Banking Law And Identity Theft Liability Spain .

Banking Law and Identity-Theft Liability in Spain

1. Introduction

Banking identity theft occurs when a person unlawfully uses another individual’s identity, account credentials, payment card, electronic signature or personal information to obtain money, credit or access to financial services.

Common forms include:

  • Phishing emails and fake banking websites;
  • SMS phishing phishing or “smishing”;
  • Fraudulent telephone calls or “vishing”;
  • SIM-swapping;
  • Theft of online-banking credentials;
  • Unauthorised card payments;
  • Fraudulent mobile-payment enrolment;
  • Loans opened using stolen identity documents;
  • Business-email compromise;
  • Account takeover;
  • Impersonation of bank employees;
  • Manipulation of customers into authorising transfers.

In Spain, liability may fall on the fraudster, the bank, another payment service provider, the customer, a telecommunications company or a data controller. The result depends particularly on whether the transaction was legally authorised, whether strong customer authentication was used and whether the customer acted fraudulently or with gross negligence.

The principal legislation includes:

  • Real Decreto-ley 19/2018 on payment services;
  • Directive (EU) 2015/2366, known as PSD2;
  • Spanish Civil Code;
  • Spanish Criminal Code;
  • General Data Protection Regulation;
  • Organic Law 3/2018 on data protection;
  • Law 10/2010 on prevention of money laundering;
  • DORA Regulation on digital operational resilience;
    --protection legislation.

2. Meaning of Identity Theft

Spanish law does not treat every misuse of personal information as one single offence called “identity theft.” Depending on the conduct, several criminal offences may arise, including:

  • Fraud or estafa;
  • Computer fraud;
  • Usurpation of civil status;
  • Forgery of documents;
  • Unlawful access to computer systems;
  • Disclosure of secrets;
  • Unauthorised use of payment instruments;
  • Money laundering;
  • Membership of a criminal organisation.

For banking liability, however, the central question is normally not only whether a crime occurred. The court must determine which party should bear the financial loss caused by the fraudulent transaction.

3. Authorised and Unauthorised Transactions

This distinction is fundamental.

3.1 Unauthorised transaction

A transaction is unauthorised when the customer did not give legally valid consent to it. Examples include:

  • A fraudster steals credentials and transfers money;
  • A cloned card is used;
  • A mobile wallet is activated without the customer’s consent;
  • A fraudster intercepts an authentication code;
  • The bank accepts an instruction given by an impersonator.

Under Article 36 of Real Decreto-ley 19/2018, a payment transaction is considered authorised only where the payer has consented to its execution.

3.2 Transaction technically confirmed by credentials

Use of the correct password, card, PIN or one-time code does not automatically prove legal authorisation. Article 44 specifically provides that the recorded use of a payment instrument is not necessarily sufficient to prove:

  • That the customer authorised the transaction;
  • That the customer acted fraudulently;
  • That the customer deliberately breached security duties;
  • That the customer was grossly negligent.

This prevents banks from relying exclusively on computer records showing that the correct credentials were entered.

3.3 Authorised push-payment fraud

The position is more complicated when a fraudster deceives the customer into personally making or confirming the transfer.

Examples include:

  • A fake investment adviser persuades the customer to transfer money;
  • A criminal impersonating the bank tells the customer to move funds to a “safe account”;
  • A fraudulent supplier sends replacement account details;
  • A customer confirms a transfer after being manipulated by a telephone caller.

The bank may argue that the payment was authorised because the customer personally entered and confirmed it. In these cases, the automatic refund regime for unauthorised transactions may not apply.

However, the bank may still face liability where it:

  • Failed to implement mandatory authentication;
  • Ignored obvious fraud indicators;
  • Executed a highly abnormal payment without adequate checks;
  • Misrepresented the purpose of the authentication step;
  • Failed to respond after receiving timely notice;
  • Breached contractual or professional duties of care;
  • Allowed a fraudster to change contact or security information without proper verification.

4. Bank’s Burden of Proof

When the customer denies authorising a transaction, the bank must prove that it was:

  1. Properly authenticated;
  2. Accurately recorded;
  3. Correctly entered in the accounts;
  4. Not affected by a technical failure or other deficiency.

Authentication alone does not establish customer consent or gross negligence.

The bank should therefore produce evidence such as:

  • Authentication logs;
  • Device-identification information;
  • IP addresses;
  • Enrolment records;
  • One-time-password delivery records;
  • Details displayed during authorisation;
  • Beneficiary-registration records;
  • Fraud-monitoring alerts;
  • Transaction-risk analysis;
  • Recorded customer communications;
  • Geolocation data, where lawfully collected;
  • Evidence that strong customer authentication was correctly applied.

A statement that “the transaction was made using the correct credentials” is generally insufficient by itself.

5. Immediate Refund Rule

Article 45 of Real Decreto-ley 19/2018 provides that, following an unauthorised transaction, the payer’s bank must normally refund the amount immediately and no later than the end of the following business day.

The bank must also restore the payment account to the position it would have been in had the transaction not occurred.

The bank may temporarily refuse immediate reimbursement where it has reasonable grounds to suspect fraud by the customer and communicates those grounds in writing to the Banco de España.

This exception concerns suspected fraud by the customer. It should not be treated as a general right to delay every phishing claim while conducting an internal investigation.

6. Customer Liability

6.1 Customer’s duties

Under Article 41, the customer must:

  • Use the payment instrument according to its conditions;
  • Take reasonable measures to protect personalised security credentials;
  • Notify the bank without undue delay after discovering loss, theft, misuse or unauthorised access.

The general maximum notification period is 13 months from the debit date. However, the customer must still report the matter promptly after becoming aware of it.

6.2 Limited liability

Before notification, the customer may ordinarily bear losses up to the statutory limit—generally €50—arising from a lost, stolen or misappropriated payment instrument.

The customer should not bear that limited loss where:

  • The loss or theft was not detectable before the transaction;
  • The loss resulted from acts or omissions of the bank or its agents;
  • The bank failed to require strong customer authentication;
  • The transaction occurred after the customer notified the bank.

6.3 Fraud or gross negligence

The customer may bear the full loss where the bank proves that the customer:

  • Acted fraudulently; or
  • Intentionally or through gross negligence breached the statutory security duties.

Gross negligence requires more than an ordinary mistake. Relevant facts may include:

  • Deliberately disclosing complete credentials despite an unmistakable warning;
  • Giving a PIN and one-time code to an unknown caller without basic verification;
  • Repeatedly approving transactions whose amount and recipient were clearly displayed;
  • Ignoring several explicit fraud warnings;
  • Leaving credentials openly accessible;
  • Delaying notification for an unjustifiable period after discovering the fraud.

Conversely, clicking a sophisticated phishing link or being deceived by a highly convincing bank impersonation does not automatically constitute gross negligence. The assessment must consider the entire fraud method, the bank’s warnings, the information displayed during authentication and the customer’s individual circumstances.

7. Strong Customer Authentication

Banks must generally use strong customer authentication when a customer:

  • Accesses an account online;
  • Initiates an electronic payment;
  • Performs a remote action creating a risk of payment fraud.

Authentication normally requires at least two independent elements from:

  • Knowledge: password or PIN;
  • Possession: registered phone or token;
  • Inherence: fingerprint, facial recognition or another biometric characteristic.

For remote electronic payments, the authentication should be dynamically linked to the transaction’s specific amount and beneficiary.

Bank liability for authentication failures

The bank’s position is weakened where:

  • Only one authentication factor was used;
  • A fraudster could change the registered telephone number too easily;
  • The confirmation message did not display the amount or beneficiary;
  • The bank relied on ordinary SMS without adequate risk controls;
  • A new device was registered without sufficient verification;
  • Several suspicious transactions were executed without intervention;
  • The bank failed to apply authentication when no lawful exemption existed.

A customer should not normally bear the loss merely because a criminal defeated inadequate authentication controls.

8. Phishing, Smishing and Vishing

Phishing

A criminal sends an email or creates a false website resembling the bank’s legitimate platform. The customer enters credentials, which the criminal then uses.

Smishing

The criminal sends a fraudulent SMS, sometimes inserted into an existing message thread, requesting immediate verification.

Vishing

The criminal impersonates the bank by telephone and persuades the customer to disclose information or approve an operation.

Liability analysis

A court should examine:

  1. Whether the payment was truly authorised;
  2. What information the customer saw during confirmation;
  3. Whether the fraudster initiated or the customer initiated the transaction;
  4. Whether strong customer authentication was used;
  5. Whether the transaction was abnormal;
  6. Whether the bank generated fraud alerts;
  7. Whether the customer disclosed complete credentials;
  8. Whether the customer acted with ordinary or gross negligence;
  9. How quickly the customer reported the incident;
  10. Whether the bank attempted to recall or freeze the payment.

9. SIM-Swap Fraud

SIM swapping occurs when a criminal obtains control of the victim’s mobile number and intercepts authentication messages.

Potentially liable parties include:

  • The fraudster;
  • The bank;
  • The telecommunications provider;
  • A data controller responsible for leaked identification information;
  • The customer, but only where fraud or serious misconduct is proved.

A bank cannot always assume that control of a telephone number proves the customer’s identity. Where account access occurs from a new device, the SIM has recently been replaced and the transaction is abnormal, additional verification may be necessary.

The telecommunications operator may face liability if it issued a replacement SIM without adequate identity checks. Liability may be shared where failures by both the bank and the operator contributed to the loss.

10. Identity Theft Used to Obtain Loans

A criminal may use a stolen national identity document, falsified payslips or unlawfully obtained personal information to open an account or obtain credit.

The victim should not be required to repay a loan that the victim neither requested nor validly accepted.

The lender must establish:

  • Identity of the contracting person;
  • Valid contractual consent;
  • Authenticity of the electronic signature;
  • Reliability of the remote-identification process;
  • Delivery of the funds;
  • Device and authentication evidence;
  • Compliance with customer due-diligence requirements.

A copy of an identity document is not necessarily sufficient proof that the victim entered the agreement.

If the lender reports the victim to a credit register despite credible evidence of impersonation, additional liability may arise for unlawful personal-data processing and reputational damage.

11. Data-Protection Liability

Banks process extensive identity, transaction and authentication data. Under the GDPR, they must implement security appropriate to the risks involved.

A bank may face data-protection liability where identity theft results from:

  • Inadequate access controls;
  • Exposure of customer records;
  • Insecure identity-verification systems;
  • Excessive employee access;
  • Poorly protected authentication data;
  • Failure to detect unauthorised account access;
  • Unlawful disclosure to third parties;
  • Inaccurate reporting to credit-information systems;
  • Failure to correct records after learning of identity theft.

The occurrence of identity theft does not automatically prove that the bank violated the GDPR. However, the bank must be able to demonstrate that its technical and organisational measures were appropriate.

12. Criminal Liability of the Fraudster

Depending on the facts, the fraudster may be prosecuted for:

  • Fraud under Articles 248 and following of the Criminal Code;
  • Computer fraud;
  • Unauthorised use of payment instruments;
  • Forgery;
  • Usurpation of civil status;
  • Unlawful access to systems;
  • Discovery and disclosure of secrets;
  • Money laundering.

Money mules who receive and transfer stolen funds may also incur criminal liability, particularly when they knew or consciously ignored the illegal origin of the money.

Criminal proceedings against the fraudster do not necessarily prevent the victim from bringing a civil or payment-services claim against the bank. The bank’s statutory reimbursement obligation is distinct from the fraudster’s criminal responsibility.

Important Case Law

1. DenizBank AG v Verein für Konsumenteninformation, Case C-287/19

The case concerned NFC contactless payments and whether the contactless function of a bank card could fall within special rules for low-value payment instruments.

The Court held that the relevant exemptions apply only where their statutory conditions are satisfied. A bank cannot broadly remove ordinary customer protections simply by describing a payment function as anonymous or low value.

Importance for Spain: Banks must assess the security and blocking characteristics of each payment function. Contractual terms cannot automatically transfer all identity-theft or contactless-payment risks to customers.

2. DM and LR v Crédit Agricole Mutuel, Case C-337/20

The dispute involved unauthorised payment transactions and the harmonised liability rules under European payment-services legislation.

The Court treated the statutory regime governing notification and provider liability as a specialised system. Claims must therefore be assessed carefully under the payment-services rules rather than only under general negligence law.

Importance for Spain: Where stolen identity or credentials produce an unauthorised payment, Articles 43–46 of Real Decreto-ley 19/2018 provide the primary liability framework.

3. ZG v Beobank SA, Case C-351/21

A customer disputed card transactions carried out in Spain. The bank provided only limited information about the payment terminal and did not adequately identify the recipient.

The Court held that the payment provider must give the payer information enabling identification of the person who benefited from the transaction.

Importance for Spain: Banks must preserve sufficient transaction data to investigate identity theft and enable customers to identify fraudulent beneficiaries. Technical references alone may be inadequate.

4. Tecnoservice Int. Srl v Poste Italiane SpA, Case C-245/18

The dispute concerned a payment executed according to the unique identifier supplied in the payment order, even though there was a discrepancy involving the beneficiary’s name.

The Court held that payment providers may generally treat an order as correctly executed where it is executed according to the specified unique identifier.

Importance for Spain: If a customer personally authorises a payment to an IBAN supplied by a fraudster, recovery from the bank may be more difficult. The legal outcome differs from a transaction initiated directly by an identity thief without the customer’s consent.

5. VB v Natsionalna Agentsia za Prihodite, Case C-340/21

Personal data was exposed following a cyberattack. The Court held that a successful cyberattack does not automatically establish that the controller’s security measures were inadequate.

However, the controller must demonstrate the appropriateness of its security measures. The Court also recognised that a well-founded fear of future misuse of personal data may constitute non-material damage.

Importance for Spain: A bank is not automatically liable every time stolen data is used. Nevertheless, it must prove that its identity systems, security controls, monitoring and incident response were appropriate.

6. Österreichische Post AG, Case C-300/21

The Court held that a GDPR infringement does not automatically create a right to compensation. The claimant must demonstrate:

  1. An infringement;
  2. Material or non-material damage;
  3. A causal link between them.

The Court also held that compensation cannot depend on the damage exceeding an artificial minimum threshold of seriousness.

Importance for Spain: An identity-theft victim may seek compensation for financial or emotional harm, but must prove actual damage and causation. A mere technical breach is insufficient for damages.

7. Scalable Capital, Joined Cases C-182/22 and C-189/22

These cases involved theft and misuse of personal data held by an online investment platform.

The Court explained that identity theft, in the relevant EU-law context, requires actual misuse of identity data by a third party. Mere possession of stolen data may create compensable fear or other harm, but it is not necessarily completed identity theft.

The Court also confirmed that GDPR compensation is compensatory, not punitive.

Importance for Spain: Victims must distinguish between exposure of identity data, risk of future misuse and actual impersonation. Each may produce different evidence and damages.

8. Wirtschaftsakademie Schleswig-Holstein, Case C-210/16

The Court adopted a broad interpretation of joint responsibility for personal-data processing where an organisation participates in determining how data is collected or used through a third-party platform.

Importance for Spain: A bank cannot always avoid responsibility by claiming that identity verification, cloud storage or digital onboarding was handled by an external provider. Responsibility depends on the bank’s actual participation and control.

9. Fashion ID, Case C-40/17

The Court held that an organisation could be jointly responsible with a third-party service provider for particular stages of data collection and transmission, even if it did not control every later use of the data.

Importance for Spain: Liability must be allocated by processing stage. A bank may be responsible for collecting and transmitting identity information, while a technology provider may bear responsibility for separate processing operations.

Allocation of Liability

SituationLikely starting position
Fraudster steals credentials and initiates paymentBank normally refunds unless customer fraud or gross negligence is proved
Customer personally transfers money after deceptionOften treated as authorised; bank liability depends on security and negligence
Bank did not use required strong authenticationCustomer generally receives stronger protection
Customer reports card or credentials stolenBank bears later unauthorised losses
Customer acted fraudulentlyCustomer bears the loss
Bank proves customer’s gross negligenceCustomer may bear the full loss
Fraudulent loan opened in victim’s nameLender must prove identity and valid consent
Bank caused or failed to secure a data breachGDPR and civil liability may arise
Telecom provider negligently approved a SIM swapTelecom liability or shared liability may arise
Payment correctly sent to IBAN supplied by customerBank may rely on execution according to the unique identifier

Practical Steps for Victims

A victim should act immediately:

  1. Notify the bank and request blocking of accounts, cards and digital access.
  2. State clearly that the transactions were not authorised.
  3. Request immediate reimbursement under Article 45.
  4. Ask the bank to preserve authentication and transaction logs.
  5. Report the matter to the police.
  6. Change email, banking and device credentials.
  7. Contact the telecommunications provider in a SIM-swap case.
  8. Check credit and loan records for fraudulent applications.
  9. Challenge inaccurate credit-register entries.
  10. Preserve emails, SMS messages, telephone records and screenshots.
  11. Submit a formal complaint to the bank’s customer service department.
  12. Escalate the complaint to Banco de España or the competent data-protection authority where appropriate.
  13. Consider civil proceedings if reimbursement is refused.

Conclusion

Spanish banking law generally places the initial risk of an unauthorised identity-theft transaction on the payment service provider. The bank must prove proper authentication and cannot rely only on the fact that correct credentials were used.

The customer bears the full loss only where the bank proves fraud, intentional misconduct or gross negligence. Ordinary carelessness is not automatically gross negligence, particularly where the fraud involved sophisticated impersonation.

The most difficult cases are authorised push-payment scams, where the customer personally confirms a transaction after being deceived. In those cases, liability depends on whether there was legally valid consent, what the authentication message displayed, whether the transaction was abnormal and whether the bank’s fraud controls were reasonably effective.

 

 

LEAVE A COMMENT