Banking Law And Digital Identity Frameworks In Finance Spain .

Banking Law and Digital Identity Frameworks in Finance Spain

Introduction

Digital identity is the set of electronic credentials, data, and verification processes used to establish who a customer is when accessing financial services. In Spain, it supports remote account opening, mobile banking, electronic signatures, online payments, credit applications, anti-money-laundering checks, open banking, and access to government-linked financial services.

A reliable digital identity framework allows banks to verify a person without requiring a physical branch visit. However, it also creates risks: identity theft, deepfakes, synthetic identities, biometric-data misuse, unauthorised account access, discriminatory automated decisions, and excessive surveillance. Spanish financial institutions must therefore balance convenient digital access with authentication security, consumer protection, confidentiality, and data-protection rights.

Legal and Regulatory Framework

Spain’s framework is strongly shaped by the EU eIDAS Regulation, which governs electronic identification, electronic signatures, electronic seals, electronic timestamps, registered electronic delivery services, and website-authentication certificates. eIDAS gives legal recognition to qualified electronic signatures and trust services across the European Union.

The revised European Digital Identity Framework, established by Regulation (EU) 2024/1183, expands eIDAS by creating the European Digital Identity Wallet. The wallet is intended to allow individuals and businesses to store and share verified identity attributes, such as name, age, address, professional qualifications, and authorised representations. In financial services, it may simplify customer onboarding and reduce repeated collection of the same identification documents.

Spain also applies Law 6/2020, which regulates certain aspects of electronic trust services within the national legal system. Financial institutions using electronic signatures or trust-service providers should ensure that the chosen signature level is appropriate to the transaction’s risk and legal consequences.

For customer due diligence, the Anti-Money Laundering Law 10/2010 requires banks and other obliged entities to identify customers, verify identity, understand ownership and control structures, assess risk, and monitor relationships on an ongoing basis. Digital onboarding may be used, but the bank remains responsible for ensuring that identification is reliable and that impersonation risks are controlled.

The payment-services framework, derived from PSD2 and implemented in Spain through Royal Decree-Law 19/2018, requires strong customer authentication for access to payment accounts and most electronic payments. Authentication must normally combine two independent factors: knowledge, possession, and inherence. Biometrics may be used as an inherence factor, but banks must provide secure alternatives where biometric use is unsuitable or unavailable.

The General Data Protection Regulation (GDPR) and Spain’s Organic Law 3/2018 apply to all personal data used in digital identity. Biometric data processed for unique identification is a special category of personal data, requiring a clear legal basis, high security, data minimisation, and careful retention controls.

Digital Onboarding and Identity Verification

A Spanish bank may onboard customers through video identification, electronic identity documents, qualified electronic signatures, bank-account verification, biometric liveness detection, or trusted third-party identity services. However, convenience does not replace verification.

A compliant process should confirm that the document is genuine, the person presenting it is alive and present, the identity data matches reliable sources, and the account is not being opened by a proxy or fraudster. The bank should also screen against sanctions lists, politically exposed persons, and adverse-risk indicators where required by AML rules.

Digital identity should not be treated as a one-time event. Banks must monitor for account takeover, changed devices, abnormal geolocation, altered contact details, suspicious payment patterns, and inconsistent customer behaviour. Re-authentication may be needed before high-risk actions such as adding a new beneficiary, changing a mobile number, recovering account credentials, or making a large transfer.

European Digital Identity Wallet and Banking

The European Digital Identity Wallet could improve banking by allowing customers to share a verified identity attribute instead of submitting multiple copies of passports, utility bills, or corporate documents. It could also make age verification, address confirmation, and proof of representation more efficient.

However, banks should not assume that possession of a wallet alone completes customer due diligence. AML law requires a risk-based assessment. A wallet may verify a core identity attribute, but a bank may still need information about beneficial ownership, source of funds, intended account use, transaction expectations, and sanctions exposure.

Financial institutions must also avoid forcing customers to disclose more data than necessary. For example, a bank that needs proof that a customer is over eighteen should normally request only that verified attribute, rather than the customer’s complete identity record.

Data Protection and Automated Decisions

Digital identity systems may use facial recognition, voice recognition, device profiling, behavioural analytics, and automated fraud scoring. These tools can improve security but may affect privacy and equality.

Banks must inform customers about processing, use appropriate security safeguards, restrict internal access, and retain data only for legitimate periods. Where an automated identity or fraud decision significantly affects a customer, such as refusing an account, blocking access, or rejecting a credit request, the customer should have meaningful information and, where applicable, the ability to seek human intervention.

Special caution is required for biometric templates. A bank should avoid retaining raw facial images or voice recordings longer than necessary. Templates should be encrypted, segregated from ordinary customer data, and protected against reuse for unrelated purposes.

Case Laws

  1. Breyer v Bundesrepublik Deutschland, Case C-582/14, CJEU. The Court held that dynamic IP addresses may be personal data where identification is reasonably possible. Banking systems must protect IP-address and device data used for fraud prevention.
  2. Planet49 GmbH, Case C-673/17, CJEU. The Court confirmed that consent must be active, informed, and specific. Pre-ticked consent for identity profiling or biometric use is not sufficient.
  3. Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW, Case C-40/17, CJEU. The Court addressed joint responsibility for data collection and transfer. Banks using identity-verification vendors must define each party’s data-protection responsibilities.
  4. Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, Case C-311/18, CJEU. The Court strengthened protection for personal data transferred outside the European Economic Area. This is relevant where identity documents or biometric data are processed through foreign cloud services.
  5. Ligue des droits humains ASBL v Conseil des ministres, Case C-817/19, CJEU. The Court stressed that large-scale personal-data processing must be necessary and proportionate. Banks should not collect or retain identity data merely because it may be useful in the future.
  6. SCHUFA Holding AG, Case C-634/21, CJEU. The Court examined automated decision-making using personal data. It is important where identity, fraud, or credit-risk algorithms determine whether a customer can access financial services.
  7. RW v Österreichische Post AG, Case C-154/21, CJEU. The Court confirmed that individuals may seek meaningful information about recipients of their personal data. Banks should maintain clear records of identity-data sharing with processors and third parties.

Conclusion

Digital identity frameworks are becoming central to banking in Spain. eIDAS, the European Digital Identity Wallet, AML rules, payment-authentication duties, and GDPR together require banks to provide secure and accessible digital onboarding without weakening privacy or customer protection.

The strongest systems use verified credentials, risk-based checks, secure authentication, limited data sharing, biometric safeguards, and human oversight of high-impact automated decisions.

 

LEAVE A COMMENT