Banking Law And Open Banking Consent Frameworks Spain .
Banking Law and Open Banking Consent Frameworks in Spain
1. Introduction
Open banking has fundamentally changed the relationship between banks, customers and financial-technology companies in Spain. Traditionally, information concerning a customer's bank account remained largely within the bank maintaining that account. Open banking allows authorised third-party providers to access certain account information or initiate payments when the customer has given the necessary authorisation.
The central legal issue is therefore consent.
Spanish banking law does not permit an open-banking provider simply to access an individual's account because the provider has a commercial relationship with a bank. Access must be connected to the customer's decision to use the relevant service.
Spain's principal payment-services legislation is Royal Decree-Law 19/2018 of 23 November on payment services and other urgent financial measures, which implemented much of Directive (EU) 2015/2366, commonly known as PSD2.
The legislation recognises two particularly important open-banking services:
Payment Initiation Services (PIS) – where a third-party provider initiates a payment from the customer's bank account.
Account Information Services (AIS) – where a third-party provider obtains information from one or more payment accounts, normally so that the customer can see consolidated financial information.
Spanish law expressly recognises the customer's right to use account-information services when the relevant payment account is accessible online.
2. Legal Sources Governing Consent
Open-banking consent in Spain operates through several overlapping legal regimes.
The most important are:
Royal Decree-Law 19/2018 on payment services;
Directive (EU) 2015/2366 (PSD2);
Regulation (EU) 2016/679 (GDPR);
Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights;
Commission Delegated Regulation (EU) 2018/389 concerning strong customer authentication and secure communication;
general Spanish consumer-protection and contract law.
Consequently, the word "consent" does not always have exactly the same legal function.
A customer's payment consent determines whether a payment transaction is authorised.
A customer's open-banking authorisation determines whether a third-party payment provider may provide the requested service.
Separately, the GDPR determines whether particular processing of personal data has an appropriate lawful basis.
These concepts overlap, but they should not automatically be treated as identical.
3. Consent to Payment Transactions
Article 36 of Royal Decree-Law 19/2018 establishes the basic Spanish rule.
A payment transaction is regarded as authorised when the payer has given consent to its execution. If the required consent does not exist, the transaction is treated as an unauthorised payment transaction.
The payer and payment-service provider normally agree on the method through which consent will be communicated.
Consent can generally be provided before execution. Where the parties have validly agreed to it, authorisation may also occur afterwards.
Spanish law therefore treats consent as one of the fundamental dividing lines between authorised and unauthorised banking transactions.
4. Withdrawal of Consent
Consent is not necessarily permanent.
Under Article 36, a payer can generally withdraw consent until the transaction reaches the legally defined point of irrevocability.
This becomes particularly important where the customer has authorised a series of transactions.
If consent covering a series of payments is withdrawn, subsequent transactions that would otherwise have fallen within that authorisation are treated as unauthorised.
Open-banking systems should therefore distinguish between:
granting consent;
continuing consent;
withdrawal of consent; and
transactions that have already become irrevocable.
A consent-management system should not treat a historical authorisation as unlimited permission for future activity.
5. Explicit Consent and Payment Initiation Services
Payment initiation services allow an authorised third-party provider to initiate a payment from the customer's account.
Article 38 of Royal Decree-Law 19/2018 provides important safeguards.
Where the payer gives the necessary explicit consent, the account-servicing bank must enable the payer to exercise the right to use an authorised payment-initiation service.
However, the payment-initiation provider is subject to strict limitations.
Among other requirements, it must:
protect the customer's personalised security credentials;
communicate securely with the bank;
avoid storing sensitive payment data;
request only information necessary for providing the payment-initiation service;
avoid using account information for unrelated purposes; and
not change fundamental characteristics of the transaction without authority.
The principle is therefore purpose-limited access.
Permission to initiate one payment does not automatically constitute permission to use the customer's banking information for unrelated commercial purposes.
6. Consent for Account Information Services
Account information services create an even clearer consent requirement.
Article 39 of Royal Decree-Law 19/2018 states that an account-information service provider must provide its services exclusively on the basis of the payment-service user's explicit consent.
The provider may access only information concerning the payment accounts designated by the customer and the corresponding payment transactions.
It must not request sensitive payment data linked to those accounts and must not use, store or access information for purposes other than providing the account-information service expressly requested by the customer.
This creates an important principle:
Consent must relate to a defined service and defined accounts rather than constituting unlimited access to the customer's financial life.
7. Data Minimisation and Purpose Limitation
Open-banking consent must also be considered alongside GDPR principles.
Financial information may reveal extensive information about an individual. Transaction histories can indicate shopping patterns, subscriptions, travel, income and other aspects of everyday life.
Therefore, an open-banking provider should identify:
what information is required;
which accounts will be accessed;
why access is necessary;
how long information will be retained;
whether information will be disclosed to another entity; and
what lawful basis supports each processing activity.
PSD2 itself reinforces this approach.
A payment-initiation provider cannot request information beyond what is necessary for providing the requested payment-initiation service.
Similarly, an account-information provider cannot use account information for purposes outside the expressly requested service.
Thus, the architecture of open banking is based on controlled rather than unrestricted data access.
8. Consent and GDPR Are Not Exactly the Same
A particularly important legal distinction concerns PSD2 consent and GDPR consent.
PSD2 uses "explicit consent" as part of the regulatory framework governing payment services and access to accounts.
GDPR separately establishes lawful bases for processing personal data.
Therefore, a financial institution should not assume that every reference to "explicit consent" under payment-services legislation necessarily means that GDPR consent is the lawful basis for every processing operation.
For example, depending upon the activity, processing might instead be necessary for:
performing a contract;
complying with a legal obligation; or
another lawful basis recognised under GDPR.
The provider must therefore conduct two related inquiries:
Payment-services question: Has the customer properly authorised the payment or open-banking service?
Data-protection question: What lawful basis permits the associated processing of personal data?
Treating these as identical can create compliance problems.
9. Consent Must Be Specific and Informed
Where GDPR consent is relied upon, the customer's decision must satisfy the GDPR standard.
The customer should understand what is being authorised.
An effective open-banking consent interface should therefore clearly identify matters such as:
the third-party provider;
the service being requested;
relevant accounts;
categories of information involved;
purposes for which information will be processed;
relevant duration;
whether information will be disclosed further; and
mechanisms for withdrawing consent where applicable.
A broad statement such as "I agree that my financial data may be used for services" may be legally problematic where it does not adequately identify the relevant purposes.
10. Active Consent
European data-protection jurisprudence strongly supports an active model of consent.
Silence, inactivity or automatically selected options are generally inadequate where GDPR consent is the legal basis.
Digital interfaces therefore should not be designed so that customers accidentally approve financial-data processing.
Customers should take a genuine affirmative action demonstrating their decision.
This principle is particularly important for mobile banking applications because interface design can determine whether consent represents a genuine choice or merely the result of default settings.
11. Strong Customer Authentication
Consent and authentication must also be distinguished.
A customer may consent to a transaction, while authentication provides evidence that the person interacting with the system is properly authenticated.
PSD2 requires Strong Customer Authentication (SCA) in important circumstances, including when a payer:
accesses a payment account online;
initiates an electronic payment; or
carries out certain remote actions presenting payment-fraud risks.
For remote electronic payments, authentication must ordinarily include dynamic linking connecting the transaction with a particular amount and payee.
Strong authentication therefore protects the process through which consent is implemented, but authentication itself should not automatically be equated with consent for unrelated data processing.
12. Bank's Obligations Toward Third-Party Providers
Open banking would be ineffective if banks could arbitrarily refuse access whenever customers selected competing third-party services.
Spanish law therefore requires account-servicing payment-service providers to communicate securely with authorised third-party providers and, in the account-information context, generally to treat their data requests without discrimination except where objective reasons justify different treatment.
A bank can nevertheless deny access in specified circumstances involving objectively justified and properly documented concerns about unauthorised or fraudulent access.
Thus, the legal framework attempts to balance:
customer control + competition + innovation + banking security.
Important Case Law
Because Spain implements EU payment-services and data-protection legislation, judgments of the Court of Justice of the European Union (CJEU) are especially important. Not all of the following disputes originated in Spain, but their interpretation of EU rules is relevant to Spanish banks, fintech companies and courts.
1. Planet49 GmbH – Case C-673/17 (2019)
Facts
Planet49 operated an online promotional service involving consent mechanisms including checkboxes. One important question was whether a pre-selected checkbox could constitute valid consent.
Decision
The CJEU held that consent requiring an active indication of the user's wishes could not validly be established through a pre-ticked checkbox.
Importance for Spanish Open Banking
Planet49 establishes an important digital-consent principle: inactivity is not equivalent to affirmative consent.
For Spanish open-banking platforms, this supports the use of active customer choices rather than pre-selected permissions.
A fintech should therefore avoid designing consent interfaces in which account access, additional data processing or optional sharing is automatically selected.
The judgment is especially relevant where GDPR consent is being relied upon as the lawful basis.
2. Orange România SA – Case C-61/19 (2020)
Facts
The case concerned a telecommunications provider collecting and storing copies of customers' identity documents.
The CJEU considered whether customers had validly consented to that processing.
Decision
The Court emphasised that consent must represent a freely given, specific and informed indication of the data subject's wishes.
The controller also carries responsibility for demonstrating that valid consent exists.
Importance for Spain
Although the dispute involved telecommunications rather than banking, its GDPR interpretation directly affects financial institutions.
An open-banking provider relying on consent should therefore be capable of demonstrating:
what information was presented;
what the customer selected;
when consent was provided;
the scope of that consent; and
whether the customer's action genuinely demonstrated agreement.
The decision makes evidence of consent almost as important operationally as obtaining consent itself.
3. DenizBank AG v Verein für Konsumenteninformation – Case C-287/19 (2020)
Facts
The dispute concerned payment services and the NFC/contactless functionality of personalised bank cards.
Among other matters, the Court examined contractual provisions dealing with tacit consent to changes in a payment-services framework contract.
Decision
The CJEU interpreted PSD2 provisions concerning information and conditions associated with tacit acceptance of amendments to framework contracts.
It also stressed that consumer terms remain capable of review under EU unfair-contract-terms legislation.
Importance for Spanish Banking
This case is particularly relevant because it concerns PSD2 itself.
It demonstrates that "consent" in payment law can operate differently depending upon context.
Consent to an individual payment transaction, consent to open-banking access and contractual mechanisms concerning acceptance of changes to framework agreements must not automatically be treated as the same legal concept.
Spanish banks therefore need carefully drafted framework agreements and customer notices.
4. Meta Platforms and Others – Case C-252/21 (2023)
Legal Issue
The case concerned GDPR lawful bases and the relationship between extensive personal-data processing, contractual necessity and consent.
Principle
The CJEU adopted an important interpretation of when processing can genuinely be considered necessary for performing a contract and examined circumstances affecting whether consent can be considered freely given.
Importance for Open Banking
The judgment matters where an open-banking or financial platform attempts to justify extensive secondary data processing simply because the customer has entered into a service contract.
A provider should distinguish information genuinely necessary for delivering the requested financial service from information valuable mainly for additional commercial purposes.
This reinforces the importance of purpose separation in open-banking consent architecture.
5. Österreichische Post AG – Case C-300/21 (2023)
Facts
The dispute concerned compensation under Article 82 GDPR for unlawful personal-data processing.
Decision
The CJEU held, among other things, that infringement of GDPR alone does not automatically produce a right to compensation: damage and a causal connection are also required.
At the same time, EU law does not impose a general minimum "seriousness" threshold before non-material damage can potentially qualify.
Importance for Spanish Financial Institutions
Open-banking providers process potentially sensitive financial information.
A breach of consent requirements can therefore create several forms of legal exposure:
regulatory enforcement;
orders restricting processing;
contractual consequences; and
potentially compensation claims where the requirements for GDPR damages are satisfied.
The case illustrates why consent-management failures are not merely technical compliance problems.
6. Verbraucherzentrale Bundesverband / Facebook – Case C-319/20 (2022)
Legal Issue
The dispute concerned enforcement of GDPR-related consumer rights by consumer-protection organisations.
Principle
The CJEU recognised, subject to the relevant statutory conditions, an important role for representative consumer organisations in proceedings concerning infringements connected with personal-data processing.
Importance for Spain
The significance for open banking is institutional.
Consent practices may affect thousands or millions of customers simultaneously because banks and fintech providers normally use standardised digital interfaces.
Consequently, questionable consent mechanisms can potentially create not merely individual disputes but broader consumer-protection and regulatory exposure.
7. Meta Platforms Ireland – Case C-446/21 (2024)
Legal Issue
This case further developed GDPR principles concerning the processing and use of personal data, particularly the limits imposed by principles such as purpose limitation and data minimisation.
Importance for Open Banking
The broader lesson is particularly relevant to financial-data aggregation.
A customer making information available in one context does not necessarily authorise unlimited processing of that information indefinitely or for unrelated purposes.
For Spanish fintech businesses, collecting more banking information than necessary simply because the technology permits it conflicts with the regulatory direction toward data minimisation and purpose-specific processing.
Practical Spanish Consent Framework
A compliant Spanish open-banking consent process can therefore be understood as a sequence.
Stage 1 – Customer Requests the Service
The customer chooses an account-information or payment-initiation service.
The provider should clearly identify the service requested.
Stage 2 – Scope Is Defined
The customer should understand which account or accounts are involved and what access is necessary.
Stage 3 – Information Is Provided
Relevant contractual, payment-services and data-protection information should be supplied clearly.
Stage 4 – Explicit Customer Action
Where explicit consent is required, the customer takes an affirmative action demonstrating that decision.
Stage 5 – Authentication
Where required, strong customer authentication verifies the customer's interaction with the bank or payment infrastructure.
Stage 6 – API Access
The third-party provider communicates securely with the account-servicing bank.
Stage 7 – Limited Data Processing
Only information necessary for the authorised service should be accessed and used.
Stage 8 – Consent Records
The provider should maintain appropriate evidence of the customer's authorisation and associated information.
Stage 9 – Withdrawal or Expiry
Where consent is withdrawn or the relevant authority expires, future access must be handled accordingly.
Stage 10 – Continued Security
Banks and third-party providers remain responsible for protecting credentials, preventing unauthorised access and maintaining secure communication.
Consent Revocation
Revocation is particularly important.
For payment transactions, Article 36 of Royal Decree-Law 19/2018 permits withdrawal until the legally applicable point of irrevocability.
Where consent concerns a series of transactions, withdrawal means subsequent transactions covered by the earlier consent are treated as unauthorised.
For personal-data processing based specifically on GDPR consent, GDPR rules concerning withdrawal must separately be considered.
This produces an important distinction:
withdrawing data-processing consent does not necessarily undo a payment that has already become irrevocable.
Payment law and data-protection law therefore have different operational consequences.
Liability for Invalid Consent
If a transaction lacks legally effective authorisation, it may be classified as an unauthorised transaction under payment-services legislation.
This can trigger statutory rules governing reimbursement and allocation of liability between the payer and payment-service providers.
Separately, unlawful processing of account information can lead to GDPR consequences.
Accordingly, one incident may potentially involve several bodies of law:
Payment law – Was the transaction authorised?
Data-protection law – Was personal information lawfully processed?
Contract law – Did the provider comply with the framework agreement?
Consumer law – Were contractual provisions or practices unfair?
Regulatory law – Did the bank or fintech comply with licensing, security and operational obligations?
These questions must be analysed independently even though they arise from the same transaction.
Consent and API Governance
APIs provide the technical infrastructure through which much open-banking access occurs.
However, an API connection does not itself create legal authority to access customer information.
The legal sequence is essentially:
Customer authority → authenticated interaction → authorised provider → secure interface → permitted information → permitted purpose.
Therefore, technical ability should never be confused with legal permission.
A provider capable of retrieving extensive transaction histories may nevertheless be legally entitled to retrieve only information falling within the service requested by the customer.
Role of the Banco de España
The Banco de España has an important supervisory role in Spain's payment-services framework.
Payment institutions and relevant third-party payment providers operate within regulatory requirements concerning authorisation or registration, security and conduct.
Banks cannot simply create private arrangements that defeat customers' statutory ability to use legitimate payment-initiation or account-information services.
At the same time, account-servicing banks retain important security responsibilities and may restrict third-party access where objectively justified concerns involving unauthorised or fraudulent access exist.
The Spanish model therefore does not create an unconditional right for every technology company to obtain banking information.
Access exists within a regulated ecosystem of authorised providers, customer authority and security controls.
Relationship Between Competition and Consent
Open banking also has an important competition dimension.
Before PSD2, incumbent banks possessed significant control over customer account infrastructure and information.
Open banking reduces that exclusivity by allowing customers to use regulated third-party services.
However, competition cannot justify removing customer control.
The model therefore attempts to achieve two objectives simultaneously:
First, banks should not unnecessarily obstruct legitimate third-party access.
Second, third-party providers should not obtain more information than the customer has authorised or than is necessary for the requested service.
Consent therefore functions as an important bridge between financial competition and individual control over banking information.
Conclusion
Spain's open-banking consent framework is based on the principle that the customer remains central to access and use of payment-account information.
Royal Decree-Law 19/2018 provides the principal Spanish payment-services framework. A payment transaction generally requires the payer's consent, while payment-initiation and account-information services operate under more specific rules requiring explicit customer authority. Account-information providers may access only designated accounts and must not use account data for purposes outside the service expressly requested by the customer.
At the same time, GDPR adds another layer of protection. Where GDPR consent is relied upon, it must satisfy EU requirements concerning a genuine, informed and affirmative choice. Cases such as Planet49 (C-673/17), Orange România (C-61/19), DenizBank (C-287/19), Meta Platforms (C-252/21), Österreichische Post (C-300/21), Verbraucherzentrale/Facebook (C-319/20), and Meta Platforms Ireland (C-446/21) collectively demonstrate that consent, transparency, proof, purpose limitation, contractual fairness and accountability are central elements of modern digital financial regulation.
The most important point is that open banking does not mean open-ended banking data access. It means regulated access for a defined service, through secure systems, under customer authority and subject to continuing payment-services, data-protection, contractual and consumer-protection obligations.

comments