Markets

B2B website visitor identification in Spain

Spain has one of the most active data protection regulators in Europe. The AEPD publishes detailed practical guides, updates its cookie guidance regularly, and issues a high volume of decisions — which means Spanish buyers tend to ask about specific published requirements rather than about principles in the abstract.

  • FrameworkGDPR + LOPDGDD (Ley Orgánica 3/2018)
  • SupervisionAgencia Española de Protección de Datos (AEPD)
  • Usual legal basisInterés legítimo, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

This page covers the Spanish framework, the LSSI duties that sit alongside the GDPR, and what a Spanish review typically wants to see.

At a glance

Framework
GDPR + LOPDGDD (Ley Orgánica 3/2018)
Supervision
Agencia Española de Protección de Datos (AEPD)
Usual legal basis
Interés legítimo, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in Spain

Regulation at a glance

  • FrameworkGDPR + LOPDGDD (Ley Orgánica 3/2018)
  • SupervisionAgencia Española de Protección de Datos (AEPD)
  • Usual legal basisInterés legítimo, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Spain implements the GDPR through the LOPDGDD, Ley Orgánica 3/2018, which is a substantial national act rather than a thin implementing law. It restates and extends parts of the GDPR, adds detail on the role of the data protection officer, sets national rules on data subject rights procedures, and contains a set of provisions on digital rights that have no direct equivalent elsewhere.

One LOPDGDD feature is directly relevant to B2B: Article 19 addresses the processing of contact data of individuals acting in their capacity as representatives of a legal entity, and treats such processing for the purpose of maintaining the business relationship as capable of resting on legitimate interest. That is a helpful anchor in a B2B setting, and it is worth citing in a Spanish assessment — but note the scope. It concerns business-contact data of representatives, not a general licence to build visitor profiles, and it does not remove the need for transparency or for a balancing test.

The cookie layer sits in the LSSI-CE, Ley 34/2002, whose Article 22.2 requires information and consent before storing or retrieving data on a visitor's device, with an exemption for what is strictly necessary. The AEPD's cookie guide is the practical yardstick here and is unusually specific: it addresses banner design, the requirement that rejecting be as accessible as accepting, and how to handle continued browsing. If your site runs a banner, it will be measured against that guide.

The LSSI also imposes duties that are not about privacy at all but come up in the same review: the obligation to publish identifying information about the service provider on the website, and rules on commercial communications by electronic means. Spanish reviewers often bundle those questions into the same conversation, so having your legal notice and outreach practice in order shortens the process.

Enforcement style matters too. The AEPD acts on individual complaints frequently and publishes its resolutions, which makes it comparatively easy to see what it objects to — most often unclear banners, missing information and opaque transfers rather than the existence of B2B analytics as such.

How Spanish buyers review it

Spanish B2B buyers, especially in mid-market and larger companies, will ask for the contrato de encargado del tratamiento (processor agreement) early and expect a sub-processor list with it. Questions about the processing location are common and an EU answer settles them quickly.

Spanish-language material helps in the sales conversation, and while lead.box's documentation is published in English and German, the substance a Spanish reviewer needs — what is stored, the legal basis, the location, the opt-out — is short enough to be summarised for an internal memo. Be explicit that no individual visitors are named; the LOPDGDD's digital-rights framing makes reviewers sensitive to anything resembling person-level profiling.

Expect a practical closing question: how does a visitor exercise their rights? Pointing at a public opt-out page and at the paragraph you add to your privacy policy is the answer that lands.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

Industrial and agri-food exporters, tourism and hospitality suppliers, IT services and B2B software companies see the clearest benefit. Spanish B2B sales cycles are relationship-heavy: knowing which company has been on your site gives a commercial team a legitimate reason to open a conversation that would otherwise be cold.

It is also useful for foreign vendors selling into Spain, where a locally relevant follow-up beats generic outreach by a wide margin.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

The Agencia Española de Protección de Datos (AEPD) is the national supervisory authority for private companies, alongside regional authorities in Catalonia, the Basque Country and Andalusia that cover their own public sectors. The AEPD is one of the most active regulators in the EU: it resolves a high volume of individual complaints, publishes detailed guides on cookies, legitimate interest and specific sectors, and makes its resolutions public, which gives companies an unusually clear picture of what it actually objects to in practice. For a private company website selling B2B, the AEPD and its published guidance — not just the GDPR text in the abstract — are the working reference. Spanish reviewers frequently cite a specific AEPD guide by name when asking questions, so being able to point to the relevant one shortens the conversation considerably.

It provides a genuinely useful anchor that most other member states' implementing laws do not have. Article 19 of the LOPDGDD addresses the processing of contact data belonging to individuals acting in their capacity as representatives of a legal entity, and treats processing carried out for the purpose of maintaining that business relationship as capable of resting on legitimate interest. That is directly relevant to B2B visitor identification and worth citing explicitly in a Spanish legal assessment. It is important to keep the scope accurate, though: Article 19 concerns business-contact data of named representatives, it is not a general licence to build individual visitor profiles, and it does not remove the need for transparency toward visitors or for carrying out a documented balancing test before relying on legitimate interest.

Article 22.2 of the LSSI-CE (Ley 34/2002) requires clear information and prior consent before storing or retrieving information on a visitor's device, unless doing so is strictly necessary for a service the visitor has explicitly requested. The AEPD's cookie guide is unusually detailed for a European regulator: it sets concrete expectations for banner layout, states plainly that rejecting cookies must be exactly as accessible as accepting them, and addresses grey areas such as continued browsing and pre-ticked boxes. lead.box identifies companies from network-level information rather than placing an advertising identifier or fingerprinting script on a visitor's device, so it does not fall within what that consent requirement targets — but the rest of your site's banner is still measured against the AEPD guide independently of this tool, and Spanish reviewers check that carefully.

Visitor data is processed in ISO-certified EU data centres, and the Art. 28 GDPR data processing agreement together with a versioned, named sub-processor list is published so a Spanish legal or procurement reviewer can complete their assessment before any commercial commitment is made. This matters in Spain specifically because the AEPD has been active on international transfer questions since Schrems II, and Spanish reviewers routinely ask where data lands as one of their first questions, well before discussing legal basis or retention. Being able to answer with an EU-only location, backed by a public sub-processor list rather than a promise made over a call, typically closes that line of questioning immediately and lets the conversation move on to the more substantive legitimate-interest assessment.

The LSSI-CE also imposes duties that Spanish reviewers frequently bundle into the same conversation even though they have nothing to do with privacy as such: an obligation to publish clear identifying information about the service provider (the aviso legal) on the website, and specific rules governing commercial communications sent by electronic means, including unsolicited email. A Spanish buyer evaluating a visitor-identification tool will often ask, almost in passing, whether your own site's legal notice is complete and whether any follow-up outreach your sales team plans to send respects those commercial-communication rules. Having both in order before the conversation starts avoids an unrelated compliance gap slowing down what is otherwise a straightforward data protection review focused on the tool itself.

Not typically for data protection purposes, but Spanish procurement teams frequently cross-check a vendor's registered details — company name, CIF tax identifier, registered address — against the Registro Mercantil as part of standard supplier due diligence, separately from the privacy assessment itself. This is routine Spanish business practice rather than a data protection requirement, and it usually runs in parallel with the AEPD-focused questions about legal basis, cookies and processing location. Larger Spanish organisations, particularly in regulated sectors, sometimes also want confirmation that no telecom-specific numbering or premium-rate rules apply, which is straightforward to answer since a company-level website identifier does not involve telephone numbering at all.

Spanish B2B sales teams commonly run on Salesforce, HubSpot or homegrown CRM setups paired with a dedicated commercial team that works relationship-led sales cycles, so a visitor-identification tool needs to feed that workflow rather than sit as a standalone report. lead.box surfaces identified companies through webhooks and CSV, Excel or JSON export, letting a Spanish sales operations contact route new company records into existing pipelines, assign them by territorio or cuenta, and trigger the same commercial follow-up used for other inbound signals. Because Spanish B2B relies heavily on warm, well-prepared outreach rather than cold volume, having a named company and its viewed pages available inside the CRM before the first call gives a commercial team a legitimate, locally relevant reason to reach out.

Yes. lead.box supports self-service management of team seats, data exports and cancellation, which matters in the Spanish market because procurement teams there are used to negotiating multi-year framework agreements for larger software purchases and often expect the same rigidity from every vendor by default. Being able to add seats as adoption grows, export everything collected at any time in CSV, Excel or JSON format, and cancel directly without going through a renewal negotiation gives a Spanish buyer a lower-risk way to trial the tool before committing budget through a formal procurement cycle. This flexibility is frequently the deciding factor for mid-market Spanish companies choosing to pilot a new data source rather than commit to it outright.

Turn Spanish traffic into named companies

Add the snippet, see the first companies within a day, and give your reviewer the processor agreement up front.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links