Data protection rules are often seen as a formality: you copy a privacy policy from another website, install a cookie banner and consider it done. The problem is that this quick fix often doesn’t comply, and fines from the Spanish Data Protection Agency (AEPD) aren’t reserved for large companies.
This article is for guidance only and is no substitute for advice from a legal professional. Our aim is for you to know what to check and what to ask.
The legal framework, in one sentence
In Spain, a business website must mainly comply with the GDPR (the EU General Data Protection Regulation), the LOPDGDD (its Spanish implementing law) and the LSSI (the Spanish Information Society Services Act), which regulates, among other things, the legal notice and the use of cookies.
The three basic legal texts
Legal notice (aviso legal). Identifies who is behind the website: name or company name, tax ID (NIF), address and contact details. It’s mandatory for any website with an economic activity.
Privacy policy. Explains what personal data you collect, why, for how long, who you share it with and how users can exercise their rights. It has to reflect what your website actually does, which is why copying another business’s policy rarely works.
Cookie policy. Details which cookies your website uses, who sets them (you or third parties such as Google), what for and for how long.
The cookie banner: where most websites fall short
Technical cookies — the ones essential for the website to work — don’t require consent. But analytics, advertising or social media cookies do. And that consent has to meet certain conditions:
- Prior: those cookies can’t be loaded before the user accepts. Many websites show the banner, but Google Analytics has already loaded.
- Rejecting as easy as accepting: the AEPD requires the reject option to be at the same level as the accept option, without forcing users through several screens.
- No pre-ticked boxes: the user must actively choose.
- Revocable: users must be able to change their mind at any time, usually via a permanent link in the footer.
A good starting point is to ask whether you really need all the third-party cookies you have. The fewer there are, the simpler it is to comply — and the faster the website.
Contact and booking forms
Every form that collects personal data should:
- Briefly state who is responsible for the data and what it’s used for, with a link to the full policy.
- Ask only for the data needed for that purpose.
- Keep consents separate: agreeing to be contacted about a booking isn’t the same as agreeing to receive marketing. If you want to send newsletters, you need a specific, unticked checkbox.
What sits behind the website
Compliance isn’t just about the texts. It also matters where the data is stored (providers outside the EU require additional safeguards), who has access to it, how long it’s kept and whether it’s properly protected.
This is where the technical and legal sides meet: a well-built website makes compliance easier, while a poorly planned one can make it almost impossible.
A quick check you can do today
Open your website in a private window. Does the banner appear? Can you reject with a single click? Do you have visible links to the legal notice, privacy and cookie policies? Do your forms explain what you do with the data? If any answer is “no”, you know where to start.