito window with Ctrl + Shift + N, or Cmd + Shift + N on a Mac. Open the developer tools with F12, or Cmd + Option + I on a Mac (Chrome). In the Network tab, tick “Disable cache”.
- Load your home page without touching the banner (minutes 2 to 6). In Network, open “More filters” and tick “3rd-party requests” (Chrome). Note down the analytics, advertising, video, map or booking calendar domains. Then open Application, “Storage”, “Cookies” and your domain (Chrome).
- Read the banner like a client (minutes 6 to 9). Is “Reject” next to “Accept”, with the same type of button? Does it say what the cookies are used for? Does it link to the policy? Does “Settings” lead straight to a panel with nothing ticked?
- Click “Reject” and browse (minutes 9 to 13). Visit 2 or 3 pages, including the contact page and one with a video or a map. Look at Network and Cookies again: nothing new from analytics, advertising, YouTube, Maps or Calendly should appear.
- Look for how to change your mind (minutes 13 to 15). There must be a permanent link, usually in the footer, that opens the settings again.
- Accept and compare (minutes 15 to 17). Close all the incognito windows and open another one. Load the website, click “Accept” and compare the cookies with your policy: each one must be listed in it.
- Check the form (minutes 17 to 19). Is there basic information next to the button, with a link to the policy? Does any checkbox come pre-ticked? Does the newsletter have its own checkbox?
- Look for remnants of copied texts (minutes 19 to 20). In the legal notice and the privacy policy, search with Ctrl + F for: “XXX”, “15/1999”, “litigios en línea” (online dispute resolution) and the name of your agency or of another company.
A note on step 2. In incognito mode, Chrome blocks third-party cookies by default (Chrome Help). That is why third parties are easier to detect in Network than in Cookies.
What you see before deciding, and what it means:
| What you see | What it usually is | What to do |
|---|---|---|
_ga and _ga_ cookies followed by letters and numbers |
Google Analytics 4, with first-party cookies that last 2 years | They should not load until the user accepts |
_fbp cookie |
Meta Pixel | The same |
| Requests to googletagmanager.com or google-analytics.com, without cookies | Google tags, perhaps in advanced consent mode | Ask whoever runs your website for basic mode |
| Requests to youtube.com, youtube-nocookie.com, calendly.com or Google maps | An embedded video, booking calendar or map | See the next section |
| A session cookie or the banner’s own cookie | Technical cookies (cautious approach) | Mention them in general terms in the policy |
WhatsApp, Calendly, maps and videos: embedded content loads when the page opens
Embedded content is downloaded from another company’s servers as soon as the page opens. Google explains this for YouTube and Analytics: the browser sends Google the URL and the visitor’s IP address, and Google may set or read cookies (Google). According to the AEPD guide, if you include third-party content that uses cookies, you must make sure that users are informed and asked for consent (section 4).
- WhatsApp. A
wa.melink with your number opens the chat when it is clicked (WhatsApp), and until then nothing loads. A floating button from a plugin can load code: check it with the audit. If you deal with clients on WhatsApp, your policy must say what you use those conversations for and how long you keep them. - Calendly. It warns that it uses cookies even if you hide its banner and, in that case, recommends not loading it until the user accepts performance cookies (Calendly). It processes the data of people who book as a processor, with transfers to the United States (DPA), and your policy must say so (GDPR, art. 13.1.f). Cautious approach: a link to your Calendly page is simpler than the embedded calendar.
- Google Maps. The embedded map is also downloaded from Google when the page opens: check with the audit which requests and cookies it generates. Cautious approach: an image of the map linking to Google Maps, or loading the map only when the user asks for it and has accepted.
- YouTube. It is the case penalised in PS/00040/2024. Privacy-enhanced mode uses the youtube-nocookie.com domain, and Google promises that those views will not influence the viewing experience on YouTube or personalise ads (YouTube). It does not promise that nothing is stored. Cautious approach: show an image of the video and load the player only after consent.
Fines for these failings reach €150,000 under the LSSI and millions under the GDPR
| What you breach | Type and article | Fine | Who imposes it |
|---|---|---|---|
| Missing tax ID, company registration, professional association or authorisation details | Minor, LSSI, art. 38.4.b | Up to €30,000 | State Secretariat for Digitalisation and AI (Secretaría de Estado de Digitalización e IA) (art. 43.1) |
| Significantly failing to make clear who you are or your prices | Serious, LSSI, art. 38.3.b | €30,001 to €150,000 | State Secretariat for Digitalisation and AI |
| Cookies without information or without consent | Minor, LSSI, art. 38.4.g | Up to €30,000 | AEPD |
| Commercial emails without permission | Minor, LSSI, art. 38.4.d; serious if they are mass or persistent, art. 38.3.c | Up to €30,000; €30,001 to €150,000 | AEPD |
| Not providing the general terms and conditions before contracting | Serious, LSSI, art. 38.3.e | €30,001 to €150,000 | State Secretariat for Digitalisation and AI |
| Forms without the information in art. 13 of the GDPR | GDPR, art. 83.5 | Up to 20 million or 4% of turnover | AEPD |
The LSSI amounts are in its art. 39 and the allocation of powers, in art. 43. For minor or serious infringements, the sanctioning body may issue a warning so that you correct the problem within a period, instead of opening proceedings (art. 39 ter). Putting things right diligently also lowers the fine bracket (art. 39 bis).
Checklist: 20 points, each with its article
| # | What to check | Basis |
|---|---|---|
| 1 | The legal notice identifies the real owner: name or company name, address and email | LSSI, art. 10.1.a |
| 2 | The tax ID (NIF) appears and, if you are a company, the Commercial Register details | LSSI, art. 10.1.b and e |
| 3 | If you practise a regulated profession: professional association, number, qualification and professional rules with a link | LSSI, art. 10.1.d |
| 4 | If your activity requires authorisation: its details and the body that supervises you | LSSI, art. 10.1.c |
| 5 | Prices state whether they include taxes and delivery costs | LSSI, art. 10.1.f |
| 6 | Each form shows the controller, the purpose, the rights and a link to the policy next to the button | LOPDGDD, art. 11 |
| 7 | The privacy policy covers all of art. 13: purposes, legal basis, recipients, retention periods and rights | GDPR, art. 13.1 and 13.2 |
| 8 | The controller’s details are yours, and the data protection officer is listed if you are required to have one | GDPR, art. 13.1.a and b; LOPDGDD, art. 34 |
| 9 | No checkbox comes pre-ticked, and the newsletter has its own optional checkbox | GDPR, art. 7.2 and recital 32 |
| 10 | You have a processor contract with your hosting, email, CRM and online booking calendar providers | GDPR, art. 28.3 |
| 11 | Commercial emails only go to those who authorised them or are clients, and each one lets them unsubscribe | LSSI, arts. 21 and 22.1 |
| 12 | Before the user decides, no analytics, advertising, video, map or booking calendar cookie or tag loads | LSSI, art. 22.2 |
| 13 | The banner has “Reject” in the first layer, at the same level as “Accept” | AEPD cookie guide, sections 3.1.2.2 and 3.2.1 |
| 14 | If there is more than one purpose, “Settings” leads to a panel by purpose, with nothing pre-ticked | AEPD cookie guide, section 3.1.2.2 |
| 15 | After rejecting, no new analytics, advertising or video cookie or request appears | LSSI, art. 22.2 |
| 16 | A permanent link lets the user change or withdraw consent | GDPR, art. 7.3; AEPD cookie guide, section 3.2.9 |
| 17 | The cookie policy lists each cookie, who uses it, what for and how long it lasts, and matches what is installed | AEPD cookie guide, section 3.1.1 |
| 18 | If you sell online: general terms and conditions that can be saved and all the pre-contractual information before payment | LSSI, art. 27; Consumer Protection Law, art. 97 |
| 19 | If you sell online: “order with obligation to pay” button, 14-day withdrawal and its form | Consumer Protection Law, arts. 97.1.j, 98.2, 102 and 104 |
| 20 | If Law 11/2023 applies to you: accessibility information in the terms or on a linked page | Law 11/2023, art. 13.2 |
Cautious approach: fix points 6, 12, 13 and 15 first. Any visitor can check them in a minute, and the three cases above began with a complaint from a user.
What to do on Monday
- Do the 20-minute audit on your home page and your contact page, and note down what loads before the user decides.
- If anything loads before the user accepts, ask whoever runs your website to block it until consent is given. For Google tags, use basic mode.
- Search your texts for “XXX”, “15/1999”, “litigios en línea” and any name that is not yours.
- Put the basic information next to each form and remove pre-ticked checkboxes.
- Ask your suppliers for their processor contract: hosting, email, CRM and booking calendar.
- If you sell online, check the payment button and withdrawal, and prepare the “withdraw from contract here” function.
- Give the checklist to whoever reviews your texts. The legal content must be validated by a lawyer or a data protection consultant.
If you are going to rebuild your website, now is the time to sort out the banner, the forms and the videos at the design stage. At NOR studio we start from this list in every website we design, and the legal content is validated by your adviser.
Sources consulted (25)
- BOE: Law 34/2002 on information society services and electronic commerce (LSSI), arts. 10, 20, 21, 22, 27, 38, 39, 39 bis, 39 ter, 43 and annex
- BOE: Regulation (EU) 2016/679, General Data Protection Regulation (arts. 6, 7, 12, 13, 28 and 83, and recital 32)
- BOE: Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (arts. 11, 34, 72 and 74, and sole repealing provision)
- AEPD: Guide on the use of cookies (May 2024 version)
- AEPD: Use of cookies for audience measurement tools (January 2024 version)
- AEPD: Decision in procedure PS/00040/2024 (YouTube cookies without consent and without an option to reject)
- AEPD: Decision in procedure PS/00079/2023 (Google Analytics cookies before consent)
- AEPD: Decision in procedure PS/00458/2023 (privacy policy with “XXXXX” as controller)
- BOE: Royal Legislative Decree 1/2007, General Law for the Defence of Consumers and Users (arts. 97, 98, 102, 104, 105 and 107; consolidated text updated on 28 February 2026)
- BOE: Directive (EU) 2023/2673, which adds art. 11 bis (withdrawal function) to Directive 2011/83/EU
- BOE: Regulation (EU) 2024/3228, which repeals Regulation (EU) 524/2013 and discontinues the European online dispute resolution platform
- BOE: Law 11/2023 on the accessibility of certain products and services (arts. 3.3 and 13.2, eighteenth final provision)
- BOE: Royal Decree 193/2023 on the basic accessibility conditions for goods and services available to the public (sixth final provision)
- Google: How Google uses information from sites or apps that use our services
- Google Analytics Help: About consent mode (basic and advanced)
- Google Analytics Help: [GA4] Google Analytics cookie usage on websites
- YouTube Help: Embed videos and playlists (privacy-enhanced mode)
- Meta for Developers: fbp and fbc parameters (Meta Pixel _fbp cookie)
- Calendly: Calendly cookie management and banner
- Calendly: Data Processing Addendum
- WhatsApp Help Center: How to use click to chat
- Google Chrome Help: Browse in private (third-party cookies in Incognito mode)
- Chrome for Developers: Open Chrome DevTools
- Chrome for Developers: View, add, edit and delete cookies
- Chrome for Developers: Network features reference (third-party requests filter)