[codicts-css-switcher id=”346″]

Global Law Experts Logo
bank payments reporting spain

What Real Decreto 253/2025 Means for Spanish Companies: Bank, Card and Bizum Payment Reporting, Compliance Steps and Director Risk

By Global Law Experts
– posted 3 hours ago

Real Decreto 253/2025 has fundamentally expanded bank payments reporting in Spain, requiring financial institutions to supply the Agencia Estatal de Administración Tributaria (AEAT) with granular data on card transactions, Bizum transfers and other electronic payment flows processed through their systems. For CFOs, company directors and compliance officers operating in Spain during 2026, the decree creates an urgent need to align internal bookkeeping with the payment data that Hacienda now receives directly from banks and payment service providers. This guide sets out exactly what the regulation requires, who is affected, what companies must do to comply, and how directors can protect themselves from the administrative and personal liability risks that accompany non-compliance.

Executive Summary: What Changed and Why It Matters

Published in the Boletín Oficial del Estado (BOE) in April 2025, Real Decreto 253/2025 amends Spain’s existing informational-obligations framework to capture a far broader set of payment-data reporting obligations. Banks, card acquirers and payment service providers must now furnish the AEAT with itemised transaction data, including card payments, mobile-wallet transfers such as Bizum and other electronic payment instruments, on a periodic basis. The AEAT confirmed the operational changes through its April 2025 notice on modifications to informational obligations.

The practical consequence is straightforward: the AEAT can now cross-reference a company’s declared income against independently reported payment receipts. Any mismatch, whether caused by fraud, administrative error or timing differences, will surface quickly in AEAT risk-analysis systems. Company compliance with AEAT reporting standards in 2026 is therefore no longer aspirational; it is an operational necessity.

Quick Compliance Checklist

  • Map every payment channel. Identify all banks, card acquirers, PSPs, Bizum accounts and electronic wallets linked to your business.
  • Request data schemas. Ask each financial institution what fields they report to the AEAT and obtain sample reporting formats.
  • Reconcile monthly. Match bank-reported transaction data against your own sales ledger, VAT records and invoicing system every month.
  • Update your ERP. Ensure your accounting software can tag transactions by payment method (card, Bizum, bank transfer, cash) for rapid reconciliation.
  • Review record-retention policies. Confirm that supporting documents, invoices, receipts, refund authorisations, are retained for the full statutory period.
  • Brief the board. Record a formal board resolution acknowledging the new reporting environment and delegating compliance responsibilities.
  • Engage external counsel. Commission a gap analysis within 30 days if your internal finance team lacks payment-reporting expertise.
  • Monitor AEAT guidance updates. Track new implementing orders or circulars that may refine thresholds and reporting windows.

What Real Decreto 253/2025 Requires, Legal Summary of Bank Payments Reporting in Spain

Real Decreto 253/2025 modifies several existing regulatory instruments governing informational obligations owed to the AEAT. At its core, the decree extends the categories of transaction data that payment-processing entities must report, closing gaps that previously allowed electronic payment flows to pass without systematic tax-authority oversight.

Key Legal Provisions

The decree introduces or amends obligations across the following reporting categories:

  • Card payments. Acquiring banks and card-payment processors must report aggregated and, where specified, itemised data on card-based transactions processed for merchants operating in Spain.
  • Mobile and instant payments (Bizum). Providers of mobile-payment services, including Bizum, which operates through the Spanish banking network, fall within the expanded reporting perimeter. Bizum reporting rules now require that transaction volumes and recipient identification data reach the AEAT.
  • E-wallet and PSP transactions. Payment service providers authorised under EU payment-services regulation that process commercial payments for Spanish-resident businesses are included.
  • Bank account and transfer data. Existing obligations on credit institutions to report account balances and significant movements are reinforced, with tighter alignment to AEAT cross-checking protocols.

The legal basis for these obligations sits within Spain’s General Tax Law (Ley General Tributaria) and the implementing regulations on informational duties, as amended by Real Decreto 253/2025. The full text is published on the BOE under reference BOE-A-2025-6599.

Effective Dates and Transitional Rules

Real Decreto 253/2025 was published in the BOE in April 2025. The AEAT confirmed through its official notice that the new informational obligations take effect for reporting periods beginning in 2026. Industry observers expect that the first full reporting cycles under the amended rules will generate data that the AEAT can deploy in cross-referencing exercises from mid-2026 onward. Companies should treat 1 January 2026 as the operational start date for internal compliance purposes, even where specific implementing orders may phase in certain reporting fields over subsequent months.

Who Must Report and Who Is Covered, Scope and Thresholds

Understanding the distinction between reporting agents (entities that transmit data to the AEAT) and affected subjects (entities whose transactions are reported) is critical for company compliance in the AEAT 2026 environment.

Reporting agents include all credit institutions operating in Spain, card-acquiring entities, payment institutions, electronic-money institutions, and providers of Bizum or equivalent mobile-payment infrastructure. These entities bear the direct obligation to collect, format and transmit payment-data reporting obligations to the AEAT.

Affected subjects are far broader: any company, sole trader (autónomo), professional or non-resident branch that receives commercial payments through the reported channels. If your business accepts card payments, Bizum transfers or payments through fintech platforms, the AEAT will receive corresponding data from the reporting agent.

Reporting Obligations for Fintechs and PSPs

Fintech platforms such as Revolut, Wise, Stripe and SumUp that act as acquirers or hold client funds in Spain fall within the reporting perimeter. Where these platforms process payments for Spanish-resident merchants, they must supply the same categories of data as traditional banks. Companies using multiple PSPs should expect their transaction data to reach the AEAT from each provider independently, making internal reconciliation across platforms essential.

What Small Businesses and Marketplaces Must Expect

Small businesses are not exempt. The decree does not establish a de minimis threshold below which card payments reporting in Spain is waived. Marketplace operators that aggregate payments on behalf of third-party sellers face particular complexity: the marketplace platform, the underlying PSP and the seller’s own bank may each generate overlapping reports to the AEAT. Early indications suggest that the AEAT’s risk-analysis algorithms will flag discrepancies across these multiple data feeds, making clean reconciliation at the seller level especially important.

Entity Type Who Reports What to Expect
Banks and card acquirers Banks and card acquirers report transaction data directly to the AEAT Monthly feeds covering card payments, Bizum transfers and other specified electronic payments
Payment Service Providers (PSPs) / fintechs PSPs report where they act as acquirers or hold client funds for Spanish merchants Standardised data schema and periodic reporting; may require contract updates with merchants
Companies / merchants Not primary reporters, but subject to AEAT cross-checks against bank-reported data Must ensure bookkeeping matches bank feeds; be prepared to produce invoices and receipts on request

The AEAT Payment Reporting Process, What Companies Will See and Timing

Companies will not directly file the new payment reports themselves. Instead, AEAT payment reporting operates upstream: banks and PSPs transmit transaction data, and the AEAT ingests it into its risk-analysis and cross-referencing systems. The practical effect for companies is that AEAT inspectors now have a mirror image of every card swipe, every Bizum receipt and every PSP settlement that flows into the company’s accounts.

The AEAT is expected to receive periodic data feeds, the likely practical frequency will be monthly or quarterly, aligned with existing informational-obligation reporting windows. The reported fields are anticipated to include transaction date, amount, payment method, truncated card identifier or Bizum reference, and merchant identification data (NIF/CIF). The AEAT can use this data to compare declared revenues, VAT filings and corporate-tax returns against actual payment inflows.

Interplay with Bank of Spain Statistical Reporting and Sepblac

Bank payments reporting in Spain does not operate in isolation. The Bank of Spain collects payment-systems statistics from credit institutions under its supervisory mandate, and Sepblac (Spain’s Financial Intelligence Unit) receives systematic reporting on transactions that may indicate money laundering or terrorist financing under Law 10/2010. Companies should be aware that the same underlying transaction data may reach multiple authorities simultaneously. Compliance programmes should address all three channels, AEAT, Bank of Spain and Sepblac, in an integrated manner.

Reported Data Field What It Shows Why AEAT Needs It
Transaction date When the payment was processed Cross-reference against declared income period (monthly VAT, annual corporate tax)
Transaction amount Value of the individual payment Aggregate totals compared to reported revenue
Payment method Card, Bizum, PSP transfer or other electronic instrument Identifies payment channels for targeted audit risk profiling
Merchant NIF/CIF Tax identification number of the receiving business Links payment data to the specific taxpayer’s filings
Truncated card PAN / Bizum reference Partial identifier of the payment instrument Enables tracing without exposing full cardholder data (AEPD compliance)

Step-by-Step Compliance Roadmap for Companies

This section provides the operational core of the compliance response. The roadmap is structured in four phases, each with clear responsibilities, timelines and deliverables that finance teams can implement immediately.

Phase 1, Immediate Triage (First 30 Days)

The first priority is a comprehensive gap analysis. Finance directors should map every payment channel through which the company receives funds: bank accounts, card terminals (physical and virtual), Bizum-enabled accounts, PSP settlement accounts (Stripe, PayPal, SumUp, Revolut Business) and any marketplace disbursement arrangements. For each channel, identify the reporting agent, the bank or PSP that will transmit data to the AEAT.

Request from each reporting agent a written summary of the data fields they will report and the frequency of reporting. This information is essential because it defines the reconciliation baseline. Assign a named internal owner, typically the financial controller or head of accounting, with explicit responsibility for payment-data reconciliation. Document this assignment in writing.

Phase 2, Accounting and Systems Updates (60–90 Days)

With the payment-channel map complete, update your accounting system to capture payment-method detail at the transaction level. Every sale recorded in the ledger should carry a tag indicating whether payment was received by card, Bizum, bank transfer or cash. This tagging is the foundation of internal controls for payment reporting.

Link each payment to its corresponding invoice or receipt. Where your business issues simplified invoices (facturas simplificadas), ensure that even these carry sufficient detail to match against bank-reported data. Reconcile historical data for the current fiscal year against bank statements to identify and resolve any pre-existing discrepancies before the AEAT’s cross-referencing algorithms surface them.

Phase 3, Controls and Reconciliations for Monthly AEAT Exposure

Implement a monthly reconciliation cycle. At the close of each month, the finance team should compare total payment receipts by channel (as recorded in the company’s books) against the bank statements and PSP settlement reports. Any variance, whether from timing differences, chargebacks, refunds or processing fees, should be documented and explained in a reconciliation workpaper.

Establish escalation protocols: variances below a defined threshold (for example, amounts attributable to rounding or bank charges) can be cleared by the controller, while larger discrepancies should be escalated to the CFO and, where appropriate, external counsel. This layered approach ensures that the company can respond swiftly if the AEAT queries a discrepancy.

Phase 4, Documentation and Record Retention (90 Days Onward)

Spain’s Ley General Tributaria requires retention of tax-relevant documentation for a minimum of four years from the end of the voluntary filing period. Best practice, and the conservative approach recommended for AEAT defence, is to retain all payment records, reconciliation workpapers and supporting invoices for at least six years. Store records in a format that is readily accessible for AEAT inspection, including electronic copies indexed by period and payment method.

Internal Control Responsible Person Frequency
Payment-channel register (list of all banks, PSPs, card acquirers) Financial controller Updated quarterly or upon any change
Monthly reconciliation: company ledger vs. bank/PSP statements Accounting team lead Monthly, within 15 days of month-end
Variance analysis and escalation report CFO / Financial director Monthly (or as variances arise)
Invoice-to-payment matching log Accounts receivable Continuous
Record-retention audit Compliance officer / external auditor Annually
Board minutes recording compliance delegation Company secretary At adoption and annually thereafter

IT, Treasury and Vendor Checklist

The compliance roadmap above depends on IT infrastructure that can capture, tag and reconcile payment data at the required granularity. Finance and IT teams should work through the following checklist jointly:

  • ERP payment-method tagging. Configure your ERP or accounting software to record payment method (card, Bizum, transfer, cash) as a mandatory field on every revenue entry.
  • PSP contract review. Request updated data-processing agreements from each PSP, confirming their reporting obligations under Real Decreto 253/2025 and the data fields they transmit.
  • Bank data feeds. Where available, activate electronic bank-statement feeds (CAMT.053 or equivalent) to automate reconciliation and reduce manual error.
  • Tokenisation and privacy. Ensure that any storage of card PANs or Bizum identifiers complies with AEPD guidance on personal-data processing and PCI-DSS requirements. Use truncated or tokenised identifiers wherever possible.
  • Access controls. Restrict access to payment-reconciliation data to authorised finance personnel and document access rights in your information-security policy.
  • Disaster recovery. Confirm that payment records are included in your backup and disaster-recovery protocols, preserving the six-year retention window.

Director Liability, Penalties and Mitigation

Director liability for reporting failures in Spain is a serious concern. Under the Ley General Tributaria, administrative penalties for failure to comply with informational obligations can include fixed and proportional fines. The exact penalty amounts depend on the nature and severity of the infraction, whether the breach involves incomplete data, late filing (by the reporting agent) or obstruction of AEAT verification activities. Where a company’s books show material discrepancies against bank-reported payment data, the AEAT may initiate a formal inspection (actuación inspectora) that can result in additional tax assessments, interest and surcharges.

Beyond administrative penalties, directors face personal exposure under the Spanish Companies Act (Ley de Sociedades de Capital). A director who fails to implement adequate internal controls, allowing the company to underreport income or obstruct AEAT cross-checks, may be held liable for the resulting tax debt through the derivative-liability (responsabilidad subsidiaria or solidaria) provisions. In extreme cases involving deliberate concealment or falsification, criminal liability under Spain’s tax-offence provisions may arise.

How to Document Director Decisions and Board Minutes

Mitigation starts with documentation. Directors should ensure that board minutes record the following:

  • Acknowledgement of the new reporting framework, a resolution noting that the board is aware of Real Decreto 253/2025 and its implications.
  • Delegation of compliance responsibilities, formal delegation to a named officer (CFO, compliance officer or external adviser) with authority and budget to implement internal controls for payment reporting.
  • Periodic compliance reporting, a standing agenda item requiring the delegated officer to report quarterly on reconciliation status and any AEAT communications.
  • D&O insurance review, confirmation that the company’s directors’ and officers’ insurance covers regulatory-investigation costs, including AEAT inspections triggered by payment-data discrepancies.

Practical Examples and Worked Scenarios

Two common business profiles illustrate how the new bank payments reporting rules in Spain affect day-to-day operations.

Scenario A, Small Retailer. A clothing shop in Barcelona accepts card payments and Bizum. Each month, the acquiring bank reports total card receipts and the Bizum provider reports mobile-payment receipts to the AEAT. The shop’s accountant reconciles the monthly bank statement against the point-of-sale system report. A €120 discrepancy arises because a customer refund was processed on the last day of the month but not reflected in the bank feed until the following month. The accountant documents the timing difference in a reconciliation workpaper, attaches the refund authorisation and files it in the monthly reconciliation folder. No further action is needed, the discrepancy is explained and evidenced.

Scenario B, Marketplace Seller. An electronics reseller operates through a major marketplace platform, a Shopify store with Stripe payments and direct Bizum links. Three separate reporting agents, the marketplace’s PSP, Stripe and the seller’s bank, each transmit data to the AEAT. The seller’s finance team must consolidate settlement reports from all three sources, match them to the internal sales ledger and verify that platform commissions and refunds are correctly netted. Without a unified reconciliation process, the AEAT may see total inflows that exceed the seller’s declared revenue, a red flag for audit selection.

Scenario What Bank / PSP Reports Company Action Required
Small retailer (card + Bizum) Monthly card and Bizum receipt totals per merchant NIF Monthly POS-to-bank reconciliation; document refunds and timing differences
Marketplace seller (multiple PSPs) Each PSP reports independently; totals may overlap or differ from net settlements Consolidate all PSP settlement reports; reconcile gross vs. net; explain commissions

Next Steps

Companies operating in Spain should treat compliance with Real Decreto 253/2025 as an immediate operational priority. The AEAT’s expanded access to bank payments reporting data in Spain means that discrepancies between reported income and actual payment inflows will be surfaced faster, and investigated more rigorously, than ever before. Begin with the quick checklist above, commission a gap analysis within 30 days, and establish monthly reconciliation routines before the first full reporting cycle completes.

For businesses that need tailored guidance, particularly those operating across multiple PSPs, marketplace platforms or cross-border payment channels, engaging a corporate compliance specialist with experience in Spanish tax and regulatory obligations is strongly recommended. The Global Law Experts lawyer directory can connect you with qualified practitioners for bespoke review. Companies concerned about broader financial-services risk may also find relevant guidance in our analysis of banks’ responsibilities and customers’ obligations in the digital-payment environment.

Last reviewed: 1 August 2026

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Oscar Folchi Riera at Unión Legal – Abogados y Economistas, a member of the Global Law Experts network.

Sources

  1. BOE, Real Decreto 253/2025
  2. Agencia Tributaria (AEAT), Modifications to Informational Obligations
  3. Banco de España, Payment Systems in Spain
  4. Sepblac, Systematic Reporting
  5. AEPD, Spanish Data Protection Agency

FAQs

What is Real Decreto 253/2025 and which payments must banks report to the AEAT?
Real Decreto 253/2025 is a Spanish regulation published in the BOE (reference BOE-A-2025-6599) that expands the payment-data reporting obligations of banks, card acquirers and payment service providers. These entities must now report card transactions, Bizum transfers and other electronic payment data to the AEAT on a periodic basis, enabling Hacienda to cross-reference reported business income against actual payment inflows.
Any company, sole trader or professional operating in Spain that receives payments via card, Bizum or other electronic payment channels covered by the decree is an affected subject. Marketplace platforms, fintechs and non-resident branches with Spanish payment flows are also within scope. The decree does not establish a de minimis exemption for small businesses.
Companies must tag each revenue transaction by payment method in their accounting system, perform monthly reconciliations between internal records and bank or PSP statements, and retain all supporting documentation, invoices, receipts, refund authorisations and reconciliation workpapers, for a minimum of four years (six years recommended).
Administrative penalties under the Ley General Tributaria apply for breaches of informational obligations, with fines varying based on severity. Directors may face personal derivative liability for resulting tax debts under the Ley de Sociedades de Capital, and criminal liability in cases involving deliberate concealment or falsification.
The statutory minimum under Spanish tax law is four years from the end of the voluntary filing period for the relevant tax. Best practice for AEAT defence is to retain records for six years, covering potential extended inspection periods and derivative-liability actions.
The AEAT will receive data on Bizum transactions processed through commercial accounts, that is, payments received by businesses and professionals. Person-to-person Bizum transfers between private individuals are governed by separate rules and thresholds. The precise scope of Bizum reporting rules depends on whether the recipient account is classified as commercial by the Bizum provider.
Record the original transaction and the refund or partial reversal as separate line items in your accounting system. Attach the refund authorisation or credit note to the reconciliation workpaper. Where a single customer payment is split across multiple settlement dates, document the split with reference to the PSP settlement report and note the timing difference in your monthly reconciliation file.
how to change child's name on birth certificate in kenya
By Global Law Experts

posted 4 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

What Real Decreto 253/2025 Means for Spanish Companies: Bank, Card and Bizum Payment Reporting, Compliance Steps and Director Risk

Send welcome message

Custom Message