Skip to main content

Spain AEPD + LGT Marketing Rules

Spain (ES) is a top-five European SMS market by volume and the EU member state whose data-protection authority publishes the largest headline GDPR fines against individual senders. Two regimes stack on top of each other for ES-bound traffic: the consent layer every other EU market shares (GDPR, plus Spain’s own opt-in overlay in the LSSI-CE for commercial electronic communications), and the telecom layer Spain re-nationalised in 2022 — the Ley 11/2022, General de Telecomunicaciones (LGT), whose Article 41 register of operators made alphanumeric sender-ID registration with the CNMC a practical requirement from 2023 onward. This page expands the ES row of the country-requirements matrix so you can close the Spanish items deliberately instead of re-reading one JSON blob per launch. Spain is a tenant-owned burden. Orbit never mandates your posture — it keeps the country-rules reference that feeds the send-time gates, and it gives you the consent ledger, sender-registration, quiet-hours, and opt-out surfaces below. The legal posture is yours.
This page is documentation, not legal advice. Spain’s AEPD enforces GDPR and LSSI-CE against the sender, and its published enforcement regularly reaches seven-figure fines for marketing traffic sent without a lawful basis; the CNMC keeps the LGT Article 41 register the carriers police. Have counsel review your consent capture and sender registration; Orbit supplies the surfaces.

The Spain-specific rules

Read the ES row of GET /compliance/country-rules?channel=sms (see Country Compliance Requirements). Consolidated: The registration: recommended level reads softer than it behaves: with the LGT operator register live, Spanish carriers treat unregistered alphanumeric traffic as unvetted, and the filtering class you hit is deliverability — not an Orbit gate.

LGT Art. 41 — the CNMC sender register

Ley 11/2022, General de Telecomunicaciones replaced the 2003 telecom act and re-made Spanish numbering governance: Article 41 sets the conditions under which numbering resources are assigned, and the CNMC register built on it tracks which operators and service providers may originate traffic. For A2P SMS the practical effect from 2023 onward is the same one other European markets reached by other routes: a registered alphanumeric sender resolves, an unregistered one is carrier-filtered. The tenant-owned control that carries this is the Sender-ID Registration submit-and-track flow — file the ES sender there even though the ES row’s registration level is recommended, and treat the approval state as a launch blocker for ES marketing traffic. Orbit records the filing and the approval; the register itself sits with CNMC.
Spain’s AEPD is the enforcement-heavy end of the European DPAs, and its published fines against marketing senders turn GDPR Articles 6 and 7 into a budgeting conversation, not just a legal one. For ES-bound marketing SMS the statute stack runs:
  • GDPR — lawful basis and provable consent for the processing behind the send. Record it the way the GDPR Posture Guide describes: a timestamped consent entry with sms scope in the Consent Management ledger before the first dispatch.
  • LSSI-CE Art. 21 — Spain’s own addition: commercial electronic communications by SMS are lawful only with the recipient’s prior express consent. AEPD reads silence, bundled consent, and pre-ticked boxes the same way German courts read them under UWG — they do not establish consent.
  • Withdrawal symmetry — an opt-out must be as easy as the opt-in and must stop the traffic. A Spanish opt-out reply fires the alias rule and writes a suppression entry scoped to all exactly like the English STOP family, so BAJA knocks the recipient off SMS, WhatsApp, and RCS in one event.
Under GDPR the consent record has to exist before the first marketing send and has to be provable on complaint — export it from Archival Export with timestamps when counsel asks.

Send-time posture for ES

Spain has no statutory no-send window like France’s 20:00–08:00 convention; what Spain has is an enforcement culture where out-of-hours marketing traffic produces complaints the AEPD prices. The tenant-owned control is the same deliberate opt-in as every other strict market: Where ES differs from FR: France’s window is a market convention surfaced in the country-rules content_restrictions; Spain’s is a complaint pattern. Both end at the same configuration — you set tenant quiet hours deliberately — but nothing ES-specific appears in the rules row to remind you, so this page does.

Where each ES obligation maps in Orbit


ES launch checklist

Narrowed from the generic launch checklist in Country Compliance Requirements to the ES row:
1

Look up the ES row

Call GET /compliance/country-rules?channel=sms&region=EU and read the ES row’s sender_types, registration, content_restrictions, and stop_requirement.
2

Register the alphanumeric sender

File the ES sender ID through Sender-ID Registration even though registration is recommended — under LGT Art. 41 the carriers filter unregistered alphanumeric traffic.
3

Capture marketing opt-in first

Record a consent entry with sms scope before any ES marketing send; LSSI-CE Art. 21 is opt-in, not opt-out. See Consent Management and the GDPR Posture Guide.
4

Wire the Spanish STOP family

Confirm BAJA, CANCELAR, SALIR, FIN are mapped into the alias table and write the suppression entry. See Opt-Out Keyword Alias Table.
5

Set tenant quiet hours deliberately

If you run ES marketing traffic, turn on tenant quiet hours over Europe/Madrid recipient time — Orbit defaults this off. See Quiet-Hours Configuration.
6

Scrub the Lista Robinson for voice

Before any outbound voice campaign into ES, scrub the audience against the Robinson list via DNC Scrub.
7

Launch

With ES enabled on the tenant, the sender registered, consent captured, keywords wired, quiet hours set, and the voice list scrubbed, start sending.