Banking Law And Ecosystem Contracting Spain .

 

Banking Law and Ecosystem Contracting in Spain

Introduction

Banking ecosystem contracting concerns agreements through which banks collaborate with fintech companies, payment institutions, cloud providers, data companies, digital platforms, insurers, telecommunications operators, and other commercial partners. Instead of supplying every financial service internally, a Spanish bank may operate through interconnected contractual arrangements involving payment initiation, account-information services, embedded finance, identity verification, credit scoring, cybersecurity, software infrastructure, and customer support.

These arrangements can improve innovation and customer access. However, they also create operational, legal, and systemic risks. A bank cannot transfer its regulatory responsibility simply by outsourcing a function or describing another company as an independent technology provider. Spanish and European banking law therefore require careful allocation of responsibility, access rights, security obligations, data controls, audit powers, and termination procedures.

Legal and Regulatory Framework

Spanish banking ecosystems are primarily governed by Law 10/2014 on the organisation, supervision, and solvency of credit institutions. It requires banks to maintain effective governance, risk management, internal controls, and organisational arrangements. The Bank of Spain supervises these obligations, while significant Spanish banks are directly supervised by the European Central Bank under the Single Supervisory Mechanism.

General contractual questions are governed by the Spanish Civil Code and Commercial Code. Contracts require valid consent, a lawful object, and a lawful cause. Parties must perform their obligations in good faith. Contractual freedom remains subject to mandatory banking, consumer, competition, payment-services, data-protection, and cybersecurity rules.

Royal Decree-Law 19/2018, implementing the Second Payment Services Directive, regulates agreements involving payment initiation, account-information services, authentication, execution of payments, unauthorised transactions, and access to payment accounts. A bank cannot use ecosystem contracts to deprive customers of mandatory payment-service protections.

The Digital Operational Resilience Act applies directly to Spanish financial entities. It establishes detailed requirements for contracts with information and communication technology providers. Agreements must address service descriptions, data locations, security, incident assistance, audit and inspection rights, subcontracting, business continuity, recovery, and termination.

Major Forms of Ecosystem Contracting

Fintech and embedded-finance agreements

Banks may allow fintech companies or digital platforms to offer payment accounts, credit, cards, or other services within non-bank applications. The contract must identify which entity supplies the regulated service, communicates with the customer, completes regulatory disclosures, handles complaints, and bears responsibility for errors.

A commercial partner must not perform regulated banking or payment activities without the required authorisation. Branding must also avoid misleading customers about which entity holds their funds or provides credit.

Open-banking and API contracts

Banks must provide regulated payment-service providers with access to payment accounts under the applicable legal conditions. Technical agreements may cover application programming interfaces, security certificates, service levels, fraud controls, and incident reporting.

Contractual provisions must not create unjustified obstacles to account access. A bank may impose proportionate security measures, but it cannot use technical standards to favour its own payment application or exclude competing providers.

Cloud and technology outsourcing

Cloud arrangements may involve customer databases, payment processing, risk models, fraud monitoring, or core banking functions. Before entering such an agreement, the bank must assess concentration risk, provider solvency, information security, data location, subcontracting chains, and the practical possibility of moving services to another provider.

The bank must retain effective access, audit, monitoring, and termination rights. Supervisory authorities must also be able to inspect outsourced functions and obtain necessary information.

Key Contractual Requirements

A well-governed ecosystem contract should contain:

  • A precise description of services and responsibilities;
  • Compliance with banking and payment-services law;
  • Confidentiality and banking-secrecy obligations;
  • Personal-data processing instructions;
  • Cybersecurity and authentication requirements;
  • Incident notification and regulatory cooperation;
  • Service levels and performance indicators;
  • Audit, access, testing, and inspection rights;
  • Controls over subcontracting;
  • Data portability and return obligations;
  • Business-continuity and disaster-recovery procedures;
  • Complaint-handling and customer-remediation rules;
  • Termination rights and an orderly exit plan.

The agreement should also prevent the provider from using customer data for unrelated advertising, profiling, or product development without a lawful basis.

Consumer and Data Protection

The General Data Protection Regulation and Spanish Organic Law 3/2018 apply where ecosystem partners process personal data. The bank must determine whether the provider is a processor, joint controller, or independent controller. This classification depends on actual decision-making power, not merely the contractual label.

Consumers must receive clear information about charges, responsibilities, data use, and complaint channels. Terms must comply with Spain’s consumer-protection legislation and the Unfair Contract Terms Directive. Clauses permitting unilateral service changes, unlimited exclusion of liability, or unrestricted data transfers may be unenforceable.

Case Laws

1. DenizBank AG v Verein für Konsumenteninformation, C-287/19

The Court of Justice examined contactless card payments and contractual changes under payment-services law. It confirmed that payment products must be classified according to their actual operation. Ecosystem contracts cannot use technical descriptions to avoid mandatory consumer protections.

2. Bundesverband der Verbraucherzentralen v Deutsche Kreditbank, C-602/19

The Court considered whether information placed in an electronic banking mailbox had been supplied on a durable medium. The judgment shows that digital contractual notices must be accessible, storable, and effectively communicated to customers.

3. Content Services Ltd v Bundesarbeitskammer, C-49/11

The Court held that merely providing information through a website did not necessarily satisfy the durable-medium requirement. Spanish banking platforms must deliver mandatory contractual information in a form customers can retain without unilateral alteration.

4. Verein für Konsumenteninformation v Amazon EU, C-191/15

The Court examined choice-of-law clauses in cross-border consumer contracts. An ecosystem agreement cannot mislead Spanish consumers into believing that foreign law removes mandatory protections available under their country’s law.

5. Data Protection Commissioner v Facebook Ireland and Schrems, C-311/18

The Court invalidated the EU-US Privacy Shield and required effective protection for international data transfers. Spanish banks using global cloud providers must examine transfer mechanisms, foreign-government access, safeguards, and supplementary security measures.

6. Orange România, C-61/19

The Court ruled that data-processing consent must be freely given, specific, informed, and demonstrated by the controller. Preselected clauses or unnecessary identity-document practices cannot establish valid consent within a banking ecosystem.

7. Wirtschaftsakademie Schleswig-Holstein, C-210/16

The Court recognised that multiple organisations may become joint controllers where they jointly influence the purposes and means of processing. Banks and platform partners cannot avoid data responsibility merely by assigning all liability to one party contractually.

8. CaixaBank France v Commission, C-442/02

The Court considered restrictions affecting banking market access and emphasised the importance of cross-border competition. The decision supports scrutiny of ecosystem arrangements that unjustifiably restrict financial providers from entering or competing in a national market.

Liability and Regulatory Consequences

Contractual allocation of liability operates between the parties but does not eliminate statutory responsibility toward customers or regulators. A bank may remain liable for an outsourced provider’s failure where the service forms part of the bank’s regulated activity.

Breaches may result in administrative sanctions, customer compensation, contractual damages, corrective orders, restrictions on outsourcing, or termination of the arrangement. Serious operational failures may also lead to capital measures or supervisory intervention.

Conclusion

Banking ecosystem contracting in Spain enables innovation but cannot become a method of regulatory avoidance. Banks must understand their providers, preserve supervisory access, protect customer data, ensure service continuity, and maintain clear accountability.

The strongest contracts combine commercial flexibility with detailed compliance, audit, security, consumer-remediation, subcontracting, and exit provisions. Ultimate responsibility remains with the regulated institution whenever the outsourced or partnered service forms part of its banking operations.

LEAVE A COMMENT