Banking Law And Embedded Insurance Regulation Spain .
Banking Law and Embedded Insurance Regulation in Spain
Introduction
Embedded insurance is insurance offered as part of another product or service rather than through a separate traditional sale. In banking, examples include travel insurance attached to a payment card, repayment insurance offered with a loan, device protection included in a financing plan, or life insurance distributed with a mortgage.
Embedding insurance may make protection easier to obtain, but it can also hide the product’s price, exclusions or optional nature. Spanish law therefore treats many embedded-insurance arrangements as regulated insurance distribution. A bank, fintech platform or retailer cannot avoid regulatory duties merely by integrating the insurance into a digital checkout or banking application.
Legal and Regulatory Framework
Spain’s principal insurance-distribution rules are contained in Royal Decree-Law 3/2020, which implemented the EU Insurance Distribution Directive. The broader framework includes:
Law 20/2015 on the organisation, supervision and solvency of insurers
Royal Decree 1060/2015 implementing insurance-supervision rules
The Insurance Contract Law 50/1980
Consumer-credit and mortgage-credit legislation
The General Consumer and User Protection Law
The General Data Protection Regulation
Law 10/2010 on preventing money laundering and terrorist financing
The Digital Operational Resilience Act
The Directorate-General for Insurance and Pension Funds supervises insurers and many insurance distributors. Banco de España remains responsible for banking conduct and prudential matters where banks distribute insurance. The Spanish Data Protection Agency supervises the processing of customer information.
Regulatory Status of Banks and Platforms
A bank selling insurance normally acts as a bancassurance operator or through another authorised distribution arrangement. It must be properly registered and must comply with professional competence, organisational, conduct and disclosure requirements.
A digital platform may become an insurance distributor where it performs more than merely displaying neutral information. Regulated distribution may include:
Recommending a particular insurance product
Comparing products and enabling the customer to conclude a policy
Collecting premiums or arranging coverage
Assisting with policy administration or claims
Enrolling customers in a group policy for remuneration
An ancillary insurance intermediary may benefit from a lighter regime where insurance is complementary to a non-insurance product and satisfies statutory conditions. However, exclusions are interpreted according to the substance of the activity, not the label chosen by the business.
Customer Needs and Product Suitability
Before concluding a contract, the distributor must identify the customer’s demands and needs. The proposed insurance must be consistent with those requirements. Where personal advice is provided, the bank should explain why the recommended product is suitable.
For insurance-based investment products, more extensive suitability or appropriateness rules may apply. The bank may need to assess the customer’s financial knowledge, experience, objectives, risk tolerance and ability to bear losses.
Automated recommendations do not remove these obligations. If an algorithm selects insurance using account activity, spending history or credit data, the bank remains responsible for the recommendation and for lawful data processing.
Bundling and Customer Consent
Customers must be told whether the insurance is compulsory or optional. A bank cannot state that insurance is legally required for a mortgage or loan when only appropriate security or coverage is required and the customer may use a qualifying policy from another provider.
Where insurance is bundled with a banking product, the customer should receive separate information about:
The insurance premium and banking charges
The identity of the insurer and distributor
Important exclusions and coverage limits
The duration and renewal mechanism
Cancellation and withdrawal rights
The consequences of terminating the associated bank product
Claims and complaint procedures
Pre-ticked boxes, silence or unclear acceptance mechanisms may not establish valid consent. The bank should retain reliable evidence that the customer knowingly agreed to the insurance.
Product Governance and Conflicts of Interest
The insurer and distributor must identify the product’s target market, evaluate customer risks and establish an appropriate distribution strategy. Products should be reviewed where claims experience, complaints or rejection rates indicate that customers are receiving poor value.
A bank may receive commissions for selling insurance linked to credit. This creates a conflict because employees may be encouraged to recommend the most profitable policy rather than the most suitable one. Remuneration arrangements must not undermine the duty to act honestly, fairly and professionally in the customer’s best interests.
Claims, Data and Operational Resilience
Embedding insurance should not make claims unreasonably difficult. Customers must be told whether the bank, insurer or technology provider handles notification and settlement. Responsibility cannot be obscured across multiple entities.
Health, biometric and behavioural information may constitute sensitive personal data. Processing requires an appropriate legal basis, transparency, security and compliance with restrictions on automated decisions.
Under DORA, regulated institutions must manage technology risks, report major incidents, test digital resilience and supervise critical outsourcing. Using an external application-programming interface does not remove the bank’s responsibility.
Relevant Case Laws
TC Medical Air Ambulance Agency, Case C-633/20
The Court held that a group-policyholder receiving remuneration for enrolling customers could qualify as an insurance intermediary. This is highly relevant to embedded group insurance.
Länsförsäkringar Sak Försäkringsaktiebolag v Dödsboet, Case C-542/16
The Court examined advice concerning an insurance-based investment product and clarified the boundary between insurance mediation and investment advice.
Aspiro SA, Case C-40/15
Claims-handling performed on behalf of an insurer did not automatically constitute insurance mediation. The exact role performed by the service provider remains decisive.
EEAE and Others v Oikonomakis, Case C-555/11
The Court interpreted insurance-intermediation requirements and confirmed that Member States may impose professional conditions consistent with EU law.
A and Others, Joined Cases C-143/20 and C-213/20
The Court addressed disclosure duties for unit-linked group insurance. Customers must receive sufficient information to understand the investment and insurance risks before joining.
Van Hove v CNP Assurances, Case C-96/14
An insurance exclusion must be expressed transparently so that a consumer can understand its economic and practical consequences.
Ocidental—Companhia Portuguesa de Seguros de Vida, Case C-263/22
The Court considered disclosure of exclusions in group insurance and emphasised that the insured person must be properly informed of coverage limitations.
Conclusion
Embedded insurance in Spain is lawful only when convenience is supported by informed consent, transparent pricing, appropriate product design and clear responsibility. Banks and platforms must determine whether their activities constitute regulated distribution and cannot rely on technology or group-policy structures to avoid the law.
Effective compliance requires demands-and-needs testing, conflict management, understandable exclusions, secure data processing and accessible claims procedures. These safeguards ensure that embedded insurance provides genuine protection instead of becoming a hidden or unsuitable banking charge.

comments