IMPORTANT: This post analyzes the regulation of online payment platforms in accordance with the European and Spanish regulatory frameworks in effect at the time of publication. Currently, any implementation of payment gateways, e-commerce, marketplaces, strong customer authentication, personal data processing, fraud prevention, PCI DSS compliance, or the provision of payment services must be reviewed on a case-by-case basis, the GDPR, PSD2, Royal Decree-Law 19/2018, the LOPDGDD, applicable technical standards, and developments in the upcoming European PSD3/PSR package on payment services.
In today’s commercial landscape, the use of online payment platforms has become essential to carry out transactions between marketplaces or e-commerce sites and customers.
The role of these payment platforms is to approve the transactions carried out, as well as to secure the information provided by the customer.
However, in this article we will examine the regulation of payment platforms from both an EU and Spanish perspective.
1.- Regulation (EU) 2016/679
The economic integration of the internal market drives cross-border flows of personal data, which requires a robust and effective European regulatory framework on data protection to ensure security in those data exchanges and thereby foster the development of the digital economy.
These ideas underpin Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. This European regulation sets out how individuals’ data must be processed, recognising the right of access to such data, the right to rectification, and the right to have it erased. In addition, it is the rule that underpins the creation of the regulation known as PCI DSS, an acronym for Payment Card Industry Data Security Standard.
2.- Directive (EU) 2015/2366
In December 2022, the latest amendment to Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market was made, introducing a neutral definition of a payment transaction in order to include other methods that were not previously contemplated, thus going beyond conventional forms of electronic payment such as credit and debit cards.
This directive considers that as more technical advances emerge, there are greater security risks in electronic payments due to their complexity. This is why, following Directive 2015/2366, commonly known as PSD2, the way users could identify themselves when making an electronic payment was changed.
Up to this point, the payment data verification process was carried out using the payment card information and a verification code or SMS and, after the introduction of this rule, e-commerce businesses are required to implement so-called two-step authentication, in which the user must identify themselves using at least two of the three available methods.
With PSD2, the payment process is also simplified, so that payment platforms cease to be external and are integrated into the merchant’s own website. With this type of payment platform, the user completes the purchase process more quickly and, by not changing pages, it gives them a greater sense of security.
3.- Royal Decree-Law 19/2018 (Spain)
At national level, Royal Decree-Law 19/2018 of 23 November on payment services and other urgent measures in financial matters classifies certain key concepts for the correct understanding of EU rules.
Its purpose is payment services and the measures related to them, such as how such payment services are provided, the legal regime of payment institutions, and their transparency regime. It also sets out the rights and obligations of payment users and of the providers of those services.
Likewise, its provisions include the definitions of certain concepts such as payment institution, payment account, payment instrument, payment transaction, payment system, and so on.
4.- Organic Law 3/2018 (Spain)
In order to align EU data protection legislation with the Spanish legal system, Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights was approved. It should be noted that another of the aims of this law is to guarantee Article 18.4 of the Spanish Constitution.
In short, since the matter to be regulated arises from economic relationships between different states, the pioneering regulations that provide security to those relationships are those of the European Union. States simply adopt that legislation aimed at regulating the operation and content of payment platforms.
5.- How can we help you?
The Banking and Finance Department and the New Technologies Department at In Diem Abogados work jointly to provide legal advice and guidance when interpreting Spanish and EU regulations for the implementation of online payment gateways. Our team specialises in payment platforms for electronic transactions.
The Banking and Finance Department and the New Technologies Department at In Diem Abogados work closely with Cryptoveritas 360, an international company specialising in consulting and development of blockchain projects, smart contracts, crypto payment method integration, among many other solutions, ensuring that their operations meet all the necessary requirements.
Contact IN DIEM Abogados 24 hours a day, any day of the week, without obligation.
We guarantee the best possible outcome, whatever your case.
- Personalized and professional service
- Assistance throughout the entire judicial process
- 24-hour contact with your expert criminal lawyer
- Absolute confidentiality
Author: Lucia Arce Espejo
Preguntas frecuentes sobre plataformas de pago online
¿Qué es una plataforma de pago online?
Una plataforma de pago online es una solución tecnológica que permite procesar pagos electrónicos entre clientes, comercios, marketplaces o e-commerce. Su función principal es autorizar transacciones, gestionar datos de pago y facilitar una operativa segura entre las partes.
¿Qué normativa regula las plataformas de pago online?
Las plataformas de pago online se ven afectadas por normativa europea y española en materia de servicios de pago, protección de datos, autenticación reforzada, prevención de fraude y seguridad de la información. Entre las normas más relevantes destacan el RGPD, la PSD2, el Real Decreto-ley 19/2018 y la Ley Orgánica 3/2018.
¿Qué es la PSD2 y por qué afecta a los pagos online?
La PSD2 es la Directiva europea sobre servicios de pago en el mercado interior. Introdujo cambios relevantes en la operativa de pagos electrónicos, especialmente en materia de autenticación reforzada, seguridad de las transacciones y acceso de nuevos proveedores al ecosistema financiero.
¿Qué es la autenticación reforzada del cliente?
La autenticación reforzada del cliente exige verificar la identidad del usuario mediante al menos dos elementos independientes, como algo que sabe, algo que posee o algo inherente al usuario. Su finalidad es reducir el fraude y aumentar la seguridad en los pagos electrónicos.
¿Qué obligaciones de protección de datos tienen los e-commerce?
Los e-commerce deben tratar los datos personales conforme al RGPD y a la normativa española de protección de datos. Esto implica informar adecuadamente al usuario, aplicar medidas de seguridad, limitar el tratamiento a finalidades legítimas y coordinar correctamente la relación con proveedores de pago y otros encargados del tratamiento.
¿Qué es PCI DSS?
PCI DSS es un estándar de seguridad aplicable al tratamiento de datos de tarjetas de pago. Su objetivo es proteger la información sensible de los titulares de tarjetas y reducir riesgos en comercios, plataformas y proveedores que intervienen en operaciones de pago.
¿Un marketplace tiene las mismas obligaciones que un e-commerce?
No siempre. Un marketplace puede tener obligaciones adicionales según su papel en la operación, especialmente si interviene en la gestión de pagos, custodia fondos, distribuye importes entre vendedores o actúa como intermediario entre usuarios y proveedores. Conviene analizar su modelo de negocio concreto.
¿Qué riesgos legales existen al integrar una pasarela de pago?
Entre los principales riesgos se encuentran el incumplimiento de la normativa de protección de datos, errores en la autenticación reforzada, falta de transparencia frente al consumidor, responsabilidades por fraude, deficiencias contractuales con el proveedor de pago y problemas de cumplimiento en operaciones transfronterizas.
¿Conviene revisar legalmente una pasarela de pago antes de implementarla?
Sí. Antes de integrar una pasarela de pago es recomendable revisar el contrato con el proveedor, la política de privacidad, las condiciones de uso, los flujos de datos, la autenticación, las responsabilidades ante fraude y el cumplimiento de la normativa de servicios de pago y protección de datos.
¿Cómo puede ayudar IN DIEM Abogados?
IN DIEM Abogados puede asesorar en la implementación legal de plataformas de pago online, revisión contractual, cumplimiento normativo, protección de datos, prevención de fraude, integración de medios de pago tradicionales o cripto y adaptación de e-commerce y marketplaces a la normativa europea y española aplicable.
Expert lawyers in online payment platforms : Malaga, Marbella, Seville, Madrid, Las Palmas de Gran Canaria, Almeria, Huelva…
In addition, IN DIEM lawyers have extensive experience and a high level of specialisation in Financial Law, providing advice in relation to the integration of payment gateways for marketplaces or e-commerce, in fiat currency or cryptocurrencies, offering clients personalised support at all times.
IN DIEM Abogados has a team with experience in previous roles as Magistrate-Judge, State Attorney, Prosecutor, or University Professor, which will provide you with peace of mind and security, having the best team, competitive and highly prepared to achieve your objectives and meet your needs.
We are at your disposal for whatever you need. You can reach us through the IN DIEM Lawyers Telephone (+34) 901 900 071. In cases of Emergency, you have us at the 24-Hour Emergency Lawyers Telephone IN DIEM: (+34) 610 667 452.
Did you know that Abogados IN DIEM offers online and expedited services?
We offer our clients the option of receiving assistance via video call or videoconference, as well as by phone, depending on their preference, so that the assistance is as personalized as possible, provided immediately, and without the need to travel. This service is complemented by communication via email, which facilitates the review and submission of documentation.
Likewise, we offer urgent and 24-hour services for our companies, handling national and international contracting operations.
For more information about the Online Legal Advice Service HERE, and for the 24-Hour and Emergency Service, HERE.


Would you like to know more about IN DIEM Abogados? Here is this short introductory video…
You will find us in Seville, Madrid, Las Palmas de Gran Canaria, Málaga, Tomares, Coria del Río, Dos Hermanas, Mairena del Alcor, Estepona, Marbella, Mairena del Aljarafe… it will be a pleasure to assist you…!!

