Skip to content

Cold Email Laws in Spain: LSSI Article 21 and the GDPR (2026)

The short answer

Cold email to a Spanish recipient is prohibited unless you already have that recipient's prior, express permission, or you already have a contract with them and you are emailing about something similar to what they bought. There is no business-to-business carve-out. The rule sits in Article 21 of Ley 34/2002, known as the LSSI, and Spain's data protection authority, the AEPD, has held for years that this rule overrides the GDPR legal basis you would normally reach for.

That last point is where almost every English-language guide gets Spain wrong. The standard advice is that business-to-business cold email is defensible across the EU under legitimate interest, GDPR Article 6.1.f, with a documented balancing test. In Spain that argument does not get you to the send button, and the AEPD said so in writing.

This is a plain-English summary of published law, not legal advice. Before you run a Spanish campaign, have a Spanish lawyer review your specific setup.

Two laws, and only one of them is the GDPR

Spanish outbound sits under two separate regimes, and passing one does not pass the other.

  • The data layer. The GDPR plus Spain's implementing act, Ley Organica 3/2018 (LOPDGDD), govern whether you may lawfully hold and process a person's contact details at all.
  • The send layer. Article 21 of the LSSI governs whether you may put a commercial message into that person's inbox by electronic means.

Most compliance write-ups only address the first layer. Spanish enforcement lives in the second. Both are policed by the same regulator: Spain's own government LSSI portal confirms that while the Ministry supervises the LSSI generally, sanctioning power for Articles 21 and 22, the commercial communications articles, belongs to the AEPD.

What Article 21 actually says

The operative sentence, in the consolidated text published by the Boletin Oficial del Estado, is short. Sending advertising or promotional communications by email or an equivalent electronic medium is prohibited where they were not previously requested or expressly authorised by their recipients.

Two words carry the weight. Previously means the permission has to exist before the first message, so there is no cure by unsubscribe link. Expressly means the AEPD will not accept implied or tacit permission, a point the agency stated directly in its legal report 0164/2018.

Why legitimate interest does not rescue you

Report 0164/2018 is the document to know. Asked whether GDPR Article 6 could supply a basis for electronic marketing, the AEPD applied the principle of specialty and concluded that the legitimating grounds in Article 6 of the GDPR must yield to the special rule in Ley 34/2002, because otherwise the LSSI would be emptied of content.

The agency also pointed at Article 95 of the GDPR and recital 173, which preserve the ePrivacy Directive as the special regime for electronic communications, and at a line of Audiencia Nacional judgments running from 9 January 2009 through 2010 and 2016 that reached the same result.

So the honest position for Spain is not that legitimate interest is risky. It is that, on the regulator's published reading, legitimate interest is not the applicable test for the send at all.

Spanish law protects companies, not just people

This is the second place the usual advice fails. Under the GDPR, a message to a generic company mailbox that identifies no individual is arguably outside scope, which is why so many playbooks recommend info@ and contacto@ addresses for EU outbound.

The LSSI does not work that way. Its Annex defines a recipient of the service as a natural or legal person who uses an information society service, whether or not for professional reasons. The AEPD quotes that definition when it applies Article 21. A limited company is a protected recipient, and its inbox is protected whether or not any personal data is involved.

One narrow relief does exist in the same Annex: an email address or domain name that simply lets someone reach a business is not itself a commercial communication. Publishing your address is fine. Mailing into someone else's without permission is the regulated act.

The only exception, and its five conditions

Article 21.2 carves out an existing customer relationship. It is narrow, and the conditions are cumulative, so failing any one of them puts you back under the prohibition.

  • A prior contractual relationship must already exist with the recipient.
  • You must have obtained the contact details lawfully in the course of that relationship.
  • The message must promote products or services of your own company, not a partner's and not a group affiliate's.
  • Those products or services must be similar to what was originally contracted.
  • Every message, and the original point of collection, must offer a simple and free way to object, and email messages must contain a valid electronic address where that right can be exercised. Sending without one is itself prohibited.

Read plainly, this is a customer reactivation right, not a prospecting right. It cannot be stretched to cover a stranger who downloaded a PDF, and it cannot be inherited from a purchased list.

What the penalties really are

Spain's LSSI grades infringements in three bands, published by the government's own LSSI portal:

  • Leve: a fine of up to 30,000 euros.
  • Grave: a fine of 30,001 to 150,000 euros.
  • Muy grave: a fine of 150,001 to 600,000 euros.

A single non-compliant commercial email is a leve infringement under Article 38.4.d. Mass sending, or insistent or systematic sending to the same recipient, is grave under Article 38.3.c.

The number most people never hear is Article 39 bis. For a first infringement in the leve or grave band, where the sender has not previously been sanctioned or warned under the LSSI, the AEPD may decline to open a sanctioning file and instead issue an apercibimiento, a formal warning requiring corrective measures within a set period. That is exactly what happened in resolution R/00198/2019, where a clothing retailer sent one unsolicited Black Friday email with no unsubscribe mechanism and received a warning rather than a fine, partly because the agency found no proven harm and no proven profit.

The practical reading: the first complaint against a small sender is often survivable. The second is not, because Article 40 lists recidivism, intent, duration, profit obtained and affected turnover as the criteria that set the amount.

The three emails a year rule is long dead

Search for Spanish spam rules and you will keep meeting a specific claim: that three or more commercial emails to the same person within a year turns a minor infringement into a serious one. It appears on Spanish law firm blogs, on English compliance pages, and in more than one country-by-country matrix.

It is not in the law. The current text of Article 38.3.c refers to mass sending of commercial communications, or insistent or systematic sending to the same recipient, with no numeric threshold at all. The numeric wording belonged to an older version of the article and was replaced by Ley 9/2014, which took effect on 11 May 2014.

The correction matters in both directions. It means two emails are not automatically safe, and it means the serious band now turns on a qualitative judgement about your sending pattern rather than a counter you can plan around. If you were sizing a Spanish sequence to stay under three touches, you were optimising against a rule that has been gone for over twelve years.

Your list is the bigger exposure

Two findings should worry anyone buying Spanish contact data.

First, public availability is not a defence. In the 9 January 2009 Audiencia Nacional judgment, the sender argued the addresses were published on a university website and therefore came from publicly accessible sources. The court rejected it, and the inspection record noted the company ran software that captured email addresses from websites. Scraping a published address does not create permission to email it.

Second, and more recent, the AEPD published a set of resolutions on 16 May 2025 concerning the personal data of sole traders. It ordered the Camara de Espana to stop supplying that data to Camerdata, ordered Camerdata to stop processing and delete the records it had received, and ordered the business information providers Informa, Iberinform Internacional and Datacentric to stop processing those records until they hold a valid Article 6.1 GDPR basis, and to delete them. The reasoning was that Spain's chamber of commerce census exists for institutional purposes, that no Spanish legal framework opens it up for commercial reuse, and that sole traders could not reasonably expect their details to end up in commercial products.

That last point lands hard on outbound teams, because Spain has more than 3.4 million registered self-employed workers according to 2026 Ministry of Labour figures. A very large share of Spanish businesses are natural persons. The comfortable assumption that business-to-business means no personal data is simply not true in this market.

What lawful outreach into Spain looks like

Spain does not close the market. It closes one channel, and the channel it closes is unsolicited email. What remains is workable, and it is what our team builds for clients running cold email programmes that touch the EU.

  • Earn the opt-in before the pitch. Paid search, LinkedIn, content, webinars and events all produce a recorded, express permission with a timestamp and a source. That permission, properly captured, is what Article 21 wants.
  • Use the channels Article 21 does not cover. Article 21 regulates email and equivalent electronic media. LinkedIn conversation, direct mail and in-person work sit under different rules, though note that commercial telephone calls tightened separately when Article 66.1.b of Ley 11/2022 replaced a right to object with a right not to receive them.
  • Keep an evidence trail. In the AEPD cases the decisive failure is almost always the same: the sender could not prove permission. Store the consent record, the wording shown, the timestamp and the origin.
  • Put a working opt-out in every message, including the first. The absence of one is an independent breach, not a mitigating detail.
  • Segment Spain out of pan-EU sequences. A single sequence tuned for Ireland or the UK will breach Spanish law by default.

If your Spanish demand has to come from outbound rather than inbound, the honest answer is to move the effort upstream into lead generation that produces permission, then let email do the follow-up it is legally allowed to do.

How Spain compares with its neighbours

The ePrivacy Directive let member states choose whether to extend the consent rule beyond individual subscribers. The UK and Ireland used that discretion to leave corporate subscribers on an opt-out footing, which is why business-to-business cold email is workable there. Spain did not. Its rule attaches to any recipient, natural or legal, professional or not.

That places Spain at the strict end of the EU, closer to Germany than to Ireland, and it explains why generic GDPR playbooks mislead here. For the neighbouring regime and its own quirks, see our guide to cold email law in France, and for the pan-EU data layer, our GDPR cold email compliance guide.

Everything above is drawn from published sources: the consolidated LSSI text at the BOE, AEPD legal reports 0164/2018 and 0052/2023, AEPD resolution R/00198/2019, the AEPD's May 2025 criteria on sole trader data, and the Spanish government's LSSI portal. None of it is a substitute for advice from a Spanish lawyer on your specific campaign.

Need a Spanish or pan-EU outbound programme that stands up to an AEPD complaint?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Not without prior express permission from the recipient. Article 21 of Ley 34/2002 (the LSSI) prohibits promotional email that was not previously requested or expressly authorised. The only exception is an existing contractual relationship where you are emailing about similar products or services from your own company, and every message still needs a simple, free opt-out.

No. Unlike the UK and Ireland, Spain did not limit the consent rule to individual subscribers. The LSSI Annex defines a recipient as a natural or legal person who uses an information society service, whether or not for professional reasons, so emailing a company mailbox such as info@ is covered even when no personal data is involved.

For the send itself, no. In legal report 0164/2018 the AEPD applied the principle of specialty and held that the legitimating grounds in GDPR Article 6 must yield to the special rule in Ley 34/2002, because otherwise the LSSI would be left with no content. Article 19 of the LOPDGDD can support holding professional contact data, but it does not replace the Article 21 permission you need to email.

The LSSI sets three bands: up to 30,000 euros for a minor infringement, 30,001 to 150,000 euros for a serious one, and 150,001 to 600,000 euros for a very serious one. A single non-compliant email is minor under Article 38.4.d. Mass or insistent and systematic sending is serious under Article 38.3.c. For a first infringement with no prior record, Article 39 bis lets the AEPD issue a formal warning instead of a fine.

That threshold was in an older version of Article 38.3.c and was replaced by Ley 9/2014, in force from 11 May 2014. The current text refers to mass sending, or insistent or systematic sending to the same recipient, with no number attached. Many guides still repeat the old rule, so do not plan a sequence around it in either direction.

Public availability is not a legal basis. In its judgment of 9 January 2009 the Audiencia Nacional rejected exactly that argument, in a case where the inspection record showed the sender used software to harvest addresses from websites. The AEPD has also, in May 2025, ordered several Spanish business data providers to stop processing and delete sole trader records that lacked a valid GDPR basis.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us