Banking Law And Embedded Finance Oversight Spain .

Banking Law and Embedded Finance Oversight in Spain

Introduction

Embedded finance describes the integration of financial services into the products or digital platforms of businesses whose primary activity is not traditionally banking. Examples include an online marketplace offering payments at checkout, a retailer providing instalment credit, a mobility application containing an electronic wallet, or a technology company integrating payment or account-information services into its platform.

Spain does not have a single statute called an “Embedded Finance Act.” Instead, embedded-finance arrangements are supervised according to the actual regulated financial activity being performed. A commercial platform cannot avoid banking or payment regulation merely because the financial service appears inside a non-financial application.

The principal framework includes Law 10/2014 on the organisation, supervision and solvency of credit institutions, Royal Decree-Law 19/2018 on payment services, Royal Decree 736/2019, Law 16/2011 on consumer credit, Law 10/2010 on prevention of money laundering and terrorist financing, EU prudential legislation, data-protection rules and the Digital Operational Resilience Act (DORA).

The Banco de España is particularly important. Persons wishing to provide banking, electronic-money, payment or other financial services falling within its supervisory competence generally require the appropriate authorisation or registration.

Regulatory Character of Embedded Finance

The fundamental regulatory principle is substance over technological presentation.

Suppose an online retailer places a payment facility inside its mobile application. The application interface may belong to the retailer, but the underlying payment transaction can still constitute a regulated payment service.

Similarly, if a platform provides customers with an electronic wallet containing redeemable monetary value, electronic-money rules may apply. If it grants credit, consumer-credit and potentially banking rules become relevant. If investment services are incorporated into the platform, securities regulation may apply.

Consequently, Spanish regulators normally examine who legally provides the service, who holds customer funds, who carries the financial risk and which entity has the contractual relationship with the customer.

Licensing and Authorisation

Embedded-finance businesses commonly operate through partnerships between technology companies and licensed banks, payment institutions or electronic-money institutions.

Under the Spanish payment-services framework, payment institutions providing regulated services require authorisation by the Banco de España, subject to specific exemptions and simplified arrangements established by law. Payment initiation and account-information services are also regulated activities.

Using a licensed bank behind a digital platform does not automatically make every activity of the technology company unregulated. The legal allocation of responsibilities must be examined carefully.

A platform that merely provides technology may be an outsourced service provider. A platform that itself performs a regulated function may require authorisation.

Banking-as-a-Service and Outsourcing

Banking-as-a-service is one of the principal structures supporting embedded finance.

A licensed institution may provide accounts, payments or other infrastructure that another company integrates into its customer-facing service.

However, outsourcing does not transfer the regulated institution's ultimate legal responsibility.

The Banco de España expressly provides that credit institutions may delegate functions to third parties only where delegation does not empty the regulated institution of its substantive activity, weaken its internal controls or prevent effective supervision. The institution continues to bear responsibility for complying with its regulatory obligations.

This principle is especially important for embedded finance because customers may interact almost entirely with the technology platform while the regulated financial service is legally supplied by a bank or payment institution.

Payment Services

Payments are one of the most common forms of embedded finance.

Spain implements the European payment-services framework principally through Royal Decree-Law 19/2018 and Royal Decree 736/2019. These rules address matters such as:

payment-service authorisation, safeguarding of customer funds, payment initiation, account-information services, authentication, execution of transactions, liability for unauthorised transactions and information supplied to customers.

The Banco de España supervises payment institutions, account-information providers, electronic-money institutions and other payment-service providers within its competence.

Therefore, placing the payment button inside an e-commerce platform does not remove the underlying payment transaction from regulatory oversight.

Consumer Protection

Embedded finance can make financial products extremely convenient. That convenience can also make the financial transaction less visible to consumers.

For example, a customer may perceive an instalment facility as merely another checkout option even though it creates a credit obligation.

Spanish and EU consumer law therefore requires appropriate transparency concerning matters such as interest, charges, repayment obligations and contractual consequences.

Digital presentation does not weaken the rules against unfair contractual terms.

The principle is particularly significant for embedded lending and “buy now, pay later” arrangements. Where the transaction legally constitutes regulated consumer credit, applicable creditworthiness, information and consumer-protection requirements must be observed.

Anti-Money-Laundering Controls

Embedded-finance arrangements can involve multiple entities: the customer-facing platform, technology provider, bank, payment institution and sometimes additional processors.

This creates potential uncertainty regarding customer identification and transaction monitoring.

Under Law 10/2010, regulated financial entities must apply measures concerning customer due diligence, beneficial ownership, transaction monitoring, record keeping and suspicious-transaction reporting.

Contracting technology companies does not permit a regulated financial institution to abandon responsibility for effective AML controls.

Operational and Technology Risk

Embedded finance depends heavily on APIs, cloud infrastructure, payment processors and outsourced technology.

Operational failure at a third-party provider can therefore interrupt financial services even where the bank itself remains operational.

DORA strengthens the EU framework for information and communications technology risk, incident management, resilience testing and oversight of important technology dependencies.

The Banco de España's current supervisory structure also includes powers relating to payment processors and providers of technological or technical services supporting payment arrangements.

Relevant Case Laws

1. Banco Español de Crédito SA v Joaquín Calderón Camino, C-618/10

This Spanish reference concerned a consumer loan containing a very high default-interest provision.

The Court of Justice held that national courts must provide effective protection against unfair consumer contractual terms and cannot simply rewrite an unfair provision to make it acceptable.

The principle applies directly to embedded lending. A credit product does not escape unfair-terms controls merely because it is offered instantly through an application or checkout interface.

2. Aziz v Catalunyacaixa, C-415/11

This major Spanish banking case concerned unfair terms and mortgage enforcement.

The Court of Justice held that national procedures must provide effective protection where banking contractual provisions may be unfair.

For embedded finance, Aziz establishes the broader principle that technological convenience cannot displace substantive consumer protection.

3. ING-DiBa Direktbank Austria, C-191/17

The Court considered the meaning of a payment account under EU payment-services legislation.

It examined whether a savings account allowing transfers only through another reference account fell within that concept.

The judgment is important to embedded finance because legal classification depends on the actual functionality of a financial product rather than the commercial name attached to it.

4. DenizBank AG v Verein für Konsumenteninformation, C-287/19

This case involved the contactless NFC functionality of bank cards and provisions governing payment instruments, information requirements and changes to payment framework contracts.

The Court examined circumstances in which contactless functionality constituted a payment instrument and the regulatory treatment of low-value contactless transactions.

The judgment is especially relevant to embedded wallets and contactless payment systems because it demonstrates that innovative payment technology remains subject to payment-services law.

5. T-Mobile Austria, C-616/11

The case arose from a telecommunications company charging customers for using particular methods of payment.

The Court considered the meaning of a payment instrument under payment-services law and the regulatory ability to restrict payment-related charges.

It is highly relevant to embedded finance because the financial interaction occurred within the commercial relationship of a non-bank telecommunications company. This illustrates precisely how payment regulation can extend into non-financial business models.

6. Tecnoservice Int. v Poste Italiane, C-245/18

The dispute involved a credit transfer executed using an incorrect unique identifier supplied with the payment instruction.

The Court clarified the responsibility of payment-service providers when execution is based upon that identifier.

The case demonstrates why embedded payment systems must carefully allocate responsibility for payment instructions, identifiers and transaction execution across platforms and financial providers.

7. CRCAM, C-337/20

This case concerned liability for unauthorised payment transactions.

The Court interpreted the harmonised liability framework applicable to payment-service providers and payment-service users.

The case is relevant where payments originate through third-party applications because liability cannot simply be determined according to the technological interface through which the instruction was transmitted.

8. Spanish Supreme Court Judgment 571/2025, 9 April 2025

The Spanish Supreme Court considered transactions conducted using a customer's credentials and confirmed through a message sent to the customer's telephone.

The Court treated transactions disputed by the customer within the framework governing unauthorised payments and emphasised the payment-service provider's burden of proving proper authentication and the circumstances necessary to shift liability to the customer.

This judgment is especially significant for embedded-finance applications, where authentication may occur through several interconnected technological systems.

Supervisory Allocation of Responsibility

A central challenge of embedded finance is determining responsibility when several firms participate in one customer journey.

Consider a customer purchasing goods from a digital marketplace using embedded credit and an integrated payment wallet.

The marketplace may provide the interface.

A payment institution may execute the payment.

A bank may provide the credit.

A cloud company may provide infrastructure.

A specialist company may perform identity verification.

Nevertheless, regulated financial entities cannot simply distribute regulatory responsibility until nobody remains accountable.

The supervisory framework requires clear responsibility for licensing, safeguarding funds, consumer information, AML controls, authentication, outsourcing, cybersecurity and complaints.

Conclusion

Banking law and embedded-finance oversight in Spain are based on the principle that financial regulation follows the economic substance of the service rather than the appearance of the digital platform.

There is no single Spanish embedded-finance statute. Instead, the applicable framework is assembled from banking, payment-services, consumer-credit, AML, data-protection and operational-resilience legislation.

The Banco de España plays a central role in supervising banks, payment institutions and electronic-money institutions. Outsourcing and banking-as-a-service arrangements are permitted, but regulated institutions cannot outsource their ultimate legal responsibility.

The case law further demonstrates that payment protections and consumer rights remain applicable as financial services become increasingly digital and integrated into non-financial businesses. Cases such as Banco Español de Crédito, Aziz, ING-DiBa, DenizBank, T-Mobile Austria, Tecnoservice, CRCAM and Spanish Supreme Court Judgment 571/2025 collectively establish principles concerning transparency, payment classification, authentication, transaction liability and consumer protection.

Accordingly, successful embedded finance in Spain requires more than technological integration. It requires correct regulatory classification, appropriate authorisation, clear allocation of responsibility, effective outsourcing controls, secure payment architecture, consumer protection and continuous regulatory supervision.

LEAVE A COMMENT