Legal compliance guide for WordPress agencies in Spain: GDPR, AEPD, LSSI and NIS2

Legal compliance guide for WordPress agencies in Spain: GDPR, AEPD, LSSI and NIS2

Last verified: September 22, 2026
12 min read
500+ WP projects

The legal landscape for corporate and ecommerce websites in Spain is no longer a set of theoretical guidelines. It has become a strict operating framework. In 2026, building a website in Spain with WordPress takes detailed knowledge not only of the technology but also of the national and European laws that govern privacy, ecommerce, invoicing and cybersecurity.

Ignoring these rules exposes companies to heavy sanctions from the Spanish Data Protection Agency (AEPD) and to exclusion from public tenders and approved supplier registers (SLA). This article walks through the technical requirements a WordPress installation has to meet to comply with the current regulatory framework in Spain.


#How to comply with the GDPR on WordPress under AEPD rules

The GDPR (Regulation (EU) 2016/679) is the foundation of personal data processing in the European Union. In Spain it is enforced very actively by the AEPD through Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

#How to host Google Fonts locally in WordPress

One of the most common and most sanctioned mistakes on WordPress sites is hotloading external resources. When a website makes a request to an external server (such as Google’s servers to download fonts), the visitor’s IP address (personal data under the GDPR) is passed to that third-party provider without explicit consent and, often, outside the European Union.

The AEPD has aligned itself with rulings from other European authorities, stating that loading Google Fonts dynamically breaches the GDPR. The technical fix in WordPress is not optional: every font must be downloaded and hosted locally on the server or bundled into the static build (for headless sites built with Astro).

To host fonts locally on a classic WordPress build:

  1. Download the font files (.woff2) from Google Webfonts Helper or a similar source.
  2. Upload the fonts to the theme or child theme folder (/assets/fonts/).
  3. Define the @font-face rules in the CSS stylesheet.
  4. Disable external requests with filters in functions.php or with optimisation tools.
@font-face {
  font-family: 'Outfit';
  font-style: normal;
  font-weight: 400;
  font-display: swap;
  src: url('/assets/fonts/outfit-v11-latin-regular.woff2') format('woff2');
}

#Choosing GDPR-compliant hosting in the EU

The GDPR requires the controller to ensure that user data is stored and processed on infrastructure that meets European rules. International data transfers to countries without an adequacy decision from the European Commission need additional safeguards (such as signing Standard Contractual Clauses, SCC).

In 2026, data sovereignty has pushed agencies towards hosting physically located in the European Union. Platforms that route traffic through proxies outside Europe without a signed DPA (Data Processing Agreement) are a significant compliance risk. CDN and hosting providers that offer storage exclusively in European data centres are the standard choice for production builds.


#What the LSSI requires from a WordPress site

The LSSI (Law 34/2002) transposes the Electronic Commerce Directive into Spanish law. It governs services offered online when they form an economic activity for the provider.

Any website in Spain that generates revenue (directly through sales or indirectly through advertising, affiliate links or lead generation) must display the following identifying information in a visible, easy and free way (usually on the Aviso Legal, or legal notice, page):

  • Name or registered company name of the owner.
  • Residence or physical address.
  • Email address and direct contact phone number.
  • Tax identification number (NIF or CIF).
  • Commercial Registry (Registro Mercantil) details.

Article 22.2 of the LSSI requires service providers to inform users clearly about cookies and obtain their consent before storing or accessing information on their device. The latest AEPD guidelines on cookies set strict conditions for the interface of consent banners (CMP, Consent Management Platform):

  • Equal buttons: the “Reject cookies” button must have the same visual weight, the same size and the same ease of clicking as the “Accept cookies” button. Highlighting the accept button with loud colours while hiding the reject option behind hard-to-read text links is not allowed.
  • Categories: users must be able to accept or reject cookies by category (analytics, advertising, functional). Technical cookies needed for the site to work (such as keeping items in the cart or remembering the language) are exempt from consent.
  • Active consent: simply continuing to browse, scrolling or staying on the page no longer counts as valid consent. Tracking scripts must be fully inactive until the user clicks “Accept”.

#How to build GDPR-compliant forms in WordPress

Lead capture through contact forms, newsletter sign-ups or quote requests is a critical point under AEPD scrutiny. Because WordPress relies heavily on form plugins (such as Contact Form 7, Gravity Forms or Formidable Forms), it needs careful configuration to avoid legal gaps:

Every contact form that collects personal data (such as name, email or phone number) must include a checkbox that is unticked by default, through which the user explicitly accepts the site’s privacy policy.

  • Pre-ticked boxes are not allowed.
  • Form submission must stay blocked until the user actively ticks the box.
  • The text next to the box must link clearly and accessibly to the Privacy Policy page.

#What the first layer of privacy information must include

The AEPD requires a simplified “first layer” of information about data processing to appear directly below the form’s submit button. It must state clearly and directly:

  • Controller: name of the site owner or company.
  • Purpose: why the data is collected (for example, answering enquiries or sending commercial offers).
  • Legal basis: the lawful basis for processing (usually the data subject’s consent).
  • Recipients: whether data will be shared with third parties (for example, email marketing tools such as Brevo or Mailchimp).
  • Rights: how users can exercise their rights of access, rectification, erasure and objection (for example, by emailing a dedicated mailbox).

To meet the GDPR accountability principle, the company must be able to prove that a specific user accepted the privacy policy on a specific date and time. In WordPress, this means configuring the form plugin to store in the database the IP address (partly anonymised where possible), the timestamp and the consent state of the ticked box for every form submission.


#What the EAA requires from a WordPress site

The European Accessibility Act (EAA), transposed in Spain through national legislation, applies in full to a wide range of private sector companies in 2026. It requires digital services, including ecommerce sites (WooCommerce) and banking, transport or telecoms services, to be fully accessible to people with disabilities:

#WCAG 2.2 level AA criteria for WordPress

The reference standard for EAA compliance is level AA of the Web Content Accessibility Guidelines (WCAG 2.2). Agencies therefore have to audit and optimise WordPress templates and blocks against strict criteria:

  • Keyboard navigation: the whole site, including dropdown menus and the WooCommerce checkout, must be usable with the keyboard alone (Tab key). Focus states must be clearly visible.
  • Screen readers: images need descriptive alt attributes, and interactive elements (buttons, links) need descriptive aria-label attributes when their text content is not explicit.
  • Colour contrast: site text must keep a minimum contrast ratio of 4.5:1 against the background (and 3:1 for large text).

#Do accessibility overlay plugins work?

Many agencies try to solve accessibility by installing overlay plugins that promise to make a site accessible automatically through a floating button. The AEPD and accessibility communities have warned that these tools do not fix the underlying code issues and sometimes interfere with the screen readers that people with disabilities already use. Accessibility has to be solved natively in semantic HTML, not with JavaScript patches.


#How NIS2 affects a WordPress agency in Spain

The European NIS2 directive aims to raise the common level of cybersecurity across the European Union. Spain has transposed it through Royal Decree-law 7/2025, which considerably widens the range of regulated companies and splits them into essential and important entities.

#NIS2 requirements for WordPress agencies in the supply chain

One of the most significant changes in NIS2 is its focus on supply chain cybersecurity. Regulated companies in Spain (operating in transport, energy, finance, food or chemicals) must audit their digital service providers.

If your agency builds, hosts or maintains a WordPress site for a company covered by NIS2, you have to show that your own organisation and your technical workflows meet strict cybersecurity standards:

  • Access control and MFA: two-factor authentication on every CMS administrator account and every server control panel.
  • Incident runbook: a documented procedure for responding to and reporting security breaches to INCIBE-CERT within 24 hours of detecting the incident.
  • Dependency audits: regular review of the WordPress plugins used in production to prevent supply chain attacks (such as backdoors slipped into updates of popular plugins).

#How to adapt WooCommerce to VeriFactu

Royal Decree 1007/2023 approves the regulation that sets the requirements for computerised invoicing systems (popularly known as the Anti-Fraud Law and the VeriFactu system). From 2026, invoicing systems in Spain must guarantee the integrity, retention, accessibility, legibility, traceability and immutability of records.

#VeriFactu technical requirements for WooCommerce

For WooCommerce stores selling on the Spanish market, invoicing has to follow the VeriFactu rules:

  • Cryptographic traceability: every invoice must include a QR code that lets the end customer verify the record directly on the Spanish Tax Agency portal.
  • Record integrity: invoices cannot be changed or deleted at will in the database. Any correction or cancellation must be done through corrective invoices numbered in sequence.
  • Connection to the AEAT: the software must be ready to send the invoicing records it generates automatically and in real time to the Tax Agency database.

WordPress development agencies should avoid generic plugins that store editable records and instead integrate WooCommerce through secure APIs with ERPs and electronic invoicing platforms approved by the Spanish Ministry of Finance.


Below is a technical checklist of the key elements to configure on any WordPress installation for the Spanish market to achieve full regulatory compliance in 2026:

graph TD
    A[Regulatory compliance in Spain] --> B[Privacy & GDPR]
    A --> C[Formal obligations & LSSI]
    A --> D[Security & NIS2]
    A --> E[Invoicing & VeriFactu]

    B --> B1["Google Fonts hosted locally"]
    B --> B2["Servers with a DPA inside the EU"]
    B --> B3["Tracking scripts blocked by default"]

    C --> C1["Visible legal notice, privacy and cookie pages"]
    C --> C2["Cookie banner with equal buttons"]
    C --> C3["Explicit and informed consent"]

    D --> D1["Two-factor authentication (MFA) for admins"]
    D --> D2["System event logging"]
    D --> D3["Automatic audit of installed plugins"]

    E --> E1["Non-editable invoices"]
    E --> E2["VeriFactu gateway integration"]
    E --> E3["Dynamic calculation of regional VAT rates"]

#WordPress and WooCommerce configuration checklist

  • Local fonts: remove every call to fonts.googleapis.com or fonts.gstatic.com.
  • No external CDN: make sure images and static assets are served from domains under EU control.
  • Up-to-date policies: accessible footer links to the Privacy Policy, Legal Notice and Cookie Policy, formatted without the long dash character (em dash).
  • Compliant cookie banner: set up AEPD-compliant tools (such as Cookiebot, Complianz or lightweight custom builds on Cloudflare Workers).
  • WordPress security:
    • Limit failed login attempts (with security plugins or at the Cloudflare proxy level).
    • Change the default WordPress database prefix (wp_) during installation.
    • Install an activity audit plugin to log critical administrator actions.
  • WooCommerce:
    • Configure shipping zones and tax calculation for the Canary Islands (IGIC), Ceuta and Melilla (IPSI).
    • Add dedicated NIF/CIF fields to the checkout billing form.
    • Connect the checkout to payment gateways that implement the 3D Secure 2 (3DS2) protocols required by PSD2.

#Conclusion

Regulatory compliance for a corporate website or online store in Spain is no longer a simple review of legal texts that can be solved with ready-made templates. In 2026, legality is tied directly to the design and technical architecture of the platform.

Web development agencies that take a proactive security by design and privacy by default approach do more than reduce significant legal risk for their clients. They gain a decisive competitive edge in winning the largest and most valuable projects on the Iberian market.

#How to avoid AEPD sanctions on WordPress

Legal compliance in the Spanish digital ecosystem calls for proactive technical oversight:

  • Managing international data transfers: after successive European court rulings on transatlantic data flows, administrators must make sure that hosting, analytics and automation providers do not transfer data to jurisdictions without adequate safeguards unless the user has expressly consented.
  • Record of processing activities (RAT) in WordPress: every company must thoroughly document its contact forms, WooCommerce customer databases and login records of registered users. Building these policies directly into the project’s technical documentation gives legal peace of mind in the event of an inspection by the Spanish Data Protection Agency. Legal rigour protects the asset value of the business.

#Backups and GDPR training for WordPress teams

Good cybersecurity practice reduces legal and operational risk on the web:

  • Controlled updates and immutable backups: automated backup systems in data centres located in Europe make immediate recovery possible after ransomware incidents or hardware failures.
  • Training the editorial team: teaching writers to handle images, author permissions and personal data responsibly builds a lasting culture of regulatory compliance across the company.
Next step

Turn the article into an actual implementation

This block strengthens internal linking and gives readers the most relevant next move instead of leaving them at a dead end.

Related cluster

Explore other WordPress services and knowledge base

Strengthen your business with professional technical support in key areas of the WordPress ecosystem.

Why does loading Google Fonts dynamically breach the GDPR in Spain?#
When fonts are downloaded from Google's servers, the visitor's IP address, which counts as personal data under the GDPR, is sent to a third party without explicit consent and often outside the European Union. The AEPD has aligned itself with other European authorities on this reading. The required fix is to download the fonts and host them locally on the server or bundle them into the static build.
What conditions does the AEPD set for a cookie consent banner?#
The reject button must have the same visual weight, size and ease of clicking as the accept button, users must be able to accept or reject by category, and continuing to browse or scrolling no longer counts as valid consent. Tracking scripts must stay inactive until the user clicks accept. Mishandled consent is one of the most frequent reasons for AEPD sanctions.
What does NIS2 require from WordPress agencies working for regulated companies?#
Royal Decree-law 7/2025 transposes NIS2 in Spain and puts the supply chain in focus. The agency must enforce two-factor authentication on every administrator account, keep a documented procedure for reporting breaches to INCIBE-CERT within 24 hours of detection, and audit the WordPress plugins running in production on a regular basis.
What technical requirements does VeriFactu place on a WooCommerce store in Spain?#
Every invoice must carry a QR code that lets anyone verify it on the Spanish Tax Agency portal, records cannot be changed or deleted at will, any correction requires corrective invoices numbered in sequence, and the software must send invoicing records to the AEAT in real time, usually through an integration with platforms approved by the Ministry of Finance.
Can the AEPD fine a company for a misconfigured cookie banner?#
Yes. Mishandled consent is one of the most frequent reasons the AEPD sanctions companies in Spain. Penalties range from a formal warning to heavy fines, depending on the size of the company and the volume of data collected unlawfully.
Can cookieless web analytics tools be used without consent?#
Yes. Some privacy-focused analytics tools (such as Plausible Analytics or Fathom Analytics) work without tracking personally identifiable information or setting persistent cookies. If they are configured not to record full IP addresses, they may be exempt from the cookie banner consent requirement under AEPD guidelines, which noticeably improves load performance and measurement accuracy.
What happens under NIS2 if a WordPress plugin on my site is hacked?#
If your organisation falls within the scope of NIS2 and suffers a security breach that affects service continuity or exposes third-party data, you must notify INCIBE-CERT of the incident within the set deadline. Failing to do so, or lacking adequate preventive technical measures, can lead to fines and civil liability for the company's directors.
Is headless WooCommerce compatible with VeriFactu rules in Spain?#
Yes, fully. A headless architecture separates the checkout process from the invoicing database. What matters is making sure the WooCommerce backend is configured to pass order data to approved invoicing software that meets the VeriFactu requirements for tamper-proof records and real-time communication with the AEAT.

Need an FAQ tailored to your industry and market? We can build one aligned with your business goals.

Let’s discuss

Related Articles