Back to blog

Anti-Money-Laundering Duties for Real Estate Agencies: What SEPBLAC Requires

2026-07-20โ€ข8 min read

Anti-Money-Laundering Duties for Real Estate Agencies: What SEPBLAC Requires

Property is where dirty money likes to hide. A single transaction moves hundreds of thousands of euros, a deed makes the funds look clean, and a quick resale adds a legitimate capital gain on top. That is exactly why Spanish and EU law treat real estate as a high-risk sector โ€” and why your agency is legally on the hook, whether or not anyone ever handed you a manual.

If you intermediate the sale or purchase of property in Spain, you are a *sujeto obligado* ("obliged subject") under Law 10/2010 on the prevention of money laundering and terrorist financing. That is not optional, and "I'm just the intermediary" is not a defense. This article lays out what the law and SEPBLAC โ€” Spain's Financial Intelligence Unit and supervisor โ€” actually require, in plain terms.

Are you an obliged subject? (Probably yes)

Law 10/2010 lists real estate agents and developers among its obliged subjects. In practice:

  • Sale intermediation: if you broker the buying or selling of property, you are obliged, full stop โ€” regardless of the price.
  • Letting intermediation: rental brokerage falls in only when the monthly rent reaches or exceeds โ‚ฌ10,000 per month, the threshold introduced across the EU by the 5th AML Directive.

So a boutique agency closing a โ‚ฌ180,000 flat sale has the same core duties as a large firm โ€” even if the deal feels small and the buyer is a lifelong neighbour.

What SEPBLAC actually requires

The obligations break down into a handful of pillars. None of them is exotic; the failures are almost always about *not doing them consistently* and *not being able to prove you did*.

1. Customer due diligence (KYC)

You must formally identify every client before the business relationship, with a valid document, and keep a copy. When a company is involved, you also have to identify the beneficial owner (*titular real*) โ€” the actual human behind the corporate structure, typically anyone owning or controlling more than 25%.

This is the step most agencies do informally ("I photographed his DNI") and then can't reconstruct in a file 18 months later. If you want the mechanics of doing this cleanly over WhatsApp, we cover it in this guide to automating KYC and DNI checks.

2. Source of funds

SEPBLAC has repeatedly flagged weak verification of the origin of funds as the sector's soft spot. For higher-risk operations you need to understand โ€” and document โ€” where the money is coming from: a mortgage, a property sale, savings, an inheritance. A buyer paying a large sum with no plausible economic story is a classic red flag.

3. Risk assessment and special examination

You have to assess the risk of each client and operation and apply a *special examination* to anything unusual: transactions with no apparent economic purpose, disproportionate to the client's profile, involving high-risk jurisdictions, or structured to fall just under thresholds.

4. Internal organisation

Every obliged subject needs:

  • A written AML manual with your policies and procedures.
  • A designated representative before SEPBLAC (*representante ante el SEPBLAC*) โ€” the internal person responsible for compliance and communication with the authority.
  • Ongoing training for staff so they can spot indicators.

Small agencies can scale this proportionately, but "proportionate" is not "nonexistent."

5. Record retention: 10 years

You must keep the due-diligence documentation for a minimum of ten years. That includes ID copies, beneficial-ownership records, the source-of-funds evidence and your risk analysis. In an inspection, if it isn't in the file, it didn't happen.

Ten years of client IDs also means a data-protection obligation running in parallel โ€” keeping the copies you're legally required to hold without breaching GDPR. We wrote a separate piece on how to store client ID copies without breaking GDPR.

6. Reporting to SEPBLAC

Two distinct duties people confuse:

  • Suspicious transaction reports (*comunicaciรณn por indicios*): when you detect facts that may indicate money laundering, you must report to SEPBLAC โ€” and you must not tip off the client. This can happen before, during or even after a transaction, and abstaining from a suspicious deal does not remove the duty to report it.
  • Systematic/negative reporting: obliged subjects also file periodic reports to SEPBLAC, including a "nil" declaration when there is nothing to report in the period.

The cash rule you can't ignore

Separate from Law 10/2010 but firmly in the same territory: since Law 11/2021, any transaction of โ‚ฌ1,000 or more cannot be paid in cash when one of the parties acts as a business or professional. Because an agency is always a professional, that limit bites on your deals. (The limit rises to โ‚ฌ10,000 only when the payer is a non-resident individual not acting as a business.) Crucially, it applies to the *whole operation* โ€” you cannot split a โ‚ฌ30,000 payment and settle "just a small part" in cash.

What happens if you don't comply

Law 10/2010 has one of the harshest sanction regimes in Spanish administrative law. Failing to keep records, for example, is a serious infraction with fines starting at โ‚ฌ60,001. For very serious infractions the penalty can reach up to โ‚ฌ10 million โ€” or up to five times the amount involved in the transaction in the worst cases. Add reputational damage and possible suspension of activity, and "we'll deal with it if we're inspected" becomes an expensive bet.

What's changing: the EU AML package (2027)

The rules are about to become more uniform across Europe. The EU's new Anti-Money-Laundering Regulation (AMLR, EU 2024/1624) becomes directly applicable on 10 July 2027, without needing national transposition. Two headline changes for agencies:

  • An EU-wide โ‚ฌ10,000 cap on cash payments in a business context.
  • Mandatory customer identification for cash payments of โ‚ฌ3,000 or more.

A new EU authority, AMLA, will supervise the highest-risk cross-border financial institutions, while real estate agents continue to be inspected by national supervisors โ€” now under harmonised rules. The direction of travel is clear: less discretion, more documented process.

How to comply without drowning in paperwork

The common thread across every pillar above is documentation you can retrieve on demand. Most agencies fail inspections not because they had bad intentions, but because the ID copy, the beneficial-owner note and the source-of-funds evidence live in three different WhatsApp chats and an email nobody can find.

The practical fix is to capture the identity data structurally at the moment the client sends it, instead of screenshotting documents into a phone gallery. Turning a photographed DNI or company deed into structured, searchable, retainable data is exactly the kind of manual step that AI document extraction removes โ€” so the compliance file builds itself as you work.

If your KYC and document intake still run on manual retyping, WhappScan turns documents sent over WhatsApp into structured data in seconds โ€” see how at whappscan.com.

Ready to automate your documents?

Try WhappScan for free today. No credit card required.

Try for free