Banking Law And Virtual Iban Regulation Spain .
Banking Law and Virtual IBAN Regulation in Spain
Detailed Explanation with Case Laws
Jurisdiction: Spain
A Virtual IBAN (vIBAN) is an IBAN-format identifier allocated to a customer, merchant, subsidiary, account, or transaction stream while funds may ultimately be credited to a different underlying or “master” payment account. Businesses use virtual IBANs for automated reconciliation, collections, marketplace payments, treasury management and cross-border transactions.
Spain does not have a single statute called the “Virtual IBAN Regulation.” A Spanish vIBAN arrangement must instead be analysed under Spanish banking and payment-services law, EU payment legislation, AML/CFT rules, SEPA requirements, data-protection rules and the regulatory perimeter governing payment institutions and credit institutions.
The most important question is therefore not whether an identifier is labelled “virtual,” but what legal and economic functions the arrangement actually performs.
1. Main Legal Framework
Virtual IBAN arrangements in Spain can fall within several overlapping legal regimes.
The principal framework includes:
- Royal Decree-Law 19/2018 of 23 November on payment services and other urgent financial measures, which implemented the core PSD2 framework in Spain.
- Directive (EU) 2015/2366 (PSD2) on payment services.
- Regulation (EU) No 260/2012, establishing technical and business requirements for euro credit transfers and direct debits under SEPA.
- Regulation (EU) 2024/886 on instant credit transfers, which amended the SEPA framework and strengthened requirements concerning matters including IBAN discrimination and verification of payee.
- Law 10/2010 of 28 April on prevention of money laundering and terrorist financing.
- Royal Decree 304/2014, implementing Law 10/2010.
- The GDPR and Spanish Organic Law 3/2018 concerning personal-data protection.
- Bank of Spain supervisory requirements applicable to regulated payment and banking entities.
The regulatory classification of a vIBAN product depends upon its structure.
2. What Is a Virtual IBAN?
Consider a Spanish payment institution providing services to an online retailer.
The provider maintains one underlying settlement account but allocates separate identifiers:
Merchant A → ES…001
Merchant B → ES…002
Merchant C → ES…003
Payments sent to those virtual identifiers can be automatically attributed to the relevant merchant even though settlement occurs through a common underlying infrastructure.
The virtual IBAN therefore works partly as an addressing and reconciliation mechanism.
But this apparently simple arrangement creates an important legal question:
Does each virtual IBAN represent a genuine payment account, or is it merely a technical identifier pointing toward another account?
The answer affects regulatory obligations.
3. Payment Account Versus Technical Identifier
Under PSD2-derived rules, a payment account is broadly an account held in the name of one or more payment-service users and used for executing payment transactions.
A vIBAN does not automatically become an independent payment account merely because it has an IBAN-format number.
Regulators should look at the substance of the arrangement.
Important questions include:
Who legally owns the underlying account?
Who has a claim to the funds?
Can the vIBAN holder independently make payments?
Can funds remain associated with that customer?
Who maintains the account ledger?
Who receives and executes payment instructions?
Can third parties send money directly to the vIBAN?
The more the arrangement functions like an ordinary customer payment account, the harder it becomes to characterize the vIBAN as a purely technical reference.
4. Authorization and Regulatory Perimeter
Virtual IBAN structures can potentially involve regulated payment services.
For example, suppose a technology company gives Spanish businesses individual vIBANs, receives customer payments through those identifiers, maintains balances and subsequently transfers the money to merchants.
The company cannot necessarily avoid payment-services regulation by saying:
“We only provide virtual numbers.”
Regulators examine the actual activity, rather than its marketing description.
Depending on the structure, services could involve operation of payment accounts, execution of credit transfers, money remittance, acquiring or other regulated payment activities.
A provider may therefore require authorization as a:
- credit institution;
- payment institution; or
- electronic-money institution,
depending on precisely what it does.
The Banco de España is consequently central to the Spanish regulatory analysis.
5. AML/KYC Requirements
Virtual IBANs create significant AML concerns because the visible payment identifier can potentially obscure the relationship between the payer, beneficiary and underlying account.
Spanish Law 10/2010 requires regulated entities to undertake customer due diligence, beneficial-ownership identification, ongoing monitoring and suspicious-transaction controls.
A compliant structure should therefore establish:
vIBAN → customer → beneficial owner → underlying account → transaction history.
The institution should be able to reconstruct this relationship when required.
A virtual account architecture that makes it impossible to identify the real customer or beneficiary would create serious AML problems.
6. Beneficial Ownership
The distinction between the named vIBAN user and the legal holder of the underlying account is particularly important.
Consider:
Underlying account: Payment Institution X
Virtual IBAN: allocated to Company Y
Economic funds: belong to Company Y's business activity.
The institution must know the ownership and control structure of Company Y where AML rules require it.
Creating thousands of virtual identifiers cannot be used to fragment customer information in a way that defeats beneficial-ownership transparency.
7. Safeguarding Customer Funds
Where a Spanish payment institution or electronic-money institution receives customer money, safeguarding requirements can become important.
Customer funds generally cannot simply be treated as the institution's unrestricted corporate assets.
Depending upon the regulatory model, safeguarding can involve segregation or other legally permitted mechanisms.
This becomes particularly significant where:
10,000 vIBANs → one pooled safeguarding account.
The provider needs accurate internal records identifying how much of the pooled money is attributable to each customer.
If the provider becomes insolvent, poor reconciliation could make determining customer entitlements extremely difficult.
8. IBAN Discrimination
An especially important EU rule is the prohibition on IBAN discrimination.
Under Article 9 of Regulation (EU) No 260/2012, payers and payees generally cannot require a payment account to be located in a particular Member State where the relevant SEPA conditions are satisfied.
For example, a Spanish business generally should not reject an otherwise eligible French or German SEPA account simply because its IBAN does not begin with ES.
This principle is highly relevant to vIBAN products because fintech providers frequently operate across several EU jurisdictions.
A provider must also be careful not to market a virtual Spanish-looking identifier in a way that creates a misleading impression concerning where the customer's actual account is legally maintained.
9. Instant Payments and Verification of Payee
Regulation (EU) 2024/886 significantly changed the European payments environment.
One important development is Verification of Payee (VoP). Payment-service providers are required, according to the applicable implementation timetable and regulatory conditions, to provide mechanisms for checking whether beneficiary information corresponds with the payment-account identifier.
Virtual IBAN structures therefore need to be designed so that payee verification works correctly.
For example:
Customer enters:
IBAN: ESXX XXXX...
Name: Empresa Alfa S.L.
The system may need to determine whether the supplied beneficiary name appropriately corresponds to the beneficiary associated with that identifier.
Virtual-account structures should not make this process misleading or technically impossible.
10. Transparency to Customers
A provider should clearly explain the legal nature of its vIBAN.
Customers should understand matters such as:
- whether the vIBAN constitutes an individual payment account;
- who provides the regulated payment service;
- where the underlying funds are held;
- whether funds are safeguarded;
- applicable fees;
- execution times;
- withdrawal arrangements; and
- what happens if the provider fails.
Calling something a “bank account” when it is merely a payment-routing identifier could create contractual, consumer-protection and regulatory concerns.
11. Outsourcing and Fintech Platforms
Spanish banks frequently obtain technology from fintech and cloud providers.
Suppose:
Spanish bank → fintech platform → vIBAN engine → corporate customer.
Outsourcing the technical infrastructure does not automatically transfer the bank's regulatory responsibilities.
Governance should address cybersecurity, operational resilience, access controls, audit rights, data availability, subcontracting, incident management and business continuity.
For regulated financial entities, the EU Digital Operational Resilience Act (DORA) is also relevant to ICT risk and third-party arrangements.
12. Data Protection
Virtual IBAN databases can contain substantial personal and commercial information.
A provider may process:
name + IBAN + payment history + customer identifier + beneficiary information + IP/device information + AML information.
The GDPR therefore becomes relevant.
Processing requires an appropriate legal basis and must satisfy principles such as purpose limitation, data minimisation, accuracy, security and appropriate retention.
The provider must also control access to the mapping database connecting virtual identifiers with actual customers.
13. Fraud and Misdirected Payments
Virtual IBANs can improve reconciliation but can also create new fraud scenarios.
Suppose a fraudster convinces a company to replace the genuine supplier's vIBAN with a fraudulent one.
Legal responsibility could depend upon:
- whether the payer authorized the transfer;
- whether authentication requirements were satisfied;
- whether the payment provider properly executed the supplied identifier;
- whether verification-of-payee obligations applied;
- whether fraud warnings existed; and
- whether either party acted negligently.
There is no universal rule making either the bank or customer automatically responsible for every vIBAN fraud.
14. Account Freezing and AML Investigations
If suspicious activity occurs through one virtual identifier linked to a pooled account, the institution needs sufficiently granular controls to isolate the affected customer.
For example:
Master account: €5 million
Customer A vIBAN: €40,000
Customer B vIBAN: €80,000
Suspicious Customer C vIBAN: €12,000
A compliance architecture should be capable of identifying Customer C's funds and transactions rather than treating every user of the pooled infrastructure as indistinguishable.
This demonstrates why reliable sub-ledgers are essential.
Important Case Laws
There are relatively few reported Spanish judgments dealing specifically with products expressly called “virtual IBANs.” It is therefore better to use Spanish/EU payment-law decisions addressing the underlying legal issues rather than inventing vIBAN-specific precedents.
1. ING-DiBa Direktbank Austria, Case C-191/17, CJEU (2018)
The Court of Justice considered the meaning of “payment account” under European payment-services legislation.
The Court emphasized the functional characteristics of the account.
Relevance
This is particularly important for virtual IBANs.
The legal classification cannot depend solely upon the label given by the provider. The question is whether the underlying arrangement performs the functions associated with a payment account.
2. Bundeskammer für Arbeiter und Angestellte v Deutsche Bahn, Case C-28/18, CJEU (2019)
This case concerned SEPA requirements and restrictions relating to the location of a customer's payment account.
The Court rejected arrangements that effectively imposed territorial requirements inconsistent with SEPA rules.
Relevance
It supports the EU principle against IBAN discrimination, highly relevant to Spanish businesses dealing with IBANs issued elsewhere in the EU.
3. Verein für Konsumenteninformation v Deutsche Lufthansa AG, Case C-290/16, CJEU (2018)
The Court examined payment-related charging within the European regulatory framework.
Relevance
Although not a virtual-IBAN case, it illustrates that payment-service structures and customer charges remain constrained by EU payment legislation rather than being purely contractual matters.
4. DenizBank AG v Verein für Konsumenteninformation, Case C-287/19, CJEU (2020)
This important PSD2 case examined payment instruments, contactless functionality and the treatment of payment transactions under EU payment law.
Relevance
The decision demonstrates the functional approach taken under PSD2: technological innovation does not operate outside payment law simply because the payment mechanism is new.
That reasoning is directly useful when analysing vIBAN products.
5. Beobank SA v Autorité de protection des données, Case C-129/21, CJEU (2023)
The CJEU addressed access to information concerning recipients of personal data under the GDPR.
Relevance
Virtual-IBAN systems frequently involve banks, processors, fintech providers, cloud companies and AML service providers. Providers therefore require clear data-governance arrangements concerning who receives customer information.
6. Schrems II — Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, Case C-311/18, CJEU (2020)
The CJEU invalidated the EU-US Privacy Shield and imposed significant requirements concerning international transfers of personal information.
Relevance
A Spanish vIBAN provider using payment or cloud infrastructure outside the EEA must assess international data-transfer requirements under the GDPR.
Compliance Model for Spanish Banks
A strong Spanish virtual-IBAN structure can be represented as:
Customer identification
↓
AML/KYC and beneficial-owner verification
↓
Regulatory classification of account/service
↓
vIBAN allocation
↓
Clear mapping to underlying account
↓
SEPA-compatible payment processing
↓
Verification of Payee where applicable
↓
Transaction monitoring
↓
Safeguarding and reconciliation
↓
Data protection and cybersecurity
↓
Audit trail and regulatory reporting
The institution should always be capable of answering three fundamental questions:
Who owns the money? Who controls the account? Who is legally providing the payment service?
Conclusion
Virtual IBANs are legally possible and commercially useful in Spain, particularly for fintech, marketplaces, corporate treasury and automated payment reconciliation. However, a virtual identifier is not a regulatory loophole.
The Spanish legal treatment depends upon the actual structure of the service. Royal Decree-Law 19/2018, PSD2, SEPA Regulation 260/2012, Regulation 2024/886, Law 10/2010, GDPR, DORA and Banco de España supervision can all become relevant.
The most important legal principle is substance over terminology. If a vIBAN arrangement effectively provides customers with payment-account functionality, receives or controls customer funds, or executes payment transactions, the provider cannot avoid the relevant banking or payment-services obligations merely by describing the IBAN as “virtual.”
The cited CJEU decisions are particularly useful because Spain operates inside the harmonised EU payments framework. Nevertheless, each virtual-IBAN product must be assessed individually according to its contractual structure, authorization model, safeguarding arrangement and actual flow of customer funds.

comments