Installing GA4, Google Ads or advertising pixels on a Spanish website is not just a technical decision. Cookies and similar technologies can trigger information and consent duties. The correct setup depends on what each technology does, not the label your tag manager gives it. This guide provides an operational framework, not legal advice.
Start with purpose, not the cookie name
Classify every technology by its actual purpose: essential operation, preferences, audience measurement, advertising or another use. Record who sets it, what data it handles, how long it lasts and whether information is shared with another party.
Changing a cookie name or moving a request through your own subdomain does not automatically make it essential or first party in the legal sense. If the underlying purpose is advertising, the user-facing explanation and control should reflect that purpose.
What a Spanish consent banner should achieve
AEPD guidance says accepting and rejecting cookies should be presented prominently and at the same level, without making rejection more difficult. Information should be clear, and users must be able to withdraw their choice as easily as they gave it.
Avoid preselected optional categories, vague buttons and designs that push visitors toward acceptance. The first layer should explain the basic purposes and provide access to more detailed settings and the cookie policy.
GA4 and analytics cookies
Do not assume every analytics implementation is exempt. AEPD has separate guidance for certain audience-measurement tools, but an exemption depends on strict conditions and the actual configuration. Standard GA4 or advertising-linked implementations should not be declared exempt without a documented assessment.
Review Google Signals, advertising features, product links, user-provided data, retention and access. Consent Mode can adjust Google tag behavior, but it does not replace the banner or create a legal basis.
Where server-side tracking helps—and where it does not
Server-side GTM gives you a controlled layer between the website and vendors. You can validate events, remove unnecessary parameters, redact data and block destinations according to consent. It can also reduce the number of third-party requests made directly by the browser.
It does not convert advertising data into essential data, bypass consent requirements or make a vendor disappear. The visitor's choice must still control collection and forwarding, and your notices must describe the actual processing.
This guide is not legal advice
Cookie rules depend on the technology, purpose, parties and current law. Consult the latest AEPD materials and qualified counsel before relying on an exemption or deploying advanced measurement without consent.
A practical cookie and tag audit
Repeat this audit whenever the CMP, website or marketing stack changes.
- 01
Scan and observe
Test a fresh browser before consent, after rejection, after partial consent and after full acceptance. Record cookies, storage and network requests.
- 02
Create a tag register
For each tag, document owner, purpose, fields, recipient, retention, trigger and consent requirement.
- 03
Align CMP categories
Make category names understandable and ensure their technical mappings match the purposes described to visitors.
- 04
Fix consent timing
Set restrictive defaults before optional tags run, then update state immediately when the visitor makes or withdraws a choice.
- 05
Apply server controls
Use sGTM triggers and transformations to minimize data and stop destinations that are not allowed for the current consent state.
- 06
Keep evidence
Save test results, configuration versions, policies and review dates so future changes can be assessed quickly.
Compliance is a maintained system
A compliant banner can be undermined by one tag that fires too early or a new marketing integration added without review. Treat consent, documentation and technical enforcement as one system.
Server-side tracking is valuable when it supports that system with minimization, control and monitoring. It is not a shortcut around Spanish cookie requirements.
AEPD, cookies and GA4: common questions
Can GA4 run before consent in Spain?
Do not assume it can. The answer depends on the configuration, purpose and whether every condition for an applicable exemption is met. Standard analytics and advertising setups commonly require consent.
Must the reject button be as visible as accept?
AEPD guidance states that accepting and rejecting should be offered prominently and at the same level, without making rejection more difficult.
Does a first-party tracking domain remove consent requirements?
No. Domain architecture does not change the underlying purpose or parties. Assess what data is processed, why and where it goes.
How often should tags be audited?
At minimum, review after every material CMP, website or vendor change. Periodic automated scans plus manual journey tests provide stronger evidence.