LOPDGDD + AEPD, cookie banner + RGPD enforcement spanish-style
LOPDGDD (Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales) is the Spanish national law that implements RGPD (GDPR) plus adds Spain-specific rules. AEPD (Agencia Española de Protección de Datos) is the enforcement body, one of the most active regulators in the EU, levying multi-million-euro fines against Spanish + foreign companies.
Concrete Magento implications:
- Cookie consent, AEPD published explicit guidance (2020, updated 2023). Must be granular, per-purpose opt-in. No pre-ticked boxes. No “continued browsing = consent”. The “Reject all” button must be as prominent as “Accept all”. Cookie walls are banned (AEPD aligned with CNIL position).
- Data residency, for sensitive sectors (health, financial, public), AEPD prefers EU-region hosting; Spanish-territory hosting is the safe posture.
- Spanish-language DSAR, data-subject access requests must be answerable in Castellano (and Catalan/Euskera/Galego if your business operates there).
- Right-to-be-forgotten audit trail, Magento
customer+orderdata with structured anonymisation pipeline (not just delete, anonymise for accounting retention). - DPO appointment, mandatory for certain categories under LOPDGDD art. 34.
We ship Cookiebot / Axeptio / Didomi (Spanish-localised) wired into Magento’s cookie API, banner copy reviewed against AEPD guidance, and a structured DSAR / RTBF workflow.