Banking Law And Embedded Finance Regulation Spain .
Banking Law and Embedded Finance Regulation Spain
Introduction
Embedded finance refers to the integration of financial services into the products or digital platforms of businesses whose principal activity is not traditionally banking. Examples include an online marketplace offering payments, a retailer providing instalment credit, a mobility application containing a digital wallet, or a software platform allowing users to initiate payments without leaving the platform.
Spain does not regulate “embedded finance” through a single dedicated statute. Its legal treatment depends on the financial function actually performed. A platform may therefore fall within banking, payment-services, electronic-money, consumer-credit, investment-services, anti-money-laundering, data-protection or digital-operational-resilience rules.
The central regulatory principle is that technological integration does not remove an activity from financial regulation. If the underlying service is regulated, embedding that service into another commercial product does not normally eliminate licensing and conduct requirements.
Legal and Regulatory Framework
Spanish embedded-finance arrangements operate within both Spanish and European Union law.
Important legislation includes:
Law 10/2014 on the regulation, supervision and solvency of credit institutions;
Real Decreto-ley 19/2018 on payment services;
Law 21/2011 on electronic money;
Law 16/2011 on consumer credit agreements;
Law 10/2010 on prevention of money laundering and terrorist financing;
Law 7/1998 on general contractual conditions;
general consumer-protection legislation; and
the EU Digital Operational Resilience Act.
Banco de España plays an important role in authorization and supervision of banks, payment institutions and electronic-money institutions within its jurisdiction.
Licensing Perimeter
The most important question is whether the non-financial platform itself performs a regulated activity.
Accepting repayable deposits from the public is fundamentally different from merely displaying a bank's account through an application.
Similarly, executing payment transactions, issuing electronic money or providing account-information or payment-initiation services may require authorization or registration.
A technology company cannot avoid regulation merely by describing itself as an “embedded finance provider.”
The substance of its activities determines the regulatory position.
Banking-as-a-Service Structures
Many embedded-finance businesses operate through Banking-as-a-Service arrangements.
A regulated bank may provide accounts, payments or credit infrastructure while the non-bank platform controls the customer interface.
This arrangement can reduce the need for the platform itself to become a bank, but it does not eliminate regulatory questions.
The parties should determine clearly:
which entity provides the regulated service;
who contracts with the customer;
who holds customer funds;
who performs customer due diligence;
who handles complaints;
who makes lending decisions; and
who bears responsibility for regulatory compliance.
The licensed financial institution cannot simply transfer all legal responsibility to the technology company.
Embedded Payments
Embedded payments allow customers to pay without leaving the commercial platform.
Where the platform itself executes regulated payment services, Spanish payment-services legislation may apply.
By contrast, where an authorized payment institution performs the regulated activity and the commercial platform provides only technical support, the regulatory position may differ.
The distinction between providing a regulated payment service and supplying a purely technical service is therefore fundamental.
Payment institutions must satisfy requirements relating to authorization, safeguarding, governance, operational security and customer protection.
Embedded Electronic Money
Digital wallets can also constitute embedded finance.
If the platform issues monetary value electronically after receiving funds and that value is accepted by persons other than the issuer, the activity may fall within Spain's electronic-money framework.
Electronic-money issuance normally requires an appropriately authorized institution.
The platform must therefore distinguish between a simple commercial loyalty balance and regulated electronic money.
Calling a product “credits,” “points” or “wallet balance” does not determine its legal classification.
Embedded Consumer Credit
Retailers, marketplaces and digital platforms increasingly integrate instalment financing or other credit directly into the purchasing process.
Where credit is provided to consumers, Law 16/2011 and general consumer law may apply.
The borrower should receive adequate information regarding:
total credit amount;
interest;
annual percentage rate;
charges;
repayment schedule;
default consequences; and
withdrawal or early-repayment rights where applicable.
Digital convenience must not reduce contractual transparency.
Outsourcing and White-Label Services
Embedded finance frequently depends on outsourcing.
Banks may use technology companies for interfaces, cloud services, identity verification, payment infrastructure or customer-support functions.
Spanish and European banking principles generally permit outsourcing subject to regulatory safeguards.
However, outsourcing does not extinguish the regulated institution's responsibility.
The institution must preserve sufficient control and supervisory access and must not outsource so extensively that it effectively becomes an empty licensed shell.
DORA and Technology Risk
The Digital Operational Resilience Act is particularly important to embedded finance because such arrangements depend heavily on interconnected technology providers.
Covered financial entities must manage ICT risks, operational incidents and third-party technology dependencies.
A bank using an embedded-finance platform therefore remains responsible for managing risks arising from its technology partners.
Contracts with important ICT providers should address security, availability, auditability, incident management and exit arrangements.
Anti-Money-Laundering Obligations
Embedded-finance structures can complicate customer identification because the customer may interact mainly with the commercial platform rather than visibly with the regulated financial institution.
Nevertheless, AML/CFT requirements cannot be avoided through interface design.
Relevant obligations can include customer identification, beneficial-owner verification, transaction monitoring, sanctions screening and suspicious-transaction reporting.
Responsibilities between the platform and regulated institution should be contractually clear.
Case Laws
1. Banco Español de Crédito SA v Calderón Camino – Case C-618/10
The Court of Justice addressed unfair terms in Spanish consumer credit.
It emphasized effective judicial protection against unfair contractual clauses.
Embedded-finance relevance: Digital credit embedded in shopping platforms remains subject to consumer protection even where acceptance occurs through a simple online interface.
2. Aziz v Caixa d'Estalvis – Case C-415/11
This important Spanish case concerned unfair terms and enforcement in consumer finance.
The Court reinforced the requirement that consumers receive effective protection from contractual imbalance.
Relevance: Embedded-finance providers cannot rely upon standard digital terms where those terms create unlawful imbalance.
3. Gutiérrez Naranjo and Others – Joined Cases C-154/15, C-307/15 and C-308/15
The Court considered the financial consequences of unfair contractual clauses used by Spanish banks.
Relevance: If an embedded credit term is unfair, digital acceptance does not necessarily prevent restitution of amounts improperly charged.
4. BAWAG PSK Bank für Arbeit und Wirtschaft – Case C-375/15
The case concerned information supplied through electronic banking communications.
The Court considered when information transmitted through a digital banking environment could satisfy durable-medium requirements.
Relevance: Embedded-finance businesses must ensure that legally required information is genuinely made available to customers in an accessible and durable form.
5. Gómez del Moral Guasch v Bankia – Case C-125/18
The Court examined transparency concerning an interest-rate mechanism in a Spanish mortgage agreement.
Relevance: Embedded lending must enable users to understand the economic consequences of pricing mechanisms, rather than merely displaying technically correct terms.
6. DenizBank AG – Case C-287/19
This case concerned payment services, contactless functionality and contractual changes associated with payment instruments.
The Court examined important questions concerning payment instruments, consent and user protection.
Relevance: Embedded payment functions remain governed by payment-law safeguards even where transactions are technologically simplified.
7. Caixabank and BBVA – Joined Cases C-224/19 and C-259/19
These cases concerned unfair contractual costs imposed on consumers in Spanish banking relationships.
Relevance: Fees embedded into digital financial products remain subject to transparency and unfair-terms controls.
8. Abanca Corporación Bancaria and Bankia – Joined Cases C-70/17 and C-179/17
The Court dealt with acceleration clauses in Spanish consumer lending.
Relevance: Automated embedded-credit systems cannot enforce disproportionate acceleration provisions simply because they were included in standardized digital contracts.
Data and Automated Decisions
Embedded finance depends heavily on customer data.
Platforms may combine purchasing history, behavioural information and conventional financial data when determining whether to offer credit or other services.
Such practices raise questions concerning data protection, automated decision-making, discrimination and transparency.
The fact that a lending decision is made by an algorithm does not remove the lender's legal responsibilities.
Banks and fintech firms should maintain governance systems capable of explaining and monitoring material automated decisions.
Consumer Protection
Embedded finance can make financial products appear to be ordinary features of an application.
This convenience creates a risk that customers may not realize they are entering into a separate regulated financial contract.
The interface should therefore make clear:
the identity of the financial provider;
the nature of the product;
material charges;
repayment responsibilities;
important risks; and
complaint procedures.
Commercial design should not obscure legally significant information.
Conclusion
Embedded finance in Spain is regulated according to the substance of the financial service rather than the technological method through which it is delivered.
Payments may trigger payment-services regulation, stored-value wallets may constitute electronic money, lending can trigger consumer-credit rules, and deposit-taking remains principally within regulated banking.
Using a licensed bank or payment institution through a white-label or Banking-as-a-Service model can allocate regulated functions to an authorized provider, but it does not eliminate supervisory, outsourcing, consumer-protection, AML or operational-resilience responsibilities.
The case law of the Court of Justice, including Banco Español de Crédito, Aziz, Gutiérrez Naranjo, BAWAG, Gómez del Moral Guasch, DenizBank, Caixabank and Abanca, demonstrates that digital delivery does not weaken fundamental requirements relating to transparency, fair terms, payment authorization and effective consumer protection.
The essential principle is therefore that finance does not cease to be regulated merely because it becomes invisible within another digital service. Spanish embedded-finance structures must identify the true regulated activity, place it with an appropriately authorized entity, and maintain clear responsibility for customers, technology and regulatory compliance.

comments