Banking Law And Open Finance Eu Regulatory Expansion Spain .

Banking Law and EU Open Finance Regulatory Expansion in Spain

1. Introduction

Open finance represents the proposed expansion of the European Union's existing open-banking model into a much wider system of customer-controlled financial-data sharing.

Spain is particularly affected because Spanish banks, payment institutions, fintech companies, insurers, investment firms and other financial businesses operate within the EU financial-services framework.

The evolution can broadly be expressed as:

Traditional banking → Online banking → Open banking → Open finance.

Open banking under the revised Payment Services Directive (PSD2) primarily created regulated access to payment-account information and payment-initiation services.

Open finance goes considerably further.

The European Commission's proposed Framework for Financial Data Access Regulation (FIDA) is designed to establish rights and obligations for sharing customer data across a wider range of financial services, beyond payment accounts.

The Commission proposed FIDA on 28 June 2023. However, as of September 2026, the proposal remains within the EU ordinary legislative procedure and should not be described as a fully applicable regulation in Spain.

Consequently, Spanish institutions must distinguish between:

existing legally binding open-banking requirements;

existing GDPR and financial-sector requirements; and

the developing FIDA open-finance framework.

 

2. What Is Open Finance?

Open finance is a financial-data-sharing model under which customers can permit regulated third parties to access and use financial information held by financial institutions.

The fundamental idea is that financial data should not remain locked inside one institution merely because that institution originally generated or stores the information.

Instead, customers should be able to authorize its use by another provider.

For example, a customer could potentially allow an authorized service provider to analyze information concerning:

bank accounts;

savings;

investments;

mortgages;

loans;

insurance;

pensions; and

other financial products falling within the eventual regulatory scope.

The customer could then obtain services such as consolidated financial dashboards, financial comparisons or personalized financial products.

Open finance therefore transforms financial information from institution-specific data into customer-controlled interoperable financial data, subject to legal safeguards.

 

3. Open Banking as the Foundation

Spain already operates within the EU open-banking framework established principally through Directive (EU) 2015/2366 — PSD2.

PSD2 created regulated categories including:

Account Information Service Providers (AISPs)

These providers can obtain payment-account information with the payment-service user's authorization.

Payment Initiation Service Providers (PISPs)

These providers can initiate payments from the customer's account with appropriate authorization.

The Spanish implementation of PSD2 includes Royal Decree-Law 19/2018 on payment services and other urgent financial measures.

Thus, Spanish banks already operate within an ecosystem in which regulated third parties can interact with payment accounts.

Open finance seeks to extend that principle substantially beyond payment accounts.

 

4. From PSD2 to FIDA

The difference can be illustrated simply.

PSD2/Open Banking

Primarily concerns:

Payment-account data + payment initiation.

FIDA/Open Finance

Would extend regulated access to significantly broader categories of:

financial customer data.

The European Commission describes FIDA as creating a framework for responsible access to individual and business customer data across a wide range of financial services.

The proposed system would establish:

rights and obligations concerning financial-data sharing;

customer control over access;

obligations on data holders;

standardized data;

technical interfaces;

regulated financial-information service providers; and

financial-data-sharing schemes.

The fundamental transition is therefore:

Open bank account → Open financial relationship.

 

5. Customer Control Is Central

The proposed framework does not mean that financial institutions can freely circulate customers' financial information.

The European Commission's FIDA model is explicitly customer-centric.

Customers would have the possibility, rather than an obligation, to make their financial information available to data users.

Accordingly:

No customer authorization → no ordinary open-finance sharing merely because another business wants the data.

The objective is to give customers greater practical control over information already generated through their financial relationships.

 

6. Data Holders

Under the proposed open-finance architecture, many financial institutions can become data holders.

A data holder possesses financial information concerning a customer and may have an obligation to make qualifying data available when the applicable legal conditions are satisfied.

Spanish banks are therefore likely to play a dual role.

They can be:

data holders, when another authorized provider seeks access to information held by the bank;

and potentially

data users, when the bank obtains authorized financial information from another institution.

This represents an important competitive change.

Large incumbent institutions would no longer necessarily possess an exclusive informational advantage merely because they have maintained a customer's financial relationship for many years.

 

7. Financial Information Service Providers

FIDA also contemplates a regulated category of businesses that would provide financial-information services.

The concept is important because open finance is not intended to create unrestricted public access to financial databases.

An entity seeking access would need to fall within the regulatory structure and comply with applicable authorization, governance, security and data-use requirements.

This represents an important difference between:

regulated data sharing and unregulated data extraction.

Open finance is intended to encourage competition without eliminating financial supervision.

 

8. Financial Data Sharing Schemes

One important element of FIDA is the development of financial-data-sharing schemes.

Such arrangements are intended to establish common rules concerning matters such as:

data standards;

technical interfaces;

access;

liability;

governance;

compensation; and

contractual arrangements between participants.

This attempts to solve a major problem that can arise when every institution develops incompatible systems.

True open finance requires interoperability.

Therefore:

Legal access + technical interoperability = practical open finance.

A legal right to data would be of limited value if the information could not be transmitted securely in a standardized and usable format.

 

9. APIs and Technical Interfaces

Application Programming Interfaces (APIs) are likely to remain fundamental to open finance.

Open banking demonstrated that third-party access should ideally occur through controlled technical interfaces rather than by requiring customers to provide their ordinary online-banking credentials to outside businesses.

Open finance continues this development.

A well-designed API structure can help institutions:

authenticate participants;

restrict access;

log data requests;

identify the information transmitted;

revoke access;

monitor abnormal activity; and

reduce dependence on insecure screen-scraping practices.

Thus, cybersecurity architecture becomes part of banking-law compliance.

 

10. Permission Dashboards

A particularly important consumer-protection feature is the concept of a permission dashboard.

Customers need an understandable mechanism showing:

Who has access?

What data can they see?

Why can they use it?

For how long?

Can access be withdrawn?

Without such tools, nominal customer control could become meaningless because individuals would be unable to remember which providers received permission.

Open finance therefore requires not merely initial authorization but continuing control over data access.

 

11. GDPR and Open Finance

Open finance must operate alongside the General Data Protection Regulation (GDPR).

Financial data can constitute personal data where it relates to an identifiable natural person.

Accordingly, institutions must consider principles such as:

lawfulness;

fairness;

transparency;

purpose limitation;

data minimization;

accuracy;

storage limitation;

integrity;

confidentiality; and

accountability.

Open-finance permission should not automatically be confused with every concept of consent under GDPR.

A financial-data-access permission may provide authority under the financial-services framework, while the processing of personal data must still have an appropriate GDPR legal basis.

This distinction is crucial.

 

12. Purpose Limitation

Suppose a Spanish customer allows an authorized service to obtain investment and account information for the purpose of producing a consolidated financial dashboard.

The provider should not automatically assume that this permission authorizes every conceivable secondary use.

Open finance must therefore be combined with purpose limitation.

The questions become:

What did the customer authorize?

What processing is legally permitted?

How much data is actually necessary?

Can the information be retained?

Can it be shared onward?

The answers depend upon the interaction between financial-services law, GDPR and the eventual FIDA regime.

 

13. Data Minimization

The GDPR principle of data minimization is particularly important in open finance.

A service should not automatically receive an entire customer's financial history merely because some information is useful.

Access should be appropriately limited to information required for the permitted service.

For example, if a service needs particular account and loan information, unrestricted access to unrelated insurance or investment information may be unnecessary.

The legal architecture must therefore reconcile:

interoperability with privacy.

 

14. Security

Open finance creates substantial cybersecurity obligations.

The more institutions capable of accessing financial data, the greater the number of potential attack points.

Important risks include:

identity theft;

unauthorized API access;

credential compromise;

fraudulent permissions;

data interception;

malicious applications;

compromised fintech providers; and

misuse of financial profiles.

Spanish institutions therefore need technical and organizational security proportionate to the sensitivity of the information processed.

 

15. DORA and Operational Resilience

The Digital Operational Resilience Act (DORA) is also important to the open-finance ecosystem.

DORA establishes EU requirements concerning information and communications technology risk in the financial sector.

Its framework addresses matters such as:

ICT risk management;

incident management;

resilience testing;

third-party ICT risk; and

supervisory oversight.

This matters because open finance depends heavily upon interconnected digital infrastructure.

A failure at one service provider can potentially affect several institutions connected through data-sharing arrangements.

Open finance therefore increases the importance of:

data openness + operational resilience.

 

16. PSD3 and the Payment Services Regulation

FIDA is not developing in isolation.

The Commission's 2023 financial-data package also proposed:

a new Payment Services Directive (PSD3); and

a directly applicable Payment Services Regulation (PSR).

These reforms are intended to modernize the PSD2 framework, improve fraud prevention, strengthen consumer rights and refine the rules applying to payment services and open banking.

As of September 2026, these reforms should also be treated according to their actual legislative status rather than being described prematurely as fully applicable replacements for PSD2.

The eventual structure will connect:

PSD3/PSR → payment services and open banking

with

FIDA → wider open finance.

 

17. Competition

Open finance is intended partly to increase competition.

Traditional banks possess large quantities of historical information concerning customers.

This information can create a commercial advantage.

If customers can authorize secure transfer of their information to competing providers, switching and comparison may become easier.

Potential results include:

greater fintech competition;

improved financial aggregation;

easier product comparison;

more personalized services;

reduced information asymmetry; and

potentially easier movement between providers.

However, greater competition must not be achieved by weakening privacy or cybersecurity.

 

18. Credit Assessment

Open finance could significantly affect credit assessment.

A lender may potentially obtain a broader picture of a customer's financial situation when the customer permits relevant data access.

Instead of relying solely upon a limited credit application, the provider may have access to structured financial information.

Potential benefits include more accurate affordability assessments.

However, risks include:

excessive profiling;

discriminatory outcomes;

opaque automated decisions;

inaccurate source data; and

inappropriate use of unrelated information.

Consequently, open finance intersects with consumer credit, data protection and automated decision-making rules.

 

19. Insurance and Investment Services

One major difference between open banking and open finance is expansion beyond conventional bank accounts.

The proposed regime potentially affects financial information relating to investment and insurance products within its statutory scope.

This could enable services that present a customer with a consolidated view of:

banking + savings + investments + insurance + other financial positions.

For Spanish financial groups operating across several sectors, this represents both an opportunity and a compliance challenge.

Institutions may simultaneously hold and use information across multiple regulated activities.

 

20. Pensions and Long-Term Financial Data

Long-term savings and pension-related information may also become relevant within the eventual framework, subject to the final scope and exclusions adopted by EU legislators.

Such information can be particularly sensitive because it can reveal:

long-term wealth;

retirement planning;

contributions;

investment strategy; and

financial vulnerability.

Therefore, broader data access must be accompanied by proportionately strong safeguards.

 

21. Liability

One of the most difficult legal questions in open finance is:

Who is responsible when something goes wrong?

Potential disputes may involve:

inaccurate data;

outdated data;

unauthorized disclosure;

cyberattack;

misuse by a data user;

failure of an API;

wrongful denial of access;

failure to revoke access; or

losses caused by reliance upon erroneous financial information.

A mature open-finance framework therefore requires clear allocation of responsibilities among:

customer → data holder → data user → technical provider.

This is one reason standardized financial-data-sharing schemes are important.

 

22. Supervisory Structure in Spain

Open finance will involve several regulatory layers.

Depending upon the institution and activity, relevant authorities may include:

Banco de España;

European Central Bank;

Spanish securities authorities;

insurance and pension supervisors;

Spanish data-protection authorities; and

European supervisory bodies.

The appropriate regulator depends upon:

who processes the data, what service is provided, and which financial sector is involved.

Open finance therefore requires cooperation between financial and data-protection supervision.

 

23. Current Legislative Status

An important qualification is essential.

The Commission proposed FIDA in June 2023, but the proposal remains in the EU legislative process as of September 2026.

The European Parliament's Legislative Observatory continues to classify Procedure 2023/0205(COD) as the Framework for Financial Data Access proposal and records it as awaiting Parliament's first-reading position.

Therefore, FIDA should not presently be described as though every proposed data-access obligation were already binding upon Spanish financial institutions.

The legally accurate distinction is:

Existing law: PSD2/open banking, GDPR, DORA and other applicable financial legislation.

Developing law: FIDA and the wider reform of EU payment-services legislation.

This distinction is crucial for banks preparing their compliance architecture.

 

24. Relevant Case Law

Because FIDA is still a developing legislative framework, there cannot yet be six mature Spanish Supreme Court judgments interpreting final FIDA obligations.

It would therefore be inaccurate to invent “FIDA cases.”

The relevant jurisprudence instead comes from Spanish references to the Court of Justice of the European Union (CJEU) concerning banking transparency, consumer information, data protection and effective remedies.

These authorities establish principles likely to remain highly important as Spanish financial services become increasingly data-driven.

 

Case 1 — Banco Español de Crédito SA v Joaquín Calderón Camino, C-618/10, CJEU, 14 June 2012

This landmark Spanish banking case concerned consumer credit and unfair contractual terms.

The Court emphasized that the consumer is generally in a weaker position than the financial institution concerning both bargaining power and knowledge.

National courts must therefore be capable of examining unfair contractual terms where the necessary legal and factual material is available.

Importance for Open Finance

Open finance can substantially increase information asymmetry in a new direction.

Financial institutions and fintechs may possess sophisticated analytical capabilities that consumers do not understand.

Therefore, customer authorization should be:

transparent;

understandable;

meaningful; and

consistent with mandatory consumer protection.

A digital click should not automatically validate an unfair arrangement.

 

Case 2 — Mohamed Aziz v Caixa d'Estalvis de Catalunya, Tarragona i Manresa, C-415/11, CJEU, 14 March 2013

This Spanish reference concerned mortgage enforcement and unfair terms.

The CJEU held that national procedural arrangements must provide effective protection of consumer rights under EU law.

Importance for Open Finance

Digitalization cannot reduce effective legal remedies.

If a customer suffers loss because financial data was misused, improperly accessed or relied upon contrary to consumer law, the surrounding procedural system must provide effective mechanisms for protection.

Therefore:

digital innovation cannot eliminate effective judicial protection.

 

Case 3 — Gutiérrez Naranjo and Others, Joined Cases C-154/15, C-307/15 and C-308/15, CJEU, 21 December 2016

These cases concerned Spanish mortgage floor clauses.

The Court emphasized the consequences required when a contractual term is declared unfair and rejected limitations that would undermine the full effectiveness of EU consumer protection.

Importance for Open Finance

The principle is relevant because an unlawful financial-data arrangement cannot necessarily be cured merely by stopping future processing.

Depending upon the applicable law, effective remedies may also need to address consequences already produced.

Open finance therefore requires attention not merely to initial permission but also to remedies when rights are violated.

 

Case 4 — Banco Santander SA, Case C-598/15, CJEU, 7 December 2017

This Spanish reference arose from proceedings involving Banco Santander and consumer-protection questions connected with mortgage enforcement.

The Court ultimately treated the particular preliminary reference as inadmissible because the referring body did not satisfy the necessary characteristics for the requested preliminary-ruling procedure in that context.

Importance for Open Finance

Although it does not establish a substantive FIDA rule, the case illustrates an important institutional principle:

EU financial rights operate within defined procedural and judicial structures.

As open finance develops, disputes concerning data access, consumer protection and financial services will likewise depend upon correct identification of:

competent authority;

available procedure;

jurisdiction; and

enforceable remedy.

 

Case 5 — Banco Santander, Case C-268/19

This Spanish reference involved Banco Santander and questions connected with consumer financial products and the transparency requirements arising from EU consumer law.

The Spanish Supreme Court's reference discussed the established CJEU principle that consumers must receive intelligible information concerning contractual conditions so that they can understand their financial and legal consequences.

Importance for Open Finance

Transparency will be fundamental to financial-data permissions.

A customer should understand:

what information is being accessed;

which provider receives it;

why the information is needed;

how it may be used;

and

what consequences may follow.

Formal disclosure without practical comprehensibility would undermine genuine customer control.

 

Case 6 — MF v Banco Santander SA, C-230/24, CJEU, 13 March 2025

This recent Spanish banking case originated from the Court of First Instance No. 8 of A Coruña.

It concerned a mortgage contract, an unfair clause allocating expenses to the consumer and the relationship between nullity and the limitation period governing restitution.

The CJEU again examined the requirement that national procedural rules preserve effective EU consumer protection.

Importance for Open Finance

Open-finance disputes may eventually involve different legal actions arising from the same data relationship.

For example:

withdrawal of data permission;

deletion or restriction claims;

contractual claims;

compensation;

regulatory complaints; and

consumer remedies.

Different claims may operate under different procedural rules and limitation periods.

Therefore, a digital data-access relationship should not be treated as one indivisible legal issue.

 

Case 7 — Banco Santander / Banco Popular Resolution, C-687/23, CJEU, 11 September 2025

This Spanish reference arose from litigation following the resolution of Banco Popular and Banco Santander's succession to it.

The dispute concerned rights arising from actions for nullity and damages connected with financial instruments marketed before the bank's resolution.

The Court addressed whether those rights could remain enforceable against Banco Santander despite the operation of EU bank-resolution rules.

Importance for Open Finance

Although this is not a financial-data-access case, it demonstrates an increasingly important feature of EU financial law:

different EU regulatory regimes must be interpreted together.

Open finance will likewise operate at the intersection of:

financial-services legislation;

data protection;

consumer protection;

prudential regulation;

operational resilience; and

potentially bank-resolution rules.

FIDA therefore cannot be interpreted as an isolated data-sharing statute.

 

25. Principles Emerging from the Case Law

These cases establish several principles relevant to Spain's transition toward open finance.

Effective consumer protection

Digital innovation cannot weaken mandatory financial-consumer rights.

Meaningful transparency

Customers need information capable of allowing them to understand the legal and economic consequences of their decisions.

Effective remedies

National procedural systems must permit EU rights to be effectively enforced.

Regulatory interaction

Banking law cannot be interpreted independently of consumer law, EU law and other applicable regulatory regimes.

Substance over technological form

A financial relationship does not escape ordinary legal protections simply because it is conducted through an API, app or digital platform.

 

26. Open Finance and Automated Decision-Making

A particularly important future issue concerns automated financial decisions.

Financial-data aggregation can allow institutions to build detailed customer profiles.

Algorithms may use those profiles for:

lending;

pricing;

investment recommendations;

insurance decisions;

fraud detection; and

customer segmentation.

This raises questions under:

GDPR;

financial consumer law;

the EU AI regulatory framework;

anti-discrimination principles; and

sector-specific financial legislation.

The customer may have authorized data access without necessarily authorizing every possible algorithmic inference derived from that data.

Open finance therefore requires regulation of both access to information and use of information.

 

27. Data Accuracy

Open finance also creates a new problem concerning inaccurate financial information.

Suppose Bank A supplies information to Provider B.

Provider B uses it to assess the customer.

If the information is incorrect, several questions arise:

Who must correct it?

Who bears responsibility for decisions made using it?

How quickly must correction propagate through the ecosystem?

What happens if multiple providers already received the incorrect information?

Data accuracy therefore becomes a financial-services issue as well as a GDPR issue.

 

28. Switching and Customer Mobility

One important policy objective of open finance is improved customer mobility.

Customers may be more willing to switch providers where their financial information can move securely with them.

This can reduce informational lock-in.

A new lender, investment provider or financial-management service may be able to understand the customer's financial position without requiring the customer manually to reconstruct years of financial information.

Potentially, this creates:

greater portability → easier comparison → stronger competition.

But customer mobility depends upon genuine interoperability and trustworthy security.

 

29. Risks of Financial Exclusion

Open finance can potentially improve access to financial services, but it can also create exclusion risks.

Detailed financial profiles might lead providers to classify customers more precisely.

That could improve pricing for some customers while making products less accessible to others.

Spanish and EU regulators therefore need to consider whether data-driven financial decisions remain:

transparent;

fair;

legally justified; and

consistent with consumer-protection rules.

Open finance should not become a mechanism for opaque digital exclusion.

 

30. Practical Compliance Model for a Spanish Bank

A Spanish bank preparing for expanded open finance should conceptually structure compliance as follows:

Step 1 — Identify relevant financial datasets

Determine what information is held and which eventual FIDA categories may apply.

Step 2 — Classify the bank's role

Determine when the institution acts as data holder and when it acts as data user.

Step 3 — Map legal bases

Separate financial-data-access permission from GDPR processing requirements.

Step 4 — Build secure interfaces

Develop interoperable and secure APIs.

Step 5 — Implement permission management

Customers need clear control over access.

Step 6 — Establish third-party controls

Verify that requesting providers possess the required regulatory status.

Step 7 — Maintain audit records

Record who accessed what information, when and under what authority.

Step 8 — Build revocation procedures

Withdrawal of permission must have practical effect.

Step 9 — Integrate operational resilience

Open-finance infrastructure must fit within cybersecurity and DORA controls.

Step 10 — Maintain complaint and liability procedures

Customers need effective remedies where data access or use goes wrong.

 

31. Regulatory Expansion in Spain

The significance of EU open finance for Spain lies in the expansion of regulation across several dimensions.

Product expansion

From payment accounts toward wider financial products.

Institutional expansion

From banks and payment providers toward a broader financial ecosystem.

Data expansion

From transaction information toward richer financial datasets.

Competition expansion

From payment-focused fintech competition toward cross-sector financial competition.

Supervisory expansion

From traditional prudential supervision toward increasingly integrated supervision of data, cybersecurity, consumer protection and technology.

This is why FIDA represents much more than a technical API reform.

 

32. Current Legal Position in Spain

As of September 2026, the legally careful position is:

PSD2/open banking already applies through the existing EU and Spanish payment-services framework.

GDPR already regulates personal-data processing.

DORA provides the EU's digital-operational-resilience framework for covered financial entities.

FIDA remains a legislative proposal and should not yet be treated as a fully applicable Spanish open-finance code.

The European Commission describes FIDA as the proposed mechanism for extending financial-data access beyond payment accounts, while the European Parliament's legislative record continues to identify the file as an ongoing ordinary legislative procedure.

Spanish institutions should therefore prepare for regulatory expansion without confusing anticipated obligations with existing binding law.

 

33. Conclusion

The EU's open-finance initiative represents a major potential expansion of banking and financial-data regulation in Spain.

The existing PSD2 framework established open banking, particularly access to payment-account information and payment-initiation services.

FIDA seeks to move the system toward open finance, extending customer-controlled data sharing across a significantly broader range of financial services.

The emerging framework is built around several central principles:

customer control;

regulated access;

interoperability;

secure technical interfaces;

data protection;

competition;

operational resilience;

and

effective consumer remedies.

For Spanish banks, the change is potentially substantial. A bank will increasingly need to think of itself not merely as the owner of a proprietary customer-information environment but as a regulated participant in a broader financial-data ecosystem.

At the same time, the jurisprudence discussed above demonstrates that technological innovation does not displace established legal safeguards. Banco Español de Crédito, Aziz, Gutiérrez Naranjo, Banco Santander C-598/15, Banco Santander C-268/19, MF v Banco Santander and Banco Santander/Banco Popular C-687/23 collectively illustrate principles concerning consumer protection, transparency, effective remedies and interaction between different parts of EU financial law.

There are not yet six genuine Spanish “FIDA cases,” because the FIDA legislation itself remains under development. These cases should therefore be described as supporting EU-Spanish banking authorities relevant to the legal environment into which open finance is expanding, rather than as judicial interpretations of FIDA itself.

The central legal development can ultimately be expressed as:

PSD2 opened the payment account; FIDA seeks to open the wider financial-data relationship.

For Spain, that transition could transform competition and financial innovation, but it also makes privacy, cybersecurity, interoperability, consumer control and regulatory accountability increasingly central components of banking law.

LEAVE A COMMENT