Banking Law And Identity Theft Prevention Systems Spain .

Banking Law and Identity Theft Prevention Systems in Spain

1. Introduction

Identity theft in banking occurs when a person unlawfully uses another individual’s identity, credentials or personal information to:

  • Open or control a bank account.
  • Obtain a loan or credit card.
  • Initiate transfers or card payments.
  • Replace a customer’s mobile number or SIM card.
  • Pass remote onboarding checks.
  • Access online or mobile banking.
  • Redirect payments to fraudulent accounts.
  • Use stolen accounts for money laundering.
  • Impersonate bank employees through phishing, smishing or vishing.

Spanish law requires banks to maintain preventive systems covering customer identification, strong authentication, transaction monitoring, data protection, cybersecurity, incident response and reimbursement of unauthorized payments.

No single Spanish statute governs the entire subject. The framework combines Spanish banking legislation, EU payment law, anti-money-laundering rules, data-protection law, electronic-identification rules and digital-operational-resilience requirements.

2. Principal Legal Framework

A. Royal Decree-Law 19/2018 on Payment Services

Royal Decree-Law 19/2018 implements the Second Payment Services Directive, commonly known as PSD2, in Spain.

It governs:

  • Electronic payment authorization.
  • Protection of payment credentials.
  • Strong customer authentication.
  • Unauthorized transactions.
  • Allocation of losses between banks and customers.
  • Payment-initiation and account-information services.
  • Fraud prevention and security incidents.

Its central principle is that when a customer denies authorizing a transaction, the payment-service provider must prove that it was properly authenticated, accurately recorded and unaffected by technical failure.

The mere fact that the correct password, card details or authentication code was used does not necessarily prove that the customer authorized the transaction or acted with gross negligence.

B. Law 10/2010 on Prevention of Money Laundering

Law 10/2010 and Royal Decree 304/2014 require banks to identify customers and beneficial owners before establishing business relationships or carrying out certain transactions.

The bank must:

  • Identify the customer using reliable documents or methods.
  • Verify that the customer is a real person.
  • Determine whether someone is acting on behalf of another person.
  • Identify the beneficial owner of a company or legal arrangement.
  • Understand the purpose of the relationship.
  • Monitor transactions continuously.
  • Keep identification and transaction records.
  • Apply enhanced due diligence in higher-risk cases.
  • Report suspicious activity to SEPBLAC.

These obligations also help prevent criminals from opening accounts using stolen identities or using victims as money mules.

C. GDPR and Organic Law 3/2018

The General Data Protection Regulation and Spain’s Organic Law 3/2018 regulate the collection and use of personal information in identity-verification and fraud-prevention systems.

Banks must satisfy requirements concerning:

  • Lawful processing.
  • Transparency.
  • Purpose limitation.
  • Data minimization.
  • Accuracy.
  • Security.
  • Storage limitation.
  • Data-subject rights.
  • Data-protection impact assessments.
  • Automated decision-making.
  • Personal-data breach notification.

Biometric data, such as facial templates used during video identification, may constitute special-category personal data. Its use requires a valid legal basis, necessity, proportionality and strong safeguards.

D. DORA

The EU Digital Operational Resilience Act has applied since 17 January 2025. It requires banks and many other financial entities to maintain comprehensive systems for:

  • ICT risk management.
  • Incident detection and reporting.
  • Operational-resilience testing.
  • Third-party technology risk.
  • Information sharing.
  • Business continuity and recovery.
  • Governance and management accountability.

Identity protection is therefore part of the bank’s wider digital-resilience obligations.

E. Regulatory Technical Standards on Strong Authentication

Commission Delegated Regulation (EU) 2018/389 establishes detailed requirements for strong customer authentication and secure communications.

It requires authentication based on at least two independent elements drawn from:

  1. Knowledge: Something only the customer knows, such as a password.
  2. Possession: Something only the customer possesses, such as a registered phone or secure token.
  3. Inherence: Something the customer is, such as a biometric characteristic.

For remote electronic payments, authentication normally must be dynamically linked to the specific amount and beneficiary.

3. Customer Identification at Account Opening

Documentary verification

For in-person onboarding, banks normally examine official identification such as:

  • Spanish national identity documents.
  • Passports.
  • Foreigner identity documents.
  • Corporate incorporation records.
  • Powers of attorney.
  • Tax-identification information.

Banks should check the document’s authenticity, validity, photograph, security features and consistency with other information provided by the applicant.

A photocopy alone may be insufficient where the risk requires verification of the original document or confirmation through an authoritative source.

Remote identification

Online account opening presents greater impersonation risks. Appropriate controls may include:

  • Video-identification procedures.
  • Qualified electronic signatures.
  • Electronic identity schemes.
  • NFC reading of electronic identity documents.
  • Document-security and liveness checks.
  • Comparison of the applicant’s face with the identity document.
  • Verification of device, telephone and email ownership.
  • Cross-checking against reliable databases.
  • Manual review of suspicious applications.

Banks should detect photographs of photographs, masks, prerecorded videos, synthetic identities and AI-generated deepfakes.

Beneficial ownership

For corporate customers, checking only the representative’s identity is insufficient. The bank must identify the natural persons who ultimately own or control the company.

Warning signs include:

  • Recently incorporated companies without genuine activity.
  • Complex ownership structures without commercial justification.
  • Nominee directors.
  • Unexplained foreign shareholders.
  • Frequent changes in ownership.
  • Accounts operated from locations unrelated to the stated business.

4. Strong Customer Authentication

Strong customer authentication is one of the main protections against account takeover and payment fraud.

A compliant system should ensure that:

  • The authentication elements are independent.
  • Compromise of one element does not compromise the others.
  • Authentication codes cannot be reused.
  • Sensitive information is protected during transmission.
  • Failed attempts trigger appropriate limits or blocking.
  • Sessions automatically expire.
  • New devices are securely registered.
  • Changes to contact information receive enhanced scrutiny.
  • Remote payments are linked to their amount and beneficiary.

A simple SMS code may not provide sufficient protection where fraudsters have already obtained the customer’s credentials or taken control of the victim’s telephone number.

Banks should assess the overall transaction context rather than treating possession of an OTP as conclusive evidence of consent.

5. Transaction Monitoring Systems

Identity theft may pass initial authentication because the criminal has obtained the victim’s credentials. Banks therefore need behavioural and transaction-monitoring controls.

The system should examine:

  • New or unknown devices.
  • Unusual IP addresses.
  • Impossible geographical travel.
  • Changes to the customer’s phone number or email.
  • Password resets followed by immediate transfers.
  • Addition of a new beneficiary.
  • Transactions inconsistent with the customer’s history.
  • Rapid transfers to several accounts.
  • Unusual cash withdrawals.
  • Attempts to increase transfer limits.
  • Repeated failed authentication.
  • Remote-access software running on the device.
  • Account activity at unusual times.
  • Payments to accounts associated with previous fraud.

High-risk events should trigger measures such as:

  • Additional authentication.
  • Temporary payment delay.
  • Manual review.
  • Customer confirmation through an independent channel.
  • Account or payment-instrument blocking.
  • Escalation to the fraud department.
  • Reporting to competent authorities.

Royal Decree-Law 19/2018 permits payment instruments to be blocked for objectively justified security reasons or where unauthorized or fraudulent use is suspected.

6. Protection Against Common Identity-Theft Methods

Phishing and smishing

Criminals create false banking websites or send fraudulent SMS messages to obtain credentials.

Banks should:

  • Monitor deceptive domains.
  • Use anti-spoofing email controls.
  • Warn customers without normalizing constant security alerts.
  • Avoid including login links in sensitive communications.
  • Detect access following suspicious credential resets.
  • Maintain accessible fraud-reporting channels.

Vishing

Fraudsters telephone victims while impersonating bank employees.

A bank should never depend on information that can easily be obtained through social engineering. High-risk payments should require independent confirmation.

SIM-swapping

Criminals transfer the victim’s mobile number to another SIM card.

Controls may include:

  • Detecting recent SIM changes.
  • Restricting high-value transactions after device changes.
  • Avoiding sole dependence on SMS.
  • Using app-based cryptographic authentication.
  • Checking device binding and behavioural signals.

Synthetic identity fraud

A criminal combines real and fabricated information to create a new identity.

Banks should cross-check information, detect repeated use of addresses or devices and examine inconsistencies between income, employment, age, transaction patterns and credit history.

Deepfake fraud

AI-generated images, voices or videos may defeat poorly designed remote onboarding.

Banks should use:

  • Active and passive liveness detection.
  • Challenge-response procedures.
  • Document-chip verification.
  • Deepfake-detection tools.
  • Manual escalation.
  • Multiple independent identity factors.

7. Customer Obligations

Under Article 41 of Royal Decree-Law 19/2018, the customer must:

  • Use the payment instrument according to its conditions.
  • Take reasonable measures to protect personalized security credentials.
  • Notify the provider without undue delay after learning of loss, theft, misappropriation or unauthorized use. 

The customer should therefore avoid:

  • Sharing authentication codes.
  • Approving unexplained app notifications.
  • Disclosing passwords to supposed bank employees.
  • Allowing strangers to install remote-access software.
  • Ignoring unusual account alerts.
  • Delaying notification after discovering fraud.

However, ordinary carelessness is not automatically “gross negligence.” Banks normally need specific evidence showing exceptionally serious disregard of basic precautions.

8. Unauthorized Transactions and Reimbursement

Burden of proof

When the customer denies authorizing a payment, the bank must establish that:

  • The transaction was authenticated.
  • It was accurately recorded.
  • It was properly accounted for.
  • It was not affected by a technical defect.

A system log showing that credentials were entered is relevant, but it does not automatically prove authorization, fraud or gross negligence by the customer.

Immediate reimbursement

For an unauthorized transaction, the bank generally must refund the amount immediately and no later than the end of the next business day after detecting or receiving notice of it.

The bank may temporarily withhold reimbursement where it has reasonable grounds to suspect fraud by the customer and communicates those grounds to the Bank of Spain through the appropriate procedure.

Notification period

The customer must report an unauthorized or incorrectly executed payment without unjustified delay and normally within 13 months of the debit.

Customer liability

The customer may bear losses where:

  • The customer acted fraudulently.
  • The loss resulted from deliberate breach of security obligations.
  • The customer acted with gross negligence.
  • The payment was genuinely authorized, even though the customer was deceived about its commercial purpose.

This last distinction is particularly important in authorised-push-payment fraud. If the victim personally confirms a transfer to the criminal, the bank may argue that the payment was technically authorized. Nevertheless, liability may still arise where the bank ignored obvious fraud indicators, breached contractual duties or failed to apply legally required authentication.

9. Data Protection in Identity-Theft Prevention

Fraud monitoring involves extensive processing of personal information, such as:

  • Device identifiers.
  • IP addresses.
  • Location information.
  • Transaction history.
  • Behavioural profiles.
  • Voice or facial data.
  • Fraud risk scores.
  • Information received from external databases.

Banks must balance security with privacy.

Legal basis

Fraud-prevention processing may be based on:

  • Compliance with legal obligations.
  • Performance of the banking contract.
  • The bank’s legitimate interest in preventing fraud.
  • Substantial public interest, where special-category data is involved and legislation supports the processing.

Consent is not always the appropriate basis because many fraud controls are mandatory and cannot realistically depend on optional consent.

Data minimization

The bank should collect only information necessary for identity verification and fraud prevention. Data should not be retained indefinitely merely because it might someday be useful.

Automated decision-making

A system that automatically rejects an account application or freezes an account can significantly affect the individual. Banks should provide:

  • Clear information about the processing.
  • Meaningful human review.
  • Procedures for challenging false fraud alerts.
  • Controls against discrimination.
  • Regular accuracy and bias testing.

10. Internal Governance and Accountability

The board and senior management should treat identity theft as an enterprise-wide risk.

A sound governance structure includes:

  • A board-approved fraud-risk policy.
  • Clearly allocated management responsibilities.
  • Coordination between fraud, cybersecurity, AML, compliance and data-protection teams.
  • Independent internal audit.
  • Regular risk assessments.
  • Staff background checks.
  • Segregation of duties.
  • Monitoring of privileged access.
  • Employee training.
  • Incident simulations.
  • Vendor oversight.
  • Management information and risk indicators.

Banks should maintain evidence explaining why a transaction was approved, challenged, delayed or blocked. Good recordkeeping is critical when the bank later has to prove authentication or dispute a reimbursement claim.

11. Third-Party and Outsourcing Risks

Identity systems are frequently supplied by external providers offering:

  • Facial recognition.
  • Video verification.
  • document authentication.
  • Cloud infrastructure.
  • Authentication services.
  • Fraud scoring.
  • Credit databases.
  • Electronic signatures.

The bank remains responsible for compliance even when the process is outsourced.

Contracts should address:

  • Security requirements.
  • Accuracy and performance.
  • Data locations.
  • Subcontractors.
  • Audit rights.
  • Incident notification.
  • Business continuity.
  • Data return and deletion.
  • Assistance with regulatory investigations.
  • Exit arrangements.

Under DORA, financial institutions must manage ICT third-party risk throughout the contractual lifecycle.

12. Relevant Case Laws

1. Supreme Court of Spain, Judgment 571/2025, 9 April 2025

The case concerned fraud involving the unlawful use of a customer’s credentials and withdrawal or transfer of funds. The Supreme Court emphasized the statutory allocation of the burden of proof: the bank must prove proper authentication and cannot treat the mere use of credentials as sufficient proof of customer authorization or gross negligence.

Legal importance: This is a major Spanish authority supporting the principle that banks need concrete evidence when seeking to shift identity-theft losses to customers.

2. Provincial Court of Murcia, 2025 – BBVA impersonation fraud

The court ordered BBVA to refund approximately €5,977 to a customer who had been the victim of banking fraud. It applied the doctrine of Supreme Court Judgment 571/2025 and found that use of the victim’s credentials did not by itself establish valid consent or gross negligence.

Legal importance: Banks must demonstrate how the transaction was authorized and how their security system responded to the risk.

3. Provincial Court of Cantabria, 2023 – Liberbank phishing case

A customer lost approximately €25,000 after becoming the victim of phishing. The Provincial Court ordered the bank to compensate her, concluding that the bank had not established fraud or gross negligence by the customer.

Legal importance: Sophisticated social engineering does not automatically make the victim legally responsible. The bank must prove the statutory exception to reimbursement.

4. Provincial Court of Badajoz, 2025 – phishing compensation case

The court upheld a judgment requiring a bank to compensate a customer for approximately €3,441 lost through phishing.

The court examined the bank’s security duties and the absence of sufficient evidence that the victim had intentionally or with gross negligence breached her obligations.

Legal importance: Customer deception must be distinguished from legally serious negligence. Banks carry the evidential burden when relying on gross negligence.

5. Spanish first-instance decision reported in 2024 – absence of strong authentication

A bank was ordered to reimburse approximately €6,000 after a fraudulent transaction because it had not required strong customer authentication capable of preventing the transaction.

Legal importance: Where strong authentication is legally required but not applied, the bank faces substantial difficulty in transferring the loss to the customer.

6. Spanish judgment reported in July 2025 – SMS impersonation fraud

The customer received a fraudulent SMS and later disputed card and account transactions. The court ordered the bank to return the stolen funds after determining that the institution had not sufficiently proved valid authorization or customer fraud.

Legal importance: An SMS that appears inside a legitimate message thread can create highly convincing impersonation. Courts may examine whether the bank’s systems should have detected the unusual transactions.

7. CJEU, DenizBank AG v Verein für Konsumenteninformation, Case C-287/19, 2020

The Court of Justice examined contactless-payment functions and the application of payment-services rules to personalized security features and low-value transactions.

Legal importance: Payment technology and contractual classification cannot be used to weaken mandatory consumer protections. Banks must clearly explain security functions and liability consequences.

8. CJEU, ZG v Beobank SA, Case C-351/21, 2023

The customer disputed a card payment and claimed not to have sufficient information identifying the recipient. The Court held that the payment provider must provide information enabling the payer to identify the natural or legal person who benefited from the payment.

Legal importance: Effective fraud investigation requires meaningful transaction information. Providing only a vague merchant description may be insufficient.

9. CJEU, CRCAM v DM and LR, Case C-337/20, 2021

The Court considered the consequences of delayed notification of unauthorized transactions. It held that the payment-services framework creates specific notification and liability rules, while also addressing how successive unauthorized transactions should be treated.

Legal importance: Customers must report fraud promptly, but liability must be assessed under the structured statutory regime rather than through a general assumption that all losses fall on the customer.

10. CJEU, Bundesverband der Verbraucherzentralen v Deutsche Kreditbank, Case C-602/19, 2021

The case concerned whether information placed in an online banking mailbox satisfied the legal requirement that information be “provided” to the customer.

Legal importance: Security notifications, authentication information and contractual changes must be communicated in a form that meets legal standards. Merely making information technically available may not always be sufficient.

13. Practical Identity-Theft Prevention Model

StageRequired controls
Account openingAuthentic documents, liveness checks and reliable database verification
Customer profileAddress, occupation, expected activity and beneficial ownership
Device registrationSecure binding, risk assessment and independent confirmation
LoginStrong authentication and behavioural monitoring
New beneficiaryDynamic linking, warnings and transaction-risk analysis
High-risk transferStep-up verification or manual review
Profile changeCooling-off period and confirmation through an existing channel
Transaction monitoringDevice, location, velocity and behavioural indicators
Incident handlingImmediate blocking, investigation and evidence preservation
ReimbursementPrompt assessment under Articles 43–46
Data protectionNecessity, proportionality, retention limits and security
Vendor managementDue diligence, audit rights and DORA-compliant contracts

Conclusion

Spanish banks must operate identity-theft prevention as a continuous system rather than a one-time identity check. The system must combine reliable onboarding, strong customer authentication, behavioural monitoring, AML controls, data protection, cybersecurity and rapid incident response.

The key liability rule is particularly important: when a customer denies authorizing a transaction, possession or use of the correct credentials does not automatically prove consent or gross negligence. The bank must produce reliable evidence of authentication and authorization and show that its systems complied with legal security requirements.

Spanish and European case law increasingly places the practical burden on banks to demonstrate that their fraud controls were proportionate, properly configured and capable of responding to foreseeable identity-theft techniques.

 

LEAVE A COMMENT