Banking Law And Data-Sharing Consent Frameworks Spain .
Banking Law And Data-Sharing Consent Frameworks Spain
Introduction
Data sharing is central to modern banking in Spain. Banks share customer data with payment providers, credit-reference agencies, group companies, outsourced technology providers, insurers, regulators, tax authorities and anti-money-laundering bodies. Open banking, mobile payments and AI-based financial services have increased these flows. However, a customer’s information cannot be shared simply because it may be commercially useful.
Spain applies the EU General Data Protection Regulation (GDPR), supplemented by Organic Law 3/2018 on Personal Data Protection and Digital Rights (LOPDGDD). For banks, consent is important but is not the only lawful basis for data sharing. Depending on the purpose, processing may instead be necessary to perform a banking contract, comply with a legal duty, protect vital interests, perform a public task, or pursue a legitimate interest. The key legal question is whether the bank has identified the correct lawful basis and given the customer clear, truthful information.
Legal and Regulatory Framework
Under Articles 4, 6 and 7 GDPR, valid consent must be freely given, specific, informed and unambiguous. It must result from a clear affirmative action. Silence, pre-ticked boxes, inactivity or confusing bundled clauses do not amount to valid consent. Where a bank relies on consent, it must be able to prove that consent was obtained and must make withdrawal as easy as giving consent.
Article 9 GDPR creates stricter rules for special-category data, including health, biometric, political and religious data. A bank should normally avoid collecting such information unless it is clearly necessary and an Article 9 condition applies.
In Spain, the LOPDGDD supports GDPR enforcement and gives the Spanish Data Protection Agency (AEPD) power to investigate, order corrective measures and impose administrative fines. Banks must also comply with confidentiality obligations under Spanish banking regulation and contractual duties owed to customers.
The revised Payment Services Directive (PSD2), implemented in Spain through Royal Decree-Law 19/2018, created open-banking rules. Account-information service providers and payment-initiation service providers may access payment-account data only when the payment-service user has given explicit consent. This PSD2 requirement does not automatically make consent the GDPR legal basis in every situation; the provider must still comply independently with GDPR principles.
Consent in Banking Data Sharing
A Spanish bank may use consent for optional activities, such as sharing data with affiliated companies for personalised insurance offers, permitting a third-party app to access account information, or using transaction patterns for voluntary marketing analytics. Consent should be separated by purpose. A customer should be able to agree to open-banking access without being forced to accept marketing, profiling or sharing with unrelated group entities.
Consent is often inappropriate where there is a serious imbalance of power or where a service is made conditional on unnecessary data sharing. For example, a mortgage applicant should not be required to accept broad marketing disclosures as a condition for receiving a credit decision. In that situation, consent is unlikely to be freely given.
Banks do not need consent for every disclosure. Customer data may be shared with the Bank of Spain, tax authorities, courts or the Financial Intelligence Unit where legislation requires it. Spain’s anti-money-laundering regime, especially Law 10/2010, requires customer due diligence, record retention and suspicious-transaction reporting. A bank must not seek “consent” for a mandatory report because the correct basis is legal obligation, and alerting the customer may amount to unlawful tipping-off.
Rights and Remedies
Customers have rights of access, rectification, erasure, restriction, objection and data portability. They also have the right to receive meaningful information about automated decisions where Article 22 GDPR applies. This matters in automated credit scoring, fraud detection and customer-risk classification.
A bank must provide a clear privacy notice explaining the identity of the controller, purposes of sharing, data categories, recipients or recipient categories, retention periods, legal basis, withdrawal procedure, international transfers and complaint rights. Generic wording such as “we may share your information with partners” is usually insufficient.
Customers can complain to the bank’s data-protection officer, its customer-service department or the AEPD. The AEPD may require deletion, restrict processing, order changes to consent mechanisms and impose significant fines. Customers may also seek compensation where unlawful processing causes material or non-material damage.
Case Laws
In Planet49 GmbH (C-673/17), the Court of Justice of the European Union (CJEU) held that pre-ticked consent boxes are invalid. Spanish banks must therefore use active opt-in choices for non-essential data sharing.
In Orange Romania (C-61/19), the CJEU found that consent was not valid where customers were not properly informed and could feel pressured to sign documents. This is relevant when banks use long account-opening forms or bundled digital onboarding screens.
In Meta Platforms (C-252/21), the CJEU confirmed that contractual necessity must be interpreted narrowly. A bank cannot claim that extensive profiling or cross-service data sharing is “necessary” merely because it improves business efficiency or advertising.
In Österreichische Post (C-154/21), the CJEU stated that a data subject may request the actual identity of recipients of personal data, not merely broad categories, unless recipients cannot yet be identified. Banks must keep accurate recipient records.
In SCHUFA Holding (C-634/21), the CJEU considered automated credit-scoring decisions and Article 22 GDPR. Where a score plays a decisive role in granting credit, the customer must receive safeguards against solely automated decision-making.
In Schrems II (C-311/18), the CJEU required strong safeguards for transfers of personal data outside the European Economic Area. Spanish banks using non-EEA cloud providers must assess foreign-access risks and apply supplementary protections where necessary.
In UI v Österreichische Post (C-300/21), the CJEU held that a GDPR breach alone does not automatically create compensation, but actual material or non-material damage can be compensated. This gives customers a remedy where unlawful banking data sharing causes distress, reputational harm or financial loss.
Conclusion
Spanish banking data-sharing frameworks require purpose limitation, transparency, data minimisation, security and a valid lawful basis. Consent must be genuine, separate, informed and easy to withdraw. It cannot be used to disguise mandatory regulatory disclosures or to force customers into unnecessary commercial sharing. As open banking and automated lending expand, Spanish banks must build consent systems that are understandable, auditable and respectful of customer control.

comments