Spain
Legal with restrictions
Overview
Intro & Key Facts
Quick Summary
Practical Usage
Permitted Document Types
Restricted Document Types
Common Exclusions
Authentication Required
Restrictions
Restrictions in Spain
Generally Permitted
Time-limited signature windows.
Sequential signing order.
Mandatory field completion.
Document expiration dates.
IP-based access restrictions.
Password-protected envelope access.
SMS verification codes.
Attachment requirements.
May Require Special Handling or Exclusions
Restrictions that prevent signers from reviewing the complete document before signing.
Restrictions that obscure material terms.
Blanket prohibitions on retaining personal copies.
Requirements for specific hardware or paid software to complete signing.
Legal Requirements
Spain E-Signature Law Explained
Legal Frameworks
Regulatory Bodies
E-Sign Retention Min.
Retention Notes
Data, Privacy & Cross-Border
Data Privacy and Compliance Spain
Privacy Frameworks
GDPR (direct application as EU member state) + LOPDGDD (Organic Law 3/2018, Spain's national data protection supplement)
Privacy Compliance Status
Firma.dev processes data as a processor under GDPR. A Data Processing Agreement is available. EU-only hosting in AWS Paris means no international transfers for standard operations. Spanish customers get EU residency by default.
Privacy Notes
The AEPD is one of the EU's most active enforcement bodies, issuing roughly 40M EUR in fines across 299 sanctions in 2025. LOPDGDD adds a unique bloqueo (data blocking) requirement: data must be made inaccessible but not deleted before permanent erasure. A DPO is mandatory for 16 specific sectors regardless of company size (LOPDGDD Art. 34). The children's data consent threshold is 14 years. Collect only the data necessary for signature validity, inform signers via a privacy notice, and define retention periods in your DPA.
Data Residency Required
Adequacy Decision
Spain is an EU member state, so GDPR adequacy decisions apply for outbound transfers. Current adequacy covers Andorra, Argentina, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, UK, Uruguay, and US (Data Privacy Framework participants only).
Cross-Border Transfer Allowed
Unrestricted within the EU/EEA. EU-US transfers rely on the Data Privacy Framework. Other third-country transfers require SCCs, BCRs, or an adequacy decision. The AEPD requires prior authorization for transfers without adequate safeguards.
Residency Notes
No country-specific data localization law for commercial data. The EU/EEA restriction comes from GDPR. Firma.dev's AWS Paris (eu-west-3) region satisfies EU residency needs for Spanish customers.
Privacy Retention Maximum
GDPR storage limitation applies: retain personal data only as long as necessary. The LOPDGDD bloqueo requirement keeps blocked data accessible only for regulatory or legal purposes before final deletion. Commercial Code baseline is 6 years, AML is 10 years, and certain civil claims extend up to 30 years.
Industry Compatibilty
E-Signatures by Industry in Spain
Fully Supported Industries
General Commercial
SaaS Software
HR Tech Employment
Education/Edtech
Construction
Supported with Agreement
Healthcare
Life Sciences/Pharma
Insurance
Financial Services/Fintech
Real Estate Tech
Should Consult Counsel
Legal Tech
Government
Industry Matrix Notes
Most B2B commercial use cases work with SES/AES thanks to Spain's freedom-of-form principle. Healthcare, financial services, and insurance carry a mandatory DPO obligation under LOPDGDD and may need enhanced identity verification. Government interactions generally require QES or an FNMT certificate, which is outside Firma.dev's current scope. Legal services should consult counsel since some court filings require QES. Notarized documents such as public deeds and wills sit outside electronic signing entirely and require a notary.
General Commercial
Standard B2B contracts, vendor agreements, NDAs, purchase orders, invoices, and service agreements all work with SES/AES under Spanish commercial law. The freedom-of-form principle in Civil Code Art. 1278 means most contracts are valid regardless of medium, and SES/AES cannot be refused as evidence solely for being electronic. No special requirements beyond reliable signer identification.
SaaS Software
SaaS companies can use SES/AES for all B2B contracts in Spain: software licenses, subscription agreements, API terms of service, MSAs, and DPAs. Freedom of form under Spanish law makes electronic signatures fully valid for commercial agreements. Firma.dev's API-first approach fits naturally into software onboarding and self-serve signup flows.
Healthcare
Healthcare organizations can use SES/AES for most administrative documents. Processing health data may require appointing a DPO and running a DPIA, and LOPDGDD mandates a DPO for the healthcare sector regardless of company size. AES with a full audit trail is recommended for patient consent forms. Firma.dev's EU hosting in AWS Paris supports GDPR-aligned workflows.
Life Sciences/Pharma
Clinical trial agreements, CRO contracts, and research collaborations work with SES/AES. Documents subject to GxP requirements may need enhanced audit trails. Quality agreements between manufacturers should specify the signature standard expected. Most B2B life sciences contracts sign cleanly with Firma.dev.
Insurance
Standard insurance policies and B2B agreements work with SES/AES. LOPDGDD mandates a DPO for the insurance sector regardless of company size, and certain regulated products may need enhanced identity verification. Retain signed policies and their audit trail in line with commercial and AML retention periods.
Financial Services/Fintech
Financial services contracts generally work with SES/AES under Spanish commercial law. AML/CFT compliance under Law 10/2010 requires 10-year document retention and may require enhanced identity verification for certain transactions. LOPDGDD mandates a DPO for the financial sector. Most B2B fintech agreements work well with Firma.dev.
HR Tech Employment
Employment contracts, offer letters, NDAs, and HR policy acknowledgments all work with SES/AES under Spanish labor law. No special signature requirements apply to standard employment documentation. Retain employment records for 3-5 years after termination per Royal Decree 5/2000.
Legal Tech
Many legal documents work with SES/AES, but some court filings and regulated procedures require QES, so law firms should confirm the requirement per matter. Law 11/2023 now allows several notarial acts via videoconference with QES. Consult counsel where a specific filing may demand a qualified signature.
Real Estate Tech
Private lease agreements under 6 years that are not registered work with SES/AES. Property conveyances require a notarial deed, though Law 11/2023 now permits some notarial acts via videoconference with QES. Firma.dev works well for lease agreements, property management contracts, and related B2B documents.
Education Tech
Administrative documents, enrollment agreements, and institutional contracts work with SES/AES. Note the children's data consent threshold of 14 years under LOPDGDD when processing student data. Firma.dev's EU hosting supports GDPR-aligned handling of education records.
Construction Tech
Construction contracts, subcontractor agreements, change orders, and project documentation work with SES/AES. Retain signed documents in line with commercial liability periods. Timestamping is worth considering for dispute resolution on long-running projects.
Government
Public administration interactions in Spain generally require QES, and an FNMT digital certificate is often specifically required. This is outside Firma.dev's current scope, which covers SES/AES only. Contractors working with the public sector should use an FNMT certificate or another EU-listed QTSP.
How we works
How We Works on Spain
Firma.dev Supports
Firma.dev supports SES and AES workflows, which cover the vast majority of B2B commercial use cases in Spain.
Firma.dev provides signer identification via email-based authentication with optional SMS verification, tamper-evident documents with cryptographic sealing, complete audit trails with timestamped logging, and EU data residency with all data hosted in AWS Paris (eu-west-3). This maps directly to what Spanish law expects for reliable SES and AES: identifiable signers, document integrity, and an evidentiary trail. Customer Workspaces give each of your customers a private, partitioned space with isolated templates and per-customer envelope usage, which suits multi-tenant SaaS building signing into their own product.
Legal Details
Spain's e-signature framework rests on the EU-wide eIDAS Regulation (No. 910/2014) and national law, principally Law 6/2020 on Trust Services and the freedom-of-form principle in the Civil Code.
eIDAS establishes three tiers of electronic signature recognized across all EU member states. Simple Electronic Signatures (SES) are the baseline: any data in electronic form attached to or logically associated with other data used to sign. Advanced Electronic Signatures (AES) add requirements under Art. 26: the signature must be uniquely linked to the signatory, capable of identifying them, created using data under their sole control, and linked to the signed data so any later change is detectable. Qualified Electronic Signatures (QES) go further, requiring a qualified certificate from a Qualified Trust Service Provider plus a qualified signature creation device.
Spain follows the freedom-of-form principle in Civil Code Art. 1278, meaning most contracts are valid regardless of the medium used. Under eIDAS Art. 25.2, only QES carries the automatic legal equivalence to a handwritten signature, but Art. 25.1 confirms that SES and AES cannot be denied legal effect or admissibility as evidence solely because they are electronic. Law 6/2020 does not mandate AES or QES for any specific private transaction type, so for most commercial agreements the choice of signature level is a matter of evidentiary strength rather than legal requirement.
Spanish case law reinforces the value of proper authentication. The Provincial Court of Lleida (Judgment 74/2021) rejected an electronic signature that lacked adequate authentication, while the Supreme Court has upheld AES supported by an audit trail and two-factor authentication as valid. The practical lesson is the same one developers should design around: a signature backed by identity verification, timestamping, and a tamper-evident audit trail is far stronger evidence than a bare electronic mark.
For most SaaS companies operating in Spain, SES and AES cover the vast majority of use cases. QES is required for public procurement, tax filings with the AEAT, notarial deeds, and certain regulated filings. The DNIe (national electronic ID) and FNMT-issued certificates are the main routes to QES in Spain. Developers building B2B signing flows can rely on SES/AES with confidence for commercial contracts, employment agreements, NDAs, software licenses, and similar documents.
Recent developments
E-Signature Landscape in Spain: 2026
Law 11/2023 (Digitalization Law, effective November 2023): Amended the Notaries Act to allow many notarial procedures via videoconference with QES, including company incorporations, powers of attorney, and corporate acts. This is expanding where qualified signatures appear in Spanish business processes.
eCMR mandate (Ley 9/2025): Spain will require digital control documents for road freight from 5 October 2026. The eCMR signature must be an AES under eIDAS. Firma.dev provides the signing layer for AES workflows, not the consignment-note document itself.
eIDAS 2.0 (Regulation 2024/1183): EU-wide, member states must deploy EU Digital Identity Wallets by 31 December 2026, with mandatory relying-party acceptance following in November 2027. Existing SES and AES methods remain fully valid throughout and after the transition.
Sources
eIDAS Regulation (EU) No 910/2014: https://eur-lex.europa.eu/eli/reg/2014/910/oj/eng
Spain Law 6/2020 on Trust Services: https://www.boe.es/eli/es/l/2020/11/11/6
Law 11/2023 (Digitalization): https://www.boe.es/eli/es/l/2023/05/08/11
Civil Code Art. 1278: https://www.boe.es/buscar/act.php?id=BOE-A-1889-4763
Commercial Code Art. 30: https://www.boe.es/buscar/act.php?id=BOE-A-1885-6627
LOPDGDD (Organic Law 3/2018): https://www.boe.es/eli/es/lo/2018/12/05/3
Ally Law Spain guide: https://ally-law.com/e-signature-regulations-spain/
Adobe Spain guide: https://helpx.adobe.com/legal/esignatures/regulations/spain.html
DocuSign Spain guide: https://www.docusign.com/products/electronic-signature/legality/spain
OneSpan Spain guide: https://www.onespan.com/resources/esignature-legality/spain
CMS Expert Guide (Spain): https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/spain
AEPD: https://www.aepd.es/
FNMT: https://www.fnmt.es/


