Key Facts
Overview
Spain implements the ePrivacy Directive through Article 22 of the LSSI (Law 34/2002). While individual cookie fines are classified as "slight" offenses with a EUR 30,000 maximum, the per-URL penalty structure means non-compliance across multiple pages can result in significant cumulative fines. AEPD allows analytics exemptions similar to France's CNIL.
What This Means for Your Website
- Prior consent is required before placing non-essential cookies on Spanish visitors
- Cookie functionality must fully cease after a visitor rejects consent
- Fines of up to EUR 30,000 apply per URL, so non-compliance across multiple pages multiplies penalties
- AEPD allows consent-exempt analytics under specific privacy-friendly configurations
- GDPR penalties of up to EUR 20 million or 4% of global turnover also apply
Key Requirements
AEPD enforces Article 22 of the LSSI with per-URL fines of up to EUR 30,000. The agency has specifically fined websites where cookies continued functioning after rejection. AEPD also supports an analytics exemption for privacy-friendly configurations, similar to CNIL's approach in France. The LOPDGDD (Organic Law on Data Protection) complements the LSSI for GDPR-related aspects.
How ConsentStack Handles This
ConsentStack ensures all non-essential cookies are blocked for Spanish visitors until consent is given, and fully cease functioning upon rejection. The platform's per-page compliance eliminates the risk of per-URL fines across your website.
Penalties
Up to EUR 30,000 per URL for cookie violations (classified as slight offense). GDPR penalties also apply.
Key Requirements
- Prior consent before placing non-essential cookies under Article 22.2
- Clear and complete information about purposes before consent
- Consent must meet GDPR standards
- Cookie functionality must cease after rejection
- Analytics potentially exempt with privacy-friendly configurations
Notable Provisions
- Modest maximum fines (EUR 30,000) but applied per URL — multiple URLs multiply penalties
- AEPD allows consent-exempt analytics under privacy-friendly configs
- Active enforcement: fines for continued cookie functioning after rejection
Other ePrivacy Directive Related Regulations
Other Europe Regulations
Frequently Asked Questions
Does Spain allow analytics without cookie consent?
AEPD allows consent-exempt analytics under specific privacy-friendly configurations, similar to France's CNIL approach. Standard analytics tools typically still require consent.
What are the cookie penalties in Spain?
Up to EUR 30,000 per URL for cookie violations. Multiple non-compliant URLs multiply penalties. GDPR fines of up to EUR 20 million or 4% of global turnover also apply.
What happens if cookies keep working after rejection in Spain?
AEPD has specifically fined websites where cookies continued functioning after visitors rejected consent. ConsentStack ensures full cessation upon rejection.
Who enforces cookie laws in Spain?
AEPD (Agencia Española de Protección de Datos) enforces both LSSI cookie requirements and GDPR provisions in Spain.
Stay compliant with LSSI
ConsentStack helps you implement Opt-in consent for Spain automatically.