{"id":36555,"date":"2018-05-22T00:00:00","date_gmt":"2018-05-21T22:00:00","guid":{"rendered":"https:\/\/aebanca.es\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/"},"modified":"2026-04-09T12:47:20","modified_gmt":"2026-04-09T10:47:20","slug":"banks-and-the-new-data-protection-regulation","status":"publish","type":"articulos","link":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/","title":{"rendered":"Banks and the New Data Protection Regulation"},"content":{"rendered":"<p>The European Data Protection Regulation (GDPR), published on May 4, 2016 and fully applicable from May 25, 2018, introduces a new global model that entails not only a harmonization of the regulatory framework for this matter across all EU Member States, but also a significant shift in approach to compliance strategy regarding the protection of personal data.<\/p>\n<p>On the one hand, it introduces a historic change in relation to the data controller&#8217;s commitment through the concept of proactive responsibility or &#8220;accountability.&#8221; This principle, which constitutes one of the pillars upon which the legislation is based, consists of the obligation to prevent harm by organizations that process personal data, requiring them to take measures that reasonably ensure that, a priori, they are in a position to comply with the principles, guarantees, and rights established in the Regulation. <\/p>\n<p>Furthermore, not only must organizations comply with the provisions of the GDPR, but they must also be in a position to demonstrate such compliance, in order to avoid any type of risk to the fundamental rights of users.<\/p>\n<p>On the other hand, it provides greater legal certainty, given that, in application of the principle of transparency, organizations are required to provide greater detail to the data subject regarding the processing of their personal data. Thus, when data is collected from the subject, certain information must be provided, such as the purposes and legal basis of the processing, the recipients or categories of recipients of their data, planned transfers thereof, or the retention period\u2014among others\u2014so that they may have, where applicable, effective control over such data. <\/p>\n<p>Likewise, the consent regime is modified, with tacit consent no longer being valid, the possibility is introduced that the legitimate interest of the controller may constitute a legal basis for processing\u2014provided that the interests or rights and freedoms of the data subject do not prevail\u2014and the rights of the latter are expanded, with the introduction of the right to be forgotten, the possibility to limit the processing of their data, or the right to data portability.<\/p>\n<p>The Regulation also establishes new specific obligations for data controllers, among which the designation of a Data Protection Officer stands out, mandatory in the case of banks as their main activity involves data processing operations that require regular and systematic monitoring on a large scale. It is also mandatory to prepare a record of processing activities taking into account their purpose and the legal basis on which they rest, conduct a risk analysis, review security measures in light of the results of such analysis, and establish mechanisms and a procedure for notifying security breaches, or carry out, where applicable, a data protection impact assessment. <\/p>\n<p>Spanish banks, as data controllers, have adopted, within the adaptation period provided by the European text, all necessary initiatives, with the implementation of technical, organizational, and internal security measures affecting their mechanisms, procedures, and internal forms, taking into account the implications for their clients of the processing of their data.<\/p>\n<p>Nevertheless, beyond the new requirements imposed by the GDPR (which will be complemented at the national level by the new Organic Law on Data Protection currently being debated in Parliament), it should not be forgotten that, given the high volume of data it handles and the diversity of services and operations it offers, the Spanish banking sector has always granted a high level of protection to its clients&#8217; data and full guarantee in the exercise of their rights. Indeed, the processing and protection of data is of fundamental importance to banks both from the perspective of their responsibility, to prevent their clients&#8217; data from being subject to unauthorized disclosure and to guarantee its integrity, and from the perspective of the repercussions on their activity, in which their clients place their trust, as the reputational impact of poor data handling can have consequences of enormous magnitude for a bank. <\/p>\n<p>Therefore, Spanish banks make and will continue to make great efforts and dedicate substantial resources, both human and material, to implement the measures that, at any given time, are necessary to comply with legal provisions in this area, committed to the purposes of the regulations and to the supervisors.<\/p>\n<p>Maria Peco, Legal Advisor to the Spanish Banking Association<\/p>\n<p><a href=\"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/los-bancos-ante-la-regulacin-de-proteccin-de-datos.-el-economista.pdf\">Download the article<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The processing and protection of data is of fundamental importance to banks both from the perspective of their responsibility, to prevent their clients&#8217; data from being subject to unauthorized disclosure and to guarantee its integrity, and from the perspective of the repercussions on their activity, in which their clients place their trust.<\/p>\n","protected":false},"featured_media":35920,"parent":0,"template":"","etiquetas":[330,415],"class_list":["post-36555","articulos","type-articulos","status-publish","has-post-thumbnail","hentry","etiquetas-aeb","etiquetas-maria-peco"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Banks and the New Data Protection Regulation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Banks and the New Data Protection Regulation\" \/>\n<meta property=\"og:description\" content=\"The processing and protection of data is of fundamental importance to banks both from the perspective of their responsibility, to prevent their clients&#039; data from being subject to unauthorized disclosure and to guarantee its integrity, and from the perspective of the repercussions on their activity, in which their clients place their trust.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/\" \/>\n<meta property=\"og:site_name\" content=\"Asociaci\u00f3n Espa\u00f1ola de Banca\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-09T10:47:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/data.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"667\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@aebanca\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/\",\"url\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/\",\"name\":\"Banks and the New Data Protection Regulation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/aebanca.es\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/data.jpg\",\"datePublished\":\"2018-05-21T22:00:00+00:00\",\"dateModified\":\"2026-04-09T10:47:20+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/aebanca.es\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/data.jpg\",\"contentUrl\":\"https:\\\/\\\/aebanca.es\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/data.jpg\",\"width\":1000,\"height\":667},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/actualidad\\\/te-interesa\\\/articulos\\\/banks-and-the-new-data-protection-regulation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aebanca.es\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Banks and the New Data Protection Regulation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/aebanca.es\\\/en\\\/\",\"name\":\"AEB\",\"description\":\"Asociaci\u00f3n Espa\u00f1ola de Banca\",\"publisher\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/aebanca.es\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#organization\",\"name\":\"AEB\",\"url\":\"https:\\\/\\\/aebanca.es\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/aebanca.es\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/LOGO-AEB-menu.svg\",\"contentUrl\":\"https:\\\/\\\/aebanca.es\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/LOGO-AEB-menu.svg\",\"width\":57,\"height\":22,\"caption\":\"AEB\"},\"image\":{\"@id\":\"https:\\\/\\\/aebanca.es\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/aebanca\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Banks and the New Data Protection Regulation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/","og_locale":"en_US","og_type":"article","og_title":"Banks and the New Data Protection Regulation","og_description":"The processing and protection of data is of fundamental importance to banks both from the perspective of their responsibility, to prevent their clients' data from being subject to unauthorized disclosure and to guarantee its integrity, and from the perspective of the repercussions on their activity, in which their clients place their trust.","og_url":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/","og_site_name":"Asociaci\u00f3n Espa\u00f1ola de Banca","article_modified_time":"2026-04-09T10:47:20+00:00","og_image":[{"width":1000,"height":667,"url":"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/data.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@aebanca","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/","url":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/","name":"Banks and the New Data Protection Regulation","isPartOf":{"@id":"https:\/\/aebanca.es\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/#primaryimage"},"image":{"@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/#primaryimage"},"thumbnailUrl":"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/data.jpg","datePublished":"2018-05-21T22:00:00+00:00","dateModified":"2026-04-09T10:47:20+00:00","breadcrumb":{"@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/#primaryimage","url":"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/data.jpg","contentUrl":"https:\/\/aebanca.es\/wp-content\/uploads\/2018\/05\/data.jpg","width":1000,"height":667},{"@type":"BreadcrumbList","@id":"https:\/\/aebanca.es\/en\/actualidad\/te-interesa\/articulos\/banks-and-the-new-data-protection-regulation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/aebanca.es\/en\/home\/"},{"@type":"ListItem","position":2,"name":"Banks and the New Data Protection Regulation"}]},{"@type":"WebSite","@id":"https:\/\/aebanca.es\/en\/#website","url":"https:\/\/aebanca.es\/en\/","name":"AEB","description":"Asociaci\u00f3n Espa\u00f1ola de Banca","publisher":{"@id":"https:\/\/aebanca.es\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/aebanca.es\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/aebanca.es\/en\/#organization","name":"AEB","url":"https:\/\/aebanca.es\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aebanca.es\/en\/#\/schema\/logo\/image\/","url":"https:\/\/aebanca.es\/wp-content\/uploads\/2025\/07\/LOGO-AEB-menu.svg","contentUrl":"https:\/\/aebanca.es\/wp-content\/uploads\/2025\/07\/LOGO-AEB-menu.svg","width":57,"height":22,"caption":"AEB"},"image":{"@id":"https:\/\/aebanca.es\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/aebanca"]}]}},"_links":{"self":[{"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/articulos\/36555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/articulos"}],"about":[{"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/types\/articulos"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/media\/35920"}],"wp:attachment":[{"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/media?parent=36555"}],"wp:term":[{"taxonomy":"etiquetas","embeddable":true,"href":"https:\/\/aebanca.es\/en\/wp-json\/wp\/v2\/etiquetas?post=36555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}