App legal requirements in Spain

Which privacy law applies to an app run from Spain, who enforces it, the pages you must publish, and what each store adds on top.

Updated · Written from the same rules terms.gg uses to generate documents

The short answer

An app operated from Spain answers to the General Data Protection Regulation (GDPR), enforced by the Agencia Española de Protección de Datos (AEPD). On top of that, each store you ship on has its own requirements, which are contract terms rather than law and are stricter in places.

Put together, a paid app on both stores from Spain publishes 7 pages: Privacy Policy, Terms of Service, Account and data deletion page, Cookie Policy, Refund Policy, End User License Agreement, Legal notice.

What is specific to Spain

What each store asks for on top

The order to do it in

Where people go wrong

Keeping it true after launch

A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. Under GDPR the drift is yours rather than your vendor's, and the Agencia Española de Protección de Datos (AEPD) is who hears about it.

Common questions

Does GDPR apply if my company is elsewhere but I live in Spain?

Two things bring you under a regime: being established there, and reaching people who are there. An establishment in Spain is enough on its own. So is offering a service to people in the region, or monitoring their behaviour there, with no company and no server in it, which is what Article 3(2) says in as many words. If both could apply, write to the stricter one.

Do I need a lawyer?

Not to publish a first version. You do once there is revenue, staff, or a complaint, and the generated documents are a much better starting point for that conversation than a blank page.