Banking Law And Digital Asset Custody Harmonisation Spain .

Banking Law and Digital Asset Custody Harmonisation in Spain

Introduction

Digital asset custody means holding, safeguarding, recording, and administering crypto-assets or the private keys that allow a person to control them. Banks, investment firms, crypto-asset service providers, and technology companies may provide custody services through wallets, institutional platforms, multi-signature systems, or offline storage.

In Spain, digital asset custody is increasingly influenced by European harmonisation. The main instrument is the European Union’s Markets in Crypto-Assets Regulation, commonly called MiCA. It creates common rules for crypto-asset service providers throughout the European Union, including providers offering custody and administration of crypto-assets on behalf of clients.

The purpose of harmonisation is to avoid different national systems, protect customers, reduce regulatory arbitrage, and create a single market. However, custody remains legally complex because crypto-assets are not always treated as traditional money, securities, or property. The legal result depends on the type of asset, the service provided, and whether the asset is classified as a financial instrument.

Legal and Regulatory Framework

MiCA provides the central European framework for crypto-asset custody. A provider offering custody and administration services generally needs authorisation as a crypto-asset service provider unless it falls within an applicable exemption. Authorised providers must act honestly, fairly, professionally, and in the best interests of clients.

Custody providers should maintain records showing which crypto-assets belong to each client. Client assets should be kept separate from the provider’s own assets. This separation is important if the custodian becomes insolvent. The customer should be able to demonstrate ownership or entitlement to the assets rather than being treated merely as an unsecured creditor.

Spanish implementation is supported by the Bank of Spain, the Comisión Nacional del Mercado de Valores, and other competent authorities depending on the service and the legal classification of the asset. The CNMV has an important role in supervising crypto-asset services covered by MiCA and in dealing with market conduct and investor-protection issues. Traditional banks remain subject to banking, prudential, outsourcing, cybersecurity, and operational-resilience requirements.

Spain also applies anti-money-laundering rules to relevant virtual-asset businesses. Customer identification, beneficial-owner verification, transaction monitoring, suspicious-activity reporting, and sanctions screening are essential. A custody provider must know who controls a wallet and must be able to respond to lawful information requests.

Not every digital asset is regulated by MiCA. Crypto-assets that qualify as financial instruments may remain subject to the Markets in Financial Instruments framework. Certain unique non-fungible tokens, decentralised activities, and lending or staking arrangements may fall partly outside the core MiCA rules, depending on their structure. This creates an important classification question before a bank begins offering custody.

Main Principles of Custody Harmonisation

Authorisation and Governance

A custody provider must have adequate management, internal controls, qualified staff, and financial resources. Its board should understand blockchain risks and should not treat custody as an ordinary deposit-taking activity.

Policies should cover wallet creation, key generation, access permissions, transaction approvals, incident response, disaster recovery, and the handling of lost or compromised keys. Multi-signature controls and segregation of duties can reduce the risk of internal fraud.

Protection and Segregation of Client Assets

Custodians should maintain accurate records of each customer’s holdings. Client crypto-assets should not be mixed with the provider’s proprietary holdings without lawful justification and clear disclosure.

The custody agreement should explain whether the provider controls the private keys directly, uses a sub-custodian, or provides only technical access. It should also state who bears the loss when assets are stolen because of hacking, employee misconduct, defective technology, or customer negligence.

Outsourcing and Operational Resilience

Many custodians rely on cloud providers, blockchain analytics companies, wallet technology firms, and overseas sub-custodians. Outsourcing does not remove the bank’s responsibility. The Spanish institution must conduct due diligence, monitor service providers, maintain audit rights, and prepare an exit plan.

Cybersecurity is central to custody. A successful attack may permanently transfer assets because blockchain transactions are often irreversible. Banks must maintain encryption, access controls, offline backups, penetration testing, and tested recovery plans.

Customer Information and Data Protection

Custody platforms process identity documents, wallet addresses, transaction histories, and behavioural information. The GDPR applies to personal data connected with identifiable customers. Banks must use data lawfully, limit collection, maintain security, and explain automated monitoring systems.

Customers should also receive clear information about volatility, loss of private keys, blockchain fees, transaction finality, and the limits of deposit insurance. Crypto-assets held in custody should not automatically be presented as equivalent to insured bank deposits.

Insolvency and Liability Issues

A major harmonisation challenge concerns insolvency. If a custodian fails, customers may claim that the digital assets belong to them and should be returned. The outcome depends on reliable records, segregation arrangements, contractual wording, and the legal character of the asset.

Liability may arise where the provider negligently loses private keys, executes an unauthorised transfer, fails to follow its security procedures, or gives misleading information. Contractual exclusions cannot necessarily protect a provider from fraud, gross negligence, or mandatory consumer-protection rules.

Case Laws

In Skatteverket v David Hedqvist, Case C-264/14, the Court of Justice of the European Union treated the exchange of Bitcoin as a transaction connected with currency exchange for VAT purposes. The judgment recognised that crypto-assets can have financial and payment-related characteristics even when they are not traditional money.

In Google Spain SL v AEPD, Case C-131/12, the Court confirmed strong protection of personal data and the responsibility of organisations processing information. The case is relevant to custody platforms holding customer identities and transaction records.

In Schrems II, Case C-311/18, the Court required effective safeguards for transfers of personal data outside the European Economic Area. This is important where Spanish custodians use foreign cloud providers or international technology vendors.

In SCHUFA Holding, Case C-634/21, the Court examined automated credit scoring and protections against decisions based mainly on automated processing. The principles may apply when banks use automated risk systems to approve custody accounts or restrict transactions.

In Dun & Bradstreet Austria GmbH v RW, Case C-203/22, the Court required meaningful information about automated decision-making. A customer whose digital-asset account is blocked by an automated compliance system should receive sufficient information to understand and challenge the decision, subject to lawful confidentiality restrictions.

In Kásler and Káslerné Rábai v OTP Jelzálogbank, Case C-26/13, the Court emphasised transparency in financial contracts. The principle is relevant to custody fees, conversion charges, network costs, and risk disclosures.

In Banco Español de Crédito v Calderón Camino, Case C-618/10, the Court strengthened judicial control over unfair consumer-contract terms. Spanish courts may apply similar reasoning to unclear custody clauses, excessive liability exclusions, or unfair termination terms.

Conclusion

Digital asset custody harmonisation in Spain is based mainly on MiCA, Spanish supervisory rules, anti-money-laundering obligations, data protection, prudential regulation, and general contract law. The framework seeks to create consistent standards across Europe while protecting clients from fraud, insolvency, cyberattacks, and misleading products.

Effective custody requires more than a digital wallet. It requires authorisation, asset segregation, accurate records, strong cybersecurity, responsible outsourcing, transparent contracts, and clear treatment of customer claims during insolvency. As Spanish banks enter the digital-asset market, harmonised European rules will be essential for building confidence while preserving financial stability.

LEAVE A COMMENT