Banking Law And Eidas Digital Identity Spain .

Banking Law and eIDAS Digital Identity in Spain

Introduction

Digital identity has become essential to Spanish banking. Banks use electronic identification when customers open accounts remotely, sign loan agreements, authorise payments, access mobile banking or complete anti-money-laundering checks. The legal framework must ensure that a person acting online can be identified reliably while protecting personal data and preventing impersonation, fraud and unauthorised transactions.

Spain applies the European Union’s eIDAS framework, which establishes common rules for electronic identification and trust services. The original eIDAS Regulation has been amended by Regulation (EU) 2024/1183, commonly called eIDAS 2.0, which creates the European Digital Identity Framework and the European Digital Identity Wallet.

Legal and Regulatory Framework

Regulation (EU) No. 910/2014 governs electronic identification, electronic signatures, electronic seals, timestamps, electronic delivery services and website-authentication certificates. It requires Member States to recognise notified electronic-identification systems from other Member States where the applicable conditions are satisfied.

Spain supplements eIDAS through Law 6/2020 regulating certain aspects of electronic trust services. Spanish legislation addresses the supervision of trust-service providers, qualified certificates, identification of certificate holders, termination of services and liability for non-compliance.

Electronic signatures are divided into three levels. A simple electronic signature may include a typed name, scanned signature or acceptance button. An advanced electronic signature must be uniquely linked to the signer, identify that person, remain under the signer’s control and reveal later alteration. A qualified electronic signature is an advanced signature created by a qualified device and based on a qualified certificate. It has the same legal effect as a handwritten signature throughout the European Union.

Banks must also comply with the General Data Protection Regulation and Spanish Organic Law 3/2018. Identity documents, facial images, behavioural information and biometric templates constitute personal data. Biometric information used to identify a person uniquely is special-category data and requires a valid legal basis, necessity, proportionality and strong security controls.

The Payment Services Directive framework, implemented principally through Royal Decree-Law 19/2018, requires strong customer authentication for many electronic payments. Authentication ordinarily combines two or more independent elements based on knowledge, possession and inherence. eIDAS identification may support this process, but it does not automatically prove that every payment was properly authorised.

European Digital Identity Wallet

Under eIDAS 2.0, Member States must provide European Digital Identity Wallets according to the implementation timetable established by EU law. The wallet will allow individuals to identify themselves, store digital credentials and disclose verified attributes, such as age or professional status.

Spanish banks may use wallets for customer onboarding, access authentication and the presentation of verified identity attributes. However, a bank remains responsible for customer due diligence under Law 10/2010 on preventing money laundering and terrorist financing. Possession of a wallet cannot replace risk-based examination where beneficial ownership, sanctions exposure, unusual transactions or document fraud creates additional concern.

Banks acting as relying parties must request only information necessary for the relevant service. They should not demand a complete identity profile where confirmation of a limited attribute would be sufficient. Consent must be specific and freely given where it is relied upon, while legally mandatory AML processing should not be inaccurately presented as optional consent.

Rights, Liability and Banking Risks

A customer may challenge an electronically signed banking contract by alleging identity theft, compromised credentials, defective certificates, lack of consent or manipulation of the document. The bank must preserve evidence showing the authentication method, certificate status, timestamp, transaction data and integrity of the signed document.

An electronic signature cannot be rejected merely because it is electronic or because it is not qualified. Nevertheless, only a qualified electronic signature receives automatic equivalence to a handwritten signature. Other signatures remain admissible evidence, but their reliability must be assessed from the surrounding facts.

Banks must maintain incident-response systems for stolen devices, compromised certificates and fraudulent wallet use. Liability may arise under payment-services law, data-protection law, contract law or the eIDAS rules, depending on whether the failure originated with the bank, customer, wallet provider or trust-service provider.

Relevant Case Laws

1. Ekofrukt EOOD, Case C-362/21

The Court of Justice held that national courts must examine whether an electronic signature satisfies eIDAS requirements and cannot treat technical labels as conclusive. The decision supports evidence-based assessment of disputed banking signatures.

2. V.B. Trade OOD, Case C-466/22

The Court clarified the conditions for recognising qualified electronic signatures. It demonstrates that validity depends on compliance with eIDAS requirements, including the qualified certificate and creation mechanism.

3. Lahorgue, Case C-99/16

The Court considered access to an electronic judicial network through secure identification equipment. It recognised that digital-access requirements must be proportionate and must not create unjustified barriers.

4. Landeshauptstadt Wiesbaden, Case C-61/22

This case examined fingerprints stored in identity cards. The Court emphasised that biometric identification must have a valid legal basis and comply with necessity, proportionality and data-protection safeguards.

5. Digital Rights Ireland, Joined Cases C-293/12 and C-594/12

The Court invalidated indiscriminate data-retention requirements. Its reasoning is relevant where banks retain extensive identity and authentication data without adequate limits or safeguards.

6. Ministerio Fiscal, Case C-207/16

The Court examined public-authority access to electronic identification and communications data. It confirmed that access must correspond to a legitimate objective and remain proportionate.

7. Spanish Constitutional Court Judgment 55/2019

The Court reviewed important provisions of Spain’s administrative-procedure legislation concerning electronic administration. It affirmed that digital transformation must operate within constitutional rules governing competence, legality and citizens’ rights.

8. Spanish Constitutional Court Judgment 6/2019

The Court addressed defective electronic communication in judicial proceedings. It stressed that technology cannot be applied formalistically where doing so causes genuine denial of effective judicial protection.

Conclusion

eIDAS provides Spanish banking with a legally recognised structure for electronic identity, signatures and trust services. eIDAS 2.0 extends that structure through interoperable digital wallets and verified electronic attributes. However, digital identity does not eliminate banks’ duties concerning AML verification, payment authentication, privacy and fraud prevention.

Spanish banks should use proportionate identification methods, minimise requested data, preserve reliable audit evidence and provide effective procedures for challenging impersonation or unauthorised transactions. The central legal principle is that technological convenience must remain compatible with security, informed customer control, data protection and access to an effective remedy.

 

LEAVE A COMMENT