E-commerce law in Spain: the complete legal guide (2026)

E-commerce in Spain is governed by the Information Society Services Act (LSSI-CE), data protection law (the GDPR and Spain’s LOPDGDD), consumer law (the TRLGDCU) and the EU’s DSA, Omnibus and GPSR rules. Every online shop, whether it sells its own products or acts as a marketplace, must comply with them to operate lawfully and avoid penalties. It is not a single law. It is a set of European and Spanish obligations that apply cumulatively.

This guide sets out which law governs each aspect of selling online in Spain, which texts are mandatory, what rights your customers have and what penalties you risk if you do not comply.

If you need e-commerce legal advice to bring your online shop into line, request a free initial assessment.

Table of contents

Which laws govern e-commerce in Spain

Online selling in Spain is governed by six main bodies of law: the LSSI-CE (Act 34/2002), the GDPR and the LOPDGDD, the Consolidated Text of the General Law for the Protection of Consumers and Users (TRLGDCU, Royal Legislative Decree 1/2007), the Digital Services Act (DSA, Regulation (EU) 2022/2065), the General Product Safety Regulation (GPSR, Regulation (EU) 2023/988) and the rules on payments and tax. Each governs a different dimension of your shop and they all apply at the same time.

LawWhat it governsCompetent authorityMaximum penalty
LSSI-CE (Act 34/2002)Identification of the provider, electronic contracting, commercial communications and cookiesThe authority responsible for digitalisation; the AEPD for commercial communicationsUp to €600,000 (very serious infringements)
GDPR + LOPDGDD (Organic Law 3/2018)Processing of personal data and consentSpanish Data Protection Agency (AEPD)Up to €20 million or 4% of annual worldwide turnover
TRLGDCU (Royal Legislative Decree 1/2007) + Omnibus DirectiveConsumer rights, withdrawal, conformity of goods, prices and reviewsRegional consumer authoritiesConsumer penalties depending on the region
DSA (Regulation (EU) 2022/2065)Intermediary services, marketplaces and content moderationDigital Services Coordinator and European CommissionUp to 6% of annual worldwide turnover
GPSR (Regulation (EU) 2023/988)Safety of non-food products and traceabilityMarket surveillance authoritiesPenalties for placing unsafe products on the market
Payments and VAT rules (PSD2; Act 37/1992)Payment methods, strong customer authentication and VAT on distance salesBank of Spain and Spanish Tax AgencyTax and financial penalties

The practical consequence is clear: complying with only one of these laws is not enough. A shop can have an impeccable privacy policy and still be penalised for failing to inform customers of the right of withdrawal or for advertising a discount without the correct reference price.

Mandatory legal texts for an online shop

Every online shop must publish four legal texts: the legal notice, the privacy policy, the cookie policy and the general terms and conditions of sale. They must be accessible from any page, clearly written and tailored to your business model. Generic templates copied from another website are one of the most common causes of non-compliance.

Legal notice

The legal notice identifies the company or professional responsible for the shop. The LSSI-CE requires it to show the name or company name, the tax identification number (NIF or CIF), the address, contact details and, where applicable, company registration details. It is mandatory for any website with an economic activity, not only those that sell directly.

Privacy policy and cookie policy

The privacy policy explains which personal data the shop collects, for what purpose and on what legal basis, in line with the GDPR and the LOPDGDD. The cookie policy details the cookies the website uses and must come with a valid consent system: no pre-ticked boxes and a real option to refuse. Cookie consent is one of the AEPD’s most frequent areas of inspection.

General terms and conditions of sale

The terms of sale govern the sales relationship: the ordering process, prices and taxes, payment methods, delivery times and costs, the right of withdrawal, conformity of goods and dispute resolution. They must be expressly accepted before the purchase is completed. An unfair or hidden term may be declared void and lead to consumer penalties.

Before putting your first product on sale, check this legal minimum:

  • A legal notice with all identification details visible.
  • A privacy policy that matches your actual data processing.
  • A cookie policy and banner with valid consent.
  • Terms of sale expressly accepted at checkout.
  • Complete pre-contractual information (total price, delivery costs, delivery times).
  • Clear information on the right of withdrawal and a withdrawal form.

Data protection (GDPR) in e-commerce

The GDPR requires every online shop to process its customers’ personal data on a valid legal basis, with transparent information and appropriate security measures. An online shop processes data with every order, registration, newsletter and cookie, so compliance is not optional.

There are four core obligations: define the legal basis for each processing operation, obtain valid consent for marketing and cookies, keep a record of processing activities and sign data processing agreements with the providers that access data (payment gateway, logistics, email platform, hosting). Breaches can be fined up to €20 million or 4% of annual worldwide turnover. Given the complexity, it is worth relying on data protection lawyers as the volume of data or the catalogue grows.

Consumer rights: withdrawal, conformity and returns

The right of withdrawal allows consumers to return an online purchase within 14 calendar days, without giving reasons and without penalty. The period runs from receipt of the product, under Article 102 of Royal Legislative Decree 1/2007 (TRLGDCU).

The key obligation for the shop is to inform customers of this right before the purchase and provide a withdrawal form. If it does not, the return period is extended by up to twelve additional months. When the customer withdraws, the shop must refund everything paid, including standard delivery costs, within 14 calendar days; if it is late, the consumer can claim double the amount. There are specific exceptions: personalised products, perishable goods or digital content already downloaded.

On top of this come the legal conformity rules: consumers are entitled to goods in conformity with the contract and to repair or replacement if they are defective. Take, for example, a fashion accessories shop that did not inform customers of the right of withdrawal or include the form. Faced with a consumer complaint, it would have to accept the return of an order placed several months earlier, because the period would have been extended to twelve months. Reviewing the legal texts before selling would have avoided the dispute.

The DSA: obligations for marketplaces and intermediary platforms

The Digital Services Act (DSA, Regulation (EU) 2022/2065) has applied since 17 February 2024 and reaches your shop as soon as you stop selling only your own products. If you allow third parties to offer theirs, you are an online platform and take on obligations that a conventional shop does not have.

The three most often overlooked are trader traceability, which means verifying the trader’s identity before allowing them to sell (known as KYBC), the notice and action system for illegal products, and the internal complaint-handling mechanism. Penalties reach 6% of annual worldwide turnover. The four tiers of the regulation and the exemptions for micro and small enterprises are covered in our guide to the Digital Services Act.

Omnibus and GPSR: prices, reviews and product safety

The Omnibus Directive and the GPSR are two recent laws that hit online selling squarely and that most guides do not yet cover: the first governs how you advertise prices and reviews; the second, the safety of the products you sell.

Omnibus Directive

The Omnibus Directive (Directive (EU) 2019/2161) was transposed in Spain by Royal Decree-Law 24/2021 and has applied since 28 May 2022. It introduces two obligations that affect any shop. In sales, you must state the lowest price applied in the 30 days before the promotion, to prevent fictitious discounts. For reviews, you must state whether the published reviews come from customers who actually bought the product and how they are verified. Publishing fake reviews or failing to prove their authenticity is an unfair commercial practice and can be penalised.

GPSR

The General Product Safety Regulation (GPSR, Regulation (EU) 2023/988) has applied since 13 December 2024 and replaces the former 2001 directive. It requires non-food products sold in the EU to be safe and imposes traceability, minimum safety information and incident reporting obligations on manufacturers, importers, distributors and marketplaces. If you sell physical products to European consumers, your own or third parties’, the GPSR requires you to document the safety and origin of what you sell.

Payment methods, invoicing and VAT in online selling

Online selling adds payment and tax obligations that are worth reviewing from the outset. For payments, the EU’s PSD2 requires strong customer authentication (two-step verification when paying by card) and clear contracts with your payment gateway. For VAT, the distance selling regime determines where you pay tax.

If you sell to consumers in other EU countries, there is a common threshold of €10,000 a year (excluding VAT). Below it, you charge Spanish VAT. Above it, your sales are taxed in the country of destination and you can declare them from Spain through the One-Stop Shop (OSS), using Form 369. For goods imported from outside the EU in consignments of up to €150, there is the IOSS scheme. On top of all this come the contracts with your logistics and technology providers, where advice on technology contracts prevents problems with deliveries, returns and liability.

Penalties for breaching e-commerce rules

Penalties for breaching e-commerce rules vary depending on the law infringed and can be cumulative. The LSSI-CE provides for fines of up to €600,000 for very serious infringements. The GDPR goes up to €20 million or 4% of annual worldwide turnover. The DSA can fine platforms up to 6% of their worldwide turnover. On top of this come the consumer penalties imposed by the regions for unfair terms, lack of information or breach of the right of withdrawal.

Many breaches do not stem from bad faith but from copying legal texts from another website without adapting them to the business model. The cost of a poor text is rarely just the fine: it means selling for months on terms that a court may declare void, with returns and complaints that could have been avoided.

Is a legal notice mandatory for an online shop?

Yes. The LSSI-CE requires every website with an economic activity to publish a legal notice with the owner’s identification details: name or company name, tax identification number (NIF or CIF), address and contact details. It must be permanently accessible. Failing to have one is an infringement that can be penalised.

Consumers have 14 calendar days from receipt of the product to withdraw without giving reasons, under Article 102 of Royal Legislative Decree 1/2007. If the shop did not inform them of this right or provide the withdrawal form, the period is extended by up to twelve additional months.

Not always. The GDPR only requires a DPO to be appointed when the core activity involves large-scale processing or systematic monitoring of individuals. Many online shops are not required to appoint one, but all must comply with the rest of the GDPR: legal basis, information, cookie consent and contracts with processors.

The DSA’s main obligations fall on intermediary services, that is, platforms and marketplaces that connect third-party sellers with buyers. If you only sell your own products you are not an intermediary in the strict sense, although the other laws still apply to you (LSSI, consumer law, GDPR). As soon as you let third parties sell on your website, the DSA reaches you.

It depends on the law: up to €600,000 under the LSSI-CE, up to €20 million or 4% of worldwide turnover under the GDPR, up to 6% of worldwide turnover under the DSA, and regional consumer penalties for breaching buyers’ rights. Infringements can coincide and add up.

Bringing your shop into line with all these rules need not be an endless project. At Innovatech we review your online shop, identify the gaps and give you a clear roadmap. Request a free initial assessment from our e-commerce lawyers and sell online with legal certainty.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.