Banking Law And Innovation Finance Governance Spain .

Banking Law and Innovation Finance Governance in Spain

1. Introduction

Innovation finance governance in Spain refers to the legal, regulatory and institutional framework governing the use of new technologies, business models and financing methods within the banking and wider financial system.

It covers areas such as:

FinTech;

digital banking;

artificial intelligence in financial services;

automated credit assessment;

blockchain and distributed-ledger technology;

digital payments;

crowdfunding and alternative finance;

crypto-assets;

open banking;

RegTech and SupTech;

cloud outsourcing;

digital identification;

financial data governance; and

regulatory sandboxes.

Spain's approach is based on an important principle: financial innovation should be encouraged, but innovation does not eliminate requirements concerning financial stability, consumer protection, market integrity, cybersecurity, data protection and anti-money-laundering controls.

A particularly important Spanish statute is Law 7/2020 of 13 November on the Digital Transformation of the Financial System, which established Spain's regulatory sandbox for technology-based financial innovation.

2. Meaning of Innovation Finance Governance

Innovation finance governance is broader than simply regulating FinTech companies.

It asks how financial institutions, technology providers and regulators should govern innovation throughout its life cycle:

Idea → development → testing → regulatory assessment → authorisation where required → commercial deployment → continuous supervision.

Governance therefore involves both private and public institutions.

Within a bank, responsibility can involve:

the board of directors;

senior management;

risk management;

compliance;

internal audit;

cybersecurity;

data-protection functions;

technology departments; and

product-governance teams.

Externally, important Spanish and European authorities include the Banco de España, CNMV, Directorate-General for Insurance and Pension Funds, European Central Bank and European supervisory authorities.

3. Law 7/2020 and Spain's Financial Sandbox

Law 7/2020 is central to understanding Spain's innovation-finance framework.

The legislation created a controlled testing environment, normally described as a regulatory sandbox, in which sufficiently advanced technology-based financial innovations can be tested under supervisory oversight.

The statute defines technology-based financial innovation broadly enough to encompass new:

applications;

processes;

products;

services; and

business models

that affect financial markets, financial services or the exercise of financial public functions.

The purpose is not deregulation.

Instead, Spain created an environment where innovative projects can be studied and tested while regulators obtain better information about their risks and potential benefits.

4. The Three Foundations of the Spanish Sandbox

Law 7/2020 identifies three fundamental characteristics.

First – Controlled Environment

Testing takes place within defined boundaries so that potential risks can be mitigated.

Second – Supervisory Instrument

The sandbox enables regulators to understand technological developments and their implications for financial services, users and financial stability.

Third – Law-and-Protocol Model

The general framework comes from legislation, while the detailed conditions governing an individual experiment are established through a testing protocol agreed between the promoter and relevant supervisory authority.

This combination seeks to provide flexibility without abandoning legal accountability.

5. Sandbox Participation Is Not a Banking Licence

One of the most important principles is that admission to the sandbox does not automatically authorise an undertaking to conduct regulated banking or financial activities indefinitely.

Article 4 of Law 7/2020 makes clear that access to the controlled testing environment does not itself amount to authorisation to conduct a reserved activity or provide financial services indefinitely.

Therefore:

Sandbox admission ≠ banking licence.

A successful project that subsequently intends to conduct a regulated activity commercially must still satisfy the applicable authorisation requirements.

This distinction protects the regulated financial perimeter.

6. Access Requirements

A project seeking sandbox admission must represent technology-based financial innovation and be sufficiently advanced for testing.

The authorities examine whether the project can provide meaningful added value.

Relevant benefits can include:

improving regulatory compliance;

strengthening customer protection;

improving financial-service efficiency;

improving financial-service delivery; and

assisting financial supervision.

Authorities can also consider the project's potential impact on the Spanish financial system.

7. Governance of Innovation Risk

Innovation creates opportunities but also introduces risks.

Banks must therefore identify and govern risks associated with technologies such as AI, cloud computing, APIs and distributed systems.

Important risk categories include:

Operational risk

A technological system may malfunction or become unavailable.

Cybersecurity risk

Digital infrastructure may be attacked or compromised.

Model risk

Automated models may generate inaccurate or unreliable outputs.

Data risk

Information can be inaccurate, improperly processed or inadequately protected.

Consumer risk

Customers may not understand highly complex digital products.

Outsourcing risk

A bank may become heavily dependent upon external technology providers.

Concentration risk

Many financial institutions may depend upon the same infrastructure or technology provider.

Compliance risk

Innovation may accidentally circumvent existing regulatory requirements.

Governance must therefore evolve alongside technological development.

8. Consumer Protection

Innovation cannot be justified simply because a financial product is technologically advanced.

Spain's sandbox legislation specifically emphasises the importance of protecting financial-service users.

The legislative framework seeks to ensure that digital transformation does not undermine consumer protection, financial stability, market integrity or measures against financial crime.

Participants in sandbox tests must therefore receive appropriate safeguards.

The broader principle is:

Innovation should change how financial services are delivered, not eliminate fundamental legal protection.

9. Data Governance

Modern financial innovation depends heavily on data.

Banks may use data for:

credit scoring;

customer identification;

fraud detection;

transaction monitoring;

personalised financial products;

investment analysis;

risk modelling; and

automated decision-making.

This creates a relationship between banking law and the EU's data-protection framework, particularly the GDPR.

Banks must consider matters including:

lawful processing;

transparency;

data minimisation;

accuracy;

security;

retention;

automated decision-making; and

rights of data subjects.

Law 7/2020 expressly identifies personal-data protection as one of the sensitive public-policy objectives that must continue to be protected within the sandbox.

10. Artificial Intelligence in Banking

AI can be used in banking for:

creditworthiness assessment;

fraud detection;

anti-money-laundering monitoring;

customer service;

risk modelling;

portfolio management;

document processing; and

regulatory compliance.

However, governance becomes particularly important where AI influences decisions affecting customers.

A responsible governance framework should address:

Data → Model → Validation → Decision → Human oversight → Monitoring.

The relevant institution needs to know how the system performs, what risks it creates and who is accountable for its use.

EU-level AI regulation increasingly supplements traditional banking, data-protection and consumer-law requirements.

11. Open Banking and APIs

Open banking represents another major form of financial innovation.

With appropriate legal foundations and customer authorisation, banking information and payment functionality can be accessed through regulated interfaces.

This creates opportunities for:

account-information services;

payment initiation;

financial-management applications;

comparison services; and

innovative lending products.

However, it also generates governance questions involving:

authentication;

customer consent;

API security;

liability;

unauthorised transactions;

cybersecurity; and

third-party access.

Innovation governance therefore requires coordination between banks and non-bank technology providers.

12. Cloud Computing and Outsourcing

Modern banks increasingly depend on external technology infrastructure.

Cloud services can improve:

scalability;

computing capacity;

data processing;

service deployment; and

operational efficiency.

But outsourcing does not mean outsourcing legal responsibility.

Banks must maintain appropriate governance over outsourced functions.

Important considerations include:

due diligence;

contractual controls;

data location;

cybersecurity;

audit rights;

operational resilience;

business continuity;

subcontracting;

concentration risk; and

exit strategies.

This principle has become increasingly important under the EU digital-operational-resilience framework.

13. FinTech and Regulatory Perimeter

A central governance question is whether an innovative company is actually conducting a regulated activity.

A technology company might describe itself as a platform, software provider or FinTech business.

That description does not determine its legal position.

Regulators examine the substance of the activity.

Depending on its activities, an innovative business may fall within rules governing:

banking;

payment services;

electronic money;

investment services;

crowdfunding;

consumer credit;

insurance;

crypto-assets; or

other regulated financial activities.

Therefore, technological innovation does not automatically place a company outside financial regulation.

14. Case Law and Innovation Finance

There is not yet a large body of Spanish Supreme Court jurisprudence dealing specifically with Law 7/2020 sandbox projects.

That is understandable because the legislation is relatively recent and sandbox experimentation does not necessarily generate litigation.

The most useful case law therefore comes from broader Spanish and EU financial jurisprudence establishing principles that govern innovative financial products and technologies.

These cases concern:

regulatory perimeter;

technology-neutral consumer protection;

electronic payments;

digital contracts;

financial information;

innovative investment products; and

transparency.

The following authorities are particularly useful.

15. Case Law 1 – CJEU, Banco Español de Crédito, C-618/10

Banco Español de Crédito SA v Joaquín Calderón Camino, Judgment of 14 June 2012

Although this case preceded Spain's sandbox legislation, it established a fundamental principle relevant to innovative finance.

The CJEU emphasised effective consumer protection against unfair standard contractual terms.

Innovation-finance significance

Financial institutions cannot avoid established consumer protections merely because products are delivered through:

mobile applications;

automated systems;

online interfaces; or

new FinTech models.

The technology may change.

The underlying consumer-protection obligations remain.

16. Case Law 2 – CJEU, Content Services, C-49/11

Content Services Ltd v Bundesarbeitskammer, Judgment of 5 July 2012

This was not a Spanish-origin banking dispute, but it is an important EU authority for digital contracting.

The Court considered requirements for supplying consumer information in a durable medium in an online environment.

The judgment demonstrates that merely making information available through technological means does not necessarily satisfy every legal requirement concerning how information must be supplied and retained.

Banking relevance

Digital banks and FinTech platforms must ensure that mandatory information is provided in legally compliant forms.

A clickable interface cannot automatically substitute for legally required disclosure.

17. Case Law 3 – CJEU, UPC Magyarország, C-388/13

The Court considered misleading information supplied by a service provider and the application of EU unfair-commercial-practices legislation.

Its broader importance for innovative finance is that digitalisation does not weaken requirements concerning accurate customer communications.

An automated communication, online statement or digital interface can still generate legal consequences if customers receive misleading information.

Governance lesson

Banks should govern customer-facing technology as carefully as traditional human communications.

18. Case Law 4 – CJEU, Verein für Konsumenteninformation v Amazon EU, C-191/15

This case dealt with online consumer contracting, applicable law and data-protection-related questions.

Its importance extends beyond banking.

Digital financial services frequently operate across national borders.

A FinTech platform may:

be incorporated in one Member State;

use servers or providers elsewhere;

offer services online; and

have customers throughout the EU.

Governance significance

Digital delivery does not eliminate conflict-of-laws and consumer-protection requirements.

Financial innovators therefore need governance capable of handling cross-border regulatory obligations.

19. Case Law 5 – CJEU, Bundesverband v Deutsche Telekom, C-568/15

The judgment concerned consumer communications and charges associated with contacting traders.

Although not exclusively a banking case, it illustrates another technology-neutral consumer principle.

Businesses cannot use technological channels to undermine mandatory consumer rights.

For financial institutions, this principle applies broadly to the design of:

customer-support systems;

digital complaint procedures;

automated assistance;

telephone services; and

online servicing arrangements.

Innovation governance therefore extends beyond the financial product itself to the entire customer journey.

20. Case Law 6 – CJEU, DenizBank, C-287/19

DenizBank AG v Verein für Konsumenteninformation, Judgment of 11 November 2020

This is particularly relevant to digital banking.

The litigation concerned payment services and contactless functionality associated with bank cards.

The Court considered questions concerning payment instruments, contractual changes and liability under EU payment-services legislation.

Innovation-finance significance

The case demonstrates that technologically convenient payment mechanisms remain subject to detailed legal rules governing:

authorisation;

liability;

contractual information;

payment instruments; and

customer rights.

Technological simplicity from the user's perspective does not mean legal simplicity.

21. Case Law 7 – CJEU, Dietzinger, C-45/96

This older EU consumer-finance authority remains useful in understanding financial innovation because it illustrates that the classification of financial transactions depends upon legal substance rather than marketing terminology.

Modern innovative finance follows the same principle.

Calling something:

peer-to-peer finance;

embedded finance;

decentralised finance;

marketplace lending; or

digital investment

does not by itself determine which legal rules apply.

The transaction's substantive characteristics remain decisive.

22. Case Law 8 – Spanish Supreme Court, Judgment 241/2013

Tribunal Supremo, Sala Primera, Judgment 241/2013 of 9 May 2013

The judgment is famous for its treatment of mortgage floor clauses and contractual transparency.

Its relevance to financial innovation is broader.

The Supreme Court developed the idea that transparency is not satisfied merely because consumers can grammatically read contractual wording.

Consumers must be capable of understanding important economic consequences.

Digital-finance significance

The same principle becomes especially important where products are purchased through:

apps;

websites;

automated onboarding;

chat interfaces;

algorithmic recommendations; or

electronic contracts.

Digital efficiency cannot replace meaningful transparency.

23. Case Law 9 – CJEU, Gómez del Moral Guasch v Bankia, C-125/18

This Spanish reference concerned the IRPH mortgage interest-rate index.

The CJEU stressed the importance of transparency and the consumer's ability to understand the economic operation of a contractual mechanism.

Innovation relevance

Innovative financial products frequently use complex pricing algorithms, indices or automated calculations.

The broader lesson is that complexity does not automatically excuse inadequate explanation.

A consumer-facing innovation should be governed so that economically important mechanisms can be understood to the extent required by applicable law.

24. Case Law 10 – CJEU, Orange România, C-61/19

This case concerned consent and personal-data processing.

It is highly relevant to data-driven finance because digital financial services frequently depend on customer information.

The judgment reinforces the principle that organisations must be capable of demonstrating valid consent where consent is relied upon as the legal basis for processing.

Financial innovation significance

FinTech governance cannot treat customer consent as a simple checkbox exercise.

Consent, transparency and evidence of the customer's decision can become important legal questions.

25. Why These Cases Matter

These authorities do not all concern Spain's regulatory sandbox directly.

Instead, together they establish the broader legal boundaries within which Spanish financial innovation operates.

They demonstrate six major principles:

1. Technology neutrality
Legal obligations generally continue even when technology changes service delivery.

2. Effective consumer protection
Digitalisation cannot eliminate mandatory customer safeguards.

3. Transparency
Complex financial mechanisms must be explained in accordance with applicable disclosure requirements.

4. Data accountability
Innovation based on customer data remains subject to data-protection law.

5. Substance over labels
Calling a service “FinTech” does not determine whether it is regulated.

6. Accountability
A financial institution remains responsible for ensuring that technology is deployed within the applicable regulatory framework.

26. Regulatory Sandbox Governance Process

A simplified Spanish sandbox process can be represented as:

Step 1 – Innovative project

The promoter develops a technology-based financial innovation.

Step 2 – Application

The project seeks admission to the controlled testing environment.

Step 3 – Regulatory evaluation

Competent authorities determine whether statutory requirements are satisfied.

Step 4 – Testing protocol

The promoter and relevant supervisor establish the conditions under which testing will occur.

Step 5 – Safeguards

Participant protection, data protection and other required controls are established.

Step 6 – Controlled testing

The technology is tested within defined limits.

Step 7 – Supervisory learning

Authorities evaluate risks, benefits and regulatory implications.

Step 8 – Exit

The experiment ends according to the statutory framework and protocol.

Step 9 – Commercial authorisation

Where the resulting business constitutes a regulated activity, the appropriate authorisation must still be obtained.

Law 7/2020 specifically makes clear that sandbox participation itself does not provide indefinite authorisation for regulated financial activity.

27. Sandbox Participant Protection

Innovation experiments can involve real users.

Accordingly, governance cannot focus only on technological success.

The Spanish framework provides safeguards intended to maintain public-policy objectives, especially:

personal-data protection;

protection of financial-service users; and

prevention of money laundering and terrorist financing.

The broader regulatory philosophy is therefore controlled experimentation rather than uncontrolled deregulation.

28. Role of Banco de España

The Banco de España plays an important role where financial innovation concerns activities within its supervisory responsibilities.

Its broader responsibilities make technological governance relevant to:

banking supervision;

payment systems;

financial stability;

customer protection;

operational resilience; and

technological risk.

Innovation therefore changes supervisory methods as well as financial products.

This development is sometimes described as SupTech—the use of technology to improve supervisory activities.

29. Role of the CNMV

Where financial innovation concerns securities markets, investment services or other activities falling within securities supervision, the CNMV becomes particularly important.

Innovation can affect:

digital investment platforms;

automated investment services;

crowdfunding;

tokenised financial instruments;

algorithmic systems; and

online securities distribution.

The fundamental governance question remains whether technological innovation changes the underlying regulatory classification of the activity.

30. RegTech

RegTech means using technology to assist regulated institutions in complying with legal obligations.

Examples include systems for:

regulatory reporting;

customer verification;

transaction monitoring;

compliance surveillance;

fraud detection;

risk assessment;

document review; and

record management.

Law 7/2020 expressly recognises that technology can improve regulatory compliance and supervision.

However, automation does not transfer ultimate responsibility from the regulated institution to the software.

31. SupTech

SupTech refers to technologies used by supervisory authorities.

Potential applications include:

automated data analysis;

risk identification;

regulatory reporting analysis;

market surveillance; and

early-warning systems.

The Spanish sandbox is itself partly a supervisory-learning mechanism.

Law 7/2020 expressly describes the sandbox as an instrument through which supervisors can better understand technological transformation and its effects on financial services and protected interests.

32. Board Responsibility

Innovation governance should ultimately connect technological decisions with institutional accountability.

A bank cannot treat technology as a completely separate IT matter.

Material innovations can affect:

strategic risk;

operational risk;

credit risk;

legal risk;

compliance risk;

cybersecurity;

customer protection; and

reputation.

Therefore, important technological projects require appropriate management oversight and internal controls.

33. Governance Model

A useful governance model is:

Board / Senior Management

Innovation Strategy

Risk and Compliance Assessment

Technology Development

Legal and Data Review

Testing and Validation

Regulatory/Sandbox Interaction where appropriate

Deployment

Continuous Monitoring

Audit and Accountability

The objective is to prevent innovation from developing separately from the institution's legal and risk-management framework.

34. Innovation Versus Regulation

A common misconception is that regulation necessarily prevents financial innovation.

Spain's sandbox legislation adopts a different model.

The purpose is to create an environment in which regulators can understand new technologies while innovators can test sufficiently advanced projects under controlled conditions.

Law 7/2020 expressly seeks improvements in efficiency and service quality while maintaining security and protection against new technological financial risks.

Thus, the objective is:

Innovation + supervision + proportionality + consumer protection + financial stability.

35. Key Case-Law Summary

At least six important authorities relevant to innovation-finance governance are:

1. Banco Español de Crédito, C-618/10 (CJEU, 2012)
Consumer-protection requirements remain effective in financial contracts.

2. Content Services, C-49/11 (CJEU, 2012)
Important principles concerning digital disclosure and durable-medium requirements.

3. Spanish Supreme Court Judgment 241/2013 (9 May 2013)
Material transparency in banking contracts.

4. Verein für Konsumenteninformation v Amazon EU, C-191/15 (CJEU, 2016)
Important principles concerning cross-border online consumer contracting.

5. DenizBank, C-287/19 (CJEU, 2020)
Payment-services rules applied to innovative contactless payment functionality.

6. Gómez del Moral Guasch v Bankia, C-125/18 (CJEU, 2020)
Transparency and consumer understanding of financial pricing mechanisms.

7. Orange România, C-61/19 (CJEU, 2020)
Important principles concerning demonstrable consent in data processing.

8. UPC Magyarország, C-388/13 (CJEU, 2015)
Customer communications and misleading commercial information.

These cases should be understood as the wider jurisprudential framework governing financial innovation rather than as cases directly interpreting Spain's Law 7/2020 sandbox.

36. Practical Example

Suppose a Spanish bank develops an AI system that evaluates small-business credit applications.

The bank should not simply deploy the system because it produces decisions faster.

Governance would involve examining:

Legality: Is the lending activity conducted within the appropriate regulatory framework?

Data: Is customer information processed lawfully?

Model risk: Is the AI sufficiently accurate and reliable?

Customer protection: Can legally required explanations and information be provided?

Cybersecurity: Is sensitive financial information protected?

Human oversight: Who can review problematic decisions?

Outsourcing: Does an external AI provider create additional dependencies?

Monitoring: Will the bank detect deterioration or unexpected behaviour after deployment?

If the technology represents a sufficiently advanced qualifying innovation, controlled testing under Spain's sandbox framework may potentially be relevant.

But admission to the sandbox would not itself grant a permanent banking authorisation.

37. Importance of Proportionality

Innovation regulation must also consider proportionality.

A small experimental project does not necessarily create the same systemic risk as a nationwide banking platform.

Law 7/2020 therefore incorporates proportionality into the broader framework and envisages regulatory learning from sandbox experience.

However, proportionality does not mean eliminating essential protections.

The level and form of regulation may respond to risk, while fundamental requirements continue to apply.

38. Regulatory Coordination

Financial innovation frequently crosses traditional regulatory boundaries.

One project could simultaneously involve:

banking;

payments;

investment services;

personal data;

cybersecurity; and

consumer protection.

Law 7/2020 therefore emphasises cooperation and coordination among relevant public authorities without fundamentally reallocating their statutory competencies.

This is particularly important for hybrid FinTech products that cannot easily be placed within a single traditional financial category.

39. Future Importance

Innovation-finance governance is likely to remain increasingly important because banking is becoming more dependent upon:

AI;

cloud infrastructure;

real-time payments;

APIs;

digital identity;

automated compliance;

data analytics;

tokenisation; and

distributed financial infrastructure.

The regulatory question is therefore shifting from simply whether technology can perform a financial function toward how that technology should be governed safely, transparently and accountably.

40. Conclusion

Banking law and innovation-finance governance in Spain represents the intersection of banking regulation, FinTech, consumer protection, data governance, cybersecurity, payments regulation and EU financial law.

The cornerstone of Spain's specific innovation framework is Law 7/2020 on the Digital Transformation of the Financial System, which created a controlled regulatory sandbox for sufficiently developed technology-based financial innovations. The sandbox is designed simultaneously as a safe testing environment and a supervisory-learning mechanism.

Crucially, Spain has not adopted the principle that innovation should operate outside financial regulation. Admission to the sandbox does not itself provide permanent authorisation to conduct regulated financial activities.

The wider jurisprudence—including Banco Español de Crédito, Content Services, Supreme Court Judgment 241/2013, Gómez del Moral Guasch, DenizBank and Orange România—shows that technological development must coexist with established principles concerning transparency, consumer protection, data accountability and effective financial regulation.

The overall Spanish model can therefore be expressed as:

Financial innovation → controlled experimentation → regulatory supervision → risk governance → consumer protection → appropriate authorisation → responsible market deployment.

Innovation is encouraged, but the governance structure seeks to ensure that greater technological efficiency does not come at the expense of financial stability, customer rights, market integrity, data protection or institutional accountability.

LEAVE A COMMENT