Banking Law And Open Banking Liability Allocation Spain .
Banking Law and Open Banking Liability Allocation in Spain
1. Introduction
Open banking changes the traditional banking relationship because a payment or data-access service may involve several different actors at the same time. In Spain, these may include the customer, the bank maintaining the payment account, a Payment Initiation Service Provider (PISP), an Account Information Service Provider (AISP), the merchant or beneficiary, and sometimes other technical intermediaries.
The central legal question is therefore: when something goes wrong, who bears the loss?
Spanish law answers this mainly through Royal Decree-Law 19/2018 of 23 November on payment services, which implemented the EU's revised Payment Services Directive, commonly known as PSD2. The system is strongly protective of payment-service users. In particular, Spanish law places important evidential and reimbursement obligations on payment-service providers when a customer denies authorising a transaction.
The Spanish Supreme Court has now characterised this framework as imposing a form of quasi-objective liability on payment-service providers for unauthorised payments. The bank cannot normally escape liability merely by showing that the correct password, SMS code, or other credentials were technically used.
2. Principal Legal Framework
The most important Spanish legislation is Royal Decree-Law 19/2018. Particularly relevant provisions are Articles 41–46 and 59–68.
Article 41 requires the payment-service user to take reasonable measures to protect personalised security credentials and to notify the provider without undue delay after discovering loss, theft, misappropriation, or unauthorised use of a payment instrument.
Article 43 generally requires an unauthorised or incorrectly executed transaction to be reported without unjustified delay and, in any event, within the statutory maximum period of thirteen months from the debit, subject to the conditions laid down in the legislation.
Most importantly, Article 44 determines the burden of proof. When the customer denies authorising a payment, the payment-service provider must demonstrate that the transaction was authenticated, accurately recorded and accounted for, and was not affected by a technical failure or another deficiency in the service.
The legislation expressly provides that the mere recorded use of a payment instrument does not necessarily prove either that the customer authorised the transaction or that the customer acted fraudulently or with gross negligence. The provider bears the burden of proving fraud or gross negligence.
3. Liability of the Account-Servicing Bank
The Account Servicing Payment Service Provider, or ASPSP, is normally the bank maintaining the customer's payment account.
Under Article 45, where an unauthorised payment has occurred, the payer's payment-service provider generally has to refund the amount immediately and no later than the end of the following business day after discovering or being informed of it.
An exception exists where the provider has reasonable grounds to suspect fraud and communicates those grounds to the Banco de España in accordance with the applicable rules.
This means that the starting point is not:
“The customer must prove that the bank was negligent.”
Instead, the statutory framework substantially reverses that position. Once an unauthorised payment is properly disputed, the bank faces the statutory burden associated with authentication, proper execution, service deficiencies and any allegation of fraud or gross negligence by the customer.
4. Liability of Payment Initiation Service Providers
A PISP initiates a payment from the customer's bank account without itself necessarily holding the customer's funds.
Open banking therefore creates a potentially complicated liability chain.
Suppose:
Customer → PISP → Customer's Bank → Beneficiary
and an unauthorised transaction occurs.
Spanish law simplifies the customer's immediate position. Article 45 provides that where a transaction has been initiated through a PISP, the account-servicing provider must still make the required reimbursement to the customer.
The bank can subsequently seek compensation from the PISP if the PISP was responsible for the unauthorised transaction.
The PISP must demonstrate, within its sphere of responsibility, that the payment was authenticated and accurately recorded and that its service was not affected by a technical failure or other relevant deficiency.
Consequently, there are effectively two liability relationships:
External liability: provider toward the customer.
Internal liability: allocation of the ultimate loss between the bank, PISP or another responsible intermediary.
Article 63 expressly provides a right of recourse where the liability of one provider is attributable to another provider or intermediary.
5. Account Information Service Providers
An AISP generally obtains consolidated account information rather than initiating payments.
Its liability therefore differs from PISP liability.
The main risks include:
unauthorised access to account information;
fraudulent access;
misuse of financial information;
security failures;
breach of confidentiality;
data-protection violations.
Spanish legislation requires AISPs to maintain professional indemnity insurance or an equivalent guarantee covering relevant liabilities arising from unauthorised or fraudulent access to payment-account information or unauthorised or fraudulent use of such information.
Consequently, an AISP is not automatically responsible for every fraudulent payment involving an account it can access. Liability should instead be connected to the obligations and failures falling within the AISP's own sphere of responsibility.
6. Customer Liability and the €50 Rule
Spanish law does not make the bank responsible in every possible situation.
Article 46 provides that a payer can, in certain circumstances, bear losses up to €50 arising from unauthorised transactions involving a lost, stolen or misappropriated payment instrument.
However, important exceptions significantly limit that exposure.
More importantly, the customer can bear the entire loss where the loss resulted from:
the customer's own fraud;
deliberate violation of security obligations; or
gross negligence in complying with those obligations.
Gross negligence is therefore one of the most important concepts in Spanish payment-fraud litigation.
Ordinary carelessness and gross negligence should not automatically be treated as equivalent. The bank also bears the burden of establishing the fraud or gross negligence on which it relies.
7. Strong Customer Authentication
Strong Customer Authentication, or SCA, is another major part of liability allocation.
For relevant electronic and remote payments, authentication ordinarily involves multiple independent authentication elements and, for remote electronic payments, mechanisms linking the authorisation dynamically to a particular amount and beneficiary.
Where the payer's payment-service provider fails to require SCA when legally required, the customer normally does not bear the resulting financial loss unless the customer acted fraudulently.
Where the beneficiary or beneficiary's payment-service provider refuses or fails to accept SCA, the financial consequences can shift through the payment chain.
This creates an important regulatory principle:
security responsibility tends to follow the entity that controlled the relevant security mechanism.
8. Phishing, SIM Swapping and Stolen Credentials
One of the most important developments in Spanish banking law concerns phishing and similar digital fraud.
Banks sometimes argued that where the correct username, password and one-time security code were used, the transaction must have been properly authorised.
The Spanish Supreme Court has rejected such a broad approach.
Correct technical authentication is not necessarily equivalent to legally valid customer consent.
A criminal may obtain the customer's credentials through phishing, SIM swapping or another form of impersonation. If the customer did not actually authorise the payment, the transaction may remain an unauthorised transaction even though the bank's computer system recorded apparently valid credentials.
The critical questions become:
Did the customer actually consent?
Was authentication properly performed?
Was there a deficiency in the payment service?
Did the bank maintain appropriate fraud-detection systems?
Did the customer act fraudulently?
Did the customer's conduct amount to gross negligence?
This distinction between authentication and authorisation is fundamental to modern Spanish banking liability.
Important Case Law
1. Tribunal Supremo, Sala Primera, Judgment 571/2025, 9 April 2025
This is the leading recent Spanish Supreme Court authority on unauthorised electronic banking transactions.
The dispute involved fraudulent transactions associated with SIM swapping, where criminals obtained control enabling access to the victim's digital banking.
The Supreme Court explained that the statutory liability of payment-service providers is essentially quasi-objective.
The Court emphasised that when a customer denies authorising a transaction, the bank must prove more than the fact that its records show the correct credentials were used.
It must establish the matters required by payment-services legislation, while fraud, deliberate breach or gross negligence on the customer's part must also be proved where the bank relies on those grounds.
Importantly, the Court interpreted a “deficiency of the service” broadly. It is not restricted to a computer malfunction. It can include deficient conduct or insufficient diligence in providing the banking service.
The case involved unusual activity including numerous transfers over a short period. The judgment stressed the relevance of systems capable of detecting anomalous transactions based on matters such as frequency, timing, amount, beneficiaries and previous account behaviour.
Legal significance: Technical authentication alone does not establish customer authorisation. The decision significantly strengthens the doctrinal basis for allocating digital-fraud risk to banks unless statutory grounds for shifting the loss are established.
2. Audiencia Provincial, Civil Chamber No. 1, Judgment 1428/2024, 31 October 2024
This case concerned approximately €4,000 taken through phishing.
The provincial court applied the payment-services framework and treated bank liability as quasi-objective unless the bank could establish the circumstances necessary to exclude liability.
The dispute illustrates the importance of two separate questions:
First, whether the bank can demonstrate proper authentication, accurate recording and the absence of a relevant deficiency.
Second, whether it can establish fraud or gross negligence by the customer where it seeks to transfer the loss to that customer.
The court upheld the approach that the financial institution could not escape liability merely by pointing to the fact that security credentials had been used.
Legal significance: The judgment illustrates the increasingly established Spanish appellate approach that the evidential burden in phishing litigation rests heavily on the payment-service provider.
3. Audiencia Provincial de Madrid, Section 20, Judgment 78/2026, 6 March 2026
The Madrid Provincial Court applied the principles subsequently consolidated by Supreme Court Judgment 571/2025.
It reiterated that recording the use of a payment instrument does not itself demonstrate that the payer authorised the transaction.
Where the customer denies consent, the provider must demonstrate proper authentication and recording as well as the absence of a technical failure or other deficiency in its service.
The provider also carries the evidential burden concerning customer fraud or gross negligence.
Legal significance: The case confirms the continuing application of the Supreme Court's approach at provincial appellate level and reinforces the distinction between possession or use of credentials and genuine authorisation.
4. Audiencia Provincial de Valencia, Section 8, Judgment 384/2026, 14 April 2026
The Valencia Provincial Court addressed banking liability in the context of fraudulent electronic transactions and reviewed the developing Spanish appellate doctrine concerning phishing.
It recognised the majority approach treating payment-service-provider liability as quasi-objective, subject principally to proof of customer fraud, deliberate breach or gross negligence and the other statutory requirements.
The case is important because it shows that the question is not merely whether banking systems functioned mechanically. Courts increasingly examine whether the provider satisfied the broader security and diligence obligations associated with modern digital banking.
Legal significance: It demonstrates the practical application of the statutory burden-of-proof regime to contemporary cyber-fraud disputes.
5. Audiencia Provincial de Tarragona, Section 1, Judgment 382/2026, 27 May 2026
The Tarragona Provincial Court expressly relied upon Supreme Court Judgment 571/2025.
The court stressed that the bank must prove gross negligence rather than merely allege that the customer acted carelessly.
It also recognised an important point about stolen credentials: the fact that a third party managed to obtain a customer's banking credentials does not, by itself, establish gross negligence.
There can be several ways in which credentials are compromised, and the provider must prove the particular conduct necessary to shift liability.
Legal significance: This case strengthens the principle that gross negligence is an evidential question requiring actual proof. It cannot simply be presumed from the success of a phishing attack.
6. Audiencia Provincial de Barcelona, Section 4, Judgment 471/2026, 17 June 2026
The Barcelona Provincial Court also applied Supreme Court Judgment 571/2025.
The judgment considered sophisticated fraudulent circumstances in which communications appeared to originate from the bank and the fraudster possessed convincing information.
The court stressed that a customer's conduct must reach the level of gross negligence before the statutory protection can be displaced.
It also considered the bank's ability to identify unusual payment patterns. Failure to detect suspicious transactions can be relevant when deciding whether there was a deficiency in the banking service.
Legal significance: The case demonstrates why phishing liability cannot be determined simply by asking whether the victim disclosed credentials. The sophistication of the deception, the customer's behaviour, transaction anomalies and the bank's fraud-prevention mechanisms must be considered together.
7. Audiencia Provincial de Zaragoza, Section 4, Judgment 317/2026, 12 June 2026
This decision provides an important counterpoint.
Not every payment made as a consequence of fraud is legally an unauthorised payment.
The case involved a transfer made by the customer as a consequence of error, deception or fraud. That creates a materially different legal problem from a situation where a criminal independently accesses the account and initiates the payment without the customer's consent.
Where the customer personally instructs the bank to make the transfer, the payment may technically be authorised even though the customer was deceived about why or to whom the money was being sent.
Legal significance: Spanish law therefore requires an important distinction between:
unauthorised fraud — the criminal initiates the transaction without the customer's consent; and
authorised push-payment fraud — the customer personally authorises the transfer because the criminal deceives the customer.
The statutory reimbursement regime for unauthorised transactions cannot automatically be transferred to the second category.
8. CJEU, DM and LR v Caisse Régionale de Crédit Agricole Mutuel, Case C-337/20
Although this is an EU rather than Spanish national judgment, it is important because Spanish payment-services legislation derives substantially from EU payment-services directives.
The Court of Justice examined the relationship between notification requirements and payment-service-provider liability for unauthorised transactions.
The judgment demonstrates that the payment-services regime establishes an integrated allocation of responsibilities involving the customer's duty to notify, the provider's evidential obligations and the statutory liability regime.
Legal significance for Spain: Spanish courts interpret domestic payment-services legislation consistently with the underlying EU framework and CJEU interpretation.
9. Allocation of Liability in Typical Open-Banking Situations
The practical position can be summarised as follows.
Unauthorised payment caused by third-party account takeover
The customer's bank will generally have the immediate reimbursement obligation. It may avoid or shift liability where the statutory requirements concerning customer fraud or gross negligence are proved.
Payment improperly initiated through a PISP
The account-servicing bank generally reimburses the customer first. If the PISP caused the problem, the bank may exercise its statutory right of recourse against the PISP.
Technical failure attributable to the PISP
The PISP can ultimately bear responsibility within its own sphere of control and may have to compensate the account-servicing provider.
AISP improperly accesses customer information
The AISP may bear responsibility for unauthorised or fraudulent access or use attributable to its service, alongside any applicable data-protection consequences.
Bank fails to require legally required SCA
Except where the payer acted fraudulently, the payer generally should not bear the resulting financial consequences.
Customer commits fraud
The statutory protections do not shield a customer who deliberately participates in fraud.
Customer acts with gross negligence
The customer may bear the losses where the provider proves the legally required level of gross negligence.
Customer merely makes an ordinary mistake
Ordinary negligence should not automatically be equated with gross negligence.
Customer personally orders payment after being deceived
This may constitute an authorised payment obtained through deception rather than an unauthorised transaction. Liability therefore requires a different analysis from account takeover or SIM-swapping fraud.
10. Contractual Allocation Cannot Simply Override Statutory Protection
Banks and fintech companies commonly regulate liability through their contractual terms.
However, payment-services contracts cannot simply declare that:
“Any transaction made using the customer's password is deemed authorised.”
Such a provision cannot displace mandatory statutory protections applicable to the relationship.
The Supreme Court's approach demonstrates why. The use of correct credentials is relevant evidence, but it is not necessarily proof of legally valid consent.
Similarly, a general contractual provision attempting to exclude all responsibility for phishing or stolen credentials cannot automatically override the statutory allocation of risk.
11. Relationship with Data Protection Law
Open banking also involves extensive processing of financial and personal data.
Accordingly, the GDPR and Spanish data-protection legislation operate alongside payment-services law.
A single incident may therefore produce several forms of liability.
For example, compromised API credentials could result in:
payment-services liability for an unauthorised transaction;
contractual liability for breach of the service agreement;
data-protection liability for unlawful disclosure or inadequate security; and
regulatory liability for failure to comply with operational-security requirements.
These regimes should not be confused. Reimbursement of an unauthorised payment does not necessarily determine every other claim arising from the same security incident.
12. Execution Errors and Incorrect Payments
Liability is not confined to cybercrime.
Articles 59–63 of Royal Decree-Law 19/2018 regulate incorrect identifiers, non-execution, defective execution, delayed payments, PISP responsibility, additional compensation and rights of recourse between providers.
Where a PISP participates, this becomes especially important because the customer should not normally have to reconstruct the entire technical chain before obtaining the protection granted by payment-services law.
The legislation instead permits the provider facing the customer to pursue the provider or intermediary ultimately responsible.
This structure is particularly suitable for open banking because otherwise consumers would have to determine whether a failure occurred in the bank's API, PISP infrastructure, authentication process, payment network or another technical component.
13. Operational Security and Fraud Monitoring
The modern Spanish approach goes beyond simply asking whether the bank's computer system crashed.
Supreme Court Judgment 571/2025 indicates that a service deficiency can encompass inadequate diligence in providing payment services.
Relevant factors can therefore include:
unusual transaction frequency;
abnormal transaction values;
unusual transaction times;
new beneficiaries;
deviation from the customer's historical activity;
repeated transfers within a short period;
earlier warnings of possible account compromise; and
failure to respond appropriately to heightened indications of fraud.
The decision therefore connects payment liability with fraud-monitoring architecture.
A bank cannot necessarily establish adequate performance merely by proving that its authentication server functioned exactly as programmed.
14. Overall Legal Position
Spain's open-banking liability regime can ultimately be understood as a layered allocation of risk.
At the customer-facing level, the system provides strong protection against genuinely unauthorised payments.
At the evidential level, payment-service providers carry significant burdens. Technical records showing that credentials were entered correctly are not automatically decisive.
At the customer level, protection can be lost where fraud, deliberate breach or gross negligence is established.
At the open-banking-provider level, responsibility is allocated according to the sphere of control of the bank, PISP, AISP or other intermediary.
At the inter-provider level, statutory rights of recourse allow the entity that reimbursed the customer to recover from the provider actually responsible for the failure.
The most important development is Tribunal Supremo Judgment 571/2025 of 9 April 2025. It establishes that Spanish payment-service-provider liability for unauthorised electronic transactions is quasi-objective and that an apparently successful technical authentication process does not automatically establish customer authorisation.
Consequently, liability allocation in Spanish open banking is increasingly based on three connected questions:
Who actually authorised the transaction?
Which participant controlled the part of the service where the failure occurred?
Can the payment-service provider prove the statutory circumstances necessary to transfer the loss away from itself?
These principles make liability allocation workable even where several banks and fintech providers participate in a single open-banking transaction.

comments