Banking Law And Information Security Duties Spain .
Banking Law and Information Security Duties in Spain
1. Introduction
Information security is a fundamental legal obligation for banks operating in Spain.
Modern banks hold enormous quantities of sensitive information, including:
customer identification data;
bank-account details;
transaction histories;
credit information;
payment credentials;
investment information;
authentication data;
employee information; and
confidential commercial information.
Banks also depend heavily on online banking, mobile applications, payment networks, cloud services, automated decision-making systems and external technology providers.
A security failure can therefore affect not only individual customers but also the operational stability of the financial system.
Information-security duties in Spain arise from several overlapping legal regimes, particularly:
Law 10/2014 on the organisation, supervision and solvency of credit institutions;
Real Decreto-ley 19/2018 on payment services;
the General Data Protection Regulation (GDPR);
Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights;
the EU Digital Operational Resilience Act (DORA);
banking secrecy and confidentiality principles;
European banking supervisory requirements; and
cybersecurity and operational-resilience rules.
The central principle is that information security is not merely an IT issue. It is a legal, governance and risk-management obligation.
2. Meaning of Information Security
Information security traditionally rests on three principal objectives.
Confidentiality
Information should be accessible only to authorized persons.
For example, one customer should not be able to see another customer's banking information.
Integrity
Information should remain accurate and protected against unauthorized modification.
A criminal or unauthorized employee should not be able to alter:
account balances;
payment instructions;
credit records; or
customer identities.
Availability
Banking information and systems should remain available when legitimately required.
A cyberattack that prevents customers from accessing their accounts can therefore create an information-security problem even where no customer information is stolen.
Modern banking security also involves:
authenticity;
accountability;
traceability; and
operational resilience.
3. Banking Governance and Information Security
Spanish credit institutions must maintain appropriate governance and internal-control arrangements.
Information-security risk therefore forms part of the broader governance responsibilities of the institution.
The board and senior management should ensure that appropriate arrangements exist for:
cybersecurity;
access control;
operational resilience;
incident management;
outsourcing;
data protection;
fraud prevention;
business continuity; and
disaster recovery.
Cybersecurity cannot be delegated completely to the bank's IT department.
Senior management must understand material technological risks and ensure that adequate controls exist.
4. GDPR Security Obligations
Banks process large quantities of personal data and are therefore subject to the GDPR.
Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures having regard to matters including:
the state of the art;
implementation costs;
nature and scope of processing;
context and purposes of processing; and
risks to individuals.
Depending upon the risk, relevant measures can include:
encryption;
pseudonymisation;
confidentiality controls;
integrity protections;
availability controls;
resilience;
restoration capabilities;
regular testing; and
evaluation of security measures.
The legal standard is therefore fundamentally risk based.
Not every bank must use identical technical measures, but every institution must establish measures appropriate to its risks.
5. Spanish Data-Protection Law
Organic Law 3/2018 supplements the GDPR within Spain.
Spanish banks must therefore combine European data-protection requirements with domestic rules.
Banks should ensure that customer information is:
processed lawfully;
protected against unauthorized access;
used only for legitimate purposes;
retained appropriately;
disclosed only where legally permitted; and
securely deleted when retention is no longer justified.
The existence of a confidentiality obligation alone is insufficient.
Banks need technological and organizational measures capable of making confidentiality effective.
6. Access Control
One of the most important information-security duties is access management.
Employees should not automatically receive access to every banking database.
Instead, banks should apply the principle of least privilege.
This means that an employee should normally receive only the access necessary for the employee's legitimate duties.
For example:
A mortgage employee may need access to mortgage records.
That does not automatically mean the employee should have unrestricted access to every customer's investment information.
Similarly, system administrators may require powerful technical privileges, but their activity should be monitored carefully.
7. Authentication
Authentication determines whether a person attempting to access a system is genuinely the authorized user.
Spanish payment law contains particularly important authentication requirements.
Real Decreto-ley 19/2018 requires strong customer authentication in specified circumstances, including where a payer:
accesses a payment account online;
initiates an electronic payment; or
remotely performs an action involving payment-fraud or abuse risk.
For remote electronic payments, the authentication process must, where applicable, dynamically link the authorization to the particular amount and beneficiary.
Payment providers must also protect the confidentiality and integrity of personalized security credentials.
8. Strong Customer Authentication
Strong Customer Authentication generally uses independent elements from different authentication categories.
The purpose is to ensure that compromise of one element does not necessarily compromise the entire authentication process.
In banking practice, authentication mechanisms can involve appropriately designed combinations of:
knowledge elements;
possession elements; and
inherence elements.
The exact mechanism depends upon the applicable legal and technical requirements.
Strong authentication is especially important for:
online banking;
mobile banking;
electronic transfers;
payment initiation; and
sensitive account actions.
9. Payment Data Security
Payment information requires particularly strong protection.
Real Decreto-ley 19/2018 defines sensitive payment data to include information, including personalized security credentials, capable of being used to commit fraud.
Payment service providers must maintain appropriate measures to protect such information.
Security obligations therefore apply not only to traditional banks but also, where relevant, to payment institutions and providers participating in open-banking services.
10. Operational and Security Risk Management
Article 66 of Real Decreto-ley 19/2018 expressly requires payment service providers to establish a framework containing appropriate mitigation measures and control mechanisms for operational and security risks.
The framework must include effective incident-management procedures.
Providers must be capable of:
detecting incidents;
classifying incidents;
responding to serious incidents;
assessing operational risks; and
evaluating whether existing controls remain adequate.
Providers must also submit updated assessments concerning operational and security risks to the Banco de España in accordance with the applicable framework.
This turns cybersecurity risk assessment into a regulatory responsibility rather than a voluntary business practice.
11. Security Incident Reporting
Article 67 of Real Decreto-ley 19/2018 requires serious operational or security incidents to be notified to the Banco de España.
Where a security incident affects or could affect users' financial interests, providers must also inform affected users without undue delay and communicate available mitigation measures.
The Banco de España can subsequently communicate relevant information to European authorities.
The legislation also requires statistical information concerning payment fraud.
Therefore, serious security incidents cannot simply be handled privately by a bank's technology department.
They can create formal regulatory-reporting obligations.
12. Personal Data Breaches
A cyber incident can also constitute a personal-data breach.
Examples include:
unauthorized disclosure of customer records;
stolen databases;
compromised customer credentials;
accidental disclosure;
ransomware affecting personal information;
unauthorized employee access; or
loss of customer information.
Under the GDPR, a qualifying personal-data breach may have to be reported to the competent data-protection authority within the applicable statutory timeframe.
Where the breach is likely to create a high risk to affected individuals, communication to those individuals may also be required, subject to the GDPR's rules and exceptions.
A single banking cyber incident can therefore create several parallel reporting duties.
13. DORA and Banking Cyber Resilience
The Digital Operational Resilience Act (DORA) has become central to information-security governance within EU financial institutions, including relevant Spanish banks.
DORA has applied since 17 January 2025.
It establishes a harmonized framework covering information and communication technology risk within the financial sector.
Its major areas include:
ICT risk management;
ICT incident management and reporting;
digital operational-resilience testing;
management of ICT third-party risk;
information-sharing arrangements; and
oversight of critical ICT third-party providers.
For Spanish banks, DORA means that cyber resilience must be managed systematically across the institution.
14. ICT Risk Management
Banks should maintain an ICT risk-management framework capable of identifying and controlling technological risks.
The framework should address matters such as:
systems;
networks;
software;
information assets;
dependencies;
cyber threats;
vulnerabilities;
recovery arrangements; and
third-party providers.
Risk assessment should not occur only after a cyberattack.
It should be continuous.
Banks should understand which systems are critical and what would happen if those systems became unavailable.
15. Business Continuity
Information security includes availability.
Banks therefore require business-continuity arrangements.
These arrangements should address situations such as:
data-centre failure;
network outage;
cyberattack;
software failure;
telecommunications disruption; and
third-party technology failure.
A continuity plan should explain how critical banking functions can continue or recover.
Recovery procedures should also be tested.
A plan existing only on paper provides limited protection.
16. Backup and Restoration
Banks should maintain appropriate backup arrangements.
However, simply having backups is insufficient.
The institution should consider:
whether backups are complete;
whether they are protected;
whether attackers can modify them;
how quickly they can be restored; and
whether restoration has actually been tested.
This becomes particularly important in ransomware and destructive cyber incidents.
The GDPR itself refers to the ability to restore availability and access to personal data following physical or technical incidents.
17. Encryption
Encryption can substantially reduce information-security risk.
Banks may use encryption to protect:
stored customer data;
communications;
backups;
payment information;
mobile banking; and
information transmitted between systems.
Encryption does not eliminate every risk.
Key management, authentication and endpoint security remain important.
Nevertheless, encryption is expressly recognized within the GDPR's security framework as one potentially appropriate security measure.
18. Employee Security
Employees represent both an essential part of security and a potential source of risk.
Information-security duties should therefore include:
employee training;
confidentiality obligations;
access restrictions;
authentication controls;
monitoring of privileged accounts;
segregation of duties;
incident reporting; and
access termination when employment ends.
A bank should also protect against insider threats.
An employee with legitimate access can still misuse that access.
19. Outsourcing and Cloud Services
Spanish banks increasingly rely on external technology providers.
Services can include:
cloud hosting;
cybersecurity;
payment processing;
data analytics;
software platforms;
customer identification; and
artificial intelligence.
Outsourcing does not automatically transfer the bank's regulatory responsibility to the technology provider.
Banks must manage third-party ICT risk.
Important considerations include:
due diligence;
contractual security requirements;
audit rights;
incident notification;
data location;
subcontracting;
continuity arrangements; and
exit strategies.
DORA gives particular importance to ICT third-party risk.
20. Security by Design
Information security should be considered while a banking product is being developed.
For example, when designing a new mobile banking application, the bank should consider from the beginning:
authentication;
encryption;
session management;
access controls;
secure communications;
transaction monitoring;
privacy;
logging;
fraud prevention; and
incident response.
Trying to add security only after the product has been launched is considerably less effective.
21. Logging and Audit Trails
Banks need reliable records showing important activities within their systems.
Logs can help determine:
who accessed information;
when access occurred;
what was changed;
which payment was authorized;
which device was used;
whether security alerts occurred; and
what happened during an incident.
Audit trails are therefore important for both prevention and investigation.
However, logs themselves contain sensitive information and must also be protected against unauthorized access and manipulation.
22. Case Law
There is no single body of Spanish jurisprudence titled "banking information-security cases." The legal principles come from Spanish-origin cases and CJEU judgments interpreting EU data-protection and financial rules applicable to Spanish banks.
Case 1 — Google Spain SL and Google Inc. v AEPD and Mario Costeja González
Case C-131/12, CJEU, 13 May 2014
This landmark case originated from Spain.
The Court considered the responsibilities of an organization processing personal information through digital systems.
It recognized the operator's responsibilities as a controller and emphasized the significance of rights relating to personal-data processing.
Importance for Banks
Although the case concerned a search engine rather than a bank, the accountability principle is highly relevant.
Banks cannot treat automated processing of customer information as legally neutral merely because technology performs the operation.
An institution controlling personal-data processing must identify its legal responsibilities.
For banks, this affects:
customer databases;
transaction records;
credit information;
automated systems; and
digital banking platforms.
Case 2 — Natsionalna agentsia za prihodite
Case C-340/21, CJEU, 14 December 2023
This is one of the most important European cybersecurity judgments.
A cyberattack against the Bulgarian National Revenue Agency resulted in personal information concerning millions of individuals being published online.
The Court considered whether the fact that hackers successfully accessed information automatically demonstrated that the controller's security measures were inappropriate.
The Court held, in substance, that unauthorized disclosure resulting from a cyberattack does not by itself automatically establish that the controller's technical and organizational measures were inappropriate.
The appropriateness of the measures must be assessed concretely.
The Court also recognized that fear of possible future misuse of personal information can potentially constitute non-material damage under the GDPR.
Importance for Spanish Banks
This judgment is directly relevant to cyberattacks against banks.
A successful attack does not automatically prove regulatory negligence.
However, the bank must be capable of demonstrating that its security measures were appropriate to the risk.
This makes documentation, risk assessments and security testing extremely important.
Case 3 — Österreichische Post AG
Case C-300/21, CJEU, 4 May 2023
The Court considered compensation for GDPR violations.
It held that a GDPR infringement alone does not automatically create a right to compensation.
Three elements are required:
infringement;
damage; and
a causal connection between them.
At the same time, non-material damage cannot be made dependent upon a nationally imposed minimum seriousness threshold.
Banking Importance
Following a banking information-security incident, regulatory infringement and customer compensation are separate legal questions.
A customer seeking compensation under Article 82 GDPR must establish the legally required elements.
This distinction is important when banks assess liability following data breaches.
Case 4 — MediaMarktSaturn
Case C-687/21, CJEU, 25 January 2024
This case concerned personal documents accidentally handed to an unauthorized third person.
The Court considered questions involving unauthorized disclosure and compensation under the GDPR.
Importance for Banks
Not every information-security incident involves sophisticated hackers.
A simple organizational error can disclose sensitive information.
Banks must therefore protect customer information against:
cyberattacks;
employee mistakes;
incorrect communications;
unauthorized physical disclosure; and
administrative errors.
Information security is consequently both technical and organizational.
Case 5 — Schrems II
Case C-311/18, CJEU, 16 July 2020
The Court examined international transfers of personal information and invalidated the EU-US Privacy Shield adequacy mechanism then in force.
It also considered safeguards required when personal information is transferred internationally using standard contractual clauses.
Importance for Spanish Banks
Spanish banks increasingly use multinational technology and cloud providers.
Customer information may therefore be processed across jurisdictions.
Banks cannot assume that signing a technology contract automatically satisfies data-protection requirements.
They must assess the legal framework governing relevant international data transfers and implement appropriate safeguards where required.
Case 6 — SCHUFA Holding (Scoring)
Case C-634/21, CJEU, 7 December 2023
The case concerned automated credit scoring.
The Court examined a system generating a probability value concerning an individual's ability to meet future payment obligations where that score played an important role in decisions taken by financial institutions.
The judgment interpreted Article 22 GDPR concerning automated individual decision-making.
Importance for Banking Information Security
Credit scoring requires large quantities of sensitive information.
Banks using automated credit systems must consider both:
security of the underlying information; and
lawful governance of automated decision-making.
An information-security programme therefore cannot focus only on preventing theft.
It must also control who can access, modify and use data within automated models.
Case 7 — Digital Rights Ireland
Joined Cases C-293/12 and C-594/12, CJEU, 8 April 2014
The Court examined extensive retention of communications information.
It emphasized the serious interference with privacy and data-protection rights created by broad retention and access to personal information.
Importance for Banks
Banks possess extensive transaction and behavioural information.
Security obligations should therefore operate alongside proper retention policies.
Information should not simply be stored indefinitely because storage is technologically possible.
Banks need appropriate:
retention periods;
access controls;
deletion procedures;
legal justifications; and
security protections.
23. Lessons from the Case Law
These cases establish several important principles.
Security Is Risk Based
Natsionalna agentsia za prihodite demonstrates that security measures must be assessed according to their appropriateness in the circumstances.
A Cyberattack Does Not Automatically Prove Negligence
Successful unauthorized access is important evidence but does not automatically establish that the controller violated its security duties.
Organizations Must Demonstrate Compliance
Banks should document risk assessments, security controls and testing.
Security Includes Human Error
MediaMarktSaturn demonstrates that unauthorized disclosure can result from ordinary organizational mistakes.
Compensation Requires Damage
Österreichische Post confirms that infringement, damage and causation are separate requirements for GDPR compensation.
International Processing Creates Additional Risk
Schrems II demonstrates that transferring information internationally can require additional legal safeguards.
Automated Systems Need Governance
SCHUFA demonstrates the importance of controlling automated processing used in financial decision-making.
24. Incident Response
When a serious security incident occurs, the bank should activate an organized response.
A typical legal and operational process includes:
Step 1 — Detection
Identify suspicious activity.
Step 2 — Containment
Prevent further unauthorized access or damage.
Step 3 — Investigation
Determine what happened and what systems and information were affected.
Step 4 — Risk Assessment
Assess consequences for customers, operations and the financial system.
Step 5 — Regulatory Analysis
Determine which notification obligations apply.
Step 6 — Customer Communication
Inform customers where legally required.
Step 7 — Recovery
Restore secure services.
Step 8 — Remediation
Correct vulnerabilities and improve controls.
Step 9 — Documentation
Preserve evidence of the incident and institutional response.
This documentation can become highly important if regulators or courts later examine whether the bank's security measures were appropriate.
25. Security Testing
Banks should regularly test their security arrangements.
Testing can include appropriately controlled:
vulnerability assessments;
security reviews;
recovery tests;
business-continuity exercises;
access-control reviews; and
resilience testing.
DORA places increased emphasis on digital operational-resilience testing.
Testing allows weaknesses to be discovered before a real incident exposes them.
26. Information Security and Artificial Intelligence
Artificial intelligence creates additional information-security challenges.
Banking AI systems may process:
customer financial histories;
payment behaviour;
credit information;
fraud indicators; and
identification information.
Banks therefore need to protect:
training data;
model inputs;
model outputs;
access credentials;
AI infrastructure; and
connected databases.
Unauthorized manipulation of a model can potentially be as serious as theft of information.
Information integrity is therefore particularly important in AI-based banking.
27. Relationship with Bank Secrecy
Banking confidentiality and cybersecurity overlap but are not identical.
Banking confidentiality determines whether information may legally be disclosed.
Information security determines how that information is protected from unauthorized disclosure, alteration or destruction.
For example:
A bank may have a legal duty not to disclose a customer's account information.
Encryption and access controls are technological mechanisms that help the bank satisfy that duty.
Legal confidentiality therefore requires practical security controls.
28. Board Responsibility
Information security should reach the highest levels of bank governance.
The board should ensure that the institution has adequate arrangements concerning:
ICT risk;
cybersecurity;
operational resilience;
incident management;
third-party risk;
business continuity; and
internal controls.
Directors do not need personally to perform technical cybersecurity operations.
However, governance arrangements should ensure that material information-security risks are identified, reported and appropriately managed.
29. Role of Banco de España
The Banco de España has important supervisory responsibilities concerning Spanish banks and payment-service providers.
For payment services, Spanish legislation expressly requires providers to maintain operational and security risk-management frameworks and report serious incidents to the Banco de España.
The Banco de España also cooperates with relevant European institutions and authorities.
Information-security failures can therefore become prudential and supervisory matters, rather than remaining merely private disputes between banks and customers.
30. Practical Example
Suppose attackers compromise a Spanish bank's online platform and obtain customer information.
Several legal questions immediately arise.
Question 1: Were the bank's technical and organizational security measures appropriate?
Question 2: What categories of information were compromised?
Question 3: Does the incident constitute a GDPR personal-data breach?
Question 4: Must the AEPD be notified?
Question 5: Must affected customers be informed?
Question 6: Does the incident trigger banking or payment-sector reporting requirements?
Question 7: Does DORA require incident reporting or other action?
Question 8: Did customers suffer legally compensable damage?
Question 9: Did an external ICT provider contribute to the incident?
Question 10: What corrective action must the bank implement?
The same cyberattack can therefore engage banking, payment, privacy, cybersecurity and civil-liability rules simultaneously.
31. Core Information-Security Duties
For practical purposes, the principal duties of a Spanish bank can be summarized as follows:
identify information-security risks;
maintain appropriate technical controls;
maintain appropriate organizational controls;
protect customer confidentiality;
protect the integrity of banking information;
maintain system availability and resilience;
use appropriate authentication;
protect payment credentials;
manage employee access;
manage third-party ICT risk;
detect security incidents;
report qualifying incidents;
maintain business-continuity arrangements;
test security and recovery systems;
document security decisions; and
continuously review whether existing controls remain appropriate.
Conclusion
Information-security duties are a central component of modern banking law in Spain.
Spanish banks are required to protect customer information and banking systems through a combination of banking governance, GDPR security requirements, Spanish data-protection legislation, payment-security obligations and the EU Digital Operational Resilience Act (DORA).
Real Decreto-ley 19/2018 is particularly important for payment services because it requires payment providers to maintain operational and security risk-management frameworks, establish effective incident-management procedures, report serious incidents and use strong customer authentication in specified circumstances.
The relevant jurisprudence further explains these duties. Google Spain (C-131/12) demonstrates organizational responsibility for personal-data processing. Natsionalna agentsia za prihodite (C-340/21) provides particularly important guidance concerning cybersecurity measures and data breaches. Österreichische Post (C-300/21) explains the requirements for GDPR compensation. MediaMarktSaturn (C-687/21) demonstrates that information-security failures can result from organizational mistakes as well as cyberattacks. Schrems II (C-311/18) addresses safeguards for international data transfers. SCHUFA Holding (C-634/21) concerns automated credit processing. Digital Rights Ireland (Joined Cases C-293/12 and C-594/12) illustrates the fundamental-rights implications of large-scale data retention.
The central legal principle is that a Spanish bank must be capable not only of protecting information but also of demonstrating that its security measures are appropriate to the risks it faces.
Information security should therefore be treated as a continuous governance process involving prevention, detection, response, recovery, documentation and improvement—not merely as a technical function performed by the IT department.

comments