Banking Law And Data Governance Frameworks Banks Spain .
Introduction
Data governance in Spanish banking concerns the lawful, secure, accurate and accountable use of customer, employee, borrower and transaction data. Banks hold highly sensitive information, including identity records, account activity, payment data, credit histories, anti-money-laundering alerts, biometric identifiers and data used in automated lending decisions. Poor governance can result in regulatory sanctions, customer claims, fraud losses and reputational harm.
Spain applies a combined European and national framework. The General Data Protection Regulation (GDPR) is directly applicable, while Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantee supplements it. Banking-specific obligations also arise under Law 10/2010 on anti-money laundering, Royal Decree-Law 19/2018 on payment services, credit-information rules, financial-sector outsourcing requirements and the Digital Operational Resilience Act (DORA).
Legal And Regulatory Framework
1. GDPR Principles and Accountability
A Spanish bank is normally the data controller because it decides why and how personal data are processed. Under Articles 5 and 24 GDPR, it must demonstrate compliance with core principles: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, confidentiality and accountability.
This means a bank cannot collect data merely because it may be commercially useful in the future. It must identify a defined purpose, retain only necessary information and document its legal basis. For routine account management, the basis is usually performance of contract or compliance with legal obligations. For optional marketing, profiling beyond core services or sharing with affiliates, consent or legitimate interests may be relevant, but these must be carefully assessed.
2. Customer Information, Transparency and Access Rights
Banks must provide understandable privacy notices explaining what data they use, why they use it, who receives it and how long it is retained. This is especially important where data are drawn from credit-reference agencies, used for fraud monitoring or shared within a banking group.
Under Article 15 GDPR, customers may request access to their data. Banks must provide meaningful information, including the categories of data, purposes, recipients and safeguards for international transfers. A generic statement that data were shared with “business partners” will usually be insufficient.
Customers may also seek correction of inaccurate data, restriction of processing, deletion where no lawful basis remains and portability of eligible data. These rights are not absolute: statutory banking, tax and AML retention duties can justify continued preservation.
3. Credit Data and Automated Decision-Making
Credit scoring, affordability assessments and anti-fraud tools increasingly use automated systems. Article 22 GDPR restricts decisions based solely on automated processing where they produce legal or similarly significant effects, such as refusing a loan or setting materially adverse credit conditions.
A bank using automated credit assessment should ensure human intervention is available, provide meaningful information about the logic involved and give the customer an opportunity to challenge the result. Data quality is central: inaccurate default records, outdated income information or opaque risk models can lead to unlawful decisions and consumer harm.
Spain also regulates credit solvency information through Organic Law 3/2018. Banks should verify that negative credit data are accurate, relevant, proportionate and lawfully reported before relying on or disclosing them.
4. AML, Financial Crime and Retention
Law 10/2010 requires banks to conduct customer due diligence, monitor transactions and retain supporting documentation. These legal duties justify substantial processing of personal data without customer consent. However, AML compliance does not remove GDPR obligations. The bank must still restrict access, apply security controls and prevent use of AML data for incompatible commercial purposes.
Suspicious-transaction information is particularly sensitive. Internal access should be strictly controlled, with segregation between compliance, business and investigation functions. Improper disclosure may undermine an investigation and breach confidentiality obligations.
5. Security, Outsourcing and Operational Resilience
Article 32 GDPR requires security measures appropriate to risk, including access controls, encryption, resilience, testing and recovery procedures. DORA, applicable to financial entities since January 2025, reinforces governance of ICT risk, incident reporting, digital-resilience testing and oversight of critical technology suppliers.
A Spanish bank remains accountable when it uses cloud providers, payment processors, analytics companies or group service centres. Contracts must define confidentiality, processing instructions, incident notification, audit rights, sub-processing controls, deletion or return of data and international-transfer safeguards.
Key Governance Issues for Spanish Banks
1. Data Sharing Within Banking Groups
Group-wide risk management may be legitimate, but sharing cannot be unlimited. Each recipient must have a defined role and legal basis. Banks should maintain data-mapping records, access controls and clear allocation of controller or processor responsibilities.
2. Marketing and Profiling
Banks commonly use transaction patterns and customer profiles to market loans, insurance or investment products. Governance requires transparent notices, a valid legal basis, an easy right to object to direct marketing and strong controls against discriminatory or unsuitable profiling.
3. International Data Transfers
Transfers outside the European Economic Area must comply with Chapter V GDPR. Banks using global cloud infrastructure must identify where data are accessed, assess foreign-law risks and use appropriate safeguards, such as standard contractual clauses and supplementary technical measures.
Case Laws
1. CJEU, SCHUFA Holding, Case C-634/21 (2023)
The Court held that automated credit scoring may fall within Article 22 GDPR where the score plays a determining role in a lender’s decision. Spanish banks must not treat a score as unquestionable where it effectively decides credit access. Human review and meaningful safeguards are essential.
2. CJEU, Österreichische Post, Case C-300/21 (2023)
The Court clarified that a GDPR infringement alone does not automatically create a right to compensation; actual damage and a causal link are required. However, no minimum seriousness threshold applies. A bank may therefore face damages claims for genuine non-material harm caused by unlawful data processing.
3. CJEU, Österreichische Post, Case C-154/21 (2023)
The Court ruled that a data subject has the right to know the actual identity of recipients of personal data, not merely broad recipient categories, unless identifying recipients is impossible or the request is manifestly unfounded. This is important for bank disclosures about group entities, vendors and credit bureaux.
4. CJEU, SCHUFA Holding, Case C-26/22 and C-64/22 (2023)
The Court stressed that retention of insolvency-related information by credit-reference systems must respect GDPR storage-limitation rules. The principle applies to Spanish banks: adverse financial data cannot be retained simply because it may remain commercially useful.
5. CJEU, Natsionalna agentsia za prihodite, Case C-340/21 (2023)
The Court held that a data breach does not automatically prove inadequate security, but the controller must show that its measures were appropriate to risk. For banks, this makes documented cybersecurity controls, testing and incident evidence vital.
6. CJEU, Schrems II, Case C-311/18 (2020)
The Court required organisations transferring personal data outside the EEA to assess whether foreign laws compromise EU-level protection and to add safeguards where necessary. Spanish banks using non-EEA cloud or group-service providers must conduct and document this assessment.
Conclusion
Spanish banking data governance is no longer only a privacy-compliance issue. It is a core part of credit decision-making, AML controls, cybersecurity, customer trust and board responsibility. Banks should maintain a complete data inventory, clear legal bases, proportionate retention schedules, strong vendor controls, reliable human oversight of automated decisions and evidence of continual compliance. A well-designed governance framework reduces both regulatory exposure and the risk of unfair, inaccurate or insecure use of customer financial data.

comments