{"id":11150,"date":"2026-05-18T09:20:38","date_gmt":"2026-05-18T08:20:38","guid":{"rendered":"https:\/\/lawwwing.com\/?p=11150"},"modified":"2026-05-18T10:01:36","modified_gmt":"2026-05-18T09:01:36","slug":"legal-notice-privacy-policy-cookie-policy","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/legal-notice-privacy-policy-cookie-policy\/","title":{"rendered":"Legal Notice vs Privacy Policy vs Cookie Policy in Spain (2026)"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p>If you run a website in Spain, you are legally required to publish three separate documents: a <strong>legal notice<\/strong> (<em>aviso legal<\/em>), a <strong>privacy policy<\/strong> and a <strong>cookie policy<\/strong>. All three form part of your website's legal texts, but each one serves a different purpose and is governed by different legislation. Mixing them up \u2014 or copying a generic template from the internet \u2014 can result in a fine from Spain's data protection authority (AEPD). Here's exactly what sets them apart and what each one must contain.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is a Legal Notice and Why Is It Mandatory for Every Website?<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>The <strong>legal notice<\/strong> (<em>aviso legal<\/em>) is the document that identifies who owns and operates the website. It is required under <strong>Article 10 of Law 34\/2002 on Information Society Services and Electronic Commerce (LSSI-CE)<\/strong>, and is mandatory for any website with activity in Spain \u2014 regardless of whether you sell products, collect data or simply publish content.<\/p>\n\n\n\n<p>A legal notice must include, at a minimum:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Full name or company name of the website owner<\/li>\n\n\n\n<li>Tax identification number (NIF\/CIF)<\/li>\n\n\n\n<li>Postal address or email address for contact<\/li>\n\n\n\n<li>Company registration details (if incorporated)<\/li>\n\n\n\n<li>For regulated professions (doctors, lawyers, architects\u2026): professional licence number and governing body<\/li>\n<\/ul>\n\n\n\n<p>Failure to comply with the LSSI-CE can result in <strong>fines of up to \u20ac150,000<\/strong> in the most serious cases.<\/p>\n\n\n\n<p><strong>What a legal notice is NOT:<\/strong> it does not regulate the processing of personal data, nor does it inform users about the use of cookies. Those are covered by the other two documents.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">What Is a Privacy Policy and When Is It Required?<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>The <strong>privacy policy<\/strong> is the document that tells users how you collect, use and protect their personal data. It is mandatory for any website that collects data \u2014 even if it's just an email address through a basic contact form.<\/p>\n\n\n\n<p>Its legal basis is the <strong>General Data Protection Regulation (GDPR, EU Regulation 2016\/679)<\/strong> and <strong>Organic Law 3\/2018 on Personal Data Protection and Digital Rights Guarantee (LOPDGDD)<\/strong>, which adapts the GDPR to Spanish law.<\/p>\n\n\n\n<p>A privacy policy must inform users of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Who is the data controller (the person or company responsible for the data)<\/li>\n\n\n\n<li>What data is collected and for what purpose<\/li>\n\n\n\n<li>The legal basis for processing (consent, legitimate interest, contract performance\u2026)<\/li>\n\n\n\n<li>How long the data is retained<\/li>\n\n\n\n<li>Who the data may be shared with (third parties, countries outside the EU\u2026)<\/li>\n\n\n\n<li>Users' rights: access, rectification, erasure (\"right to be forgotten\"), portability, restriction, objection<\/li>\n<\/ul>\n\n\n\n<p><strong>The AEPD issued 299 sanctions totalling \u20ac40 million in 2025<\/strong>, many of them for privacy policies that were missing, incomplete or copied without being adapted to the actual business. A generic policy downloaded from the internet does not comply with GDPR requirements unless it accurately reflects how you actually process data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is a Cookie Policy and What Does the AEPD Require?<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>The <strong>cookie policy<\/strong> informs users about which cookies your website uses, what they are for and how users can manage them. It is mandatory under <strong>Article 22.2 of the LSSI-CE<\/strong> and must comply with the <strong>Cookie Usage Guide published by the AEPD<\/strong> (current version).<\/p>\n\n\n\n<p>A cookie policy is not the same as a cookie banner, though the two are related:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <strong>cookie banner<\/strong> is the consent mechanism \u2014 the pop-up or bar that appears when a user first visits your site.<\/li>\n\n\n\n<li>The <strong>cookie policy<\/strong> is the full, detailed document describing all cookies used.<\/li>\n<\/ul>\n\n\n\n<p>A cookie policy must include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The types of cookies used (first-party, third-party, session, persistent)<\/li>\n\n\n\n<li>The purpose of each cookie (analytics, advertising, functional, strictly necessary)<\/li>\n\n\n\n<li>The retention period for each cookie<\/li>\n\n\n\n<li>Whether data is transferred to third countries<\/li>\n\n\n\n<li>How users can accept, reject or withdraw their consent<\/li>\n<\/ul>\n\n\n\n<p>The AEPD has issued fines of <strong>up to \u20ac90,000 for installing cookies without prior consent<\/strong>, and has ruled that even using Google Analytics without proper configuration can constitute a violation.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Comparison Table: Legal Notice vs Privacy Policy vs Cookie Policy<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Feature<\/th><th>Legal Notice<\/th><th>Privacy Policy<\/th><th>Cookie Policy<\/th><\/tr><\/thead><tbody><tr><td><strong>Purpose<\/strong><\/td><td>Identify the website owner<\/td><td>Inform users about personal data processing<\/td><td>Inform users about cookie usage<\/td><\/tr><tr><td><strong>Legal basis<\/strong><\/td><td>LSSI-CE (Art. 10)<\/td><td>GDPR + LOPDGDD<\/td><td>LSSI-CE (Art. 22) + AEPD Cookie Guide<\/td><\/tr><tr><td><strong>Always mandatory?<\/strong><\/td><td>Yes, for every website<\/td><td>Only if personal data is collected<\/td><td>Only if the website uses cookies<\/td><\/tr><tr><td><strong>Requires active consent?<\/strong><\/td><td>No<\/td><td>No (except for data processing itself)<\/td><td>Yes, for non-essential cookies<\/td><\/tr><tr><td><strong>Maximum fine for non-compliance<\/strong><\/td><td>Up to \u20ac150,000 (LSSI)<\/td><td>Up to \u20ac20M or 4% of global turnover (GDPR)<\/td><td>Up to \u20ac20M or 4% of global turnover (GDPR)<\/td><\/tr><tr><td><strong>Must be updated when?<\/strong><\/td><td>When owner's details change<\/td><td>With every change in data processing<\/td><td>With every change in cookies used<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Can I Combine All Three Documents Into One Page?<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>There is no legal obligation to have them on separate pages, but <strong>best practice \u2014 and the most common approach<\/strong> \u2014 is to publish them as individual pages or at least clearly distinct sections. The AEPD requires that information be easily accessible, readable and understandable.<\/p>\n\n\n\n<p>Some CMS platforms like WordPress or Shopify combine the privacy policy and cookie policy into a single \"Privacy and Cookie Policy\" page. This is acceptable provided both documents are complete and clearly differentiated within the page.<\/p>\n\n\n\n<p>What is <strong>not acceptable<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Having only one of the three documents and omitting the others<\/li>\n\n\n\n<li>Using generic templates that don't reflect your actual website or business<\/li>\n\n\n\n<li>Failing to update the documents when you add new tools (Google Analytics, Meta Pixel, live chat, etc.)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<p><strong>Does my personal blog also need all three documents?<\/strong> Yes. If your blog uses cookies \u2014 which is almost inevitable with WordPress, Google Analytics or any social sharing plugin \u2014 and if you have a contact form or newsletter sign-up, you need all three documents. The legal notice is always required, regardless of the type of website.<\/p>\n\n\n\n<p><strong>What happens if I copy the legal texts from another website?<\/strong> Copying another website's legal texts is a serious mistake on two levels: legally, the owner's details won't match yours, which is a direct violation of the LSSI-CE; technically, if the other site uses different tools from yours, the cookie policy will be inaccurate and non-compliant. The AEPD can sanction you even if you have the documents, if they are inaccurate or outdated.<\/p>\n\n\n\n<p><strong>How often should I update these documents?<\/strong> You should review your legal texts whenever: (1) you add or change tools that collect data or install cookies (CRM, ad pixels, live chat\u2026); (2) there is a relevant regulatory update (new AEPD cookie guide, GDPR amendments\u2026); or (3) the website owner's details change. At a minimum, an annual review is strongly recommended.<\/p>\n\n\n\n<p><strong>Does a cookie banner replace the need for a cookie policy?<\/strong> No. They are complementary. The banner collects consent; the cookie policy is the detailed document that the banner must link to. Without the policy, the banner does not meet AEPD requirements.<\/p>\n\n\n\n<p><strong>What's the difference between a privacy policy and a cookie policy in relation to GDPR?<\/strong> Both relate to GDPR, but they cover different aspects. The privacy policy governs personal data processing in general \u2014 forms, orders, user registrations. The cookie policy focuses specifically on the data processing that results from installing cookies, which may also involve personal data if cookies are used for tracking or identification. In practice, many websites merge them into a single \"Privacy and Cookie Policy\" document.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: Three Documents, One Obligation \u2014 Compliance<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>A legal notice, privacy policy and cookie policy are distinct obligations under different laws, but they share the same goal: ensuring that your website's users know their rights and understand how you handle their information.<\/p>\n\n\n\n<p>In 2026, with the AEPD tightening its enforcement \u2014 299 sanctions and \u20ac40 million in fines in 2025 alone \u2014 having outdated or copied legal texts is a real risk for any business, large or small.<\/p>\n\n\n\n<p>The good news is that you don't need to write them from scratch or hire a lawyer every time the law changes. <strong><a href=\"https:\/\/lawwwing.com\">Lawwwing<\/a><\/strong> automatically generates a customised legal notice, privacy policy and cookie policy for your website, keeps them updated as regulations evolve, and integrates them with your cookie banner on WordPress, Shopify, Wix and more. <a href=\"https:\/\/app.lawwwing.com\/signup\/\">Try it free<\/a> and have your website compliant in under 10 minutes.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><em>Sources: <a href=\"https:\/\/www.boe.es\/buscar\/act.php?id=BOE-A-2002-13758\">LSSI-CE - BOE<\/a> | <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32016R0679\">GDPR - EUR-Lex<\/a> | <a href=\"https:\/\/www.aepd.es\/guias\/guia-cookies.pdf\">AEPD Cookie Guide<\/a> | <a href=\"https:\/\/www.boe.es\/boe\/dias\/2018\/12\/06\/pdfs\/BOE-A-2018-16673.pdf\">LOPDGDD - BOE<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you run a website in Spain, you are legally required to publish three separate documents: a legal notice (aviso legal), a privacy policy and a cookie policy. All three form part of your website's legal texts, but each one serves a different purpose and is governed by different legislation. Mixing them up \u2014 or [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":11151,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[203,210,209,200,208,207,201,211,202,206],"tags":[],"class_list":["post-11150","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-en","category-data-protection","category-gdpr-en","category-legal-notice","category-lopd-en","category-lopdgdd-en","category-privacy-en","category-privacy-policy-en","category-rgpd-en","category-web-legal-texts"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=11150"}],"version-history":[{"count":2,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11150\/revisions"}],"predecessor-version":[{"id":11167,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11150\/revisions\/11167"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/11151"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=11150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=11150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=11150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}