Banking Law And Data Sharing Obligations Spain .

Introduction

In Spain, banks hold extensive personal and financial information, including account records, payment data, credit history, identity documents, transaction patterns and anti-money-laundering records. They cannot freely share this information merely because another company, group entity or public authority requests it. Data sharing must be necessary, legally justified, transparent and secure.

The main rule is that customer confidentiality and data protection apply by default. However, Spanish banking law creates specific situations where banks must share data, especially with regulators, tax authorities, courts, payment-service providers and anti-money-laundering authorities. The legal challenge is to balance supervision, fraud prevention and financial-system integrity with customers’ privacy rights.

Legal and Regulatory Framework

The central legal framework is the EU General Data Protection Regulation (GDPR), directly applicable in Spain, together with Organic Law 3/2018 on Personal Data Protection and Digital Rights. A bank must identify a lawful basis before it shares personal data. The most important bases are legal obligation, performance of a contract, legitimate interests, consent, and protection against fraud.

Consent is not always required. For example, a bank may disclose data to the Bank of Spain, the Spanish tax authority, a court or the financial intelligence unit where legislation obliges it to do so. But where disclosure is for commercial profiling, sharing with affiliates, or marketing by third parties, the bank normally needs a valid and clearly explained basis, often explicit consent.

Spanish Law 10/2010 on anti-money laundering and terrorist-financing prevention requires banks to identify customers, monitor transactions, retain information and report suspicious activity. These duties can justify sharing data with SEPBLAC, Spain’s anti-money-laundering authority. Customers generally cannot use privacy law to block a disclosure that is legally required for AML purposes.

Banks may also provide information to the Bank of Spain for prudential supervision, risk monitoring and the Central Credit Register. Under the Law on Financial System Reform Measures, credit institutions must provide relevant exposure and borrower information to the Central Credit Register. This supports assessment of credit risk and systemic risk.

For payment services, Royal Decree-Law 19/2018, implementing PSD2 in Spain, requires banks to share account-access and payment information with authorised third-party providers when the customer gives explicit consent. Banks must verify that the provider is authorised and must use secure communication methods. They cannot use data-sharing obligations as an excuse to expose more information than is necessary.

Key Data Sharing Obligations

A bank may have to share customer data with public authorities where a valid legal power exists. This can include courts, law-enforcement bodies, tax authorities, the Bank of Spain, SEPBLAC and other competent regulators. The request must remain within the authority’s legal powers. A broad, vague or excessive request may breach the GDPR principle of data minimisation.

Banks also share data with processors, such as cloud providers, IT vendors, payment processors, call centres and document-storage providers. In these cases, Article 28 GDPR requires a written data-processing agreement. The processor may only use the data on the bank’s documented instructions and must apply confidentiality and security measures.

Sharing within a banking group also requires care. A parent company, insurer, investment affiliate or overseas branch is not automatically entitled to receive all customer information. The bank must identify the purpose, legal basis, categories of data, retention period and safeguards. Group convenience alone is not enough.

Where data is transferred outside the European Economic Area, the bank must comply with GDPR Chapter V. It may rely on an adequacy decision, standard contractual clauses or another limited transfer mechanism. After the Schrems II decision, banks must also assess whether the destination country provides effective protection in practice.

Customers’ Rights and Remedies

Spanish customers have the GDPR rights of access, rectification, erasure, restriction, objection and data portability. They may ask a bank to identify the recipients or categories of recipients that received their data. A general answer such as “our partners” may be insufficient.

Customers also have protection against solely automated decisions that significantly affect them, including some automated credit-scoring or fraud-screening decisions. A bank must provide meaningful information about the logic involved and offer appropriate human intervention where Article 22 GDPR applies.

Complaints can be made to the Spanish Data Protection Agency (AEPD). The AEPD may investigate, order corrective measures and impose major administrative fines. Customers may also seek compensation for material or non-material damage before Spanish courts.

Case Laws

1. Constitutional Court of Spain, STC 292/2000: The Court recognised the constitutional right to personal data protection as a power of individuals to control the use of their personal information. This principle limits unjustified financial-data sharing.

2. CJEU, C-311/18, Data Protection Commissioner v Facebook Ireland and Schrems: The Court held that international transfers require real protection equivalent to EU standards. Spanish banks transferring customer data to non-EEA service providers must assess local surveillance risks and add safeguards where needed.

3. CJEU, C-184/20, Vyriausioji tarnybinės etikos komisija: The Court stressed data minimisation and held that information capable of revealing sensitive personal circumstances deserves strong protection. Banks should therefore avoid over-sharing transaction or customer-profile data.

4. CJEU, C-154/21, RW v Österreichische Post: The Court ruled that a data subject can request the identity of actual recipients of personal data, not only broad categories. This is highly relevant where a bank shares data with affiliates, processors or credit-reference entities.

5. CJEU, C-634/21, SCHUFA Holding: The Court held that automated scoring may fall within GDPR Article 22 where it plays a decisive role in lending decisions. Spanish banks must not rely blindly on automated credit information without proper safeguards.

6. CJEU, C-300/21, UI v Österreichische Post: The Court confirmed that a GDPR breach alone does not automatically create compensation, but non-material harm can be recoverable when actual damage is shown. Improper banking-data disclosure may therefore create civil liability.

7. CJEU, C-487/21, F.F. v Österreichische Datenschutzbehörde: The Court explained that the right of access must enable a person to understand and verify the lawfulness of processing. Banks must give meaningful information when customers ask how and with whom their data has been shared.

Conclusion

Spanish banks must share data in several legally required situations, particularly for supervision, AML compliance, taxation, court proceedings, credit-risk reporting and customer-authorised payment services. Yet every disclosure must comply with purpose limitation, minimisation, security, transparency and accountability.

The safest approach is for banks to maintain a documented data-sharing framework: identify the legal basis, limit the data, verify the recipient, use contractual safeguards, keep an audit trail and provide customers with clear privacy information. Data sharing is a regulatory duty in some contexts, but it is never a licence for unrestricted use of customer information.

LEAVE A COMMENT