Banking Law And Open Data Banking Initiatives Spain .
Banking Law and Open Data Banking Initiatives in Spain
1. Introduction
Spain’s approach to open data banking is mainly built on European Union law, supplemented by Spanish banking, payment-services, data-protection and cybersecurity rules. The central idea is that customers should be able to permit regulated third parties to access certain banking information electronically so that competing providers can offer services such as account aggregation, financial-management tools and payment initiation.
The principal Spanish implementation of the EU’s second Payment Services Directive (PSD2) is Royal Decree-Law 19/2018 of 23 November on payment services and other urgent financial measures. It expressly recognises account-information services and payment-initiation services, both of which involve third-party access to customers’ payment accounts.
Open banking should be distinguished from the broader concept of open finance. Existing PSD2-style open banking primarily concerns payment accounts and payment data. Open finance aims eventually to establish controlled sharing arrangements for a much wider range of financial information.
Importantly, there are not six major reported Spanish judgments dealing specifically and exclusively with open-data banking. Consequently, the most useful case law consists largely of judgments of the Court of Justice of the European Union (CJEU) interpreting payment-services and GDPR rules that bind or guide Spanish courts and regulators.
2. Spanish Legal Foundation
Royal Decree-Law 19/2018
Royal Decree-Law 19/2018 is the core Spanish legislation governing modern payment services.
It recognises, among other things:
traditional payment services;
payment-initiation services;
account-information services;
payment institutions;
access by regulated providers to payment accounts;
security requirements;
customer authentication;
liability rules; and
supervisory powers of the Banco de España.
Article 7 establishes the customer's right to use an account-information service where the relevant payment account can be accessed online. Significantly, provision of such a service cannot be made dependent upon a separate contractual relationship between the account-information provider and the customer's account-servicing bank.
This prevents an incumbent bank from effectively controlling which competing account-information providers its customers may use.
3. Account Information Service Providers
An Account Information Service Provider, commonly called an AISP, can collect information from payment accounts selected by a customer.
For example, a person with accounts at several Spanish banks could authorise an authorised financial application to retrieve information from those accounts and display the information through a single interface.
Spanish law imposes significant restrictions on such access.
Under Article 39 of Royal Decree-Law 19/2018, an account-information provider must:
act on the user's explicit consent;
protect personalised security credentials;
identify itself when communicating with the account-servicing bank;
communicate through secure channels;
access only accounts selected by the customer;
access only relevant payment information;
avoid requesting sensitive payment data; and
refrain from using or storing information for purposes unrelated to the service requested by the customer.
The account-servicing bank, meanwhile, must communicate securely with AISPs and generally treat their legitimate data requests without discrimination.
Therefore, open banking is not a general right for fintech businesses to inspect bank databases. Access exists only within a regulated framework.
4. Customer Consent and Control
Customer control is one of the central principles of Spain's open-banking framework.
A bank does not ordinarily disclose payment-account information to an AISP merely because the AISP asks for it. The customer's authorisation is fundamental.
This creates three separate relationships:
Customer → Bank
The bank holds and administers the payment account.
Customer → Third-party provider
The customer requests an account-information or payment-initiation service.
Third-party provider → Bank
The third party accesses the designated account through the legally regulated communication mechanism.
The structure seeks to make customer data portable without converting banking information into unrestricted public information.
5. APIs and Secure Communication
Application Programming Interfaces, or APIs, are central to practical open banking.
They allow authorised computer systems to communicate with banking systems in a standardised and controlled manner.
The relevant EU regulatory framework requires common and secure communication mechanisms. Spain's legislation specifically refers to Commission Delegated Regulation (EU) 2018/389 when regulating secure communication between account-information providers and banks.
An API therefore functions as a controlled gateway rather than giving the fintech unrestricted access to the bank's internal infrastructure.
The regulatory objective is to combine:
interoperability + competition + cybersecurity + customer control.
6. Strong Customer Authentication
Open banking also depends heavily upon Strong Customer Authentication (SCA).
Article 68 of Royal Decree-Law 19/2018 requires strong customer authentication in circumstances including when a customer:
accesses a payment account online;
initiates an electronic payment; or
performs remotely an action carrying a payment-fraud or abuse risk.
Appropriate security measures must also protect the confidentiality and integrity of customers' personalised security credentials. These requirements extend, where relevant, to payment initiation and account-information services.
Consequently, greater data portability does not mean weaker authentication.
7. GDPR and Banking Data
Bank-account information will frequently constitute personal data where it relates to an identified or identifiable natural person.
Open-data banking therefore operates simultaneously under payment-services legislation and the General Data Protection Regulation (GDPR).
Important GDPR principles include:
lawfulness;
fairness;
transparency;
purpose limitation;
data minimisation;
accuracy;
storage limitation;
integrity and confidentiality; and
accountability.
This overlap is extremely important.
Payment-services law may determine whether and how a regulated provider can access an account, while GDPR determines how personal information obtained through that access may lawfully be processed.
An AISP cannot assume that receiving authorised access to an account automatically permits unlimited secondary use of the customer's information.
8. Purpose Limitation
Suppose a customer permits an application to aggregate balances and transactions from three banks.
The provider cannot automatically conclude:
“Because we can access these transactions, we can use them for every commercial purpose.”
Spanish payment-services legislation expressly restricts account-information providers from using, accessing or storing account data for purposes other than providing the account-information service expressly requested by the customer, subject also to applicable data-protection requirements.
This is one of the strongest legal protections within the system.
9. Data Minimisation
Open banking must also observe data minimisation.
If a service requires only particular payment-account information, unnecessary customer information should not be collected merely because technically it could be obtained.
This principle becomes especially significant with:
AI financial assistants;
credit-scoring systems;
spending analytics;
personalised advertising;
fraud-detection algorithms; and
behavioural profiling.
The technical possibility of processing information does not itself establish a lawful entitlement to process it.
10. Competition and Non-Discrimination
Open banking has an important competition-law dimension.
Historically, banks controlled both customer accounts and the principal technological interfaces through which customers interacted with those accounts.
PSD2 changed that structure by legally recognising independent payment-initiation and account-information providers.
Spanish law additionally provides that payment institutions must receive access to payment-account services at credit institutions on objective, non-discriminatory and proportionate terms, sufficiently broad to permit efficient provision of payment services.
The purpose is not simply technological innovation. It also reduces the possibility that established institutions could use control over banking infrastructure to exclude regulated competitors.
11. Can a Bank Block Third-Party Access?
Yes, but not arbitrarily.
There can be objectively justified and evidenced reasons connected with unauthorised or fraudulent access.
Where access is denied under the relevant statutory mechanism, the customer generally must be informed of the denial and its reasons unless providing that information would compromise objectively justified security measures or would be prohibited by law.
Once the reasons for refusing access disappear, access must be restored.
Spanish law also requires relevant incidents involving an account-information or payment-initiation provider to be communicated to the Banco de España, which may evaluate the case and take appropriate action.
Thus, security provides an important safeguard but is not intended to operate as an unrestricted justification for excluding fintech competitors.
Important Case Law
12. Case 1 — CJEU, C-191/17, ING-DiBa Direktbank Austria
Case: Bundeskammer für Arbeiter und Angestellte v ING-DiBa Direktbank Austria, C-191/17, judgment of 4 October 2018.
The dispute concerned the meaning of a “payment account” under the earlier Payment Services Directive.
The Court examined whether a savings account from which payments and withdrawals could effectively be made only through another current account qualified as a payment account.
The case is important to Spanish open banking because the scope of the payment-account concept determines which types of accounts fall within payment-services protections and, consequently, the architecture on which PSD2 account access operates.
Principle
Not every financial account held at a bank automatically becomes a payment account.
Its functionality matters.
Importance for Spain
The decision prevents “open banking” from automatically being interpreted as a legal right of third parties to access every financial product that a customer has with a bank.
13. Case 2 — CJEU, C-287/19, DenizBank
Case: DenizBank AG v Verein für Konsumenteninformation, C-287/19, judgment of 11 November 2020.
The case concerned payment services, including the legal treatment of the NFC functionality of bank cards, information requirements and changes to framework-contract conditions.
The Court examined important PSD2 concepts concerning payment instruments and contractual relationships between payment-service providers and customers.
Principle
Technological innovation in payment services does not remove the provider's obligations concerning transparency, contractual information and statutory customer protections.
Importance for Open Banking
Open banking frequently introduces new interfaces without creating an entirely new body of contract law.
The DenizBank reasoning demonstrates that innovative payment technology continues to operate within mandatory payment-services protections.
Spanish banks and fintech providers therefore cannot treat digital innovation as a contractual “law-free zone.”
14. Case 3 — CJEU, C-245/18, Tecnoservice
Case: Tecnoservice Int. Srl v Poste Italiane SpA, C-245/18, judgment of 21 March 2019.
This dispute involved a credit transfer executed using an incorrect unique identifier supplied by the payer.
The CJEU examined responsibility under the Payment Services Directive where payment providers execute transactions according to the supplied identifier.
Principle
Payment-services legislation creates carefully allocated responsibilities between users and payment-service providers.
Importance for Open Banking
The case is particularly relevant when payments are initiated through digital intermediaries.
Open banking can involve several actors:
customer → payment-initiation provider → customer's bank → payment network → recipient's bank.
When something goes wrong, liability cannot simply be placed on whichever institution is most visible to the customer. The applicable payment rules determine which participant had the relevant legal obligation.
15. Case 4 — CJEU, C-154/21, Österreichische Post
Case: RW v Österreichische Post AG, C-154/21, judgment of 12 January 2023.
This is a major GDPR transparency decision.
The Court considered a person's right to know the recipients to whom personal data had been disclosed.
It held, in substance, that where personal data have been or will be disclosed, the controller generally must provide the actual identity of the recipients when the data subject requests it, unless circumstances recognised by GDPR justify giving only categories of recipients.
Importance for Spanish Open Banking
Financial-data ecosystems can contain multiple participants:
banks;
fintech companies;
processors;
cloud providers;
analytics companies; and
other authorised service providers.
The judgment strengthens transparency concerning where personal information goes after collection.
For Spanish banks and fintechs, merely saying that information may be shared with generic categories of companies will not necessarily satisfy every GDPR access request.
16. Case 5 — CJEU, C-300/21, Österreichische Post
Case: UI v Österreichische Post AG, C-300/21, judgment of 4 May 2023.
This case concerned compensation under Article 82 GDPR.
The Court held that infringement of GDPR by itself is insufficient for compensation. There must be:
an infringement;
damage; and
a causal connection between the infringement and the damage.
At the same time, EU law does not impose a general minimum seriousness threshold for non-material damage.
Importance for Open Banking
Imagine that an open-banking provider unlawfully processes customer transaction data.
Regulatory infringement and private compensation are related but separate questions.
The customer does not automatically receive damages simply because GDPR was violated. The requirements for compensation must independently be established.
This distinction is highly relevant to data breaches, unlawful profiling and improper financial-data sharing.
17. Case 6 — CJEU, C-487/21, F.F. v Österreichische Datenschutzbehörde (CRIF)
Case: F.F. v Österreichische Datenschutzbehörde, C-487/21.
This litigation concerned the meaning of the GDPR right to obtain a copy of personal data undergoing processing under Article 15(3).
The dispute arose from an information request made to CRIF, a business-information/credit-related company.
The CJEU interpreted the concept of a “copy” in a way intended to make the GDPR access right practically effective. Depending on what is necessary for the data subject to understand the information, providing merely an abstract description may not always be sufficient.
Importance for Spain
This has obvious consequences for increasingly data-driven financial services.
A Spanish customer may have personal information contained in:
account records;
transaction histories;
credit files;
digital profiles;
analytical records; and
other financial databases.
Article 15 GDPR can therefore operate alongside open-banking legislation as an important transparency mechanism.
18. Additional Banking-Data Principle from CJEU Case Law
CJEU jurisprudence has also addressed situations involving access to customer information held by a bank.
The Court has emphasised that the fact that a controller operates in the banking sector does not, by itself, remove GDPR access rights. Its 2023 judicial review specifically highlighted a banking dispute in which a customer sought information concerning internal consultations of the customer's personal data.
This matters because financial confidentiality and GDPR rights must be reconciled rather than treating banking secrecy as an automatic answer to every data-access request.
19. Supervisory Role of Banco de España
The Banco de España has a central supervisory role in Spanish payment services.
Among other functions, it supervises regulated payment institutions and maintains relevant registration structures.
Royal Decree-Law 19/2018 provides for a special register and expressly includes providers of account-information services within the regulatory architecture.
The Banco de España can also request information needed for supervision, including books, records, documents, computer programs, files and databases where legally necessary for its supervisory responsibilities.
This demonstrates an important feature of open banking:
data access creates regulatory obligations for providers as well as rights for customers.
20. Role of the Spanish Data Protection Authority
Where open-banking activities involve personal data, Spain's data-protection framework and the Spanish Data Protection Agency (AEPD) become relevant alongside banking supervision.
The distinction between regulators can be simplified as follows:
| Issue | Principal Regulatory Perspective |
|---|---|
| Payment institution authorisation | Banking/payment supervision |
| Account-information services | Payment-services regulation |
| Secure account access | PSD2/payment-security framework |
| Personal-data processing | GDPR/data-protection law |
| Customer authentication | Payment-security legislation |
| Data breach | GDPR and potentially banking/security regulation |
| Anti-competitive exclusion | Competition/payment-access rules |
In practice, the same incident can involve several legal regimes.
21. Cybersecurity and Operational Risk
Opening interfaces between banks and external providers necessarily creates cybersecurity risks.
The legal architecture therefore requires secure communication, protection of credentials and strong authentication.
Open banking should consequently be understood as:
controlled openness rather than unrestricted openness.
The underlying policy balance is between:
Innovation
versus
Financial stability
versus
Competition
versus
Cybersecurity
versus
Privacy.
None completely overrides the others.
22. From Open Banking to Open Finance
Spain's future financial-data environment is also connected to the EU's broader movement toward open finance.
The European Commission's financial-data-access initiative is designed to extend structured customer-controlled data sharing beyond payment accounts. Its proposed framework envisages obligations for financial-data holders to make covered customer data available to authorised data users, while maintaining customer control and standardising relevant data and technical interfaces.
The distinction is important:
Open banking
Payment accounts → account information → payment initiation.
Open finance
Potentially broader categories of financial information → broader financial products and services.
The Commission's broader payments reform package also proposes modernisation of PSD2 through a new payment-services framework involving PSD3 and a directly applicable Payment Services Regulation.
Therefore, Spain's present system should be understood as part of an evolving EU-wide financial-data architecture rather than as a completed regulatory project.
23. Consumer Benefits
Properly regulated open banking can provide several benefits.
Customers may obtain:
consolidated account information;
improved personal financial-management services;
easier payment initiation;
greater ability to switch service providers;
competing fintech products;
automated transaction categorisation; and
potentially more personalised financial services.
Businesses can similarly use authorised banking information for accounting, cash-flow analysis and financial administration.
24. Legal Risks
The same system creates substantial legal risks.
Unlawful data processing
A fintech may process information beyond the purpose authorised by the customer.
Excessive collection
A provider may obtain more information than necessary.
Cyberattack
APIs and interconnected systems increase the number of technological relationships that must be secured.
Profiling
Detailed transaction information can reveal highly sensitive aspects of a person's behaviour.
Authentication fraud
Criminals may impersonate customers or legitimate service providers.
Liability disputes
Banks and fintechs may disagree over which participant caused an unauthorised transaction or disclosure.
Competition disputes
Banks may claim access restrictions are required for security, while third-party providers may contend that restrictions improperly obstruct competition.
Spanish and EU law therefore attempt to regulate both sides of data portability: access and responsibility.
25. Practical Example
Assume María has accounts at three Spanish banks.
She uses an authorised financial-management application.
She expressly requests the application to aggregate information from those three payment accounts.
The application acts as an account-information provider.
The legal structure works approximately as follows:
Step 1: María selects the accounts.
Step 2: Her authorisation is obtained through the regulated process.
Step 3: The fintech identifies itself to the relevant banks.
Step 4: Secure communication mechanisms are used.
Step 5: Authentication requirements are satisfied where applicable.
Step 6: The banks provide the information that the provider is legally entitled to obtain.
Step 7: The fintech uses the information for the service requested by María.
The fintech cannot simply treat that access as unlimited permission to create unrelated commercial profiles from her complete financial history.
If the provider wants to undertake additional processing, the legality of that processing must be independently assessed under GDPR and other applicable rules.
26. Overall Legal Position
Spain has moved from the traditional model of:
Bank controls account + bank controls interface + bank controls access
toward:
Customer controls permission + bank safeguards account + authorised third parties can provide competing services.
Royal Decree-Law 19/2018 is central to this transition. It recognises account-information and payment-initiation providers, establishes customer rights, imposes security requirements and gives the Banco de España supervisory responsibilities.
GDPR adds a second layer by controlling what may happen to personal information once it is accessed or otherwise processed.
The CJEU cases discussed above provide important interpretative principles:
ING-DiBa, C-191/17 — clarifies the concept of a payment account.
DenizBank, C-287/19 — confirms the continuing importance of payment-service consumer protections in technologically innovative payment arrangements.
Tecnoservice, C-245/18 — illustrates statutory allocation of responsibility in electronic payment execution.
Österreichische Post, C-154/21 — strengthens transparency concerning recipients of personal information.
Österreichische Post, C-300/21 — explains the requirements for GDPR compensation.
CRIF, C-487/21 — develops the GDPR right to receive an effective copy of personal data undergoing processing.
Conclusion
Banking law and open-data banking initiatives in Spain represent a shift from institution-controlled financial information toward regulated, customer-controlled financial-data portability.
The Spanish system does not make banking information “open” in the ordinary sense. Instead, it creates a controlled legal mechanism through which authorised providers can access specified payment-account information when the customer requests the service.
The system rests on five interconnected principles:
customer control, regulated third-party access, secure technical communication, data protection and fair competition.
Royal Decree-Law 19/2018 supplies the principal Spanish payment-services framework, while GDPR governs much of the processing of personal financial information. CJEU jurisprudence then provides binding interpretations of EU payment and data-protection rules that Spanish courts and regulators must apply.
The next major development is the movement from open banking to open finance. That transition would broaden structured financial-data sharing beyond payment accounts and make questions of consent, transparency, API governance, cybersecurity, competition, liability and data minimisation even more important.
Accordingly, Spain's open-data banking framework is best understood not simply as a fintech initiative, but as an integrated area of banking law, payment law, privacy law, cybersecurity regulation, consumer protection and competition law.

comments