Compliance

Cookies, GDPR and Spain's LSSI: what your website actually needs

Not legal advice — a practical look at what a Spanish website needs for consent, what people forget, and the embeds that quietly load trackers anyway.

7 min read

The Spanish data protection conversation has two parts, and most websites in this market only know about one of them. There is the GDPR, which applies across Europe. There is also the LSSI — Ley 34/2002, Ley de Servicios de la Sociedad de la Información — which adds its own rules about cookies and consent on top. Get the first one right and ignore the second and you are still exposed. We are not lawyers, and this is not legal advice, but it is the checklist we build to.

What the law actually asks for

Consent has to be informed, specific, unambiguous and freely given. In practice that means a banner that explains what is being stored and why, in a language the visitor understands, before anything non-essential loads. It also means the option to refuse has to be as easy to find and as easy to use as the option to accept.

  • No analytics, advertising or marketing tag loading before someone has agreed
  • A genuine 'reject all' that is as prominent as 'accept all', not a greyed-out link
  • Granular choices where people want them — cookies, measurement, marketing, third parties
  • A record of what was consented to and when, so you can answer a question later
  • A way to change the decision later, on every page, not just by clearing cookies

The embeds everyone forgets

This is where well-intentioned sites get into trouble. The cookie banner is fitted, the policy is written, and then somebody adds a booking widget, a map, a Facebook pixel, an Instagram feed, a YouTube video and a live chat tool — and every one of those arrives from a different company and sets its own storage. The visitor agreed to one thing and ended up with six.

  • Google Analytics, or the Spanish-hosted equivalents people use instead
  • The Meta pixel, and any retargeting tag that follows a visitor around
  • Booking.com, Resy and restaurant reservation widgets
  • YouTube embeds, and the cookies they set before you press play
  • Google Maps embeds, which are not as harmless as they look
  • Fonts and scripts loaded from someone else's content delivery network

What we actually build

A consent layer that actually blocks. Not one that fires a message and then loads the script regardless — we have taken over sites where the 'reject' button did precisely that, which is worse than having no banner at all, because it looks compliant to everyone except the visitor. Blocking means the script does not execute until the decision has been made, and it stays blocked for anyone who declines.

On top of that: a privacy policy written around what your business genuinely does, with retention periods rather than vague promises; a legal notice that identifies the business properly; hosting inside the European Union wherever there is a choice; and analytics that stay switched off until the visitor agrees to them.

When the data is genuinely sensitive

Health information, identity documents, NIE and passport scans, legal and tax details — these belong to a different category under the GDPR, with a higher bar and shorter retention. A clinic enquiry form that asks for a medical history is collecting more than it needs. A gestor's site that takes a passport over email is doing something no amount of cookie policy makes acceptable. Where documents are needed, we build a secure route with a defined deletion date, and say on the page when the file will be destroyed.

Newsletters and the messages you send

A newsletter needs its own consent, and it needs to be consent for that newsletter — not a vague 'by continuing to browse'. Every message needs a working unsubscribe that takes one click and does not ask for a reason. And if you email a list you bought rather than earned, you are inviting an administrative fine that nobody needs.

The practical version: get the technical side right, then have a Spanish lawyer read the legal wording. We handle the first properly and we would always rather you did the second than took our word for it. If you already have a site and are not sure what state it is in, ask for a free audit and we will tell you what is missing before you spend anything on it.

Free, no-obligation

Get a free website audit and quote

Tell us about your business and we’ll come back with honest, friendly advice — including a clear quote and what we’d improve first.

Trusted by businesses across Marbella & the Costa del Sol