Banking Law And Technological Innovation Spain .
Banking Law and Technological Innovation — Spain
Jurisdiction: Spain | Banking Law | FinTech | Digital Banking | Detailed Explanation with Case Laws
Banking law and technological innovation in Spain concerns the legal framework governing the use of new technologies by banks, fintech firms, payment institutions and other financial-service providers. It covers developments such as digital banking, artificial intelligence (AI), open banking, instant payments, cloud computing, blockchain, crypto-assets, digital identity, automated credit scoring, APIs and cybersecurity.
Spain does not regulate banking innovation through one single “Technological Innovation in Banking Act.” Instead, technological innovation is governed through interconnected Spanish and European Union banking, payments, data-protection, operational-resilience, AI, crypto-asset and consumer-protection rules.
Spain is particularly important because it combines domestic fintech initiatives—including a statutory regulatory sandbox—with the increasingly harmonised EU digital-finance framework.
1. Basic Spanish banking-law framework
The starting point remains Law 10/2014 on the organisation, supervision and solvency of credit institutions (Ley 10/2014).
It regulates fundamental matters including authorisation, governance, supervision and prudential requirements for Spanish credit institutions.
Banks also operate within the EU framework, particularly:
- the Capital Requirements Regulation and CRD framework;
- the Single Supervisory Mechanism;
- payment-services legislation;
- the Digital Operational Resilience Act;
- the Markets in Crypto-Assets Regulation;
- GDPR;
- the EU AI Act; and
- EU consumer-protection legislation.
Consequently:
Technology changes how banking services are delivered, but it does not remove the underlying banking-law obligations.
A bank does not cease being regulated because the transaction takes place through an app rather than a branch.
2. Spain's regulatory sandbox
One of Spain's most important innovation measures is Law 7/2020 for the digital transformation of the financial system.
It established a controlled testing environment commonly known as the Spanish financial sandbox.
The sandbox allows innovative financial projects to be tested under regulatory supervision.
A hypothetical project might involve:
Fintech company → AI lending technology → sandbox testing → regulatory assessment → commercial deployment.
The sandbox does not mean that ordinary financial regulation disappears. Instead, it provides a supervised environment for examining innovative technology before wider market deployment.
This can help regulators understand emerging risks while allowing firms to test genuinely innovative services.
3. Banco de España and technological innovation
The Banco de España plays an important role in banking supervision and financial innovation, while significant Spanish banks may be directly supervised by the European Central Bank under the SSM.
Depending on the activity, the CNMV may also have jurisdiction, particularly for securities and investment-related innovation.
A technology business therefore needs to identify the correct regulatory perimeter.
For example:
| Technology | Potential regulatory relevance |
|---|---|
| Digital bank | Banking authorisation |
| Payment app | Payment-services regulation |
| Robo-adviser | Investment-services regulation |
| Crypto platform | MiCA/other applicable rules |
| AI credit scoring | Banking + AI + data rules |
| Digital securities | Capital-markets rules |
A company cannot normally avoid financial regulation merely by describing itself as a “technology platform.”
4. Digital banking
Spanish banks increasingly provide services through mobile applications and online platforms.
A digital bank can allow customers to:
Open account → identify themselves electronically → deposit funds → obtain credit → make payments → invest.
Each stage raises legal questions.
Electronic onboarding must comply with applicable identification and AML requirements. Payments must satisfy payment-services requirements. Consumer lending must comply with relevant credit rules. Customer information must satisfy GDPR requirements.
The legal principle is therefore:
Digital delivery ≠ regulatory exemption.
5. Open banking
Open banking represents one of the most important technological transformations of European banking.
Under the PSD2 framework, regulated third-party providers can, subject to applicable requirements and customer authorisation, access certain account information or initiate payments.
Traditional model:
Customer → Bank
Open-banking model:
Customer → Fintech/API → Bank.
This creates competition and innovation but also produces security and liability issues.
Banks must determine whether access requests are legitimate and implement appropriate authentication and API security.
6. Payment innovation
Spain's payment sector increasingly involves instant payments, mobile wallets and API-based transactions.
Payment regulation determines matters such as:
- authorisation;
- authentication;
- execution;
- unauthorised transactions;
- refund rights;
- security; and
- allocation of liability.
Technology can execute a payment in seconds, but the legal system must still determine who bears the loss if the transaction is fraudulent.
This makes payments law one of the most important areas where banking law and technology interact.
7. Artificial intelligence
Banks increasingly use AI for:
- credit scoring;
- fraud detection;
- AML monitoring;
- customer support;
- investment analysis;
- cybersecurity;
- risk modelling; and
- marketing.
AI can improve efficiency, but banks remain responsible for regulated decisions.
Suppose:
AI system → rejects mortgage application.
The bank cannot automatically answer:
“The computer made the decision.”
The institution must comply with applicable banking, consumer, data-protection and AI requirements.
8. EU Artificial Intelligence Act
The EU AI Act—Regulation (EU) 2024/1689—is particularly important for future banking technology.
Certain AI systems used to evaluate the creditworthiness of natural persons or establish their credit score can fall within the Act's high-risk framework, subject to the Regulation's precise scope and exceptions.
High-risk systems face significant requirements concerning matters such as:
- risk management;
- data governance;
- technical documentation;
- recordkeeping;
- transparency;
- human oversight;
- accuracy;
- robustness; and
- cybersecurity.
Spanish banks therefore increasingly need both model-risk governance and AI-law governance.
9. Automated decision-making and GDPR
The General Data Protection Regulation (GDPR) is crucial to technological banking.
Article 22 provides safeguards concerning certain decisions based solely on automated processing that produce legal or similarly significant effects.
Credit decisions can therefore create important GDPR issues.
Banks must also comply with broader principles including:
lawfulness + transparency + purpose limitation + data minimisation + accuracy + security.
An AI model cannot be justified merely because it produces accurate predictions. The underlying processing must itself have a lawful basis and satisfy applicable safeguards.
10. Cloud computing
Spanish banks increasingly use external cloud infrastructure.
The model may look like:
Spanish bank → cloud provider → data centres/software infrastructure.
Cloud technology offers scalability and lower infrastructure costs but creates:
- outsourcing risk;
- concentration risk;
- cybersecurity risk;
- business-continuity risk;
- data risk; and
- exit risk.
A bank remains responsible for regulated operations even when technological infrastructure is outsourced.
11. Digital Operational Resilience Act
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has become a central part of technological banking regulation.
It applies from 17 January 2025.
DORA establishes harmonised requirements concerning ICT risk across much of the EU financial sector.
Important areas include:
- ICT risk management;
- incident reporting;
- digital operational-resilience testing;
- ICT third-party risk;
- contractual arrangements; and
- oversight of critical ICT third-party providers.
For Spanish banks, cybersecurity is therefore no longer simply an internal technical matter.
It is a regulatory-governance obligation.
12. Cybersecurity
Suppose a Spanish bank suffers ransomware affecting online banking for 24 hours.
The consequences can include:
ICT incident
→ payment interruption
→ customer losses
→ regulatory reporting
→ operational losses
→ reputational damage
→ potential data-protection consequences.
Bank boards therefore need adequate oversight of cybersecurity and operational resilience.
Cyber risk has effectively become prudential risk.
13. Blockchain and distributed-ledger technology
Blockchain can potentially be used for:
- securities settlement;
- tokenisation;
- payments;
- collateral records;
- trade finance;
- digital identity; and
- smart contracts.
However:
Blockchain does not remove banking law.
A token representing a regulated financial instrument can remain subject to financial regulation.
The legal analysis depends on the economic and legal characteristics of the instrument rather than simply the technological architecture used to issue it.
14. Crypto-assets
The EU Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114, substantially harmonises crypto-asset regulation.
MiCA establishes rules for specified crypto-assets and crypto-asset service providers.
Depending upon the activity, requirements can concern:
- authorisation;
- governance;
- disclosures;
- custody;
- customer protection;
- conflicts of interest; and
- prudential safeguards.
However, not every blockchain-based instrument falls within MiCA. Instruments qualifying as financial instruments may instead fall within existing securities legislation.
Correct legal classification is therefore essential.
15. Digital euro
The potential digital euro is another important area of technological innovation.
A central-bank digital currency differs fundamentally from privately issued crypto-assets.
Conceptually:
Commercial bank deposit = liability of commercial bank.
Digital euro = potential direct central-bank money in digital form.
Its final legal architecture depends on the EU legislative framework ultimately adopted.
For Spanish banks, a digital euro could influence payment services, deposit behaviour, liquidity management and technological infrastructure.
16. Digital identity and remote onboarding
Digital banking requires reliable identification.
Remote onboarding can involve:
- electronic identification;
- biometric systems;
- document verification;
- electronic signatures;
- video identification; and
- fraud-detection technologies.
Spanish institutions must reconcile convenience with AML/CFT and privacy obligations.
Weak onboarding technology can facilitate identity theft and financial crime.
Overly intrusive identification technology, however, can create data-protection problems.
17. AML technology
Banks increasingly use technology to monitor suspicious transactions.
A modern AML platform might process:
transaction history + customer profile + counterparties + geographical risk + behavioural anomalies.
AI can reduce manual monitoring, but excessive false positives can overwhelm compliance teams, while false negatives can allow financial crime to go undetected.
Banks therefore require appropriate validation, governance and human oversight.
18. Consumer protection
Technology can increase financial inclusion and reduce transaction costs, but it can also create new consumer risks.
Examples include:
- confusing app interfaces;
- misleading digital advertising;
- hidden fees;
- automated selling;
- unauthorised payments;
- impersonation scams; and
- unsuitable algorithmic recommendations.
Traditional consumer-protection principles continue to apply even where contracts are concluded entirely online.
19. Big Tech and banking
Large technology platforms can increasingly provide services traditionally associated with banks.
Consider:
Platform → wallet → payments → consumer credit → investment products.
This creates regulatory-perimeter questions.
If economically equivalent activities face completely different regulation merely because one provider calls itself a technology company, regulatory arbitrage can emerge.
The principle of “same activity, same risk, appropriate regulation” therefore becomes increasingly important.
Important Case Laws
1. Google Spain SL and Google Inc. v AEPD and Mario Costeja González
CJEU, Case C-131/12
This landmark Spanish reference concerned personal-data processing by a technology intermediary.
The Court recognised significant responsibilities associated with digital processing of personal information.
Banking significance
Modern banking depends heavily on searchable, analysable customer data.
The case demonstrates that technological control over information can generate independent legal responsibilities.
For banks, data architecture must therefore be designed around GDPR obligations rather than treating privacy as an afterthought.
2. SCHUFA Holding (Scoring)
CJEU, Case C-634/21
This case is especially important for automated credit scoring.
The Court considered whether automated creation of a probability value concerning a person's future ability to meet payment commitments could constitute automated individual decision-making where a third party gives that score a determining role.
Spanish banking significance
The judgment has major implications for:
AI credit scoring → automated lending → GDPR Article 22.
A Spanish bank cannot automatically avoid automated-decision obligations merely by outsourcing scoring to another company.
3. Orange România SA v ANSPDCP
CJEU, Case C-61/19
The CJEU examined requirements for valid consent under EU data-protection law.
Banking relevance
Digital banks frequently collect customer consent through apps.
Consent cannot simply be assumed from confusing interfaces or pre-designed documentation.
The case reinforces the need for genuine and demonstrable consent where consent is relied upon as the legal basis.
4. Bundeskartellamt v Meta Platforms and Others
CJEU, Case C-252/21
The Court considered the interaction between competition enforcement and GDPR in relation to extensive processing of user information by a major digital platform.
Banking relevance
The case is highly relevant to emerging Big Tech-finance ecosystems.
A company combining payment, shopping, social and financial information may face both privacy and competition concerns.
Data can therefore become simultaneously:
commercial asset + privacy risk + competition-law issue.
5. La Quadrature du Net and Others
CJEU, Joined Cases C-511/18, C-512/18 and C-520/18
These proceedings addressed large-scale retention and processing of electronic communications data.
Financial-technology relevance
Although not a banking case, the decisions demonstrate the importance of necessity and proportionality when large quantities of digital information are retained or accessed.
Banks implementing large-scale monitoring technologies should therefore distinguish legitimate compliance requirements from excessive data collection.
6. Digital Rights Ireland Ltd
CJEU, Joined Cases C-293/12 and C-594/12
The CJEU invalidated the Data Retention Directive because of disproportionate interference with fundamental rights.
Banking relevance
Financial institutions increasingly retain enormous datasets for fraud detection, AML, analytics and cybersecurity.
The broader lesson is that technological capability does not automatically justify unlimited collection and retention.
7. Banco Español de Crédito SA v Joaquín Calderón Camino
CJEU, Case C-618/10
This Spanish banking case concerned unfair terms in consumer credit.
Technology relevance
Digital lending does not weaken consumer protection.
If a fintech system automatically generates thousands of standard credit agreements containing unfair terms, automation simply reproduces the legal problem at much greater scale.
8. Aziz v Caixa d'Estalvis de Catalunya, Tarragona i Manresa
CJEU, Case C-415/11
The Court addressed unfair contractual terms and effective consumer protection in Spanish mortgage enforcement.
Digital-banking relevance
Moving mortgage origination to an online platform does not remove the substantive protections established by EU consumer law.
Technology changes the interface, not the underlying rights.
Practical example: AI lending platform
Suppose Banco Digital España launches an AI system capable of approving personal loans in 20 seconds.
The process is:
Customer application
↓
Identity verification
↓
Credit database
↓
AI scoring
↓
Fraud detection
↓
Automatic loan decision
↓
Electronic contract
This apparently simple digital process can involve several legal frameworks simultaneously.
| Stage | Principal legal concern |
|---|---|
| Customer onboarding | Identity + AML |
| Data collection | GDPR |
| AI scoring | AI Act + GDPR |
| Credit decision | Banking/consumer law |
| Payment | Payment regulation |
| Cloud processing | DORA |
| Cybersecurity | DORA/GDPR |
| Contract | Consumer protection |
| Outsourced AI | Third-party risk |
| Customer complaint | Transparency and redress |
The bank cannot delegate legal responsibility simply because an external technology company designed the algorithm.
Major technological risks for Spanish banks
| Technology | Principal regulatory risk |
|---|---|
| Artificial intelligence | Bias, opacity, model failure |
| Cloud computing | Concentration and outage |
| APIs | Cybersecurity and access control |
| Open banking | Authentication and liability |
| Blockchain | Legal classification |
| Crypto-assets | Investor/consumer risk |
| Digital identity | Identity theft/privacy |
| Biometrics | Sensitive-data processing |
| Automated lending | Consumer and AI compliance |
| Big Data | GDPR concerns |
| Third-party fintech | Outsourcing risk |
| Instant payments | Fraud and operational risk |
Regulatory structure
A useful way to understand Spanish technological banking regulation is:
Banco de España / ECB
→ prudential banking supervision
CNMV
→ securities and investment-market supervision
Spanish Data Protection Agency (AEPD)
→ GDPR/data protection
EU digital-finance legislation
→ DORA + MiCA + AI Act + payments framework
Spanish courts + CJEU
→ interpretation and enforcement.
Technological innovation therefore creates multi-regulator compliance, rather than replacing traditional banking supervision.
Conclusion
Banking law and technological innovation in Spain are increasingly inseparable. Digitalisation has transformed banking from a branch-based business into an ecosystem involving apps, APIs, AI, cloud infrastructure, instant payments, digital identity, blockchain and crypto-assets.
Spain's Law 7/2020 regulatory sandbox provides an important domestic mechanism for controlled financial innovation, while the broader legal architecture increasingly comes from harmonised EU legislation—especially DORA, MiCA, GDPR and the AI Act, alongside traditional prudential and consumer-protection rules.
The case law reinforces this approach. Google Spain demonstrates the responsibilities associated with digital data; SCHUFA is particularly important for automated credit scoring; Orange România addresses meaningful consent; Meta Platforms illustrates the intersection of data and competition law; while Banco Español de Crédito and Aziz confirm that technological delivery does not displace established consumer protections.
The central regulatory principle is therefore:
Innovation may change the technology, but it does not eliminate the regulated activity.
For Spanish banks, responsible technological innovation consequently requires prudential supervision + cybersecurity and operational resilience + AI governance + data protection + consumer protection + regulatory classification + effective board oversight.

comments