Banking Law And Identity And Access Management In Financial Institutions Kuwait .

Banking Law and Identity Formation in Finance — Spain

1. Meaning of Identity Formation in Finance

“Identity formation in finance” refers to the legal and operational process through which a Spanish bank or financial institution:

  • Determines who a customer really is.
  • Verifies the customer’s identity using reliable documents or electronic methods.
  • Connects that verified identity to a bank account, loan, payment instrument, investment account, insurance product, or other financial service.
  • Identifies the natural person who ultimately owns or controls a company.
  • Creates and maintains a reliable customer profile.
  • Updates the identity information throughout the business relationship.
  • Prevents impersonation, identity theft, money laundering, fraud, and misuse of financial accounts.

Identity formation is therefore broader than merely collecting a name and identity-card number. It includes documentary verification, beneficial-ownership checks, electronic authentication, risk classification, transaction monitoring, record retention, and correction of inaccurate identity data.

2. Main Legal Framework in Spain

2.1 Law 10/2010 on Money Laundering and Terrorist Financing

Law 10/2010 is the central Spanish law governing customer identification in banking and finance.

Banks, payment institutions, investment firms, insurers and other regulated entities must identify customers before:

  • Establishing a continuing business relationship.
  • Opening an account.
  • Granting credit.
  • Executing certain occasional transactions.
  • Providing payment or investment services.
  • Allowing a person to act on behalf of another customer.

The institution must not establish the relationship when it cannot complete the required identification and verification.

The law distinguishes between:

  1. Formal identity – the legal identity shown through official documents.
  2. Beneficial ownership – the natural person who ultimately owns, controls or benefits from the relationship.
  3. Purpose of the relationship – why the account or service is required.
  4. Economic and professional profile – the expected source and nature of funds.
  5. Ongoing identity – whether the customer’s information remains accurate throughout the relationship.

2.2 Royal Decree 304/2014

Royal Decree 304/2014 develops the practical requirements of Law 10/2010.

For Spanish individuals, the DNI is normally the principal identity document. For foreign nationals, acceptable documents may include:

  • Foreigner Identity Card.
  • Passport.
  • Official identity document issued by another country.
  • Other documents recognised under Spanish rules.

For legal persons, the institution normally examines:

  • Incorporation documents.
  • Commercial Registry information.
  • Tax identification number.
  • Registered office.
  • Governing body and authorised representatives.
  • Ownership and control structure.
  • Powers of attorney.
  • Beneficial ownership declarations and supporting evidence.

A bank cannot rely only on the fact that a company is registered. It must determine which natural person ultimately controls or benefits from the company.

2.3 Central Register of Beneficial Ownership

Royal Decree 609/2023 established Spain’s Central Register of Beneficial Ownership.

Financial institutions use beneficial-ownership information when identifying companies and other legal arrangements. However, a register entry does not automatically discharge the bank’s responsibility. If information appears incomplete, outdated or inconsistent, the bank must conduct additional checks.

This is especially important where:

  • Ownership passes through several companies.
  • Foreign entities are involved.
  • Nominee shareholders or directors are used.
  • A trust or similar arrangement appears in the structure.
  • Control exists through voting agreements rather than direct share ownership.
  • The declared owner does not appear to exercise genuine control.

2.4 GDPR and Organic Law 3/2018

Identity formation requires extensive processing of personal data. Consequently, the General Data Protection Regulation and Spain’s Organic Law 3/2018 apply.

Banks must comply with principles including:

  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitation.
  • Security and confidentiality.
  • Accountability.

A bank may process identity data without consent where processing is necessary to comply with its legal duties, such as anti-money-laundering verification. Nevertheless, the bank cannot collect unlimited information merely because identification is required.

For example, there is an important difference between:

  • Inspecting an identity document.
  • Recording necessary identity details.
  • Retaining a complete copy of the document.
  • Using the document for biometric analysis.
  • Reusing the information for marketing or profiling.

Each additional use needs an appropriate legal basis.

2.5 eIDAS and Spanish Law 6/2020

The European electronic identification framework, commonly known as eIDAS, regulates:

  • Electronic identification.
  • Electronic signatures.
  • Electronic seals.
  • Electronic timestamps.
  • Registered electronic delivery.
  • Trust services.

Spanish Law 6/2020 supplements the European rules on electronic trust services.

An electronic signature does not automatically prove that the real customer personally entered into the transaction. Its evidential value depends on matters such as:

  • The type of electronic signature.
  • How the signature credentials were issued.
  • Whether the signatory had exclusive control.
  • The strength of the authentication process.
  • Whether the document was altered.
  • Whether credentials were stolen or misused.
  • Whether the bank complied with security requirements.

A qualified electronic signature normally receives the strongest legal recognition, but courts may still examine allegations of fraud or identity theft.

2.6 Payment Services Law

Royal Decree-Law 19/2018 governs payment services in Spain and implements the revised Payment Services Directive.

Banks must use strong customer authentication in circumstances such as:

  • Access to online banking.
  • Initiation of an electronic payment.
  • Performance of an action presenting a risk of fraud.

Strong customer authentication generally combines at least two independent elements from:

  • Knowledge: something the customer knows.
  • Possession: something the customer possesses.
  • Inherence: something physically characteristic of the customer.

The bank must distinguish between identifying the customer during onboarding and authenticating that customer during later transactions.

3. Stages of Financial Identity Formation

Stage 1: Collection of Identity Information

The institution obtains basic information such as:

  • Full legal name.
  • Date and place of birth.
  • Nationality.
  • Address.
  • DNI, NIE, passport or equivalent number.
  • Tax identification details.
  • Occupation or business activity.
  • Contact information.

For companies, the institution also gathers corporate identity, ownership, directors and representation information.

Stage 2: Verification

The information must be checked against reliable and independent sources. A document should be valid, authentic and connected to the person presenting it.

Verification may involve:

  • Physical examination of an identity document.
  • Electronic verification of document security features.
  • Comparison with official databases.
  • Video-identification procedures.
  • Qualified electronic certificates.
  • Biometric facial comparison.
  • Confirmation through an existing regulated institution.

Automated verification should not be treated as infallible. The bank remains responsible for assessing false matches, manipulated documents and impersonation risks.

Stage 3: Authority and Representation

If a person acts for another individual or company, the institution must verify:

  • The representative’s identity.
  • The identity of the represented person.
  • The existence and scope of the authority.
  • Whether the authority remains valid.
  • Whether the proposed transaction falls within that authority.

Possession of an identity document does not itself establish authority to operate another person’s account.

Stage 4: Beneficial-Owner Identification

For corporate customers, the bank must look beyond the named company. It must identify the natural person who ultimately owns or controls it.

As a general principle, ownership or control of more than 25% may indicate beneficial ownership. Control can also arise indirectly or through other means.

If no natural person can be identified through ownership or control, the institution may ultimately record the senior managing official, but only after taking reasonable measures and documenting why no other beneficial owner could be determined.

Stage 5: Customer Risk Profile

The institution then builds a financial identity or risk profile based on:

  • Occupation or commercial activity.
  • Source of funds.
  • Expected transactions.
  • Countries involved.
  • Ownership structure.
  • Delivery channel.
  • Use of cash or digital assets.
  • Political exposure.
  • Sanctions-related risks.

The profile helps the institution decide whether simplified, standard or enhanced due diligence is appropriate.

Stage 6: Ongoing Monitoring

Identity formation continues after onboarding. The institution must verify that transactions remain consistent with the customer’s known profile.

Information may need to be updated when:

  • An identity document expires.
  • The customer changes address.
  • Company ownership changes.
  • A new representative is appointed.
  • Transactions differ materially from the expected activity.
  • Adverse information becomes available.
  • The customer becomes a politically exposed person.
  • The institution detects possible impersonation.

4. Remote and Digital Identity Formation

Spanish financial institutions may onboard customers remotely, but remote onboarding creates additional risks.

A compliant system should generally include:

  • High-quality document capture.
  • Verification of security features.
  • Detection of forged or altered documents.
  • Liveness testing where facial recognition is used.
  • Comparison between the customer and the identity document.
  • Protection against deepfakes and replay attacks.
  • Secure recording of the identification process.
  • Human review of doubtful cases.
  • Procedures for customers who cannot use biometric tools.
  • Fraud escalation mechanisms.

Video identification must follow applicable Spanish anti-money-laundering requirements and supervisory authorisations or guidance.

A successful facial match alone does not prove lawful identity formation. The institution must also verify the document, assess the surrounding risk and ensure that the person has legal capacity and genuine intention to enter into the contract.

5. Biometric Identity

Banks increasingly use facial recognition, voice recognition and behavioural biometrics.

Biometric information used for uniquely identifying a person is special-category personal data under the GDPR. Its processing requires both:

  1. A general legal basis under Article 6 of the GDPR; and
  2. A separate condition under Article 9.

A bank should therefore establish:

  • Whether biometric identification is genuinely necessary.
  • Whether a less intrusive alternative exists.
  • How biometric templates are stored.
  • How false positives and false negatives are managed.
  • Whether a data-protection impact assessment is required.
  • Whether the customer can access a non-biometric channel.
  • When biometric data will be deleted.
  • Whether external technology providers receive the data.

Consent may not always be appropriate where the customer has no realistic alternative to biometric verification.

6. Identity Fraud and Bank Responsibility

Identity fraud can occur when a criminal:

  • Uses a stolen DNI or passport.
  • Alters an identity document.
  • Opens an account in another person’s name.
  • Obtains a loan through impersonation.
  • Takes control of a telephone number.
  • Intercepts one-time passwords.
  • Uses synthetic or partially fabricated identity information.
  • Manipulates video-identification systems.
  • Uses a money mule as the nominal account holder.

The bank is not automatically liable for every successful fraud. Liability normally depends on whether it applied appropriate legal, technical and organisational measures.

Relevant questions include:

  • Was the identity document properly checked?
  • Were obvious inconsistencies ignored?
  • Did the bank rely on a weak copy of a document?
  • Was strong customer authentication applied?
  • Did the bank respond to fraud warnings?
  • Was the customer grossly negligent?
  • Can the bank prove authentication and authorisation?
  • Were personal data reported to credit databases despite a genuine identity dispute?

A technical record showing that credentials were used does not conclusively prove that the legitimate customer authorised the transaction.

7. Relationship with Creditworthiness and Automated Profiling

Financial identity formation may lead to credit scoring, fraud scoring and automated customer classification.

The institution must distinguish between:

  • Identity verification.
  • Fraud prevention.
  • Creditworthiness assessment.
  • Anti-money-laundering risk assessment.
  • Marketing profiling.

These activities may use overlapping data, but they do not necessarily have the same legal basis.

If an automated score effectively determines whether a person receives credit, Article 22 of the GDPR may apply. The customer may be entitled to:

  • Meaningful information about the logic involved.
  • Human intervention.
  • An opportunity to express their position.
  • A procedure for challenging incorrect information.
  • Correction of inaccurate identity or credit data.

Important Case Laws

1. Jyske Bank Gibraltar Ltd v Administración del Estado

CJEU, Case C-212/11, judgment of 25 April 2013

Jyske Bank operated from Gibraltar but provided services in Spain. Spanish authorities required it to provide information concerning transactions carried out in Spain for anti-money-laundering purposes.

The Court held that, under certain conditions, Spain could require a financial institution operating through cross-border services to provide information directly to the Spanish financial intelligence authority.

Importance: Financial identity information cannot always remain only with the institution’s home-state authority. Spain may require access to customer and transaction information when necessary to combat money laundering, subject to proportionality and EU law.

2. Safe Interenvíos SA v Liberbank SA and Others

CJEU, Case C-235/14, judgment of 10 March 2016

Safe Interenvíos transferred money for customers. Several banks closed or restricted its accounts because of money-laundering concerns.

The Court accepted that banks may apply enhanced customer due diligence to another regulated financial institution when justified by risk. However, measures cannot be automatic, discriminatory or disproportionate.

Importance: A bank cannot treat an entire category of customers as suspicious without an individual assessment. Identity and risk formation must be evidence-based. Account closure should follow a documented evaluation of the specific customer and its operations.

3. Orange România SA v Romanian Data Protection Authority

CJEU, Case C-61/19, judgment of 11 November 2020

Customers’ identity documents had been copied and retained in connection with service contracts. The Court examined whether the customers had validly consented.

It held that the controller must prove that consent was freely given, specific, informed and unambiguous. Pre-selected clauses and contractual arrangements that make refusal unnecessarily difficult do not establish valid consent.

Importance in Spanish finance: A signature on an account-opening form does not automatically prove valid consent to every form of identity-document copying or reuse. Banks must separate legally required identification from optional data uses.

4. Patrick Breyer v Germany

CJEU, Case C-582/14, judgment of 19 October 2016

The Court held that information may constitute personal data where the controller has legal means reasonably likely to be used to identify the individual, even if the information does not identify that person by itself.

Importance: Device identifiers, online-session data, IP addresses and related digital traces used in remote banking may form part of a customer’s identifiable financial identity. They must be protected under data-protection law.

5. Nowak v Data Protection Commissioner

CJEU, Case C-434/16, judgment of 20 December 2017

The Court adopted a broad understanding of personal data. Information is personal data when it relates to a person by reason of its content, purpose or effect.

Importance: Identity formation includes more than names and document numbers. A bank’s verification notes, fraud indicators, risk assessments and conclusions about a customer may constitute personal data. Customers may have rights of access and correction, although anti-money-laundering restrictions may limit disclosure in particular circumstances.

6. SCHUFA Holding — Automated Credit Scoring

CJEU, Case C-634/21, judgment of 7 December 2023

The case concerned automated credit scoring. The Court held that producing a probability score can constitute an automated individual decision where a lender gives the score a determining role in deciding whether to grant credit.

Importance: Once a verified identity is connected to a financial profile, the bank cannot treat automated scoring as legally neutral. Where a score effectively controls access to credit, protections relating to automated decision-making may apply.

7. SCHUFA Holding — Retention of Insolvency Information

Joined CJEU Cases C-26/22 and C-64/22, judgments of 7 December 2023

The Court examined the retention of personal insolvency information by a private credit-information agency after the information had been removed from the relevant public register.

It held that private retention cannot automatically continue for longer than justified merely because the information was once lawfully public.

Importance: Financial identity is not permanent in every respect. Historical adverse information must not remain attached to a person indefinitely without a lawful and proportionate basis. Erasure, accuracy and storage-limitation principles remain applicable.

8. Österreichische Post — Identification of Data Recipients

CJEU, Case C-154/21, judgment of 12 January 2023

The Court held that a person exercising the GDPR right of access is generally entitled to know the actual identities of recipients to whom personal data were disclosed, rather than receiving only broad categories of recipients.

Importance: A banking customer may be entitled to know which credit agencies, service providers or other recipients received identity data, unless identifying them is impossible or the request is manifestly unfounded or excessive.

9. UI v Österreichische Post — GDPR Compensation

CJEU, Case C-300/21, judgment of 4 May 2023

The Court ruled that a GDPR infringement alone does not automatically create a right to compensation. The claimant must show infringement, damage and a causal connection. However, EU law does not require a minimum level of seriousness for non-material damage.

Importance: A person whose identity has been wrongly connected to an account, debt or credit record may claim compensation if actual material or non-material damage can be established.

10. AEPD Proceedings Concerning Fraudulent BBVA Account Opening

Spanish Data Protection Authority, proceeding EXP202313731

The proceeding concerned the opening of a bank account through alleged identity impersonation. It demonstrates the practical importance of verifying that the person opening an account is genuinely the holder of the identity data used.

Importance: If a bank creates a financial identity without sufficient verification, it may process inaccurate data without a valid legal basis and expose the impersonated person to debts, fraud investigations or adverse credit consequences.

Although an AEPD decision is an administrative enforcement decision rather than a judgment of the Supreme Court, it is highly relevant to the practical application of Spanish financial identity and data-protection obligations.

8. Rights of the Customer

A customer generally has the right to:

  • Receive information about the processing of identity data.
  • Access personal data held by the institution.
  • Correct inaccurate identity information.
  • Challenge an account or debt created through impersonation.
  • Request restriction of disputed processing.
  • Seek deletion where retention is no longer lawful.
  • Object to certain forms of profiling.
  • Request human review of qualifying automated decisions.
  • Submit a complaint to the Spanish Data Protection Authority.
  • Seek compensation for proven damage.
  • Report identity fraud to the police or Civil Guard.

However, the right to deletion is not absolute. Banks may retain identity and transaction records where anti-money-laundering, tax, accounting, payment-services or litigation rules require preservation.

9. Duties of Financial Institutions

A Spanish financial institution should maintain:

  1. A written customer-identification policy.
  2. Procedures for physical and remote onboarding.
  3. Document-authenticity controls.
  4. Beneficial-ownership verification.
  5. Procedures for representatives and powers of attorney.
  6. Enhanced checks for high-risk customers.
  7. Politically exposed person screening.
  8. Sanctions screening.
  9. Strong customer authentication.
  10. Fraud and identity-theft response procedures.
  11. Periodic updating of customer information.
  12. Data-retention and deletion schedules.
  13. Human review of automated alerts.
  14. Procedures for correcting identity mistakes.
  15. Vendor controls for biometric and identity-verification providers.

Outsourcing identification technology does not transfer the bank’s legal responsibility to the service provider.

10. Consequences of Defective Identity Formation

Failure to create and verify identity properly may produce:

  • Anti-money-laundering sanctions.
  • Data-protection fines.
  • Payment-services liability.
  • Civil claims for damages.
  • Invalid or disputed contracts.
  • Unlawful reporting to credit databases.
  • Regulatory intervention by the Bank of Spain.
  • Criminal investigations.
  • Reputational damage.
  • Financial exclusion of legitimate customers.
  • Facilitation of money laundering or terrorist financing.

The institution may face liability both for insufficient verification and for excessive data collection. Spanish law requires a proportionate balance: enough information to establish a reliable financial identity, but not unnecessary or indefinite surveillance.

Conclusion

Identity formation in Spanish finance is a continuing legal process rather than a single document check. It begins with formal identification, extends to beneficial ownership and customer-risk assessment, and continues through authentication, transaction monitoring and periodic updating.

The Spanish framework requires banks to reconcile four major objectives:

  • Preventing money laundering and identity fraud.
  • Ensuring that financial contracts are attributable to the correct person.
  • Protecting personal and biometric data.
  • Preserving fair access to banking and credit.

A compliant institution must be able to demonstrate not merely that it collected identity information, but that it verified the information through reliable, proportionate and secure procedures. It must also correct the financial record promptly when identity theft, inaccurate attribution or unlawful profiling is established.

LEAVE A COMMENT