Legal compliance guide for WordPress agencies in Spain: GDPR, AEPD, LSSI and NIS2
The legal landscape for corporate and ecommerce websites in Spain is no longer a set of theoretical guidelines. It has become a strict operating framework. In 2026, building a website in Spain with WordPress takes detailed knowledge not only of the technology but also of the national and European laws that govern privacy, ecommerce, invoicing and cybersecurity.
Ignoring these rules exposes companies to heavy sanctions from the Spanish Data Protection Agency (AEPD) and to exclusion from public tenders and approved supplier registers (SLA). This article walks through the technical requirements a WordPress installation has to meet to comply with the current regulatory framework in Spain.
How to comply with the GDPR on WordPress under AEPD rules
The GDPR (Regulation (EU) 2016/679) is the foundation of personal data processing in the European Union. In Spain it is enforced very actively by the AEPD through Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
How to host Google Fonts locally in WordPress
One of the most common and most sanctioned mistakes on WordPress sites is hotloading external resources. When a website makes a request to an external server (such as Google’s servers to download fonts), the visitor’s IP address (personal data under the GDPR) is passed to that third-party provider without explicit consent and, often, outside the European Union.
The AEPD has aligned itself with rulings from other European authorities, stating that loading Google Fonts dynamically breaches the GDPR. The technical fix in WordPress is not optional: every font must be downloaded and hosted locally on the server or bundled into the static build (for headless sites built with Astro).
To host fonts locally on a classic WordPress build:
- Download the font files (
.woff2) from Google Webfonts Helper or a similar source. - Upload the fonts to the theme or child theme folder (
/assets/fonts/). - Define the
@font-facerules in the CSS stylesheet. - Disable external requests with filters in
functions.phpor with optimisation tools.
@font-face {
font-family: 'Outfit';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url('/assets/fonts/outfit-v11-latin-regular.woff2') format('woff2');
}Choosing GDPR-compliant hosting in the EU
The GDPR requires the controller to ensure that user data is stored and processed on infrastructure that meets European rules. International data transfers to countries without an adequacy decision from the European Commission need additional safeguards (such as signing Standard Contractual Clauses, SCC).
In 2026, data sovereignty has pushed agencies towards hosting physically located in the European Union. Platforms that route traffic through proxies outside Europe without a signed DPA (Data Processing Agreement) are a significant compliance risk. CDN and hosting providers that offer storage exclusively in European data centres are the standard choice for production builds.
What the LSSI requires from a WordPress site
The LSSI (Law 34/2002) transposes the Electronic Commerce Directive into Spanish law. It governs services offered online when they form an economic activity for the provider.
What the Aviso Legal page must include
Any website in Spain that generates revenue (directly through sales or indirectly through advertising, affiliate links or lead generation) must display the following identifying information in a visible, easy and free way (usually on the Aviso Legal, or legal notice, page):
- Name or registered company name of the owner.
- Residence or physical address.
- Email address and direct contact phone number.
- Tax identification number (NIF or CIF).
- Commercial Registry (Registro Mercantil) details.
AEPD requirements for the cookie banner
Article 22.2 of the LSSI requires service providers to inform users clearly about cookies and obtain their consent before storing or accessing information on their device. The latest AEPD guidelines on cookies set strict conditions for the interface of consent banners (CMP, Consent Management Platform):
- Equal buttons: the “Reject cookies” button must have the same visual weight, the same size and the same ease of clicking as the “Accept cookies” button. Highlighting the accept button with loud colours while hiding the reject option behind hard-to-read text links is not allowed.
- Categories: users must be able to accept or reject cookies by category (analytics, advertising, functional). Technical cookies needed for the site to work (such as keeping items in the cart or remembering the language) are exempt from consent.
- Active consent: simply continuing to browse, scrolling or staying on the page no longer counts as valid consent. Tracking scripts must be fully inactive until the user clicks “Accept”.
How to build GDPR-compliant forms in WordPress
Lead capture through contact forms, newsletter sign-ups or quote requests is a critical point under AEPD scrutiny. Because WordPress relies heavily on form plugins (such as Contact Form 7, Gravity Forms or Formidable Forms), it needs careful configuration to avoid legal gaps:
Consent checkbox on the contact form
Every contact form that collects personal data (such as name, email or phone number) must include a checkbox that is unticked by default, through which the user explicitly accepts the site’s privacy policy.
- Pre-ticked boxes are not allowed.
- Form submission must stay blocked until the user actively ticks the box.
- The text next to the box must link clearly and accessibly to the Privacy Policy page.
What the first layer of privacy information must include
The AEPD requires a simplified “first layer” of information about data processing to appear directly below the form’s submit button. It must state clearly and directly:
- Controller: name of the site owner or company.
- Purpose: why the data is collected (for example, answering enquiries or sending commercial offers).
- Legal basis: the lawful basis for processing (usually the data subject’s consent).
- Recipients: whether data will be shared with third parties (for example, email marketing tools such as Brevo or Mailchimp).
- Rights: how users can exercise their rights of access, rectification, erasure and objection (for example, by emailing a dedicated mailbox).
How to log form consent in WordPress
To meet the GDPR accountability principle, the company must be able to prove that a specific user accepted the privacy policy on a specific date and time. In WordPress, this means configuring the form plugin to store in the database the IP address (partly anonymised where possible), the timestamp and the consent state of the ticked box for every form submission.
What the EAA requires from a WordPress site
The European Accessibility Act (EAA), transposed in Spain through national legislation, applies in full to a wide range of private sector companies in 2026. It requires digital services, including ecommerce sites (WooCommerce) and banking, transport or telecoms services, to be fully accessible to people with disabilities:
WCAG 2.2 level AA criteria for WordPress
The reference standard for EAA compliance is level AA of the Web Content Accessibility Guidelines (WCAG 2.2). Agencies therefore have to audit and optimise WordPress templates and blocks against strict criteria:
- Keyboard navigation: the whole site, including dropdown menus and the WooCommerce checkout, must be usable with the keyboard alone (Tab key). Focus states must be clearly visible.
- Screen readers: images need descriptive
altattributes, and interactive elements (buttons, links) need descriptivearia-labelattributes when their text content is not explicit. - Colour contrast: site text must keep a minimum contrast ratio of 4.5:1 against the background (and 3:1 for large text).
Do accessibility overlay plugins work?
Many agencies try to solve accessibility by installing overlay plugins that promise to make a site accessible automatically through a floating button. The AEPD and accessibility communities have warned that these tools do not fix the underlying code issues and sometimes interfere with the screen readers that people with disabilities already use. Accessibility has to be solved natively in semantic HTML, not with JavaScript patches.
How NIS2 affects a WordPress agency in Spain
The European NIS2 directive aims to raise the common level of cybersecurity across the European Union. Spain has transposed it through Royal Decree-law 7/2025, which considerably widens the range of regulated companies and splits them into essential and important entities.
NIS2 requirements for WordPress agencies in the supply chain
One of the most significant changes in NIS2 is its focus on supply chain cybersecurity. Regulated companies in Spain (operating in transport, energy, finance, food or chemicals) must audit their digital service providers.
If your agency builds, hosts or maintains a WordPress site for a company covered by NIS2, you have to show that your own organisation and your technical workflows meet strict cybersecurity standards:
- Access control and MFA: two-factor authentication on every CMS administrator account and every server control panel.
- Incident runbook: a documented procedure for responding to and reporting security breaches to INCIBE-CERT within 24 hours of detecting the incident.
- Dependency audits: regular review of the WordPress plugins used in production to prevent supply chain attacks (such as backdoors slipped into updates of popular plugins).
How to adapt WooCommerce to VeriFactu
Royal Decree 1007/2023 approves the regulation that sets the requirements for computerised invoicing systems (popularly known as the Anti-Fraud Law and the VeriFactu system). From 2026, invoicing systems in Spain must guarantee the integrity, retention, accessibility, legibility, traceability and immutability of records.
VeriFactu technical requirements for WooCommerce
For WooCommerce stores selling on the Spanish market, invoicing has to follow the VeriFactu rules:
- Cryptographic traceability: every invoice must include a QR code that lets the end customer verify the record directly on the Spanish Tax Agency portal.
- Record integrity: invoices cannot be changed or deleted at will in the database. Any correction or cancellation must be done through corrective invoices numbered in sequence.
- Connection to the AEAT: the software must be ready to send the invoicing records it generates automatically and in real time to the Tax Agency database.
WordPress development agencies should avoid generic plugins that store editable records and instead integrate WooCommerce through secure APIs with ERPs and electronic invoicing platforms approved by the Spanish Ministry of Finance.
Legal compliance checklist for WordPress in Spain
Below is a technical checklist of the key elements to configure on any WordPress installation for the Spanish market to achieve full regulatory compliance in 2026:
graph TD
A[Regulatory compliance in Spain] --> B[Privacy & GDPR]
A --> C[Formal obligations & LSSI]
A --> D[Security & NIS2]
A --> E[Invoicing & VeriFactu]
B --> B1["Google Fonts hosted locally"]
B --> B2["Servers with a DPA inside the EU"]
B --> B3["Tracking scripts blocked by default"]
C --> C1["Visible legal notice, privacy and cookie pages"]
C --> C2["Cookie banner with equal buttons"]
C --> C3["Explicit and informed consent"]
D --> D1["Two-factor authentication (MFA) for admins"]
D --> D2["System event logging"]
D --> D3["Automatic audit of installed plugins"]
E --> E1["Non-editable invoices"]
E --> E2["VeriFactu gateway integration"]
E --> E3["Dynamic calculation of regional VAT rates"]WordPress and WooCommerce configuration checklist
- Local fonts: remove every call to
fonts.googleapis.comorfonts.gstatic.com. - No external CDN: make sure images and static assets are served from domains under EU control.
- Up-to-date policies: accessible footer links to the Privacy Policy, Legal Notice and Cookie Policy, formatted without the long dash character (em dash).
- Compliant cookie banner: set up AEPD-compliant tools (such as Cookiebot, Complianz or lightweight custom builds on Cloudflare Workers).
- WordPress security:
- Limit failed login attempts (with security plugins or at the Cloudflare proxy level).
- Change the default WordPress database prefix (
wp_) during installation. - Install an activity audit plugin to log critical administrator actions.
- WooCommerce:
- Configure shipping zones and tax calculation for the Canary Islands (IGIC), Ceuta and Melilla (IPSI).
- Add dedicated NIF/CIF fields to the checkout billing form.
- Connect the checkout to payment gateways that implement the 3D Secure 2 (3DS2) protocols required by PSD2.
Conclusion
Regulatory compliance for a corporate website or online store in Spain is no longer a simple review of legal texts that can be solved with ready-made templates. In 2026, legality is tied directly to the design and technical architecture of the platform.
Web development agencies that take a proactive security by design and privacy by default approach do more than reduce significant legal risk for their clients. They gain a decisive competitive edge in winning the largest and most valuable projects on the Iberian market.
How to avoid AEPD sanctions on WordPress
Legal compliance in the Spanish digital ecosystem calls for proactive technical oversight:
- Managing international data transfers: after successive European court rulings on transatlantic data flows, administrators must make sure that hosting, analytics and automation providers do not transfer data to jurisdictions without adequate safeguards unless the user has expressly consented.
- Record of processing activities (RAT) in WordPress: every company must thoroughly document its contact forms, WooCommerce customer databases and login records of registered users. Building these policies directly into the project’s technical documentation gives legal peace of mind in the event of an inspection by the Spanish Data Protection Agency. Legal rigour protects the asset value of the business.
Backups and GDPR training for WordPress teams
Good cybersecurity practice reduces legal and operational risk on the web:
- Controlled updates and immutable backups: automated backup systems in data centres located in Europe make immediate recovery possible after ransomware incidents or hardware failures.
- Training the editorial team: teaching writers to handle images, author permissions and personal data responsibly builds a lasting culture of regulatory compliance across the company.







