Banking Law And Digital Identity Fraud Offenses Spain .
Banking Law and Digital Identity Fraud Offenses in Spain
Introduction
Digital identity fraud is a major risk for Spanish banks, payment institutions, fintech firms and their customers. It occurs when an offender unlawfully obtains, creates, manipulates or uses another person’s identifying information to open accounts, obtain credit, access online banking, authorise payments, receive benefits or conceal the real origin of funds.
The fraud may involve stolen identity documents, phishing, SIM swapping, malware, deepfake voice or video, compromised electronic certificates, forged electronic signatures and synthetic identities created from a mixture of real and false data. Spanish law does not treat every form of identity misuse as one separate offence. Instead, liability depends on the conduct: computer fraud, unlawful access, document forgery, usurpation of civil status, misuse of payment instruments, data-protection violations, money laundering or participation in an organised criminal group.
Legal and Regulatory Framework
The Spanish Penal Code is the central criminal-law instrument. Article 248 covers fraud, including computer fraud committed by manipulating data, software, systems or electronic payment instruments in order to obtain an unlawful economic benefit. This provision can apply where an offender uses stolen credentials to transfer funds, changes payment instructions or causes an automated system to make a payment.
Article 401 criminalises usurpation of civil status. In banking matters, it may apply where a person presents themselves as another individual in a legally meaningful and continuing way, such as opening an account, signing a credit agreement or exercising rights in that person’s name. Mere use of another person’s name online may not always satisfy the offence; courts examine whether the impersonation affected legally relevant rights, duties or relationships.
Articles 197 and following protect the secrecy of communications and personal data. Unauthorised access to banking systems, extraction of customer files, interception of authentication codes and disclosure of confidential data may create criminal liability. Article 197 bis is particularly relevant to unlawful access to information systems. The Cybercrime framework also addresses the production, possession or supply of tools intended for committing computer offences.
Forgery provisions may apply where identity documents, bank records, electronic certificates, payment instructions or digital signatures are fabricated or altered. Where fraud concerns cards, payment tokens or comparable instruments, the Penal Code contains specific offences relating to counterfeit or unlawfully used payment means.
Banking Duties and Customer Identification
Spanish credit institutions must comply with Law 10/2010 on the prevention of money laundering and terrorist financing. Customer due diligence requires institutions to identify and verify the customer, identify beneficial owners, understand the purpose of the relationship and monitor transactions. Digital onboarding is permitted, but it must be reliable and proportionate to the risk.
Banks should use layered identity controls. These may include document verification, live facial checks, electronic-signature validation, device intelligence, address confirmation, sanctions screening, account-behaviour monitoring and independent verification of source-of-funds information. A single uploaded image of an identity document is usually insufficient for higher-risk products.
The EU eIDAS framework and Spain’s Law 6/2020 on certain aspects of electronic trust services support the legal use of electronic signatures, seals, timestamps and certificates. A qualified electronic signature generally has the legal effect of a handwritten signature. However, the existence of a valid signature does not automatically prove that the genuine customer personally acted; coercion, credential theft, device compromise and false enrolment may still be alleged.
The General Data Protection Regulation and Spain’s Organic Law 3/2018 also apply. Banks may process identity and biometric information only when they have a lawful basis, comply with data-minimisation requirements and protect the information through appropriate technical and organisational measures. Fraud prevention is a legitimate objective, but it does not justify unlimited collection or indefinite retention of customer data.
Investigation and Evidence
When identity fraud is suspected, a bank should preserve evidence without delay. Relevant materials include account-opening recordings, identity-document copies, electronic-signature certificates, IP addresses, device identifiers, geolocation indicators, login histories, one-time-password records, transaction logs, call recordings and communications with receiving banks.
The institution should separate internal suspicion from proven wrongdoing. Blocking a transaction or account may be justified where there is a serious fraud or AML concern, but the bank should document the reason, notify the customer where legally appropriate and preserve the possibility of review. Incorrectly freezing an account can expose a bank to contractual and reputational claims.
Digital evidence must be authentic, complete and traceable. Screenshots alone are vulnerable to challenge. Stronger evidence includes original system records, tamper-resistant logs, timestamps, expert reports and a clear chain of custody. In serious cases, banks should cooperate with police, prosecutors, SEPBLAC and competent judicial authorities.
Rights and Remedies
A victim may report the offence to the police or Public Prosecutor, seek recovery of diverted funds and claim civil damages within criminal proceedings or separately. Customers may also complain to the bank and, where relevant, to Banco de España. If a bank failed to apply reasonable security measures or ignored clear warning signs, it may face civil liability.
Customers have duties as well. Sharing passwords, one-time codes, security tokens or identity documents through unverified channels can affect the assessment of negligence. Nevertheless, a bank cannot simply rely on standard terms to place every loss on the customer; it must show that its authentication and monitoring systems were reasonably secure.
Case Laws
Spanish Supreme Court case law on Article 401 distinguishes true usurpation of civil status from casual or isolated use of another person’s name. Liability is stronger where impersonation is sustained and used to obtain legally significant rights or benefits.
Spanish Supreme Court case law on computer fraud under Article 248 recognises that manipulation of electronic systems and misuse of payment credentials can amount to fraud when it produces an unlawful transfer of value.
Spanish Supreme Court case law on electronic evidence requires courts to assess authenticity, integrity and attribution carefully, particularly for messages, screenshots and online communications that can be altered or fabricated.
Google Spain v AEPD and Mario Costeja González (C-131/12) established important data-protection principles concerning personal information and online search results. Its reasoning matters where fraud victims seek removal of identity-related material from search services.
Planet49 (C-673/17) confirmed that consent for data processing must be active and informed. Banks cannot rely on vague or pre-ticked consent to justify broad profiling or identity-data sharing.
Schrems II, Data Protection Commissioner v Facebook Ireland (C-311/18) required effective safeguards for international data transfers. Spanish banks using foreign identity-verification or cloud providers must ensure adequate protection of customer identity data.
SCHUFA Holding (C-634/21) addressed automated decision-making and credit scoring under GDPR. It is relevant where a bank’s automated fraud or identity-risk system has a decisive effect on a customer’s access to credit or account services.
Conclusion
Spain addresses digital identity fraud through a combined system of criminal law, AML duties, electronic-trust rules, data protection and banking supervision. The key legal challenge is balancing secure identity verification with fair customer treatment and privacy. Banks must use reliable authentication, preserve strong digital evidence and investigate fraud carefully. Customers, in turn, should protect credentials and report suspicious activity immediately. Effective prevention depends on technology, but legal accountability remains with the institution that relies on that technology.

comments