Banking Law And Electronic Signatures In Banking Spain .
Banking Law and Electronic Signatures in Banking in Spain
Introduction
Electronic signatures have become essential to Spanish banking. Banks use them for opening accounts, granting consumer credit, approving payment instructions, accepting investment documents and changing contractual terms. A customer may sign through a digital certificate, banking application, biometric process, PIN or one-time password sent by SMS.
Spanish law generally recognises electronically signed banking contracts. However, electronic form alone does not prove that a particular customer understood, authorised or signed a transaction. The bank must establish the customer’s identity, the integrity of the document, the reliability of the signature process and compliance with consumer-protection rules. Electronic signatures therefore facilitate banking activity but do not remove the bank’s duties of transparency, security and proof.
Legal and Regulatory Framework
The principal framework is Regulation (EU) No 910/2014, commonly called the eIDAS Regulation. It distinguishes three levels of electronic signature:
A simple electronic signature, such as typing a name, clicking an acceptance button or using a basic PIN.
An advanced electronic signature, which must be uniquely linked to the signer, identify that person, remain under the signer’s control and reveal subsequent alteration of the signed data.
A qualified electronic signature, which is an advanced signature created using a qualified device and based on a qualified certificate.
Article 25 of eIDAS provides that a signature cannot be denied legal effect merely because it is electronic or because it is not qualified. Nevertheless, only a qualified electronic signature automatically has the same legal effect as a handwritten signature throughout the European Union.
Spain supplements eIDAS through Law 6/2020 regulating certain aspects of electronic trust services. Trust-service providers issue and manage certificates, timestamps and other tools used to prove identity and document integrity.
The Spanish Civil Code and Commercial Code continue to govern consent, capacity and contractual validity. Law 34/2002 on information-society services recognises electronic contracting. The Civil Procedure Act governs the evidential use and challenge of electronic documents. Consumer banking is additionally controlled by consumer-credit legislation, payment-services rules, data-protection law and financial transparency requirements.
Use in Banking Transactions
Spanish banks may use electronic signatures for account-opening forms, loan contracts, payment mandates, investment orders and customer communications. A qualified signature offers the strongest formal presumption, but many ordinary banking contracts may validly be concluded using an advanced or simple signature.
Validity and proof must be distinguished. A contract may be legally valid without a qualified signature, but the bank may face difficulty proving it if the customer denies participation. A mere record stating “accepted” may be insufficient where the bank cannot produce the complete contract, authentication records and evidence connecting the signature to the customer.
Banks should preserve the signed document, its cryptographic hash, certificate information, timestamp, IP and device records, authentication events and the evidence showing delivery of pre-contractual information. They should also prove that the customer could download and retain the contractual terms.
An SMS code does not automatically constitute an advanced signature. Its evidential value depends on whether the process reliably connects the code, customer, device and specific document. If fraudsters obtain a code through phishing or SIM-swapping, possession of the code may not establish genuine consent.
Customer Protection and Bank Responsibility
Electronic signature does not cure an unfair term or inadequate disclosure. Before signing, customers must receive clear information concerning interest, commissions, duration, repayment obligations, default consequences and cancellation rights. For mortgages, consumer credit and investment products, specialised disclosure and suitability rules may apply.
Under payment-services law, the use of a customer’s authentication credentials does not by itself prove that the customer authorised a disputed payment. The bank must demonstrate authentication, accurate recording and the absence of a technical failure. Unless fraud or gross negligence by the customer is established, the bank may remain responsible for an unauthorised transaction.
Data-protection duties are equally important. Biometric signatures, behavioural information and device identifiers may constitute personal data. Banks must have a lawful basis, follow purpose limitation, apply security safeguards and avoid collecting excessive information.
Relevant Case Laws
1. EKOFRUKT, Case C-362/21
The Court of Justice explained that the requirements for a qualified electronic signature are cumulative. The signature must be advanced, created through a qualified device and supported by a qualified certificate. A provider’s label cannot replace judicial examination of those requirements.
2. V.B. Trade, Case C-466/22
The Court held that a qualified electronic signature may be challenged under applicable procedural rules, just as a handwritten signature may be contested. Qualification gives legal equivalence, but it does not make the signature immune from examination for authenticity or misuse.
3. Jarocki, Case C-302/23
This judgment concerned an electronically signed procedural document. It confirmed that eIDAS prevents discrimination against signatures merely because they are electronic, while national law may still establish proportionate procedural requirements. The principle is relevant when banks submit electronically signed records in litigation.
4. BAWAG, Case C-375/15
The Court considered whether information placed in an online banking mailbox was supplied on a durable medium. An electronic banking system can qualify where customers can store information unchanged and access it for an adequate period. Banks may also need to alert customers that important information is available.
5. Content Services, Case C-49/11
The Court ruled that merely making contractual information accessible through a website link did not necessarily amount to providing it on a durable medium. For Spanish banks, displaying terms during a signature journey may therefore be insufficient unless customers can retain an unchanged copy.
6. Home Credit Slovakia, Case C-42/15
The Court examined formal and informational requirements for consumer-credit agreements. It confirmed the importance of giving consumers contractual information in a durable and reproducible form. Electronic execution cannot be used to avoid mandatory credit disclosures.
7. Banco Español de Crédito, Case C-618/10
The Court emphasised effective judicial control of unfair terms in consumer banking contracts. Even where a customer electronically signs a loan, courts must still examine whether its terms are unfair and cannot treat the signature as unconditional acceptance of unlawful provisions.
Conclusion
Electronic signatures are legally recognised and widely usable in Spanish banking. Qualified signatures provide the strongest legal equivalence, but advanced and simple signatures can also establish valid contracts. Their effectiveness depends on reliable identification, document integrity, secure authentication and complete evidential records.
Banks must not treat an OTP, digital click or certificate as conclusive proof in every case. They must also demonstrate informed consent, proper disclosure, durable delivery and compliance with payment, consumer and data-protection law. For customers, an electronic signature creates real legal obligations, but it does not remove the right to challenge fraud, defective authentication, unfair terms or inadequate information.

comments