Banking Law And Flight Data Governance Spain .
1. Legal framework in Spain
A. Spanish constitutional protection
The Spanish Constitution of 1978 provides the foundation for privacy and economic regulation.
Article 18.4 — Data protection
The Constitution requires the law to limit the use of information technology to protect honour, personal and family privacy, and the exercise of rights.
This is important because:
A bank account contains personal and financial information.
Airline booking records contain identity and travel information.
Both types of records can be used to identify individuals and their activities.
Article 38 — Freedom of enterprise
Recognizes freedom of enterprise within a market economy, subject to the legal framework.
Article 51 — Consumer protection
Requires public authorities to protect consumers' economic interests and provide information and education.
B. Main data protection legislation
| Law | Relevance |
|---|---|
| Spanish Constitution, Articles 18.4, 38 and 51 | Privacy, enterprise, and consumer protection |
| Organic Law 3/2018 (LOPDGDD) | Spanish implementation and development of data protection law |
| GDPR, Regulation (EU) 2016/679 | General personal data protection |
| Law 10/2010 | Prevention of money laundering and terrorist financing |
| Law 5/2019 | Real estate credit contracts |
| Law 16/2011 | Consumer credit contracts |
| Law 7/1996 and other consumer legislation | Consumer and commercial protections, where applicable |
| Law 48/1960 | Spanish Air Navigation Law |
| Law 21/2003 | Aviation safety and security framework |
| Law 1/2020 | Spanish implementation of the EU PNR Directive |
The exact scope of these laws depends on the activity. For example, a bank's anti-money-laundering duties are not identical to an airline's obligations to transmit passenger data to a national Passenger Information Unit.
PART I — BANKING LAW IN SPAIN
2. Meaning and scope of Spanish banking law
Banking law is the body of rules governing:
Establishment and licensing of banks.
Banking supervision and prudential regulation.
Deposit-taking and lending.
Payment services and electronic banking.
Customer rights and consumer protection.
Financial crime prevention.
Bank confidentiality and data protection.
Insolvency and resolution of banks.
In Spain, banking regulation operates at three levels:
European Union law
Banking directives, regulations, GDPR, EU banking supervision
Spanish legislation
Banking statutes, consumer credit, anti-money laundering, data protection
Supervisory authorities
Banco de España, ECB, CNMV, AEPD and other competent bodies
Principal banking authorities
1. Banco de España
The central bank of Spain. It supervises certain banking activities, payment institutions and credit institutions within its legal powers, and handles banking customer complaints through its complaints service.
2. European Central Bank (ECB)
Under the Single Supervisory Mechanism, the ECB directly supervises significant credit institutions and works with national supervisors.
3. CNMV
The Spanish securities market supervisor. It regulates and supervises investment services and securities markets.
4. AEPD
The Spanish Data Protection Agency. It supervises compliance with data protection law, including personal information processed by banks and airlines within its jurisdiction.
3. Bank customer information and confidentiality
What is bank secrecy?
Bank secrecy refers to the obligation of financial institutions to protect confidential customer information.
A bank may possess:
Account numbers and balances.
Transaction records.
Income and financial history.
Loan and mortgage details.
Payment card information.
Identification documents.
Information used for fraud prevention.
Spanish law does not make bank secrecy an absolute right. A bank may be legally required to disclose information to competent authorities.
Permitted disclosure
A bank may disclose information where there is a valid legal basis, such as:
Customer consent, where consent is the appropriate legal basis.
A legal obligation, including certain anti-money-laundering requirements.
A lawful request by a competent authority.
A court order.
A regulatory or supervisory requirement.
Other legally valid grounds under data protection law.
Example: If a Spanish bank receives a lawful request from a competent authority investigating money laundering, the bank may have a duty to provide the requested information. The request must still comply with applicable legal requirements.
GDPR principles relevant to banking
The GDPR establishes the following principles:
| Principle | Banking application |
|---|---|
| Lawfulness, fairness and transparency | Customers must be informed about relevant data processing |
| Purpose limitation | Data collected for one purpose should not be used incompatibly for another |
| Data minimisation | Only necessary data should be processed |
| Accuracy | Incorrect customer records should be corrected |
| Storage limitation | Data should not be retained longer than legally justified |
| Integrity and confidentiality | Banks must protect customer information |
| Accountability | Banks must be able to demonstrate compliance |
The legal basis for processing is particularly important. A bank cannot simply rely on a customer's general acceptance of its terms for every use of personal data.
4. Banking law and anti-money laundering
Law 10/2010
Spanish Law 10/2010, on the prevention of money laundering and terrorist financing, imposes duties on banks and other obliged entities.
These include:
Customer due diligence.
Identification and verification of customers.
Identification of beneficial owners.
Monitoring transactions.
Reporting suspicious activity.
Recordkeeping.
Internal controls and compliance procedures.
Why this matters for data governance
A bank must balance two obligations:
Customer privacy — protect personal information.
Legal compliance — retain and disclose information when required by anti-money-laundering legislation.
These duties may coexist. Data protection law does not automatically prevent lawful anti-money-laundering processing.
However, banks must still comply with requirements such as necessity, proportionality, security, and appropriate access controls.
5. Six major case laws relevant to banking and data governance
The following cases are important European and Spanish legal authorities. They include banking and consumer-credit cases, constitutional data protection, and major cases governing the use of personal information by public authorities.
Case 1 — Banco Español de Crédito v Joaquín Calderón Camino
CJEU
C-618/10
Banco Español de Crédito v Calderón Camino
Judgment: 14 June 2012
Area: Banking contracts and consumer protection
Facts
Banco Español de Crédito brought proceedings concerning an unpaid consumer credit debt. The Spanish legal procedure allowed a court to issue a payment order, and the question arose whether an unfair contractual term could be left unexamined by the court.
Legal issue
Can a Spanish court enforce a consumer contract without examining whether its terms are unfair under EU consumer protection law?
Judgment
The Court of Justice held that national procedural rules must not make it excessively difficult to enforce consumer rights under EU law.
In particular, courts must be able to examine unfair terms in consumer contracts, including where necessary on their own initiative.
Importance for banking law
The case establishes that:
Consumer credit contracts are subject to EU consumer protection.
Banks cannot rely on procedural mechanisms to bypass legal protections.
National courts have an important role in reviewing unfair contract terms.
Application in Spain
Spanish courts must apply EU consumer protection requirements when dealing with consumer banking and credit agreements.
Legal principle: Consumer protection can limit the enforcement of banking contract terms.
Case 2 — Aziz v Caixa d'Estalvis de Catalunya
CJEU
C-415/11
Mohamed Aziz v Caixa d'Estalvis de Catalunya
Judgment: 14 March 2013
Area: Spanish mortgage law and unfair terms
Facts
Mohamed Aziz entered into a mortgage loan agreement with Caixa d'Estalvis de Catalunya. Following default, mortgage enforcement proceedings were brought. Mr Aziz argued that certain contractual terms were unfair.
Legal issue
Did Spanish mortgage enforcement procedures provide sufficient protection for consumers where the mortgage contract contained potentially unfair terms?
Judgment
The CJEU held that the Spanish procedural framework could be incompatible with EU consumer protection rules because it made it difficult for a court to suspend mortgage enforcement while unfair terms were examined.
Importance
This case is important because it demonstrates:
Consumer rights apply to mortgage contracts.
Banking enforcement procedures must respect EU consumer protection.
Courts must have effective means to assess unfair contractual terms.
National procedural rules cannot undermine substantive consumer rights.
Banking law significance
A mortgage is a banking product. Its enforcement is not only a matter of contract law; it is also subject to consumer protection obligations.
Legal principle: Banking enforcement procedures must provide effective protection against unfair contract terms.
Case 3 — STC 292/2000, Spanish Constitutional Court
Spain
STC 292/2000
Spanish Constitutional Court Judgment 292/2000
Judgment: 30 November 2000
Area: Fundamental right to personal data protection
Legal issue
What is the scope of the constitutional right to personal data protection under Article 18.4 of the Spanish Constitution?
Judgment
The Constitutional Court recognized personal data protection as an autonomous fundamental right. It is not merely a part of general privacy.
The right gives individuals powers over their personal information, including the ability to control the collection and use of personal data.
Importance for banks
Banks process extensive information about customers. This judgment supports the principle that:
Financial data is personal data.
Individuals have rights over their personal information.
Public authorities and private entities must respect constitutional data protection.
Data processing must have an adequate legal basis and safeguards.
Banking application
If a bank collects customer data, it must comply with applicable data protection rules. A bank's commercial interest does not automatically override the customer's fundamental rights.
Legal principle: Personal data protection is an independent fundamental right under the Spanish Constitution.
Case 4 — Digital Rights Ireland Ltd and Seitlinger
CJEU
Joined Cases C-293/12 and C-594/12
Digital Rights Ireland
Judgment: 8 April 2014
Area: Data retention and fundamental rights
Facts
The cases challenged the EU Data Retention Directive, which required certain communications data to be retained for the purpose of investigating serious crime.
Legal issue
Did the broad retention of communications data comply with fundamental rights to privacy and data protection?
Judgment
The CJEU invalidated the Data Retention Directive because the general and indiscriminate retention of data constituted a serious interference with fundamental rights and lacked sufficient limitations and safeguards.
Importance for banking and flight data
Although the case did not concern bank accounts or airline bookings directly, it is important for data governance because it explains that:
Large-scale data retention interferes with privacy.
Data collection must be limited to what is necessary.
Retention periods must be justified.
Access to data must be subject to safeguards.
Security and oversight are important.
Banking example: A bank may be required to retain transaction records under anti-money-laundering law. That does not mean it may retain every item of personal information indefinitely without a legal purpose.
Legal principle: Data retention must comply with necessity, proportionality, and fundamental rights.
Case 5 — Schrems II
CJEU
C-311/18
Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
Judgment: 16 July 2020
Area: International data transfers
Facts
Maximillian Schrems challenged the transfer of personal data from the European Union to the United States by Facebook Ireland.
Legal issue
Could EU personal data be transferred to a third country under the EU-US Privacy Shield, and what safeguards were required for transfers under standard contractual clauses?
Judgment
The CJEU invalidated the EU-US Privacy Shield decision. It held that standard contractual clauses could remain valid, but data exporters and importers must assess whether the destination country provides adequate protection and use supplementary safeguards where necessary.
Importance for Spanish banking law
Spanish banks often use international service providers for:
Cloud storage.
Customer relationship management.
Payment processing.
Fraud detection.
IT support.
Cybersecurity services.
If personal data is transferred outside the EEA, the bank must comply with GDPR Chapter V.
Importance for airlines
Airlines and reservation systems may use international data processors. The same rules apply to transfers of passenger data.
Legal principle: International transfers of personal data require legally adequate safeguards.
PART II — FLIGHT DATA GOVERNANCE IN SPAIN
6. Meaning of flight data governance
Flight data governance is the legal and organisational framework controlling the collection, processing, sharing, storage, and deletion of data relating to flights and passengers.
It includes:
Passenger Name Records (PNR).
Advance Passenger Information (API).
Passenger identity records.
Booking and reservation information.
Travel itinerary.
Ticket and payment information.
Baggage information.
Flight manifests.
Airline operational information.
Aviation security data.
Data shared with border and law enforcement authorities.
Difference between PNR and API
| Feature | PNR | API |
|---|---|---|
| Full name | Usually included | Included |
| Travel document details | May be included | Included |
| Booking reference | Included | Not necessarily |
| Flight itinerary | Included | Included |
| Payment details | May be included | Generally not part of core API |
| Purpose | Booking, travel and security uses | Border control and passenger identification |
| Source | Airline reservation system | Passenger travel document/check-in data |
Important: PNR and API are different datasets, although they may overlap.
7. Legal framework for flight data in Spain
A. EU PNR Directive — Directive (EU) 2016/681
The EU PNR Directive regulates the use of Passenger Name Record data for the prevention, detection, investigation, and prosecution of terrorist offences and serious crime.
It governs the transfer of certain PNR data by air carriers to Passenger Information Units.
B. Spanish implementation
Spain implemented the EU PNR framework through Law 1/2020, of 16 September, on the use of Passenger Name Record data for the prevention, detection, investigation, and prosecution of terrorist offences and serious crime.
The framework includes the Spanish Passenger Information Unit (PIU), associated with the Ministry of the Interior.
C. GDPR and law enforcement data
Flight data governance can involve two different legal regimes:
| Processing context | Applicable framework |
|---|---|
| Airline commercial booking and customer services | GDPR and Spanish data protection law |
| Processing for aviation security and serious crime prevention | PNR rules and applicable law enforcement data protection framework |
| Border control and immigration | Applicable EU and Spanish border-control laws |
| International data transfers | GDPR Chapter V or other applicable transfer rules |
Not every processing operation is governed by exactly the same legal instrument.
8. What information can be contained in PNR data?
PNR data may include booking and travel information such as:
Passenger name.
Contact details.
Travel itinerary.
Ticket information.
Travel agent information.
Seat number.
Baggage information.
Payment and billing information where collected in the PNR.
Information about accompanying passengers.
Special service requests where included in the record.
Sensitive data concern
PNR records can reveal information about a person's travel patterns, associations, and potentially sensitive personal circumstances.
For example, a travel record may reveal:
A person's repeated travel to a particular country.
The identity of travelling companions.
Frequent travel patterns.
Certain special service requests.
The presence of information in a PNR does not mean every possible use is lawful.
9. Purpose limitation in flight data governance
The principle of purpose limitation means that personal data should be collected for specified, explicit, and legitimate purposes.
Lawful example
An airline collects passenger names and booking information to issue tickets and manage travel.
Law enforcement example
A competent authority processes PNR data under the PNR Directive for the prevention, detection, investigation, or prosecution of terrorist offences and serious crime.
Unlawful or problematic example
Using flight records for unrelated purposes without a valid legal basis, or retaining information indefinitely without a legally justified reason.
Legal principle: The fact that a database contains information does not give every authority unrestricted permission to use it.
10. Three major case laws on flight data governance
These cases are especially important for PNR, passenger privacy, and the sharing of flight data with public authorities.
Case 6 — Opinion 1/15: EU–Canada PNR Agreement
CJEU
Opinion 1/15
EU–Canada PNR Agreement
Opinion: 26 July 2017
Area: International transfer of passenger data
Facts
The European Union negotiated an agreement with Canada concerning the transfer and processing of Passenger Name Record data of air passengers travelling between the EU and Canada.
The agreement was submitted to the CJEU for an opinion on its compatibility with EU law.
Legal issues
The Court examined whether the agreement complied with:
The right to privacy.
The right to protection of personal data.
The legal requirements governing international data transfers.
The Charter of Fundamental Rights of the EU.
Judgment
The CJEU found that the agreement in its proposed form could not be concluded because several provisions were incompatible with fundamental rights.
The Court identified concerns relating to the scope of processing, sensitive data, retention, and safeguards.
Importance for Spain
Spain is an EU Member State. Therefore, the legal principles in this opinion are relevant to Spanish authorities handling international passenger data.
Importance for airlines
Airlines may transfer PNR data to authorities outside the EU. Such transfers must satisfy applicable legal requirements.
Legal principle: International passenger-data agreements must provide adequate safeguards for privacy and personal data protection.
Case 7 — Ligue des droits humains v Conseil des ministres
CJEU
C-817/19
Ligue des droits humains v Conseil des ministres
Judgment: 21 June 2022
Area: EU PNR Directive and fundamental rights
Facts
The case concerned the Belgian system for processing passenger data and the compatibility of the EU PNR Directive with fundamental rights.
The national proceedings raised questions about the scope of the PNR framework, data retention, and the use of passenger information.
Legal issues
The CJEU examined:
Whether the PNR Directive was compatible with the Charter of Fundamental Rights.
Whether passenger data could be used for purposes beyond the prevention and prosecution of serious crime.
Whether the retention of passenger data was proportionate.
What limits applied to the use of PNR data by public authorities.
Judgment
The CJEU upheld the general validity of the PNR Directive but imposed important limits on its interpretation and application.
The Court emphasized that PNR processing must respect fundamental rights and cannot be treated as unlimited or indiscriminate surveillance.
Importance for Spain
Spanish authorities must interpret and apply the Spanish PNR framework consistently with EU law.
Importance for passenger privacy
The judgment reinforces that:
PNR processing must have a lawful purpose.
Data processing must be necessary and proportionate.
Retention and access must have safeguards.
The PNR system cannot be used without regard to fundamental rights.
Legal principle: PNR processing must be limited to what is necessary and justified under EU law.
Case 8 — La Quadrature du Net and Others
CJEU
Joined Cases C-511/18, C-512/18 and C-520/18
La Quadrature du Net and Others
Judgment: 6 October 2020
Area: Electronic communications data and national security
Facts
The case concerned French legislation on the retention and transmission of electronic communications data for national security and law enforcement purposes.
Legal issues
The Court examined:
Whether general and indiscriminate retention of communications data was lawful.
Whether national security concerns justified broad data retention.
The conditions under which public authorities could access communications data.
Judgment
The CJEU held that EU law imposes limits on the general and indiscriminate retention of communications data. It recognized certain circumstances in which targeted or other forms of retention may be permitted, subject to strict safeguards.
Importance for banking and airline data
Modern banks and airlines use electronic communication systems and digital platforms.
The case is relevant to:
Digital transaction records.
Electronic communications metadata.
Airline booking systems.
Data held by communication service providers.
Government requests for access to information.
Legal principle
Security objectives do not automatically justify unlimited collection or retention of personal data.
11. Banking law and flight data governance: Comparison
| Issue | Banking law | Flight data governance |
|---|---|---|
| Main objective | Financial stability, customer protection, lawful banking operations | Aviation security, passenger management and serious crime prevention |
| Common personal data | Account details, financial records, identity | Names, booking details, travel information |
| Main regulators | Banco de España, ECB, CNMV, AEPD | Spanish aviation authorities, Ministry of the Interior, AEPD, EU institutions |
| Privacy framework | GDPR, LOPDGDD and sector-specific rules | GDPR, PNR Directive, Law 1/2020 and applicable law enforcement rules |
| Data retention | Banking and anti-money-laundering obligations | PNR retention rules and applicable airline/legal requirements |
| Public access | Lawful requests, supervision, criminal investigations | Authorized Passenger Information Unit and competent authorities |
| Key legal issue | Balancing confidentiality and regulatory duties | Balancing security and passenger privacy |
12. Practical examples
Example 1 — Bank requests customer identification
A Spanish bank asks a customer for identification documents.
Legal analysis
The bank may process the information when there is an appropriate legal basis, such as compliance with legal obligations or a necessary contractual relationship.
The bank should:
Explain the relevant processing.
Collect appropriate information.
Protect the data.
Avoid excessive collection.
Comply with retention requirements.
Relevant cases
STC 292/2000.
Digital Rights Ireland.
Schrems II.
Example 2 — Bank shares transaction data with authorities
A Spanish bank receives a lawful request concerning suspected money laundering.
Legal analysis
The bank may be required to disclose information under anti-money-laundering legislation.
The bank must still comply with applicable requirements governing the request and the processing of data.
Relevant legal principles
Law 10/2010.
GDPR legal basis and security obligations.
Confidentiality subject to legal exceptions.
Example 3 — Airline transfers PNR data to Spain
An airline transmits passenger information to the Spanish Passenger Information Unit.
Legal analysis
The processing must fall within the applicable PNR framework and satisfy its requirements.
The airline and authorities must consider:
Lawful purpose.
Scope of the data.
Security.
Retention.
Access controls.
Passenger rights, subject to lawful restrictions.
Relevant cases
Opinion 1/15.
Ligue des droits humains, C-817/19.
La Quadrature du Net.
13. Detailed legal principles arising from the case laws
Principle 1 — Fundamental rights apply to data processing
The Spanish Constitution and EU Charter protect personal information.
This applies to both bank data and passenger data.
Principle 2 — Consumer protection limits banking contracts
Banco Español de Crédito and Aziz demonstrate that consumer credit and mortgage enforcement must comply with EU consumer protection.
Principle 3 — Data retention must be justified
Digital Rights Ireland and La Quadrature du Net establish important limits on indiscriminate retention of personal information.
Principle 4 — International transfers require safeguards
Schrems II and Opinion 1/15 establish that transferring personal data outside the EU requires compliance with legal safeguards.
Principle 5 — Security does not remove privacy rights
The PNR case law recognizes the importance of aviation security while requiring compliance with fundamental rights.
Principle 6 — Lawful access is not unlimited access
Authorities may obtain information only within their legal powers and subject to applicable safeguards.
14. Important distinctions for examinations
Banking secrecy vs data protection
Banking secrecy is a confidentiality obligation associated with financial information. Data protection is a broader legal framework governing personal information.
They overlap, but they are not identical.
PNR vs API
PNR is mainly booking and reservation information. API is passenger identification information obtained in connection with travel.
Commercial airline data vs law enforcement data
An airline's use of data for ticketing is different from a public authority's use of PNR for serious crime prevention.
Data collection vs data retention
Collecting data and keeping it for a period are separate legal questions. A lawful initial collection does not automatically justify unlimited retention.
15. Conclusion
Spanish banking law and flight data governance are both influenced by European Union law and the protection of personal information.
Banking law focuses on:
Banking supervision.
Financial contracts.
Customer protection.
Confidentiality.
Anti-money-laundering compliance.
Flight data governance focuses on:
Passenger information.
Aviation security.
PNR processing.
Data transfers.
Law enforcement access.
Passenger privacy.
The case laws demonstrate that privacy and data protection must be balanced with legitimate commercial and security objectives. Neither banks nor public authorities have unlimited discretion to collect, retain, or share personal information.
Case law revision list
| No. | Case | Citation | Main subject |
|---|---|---|---|
| 1 | Banco Español de Crédito v Calderón Camino | C-618/10 | Unfair banking contract terms |
| 2 | Aziz v Caixa d'Estalvis de Catalunya | C-415/11 | Mortgage enforcement |
| 3 | Spanish Constitutional Court | STC 292/2000 | Fundamental data protection |
| 4 | Digital Rights Ireland | C-293/12 and C-594/12 | Data retention |
| 5 | Schrems II | C-311/18 | International data transfers |
| 6 | EU–Canada PNR Agreement | Opinion 1/15 | International passenger data |
| 7 | Ligue des droits humains | C-817/19 | PNR Directive |
| 8 | La Quadrature du Net | C-511/18, C-512/18, C-520/18 | Electronic data retention |
Note on legal accuracy: These are leading authorities, not all of which concern Spanish banking or airline law directly. The cases from the CJEU are relevant to Spain because EU law governs the applicable subject matter. This is an educational overview, not legal advice for a particular banking, airline, or data protection dispute.

comments