Certix

LSSI: what it is and what it requires

Certix
Certix®
· 27 May 2026 · 12 min read

Informative article. It does not replace individualised professional advice.

If your company has any digital presence — a website, an online shop, a blog or even a mobile app — the LSSICE applies to you. And it is not optional. Law 34/2002, of 11 July, on information society services and electronic commerce has been in force since 2002 and remains one of the most widely breached digital compliance rules in Spain, particularly among SMEs and self-employed professionals.

This guide explains what the LSSICE requires, how it fits alongside the GDPR and the LOPDGDD, what fines it carries, and what any organisation with a digital presence in Spain must have in order.

What is the LSSICE and why does it still matter in 2026?

The LSSICE transposed into Spanish law EU Directive 2000/31/EC on electronic commerce. Its original purpose was to provide legal certainty for internet transactions and to establish clear rules for digital service providers.

More than two decades later, the law has been amended several times — most notably in relation to cookies (art. 22.2, introduced by Law 56/2007 and Law 25/2009) and commercial communications — but its core structure remains: anyone who provides information society services must identify themselves, inform their users and comply with specific rules on electronic advertising and digital contracting.

Unlike the GDPR, the LSSICE does not regulate personal data alone. It regulates digital activity in the broadest sense: internet services, e-commerce, intermediary liability and commercial communications across any electronic channel.

LSSICE, GDPR and LOPDGDD: the digital compliance triangle

All three rules coexist and complement one another. Complying with one does not exempt you from the others. Any Spanish company with a digital presence must comply with all three simultaneously.

Rule What it regulates Supervisory authority (Spain)
LSSICE (Law 34/2002) Digital services, e-commerce, spam, cookies, legal notice, intermediary liability AEPD (spam & cookies) · Secretariat of State for Telecommunications (other matters)
GDPR (Regulation EU 2016/679) Processing of personal data across the EU AEPD (Spanish Data Protection Agency)
LOPDGDD (Organic Law 3/2018) Spanish adaptation of the GDPR + digital rights AEPD

Practical rule: when data processing occurs in the digital environment (a web form, a newsletter, analytics tools), all three rules apply simultaneously. Cookie policy, for example, is governed by the LSSICE in terms of prior consent, and by the GDPR in terms of what makes that consent valid.

Scope of application: who is bound by the LSSICE?

The LSSICE applies to information society service providers established in Spain, and also — in certain respects — to those established in another EU member state when their services are primarily directed at the Spanish market.

What is an "information society service"? The law defines it broadly: any service provided at a distance, by electronic means and at the individual request of the recipient, whether or not for remuneration. In practice, this covers:

  • Corporate websites offering information about products or services
  • Online shops (e-commerce)
  • SaaS platforms and mobile applications
  • Blogs and digital media outlets
  • Email or messaging services
  • Web hosting and internet access providers
  • Search engines

The LSSICE does not apply to services provided through non-electronic means, nor to sound broadcasting or television, nor to telecommunications services stricto sensu.

The service provider's information obligations: the legal notice (art. 10)

Article 10 of the LSSICE is the provision that most directly affects any company with a website. It requires service providers to make certain information permanently accessible in an easy and free manner to both users and competent authorities. This information is typically collected in a website's legal notice.

Required information What must be included
Corporate name Full name of the natural or legal person operating the service.
Registered address Full postal address where the provider is established.
Contact details Email address and any other data enabling direct and effective communication.
Tax identification number Spanish NIF or CIF (or equivalent) identifying the provider in commercial transactions.
Registry details If registered in the Mercantile Registry or another public register, the registration number must be stated.
Prior administrative authorisation If the activity requires prior administrative authorisation (e.g. financial or pharmaceutical services), the details of that authorisation.
Regulated professions If the provider practises a regulated profession: professional body, academic qualification, issuing state and the profession's applicable rules.
Pricing Where the service involves a price, it must be stated transparently, including applicable taxes and delivery costs where applicable.

"A legal notice is not something you copy from another website and paste onto yours. It is the document that identifies your company to your clients and to the law. When it is wrong, it is like having someone else's tax ID hanging on your door."

Mario P. Talamillo · Managing Partner, Certix®

Commercial communications by electronic means: the anti-spam rules (arts. 19–22)

The LSSICE regulates electronic commercial communications in detail — meaning any message sent by email, SMS, WhatsApp or any other electronic channel for advertising or promotional purposes, including loyalty messages and newsletters.

Prohibition of spam (art. 21)

The LSSICE prohibits the sending of advertising or promotional communications by email or other electronic means that have not been previously requested or authorised by the recipient. This is the prior opt-in principle: without prior consent, there is no sending.

Two relevant exceptions exist:

  • Pre-existing contractual relationship: if the recipient is a customer and their data was obtained lawfully, the provider may send communications about their own products or services similar to those already purchased, provided each communication offers a simple and free means to opt out.
  • Legal entities: while the LSSICE has its own framework, B2B communications also fall under the GDPR when directed at identifiable contact persons (e.g. "jose@company.com").

Identification requirements for commercial communications (art. 20)

  • They must be clearly identifiable as commercial communications.
  • The natural or legal person on whose behalf they are sent must be clearly identifiable.
  • Promotional offers (discounts, gifts, contests) must be clearly identified as such, and their terms must be accessible and presented clearly and unambiguously.
  • Unsolicited messages must be identifiable as such without the recipient having to open them (from the subject line).

The cookie policy: art. 22.2 LSSICE and GDPR

Article 22.2 of the LSSICE, as amended, requires providers to obtain the user's informed prior consent before installing cookies or other data storage and retrieval devices on their device, where those cookies are not strictly necessary for the provision of the service.

In practice, cookie regulation in Spain operates at two simultaneous levels:

Aspect LSSICE (art. 22.2) GDPR
Main obligation Prior informed consent for non-technical cookies Conditions for valid consent (free, specific, informed, unambiguous)
Technical cookies Exempt from consent (necessary for the service) Legal basis: legitimate interest or contract performance
Analytics / marketing cookies Require prior consent (opt-in) Require valid consent (art. 6.1.a GDPR)
Information Clear and complete information about cookie use Layered information (arts. 13–14 GDPR)
Withdrawal of consent Must be possible simply and without cost As easy as giving it (art. 7 GDPR)

The AEPD's Guide on the Use of Cookies (updated May 2024) sets out the criteria cookie banners must meet to be compliant. Among the most common errors: a more prominent "Accept" button than "Reject", the absence of an equally prominent refusal option, or analytics cookies loading before consent is obtained.

Electronic contracting (arts. 23–29)

The LSSICE establishes the legal framework for contracts concluded by electronic means. Its purpose is to provide legal certainty for online transactions, placing them on an equal footing with paper-based contracts.

Key principles

  • Validity of electronic contracts (art. 23): contracts concluded by electronic means produce all the effects provided for by law, provided the general requirements for contract formation are met (consent, lawful subject matter and cause).
  • Pre-contractual information obligations (art. 27): before initiating the contracting process, the provider must make permanently and freely available: the general terms and conditions, the steps to be followed, whether the contract will be archived and whether it will be accessible, technical means to identify and correct errors, and the languages in which the contract may be concluded.
  • Order confirmation (art. 28): the provider must confirm receipt of the order to the recipient by email or equivalent communication as soon as the order has been sent.
  • Durable medium (art. 24): the offer and acceptance may be archived and reproduced. The provider must supply the accepting party with an acknowledgement of receipt.

Intermediary liability (arts. 13–17)

The LSSICE establishes a specific regime of limited liability for intermediary service providers: network operators, access providers, caching service providers, data hosting providers and linking services. The general principle is that these intermediaries are not responsible for the content they transmit, store or link to, provided they have no actual knowledge of its unlawfulness and act diligently to remove it once they do.

This is relevant for companies operating platforms, marketplaces, forums or any service where users generate content.

The LSSICE sanctions framework

Infringements of the LSSICE may result in significant fines. Sanctions are classified into three tiers according to the seriousness of the conduct:

Tier Maximum fine Examples of infringement
Minor €30,000 Formal information failures (incomplete legal notice), failure to notify the recipient that the contract will be archived.
Serious €150,000 Sending commercial communications without identifying them as such, failure to provide pre-contractual information, absence of an opt-out mechanism.
Very serious €600,000 Mass sending of commercial communications without prior consent (spam), non-compliance with orders to remove unlawful content, obstruction of inspection.

In matters of cookies and spam, the AEPD (Spanish Data Protection Agency) is the competent body for investigating and resolving enforcement proceedings. Its decisions are public and searchable on the agency's website.

What every company with a website in Spain must have in order

Element Legal basis
Legal notice with all data required by art. 10 LSSICE Art. 10 LSSICE
GDPR-compliant privacy policy (arts. 13–14) Arts. 13–14 GDPR
Form adaptation: information clause and consent checkbox in every contact or lead-capture form Arts. 13–14 GDPR · Art. 7 GDPR
Cookie banner with prior opt-in for non-technical cookies Art. 22.2 LSSICE · Art. 6.1.a GDPR
Detailed cookie policy (types, purposes, third parties, duration) Art. 22.2 LSSICE · AEPD Guide 2023
Express prior consent for email marketing campaigns Art. 21 LSSICE · Art. 6.1.a GDPR
Clear identification of commercial communications (subject line + email footer) Art. 20 LSSICE
Simple and free unsubscribe mechanism in all communications Art. 22.2 LSSICE · Art. 21 GDPR
Pre-contractual information (accessible general terms and conditions) for e-commerce Art. 27 LSSICE
Automatic order confirmation / acknowledgement of receipt Art. 28 LSSICE
Data processing agreements with digital providers (hosting, CRM, email…) Art. 28 GDPR

Frequently asked questions about the LSSICE

Does the LSSICE also apply to sole traders and micro-businesses?

Yes. The LSSICE does not distinguish by company size. Any natural or legal person providing services over the internet — even a sole trader with a simple company website — is required to comply with the information obligations of article 10. An absent or incomplete legal notice is one of the most frequent infringements found in small digital businesses.

What about sending commercial emails to existing customers?

Art. 21.2 LSSICE sets out an exception for customers with a prior contractual relationship: in certain circumstances, it may be possible to send communications about your own products or services similar to those already purchased, provided the recipient has not objected and each communication includes a simple, free means to opt out. However, the correct application of this exception depends on multiple factors — the nature of the relationship, the type of products, when the data was collected and the customer's reasonable expectations — all of which must be assessed on a case-by-case basis. It must not be read as a blanket licence to send without consent. The safest approach is always to obtain explicit, documented consent. If in doubt, consult a specialist before launching any email marketing campaign.

Does my website need a cookie banner if I only use Google Analytics?

Yes. Google Analytics installs cookies on visitors' devices for analytical purposes. Since these are not cookies technically necessary for the functioning of the service, they require prior informed consent under art. 22.2 LSSICE and art. 6.1.a GDPR. The AEPD has confirmed this repeatedly in its guidelines and enforcement decisions.

Does the LSSICE apply to mobile apps?

Yes. Mobile applications that constitute an information society service — that is, those provided at a distance, by electronic means and at the individual request of the user — are subject to the LSSICE. Information obligations may be met through the app's "About" or "Legal Information" sections, and the terms must be available before the user installs or uses the service.

Are the legal notice and the privacy policy the same thing?

No. They are separate documents with different legal bases. The legal notice fulfils the identification requirements of art. 10 LSSICE. The privacy policy fulfils the obligation to inform data subjects under arts. 13–14 GDPR, explaining what data is processed, for what purpose and legal basis, how long it is retained and what rights may be exercised. A properly compliant website must have both documents, and in practice should also have a specific cookie policy.

What is the relationship between the LSSICE and the DSA Regulation?

Regulation (EU) 2022/2065 on Digital Services (DSA), applicable since February 2024, updates and expands the legal framework for digital intermediaries in the EU, particularly for larger platforms. It does not repeal the LSSICE for the national sphere, but establishes additional obligations — especially for online marketplaces, platforms with more than 45 million users in the EU and large search engines — that operate on a complementary basis. Companies potentially affected by the DSA should verify their situation specifically.


This content is for informational and educational purposes only; it does not constitute legal advice in any case. The application of regulations to each specific case requires individual analysis. For an assessment of your organisation's compliance position, contact a specialist in data protection and digital compliance.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →