Data protection
Cookie policy: what the law requires and why a badly built banner gives you away
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: the cookie policy explains which cookies your website uses and what for, and it goes hand in hand with a banner that asks for permission before switching them on. Article 22.2 of Ley 34/2002 (LSSI, Spain's information society services act) requires it, and the consent has to meet the conditions of the RGPD (art. 7). The most common and most penalised mistake is a banner that only offers "Accept" and hides the refusal. Tranquilia generates the policy tailored to the cookies you actually use.
Contents
- What is the cookie policy?
- What does the law say?
- The banner: refusing has to be as easy as accepting
- What risk do you run if the banner is wrong?
- How Tranquilia generates it
- Frequently asked questions
- Official sources
What is the cookie policy?
It is the document where you list the cookies and similar technologies your website uses: which ones are technical (necessary for the website to work), which ones are for analytics or advertising, who places them and how long they last. It is linked from the cookie banner and from the footer.
A cookie is a small file that a website stores in the browser of whoever visits it. Some are essential; others are there to measure or to follow you around with adverts, and those need your permission.
What does the law say?
Art. 22.2 of the LSSI allows the use of cookies that are not strictly necessary only if the person has given their consent, after receiving clear information about them. And that consent has to comply with the RGPD: it must be free, specific, informed and unambiguous (art. 7) — that is, a clear act of saying "yes", not silence and not a pre-ticked box.
Technical cookies (the ones that make the website work, such as keeping your basket) do not need permission. Analytics, personalisation or advertising ones do.
The banner: refusing has to be as easy as accepting
This is where the most common mistake is. The AEPD, in its cookies guide, makes it clear that:
- There has to be an option to refuse that is as visible and as easy as the one to accept.
- Options cannot be pre-ticked, and cookies cannot be switched on before the person decides.
- Carrying on browsing is not equivalent to accepting.
A banner with a big "Accept all" button and a refusal hidden three clicks away does not comply: it is exactly the pattern the AEPD points to as wrong.
What risk do you run if the banner is wrong?
Badly asked-for cookies are one of the easiest things to check: the AEPD itself (Agencia Española de Protección de Datos, Spain's data protection authority) can look at your banner without setting foot in your business. Breaches of the LSSI on cookies are classified as an infringement, and the AEPD has penalised websites for banners that did not let people refuse.
We do not give an exact figure here because it depends on the case, but we will give an honest idea: this is one of the most visible breaches and one of the cheapest to avoid, which is why it is worth having the banner and the policy properly done from the start.
How Tranquilia generates it
Tranquilia generates the cookie policy from what your website actually uses, without listing cookies you do not have or promising a banner that does not comply. You end up with a clear text, linkable from the footer and consistent with the consent you ask for.
Frequently asked questions
If my website only has technical cookies, do I need a banner?
You do not need to ask permission for strictly necessary cookies. Even so, it is worth saying that you only use technical cookies, so that it is clear you are not tracking anybody.
Does Google Analytics need consent?
Yes. Analytics is not considered strictly necessary, so its cookies can only be switched on after the person accepts. Before that "yes", they should not load.
Does the cookie policy replace the privacy policy?
No. They are different documents: the cookie one is about tracking on the website (LSSI), and the privacy one is about the processing of personal data in general (RGPD). Many websites have both.
Official sources
- BOE — Ley 34/2002 (LSSI), article 22.2.
- Reglamento (UE) 2016/679 (RGPD), article 7 (conditions for consent) — text at EUR-Lex.
- AEPD — Guía sobre el uso de las cookies (PDF).
General information about the rules. It does not replace a lawyer's advice or an analysis of your specific case. If you have any doubts, check with your gestoría (a firm that handles other businesses' administrative paperwork) or with a legal professional.
Review: Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.