CaixaBankNow does not work: failures in the app and online banking of the entity

CaixaBank customers report failures to access the app and online banking, while the entity has not yet informed of the cause or the extent of the incident.

1 minute

fotonoticia 20260810115228 1920

fotonoticia 20260810115228 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

1 minute

Most read

CaixaBankNow is not functioning normally this Monday, September 7. Numerous CaixaBank customers are reporting problems accessing their accounts from the mobile app and, in some cases, from online banking.

The alerts began to increase during the early hours of the morning. Downdetector, a platform that collects notifications sent by users themselves, reflects a concentration of problems related to the entity's digital services.

What problems does CaixaBankNow present

Affected customers report difficulties logging in, checking their accounts, or correctly loading the information available in the app. There are also alerts about transactions that do not get completed.

The incident mainly affects CaixaBankNow, although some users claim they cannot access normally from the bank's website either.

The available information focuses on access and functionality problems of the app and online banking. It is not confirmed that there is a general interruption of cards, ATMs, or payments via Bizum.

CaixaBank has not yet explained the cause

CaixaBank has not published an official communication detailing the origin of the failures, their territorial scope, or the number of affected customers. There is also no confirmed time for the complete recovery of the service. The entity keeps its customer service phones available 24 hours a day: 93 887 25 25 and 900 40 40 90.

What to do if the CaixaBank app is not working

Customers who encounter problems should avoid repeating a transfer or payment without first checking if the transaction has been recorded. When access is restored, it is advisable to review the movements and pending transactions.

The app's outage does not require changing CaixaBankNow passwords. Users should be wary of messages, calls, or links that attribute the failure to an account lock and request passwords or confirmation codes.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What specific regulation governs the protection of users against failures of digital banking services in Spain?

In Spain, there is no single “online banking outage law,” but rather a framework of European and Spanish regulations that collectively protect users when digital banking services (online banking, apps, card payments, etc.) are interrupted. These regulations cover both the rights of payment service users and the digital operational resilience that financial institutions must ensure.

1. Payment services and user rights (PSD2 and its Spanish implementation)

The basic pillar is the regulation of payment services, which covers transfers, card payments, direct debits, or solutions like Bizum:

  • At the European level, the Payment Services Directive (PSD2) has been transposed into Spanish law through the Royal Decree-Law 19/2018, of November 23, on payment services and other urgent financial measures, which establishes the rights and obligations of users and payment service providers (information, execution deadlines, liability for unauthorized or incorrectly executed transactions, etc.). Its preamble and Title III emphasize user protection and the management of operational and security risks.
  • This RDL is further developed by the Royal Decree 736/2019, of December 20, on the legal regime of payment services and payment institutions, which specifies, among other aspects, solvency obligations, internal governance, and outsourcing of important operational functions, including conditions for critical technology providers. A specific chapter develops solvency guarantees and user protection.
  • Regarding specific transparency in payment services, the Order ECE/1263/2019, of December 26, on transparency of conditions and information requirements applicable to payment services, adapts the framework to PSD2 and modifies previous regulations to strengthen pre-contractual and contractual information, as well as customer service requirements.

These regulations address not only fraud but also incorrect execution or non-execution of transactions, so users have the right, for example, to the restitution of funds when a payment has not been correctly executed due to causes attributable to the institution or payment systems.

2. Banking transparency and customer conduct

Two key pieces underpin the general layer of banking conduct:

  • The Order EHA/2899/2011, on transparency and protection of banking service customers, which sets general principles of fair treatment, transparency, and information in the marketing of banking products and services. It is the basis for good practice criteria used by the Bank of Spain to supervise how incidents are handled, including those related to digital channels.
  • The Circular 5/2012, of June 27, from the Bank of Spain, to credit institutions and payment service providers, on transparency of banking services and responsibility in loan granting, develops Order EHA/2899/2011 and is repeatedly cited in official Bank of Spain notes as a reference for interest rate calculation and standards of information and customer service.

Recent interventions by the governor and deputy governor of the Bank of Spain highlight that this framework has evolved towards a model in which institutions must act honestly, impartially, transparently, and professionally, and where conduct supervision aims to prevent harm to customers, also in contexts of digitalization and possible system outages (see, for example, the 2024 and 2025 interventions available on the Bank of Spain website).

3. Digital operational resilience (DORA and resilience regulations)

For digital service outages, the regulation of digital operational resilience in the financial sector is key:

  • The European Digital Operational Resilience Act (DORA) establishes uniform rules for ICT risk management, resilience testing, incident management, and supervision of critical technology providers. Notes from the European Commission and the Bank of Spain emphasize that DORA aims to ensure that banks and other entities can continue providing essential services despite cyberattacks or technological failures.
  • Spain has received reasoned opinions for not timely transposing the accompanying DORA Directive, but the Government itself has announced measures to apply the Regulation and assign new supervisory functions to the Bank of Spain in this area, as reflected in Council of Ministers notes and articles from Demócrata.
  • Meanwhile, a Law on Protection and Resilience of Critical Entities (transposing Directive 2022/2557) is being processed, whose draft – accessed by Demócrata – introduces the concept of “significant disruptive effect” for interruptions of essential services. Although the text expressly excludes the banking sector and financial market infrastructures because they already have specific cybersecurity and resilience frameworks, its logic reinforces the idea that a prolonged digital banking outage is a matter of public interest.

4. What does this imply in practice for the user?

From this set of regulations, several practical effects arise in the event of a digital banking service outage:

  • The institution must have continuity and digital resilience plans that limit the duration and scope of the interruption, and manage incidents according to DORA and Bank of Spain supervision.
  • If the outage causes non-execution or incorrect execution of payment transactions (transfers, card charges, etc.), the liability and reimbursement regimes of Royal Decree-Law 19/2018 and its regulatory development apply.
  • The customer has the right to clear information about the incident, to file complaints with the institution’s Customer Service or Customer Ombudsman, and, in case of disagreement, to complain to the Bank of Spain, which applies good practice criteria and transparency regulations.

There is currently no general regime of automatic compensation for any isolated outage, but the combination of payment services regulation, banking transparency, and digital resilience provides a framework to demand accountability when the interruption causes specific harm to the user or reveals deficiencies in the institution’s operational risk management.

What is the procedure a banking institution must follow to officially communicate technical incidents to its customers according to current regulation?

Current regulation does not provide a single detailed “manual” on how a bank must communicate technical incidents, but rather a set of dispersed obligations that, in practice, require a very clear protocol. The key pieces are the Royal Decree-Law 19/2018, on payment services (for payment operations), Order EHA/2899/2011 and Bank of Spain Circular 5/2012 (general banking transparency), and Order ECE/1263/2019 (information in payment services).

From this regulation, the following summary scheme can be deduced:

1. Basic regulatory framework
  • Payment services: Royal Decree-Law 19/2018, of November 23, on payment services (text in BOE) requires payment service providers to:
    • Have effective incident management procedures, particularly for detecting and classifying serious operational and security incidents.
    • Notify without delay the Bank of Spain of serious operational or security incidents.
    • If the incident affects or may affect users’ financial interests, inform them without undue delay about the incident and available mitigating measures.
  • General banking transparency: Order EHA/2899/2011 (text in BOE) and Bank of Spain Circular 5/2012 (text in BOE) require:
    • Providing clear, sufficient, and accessible information about the conditions and functioning of banking services.
    • A communication regime with the customer that reduces information asymmetries.
  • Information in payment services: Order ECE/1263/2019 (text in BOE) develops the content and format of information to payment service users (informative brochures, contracts, etc.), imposing:
    • Prior information on durable medium.
    • Clear, understandable, and accessible language, including for people with disabilities.
2. Communication of unplanned incidents (failures, outages, breakdowns)

Applying these rules, the minimum procedure a banking institution should follow is:

  • Internal detection and classification: the incident management system (required by Royal Decree-Law 19/2018 for payment services) must identify:
    • Whether the incident is serious and if it affects or may affect customers’ financial interests.
    • Affected services (online banking, cards, ATMs, transfers, etc.) and temporal scope.
  • Notification to the supervisory authority:
    • If it is a serious operational or security incident in payment services, immediately notify the Bank of Spain in the manner it determines.
    • Submit the information the supervisor requires in its guides or technical circulars.
  • Information to the customer without undue delay (when it may affect their financial interests):
    • Use usual and wide-reaching channels: bank website and app (banners/notices), SMS or email, push notifications, messages on ATMs and branches.
    • Recommended minimum content:
      • Clear description of the incident (without unnecessary technical jargon).
      • Affected services and practical limitations.
      • Estimated duration or, at least, that resolution is in progress.
      • Measures the bank is taking and recommendations to the customer to mitigate risks (e.g., check transactions, use alternative channels, etc.).
    • The message must be clear, legible, and accessible, in line with the transparency requirements of the cited ministerial orders.
  • Internal record:
    • Document the incident, its classification, communications sent to customers and authorities, and measures taken.
    • Include these incidents in the periodic evaluations of operational and security risks that Royal Decree-Law 19/2018 requires to be submitted to the Bank of Spain at least once a year.
3. Scheduled interruptions (maintenance)

Although the regulation does not detail article by article the notice of maintenance, the general duty of transparency and good faith implies that the bank must:

  • Inform with reasonable advance notice of any planned interruption affecting essential services (electronic banking, cards, ATMs, etc.).
  • Communicate it on durable medium and/or usual channels (email, app, website), indicating:
    • Expected start and end date and time.
    • Affected services.
    • Available channels or alternatives (branches, telephone channels, etc.).
  • Draft the notice in clear and easily understandable terms, consistent with Order EHA/2899/2011 and Order ECE/1263/2019.
4. Differences between payment services and other banking services
  • In payment services, there is a specific regime: express obligation to:
    • Have incident management procedures.
    • Notify serious incidents to the Bank of Spain.
    • Inform affected users without undue delay.
  • In deposits, credit, and other banking services, the regulatory focus is on transparency and customer protection (Order EHA/2899/2011 and Circular 5/2012). Technical incidents are not described in as much detail, but:
    • The duty of information, diligence, and loyalty implies notifying when an incident may affect fund availability, transaction execution, or proper service provision.

In conclusion, a bank wishing to comply with regulation should have an internal protocol combining: incident detection and classification, immediate notification to the Bank of Spain in serious payment service cases, rapid, clear, and multichannel communication to affected customers, prior notices for scheduled interruptions, and systematic recording of all incidents and communications issued.

Could you detail what the regulation considers a “serious operational or security incident” in payment services and provide practical examples? How could I structure a step-by-step internal procedure to manage and communicate technical incidents in a specific bank? What differences exist between these communication obligations and those applied to non-financial service companies (e.g., telecommunications)?

What powers does the Bank of Spain have regarding the supervision of digital banking services?

The Bank of Spain is the national banking supervisor, and many of its powers also apply when services are provided through digital channels (online banking, mobile apps, electronic payments, neobanks, fintech, etc.). There is no “parallel regime” for digital: the same prudential and conduct regulations apply to traditional and digital banking services, with some specific reinforcements in technology and cybersecurity.

1. Basic regulatory framework

The main legal bases of its powers are:

  • Law 13/1994, on the Autonomy of the Bank of Spain, which establishes it as the supervisory authority of the Spanish banking system and other intermediaries whose supervision is assigned to it.
  • Law 10/2014, on the organization, supervision, and solvency of credit institutions, which grants broad prudential supervisory powers over banks and other credit institutions, including their technological and operational risks.
  • Payment services regulations (PSD2 and Spanish developments), especially Royal Decree-Law 19/2018 and Royal Decree 736/2019 on payment services and payment institutions, which designate the Bank of Spain as the competent authority to authorize and supervise payment and electronic money service providers.
  • European Digital Operational Resilience Regulation (DORA), which sets cybersecurity and ICT risk management requirements for the entire financial sector and assigns new supervisory tasks to authorities like the Bank of Spain, including supervision of certain critical technology providers.
2. Prudential supervision of digital banking

On the prudential level, the Bank of Spain ensures that institutions are sound and manage their risks well, also when operating through digital channels:

  • Solvency and capital: it requires banks and payment service providers it supervises to have sufficient own resources against risks arising from their digital platforms and business models.
  • Governance and internal control: it evaluates the quality of corporate governance, risk and compliance functions, and how they integrate digitalization-related risks (e.g., intensive use of cloud or artificial intelligence) into their organization.
  • Technological and operational risk: according to supervisory reports, a priority is the operational resilience of essential services (transfers, card payments, online banking) to keep functioning even under stress or serious incidents.
  • Application of DORA: the Bank of Spain itself has explained it will be responsible for implementing the DORA Regulation, supervising:
    • ICT risk and cybersecurity management,
    • incident notification and classification,
    • operational resilience testing,
    • and relationships with critical technology providers (cloud, payment processors, etc.).
3. Conduct supervision and customer protection in the digital channel

Beyond solvency, the Bank of Spain supervises the market conduct of institutions when selling and providing services through digital means:

  • Transparency and customer information: it controls that information about conditions, fees, and risks is clear and sufficient on websites and apps, including account comparators and fee panels.
  • Product marketing: it monitors the sale of complex products or consumer credit through online channels and has highlighted the importance of avoiding inappropriate practices with vulnerable customers.
  • Payment services and digital fraud: its supervisory priorities include preventing card and digital payment fraud and proper management of complaints and refunds when unauthorized transactions occur.
  • Complaints and sanctions: it receives complaints from banking users (also regarding online banking or app problems) and can impose corrective measures and sanctions when repeated non-compliance is detected.
4. Payment systems and new infrastructures

The Bank of Spain also monitors and supervises payment infrastructures that support digital services:

  • It is responsible for overseeing wholesale systems (such as TARGET) and participates in deploying solutions like instant payments and the future digital euro, always alongside the European Central Bank.
  • It supervises that electronic payment operations are secure and continuous, an aspect expressly mentioned in its recent communications.
5. Coordination with other authorities

Supervision of digital banking services is not exclusive to the Bank of Spain but is organized in a network:

  • With the European Central Bank: within the Single Supervisory Mechanism, the ECB directly supervises the most significant entities, and the Bank of Spain acts as the national authority within that framework.
  • With other Spanish authorities: it cooperates with the CNMV, the Directorate General of Insurance, and other bodies on financial stability, cybersecurity, and customer protection; and with SEPBLAC on anti-money laundering in payment services.
  • At the European level: it participates in work by the European Banking Authority (EBA) and international forums on financial innovation, crypto-assets, and technological risks.

In summary, the Bank of Spain applies to digital banking services the same core powers as to the rest of banking business — solvency, risks, conduct, payment systems — reinforced by new European obligations on digital resilience and supervision of technology providers, with a growing focus on cybersecurity and consumer protection in the online environment.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What type of problems have CaixaBankNow users reported on September 7?

Question 1 of 3

What recommendation is given to affected customers before repeating a transfer or payment?

Question 2 of 3

Has CaixaBank officially explained the cause and scope of the incident?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?