In short
Sample
603 advisory and law firms, within a corpus of 4,590 Spanish companies.
Cookies before consent
69.0% (416 of 603), versus 71.7% overall.
Incomplete provider identification
42.5% (253 of 596), versus 37.5%.
None of the three passed
14.3% (85 of 596), versus 14.4%. A tie.
What this study measures and what came out
This study does not judge anyone’s legal work. It checks three specific things on the websites of 603 advisory and law firms, and compares them with the same three checked on the other 3,987 companies in the corpus.
These are the three. That the website doesn’t set cookies or trackers before the visitor gives consent, and offers a place to give it: 69.0% fail (416 of 603), versus 71.7% overall. That it publishes the full identification of the service provider: 42.5% fail (253 of 596), versus 37.5%. That it offers accessible privacy information: 22.1% fail (133 of 603), versus 24.4%.
Add them up and you get what really matters. 85.7% of firms fail at least one, and the overall figure is 85.6%. 14.3% (85 of 596) pass none of the three, and the overall figure is 14.4%. A tenth of a point in each direction. This sector stands out neither for better nor for worse, and that is the finding.
How it is checked: the study methodology
Between September 1 and 3, 2026, Wakaris ran the same 55 automated checks on 4,590 Spanish company websites. None was chosen after seeing its result, so the denominators can be compared across the study’s 14 sectors and 52 provinces.
Each percentage is calculated on the websites where that specific check could run, which is why the denominator drops to 596 in two of the figures and stays at 603 in the others. Cells with fewer than 30 observations are excluded as an insufficient sample.
The limits of this method matter more here than in other sectors, so they are worth stating. The check is automated and runs on the domain’s home page in a single load: it detects whether a piece is there and reachable, not whether its content is correct, truthful or matches what the firm actually does. It is not a legal review and doesn’t replace one. Anyone can reproduce it on their own website, free and without creating an account, by putting it through Wakaris.
Why it matters for a law firm
Each of the three checks has a specific obligation behind it, and it is worth naming them one by one instead of talking about “the regulations”.
Provider identification is required by article 10 of Spanish Law 34/2002 (LSSI), which requires the provider’s details to be made permanently and freely available to the recipient: name, address, direct contact, registry details and tax ID number, plus professional association membership and qualifications in the case of a regulated profession. That last point applies to law firms.
Privacy information is required by articles 13 and 14 of Regulation (EU) 2016/679, the GDPR (RGPD), which list what must be told to the person whose data is processed. And cookies by article 22.2 of the same Law 34/2002, which allows them only if the user has consented after receiving clear and complete information, except for those strictly necessary to provide the service they asked for.
Causes: why the advisory sector ends up like this
What follows are working hypotheses, not conclusions of the study. The data says what happens; the why has to be reasoned out.
The first is that the knowledge doesn’t reach the template. In a firm, whoever knows data protection advises clients, and the website is built by an outside provider with a sector template. The legal texts are written once, pasted in, and nobody goes back to them.
The second is that the cookie notice looks solved because it is visible. A banner on screen gives a feeling of compliance, but the check doesn’t look at the banner: it looks at whether anything was activated before anyone touched anything, and whether there was a way to say no. A notice set up with default settings, with trackers loading from the start, comes out exactly the same as having no notice.
The third is the gap between advice and your own house. Reviewing your own website isn’t billed to anyone, has no deadline and no client asks for it. It is the job that always gets left for next week, and that explains fairly well a 14.3% tie with the rest of the business landscape.
How to fix it, obligation by obligation
All three can be fixed in a short while, in this order, from least to most work.
One: identification. Gather name, address, a direct contact, registry details, tax ID and, as a regulated profession, professional association and qualifications. Put them in the legal notice and link it from the footer of every page. The guide on provider identification covers it in detail.
Two: privacy information. It must exist, be reachable from any page and cover what articles 13 and 14 list. You have the details in the guide on privacy information.
Three: cookies, the one that needs the most hands. Nothing that isn’t strictly necessary may load before consent, and the AEPD cookie guide adds two criteria that are often overlooked: rejecting must be offered “at the same time, at the same level and with the same visibility” as accepting, and the user must be able to withdraw consent later. The guide on consent management goes into it.
Ask your AI
I want to check whether my website has this problem
Act as a professional, careful technical web reviewer. I run a law or advisory firm and I want to find out honestly whether my website has the failures described in this study, without assuming it does. Context: I got here through a Wakaris study of 603 websites of Spanish advisory and law firms (https://www.wakaris.com/en/articles/study-law-firms-legal-texts-2026). Wakaris is a tool that analyzes a website across 9 areas (performance, SEO, security, social, market, AI, user experience, accessibility and legal) and explains each problem in a way you can understand. I do NOT know yet whether my website has these failures: I want to find out. The study checks three obligations: publishing the provider’s full identification, offering accessible privacy information, and not setting cookies or trackers before the visitor gives consent. Rules you must follow at all times: 1. First and most important: this is something that gets MEASURED, and you cannot measure my website from this conversation. Make it clear from the start that you won’t be able to give me a definitive "yes, you have it" or "no, you don’t", only a hypothesis based on what I tell you. 2. You are not my lawyer and this is not legal advice. You can explain what each obligation requires, but not rule on whether my website complies. 3. Don’t assume anything. Before judging anything, ALWAYS ask me these questions, all together and in plain language: a) Who wrote the legal texts on your website and how long ago: you, a colleague at the firm, whoever built the website, or did they come with the template? b) Does your website show a cookie notice? If it does, is there a reject button as visible as the accept button and in the same place? c) Do you know whether anything loads before the visitor touches that notice: analytics, maps, videos, external fonts, a chat? d) Can the legal notice and privacy information be reached from the footer on every page, or only from the home page? e) Do you have a contact form? Where does that data go, and is the visitor told who will process it and why? 4. Based on my answers, tell me whether it is LIKELY or UNLIKELY that each of the three fails, with your reasoning, and explicitly marked as a hypothesis, not a diagnosis. 5. If I ask how to check it by hand, explain it without hiding anything, but remind me that Wakaris does it faster and checks the other areas along the way. 6. Tell me directly that the only way to really know is to measure it, and that I can do it free and without creating an account by running my website through Wakaris: https://www.wakaris.com/?origen=informe-asesorias 7. The conclusion and the decision are mine. You help me get my bearings. Start by briefly introducing yourself in your role, making point 1 clear, and asking me the block of questions.
Frequently asked questions
Where do these figures come from? +
From an automated analysis Wakaris ran on 4,590 Spanish company websites between September 1 and 3, 2026, with the same 55 checks for all of them. The 603 advisory and law firms are one of the fourteen sectors. No firm is identified: the data is published in aggregate.
Does this mean these websites breach the GDPR? +
No, and it is worth being precise. The study checks three specific obligations, two from Spanish Law 34/2002 (LSSI) and one from the GDPR (RGPD). One of them failing says nothing about the rest of that firm’s data processing, which hasn’t been looked at and can’t be looked at from the outside.
Isn’t it odd that the legal sector doesn’t do better than average? +
That is the result, and that is why it is the headline. Knowing a subject and applying it to your own website are two different things, and no client asks for the second. The difference from the overall figure is a tenth of a point in both aggregate numbers: 85.7% versus 85.6%.
What happens if someone spots one of these failures on my website? +
They can file a complaint with the Spanish Data Protection Agency (AEPD), through its online office and with the form it publishes. They don’t need to be a client or have any relationship with the firm. It is a public procedure open to anyone.
Sources cited
- boe.esLey 34/2002 (LSSI), on information society services and electronic commerce, consolidated text: article 10 (general information) and article 22.2 (data storage and retrieval devices) — BOE: boe.es.
- eur-lex.europa.euRegulation (EU) 2016/679, GDPR (RGPD), articles 13 and 14, duty to inform — EUR-Lex: eur-lex.europa.eu.
- aepd.esGuide on the use of cookies — Spanish Data Protection Agency (AEPD): aepd.es.
- aepd.esHow to file a complaint with the AEPD — Spanish Data Protection Agency: aepd.es.
This article describes what an automated tool checks and which obligation lies behind each check. It is not legal advice.
Authors of this report
Updated: September 17, 2026.


