If you run a business in Spain, two sets of rules apply to your website: the EU's GDPR, which covers personal data, and Spain's own LSSI-CE, which covers commercial websites. It does not matter where you are from, where your hosting is, or whether the site is in English. What matters is that the business operates in Spain.
The four things that must be there
| What | Where | What it must say |
|---|---|---|
| Legal notice (Aviso legal) | Footer link | Your name or company name, NIF/CIF, address and contact |
| Privacy policy | Footer and under every form | What data you collect, why, and how long you keep it |
| Cookie policy | Footer and from the banner | Which cookies you use and what for |
| Cookie banner | On arrival | Accept and reject equally easy |
The single most-fined mistake in Spain is not missing the banner: it is making rejection harder than acceptance. A big "Accept" button with rejection buried in a settings screen is already a breach. Both options, same screen, same prominence.
Your NIE or CIF has to be on the site
This is the one that catches out most foreign business owners, because it has no equivalent in the UK or Ireland. Spanish law requires your tax identification —NIE if you are autónomo, CIF if you have an SL— to be publicly visible in the legal notice, along with a real address. Not a PO box, not just an email.
Contact forms
- A consent checkbox that is not pre-ticked, linking to your privacy policy.
- Ask only for what you need. If you can reply with a name and a phone number, do not ask for anything else.
- Say what you will use it for. "To answer your enquiry" is fine if that is the truth.
- Marketing consent is a separate checkbox. One tick cannot cover two purposes.
Google Analytics
Analytics cannot load before the visitor accepts. The correct way is consent mode: the tag loads with everything denied by default and only switches to granted if the person accepts. Loading it straight away and showing the banner for decoration is what most sites do, and it is exactly what gets sanctioned.
What the fines actually look like
Nobody is going to fine a bar in Guardamar twenty million euros. Real sanctions from the Spanish data protection agency against small businesses run from a few hundred to a few thousand euros, and they almost always start with a complaint from a member of the public or a competitor — not a routine inspection. Low risk, but very easy to remove entirely.