Banking Law And Ecosystem Banking Governance Spain .

Banking Law and Ecosystem Banking Governance in Spain

Introduction

Ecosystem banking governance concerns the legal control of interconnected financial networks involving banks, fintech companies, payment institutions, technology providers, digital platforms, data intermediaries, insurers and investment firms. Unlike traditional banking, where most services were produced inside one institution, ecosystem banking distributes activities across numerous entities connected through outsourcing agreements, application programming interfaces, cloud systems and shared databases.

In Spain, this model can improve innovation, competition and financial inclusion. However, it also creates governance risks. A bank may remain legally responsible to customers and regulators even when an external company performs identity verification, credit scoring, payment processing or data storage. Spanish banking law therefore requires clear accountability, effective risk management and continuous regulatory oversight throughout the ecosystem.

Legal and Regulatory Framework

Law 10/2014 on the organisation, supervision and solvency of credit institutions is the central Spanish banking statute. It regulates authorisation, qualifying holdings, corporate governance, internal controls, remuneration and prudential supervision. Royal Decree 84/2015 develops many of its requirements.

Significant Spanish banks are directly supervised by the European Central Bank under the Single Supervisory Mechanism. Less significant institutions are primarily supervised by the Bank of Spain within the common European framework.

EU Regulation 575/2013 establishes capital, liquidity and exposure requirements. Directive 2013/36/EU provides rules on authorisation, governance and prudential supervision. Their newer amendments reinforce management-body accountability, third-country branch regulation and environmental, social and governance risk management.

The Payment Services framework, implemented in Spain principally through Royal Decree-Law 19/2018, supports open banking and regulated access to payment-account information. Banks must permit authorised third-party providers to access information or initiate payments when the customer gives valid consent.

The Digital Operational Resilience Act establishes harmonised requirements for information and communication technology risk, incident reporting, resilience testing and third-party oversight. The General Data Protection Regulation and Organic Law 3/2018 regulate the processing, sharing and security of personal information.

Governance Responsibilities

The management body remains responsible for the bank’s overall strategy and risk profile. It must understand how ecosystem relationships affect credit, liquidity, operational, cyber, legal and reputational risks. Directors cannot avoid responsibility merely because a function has been outsourced.

A bank should maintain a complete register of external providers, contractual dependencies, data transfers and subcontracting chains. Critical arrangements require detailed due diligence before appointment and continuing monitoring afterward.

Contracts with technology providers should address:

  • Service standards and security requirements;
  • Regulatory access and audit rights;
  • Incident reporting and cooperation;
  • Data location, confidentiality and portability;
  • Subcontracting restrictions;
  • Business continuity and disaster recovery;
  • Termination assistance and exit arrangements.

Where several institutions rely on the same cloud provider, payment processor or identity service, an operational failure can affect the entire financial system. Ecosystem governance must consequently assess concentration risk as well as the individual bank’s contractual position.

Open Banking, Data and Customer Protection

Open banking allows customers to share account information with authorised providers. Banks must verify that third parties have the necessary regulatory status, but they should not create unjustified obstacles that prevent lawful market access.

Customer consent must be specific, informed and capable of being withdrawn. Data obtained for payment initiation should not automatically be used for unrelated advertising or credit profiling. Banks and their partners must determine whether each participant acts as a controller, joint controller or processor under data-protection law.

Customers should also receive clear information about which entity provides each service. A digital interface must not create the misleading impression that an unregulated product is protected as a bank deposit. Complaint procedures must remain accessible even when services pass through several connected providers.

Automated lending and personalised pricing require additional safeguards. Banks should test algorithms for inaccurate information, unlawful discrimination and unexplained outcomes. Human oversight is particularly important where an automated decision has serious effects on a customer.

Prudential Supervision and Resolution

Supervisors assess ecosystem risks through the Supervisory Review and Evaluation Process. They may require additional controls, capital, liquidity or remediation where outsourcing and interconnectedness increase institutional risk.

Banks must also prepare recovery plans identifying how critical services will continue during financial stress. Resolution authorities must determine whether outsourced technology, payment infrastructure and customer information can be transferred to another institution. Contracts that permit immediate termination solely because a bank enters resolution may undermine continuity and require regulatory treatment.

Relevant Case Laws

1. Landeskreditbank Baden-Württemberg v ECB, Case C-450/17 P

The Court of Justice confirmed the ECB’s central authority within the Single Supervisory Mechanism. National supervision operates inside an integrated European system. The decision is relevant to Spanish ecosystem governance because risks crossing institutions or borders may require coordinated ECB and Bank of Spain action.

2. Berlusconi and Fininvest v Banca d’Italia, Case C-219/17

This judgment concerned the judicial review of national preparatory measures leading to an ECB decision on a qualifying holding. It demonstrates that ownership and control within banking ecosystems are subject to a unified European authorisation procedure.

3. Crédit Mutuel Arkéa v ECB, Cases T-712/15 and T-52/16

The General Court examined consolidated supervision within a banking group. It recognised the importance of assessing the economic and organisational relationships connecting affiliated entities. The case is relevant where ecosystem participants form an operational network despite retaining separate legal personalities.

4. Wirtschaftsakademie Schleswig-Holstein, Case C-210/16

The Court held that an organisation operating a social-media page could be jointly responsible for data processing with the platform provider. By analogy, a Spanish bank cannot always avoid data-protection responsibility merely because a fintech or technology platform technically processes customer information.

5. Fashion ID GmbH v Verbraucherzentrale NRW, Case C-40/17

A website operator using a third-party digital component could be a joint controller for stages of data collection and transmission. The judgment is important when banking applications embed external analytics, identification, payment or marketing services.

6. Tietosuojavaltuutettu v Jehovan todistajat, Case C-25/17

The Court adopted a functional approach to joint controllership. Participants do not need equal access to every item of data to share responsibility. This principle assists in allocating obligations among banks, fintech firms and platform operators.

7. Bundesverband der Verbraucherzentralen v Planet49, Case C-673/17

The Court ruled that valid consent cannot be obtained through pre-selected boxes and must be active and informed. The principle applies to open-banking permissions, cookies, digital marketing and the sharing of financial information.

8. Aeris Invest v Commission and SRB, Case T-628/17

This case concerned the resolution of Banco Popular Español. The General Court examined urgency, valuation, public interest and procedural protection. It demonstrates why ecosystem governance must ensure that critical payments, information and outsourced operations remain available during a bank resolution.

Conclusion

Spanish ecosystem banking governance combines traditional prudential regulation with rules on payments, outsourcing, data protection, digital resilience and resolution. Its central principle is that accountability follows the regulated bank even when operational tasks are distributed among external providers.

Effective governance requires transparent responsibility, management-body oversight, lawful data sharing, resilient technology and credible exit planning. As banking ecosystems become more interconnected, supervision must address not only the safety of individual institutions but also the concentration and contagion risks created by shared digital infrastructure.

 

 

LEAVE A COMMENT