How banks in Barcelona reinforce the security and regulatory compliance with Google Cloud
The banking sector in Barcelona is facing DORA, the Bank of Spain’s circulars, and the challenge of modernizing without sacrificing traceability. Here, we explain how Google Cloud provides a compliance foundation for regulated entities in Spain.
Introduction
The banking sector in Barcelona is accelerating its digital transformation in an environment where the security, operational resilience, and regulatory compliance are a necessity and a priority for any financial institution that outsources or modernizes critical technology services. In this scenario, Google Cloud It has positioned itself as a relevant and secure option for regulated entities in Spain, as it offers compliance frameworks tailored to Bank of Spain requirements, along with native security, audit, and control capabilities.
In addition to addressing technological needs, this change is also driven by the obligation to better manage risks such as data location, the audit rights, the business continuity and the cloud provider oversightToday, discussing cloud security in banking no longer means just infrastructure: it means data governance, traceability, access control, and incident response capability.
Why cloud security is key in banking
Financial institutions handle extremely sensitive information while simultaneously maintaining stable, auditable operations that are aligned with national and European regulations. European recommendations regarding the use of cloud providers in financial services highlight five critical areas:
- Data and system security — verifiable technical and organizational controls.
- Data localization — clarity regarding where they are processed and stored.
- Access and audit rights — capacity of the entity and the supervisor to inspect the provider.
- Sub-outsourcing — control over whom the cloud provider subcontracts.
- Contingency and exit plans — what happens if the provider needs to be changed or the service brought back in-house.
In Spain, the Bank of Spain ...has established specific requirements for regulated entities that outsource services—including due diligence, service monitoring, auditing, transition, subcontracting, business continuity, and data security. Any banking modernization initiative must be designed from the outset with an architecture that prioritizes financial regulatory compliance and banking cybersecurity.
The Regulation (EU) 2022/2554 (DORA) ...on digital operational resilience is now fully applicable. It applies to over 22,000 financial entities in the EU and their critical ICT providers. In November 2025, European authorities designated major hyperscalers—including Google Cloud —as critical ICT providers subject to direct supervision. This changes the model: it is no longer just the bank that is accountable for the cloud; the cloud provider is also directly accountable to supervisors.
How Google Cloud strengthens banking security
Google Cloud provides a compliance foundation for regulated entities in Spain through contracts and mapping documents aligned with the requirements of the Bank of Spain, including explicit references to the Circulars 2/2016 and 3/2022 ...regarding the outsourcing and delegation of services or functions. This foundation is particularly valuable for banks seeking to accelerate cloud migration or infrastructure modernization projects without starting from scratch when designing regulatory controls.
From an operational perspective, the platform features global compliance and certification resources — ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI-DSS, ENS, GDPR — which help support audits, control assessments, and risk governance. In addition, there are specific security and audit services that enable the monitoring of access, administrative changes, and data-related activities within the cloud environment.
The four pillars of banking
Identity and access
Cloud IAM with the principle of least privilege, BeyondCorp Enterprise for Zero Trust, mandatory MFA , and granular control based on role and context.
Detection and response
Security Command Center, Google SecOps (Chronicle SIEM), and Cloud Audit Logs to identify threats and reduce response time.
Data protection
AES-256 encryption at rest and TLS 1.3 in transit by default; CMEK, EKM, Cloud DLP, and Confidential Computing for more sensitive workloads.
Perimeter and network
VPC Service Controls for perimeters that prevent exfiltration, Cloud Armor against DDoS, and firewall rules consistent with the entity's policy.
Protection of sensitive financial data
Data protection in banking requires technical and organizational mechanisms capable of reducing exposure, limiting access, and strengthening information governance throughout its lifecycle. In Google Cloud , a well-designed strategy relies on controls such as identity and access management, continuous auditing, and monitoring of security services, complemented by encryption by default and logical segmentation.
For entities operating in Spain, the data localization and information processing are particularly relevant in the assessment of outsourcing risks. Google Cloud operates regions within the EU — including Madrid (europe-southwest1) — which enable local data residency, low latency, and traceability regarding where each workload is processed. The commercial messaging around cloud in banking must be accompanied by a clear narrative regarding control, visibility, and auditable evidence — the three factors justifying the decision to the compliance, risk, and technology departments.
Financial regulatory compliance in Spain
Regulatory compliance in Spanish banking is not limited to protecting systems; it also requires demonstrating that the cloud provider can be evaluated as an outsourced third party under specific regulatory criteria. Google Cloud expressly states that its contracts for financial institutions in Spain address the requirements of the Bank of Spain, and offers mapping documents to help entities assess that regulatory alignment.
Regulatory framework applicable to banking in Spain
| Standard | What is demanded of the bank |
|---|---|
| DORA (EU 2022/2554) | ICT risk management, major incident reporting, resilience testing, direct oversight of critical ICT providers. |
| Bank of Spain Circular 2/2016 | Minimum requirements regarding outsourcing: due diligence, locations, monitoring, auditing, continuity, and security. |
| Banco de España Circular 3/2022 | Update on the delegation of essential functions and the oversight of critical providers. |
| EBA/GL/2019/02 | European guidelines on outsourcing: a harmonised basis for the EU financial sector. |
| PSD2 | Strong Customer Authentication (SCA), Open Banking, secure communication between TPPs and banks. |
| GDPR | Personal data governance, international transfers, data subject rights, and breach notification. |
The Circulars 2/2016 and 3/2022 They are particularly relevant because they detail expectations regarding risk management, service monitoring, auditing, concentration, security, continuity, and the delegation of essential functions. Furthermore, credit institutions must submit prior notification to the Bank of Spain at least two months before the actual outsourcing of essential functions—an operational requirement that should be incorporated into the timeline of any cloud project.
Identity and Access Management
Identity and access management is a core component of any banking cybersecurity strategy. It enables the definition of which users and services can interact with sensitive resources and under what conditions—from identity verification to the context of the device or the network used for access.
In Google Cloud , this level of control is integrated with Cloud IAM (granular policies by project, dataset, table, or service), BeyondCorp Enterprise (Zero Trust model that replaces the traditional VPN) and Workforce Identity Federation (integration with the corporate identity provider, without duplicating users). This combination is useful for banks that need to reduce operational risk while also having verifiable evidence for internal and external audits.
Threat detection and incident response
Early threat detection is becoming increasingly important because the current financial security model does not rely solely on prevention—it also relies on identify anomalies and respond quicklyUnder DORA, financial entities must notify their competent authority of major incidents within short timeframes (4 hours for the initial notification), necessitating automated detection and classification processes.
Google Cloud y Google SecOps they provide audit logs and findings that help monitor changes to IAM, audit configurations, network rules, and other sensitive events. The collection of findings from Security Command Center includes events linked to anomalous access, unmonitored changes to critical configurations, and the absence of alerts regarding sensitive permissions or roles.
For a banking institution, this translates into three concrete operational capabilities: continuous visibility regarding the security posture, forensic investigation with long-term log retention (Chronicle offers 12 months included by default at no cost per ingested GB) and automated response ...via SOAR for defined scenarios. Three levers that transform reactive auditing into proactive oversight—exactly what regulators expect following DORA.
Is your organization prepared for DORA and the Bank of Spain's circulars on Google Cloud ?
As a Google Cloud Premier Partner specializing in security and compliance, The Cloud Collective helps financial institutions in Barcelona design auditable architectures, manage notifications to the Bank of Spain, and harden configurations in accordance with DORA requirements and Circulars 2/2016 and 3/2022.
Speak with our teamFrequently Asked Questions
Yes. Google Cloud It indicates that its contracts for financial institutions in Spain address the requirements of the Bank of Spain and offers mapping documents regarding Circulars 2/2016 and 3/2022 to assist regulated entities with their compliance assessments. This includes clauses regarding audit rights, data location, sub-outsourcing, continuity and exit plans, and supervision by the competent authority.
It provides auditing, traceability, and monitoring capabilities for administrative and data-access activities, alongside security services such as Google SecOps (Chronicle SIEM) and Security Command Center to support threat detection and event investigation. The operational difference compared to other SIEMs is that Chronicle does not charge based on ingestion volume, allowing a bank to analyze all its logs without a financial trade-off.
DORA applies directly to the bank as a regulated entity and, from November 2025, also to Google Cloud as a designated critical ICT provider under the direct supervision of European authorities. For the bank, this entails reviewing outsourcing contracts to align them with DORA requirements (ICT risk management, 4-hour incident notification, resilience testing, exit strategy), maintaining an information register, and notifying the supervisor of major incidents.
Google Cloud allows you to select specific regions for data storage and processing. For entities in Spain, the most relevant European regions are Madrid (europe-southwest1), Frankfurt, the Netherlands, and Finland. The customer decides in which region each workload is deployed and maintains visibility into the actual data location, which is key to complying with the localization requirements of the Bank of Spain and the GDPR.
Credit institutions must submit a prior notification to the Bank of Spain at least two months in advance before outsourcing functions considered essential or critical. The documentation includes an outsourcing policy approved by the Board of Directors, a risk analysis, mitigation measures, the provider's identity, and a description of the service. Payment institutions follow a similar process with a one-month timeframe, in accordance with Royal Decree 736/2019.
PSD2 mandates Strong Customer Authentication (SCA), secure APIs based communication between the bank and authorized third-party providers (TPPs), and full transaction traceability. Google Cloud supports these requirements with Apigee for APIs management, Cloud Identity and Identity Platform for authentication, Cloud Armor for protection against attacks on public endpoints, and Cloud Audit Logs to maintain a record of every API call.

