To answer the first question, the list of trusted CAs is set by the browser/OS root store. They start from standards like the CA/Browser Forum Baseline Requirements (cf.
https://cabforum.org) and then apply their own criteria as they deem appropriate. For government CAs, they sometimes don’t use the applicable public audit standards (WebTrust, ETSI), so the root stores have to decide individually whether the audit standard the entity in question
does apply is sufficient to meet their requirements.
Worth noting that there’s an effort underway in the EU to take that decision out of the hands of browsers and mandate inclusions for EU CAs that meet the EU’s QWAC TSP standard, which would presumably include OP’s Spanish govt. CA.
For the inability to modify those lists on iOS, I’m with you: I would want to see the same level of modification ability for mobile platforms that we currently have on desktop OSes, but it’s up to Apple to implement that.