Banking Law And E-Kyc Biometric Verification Spain .
Banking Law and E-KYC Biometric Verification in Spain
Introduction
Electronic Know Your Customer, or e-KYC, allows Spanish banks and financial institutions to identify customers remotely through digital documents, video identification, facial comparison, fingerprints, voice recognition or other biometric technologies. It supports online account opening, fraud prevention and compliance with anti-money-laundering obligations.
Biometric e-KYC creates significant legal risks because facial templates, fingerprints and similar identifiers are permanent characteristics that cannot be replaced like passwords. Spanish banks must therefore reconcile customer-identification duties with privacy, cybersecurity, equality and consumer-protection requirements. Biometric verification is not automatically lawful merely because it improves security or operational efficiency.
Legal and Regulatory Framework
The principal framework is Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing. It requires banks to identify customers, verify their identity from reliable sources, identify beneficial owners, understand the intended business relationship and conduct continuing monitoring.
Royal Decree 304/2014 develops these duties and permits non-face-to-face business relationships subject to approved identification procedures and appropriate safeguards. Applicable methods can include qualified electronic signatures, previously verified customer information, video-identification systems and other secure procedures authorised or accepted under the regulatory framework. SEPBLAC and the Bank of Spain supervise compliance within their respective responsibilities.
Regulation (EU) 2024/1624 will progressively harmonise customer-due-diligence requirements across the European Union. The eIDAS framework and the European Digital Identity system are also relevant where banks rely on electronic identification means, trust services or digital identity wallets.
Biometric processing is primarily governed by the General Data Protection Regulation and Organic Law 3/2018. Under Article 4(14) GDPR, biometric data result from specific technical processing of physical, physiological or behavioural characteristics that permit or confirm unique identification. Article 9 generally prohibits processing biometric data for uniquely identifying a person unless a recognised exception applies.
A bank needs both an Article 6 legal basis for ordinary personal-data processing and an Article 9 exception when special-category biometric data are involved. Compliance with a legal obligation may support identity verification generally, but it does not necessarily authorise every biometric technique. The bank must demonstrate that the particular biometric processing has a sufficiently precise legal basis or another valid Article 9 exception.
Key Legal Issues and Principles
Necessity and proportionality
Banks must determine whether biometric identification is genuinely necessary. A facial-comparison system may be defensible where remote impersonation creates substantial risk, but the institution should examine less intrusive alternatives, including qualified electronic identification, manual video review or in-person verification.
Convenience, cost reduction or faster onboarding will rarely justify highly intrusive biometric processing by themselves. The system must collect only the information needed for identification and must not reuse templates for marketing, behavioural analysis or unrelated profiling.
Consent and customer choice
Explicit consent may sometimes satisfy Article 9, but consent must be freely given, informed, specific and revocable. It is doubtful whether consent is voluntary where refusing facial recognition prevents a person from obtaining ordinary banking services and no equivalent alternative is available.
Banks should therefore provide a genuinely accessible non-biometric route where consent is relied upon. Withdrawing consent must not produce unjustified penalties, although the bank may still perform identification through another lawful method.
Data protection impact assessment
Biometric e-KYC normally presents a high risk to individual rights. Before deployment, the bank should conduct a data protection impact assessment under Article 35 GDPR. It must evaluate identity theft, template leakage, spoofing, function creep, discrimination, false rejections and risks affecting vulnerable customers.
Appropriate safeguards include encryption, restricted access, short retention periods, liveness detection, separation of identity records from biometric templates, human review and procedures for correcting erroneous matches.
Automated decisions and discrimination
Biometric systems may perform differently across age, sex, skin tone, disability or facial condition. If automated rejection prevents account opening, Article 22 GDPR may apply where the decision produces legal or similarly significant effects. Customers should receive meaningful information, an opportunity to contest the result and review by a competent person.
Enforcement and Remedies
The Spanish Data Protection Agency may investigate biometric processing and impose corrective measures, suspension orders and administrative fines. SEPBLAC may address deficient customer verification, while the Bank of Spain may examine governance and banking-conduct concerns.
Affected customers may request access, rectification, erasure or restriction where legally available, object to certain processing and complain to the AEPD. They may also claim compensation under Article 82 GDPR for material or non-material damage. AML retention duties can restrict immediate erasure, but retained information must not be used for incompatible purposes.
Case Laws
1. Spanish Constitutional Court Judgment 292/2000
The Court recognised data protection as an autonomous fundamental right giving individuals control over the collection, use and disclosure of personal information. This is the constitutional foundation for scrutiny of banking e-KYC systems.
2. Spanish Constitutional Court Judgment 76/2019
The Court invalidated legislation permitting broad collection of political-opinion data without adequate safeguards. It demonstrates that sensitive-data processing requires precise legal authority and cannot rest on vague public-interest claims.
3. Orange România, Case C-61/19
The CJEU held that consent must be active, informed and demonstrable. A pre-formulated document or customer signature does not prove freely given consent where the controller has not established genuine choice.
4. Meta Platforms v Bundeskartellamt, Case C-252/21
The CJEU confirmed that special-category processing and consent require strict examination. A dominant service provider cannot assume that acceptance of general terms establishes freely given consent.
5. Ministerstvo na vatreshnite raboti, Case C-205/21
The CJEU ruled that collection of biometric and genetic data must satisfy strict necessity. Indiscriminate biometric collection is incompatible with heightened protection where individual circumstances are not properly assessed.
6. SCHUFA Holding, Case C-634/21
The CJEU held that automated scoring can constitute an automated decision where a third party gives the score a determining role. The principle is relevant when biometric risk scores effectively decide whether a bank accepts a customer.
7. Ligue des droits humains, Case C-817/19
The CJEU required automated data analysis to observe necessity, proportionality, non-discrimination and effective human review. These principles guide algorithmic identity and fraud-screening systems.
Conclusion
Spanish banks may use biometric e-KYC only within a carefully documented AML and data-protection framework. They must establish a valid legal basis, prove necessity, minimise data, perform a risk assessment, secure biometric templates and provide human review. Where biometrics are optional, customers need a realistic alternative. Effective e-KYC therefore depends not only on accurate technology but also on proportionality, transparency and protection of fundamental rights.

comments