Banking Law And Digital Identity In Aviation Spain .
Banking Law And Digital Identity In Aviation Spain
Introduction
Digital identity in Spanish aviation connects banking, passenger verification, airport security and electronic payments. Airlines and airports increasingly use online identity checks, passport authentication, biometric boarding, mobile applications, digital wallets and card-based payments. These systems can reduce fraud and improve passenger convenience, but they also create legal risks involving privacy, discrimination, cybersecurity, payment fraud and unauthorised use of personal data.
The Spanish framework is mainly based on EU law, Spanish data-protection legislation, electronic-identification rules, aviation regulations and banking supervision. The central legal question is whether an airline, airport or payment provider can reliably establish that a particular passenger authorised a booking, refund, charge, loyalty transaction or airport payment.
Legal And Regulatory Framework
The General Data Protection Regulation (GDPR) is the principal framework. Identity information such as a name, passport number, booking reference, payment history, device identifier or travel profile constitutes personal data. Facial images and biometric templates used to identify a passenger are special-category biometric data under Article 9 GDPR.
Processing must comply with lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. Airlines and airports must identify a lawful basis for processing. Contractual necessity may support identity verification for ticketing or payment, while legal obligation or public interest may support border control and aviation security. Consent must be genuine, specific, informed and freely withdrawable.
Spain’s Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights supplements the GDPR. The Spanish Data Protection Agency, AEPD, supervises private airlines, airport operators and payment-related data processing.
Regulation (EU) No. 910/2014, known as eIDAS, recognises electronic identification, electronic signatures, electronic seals, time stamps and trust services. It allows electronic documents and signatures to have legal effect where the required technical and legal conditions are satisfied. The revised European Digital Identity framework will further support digital wallets and cross-border identity verification.
The Spanish Civil Code and Commercial Code govern contractual obligations between passengers, airlines, airports, banks and payment intermediaries. The Payment Services Directive framework, implemented in Spain through Royal Decree-Law 19/2018, regulates payment accounts, card transactions, authentication, unauthorised payments, payment-initiation services and strong customer authentication.
Strong customer authentication normally requires two or more elements from knowledge, possession or inherence. For example, a passenger may confirm a flight payment through a password, a registered mobile device and a fingerprint. However, successful authentication does not always prove that the passenger intended or understood the transaction.
The Anti-Money Laundering Law 10/2010 is relevant where banks, payment institutions or financial intermediaries process aviation payments, refunds, travel-agent settlements or corporate aviation accounts. Customer identification, beneficial-owner checks, transaction monitoring and suspicious-transaction reporting may be required.
Aviation law adds another layer. Regulation (EC) No. 261/2004 protects passengers in cases of cancellation, long delay and denied boarding. Digital identity must not become a mechanism for unlawfully denying boarding, refusing refunds or making passenger remedies inaccessible.
Digital Identity In Aviation Payments
Digital identity is used in several aviation situations. A passenger may create an airline account, buy a ticket, store a payment card, request a refund, use a mobile boarding pass or enter an airport lounge. The airline must be able to link the transaction to the correct customer without collecting unnecessary information.
Biometric boarding requires special caution. One-to-one verification, where a passenger’s live image is compared with the photograph on a passport or identity document, is generally less intrusive than one-to-many identification, where the passenger is matched against a large database. Airlines should prefer the least intrusive system capable of achieving the security objective.
A passenger should normally have a non-biometric alternative. A person who refuses facial recognition should not automatically lose the right to travel if manual identity verification is reasonably available. The system must also address false matches, disability, ageing, facial injuries, religious coverings and unequal performance across demographic groups.
Banks and airlines must divide responsibilities clearly. The bank may process payment credentials, while the airline processes passenger and booking data. Where technology vendors provide identity verification, the airline or bank must control processor contracts, security measures, retention periods and international data transfers.
Key Legal Issues And Principles
The first principle is authentication integrity. Systems should record the identity method used, device information, time, transaction amount, payment beneficiary, risk alerts and customer confirmation.
The second principle is purpose limitation. Passport or biometric information collected for boarding should not automatically be reused for targeted advertising, credit profiling or unrelated loyalty analysis.
The third principle is payment liability. Under payment-services rules, a customer may be entitled to reimbursement for an unauthorised payment, subject to statutory exceptions such as fraud or serious negligence. A bank cannot rely only on the fact that a password or one-time code was used.
The fourth principle is transparency. Passengers must be told what information is collected, why it is needed, how long it is retained and with whom it is shared. Privacy notices must be understandable, especially when the passenger is under time pressure at an airport.
The fifth principle is human review. If an automated identity decision results in a cancelled booking, blocked account, refused refund or denied boarding, the passenger should have access to meaningful human intervention and a method of challenging the decision.
Case Laws
1. McDonagh v Ryanair Ltd, Case C-12/11, CJEU. The Court held that airlines must provide care to passengers affected by long flight cancellations even where extraordinary circumstances exist. Digital identity systems cannot be used to obstruct statutory passenger assistance.
2. Airhelp Ltd v SAS Scandinavian Airlines, Case C-28/20, CJEU. The Court interpreted passenger rights under Regulation 261/2004 in the context of airline strikes. The case confirms that airline payment, booking and identity systems must support effective compensation claims.
3. Sousa Rodríguez and Others v Air France, Case C-83/10, CJEU. The Court examined passenger compensation and contractual consequences of flight disruption. It supports the principle that airline systems must preserve accurate booking and payment records for the enforcement of passenger rights.
4. Schrems II, Case C-311/18, CJEU. The Court invalidated the EU–US Privacy Shield and required strong safeguards for international data transfers. Airlines, banks and identity vendors transferring passenger or payment data outside the European Economic Area must assess foreign-access risks and implement appropriate safeguards.
5. Google Spain SL v AEPD and Costeja González, Case C-131/12, CJEU. The Court recognised important principles concerning control over personal information and search-engine processing. The case demonstrates that digital identity data may remain legally significant even after it has been published or processed by another organisation.
6. Bodil Lindqvist, Case C-101/01, CJEU. The Court confirmed that information identifying a person on the internet constitutes processing of personal data. The principle applies to passenger profiles, online booking accounts, digital boarding credentials and payment-related identity information.
7. Planet49, Case C-673/17, CJEU. The Court held that consent must be active and informed; pre-ticked boxes are insufficient. Airlines cannot treat a passenger’s continued use of a booking website as blanket consent for biometric, marketing or tracking activities.
8. SCHUFA, Joined Cases C-26/22 and C-64/22, CJEU. The Court considered automated scoring and individual decision-making. The reasoning is relevant where banks or airlines use automated risk scores to block payments, refuse bookings or investigate suspected fraud.
Conclusion
Spain’s aviation identity framework is built on GDPR, eIDAS, payment-services law, anti-money-laundering rules, Spanish data-protection legislation and passenger-rights regulations. Digital identity can make aviation payments faster and safer, but it must not convert authentication into automatic proof of consent or allow biometric data to be used without strict necessity.
Airlines, airports and banks should apply strong authentication, data minimisation, privacy by design, secure vendor governance, human review and accessible non-biometric alternatives. The legally sound model is one that verifies identity for a specific purpose, records reliable evidence of payment authorisation and preserves the passenger’s right to privacy, refund, compensation and effective legal remedy.

comments