Banking Law And Critical Third-Party Dependency Regulation Spain .

BANKING LAW AND CRITICAL THIRD-PARTY DEPENDENCY REGULATION IN SPAIN

INTRODUCTION

Critical third-party dependency regulation in banking concerns the legal framework controlling situations where banks rely on external companies for essential services, technology, infrastructure or operational functions.

Modern Spanish banks increasingly depend on third-party providers for:

Cloud computing;

Data storage;

Cybersecurity services;

Payment processing;

Core banking software;

Artificial intelligence systems;

Digital identity services;

Network infrastructure.

This dependency creates a major regulatory concern: a failure at a third-party provider may affect multiple banks simultaneously and create systemic financial risks.

The European Union has responded through the Digital Operational Resilience Act (DORA) – Regulation (EU) 2022/2554, which establishes requirements for ICT risk management, incident reporting, resilience testing and supervision of critical ICT third-party providers. DORA applies directly to EU financial entities, including Spanish banks.

The central legal principle is:

A bank may outsource activities, but it cannot outsource regulatory responsibility.

1. LEGAL AND REGULATORY FRAMEWORK

A. Spanish Banking Supervision Framework

Spanish banking institutions operate under:

Law 10/2014 on the Regulation, Supervision and Solvency of Credit Institutions;

Royal Decree 84/2015;

European Banking Union rules;

European Central Bank supervision for significant institutions;

Banco de España supervision for other institutions.

These rules require banks to maintain:

sound governance;

internal controls;

risk-management systems;

operational continuity.

Third-party dependency is therefore treated as part of general banking risk management.

B. Digital Operational Resilience Act (DORA)

DORA represents the main European framework for third-party technology dependency.

It introduces specific obligations for banks concerning:

1. ICT Third-Party Risk Management

Banks must:

identify all critical technology dependencies;

maintain records of ICT providers;

evaluate risks before outsourcing;

monitor providers continuously.

DORA requires financial entities to manage ICT third-party risks throughout the entire relationship lifecycle, including due diligence, contracts, monitoring and exit planning.

2. Critical ICT Third-Party Providers (CTPPs)

Some technology providers may become systemically important because many banks depend on them.

Examples include providers of:

cloud infrastructure;

software platforms;

cybersecurity solutions;

data-processing services.

Under DORA, European supervisory authorities can designate certain ICT providers as Critical ICT Third-Party Providers and subject them to oversight.

2. CONCEPT OF CRITICAL THIRD-PARTY DEPENDENCY

A third-party dependency becomes "critical" when failure of the provider could significantly affect:

banking operations;

customer access to services;

payment systems;

financial stability.

Examples:

A. Cloud Dependency

Banks may store:

customer information;

transaction data;

applications;

analytical systems

with external cloud providers.

A cloud outage could affect several financial institutions simultaneously.

B. Payment Infrastructure Providers

Banks depend on external systems for:

payment processing;

card networks;

settlement services.

Failure may interrupt economic activity.

C. Cybersecurity Providers

External security providers may manage:

threat detection;

incident response;

monitoring systems.

A failure could increase vulnerability across multiple institutions.

3. GOVERNANCE DUTIES OF SPANISH BANKS

Bank boards remain responsible for third-party risk.

Responsibilities include:

approving outsourcing strategies;

understanding dependency risks;

ensuring adequate controls;

reviewing provider performance.

A board cannot argue that responsibility belongs entirely to a technology supplier.

The outsourcing decision itself is a governance decision.

4. DUE DILIGENCE BEFORE OUTSOURCING

Before appointing a third party, banks should evaluate:

Technical Capability

Does the provider have adequate:

security controls;

infrastructure;

resilience capacity?

Financial Stability

Can the provider continue operating during market stress?

Legal Compliance

Does the provider comply with:

data protection rules;

cybersecurity obligations;

regulatory requirements?

Concentration Risk

Would dependence on one provider create excessive systemic exposure?

5. CONTRACTUAL REQUIREMENTS

Banking contracts with critical providers require strong protections.

Important clauses include:

Audit Rights

Banks and supervisors must be able to examine provider controls.

Security Obligations

Contracts should establish:

cybersecurity standards;

confidentiality duties;

incident response obligations.

Incident Notification

Providers must promptly notify banks of disruptions.

Termination and Exit Rights

Banks require alternatives if a provider fails.

An effective exit strategy prevents dangerous dependency.

6. CONCENTRATION RISK

A major concern is excessive dependence on a small number of technology companies.

If many banks rely on the same provider:

Provider failure → Multiple banks affected → Systemic disruption.

Regulators therefore examine:

number of critical providers;

substitutability;

geographic concentration;

subcontractor dependencies.

DORA specifically addresses the systemic risks created by dependence on external ICT providers.

7. CLOUD COMPUTING AND BANKING LAW

Cloud services provide efficiency but create legal challenges.

Issues include:

Data Location

Where is banking data stored?

Access Rights

Can regulators access necessary information?

Service Continuity

Can customers continue receiving banking services during cloud failure?

Subcontracting

Does the provider rely on additional companies?

Banks must ensure that cloud adoption does not weaken regulatory control.

8. CYBERSECURITY AND THIRD-PARTY INCIDENTS

Third-party failures may involve:

cyberattacks;

data breaches;

service interruptions;

unauthorized access.

Banks must have:

incident response plans;

recovery procedures;

communication mechanisms.

A technology failure at a supplier may still create regulatory consequences for the bank.

9. DATA PROTECTION RESPONSIBILITIES

Third-party providers often process significant amounts of personal financial information.

Applicable rules include:

General Data Protection Regulation (GDPR);

Spanish Organic Law 3/2018 on Data Protection.

Banks must ensure:

lawful processing;

confidentiality;

security measures;

proper contractual arrangements.

A supplier's mistake does not eliminate the bank's responsibility toward customers.

10. OPERATIONAL RESILIENCE AND EXIT STRATEGIES

A key requirement of third-party dependency regulation is avoiding situations where a bank cannot operate without one provider.

Banks should maintain:

alternative providers;

backup systems;

migration plans;

tested recovery procedures.

An exit strategy is not simply a contractual clause; it is a financial stability requirement.

KEY LEGAL PRINCIPLES

1. Responsibility Remains With the Bank

Outsourcing transfers performance of a function, not regulatory accountability.

2. Critical Providers Become Part of Financial Infrastructure

A technology company providing essential banking services may effectively become part of the financial system.

3. Risk Must Be Managed Before Failure

Regulation focuses on prevention rather than only compensation after disruption.

CASE LAW

CASE 1: Banco Santander SA v. European Commission (General Court of the EU – Banking Regulation Principles)

Facts

The case involved regulatory measures affecting banking institutions and EU supervisory powers.

Legal Principle

Banks operating within the European financial system remain subject to extensive regulatory oversight designed to protect financial stability.

Importance

Third-party dependency decisions are also subject to regulatory expectations because operational failures may affect stability.

CASE 2: Google Spain SL v AEPD and Mario Costeja González (CJEU Case C-131/12)

Facts

The case concerned responsibilities of digital operators processing personal information.

Legal Principle

Organizations handling personal data must respect data-protection obligations.

Importance for Banking

Banks using external technology providers must ensure customer financial information remains protected.

CASE 3: Banco Español de Crédito SA v Camino (CJEU Case C-618/10)

Facts

The case concerned consumer protection and unfair banking contract terms.

Legal Principle

Banks must maintain transparency and fairness in their relationships with customers.

Importance

Where third-party failures affect banking services, customers remain entitled to protection and effective remedies.

CASE 4: Schrems II (CJEU Case C-311/18)

Facts

The case examined international transfer of personal data and adequacy of protection mechanisms.

Legal Principle

Organizations transferring personal data must ensure appropriate legal protection.

Importance for Banking

Spanish banks using foreign technology providers must consider data-location and transfer risks.

CASE 5: Banco Popular Resolution Litigation (EU General Court)

Facts

The litigation followed the resolution of Banco Popular and concerned banking stability mechanisms.

Legal Principle

Banking failures may have consequences beyond individual institutions and require regulatory intervention.

Importance

Third-party technology failures can similarly create systemic concerns requiring preventive regulation.

11. SUPERVISORY ENFORCEMENT

Spanish regulators may examine:

outsourcing arrangements;

ICT governance;

cybersecurity controls;

provider dependency.

Supervisory concerns may lead to:

corrective measures;

additional requirements;

restrictions on outsourcing practices.

12. FUTURE CHALLENGES

Artificial Intelligence Providers

Banks increasingly depend on external AI systems for:

fraud detection;

credit analysis;

customer services.

Questions arise concerning:

transparency;

accountability;

model failures.

Quantum and Cybersecurity Risks

Future technologies may challenge existing security systems.

Technology Concentration

Heavy reliance on a few global providers may create strategic dependency risks.

CONCLUSION

Critical third-party dependency regulation in Spanish banking law reflects the transformation of banking from a purely financial activity into a technology-dependent infrastructure service.

Spain applies a layered framework based on:

national banking supervision;

Banco de España oversight;

EU operational resilience rules;

DORA requirements;

data-protection law.

The modern regulatory approach recognises that external technology providers can become essential components of the financial system.

Case law demonstrates that banks remain responsible for protecting customers, maintaining transparency and ensuring lawful processing of information even when services are performed through external providers.

The fundamental principle is:

A bank may rely on third parties for technology and services, but it cannot transfer responsibility for financial stability, customer protection and operational resilience.

LEAVE A COMMENT