Email is where imported marketing practice collides with Spanish law most directly, because the gap is not a matter of design preference but of legal basis. In much of the world a commercial email to a business contact is lawful until the recipient objects. In Spain, the general position is the reverse: the message needs a lawful basis before it is sent, and for most marketing that basis is consent obtained in advance.
Two regimes operate together. The LSSI-CE governs commercial communications sent by electronic means, requiring prior authorisation and imposing identification and opt-out obligations on every message. The GDPR defines what valid consent looks like and requires that it be demonstrable. Both are enforced by the AEPD.
What valid consent has to look like.
The conditions a compliant sign-up meets
- Affirmative action — an unticked box the user ticks, not a pre-ticked one they fail to notice
- Specific to marketing — separate from accepting terms, creating an account or completing a purchase
- Informed — who is sending, what they will send, and the categories of content covered
- Granular where relevant — newsletters, offers and third-party communications treated separately
- Freely given — not a condition of accessing a service that does not require it
- Recorded — timestamp, source, wording shown, and IP or equivalent evidence retained
- Withdrawable — a working unsubscribe in every message, honoured promptly and free of charge
- Sender identified — the message must make clear who is behind it and its commercial nature
The record is the whole defence
If you cannot show how consent was obtained, you do not have it.
When a complaint arrives, the question is not whether the recipient once visited your site but whether you can produce the evidence of their agreement. Imported lists, scraped addresses and contacts acquired with an acquisition are the three sources that most often fail this test.
Where imported practice diverges.
| Practice | Common elsewhere | Position in Spain |
| Cold B2B email to named individuals | Widely practised | Requires a lawful basis; consent is the safe route |
| Purchased or rented lists | A market exists | Consent obtained by a third party rarely transfers validly |
| Pre-ticked subscription box | Historically normal | Not valid consent |
| Marketing consent bundled into terms | Frequent | Not specific or freely given |
| Opt-out only, no prior consent | The default in several markets | Insufficient as a general rule |
| Email to existing customers about similar goods | Permitted in many regimes | A narrow soft opt-in exists — conditions are strict and should be checked |
| Unsubscribe via reply only | Common | A simple, free and effective mechanism must be provided |
The soft opt-in row deserves care. Spanish law recognises a limited route for communications to people who are already customers, about products or services similar to those they bought, where the opportunity to object was given at collection and is repeated in every message. It is narrower than the equivalent in some other countries, and it is not a general licence to email a customer database about anything.
Building a list that survives scrutiny.
Step 01
Design the collection pointSeparate, unticked marketing checkbox with plain-language wording naming the sender and the content. Distinct from terms acceptance and from the purchase itself. Step 02
Use confirmed opt-inDouble opt-in is not universally mandatory, but it produces the cleanest evidence and the healthiest list. In a jurisdiction where you carry the burden of proof, this is cheap insurance. Step 03
Store the evidence properlyTimestamp, source URL, the exact wording displayed, consent version and withdrawal history — retained for as long as you rely on the consent. Step 04
Publish the information layerA privacy notice covering identity, purposes, legal basis, retention, recipients and data subject rights, linked at the point of collection. Step 05
Honour withdrawal immediatelyWorking unsubscribe in every message, processed without delay, with suppression that survives platform migrations. Does this apply to a company outside Spain?
The assumption
"We send from abroad, so our own rules apply."
GDPR reaches processing connected to offering goods or services to people in the EU. Sending marketing to Spanish recipients brings the activity within scope regardless of where the servers or the sender sit.
The workable position
Segment by recipient location, or comply at the strictest level.
Either apply Spanish and EU standards to your whole programme, or maintain a properly segmented EU list with its own consent capture and evidence trail. Mixed lists with a single opt-out policy are where problems begin.
Get the base right once
Consent capture, records and notices — before the first send.
Privacy and cookie documentation, LSSI identification, and a consent flow that produces evidence you can actually produce later. Far cheaper before launch than after a complaint.
Compliance service ↗ Terms you will meet
- LSSI-CE
- Ley 34/2002 — governs commercial communications by electronic means, including prior authorisation and identification duties.
- AEPD
- Agencia Espanola de Proteccion de Datos — the supervisory authority that investigates complaints and issues sanctions.
- Consentimiento
- Consent, which must be free, specific, informed, unambiguous and demonstrable.
- Baja / darse de baja
- Unsubscribe — the wording Spanish recipients look for in a marketing email.
- Comunicacion comercial
- Commercial communication — the regulated category your marketing email falls into.
- Responsable del tratamiento
- Data controller — the entity that must be identified and that carries the accountability.
Frequently asked
Can we email business addresses without consent?
Not as a general rule. Spanish practice does not treat B2B email as a free zone, and messages to named individuals at a company involve personal data. Some limited routes exist for generic corporate addresses and for existing customer relationships, but they are narrower than the equivalents in several other markets and should be checked before you rely on them.
Is double opt-in legally required?
Not universally mandated, but strongly advisable. Because you carry the burden of demonstrating consent, a confirmed opt-in gives you the evidence a single checkbox often does not — and it removes the risk of addresses entered by someone other than their owner.
What about a list we acquired with a business?
Treat it as unusable until you can verify what each contact consented to and whether that consent extends to communications from your entity. In many acquisitions it does not, and the cleanest route is a permission-refresh campaign under a lawful basis rather than assuming inheritance.
How long does consent last?
There is no fixed statutory expiry, but consent that is old and unexercised becomes hard to defend, particularly where the recipient has not engaged for a long period. Periodic re-permission is both a compliance measure and a list-quality measure.
Position described as at July 2026 under Spanish and EU law, including the LSSI-CE and GDPR. General information, not legal advice — lawful bases, the scope of the soft opt-in and B2B communications are fact-specific and should be reviewed professionally before a campaign is sent.