> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Spain AEPD + LGT Marketing Rules

> The Spain SMS and voice rules expanded from the country-requirements matrix: GDPR and LSSI-CE opt-in, the Ley 11/2022 General de Telecomunicaciones (LGT) sender-ID registration regime in force since 2023, AEPD enforcement exposure, the Spanish BAJA keyword family, and the Lista Robinson scrub — mapped to the Orbit surfaces you already own.

# Spain AEPD + LGT Marketing Rules

Spain (`ES`) is a top-five European SMS market by volume and the EU
member state whose data-protection authority publishes the largest
headline GDPR fines against individual senders. Two regimes stack on
top of each other for ES-bound traffic: the consent layer every other
EU market shares (GDPR, plus Spain's own opt-in overlay in the LSSI-CE
for commercial electronic communications), and the telecom layer
Spain re-nationalised in 2022 — the Ley 11/2022, General de
Telecomunicaciones (LGT), whose Article 41 register of operators made
alphanumeric sender-ID registration with the CNMC a practical
requirement from 2023 onward. This page expands the ES row of the
[country-requirements matrix](/compliance/country-requirements) so you
can close the Spanish items deliberately instead of re-reading one
JSON blob per launch.

Spain is a **tenant-owned burden**. Orbit never mandates your posture —
it keeps the [country-rules reference](/compliance/country-requirements)
that feeds the send-time gates, and it gives you the consent ledger,
sender-registration, quiet-hours, and opt-out surfaces below. The
legal posture is yours.

<Note>
  This page is documentation, not legal advice. Spain's AEPD enforces
  GDPR and LSSI-CE against the sender, and its published enforcement
  regularly reaches seven-figure fines for marketing traffic sent
  without a lawful basis; the CNMC keeps the LGT Article 41 register
  the carriers police. Have counsel review your consent capture and
  sender registration; Orbit supplies the surfaces.
</Note>

***

## The Spain-specific rules

Read the ES row of `GET /compliance/country-rules?channel=sms` (see
[Country Compliance Requirements](/compliance/country-requirements)).
Consolidated:

| Rule | ES value | What it means for you |
| - | - | - |
| Sender types | `alphanumeric`, `long_code` | Both accepted. Alphanumeric sender IDs under LGT are expected to resolve to a sender the CNMC register can identify — unregistered alphanumeric traffic is the class Spanish carriers most aggressively relabel or drop. |
| Registration | `recommended` | The send-time gate does not hold ES on a missing registration, but under LGT Art. 41 the practical posture since 2023 is "register or be filtered." File the sender through [Sender-ID Registration](/compliance/sender-id-registration). |
| Marketing consent | Prior opt-in required (GDPR + LSSI-CE) | Spain's LSSI-CE (Ley 34/2002) Art. 21 gates commercial electronic communications behind prior express consent; AEPD applies the same reading to SMS. Consent must exist before dispatch — record it in the consent ledger with `sms` scope. |
| Opt-out keyword | Spanish vocabulary mandatory | Every ES marketing message must accept the Spanish opt-out family; the seeded alias table maps `BAJA`, `CANCELAR`, `SALIR`, `FIN` (plus case/Unicode-normalised variants) to your suppression ledger. See [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table). |
| Voice scrub | Lista Robinson | For outbound voice marketing, Spain's Robinson list (Lista Robinson, run by the AEPD) is the do-not-call register recipients opt into; scrub campaign audiences against it the same way US tenants scrub the national DNC. |

The `registration: recommended` level reads softer than it behaves:
with the LGT operator register live, Spanish carriers treat
unregistered alphanumeric traffic as unvetted, and the filtering class
you hit is deliverability — not an Orbit gate.

***

## LGT Art. 41 — the CNMC sender register

Ley 11/2022, General de Telecomunicaciones replaced the 2003 telecom
act and re-made Spanish numbering governance: Article 41 sets the
conditions under which numbering resources are assigned, and the CNMC
register built on it tracks which operators and service providers may
originate traffic. For A2P SMS the practical effect from 2023 onward
is the same one other European markets reached by other routes: a
registered alphanumeric sender resolves, an unregistered one is
carrier-filtered.

The tenant-owned control that carries this is the
[Sender-ID Registration](/compliance/sender-id-registration)
submit-and-track flow — file the ES sender there even though the ES
row's `registration` level is `recommended`, and treat the approval
state as a launch blocker for ES marketing traffic. Orbit records the
filing and the approval; the register itself sits with CNMC.

***

## AEPD consent posture — GDPR plus the LSSI-CE overlay

Spain's AEPD is the enforcement-heavy end of the European DPAs, and
its published fines against marketing senders turn GDPR Articles 6
and 7 into a budgeting conversation, not just a legal one. For
ES-bound marketing SMS the statute stack runs:

* **GDPR** — lawful basis and provable consent for the processing
  behind the send. Record it the way the
  [GDPR Posture Guide](/compliance/gdpr-posture-guide) describes:
  a timestamped consent entry with `sms` scope in the
  [Consent Management](/compliance/consent-management) ledger before
  the first dispatch.
* **LSSI-CE Art. 21** — Spain's own addition: commercial electronic
  communications by SMS are lawful only with the recipient's prior
  express consent. AEPD reads silence, bundled consent, and
  pre-ticked boxes the same way German courts read them under UWG —
  they do not establish consent.
* **Withdrawal symmetry** — an opt-out must be as easy as the opt-in
  and must stop the traffic. A Spanish opt-out reply fires the alias
  rule and writes a suppression entry scoped to `all` exactly like the
  English `STOP` family, so `BAJA` knocks the recipient off SMS,
  WhatsApp, and RCS in one event.

Under GDPR the consent record has to *exist* before the first
marketing send and has to be *provable* on complaint — export it from
[Archival Export](/compliance/archival-export) with timestamps when
counsel asks.

***

## Send-time posture for ES

Spain has no statutory no-send window like France's 20:00–08:00
convention; what Spain has is an enforcement culture where
out-of-hours marketing traffic produces complaints the AEPD prices.
The tenant-owned control is the same deliberate opt-in as every other
strict market:

| Surface | Behaviour for ES |
| - | - |
| Tenant quiet hours (deliberate) | [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — opt-in tenant control, default **OFF / fail-open**; configure a Europe/Madrid recipient-local window (the common posture mirrors Germany's 21:00–09:00) if you want the platform to hold ES marketing sends. Nothing in Orbit defaults this on. |
| Consent-default policy | Set the org-level consent-default policy so ES marketing traffic requires a consent record, not a consent assumption — see [Consent Default Policy](/compliance/consent-default-policy). |
| Lista Robinson (voice) | For outbound voice campaigns into ES, scrub against the Robinson list before each launch the same way you run [DNC Scrub](/compliance/dnc-scrub) against the US registers. |

Where ES differs from FR: France's window is a market convention
surfaced in the country-rules `content_restrictions`; Spain's is a
complaint pattern. Both end at the same configuration — you set
tenant quiet hours deliberately — but nothing ES-specific appears in
the rules row to remind you, so this page does.

***

## Where each ES obligation maps in Orbit

| ES obligation | Orbit surface |
| - | - |
| Consent before marketing send (GDPR + LSSI-CE) | [Consent Management](/compliance/consent-management) — a consent record with `sms` scope before dispatch; posture in the [GDPR Posture Guide](/compliance/gdpr-posture-guide) |
| LGT Art. 41 sender registration (CNMC) | [Sender-ID Registration](/compliance/sender-id-registration) submit-and-track flow; the [send-time gate](/compliance/send-gates) holds only `required` countries, so treat ES `recommended` as a launch blocker |
| Spanish opt-out vocabulary | [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) — `BAJA`, `CANCELAR`, `SALIR`, `FIN` map to the suppression ledger, scoped to `all` |
| Provable consent on AEPD complaint | [Archival Export](/compliance/archival-export) — export the ledger with the consent-granted-at timestamp |
| Send-window discipline | [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — deliberate tenant opt-in over Europe/Madrid recipient time |
| Robinson list (voice marketing) | [DNC Scrub](/compliance/dnc-scrub) — same scrub surface as the US register, run against the ES list before each voice campaign |

***

## ES launch checklist

Narrowed from the generic launch checklist in
[Country Compliance Requirements](/compliance/country-requirements) to
the ES row:

<Steps>
  <Step title="Look up the ES row">
    Call `GET /compliance/country-rules?channel=sms&region=EU` and read
    the ES row's `sender_types`, `registration`, `content_restrictions`,
    and `stop_requirement`.
  </Step>

  <Step title="Register the alphanumeric sender">
    File the ES sender ID through
    [Sender-ID Registration](/compliance/sender-id-registration) even
    though `registration` is `recommended` — under LGT Art. 41 the
    carriers filter unregistered alphanumeric traffic.
  </Step>

  <Step title="Capture marketing opt-in first">
    Record a consent entry with `sms` scope before any ES marketing
    send; LSSI-CE Art. 21 is opt-in, not opt-out. See
    [Consent Management](/compliance/consent-management) and the
    [GDPR Posture Guide](/compliance/gdpr-posture-guide).
  </Step>

  <Step title="Wire the Spanish STOP family">
    Confirm `BAJA`, `CANCELAR`, `SALIR`, `FIN` are mapped into the
    alias table and write the suppression entry. See
    [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table).
  </Step>

  <Step title="Set tenant quiet hours deliberately">
    If you run ES marketing traffic, turn on tenant quiet hours over
    Europe/Madrid recipient time — Orbit defaults this off. See
    [Quiet-Hours Configuration](/guides/quiet-hours-configuration).
  </Step>

  <Step title="Scrub the Lista Robinson for voice">
    Before any outbound voice campaign into ES, scrub the audience
    against the Robinson list via [DNC Scrub](/compliance/dnc-scrub).
  </Step>

  <Step title="Launch">
    With ES enabled on the tenant, the sender registered, consent
    captured, keywords wired, quiet hours set, and the voice list
    scrubbed, start sending.
  </Step>
</Steps>

***

## Related references

* [Country Compliance Requirements](/compliance/country-requirements) —
  the full matrix this page expands one row of.
* [GDPR Posture Guide](/compliance/gdpr-posture-guide) — the EU-side
  consent and data-residency posture behind Spain's opt-in rule set.
* [Sender-ID Registration](/compliance/sender-id-registration) — the
  submit-and-track flow for the ES `recommended` registration.
* [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) —
  the Spanish `BAJA` family and its scope.
* [Consent Management](/compliance/consent-management) — where the ES
  marketing opt-in record lives.
* [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — the
  tenant-owned opt-in control you use to set the ES send window.
* [DNC Scrub](/compliance/dnc-scrub) — the scrub surface for the
  Robinson list on outbound voice.
* [Send Gates](/compliance/send-gates) — the gates that enforce the ES
  `registration` level at send time.
