Banking Law And Database Rights In Banking Spain .
Banking Law And Database Rights In Banking Spain
Introduction
Spanish banks create and use valuable databases every day. These may contain customer information, payment records, credit histories, fraud indicators, transaction patterns, risk models, pricing data, market information, and regulatory-reporting data. Such databases are commercially important, but their legal protection is complex.
A bank cannot claim “ownership” of all information in a database merely because it collected or stored it. Different legal rules apply to different elements. The database structure may receive copyright protection if it is original. The investment in collecting, verifying, or presenting data may receive a separate sui generis database right. Individual customer information is protected by data-protection law and banking confidentiality. Software used to manage the database may be protected by copyright or trade-secret law.
In Spain, database rights are governed mainly by the Spanish Intellectual Property Law, which implements the EU Database Directive. Banks must use these rights carefully because intellectual-property protection cannot override GDPR, customer rights, competition law, regulatory disclosure duties, or anti-money-laundering obligations.
Legal And Regulatory Framework
1. Copyright Protection For Original Databases
A database may receive copyright protection where the selection or arrangement of its contents is the author’s own intellectual creation. For example, a bank’s specially designed research database, risk-information platform, or organised financial-data catalogue may qualify if its structure involves original creative choices.
Copyright protects the structure, selection, or arrangement of data. It does not protect the underlying facts themselves. Account balances, interest rates, public market prices, and transaction facts are not protected by copyright simply because they appear in a bank’s database.
This distinction is important. A competitor may use independently obtained factual information, but it cannot copy a protected database structure or reproduce protected original content without permission.
2. Sui Generis Database Right
Spanish law also protects databases through the sui generis database right. This right protects substantial investment in obtaining, verifying, or presenting database contents. It is particularly relevant where a database is commercially valuable but not sufficiently original to receive copyright protection.
The maker of a qualifying database may prevent extraction or re-utilisation of all, or a substantial part, of its contents. The right lasts for 15 years from completion or publication of the database. A substantial new investment that materially changes the database may start a new protection period.
For a bank, this may apply to costly databases of credit-risk information, transaction reference data, market intelligence, or fraud patterns. However, the investment must be in obtaining, checking, or presenting existing data. Investment in creating the data itself may not be enough.
3. Banking Confidentiality And GDPR
Database rights do not give banks unrestricted freedom to exploit customer information. Personal data in banking databases is governed by the GDPR and Spanish Organic Law 3/2018. A bank must have a lawful basis to collect and use personal data and must respect principles of purpose limitation, data minimisation, security, transparency, and accountability.
Banking confidentiality also restricts disclosure of customer information. Therefore, even if a bank owns the database structure or has a sui generis right in its investment, it cannot sell, licence, or share customer data without a lawful basis.
A bank’s database right protects its investment; it does not cancel the customer’s privacy rights.
4. Regulatory And Public-Interest Access
Banks must provide certain information to the Banco de España, the European Central Bank, tax authorities, courts, and anti-money-laundering authorities. They cannot use database rights to block legally required disclosure.
Similarly, contractual arrangements with cloud providers or data-analytics firms must preserve regulatory access, audit rights, confidentiality, and data-security controls. A bank remains responsible for the lawful handling of financial data even when its database is hosted or processed by an external provider.
Key Issues And Principles
1. Data Creation Versus Data Collection
A central legal issue is whether a bank invested in creating data or in obtaining and verifying existing data. If a bank creates loan-risk scores through its own lending activity, the cost of generating those scores may not automatically qualify for sui generis database protection.
By contrast, substantial resources spent gathering, cleaning, verifying, and systematically presenting data from many sources may support a database right.
2. Extraction And Re-Utilisation
Extraction means transferring database content to another medium. Re-utilisation means making that content available to the public, such as by sharing it through an application, report, data platform, or commercial service.
A competitor, former employee, contractor, or technology vendor may infringe a bank’s database right if it extracts a substantial part of a protected database. Repeated extraction of small parts may also infringe where it amounts to systematic copying that harms the normal exploitation of the database.
3. Contracts, Trade Secrets And Cybersecurity
Database rights are not the only protection available. Banks should use confidentiality agreements, employee obligations, access controls, encryption, logging, and trade-secret measures. These protections are particularly important for non-public risk models, customer segmentation, fraud rules, and proprietary datasets.
A contractual user may also be restricted from extracting even non-substantial parts of a database, subject to applicable law and fairness requirements.
Case Laws
1. British Horseracing Board Ltd v William Hill Organization Ltd, Case C-203/02 (CJEU, 2004)
The Court held that the database right protects investment in obtaining, verifying, or presenting existing contents, not investment in creating the data itself.
Relevance: A Spanish bank must distinguish investment in generating internal banking data from investment in collecting and verifying database contents.
2. Fixtures Marketing Ltd v Oy Veikkaus Ab, Case C-46/02 (CJEU, 2004)
The Court confirmed that the database right does not protect the effort spent creating the underlying data.
Relevance: A bank cannot assume that every internally produced data point creates a separate database right.
3. Directmedia Publishing GmbH v Albert-Ludwigs-Universität Freiburg, Case C-304/07 (CJEU, 2008)
The Court explained that extraction can occur where content is transferred to another medium, even after consultation of the original database.
Relevance: Copying banking data into a separate analytics tool or competitor platform may amount to extraction.
4. Apis-Hristovich EOOD v Lakorda AD, Case C-545/07 (CJEU, 2009)
The Court considered repeated extraction and re-utilisation of database content.
Relevance: Repeated small-scale copying of bank database material may be unlawful if it systematically reproduces valuable content.
5. Ryanair Ltd v PR Aviation BV, Case C-30/14 (CJEU, 2015)
The Court held that contractual terms may restrict use of a database that does not qualify for Directive-based protection.
Relevance: Spanish banks can use clear contractual terms to limit scraping, copying, and unauthorised commercial use of their platforms.
6. CV-Online Latvia SIA v Melons SIA, Case C-762/19 (CJEU, 2021)
The Court held that infringement analysis must consider whether extraction or re-utilisation risks harming the database maker’s investment.
Relevance: A bank claiming database-right infringement should show how unauthorised use damages the value or recovery of its investment.
Conclusion
Database rights give Spanish banks important protection for valuable collections of financial information, but the protection is not absolute. Copyright protects original database structure, while the sui generis right protects substantial investment in obtaining, verifying, and presenting contents.
Banks must combine intellectual-property protection with GDPR compliance, banking secrecy, strong contracts, cybersecurity controls, and regulatory cooperation. The safest approach is to identify which data is personal, confidential, proprietary, public, or regulated, and then apply the correct legal protection to each category.

comments