Introduction
*Updated for 2026 compliance practices.*
If you run a website on HubSpot CMS and target visitors in Spain, you need to ensure your analytics and advertising trackers comply with cookie regulations. A **HubSpot CMS cookie compliance Spain analytics and advertising tracker audit** is the process of verifying that your site obtains valid consent before loading tracking technologies, respects user choices, and provides transparent disclosures. This guide walks you through the practical steps, common pitfalls, and how to validate your setup using GDPRChecker’s scanning tools.
Spain enforces the GDPR and the national Ley Orgánica de Protección de Datos y Garantía de los Derechos Digitales (LOPDGDD), along with guidance from the Spanish Data Protection Agency (AEPD). The AEPD aligns with the European Data Protection Board (EDPB) on strict consent requirements: analytics and advertising cookies require prior, informed, and unambiguous consent unless strictly necessary. This means your HubSpot CMS site must block non-essential trackers until the user takes an affirmative action, such as clicking “Accept.”
This guide is for informational and technical implementation purposes only and does not constitute legal advice. For legal questions, consult a qualified privacy professional.
Requirements and Compliance Expectations in Spain
Spanish regulators expect website owners to implement cookie compliance that meets the following criteria:
- **Prior consent**: Non-essential cookies—including analytics (e.g., Google Analytics 4) and advertising (e.g., Meta Pixel, LinkedIn Insight Tag)—must not be set or read before the user gives consent. This applies even if you use Google Consent Mode v2; the default consent state must be denied.
- **Granular choice**: Users must be able to accept or reject cookies by category (analytics, marketing, preferences) and withdraw consent easily.
- **Transparent information**: A cookie notice or privacy policy must clearly identify each tracker, its purpose, duration, and any third-party recipients.
- **Proof of consent**: You must keep records of consent, including timestamps and the scope of consent granted.
- **No cookie walls**: Access to content cannot be conditional on accepting non-essential cookies unless you offer an equivalent paid alternative.
For HubSpot CMS users, this means configuring the native cookie consent features correctly and supplementing them with a consent management platform (CMP) if needed. Note that GDPRChecker provides scanning, verification, and monitoring tools, but it is not a Google Certified CMP, an IAB TCF CMP, and does not generate TC Strings or issue CMP IDs. You can use GDPRChecker to validate that your chosen CMP or HubSpot consent settings work as intended.
How to Implement Step by Step
1. Inventory Your Trackers Start by listing every analytics and advertising tracker on your HubSpot CMS site. Common examples include: - Google Analytics 4 (GA4) - Google Ads conversion tracking - Meta (Facebook) Pixel - LinkedIn Insight Tag - HubSpot’s own analytics and marketing cookies - Hotjar, Crazy Egg, or other session recording tools
Use GDPRChecker’s public scanner to get an initial cookie and tracker report. This will show you what’s currently loading and help you identify any unknown or legacy tags.
2. Configure Consent Defaults In HubSpot CMS, you can enable the built-in cookie consent banner. However, the default behavior may not block all trackers before consent. To achieve prior blocking: - Set the consent banner to “Opt-in” mode. - For Google tags, implement Google Consent Mode v2 with default consent set to `denied` for `analytics_storage`, `ad_storage`, `ad_user_data`, and `ad_personalization`. This tells Google’s tags to behave in consent mode and not set cookies until consent is updated. - For non-Google scripts (e.g., Meta Pixel), you must wrap them in a consent check or use a tag manager that respects consent signals. HubSpot’s native consent API can be used to conditionally load scripts.
3. Set Up a Consent Banner Your cookie banner must: - Appear on the first page load. - Clearly state that the site uses cookies and for what purposes. - Offer “Accept All” and “Reject All” buttons with equal prominence. - Link to a detailed cookie policy or privacy policy. - Allow users to change preferences later via a persistent widget.
If you use a third-party CMP integrated with HubSpot CMS, ensure it supports the IAB TCF v2.2 or Google Consent Mode v2 if you run Google ads. GDPRChecker can scan your banner to verify that the reject button actually prevents non-essential cookies from loading.
4. Update Your Privacy and Cookie Policies Your privacy policy must disclose: - The identity of the data controller. - The categories of personal data processed via cookies. - The purposes (analytics, advertising, personalization). - The legal basis (consent). - How to withdraw consent. - Third-party recipients and any international transfers.
Link this policy from your cookie banner and footer. GDPRChecker’s scanner checks for the presence and accessibility of your policy links.
5. Test Pre-Consent Behavior Before launching, test your site with browser developer tools: - Open the Network tab and reload the page without interacting with the cookie banner. - Verify that no requests to analytics or advertising endpoints (e.g., `google-analytics.com`, `facebook.com/tr`, `px.ads.linkedin.com`) are present. - Check that strictly necessary cookies (like session cookies) are still allowed.
GDPRChecker’s pre-consent scan automates this check and flags any unauthorized network requests.
6. Validate Post-Consent Behavior After the user accepts cookies, all consented trackers should load. After rejection, only essential trackers should remain. Use GDPRChecker to scan both scenarios and compare the results.
Common Mistakes and How to Avoid Them
Mistake 1: Analytics Loaded Before Consent Many HubSpot CMS sites embed the Google Analytics or HubSpot tracking code directly in the site header without a consent check. Even with Consent Mode v2, if the default is not set to `denied`, cookies may be set prematurely.
**Fix**: Implement Consent Mode v2 with denied defaults and ensure your CMP updates consent states only after user interaction. Verify with a pre-consent scan.
Mistake 2: Reject Button Doesn’t Actually Block Trackers Some consent banners have a “Reject” button that merely hides the banner but does not prevent tracking scripts from executing.
**Fix**: Test the reject flow with GDPRChecker. The scanner will report if any non-essential cookies or requests persist after rejection.
Mistake 3: Incomplete Cookie Disclosures The cookie policy lists only a few cookies but omits those set by embedded videos, social media widgets, or third-party plugins.
**Fix**: Run a full cookie scan and compare the results with your policy. Update the policy to include all discovered cookies, their durations, and purposes.
Mistake 4: Ignoring Consent Mode Gaps Using Google Consent Mode v2 without a properly integrated CMP can lead to gaps where Google tags fire in an unconsented state. This is a common finding in AEPD audits.
**Fix**: Use GDPRChecker’s Consent Mode diagnostics to confirm that consent signals are correctly passed to Google tags and that the default state is denied.
How to Validate with GDPRChecker
GDPRChecker provides a suite of scanning and monitoring tools to verify your HubSpot CMS cookie compliance in Spain:
- **Public Scanner**: Enter your URL to get an instant report on cookies, trackers, and consent banner presence. This is a free starting point.
- **Pre-Consent Scan**: Checks for network requests that fire before user interaction. Essential for proving prior consent.
- **Consent Mode Diagnostics**: Validates that Google Consent Mode v2 is implemented correctly, with default denied states and proper update triggers.
- **Banner Behavior Test**: Simulates accept and reject actions to confirm that tracking scripts respond accordingly.
- **Policy Link Checker**: Verifies that your privacy and cookie policies are linked and accessible.
- **Scheduled Monitoring** (paid plans): Automatically re-scans your site at intervals and alerts you to new trackers or compliance drift.
To get started, run a free scan on your HubSpot CMS site. If you find gaps, use the step-by-step implementation above to fix them, then re-scan to confirm.
For ongoing compliance, consider GDPRChecker’s paid plans, which include managed consent banners, runtime protection, consent records, and advanced diagnostics. These tools help you maintain evidence of compliance for potential AEPD inquiries.
Real-World Examples
Example 1: Spanish E-commerce Site on HubSpot CMS An online store using HubSpot CMS had Google Analytics 4, Meta Pixel, and HubSpot tracking. A GDPRChecker pre-consent scan revealed that the Meta Pixel was firing on page load before any consent. The fix involved wrapping the Pixel code in a consent check that only fired after the user accepted marketing cookies. A follow-up scan confirmed zero pre-consent marketing requests.
Example 2: B2B Lead Generation Site A B2B company used LinkedIn Insight Tag and Google Ads conversion tracking. Their cookie banner had a “Reject” button, but GDPRChecker’s banner behavior test showed that the LinkedIn tag still loaded after rejection. The issue was that the CMP was not correctly blocking the tag. After reconfiguring the CMP to honor the reject signal, the scan passed.
Example 3: HubSpot CMS Blog with Embedded YouTube Videos A blog embedded YouTube videos, which set third-party cookies. The cookie policy did not mention YouTube or its tracking. A full cookie scan identified these cookies, and the policy was updated to include YouTube’s privacy practices and how to opt out. The site also implemented a two-click solution for video embeds to block cookies until consent.
Implementation Checklist
- Inventory all analytics and advertising trackers on your HubSpot CMS site.
- Configure your consent banner to “Opt-in” mode with equal “Accept” and “Reject” buttons.
- Implement Google Consent Mode v2 with default denied states for all relevant storage types.
- Wrap non-Google scripts (Meta, LinkedIn, etc.) in consent checks or use a CMP that blocks them by default.
- Update your privacy and cookie policies to list all trackers, purposes, and third-party recipients.
- Run a GDPRChecker pre-consent scan to verify no tracking requests fire before consent.
- Test the reject flow: use GDPRChecker to confirm that rejecting cookies stops all non-essential trackers.
- Test the accept flow: confirm that accepting cookies loads all consented trackers.
- Check that your cookie banner links to the privacy policy and that the policy is accessible.
- Set up scheduled scans (if using GDPRChecker paid plans) to monitor for new trackers or configuration drift.
- Document your compliance measures and keep consent records for potential regulatory inquiries.
- Review and update your setup whenever you add new marketing tags or HubSpot CMS updates.
FAQ
What is HubSpot CMS cookie compliance Spain analytics and advertising tracker audit? It is the process of verifying that a HubSpot CMS website meets Spanish and GDPR cookie consent requirements for analytics and advertising trackers. This includes checking consent defaults, banner behavior, policy disclosures, and pre-consent network requests to ensure trackers only load after valid consent.
Do I need HubSpot CMS cookie compliance Spain analytics and advertising tracker audit for GDPR? Yes, if your HubSpot CMS site targets users in Spain, you must comply with the GDPR and Spanish LOPDGDD. An audit helps you identify and fix compliance gaps, such as trackers loading before consent or incomplete disclosures, reducing the risk of AEPD fines.
How do I implement HubSpot CMS cookie compliance Spain analytics and advertising tracker audit? Start by inventorying your trackers, then configure consent defaults to block non-essential scripts. Set up a compliant cookie banner, update your policies, and test pre- and post-consent behavior. Use GDPRChecker to scan and validate each step.
How can I verify HubSpot CMS cookie compliance Spain analytics and advertising tracker audit with a scanner? Use GDPRChecker’s public scanner for an initial cookie report, then run pre-consent and banner behavior tests. These scans check for unauthorized network requests, verify reject functionality, and confirm Consent Mode v2 defaults. Paid plans offer ongoing monitoring.
What are common HubSpot CMS cookie compliance Spain analytics and advertising tracker audit mistakes? Common mistakes include analytics loading before consent, reject buttons that don’t block trackers, incomplete cookie disclosures, and Consent Mode v2 misconfigurations. Regular scanning with GDPRChecker helps catch these issues.
Which cookies and trackers should I check for HubSpot CMS cookie compliance Spain analytics and advertising tracker audit? Check all analytics (e.g., Google Analytics 4, HubSpot analytics) and advertising trackers (e.g., Meta Pixel, LinkedIn Insight Tag, Google Ads). Also review third-party cookies from embedded content like YouTube videos or social widgets.
How often should I review HubSpot CMS cookie compliance Spain analytics and advertising tracker audit? Review your compliance at least quarterly, or whenever you add new trackers, update your CMS, or change consent settings. Continuous monitoring with GDPRChecker’s scheduled scans can alert you to changes in real time.
What evidence should I keep for HubSpot CMS cookie compliance Spain analytics and advertising tracker audit? Keep records of consent logs, cookie scan reports, policy screenshots, and documentation of your consent configuration. GDPRChecker’s paid plans provide consent records and scan history that can serve as evidence of compliance.
Next Steps
Ensuring **HubSpot CMS cookie compliance Spain analytics and advertising tracker audit** is an ongoing responsibility. Start with a free GDPRChecker scan to see where your site stands. If you find gaps, follow the implementation steps in this guide and re-scan to confirm. For deeper protection, explore our related guides:
- [GDPR Checklist for Small Businesses](/guides/gdpr-checklist-for-small-businesses) – a broader compliance roadmap.
- [Google Analytics GDPR Compliance](/guides/google-analytics-gdpr-compliance) – specific steps for GA4.
- [Google Consent Mode v2 Guide](/guides/google-consent-mode-v2-guide) – technical setup for consent signals.
- [Consent Mode v2 vs. Google Certified CMP](/guides/consent-mode-v2-vs-google-certified-cmp) – understand the differences.
- [Do I Need a CMP If I Do Not Run Google Ads?](/guides/do-i-need-a-cmp-if-i-do-not-run-google-ads) – decision guidance.
- [Cookie Banner Requirements](/guides/cookie-banner-requirements) – design and legal essentials.
Ready to validate your HubSpot CMS site? Run a free scan now and close your compliance gaps with confidence.
Next step
Run a GDPRChecker scan to validate consent behavior, trackers, and disclosures after you implement the checklist above.
> This guide is technical implementation guidance for website owners. It is not legal advice.
Article schema
```json { "@context": "https://schema.org", "@type": "Article", "headline": "HubSpot CMS Cookie Compliance in Spain: Analytics and Advertising Tracker Audit Guide", "description": "Practical guide to auditing HubSpot CMS cookie compliance in Spain for analytics and advertising trackers. Step-by-step implementation, common mistakes, and verification with GDPRChecker scanner.", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.gdprchecker.online/guides/hubspot-cms-cookie-compliance-in-spain-analytics-and-advertising-tracker-audit" }, "publisher": { "@type": "Organization", "name": "GDPRChecker", "url": "https://www.gdprchecker.online" } } ```
Copyright and editorial notice
© GDPRChecker
This original AI-assisted editorial draft was selected, reviewed, and published by GDPRChecker. All rights are reserved where protected by applicable law. Do not reproduce the article without permission.