Banking Law And Flight Data Governance Spain .

1. Legal framework in Spain

A. Spanish constitutional protection

The Spanish Constitution of 1978 provides the foundation for privacy and economic regulation.

Article 18.4 — Data protection

The Constitution requires the law to limit the use of information technology to protect honour, personal and family privacy, and the exercise of rights.

This is important because:

A bank account contains personal and financial information.

Airline booking records contain identity and travel information.

Both types of records can be used to identify individuals and their activities.

Article 38 — Freedom of enterprise

Recognizes freedom of enterprise within a market economy, subject to the legal framework.

Article 51 — Consumer protection

Requires public authorities to protect consumers' economic interests and provide information and education.

B. Main data protection legislation

LawRelevance
Spanish Constitution, Articles 18.4, 38 and 51Privacy, enterprise, and consumer protection
Organic Law 3/2018 (LOPDGDD)Spanish implementation and development of data protection law
GDPR, Regulation (EU) 2016/679General personal data protection
Law 10/2010Prevention of money laundering and terrorist financing
Law 5/2019Real estate credit contracts
Law 16/2011Consumer credit contracts
Law 7/1996 and other consumer legislationConsumer and commercial protections, where applicable
Law 48/1960Spanish Air Navigation Law
Law 21/2003Aviation safety and security framework
Law 1/2020Spanish implementation of the EU PNR Directive

The exact scope of these laws depends on the activity. For example, a bank's anti-money-laundering duties are not identical to an airline's obligations to transmit passenger data to a national Passenger Information Unit.

PART I — BANKING LAW IN SPAIN

2. Meaning and scope of Spanish banking law

Banking law is the body of rules governing:

Establishment and licensing of banks.

Banking supervision and prudential regulation.

Deposit-taking and lending.

Payment services and electronic banking.

Customer rights and consumer protection.

Financial crime prevention.

Bank confidentiality and data protection.

Insolvency and resolution of banks.

In Spain, banking regulation operates at three levels:

European Union law

Banking directives, regulations, GDPR, EU banking supervision

 

Spanish legislation

Banking statutes, consumer credit, anti-money laundering, data protection

 

Supervisory authorities

Banco de España, ECB, CNMV, AEPD and other competent bodies

Principal banking authorities

1. Banco de España

The central bank of Spain. It supervises certain banking activities, payment institutions and credit institutions within its legal powers, and handles banking customer complaints through its complaints service.

2. European Central Bank (ECB)

Under the Single Supervisory Mechanism, the ECB directly supervises significant credit institutions and works with national supervisors.

3. CNMV

The Spanish securities market supervisor. It regulates and supervises investment services and securities markets.

4. AEPD

The Spanish Data Protection Agency. It supervises compliance with data protection law, including personal information processed by banks and airlines within its jurisdiction.

3. Bank customer information and confidentiality

What is bank secrecy?

Bank secrecy refers to the obligation of financial institutions to protect confidential customer information.

A bank may possess:

Account numbers and balances.

Transaction records.

Income and financial history.

Loan and mortgage details.

Payment card information.

Identification documents.

Information used for fraud prevention.

Spanish law does not make bank secrecy an absolute right. A bank may be legally required to disclose information to competent authorities.

Permitted disclosure

A bank may disclose information where there is a valid legal basis, such as:

Customer consent, where consent is the appropriate legal basis.

A legal obligation, including certain anti-money-laundering requirements.

A lawful request by a competent authority.

A court order.

A regulatory or supervisory requirement.

Other legally valid grounds under data protection law.

Example: If a Spanish bank receives a lawful request from a competent authority investigating money laundering, the bank may have a duty to provide the requested information. The request must still comply with applicable legal requirements.

GDPR principles relevant to banking

The GDPR establishes the following principles:

PrincipleBanking application
Lawfulness, fairness and transparencyCustomers must be informed about relevant data processing
Purpose limitationData collected for one purpose should not be used incompatibly for another
Data minimisationOnly necessary data should be processed
AccuracyIncorrect customer records should be corrected
Storage limitationData should not be retained longer than legally justified
Integrity and confidentialityBanks must protect customer information
AccountabilityBanks must be able to demonstrate compliance

The legal basis for processing is particularly important. A bank cannot simply rely on a customer's general acceptance of its terms for every use of personal data.

4. Banking law and anti-money laundering

Law 10/2010

Spanish Law 10/2010, on the prevention of money laundering and terrorist financing, imposes duties on banks and other obliged entities.

These include:

Customer due diligence.

Identification and verification of customers.

Identification of beneficial owners.

Monitoring transactions.

Reporting suspicious activity.

Recordkeeping.

Internal controls and compliance procedures.

Why this matters for data governance

A bank must balance two obligations:

Customer privacy — protect personal information.

Legal compliance — retain and disclose information when required by anti-money-laundering legislation.

These duties may coexist. Data protection law does not automatically prevent lawful anti-money-laundering processing.

However, banks must still comply with requirements such as necessity, proportionality, security, and appropriate access controls.

5. Six major case laws relevant to banking and data governance

The following cases are important European and Spanish legal authorities. They include banking and consumer-credit cases, constitutional data protection, and major cases governing the use of personal information by public authorities.

Case 1 — Banco Español de Crédito v Joaquín Calderón Camino

CJEU

C-618/10

Banco Español de Crédito v Calderón Camino

Judgment: 14 June 2012

Area: Banking contracts and consumer protection

Facts

Banco Español de Crédito brought proceedings concerning an unpaid consumer credit debt. The Spanish legal procedure allowed a court to issue a payment order, and the question arose whether an unfair contractual term could be left unexamined by the court.

Legal issue

Can a Spanish court enforce a consumer contract without examining whether its terms are unfair under EU consumer protection law?

Judgment

The Court of Justice held that national procedural rules must not make it excessively difficult to enforce consumer rights under EU law.

In particular, courts must be able to examine unfair terms in consumer contracts, including where necessary on their own initiative.

Importance for banking law

The case establishes that:

Consumer credit contracts are subject to EU consumer protection.

Banks cannot rely on procedural mechanisms to bypass legal protections.

National courts have an important role in reviewing unfair contract terms.

Application in Spain

Spanish courts must apply EU consumer protection requirements when dealing with consumer banking and credit agreements.

Legal principle: Consumer protection can limit the enforcement of banking contract terms.

Case 2 — Aziz v Caixa d'Estalvis de Catalunya

CJEU

C-415/11

Mohamed Aziz v Caixa d'Estalvis de Catalunya

Judgment: 14 March 2013

Area: Spanish mortgage law and unfair terms

Facts

Mohamed Aziz entered into a mortgage loan agreement with Caixa d'Estalvis de Catalunya. Following default, mortgage enforcement proceedings were brought. Mr Aziz argued that certain contractual terms were unfair.

Legal issue

Did Spanish mortgage enforcement procedures provide sufficient protection for consumers where the mortgage contract contained potentially unfair terms?

Judgment

The CJEU held that the Spanish procedural framework could be incompatible with EU consumer protection rules because it made it difficult for a court to suspend mortgage enforcement while unfair terms were examined.

Importance

This case is important because it demonstrates:

Consumer rights apply to mortgage contracts.

Banking enforcement procedures must respect EU consumer protection.

Courts must have effective means to assess unfair contractual terms.

National procedural rules cannot undermine substantive consumer rights.

Banking law significance

A mortgage is a banking product. Its enforcement is not only a matter of contract law; it is also subject to consumer protection obligations.

Legal principle: Banking enforcement procedures must provide effective protection against unfair contract terms.

Case 3 — STC 292/2000, Spanish Constitutional Court

Spain

STC 292/2000

Spanish Constitutional Court Judgment 292/2000

Judgment: 30 November 2000

Area: Fundamental right to personal data protection

Legal issue

What is the scope of the constitutional right to personal data protection under Article 18.4 of the Spanish Constitution?

Judgment

The Constitutional Court recognized personal data protection as an autonomous fundamental right. It is not merely a part of general privacy.

The right gives individuals powers over their personal information, including the ability to control the collection and use of personal data.

Importance for banks

Banks process extensive information about customers. This judgment supports the principle that:

Financial data is personal data.

Individuals have rights over their personal information.

Public authorities and private entities must respect constitutional data protection.

Data processing must have an adequate legal basis and safeguards.

Banking application

If a bank collects customer data, it must comply with applicable data protection rules. A bank's commercial interest does not automatically override the customer's fundamental rights.

Legal principle: Personal data protection is an independent fundamental right under the Spanish Constitution.

Case 4 — Digital Rights Ireland Ltd and Seitlinger

CJEU

Joined Cases C-293/12 and C-594/12

Digital Rights Ireland

Judgment: 8 April 2014

Area: Data retention and fundamental rights

Facts

The cases challenged the EU Data Retention Directive, which required certain communications data to be retained for the purpose of investigating serious crime.

Legal issue

Did the broad retention of communications data comply with fundamental rights to privacy and data protection?

Judgment

The CJEU invalidated the Data Retention Directive because the general and indiscriminate retention of data constituted a serious interference with fundamental rights and lacked sufficient limitations and safeguards.

Importance for banking and flight data

Although the case did not concern bank accounts or airline bookings directly, it is important for data governance because it explains that:

Large-scale data retention interferes with privacy.

Data collection must be limited to what is necessary.

Retention periods must be justified.

Access to data must be subject to safeguards.

Security and oversight are important.

Banking example: A bank may be required to retain transaction records under anti-money-laundering law. That does not mean it may retain every item of personal information indefinitely without a legal purpose.

Legal principle: Data retention must comply with necessity, proportionality, and fundamental rights.

Case 5 — Schrems II

CJEU

C-311/18

Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

Judgment: 16 July 2020

Area: International data transfers

Facts

Maximillian Schrems challenged the transfer of personal data from the European Union to the United States by Facebook Ireland.

Legal issue

Could EU personal data be transferred to a third country under the EU-US Privacy Shield, and what safeguards were required for transfers under standard contractual clauses?

Judgment

The CJEU invalidated the EU-US Privacy Shield decision. It held that standard contractual clauses could remain valid, but data exporters and importers must assess whether the destination country provides adequate protection and use supplementary safeguards where necessary.

Importance for Spanish banking law

Spanish banks often use international service providers for:

Cloud storage.

Customer relationship management.

Payment processing.

Fraud detection.

IT support.

Cybersecurity services.

If personal data is transferred outside the EEA, the bank must comply with GDPR Chapter V.

Importance for airlines

Airlines and reservation systems may use international data processors. The same rules apply to transfers of passenger data.

Legal principle: International transfers of personal data require legally adequate safeguards.

PART II — FLIGHT DATA GOVERNANCE IN SPAIN

6. Meaning of flight data governance

Flight data governance is the legal and organisational framework controlling the collection, processing, sharing, storage, and deletion of data relating to flights and passengers.

It includes:

Passenger Name Records (PNR).

Advance Passenger Information (API).

Passenger identity records.

Booking and reservation information.

Travel itinerary.

Ticket and payment information.

Baggage information.

Flight manifests.

Airline operational information.

Aviation security data.

Data shared with border and law enforcement authorities.

Difference between PNR and API

FeaturePNRAPI
Full nameUsually includedIncluded
Travel document detailsMay be includedIncluded
Booking referenceIncludedNot necessarily
Flight itineraryIncludedIncluded
Payment detailsMay be includedGenerally not part of core API
PurposeBooking, travel and security usesBorder control and passenger identification
SourceAirline reservation systemPassenger travel document/check-in data

Important: PNR and API are different datasets, although they may overlap.

7. Legal framework for flight data in Spain

A. EU PNR Directive — Directive (EU) 2016/681

The EU PNR Directive regulates the use of Passenger Name Record data for the prevention, detection, investigation, and prosecution of terrorist offences and serious crime.

It governs the transfer of certain PNR data by air carriers to Passenger Information Units.

B. Spanish implementation

Spain implemented the EU PNR framework through Law 1/2020, of 16 September, on the use of Passenger Name Record data for the prevention, detection, investigation, and prosecution of terrorist offences and serious crime.

The framework includes the Spanish Passenger Information Unit (PIU), associated with the Ministry of the Interior.

C. GDPR and law enforcement data

Flight data governance can involve two different legal regimes:

Processing contextApplicable framework
Airline commercial booking and customer servicesGDPR and Spanish data protection law
Processing for aviation security and serious crime preventionPNR rules and applicable law enforcement data protection framework
Border control and immigrationApplicable EU and Spanish border-control laws
International data transfersGDPR Chapter V or other applicable transfer rules

Not every processing operation is governed by exactly the same legal instrument.

8. What information can be contained in PNR data?

PNR data may include booking and travel information such as:

Passenger name.

Contact details.

Travel itinerary.

Ticket information.

Travel agent information.

Seat number.

Baggage information.

Payment and billing information where collected in the PNR.

Information about accompanying passengers.

Special service requests where included in the record.

Sensitive data concern

PNR records can reveal information about a person's travel patterns, associations, and potentially sensitive personal circumstances.

For example, a travel record may reveal:

A person's repeated travel to a particular country.

The identity of travelling companions.

Frequent travel patterns.

Certain special service requests.

The presence of information in a PNR does not mean every possible use is lawful.

9. Purpose limitation in flight data governance

The principle of purpose limitation means that personal data should be collected for specified, explicit, and legitimate purposes.

Lawful example

An airline collects passenger names and booking information to issue tickets and manage travel.

Law enforcement example

A competent authority processes PNR data under the PNR Directive for the prevention, detection, investigation, or prosecution of terrorist offences and serious crime.

Unlawful or problematic example

Using flight records for unrelated purposes without a valid legal basis, or retaining information indefinitely without a legally justified reason.

Legal principle: The fact that a database contains information does not give every authority unrestricted permission to use it.

10. Three major case laws on flight data governance

These cases are especially important for PNR, passenger privacy, and the sharing of flight data with public authorities.

Case 6 — Opinion 1/15: EU–Canada PNR Agreement

CJEU

Opinion 1/15

EU–Canada PNR Agreement

Opinion: 26 July 2017

Area: International transfer of passenger data

Facts

The European Union negotiated an agreement with Canada concerning the transfer and processing of Passenger Name Record data of air passengers travelling between the EU and Canada.

The agreement was submitted to the CJEU for an opinion on its compatibility with EU law.

Legal issues

The Court examined whether the agreement complied with:

The right to privacy.

The right to protection of personal data.

The legal requirements governing international data transfers.

The Charter of Fundamental Rights of the EU.

Judgment

The CJEU found that the agreement in its proposed form could not be concluded because several provisions were incompatible with fundamental rights.

The Court identified concerns relating to the scope of processing, sensitive data, retention, and safeguards.

Importance for Spain

Spain is an EU Member State. Therefore, the legal principles in this opinion are relevant to Spanish authorities handling international passenger data.

Importance for airlines

Airlines may transfer PNR data to authorities outside the EU. Such transfers must satisfy applicable legal requirements.

Legal principle: International passenger-data agreements must provide adequate safeguards for privacy and personal data protection.

Case 7 — Ligue des droits humains v Conseil des ministres

CJEU

C-817/19

Ligue des droits humains v Conseil des ministres

Judgment: 21 June 2022

Area: EU PNR Directive and fundamental rights

Facts

The case concerned the Belgian system for processing passenger data and the compatibility of the EU PNR Directive with fundamental rights.

The national proceedings raised questions about the scope of the PNR framework, data retention, and the use of passenger information.

Legal issues

The CJEU examined:

Whether the PNR Directive was compatible with the Charter of Fundamental Rights.

Whether passenger data could be used for purposes beyond the prevention and prosecution of serious crime.

Whether the retention of passenger data was proportionate.

What limits applied to the use of PNR data by public authorities.

Judgment

The CJEU upheld the general validity of the PNR Directive but imposed important limits on its interpretation and application.

The Court emphasized that PNR processing must respect fundamental rights and cannot be treated as unlimited or indiscriminate surveillance.

Importance for Spain

Spanish authorities must interpret and apply the Spanish PNR framework consistently with EU law.

Importance for passenger privacy

The judgment reinforces that:

PNR processing must have a lawful purpose.

Data processing must be necessary and proportionate.

Retention and access must have safeguards.

The PNR system cannot be used without regard to fundamental rights.

Legal principle: PNR processing must be limited to what is necessary and justified under EU law.

Case 8 — La Quadrature du Net and Others

CJEU

Joined Cases C-511/18, C-512/18 and C-520/18

La Quadrature du Net and Others

Judgment: 6 October 2020

Area: Electronic communications data and national security

Facts

The case concerned French legislation on the retention and transmission of electronic communications data for national security and law enforcement purposes.

Legal issues

The Court examined:

Whether general and indiscriminate retention of communications data was lawful.

Whether national security concerns justified broad data retention.

The conditions under which public authorities could access communications data.

Judgment

The CJEU held that EU law imposes limits on the general and indiscriminate retention of communications data. It recognized certain circumstances in which targeted or other forms of retention may be permitted, subject to strict safeguards.

Importance for banking and airline data

Modern banks and airlines use electronic communication systems and digital platforms.

The case is relevant to:

Digital transaction records.

Electronic communications metadata.

Airline booking systems.

Data held by communication service providers.

Government requests for access to information.

Legal principle

Security objectives do not automatically justify unlimited collection or retention of personal data.

11. Banking law and flight data governance: Comparison

IssueBanking lawFlight data governance
Main objectiveFinancial stability, customer protection, lawful banking operationsAviation security, passenger management and serious crime prevention
Common personal dataAccount details, financial records, identityNames, booking details, travel information
Main regulatorsBanco de España, ECB, CNMV, AEPDSpanish aviation authorities, Ministry of the Interior, AEPD, EU institutions
Privacy frameworkGDPR, LOPDGDD and sector-specific rulesGDPR, PNR Directive, Law 1/2020 and applicable law enforcement rules
Data retentionBanking and anti-money-laundering obligationsPNR retention rules and applicable airline/legal requirements
Public accessLawful requests, supervision, criminal investigationsAuthorized Passenger Information Unit and competent authorities
Key legal issueBalancing confidentiality and regulatory dutiesBalancing security and passenger privacy

12. Practical examples

Example 1 — Bank requests customer identification

A Spanish bank asks a customer for identification documents.

Legal analysis

The bank may process the information when there is an appropriate legal basis, such as compliance with legal obligations or a necessary contractual relationship.

The bank should:

Explain the relevant processing.

Collect appropriate information.

Protect the data.

Avoid excessive collection.

Comply with retention requirements.

Relevant cases

STC 292/2000.

Digital Rights Ireland.

Schrems II.

Example 2 — Bank shares transaction data with authorities

A Spanish bank receives a lawful request concerning suspected money laundering.

Legal analysis

The bank may be required to disclose information under anti-money-laundering legislation.

The bank must still comply with applicable requirements governing the request and the processing of data.

Relevant legal principles

Law 10/2010.

GDPR legal basis and security obligations.

Confidentiality subject to legal exceptions.

Example 3 — Airline transfers PNR data to Spain

An airline transmits passenger information to the Spanish Passenger Information Unit.

Legal analysis

The processing must fall within the applicable PNR framework and satisfy its requirements.

The airline and authorities must consider:

Lawful purpose.

Scope of the data.

Security.

Retention.

Access controls.

Passenger rights, subject to lawful restrictions.

Relevant cases

Opinion 1/15.

Ligue des droits humains, C-817/19.

La Quadrature du Net.

13. Detailed legal principles arising from the case laws

Principle 1 — Fundamental rights apply to data processing

The Spanish Constitution and EU Charter protect personal information.

This applies to both bank data and passenger data.

Principle 2 — Consumer protection limits banking contracts

Banco Español de Crédito and Aziz demonstrate that consumer credit and mortgage enforcement must comply with EU consumer protection.

Principle 3 — Data retention must be justified

Digital Rights Ireland and La Quadrature du Net establish important limits on indiscriminate retention of personal information.

Principle 4 — International transfers require safeguards

Schrems II and Opinion 1/15 establish that transferring personal data outside the EU requires compliance with legal safeguards.

Principle 5 — Security does not remove privacy rights

The PNR case law recognizes the importance of aviation security while requiring compliance with fundamental rights.

Principle 6 — Lawful access is not unlimited access

Authorities may obtain information only within their legal powers and subject to applicable safeguards.

14. Important distinctions for examinations

Banking secrecy vs data protection

Banking secrecy is a confidentiality obligation associated with financial information. Data protection is a broader legal framework governing personal information.

They overlap, but they are not identical.

PNR vs API

PNR is mainly booking and reservation information. API is passenger identification information obtained in connection with travel.

Commercial airline data vs law enforcement data

An airline's use of data for ticketing is different from a public authority's use of PNR for serious crime prevention.

Data collection vs data retention

Collecting data and keeping it for a period are separate legal questions. A lawful initial collection does not automatically justify unlimited retention.

15. Conclusion

Spanish banking law and flight data governance are both influenced by European Union law and the protection of personal information.

Banking law focuses on:

Banking supervision.

Financial contracts.

Customer protection.

Confidentiality.

Anti-money-laundering compliance.

Flight data governance focuses on:

Passenger information.

Aviation security.

PNR processing.

Data transfers.

Law enforcement access.

Passenger privacy.

The case laws demonstrate that privacy and data protection must be balanced with legitimate commercial and security objectives. Neither banks nor public authorities have unlimited discretion to collect, retain, or share personal information.

Case law revision list

No.CaseCitationMain subject
1Banco Español de Crédito v Calderón CaminoC-618/10Unfair banking contract terms
2Aziz v Caixa d'Estalvis de CatalunyaC-415/11Mortgage enforcement
3Spanish Constitutional CourtSTC 292/2000Fundamental data protection
4Digital Rights IrelandC-293/12 and C-594/12Data retention
5Schrems IIC-311/18International data transfers
6EU–Canada PNR AgreementOpinion 1/15International passenger data
7Ligue des droits humainsC-817/19PNR Directive
8La Quadrature du NetC-511/18, C-512/18, C-520/18Electronic data retention

Note on legal accuracy: These are leading authorities, not all of which concern Spanish banking or airline law directly. The cases from the CJEU are relevant to Spain because EU law governs the applicable subject matter. This is an educational overview, not legal advice for a particular banking, airline, or data protection dispute.

LEAVE A COMMENT