Banking Law And Identity Formation In Finance Spain .
Banking Law and Identity Formation in Finance in Spain
1. Meaning of Identity Formation in Finance
“Identity formation” in Spanish banking law refers to the legal and operational process through which a financial institution determines:
- Who its customer is;
- Whether the customer is acting personally or for another person;
- Who ultimately owns or controls a legal entity;
- Whether identification documents are genuine;
- Whether the person opening or operating an account has legal authority;
- What level of financial-crime risk the customer presents;
- Whether a digital user is the same person whose identity was originally verified;
- How identity information must be updated, protected and corrected.
Identity formation is therefore broader than checking a passport or Spanish national identity document. It includes initial identification, identity verification, beneficial-ownership checks, digital authentication, sanctions screening, fraud prevention and continuous monitoring.
In Spain, this framework is based on anti-money-laundering law, banking regulation, payment-services law, data-protection law and electronic-identification legislation.
2. Principal Legal Framework
2.1 Law 10/2010 on money laundering and terrorist financing
Law 10/2010 is the central Spanish legislation governing customer identity in financial services. It applies to banks, payment institutions, electronic-money institutions, investment firms, insurers and other regulated businesses.
Its principal identity-related duties are:
- Formal identification of customers;
- Verification through reliable documents;
- Identification of beneficial owners;
- Understanding the purpose and intended nature of the relationship;
- Continuous monitoring;
- Keeping customer information updated;
- Enhanced due diligence in higher-risk cases;
- Retaining identification records;
- Refusing or terminating relationships where identification cannot be completed.
A financial institution must identify individuals intending to establish a business relationship or participate in a covered transaction. It must verify their identities before establishing the relationship or executing the transaction, subject to limited statutory exceptions.
2.2 Royal Decree 304/2014
Royal Decree 304/2014 develops the requirements of Law 10/2010. It specifies acceptable documents, verification procedures, beneficial-ownership rules, simplified and enhanced due diligence and non-face-to-face onboarding requirements.
For a Spanish individual, the principal reliable document is normally the DNI. Depending on the person’s status, other accepted documents may include:
- Spanish passport;
- Foreigner Identity Card;
- Passport issued by another country;
- Official identity documents recognised by Spanish law;
- Electronic identification credentials meeting legal requirements.
The mere submission of a photocopy is not always sufficient. The bank must use a procedure capable of establishing authenticity and linking the document to the applicant.
2.3 EU General Data Protection Regulation
The GDPR controls how banks collect and process identity data. Relevant information can include:
- Names and addresses;
- Identity-document numbers;
- Photographs;
- Signatures;
- IP addresses and device identifiers;
- Voice or facial templates;
- Tax-residence information;
- Transaction patterns;
- Fraud and sanctions alerts.
A bank must identify a lawful basis for processing. Ordinary KYC processing is generally based on a legal obligation rather than consent. A bank should not suggest that legally compulsory AML processing is optional simply by placing it inside a consent form.
GDPR requirements include:
- Lawfulness, fairness and transparency;
- Purpose limitation;
- Data minimisation;
- Accuracy;
- Storage limitation;
- Security;
- Accountability;
- Protection against unlawful automated decisions.
2.4 Payment-services law
Spanish payment-services law, implementing the EU payment-services framework, requires secure authentication and governs liability for unauthorised transactions.
Identity formation and transaction authentication must be distinguished:
- Identification answers: “Who is this customer?”
- Authentication answers: “Is the current user genuinely that customer?”
- Authorisation answers: “Did the customer consent to this transaction?”
A bank can correctly identify a customer when the account is opened but still fail to authenticate a later payment adequately.
2.5 eIDAS and the European Digital Identity framework
The eIDAS framework regulates electronic identification, electronic signatures, seals, timestamps and trust services throughout the EU. Its importance to Spanish finance includes:
- Remote account opening;
- Legally recognised electronic signatures;
- Cross-border recognition of electronic identities;
- Authentication using qualified trust services;
- Verification of corporate authority;
- Future use of European Digital Identity Wallets.
An electronic signature cannot be denied legal effect merely because it is electronic. However, evidential weight depends upon the type of signature and the reliability of the process used.
3. Individual Customer Identity
Before opening an account, the institution normally collects:
- Full legal name;
- Date and place of birth;
- Nationality;
- DNI, NIE or passport details;
- Residential address;
- Tax residence;
- Occupation or economic activity;
- Contact details;
- Expected use of the account;
- Source of funds where relevant.
The bank must compare this information with reliable evidence. Where the documents contain discrepancies, the institution must resolve them before treating the identity as verified.
Examples of warning signs include:
- Different names across documents;
- A recently altered photograph;
- An address inconsistent with other information;
- Repeated use of the same telephone or device for unrelated customers;
- Applications using temporary email addresses;
- A customer unable to explain the intended account activity;
- Identity documents reported as lost or stolen;
- Inconsistent biometric results;
- A person following instructions from someone outside the camera during video identification.
Identity formation must be risk-sensitive. A low-risk salary account and a private-banking relationship involving complex foreign structures do not require identical levels of investigation.
4. Corporate Customers and Beneficial Ownership
For a company, identifying its registered name and corporate number is not enough. The bank must determine:
- Whether the company legally exists;
- Its registered office;
- Its governing body;
- Who may act on its behalf;
- Its ownership structure;
- The natural person who ultimately owns or controls it;
- Whether it is acting for another person.
Under Spanish AML law, the beneficial owner is normally the natural person who ultimately owns or controls the customer. Direct or indirect ownership exceeding the statutory threshold—commonly more than 25%—is an important indicator, but control can exist through other means.
Where no natural person can be identified through ownership or control after appropriate investigation, the relevant senior managing official may be recorded under the residual rule. This is not a shortcut: the bank must first make reasonable efforts to identify an actual owner or controller.
Spanish obliged entities may consult the Central Register of Beneficial Ownership. Nevertheless, reliance on a registry does not completely remove the bank’s responsibility to assess inconsistent or suspicious information.
Trusts and comparable arrangements
Where a trust or similar legal arrangement is involved, identity formation may require identification of:
- Settlor;
- Trustee;
- Protector;
- Beneficiaries or classes of beneficiaries;
- Other persons exercising ultimate control.
Complexity by itself is not proof of criminal conduct, but unexplained complexity can increase risk and justify enhanced due diligence.
5. Purpose and Nature of the Relationship
A bank must understand why the customer wants the financial product and how it is expected to be used.
Relevant questions can include:
- Is the account for salary payments, savings or commercial trading?
- What transactions are expected?
- Which countries will be involved?
- What is the expected value and frequency of transfers?
- What is the source of the customer’s money?
- Will the account receive funds belonging to third parties?
- Is the customer acting as an intermediary?
- Does the business model involve cash, crypto-assets or high-risk jurisdictions?
The answers form the customer’s initial risk profile. Continuous monitoring then compares actual activity with that profile.
Spanish law permits institutions to verify declared activity, obtain information from independent sources and ensure that existing customer information remains current.
6. Remote and Digital Identity Formation
Spanish financial institutions may open accounts remotely, but remote onboarding must satisfy AML and security requirements.
Common methods include:
- Live video conference;
- Automated video identification;
- Qualified electronic signatures;
- Recognised electronic-identification systems;
- Bank-to-bank identity verification;
- Use of trusted identity providers;
- Document verification combined with facial comparison.
A compliant video-identification process may require:
- Adequate image and sound quality;
- Presentation of the original identity document;
- Verification of security features;
- Liveness detection;
- Comparison between the applicant and the document photograph;
- Recording or preservation of legally required evidence;
- Interruption where fraud indicators arise;
- Human review in uncertain cases.
Remote identification must not become a purely mechanical exercise. Deepfakes, synthetic identities, stolen documents and manipulated video streams require banks to use proportionate anti-spoofing measures.
7. Biometric Identity
Facial recognition, fingerprints and voice recognition can strengthen authentication, but they also create substantial privacy risks.
Biometric information is “special-category” personal data when processed to identify a person uniquely. Its use requires both:
- A lawful basis under Article 6 GDPR; and
- An applicable exception under Article 9 GDPR.
A bank should establish:
- Why biometric processing is necessary;
- Whether a less intrusive alternative exists;
- Whether the template is stored centrally or on the customer’s device;
- How false matches are handled;
- How long the data is retained;
- Whether customers can obtain human review;
- How the system is tested for demographic bias;
- Whether a data-protection impact assessment is required.
Consent may be questionable where the customer has no genuine alternative or where access to an essential banking service is conditional on unnecessary biometric processing.
8. Risk-Based Identity Verification
Spanish AML law follows a risk-based approach. Enhanced due diligence may be required where:
- The customer is a politically exposed person;
- The person or transaction is connected to a high-risk country;
- The ownership structure is unusually complex;
- The relationship is established remotely under risky circumstances;
- Funds come from unexplained sources;
- The customer uses nominees without a credible reason;
- Identity information is inconsistent;
- The customer is involved in cash-intensive or high-risk activity;
- Sanctions or adverse-media results require further investigation.
Enhanced measures may include:
- Obtaining additional identity documents;
- Verifying wealth and source of funds;
- Requiring senior-management approval;
- Increasing monitoring frequency;
- independently confirming business activities;
- Examining ownership through several corporate layers.
A bank must not apply risk models in a discriminatory manner. Nationality or residence may be a relevant risk factor in legally defined circumstances, but it should not automatically determine that every person from a particular country is suspicious.
9. Continuous Identity Management
Identity formation does not end when the account is opened. Institutions must keep the customer profile accurate throughout the relationship.
Updates may be necessary when:
- An identity document expires;
- The customer changes address;
- Corporate ownership changes;
- A new authorised signatory is appointed;
- Transaction behaviour changes materially;
- The customer becomes a politically exposed person;
- Sanctions lists are amended;
- Fraud indicators appear;
- Dormant accounts are reactivated.
If the institution cannot complete legally required due diligence, it may have to refrain from opening the account, restrict certain operations or terminate the relationship. It should also consider whether a suspicious-transaction report is required.
However, account restrictions must have a valid legal and contractual basis. A bank should communicate clearly with the customer as far as AML confidentiality rules permit.
10. Synthetic Identity and Impersonation Fraud
A synthetic identity combines genuine and false information—for example, a real DNI number with a different photograph, phone number and address.
Banks should control this risk through:
- Verification against trusted sources;
- Device and behavioural analysis;
- Liveness detection;
- Duplicate-identity detection;
- Checks for repeated contact details;
- Monitoring account use immediately after onboarding;
- Limits on newly opened high-risk accounts;
- Confirmation of changes to telephone numbers and authentication devices.
Where a criminal opens an account in another person’s name, several legal questions arise:
- Did the bank apply reasonable onboarding controls?
- Was the document verification process defective?
- Did the genuine person contribute to the loss?
- Were later payments properly authenticated?
- Did the bank respond promptly to notification?
- Was personal information processed inaccurately?
- Must the false account be blocked and corrected?
The victim may have remedies under payment law, contract law, tort law and data-protection law.
11. Relevant Case Laws
1. SCHUFA Holding (Scoring), Case C-634/21, CJEU, 7 December 2023
SCHUFA generated credit scores that financial institutions used when deciding whether to enter into contracts. The Court held that credit scoring may constitute an automated individual decision under Article 22 GDPR where a third party attributes a determining role to the score.
Importance for Spain
A Spanish bank cannot necessarily avoid automated-decision rules by claiming that an external provider produced the identity or risk score. If a score effectively determines whether a person can open an account, obtain credit or pass fraud screening, Article 22 protections may apply.
These protections can include:
- Meaningful information about the logic involved;
- The right to contest the decision;
- Human intervention;
- Review of inaccurate identity data.
2. SCHUFA Holding (Public-register data), Joined Cases C-26/22 and C-64/22, CJEU, 7 December 2023
The Court considered private retention of information obtained from public insolvency registers. It held that private credit agencies could not keep such information longer than the period for which it remained publicly available under the applicable legal framework.
Importance for Spain
Financial institutions and identity-verification vendors cannot assume that data may be retained indefinitely merely because it was originally obtained from a public register. Retention must satisfy necessity, proportionality and storage-limitation requirements.
3. UI v Österreichische Post, Case C-300/21, CJEU, 4 May 2023
The Court held that a GDPR infringement does not automatically create a right to damages. The claimant must establish an infringement, actual material or non-material damage, and a causal connection. However, EU law does not permit a national rule requiring a minimum level of seriousness.
Importance for Spain
A customer whose identity information is mishandled may obtain compensation even where the non-material harm is not extremely serious. Nevertheless, the customer must prove actual damage, such as distress, loss of control, reputational harm or exposure to identity fraud.
4. RW v Österreichische Post, Case C-154/21, CJEU, 12 January 2023
The Court held that a data subject is generally entitled to know the actual recipients to whom personal data has been disclosed, not merely categories of recipients, unless identifying them is impossible or the request is manifestly unfounded or excessive.
Importance for Spain
A banking customer may ask which identity-verification providers, fraud-prevention companies, group entities or other recipients received their personal data. Banks should therefore maintain reliable records of disclosures.
5. F.F. v Österreichische Datenschutzbehörde, Case C-487/21, CJEU, 4 May 2023
The Court explained that the GDPR right to a “copy” requires a faithful and intelligible reproduction of personal data. Extracts from documents—or entire documents—may have to be supplied where necessary for the data subject to understand how the information is processed.
Importance for Spain
A bank may need to provide meaningful copies or extracts of onboarding files, recorded identity attributes, verification results or related documents. Supplying only a general summary may be insufficient where context is necessary.
6. Orange România, Case C-61/19, CJEU, 11 November 2020
The case concerned the storage of identity-document copies and the validity of consent. The Court held that consent must be freely given, specific, informed and unambiguous. The controller bears the burden of proving valid consent.
Importance for Spain
Pre-ticked boxes, confusing forms or requiring customers to write that they “refuse” processing do not demonstrate valid consent. If a Spanish bank copies an identity document, it should identify the proper legal basis and avoid relying on artificial consent where processing is legally mandatory.
7. Patrick Breyer v Germany, Case C-582/14, CJEU, 19 October 2016
The Court held that a dynamic IP address may constitute personal data where the controller has legal means reasonably likely to identify the person with additional information held by another party.
Importance for Spain
Online identifiers used during digital banking—IP addresses, device fingerprints and session identifiers—can be personal data even if they do not directly display the customer’s name. Banks must protect such information and process it under GDPR principles.
8. Nowak v Data Protection Commissioner, Case C-434/16, CJEU, 20 December 2017
The Court adopted a broad interpretation of personal data. Information is personal where, by reason of its content, purpose or effect, it relates to an identifiable individual.
Importance for Spain
KYC analyst notes, fraud indicators, identity-confidence scores and internal assessments may constitute the customer’s personal data. They are not automatically excluded merely because they contain professional opinions.
9. Fashion ID GmbH & Co. KG, Case C-40/17, CJEU, 29 July 2019
The Court held that an organisation embedding third-party technology may be a joint controller for the collection and transmission of personal data where it jointly determines the purposes and means of those operations.
Importance for Spain
A bank using an embedded onboarding, facial-recognition or identity-analytics tool may share controller responsibility with the technology provider for certain processing stages. Contracting out the technology does not necessarily transfer all GDPR responsibility.
10. Spanish Provincial Court of Oviedo—Unauthorised Transaction and Strong Authentication, 2024
The Provincial Court required a bank to reimburse €6,000 lost through fraud because the institution had not required legally sufficient strong customer authentication for the disputed operation.
Importance
The decision demonstrates that possession of correct customer identity information does not prove that a payment was authorised. Banks must show that the specific operation was authenticated and correctly recorded.
11. Provincial Court of Badajoz—Phishing Liability, 2025
The Provincial Court ordered compensation where a customer suffered losses through phishing and the bank’s security response was inadequate.
Importance
Identity controls must extend beyond account opening. Banks must monitor impersonation techniques and unusual payment activity and cannot automatically transfer every phishing loss to the customer.
12. Provincial Court of A Coruña—Unauthorised Transfers, 2026
The court required a bank to reimburse transfers made without the account holder’s consent.
Importance
Authentication records are evidence but are not conclusive proof of consent. The bank must demonstrate proper authentication and transaction execution, while gross negligence by the customer must be established rather than presumed.
12. Customer Rights
A banking customer generally has the right to:
- Receive information about identity-data processing;
- Access personal data;
- Correct inaccurate identity details;
- Request restriction in appropriate cases;
- Challenge certain automated decisions;
- Obtain human intervention;
- Complain to the Spanish Data Protection Agency;
- Complain through the bank’s customer-service system;
- Approach the Banco de España complaints service where appropriate;
- Seek judicial compensation for proven loss.
The right to erasure is limited where the bank must retain information under AML, tax, accounting, litigation or regulatory requirements.
A customer cannot ordinarily demand immediate deletion of all KYC records simply because the account has been closed.
13. Bank Compliance Requirements
A sound Spanish financial identity framework should include:
- A written customer-identification policy;
- Clear lists of acceptable documents;
- Remote-onboarding controls;
- Beneficial-owner verification;
- Screening against sanctions and PEP databases;
- Risk-based due diligence;
- Human review of doubtful cases;
- Data-protection impact assessments for biometrics and high-risk profiling;
- Controls over outsourced identity providers;
- Strong customer authentication;
- Regular customer-data updates;
- Procedures for correcting false or stolen identities;
- Retention and deletion schedules;
- Fraud-response and account-recovery procedures;
- Audit trails showing how identity decisions were made.
Conclusion
Identity formation in Spanish finance is a continuing legal process, not a single document check. A bank must establish the customer’s formal identity, determine beneficial ownership, understand the intended relationship and verify that the person using the account remains the properly authenticated customer.
Spanish AML legislation provides the basic identification duties, while the GDPR controls how identity information is collected, shared, retained and used in automated decisions. Payment-services law governs authentication and unauthorised transactions, and eIDAS supports reliable electronic identification.
The case law shows three central principles: outsourcing does not remove the bank’s responsibility; identity information must be accurate, proportionate and transparent; and proving that a user supplied correct credentials does not necessarily prove that a disputed transaction was genuinely authorised.

comments