Banking Law And Space-Based Payment Networks Spain .

Banking Law and Space-Based Payment Networks in Spain

1. Introduction

Space-based payment networks are payment systems that use satellites or other space infrastructure for communication, authentication, data transmission, positioning, or connectivity. Examples may include satellite-supported card terminals, satellite internet used for online banking, payment services operating in remote locations, and future financial networks in which satellites form an important part of the communications infrastructure.

Spain does not currently have a separate banking statute specifically governing “space-based payment networks.” Instead, such a network would sit at the intersection of Spanish and European Union banking, payment-services, cybersecurity, telecommunications, data-protection, operational-resilience, and space law.

The main legal question is therefore not whether a payment travels through space, but who provides the regulated financial service, where that service is provided, how customer funds and data are protected, and how operational risks are controlled.

2. Main Regulatory Framework

Spain's principal banking supervisor is the Banco de España. Depending on the institution and activity, the European Central Bank and other EU authorities can also have important roles.

A Spanish space-supported payment system may fall within several overlapping legal regimes.

The most important payment legislation includes Spain's Royal Decree-Law 19/2018 on payment services and other urgent financial measures, which implemented much of the EU PSD2 framework into Spanish law.

It is supplemented by EU payment-services legislation and technical standards dealing with matters such as authorization, payment execution, customer protection, authentication and security.

If the operator accepts deposits or conducts banking business, Spanish banking legislation and the EU prudential framework become relevant as well.

3. Authorization of Payment Providers

Using satellites does not remove the authorization requirement for financial services.

Suppose a company establishes a satellite network that allows customers in Spain to send money through satellite-connected terminals. If the company itself provides regulated payment services, it may have to qualify as a:

credit institution;

payment institution;

electronic-money institution; or

another appropriately authorized payment-service provider.

The precise classification depends on the activities undertaken rather than the technology used.

A satellite telecommunications company merely carrying encrypted payment information would not automatically become a bank. However, if that company begins holding customer money, executing payment transactions or issuing electronic money, financial regulation can become directly applicable.

4. Satellite Infrastructure as Outsourced Banking Infrastructure

A particularly important issue is outsourcing.

Banks increasingly depend on external communications, cloud and technology providers. A satellite operator could similarly provide critical connectivity between payment terminals and a bank's processing infrastructure.

The bank cannot normally escape its regulatory responsibilities merely because an external satellite company performs part of the technological function.

The regulated institution must therefore assess matters such as operational risk, availability, cybersecurity, subcontracting, concentration risk, audit rights, business continuity and exit arrangements.

This principle becomes particularly significant where an entire payment service depends upon one satellite constellation.

5. DORA and Operational Resilience

The EU Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has major importance for modern payment networks.

DORA establishes requirements concerning ICT risk management, incident reporting, resilience testing and third-party ICT risk.

For a satellite-dependent Spanish payment network, relevant risks could include:

satellite communication failure, ground-station outages, cyberattacks, software failures, loss of connectivity and failures affecting third-party technology providers.

A bank using satellite infrastructure must therefore design its payment architecture so that a technological disruption does not automatically create an uncontrolled financial disruption.

Business-continuity arrangements and alternative communication channels can consequently become important.

6. Strong Customer Authentication

Space transmission does not eliminate payment-security requirements.

Under the PSD2-derived framework, strong customer authentication (SCA) generally requires authentication based on independent elements drawn from categories such as knowledge, possession and inherence, subject to applicable exemptions.

A satellite-connected payment terminal must therefore provide security comparable to other regulated payment channels.

For remote electronic payments, authentication requirements and protection against payment fraud remain particularly important.

A satellite link is essentially part of the communications architecture; it does not replace the legal obligation to authenticate the customer appropriately.

7. Liability for Unauthorized Payments

A difficult problem arises when a satellite-supported transaction is disputed.

Imagine that a customer makes a payment through a satellite terminal and later argues that the transaction was unauthorized.

The payment-services framework contains rules concerning notification, authentication, evidence and allocation of losses resulting from unauthorized payment transactions.

A payment provider therefore needs reliable records showing matters such as authentication and transaction processing.

Satellite systems should accordingly preserve sufficiently reliable and legally usable transaction records.

The existence of technically sophisticated infrastructure does not automatically establish that the customer authorized the transaction.

8. Data Protection and International Satellite Networks

Space-based payment systems may process large quantities of personal information, including:

customer identity information, account identifiers, transaction information, device information and potentially location-related data.

The General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights therefore become relevant.

The network must address lawful processing, security, transparency, data minimization, retention and international transfers.

This can become particularly complicated where ground stations, processing centers and service providers operate in different countries.

The fact that information travels through a satellite does not place that information outside European data-protection law.

9. Cybersecurity

Payment networks are attractive targets for cybercrime.

Space-based systems introduce additional infrastructure, including satellites, ground stations, gateways, terminals and control systems.

A security incident affecting any important component could disrupt payment availability or compromise information.

Banks and payment institutions therefore have to combine payment-security obligations with the broader EU operational-resilience and cybersecurity environment.

Security responsibilities should also be allocated clearly between the financial institution and satellite/technology provider.

10. Anti-Money-Laundering Requirements

Satellite payments could eventually make financial services accessible in areas where ordinary terrestrial communications are unreliable.

That accessibility does not weaken anti-money-laundering obligations.

Regulated institutions remain responsible for relevant customer due diligence, transaction monitoring, suspicious-activity controls and sanctions compliance.

Satellite infrastructure therefore cannot lawfully be treated as an anonymous alternative to the regulated banking system.

11. Interaction with Spanish Space Law

Where the payment provider also owns or operates space infrastructure, an additional legal layer arises.

Spain participates in the principal international space-law framework, including the Outer Space Treaty and Liability Convention.

Domestic authorization and administrative requirements concerning space activities, spectrum and telecommunications can also become relevant depending on the particular system.

This creates two legally distinct layers:

financial regulation governs the payment activity, while space and telecommunications regulation governs important aspects of the infrastructure.

A business conducting both functions may therefore require multiple regulatory approvals.

12. Competition Issues

Satellite payment networks may also raise competition-law concerns.

For example, a dominant satellite connectivity provider could potentially control an important gateway through which financial institutions reach customers in isolated areas.

Exclusive contracts, discriminatory access, tying practices or exclusionary pricing could attract scrutiny under Articles 101 and 102 TFEU and Spanish competition legislation.

Interoperability may consequently become an important regulatory consideration if satellite payment infrastructure develops into an essential part of European payments.

Relevant Case Law

Because dedicated Spanish litigation specifically concerning space-based payment networks is not yet a developed body of case law, the most useful authorities come from adjacent fields. These decisions should therefore be treated as analogical authorities, not as judgments directly deciding satellite-payment disputes.

1. CJEU, C-191/17, Bundeskammer für Arbeiter und Angestellte v ING-DiBa Direktbank Austria

The Court examined the meaning of a payment account under EU payment-services legislation.

The judgment demonstrates that regulatory classification depends substantially on the function of the financial product, rather than the technological label attached to it.

For space-based networks, the same reasoning suggests that calling a system a “satellite platform” does not prevent it from being legally classified as a payment service where its actual functions satisfy the statutory requirements.

2. CJEU, C-295/18, Verein für Konsumenteninformation v DenizBank AG

This case concerned payment services and contactless functionality.

It is useful because it illustrates how payment law applies to new technological methods of initiating transactions rather than creating a regulatory vacuum whenever payment technology changes.

The principle is directly relevant by analogy to satellite-enabled payment technology.

3. CJEU, C-287/19, DenizBank AG v Verein für Konsumenteninformation

The judgment considered issues concerning contactless payments, payment instruments and liability within the PSD2 framework.

For satellite payments, the case supports the proposition that innovative payment channels remain subject to statutory rules governing authorization, security and allocation of risk.

4. CJEU, C-616/11, T-Mobile Austria GmbH

The case concerned payment-related charges involving telecommunications operators.

Its significance for satellite payments lies in the boundary between telecommunications services and regulated payment activities.

A satellite operator providing communications infrastructure does not necessarily become a payment-service provider. Its actual role in processing or executing payments must be examined.

5. CJEU, Joined Cases C-203/15 and C-698/15, Tele2 Sverige AB and Watson

Although this was not a banking case, it is highly relevant to communications-data protection.

The Court imposed important limits concerning generalized retention of communications data.

A satellite-based payment network involving telecommunications metadata must therefore consider privacy rights alongside financial-security requirements.

6. CJEU, C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (Schrems II)

The Court invalidated the EU-US Privacy Shield and emphasized safeguards for international transfers of personal data.

The decision is particularly important for a global satellite-payment architecture in which financial or customer information could be processed through infrastructure located outside the European Economic Area.

Financial institutions must therefore examine the legal basis and safeguards applicable to international data transfers.

7. CJEU, C-300/21, Österreichische Post AG

This GDPR judgment dealt with compensation for damage resulting from infringements of data-protection law.

Its relevance is that payment-network operators may face not only regulatory enforcement but also potential claims relating to unlawful processing of customer information.

Satellite architecture therefore needs privacy compliance from the design stage.

8. CJEU, C-634/21, SCHUFA Holding (Scoring)

The Court considered automated decision-making and credit scoring under the GDPR.

Although it did not concern satellite payments, it is important where advanced space-based financial platforms combine payment information with automated fraud detection, customer profiling or financial decision-making.

Automated processing must comply with applicable GDPR protections.

Practical Example

Consider a Spanish fintech called OrbitalPay.

OrbitalPay wants to install satellite-connected payment terminals on ships, aircraft and isolated locations where ordinary mobile connectivity is unavailable.

A customer's instruction travels:

Terminal → satellite connection → ground station → OrbitalPay infrastructure → banking/payment network → recipient.

OrbitalPay cannot argue that ordinary banking rules do not apply because part of the transaction passes through outer space.

Instead, regulators would examine OrbitalPay's actual activities.

If OrbitalPay executes regulated payments, appropriate payment authorization may be required.

If a Spanish bank operates the service, banking and prudential requirements apply.

GDPR governs relevant personal-data processing.

DORA addresses ICT and operational resilience for financial entities within its scope.

AML rules apply to regulated financial activity.

Telecommunications and spectrum requirements apply to the communications infrastructure.

Space-law requirements may additionally become relevant to the operator of the satellite system.

The regulatory structure can therefore be represented as:

Space infrastructure → Telecommunications regulation → ICT/DORA controls → Payment-services regulation → Banking supervision → AML and data protection → Customer transaction.

Conclusion

Spanish law does not currently treat “space-based payment networks” as an independent category of banking activity. The stronger legal approach is technology-neutral regulation.

A payment does not cease to be a regulated payment merely because its instructions travel through a satellite.

For Spanish banks and fintech companies, the central legal issues would therefore include authorization, PSD2/payment-services compliance, strong customer authentication, unauthorized-payment liability, safeguarding, AML controls, GDPR, cybersecurity, DORA operational resilience and management of satellite or ICT outsourcing.

The existing CJEU authorities on payment instruments, telecommunications, privacy and international data transfers provide useful analogies, but they should not be presented as direct Spanish precedents on satellite payments. As commercial satellite connectivity becomes more integrated into financial infrastructure, dedicated regulatory guidance and eventually specific litigation are likely to clarify how these established banking principles apply to space-based payment networks.

LEAVE A COMMENT