

If your website collects user data, you need a privacy policy that complies with the GDPR and the LOPDGDD. The quickest and safest way to have one is to use a privacy policy generator that automatically adapts to your business.
In this article, we explain what your website's privacy policy must include, when it is mandatory, how to generate it correctly, and what mistakes to avoid so that it actually protects you in the event of an inspection.
A privacy policy is the document that informs your website users about what personal data you collect, for what purposes, how long you retain it, who you share it with, and how they can exercise their ARSOPOL rights.
It is mandatory whenever your website processes personal data, which includes virtually any site with:
The legal basis is the General Data Protection Regulation (GDPR, EU Regulation 2016/679), implemented in Spain through Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD). Non-compliance may result in fines imposed by the Spanish Data Protection Agency (AEPD) of up to €20 million or 4% of the company's total worldwide annual turnover, whichever is higher.

The GDPR lists the information that must be provided when data is collected directly from the data subject:
The usual shortcut is to copy the privacy policy from another website in your industry, and this is precisely what the Data Protection Agency can detect most easily. If your document mentions a Data Protection Officer you do not have, data sharing with providers you do not work with, or retention periods you do not apply, the document does not meet the duty to provide information, even if it is impeccably written.
Not all ways of obtaining a privacy policy are equally safe. That is why we have provided a comparison between filling out any free template and using a specialised automated generator that is updated according to current regulations:
| Aspect | Free template | Specialised automated generator |
| Cost | €0 | See our plans |
| Customisation | Generic template | Adapted to your actual website |
| Automation | No | Yes, includes website scanning |
| Mentions your actual providers | No | Yes, detects them automatically |
| Assigns a legal basis to each purpose | Rarely | Yes |
| Includes Spanish regulations | Rarely (usually a GDPR translation) | Yes (GDPR + LOPDGDD + LSSI-CE + TRLGDCU) |
| Automatically updated | No | Yes, automatically |
| Consent records | No | Yes |
| Platform integration | No | Yes (WordPress, Shopify, Wix, WooCommerce, etc.) |
| Risk of an AEPD fine | High (easy to detect a copied policy) | Very low (constant updates) |
| Maintenance required | Weekly/monthly | None (automatic) |
| Legal validity | Low if generic | High if specific |
Yes. As soon as you collect a name, email address, or any other personal data through a form, you are processing personal data and need to provide information about it through a privacy policy, in accordance with the GDPR.
A privacy policy regulates the processing of personal data in general (forms, orders, user accounts). A cookie policy specifically regulates the use of cookies and tracking technologies in the browser. If your website uses analytics or advertising cookies, you need both documents. The former is governed by the GDPR and the LOPDGDD; the latter by Article 22.2 of the LSSI-CE and the AEPD Guidelines. In addition, non-essential cookies require prior consent through a banner with a rejection option on the first layer.
Violations of the duty to provide information fall under Article 83.5 of the GDPR, with a maximum penalty of €20 million or 4% of total worldwide annual turnover. In practice, sanctions against Spanish SMEs for missing, incomplete, or copied privacy policies have generally ranged in the thousands of euros, but the proceedings and reputational exposure are unavoidable.
You have one month to handle a data subject rights request, which may be extended by a further two months in complex and justified cases. Failing to respond is one of the violations that the AEPD sanctions most automatically, with fines for SMEs starting at €5,000.
Lawwwing generates a privacy policy for your website that is adapted to your actual business activity, integrations, and current Spanish regulations (GDPR, LOPDGDD, LSSI-CE), and keeps it updated in accordance with current legislation.
It is fully compatible with WordPress, Shopify, Wix, WooCommerce, PrestaShop, and Magento, together with the rest of the mandatory legal texts (legal notice, cookie policy, and terms and conditions of sale). In addition, the cookie banner complies with regulations and holds Google's Gold category for Consent Mode v2.
This means you do not have to keep track of every regulatory change or manually review the text every time you add a new tool to your business. The texts are automatically updated whenever the regulations change.