Banking Law And Digital Identity Frameworks Spain .
Introduction
Digital identity is central to modern banking in Spain. Banks use electronic identification for account opening, customer authentication, credit applications, payment services, anti-money-laundering checks and remote contractual transactions. Spanish law does not regulate digital identity through one single statute. Instead, it operates through a combined framework of European Union law, Spanish banking legislation, data-protection rules, electronic-signature legislation and cybersecurity requirements.
The legal challenge is to balance three objectives: reliable identification of customers, prevention of fraud and money laundering, and protection of privacy and financial autonomy.
Legal and Regulatory Framework
The primary European instrument is Regulation (EU) No. 910/2014, commonly known as the eIDAS Regulation. It establishes rules for electronic identification schemes, electronic signatures, electronic seals, time stamps and trust services. A qualified electronic signature has legal effect equivalent to a handwritten signature and may be used to authenticate banking contracts and instructions. Electronic identification schemes notified by EU Member States may also be recognised across borders. The future European Digital Identity Wallet will further strengthen interoperable identity credentials within banking and other regulated services. EUR-Lex, eIDAS Regulation
In Spain, Law 6/2020 on electronic trust services complements eIDAS. It regulates trust-service providers, electronic certificates, signature validation and evidentiary consequences. Banks may rely on electronic certificates and strong authentication, but they must still maintain systems capable of proving who authenticated a transaction, when authentication occurred and whether the record was altered.
The General Data Protection Regulation and Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights govern the processing of identity data. A bank must have a lawful basis for collecting identity documents, biometric information, device data, geolocation or behavioural information. Data must be adequate, relevant and limited to what is necessary. Excessive retention, undisclosed profiling or indefinite storage of identity records may violate the principles of necessity and proportionality. Spanish Data Protection Authority, AEPD
The Prevention of Money Laundering and Terrorist Financing Law 10/2010 imposes customer-due-diligence duties on banks. Institutions must identify customers, verify beneficial ownership, understand the purpose of the business relationship and monitor transactions. Remote onboarding is permitted only where the method provides sufficient reliability. Digital identity tools therefore support compliance, but they do not remove the bank’s independent responsibility to detect impersonation, forged documents or unusual activity.
Payment authentication is also governed by the Payment Services Directive framework, implemented in Spain through Royal Decree-Law 19/2018. Banks and payment-service providers must normally use strong customer authentication based on two or more independent factors, such as knowledge, possession and inherence. Authentication must be linked to the specific amount and payee where required. Failure to apply effective authentication can create liability for unauthorised payment transactions.
The Digital Operational Resilience Act is increasingly relevant to Spanish banks. It requires financial entities to manage information-technology risk, identity-access controls, incident reporting, testing and third-party ICT dependency. Identity-management systems must therefore be resilient against credential theft, phishing, SIM swapping, insider misuse and cloud-service failures.
Key Legal Principles
First, identification and authentication are different legal concepts. Identification determines who the customer claims to be; authentication verifies that the person controls the relevant credential or device. A bank that merely receives an uploaded identity document may not have adequately authenticated the customer.
Second, biometric identification requires heightened safeguards. Facial recognition or voice recognition may involve special-category biometric data under the GDPR when used to uniquely identify a person. Banks must demonstrate necessity, security and a lawful basis. Less intrusive alternatives should be considered.
Third, digital identity systems must preserve human access and financial inclusion. Customers who cannot use smartphones, biometric tools or online platforms should ordinarily have an alternative method of accessing essential banking services. A purely digital system can create discrimination against elderly persons, persons with disabilities, migrants and people lacking reliable connectivity.
Fourth, the bank must preserve auditability. It should retain authentication logs, device information, consent records, transaction data and evidence of customer warnings for an appropriate period. However, retention must remain proportionate and subject to security controls.
Case Laws
Google Spain SL v AEPD and Mario Costeja González, C-131/12, Court of Justice of the European Union. The Court recognised the importance of controlling the dissemination of personal information and developed the right to delisting from search results. For banking, the case demonstrates that identity-related information cannot be treated as permanently and universally available merely because it appears online.
Breyer v Bundesrepublik Deutschland, C-582/14. The Court held that dynamic IP addresses may constitute personal data where the controller has legally available means of identifying the individual. The decision is relevant to banks because device identifiers, IP addresses and login records may be personal data even when the bank does not initially know the customer’s real-world identity.
Schrems II, Data Protection Commissioner v Facebook Ireland, C-311/18. The Court invalidated the EU-US Privacy Shield and required safeguards for international data transfers. A Spanish bank using foreign cloud, identity-verification or fraud-detection providers must assess whether customer identity data receives legally adequate protection outside the European Economic Area.
Wirtschaftsakademie Schleswig-Holstein, C-210/16. The Court adopted a broad approach to joint responsibility for data processing. The principle may apply where banks jointly determine how identity information is processed with fintech providers, digital platforms or identity-verification vendors.
STC 292/2000, Spanish Constitutional Court. The Court recognised informational self-determination as constitutionally protected under Article 18.4 of the Spanish Constitution. The decision supports the requirement that identity data processing must be transparent, controlled and proportionate.
STC 76/2019, Spanish Constitutional Court. The Court emphasised constitutional limits on the processing and dissemination of personal data for political purposes. Its wider significance is that data processing cannot be justified solely by technological convenience; a clear legal basis and safeguards are required.
Conclusion
Spain’s banking identity framework combines eIDAS, Spanish electronic-trust legislation, GDPR, Organic Law 3/2018, anti-money-laundering rules, payment-authentication requirements and cybersecurity regulation. Banks may use electronic signatures, certificates, biometrics and digital wallets, but they remain responsible for accuracy, security, privacy and accessibility.
The legally compliant model is therefore not simply “digital first.” It must be secure, explainable, auditable, proportionate and supported by effective remedies when identity theft or unauthorised banking transactions occur.

comments