Banking Law And Identity Verification Fintech Regulation Spain .

Banking Law and Identity Verification in FinTech Regulation in Spain

1. Introduction

Identity verification is one of the most important legal obligations for FinTech businesses operating in Spain. A FinTech company must know who its customers are before allowing them to open accounts, transfer money, obtain credit, invest, trade crypto-assets or use other regulated financial services.

Identity verification in Spain is governed by a combination of:

  • Spanish anti-money-laundering legislation;
  • EU anti-money-laundering rules;
  • Payment-services regulation;
  • Electronic-identification legislation;
  • GDPR and Spanish data-protection law;
  • Digital operational-resilience requirements;
  • Consumer-protection rules;
  • Sector-specific banking, investment and crypto-asset regulation; and
  • Guidance and authorisations issued by SEPBLAC.

The principal regulatory authorities include:

  • Banco de España for banks, payment institutions and electronic-money institutions;
  • CNMV for investment firms, crowdfunding providers and certain crypto-asset services;
  • SEPBLAC for anti-money-laundering supervision;
  • Spanish Data Protection Agency, or AEPD, for privacy and biometric-data matters; and
  • The European Central Bank for significant credit institutions.

Identity verification is not limited to checking an identity card. It includes understanding the customer, verifying beneficial ownership, determining who controls an account, examining the purpose of the relationship and monitoring whether later transactions are consistent with the verified identity.

2. Meaning of Identity Verification

Identity verification is the process by which a FinTech company confirms that a person or legal entity is genuinely who it claims to be.

It normally includes three connected processes:

Identification

The customer provides information such as:

  • Full name;
  • Date and place of birth;
  • Nationality;
  • Residential address;
  • DNI, NIE or passport number;
  • Tax-identification number;
  • Contact details; and
  • Information about occupation or business activities.

Verification

The FinTech checks that the information is genuine by examining reliable and independent documents or electronic sources.

Authentication

After the identity has been verified, authentication confirms that the same person is accessing the account or authorising a transaction.

Identification asks: Who do you claim to be?

Verification asks: Can the claim be proved?

Authentication asks: Are you the same person returning to use the service?

3. Spanish Anti-Money-Laundering Framework

3.1 Law 10/2010

The main Spanish statute is Law 10/2010 on the prevention of money laundering and terrorist financing.

Depending on their regulated activities, covered FinTech entities can include:

  • Credit institutions;
  • Payment institutions;
  • Electronic-money institutions;
  • Investment-service providers;
  • Consumer-credit businesses;
  • Currency-exchange providers;
  • Crowdfunding service providers;
  • Crypto-asset service providers;
  • Money-remittance businesses; and
  • Certain financial intermediaries.

Before establishing a business relationship, an obliged entity must normally identify and verify the customer using reliable documents or permitted electronic procedures.

The entity must not establish or continue a relationship when it cannot properly identify the customer or beneficial owner.

3.2 Royal Decree 304/2014

Royal Decree 304/2014 develops Law 10/2010 and provides more detailed rules concerning:

  • Formal identification;
  • Reliable identification documents;
  • Beneficial ownership;
  • Non-face-to-face relationships;
  • Simplified due diligence;
  • Enhanced due diligence;
  • Record retention;
  • Internal controls; and
  • Reliance on third parties.

The regulations are particularly important for digital-only FinTech firms because their customers may never attend a physical branch.

3.3 Customer due diligence

A FinTech must generally perform the following steps:

  1. Identify the customer.
  2. Verify the customer’s identity.
  3. Identify and verify the beneficial owner.
  4. Understand the purpose and intended nature of the relationship.
  5. Establish the customer’s risk profile.
  6. Monitor transactions throughout the relationship.
  7. Keep the identification information updated.
  8. Investigate inconsistent or suspicious activity.

Identity verification is therefore an ongoing obligation, not a one-time onboarding exercise.

4. Verification of Natural Persons

For an individual, the FinTech should obtain and verify information from an accepted identification document.

Depending on the customer, this may include:

  • Spanish National Identity Document;
  • Foreigner Identity Card;
  • Passport;
  • Official identity document issued by another EU or EEA state; or
  • Another reliable document permitted under Spanish AML rules.

The FinTech should examine:

  • Document validity;
  • Expiry date;
  • Photograph;
  • Security features;
  • Document number;
  • Name and date of birth;
  • Evidence of alteration or forgery;
  • Whether the document has been reported stolen; and
  • Whether the person presenting it matches the document holder.

Automated document verification may support the process, but the regulated firm remains legally responsible for the final result.

5. Verification of Companies and Beneficial Owners

When the customer is a company, checking the company’s commercial name is insufficient.

The FinTech should identify:

  • Legal name;
  • Corporate form;
  • Registered office;
  • Tax-identification number;
  • Registration information;
  • Directors;
  • Persons authorised to operate the account;
  • Ownership structure; and
  • Ultimate beneficial owner.

A beneficial owner is generally the natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted.

The FinTech should examine:

  • Direct and indirect shareholdings;
  • Voting rights;
  • Shareholder agreements;
  • Control through other entities;
  • Trust or fiduciary arrangements;
  • Nominee shareholders;
  • Senior managing officials where no controlling individual can be identified; and
  • Whether any owner is a politically exposed person.

Complex corporate structures should not automatically be accepted merely because each company in the chain is formally registered.

6. Remote and Non-Face-to-Face Verification

6.1 Higher impersonation risk

Digital onboarding creates additional risks, including:

  • Stolen identity documents;
  • Synthetic identities;
  • Deepfake videos;
  • Screen-replay attacks;
  • Facial masks;
  • Manipulated photographs;
  • Fraudulent mobile numbers;
  • Compromised electronic certificates;
  • Money-mule accounts; and
  • Applications submitted through remote-access software.

A remote process should provide assurance equivalent to an appropriately controlled physical process.

6.2 SEPBLAC-authorised procedures

SEPBLAC has authorised regulated entities to use certain non-face-to-face identification procedures, including controlled videoconference and video-identification mechanisms. Its video-identification authorisations have operated alongside other permitted non-face-to-face methods.

A compliant process normally requires:

  • An accepted and valid identity document;
  • A clear image of the customer;
  • Verification that the customer is physically present;
  • Comparison of the customer’s face with the document photograph;
  • Examination of document security elements;
  • Time and date records;
  • Integrity of the video or evidence;
  • Trained personnel or validated automated systems;
  • Security against replay and manipulation;
  • Retention of legally required evidence; and
  • Manual review of doubtful cases.

The FinTech must follow the conditions of the applicable SEPBLAC authorisation. It should not assume that every commercial video-identification product is automatically lawful.

6.3 Liveness detection

Liveness detection attempts to determine whether the applicant is a real person physically present during onboarding.

It may include:

  • Random head movements;
  • Spoken phrases;
  • Blinking instructions;
  • Three-dimensional facial analysis;
  • Challenge-response actions;
  • Detection of screen reflection;
  • Texture analysis;
  • Device and session intelligence; and
  • Detection of injected or prerecorded video.

Liveness technology should be tested against deepfakes, masks, photographs and video-replay attacks.

6.4 Human review

Fully automated verification should include a reliable escalation mechanism.

Human review is particularly important where:

  • The document image is unclear;
  • Facial similarity is uncertain;
  • The customer uses an unusual document;
  • Fraud indicators are detected;
  • The customer is a politically exposed person;
  • Sanctions screening produces a possible match;
  • Several accounts use the same device;
  • The IP address conflicts with the declared location; or
  • The customer has accessibility difficulties.

7. Electronic Identification and eIDAS

The EU eIDAS framework regulates electronic identification, electronic signatures, seals and trust services.

A Spanish FinTech may use:

  • Qualified electronic signatures;
  • Electronic seals;
  • Recognised electronic certificates;
  • Notified national electronic-identification schemes; and
  • Other secure electronic-identification methods permitted under AML rules.

However, possession of an electronic certificate does not remove the FinTech’s AML obligations. The firm must still:

  • Understand the customer’s risk;
  • Identify beneficial ownership;
  • Check sanctions and PEP status;
  • Understand the purpose of the relationship; and
  • Monitor transactions.

The revised eIDAS framework also introduces the European Digital Identity Wallet. As implementation develops, FinTech firms will increasingly be able to receive verified identity attributes through digital credentials. Nevertheless, firms must prevent excessive collection and ensure that wallet-based verification satisfies AML and sector-specific requirements.

8. Payment Services and Strong Customer Authentication

Identity verification during onboarding must be distinguished from strong customer authentication, or SCA, under payment-services law.

SCA normally requires at least two independent elements from the following categories:

  1. Knowledge: something only the customer knows, such as a PIN;
  2. Possession: something only the customer possesses, such as a registered device; and
  3. Inherence: something the customer is, such as a biometric characteristic.

For remote electronic payments, authentication may also need to be dynamically linked to the amount and the payee.

A FinTech must therefore manage two different questions:

  • Was the person properly identified when the account was created?
  • Was the later transaction genuinely authorised by that person?

A payment can be authenticated using registered credentials but still be fraudulent if the credentials or device have been compromised.

9. GDPR and Spanish Data-Protection Law

Identity verification involves extensive processing of personal data. It is governed by:

  • The EU General Data Protection Regulation;
  • Spanish Organic Law 3/2018 on data protection and digital rights; and
  • Sector-specific retention and confidentiality rules.

9.1 Lawful basis

Processing necessary to comply with AML identification requirements will generally be based on a legal obligation.

However, not every additional use of identity data is automatically justified. A FinTech should identify a separate lawful basis before using verification data for:

  • Advertising;
  • Customer profiling unrelated to AML;
  • Product personalisation;
  • Training commercial AI models;
  • Sale or disclosure to unrelated entities; or
  • Behavioural analytics unrelated to fraud prevention.

9.2 Data minimisation

The FinTech should collect only what is reasonably necessary.

For example, if the law requires confirmation of age, storing an unnecessary complete copy of an identification document may be disproportionate where a reliable age attribute would be sufficient.

AML rules may nevertheless require more extensive collection and retention in regulated situations. The firm must reconcile its data-minimisation duty with its statutory compliance obligations.

9.3 Biometric data

Facial templates used to uniquely identify a customer can constitute special-category biometric data.

The FinTech must establish:

  • A lawful basis under Article 6 GDPR;
  • An applicable condition under Article 9 GDPR;
  • Necessity and proportionality;
  • Strict retention limits;
  • Strong security;
  • Restricted internal access;
  • A data-protection impact assessment where required; and
  • Safeguards against secondary use.

Consent may be inappropriate where the customer has no genuine alternative or where the processing is required by law.

9.4 Automated decision-making

Automated systems may reject a customer because of:

  • Facial mismatch;
  • Document inconsistency;
  • Fraud score;
  • Sanctions match;
  • Device-risk score; or
  • Suspected synthetic identity.

Where an automated decision produces legal or similarly significant effects, Article 22 GDPR may apply.

The FinTech should provide:

  • Meaningful information about the process;
  • An opportunity to contest the result;
  • Human intervention;
  • Correction of inaccurate information; and
  • A process for handling false positives.

9.5 Security and breaches

Identification data is highly valuable to criminals. Appropriate security should include:

  • Encryption;
  • Separation of biometric templates from identity records;
  • Access logging;
  • Privileged-access controls;
  • Data-loss-prevention systems;
  • Secure deletion;
  • Vendor monitoring;
  • Penetration testing;
  • Incident-response arrangements; and
  • Breach-notification procedures.

10. DORA and Operational Resilience

The Digital Operational Resilience Act has applied since 17 January 2025 to a broad range of regulated financial entities.

Identity-verification systems may be treated as critical or important ICT services because failure could prevent onboarding, create fraud exposure or interrupt regulated financial services.

A FinTech should therefore manage:

  • ICT risks affecting verification systems;
  • Availability of onboarding services;
  • Cyberattacks against identity databases;
  • Third-party verification vendors;
  • Cloud concentration;
  • Incident reporting;
  • Business continuity;
  • Backup and recovery;
  • Resilience testing; and
  • Contractual rights against ICT providers.

Outsourcing identity verification does not outsource regulatory responsibility.

11. New EU Anti-Money-Laundering Regulation

Regulation (EU) 2024/1624 creates a more harmonised EU AML rulebook. Most of its operative requirements will apply from 10 July 2027.

Until then, Spanish FinTech firms remain principally subject to the existing Spanish framework implementing the current EU AML directives. Firms should nevertheless prepare for the new regulation because it will introduce more directly harmonised requirements across Member States.

The new framework emphasises that customer due diligence is wider than basic identity verification. It includes understanding beneficial ownership, the intended relationship and the customer’s risk.

12. Liability for Verification Failures

A FinTech may face several forms of liability.

Administrative liability

SEPBLAC, Banco de España, CNMV or the AEPD may investigate failures involving:

  • Inadequate customer identification;
  • Failure to identify beneficial owners;
  • Weak remote-verification procedures;
  • Insufficient transaction monitoring;
  • Excessive collection of personal data;
  • Unlawful biometric processing;
  • Poor data security;
  • Deficient outsourcing controls; or
  • Failure to retain required evidence.

Civil liability

A customer may claim compensation where negligent verification permits:

  • Identity theft;
  • Account takeover;
  • Unauthorised credit;
  • Fraudulent payments;
  • Misuse of personal data; or
  • Damage caused by an incorrect sanctions or fraud match.

Criminal liability

Criminal responsibility may arise where individuals knowingly facilitate:

  • Money laundering;
  • Terrorist financing;
  • Document forgery;
  • Identity theft;
  • Computer fraud;
  • Unlawful system access; or
  • Use of mule accounts.

Contractual liability

A regulated entity can also be liable to business partners where it falsely represents that customers were properly verified or fails to meet agreed verification standards.

13. Important Case Laws

Case 1: Safe Interenvíos SA v Liberbank SA, Banco de Sabadell SA and Banco Bilbao Vizcaya Argentaria SA

Court of Justice of the European Union, Case C-235/14, 10 March 2016

Facts

Safe Interenvíos provided money-transfer services. Spanish banks closed or restricted its accounts because of money-laundering concerns. Safe argued that the banks were not entitled to apply their own due-diligence measures because it was itself a regulated payment institution.

Judgment

The Court held that the AML framework did not necessarily prevent a bank from applying enhanced customer-due-diligence measures to another regulated financial institution where circumstances justified higher scrutiny. Such measures had to remain proportionate and risk-based.

Importance

A Spanish FinTech’s licence does not make it exempt from identity verification by its banking partners.

Banks may require information about:

  • The FinTech’s customers;
  • Beneficial owners;
  • Transaction flows;
  • AML systems;
  • Agents and distributors; and
  • Geographic exposure.

However, account restrictions should be supported by a genuine risk assessment rather than a general assumption that all FinTech businesses are high risk.

Case 2: Jyske Bank Gibraltar Ltd v Administración del Estado

CJEU, Case C-212/11, 25 April 2013

Facts

A bank established in Gibraltar provided services in Spain without a Spanish branch. Spanish law required information concerning certain transactions to be sent directly to Spanish AML authorities.

Judgment

The Court accepted that Spain could impose direct reporting obligations where justified by the prevention of money laundering, provided the measures complied with EU law and proportionality.

Importance

A FinTech providing cross-border services into Spain cannot assume that home-state supervision removes every Spanish AML obligation.

Identity verification and reporting systems must consider:

  • The location of customers;
  • The place where services are offered;
  • Passporting arrangements;
  • Spanish AML reporting requirements; and
  • Cooperation between national authorities.

Case 3: Ordre des barreaux francophones et germanophone and Others

CJEU, Case C-305/05, 26 June 2007

Facts

The case concerned the application of AML identification and reporting obligations to lawyers and whether those obligations interfered with professional confidentiality and the right to a fair trial.

Judgment

The Court upheld AML obligations but recognised limits connected with judicial proceedings and legal advice closely associated with such proceedings.

Importance

The judgment illustrates that customer identification and reporting obligations may interfere with confidentiality rights but can be justified for preventing money laundering.

FinTech firms must balance AML duties with:

  • Privacy;
  • Confidentiality;
  • Legal privilege;
  • Data minimisation; and
  • Fundamental rights.

Case 4: Orange România SA v ANSPDCP

CJEU, Case C-61/19, 11 November 2020

Facts

A telecommunications provider retained copies of customers’ identity documents. The dispute concerned whether customers had validly consented to the copying and storage.

Judgment

The Court held that consent must be freely given, specific, informed and demonstrated by the controller. A pre-selected contractual clause was insufficient, and the customer should not bear the burden of proving refusal.

Importance

A Spanish FinTech should not treat a signed contract as automatic permission to copy and reuse an identity document.

Where copying is legally required, the firm should rely on the relevant legal obligation. Where it is optional, consent must satisfy GDPR standards.

The company should clearly explain:

  • Whether copying is mandatory;
  • The legal basis;
  • The purpose;
  • The retention period;
  • Who receives the copy; and
  • The consequences of refusing.

Case 5: Wirtschaftsakademie Schleswig-Holstein GmbH

CJEU, Case C-210/16, 5 June 2018

Facts

An organisation operated a social-media page while the platform collected and analysed visitor data.

Judgment

The Court found that more than one party could be jointly responsible for data processing where both contributed to determining its purposes and means.

Importance

A FinTech and an external identity-verification provider may be joint controllers in some circumstances.

The parties must carefully determine whether the provider is:

  • An independent controller;
  • A joint controller; or
  • A processor acting only on the FinTech’s instructions.

The contractual label is not decisive. The actual allocation of decision-making power matters.

Case 6: Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW

CJEU, Case C-40/17, 29 July 2019

Facts

A website transmitted visitor data to a social-media platform through an embedded component.

Judgment

The Court held that an organisation may be jointly responsible for the collection and transmission stage even if it does not control all later processing.

Importance

Where a FinTech integrates a third-party verification tool into its app, it may remain responsible for:

  • Data collected through the interface;
  • Transmission to the provider;
  • Customer information;
  • Lawful basis; and
  • Security of the integration.

The FinTech cannot avoid responsibility simply because the provider’s software performs the technical verification.

Case 7: Meta Platforms Ireland Ltd v Bundeskartellamt

CJEU, Case C-252/21, 4 July 2023

Facts

The case concerned the combination of personal data from several services and sources for personalised processing.

Judgment

The Court examined the legal bases for processing and confirmed that contractual necessity must be interpreted strictly. Processing is not “necessary for a contract” merely because it is commercially useful.

Importance

Identity data collected for KYC should not automatically be combined with unrelated data for advertising, personalisation or behavioural profiling.

A Spanish FinTech must separate:

  • Legally required identity verification;
  • Fraud prevention;
  • Credit assessment;
  • Marketing;
  • Product analytics; and
  • AI-model training.

Each purpose requires an appropriate legal basis.

Case 8: Österreichische Post AG

CJEU, Case C-300/21, 4 May 2023

Facts

The claimant sought compensation for alleged non-material damage caused by unlawful processing of personal data.

Judgment

The Court held that a GDPR infringement alone does not automatically create a right to compensation. There must be damage and a causal connection, although national courts cannot impose an artificial seriousness threshold.

Importance

A verification failure can produce regulatory liability even where the customer cannot prove compensable damage. When actual financial, emotional or reputational harm is established, compensation may also become available.

Case 9: RW v Österreichische Post AG

CJEU, Case C-154/21, 12 January 2023

Facts

A data subject requested information about the recipients to whom personal data had been disclosed.

Judgment

The Court held that the controller must generally provide the actual identity of recipients, not merely categories of recipients, unless identification is impossible or the request is manifestly unfounded or excessive.

Importance

A FinTech must maintain reliable records showing whether identity data was shared with:

  • Verification vendors;
  • Cloud providers;
  • Credit-reference agencies;
  • Fraud-prevention networks;
  • Group companies;
  • Payment processors; or
  • Public authorities.

14. Compliance Model for Spanish FinTech Firms

A strong verification system should follow these stages:

Stage 1: Risk classification

Determine risk by considering:

  • Product;
  • Customer type;
  • Country;
  • Delivery channel;
  • Transaction size;
  • Ownership structure;
  • PEP status;
  • Sanctions exposure; and
  • Fraud indicators.

Stage 2: Identity collection

Collect only necessary identity attributes and explain their purpose.

Stage 3: Document authentication

Check the document’s validity, security features, integrity and issuing authority.

Stage 4: Person-to-document matching

Use controlled video, facial comparison or another legally permitted method.

Stage 5: Liveness and anti-spoofing

Test whether the applicant is physically present and whether the session is genuine.

Stage 6: Screening

Screen the customer and beneficial owners against:

  • Sanctions lists;
  • PEP databases;
  • Relevant adverse information; and
  • Internal fraud records.

Stage 7: Approval and escalation

Refer uncertain or high-risk applications for trained human review.

Stage 8: Ongoing monitoring

Monitor whether activity remains consistent with the verified identity and declared purpose.

Stage 9: Reverification

Reverify identity when:

  • Documents expire;
  • Contact details materially change;
  • A new device is registered;
  • Account recovery is requested;
  • Fraud indicators emerge;
  • Ownership changes; or
  • Existing information becomes unreliable.

Stage 10: Audit evidence

Retain evidence sufficient to show:

  • What information was collected;
  • Which checks were performed;
  • Which system or person approved the customer;
  • The result of sanctions and PEP screening;
  • Reasons for overrides;
  • Subsequent changes; and
  • Compliance with retention requirements.

15. Practical Legal Checklist

A FinTech operating in Spain should ensure that:

  1. It is properly authorised or registered.
  2. Its AML status is correctly determined.
  3. Its verification method is permitted under Spanish law.
  4. SEPBLAC conditions for remote identification are followed.
  5. Natural persons and beneficial owners are verified.
  6. Higher-risk customers receive enhanced due diligence.
  7. Biometric processing has valid legal grounds.
  8. A data-protection impact assessment is completed where necessary.
  9. Automated rejection decisions can be reviewed by a human.
  10. Verification vendors undergo legal and security due diligence.
  11. Vendor contracts allocate data-protection and audit responsibilities.
  12. Identity evidence is securely retained.
  13. Data is not reused for incompatible commercial purposes.
  14. Deepfake and replay risks are regularly tested.
  15. DORA requirements are incorporated into vendor and ICT controls.
  16. Customers can correct inaccurate identity information.
  17. Account recovery receives controls equivalent to initial onboarding.
  18. Suspicious activity is escalated to the AML function.
  19. Significant incidents are reported to the competent authorities.
  20. The system is independently audited and regularly updated.

Conclusion

Identity verification under Spanish FinTech regulation is not simply a document-checking requirement. It is a continuing legal process combining AML due diligence, fraud prevention, payment authentication, privacy, cybersecurity and operational resilience.

Spanish FinTech companies may use remote onboarding, videoconferencing, electronic identification, biometric comparison and automated verification. However, they remain responsible for ensuring that these methods are lawful, proportionate, secure and sufficiently reliable.

The case law demonstrates five central principles:

  • A regulated FinTech can still be subjected to enhanced verification by its bank.
  • Cross-border digital activity may remain subject to Spanish AML obligations.
  • Copying an identity document requires a clear lawful basis.
  • Outsourcing verification does not eliminate the FinTech’s responsibility.
  • Identity data collected for compliance cannot automatically be reused for advertising or unrelated profiling.

The safest legal approach is a risk-based verification system that combines reliable technology, human escalation, transparent data processing, continuing monitoring and complete audit evidence.

LEAVE A COMMENT