Banking Law And Embedded Finance Regulatory Perimeter Spain .

Banking Law and Embedded Finance Regulatory Perimeter in Spain

Introduction

Embedded finance refers to the integration of financial products into the digital platforms, applications or commercial processes of businesses whose principal activity may not itself be financial services. Common examples include an online marketplace incorporating payments, a retailer offering instalment credit, a mobility application providing a wallet, or a software platform offering banking services through a licensed financial institution.

Spanish law does not contain a single statute called an Embedded Finance Act. Instead, the regulatory perimeter is determined according to the actual financial activity performed. Depending on the business model, the relevant framework may include banking law, payment-services legislation, electronic-money regulation, consumer-credit rules, anti-money-laundering requirements, data-protection law and outsourcing requirements.

The central legal question is therefore not whether a company describes itself as a technology platform. The question is what regulated activity the company actually performs and which entity bears legal responsibility for that activity.

Legal and Regulatory Framework

Important legislation includes:

Law 10/2014 on the regulation, supervision and solvency of credit institutions, which governs banks and the reserved business of credit institutions.

Royal Decree-Law 19/2018 on payment services and other urgent financial measures, which implements the European PSD2 framework in Spain.

Law 21/2011 on Electronic Money, governing electronic-money institutions.

Law 16/2011 on Consumer Credit Agreements, relevant where embedded platforms offer consumer financing.

Law 10/2010 on prevention of money laundering and terrorist financing, which imposes customer-identification and financial-crime controls on regulated entities.

The Banco de España plays a central role in supervising credit institutions, payment institutions and electronic-money institutions.

The Regulatory Perimeter Principle

Embedded finance does not create an exemption from financial regulation.

If a non-financial business merely introduces customers to a licensed bank, while the bank enters into the financial contract, controls the regulated service and remains responsible for compliance, the technology company may remain outside the core banking licence perimeter.

However, the position changes where the platform itself performs activities legally reserved to regulated financial institutions.

Examples include:

accepting repayable funds from the public;

issuing electronic money;

executing regulated payment transactions;

maintaining regulated payment accounts;

providing account-information or payment-initiation services;

professionally granting certain forms of regulated credit; or

carrying out regulated investment services.

The legal classification therefore depends upon economic substance rather than marketing terminology.

Payments Embedded in Commercial Platforms

Payments are among the most common embedded-finance services.

Royal Decree-Law 19/2018 reserves professional provision of statutory payment services to recognized payment-service providers, including credit institutions, payment institutions and qualifying electronic-money institutions.

A retailer or technology company cannot avoid this requirement simply by calling its payment function a technological feature.

There are nevertheless statutory exclusions. For example, certain commercial-agent arrangements and limited-network instruments can fall outside the full payment-services regime where the legal conditions are satisfied.

Those exclusions are interpreted according to their actual circumstances. A business cannot automatically rely on them merely because payments occur inside a closed application or commercial ecosystem.

Limited-Network Models

Embedded payment products sometimes operate within a limited network, such as a payment instrument accepted only by a restricted group of providers or for a narrow range of goods and services.

Spanish payment law recognizes a limited-network exclusion derived from PSD2.

However, where transaction volumes exceed applicable thresholds, notification to Banco de España may be required so that the authorities can determine whether the arrangement genuinely remains within the exclusion.

A platform that expands from a narrowly defined retailer network into a widely accepted payment system may therefore cross the regulatory perimeter.

Electronic Money

A particularly important dividing line concerns stored monetary value.

Under Law 21/2011, electronic money broadly involves monetary value stored electronically or magnetically, representing a claim against the issuer, issued upon receipt of funds and accepted by parties other than the issuer.

If an embedded wallet satisfies these characteristics, electronic-money regulation may apply.

A platform cannot avoid the regime simply by describing balances as “credits,” “tokens” or “wallet points” if their actual characteristics constitute electronic money.

Issuing electronic money generally requires an appropriately authorized credit institution or electronic-money institution.

Agents, Distributors and Outsourcing

A technology company does not always need to become a fully licensed financial institution.

A regulated payment institution may provide services through registered agents where statutory requirements are satisfied.

Similarly, electronic-money institutions may use third parties for certain activities.

However, an important distinction exists between outsourcing a function and outsourcing regulatory responsibility.

A licensed financial institution may delegate technological or operational tasks, but it normally remains responsible for compliance with the financial-services rules applicable to its regulated activities.

Material outsourcing must also not prevent Banco de España from effectively supervising the institution.

This principle is highly important for Banking-as-a-Service and embedded-finance arrangements.

Banking-as-a-Service

Banking-as-a-Service commonly involves a licensed bank or financial institution supplying regulated infrastructure that allows another company to provide financial features through its own interface.

A Spanish technology company might therefore provide the customer-facing application while a licensed institution supplies the regulated account, payment or credit product.

The parties must clearly allocate responsibilities concerning:

customer onboarding;

regulatory disclosures;

transaction monitoring;

complaints;

fraud controls;

cybersecurity;

customer authentication;

data management;

outsourcing oversight; and

regulatory reporting.

The existence of a licensed banking partner does not automatically legalize every activity undertaken independently by the platform.

Embedded Credit

Retailers and digital platforms increasingly provide “buy now, pay later,” instalment financing and other forms of embedded credit.

Where the arrangement constitutes consumer credit, Law 16/2011 may impose requirements concerning pre-contractual information, annual percentage rates, creditworthiness assessments, withdrawal rights and early repayment.

If the platform merely introduces customers to a bank, the regulatory position differs from a model in which the platform itself originates, funds and controls loans.

Consequently, determining who is legally the creditor is crucial.

Deposits and Repayable Funds

Accepting deposits or other repayable funds from the public represents one of the strongest banking-law boundaries.

A technology company should not structure an embedded product so that it effectively accepts customer deposits without the appropriate banking authorization.

Payment institutions and electronic-money institutions may hold customer money for their permitted services, but those funds are subject to specific safeguarding requirements and do not become ordinary bank deposits merely because they are displayed as an account balance in an application.

Anti-Money-Laundering Regulation

Embedded finance frequently involves remote customer onboarding and high-volume digital transactions.

Spanish AML law therefore plays an important role.

Depending upon the structure, regulated institutions may have to perform:

customer identification;

beneficial-owner verification;

risk assessment;

transaction monitoring;

enhanced due diligence;

suspicious-transaction reporting; and

record keeping.

Using a commercial platform or fintech intermediary does not remove these obligations.

Consumer Protection and Transparency

Customers may interact only with the non-bank brand even though the underlying financial product comes from another institution.

Spanish and EU consumer law therefore require transparency regarding matters such as:

identity of the regulated provider;

fees;

interest;

payment obligations;

withdrawal rights;

liability for unauthorized transactions;

complaint procedures; and

contractual changes.

The embedded model should not make it difficult for customers to understand who legally provides the financial service.

Important Case Laws

1. Safe Interenvíos SA v Liberbank SA and Others – Case C-235/14

This case arose from Spain and involved a payment institution whose banking relationships were affected by enhanced anti-money-laundering measures.

The Court of Justice examined the interaction between payment-services rules and AML obligations.

Principle: financial institutions may adopt enhanced due-diligence measures where justified by identified risks, but such measures must comply with EU principles, including proportionality.

For embedded finance, the case shows that fintech and payment businesses remain subject to financial-crime controls even where their business model differs from traditional banking.

2. ABC Projektai – Case C-661/22

The Court of Justice considered the distinction between payment services and issuance of electronic money.

The dispute concerned whether funds retained in a payment account could amount to electronic money.

Principle: the regulatory characterization of a financial service depends upon its actual legal and economic features.

This case is particularly important to embedded wallets because a platform cannot determine the applicable regulatory regime simply by choosing its preferred contractual terminology.

3. Paysera LT – Case C-389/17

The Court considered activities connected with issuance of electronic money and the calculation of regulatory own funds.

Principle: activities closely linked with electronic-money issuance must be properly classified under the electronic-money regulatory framework.

The decision demonstrates that authorities examine the real function of fintech activities when determining prudential obligations.

4. T-Mobile Austria – Case C-616/11

The case examined whether particular procedures used to initiate payments constituted payment instruments under EU payment-services legislation.

Principle: the concept of a payment instrument is determined functionally rather than by the commercial sector of the provider.

This has direct significance for embedded finance because a telecommunications company, retailer or technology platform may fall within payment rules when it introduces payment functionality.

5. BAWAG – Case C-375/15

The Court examined whether information made available through an online banking mailbox had been provided on a legally acceptable durable medium.

Principle: digital delivery does not automatically satisfy mandatory financial-information requirements. Customers must be capable of storing and reproducing required information under appropriate conditions.

Embedded-finance providers therefore cannot assume that placing terms somewhere inside an application satisfies disclosure obligations.

6. DenizBank – Case C-287/19

This case concerned contactless payment functionality, payment instruments and contractual changes.

Principle: technological innovation does not displace mandatory payment-services protections.

The Court's approach demonstrates that new interfaces and payment technologies remain subject to established rules concerning authorization, customer information and payment liability.

7. Banco Español de Crédito SA v Joaquín Calderón Camino – Case C-618/10

This Spanish case concerned unfair terms in a consumer credit agreement.

The Court of Justice emphasized the responsibility of national courts to provide effective protection against unfair contractual provisions.

Principle: embedding a credit agreement within a retail or digital transaction does not remove consumer-law protection.

The case is particularly relevant to embedded instalment loans and other digital consumer-credit products.

Regulatory Perimeter and Substance Over Form

These cases demonstrate an overarching rule: legal substance prevails over technological presentation.

An application may call a product a wallet, account, balance, instalment service or customer-credit system. Those descriptions do not determine its legal status.

Authorities will instead consider matters such as:

who receives the customer's funds;

who owes repayment;

who controls the payment transaction;

who bears credit risk;

whether funds are accepted by third parties;

whether the customer has a claim against an issuer;

who makes the lending decision; and

whether the service is provided professionally.

These factors determine which financial licence or exemption is relevant.

Open Banking and Embedded Finance

PSD2 also enables embedded services through regulated account-information and payment-initiation businesses.

An authorized provider can, subject to the applicable requirements, access payment-account information or initiate payments using regulated interfaces.

Open banking therefore supports embedded finance while simultaneously bringing relevant activities within a regulatory framework governing authorization, security and customer consent.

Outsourcing and Operational Resilience

Embedded-finance structures commonly depend on cloud platforms, APIs and third-party technology companies.

The regulated institution must ensure that outsourcing does not materially weaken internal controls or prevent regulators from supervising the activity.

Particularly important functions may include:

payment processing;

cloud hosting;

customer authentication;

fraud detection;

account infrastructure; and

transaction monitoring.

The regulated institution remains responsible for ensuring compliance even where technology is supplied by another company.

Main Regulatory Risks

A Spanish embedded-finance business faces several major perimeter risks.

The first is unauthorized regulated activity, where the technology company performs activities reserved for banks, payment institutions or electronic-money institutions.

The second is misclassification, particularly between ordinary commercial balances, payment accounts and electronic money.

The third concerns agency and outsourcing, because outsourcing technology does not transfer the regulated institution's legal responsibility.

The fourth is consumer protection, especially where the regulated provider is hidden behind another company's brand.

The fifth concerns AML and financial crime, particularly in remotely operated financial products.

Finally, rapidly evolving business models can move across the regulatory perimeter as new services are added. A model that originally qualified for an exclusion may therefore later require authorization.

Conclusion

Embedded finance in Spain is regulated according to the financial activity actually performed rather than according to the technology or branding used to deliver it.

The principal framework includes Law 10/2014, Royal Decree-Law 19/2018, Law 21/2011, Law 16/2011 and Law 10/2010, together with EU payment, consumer and financial-services rules.

Cases including Safe Interenvíos, ABC Projektai, Paysera LT, T-Mobile Austria, BAWAG, DenizBank and Banco Español de Crédito demonstrate that courts focus upon economic substance, consumer protection and effective financial regulation.

A non-bank platform may therefore distribute financial products through a properly licensed institution, agent or outsourcing arrangement without necessarily becoming a bank itself. However, once the platform independently performs a reserved activity, regulatory authorization may become necessary.

The central principle of Spain's embedded-finance perimeter is consequently clear: technology can change how financial services are delivered, but it does not eliminate the licensing, prudential, consumer-protection and financial-crime rules attached to the underlying financial activity.

LEAVE A COMMENT