Banking Law And Open Banking Ecosystems Spain .

 

Banking Law and Open Banking Ecosystems in Spain

1. Introduction

Open banking has significantly changed the traditional relationship between banks and customers in Spain. Traditionally, a bank controlled the technical environment through which customers accessed their accounts, initiated payments and obtained financial information. Under open banking, customers can permit regulated third-party providers to access certain payment-account information or initiate payments on their behalf.

Spain's open-banking ecosystem is principally based on the European Union's payment-services framework, particularly the Second Payment Services Directive (PSD2), which Spain implemented primarily through Real Decreto-ley 19/2018, of 23 November, on payment services and other urgent financial measures.

The Spanish framework recognises payment institutions and account-information service providers and establishes rules concerning access to payment accounts, authentication, security, liability and supervision. Account-information service providers are subject to registration requirements, while payment institutions generally require authorisation or another legally recognised status.

Open banking therefore does not mean that bank information becomes publicly available. Rather, it establishes a regulated system under which authorised or registered providers can access particular information or initiate transactions when the legal requirements are satisfied.

 

2. Main Legal Framework

A. PSD2

Directive (EU) 2015/2366, commonly called PSD2, forms the foundation of modern European open banking.

PSD2 sought to adapt payment regulation to technological developments and the emergence of financial-technology companies. Instead of allowing banks to remain the exclusive technological gateway to customers' payment accounts, PSD2 recognises regulated third-party payment services.

Spain incorporated this framework mainly through Real Decreto-ley 19/2018.

The Spanish legislation expressly recognises the customer's right to use account-information services where the relevant payment account is accessible online. Importantly, the legislation provides that the account-information provider does not need a separate contractual relationship with the customer's account-servicing payment service provider simply in order to provide that service.

B. Real Decreto-ley 19/2018

This legislation constitutes one of the principal Spanish statutes governing payment services.

It deals with matters including:

payment institutions;

account-information services;

payment-initiation services;

access to payment systems;

access to payment accounts;

authorisation and registration;

operational and security risks;

authentication;

consumer rights;

liability;

fraud reporting; and

regulatory supervision.

Payment institutions must normally be entered in the Banco de España's special register before commencing regulated activities. Account-information service providers are also subject to a specific registration regime.

 

3. Main Participants in the Spanish Open-Banking Ecosystem

An open-banking transaction may involve several legally distinct participants.

Account Servicing Payment Service Provider

An ASPSP is normally the bank or other payment service provider maintaining the customer's payment account.

For example, if a Spanish consumer maintains a current account with a bank, that institution will normally act as the ASPSP.

Payment Initiation Service Provider

A PISP enables a customer to initiate a payment from an account maintained with another institution.

Instead of entering the bank's own digital environment to make the payment, the customer can instruct a regulated third-party provider to initiate it.

Account Information Service Provider

An AISP accesses information concerning one or more payment accounts with the customer's permission.

This allows services such as account aggregation, where a customer can view information concerning accounts maintained with several financial institutions through one interface.

Spanish law specifically recognises the customer's right to use account-information services where the account is accessible online.

 

4. API-Based Banking

Application Programming Interfaces, or APIs, are central to modern open banking.

An API provides a controlled technological channel through which different computer systems communicate.

In practical terms, an open-banking API may allow a regulated provider to request account information or send a payment-initiation instruction to a customer's bank.

The legal importance of APIs is that banks cannot structure technical access in a manner that improperly defeats the rights created by payment-services legislation.

The ecosystem therefore attempts to balance two competing objectives:

openness and competition, because regulated third parties need workable access;

and

security and confidentiality, because banks must protect payment credentials and customer information.

 

5. Customer Consent

Customer control is fundamental to open banking.

A third-party provider does not receive unlimited authority over a customer's bank account merely because it participates in the open-banking ecosystem.

The service must operate within the customer's instructions and the applicable payment-services and data-protection rules.

This becomes particularly important where financial information is used for additional purposes such as:

financial profiling;

personalised products;

creditworthiness analysis;

advertising;

automated recommendations; or

credit decisions.

Permission to obtain data for one regulated service should not automatically be treated as unlimited permission to reuse that information for unrelated purposes.

 

6. Strong Customer Authentication

Security is another central component.

Spanish payment-services legislation requires strong customer authentication (SCA) in important situations, including when a payer:

accesses a payment account online;

initiates an electronic payment; or

performs a remote action carrying a risk of payment fraud or similar abuse.

For remote electronic payments, authentication may also have to dynamically link the transaction to a specified amount and beneficiary.

The authentication requirements also extend to relevant transactions involving payment-initiation and account-information providers.

The objective is to prevent open banking from becoming an easier route for account takeover or payment fraud.

 

7. GDPR and Open Banking

Open banking cannot be considered only under banking legislation.

The General Data Protection Regulation (GDPR) is also fundamental because bank-account information will frequently constitute personal data.

Spanish payment-services legislation expressly subjects relevant processing and disclosure of data to the GDPR and Spanish data-protection legislation.

Consequently, an open-banking provider may need to consider:

lawfulness of processing;

purpose limitation;

data minimisation;

transparency;

security;

retention periods;

rights of access and correction;

automated decision-making;

processor/controller relationships; and

data-breach obligations.

This creates an important distinction between permission under payment-services law to access an account and the broader question of whether particular processing of the resulting personal data is lawful under data-protection law.

The two regulatory systems overlap but are not identical.

 

8. Open Banking and Credit Assessment

Open-banking information can potentially provide lenders with detailed evidence concerning income, recurring expenditure and financial behaviour.

This can support innovative credit-assessment models.

However, automated credit assessment creates additional legal risks.

If an algorithm uses financial data to generate a score that effectively determines whether credit will be granted, GDPR rules concerning automated individual decision-making may become important.

The CJEU's SCHUFA judgment is especially significant in this context because the Court considered circumstances in which automatically calculated credit scores can fall within Article 22 GDPR when a third party gives the score a determining role in its decision.

 

9. Competition and Market Access

One objective of open banking is to increase competition.

Banks traditionally possessed significant advantages because they controlled both the customer's account and the technological interface through which it was accessed.

Open banking reduces that structural advantage by allowing appropriately regulated third parties to provide services around bank accounts.

Spanish legislation therefore contains important market-access principles.

Access rules for relevant payment systems must generally be objective, proportionate and non-discriminatory.

Similarly, payment institutions are entitled to access payment-account services supplied by credit institutions on an objective, non-discriminatory and proportionate basis. Where a credit institution refuses certain account access to a payment institution, Spanish legislation requires the refusal to be properly reasoned under the applicable conditions.

 

10. Cybersecurity and Operational Risk

Opening banking infrastructure to additional regulated participants inevitably increases the number of technological connections that have to be protected.

Spanish law consequently requires payment service providers to establish frameworks containing appropriate controls and mitigation measures for operational and security risks.

Providers must also maintain procedures for detecting and classifying major operational and security incidents.

They must periodically provide the Banco de España with assessments concerning their operational and security risks and the adequacy of their controls.

Therefore, cybersecurity in open banking is not simply an IT issue. It is part of regulatory compliance.

 

Important Case Law

Because Spain operates within the harmonised EU payment-services and GDPR systems, CJEU decisions interpreting these rules are particularly relevant to Spanish open banking.

1. CJEU — T-Mobile Austria GmbH v Verein für Konsumenteninformation, Case C-616/11 (2014)

This case concerned the meaning of a payment instrument under the earlier Payment Services Directive.

The Court considered payment instructions given through mechanisms including online banking and paper transfer orders.

The decision demonstrated that EU payment-services concepts must receive functional interpretation rather than being confined to traditional physical payment devices.

Importance for Spain

The principle is relevant to open banking because payment services increasingly operate through APIs, applications and digital interfaces.

A financial service does not escape payment regulation merely because the customer interacts with it through modern technological infrastructure rather than a conventional banking instrument.

 

2. CJEU — ING-DiBa Direktbank Austria, Case C-191/17 (2018)

This case examined the concept of a payment account.

The dispute involved a savings account through which transactions depended upon an associated reference account.

The Court examined whether such an arrangement fell within the concept of a payment account under EU payment-services legislation.

Importance for Spain

Open-banking rights largely depend on whether the relevant product qualifies as a payment account within the applicable regulatory framework.

Not every financial account automatically becomes an open-banking payment account.

Consequently, the legal characteristics and functionality of the account are important.

 

3. CJEU — Tecnoservice Int. Srl v Poste Italiane SpA, Case C-245/18 (2019)

This dispute involved a credit transfer executed using an incorrect unique identifier supplied by the payer.

The Court examined the liability consequences under the Payment Services Directive where the transaction was executed according to that identifier.

Importance for Spain

Open banking may make payment initiation technologically faster, but it does not eliminate legal rules concerning payment instructions.

The case illustrates the importance of correctly identifying payment destinations and allocating responsibility between the payer and payment service providers.

For PISPs and banks operating in Spain, accurate transmission and execution of payment instructions therefore remain crucial.

 

4. CJEU — DenizBank AG v Verein für Konsumenteninformation, Case C-287/19 (2020)

DenizBank concerned contactless NFC functionality on bank cards and several questions concerning payment instruments, information obligations and contractual changes.

The Court considered, among other things, the concept of a payment instrument and circumstances involving tacit acceptance of amendments to framework contracts.

Importance for Spain

The case is significant beyond contactless cards.

Digital banking ecosystems frequently change functionality, security processes and contractual terms.

Banks and payment providers cannot assume that technological innovation removes statutory consumer-protection and information requirements.

Open-banking contractual arrangements therefore need to remain compatible with mandatory payment-services protections.

 

5. CJEU — Österreichische Post, Case C-300/21 (2023)

This is an important GDPR damages judgment.

The Court held that infringement of the GDPR alone does not automatically create a right to compensation.

Three elements are required:

infringement of the GDPR;

damage suffered by the individual; and

a causal relationship between the infringement and the damage.

At the same time, the Court rejected the proposition that non-material damage must exceed a particular seriousness threshold before compensation can potentially arise.

Importance for Spanish Open Banking

An open-banking provider may process highly detailed personal financial information.

A GDPR breach therefore potentially creates civil liability, but compensation is not automatically payable simply because a technical GDPR violation occurred.

A claimant must establish the legally required elements.

 

6. CJEU — SCHUFA Holding (Scoring), Case C-634/21 (2023)

This decision is especially important for the relationship between open banking and algorithmic lending.

SCHUFA generated probability values designed to predict whether individuals would meet future payment commitments.

The CJEU considered Article 22 GDPR and automated individual decision-making.

The judgment establishes that automatically generating a probability score may constitute automated individual decision-making within Article 22 where a third party receiving that score gives it a determining role in deciding matters such as whether to establish, implement or terminate a contractual relationship.

Importance for Spain

Spanish fintech companies can potentially combine open-banking transaction information with automated credit-scoring technology.

Where such scoring effectively determines whether a customer receives credit, GDPR Article 22 protections may therefore become relevant.

The case demonstrates why open banking cannot be analysed separately from data-protection and automated-decision rules.

 

11. Liability Within an Open-Banking Ecosystem

Open banking creates a multi-party environment.

A transaction can potentially involve:

Customer → Fintech/PISP → Bank/ASPSP → Payment infrastructure → Beneficiary

If something goes wrong, identifying the responsible participant becomes important.

Possible disputes include:

unauthorised transactions;

incorrect payment instructions;

duplicated payments;

API failures;

incorrect account information;

compromised credentials;

fraudulent authentication;

data breaches; and

service interruptions.

Payment-services legislation provides specialised rules governing authorisation, authentication and liability.

Contractual arrangements between banks and fintech companies cannot simply eliminate mandatory protections granted to payment-service users.

 

12. Banco de España

The Banco de España occupies a central supervisory position.

Among other functions under the payment-services framework, it maintains relevant registers and supervises aspects of payment institutions and payment services.

Spanish legislation also requires providers to supply information concerning operational and security risks and fraud-related matters.

For example, payment service providers must provide statistical information concerning payment fraud, which the Banco de España can transmit in aggregated form to relevant European authorities.

Thus, an open-banking business operating in Spain must consider regulatory supervision in addition to contractual relationships with banks and customers.

 

13. Cross-Border Open Banking

Spain's open-banking market is not isolated from the rest of the European Union.

Under the EU passporting system, appropriately authorised payment institutions from another Member State can, subject to the applicable requirements, provide payment services in Spain through establishment or cross-border provision of services.

Spanish legislation expressly provides mechanisms allowing qualifying entities authorised elsewhere in the EU to provide payment services in Spain.

This creates a European rather than purely Spanish fintech ecosystem.

A provider based in another Member State may therefore compete for Spanish customers without establishing an entirely independent Spanish payment institution, provided the passporting and regulatory requirements are satisfied.

 

14. Consumer Protection

Consumer protection remains a central part of the framework.

Open banking should not mean that customers lose protection simply because another company sits between them and their bank.

Important protections include:

transparent information;

secure authentication;

restrictions concerning unauthorised transactions;

protection of credentials;

data-protection rights;

complaint mechanisms; and

regulatory supervision.

The regulatory model therefore attempts to promote innovation without transferring all technological and financial risks to consumers.

 

15. Relationship Between Open Banking and Traditional Banking Law

Open banking does not replace traditional banking law.

Instead, several bodies of law operate simultaneously.

A Spanish bank participating in an open-banking ecosystem may have to consider:

Banking regulation — authorisation, governance and prudential obligations.

Payment-services law — payment initiation, account information, authentication and liability.

Data-protection law — GDPR and Spanish data-protection requirements.

Consumer law — transparency, contractual fairness and consumer rights.

Competition law — market access and potentially exclusionary behaviour.

Cybersecurity regulation — operational resilience, security controls and incident management.

AML law — customer identification, transaction monitoring and financial-crime prevention where applicable.

Open banking is consequently best understood as a regulatory ecosystem rather than a single legal regime.

 

16. Practical Example

Suppose a customer in Madrid has accounts with Bank A and Bank B.

The customer downloads a regulated financial-management application and instructs it to display information from both accounts.

The application acts as an account-information provider.

The customer authenticates appropriately, and the provider obtains permitted account information through the relevant banking interfaces.

If the application subsequently provides a payment-initiation function, a PISP function may also be involved.

Several separate legal questions then arise:

Is the third-party provider properly authorised or registered?

Has the customer validly requested the service?

Is authentication compliant?

Is only necessary account information being accessed?

Is personal data processed lawfully?

Is the API connection secure?

Who bears responsibility if an unauthorised payment occurs?

What happens if the provider suffers a data breach?

Is transaction information being reused for profiling?

Is an algorithm making consequential decisions about the customer?

This illustrates why open banking involves considerably more than merely providing an API.

 

17. Major Legal Risks

For banks and fintech providers operating within Spain, major risks include:

operating regulated payment services without proper authorisation or registration;

excessive collection of financial data;

insufficient authentication;

misuse of payment credentials;

unclear consent mechanisms;

unlawful secondary use of account data;

discriminatory or unlawful automated credit scoring;

cybersecurity failures;

incorrect payment execution;

inadequate incident management;

failures in outsourcing arrangements; and

improper restrictions on third-party access.

These risks can potentially generate supervisory, contractual, data-protection and civil consequences simultaneously.

 

18. Future Development: From Open Banking to Open Finance

The broader European policy direction increasingly extends beyond payment-account information toward open finance.

Conceptually, open finance could allow customer-controlled sharing across a wider range of financial products, potentially including areas such as investments, savings, insurance and credit information, subject to the final applicable legislative framework.

This represents an important shift.

Traditional banking can be represented as:

Bank → owns infrastructure → provides service to customer

Open banking changes the structure to:

Bank + regulated third parties → customer-authorised account services

Open finance potentially develops this further:

Multiple financial institutions + multiple regulated digital providers → customer-controlled financial-data ecosystem

The legal challenge is therefore moving from simply regulating bank accounts toward governing interconnected financial-data infrastructures.

 

Conclusion

Spain's open-banking ecosystem is based on the interaction between EU financial regulation and Spanish banking law, particularly PSD2 and Real Decreto-ley 19/2018.

The system allows regulated third parties to provide payment-initiation and account-information services while imposing requirements relating to registration or authorisation, authentication, operational security, consumer protection and regulatory supervision.

At the same time, open banking creates significant data-protection issues because payment-account information can reveal detailed information about an individual's financial behaviour. GDPR requirements therefore operate alongside payment-services law.

The CJEU decisions in T-Mobile Austria (C-616/11), ING-DiBa (C-191/17), Tecnoservice (C-245/18), DenizBank (C-287/19), Österreichische Post (C-300/21), and SCHUFA (C-634/21) illustrate the major legal themes surrounding payment instruments, payment accounts, transaction liability, digital payment contracts, data-protection damages and automated credit scoring.

Consequently, open banking in Spain should not be understood merely as a technological system for connecting banks and fintech companies. It is a regulated legal ecosystem in which banking law, payment law, data protection, cybersecurity, consumer protection and competition principles operate together.

For Spanish financial institutions, the central legal objective is to permit secure innovation and customer-controlled financial services while preserving the integrity of payment systems and the rights of banking customers.

LEAVE A COMMENT