Banking Law And Identity Protection For Family Accounts Spain .

Banking Law and Identity Protection for Family Accounts in Spain

1. Introduction

“Family account” is not a separate statutory category under Spanish banking law. The expression may cover:

  • A joint account held by spouses or partners;
  • A parent–child account;
  • An account opened for a minor;
  • An account operated by a guardian or support person;
  • An account held by an elderly or dependent family member;
  • An account with one or more authorised family users; or
  • A deceased person’s account administered by heirs.

The central legal concern is that family relationships do not automatically create authority over a bank account. A spouse, parent, adult child, sibling or heir may access or operate an account only where that power arises from:

  • Account ownership;
  • A valid authorisation;
  • Parental representation;
  • A power of attorney;
  • A judicial or legally recognised support measure; or
  • Succession rights following the account holder’s death.

Banks must verify the identity and authority of every person who opens, controls or operates a family account.

2. Principal Legal Framework

Identity protection for family accounts is governed by several overlapping laws.

2.1 Spanish payment-services legislation

Royal Decree-Law 19/2018 regulates payment services in Spain and implements the principal requirements of the EU’s Second Payment Services Directive.

It governs:

  • Consent to payment transactions;
  • Authentication;
  • Unauthorised payments;
  • Lost or stolen payment instruments;
  • Customer-notification duties;
  • The bank’s burden of proof;
  • Refunds; and
  • Liability for fraud or gross negligence.

A payment is authorised only when the relevant account holder or properly authorised user has consented in the agreed form. The fact that another family member knew the password or had physical access to the customer’s telephone does not necessarily establish legal consent.

Spanish payment law also treats breaches of confidentiality and custody of payment data as regulatory violations.

2.2 Anti-money-laundering law

Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing and Royal Decree 304/2014 require banks to identify:

  • The account holder;
  • Joint account holders;
  • Legal representatives;
  • Authorised users;
  • Persons acting on behalf of customers; and
  • The beneficial owner—the natural person for whose benefit the account or transaction is actually operated.

The bank must verify identity before establishing the business relationship. If a parent, spouse or adult child appears to be operating an account for an undisclosed person, the bank may request further information or refuse the transaction.

2.3 GDPR and Spanish data-protection law

Banks process highly sensitive identity and financial information. They must comply with:

  • Regulation (EU) 2016/679—the GDPR;
  • Organic Law 3/2018 on Personal Data Protection and Digital Rights;
  • Banking confidentiality duties; and
  • Security and fraud-prevention requirements.

Being related to the customer does not give a person an automatic right to receive:

  • Account balances;
  • Statements;
  • Login records;
  • Spending details;
  • Transaction descriptions;
  • Addresses;
  • Telephone numbers; or
  • Copies of identity documents.

Disclosure requires a legal basis, such as the customer’s authority, parental representation, a valid power, an inheritance right or a judicial order.

2.4 Strong customer authentication

Electronic access and payments generally require strong customer authentication using at least two independent elements drawn from:

  1. Knowledge: password, PIN or secret information;
  2. Possession: registered telephone, card or authentication device; and
  3. Inherence: fingerprint, facial characteristics or another biometric feature.

For remote electronic payments, authentication should normally be dynamically linked to the amount and payee.

A shared household telephone or email address can create significant risk. Banks should not assume that authentication proves which family member actually gave consent where several people use the same device or know the same password.

2.5 Spanish Civil Code

The Civil Code regulates:

  • Parental authority;
  • Representation of minors;
  • Property administration;
  • Conflicts of interest;
  • Powers of attorney;
  • Support measures for persons with disabilities; and
  • Succession after death.

Following Law 8/2021, Spanish law emphasises support for persons with disabilities rather than automatic substitution of their decision-making. Banks should examine the actual support measure and must not assume that disability or age gives a relative unrestricted control of the account.

3. Joint Family Accounts

3.1 Joint ownership does not necessarily prove ownership of all funds

The names appearing on an account determine the contractual relationship with the bank, but they do not conclusively determine the beneficial ownership of the money.

For example, a husband and wife may both be account holders, while the funds may have been contributed entirely by one spouse. Whether the money belongs to one or both depends on:

  • Source of the funds;
  • Matrimonial-property regime;
  • Agreements between the parties;
  • Purpose of the account;
  • Gifts or transfers between family members; and
  • Evidence of beneficial ownership.

Therefore, the bank’s authority to honour an instruction is different from the private-law question of who ultimately owns the money.

3.2 Indistinct accounts

In an indistinct or several-signature account, each holder may generally operate the account separately.

However, separate operating authority does not mean that one holder legally owns the entire balance. A holder who withdraws money belonging to another family member may face:

  • Restitution claims;
  • Liability for unjust enrichment;
  • Matrimonial-property claims;
  • Inheritance claims; or
  • In serious cases, criminal allegations.

3.3 Joint-signature accounts

In a joint or collective-signature account, transactions require the approval of all holders or the number specified in the contract.

The bank must not execute an instruction from only one relative where the mandate requires multiple signatures. Digital banking systems should apply the same signing rule as the underlying account contract.

3.4 Disputes between family members

When the bank receives contradictory instructions from joint holders, it should act neutrally. Depending on the contract and seriousness of the dispute, it may:

  • Suspend disputed transactions;
  • Require joint instructions;
  • Restrict digital access;
  • Preserve the funds;
  • Request documentary clarification; or
  • Await a court order.

The bank should not decide the underlying ownership dispute unless it has a clear contractual or legal basis.

4. Authorised Family Members

An authorised person is not necessarily an account holder. The distinction is important:

PositionOwns contractual account rights?May operate account?Continues after death?
Sole holderYesYesAccount passes into estate
Joint holderYesAccording to signing rulesRights depend on account type
Authorised userNoWithin authorisationNormally ends on holder’s death
AttorneyNoWithin the power of attorneyDepends on law and terms, but ordinarily ends at death
HeirBy successionAfter proving status and authorityYes, within inheritance rules
Parent of minorNot personallyAs legal representativeSubject to the child’s interests
Support personNot personallyOnly within applicable support measureAccording to measure or court order

An authorised family member must use their own recognised identity and authority. They should not impersonate the holder by using:

  • The holder’s password;
  • The holder’s PIN;
  • The holder’s biometric authentication;
  • A copied identity document;
  • A SIM card obtained without authority; or
  • The holder’s digital signature.

The bank should create separate credentials and an audit trail for authorised users wherever possible.

5. Accounts Belonging to Minors

5.1 Identity verification

When an account is opened for a minor, the bank should identify:

  • The minor;
  • The parent or legal representative;
  • The representative’s legal authority;
  • Any restrictions on parental authority; and
  • The source and purpose of the funds.

Documents may include the child’s identity document, birth certificate, family-registry evidence, guardianship documentation or judicial decisions.

5.2 Ownership of the money

Money deposited in the minor’s account normally belongs to the minor, even where a parent controls the account.

Parents administer the child’s property, but they must act in the child’s interests. They cannot treat the child’s account as their personal account or freely use the child’s money to satisfy unrelated personal debts.

5.3 Conflicts of interest

Where a transaction creates a conflict between the parent and child, ordinary parental representation may be insufficient. An independent representative or judicial intervention may be necessary.

Examples include:

  • Transferring the child’s money to the parent;
  • Using the child’s savings as security for the parent’s loan;
  • Waiving a claim belonging to the child;
  • Giving the child’s money to another family member; or
  • Closing the child’s account to appropriate its balance.

5.4 Reaching adulthood

When the minor becomes an adult, parental operating authority based solely on parental responsibility ordinarily ends. The bank should ensure that:

  • The adult account holder receives independent credentials;
  • Previous parental permissions are reviewed;
  • Contact information is updated;
  • The customer can revoke continuing authorisations; and
  • Information is no longer automatically disclosed to parents.

6. Elderly Customers and Persons Requiring Support

A bank should not presume incapacity merely because a customer is elderly, ill or dependent on relatives.

The bank should distinguish between:

  • Informal assistance;
  • A normal bank authorisation;
  • A notarial power of attorney;
  • A preventive power;
  • A voluntary support measure;
  • A judicial curatorship or support order; and
  • A court-appointed representative.

The document must be examined to determine:

  • Who may act;
  • Whether the account is covered;
  • Whether acts require joint participation;
  • Whether gifts or transfers are permitted;
  • Whether the authority remains valid during incapacity; and
  • Whether judicial approval is required.

Banks must also watch for financial abuse, such as an adult child:

  • Redirecting pension payments;
  • Changing the registered telephone number;
  • Adding themselves as an authorised user;
  • Making unusual transfers;
  • Isolating the customer from banking communications; or
  • Pressuring the customer to grant a broad power.

Protective intervention should be proportionate. Suspicion of family abuse does not automatically authorise the bank to freeze every transaction indefinitely, but it can justify enhanced verification and escalation.

7. Death of an Account Holder

7.1 Identity and succession documents

Before giving account information or releasing funds, the bank may request:

  • Death certificate;
  • Certificate of last wills;
  • Will or declaration of heirs;
  • Identity documents of the heirs;
  • Acceptance or partition of inheritance;
  • Tax documentation; and
  • Authority of any estate representative.

Family relationship alone is insufficient. A child or spouse must establish the legal capacity in which information or payment is requested.

7.2 Joint and indistinct accounts

Banco de España distinguishes between joint-signature and indistinct accounts:

  • In a joint-signature account, surviving holders generally cannot dispose of the deceased’s position without the consent of the heirs.
  • In an indistinct account, a surviving holder may continue operating according to the contractual mandate.

However, operating authority does not decide the beneficial ownership of the funds. An heir may challenge withdrawals that improperly reduce the estate.

7.3 Rights of heirs

Once their status is proved, heirs may obtain information necessary to administer the inheritance. This generally includes:

  • Balances at the date of death;
  • Accounts and products held by the deceased;
  • Movements after death; and
  • Certain earlier transactions relevant to the estate.

The privacy rights of surviving co-holders must also be considered. Banco de España treats disclosure of movements from approximately the year before death as consistent with good banking practice, subject to the circumstances and possible objections by co-holders.

7.4 Cancellation

For an account held solely by the deceased, cancellation generally requires the consent of all heirs. For a shared account, the bank may require the participation of surviving holders and the deceased holder’s heirs.

8. Unauthorised Use by a Family Member

A transaction may be unauthorised even where it was made by:

  • A spouse;
  • An adult child;
  • A parent;
  • A sibling;
  • A former partner; or
  • A person living in the same home.

The legal question is whether the account holder consented to that particular transaction or validly authorised the person to perform it.

Bank’s burden of proof

When the customer denies authorising a payment, the bank must generally prove that the transaction was:

  • Authenticated;
  • Accurately recorded;
  • Properly accounted for; and
  • Not affected by a technical failure.

The mere electronic record that a password, card or authentication code was used does not automatically prove that the holder consented or acted with gross negligence.

Customer’s responsibility

Customers must:

  • Protect credentials;
  • Not share PINs or passwords;
  • Notify the bank of a lost device or compromised credentials;
  • Review transactions;
  • Report unauthorised payments without undue delay; and
  • Follow reasonable security warnings.

A customer may lose some or all reimbursement rights where the bank proves fraud, intentional breach or gross negligence.

Ordinary carelessness, deception by a sophisticated fraudster or the mere fact that a family member discovered credentials is not automatically gross negligence.

9. Data Protection Between Family Members

Each holder’s personal information remains protected even within a shared account.

A co-holder may be entitled to information needed to operate and understand the common account, but this does not necessarily give access to:

  • Another holder’s separate accounts;
  • Private loans;
  • Individual credit reports;
  • Personal identification files;
  • Telephone or email records;
  • Individual investment portfolios; or
  • Accounts held with other relatives.

Banks should use data minimisation. Statements and online platforms should disclose only the information necessary for the account relationship.

For minors or supported adults, disclosure to a representative should be limited to the representative’s actual legal powers.

10. Relevant Case Laws

Because “family account identity protection” is not a separate judicial category, the relevant decisions arise from unauthorised payments, identity impersonation, authentication, joint accounts and customer-data protection.

1. DenizBank AG v Verein für Konsumenteninformation, Case C-287/19

The CJEU considered contactless-card payments and the rules applicable to payment instruments used without personalised security credentials.

The Court emphasised that payment providers must satisfy the conditions for relying on special rules or exemptions. The provider bears important evidentiary responsibilities concerning authentication and use of the payment instrument.

Family-account significance: If one family member uses another person’s card or contactless facility, the bank cannot simply equate possession of the card with the account holder’s legal consent.

2. CRCAM, Case C-337/20

This case addressed the liability system for unauthorised payment transactions and evidence concerning authentication and execution.

The CJEU’s approach confirms that the payment-services regime creates a specialised allocation of responsibility. The provider must produce evidence of proper authentication; the customer’s liability cannot be established merely by showing that correct credentials were entered.

Family-account significance: A bank must investigate who had authority, rather than assuming that any technically authenticated family transaction was legally authorised.

3. Beobank SA, Case C-351/21

The CJEU examined the information a payment provider must supply so that a customer can identify transactions and the relevant beneficiary.

The Court stressed the practical importance of meaningful transaction information. A vague statement description may prevent a customer from recognising misuse or reporting it promptly.

Family-account significance: Clear statements help holders detect transfers made by relatives, caregivers or authorised users beyond their powers.

4. IL v Veracash SAS, Case C-665/23

The case concerned withdrawals using a card that the customer claimed never to have received.

The Court distinguished the maximum notification period from the customer’s obligation to report an unauthorised payment without undue delay after discovering it. Loss of reimbursement normally requires proof that delayed notification involved intention or gross negligence, subject to the applicable facts.

Family-account significance: A customer who discovers that a relative has intercepted or used a card must notify the bank immediately. The bank still bears the burden of proving authentication and any alleged gross negligence.

5. Badajoz Provincial Court phishing judgment, 24 February 2025

The Badajoz Provincial Court ordered a bank to compensate a phishing victim. It stated that being deceived does not by itself establish gross negligence, particularly where fraudsters impersonate the bank convincingly.

Family-account significance: Where a relative controlling a family telephone is deceived by bank impersonation, the court must examine the actual conduct and security system. Fraud victimisation alone does not remove statutory payment protection.

6. Judgment concerning absence of strong authentication, reported 7 June 2024

A Spanish court ordered a bank to reimburse approximately €6,000 because the institution had not required appropriate strong customer authentication for the fraudulent transaction.

Family-account significance: Banks must apply effective authentication even when the transaction appears to originate from a device used by the customer’s household.

7. Moncada Court phishing judgment, reported 31 July 2023

A Moncada court ordered reimbursement of approximately €5,800 after finding that the customer had been a phishing victim and had not acted negligently.

Family-account significance: The bank must prove more than the use of correct security credentials. It must establish authorisation or conduct sufficiently serious to meet the gross-negligence threshold.

8. A Coruña Provincial Court judgment, reported 3 February 2026

The Provincial Court required a bank to reimburse non-consensual transfers made from a customer’s accounts. The decision reinforces the distinction between technical execution and genuine customer consent.

Family-account significance: The same principle applies when the person initiating the transfer is a relative: family access is not equivalent to legally valid consent.

11. Recommended Bank Controls

Spanish banks should adopt the following safeguards for family accounts:

  1. Verify every holder and authorised user separately.
  2. Record whether the account is indistinct or joint-signature.
  3. Issue separate digital credentials to each user.
  4. Prohibit credential sharing in clear contractual language.
  5. Apply strong customer authentication.
  6. Send transaction alerts to the proper holder.
  7. Require enhanced checks before changing telephone numbers or email addresses.
  8. Verify powers of attorney and support measures.
  9. Review parental authority when a minor reaches adulthood.
  10. Monitor unusual transfers to authorised relatives.
  11. Establish procedures for suspected elder financial abuse.
  12. Revoke or review authority after death, separation, incapacity or court orders.
  13. Preserve complete authentication and audit records.
  14. Give heirs only information justified by succession rights.
  15. Provide rapid blocking and fraud-reporting channels.

12. Conclusion

Spanish law protects identity in family accounts by separating family status from legal authority. Marriage, parenthood, cohabitation or kinship does not by itself permit a person to operate another family member’s account.

Banks must identify account holders, representatives, authorised users and beneficial owners; apply strong authentication; protect financial data; investigate disputed transactions; respect minors’ ownership; verify support measures; and establish inheritance rights before releasing information or funds.

The most important rule is:

A transaction is not authorised merely because it was performed by a relative or through a device used by the family.

Where a customer disputes a transaction, the bank must demonstrate proper authentication and cannot rely solely on the fact that correct credentials were used. At the same time, customers must protect their credentials and report suspected misuse without undue delay.

 

LEAVE A COMMENT