Banking Law And Open Finance Ecosystem Governance Spain .

Banking Law and Open Finance Ecosystem Governance in Spain

1. Introduction

Open finance describes a financial system in which customers can permit regulated third parties to access and use financial information held by banks and other financial institutions to provide services such as payments, financial management, credit assessment and personalised financial products.

It is broader than open banking.

Open banking under the existing PSD2 framework primarily concentrates on payment accounts and payment services. Open finance seeks to extend controlled financial-data sharing into areas such as:

savings;

investments;

securities;

pensions;

mortgages;

credit;

insurance; and

other financial products.

In Spain, governance of this ecosystem is not based on one single “Open Finance Act.” It results from overlapping Spanish and European Union rules.

The principal framework includes:

Directive (EU) 2015/2366 (“PSD2”);

Spanish Royal Decree-Law 19/2018 on payment services;

Royal Decree 736/2019;

the General Data Protection Regulation (“GDPR”);

Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights;

banking and payment-services regulation;

consumer-protection rules;

cybersecurity requirements;

competition law;

outsourcing and operational-resilience rules;

the Digital Operational Resilience Act (“DORA”); and

the developing EU framework for broader financial-data access.

Spain's current payment-services framework continues to include Royal Decree-Law 19/2018 and Royal Decree 736/2019.

The central governance question is therefore:

Who may access financial data, for what purpose, on whose authority, under which technical safeguards, and who is responsible if something goes wrong?

 

2. From Open Banking to Open Finance

Open banking and open finance should not be treated as identical concepts.

Open Banking

The PSD2 model principally permits regulated third-party providers to interact with customers' payment accounts.

Important participants include:

Account Servicing Payment Service Provider (ASPSP)
Usually the customer's bank.

Payment Initiation Service Provider (PISP)
Initiates a payment at the customer's request.

Account Information Service Provider (AISP)
Obtains account information with the customer's permission and provides account-information services.

Open Finance

Open finance expands the concept beyond payment accounts.

The ecosystem may eventually connect information concerning:

Bank accounts

 

Savings

 

Credit

 

Investments

 

Insurance

 

Other financial products.

Consequently, governance becomes significantly more complicated.

 

3. PSD2 as the Foundation

PSD2 established the legal foundation for modern European open banking.

Spain implemented the payment-services framework principally through Royal Decree-Law 19/2018 of 23 November on payment services and other urgent financial measures.

The legislation opened payment-account infrastructure to authorised third-party providers while imposing regulatory requirements concerning:

authorisation;

customer consent;

authentication;

security;

information;

liability; and

supervision.

The legal structure therefore moved banking away from a completely closed model.

Traditional model:

Customer ↔ Bank

Open-banking model:

Customer ↔ Bank ↔ Authorised Third-Party Provider

The customer remains central because access should occur under the legally required authority.

 

4. Regulatory Governance

Spain's open-finance environment involves several regulators rather than a single authority controlling every issue.

Banco de España

The Bank of Spain performs major functions concerning:

credit institutions;

payment institutions;

payment services;

prudential supervision;

payment infrastructure; and

customer-facing banking regulation.

A person wishing to provide regulated banking, electronic-money or payment services supervised by the Bank of Spain generally requires the appropriate authorisation.

CNMV

The Comisión Nacional del Mercado de Valores (CNMV) supervises securities markets and investment-services activities.

Where open finance extends into investment products, securities or regulated investment services, CNMV rules can therefore become relevant.

AEPD

The Agencia Española de Protección de Datos (AEPD) supervises data-protection requirements.

Its role is especially important because open finance depends upon processing potentially extensive personal financial information.

Thus:

Banking issue → Banco de España

Investment issue → CNMV

Personal-data issue → AEPD

with coordination required where a service crosses regulatory boundaries.

 

5. Authorisation of Third-Party Providers

An open ecosystem does not mean that anyone can connect to banking infrastructure.

Regulated services generally require proper authorisation or registration.

For example, a payment institution wishing to provide regulated payment services must satisfy legal requirements concerning matters such as:

governance;

management;

capital;

internal controls;

risk management;

safeguarding;

operational arrangements; and

security.

This is a fundamental governance mechanism.

Without authorisation controls, an open-finance ecosystem could become an uncontrolled data marketplace.

Instead, the regulatory objective is:

Openness + controlled access + accountability.

 

6. Customer Control

Customer authority is at the heart of open finance.

A bank cannot ordinarily treat the existence of an API as permission to distribute a customer's financial information to anyone requesting it.

The governance structure requires a legally valid basis for access and processing.

A typical structure is:

Customer

↓

requests third-party service

↓

appropriate authority/consent

↓

regulated provider requests permitted data

↓

bank authenticates interaction

↓

data supplied securely

↓

provider uses data for permitted purpose.

The customer's decision therefore acts as a gateway to the ecosystem.

 

7. Consent Under PSD2 and GDPR

One important legal difficulty is that “consent” can have different meanings under different legislation.

PSD2 contains requirements concerning the payment-service user's explicit consent.

The GDPR separately establishes lawful bases for processing personal data.

Therefore:

PSD2 consent

is not automatically identical to

GDPR consent.

A provider must determine the appropriate legal basis for each processing operation under data-protection law rather than assuming that one click resolves every regulatory requirement.

This distinction is crucial in open-finance governance.

 

8. GDPR and Financial Data

Financial information will normally constitute personal data when it relates to an identified or identifiable natural person.

The GDPR therefore plays a central role.

Relevant principles include:

Lawfulness, fairness and transparency

Customers should understand how their data is processed.

Purpose limitation

Data obtained for one purpose should not automatically be reused for unrelated purposes.

Data minimisation

Only data reasonably necessary for the relevant purpose should be processed.

Accuracy

Financial data should be sufficiently accurate for the purpose for which it is used.

Storage limitation

Information should not be retained indefinitely without a lawful justification.

Integrity and confidentiality

Appropriate security must protect financial information.

Accountability

The organisation should be capable of demonstrating compliance.

Open finance therefore cannot be governed solely as an API engineering project.

It is also a data-governance project.

 

9. Spanish Data-Protection Framework

The GDPR operates in Spain together with Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights.

The AEPD is the principal Spanish data-protection supervisory authority.

Open-finance businesses must therefore consider both sector-specific financial regulation and general data-protection requirements.

The basic relationship is:

Financial regulation asks:

“Is this entity authorised to provide the service?”

while

data-protection regulation asks:

“Is this processing of personal information lawful and appropriately controlled?”

Both questions must be answered.

 

10. API Governance

Application Programming Interfaces (“APIs”) provide much of the technological infrastructure behind open banking.

An API allows authorised systems to communicate electronically.

A simplified structure is:

Third-party application

↓

API request

↓

Bank API

↓

authentication/authorisation

↓

permitted account information

↓

secure response.

Governance must therefore address:

who can connect;

how providers are authenticated;

what information can be requested;

security standards;

availability;

incident management;

access logging;

customer authorisation; and

revocation of access.

Poor API governance can create both financial and privacy risks.

 

11. Strong Customer Authentication

Strong Customer Authentication (“SCA”) is an important PSD2 security mechanism.

Authentication generally requires elements from independent categories involving:

knowledge — something the customer knows;

possession — something the customer possesses; and

inherence — something characteristic of the customer.

The objective is to reduce fraud and unauthorised access.

However, SCA is only one component of open-finance governance.

Even perfectly authenticated access can still be unlawful if data is used outside the permitted purpose.

Therefore:

Authentication asks who is accessing.

Authorisation asks what they may do.

Data governance asks how the information may subsequently be used.

 

12. Data Minimisation

Open finance creates a temptation to collect as much information as possible.

The GDPR points in the opposite direction.

Suppose a customer uses an application simply to compare savings products.

The provider should not automatically assume that it may collect the customer's entire financial history merely because the technical interface permits it.

The correct question is:

What information is genuinely necessary for the service?

This makes data minimisation an important ecosystem-governance principle.

 

13. Purpose Limitation

Purpose limitation becomes especially important when financial information has significant commercial value.

Suppose a customer authorises access to account information for a budgeting application.

That does not automatically mean the provider can subsequently use all transaction information for:

unrelated advertising;

profiling;

sale to unrelated third parties;

unrelated credit scoring; or

another incompatible commercial purpose.

The lawful basis and transparency requirements for any additional processing must be assessed separately.

Open finance therefore requires control over the entire data lifecycle, not merely the moment at which information leaves the bank.

 

14. Data Lifecycle Governance

A strong governance model follows financial information through every stage:

Collection

↓

Transmission

↓

Storage

↓

Analysis

↓

Sharing

↓

Updating

↓

Deletion/retention.

Each stage raises different legal risks.

For example, secure API transmission does not solve a problem caused by excessive retention after the information has reached the third-party provider.

 

15. Security Governance

Financial data is particularly attractive to cybercriminals.

The ecosystem therefore requires controls concerning:

encryption;

identity management;

authentication;

access permissions;

API security;

incident detection;

vulnerability management;

business continuity;

security testing; and

third-party risk.

The broader the open-finance network becomes, the larger the potential attack surface.

Security therefore becomes an ecosystem responsibility rather than solely a bank responsibility.

 

16. DORA

The Digital Operational Resilience Act (DORA) significantly strengthens the EU framework for financial-sector digital resilience.

DORA addresses areas including:

ICT risk management;

incident reporting;

digital operational-resilience testing;

third-party ICT risk; and

oversight of critical ICT providers.

This is highly relevant to open finance because services may depend on:

Bank

↓

API provider

↓

cloud infrastructure

↓

data processor

↓

FinTech

↓

customer application.

A failure at one technological provider can therefore affect several financial institutions simultaneously.

Open-finance governance must consequently include operational-resilience governance.

 

17. Outsourcing and Third-Party Risk

Banks and FinTech businesses increasingly rely upon external technology providers.

Outsourcing does not necessarily outsource regulatory responsibility.

An institution should therefore understand:

which provider performs which function;

where information is processed;

subcontracting chains;

security arrangements;

audit rights;

business-continuity arrangements;

exit strategies; and

concentration risk.

If many financial institutions depend upon the same cloud or API infrastructure, the ecosystem can develop a systemic concentration risk.

 

18. Competition

Open banking was partly designed to increase competition by reducing banks' exclusive control over payment-account information.

Open finance could expand this effect.

Potential benefits include:

easier product comparison;

new FinTech services;

greater customer mobility;

improved financial-management tools;

innovative credit assessment; and

lower barriers for authorised competitors.

However, governance must also prevent data-sharing arrangements from becoming mechanisms for anti-competitive coordination.

Competition law therefore remains relevant.

 

19. Credit Scoring and Profiling

Open finance may allow providers to analyse detailed transaction histories when assessing creditworthiness.

For example:

income

 

regular expenses

 

existing debt

 

payment history

 

financial behaviour

↓

credit assessment.

Such systems can potentially improve credit assessment, but they also raise significant GDPR issues.

The most important concerns include:

transparency;

data accuracy;

profiling;

automated decision-making;

discrimination risks; and

rights of affected individuals.

Governance must therefore address not only access to data, but also decisions produced from data.

 

20. Automated Decision-Making

Article 22 GDPR is particularly important where financial data feeds automated decisions having legal or similarly significant effects.

An automated credit decision can significantly affect a person.

Therefore, depending upon the precise circumstances and applicable exception, organisations may need safeguards concerning:

information about automated processing;

meaningful human involvement;

ability to challenge a decision; and

protection against inappropriate solely automated decision-making.

Open finance therefore creates a progression:

Financial data sharing

↓

profiling

↓

automated assessment

↓

financial decision

↓

legal consequences.

Governance must control the entire chain.

 

21. Consumer Protection

Open-finance customers may struggle to understand which organisation is responsible for a service.

For example:

Bank A holds account

↓

FinTech B accesses information

↓

Technology Provider C processes information

↓

Lender D makes offer.

If something goes wrong, the customer needs to know:

who provided the service;

who controlled the data;

who made the decision;

who handles complaints;

which regulator supervises the activity; and

who bears liability.

Clear allocation of responsibility is therefore one of the most important ecosystem-governance requirements.

 

22. Financial Data Access Regulation

The European Union's proposed broader financial-data-access framework—commonly associated with FIDA—has been intended to move European financial services beyond the payment-account focus of PSD2.

Its conceptual importance is the development of controlled access to broader categories of customer financial information.

The intended governance model involves concepts such as:

customer-controlled data sharing;

authorised financial-information service providers;

data holders;

data users;

financial-data-sharing schemes;

technical standards;

access controls; and

liability arrangements.

For Spain, such a framework would significantly deepen the existing open-banking ecosystem.

Until the applicable legislative framework becomes operative, however, PSD2 should not simply be treated as though it already provides unrestricted access to every category of financial data.

 

23. PSD3 and the Payment Services Regulation

The European payments framework is also evolving beyond PSD2.

The reform package involving a new Payment Services Directive and Payment Services Regulation seeks to modernise areas including:

fraud prevention;

customer authentication;

open-banking functionality;

payment-provider obligations;

enforcement; and

consumer protection.

For ecosystem governance, the important lesson is that Spain's open-finance architecture is dynamic.

Banks and FinTech businesses therefore need regulatory-change governance rather than compliance systems designed around one permanently fixed version of PSD2.

 

24. Cryptoassets and Open Finance

The boundary between payments, cryptoassets and traditional finance is also becoming increasingly important.

In March 2026, the Bank of Spain reiterated that cryptoasset service providers providing payment services involving electronic-money tokens may need appropriate PSD2 payment-service authorisation.

This illustrates a fundamental governance principle:

Technology label does not determine regulatory status.

A business calling itself a “crypto platform” or “FinTech” does not escape payment-services regulation when its actual activities constitute regulated payment services.

Open-finance governance therefore depends on the substance of the service.

 

25. Supervisory Cooperation

Open finance cuts across traditional regulatory categories.

An ecosystem may simultaneously involve:

banking supervision

 

payment supervision

 

investment regulation

 

data protection

 

competition law

 

cybersecurity

 

consumer protection.

No single regulator necessarily controls every component.

Effective governance therefore increasingly depends upon regulatory cooperation.

 

26. Relevant Case Law

There is not yet a large body of Spanish Supreme Court judgments specifically using the modern expression “open finance ecosystem governance.”

The legal principles are instead developing through Spanish litigation and Court of Justice of the European Union (“CJEU”) decisions concerning payment services, financial-data sharing, data protection, credit information, authentication and financial regulation.

Because EU law directly shapes Spain's framework, CJEU judgments arising from Spain or interpreting the relevant EU rules are particularly important.

 

Case 1 — ASNEF-EQUIFAX, Case C-238/05, CJEU, 23 November 2006

This case arose from proceedings before the Spanish Supreme Court concerning a system through which financial institutions exchanged information regarding customers' solvency and creditworthiness.

The dispute principally concerned EU competition law.

Principle

The Court did not treat financial-information sharing as inherently unlawful.

Its legality depended upon factors including the structure of the market, the characteristics of the information-sharing system and its effects on competition and consumers.

Open-finance relevance

This is an important early Spanish financial-data-governance authority.

It demonstrates that financial-data sharing has both:

efficiency benefits

and

competition risks.

Open-finance governance must therefore prevent information-sharing infrastructure from becoming a vehicle for anti-competitive coordination.

 

Case 2 — Safe Interenvíos SA v Liberbank SA, Banco de Sabadell SA and BBVA, Case C-235/14, CJEU, 10 March 2016

This case arose from the Audiencia Provincial de Barcelona.

It concerned banks that had terminated accounts used by a payment institution because of concerns connected with money laundering and terrorist-financing requirements.

Principle

Payment-services rights must coexist with AML/CFT obligations.

Banks can apply enhanced customer-due-diligence measures in circumstances permitted by AML legislation, but national measures must remain compatible with EU law and proportionality requirements.

Open-finance relevance

A regulated third-party provider's participation in the financial ecosystem does not eliminate the bank's AML responsibilities.

Therefore:

Open access ≠ unconditional access.

Banks must balance ecosystem openness with financial-crime controls.

 

Case 3 — SCHUFA Holding (Scoring), Case C-634/21, CJEU, 7 December 2023

The Court examined automated credit scoring based on personal information.

It held, in substance, that calculating a probability value concerning a person's future ability to meet payment commitments can fall within GDPR rules governing automated decision-making where that score plays a determining role in the ultimate decision.

Open-finance relevance

This judgment is extremely important for data-driven lending.

Open-finance data may produce sophisticated credit scores.

However:

more data

does not mean

unrestricted automated decision-making.

Where scoring materially determines whether credit is granted, Article 22 GDPR safeguards can become relevant.

 

Case 4 — Österreichische Post, Case C-300/21, CJEU, 4 May 2023

This judgment concerned compensation under Article 82 GDPR.

Principle

A GDPR infringement alone does not automatically produce compensation.

There must be:

an infringement;

damage; and

a causal connection between the infringement and damage.

However, EU law does not permit a general requirement that non-material damage must reach a particular seriousness threshold before compensation can be available.

Open-finance relevance

If financial information is unlawfully processed or disclosed within an open-finance ecosystem, liability cannot be assessed merely by asking whether a technical GDPR violation occurred.

Actual damage and causation also matter for compensation.

This becomes important when allocating liability among banks, FinTechs and data processors.

 

Case 5 — UI v Österreichische Post, Case C-154/21, CJEU, 12 January 2023

The case concerned a person's right under Article 15 GDPR to obtain information about recipients of personal data.

Principle

Where personal data have been or will be disclosed, the data subject is generally entitled to information concerning the actual recipients rather than merely categories of recipients, subject to the qualifications identified by the Court.

Open-finance relevance

This supports transparency within complex data-sharing networks.

A customer should not lose visibility merely because information moves through multiple organisations.

The case reinforces the governance principle:

Customers should be able to understand where their personal information has gone.

 

Case 6 — Meta Platforms and Others v Bundeskartellamt, Case C-252/21, CJEU, 4 July 2023

Although this case arose outside banking, it is highly relevant to open-finance data governance.

Principle

The Court examined the interaction between competition enforcement and GDPR requirements and confirmed, subject to the limits of their powers, that competition authorities may need to consider GDPR compliance when examining potentially abusive conduct involving personal data.

Open-finance relevance

The judgment demonstrates that data governance and competition governance cannot always be separated.

In open finance, control over valuable financial data can affect:

market power;

competition;

customer choice; and

privacy.

The same ecosystem may therefore attract scrutiny under several legal regimes simultaneously.

 

Case 7 — Latvijas Republikas Saeima, Case C-439/19, CJEU, 22 June 2021

The Court examined the processing and public availability of personal information associated with road-traffic penalty points.

Although not a banking dispute, it contains important GDPR principles concerning necessity, proportionality and disclosure of personal information.

Open-finance relevance

Financial-data sharing should not become excessive merely because sharing produces commercial benefits.

Data access must remain tied to legitimate purposes and proportional processing.

This supports the open-finance principle of controlled rather than unlimited data circulation.

 

Case 8 — CJEU Payment Services/Ancillary Financial Services Judgment, Spanish Reference, 2026

In a 2026 judgment arising from a Spanish reference, the CJEU interpreted Article 18(1)(a) PSD2 concerning activities that payment-service providers may undertake alongside payment services.

The Court held that authorised payment-service providers may provide closely related ancillary services, including certain foreign-exchange arrangements falling within the circumstances examined by the Court.

Open-finance relevance

The decision illustrates an increasingly important ecosystem problem:

Where does one regulated financial service end and another begin?

FinTech businesses frequently combine payments, foreign exchange, information services and other financial functionality within a single digital interface.

The legal classification of each activity determines:

licensing;

supervisory authority;

organisational requirements; and

applicable customer protections.

Open-finance governance must therefore examine the substance of bundled digital services rather than treating the entire application as one legally uniform product.

 

27. Practical Example

Assume a Spanish customer uses a financial-management application.

The customer connects:

Bank account

 

credit card

 

investment account

 

other financial information.

The application analyses the information and recommends a credit product.

A complete governance analysis should ask:

Step 1 — Regulatory status

Is the provider properly authorised for the regulated services it performs?

Step 2 — Access authority

Has the customer validly authorised access?

Step 3 — Data scope

Is the provider obtaining only information necessary for the service?

Step 4 — GDPR basis

What lawful basis supports each processing operation?

Step 5 — Purpose

Is information being used only for properly disclosed and lawful purposes?

Step 6 — Security

Are APIs and stored data adequately protected?

Step 7 — Profiling

Is customer behaviour being profiled?

Step 8 — Automated decisions

Does an automated score effectively determine whether the customer receives credit?

Step 9 — Third parties

Which external technology providers process the information?

Step 10 — Liability

Who is responsible if data is incorrect, leaked or improperly used?

This demonstrates why open finance is fundamentally a governance architecture, not merely a data-sharing technology.

 

28. Governance Model for Spain

A sound Spanish open-finance governance structure can be expressed as:

Customer

↓

clear request / appropriate authority

↓

regulated financial-data holder

↓

secure API

↓

authorised third-party provider

↓

lawful and purpose-limited processing

↓

financial service

↓

transparent customer outcome

supported by:

Banco de España supervision

 

CNMV supervision where relevant

 

AEPD data-protection supervision

 

EU financial regulation

 

competition law

 

DORA operational resilience

 

consumer-protection law.

 

29. Main Governance Risks

The principal legal risks can be grouped into six categories.

1. Access Risk

An unauthorised organisation obtains financial information.

2. Privacy Risk

An authorised organisation processes more information than legally justified.

3. Cybersecurity Risk

Information is compromised through a bank, FinTech or technology provider.

4. Decision Risk

Incorrect or biased data produces an adverse financial decision.

5. Competition Risk

Dominant firms restrict access or data-sharing arrangements facilitate anti-competitive behaviour.

6. Accountability Risk

Several organisations participate in the service but responsibility for failure is unclear.

Good governance must address all six.

 

30. Open Finance Versus Traditional Banking Governance

Traditional banking governance concentrated primarily on:

capital + liquidity + credit + operational risk + customer protection.

Open-finance governance adds another layer:

data access + APIs + consent + privacy + third parties + algorithms + cyber resilience + cross-sector supervision.

Banks therefore increasingly operate not only as financial intermediaries but also as custodians of highly valuable financial data.

 

31. Importance of Customer Mobility

A major objective of open finance is to give customers greater control over their financial relationships.

If financial information can move securely at the customer's direction, customers may find it easier to:

compare products;

change providers;

obtain personalised services;

consolidate financial information; and

access innovative FinTech services.

Research published by the Bank of Spain has examined evidence from Spain indicating that open-banking initiatives affect FinTech providers and are intended to encourage competition and innovation through customer-authorised financial-data sharing.

Governance must therefore avoid two extremes:

Closed system: customer cannot effectively use their financial information elsewhere.

Uncontrolled system: financial information circulates without sufficient safeguards.

The regulatory objective lies between them.

 

32. Future Direction

Spain's open-finance framework is developing from a relatively narrow payment-account-access system toward a broader financial-data ecosystem.

The direction can be represented as:

Traditional banking

↓

PSD2

↓

Open banking

↓

broader financial-data access

↓

Open finance

↓

potential increasingly interconnected financial ecosystem.

As this development continues, regulatory attention is likely to remain concentrated on:

customer control;

data protection;

secure APIs;

third-party authorisation;

operational resilience;

fraud prevention;

automated decision-making;

competition;

liability; and

regulatory cooperation.

 

33. Conclusion

Open-finance ecosystem governance in Spain is best understood as a multi-regulator, multi-layer legal framework governing controlled access to financial data.

PSD2 and Royal Decree-Law 19/2018 provide the core existing foundation for open banking and payment-account access. GDPR and Organic Law 3/2018 govern the processing of personal financial information. The Bank of Spain supervises important banking and payment activities, while the CNMV becomes relevant to investment activities and the AEPD supervises personal-data protection.

DORA adds another essential layer by addressing ICT risk and operational resilience.

The central governance model is therefore:

Customer control

 

authorised providers

 

secure technical access

 

purpose-limited data use

 

privacy

 

cybersecurity

 

operational resilience

 

clear liability

 

regulatory supervision.

The case law demonstrates that open-finance governance is not simply about forcing banks to share information. ASNEF-EQUIFAX shows the competition implications of financial-data exchange; Safe Interenvíos demonstrates that access must coexist with AML/CFT obligations; SCHUFA highlights the risks of automated credit scoring; Österreichische Post clarifies the requirements for GDPR compensation; UI v Österreichische Post strengthens transparency concerning data recipients; Meta Platforms illustrates the interaction between privacy and competition regulation; and the more recent payment-services jurisprudence demonstrates the importance of correctly classifying bundled FinTech activities.

The fundamental legal principle is therefore:

Open finance does not mean open access to everything. It means regulated, secure and accountable access to financial information under a framework that preserves customer control and allocates responsibility throughout the ecosystem.

Case-Law Qualification

The cases discussed above should not be described as eight Spanish Supreme Court judgments specifically deciding “open finance ecosystem governance.” The concept is newer than much of the underlying jurisprudence. They are Spanish-origin and EU authorities establishing legal principles directly relevant to financial-data sharing, payment services, credit scoring, data protection, competition and FinTech governance.

For formal litigation or academic citation, the original judgment, procedural history and applicable version of Spanish and EU legislation should be checked before relying on any individual proposition.

LEAVE A COMMENT