Banking Law And Financial Discrimination Audits Spain .
Banking Law and Financial Data Breach Compensation — Spain
Introduction
Financial data breach compensation in Spain concerns the right of bank customers and other individuals to seek compensation when unlawful processing or inadequate protection of their personal data causes them material or non-material damage.
Banks process particularly sensitive financial information, including identity details, account numbers, transaction histories, credit information, payment information and authentication data. A security incident involving such information may create risks of financial loss, identity misuse, fraud, reputational harm or loss of control over personal information.
The principal legal framework is the EU General Data Protection Regulation (GDPR), supplemented in Spain by Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD). Banking, payment-services, cybersecurity and operational-resilience requirements can provide additional layers of protection.
Most importantly, Article 82 GDPR gives a person who has suffered material or non-material damage resulting from a GDPR infringement a right to compensation. EU case law makes clear, however, that an infringement alone does not automatically produce compensation: infringement, actual damage and a causal connection must be established.
Duties of Spanish Banks
Banks normally act as controllers of substantial quantities of customer personal data.
Under the GDPR, they must implement appropriate technical and organisational measures proportionate to the risks associated with processing.
Relevant measures can include access controls, authentication, encryption where appropriate, monitoring, incident-management procedures, employee controls, backups, vulnerability management and procedures for responding to security incidents.
Article 32 GDPR does not create a guarantee that no cyberattack can ever succeed. The legal issue is whether the institution adopted security measures appropriate to the particular risks.
Consequently, the fact that criminals caused a breach does not automatically establish either liability or exemption from liability.
What Constitutes a Personal Data Breach?
A personal data breach is broadly a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
In banking, examples could include unauthorized access to customer records, accidental disclosure of account information, compromised databases or improper transmission of customer information.
A security incident and a compensable claim should nevertheless be distinguished.
A customer seeking compensation under Article 82 generally needs three elements:
an infringement of the GDPR;
material or non-material damage; and
a causal relationship between the infringement and that damage.
This three-part approach has been repeatedly confirmed by European case law.
Material Damage
Material damage concerns measurable economic loss.
In a banking context, it could potentially include financial losses caused by misuse of compromised information or reasonable financial consequences directly resulting from the relevant infringement, provided the necessary causal relationship can be demonstrated.
Compensation is not designed to create a financial windfall. Article 82 has a compensatory rather than punitive function.
The objective is to compensate the damage actually suffered.
Non-Material Damage
Non-material damage is especially important in data-breach litigation because a customer may suffer harm even where money has not immediately disappeared from an account.
EU jurisprudence recognizes that non-material damage is compensable and cannot be subjected to an artificial minimum-seriousness threshold.
At the same time, simply proving that a GDPR provision was infringed is insufficient. The claimant must establish damage caused by that infringement.
The Spanish Supreme Court has adopted this distinction. In Judgment 398/2024 of 19 March 2024, it explained, drawing on CJEU jurisprudence, that not every data-protection infringement automatically produces a right to damages; damage and causation must also exist.
Fear of Future Misuse
One difficult question arises where information has been stolen but has not yet been fraudulently used.
A person may nevertheless be concerned that criminals could misuse the information later.
European case law recognizes that the fear of possible future misuse can, in appropriate circumstances, constitute non-material damage. Courts must examine whether the claimed harm is actually established rather than merely presumed.
This is particularly significant for financial information because stolen identity or account-related information can remain relevant after the original security incident.
Liability for Cyberattacks by Third Parties
Banks frequently argue that hackers or other external criminals, rather than the institution, caused a breach.
The CJEU addressed this issue directly in Natsionalna agentsia za prihodite, Case C-340/21.
The Court held that unauthorized disclosure or access caused by a third party does not, by itself, release the controller from Article 82 liability. To obtain the relevant exemption, the controller must establish that it was in no way responsible for the event that caused the damage.
Therefore, a Spanish bank cannot automatically defeat a compensation claim simply by saying that an external hacker committed the attack.
Important Case Laws
1. Österreichische Post AG — CJEU, Case C-300/21
This is one of the foundational Article 82 GDPR compensation judgments.
The CJEU established that three cumulative requirements apply: infringement of the GDPR, damage suffered by the individual and a causal connection between the infringement and the damage.
The Court also rejected the idea that non-material damage must reach a predetermined minimum level of seriousness before compensation can become available.
Importance for Spain: Spanish courts applying Article 82 must follow these principles. A minor injury is not automatically excluded merely because it fails an artificial seriousness threshold, although actual damage still needs to be established.
2. Natsionalna agentsia za prihodite — CJEU, Case C-340/21
This case arose after a cyberattack resulted in personal information being published online.
The Court examined security obligations, responsibility for cyberattacks by third parties and compensation for non-material harm.
It held that a controller cannot escape responsibility merely because criminals caused the unauthorized disclosure. The controller must demonstrate the conditions necessary for exemption from liability.
Importance for Spanish banking: A cyberattack against a bank does not automatically prove that the bank breached the GDPR, but neither does the attack automatically absolve it. The adequacy of security measures and responsibility for the resulting harm must be examined.
3. JU and SO v Scalable Capital GmbH — CJEU, Joined Cases C-182/22 and C-189/22
These cases are particularly relevant to financial services because they concerned personal data stolen from an online securities-trading application.
The CJEU held that Article 82 compensation is exclusively compensatory. The seriousness or intentional nature of the infringement does not operate like punitive damages.
It also clarified that compensation for data theft is not restricted to situations where actual identity fraud subsequently occurs.
Importance: A Spanish financial customer does not necessarily need to wait until stolen information results in completed identity fraud before non-material damage can potentially be considered. Actual compensable harm must nevertheless be demonstrated.
4. MediaMarktSaturn — CJEU, Case C-687/21
This case further developed Article 82 principles concerning unauthorized access to personal information and compensation.
The CJEU maintained the distinction between an infringement and compensable damage and reinforced the compensatory character of Article 82.
Importance for banks: A procedural or security failure does not automatically determine the amount of compensation. Courts must focus on the harm actually suffered by the affected customer.
5. Krankenversicherung Nordrhein — CJEU, Case C-667/21
The Court considered Article 82 liability and compensation for unlawful processing.
It clarified aspects of responsibility under the GDPR and confirmed that Article 82 compensation is concerned with repairing the harm suffered rather than punishing the controller.
Importance: The degree of fault does not automatically determine the amount awarded for non-material damage. Compensation must correspond to the damage requiring reparation.
6. PS (Incorrect Address) — CJEU, Case C-590/22
This case concerned personal information being sent to an incorrect recipient.
The CJEU continued its Article 82 jurisprudence by emphasizing that infringement, damage and causation are distinct requirements.
Importance for Spanish banks: Accidental disclosure can potentially produce liability even without a sophisticated cyberattack. A banking data breach can result from operational mistakes as well as malicious hacking.
7. Spanish Supreme Court Judgment 398/2024 — 19 March 2024
This is an especially useful Spanish authority.
The Supreme Court distinguished the fundamental right to privacy from the broader right to personal-data protection. It also relied on the CJEU's Article 82 jurisprudence when considering compensation.
The Court stated that not every breach of personal-data legislation automatically creates a right to compensation. An infringement, actual damage and causation are required.
Importance: This judgment demonstrates the direct influence of CJEU compensation principles on Spanish judicial treatment of data-protection damages.
8. Scalable Capital — Compensation Quantification Principle
The joined Scalable Capital cases also established an important principle concerning the amount of damages.
The CJEU explained that non-material damage caused by a personal-data breach is not inherently less important than physical injury. Where actual damage is established but is limited in seriousness, a national court can award a relatively small amount, provided that amount fully compensates the particular damage suffered.
Importance: Spanish courts have discretion under national procedural rules when quantifying compensation, but EU principles of effectiveness and full compensation must be respected.
Data Breach Notification
Compensation should be distinguished from breach notification.
Under Article 33 GDPR, a controller must notify the competent supervisory authority of a qualifying personal-data breach unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The GDPR generally establishes a 72-hour notification framework once the controller becomes aware of a breach, where notification is required.
Article 34 separately deals with communication to affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
Failure to satisfy notification obligations may create regulatory consequences, but it does not automatically mean that every affected customer receives compensation.
Role of the AEPD
The Spanish Data Protection Agency (AEPD) is Spain's principal independent data-protection supervisory authority.
It can investigate alleged infringements, exercise corrective powers and impose administrative sanctions within the GDPR framework.
However, regulatory fines and customer compensation perform different functions.
An administrative fine is designed to enforce data-protection law. Article 82 compensation is designed to repair damage suffered by an individual.
A large regulatory penalty therefore does not automatically determine how much compensation a particular bank customer should receive.
Identity Theft and Financial Fraud
A financial data breach can increase the risk of identity-related misuse.
The CJEU in Scalable Capital clarified that "identity theft" for the particular GDPR analysis requires actual misuse of the affected person's identity by a third party. Nevertheless, Article 82 compensation for damage resulting from stolen personal information is not restricted exclusively to cases involving completed identity theft or fraud.
This distinction is significant.
A customer can potentially establish non-material damage before a criminal successfully obtains money in the customer's name, provided the legally required damage and causal relationship are proved.
Calculating Compensation
There is no automatic fixed amount payable for every banking data breach.
The amount depends upon the damage actually established in the individual case.
National courts apply domestic rules concerning assessment of damages while respecting the EU principles of equivalence and effectiveness.
The compensation must be capable of fully repairing the actual harm, but Article 82 is not a system of punitive damages.
Consequently, the seriousness of the bank's misconduct and the amount of the customer's compensable injury are conceptually different questions.
Relationship With Banking Cybersecurity Rules
A financial data breach may engage legal regimes beyond the GDPR.
Spanish banks operate within extensive EU prudential, cybersecurity and operational-resilience requirements. Depending on the institution and incident, banking supervision and the EU Digital Operational Resilience Act (DORA) may also be relevant.
However, violation of another financial-security requirement should not automatically be treated as proof of an Article 82 GDPR compensation claim.
The claimant must still satisfy the legal conditions applicable to the particular cause of action.
Practical Legal Structure of a Compensation Claim
A Spanish banking data-breach claim will therefore usually involve several questions.
First, the court determines whether the processing or security arrangements infringed applicable data-protection obligations.
Second, it considers whether the customer actually suffered material or non-material damage.
Third, the claimant must establish the necessary causal connection between the infringement and the claimed injury.
Finally, the court determines compensation under applicable national rules while respecting Article 82 and the CJEU's interpretation of full and effective compensation.
This structure prevents two opposite errors: assuming that every technical breach automatically generates damages, and assuming that only direct financial theft can qualify as compensable harm.
Conclusion
Financial data breach compensation in Spain is principally governed by Article 82 GDPR, the LOPDGDD, Spanish civil-law principles and binding CJEU interpretations of EU data-protection law.
Spanish banks must protect customer information through appropriate technical and organisational measures. If a breach occurs, external criminal involvement does not automatically absolve the institution, but the mere occurrence of a cyberattack does not automatically establish liability either.
The leading authorities—including Österreichische Post, Natsionalna agentsia za prihodite, Scalable Capital, MediaMarktSaturn, Krankenversicherung Nordrhein, PS (Incorrect Address), and Spanish Supreme Court Judgment 398/2024—establish the central compensation principles.
Most importantly, a successful Article 82 claim requires an infringement, actual material or non-material damage, and a causal relationship between them. Compensation is intended to provide full and effective reparation for proven harm, not to impose punitive damages on the bank.

comments