Banking Law And Open Banking Contracts Spain .
Banking Law and Open Banking Contracts in Spain
1. Introduction
Open banking has significantly changed the contractual relationship between banks, customers and financial technology providers in Spain. Traditionally, a customer entered into a banking contract directly with a bank, and the bank controlled access to the customer's account and payment infrastructure. Open banking introduces additional regulated participants that may access payment-account information or initiate payments when the customer authorises them.
Spain's open-banking contractual framework is principally derived from the EU Second Payment Services Directive, commonly called PSD2, implemented in Spain mainly through Royal Decree-Law 19/2018 of 23 November on payment services and other urgent financial measures. The legislation regulates payment-service contracts, payment authorisation, account-information services, payment-initiation services, contractual transparency and liability.
Open banking therefore does not eliminate the traditional bank-customer contract. Instead, it creates a multi-party contractual environment involving the customer, the account-servicing bank and, where applicable, a third-party provider.
2. Main Parties to an Open Banking Contract
Three participants are particularly important.
Account Servicing Payment Service Provider
The Account Servicing Payment Service Provider (ASPSP) is normally the customer's bank. It maintains the customer's payment account and provides the technical infrastructure through which account information and payments are processed.
Account Information Service Provider
An Account Information Service Provider (AISP) accesses information from one or several payment accounts and normally presents the information to the customer through an application or digital platform.
Spanish legislation specifically recognises the user's right to use account-information services where the relevant payment account is accessible online.
Importantly, Spanish law states that an account-information service does not depend upon the existence of a separate contractual relationship between the AISP and the account-servicing bank.
This provision is fundamental to open banking. A bank cannot simply argue that a fintech company lacks a bilateral commercial agreement with the bank and therefore cannot access an eligible account.
Payment Initiation Service Provider
A Payment Initiation Service Provider (PISP) initiates a payment from the customer's bank account at the customer's request.
Instead of entering the bank's own application and making the payment directly, the customer can instruct a regulated PISP to initiate it.
The customer's bank remains responsible for maintaining the payment account, while the PISP provides the initiation service.
3. The Contractual Structure
Open banking can produce several overlapping contractual relationships.
The first is the traditional bank-customer framework contract governing the payment account.
The second may be a customer-AISP contract, under which the customer permits a provider to retrieve and organise account information.
The third may be a customer-PISP contract, under which a provider initiates payments on behalf of the customer.
There may also be technical or commercial agreements between banks and fintech providers. However, PSD2-based statutory access rights mean that regulated access cannot generally be made dependent on a private bilateral contract between the bank and the AISP/PISP where the legislation gives the provider an independent right of access.
Spanish law defines a framework contract essentially as a payment-services contract governing future individual or successive payment transactions and potentially providing for the opening of a payment account.
4. Formation of the Open Banking Contract
General Spanish contract law remains relevant.
A valid banking or fintech contract ordinarily requires the usual elements of contractual consent, an identifiable contractual object and lawful contractual purpose.
However, because open banking concerns regulated payment services and potentially sensitive financial information, ordinary contract rules operate together with specialised payment-services legislation, consumer law and data-protection requirements.
The provider must therefore clearly identify matters such as:
the service being supplied;
the identity of the provider;
fees or charges where applicable;
methods of communication;
security procedures;
payment-authorisation procedures;
circumstances permitting blocking or refusal;
liability arrangements;
complaint procedures;
duration of the agreement; and
termination arrangements.
The regulatory philosophy is that contractual consent should be meaningful rather than hidden inside unclear digital terms.
5. Explicit Consent in Open Banking
Consent is one of the most important elements of Spanish open-banking law.
Under Article 36 of Royal Decree-Law 19/2018, a payment transaction is authorised when the payer has consented to its execution. Without such consent, it is treated as an unauthorised transaction. Consent may also be communicated through a payment-initiation provider.
The customer and payment-service provider may contractually establish the manner in which consent is provided.
Consent can normally be withdrawn until the point at which the payment order becomes irrevocable.
For account-information services, Spanish legislation goes further: an AISP must provide its services only on the basis of the user's explicit consent.
Thus, merely having an account with a bank does not amount to permission for an unrelated fintech provider to access it.
The Bank of Spain similarly describes open banking as financial information being shared digitally and securely under conditions expressly authorised by customers, with customers retaining the ability to withdraw that permission.
6. Consent and the Underlying Banking Contract Are Different
An important legal distinction exists between:
contractual consent to receive a service,
payment authorisation, and
data-processing consent or another GDPR legal basis.
These concepts should not automatically be treated as identical.
For example, a customer may have a contractual relationship with an account-information application while the provider must separately satisfy the regulatory conditions governing access to payment-account information.
Likewise, authorising access to account information does not automatically authorise every possible secondary commercial use of that information.
Consequently, contractual drafting should specify the scope and purpose of access.
7. API Access and the Bank's Contractual Position
Open banking relies heavily on application programming interfaces or comparable secure interfaces.
Banks acting as account-servicing providers must allow regulated third-party providers to communicate with their systems according to the PSD2 framework and associated regulatory technical standards.
Spanish banking practice therefore incorporates dedicated interfaces through which account-information providers, payment-initiation providers and certain other authorised providers can interact with payment accounts.
The bank generally cannot treat the customer's use of a properly regulated PISP or AISP as a breach of the ordinary banking agreement merely because a third party becomes involved.
8. No Mandatory Contract Between Bank and AISP
One of the most significant rules appears in Article 7 of Royal Decree-Law 19/2018.
It provides that the provision of account-information services cannot be made conditional upon a contractual relationship between the AISP and the customer's account-servicing payment provider.
Suppose:
Customer → holds account with Bank A.
Customer → contracts with Fintech B for account aggregation.
Fintech B → is properly entitled to provide account-information services.
Bank A therefore cannot simply insist that Fintech B first negotiate a separate private commercial agreement before exercising PSD2 access rights.
The legal right of access derives substantially from regulation and customer authorisation rather than exclusively from contractual privity between the two providers.
9. Contractual Information and Transparency
Transparency is particularly important in digital banking contracts.
Customers should understand what they are agreeing to before the service begins.
The contractual documents should therefore explain the provider's identity, service, charges, communication methods, security arrangements, authorisation procedure and liability regime in clear language.
This principle also interacts with the EU rules on unfair terms in consumer contracts.
A clause may therefore comply formally with payment-services legislation but still potentially be challenged under consumer law if it creates an unfair imbalance or lacks sufficient transparency.
10. Modification of Open Banking Framework Contracts
Banks and payment institutions frequently need to amend contractual terms because of technological or regulatory changes.
Spanish law imposes controls on those modifications.
Article 33 of Royal Decree-Law 19/2018 requires proposed changes to relevant framework-contract conditions to be communicated clearly and individually, generally on paper or another durable medium, with at least two months' advance notice before the proposed changes take effect.
Consequently, a bank cannot assume unlimited contractual power to alter essential payment conditions immediately.
Any contractual mechanism based on deemed or tacit acceptance must also comply with consumer-protection requirements.
11. Termination of Framework Contracts
Spanish payment law gives payment-service users strong termination rights.
Under Article 32 of Royal Decree-Law 19/2018, the user may generally terminate a framework contract at any time without prior notice, subject to specific statutory qualifications. The provider must normally act on the termination request within 24 hours.
Termination is generally free where the agreement has existed for at least six months.
Where a contract permits the payment-service provider to terminate an indefinite framework agreement, at least two months' notice is generally required.
These rules reduce the possibility of customers becoming indefinitely locked into payment-service arrangements.
12. Blocking Access and Security
Security provisions are legitimate contractual components, but banks do not possess unlimited discretion.
A framework contract may permit blocking of a payment instrument where objectively justified reasons exist, including:
security concerns;
suspected unauthorised use;
suspected fraudulent use; or
certain significant credit risks.
Where legally permitted, the customer should be informed about the blocking and its reasons.
Similar principles are important in open banking because security cannot ordinarily be used merely as a pretext for excluding lawful third-party providers.
13. Refusal to Execute Payment Orders
Spanish law also limits contractual clauses permitting banks to reject payments.
Where the conditions contained in the framework contract are satisfied, the account-servicing payment provider generally cannot refuse an authorised payment order merely because the transaction was initiated through a payment-initiation provider.
Where an order is rejected, the provider normally has to communicate the rejection, reasons and relevant correction procedure unless another legal rule prevents disclosure.
This protects the practical effectiveness of open banking.
14. Unauthorised Payments and Contractual Liability
Unauthorised transactions are one of the most important sources of disputes.
If the customer denies authorising a transaction, the existence of electronic records does not automatically permit every loss to be transferred contractually to the customer.
Payment-service legislation establishes rules concerning authentication, notification, reimbursement and allocation of losses.
A contract attempting to place substantially all technological or fraud risk on a consumer may therefore conflict with mandatory payment-services or consumer-protection rules.
This becomes particularly important where several providers participate in a transaction.
For example:
Customer → PISP → Bank → Beneficiary
A failure may originate with the customer's authentication, the PISP, the bank's interface or another part of the payment chain.
Contractual clauses therefore need to operate alongside statutory liability rules rather than replace them.
Important Case Law
Because reported Spanish judgments specifically dealing with mature AISP/PISP contractual disputes remain comparatively limited, EU payment-services and Spanish banking-consumer jurisprudence is especially important. EU payment-services judgments directly influence interpretation of Spain's PSD2-derived legislation.
1. DenizBank AG v Verein für Konsumenteninformation — C-287/19, CJEU, 2020
This is one of the most important cases concerning payment-service framework contracts.
The dispute concerned a bank's contactless-payment arrangements and contractual provisions dealing with modifications and liability.
The Court examined whether contractual changes could be accepted through a tacit-consent mechanism.
It held that PSD2 permits contractual arrangements under which changes to framework contracts may, under the Directive's conditions, become accepted through tacit consent. However, where the user is a consumer, this does not prevent separate examination of the relevant contractual terms under the EU Unfair Contract Terms Directive.
Importance for Spanish open banking
The case establishes that PSD2 contractual flexibility does not remove consumer-law controls.
Therefore, an open-banking provider cannot simply rely upon a clause saying:
continued use automatically means acceptance of every future contractual change.
The validity and transparency of such a clause remain open to consumer-law scrutiny.
2. Beobank SA v ZG — C-351/21, CJEU, 2023
This case concerned disputed card transactions and the information that a payment provider must supply concerning the beneficiary of a transaction.
The customer had made a legitimate payment in Valencia, Spain, after which additional disputed transactions occurred using the same payment terminal.
The Court examined the information duties imposed on the payment-service provider and their relationship with the liability regime governing unauthorised transactions.
Importance for open banking
The case demonstrates that contractual payment records must contain sufficient information to allow customers to identify transactions and exercise their legal rights.
This principle becomes even more important in open banking, where several intermediaries may participate in a transaction.
A customer should be able to determine what transaction occurred and who participated in it rather than receiving incomprehensible technical information.
3. Caixabank and Others — Joined Cases C-810/21 to C-813/21, CJEU, 2024
These proceedings originated from the Audiencia Provincial de Barcelona and involved Caixabank, BBVA, Banco Santander and Banco Sabadell.
Although the disputes concerned mortgage contractual terms rather than open-banking APIs, they form part of the important Spanish banking-contract jurisprudence concerning consumer remedies and unfair contractual provisions.
Importance for open banking contracts
Open-banking agreements with consumers do not exist outside general EU consumer protection.
Where contractual terms are potentially unfair, national procedural rules cannot make the consumer's EU-derived protections practically ineffective.
The broader lesson is that contractual limitation periods and procedural arrangements must be considered alongside effective consumer protection.
4. Caixabank and Others — C-450/22, CJEU, 2024
This case arose from the Spanish Supreme Court and concerned mortgage "floor clauses" and collective consumer proceedings involving numerous Spanish financial institutions.
The Court addressed transparency under Directive 93/13 on unfair terms in consumer contracts.
Importance for open banking
Although not an AISP/PISP case, the transparency principles are relevant to standard-form digital banking contracts.
Open-banking contracts are commonly concluded through applications, websites and standard terms.
A provider therefore cannot assume that placing a complicated clause somewhere in lengthy digital terms necessarily makes that provision transparent.
The consumer must have a genuine opportunity to understand the economic and legal consequences of important provisions.
5. Banco Santander SA v Asociación de Consumidores y Usuarios de Servicios Generales-Auge — C-346/23, CJEU, 2025
This Spanish reference arose from the Tribunal Supremo.
The dispute concerned contracts for the acquisition of financial instruments by retail clients and the ability of a consumer organisation to pursue proceedings protecting its members.
The Court considered the relationship between EU financial-services regulation, consumer representation and Spanish procedural rules.
Importance for open banking contracts
The case reinforces a broader proposition relevant to financial-services contracts: regulated financial products do not automatically fall outside consumer-protection mechanisms simply because they are sophisticated or economically significant.
For open banking, contractual classification therefore does not necessarily eliminate consumer remedies.
6. DenizBank — Consumer-Unfairness Dimension
The DenizBank judgment deserves separate treatment for another contractual principle.
The Court distinguished between the PSD2 rules permitting certain contractual arrangements and the separate question whether an individual term is unfair under Directive 93/13.
That distinction matters enormously for Spain.
A clause might satisfy the technical requirements of payment-services legislation but still potentially fail consumer-law scrutiny because it:
creates a significant imbalance;
transfers excessive risk to the customer;
lacks transparency; or
restricts statutory rights.
Thus, PSD2 compliance should not be treated as complete immunity from ordinary consumer-contract review.
7. Spanish Floor-Clause Banking Litigation and Open-Banking Contract Principles
The extensive Spanish banking litigation concerning mortgage floor clauses provides another important body of principles relevant by analogy to open banking.
The major lesson from that jurisprudence is that formal contractual acceptance is not always equivalent to substantive transparency.
Digital open-banking contracts may therefore face similar scrutiny.
A user clicking "accept" can establish contractual consent, but that fact alone does not necessarily determine whether every limitation-of-liability, fee, data-use or unilateral-modification clause is enforceable.
The transparency

comments