Banking Law And Digital Identity Wallet Regulation Spain .

Banking Law and Digital Identity Wallet Regulation in Spain

Introduction

Digital identity wallets are becoming an important part of banking regulation in Spain. A digital identity wallet allows a person to store and use verified identity information, electronic signatures, payment credentials, professional qualifications and other official documents through a mobile application. In banking, it may be used for remote account opening, customer identification, strong customer authentication, loan applications, electronic signatures and access to financial services.

Spain does not regulate digital identity wallets through one single banking statute. Their legal framework results from the interaction of European Union law, Spanish financial legislation, data-protection rules, anti-money-laundering requirements and electronic-signature regulation.

Legal and Regulatory Framework

1. eIDAS and the European Digital Identity Wallet

The principal framework is Regulation (EU) 910/2014 on electronic identification and trust services, known as the eIDAS Regulation. It was substantially amended by Regulation (EU) 2024/1183, which establishes the European Digital Identity Framework and European Digital Identity Wallets.

The revised framework requires Member States to make recognised digital identity wallets available to citizens, residents and businesses. These wallets are intended to permit secure identification and the selective sharing of verified attributes, such as age, address, identity number or authorisation to act for a company.

For Spanish banks, the wallet may become a legally reliable method of identifying customers, provided that the wallet, identity provider and relying bank satisfy the relevant technical, security and assurance requirements. Electronic signatures created through qualified trust services may have the same legal effect as handwritten signatures.

2. Spanish electronic-identification law

Spain applies eIDAS through Law 6/2020 on electronic trust services. The law regulates qualified and non-qualified trust-service providers, electronic signatures, electronic seals, electronic time stamps and electronic delivery services.

The Spanish National Currency and Stamp Factory, public authorities and private trust-service providers may participate in identity and trust-service infrastructure. The Spanish supervisory authority for many trust-service functions is the Secretaría de Estado de Digitalización e Inteligencia Artificial, while the Agencia Española de Protección de Datos supervises personal-data processing.

A bank using a digital wallet must verify:

  • the authenticity and validity of the identity credential;
  • the assurance level of the identification method;
  • whether the credential has been revoked or suspended;
  • whether the person is acting personally or on behalf of a company;
  • whether the transaction requires a qualified electronic signature.

3. Anti-money-laundering and customer due diligence

Spanish banks remain subject to Law 10/2010 on the prevention of money laundering and terrorist financing and its implementing regulations. A digital wallet does not remove the bank’s customer-due-diligence obligations.

Banks must still identify and verify the customer, determine the beneficial owner, understand the purpose of the relationship, assess risk and monitor transactions. A wallet can provide reliable identification evidence, but the bank must not automatically treat every wallet credential as sufficient for every AML purpose.

Enhanced due diligence may be required where the customer is a politically exposed person, operates through complex structures, uses high-risk jurisdictions or conducts unusual transactions. The bank must also retain appropriate records and report suspicious activity to SEPBLAC.

4. GDPR and Spanish data protection

The General Data Protection Regulation applies whenever a bank, wallet provider or identity provider processes personal data. Spain supplements the GDPR through Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights.

The most important principles are data minimisation, purpose limitation, accuracy, security, transparency and accountability. A bank should request only the attributes necessary for the service. For example, confirming that a customer is over eighteen should not require disclosure of the customer’s complete identity document if an age attribute is sufficient.

Banks must determine their legal basis for processing. AML identification generally rests on legal obligations, while marketing, profiling or optional data-sharing may require consent. Consent must be specific and freely given; refusing unnecessary commercial data-sharing should not normally prevent access to basic banking services.

High-risk wallet systems may require a data-protection impact assessment. Banks must also address biometric data, device security, identity theft, unauthorised access, data breaches and the transfer of data to technology providers.

5. PSD2, strong customer authentication and DORA

The Payment Services Directive 2 and its Spanish implementing legislation regulate payment services and strong customer authentication. A wallet may function as one authentication factor, but authentication must still satisfy the legal requirements of possession, knowledge or inherence where applicable.

For example, a mobile wallet may combine possession of a registered device with a biometric or PIN verification. The bank remains responsible for secure authentication, fraud controls and appropriate customer communication.

The Digital Operational Resilience Act also applies to financial entities and becomes highly relevant to wallet integration. Banks must manage information-technology risks, maintain incident-response procedures, test critical systems and control outsourcing relationships with cloud, identity and authentication providers.

Rights and Responsibilities

Customers have the right to transparent information, access to their personal data, correction of inaccurate information, erasure where legally possible, restriction of processing and protection against unlawful automated decision-making.

However, erasure may be restricted where the bank must retain identity and transaction records under AML, accounting or prudential rules. Banks must also provide a workable alternative where reliance on a wallet would unjustifiably exclude customers who lack compatible devices, digital skills or stable connectivity.

Banks are responsible for verifying the identity evidence, preventing impersonation, documenting decisions, protecting authentication credentials and investigating unauthorised transactions. A bank cannot escape liability merely by arguing that a fraudulent transaction was technically authenticated.

Relevant Case Law

  1. STC 292/2000, Spanish Constitutional Court – recognised data protection as an autonomous fundamental right and emphasised control over personal information.
  2. STC 76/2019, Spanish Constitutional Court – invalidated broad data-processing provisions that lacked sufficient safeguards, reinforcing legality, purpose limitation and proportionality.
  3. CJEU, Case C-291/12, Schwarz v Stadt Bochum – accepted biometric identity checks only where they are necessary, proportionate and protected by safeguards. The reasoning is relevant to facial recognition or biometric wallet authentication.
  4. CJEU, Case C-311/18, Schrems II – stressed that personal-data transfers must provide protection essentially equivalent to EU standards. Spanish banks must therefore control international transfers by wallet and cloud providers.
  5. CJEU, Case C-634/21, SCHUFA – restricted significant decisions based solely on automated processing. A bank should not reject a customer or loan application solely through opaque automated identity or risk scoring without appropriate safeguards.
  6. CJEU, Joined Cases C-26/22 and C-64/22, SCHUFA – confirmed that data-retention and credit-information practices must comply with GDPR principles, especially necessity, accuracy and proportionality.
  7. CJEU, Case C-175/20, Valsts ieņēmumu dienests – confirmed that AML-related information duties must respect data protection and cannot justify unlimited or indiscriminate access to personal information.

Conclusion

Digital identity wallets can make Spanish banking faster, more secure and more interoperable across the EU. Nevertheless, they are not a substitute for AML compliance, GDPR accountability, strong customer authentication or operational-resilience controls. The central legal principle is proportionality: banks should accept reliable digital identification while requesting only the information necessary for the particular banking service. Their implementation must also preserve accessibility, human review, cybersecurity and effective remedies for customers affected by fraud or erroneous automated decisions.

This is a general legal overview, not legal advice. The principal EU framework is Regulation (EU) 2024/1183 amending eIDAS, alongside GDPR, PSD2, AML legislation, Spanish Law 6/2020 and Organic Law 3/2018.

LEAVE A COMMENT