A company selling into Spain from abroad usually arrives with a consent banner that was designed for a different legal culture: a notice bar, an "accept" button, analytics already running, and a "we use cookies to improve your experience" line. In Spain that configuration is not a soft compliance gap. It is the specific pattern the supervisory authority looks for, and the one that generates fines.
Two instruments govern this. The LSSI-CE — the Spanish law on information society services and electronic commerce — requires site operators to identify themselves and to inform users about cookie use. The GDPR supplies the consent standard. The AEPD enforces both, and publishes guidance on what an acceptable banner looks like.
What "prior consent" actually requires.
The requirement is narrower than most imported banners assume, and it is testable from outside: a regulator, a competitor or a complainant can open the site and observe whether trackers fire before any interaction.
The conditions a compliant banner meets
- Nothing non-essential fires first. Analytics, advertising and social pixels stay blocked until consent is given
- Reject is as easy as accept. Both available at the same level, in comparable prominence — not one click versus a settings journey
- Granular by purpose. The user can accept some categories and refuse others
- Consent is informed. Purposes, categories, retention and third parties identified in accessible language
- No cookie walls that condition access on acceptance, absent a genuine equivalent alternative
- Withdrawal is possible and as easy as giving consent — a persistent settings link
- Consent is recorded so it can be demonstrated later; continued browsing is not consent
- Legal identification published — company name, NIF, registered address and contact, as LSSI requires
The two patterns that get sanctioned
Pre-consent tracking, and an asymmetric banner.
If Google Analytics or an advertising pixel loads on arrival, the breach is already complete and observable. If "Accept all" is a button and "Reject" requires opening preferences, the consent obtained is treated as not freely given. Both are visible from the outside in under a minute.
Where imported setups diverge from Spanish practice.
| Practice | Common outside the EU | Position in Spain |
| Analytics on page load | Standard | Breach — requires prior consent |
| Notice-only banner | Often sufficient | Insufficient — notice is not consent |
| "Accept" prominent, "Reject" hidden | Widespread | Consent not freely given |
| Implied consent by scrolling | Historically accepted | Not valid |
| Single global privacy policy | Normal | Acceptable only if it meets EU content and language expectations |
| No legal identification on site | Common for brand sites | LSSI requires name, NIF, address and contact |
| Consent records not retained | Frequent | Must be demonstrable on request |
Consent Mode and the analytics question.
Marketing teams reasonably worry that a compliant banner destroys measurement. The workable answer is a consent management platform wired to a consent-mode implementation: tags load in a denied state by default and update only when the user agrees, so nothing personal is collected pre-consent while modelled reporting still functions.
01
Block by defaultEvery non-essential tag is denied until an explicit signal arrives. This is a configuration decision, not a plugin toggle, and it should be verified in the browser rather than assumed. 02
Update on consentConsent state propagates to analytics and advertising tags at the moment of agreement, with the choice stored and re-presentable. 03
Test what actually firesOpen the site in a clean browser and inspect network requests before interacting. Most non-compliance is discovered this way, and so is most of the remediation work. Getting the legal base right
Consent, identification and policies — before the first campaign.
Site identification under LSSI, a compliant consent flow, and privacy and cookie documentation that match how your site actually behaves. Cheap before launch; expensive to reconstruct afterwards.
Compliance service ↗ Does this apply to a company with no Spanish entity?
Generally yes. GDPR reaches processing connected to offering goods or services to people in the EU or monitoring their behaviour, regardless of where the controller is established. A US or UK company running a Spanish-language site, advertising to Spanish users and measuring their behaviour is within scope — and being outside Spain does not make the site harder for a regulator or a complainant to inspect.
The assumption
"We are not established there, so it does not reach us."
Establishment is one route into scope, not the only one. Targeting and monitoring bring a foreign site within the regime, and a non-EU controller may additionally face representation obligations.
The workable position
Comply at the level of the strictest market you sell into.
One compliant consent implementation serving all EU traffic is cheaper than maintaining divergent versions and far cheaper than remediation after a complaint.
Terms you will encounter
- LSSI-CE
- Ley 34/2002 on information society services and electronic commerce — the source of cookie information duties and site identification requirements.
- AEPD
- Agencia Espanola de Proteccion de Datos — the supervisory authority that investigates and sanctions.
- Aviso legal
- Legal notice page carrying the LSSI identification details. Expected by both regulators and cautious buyers.
- Politica de cookies
- Cookie policy describing categories, purposes, retention and third parties.
- Consentimiento previo
- Prior consent — the standard that must be met before non-essential cookies are set.
- CMP
- Consent management platform — the tool that presents choices, records them and signals tags.
Frequently asked
Can we reuse our existing cookie banner from another market?
Only if it already blocks non-essential tags before consent, offers reject with equal prominence, allows granular choice and records the outcome. Banners built for opt-out jurisdictions typically fail on the first two points, which are also the easiest for a regulator to observe.
Do we need the policies in Spanish?
Consent must be informed, which in practice means intelligible to the user. For a site targeting Spanish consumers, Spanish-language policies and banner text are the defensible position; English-only documentation on a Spanish-language commercial site is a weak place to stand.
Are analytics cookies really non-essential?
As a general matter, yes — analytics is not strictly necessary to deliver the service the user requested, and the AEPD's guidance treats it accordingly. Narrow exceptions have been discussed for certain first-party measurement configurations, but relying on them without advice is a risk.
What happens if a complaint is filed?
The authority can investigate, request the consent records you are obliged to keep, and sanction. Because the underlying facts are observable from the public site, these cases are comparatively simple to establish — which is why prevention is so much cheaper than defence.
Position described as at July 2026 under Spanish and EU law, including the LSSI-CE and GDPR, with enforcement figures from published AEPD reporting. General information, not legal advice — consent design, lawful bases and identification obligations are fact-specific and should be reviewed professionally before launch.