Banking Law And Critical Third-Party Dependency Regulation Spain .
BANKING LAW AND CRITICAL THIRD-PARTY DEPENDENCY REGULATION IN SPAIN
INTRODUCTION
Critical third-party dependency regulation in banking concerns the legal framework controlling situations where banks rely on external companies for essential services, technology, infrastructure or operational functions.
Modern Spanish banks increasingly depend on third-party providers for:
Cloud computing;
Data storage;
Cybersecurity services;
Payment processing;
Core banking software;
Artificial intelligence systems;
Digital identity services;
Network infrastructure.
This dependency creates a major regulatory concern: a failure at a third-party provider may affect multiple banks simultaneously and create systemic financial risks.
The European Union has responded through the Digital Operational Resilience Act (DORA) – Regulation (EU) 2022/2554, which establishes requirements for ICT risk management, incident reporting, resilience testing and supervision of critical ICT third-party providers. DORA applies directly to EU financial entities, including Spanish banks.
The central legal principle is:
A bank may outsource activities, but it cannot outsource regulatory responsibility.
1. LEGAL AND REGULATORY FRAMEWORK
A. Spanish Banking Supervision Framework
Spanish banking institutions operate under:
Law 10/2014 on the Regulation, Supervision and Solvency of Credit Institutions;
Royal Decree 84/2015;
European Banking Union rules;
European Central Bank supervision for significant institutions;
Banco de España supervision for other institutions.
These rules require banks to maintain:
sound governance;
internal controls;
risk-management systems;
operational continuity.
Third-party dependency is therefore treated as part of general banking risk management.
B. Digital Operational Resilience Act (DORA)
DORA represents the main European framework for third-party technology dependency.
It introduces specific obligations for banks concerning:
1. ICT Third-Party Risk Management
Banks must:
identify all critical technology dependencies;
maintain records of ICT providers;
evaluate risks before outsourcing;
monitor providers continuously.
DORA requires financial entities to manage ICT third-party risks throughout the entire relationship lifecycle, including due diligence, contracts, monitoring and exit planning.
2. Critical ICT Third-Party Providers (CTPPs)
Some technology providers may become systemically important because many banks depend on them.
Examples include providers of:
cloud infrastructure;
software platforms;
cybersecurity solutions;
data-processing services.
Under DORA, European supervisory authorities can designate certain ICT providers as Critical ICT Third-Party Providers and subject them to oversight.
2. CONCEPT OF CRITICAL THIRD-PARTY DEPENDENCY
A third-party dependency becomes "critical" when failure of the provider could significantly affect:
banking operations;
customer access to services;
payment systems;
financial stability.
Examples:
A. Cloud Dependency
Banks may store:
customer information;
transaction data;
applications;
analytical systems
with external cloud providers.
A cloud outage could affect several financial institutions simultaneously.
B. Payment Infrastructure Providers
Banks depend on external systems for:
payment processing;
card networks;
settlement services.
Failure may interrupt economic activity.
C. Cybersecurity Providers
External security providers may manage:
threat detection;
incident response;
monitoring systems.
A failure could increase vulnerability across multiple institutions.
3. GOVERNANCE DUTIES OF SPANISH BANKS
Bank boards remain responsible for third-party risk.
Responsibilities include:
approving outsourcing strategies;
understanding dependency risks;
ensuring adequate controls;
reviewing provider performance.
A board cannot argue that responsibility belongs entirely to a technology supplier.
The outsourcing decision itself is a governance decision.
4. DUE DILIGENCE BEFORE OUTSOURCING
Before appointing a third party, banks should evaluate:
Technical Capability
Does the provider have adequate:
security controls;
infrastructure;
resilience capacity?
Financial Stability
Can the provider continue operating during market stress?
Legal Compliance
Does the provider comply with:
data protection rules;
cybersecurity obligations;
regulatory requirements?
Concentration Risk
Would dependence on one provider create excessive systemic exposure?
5. CONTRACTUAL REQUIREMENTS
Banking contracts with critical providers require strong protections.
Important clauses include:
Audit Rights
Banks and supervisors must be able to examine provider controls.
Security Obligations
Contracts should establish:
cybersecurity standards;
confidentiality duties;
incident response obligations.
Incident Notification
Providers must promptly notify banks of disruptions.
Termination and Exit Rights
Banks require alternatives if a provider fails.
An effective exit strategy prevents dangerous dependency.
6. CONCENTRATION RISK
A major concern is excessive dependence on a small number of technology companies.
If many banks rely on the same provider:
Provider failure → Multiple banks affected → Systemic disruption.
Regulators therefore examine:
number of critical providers;
substitutability;
geographic concentration;
subcontractor dependencies.
DORA specifically addresses the systemic risks created by dependence on external ICT providers.
7. CLOUD COMPUTING AND BANKING LAW
Cloud services provide efficiency but create legal challenges.
Issues include:
Data Location
Where is banking data stored?
Access Rights
Can regulators access necessary information?
Service Continuity
Can customers continue receiving banking services during cloud failure?
Subcontracting
Does the provider rely on additional companies?
Banks must ensure that cloud adoption does not weaken regulatory control.
8. CYBERSECURITY AND THIRD-PARTY INCIDENTS
Third-party failures may involve:
cyberattacks;
data breaches;
service interruptions;
unauthorized access.
Banks must have:
incident response plans;
recovery procedures;
communication mechanisms.
A technology failure at a supplier may still create regulatory consequences for the bank.
9. DATA PROTECTION RESPONSIBILITIES
Third-party providers often process significant amounts of personal financial information.
Applicable rules include:
General Data Protection Regulation (GDPR);
Spanish Organic Law 3/2018 on Data Protection.
Banks must ensure:
lawful processing;
confidentiality;
security measures;
proper contractual arrangements.
A supplier's mistake does not eliminate the bank's responsibility toward customers.
10. OPERATIONAL RESILIENCE AND EXIT STRATEGIES
A key requirement of third-party dependency regulation is avoiding situations where a bank cannot operate without one provider.
Banks should maintain:
alternative providers;
backup systems;
migration plans;
tested recovery procedures.
An exit strategy is not simply a contractual clause; it is a financial stability requirement.
KEY LEGAL PRINCIPLES
1. Responsibility Remains With the Bank
Outsourcing transfers performance of a function, not regulatory accountability.
2. Critical Providers Become Part of Financial Infrastructure
A technology company providing essential banking services may effectively become part of the financial system.
3. Risk Must Be Managed Before Failure
Regulation focuses on prevention rather than only compensation after disruption.
CASE LAW
CASE 1: Banco Santander SA v. European Commission (General Court of the EU – Banking Regulation Principles)
Facts
The case involved regulatory measures affecting banking institutions and EU supervisory powers.
Legal Principle
Banks operating within the European financial system remain subject to extensive regulatory oversight designed to protect financial stability.
Importance
Third-party dependency decisions are also subject to regulatory expectations because operational failures may affect stability.
CASE 2: Google Spain SL v AEPD and Mario Costeja González (CJEU Case C-131/12)
Facts
The case concerned responsibilities of digital operators processing personal information.
Legal Principle
Organizations handling personal data must respect data-protection obligations.
Importance for Banking
Banks using external technology providers must ensure customer financial information remains protected.
CASE 3: Banco Español de Crédito SA v Camino (CJEU Case C-618/10)
Facts
The case concerned consumer protection and unfair banking contract terms.
Legal Principle
Banks must maintain transparency and fairness in their relationships with customers.
Importance
Where third-party failures affect banking services, customers remain entitled to protection and effective remedies.
CASE 4: Schrems II (CJEU Case C-311/18)
Facts
The case examined international transfer of personal data and adequacy of protection mechanisms.
Legal Principle
Organizations transferring personal data must ensure appropriate legal protection.
Importance for Banking
Spanish banks using foreign technology providers must consider data-location and transfer risks.
CASE 5: Banco Popular Resolution Litigation (EU General Court)
Facts
The litigation followed the resolution of Banco Popular and concerned banking stability mechanisms.
Legal Principle
Banking failures may have consequences beyond individual institutions and require regulatory intervention.
Importance
Third-party technology failures can similarly create systemic concerns requiring preventive regulation.
11. SUPERVISORY ENFORCEMENT
Spanish regulators may examine:
outsourcing arrangements;
ICT governance;
cybersecurity controls;
provider dependency.
Supervisory concerns may lead to:
corrective measures;
additional requirements;
restrictions on outsourcing practices.
12. FUTURE CHALLENGES
Artificial Intelligence Providers
Banks increasingly depend on external AI systems for:
fraud detection;
credit analysis;
customer services.
Questions arise concerning:
transparency;
accountability;
model failures.
Quantum and Cybersecurity Risks
Future technologies may challenge existing security systems.
Technology Concentration
Heavy reliance on a few global providers may create strategic dependency risks.
CONCLUSION
Critical third-party dependency regulation in Spanish banking law reflects the transformation of banking from a purely financial activity into a technology-dependent infrastructure service.
Spain applies a layered framework based on:
national banking supervision;
Banco de España oversight;
EU operational resilience rules;
DORA requirements;
data-protection law.
The modern regulatory approach recognises that external technology providers can become essential components of the financial system.
Case law demonstrates that banks remain responsible for protecting customers, maintaining transparency and ensuring lawful processing of information even when services are performed through external providers.
The fundamental principle is:
A bank may rely on third parties for technology and services, but it cannot transfer responsibility for financial stability, customer protection and operational resilience.

comments