Banking Law And Data-Sharing Agreements Spain .
Banking Law And Data-Sharing Agreements Spain
Introduction
Data-sharing agreements are essential in Spanish banking because banks regularly exchange customer, transaction, credit, fraud, and compliance data with payment providers, fintech companies, cloud vendors, credit bureaux, group entities, regulators, and public authorities. These arrangements can improve lending decisions, fraud prevention, anti-money-laundering controls, and digital payment services. However, financial data is highly sensitive. A bank cannot share it merely because sharing is commercially useful.
In Spain, data-sharing agreements must comply mainly with the General Data Protection Regulation (GDPR), Spain’s Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), banking confidentiality duties, consumer-protection rules, and sectoral rules such as anti-money-laundering law and payment-services regulation. The agreement must clearly identify why data is shared, which party controls the processing, what security safeguards apply, and when the data must be deleted.
Legal and Regulatory Framework
The GDPR is directly applicable in Spain and is the central legal framework. It requires every processing activity, including disclosure of banking data, to have a lawful basis under Article 6. Common bases include performance of a banking contract, compliance with a legal obligation, legitimate interests, protection against fraud, and consent. Consent is not always appropriate because customers may feel unable to refuse a service offered by their bank.
The LOPDGDD supplements the GDPR in Spain. It regulates national enforcement, employee-data issues, digital rights, sanctions, and procedural matters. The Spanish Data Protection Agency, known as the AEPD, investigates complaints and can impose corrective measures and administrative fines.
A bank must also respect confidentiality obligations under Spanish banking law and its contractual relationship with the customer. A lawful GDPR basis does not automatically remove banking confidentiality. Before sharing, the bank should assess whether the disclosure is necessary, proportionate, transparent, and consistent with customer expectations.
Where the bank engages a technology company, cloud provider, analytics company, or outsourced service provider only to process data on the bank’s instructions, the provider is generally a processor. Article 28 GDPR requires a written data-processing agreement. It must specify the subject matter, duration, nature, purpose, data categories, and categories of data subjects. It must also require confidentiality, security measures, assistance with data-subject rights, breach support, return or deletion of data, and audit rights.
If two parties jointly decide why and how the data will be used, they may be joint controllers under Article 26 GDPR. Their agreement must transparently allocate GDPR responsibilities, especially notices, consent management where needed, responses to customers, security, and contact points. Calling one party a “processor” does not determine its legal status; the real role and decision-making power matter.
Data Sharing in Banking Practice
Banks often share data within their corporate group for risk management, customer administration, cyber-security, or anti-fraud activity. Such sharing requires a documented legal basis and must follow the purpose-limitation principle. Data collected for account management cannot automatically be reused for unrelated marketing, profiling, or sale to third parties.
Open-banking arrangements require special care. Under PSD2, where a customer authorises an account-information service provider or payment-initiation service provider, the bank must provide access through secure channels. The bank should share only the information necessary for the requested service. It should not use the access as an opportunity to disclose extra customer data, including data concerning other account holders.
Credit reporting and lending arrangements also involve substantial risk. Before sending information to a credit bureau or receiving third-party credit data, the bank should ensure accuracy, relevance, necessity, retention limits, and transparent customer information. Incorrect credit data can affect access to loans, mortgages, cards, and employment-related financial checks.
Anti-money-laundering obligations may require disclosure to Spanish authorities, including SEPBLAC. In this area, the legal obligation provides the principal basis for sharing. Nevertheless, the bank should disclose only what the law requires, preserve secure records, and avoid impermissible “tipping off” to the customer.
Essential Terms of a Data-Sharing Agreement
A strong agreement should contain the following protections:
- Clear classification of each party as controller, joint controller, or processor.
- Precise description of the data, purpose, legal basis, systems, and permitted recipients.
- A prohibition on using customer data for independent commercial purposes without a separate legal basis.
- Encryption, access controls, staff confidentiality, logging, testing, and incident-response requirements.
- A duty to notify the bank promptly of a personal-data breach and to assist with investigations.
- Rules for responding to access, rectification, erasure, objection, and portability requests.
- Limits on sub-processors and a prior approval or notice mechanism.
- Retention periods, secure deletion, and return of data at termination.
- Audit, inspection, and evidence rights for the bank.
- Special safeguards for international transfers outside the European Economic Area.
For transfers to a non-EEA country, the parties must use a valid GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, together with a transfer-impact assessment and supplementary technical safeguards where required.
Case Laws
Google Spain SL, Google Inc. v AEPD and Mario Costeja González (C-131/12): The Court confirmed that EU data-protection rules can apply to companies operating through an establishment in Spain. It strengthened practical protection for Spanish individuals and supports the AEPD’s enforcement role.
Wirtschaftsakademie Schleswig-Holstein (C-210/16): The Court held that an organisation using a social-media page could be a joint controller with the platform. In banking, a fintech partnership may similarly create joint-controller duties where both parties influence purposes and means.
Fashion ID GmbH & Co. KG (C-40/17): The Court stated that responsibility can arise at the stage of collecting and transmitting data, even where a party does not control later processing. Banks must assess responsibility at every stage of a data-sharing chain.
Planet49 GmbH (C-673/17): Consent must be active, informed, and specific; pre-ticked boxes are insufficient. A bank cannot rely on vague or bundled consent for marketing or optional data-sharing.
Data Protection Commissioner v Facebook Ireland and Schrems (C-311/18) – Schrems II: The Court invalidated Privacy Shield and required effective protection for international transfers using contractual clauses. Spanish banks must assess foreign surveillance and access risks before overseas data transfers.
Facebook Ireland Ltd v Bundesverband der Verbraucherzentralen (C-319/20): The judgment recognised the importance of consumer bodies in enforcing GDPR-linked rights. Poor privacy information in banking services may therefore create both regulatory and consumer-law exposure.
Österreichische Post AG (C-154/21): The Court held that a data subject can request the actual identity of recipients of personal data, not merely broad recipient categories. Banks should maintain accurate records of every recipient.
Conclusion
Spanish banks should treat data-sharing agreements as governance documents, not routine vendor paperwork. A lawful agreement requires correct role allocation, a specific purpose, a valid legal basis, strong security, customer transparency, and controlled international transfers. If the arrangement is unclear or data is reused beyond its original purpose, the bank may face AEPD action, customer claims, contractual disputes, reputational damage, and regulatory scrutiny.

comments