Banking Law And Eidas Regulation Financial Sector Spain .

Banking Law and the eIDAS Regulation in Spain

Introduction

The eIDAS framework establishes common European rules for electronic identification, electronic signatures and digital trust services. It is highly important to Spanish banks because customers increasingly open accounts, obtain loans, sign investment agreements and authorise transactions remotely.

The original framework was created by Regulation (EU) No 910/2014. It was substantially amended by Regulation (EU) 2024/1183, commonly called eIDAS 2.0, which introduced the European Digital Identity Wallet. For Spanish financial institutions, eIDAS operates alongside banking, consumer-protection, payment-services, anti-money-laundering, cybersecurity and data-protection laws.

Legal and Regulatory Framework

Regulation 910/2014 applies directly in Spain. Law 6/2020 on certain aspects of electronic trust services supplements it nationally and regulates matters such as trust-service providers, certificates, supervision and liability. Spain’s supervisory authority maintains the trusted list identifying qualified trust-service providers.

Article 25 of eIDAS establishes that an electronic signature cannot be denied legal effect or admissibility as evidence merely because it is electronic or is not qualified. However, only a qualified electronic signature automatically has the legal effect equivalent to a handwritten signature throughout the EU.

The framework recognises three principal levels:

A simple electronic signature may include clicking an acceptance box, typing a name or using a basic one-time password.

An advanced electronic signature must be uniquely linked to the signatory, identify that person, remain under the signatory’s control and reveal subsequent changes to the signed information.

A qualified electronic signature is an advanced signature created using a qualified device and supported by a qualified certificate issued by a qualified trust-service provider.

Banks must select a method proportionate to the legal and operational risk. A simple signature may be sufficient for low-risk instructions, while guarantees, significant credit agreements or transactions requiring strong evidence may justify an advanced or qualified signature.

Application to the Spanish Financial Sector

Remote customer identification: Banks may use electronic identification during digital onboarding, but eIDAS does not replace customer-due-diligence obligations under Law 10/2010. Institutions must still identify customers, verify beneficial ownership, understand the business relationship and apply enhanced measures where risk is higher.

Electronic banking contracts: Spanish contract law generally permits electronic formation of current-account, credit and investment contracts. Nevertheless, the institution must prove the customer’s identity, consent and access to pre-contractual information. A valid technical signature does not cure an unfair term or inadequate disclosure.

Electronic seals and timestamps: Banks can use electronic seals to establish the origin and integrity of automated statements, certificates and corporate documents. Qualified electronic timestamps provide strong evidence that particular electronic data existed at a stated time.

European Digital Identity Wallet: Under eIDAS 2.0, customers will be able to present verified identity attributes through an EU digital wallet. Spanish banks may use it for onboarding, authentication and controlled disclosure of information. The framework is designed to reduce unnecessary copying of complete identity documents and support selective disclosure.

Banks classified as relying parties must comply with registration, security, transparency and data-minimisation requirements. Where applicable under the amended framework, certain private relying parties providing services in regulated sectors may be required to accept the wallet at the user’s voluntary request.

Cybersecurity and operational resilience: Banks must combine eIDAS compliance with PSD2 authentication requirements, the Digital Operational Resilience Act and data-protection rules. A qualified signature proves attribution and document integrity, but it does not by itself show that a payment was properly authorised or that credentials were not obtained through fraud.

Rights, Liability and Evidence

Customers may challenge an electronic banking agreement by alleging identity theft, defective consent, manipulation or inadequate information. The bank should retain the signed document, certificate chain, timestamps, authentication logs, delivery records and evidence showing what information appeared before acceptance.

Qualified trust-service providers may incur liability where they intentionally or negligently fail to meet eIDAS obligations and cause damage. Banks may also remain liable under payment-services or consumer law even when authentication was technically successful. Contractual clauses cannot automatically transfer every phishing, impersonation or system-security risk to the customer.

GDPR principles apply to digital-identity information. Banks must establish a lawful basis, collect only necessary data, define retention periods and protect biometric or identity information with appropriate safeguards.

Case Laws

1. Ekofrukt EOOD, Case C-362/21

The Court of Justice held that electronic signatures cannot be denied legal effect merely because they are electronic or non-qualified. However, eIDAS does not require national law to give every non-qualified signature the same effect as a handwritten signature.

2. Bundesdruckerei, Case C-61/22

The Court examined the compulsory storage of fingerprints in identity cards. It confirmed that digital identification systems must respect necessity, proportionality and data-protection safeguards. The reasoning is relevant when banks process biometric identity credentials.

3. Orange România, Case C-61/19

The Court held that valid consent must be freely given, specific, informed and demonstrated by the controller. A customer should not be required to prove refusal of consent through unnecessarily burdensome procedures. This principle applies to bank onboarding and identity-document processing.

4. Planet49, Case C-673/17

The Court ruled that pre-selected consent mechanisms do not establish valid consent. For banks, electronic acceptance must result from an active and properly informed customer decision.

5. Schrems II, Case C-311/18

The Court invalidated the EU–US Privacy Shield and required effective protection when personal data is transferred internationally. Spanish banks and identity-service providers must assess safeguards when authentication data is processed outside the European Economic Area.

6. Digital Rights Ireland, Joined Cases C-293/12 and C-594/12

General and indiscriminate retention of communications data was found to interfere disproportionately with privacy rights. The judgment supports strict necessity and retention controls for extensive electronic-identification records.

7. Spanish Supreme Court Decision of 15 February 2011

The Supreme Court recognised the legal significance of a duly verified electronic signature in a document processed through notarial channels. The decision illustrates that reliable identification and verification can give electronic documents strong evidential value.

Conclusion

eIDAS provides Spanish banks with a harmonised foundation for secure digital contracting and identification. Its central principles are cross-border recognition, technological neutrality, proportionality and evidential reliability. Banks should not treat electronic signatures as purely technical tools. They must connect them with informed consent, AML verification, privacy, cybersecurity and consumer protection. eIDAS 2.0 and the European Digital Identity Wallet will further reshape onboarding and authentication, but responsibility for fair contracting and secure banking operations remains with the financial institution.

LEAVE A COMMENT