Banking Law And Virtual Regulatory Laboratories Spain .
Banking Law and Virtual Regulatory Laboratories — Spain
1. Introduction
In Spain, virtual regulatory laboratories are generally understood as controlled environments in which financial institutions, fintech firms and technology providers can test innovative financial products or services under regulatory supervision before full-scale market deployment.
The best-known Spanish framework is the financial regulatory sandbox, established principally by Law 7/2020 of 13 November for the digital transformation of the financial system (Ley 7/2020 para la transformación digital del sistema financiero).
The sandbox is particularly relevant to banking innovations involving:
- artificial intelligence;
- digital identity and electronic KYC;
- blockchain and distributed-ledger technology;
- tokenisation and crypto-assets;
- automated credit assessment;
- RegTech and SupTech;
- payment technologies;
- biometric authentication;
- smart contracts; and
- cybersecurity and operational-resilience solutions.
A regulatory laboratory does not create a law-free environment. It creates a supervised testing environment in which regulatory consequences and risks can be studied under controlled conditions.
2. Spanish Legal Framework
Spain's regulatory-laboratory regime must be understood through several overlapping layers.
Law 7/2020
This is the central Spanish legislation establishing the controlled testing environment for technological innovation in the financial system.
Its objective is to encourage digital financial innovation while protecting customers and preserving financial stability.
Banking legislation
Where the experiment concerns banking activities, Spanish banking rules remain relevant, including Law 10/2014 on the organisation, supervision and solvency of credit institutions.
EU financial-services law
Depending upon the experiment, the project may also encounter:
- CRR/CRD prudential rules;
- PSD2 and the evolving EU payments framework;
- MiCA;
- MiFID II;
- DORA;
- GDPR;
- EU AML legislation; and
- EU rules governing artificial intelligence.
Consequently, admission into the Spanish sandbox does not automatically exempt a project from EU law.
3. What Is a Regulatory Sandbox?
A regulatory sandbox can be illustrated simply.
Suppose a Spanish bank develops an AI system that evaluates loan applications using alternative financial data.
Deploying the technology immediately to millions of customers could create significant risks.
Instead, the bank proposes a limited test:
2,000 participants → controlled AI credit assessment → regulator supervises → results evaluated → safeguards adjusted.
This controlled environment functions as a regulatory laboratory.
It allows both the institution and supervisory authorities to understand how the innovation behaves before widespread commercial implementation.
4. Authorities Involved
The relevant authority depends on the financial activity being tested.
For banking innovations, the Banco de España may play a major supervisory role.
For securities and investment-market innovations, the CNMV (Comisión Nacional del Mercado de Valores) may be relevant.
For insurance and pension innovations, the Dirección General de Seguros y Fondos de Pensiones (DGSFP) may participate.
A project involving several financial sectors can therefore require cooperation between authorities.
This is particularly important for hybrid products.
For example:
Bank account + tokenised investment + insurance protection + automated investment advice.
Such a product may cross traditional regulatory boundaries.
5. Admission to the Sandbox
Not every technology project qualifies merely because it is innovative.
A project normally needs to demonstrate genuine technological innovation applicable to the financial system and sufficient maturity to undergo testing.
The innovation should also potentially provide benefits such as:
- improved regulatory compliance;
- greater consumer protection;
- improved financial-service efficiency;
- better accessibility;
- enhanced competition; or
- improved functioning of financial markets.
A purely theoretical idea without sufficient development is therefore different from a project ready for controlled experimentation.
6. Testing Protocol
One of the most important legal components is the testing protocol.
The protocol establishes the conditions under which the experiment operates.
It can cover matters such as:
- scope of the test;
- duration;
- number and type of participants;
- supervisory arrangements;
- information requirements;
- risk controls;
- customer safeguards;
- data processing;
- withdrawal arrangements;
- liability;
- suspension conditions; and
- termination of testing.
Therefore, sandbox admission should not be confused with unrestricted regulatory permission.
The project operates inside an agreed supervisory framework.
7. Participant Protection
Where real customers participate, their protection becomes central.
Participants should understand that they are participating in an experimental environment.
Relevant safeguards can include:
- prior information;
- informed participation;
- transparent disclosure of risks;
- protection of personal data;
- withdrawal mechanisms;
- confidentiality arrangements;
- compensation or liability safeguards where applicable; and
- procedures if the experiment is suspended.
A bank cannot use the word “experimental” as a general contractual exclusion of responsibility.
8. Sandbox and Banking Authorisation
This distinction is fundamental:
Sandbox admission is not the same as a banking licence.
Suppose a technology company tests a blockchain-based deposit platform successfully in the Spanish regulatory sandbox.
Successful completion does not automatically transform the company into an authorised credit institution.
If its eventual commercial activity requires banking authorisation, payment-institution authorisation, CASP status or another regulated permission, the appropriate regulatory requirements must still be satisfied.
The sandbox tests the innovation; it does not generally replace the ordinary authorisation system.
9. Virtual Assets and MiCA
Regulatory laboratories are particularly useful for blockchain projects.
A Spanish project could test:
- tokenised settlement;
- crypto custody;
- blockchain identity systems;
- tokenised collateral;
- stablecoin infrastructure;
- smart-contract payments; or
- bank-to-wallet transfers.
However, the legal classification of the token remains essential.
If the instrument constitutes a crypto-asset governed by MiCA, MiCA requirements must be considered.
If it constitutes a financial instrument, the MiFID/securities framework may apply instead.
Therefore:
Sandbox participation does not change the legal nature of the token.
A security token does not become an ordinary MiCA token simply because it is tested inside a sandbox.
10. Artificial Intelligence Laboratories
AI provides another important application.
Consider a Spanish bank testing an AI fraud-detection system.
The system analyses:
- transaction histories;
- payment behaviour;
- device information;
- location anomalies; and
- unusual transaction patterns.
The regulatory laboratory allows the institution and supervisor to examine accuracy, explainability, cybersecurity, discrimination risks and data protection before large-scale deployment.
Where EU AI legislation applies, sandbox testing must also be considered alongside the EU Artificial Intelligence Act.
11. Automated Credit Decisions
AI lending creates particularly sensitive banking-law issues.
Suppose an algorithm automatically decides:
Customer A — loan approved.
Customer B — loan rejected.
Testing must consider more than predictive accuracy.
Important legal questions include:
- Is the data lawful?
- Is the model discriminatory?
- Can significant decisions be explained?
- Is human intervention required?
- Are customers adequately informed?
- Is the model continuously monitored?
- Can incorrect decisions be challenged?
The GDPR, especially rules concerning automated decision-making, can become highly relevant.
12. AML and Digital KYC Laboratories
Spanish regulatory laboratories can also be important for AML innovation.
A project might test remote customer identification using:
ID document + facial verification + liveness detection + database verification.
Even inside a sandbox, the underlying objective remains compliance with Spanish AML requirements, particularly Law 10/2010 on the prevention of money laundering and terrorist financing.
Testing cannot simply remove customer-identification obligations.
Instead, the laboratory examines whether new technology can satisfy regulatory objectives reliably and securely.
13. Data Protection
Sandbox experiments frequently require significant volumes of personal data.
Consequently, the GDPR and Spanish data-protection legislation remain important.
The institution should consider:
- lawful basis;
- data minimisation;
- purpose limitation;
- security;
- retention;
- transparency;
- automated decision-making; and
- data-subject rights.
A regulatory sandbox is therefore not a data-protection sandbox unless the applicable framework specifically provides otherwise.
Financial-regulatory approval cannot automatically substitute for GDPR compliance.
14. Cybersecurity and DORA
Since DORA — Regulation (EU) 2022/2554 — applies to a broad range of EU financial entities, operational resilience has become particularly important.
A virtual regulatory laboratory testing cloud banking, APIs, AI or blockchain should examine:
- ICT risk;
- cyberattacks;
- service interruptions;
- incident response;
- data recovery;
- third-party technology providers; and
- business continuity.
For banks, successful functionality is insufficient if the technology cannot operate securely and resiliently.
15. Smart Contracts
Suppose a sandbox project tests a smart contract that automatically releases collateral after repayment of a bank loan.
The experiment should examine:
- whether code accurately represents the legal agreement;
- what happens if an oracle provides incorrect information;
- whether transactions can be reversed;
- responsibility for coding errors;
- cybersecurity;
- legal enforceability; and
- insolvency consequences.
The important legal principle is:
Automatic technological execution does not necessarily eliminate ordinary contractual law.
Spanish Civil Code principles concerning consent, interpretation, good faith and liability can remain applicable.
16. Cross-Border Innovation
Digital banking experiments frequently cross borders.
A Spanish fintech might have:
- Spanish customers;
- cloud infrastructure in Ireland;
- a technology provider in Germany;
- blockchain validators globally; and
- a parent company elsewhere in the EU.
Spanish sandbox admission does not automatically authorise commercial operation throughout the European Union.
Passporting, licensing and EU sector-specific rules must still be examined.
17. Important Case Law
There is comparatively limited reported case law specifically interpreting Law 7/2020 sandbox experiments. This is understandable because a regulatory sandbox is primarily a supervisory mechanism rather than a traditional source of litigation.
Therefore, the most useful cases come from surrounding areas of EU banking, fintech, data and consumer law.
Case 1 — CJEU, SCHUFA Holding (Scoring), Case C-634/21, 7 December 2023
The case concerned automated credit scoring and GDPR Article 22.
The Court held, under the circumstances considered, that automated establishment of a probability value can itself constitute automated individual decision-making where a third party gives that score a determining role in establishing or terminating a contractual relationship.
Sandbox significance
An AI credit-scoring project cannot assume that calling its output a “recommendation” automatically removes GDPR concerns.
If banks effectively rely on the score to determine access to credit, automated-decision rules may apply.
Case 2 — CJEU, SCHUFA Holding, Joined Cases C-26/22 and C-64/22
These proceedings concerned retention and processing of information by credit-information organisations.
Relevance
Financial innovation projects involving alternative credit data must respect GDPR principles concerning lawful processing and retention.
A regulatory experiment does not justify indefinite collection of customer information.
Case 3 — CJEU, Kásler, Case C-26/13
Kásler established influential principles concerning transparency of consumer contractual terms.
The consumer must be able to understand more than merely the grammatical wording of an important contractual mechanism; relevant economic consequences matter.
Regulatory-laboratory significance
When customers participate in innovative banking products, disclosures concerning algorithmic pricing, token values or variable charges should provide meaningful information rather than incomprehensible technical descriptions.
Case 4 — CJEU, Banco Español de Crédito, Case C-618/10
This Spanish reference became a major authority on unfair consumer contract terms.
The judgment strengthened the EU framework requiring effective judicial protection against unfair clauses.
Sandbox significance
Experimental products remain subject to consumer protection.
A term stating:
“The participant accepts every consequence of the experiment and waives all rights against the bank”
cannot automatically override mandatory consumer law.
Case 5 — CJEU, Google Spain v AEPD and Mario Costeja González, Case C-131/12
Although not a banking case, this landmark Spanish reference established fundamental principles concerning personal-data processing and individual rights under EU data-protection law.
Sandbox significance
Fintech experimentation involving large databases, profiling or digital identity must respect data-protection rights.
Technological innovation does not create an exemption from fundamental privacy protections.
Case 6 — CJEU, Digital Rights Ireland, Joined Cases C-293/12 and C-594/12
The Court invalidated the EU Data Retention Directive because of disproportionate interference with fundamental rights.
Relevance
The case illustrates the broader principle that large-scale technological data processing must satisfy proportionality and fundamental-rights requirements.
Regulators and banks therefore need to consider whether extensive experimental data collection is actually necessary.
Case 7 — CJEU, La Quadrature du Net, Joined Cases including C-511/18 and C-512/18
These judgments examined extensive electronic-data retention against EU privacy and fundamental-rights requirements.
Regulatory significance
Financial-security objectives do not automatically justify unlimited data retention or surveillance.
A virtual banking laboratory using behavioural monitoring should therefore apply necessity and proportionality principles.
Case 8 — CJEU, Hedqvist, Case C-264/14
The Court considered Bitcoin exchange transactions under EU VAT law.
Sandbox significance
Innovative technology does not eliminate the need for legal classification.
A blockchain experiment must determine whether its token operates as a payment mechanism, crypto-asset, financial instrument, e-money-like product or another legally regulated instrument.
18. Practical Example
Assume Banco Innovación España wants to test an AI/blockchain lending platform.
Customers apply digitally.
The system performs:
Stage 1 — Digital identity
AI verifies customer identity.
Stage 2 — AML screening
Automated systems evaluate sanctions and transaction risks.
Stage 3 — Credit scoring
Machine learning estimates default probability.
Stage 4 — Loan approval
The system proposes or automatically determines the lending decision.
Stage 5 — Tokenised collateral
Collateral is represented digitally.
Stage 6 — Smart contract
Repayment information automatically changes the collateral status.
A Spanish regulatory laboratory would allow these technologies to be tested under controlled conditions.
But multiple legal regimes remain relevant:
| Issue | Principal Legal Area |
|---|---|
| Bank supervision | Law 10/2014 |
| Regulatory sandbox | Law 7/2020 |
| Personal information | GDPR |
| Automated decisions | GDPR / EU AI framework |
| AML/KYC | Law 10/2010 |
| Crypto-assets | MiCA, where applicable |
| Financial instruments | MiFID framework, where applicable |
| ICT resilience | DORA |
| Customer terms | Spanish/EU consumer law |
| Smart contracts | Contract law + sector regulation |
The laboratory therefore provides controlled experimentation, not general regulatory immunity.
19. Liability During Testing
The allocation of responsibility is one of the most important parts of sandbox design.
Potential harm could arise from:
- incorrect algorithmic decisions;
- cyberattacks;
- software defects;
- inaccurate data;
- wrongful account blocking;
- smart-contract malfunction;
- privacy violations; or
- operational outages.
The testing protocol should therefore establish risk controls and responsibility clearly.
Where mandatory legislation gives customers particular rights, contractual wording cannot simply eliminate those rights.
20. Exit from the Regulatory Laboratory
A successful sandbox test does not represent the final regulatory stage.
After testing, broadly three possibilities exist.
Successful project: the promoter proceeds toward commercial deployment and obtains any required authorisation.
Project requiring modification: weaknesses discovered during testing are corrected.
Unsuccessful or unsafe project: the experiment ends without general deployment.
This is one of the principal advantages of regulatory laboratories: problems can be discovered before technology reaches the wider financial system.
21. Regulatory Laboratory vs Full Market
| Regulatory Laboratory | Ordinary Market |
|---|---|
| Limited testing | Large-scale operation |
| Controlled participants | General customers |
| Close supervisory involvement | Ordinary continuing supervision |
| Experimental technology | Commercially deployed product |
| Defined testing protocol | Full regulatory framework |
| Limited duration | Continuing operation |
| Risks actively evaluated | Risks must already be adequately managed |
| Does not itself equal authorisation | Required licences/permissions must exist |
22. Banking-Law Importance
Spain's sandbox framework serves two objectives that can sometimes conflict.
The first is innovation. Excessively rigid regulation can prevent beneficial financial technologies from developing.
The second is financial and consumer protection. Untested technology can expose customers and financial institutions to serious operational, privacy, credit, cybersecurity and financial-stability risks.
Law 7/2020 attempts to create a bridge between these objectives through supervised experimentation.
23. Conclusion
Spain has a relatively developed legal framework for virtual regulatory laboratories, principally through Law 7/2020 on the digital transformation of the financial system.
For banking projects, a regulatory laboratory can permit controlled testing of technologies such as AI lending, blockchain, digital identity, smart contracts, crypto-assets, automated AML systems and advanced payment infrastructure.
However, sandbox admission should never be understood as a general exemption from financial law. Banking authorisation, Law 10/2014, AML requirements under Law 10/2010, GDPR, MiCA, DORA, consumer law and other EU rules can continue to determine what the institution may ultimately do.
The surrounding case law—including SCHUFA (C-634/21), SCHUFA (C-26/22 and C-64/22), Kásler, Banco Español de Crédito, Google Spain, Digital Rights Ireland, La Quadrature du Net and Hedqvist—reinforces four particularly important principles: automated financial decisions remain legally accountable, experimental customer contracts remain subject to consumer protection, financial innovation remains constrained by privacy and fundamental rights, and new technology must still be classified according to its real legal and economic function.
Thus, the Spanish regulatory laboratory is best understood as a supervised bridge between financial experimentation and fully regulated commercial banking—not as a zone outside banking law.

comments