Banking Law And Virtual Public Institutions Spain .

Banking Law and Virtual Public Institutions in Spain

Jurisdiction: Spain

“Virtual public institutions” is not a single defined category under Spanish banking legislation. In banking-law terms, it is better understood as the digital delivery of public-sector financial, administrative, identity, payment, supervisory and related services through electronic platforms. This can include online government bodies, electronic administrative portals, public digital-identity systems, digital payment infrastructure, supervisory portals and public financial institutions operating through digital channels.

Spain's framework is especially important because domestic banking law operates together with EU financial-services, payment-services, electronic-identification, cybersecurity, data-protection and digital-administration law.

1. Meaning of Virtual Public Institutions

A virtual public institution can be understood functionally as a public authority or publicly controlled institution that performs some or all of its functions electronically rather than requiring physical interaction.

In the banking sector this can involve:

  • Banco de España's electronic supervisory services;
  • electronic interaction with tax and social-security authorities;
  • digital public identification and authentication;
  • public-sector electronic payments;
  • online administrative procedures;
  • digital interaction with public credit institutions;
  • electronic submission of regulatory information by banks; and
  • digitally authenticated communications between customers, banks and government agencies.

The institution does not become legally “virtual.” Its statutory powers and public-law responsibilities continue to exist irrespective of whether they are exercised through an office or an electronic platform.

2. Constitutional and Administrative-Law Foundation

Spanish public bodies remain subject to the Spanish Constitution, including principles concerning legality, legal certainty, equality, effective judicial protection and the functioning of public administration.

Two particularly important statutes are:

Law 39/2015, of 1 October, on the Common Administrative Procedure of Public Administrations, and

Law 40/2015, of 1 October, on the Legal Regime of the Public Sector.

Law 39/2015 is fundamental to electronic administration. It establishes mechanisms through which individuals, companies and other entities can interact electronically with public authorities.

For banks, this means that important administrative interactions—applications, regulatory communications, notices and filings—can have full legal consequences even though they occur entirely electronically.

3. Banco de España as a Digital Supervisory Institution

The Banco de España is Spain's national central bank and a central component of banking supervision.

Its functions operate within both Spanish law and the European framework, particularly the European System of Central Banks and the Single Supervisory Mechanism (SSM).

Many regulatory relationships between banks and authorities are already heavily digital.

Banks can be required to submit prudential, statistical, financial and supervisory information electronically.

A bank cannot argue that a regulatory obligation is less binding merely because the relevant communication was delivered through an electronic supervisory system.

The underlying principle is:

digital administration changes the channel, not the legal authority of the regulator.

4. European Central Bank and Virtual Supervision

Spain's significant banking institutions are supervised within the SSM, under which the European Central Bank (ECB) has important direct supervisory powers.

Modern prudential supervision relies extensively upon digital information flows.

Banks submit large quantities of data concerning capital, liquidity, governance, credit risk and other prudential matters.

Consequently, Spanish banking law must increasingly address not simply traditional inspections but data-driven and remote supervision.

A supervisory decision delivered through an authorized electronic procedure can carry the same legal consequences as one associated with traditional paper administration.

5. Electronic Identification

Reliable identity is essential to virtual public institutions.

Spain has developed extensive electronic-identification infrastructure, including electronic certificates, the DNI electrónico (DNIe) and public authentication mechanisms such as Cl@ve.

The EU framework is equally important.

Regulation (EU) No 910/2014 (eIDAS) established rules concerning electronic identification, electronic signatures, electronic seals and trust services. Its framework has subsequently been expanded through the European Digital Identity reforms.

For banking purposes, electronic identity can assist in establishing who is communicating with a public authority or financial institution.

However:

electronic authentication is not identical to AML customer due diligence.

A bank may still have additional obligations under AML legislation even where the customer's identity has been authenticated electronically.

6. AML/CFT and Virtual Institutions

Spain's principal AML statute is Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing.

Banks are obliged entities under this regime.

Digital interaction with public institutions can improve verification because authoritative databases and electronic identification mechanisms can provide reliable information.

Nevertheless, the bank remains responsible for appropriate:

customer identification, beneficial-ownership identification, risk assessment, enhanced due diligence where necessary, ongoing monitoring and suspicious-transaction controls.

The use of government digital infrastructure therefore supports compliance but does not transfer the bank's AML responsibility to the government.

7. Public Financial Institutions

Spain also has institutions performing public financial functions.

An important example is the Instituto de Crédito Oficial (ICO).

ICO operates as a public financial institution and plays an important role in financing businesses, investment projects and economic-policy initiatives.

Where financing schemes are administered through banks and digital platforms, several legal relationships can exist simultaneously:

State/public institution → participating bank → borrower.

The presence of a public institution does not automatically make every loan a public-law contract.

The exact legal character depends upon the statutory programme, contractual arrangements and role performed by each institution.

8. Virtual Public Lending Programmes

Digitalisation enables public credit and guarantee programmes to be distributed rapidly through financial institutions.

Consider a hypothetical government-supported SME programme.

A company submits information electronically, a participating bank processes the application, a public institution provides a guarantee and funds are transferred electronically.

Several legal regimes can apply simultaneously:

  • public finance rules;
  • banking regulation;
  • contractual law;
  • AML/CFT;
  • EU State-aid law;
  • data protection; and
  • administrative law.

Digital delivery does not remove any of these layers.

9. Payment Services

Virtual public institutions increasingly depend upon electronic payments.

Spain implements the European payment-services framework principally through Royal Decree-Law 19/2018 on payment services and other urgent financial measures, reflecting PSD2.

When citizens make public-sector payments electronically, questions can arise regarding authentication, execution, unauthorized transactions, fraud and payment-provider liability.

The fact that the recipient is a government authority does not automatically eliminate the protections applicable to the payment transaction.

10. Data Protection

Virtual public institutions inevitably process large quantities of personal information.

The principal framework consists of the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).

Banking information is particularly sensitive in practice.

Where financial information is exchanged between a bank and a public authority, there must be an appropriate legal basis for the processing and disclosure.

A government request does not automatically permit unlimited disclosure of banking information.

The principles of legality, purpose limitation, data minimisation, security and accountability remain important.

11. Banking Secrecy and Public Authorities

Spanish banking confidentiality is not absolute.

Legislation can require financial institutions to provide information to competent authorities, including in taxation, criminal investigation, AML supervision and prudential supervision.

The important question is whether disclosure has a proper legal basis.

Therefore:

digital access by a public institution ≠ unrestricted access to customer accounts.

The authority must operate within the powers granted by law.

12. Cybersecurity and Operational Resilience

The movement of public and financial services online creates substantial operational risks.

A cyberattack against a public identification platform could potentially affect banks relying on that infrastructure.

Likewise, disruption of a regulatory reporting portal could affect financial institutions' ability to satisfy reporting obligations.

The EU's Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has substantially strengthened operational-resilience requirements for financial entities.

Banks must manage ICT risks even where external or interconnected digital infrastructure contributes to those risks.

13. Automated Public Decisions

A particularly important future issue is automated administration.

Suppose a public financial programme uses an algorithm to determine eligibility for financing guarantees.

If the system automatically rejects an applicant, questions can arise concerning:

  • statutory authority;
  • transparency;
  • procedural fairness;
  • data accuracy;
  • discrimination;
  • reasons for the decision;
  • human oversight; and
  • judicial review.

Technology cannot transform an unlawful administrative decision into a lawful one.

The relevant public authority remains bound by administrative-law requirements.

14. Artificial Intelligence

The EU AI Act, Regulation (EU) 2024/1689, adds another layer where public authorities or financial institutions use qualifying AI systems.

The applicable obligations depend upon how the AI system is classified and used.

For banking, AI can potentially be involved in identity verification, fraud detection, creditworthiness analysis, supervisory analytics and public-benefit administration.

Banks and public institutions therefore need to distinguish ordinary software automation from AI systems falling within specific regulatory categories.

Important Case Laws

There is no substantial Spanish jurisprudential category literally called “virtual public institutions banking cases.” The most useful authorities instead concern electronic administration, banking regulation, EU supervision, electronic payments, privacy and digital financial services.

1. Landeskreditbank Baden-Württemberg v ECB — C-450/17 P

Although involving a German institution, this CJEU judgment is highly relevant to Spanish banking because Spain participates in the Single Supervisory Mechanism.

The Court confirmed the central role of the ECB within the SSM architecture concerning prudential supervision.

Banking significance

Spanish banks operate within a multi-level regulatory system in which national digital supervisory structures cannot be considered independently from EU supervisory authority.

2. Berlusconi and Fininvest — C-219/17

The CJEU considered judicial review where national authorities participate in a procedure ultimately leading to an ECB decision concerning qualifying holdings in a credit institution.

Principle

Where EU and national authorities participate in a composite banking procedure, determining which institution makes the final legally binding decision is critical to determining the appropriate judicial remedy.

Virtual-institution relevance

Digital regulatory workflows do not change this allocation of legal authority.

3. Baumeister — C-15/16

This important CJEU judgment concerned confidential information held by financial supervisory authorities.

The Court recognized the importance of professional secrecy within financial supervision.

Relevance

Digitisation does not mean supervisory banking information becomes freely accessible merely because a public authority stores it electronically.

Confidentiality continues to apply to regulatory data.

4. Digital Rights Ireland — Joined Cases C-293/12 and C-594/12

This major CJEU decision concerned large-scale retention of communications data.

Although not a banking case in the narrow sense, it established important principles concerning privacy, proportionality and large-scale state processing of personal information.

Banking relevance

The creation of interconnected digital public infrastructures must still respect fundamental rights concerning personal information.

5. Schrems II — C-311/18

The CJEU addressed international transfers of personal data and invalidated the EU-US Privacy Shield while emphasizing safeguards required under EU data-protection law.

Banking relevance

A Spanish bank or public financial body using overseas cloud or technology providers cannot ignore GDPR restrictions merely because the underlying service is digital.

International data transfers require an appropriate legal mechanism and adequate safeguards.

6. Bundeskartellamt v Meta Platforms — C-252/21

The CJEU considered the interaction between GDPR requirements and other regulatory enforcement.

Wider significance

Public institutions handling digitally interconnected information must recognize that regulatory authority does not eliminate GDPR requirements.

For digital banking ecosystems, data sharing between platforms, banks and public bodies therefore requires careful legal analysis.

7. SCHUFA Holding (Scoring) — C-634/21

The CJEU examined automated credit scoring under Article 22 GDPR.

The Court held, in substance, that scoring can constitute an automated individual decision where a third party gives the score a determining role in deciding whether to establish, implement or terminate a contractual relationship.

Spanish banking relevance

This is particularly important where digital public or private infrastructures provide automated assessments that materially determine access to credit.

Calling the system an “information platform” does not necessarily avoid automated-decision protections.

8. SCHUFA Holding (Discharge from Remaining Debts) — Joined Cases C-26/22 and C-64/22

These cases concerned processing and retention of financial information derived from public registers.

Principle

The fact that information originates from an official public source does not mean private institutions may store and process it indefinitely without complying with GDPR.

Relevance to Spain

This is highly relevant to banks consuming information supplied through increasingly digital public databases.

Publicly available data is still regulated personal data.

Relationship Between the Main Rules

A Spanish virtual public-financial ecosystem can therefore be represented as:

Spanish Constitution
↓
EU banking and financial legislation
↓
Law 39/2015 + Law 40/2015
↓
Banco de España / ECB / other competent authorities
↓
Electronic identity and trust services
↓
Banks and public financial institutions
↓
Digital customer/public services
↓
AML + GDPR + payments + cybersecurity + DORA + AI regulation

Each layer performs a different legal function.

Liability Example

Suppose a Spanish bank relies on a government digital-identity service when opening an account.

An attacker obtains access through identity fraud and uses the account for unlawful transactions.

The existence of government authentication would not automatically absolve the bank.

A court or regulator could still examine whether the bank complied with its own CDD obligations, whether additional verification was reasonably required, whether transaction monitoring operated properly, whether security controls were adequate and whether regulatory requirements were followed.

Responsibility therefore depends upon which institution had which legal duty, rather than simply which institution supplied the technology.

Conclusion

Banking law and virtual public institutions in Spain should be understood as an interconnected digital public-financial framework, rather than as a separate branch of banking law.

The central legal instruments include Law 39/2015, Law 40/2015, Law 10/2010 on AML/CFT, Royal Decree-Law 19/2018, GDPR, Organic Law 3/2018, eIDAS, DORA, EU banking legislation and the ECB/SSM framework.

The central principle is straightforward:

A public institution does not lose its legal powers or responsibilities when it becomes digital, and a bank does not lose its regulatory obligations merely because it relies on public digital infrastructure.

Spain's increasing use of electronic administration, digital identity, automated decision-making and data-driven banking supervision therefore makes questions of legal authority, authentication, privacy, cybersecurity, accountability and judicial review increasingly important. The CJEU authorities discussed above provide particularly important principles because EU law forms an integral part of Spain's banking and digital-government framework.

LEAVE A COMMENT