Banking Law And Data Governance In Banking Institutions Spain .
Banking Law And Data Governance In Banking Institutions Spain
Introduction
Data governance in Spanish banking institutions means the system through which a bank collects, uses, protects, shares, retains, corrects, and deletes data. It covers customer identity data, account records, payment information, credit files, transaction histories, fraud indicators, employee data, and information used by automated risk models.
For Spanish banks, data governance is not only a privacy matter. It is a core banking-law issue because weak data can produce incorrect lending decisions, anti-money-laundering failures, unauthorised payments, unfair customer treatment, cyber incidents, and inaccurate regulatory reporting. The board and senior management must therefore ensure that data is reliable, secure, traceable, and used lawfully.
Legal And Regulatory Framework
1. GDPR and Spanish Data Protection Law
The General Data Protection Regulation applies directly in Spain, supplemented by Organic Law 3/2018 on Data Protection and Digital Rights. Banks must process personal data lawfully, fairly, and transparently. They must collect only necessary data, keep it accurate, secure it appropriately, and retain it no longer than needed.
A bank must identify a lawful basis for each purpose. Contract performance may justify processing needed to operate an account or execute a payment. Legal obligations may justify AML, tax, and prudential reporting. However, marketing, profiling, and data-sharing arrangements require closer examination and may require consent or a separate legitimate-interest assessment.
2. Banking Supervision and Governance
Law 10/2014 on the regulation, supervision, and solvency of credit institutions requires Spanish banks to maintain sound governance and internal-control arrangements. Data quality is part of operational-risk management. A bank cannot safely manage capital, credit risk, liquidity, fraud, or compliance if its records are incomplete, duplicated, biased, or inaccessible.
The Banco de España may assess whether a bank has effective controls over information used in risk management and regulatory reporting. Poor data lineage—where the bank cannot show where a figure came from, how it changed, and who approved it—can create supervisory concern.
3. Payments, Credit Information and Automated Decisions
Royal Decree-Law 19/2018, implementing PSD2, requires secure payment processing and appropriate protection of customer payment data. Banks must limit access to account information and apply strong customer authentication where required.
Credit scoring and automated lending decisions are also governed by GDPR rules on profiling and automated decision-making. A customer should not be subjected to a solely automated decision with significant effects, such as refusal of credit, unless a valid legal exception and proper safeguards exist. Those safeguards include meaningful information, human intervention, the ability to express a view, and the ability to challenge the result.
4. Cybersecurity and Outsourcing
Banks increasingly use cloud providers, fintech partners, analytics vendors, and shared digital platforms. They remain responsible for the governance of outsourced processing. Contracts must define confidentiality, security, audit rights, incident notification, data location, sub-processing, return or deletion of data, and business-continuity obligations.
The Digital Operational Resilience Act has strengthened expectations for ICT-risk management, incident reporting, resilience testing, and oversight of critical technology providers. In practice, data governance and cybersecurity must operate together.
Key Data Governance Duties
A Spanish bank should maintain a clear data-governance framework containing:
- A board-approved data strategy and data-risk appetite.
- Defined ownership for important datasets.
- Data-quality controls for completeness, accuracy, consistency, and timeliness.
- Role-based access controls and monitoring of privileged access.
- A reliable record of processing activities.
- Data-retention and deletion schedules.
- Procedures for customer access, correction, objection, and portability requests.
- Controls over automated models and meaningful human review.
- Rapid breach-response and notification procedures.
The most important principle is accountability. A bank must not merely state that it complies; it must be able to prove compliance through policies, system logs, risk assessments, training records, contracts, audit trails, and management oversight.
Risks For Banking Institutions
Poor data governance can create several forms of liability. An inaccurate credit file may result in unfair refusal of finance. Excessive monitoring may breach privacy principles. A weak vendor contract may expose customer data. A biased algorithm may discriminate indirectly against certain groups. A delayed response to a data breach may result in regulatory penalties and customer claims.
Banks must also distinguish between data use for legal compliance and data use for commercial advantage. AML monitoring may be legally required, but using the same financial information for unrelated marketing or customer profiling may need a separate lawful basis and greater transparency.
Case Laws
1. CJEU, SCHUFA Holding, Case C-634/21
Facts: A consumer’s creditworthiness was assessed through automated scoring.
Legal Issue: Whether automated scoring that strongly influences credit approval can amount to prohibited automated decision-making.
Principle: Where a score plays a decisive role in granting or refusing credit, it may constitute an automated individual decision under GDPR.
Importance: Spanish banks must not hide material lending decisions behind an algorithm. They need transparency, human review, and a challenge process.
2. CJEU, Österreichische Post, Case C-300/21
Facts: A person claimed compensation after unlawful processing of personal data.
Legal Issue: Whether a GDPR breach automatically creates a right to compensation.
Principle: A breach alone is insufficient; the claimant must show damage and a causal link. No minimum seriousness threshold applies once real damage is established.
Importance: Banks should document compliance because poor data handling may lead to compensation claims even where financial loss is limited.
3. CJEU, Natsionalna agentsia za prihodite, Case C-340/21
Facts: Personal data was exposed through a cyberattack on a public authority.
Legal Issue: Whether a controller is automatically liable whenever hackers obtain data.
Principle: A cyberattack does not automatically prove inadequate security, but the controller must show that its technical and organisational measures were appropriate to the risk.
Importance: Spanish banks must conduct risk-based security assessments and preserve evidence of controls, testing, and incident response.
4. CJEU, Nowak, Case C-434/16
Facts: The case concerned whether examination material relating to a person constituted personal data.
Legal Issue: How broadly “personal data” should be understood.
Principle: Personal data includes information relating to a person where its content, purpose, or effect concerns that individual.
Importance: Bank records, internal credit notes, fraud comments, risk flags, and assessment outputs may all be personal data.
5. CJEU, Breyer, Case C-582/14
Facts: A website operator processed dynamic IP addresses.
Legal Issue: Whether information may be personal data even where identification requires additional information held elsewhere.
Principle: Data can be personal data where a realistic legal and practical means exists to identify the person.
Importance: Banks must treat device identifiers, IP addresses, cookies, and transaction metadata carefully, especially in fraud and digital-banking systems.
6. CJEU, Rīgas satiksme, Case C-13/16
Facts: An organisation sought personal information held by another entity to pursue a civil claim.
Legal Issue: Whether data-protection law required disclosure.
Principle: Personal-data rules require a balance between privacy, necessity, and the legitimate interests of others; disclosure is not automatic.
Importance: Banks must carefully assess requests from insurers, creditors, law-enforcement bodies, and other third parties before sharing customer information.
Conclusion
Data governance is a central part of banking governance in Spain. A bank must ensure that its data is lawful, accurate, secure, explainable, and available to the right people for the right purpose. The strongest framework combines board oversight, clear data ownership, robust cybersecurity, vendor controls, reliable automated-decision safeguards, and documented accountability.
Spanish banks that treat data merely as a technical asset risk regulatory action, customer claims, operational losses, and reputational harm. Effective data governance instead supports safer lending, trustworthy digital banking, accurate reporting, and stronger customer protection.

comments