Banking Law And Digital Infrastructure Resilience Spain .
Banking Law And Digital Infrastructure Resilience Spain
Introduction
Digital infrastructure resilience means the ability of banks and financial institutions to prevent, withstand, respond to, and recover from failures affecting information technology, payment systems, cloud services, telecommunications, data centres, cybersecurity, and digital applications.
Spanish banks depend on interconnected digital infrastructure for account access, card payments, instant transfers, securities settlement, credit decisions, anti-money-laundering monitoring, and customer communication. A failure at one bank or technology provider can therefore affect the wider financial system.
Spain’s resilience framework is mainly based on European Union rules, particularly the Digital Operational Resilience Act (DORA), Spanish banking supervision, cybersecurity law, data-protection law, payment-services regulation, and corporate-governance duties. The Banco de España, the European Central Bank, the European Banking Authority, and other competent authorities share supervisory responsibilities.
1. Legal And Regulatory Framework
Digital Operational Resilience Act
DORA creates a common EU framework for digital operational resilience in financial services. It applies to banks, investment firms, payment institutions, electronic-money institutions, insurance companies, certain crypto-asset providers, and critical information and communication technology providers.
Its principal requirements include:
Information and communication technology risk-management systems;
Incident classification and regulatory reporting;
Operational-resilience testing;
Threat-led penetration testing for relevant institutions;
Management of ICT third-party and cloud risk;
Contractual requirements for technology suppliers;
Business-continuity and recovery arrangements; and
Oversight of critical third-party technology providers.
For Spanish banks, DORA operates alongside prudential supervision. Compliance is not limited to the information-technology department. Boards and senior management remain responsible for approving risk appetite, allocating resources, reviewing incidents, and ensuring that resilience weaknesses are corrected.
Spanish Cybersecurity And Banking Supervision
Spanish banks must also comply with national cybersecurity, electronic-services, data-protection, payment-services, and financial-sector rules. The Banco de España can require corrective measures, information, inspections, and improvements in internal controls.
Where a digital incident could threaten payment continuity or financial stability, the bank may need to notify the relevant authority, coordinate with law-enforcement bodies, and communicate with customers and counterparties.
2. Main Resilience Obligations
Risk Identification And Prevention
Banks must map important business services and identify the systems supporting them. These may include:
Mobile and online banking;
Card and ATM networks;
Instant-payment systems;
Customer authentication;
Treasury and liquidity systems;
Anti-money-laundering controls;
Core banking applications;
Cloud-hosted databases; and
Outsourced customer-service platforms.
The bank should assess the effect of a disruption on customers, markets, liquidity, data integrity, and financial stability. Critical systems require stronger controls, redundancy, access management, encryption, monitoring, and tested recovery procedures.
Incident Management And Reporting
A bank must detect and classify incidents rapidly. The classification should consider operational impact, affected customers, duration, geographical scope, financial loss, data compromise, and possible systemic consequences.
Incident reporting should not be delayed because the bank is still investigating every detail. Initial notifications can be followed by updated reports. The bank must also preserve logs, transaction records, forensic evidence, and communications.
Testing And Recovery
Resilience testing may include vulnerability assessments, scenario analysis, penetration testing, disaster-recovery exercises, backup restoration, and crisis simulations involving senior management.
A recovery plan should identify:
Which services must be restored first;
Who has authority to suspend or restart systems;
How customers will access essential funds;
How transactions will be reconciled;
How alternative payment channels will operate; and
How the bank will communicate with the public.
An untested plan has limited legal and practical value.
3. Cloud And Third-Party Technology Risk
Spanish banks increasingly rely on cloud providers, software vendors, cybersecurity firms, payment processors, telecommunications companies, and digital-identity providers. DORA requires stronger oversight of these relationships.
A bank should not assume that outsourcing transfers legal responsibility. Contracts should cover:
Security standards;
Audit and inspection rights;
Access to data and systems;
Incident notification;
Business continuity;
Subcontracting;
Data location;
Assistance during investigations; and
Orderly termination and migration.
Concentration risk is particularly important. If many Spanish banks use the same cloud provider, one technical failure may have systemic consequences. Supervisors may therefore examine shared infrastructure and critical third-party providers.
4. Consumer Protection And Liability
A digital outage can prevent customers from accessing salaries, making mortgage payments, receiving benefits, or completing urgent transfers. Banks should provide alternative channels, clear notices, emergency support, and fair complaint procedures.
Where customers suffer losses, liability may depend on the cause of the incident, the payment contract, authentication records, negligence, and applicable payment-services rules. Banks may face claims for unauthorised transactions, incorrect balances, delayed payments, data breaches, or inadequate security.
Customer communications must be accurate and timely. Concealing a serious incident may increase regulatory penalties and civil liability.
5. Board Accountability And Comply Or Explain
DORA imposes binding duties. Banks cannot simply explain why they have chosen not to comply with mandatory ICT-risk requirements. However, some governance codes, supervisory expectations, and technical standards may operate through a “comply or explain” approach.
Boards should receive regular reports on:
Critical systems and recovery times;
Material incidents;
Cybersecurity weaknesses;
Cloud and outsourcing concentration;
Results of resilience testing;
Unresolved audit findings; and
Customer harm caused by disruptions.
Directors may face liability where they ignore serious warnings, fail to allocate adequate resources, or approve an obviously deficient risk framework.
6. Case Laws
Direct Spanish judgments specifically applying DORA are still limited. The following cases are relevant through privacy, banking accountability, consumer protection, and digital-risk principles.
1. Digital Rights Ireland, Court of Justice of the European Union (2014)
Facts: EU rules required broad retention of communications data.
Legal Issue: Whether extensive data retention was compatible with privacy rights.
Principle: Digital-security measures must be necessary, proportionate, and protected by safeguards.
Importance: Resilience controls must not become unlimited surveillance of Spanish banking customers.
2. Schrems II, Court of Justice of the European Union (2020)
Facts: Personal data was transferred to service providers outside the European Union.
Legal Issue: Whether international transfers ensured adequate protection.
Principle: Cross-border data processing requires effective safeguards and enforceable rights.
Importance: Banks using global cloud and cybersecurity providers must control data access and transfer risks.
3. Wirtschaftsakademie, Court of Justice of the European Union (2018)
Facts: A business used an online page that processed visitor data.
Legal Issue: Whether multiple organisations could share responsibility for data processing.
Principle: Entities that influence the purposes and means of processing may be joint controllers.
Importance: Banks and outsourced technology providers may share responsibility for digital infrastructure failures and data misuse.
4. Google Spain v AEPD, Court of Justice of the European Union (2014)
Facts: An individual sought removal of search results containing personal information.
Legal Issue: The responsibility of digital intermediaries for personal-data processing.
Principle: Digital operators may have direct legal duties concerning personal information.
Importance: Banks cannot avoid accountability by claiming that a technology supplier operates the relevant digital system.
5. UI v Österreichische Post, Court of Justice of the European Union (2023)
Facts: An individual sought compensation for unlawful data processing.
Legal Issue: Whether every GDPR infringement automatically creates a damages claim.
Principle: Compensation requires an infringement, damage, and a causal connection.
Importance: Customers affected by a cyber incident may claim compensation where they prove financial, privacy, or other legally recognised harm.
6. Bankia Preferred-Shares And IPO Litigation, Spanish Supreme Court
Facts: Investors claimed that banking information and risk disclosures were inaccurate or incomplete.
Legal Issue: Whether financial institutions could be liable for misleading information provided to customers and investors.
Principle: Banks must provide accurate, reliable, and sufficiently clear information.
Importance: The same principle supports liability where a bank misrepresents digital-security standards, system reliability, or the safety of an online financial service.
Conclusion
Digital infrastructure resilience is now a core banking-law obligation in Spain. DORA requires banks to treat technology risk as a governance, supervisory, and financial-stability issue rather than merely an internal IT matter.
Spanish banks should map critical services, test recovery systems, control cloud providers, report incidents promptly, protect customer data, and maintain alternative payment channels. Resilience is legally effective only when it is supported by accountable boards, well-drafted outsourcing contracts, tested continuity plans, transparent customer communication, and meaningful remedies for losses caused by digital failures.

comments