Comparative Guides

Welcome to Mondaq Comparative Guides - your comparative global Q&A guide.

Our Comparative Guides provide an overview of some of the key points of law and practice and allow you to compare regulatory environments and laws across multiple jurisdictions.

Start by selecting your Topic of interest below. Then choose your Regions and finally refine the exact Subjects you are seeking clarity on to view detailed analysis provided by our carefully selected internationally recognised experts.

4. Results: Answers
FinTech
5.
Data security and cybersecurity
5.1
What is the applicable data protection regime in your jurisdiction and what specific implications does this have for fintech companies?
Spain

Answer ... Fintech companies must abide by the Organic Law on Protection of Personal Data and Digital Rights, which means they are obliged to respect fundamental rights regarding personal data protection.

Certain particularities regarding credit information systems must be taken into account. First, fintech companies are obliged to inform the client in the event of a denial of service due to information obtained from credit bureaux. Second, they are also obliged to inform the client when payment defaults are registered with credit bureaux.

For more information about this answer please contact: Xavier Foz Giralt from Roca Junyent Abogados
5.2
What is the applicable cybersecurity regime in your jurisdiction and what specific implications does this have for fintech companies?
Spain

Answer ... The most relevant regulations with regard to cybersecurity include:

  • the Law on Information Society Services and Electronic Commerce;
  • the Law on Electronic Signatures (50/2003);
  • the Organic Law on Protection of Personal Data and Digital Rights;
  • the Law on General Telecommunications (9/2014);
  • the Law on Retention of Data Related to Electronic Communications and Public Communication Networks;
  • Royal Decree 381/2015, which establishes measures against illegal or irregular traffic which has fraudulent purposes in electronic communications;
  • the Criminal Code;
  • the National Cybersecurity Strategy 2019; and
  • the Regulation on the Evaluation and Certification of Technology Security.

As a general principle, fintech companies must adopt special technical measures to manage, reduce and prevent incidences that may affect the security of the network and information systems that they use and provide.

For more information about this answer please contact: Xavier Foz Giralt from Roca Junyent Abogados
Contributors
Topic
FinTech