Banking Law And Data Economy Finance Spain .
Introduction
The data economy has transformed Spanish finance. Banks, payment institutions, electronic-money institutions, insurers, fintech firms, credit bureaux and investment platforms now rely on customer data, transaction histories, device identifiers, credit scores, behavioural analytics and artificial intelligence. Data enables fraud prevention, credit assessment, personalised products, open banking and faster payments. However, it also creates major legal risks: misuse of confidential information, discriminatory automated decisions, opaque profiling, cybersecurity failures, market power based on data, and unfair consumer practices.
Spain’s framework is largely based on European Union law, supplemented by Spanish banking, data-protection and consumer rules. The principal authorities are the Banco de España, the Spanish Data Protection Agency (AEPD), the National Securities Market Commission (CNMV), and the Spanish competition authority (CNMC).
Legal and Regulatory Framework
1. GDPR and Spain’s Organic Law 3/2018
The General Data Protection Regulation (GDPR) applies directly in Spain. Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantees complements it nationally. A bank must have a lawful basis for each use of personal data, such as performance of a banking contract, compliance with anti-money-laundering duties, legitimate interest, or valid consent.
Banks must apply purpose limitation and data minimisation. Information collected to open an account should not automatically be reused for unrelated marketing, profiling or third-party sharing. Customers have rights of access, correction, deletion in appropriate circumstances, objection, portability and protection against certain solely automated decisions.
Financial data is especially sensitive because it can reveal spending patterns, health-related purchases, religious donations, political activity, location, family circumstances and financial vulnerability. Therefore, banks need strong access controls, retention schedules, audit trails and governance procedures.
2. Banking Secrecy and Prudential Supervision
Spanish credit institutions operate under Law 10/2014 on the organisation, supervision and solvency of credit institutions, European prudential rules, and Banco de España supervision. Banking secrecy and confidentiality remain essential contractual and regulatory duties.
A bank may disclose data where legally required, including to tax, court, anti-money-laundering or supervisory authorities. Yet disclosure must be necessary, proportionate, secure and properly documented. Outsourcing data processing to cloud providers, analytics vendors or fintech partners does not remove the bank’s responsibility.
Banco de España also expects institutions to maintain sound governance, internal controls and operational resilience. Data quality is increasingly a prudential issue because inaccurate or incomplete information can distort credit-risk models, capital calculations, liquidity monitoring and fraud detection.
3. Open Banking, PSD2 and Data Sharing
Spain implemented the revised Payment Services Directive through Royal Decree-Law 19/2018. It allows authorised payment-initiation and account-information service providers to access payment-account data with the customer’s explicit consent and through secure interfaces.
Open banking is not unrestricted data ownership. The customer controls access, and banks must ensure strong customer authentication, secure communication and transparent information. A bank cannot use security as an unjustified reason to block legitimate third-party providers, but it may take proportionate measures against fraud or unauthorised access.
4. AI, Credit Scoring and Automated Decisions
Credit scoring is central to the data economy. Banks use algorithms to decide whether to lend, price credit, detect fraud or monitor default risk. GDPR Article 22 limits decisions based solely on automated processing where they produce legal or similarly significant effects.
A rejected loan application may be a significant effect. Banks must therefore identify the legal basis for automation, provide meaningful information about the processing, allow human intervention where required, and enable the consumer to contest the decision. They must test models for accuracy, bias, explainability and data quality.
The EU Artificial Intelligence Act also treats certain creditworthiness and credit-scoring systems as high-risk. Financial institutions must prepare for governance duties concerning risk management, data quality, documentation, human oversight and monitoring.
5. Digital Operational Resilience and Cybersecurity
The Digital Operational Resilience Act (DORA) applies to relevant Spanish financial entities. It requires governance of ICT risk, incident management, resilience testing, third-party risk controls and contractual safeguards for critical technology providers.
A data economy cannot function without reliable systems. A cyberattack, cloud outage or data breach can interrupt payments, expose confidential records and create systemic risk. Banks must maintain response plans, report qualifying major ICT incidents, preserve evidence and review lessons after an incident.
Key Legal Issues and Principles
1. Data Is Valuable but Not Freely Exploitable
Financial data may have commercial value, but personal data is not a tradable asset that a bank can use without legal limits. The bank must distinguish between anonymised data, pseudonymised data and identifiable personal data. Pseudonymised data generally remains personal data.
2. Transparency Is a Consumer-Protection Requirement
Privacy notices, consent screens and digital interfaces must be understandable. A bank should not obtain consent through pre-ticked boxes, hidden options or confusing “dark patterns.” Customers must know what data is collected, why, who receives it, how long it is retained, and how automated decisions affect them.
3. Competition Concerns in Data-Driven Finance
Large platforms may combine payment, social-media, advertising and behavioural data to strengthen market power. Competition law can intervene where a dominant undertaking uses data in an exploitative or exclusionary manner. Financial institutions should assess whether data-sharing arrangements, joint analytics projects or platform partnerships restrict competition.
Case Laws
1. SCHUFA Holding (Scoring), C-634/21
The Court of Justice of the European Union held that automated credit scoring can fall within GDPR restrictions on solely automated decision-making where lenders rely heavily on the score. This is highly relevant to Spanish banks using credit-bureau or internal scoring systems.
2. Österreichische Post, C-300/21
The Court held that a GDPR infringement alone does not automatically create compensation; the claimant must show actual damage and a causal link. Spanish banks may still face compensation claims where unlawful data processing causes material or non-material harm.
3. RW v Österreichische Post, C-154/21
The Court ruled that data subjects may request information about the actual recipients of their data, not merely broad recipient categories. Banks must maintain accurate records of vendors, affiliates and other recipients.
4. Meta Platforms v Bundeskartellamt, C-252/21
The Court confirmed that competition authorities may consider GDPR compliance when assessing abusive conduct by dominant firms. The ruling matters for data-rich financial platforms and bank-platform partnerships.
5. Vyriausioji tarnybinės etikos komisija, C-184/20
The Court stressed data minimisation and the need to avoid unnecessary disclosure of personal information. Spanish financial institutions should collect only data genuinely necessary for the relevant banking purpose.
6. Schrems II, C-311/18
The Court invalidated the EU–US Privacy Shield and required stronger safeguards for many international data transfers. Spanish banks using global cloud, payment or analytics providers must assess cross-border transfers carefully.
Conclusion
Spain’s data economy finance framework permits innovation, open banking and AI-driven services, but only within strict rules on privacy, confidentiality, fairness, resilience and accountability. Banks must treat data governance as a board-level responsibility. Strong consent management, reliable credit models, transparent automated decisions, secure outsourcing, and effective consumer remedies are essential to lawful and trustworthy digital finance.

comments