Opinion of the European Central Bank of 16 December 2025 on digitalisation and modernisation of the financial sector (CON/2025/42)
OPINION OF THE EUROPEAN CENTRAL BANK of 16 December 2025 on digitalisation and modernisation of the financial sector (CON/2025/42) Introduction and legal basis
On 26 September 2025, the European Central Bank (ECB) received a request from the Banco de España, on behalf of the Spanish Ministry of Economy, Trade and Business, for an opinion on a draft law on the digitalisation and modernisation of the financial sector (hereinafter the ‘draft law’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and Article 2(1), third, fifth and sixth indents, of Council Decision 98/415/EC , as the draft law relates to the Banco de España, payment and settlement systems and rules applicable to financial institutions insofar as they materially influence the stability of financial institutions and markets. In addition, pursuant to Article 25.1 of the Statute of the European System of Central Banks and of the European Central Bank (hereinafter the ‘Statute of the ESCB’), the ECB may offer advice to and be consulted by, inter alia, the competent authorities of the Member States on the implementation of Union legislation relating, inter alia, to the stability of the financial system. In accordance with Article 17.5, first sentence, of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.
1. Purpose of the draft law
1.1 According to the explanatory memorandum accompanying the draft law, the draft law acknowledges that the process of digitalisation in the financial sector is widespread and is progressing rapidly, bringing significant opportunities in the sector as a result of cost savings, the creation of new services and the development of new functionalities. In this respect, mechanisms are needed to ensure that the regulatory framework and supervisory activities are properly developed so that they are adapted to changing realities and disruptive technologies, which require an updated legal framework to accompany the digitalisation process of the financial sector. Accordingly, the aim of the draft law is to develop an innovation-friendly framework in Spain that offers guarantees in terms of stability, customer protection and risk mitigation to ensure that the national legal system is at the forefront in the area of financial legislation, taking into account digitalisation developments. 1.2 The explanatory memorandum accompanying the draft law highlights the area of cybersecurity as a financial policy priority in which it is essential to have appropriate processes and mechanisms in place to identify and prevent unauthorised access to financial institutions’ information systems. In this respect,
the draft law incorporates into Spanish law the elements to ensure compliance with Regulation (EU)
2022/2554 of the European Parliament and of the Council (hereinafter the ‘DORA Regulation’) . In
addition, the draft law transposes Directive (EU) 2022/2556 of the European Parliament and of the
Council and partially transposes Directive (EU) 2023/2864 of the European Parliament and of the
Council into national law.
1.3 The draft law provides that operators of payment systems, operators of payment schemes, operators of
electronic payment arrangements and payment processing entities providing services in Spain and
subject to supervision or oversight by Spanish authorities must comply with the obligations set out in
Chapter II (‘ICT risk management’), as has been the case to date, and also with those established in
Chapter V, Section I (‘Key principles for a sound management of ICT third-party risk’), of the DORA
Regulation . The draft law upholds the current clarification that these obligations do not apply to
operators of payment systems considered of systemic importance by the ECB based on Regulation of
the European Central Bank (EU) No 795/2014 (ECB/2014/28) (hereinafter the ‘SIPS Regulation’) .
1.4 The Banco de España is to be the competent authority for the supervision and sanctioning of compliance
with the requirements set out in Chapter II and Chapter V, Section I, of the DORA Regulation .
1.5 The draft law introduces developments in the provision of payment services and the regulation of
payment systems with the purpose of modernising the legal framework and fostering competition
between different types of institutions. Due to the adoption of Regulation (EU) 2024/886 of the European
Parliament and of the Council – which amends Article 2 of Directive 98/26/EC of the European
Parliament and of the Council (SFD) and inserts Article 35a into Directive (EU) 2015/2366 of the
European Parliament and of the Council (PSD2) to allow for the direct participation of payment and electronic money institutions in payment systems designated under the SFD, without the need for intermediary entities as was previously the case – payment and electronic money institutions that wish to have direct access to those payment systems will have to comply with additional requirements relating to customer asset protection or internal governance and organisation, in order to ensure the smooth operation of payment systems. 1.6 The draft law transposes into Spanish law the amendments to the SFD and the PSD2 and regulates the conditions for requesting participation in Spanish designated payment systems. In particular, the draft law provides that when a payment institution or electronic money institution intends to access a designated payment system, it must submit to the Banco de España the following documentation: (a) a description of the measures taken to safeguard users’ funds; (b) a description of the governance arrangements and internal control mechanisms in relation to the payment and/or electronic money services it intends to provide; and (c) a liquidation plan . The draft law further provides that the Banco de España is responsible for deciding on the institution’s compliance within three months of its entry in the Banco de España’s electronic register, and that the resolution on compliance by the Banco de 13 España is a prerequisite for the submission of a request to participate in a payment system .
2. Observations
2.1 Digital operational resilience 2.1.1 The draft law modifies the scope of application of certain provisions of the DORA Regulation to include operators of payments systems, operators of payment schemes, operators of electronic payment arrangements and payment processing entities, not only providing services in Spain, but also subject to supervision or oversight by the Spanish authorities. Under the draft law, these entities must comply with the provisions of the DORA Regulation designed to ensure the smooth functioning of information and communication technologies (ICT) and on outsourcing to third party entities. As a result, technology and technical service providers become subject to the draft law through these entities. 2.1.2 The DORA Regulation allows Member States – until a harmonised regime and the supervision of operators of payment systems and processing entities are put in place at Union level – to draw inspiration from the digital operational requirements laid down by the DORA Regulation when applying rules to operators of payment systems and processing entities supervised under their own jurisdictions, with a view to applying similar market practices . This is the first time that the ECB has been consulted on a draft law implementing this option under the DORA Regulation. 2.1.3 The ECB welcomes that the draft law limits the scope of application of certain provisions of the DORA Regulation to entities subject to supervision or oversight by the relevant Spanish authorities in line with
the wording of the DORA Regulation, which refers to ‘operators of payment systems and processing
entities supervised under their own jurisdictions’15.
2.1.4 In this respect, the ECB recalls that in its opinion on the proposal for the DORA Regulation16 it
welcomed the exclusion of payment systems, payment schemes and payment arrangements from the
DORA Regulation in view of the existence of an already applicable Eurosystem oversight policy
framework17.
2.1.5 The ECB welcomes that the draft law excludes operators of payment systems identified as systemically
important payment systems (SIPS) under the SIPS Regulation from the scope of application of the
requirements set out under the DORA Regulation. The reference in the draft law to the repealed
Regulation (EU) 795/2014 should be updated with a reference to the current version of the SIPS
Regulation .
2.1.6 On the basis of the above considerations, and recalling, in passing, one of its earlier opinions , the ECB
suggests that, when activating, nationally, the option set out in recital 104 of the DORA Regulation, and
exercising oversight over certain supervised entities within their jurisdiction, Member States should give
appropriate consideration to the existing Eurosystem oversight frameworks and policies . The ECB
considers that this will ensure that national prerogatives are exercised in a way that promotes a more
harmonised approach to oversight throughout the Union, while at the same time avoiding any potential
duplication of oversight requirements and actions. Finally, the ECB recalls its power to make regulations,
to ensure efficient and sound clearing and payment systems under Article 22 of the Statute of the ESCB.
2.1.7 Finally, the ECB also wishes to highlight that the terms ‘operators of payment schemes’ and ‘operators
of payment arrangements’ are not commonly used terms in Union law or more generally, and hence, to
ensure consistency and clarity, Member States when legislating should opt for established and
recognised terminology used for example under the Eurosystem oversight framework for electronic
payment instruments, schemes and arrangements.
2.2 Access to payment systems 2.2.1 The draft law’s provisions on the conditions for payment and electronic money institutions requesting 21 22 participation in designated payment systems transpose the relevant provisions of Union law into Spanish law. In this respect, the ECB understands that, in conformity with the relevant provisions of Union law, the responsibility for the authorisation and prudential supervision of payment institutions and electronic money institutions, including compliance with the mentioned conditions, lies with the competent authorities of the home Member State . The ECB understands that the Banco de España’s role as the responsible authority for deciding on the compliance by payment institutions and electronic money institutions with these provisions of the draft law is limited to those payment institutions and electronic money institutions authorised by the Banco de España . 2.2.2 The ECB also understands that the Banco de España’s role as the responsible authority for deciding on the compliance by payment institutions and electronic money institutions authorised by it with these conditions is not to be limited to the access by these institutions to Spanish designated payments systems, but to all designated payment systems in the Union. As it currently stands, the draft law is not clear in this respect. Therefore, for the avoidance of any possible doubt, the ECB suggests the inclusion of the necessary wording to explicitly clarify this point.
This opinion will be published on EUR-Lex.
Done at Frankfurt am Main, 16 December 2025.
[signed]
The President of the ECB
Christine LAGARDE
Fotnoter
- 1 Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42, ELI: http://data.europa.eu/eli/dec/1998/415/oj).
- 2 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj). 3 Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022 amending Directives 2009/65/EC, 2009/138/EC, 2011/61/EU, 2013/36/EU, 2014/59/EU, 2014/65/EU, (EU) 2015/2366 and (EU) 2016/2341 as regards digital operational resilience for the financial sector (OJ L 333, 27.12.2022, p. 153, ELI: http://data.europa.eu/eli/dir/2022/2556/oj). 4 Directive (EU) 2023/2864 of the European Parliament and of the Council of 13 December 2023 amending certain Directives as regards the establishment and functioning of the European single access point (2023/2864, 20.12.2023, ELI: http://data.europa.eu/eli/dir/2023/2864/oj). 5 See Article 4(1) of Royal Decree-Law 8/2023 on measures to address the economic and social consequences derived from the conflict in Ukraine and the Middle East as well as to alleviate the effects of the drought (Real Decreto-ley 8/2023, de 27 de diciembre, por el que se adoptan medidas para afrontar las consecuencias económicas y sociales derivadas de los conflictos en Ucrania y Oriente Próximo, así como para paliar los efectos de la sequía, «BOE» núm. 310, de 28/12/2023) (hereinafter ‘Royal Decree-Law 8/2023’), as amended by Article 21 of the draft law. 6 Regulation of the European Central Bank (EU) No 795/2014 of 3 July 2014 on oversight requirements for systemically important payment systems (ECB/2014/28) (OJ L 217, 23.7.2014, p. 16, ELI: http://data.europa.eu/eli/reg/2014/795/oj) repealed by Regulation (EU) 2025/1355 of the European Central Bank of 2 July 2025 on oversight requirements for systemically important payment systems (ECB/2025/22) (OJ L, 2025/1355, ELI: http://data.europa.eu/eli/reg/2025/1355/oj). 7 See Article 4(5) of Royal Decree-Law 8/2023, as amended by Article 21 of the draft law. 8 The Banco de España may apply for this purpose the provisions contained in Article 50, in Title IV and in the twenty-fourth additional provision of Law 10/2014 on the regulation, supervision and solvency of credit institutions (Ley 10/2014, de 26 de junio, de ordenación, supervisión y solvencia de entidades de crédito, «BOE» núm. 156, de 27/06/2014) (hereinafter ‘Law 10/2014’). See Article 4(3) and (4), of Royal Decree-Law 8/2023, as amended by Article 21 of the draft law, and Article 50, Title IV and the 24th additional provision of Law 10/2014. 9 Regulation (EU) 2024/886 of the European Parliament and of the Council of 13 March 2024 amending Regulations (EU) No 260/2012 and (EU) 2021/1230 and Directives 98/26/EC and (EU) 2015/2366 as regards instant credit transfers in euro (OJ L, 2024/886, 19.3.2024, ELI: http://data.europa.eu/eli/reg/2024/886/oj). 10 Directive 98/26/EC of the European Parliament and of the Council of 19 May 1998 on settlement finality in payment and securities settlement systems (OJ L 166, 11.6.1998, p. 45, ELI: http://data.europa.eu/eli/dir/1998/26/oj).
- 11 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35, ELI: http://data.europa.eu/eli/dir/2015/2366/oj). 12 See Article 15 of the draft law, which inserts a new Article 8bis into Royal Decree-Law 19/2018 on payment services and other urgent measures on financial matters (Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, «BOE» núm. 284, de 24 de noviembre de 2018, páginas 114474 a 114568 (95 págs.) (hereinafter ‘Royal Decree-Law 19/2018’). 13 See Article 15 of the draft law, which inserts a new Article 8bis(2) into Royal Decree-Law 19/2018. 14 See recital 104 of the DORA Regulation.
- 15 See recital 104 of the DORA Regulation. 16 See paragraphs 2.1.1 and 2.1.2 of Opinion CON/2021/20 of the European Central Bank of 4 June 2021 on a proposal for a regulation of the European Parliament and of the Council on digital operational resilience for the financial sector (OJ C 343, 26.8.2021, p. 1). All ECB opinions are published on EUR-Lex. 17 The ECB also draws the Spanish authorities’ attention to section 3.2 of the Report from the Commission to the European Parliament, the Council, the European Central Bank and the European Economic and Social Committee on the review of Directive 2015/2366/EU of the European Parliament and of the Council on payment services in the internal market (COM/2023/365 final), which includes the following: ‘DORA mandated the Commission, in the context of the PSD2 review, to consider the inclusion of “operators of payment systems and entities involved in payment–processing activities” within the scope of PSD2, which would consequently allow their inclusion within the scope of DORA. The Commission has reached the conclusion that such inclusion would, at this stage, be premature. There is no prevailing view on this question among stakeholders - whether private or public - consulted by the Commission during its PSD2 review, and no clear detriment or risk to consumers or other market players has yet been observed. Many of the currently excluded services and their providers are already - or are about to be - subjected to European Central Bank/Eurosystem oversight (based on article 127§2 of the Treaty). Schemes and so-called “arrangements” (such as digital wallets) are covered by the new ‘PISA’ oversight framework of the Eurosystem, which is currently being progressively rolled out. There would therefore be a significant risk of duplication if a new layer of EU supervision were to be added to the existing layer of ECB/Eurosystem oversight, without robust evidence of the need for it.’ 18 Regulation (EU) 2025/1355 of the European Central Bank of 2 July 2025 on oversight requirements for systemically important payment systems (ECB/2025/22) (OJ L, 2025/135, 14.7.2025, ELI: http://data.europa.eu/eli/reg/2025/1355/oj). 19 See paragraphs 2.4 and 3.1.3 of Opinion CON/2024/42. 20 See the ECB’s Revised oversight framework for retail payment systems, February 2016, and the Revised assessment methodology for payment systems, June 2018, the Eurosystem oversight framework for electronic payment instruments, schemes and arrangements, November 2021, the Cyber resilience oversight expectations for financial market infrastructures, December 2018, and the ECB policy regarding the identification and oversight of critical service providers of financial market infrastructures, August 2017. Available on the ECB’s website at www.ecb.europa.eu.
- 21 See Article 15 of the draft law, which inserts a new Article 8bis into Royal Decree-Law 19/2018. 22 See, in particular, Article 35a of the PSD2, inserted by Article 3(3) of Regulation (EU) 2024/886. 23 As concerns payment institutions, see Article 5, Article 22(4), Article 23 and Article 35a of the PSD2. Article 4(1) of the PSD2 defines ‘home Member State’ as either of the following: (a) the Member State in which the registered office of the payment service provider is situated; or (b) if the payment service provider has, under its national law, no registered office, the Member State in which its head office is situated. As concerns electronic money institutions, see Article 35a of the PSD2 and Article 3(1) of Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit, and prudential supervision of the business of electronic money institutions, amending Directives 2005/60/EC and 2006/48/EC and repealing Directive 2000/46/EC (OJ L 267, 10.10.2009, p. 7, ELI: http://data.europa.eu/eli/dir/2009/110/oj), according to which, Articles 5, 22(4), and 23 of the PSD2 shall apply, among others, to electronic money institutions mutatis mutandis. 24 Article 3(1) of Law 21/2011 on electronic money (Ley 21/2011, de 26 de julio, de dinero electrónico, «BOE» núm. 179, de 27/07/2011) defines as an ‘electronic money institution’ those entities which have been granted authorisation to issue electronic money; Article 4(1) states that the Banco de España is responsible for authorising the creation of electronic money institutions; and Article 4(4) clarifies that the authorisation of electronic money institutions with a corporate form will require that their central administration, registered office, and part of their payment service activities be located in Spain. Article 11(2) of Royal Decree-Law 19/2018 states that the Banco de España is responsible for authorising the establishment of payment institutions, and Article 11(3) clarifies that the authorisation of payment institutions requires that their central administration, registered office, and part of their payment service activities be located in Spain.