Banking Law And Orbital Security Governance Spain .
Banking Law and Orbital Security Governance in Spain
1. Introduction
“Orbital security governance” is not a separate, fully codified branch of Spanish banking law. It is better understood as the combination of banking regulation, space law, cybersecurity, national-security controls, data protection, sanctions, export controls, insurance, and contractual risk allocation that becomes relevant when Spanish banks finance or provide payment and financial services to satellite and other space-sector businesses.
Examples include financing satellite constellations, ground-control infrastructure, launch services, Earth-observation systems, satellite communications, space-data platforms, and companies supplying dual-use technology.
For a Spanish bank, the important legal question is therefore not simply whether a space project is commercially viable. The bank must determine whether financing, taking security, processing payments, holding sensitive information, and dealing with the relevant counterparties are legally permissible and adequately controlled.
Spanish law operates together with a substantial body of EU law and international space law.
2. Main Legal Framework
Spanish banks involved in orbital projects remain subject to ordinary banking regulation, particularly Law 10/2014 on the organisation, supervision and solvency of credit institutions and the associated Spanish and EU prudential framework.
The Banco de España, European Central Bank and, where appropriate, the Single Supervisory Mechanism can therefore scrutinise risks arising from lending to highly technological space businesses.
Several additional regulatory layers become important.
International Space Law
Spain is bound by major international space treaties, including the 1967 Outer Space Treaty.
A fundamental principle is that states bear international responsibility for national space activities, including activities performed by private entities. Private space activities consequently require appropriate governmental authorisation and continuing supervision.
The 1972 Liability Convention also establishes an international framework for damage caused by space objects.
This matters to lenders because potentially large liabilities can affect a borrower's creditworthiness and the value of financed assets.
3. Security Governance as a Banking Issue
Orbital assets are unusual collateral.
A satellite may cost hundreds of millions of euros but cannot normally be physically repossessed in the same way as aircraft, machinery or real estate.
Consequently, banks commonly need a broader security package involving rights over:
- shares in the satellite operating company;
- bank accounts and project revenues;
- insurance proceeds;
- ground infrastructure;
- intellectual-property rights;
- contractual receivables;
- launch and manufacturing agreements;
- licences and authorisations.
The lender must also consider whether regulatory approvals can survive an enforcement or restructuring process.
A contractual security interest is considerably less useful when the licences necessary to operate the satellite cannot automatically be transferred to the purchaser.
4. Cybersecurity and Operational Resilience
Orbital infrastructure increasingly depends on interconnected digital systems.
A cyber incident affecting satellite command systems, ground stations or communications infrastructure could interrupt the borrower's operations and therefore its ability to repay financing.
For banks, this makes cybersecurity relevant both as credit risk and as operational risk.
The EU Digital Operational Resilience Act (DORA) establishes extensive ICT-risk requirements for financial entities. Banks must maintain ICT risk-management arrangements, incident-management procedures, resilience testing and controls concerning ICT third-party providers.
A bank financing orbital infrastructure would therefore normally examine cybersecurity risks during due diligence even where the satellite operator itself is not regulated as a bank.
5. NIS2 and Critical Infrastructure
The EU's NIS2 Directive considerably strengthens cybersecurity requirements for important and essential entities.
The space sector is expressly relevant within the NIS2 framework.
Accordingly, certain satellite operators, ground infrastructure providers and related businesses can face cybersecurity governance requirements concerning areas such as:
risk analysis, incident handling, business continuity, supply-chain security, access control and vulnerability management.
A bank financing such an undertaking should investigate whether the borrower falls within applicable cybersecurity legislation and whether compliance failures could result in sanctions or operational interruption.
6. National-Security Considerations
Space technology frequently has both civilian and military applications.
For example, Earth-observation technology can support agriculture and environmental monitoring but can also produce strategically sensitive intelligence.
Similarly, satellite communications can have civilian, governmental and defence applications.
Spanish banks therefore need to consider whether a transaction involves strategic infrastructure, foreign investment screening, defence interests or national-security restrictions.
Security governance becomes particularly important when investors or lenders obtain substantial influence over companies operating strategic infrastructure.
7. Export Controls and Dual-Use Technology
Many satellite components can qualify as dual-use products or technologies.
EU export-control legislation therefore becomes important.
Banks financing satellite manufacturers or operators should determine whether relevant equipment, software or technical information requires export authorisation.
The risk is not limited to physically exporting hardware. Certain transfers of technical information or software can also create regulatory issues.
Financing documentation can consequently contain representations, warranties and undertakings concerning export-control compliance.
8. Sanctions and Financial Crime
Orbital projects commonly involve international supply chains.
A Spanish satellite project might involve components manufactured in several jurisdictions, a foreign launch provider, international investors and customers located worldwide.
Banks remain subject to sanctions, AML and counter-terrorist-financing requirements.
Due diligence therefore extends beyond the immediate borrower.
Banks may examine beneficial owners, contractors, launch providers, customers and payment destinations.
The risk can become particularly significant where satellite technology has military or surveillance applications.
9. Data Protection
Satellites can generate enormous quantities of information.
Some Earth-observation data will not constitute personal data. However, associated services may process identifiable location, communications, subscriber or employee information.
Where personal data are processed, the GDPR and Spanish Organic Law 3/2018 can become relevant.
Banks should therefore distinguish between ordinary commercial satellite data and information legally classified as personal or otherwise protected data.
10. Insurance and Orbital Risk
Insurance is particularly important in satellite finance because lenders cannot eliminate many physical risks through ordinary collateral.
Relevant policies can include:
- launch insurance;
- in-orbit insurance;
- third-party liability insurance;
- property insurance for ground infrastructure;
- cyber insurance.
Financing agreements may require insurance proceeds to be assigned or pledged for the benefit of lenders where legally permissible.
A major satellite failure can otherwise destroy both the borrower's revenue-generating capacity and much of the practical value of the lender's security.
Relevant Case Law
There is limited reported Spanish case law specifically combining bank lending and orbital-security governance. It would therefore be misleading to present six Spanish judgments as direct “satellite banking” cases.
Instead, the following European cases establish legal principles that can materially affect Spanish banks financing space and security-sensitive businesses.
1. Schrems II — CJEU, Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (2020)
The Court invalidated the EU-US Privacy Shield and stressed the importance of adequate protection when personal data are transferred internationally.
Orbital relevance: Satellite businesses often operate internationally and may transmit information through foreign ground stations, cloud platforms and service providers.
Banking relevance: Banks conducting technology and data-risk due diligence should examine whether sensitive project information and personal data are transferred lawfully.
2. Digital Rights Ireland — Joined Cases C-293/12 and C-594/12 (2014)
The CJEU invalidated the Data Retention Directive because the interference with privacy and personal-data rights was disproportionate.
Orbital relevance: Large-scale communications or satellite-data systems cannot assume that security objectives automatically justify unlimited collection or retention of information.
For banks, this demonstrates why regulatory legality should form part of technology-project due diligence.
3. Tele2 Sverige and Watson — Joined Cases C-203/15 and C-698/15 (2016)
The CJEU considered national rules requiring retention of communications data and imposed important limitations based on EU fundamental rights.
Orbital relevance: Satellite communication networks handling traffic or location information may operate within a legal environment where surveillance and retention requirements must satisfy proportionality standards.
The decision illustrates the interaction between security objectives and privacy protections.
4. La Quadrature du Net — Joined Cases C-511/18, C-512/18 and C-520/18 (2020)
This judgment further developed EU principles governing retention and access to communications information for national-security and law-enforcement purposes.
Relevance: Orbital communications infrastructure can potentially become strategically important communications infrastructure.
A Spanish lender financing such infrastructure therefore cannot treat cybersecurity, government-access obligations and privacy compliance as unrelated issues.
5. Privacy International — CJEU, Case C-623/17 (2020)
The case addressed the relationship between national-security measures and EU electronic-communications privacy law.
The Court confirmed that invoking national security does not automatically remove every activity from the constraints imposed by EU law.
Orbital-security relevance: Satellite telecommunications can involve government, defence and civilian communications simultaneously.
This makes the boundary between commercial regulation and national security particularly important.
6. Google Spain v AEPD and Mario Costeja González — CJEU, Case C-131/12 (2014)
This major Spanish-reference case established important principles concerning the territorial reach of EU data-protection rules and responsibilities associated with processing personal information.
Although it concerned search engines rather than satellites, its broader importance is substantial.
Orbital relevance: A technology company cannot necessarily avoid European regulatory responsibilities merely because parts of its technological infrastructure or corporate organisation are located outside Spain.
7. Bank Mellat v Council — CJEU, Case T-496/10 and related proceedings
The litigation concerned EU restrictive measures imposed on an Iranian bank and illustrates the legal importance of sanctions, procedural safeguards and evidentiary justification.
Orbital-finance relevance: Satellite and aerospace transactions frequently intersect with sanctions and export controls. Banks must therefore conduct careful counterparty and transaction screening.
8. Rosneft — CJEU, Case C-72/15 (2017)
The case concerned EU restrictive measures associated with Russia and addressed important questions concerning the interpretation and judicial review of EU sanctions.
Orbital relevance: Space projects frequently have cross-border supply chains involving advanced technology.
Spanish banks must therefore determine whether financing, payment processing, technical services or particular counterparties are affected by EU restrictive measures.
11. Due Diligence for Spanish Banks
A Spanish bank considering financing for an orbital project would generally need a multidisciplinary investigation.
The bank should identify the actual owner and operator of the satellite, determine which state exercises regulatory jurisdiction, examine launch arrangements and confirm that necessary licences and spectrum rights exist.
It should also analyse cybersecurity architecture, data flows, sanctions exposure, export-control requirements and insurance coverage.
A particularly important question is change of control.
If lenders enforce their security and obtain control over the project company, regulatory approvals may be required. Enforcement therefore needs to be designed before financing is granted rather than after default occurs.
12. Orbital Debris and Sustainability Risk
Orbital debris creates another unusual credit risk.
Collision can destroy or substantially impair a satellite even where the borrower itself has committed no contractual default.
Banks financing satellites may consequently investigate collision-avoidance arrangements, tracking capabilities, end-of-life disposal plans and applicable licensing conditions.
These considerations increasingly connect environmental sustainability with traditional credit-risk management.
13. Security Enforcement
Suppose a Spanish bank finances a satellite operator and takes security over the operator's shares, receivables and insurance proceeds.
If the borrower defaults, the bank cannot simply treat enforcement as an ordinary asset sale.
The potential purchaser may require regulatory approval. Export-control restrictions might apply. Spectrum rights may not be freely transferable. National-security screening could be triggered. Existing governmental licences might contain change-of-control restrictions.
Therefore, regulatory transferability is part of collateral value.
A satellite theoretically worth €200 million may have considerably less practical enforcement value if the lender cannot legally transfer the operational rights accompanying it.
14. Governance Structure
A sophisticated orbital-finance transaction therefore requires several layers of governance:
Banking governance deals with credit, capital, concentration and operational risks.
Space governance concerns authorisation, supervision, registration and liability for space activities.
Cybersecurity governance protects command, communications and ground infrastructure.
National-security governance addresses strategic assets and sensitive ownership.
Financial-crime governance covers AML, sanctions and suspicious transactions.
Technology governance addresses software, artificial intelligence, cloud systems and third-party providers.
These systems overlap rather than operate independently.
15. Practical Example
Consider a Spanish company seeking €300 million financing for a satellite communications constellation.
A lending syndicate would not merely analyse revenue forecasts.
It could require evidence of regulatory authorisations, spectrum rights, satellite and launch contracts, cybersecurity controls, export licences, sanctions compliance and insurance.
The lenders could take security over project-company shares, receivables, accounts, insurance proceeds and contractual rights.
Loan documentation might also require continuing compliance with space, cybersecurity, sanctions and export-control laws.
A serious cyber incident, loss of an essential licence or prohibited sanctions exposure could potentially constitute a contractual default if the financing documents are drafted accordingly.
Conclusion
Banking law and orbital security governance in Spain should be understood as a cross-regulatory framework rather than a single specialist statute.
Spanish banks financing satellites, orbital infrastructure or space-technology businesses must combine conventional prudential and secured-lending analysis with space regulation, cybersecurity, GDPR, national security, sanctions, export controls and insurance.
The European cases discussed above—including Schrems II, Digital Rights Ireland, Tele2 Sverige, La Quadrature du Net, Privacy International, Google Spain, Bank Mellat and Rosneft—are not satellite-finance judgments themselves. Their importance lies in establishing legal principles governing data, security, sanctions and cross-border technology that can apply to orbital projects.
The central banking-law principle is therefore straightforward: the financial value of an orbital asset depends not only on ownership and physical technology, but also on the regulatory permissions, cybersecurity arrangements, insurance and legal rights necessary to keep that asset operational and transferable.

comments