Data Protection in Spain

Online privacy in Spain

Cookies are regulated in Spain, in addition to the Spanish Data Protection Act, by the Spanish Act on the Information Society Services and e-Commerce (“LSSI”), as amended in March 2012. In July 2023, the AEPD released new Guidance Notes on the use of cookies. Although the Guidance Notes are not legally binding they give useful indications on the best market practice and on the criteria that the AEPD would follow when enforcing the law. AEPD has carefully monitored the Spanish market to verify that the new criteria stated in the Guidance Notes were adequately followed. A new version of the Guidance Notes, paying special attention to "cookies' walls" was released by the AEPD in May 2024.  

The Guidance Notes require data controllers to inform cookies’ recipients – including legal entities – of the existence and use of cookies, their scope and how to deactivate them. The regulator stresses the need for cookies’ sponsors to make sure (and be able to demonstrate later on) that the user has noticed the invitation to install and use the cookies and has voluntarily and unmistakably decided to accept it. Certain types of cookies (e.g. session cookies) are exempt from these restrictions.

Continue reading

  • no results

Previous topic
Back to top