Banking Law And Digital Infrastructure Finance Spain .
Banking Law and Digital Infrastructure Finance in Spain
Introduction
Digital infrastructure has become essential to modern banking in Spain. Banks, payment institutions, fintech companies, securities firms and insurers depend on cloud computing, data centres, telecommunications networks, digital identity systems, application programming interfaces, cybersecurity tools and electronic payment platforms. Financing this infrastructure creates legal questions concerning licensing, prudential regulation, data protection, cybersecurity, outsourcing, competition, consumer protection and public procurement.
Spanish regulation operates within a European framework. The principal objective is to ensure that digital infrastructure supporting financial services is secure, reliable, accessible and capable of continuing during cyberattacks, technical failures or financial crises.
Legal and Regulatory Framework
The central instrument is Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector, commonly known as DORA. It applies from 17 January 2025 and covers banks, payment institutions, electronic-money institutions, investment firms, crypto-asset service providers, trading venues and other financial entities. DORA requires governance of information and communication technology risks, incident reporting, resilience testing, business-continuity planning and control of ICT third-party providers. It is particularly important for projects financed through cloud platforms, shared banking utilities and outsourced technology systems. DORA Regulation
Spanish banks must also comply with the Spanish Banking Law framework, including Law 10/2014 on the organisation, supervision and solvency of credit institutions. The Banco de España supervises many banking activities, while the European Central Bank supervises significant institutions under the Single Supervisory Mechanism. The CNMV supervises investment firms, trading infrastructure and securities markets.
Payment and electronic-money infrastructure is governed principally by Royal Decree-Law 19/2018, which transposes the revised Payment Services Directive. It regulates payment initiation, account-information services, authentication, operational security and access to payment accounts. Financing a digital payment platform therefore requires both corporate financing and regulatory authorisation.
The General Data Protection Regulation and Organic Law 3/2018 regulate customer and transaction data. Digital infrastructure financiers must consider lawful processing, cybersecurity, international data transfers, retention periods, automated decision-making and the allocation of liability between banks and technology providers.
The NIS2 cybersecurity framework may also affect digital infrastructure operators. However, for entities directly covered by DORA, DORA generally operates as the more specific financial-sector regime. Critical infrastructure projects may additionally be subject to Spain’s national cybersecurity, national-security and critical-infrastructure rules.
Key Issues and Principles
1. Prudential and regulatory approval
A bank cannot treat digital infrastructure merely as an ordinary commercial investment. A project involving payment processing, custody, account access, digital assets or financial-market infrastructure may require authorisation. Supervisors may examine capital adequacy, governance, operational resilience, outsourcing arrangements and the fitness of directors.
Financing documents should therefore include regulatory-approval conditions, compliance representations, change-of-control clauses and termination rights if the relevant licence is withdrawn.
2. Outsourcing and cloud concentration
DORA requires financial entities to maintain responsibility for outsourced functions. A bank cannot avoid regulatory liability by arguing that a cloud provider or fintech contractor caused the failure. Contracts should address audit rights, access to information, security standards, incident reporting, subcontracting, data location, exit plans and continuity of service.
Concentration risk is significant where several Spanish banks use the same cloud provider, data centre or payment processor. Failure of one technology provider could affect the entire financial system. Regulators may therefore require alternative providers, recovery arrangements and tested exit strategies.
3. Cybersecurity and resilience
Digital infrastructure financing must include the cost of encryption, identity management, penetration testing, backup systems, disaster recovery and continuous monitoring. DORA requires serious ICT incidents to be classified and reported. Boards and senior management are responsible for establishing appropriate risk-management arrangements.
Loan agreements may use cybersecurity covenants, minimum resilience standards, reporting obligations and insurance requirements. A serious cyber incident may constitute a material adverse change or an event of default, although excessively broad clauses may create uncertainty and discourage investment.
4. Data protection and digital identity
Digital identity infrastructure can improve customer onboarding and anti-money-laundering controls, but it also creates risks of excessive surveillance, identity theft and unlawful profiling. Banks must apply data minimisation, purpose limitation and privacy-by-design principles.
Where infrastructure is financed through public-private partnerships, the parties must clearly identify the data controller, processor, retention obligations and responsibility for breaches. Cross-border cloud transfers must comply with GDPR requirements.
5. Sustainable and public infrastructure finance
Data centres and telecommunications systems consume substantial electricity and may generate environmental impacts. Sustainability-linked loans and green bonds may finance energy-efficient data centres, secure payment infrastructure and low-carbon connectivity. However, green-finance claims must be supported by measurable criteria and reliable reporting.
Projects involving public authorities may also be governed by public-procurement, state-aid and concession rules. A financing structure cannot be used to bypass transparency, equal-treatment or competitive-tendering requirements.
Case Laws
- Google Spain SL v AEPD and Mario Costeja González, Case C-131/12 – The Court recognised the importance of data protection and the right to request removal of search results involving personal information. The decision is relevant to banking identity systems and customer-data infrastructure.
- Digital Rights Ireland, Joined Cases C-293/12 and C-594/12 – The Court invalidated excessive data-retention rules, confirming that security objectives must respect privacy and proportionality.
- Schrems II, Case C-311/18 – International data transfers require effective protection for personal data. This affects banks using cloud providers located outside the European Economic Area.
- Breyer v Germany, Case C-582/14 – Dynamic IP addresses may constitute personal data where an organisation can identify the individual through additional information. The case is relevant to logging, monitoring and cybersecurity records.
- Wirtschaftsakademie Schleswig-Holstein, Case C-210/16 – The Court accepted joint responsibility for certain digital-platform data processing. Banks and technology providers may similarly share responsibility for customer-data operations.
- Planet49, Case C-673/17 – Consent for storing and accessing information on users’ devices must be informed and specific. The ruling is relevant to banking applications, authentication cookies and digital customer interfaces.
- Schrems I, Case C-362/14 – The invalidation of the Safe Harbor system demonstrates that commercial convenience cannot override fundamental data-transfer safeguards.
- Commission v Spain, Case C-61/11 – The Court emphasised the obligation of Member States to comply effectively with EU legal requirements. Spanish regulators and financial entities must therefore implement European digital-finance standards in a practical and enforceable manner.
Conclusion
Digital infrastructure finance in Spain is governed by a combination of banking supervision, DORA, payment-services law, GDPR, cybersecurity rules, competition law and public-procurement principles. The most important legal approach is responsibility throughout the technology chain: banks remain accountable even when infrastructure is financed, owned or operated by external providers. Successful projects require regulatory approval, resilient architecture, strong contractual controls, data-protection safeguards, tested exit plans and transparent risk allocation.

comments