Banking Law And Space Cybersecurity Law Spain
1. Introduction
Banking law and space cybersecurity law in Spain intersect because modern banking increasingly depends on space-based infrastructure. Banks and financial institutions may rely on satellites for:
- secure communications;
- positioning and timing;
- disaster recovery;
- connectivity to remote branches and ATMs;
- transaction-network resilience;
- cloud and data-centre synchronization;
- fraud detection and geolocation;
- emergency communications; and
- continuity of financial-market infrastructure.
Spain therefore approaches this subject through a multi-layer legal framework rather than through one statute called "Space Cybersecurity Law."
The relevant legal layers include:
- Spanish banking and financial-services regulation;
- Spanish cybersecurity and critical-infrastructure legislation;
- EU banking legislation;
- EU cybersecurity legislation;
- EU data-protection law;
- EU space law and the EU Space Programme;
- international space law; and
- contractual and liability rules governing satellite and technology suppliers.
A particularly important point is that there is not yet a large body of Spanish reported case law specifically deciding "banking + satellite cybersecurity" disputes. Consequently, the most useful authorities are cases concerning cybersecurity, data protection, financial institutions, electronic communications, critical infrastructure and technology risk, which establish principles that can apply when space infrastructure supports banking services.
2. Why Space Cybersecurity Matters to Spanish Banking
A bank can be exposed to a space-related cyber incident even when the bank does not own a satellite.
For example:
Satellite operator → communications provider → bank → payment system → customer
A cyberattack against the satellite or ground infrastructure could therefore create consequences for banking operations.
Potential risks include:
- loss of satellite communications;
- manipulation of navigation or timing signals;
- compromise of satellite ground stations;
- ransomware against satellite-service providers;
- attacks on telemetry and control systems;
- compromise of cloud systems connected to satellite networks;
- supply-chain attacks;
- interception of communications;
- disruption of payment connectivity;
- operational outages; and
- unauthorized access to financial data.
This makes space cybersecurity partly a banking operational-resilience issue.
3. Spanish Banking Regulatory Framework
Spanish banks operate principally under the Spanish framework implementing EU banking legislation.
Important institutions include:
- Banco de España;
- Comisión Nacional del Mercado de Valores (CNMV);
- European Central Bank (ECB) for institutions within the Single Supervisory Mechanism;
- European Banking Authority (EBA); and
- European Systemic Risk Board (ESRB).
The main banking legislation includes the Spanish framework derived from:
- Capital Requirements Directive (CRD);
- Capital Requirements Regulation (CRR);
- Bank Recovery and Resolution Directive (BRRD);
- Deposit Guarantee Schemes Directive;
- Payment Services Directive;
- Markets in Financial Instruments legislation; and
- the Digital Operational Resilience Act (DORA).
DORA is especially important for cybersecurity.
4. DORA and Space-Based Banking Infrastructure
The Digital Operational Resilience Act (EU) 2022/2554 establishes a harmonised framework for ICT risk management in the financial sector.
For a Spanish bank, the important question is not simply:
"Does the bank own a satellite?"
Instead, the question is:
"Does the bank depend on an ICT system or ICT third-party service whose disruption could affect its financial services?"
That distinction is critical.
A bank using satellite connectivity may therefore need to evaluate:
- cybersecurity;
- availability;
- resilience;
- incident management;
- business continuity;
- disaster recovery;
- third-party ICT risk;
- concentration risk;
- contractual controls; and
- testing.
5. ICT Third-Party Risk
Suppose a Spanish bank obtains satellite connectivity from an external technology company.
The contractual chain could look like:
Bank → telecom provider → satellite operator → ground station → software supplier
The bank cannot necessarily treat cybersecurity responsibility as disappearing merely because the technical service is outsourced.
DORA places significant emphasis on ICT third-party risk management.
This becomes particularly important for space services because a satellite operator can potentially become an important technological dependency.
Relevant contractual provisions may include:
- cybersecurity standards;
- incident notification;
- audit rights;
- business-continuity obligations;
- disaster recovery;
- data-location requirements;
- subcontracting controls;
- termination assistance;
- access to information;
- resilience testing; and
- exit strategies.
6. NIS2 and Space Cybersecurity
The EU NIS2 Directive (EU) 2022/2555 substantially strengthens cybersecurity requirements for important sectors and entities.
Its importance to the space sector arises from the recognition that certain space-related infrastructure can form part of critical digital and communications ecosystems.
For Spain, the practical issue is the relationship between:
NIS2 cybersecurity obligations + Spanish cybersecurity legislation + DORA financial-sector requirements.
Where a financial institution falls under DORA, DORA is particularly important for its financial ICT resilience.
A space operator or technology supplier may separately fall within cybersecurity obligations depending upon:
- its activities;
- size;
- sector classification;
- services supplied; and
- the applicable Spanish implementation framework.
Therefore, a bank should not assume that one cybersecurity regime automatically covers its entire satellite supply chain.
7. Spanish Critical-Infrastructure Law
Spain has a significant critical-infrastructure framework.
An important statute is:
Law 8/2011
Ley 8/2011, de 28 de abril, por la que se establecen medidas para la protección de las infraestructuras críticas.
It establishes a framework for protecting infrastructure whose disruption could seriously affect essential services.
Financial services are particularly relevant because banking and financial-market infrastructure can have systemic consequences.
The framework is supplemented by regulatory measures concerning:
- identification of critical infrastructure;
- security plans;
- operator security;
- risk analysis;
- incident prevention;
- coordination with authorities; and
- protection against physical and technological threats.
8. Cybersecurity of Satellite Ground Stations
A major legal mistake would be to focus exclusively on the satellite itself.
Cybersecurity risk often exists on the ground.
A satellite ecosystem may include:
Satellite
↓
Ground station
↓
Network
↓
Cloud platform
↓
Banking application
↓
Customer
A compromise of the ground station could therefore indirectly affect banking services.
Spanish cybersecurity compliance should consequently consider:
- access control;
- authentication;
- encryption;
- network segmentation;
- privileged-access management;
- logging;
- incident response;
- vulnerability management;
- backup systems; and
- continuity planning.
9. EU Space Programme Regulation
The EU Space Programme Regulation (EU) 2021/696 establishes the EU Space Programme and includes security-related requirements concerning EU space infrastructure and services.
Relevant EU space capabilities include:
- Galileo;
- EGNOS;
- Copernicus;
- GOVSATCOM;
- secure governmental communications; and
- related space infrastructure.
For banking, Galileo is particularly interesting because financial systems increasingly depend upon accurate timing and positioning technologies.
A disruption of timing information could theoretically affect:
- transaction sequencing;
- network synchronization;
- authentication systems;
- trading infrastructure;
- fraud systems; and
- telecommunications.
This creates an indirect connection between space resilience and financial stability.
10. Cybersecurity and Financial Timing
Modern financial networks require extremely accurate timestamps.
Consider:
Satellite navigation/timing → telecommunications → bank network → payment transaction
If an attacker manipulated timing information, the resulting problem might not be a conventional data breach.
It could instead be an integrity and availability problem.
Banks should therefore consider:
- GNSS spoofing;
- GNSS jamming;
- loss of satellite timing;
- alternative timing sources;
- redundancy;
- terrestrial synchronization;
- monitoring; and
- incident-response procedures.
The legal issue is increasingly one of operational resilience, rather than simply confidentiality.
11. GDPR and Satellite Banking Data
The General Data Protection Regulation (EU) 2016/679 (GDPR) can become relevant where satellite-enabled banking systems process personal data.
Examples include:
- customer identification;
- location information;
- employee information;
- transaction information;
- authentication information; and
- communications metadata.
Important GDPR principles include:
Article 5
Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability.
Article 25
Data protection by design and by default.
Article 32
Security of processing.
Articles 33–34
Personal-data breach notification and communication.
Thus, cybersecurity architecture for satellite-supported banking systems should incorporate privacy requirements from the design stage.
12. Data Transfers Through Satellite Networks
Satellite systems can involve multinational infrastructure.
For example:
Spain → EU cloud → satellite operator → non-EU ground infrastructure
This creates potential GDPR questions concerning:
- international transfers;
- adequacy decisions;
- Standard Contractual Clauses;
- supplementary safeguards;
- processor/subprocessor relationships; and
- government access to data.
The location of a satellite in orbit does not itself determine the GDPR's applicability.
The critical questions concern:
- who processes the data;
- where processing occurs;
- what entities receive it; and
- which legal regime governs those entities.
13. Banking Secrecy and Confidentiality
Banks have extensive confidentiality obligations.
A satellite communication system can therefore create a confidentiality risk if:
- communications are inadequately encrypted;
- satellite links are intercepted;
- ground stations are compromised;
- credentials are stolen; or
- suppliers obtain excessive access.
The bank should maintain security controls over:
- customer information;
- transaction information;
- authentication credentials;
- payment instructions;
- internal banking communications; and
- supervisory information.
14. Space Supply-Chain Cybersecurity
One of the most important legal issues is third-party risk.
A bank may never directly interact with the satellite operator.
Instead:
Bank → ICT supplier → telecom company → satellite operator → software vendor
This creates a chain of dependencies.
A cybersecurity incident at the bottom of the chain could still become an operational incident for the bank.
Consequently, contracts should address:
- security standards;
- incident reporting;
- subcontractor management;
- vulnerability disclosure;
- penetration testing;
- audit rights;
- business continuity;
- recovery time objectives;
- data protection;
- termination;
- transition assistance; and
- regulatory access.
15. Operational Resilience Under DORA
DORA requires financial entities to establish an extensive ICT-risk management framework.
For satellite-dependent banking operations, this can translate into questions such as:
What happens if the satellite link disappears?
What happens if the ground station is attacked?
What happens if the satellite supplier suffers ransomware?
Can the bank switch to terrestrial communications?
How quickly can critical banking services recover?
Does the bank have alternative suppliers?
These are legal compliance questions as well as technical questions.
16. Incident Reporting
Cyber incidents affecting banking services can trigger regulatory obligations.
The legal analysis depends on:
- type of incident;
- severity;
- affected service;
- entity involved;
- applicable legislation; and
- contractual structure.
DORA provides a specific framework for major ICT-related incident reporting by financial entities.
Separately, cybersecurity legislation may create reporting obligations for other entities in the technology chain.
A bank should therefore maintain an incident classification matrix showing which authority must be notified and under which legislation.
17. Space Cybersecurity and Criminal Law
Cyberattacks against satellite systems can potentially involve criminal offences.
Depending on the conduct, issues can include:
- unauthorized access;
- unlawful interception;
- computer-system interference;
- data interference;
- fraud;
- damage to infrastructure; and
- misuse of credentials.
Spanish criminal law therefore potentially operates alongside regulatory cybersecurity law.
The cross-border character of space infrastructure makes jurisdiction especially complicated.
18. Jurisdictional Problems
Imagine:
- Spanish bank;
- French satellite operator;
- US software provider;
- ground station in another EU country;
- cloud infrastructure distributed internationally.
A single cyber incident may therefore involve several legal systems.
Potential questions include:
- Which country's courts have jurisdiction?
- Which cybersecurity regulator investigates?
- Which country's criminal law applies?
- Which contractual law governs?
- Where did the damage occur?
- Where was the data processed?
- Which entity is legally responsible?
This is why space cybersecurity contracts need carefully drafted:
- governing-law clauses;
- jurisdiction clauses;
- arbitration provisions;
- cybersecurity obligations; and
- evidence-preservation requirements.
19. Important Case Law
There is no substantial Spanish reported case-law category specifically dealing with a cyberattack on a satellite used by a Spanish bank. The following cases are therefore best understood as analogous authorities establishing principles relevant to banking-space cybersecurity.
Case 1 — CJEU, Digital Rights Ireland
Joined Cases C-293/12 and C-594/12, Digital Rights Ireland
The Court of Justice examined EU data-retention rules and their impact on fundamental rights.
Relevance
The judgment demonstrates that technological systems handling communications information must be assessed against:
- privacy;
- proportionality;
- necessity;
- security; and
- protection of personal information.
For satellite-enabled banking communications, the case is relevant to the design of systems that collect or retain communications-related information.
20. Case 2 — Schrems II
C-311/18, Data Protection Commissioner v Facebook Ireland and Schrems
The CJEU examined international transfers of personal data and invalidated the EU-US Privacy Shield while retaining the possibility of using Standard Contractual Clauses subject to appropriate safeguards.
Relevance to Space Banking
A satellite banking architecture can involve multinational service providers.
The case therefore demonstrates that a bank cannot simply assume that contractual arrangements solve every international-data-transfer problem.
It must examine:
- destination-country law;
- government-access risks;
- safeguards;
- encryption; and
- practical protection of data.
21. Case 3 — Tele2 Sverige
Joined Cases C-203/15 and C-698/15
The CJEU considered the retention and access to electronic communications data.
Principle
The Court placed strong emphasis on:
- necessity;
- proportionality;
- privacy;
- communications confidentiality; and
- safeguards against excessive access.
Space Cybersecurity Relevance
Satellite communications can create significant volumes of metadata.
The case therefore helps establish the legal importance of protecting communications data rather than treating it as technologically neutral information.
22. Case 4 — Breyer
C-582/14, Patrick Breyer v Bundesrepublik Deutschland
The CJEU examined whether dynamic IP addresses can constitute personal data.
Relevance
The decision illustrates that technical identifiers can potentially qualify as personal data.
For satellite-connected banking networks, similar questions may arise regarding:
- IP addresses;
- device identifiers;
- network identifiers;
- location information; and
- authentication records.
23. Case 5 — Fashion ID
C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW
The CJEU considered responsibilities associated with processing personal data through embedded technologies.
Relevance
The case is useful for understanding joint responsibility and technical data-processing arrangements.
In a banking technology chain, several entities may participate in processing data.
The legal question may therefore become:
Which entity is controller, processor, or otherwise legally responsible for the processing?
That question can become complicated where satellite, telecom, cloud and banking providers interact.
24. Case 6 — La Quadrature du Net
Joined Cases C-511/18, C-512/18 and C-520/18
The CJEU examined national measures concerning electronic communications data retention and national security.
Relevance
The case is significant because it illustrates the interaction between:
- cybersecurity;
- national security;
- electronic communications;
- privacy; and
- EU fundamental rights.
Satellite infrastructure can have both commercial and strategic significance, making this balance relevant to space cybersecurity.
25. Case 7 — Schrems I
C-362/14, Schrems v Data Protection Commissioner
The CJEU invalidated the Safe Harbour framework for EU-US personal-data transfers.
Relevance
The case established an important principle:
International technology infrastructure cannot be treated as legally neutral merely because contractual arrangements exist.
This is relevant where banking data moves through multinational technology or communications infrastructure.
26. Banking-Specific Judicial Dimension
European banking case law also demonstrates that banks are subject to extensive regulatory oversight where financial stability and prudential requirements are concerned.
Cases involving the Single Resolution Mechanism, banking supervision, and Banco Popular illustrate the broader principle that EU and Spanish banking activities operate within a highly regulated public-law framework.
However, those cases should not be described as satellite-cybersecurity cases. Their value here is primarily in demonstrating how EU financial regulation interacts with Spanish banking institutions.
27. Relationship Between DORA and Space Cybersecurity
A useful legal model is:
| Issue | Relevant legal layer |
|---|---|
| Bank ICT risk | DORA |
| Bank cybersecurity | DORA + Spanish banking regulation |
| Critical infrastructure | Spanish critical-infrastructure framework |
| Network cybersecurity | NIS2-related framework |
| Personal data | GDPR |
| Satellite infrastructure | EU/Spanish space framework |
| Communications | Electronic communications law |
| Cybercrime | Spanish/EU criminal law |
| Supplier risk | DORA + contract law |
| Cross-border data | GDPR |
| Financial continuity | DORA + prudential regulation |
The important lesson is that space cybersecurity is not a standalone legal silo.
28. Space Cybersecurity Governance Model for Spanish Banks
A Spanish bank using satellite-dependent services could establish a governance model such as:
Board
↓
Chief Risk Officer
↓
Chief Information Security Officer
↓
ICT Risk Management
↓
Space/Satellite Supplier Risk
↓
Cybersecurity Monitoring
↓
Incident Response
↓
Business Continuity
↓
Regulatory Reporting
This allows the satellite dependency to become part of the bank's overall operational-risk framework.
29. Risk Classification
A bank should classify satellite dependencies according to their effect on:
Confidentiality
Could the attacker obtain banking information?
Integrity
Could the attacker manipulate data or communications?
Availability
Could the bank lose connectivity?
Authenticity
Could false commands or communications be accepted?
Resilience
Can the bank continue operating through another network?
Recoverability
How quickly can services be restored?
This CIA + resilience approach is particularly useful for satellite-supported financial systems.
30. Space Cybersecurity and Payment Systems
Payment systems create particularly important dependencies.
For example:
Satellite timing
→ telecommunications synchronization
→ banking network
→ payment authorization
→ settlement
A cyberattack that disrupts timing or communications might therefore cause:
- transaction delays;
- authentication problems;
- reconciliation difficulties;
- duplicate-processing risks;
- failed communications; or
- temporary service interruption.
The bank should therefore have independent terrestrial alternatives wherever the satellite dependency is operationally important.
31. Satellite Spoofing and Banking
Spoofing occurs when false signals are presented to a receiver so that it believes the information is genuine.
For financial institutions, the concern is not necessarily that a satellite signal directly transfers money.
The risk is indirect.
For example:
False positioning/timing information
↓
Network-system error
↓
Incorrect system behaviour
↓
Banking-service disruption
Consequently, financial institutions should not assume that satellite cybersecurity is purely an aerospace-engineering issue.
32. Space Cybersecurity and Business Continuity
Business-continuity planning should identify:
- critical satellite dependencies;
- alternative terrestrial links;
- backup communications;
- redundant data centres;
- backup authentication;
- alternative timing systems;
- manual procedures;
- recovery priorities; and
- supplier emergency contacts.
A bank should be able to answer:
"If this satellite service becomes unavailable today, which banking services stop functioning?"
That question is directly connected to operational resilience.
33. Liability for a Space Cyberattack
Liability could potentially arise under several legal relationships.
Bank ↔ Satellite Provider
Contractual liability.
Bank ↔ ICT Provider
DORA-related contractual and regulatory obligations.
Satellite Provider ↔ Software Supplier
Technology and supply-chain contract.
Attacker ↔ Victim
Potential criminal and civil consequences.
Bank ↔ Customer
Potential consequences where the incident causes unauthorized transactions, data breaches or service failures.
The exact liability depends heavily on:
- contract wording;
- causation;
- negligence;
- statutory duties;
- cybersecurity controls; and
- applicable jurisdiction.
34. International Space Law
Space cybersecurity also operates against the background of international space law, particularly:
- Outer Space Treaty 1967;
- Liability Convention 1972;
- Registration Convention 1975; and
- other international instruments.
These treaties were not drafted specifically for modern cyberattacks.
This creates an important legal challenge:
Traditional space law primarily addresses physical activities in outer space, while modern cyberattacks can originate from terrestrial networks and affect space infrastructure remotely.
Consequently, cybersecurity responsibility often has to be constructed through domestic law, EU law, contracts and general international-law principles.
35. Key Legal Problem: Attribution
One of the hardest issues is identifying who conducted a cyberattack.
Suppose a Spanish bank experiences disruption.
Investigators discover:
- compromised satellite software;
- infrastructure in another state;
- a subcontractor in a third country; and
- an unknown attacker.
The legal problem is:
Who is responsible?
Technical attribution does not automatically establish legal responsibility.
The distinction between:
technical attribution → factual attribution → legal attribution → liability
is essential.
36. Regulatory Compliance Matrix
For a Spanish financial institution, a practical compliance matrix could look like this:
| Risk | Main legal concern |
|---|---|
| Satellite outage | DORA operational resilience |
| Ground-station hacking | Cybersecurity |
| Banking-data interception | GDPR + confidentiality |
| Supplier ransomware | ICT third-party risk |
| GNSS disruption | Operational resilience |
| Data transfer outside EU | GDPR |
| Critical banking infrastructure attack | Critical-infrastructure law |
| Cybercrime | Criminal law |
| Contractual supplier failure | Contract law |
| Major ICT incident | DORA reporting |
| Space-system compromise | Space + cybersecurity regulation |
| Cross-border incident | EU/international cooperation |
37. Six Important Legal Authorities at a Glance
| Authority | Main principle | Relevance |
|---|---|---|
| Digital Rights Ireland, C-293/12 & C-594/12 | Privacy/proportionality in communications data | Satellite communications |
| Schrems I, C-362/14 | International data-transfer safeguards | Global space suppliers |
| Schrems II, C-311/18 | Transfers require effective safeguards | Satellite/cloud infrastructure |
| Tele2 Sverige, C-203/15 & C-698/15 | Communications-data retention/access | Satellite metadata |
| Breyer, C-582/14 | Technical identifiers can be personal data | Network identifiers |
| Fashion ID, C-40/17 | Responsibility for technical data processing | Multi-supplier banking systems |
These should be cited as analogous cybersecurity/data-protection authorities, rather than as direct Spanish space-banking precedents.
38. Major Legal Challenges in Spain
The most significant emerging issues are likely to involve:
1. Regulatory overlap
DORA, NIS2-related requirements, GDPR, Spanish cybersecurity legislation and space regulation may apply simultaneously.
2. Supply-chain dependency
Banks may depend upon satellite operators without having a direct contractual relationship with every entity in the chain.
3. Attribution
Identifying the technically and legally responsible actor can be difficult.
4. Cross-border jurisdiction
Space infrastructure is inherently international.
5. Timing and navigation security
GNSS disruption can become a financial operational-risk problem.
6. Data protection
Satellite networks can carry sensitive financial and personal information.
7. Resilience
Financial institutions need alternatives when space infrastructure becomes unavailable.
39. Future Direction of Spanish Banking-Space Cybersecurity Law
The regulatory trend is toward resilience rather than merely prevention.
The legal question is increasingly not:
"Can the bank prevent every cyberattack?"
but:
"Can the bank continue providing essential services when a serious cyberattack occurs?"
For space-dependent banking, this means greater attention to:
- redundancy;
- zero-trust architecture;
- supplier concentration;
- incident reporting;
- cyber testing;
- satellite-ground segmentation;
- alternative communications;
- secure software development;
- encryption;
- supply-chain monitoring; and
- recovery planning.
40. Conclusion
Banking Law and Space Cybersecurity Law in Spain is an emerging interdisciplinary field rather than a single consolidated branch of Spanish legislation.
The central legal relationship can be represented as:
Space infrastructure
↓
Cybersecurity
↓
ICT suppliers
↓
Banking operational resilience
↓
Financial stability
↓
Customer protection
For Spanish banks, DORA is particularly important for ICT and operational resilience, while GDPR governs personal-data protection and Spanish/EU cybersecurity and critical-infrastructure frameworks address broader cyber risks. EU space legislation adds another layer where space infrastructure and services are involved.
The available case law is largely indirect rather than space-specific. The CJEU decisions in Digital Rights Ireland, Tele2 Sverige, Breyer, Schrems I, Schrems II and Fashion ID provide important principles concerning communications data, privacy, international transfers and technological responsibility. They can therefore help interpret legal problems arising from satellite-supported banking systems, but they should not be presented as judgments directly deciding Spanish satellite-banking cyberattacks.
Core legal takeaway: Spain's approach is best understood as a multi-layer resilience framework in which banking regulation, cybersecurity, data protection, critical infrastructure, technology contracts and space regulation interact.

comments