Banking Law And Data Studies Spain .
Banking Law and Data Studies in Spain
Introduction
“Data studies” in banking refers to the collection, analysis, modelling, sharing and retention of data for purposes such as credit-risk assessment, fraud detection, anti-money-laundering monitoring, customer segmentation, market research, product design, financial inclusion studies and regulatory reporting. In Spain, these activities are not governed by one separate “data studies” statute. Instead, banks must comply with the EU General Data Protection Regulation (GDPR), Spain’s Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), banking-sector rules, consumer-protection requirements and supervisory expectations.
Banks hold highly sensitive information: account movements, salary records, borrowing history, card use, transaction locations and behavioural patterns. A data study may therefore be commercially useful, but it cannot override a customer’s privacy, confidentiality, fairness or non-discrimination rights. Spanish banks must establish a lawful purpose, minimise the data used, secure it, explain significant automated decisions and maintain governance records.
Legal and Regulatory Framework
The GDPR is directly applicable in Spain. It requires every banking data study to have a lawful basis, such as performance of a contract, compliance with a legal obligation, legitimate interests or valid consent. Consent is particularly important where a bank uses data for optional marketing, external research or unrelated commercial analysis. It must be freely given, specific, informed and easy to withdraw.
The LOPDGDD supplements the GDPR in Spain. It regulates national enforcement mechanisms, sanctions and certain employment, digital-rights and data-processing issues. The Spanish Data Protection Agency (AEPD) is the principal privacy regulator and may investigate banks, order corrective steps and impose significant administrative fines.
Spanish banking legislation also matters. Law 10/2014 on the regulation, supervision and solvency of credit institutions requires sound governance and risk-management arrangements. Banks must ensure that the use of data for risk models, capital assessment and internal controls is reliable and properly supervised. Law 44/2002 on financial-system reform reinforces duties of confidentiality and the protection of financial customers.
Where data studies concern creditworthiness, consumer-credit rules are central. A lender must assess a borrower’s ability to repay before granting credit. However, a credit study cannot become opaque automated exclusion. If the customer is rejected, charged more, or placed in a disadvantageous category through an automated system, the bank must consider GDPR safeguards, including human intervention where Article 22 applies.
Key Issues and Principles
First, purpose limitation is essential. Data collected to operate an account cannot automatically be reused for unrelated marketing research, profiling or sale to commercial partners. A bank must identify the new purpose and confirm that it has a lawful basis.
Second, data minimisation requires the institution to use only data genuinely necessary for the study. A fraud model may need transaction patterns, but not necessarily a customer’s full identity, personal contacts or unrelated historic information. Pseudonymisation, aggregation and anonymisation should be used whenever possible. Truly anonymised data falls outside the GDPR, but pseudonymised data remains personal data.
Third, transparency is critical. Privacy notices must explain the categories of data used, purposes of profiling, retention periods, recipients and available rights. Vague statements such as “we use your data to improve services” may be insufficient where the bank conducts material behavioural analysis.
Fourth, automated decision-making creates special risk. Credit scoring, fraud blocks and algorithmic affordability assessments can have substantial effects on customers. A bank should validate model accuracy, test for bias, permit meaningful review by a competent person and give the customer useful information about the decision. It should not hide behind trade secrecy to provide an empty explanation.
Fifth, studies involving special-category data demand greater caution. Health, biometric, political, religious or similar data generally cannot be processed unless a strict GDPR exception applies. In ordinary retail banking, using such data for commercial studies will rarely be justified.
Finally, banks must respect data-subject rights: access, rectification, erasure where applicable, restriction, objection, portability and the right not to be subject to certain solely automated decisions. Regulatory-reporting, AML and prudential-retention duties may limit deletion, but the bank must explain the legal reason and retain the data only for the required period.
Enforcement and Institutional Oversight
The AEPD investigates privacy complaints and can issue fines, warnings, processing bans and orders to improve controls. The Bank of Spain supervises prudential governance, customer conduct and operational resilience. Depending on the activity, the National Securities Market Commission and competition authorities may also be relevant.
Banks should maintain a clear data-governance framework: a data inventory, approved purposes, retention schedule, access controls, vendor agreements, model-validation procedures, incident-response plan and documented data-protection impact assessment for high-risk profiling. A data protection officer should be involved early where a proposed study may materially affect customers.
Case Laws
SCHUFA Holding (C-634/21, CJEU): The Court held that automated credit scoring may amount to prohibited automated individual decision-making where lenders rely heavily on the score. Spanish banks using external or internal scores must ensure meaningful safeguards and avoid treating a score as unquestionable.
Dun & Bradstreet Austria (C-203/22, CJEU): A person affected by automated credit assessment must receive meaningful information about the logic used. This is highly relevant to banking credit studies and requires explanations that are understandable, not merely generic.
Meta Platforms (C-252/21, CJEU): The Court emphasised that a dominant undertaking cannot freely combine personal data from multiple services without a valid GDPR basis. Banks likewise cannot combine transaction, app, partner and browsing data simply because it is commercially valuable.
Österreichische Post (C-300/21, CJEU): GDPR compensation requires actual damage, but no minimum seriousness threshold applies. A bank’s unlawful profiling can therefore create civil-liability exposure where a customer proves material or non-material harm.
RW v Österreichische Post (C-154/21, CJEU): Data subjects may seek information about the actual recipients of their personal data, not merely broad categories. Banks must be able to identify vendors, affiliates or partners receiving study-related data.
Vyriausioji tarnybinės etikos komisija (C-184/20, CJEU): The Court confirmed that data can reveal sensitive information by inference, even if the sensitive fact is not directly collected. A banking model that infers health, religion or political views from spending patterns may therefore trigger stricter safeguards.
Conclusion
Data studies can improve banking services, compliance and risk control in Spain, but they must remain lawful, proportionate and explainable. The strongest compliance approach is to design studies around a defined purpose, minimal data, transparent customer communication, secure governance and human accountability. In modern banking, data quality is important, but lawful and fair use of that data is equally essential.

comments