Website legal texts: what you really need in Spain and in Chile

Legal notice, privacy, cookies and terms of sale: which ones are compulsory, what each has to say, and why copying another site's is the mistake that turns a formality into a problem.
· AI and data compliance
Website legal texts nearly always get resolved the same way: by copying them from a similar company and changing the name. It is fast, and it is exactly what turns a simple formality into a problem — because those texts describe processing you do not do and leave out the processing you do.
So here is what is genuinely compulsory, and what each document has to say.
1. Legal notice — who is behind the website
In Spain, the information society services act requires providers to display permanently, easily, directly and free of charge: name, address, email address and other contact details, registry entry details where applicable, tax identification number, and — where the activity requires authorisation or is a regulated profession — the corresponding details of the professional body, qualification and professional rules.
That last point carries an important reading: you cannot display qualifications or professional memberships you do not hold. Claiming a professional status that does not correspond to you is not a decorative flourish in a legal notice: it is misleading advertising and, depending on the case, professional impersonation.
2. Privacy policy — what you do with the data
Compulsory as soon as you collect any personal data, and a contact form already counts. It has to state:
- Who the controller is and how to get in touch.
- What the data is used for and on what legal basis for each purpose.
- Who it is disclosed or transferred to, technology suppliers included.
- Whether there are international transfers and under what safeguard.
- How long it is kept.
- The data subject's rights and how to exercise them, including complaining to the supervisory authority.
The honesty test for a privacy policy is simple: read it and check whether it describes what you actually do. If it mentions tools you do not use, or promises deletions nobody carries out, the document is describing a different company. And a policy that promises what is not delivered is worse than not having one, because it documents the breach.
3. Cookie policy — only if you set cookies
Precision matters here, because a lot of confusion circulates.
Consent is required for cookies and similar technologies that are not exempted. Those strictly necessary to provide the service the user asked for are exempted. Analytics and advertising ones are not.
A little-known consequence: a website that sets no cookies at all needs neither a banner nor a cookie policy. It is perfectly possible and, for a corporate site, often preferable: traffic can be measured with methods that require no consent. We cover it in what to measure without installing cookies.
And if you do set them, two rules that get broken a lot: refusing has to be as easy as accepting, and non-exempt cookies are not loaded before the user accepts. A banner that has already loaded the trackers while it asks complies with nothing.
4. Terms of sale — if you sell
Compulsory where there is online purchasing. They have to cover: identification of the seller, features and final price with taxes, shipping costs, payment methods, delivery times, and the withdrawal or retraction regime with its period and its form.
Spain and Chile differ here and it is worth not mixing them up:
- In Spain, the consumer generally has a fourteen calendar day withdrawal period in distance contracts, with a closed list of exceptions.
- In Chile, the right of retraction in electronic contracts runs for ten days from receipt of the product or from contracting the service and before it has been performed, and the supplier may exclude it expressly by stating so prominently before the contract is made. On top of that, if the written confirmation of the contract is not sent, that period extends to ninety days.
Copying the terms of a Spanish shop for a Chilean one, or the other way round, produces a document that promises what does not apply — and what is promised on the site is enforceable.
The four most frequent mistakes
- Copy and paste. Another company's details, non-existent processing and the wrong jurisdictions all show up.
- A cookie policy with no cookies, or a banner that loads before it asks.
- Blank retention periods, or «as long as necessary», which informs nobody of anything.
- Texts that are never reviewed when the tools change. You switch email provider or add a payment gateway and the document goes stale.
How to do it properly in an afternoon
- Take the inventory of what data you collect and with which tools. It is the same exercise as the record of processing: how to build the record.
- Write the policy from that inventory, not from a template.
- Decide whether you need cookies. If you do not, remove the banner and the policy.
- Fit the terms to the jurisdiction you sell in.
- Put an annual review in the calendar, and another one every time you change tools.
If this sounds like you
Texts written from what you actually do — not from a template — are AI and data compliance. The website they sit on is web and online shop.
We are Mindset & Code: automation, data and development for small businesses. We build the technical side of selling abroad: the catalogue, per-country tax in the shop and the feed into your management software. You can see what we do and what it costs.
Sources: Ley 34/2002 on information society services, articles 10 and 22.2; Regulation (EU) 2016/679, articles 13 and 14; Real Decreto Legislativo 1/2007, consolidated text of the General Consumer Protection Act, right of withdrawal; Ley 19.496 of Chile, articles 3 bis and 12 A; AEPD, guidance on the use of cookies. General guidance; it does not replace legal advice.