Banking Law And Securities Fraud Involving Banks Spain .

Banking Law and Securities Fraud Involving Banks in Spain

1. Introduction

Securities fraud involving banks in Spain covers unlawful or misleading conduct connected with financial instruments where a bank acts as an issuer, intermediary, distributor, investment-service provider, lender, custodian, adviser, market participant, or investor.

Typical problems include:

misleading securities disclosures;

market manipulation;

insider dealing;

false or incomplete prospectuses;

misleading investment advice;

concealment of material risks;

improper sale of complex securities;

manipulation of prices or benchmarks;

fraudulent securities transactions; and

failures of internal controls.

Spain's framework is strongly shaped by EU securities law. Important sources include the Spanish Securities Markets and Investment Services Law, the EU Market Abuse Regulation (MAR), MiFID II, the Prospectus Regulation, Spanish criminal law and general civil-law rules.

Banks can therefore face several different forms of responsibility from the same misconduct:

criminal + administrative/regulatory + civil/contractual + supervisory consequences.

 

2. Main Regulatory Authorities

CNMV

The Comisión Nacional del Mercado de Valores (CNMV) is Spain's principal securities-market regulator.

Its responsibilities include supervision of:

securities markets;

investment firms;

securities offerings;

listed-company disclosure;

market conduct;

investment services; and

market abuse.

Banks providing investment services can therefore fall within CNMV securities supervision even though they are also banking institutions.

Banco de España

Banco de España supervises important aspects of banking activity and participates in the European banking-supervision framework.

European Central Bank

Significant Spanish banking groups are prudentially supervised by the ECB under the Single Supervisory Mechanism.

Thus:

Banking supervision and securities-market supervision overlap but serve different functions.

 

3. Spanish Securities Legislation

Spain's modern securities framework is principally contained in Law 6/2023 on Securities Markets and Investment Services (Ley 6/2023, de los Mercados de Valores y de los Servicios de Inversión).

It replaced the previous consolidated Securities Market Law framework.

The legislation operates together with directly applicable EU regulations and implementing measures.

Relevant subjects include:

securities offerings;

investment services;

investor protection;

market infrastructure;

disclosure;

supervisory powers;

infringements; and

sanctions.

 

4. EU Market Abuse Regulation

Regulation (EU) No 596/2014 — Market Abuse Regulation (MAR) is particularly important.

MAR regulates matters including:

insider dealing;

unlawful disclosure of inside information; and

market manipulation.

Because it is an EU Regulation, it is directly applicable in Spain.

Banks must therefore maintain systems capable of preventing and detecting market abuse.

 

5. Insider Dealing

Insider dealing can arise when a person possessing inside information uses it in relation to financial instruments covered by the applicable regime.

Inside information generally requires characteristics such as:

precise nature;

non-public status;

direct or indirect relationship to relevant issuers or financial instruments; and

potential significant price effect if made public.

Banks frequently receive confidential information through:

lending relationships;

mergers and acquisitions;

underwriting;

restructuring;

securities issuance;

corporate advisory work; and

investment banking.

This makes information barriers particularly important.

 

6. Example of Inside Information

Suppose a Spanish bank advises Company A on a confidential takeover.

The bank's investment-banking team knows that Company A will acquire listed Company B.

Before public announcement, an employee buys Company B shares.

If the statutory requirements are satisfied, this can create serious insider-dealing issues.

The fact that the employee obtained the information through legitimate employment does not make trading on it legitimate.

 

7. Information Barriers

Banks frequently operate several businesses simultaneously.

For example:

Corporate lending

Investment banking

Trading

Asset management

Research

Private banking

Confidential information obtained in one division should not improperly flow to another division.

Banks therefore use measures such as:

information barriers;

restricted lists;

watch lists;

personal-account-dealing controls;

access restrictions;

transaction monitoring; and

employee training.

Historically these arrangements have sometimes been described as “Chinese walls.”

 

8. Market Manipulation

Market manipulation can include conduct that creates or is capable of creating misleading signals concerning:

supply;

demand;

price; or

trading conditions.

Potential examples include:

artificial transactions;

deceptive orders;

dissemination of false information;

coordinated manipulation;

certain benchmark-related conduct; and

other artificial price practices.

Not every large trade or unusual price movement constitutes manipulation.

Intent, conduct, market circumstances and the specific MAR provisions must be examined.

 

9. False or Misleading Information

Banks and listed banking groups must communicate accurately with markets.

Potentially problematic conduct includes knowingly or unlawfully disseminating false or misleading information concerning:

financial condition;

losses;

capital;

asset quality;

liquidity;

securities;

acquisitions; or

other price-sensitive matters.

Market disclosure therefore interacts with accounting, audit and corporate-governance obligations.

 

10. Prospectus Fraud

A public offering or admission of securities to trading can require a prospectus under the applicable EU and Spanish framework.

The EU Prospectus Regulation — Regulation (EU) 2017/1129 is central.

The prospectus provides investors with information concerning matters such as:

issuer;

financial condition;

securities;

material risks;

use of proceeds; and

offering terms.

False or materially misleading prospectus information can create significant liability.

 

11. Bankia Litigation

One of the most important Spanish examples concerns Bankia's 2011 stock-market flotation.

Investors alleged that information accompanying the offering did not accurately represent Bankia's financial condition.

The litigation produced important Spanish and European judgments concerning investor protection and prospectus liability.

It demonstrates that banks themselves can become defendants in securities-related claims when they issue securities.

 

12. Tribunal Supremo — Bankia IPO Cases

Spain's Supreme Court (Tribunal Supremo) issued important judgments on 3 February 2016 concerning Bankia's IPO.

The Court upheld claims brought by retail investors seeking relief concerning their acquisition of Bankia shares.

A central issue was the discrepancy between the financial picture presented during the offering and the bank's subsequent financial position.

Importance

The judgments demonstrate that securities admitted to trading do not exist outside ordinary private-law protections.

Misleading information surrounding an offering can affect the validity or consequences of an investor's contractual decision.

 

13. Bankia — C-910/19

In Bankia SA v Unión Mutua Asistencial de Seguros (UMAS), C-910/19, the CJEU considered prospectus liability in the context of a qualified investor.

The dispute concerned whether an investor that had participated in Bankia's offering could rely on prospectus-related liability.

Importance

The judgment is significant because prospectus information can matter even in transactions involving sophisticated investors.

The precise rights depend on the applicable EU framework and factual circumstances.

 

14. Bankia — C-45/20 and C-46/20 Context

Bankia-related European litigation has also contributed to interpretation of investor-protection and prospectus principles.

The broader lesson is that the European disclosure regime can create meaningful consequences when securities are marketed on the basis of inaccurate or incomplete information.

Banks issuing securities therefore need strong disclosure controls.

 

15. Criminal Proceedings Concerning Bankia

The Bankia flotation also generated major criminal proceedings in Spain.

The Audiencia Nacional ultimately acquitted the defendants in the principal criminal trial concerning the IPO.

This distinction is legally important.

Civil investor claims and criminal liability apply different legal standards.

Therefore:

Civil liability finding ≠ automatic criminal guilt.

Likewise, an acquittal in criminal proceedings does not necessarily erase every civil or regulatory issue arising from the same events.

 

16. Mis-Selling of Securities

Securities fraud must also be distinguished from mis-selling.

Mis-selling can occur where a bank sells an investment product without complying with applicable investor-protection requirements.

Examples can involve:

preference shares;

subordinated debt;

structured products;

derivatives; and

other complex instruments.

Mis-selling does not necessarily require criminal fraud.

It can instead create:

contractual liability;

restitution;

regulatory sanctions; or

damages.

 

17. Spanish Preference-Shares Litigation

Spanish banks faced extensive litigation following the financial crisis concerning the sale of participaciones preferentes (preference shares) to retail customers.

Customers often argued that they did not understand:

perpetual characteristics;

liquidity risk;

loss risk;

subordination; or

complexity.

Spanish courts frequently examined whether the bank had properly informed the investor and complied with MiFID-related obligations.

 

18. Banco Santander — C-598/18

Banco de Santander SA v Demba and Bonet, C-598/18 arose in a different financial context but forms part of the broader CJEU jurisprudence concerning Spanish banking contracts and consumer protection.

Its relevance is mainly contextual rather than a direct securities-fraud precedent.

For securities litigation, it is important not to label every banking consumer case as securities fraud.

The legal basis must be identified precisely.

 

19. Genil 48 — C-604/11

Genil 48 SL and Comercial Hostelera de Grandes Vinos SL v Bankinter SA and BBVA SA, C-604/11 is particularly important for Spanish banking and investment services.

The case concerned interest-rate swaps sold by banks.

The CJEU examined the relationship between MiFID investment-service obligations and other EU legislation.

Importance

Where a bank provides investment services, it may have duties relating to:

information;

suitability;

appropriateness; and

conflicts of interest.

Failure to satisfy these obligations can support private-law consequences under national law, depending on the circumstances.

 

20. MiFID II

Directive 2014/65/EU (MiFID II) is fundamental to securities distribution by Spanish banks.

Banks providing investment services must comply with requirements concerning:

client classification;

suitability;

appropriateness;

product governance;

conflicts of interest;

inducements;

information;

best execution; and

record keeping.

These requirements are intended to reduce the risk of customers purchasing products they do not understand or that are inappropriate for them.

 

21. Suitability

When investment advice or portfolio management is provided, the bank generally needs information relevant to assessing suitability.

This can include the customer's:

investment knowledge;

experience;

financial situation;

ability to bear losses;

investment objectives; and

risk tolerance.

A bank should not simply recommend a high-risk security because it generates higher fees.

 

22. Appropriateness

For certain non-advised investment services involving complex instruments, an appropriateness assessment may be required.

The bank examines whether the customer has sufficient knowledge and experience to understand the product's risks.

Suitability and appropriateness are not identical concepts.

 

23. Conflicts of Interest

Banks can have conflicts because they may simultaneously:

lend to an issuer;

underwrite its securities;

publish research;

advise investors;

trade the securities;

manage client portfolios; and

hold the securities themselves.

Banks must identify and manage conflicts under applicable rules.

Disclosure alone may not always be sufficient where stronger organizational controls are required.

 

24. Product Governance

MiFID II introduced stronger product-governance requirements.

Banks manufacturing or distributing investment products should identify an appropriate target market.

A highly complex security designed for sophisticated institutional investors should not casually be distributed to inexperienced retail customers.

Product governance therefore acts as a preventive mechanism against mis-selling.

 

25. Securities Fraud and Criminal Law

Certain serious securities misconduct can constitute criminal offences under Spain's Criminal Code (Código Penal).

Potentially relevant areas include:

investment fraud;

false financial information;

market manipulation;

insider dealing;

corporate offences;

document falsification; and

money laundering.

Criminal liability requires satisfaction of the statutory elements of the particular offence.

A regulatory breach should not automatically be described as criminal fraud.

 

26. Market Abuse as Criminal Conduct

Particularly serious insider dealing or market manipulation can potentially trigger criminal liability where the requirements of Spanish criminal law are met.

Other cases may instead result in administrative enforcement.

The distinction can depend on matters such as:

seriousness;

financial benefit;

losses;

market impact;

intent; and

statutory thresholds.

 

27. Administrative Sanctions

The CNMV can investigate securities-law infringements and, within its legal powers, impose administrative sanctions.

Possible consequences can include:

fines;

public reprimands;

restrictions;

suspension;

disqualification; and

other measures provided by law.

Banks should therefore maintain surveillance systems before misconduct reaches the level of criminal proceedings.

 

28. Corporate Criminal Liability

Spanish law recognizes criminal liability of legal persons for specified offences where statutory conditions are satisfied.

A bank can therefore potentially face corporate criminal exposure for qualifying misconduct committed within the organization.

An effective compliance system can be highly important.

Relevant measures include:

compliance policies;

risk mapping;

employee training;

reporting channels;

monitoring;

independent investigation; and

disciplinary mechanisms.

 

29. Management Responsibility

Senior executives and directors are not automatically criminally liable merely because misconduct occurs inside a bank.

Individual liability requires the elements required by applicable law.

However, governance failures can create:

supervisory consequences;

corporate-law responsibility;

administrative liability; and

in sufficiently serious cases, criminal issues.

Responsibility must therefore be established individually rather than assumed from job title.

 

30. Benchmark Manipulation

Banks participate in markets where financial benchmarks affect enormous volumes of contracts.

Manipulating benchmark submissions can affect:

derivatives;

loans;

bonds;

mortgages; and

investment products.

Following international benchmark scandals, EU legislation strengthened benchmark governance through Regulation (EU) 2016/1011 (Benchmarks Regulation).

Manipulative conduct can also fall within market-abuse rules.

 

31. Research and Investment Recommendations

Bank research can influence securities prices.

Research functions should therefore maintain controls concerning:

conflicts;

issuer relationships;

personal trading;

disclosure;

factual accuracy; and

independence.

Publishing misleading research to influence a security's price can create serious regulatory concerns.

 

32. Spoofing and Algorithmic Trading

Modern manipulation can involve electronic orders rather than false paper documents.

Examples may include patterns intended to create a misleading appearance of market demand or supply.

Banks operating algorithmic-trading systems therefore require:

pre-trade controls;

market-abuse surveillance;

order monitoring;

algorithm testing;

kill mechanisms; and

audit trails.

Automation does not remove legal responsibility.

 

33. Suspicious Transaction and Order Reports

EU market-abuse rules require relevant market participants to identify and report suspicious transactions and orders in circumstances covered by the legislation.

Banks therefore use surveillance systems to detect patterns potentially indicating:

insider dealing;

manipulation; or

attempted manipulation.

A suspicious report is not itself proof of criminal conduct.

It is a regulatory detection mechanism.

 

34. Whistleblowing

Internal reporting channels can identify securities misconduct before regulators discover it externally.

Employees may report:

false disclosures;

improper trading;

conflicts;

manipulation;

misuse of confidential information; or

control failures.

Spanish and EU whistleblower-protection frameworks provide protections in qualifying circumstances.

 

35. Civil Liability

Investors suffering loss can potentially pursue civil claims depending upon the legal basis.

Possible claims can involve:

contractual breach;

invalid consent;

damages;

prospectus liability;

negligent advice; or

other private-law remedies.

The investor generally needs to establish the elements required for the particular claim.

Not every investment loss establishes bank liability.

 

36. Investment Loss Is Not Automatically Fraud

This distinction is essential.

Suppose a customer purchases shares for €20,000 and their value falls to €10,000.

The loss alone does not establish securities fraud.

Markets involve legitimate risk.

Potential liability instead depends on issues such as:

Was material information false?

Was information unlawfully withheld?

Was the customer deceived?

Did manipulation occur?

Were investment-service obligations breached?

Did the misconduct cause the claimed loss?

 

37. Causation

Causation is particularly important in securities litigation.

An investor may need to establish a sufficient relationship between:

wrongful conduct → investment decision or market effect → financial loss.

If the loss resulted entirely from unrelated market developments, establishing damages against the bank may be more difficult.

The precise test depends upon the legal cause of action.

 

38. Evidence

Securities-fraud investigations can involve large amounts of evidence:

emails;

recorded calls;

trading records;

order books;

prospectuses;

financial statements;

board minutes;

compliance alerts;

internal reports;

customer files; and

electronic communications.

Banks therefore have extensive record-keeping obligations.

Electronic evidence can be particularly important in proving knowledge and intent.

 

39. Market Abuse and AML

Securities fraud can also generate money-laundering risks.

For example:

market manipulation → illegal profit → movement of proceeds through accounts.

Banks therefore need coordination between:

market-surveillance teams;

AML teams;

fraud investigators;

compliance;

legal departments; and

internal audit.

Financial-crime risks should not be managed in isolated silos.

 

40. Case: Spector Photo Group — C-45/08

Spector Photo Group NV and Chris Van Raemdonck v CBFA, C-45/08 is an important CJEU insider-dealing judgment.

The Court interpreted elements of the EU insider-dealing regime.

Relevance to Spanish Banks

Because Spain operates within the harmonized EU market-abuse framework, European jurisprudence concerning inside information and its use is highly relevant to Spanish financial institutions.

 

41. Case: Geltl v Daimler — C-19/11

Markus Geltl v Daimler AG, C-19/11 concerned the concept of inside information.

The Court considered whether intermediate steps in a multi-stage process can constitute precise information.

Banking Relevance

Banks advising clients on:

mergers;

acquisitions;

restructurings; or

major securities transactions

may obtain information before a final corporate decision is completed.

Geltl shows why compliance teams cannot assume that information becomes “inside information” only when the final transaction is signed.

 

42. Case: Lafonta — C-628/13

Jean-Bernard Lafonta v Autorité des marchés financiers, C-628/13 further interpreted the meaning of precise information under EU market-abuse law.

Importance

Inside information does not necessarily require certainty about whether the eventual price movement will be upward or downward.

This is relevant to banks handling confidential issuer information.

 

43. Case: Grøngaard and Bang — C-384/02

Knud Grøngaard and Allan Bang, C-384/02 concerned disclosure of inside information.

The CJEU considered circumstances in which communication of inside information could potentially be justified in the normal exercise of employment, profession or duties.

Banking Relevance

Bank employees often need to share confidential information internally.

The case helps illustrate why legitimate professional disclosure must be distinguished from unlawful disclosure.

 

44. Case: IMC Securities — C-445/09

IMC Securities BV v Stichting Autoriteit Financiële Markten, C-445/09 concerned market manipulation under the earlier EU framework.

Relevance

The case contributes to the interpretation of manipulative market conduct and remains useful background for understanding the development of the current MAR regime.

 

45. Case: Genil 48 — C-604/11

This Spanish reference is particularly relevant because it directly involved Bankinter and BBVA.

The CJEU examined investment-service obligations relating to financial products.

Core Lesson

A bank's status as a traditional lender does not exempt it from securities and investment-services requirements when it performs investment activities.

Banking law and securities law can therefore apply simultaneously.

 

46. Case: Bankia IPO — Spanish Supreme Court, 3 February 2016

The Bankia judgments provide an especially important Spanish example.

Retail investors had purchased shares during Bankia's 2011 flotation.

The Supreme Court addressed the consequences of the financial information provided to those investors.

Core Lesson

Accurate issuer disclosure is fundamental to informed investment consent.

A bank issuing its own securities can therefore face private-law consequences if legally material offering information is defective.

 

47. Case: Bankia v UMAS — C-910/19

This case further developed the European dimension of Bankia prospectus litigation.

Core Lesson

Prospectus liability cannot be understood exclusively through national contract law.

The EU securities-disclosure framework must also be considered, including where sophisticated investors are involved.

 

48. Practical Example — False Prospectus

Suppose a Spanish bank issues shares.

The prospectus states that the bank has:

strong asset quality and stable profitability.

Internal documents, however, allegedly show material losses that should legally have been disclosed.

Investors purchase the securities and later suffer losses.

Possible legal questions include:

Was the prospectus inaccurate?

Was the omitted information material?

Who was legally responsible for the prospectus?

Did the investor rely on legally relevant information?

Did the defect cause the claimed loss?

Does civil, administrative or criminal liability arise?

The answers depend on evidence and the applicable legal provisions.

 

49. Practical Example — Insider Trading

A bank employee learns confidentially that a listed company will be acquired.

Before announcement, the employee purchases shares.

The compliance analysis would examine:

Was the information inside information?

Did the employee possess it?

Was it used in acquiring the shares?

Was any statutory exception applicable?

Were other people tipped?

The bank would also examine whether its internal controls detected or should have detected the activity.

 

50. Practical Example — Mis-Selling

A retired retail customer with little investment experience approaches a bank seeking a low-risk savings product.

The bank instead recommends a complex subordinated security without adequately explaining the possibility of substantial loss.

This may raise:

MiFID suitability issues;

disclosure questions;

contractual-consent issues;

civil liability; and

regulatory concerns.

It should not automatically be labelled criminal securities fraud unless the elements of a criminal offence are independently established.

 

51. Bank Compliance Framework

An effective securities-fraud prevention programme should include:

Governance

Board and senior-management oversight.

Information Barriers

Separation of confidential functions.

Market Surveillance

Monitoring orders and trades.

Personal Trading Controls

Employee dealing restrictions.

Disclosure Controls

Verification of issuer statements.

Product Governance

Identification of appropriate customers.

Suitability and Appropriateness

MiFID assessments.

Conflict Management

Identification and mitigation of conflicts.

Whistleblowing

Protected internal reporting.

Investigation

Independent examination of suspicious activity.

 

52. Three Layers of Liability

A useful distinction is:

Administrative

CNMV / competent authority → investigation → regulatory sanction.

Civil

Investor → bank → compensation, restitution or other private remedy.

Criminal

Prosecutor → accused person/entity → criminal proceedings.

The same event may generate more than one form of proceeding, but each requires its own legal basis and standard.

 

53. Key Case-Law Principles

The principal authorities illustrate several different areas:

Aziz and consumer-banking cases concern consumer protection rather than securities fraud and should not be confused with securities-market cases.

Genil 48 (C-604/11) demonstrates the significance of investment-service obligations when banks sell financial products.

Spector Photo Group (C-45/08) addresses insider-dealing principles.

Geltl (C-19/11) and Lafonta (C-628/13) help define inside information.

Grøngaard and Bang (C-384/02) addresses disclosure of inside information.

IMC Securities (C-445/09) concerns market manipulation.

Bankia's 2016 Spanish Supreme Court litigation demonstrates the consequences of defective information surrounding a bank securities offering.

Bankia v UMAS (C-910/19) addresses prospectus liability within the EU framework.

 

54. Key Legal Principles

Spanish securities fraud involving banks can be summarized through ten principles:

1. Banks are subject to securities law when performing securities or investment activities.

2. Inside information cannot lawfully be exploited merely because it was obtained through ordinary banking work.

3. Market manipulation can occur through transactions, orders or information.

4. Securities prospectuses must provide legally required, accurate material information.

5. Investment loss alone does not prove fraud.

6. Mis-selling and criminal fraud are legally distinct.

7. MiFID requires substantial investor-protection controls.

8. Conflicts between lending, underwriting, research and trading must be managed.

9. Corporate, individual, administrative and civil responsibility must be analysed separately.

10. EU law is fundamental to Spanish securities enforcement.

 

55. Conclusion

Banking Law and Securities Fraud Involving Banks in Spain sits at the intersection of banking regulation, securities law, criminal law, investor protection and EU market-abuse legislation.

The principal modern framework includes Spanish Law 6/2023 on Securities Markets and Investment Services, Market Abuse Regulation (EU) 596/2014, MiFID II (Directive 2014/65/EU), Prospectus Regulation (EU) 2017/1129, the Spanish Criminal Code, and applicable civil-law rules.

Banks can become involved in securities misconduct in several capacities:

Bank as issuer → prospectus/disclosure risk

Bank as adviser → suitability and conflict risk

Bank as broker → execution and market-abuse risk

Bank as trader → insider-dealing/manipulation risk

Bank as distributor → mis-selling risk

Bank as custodian → asset and operational risks

Important authorities include Genil 48 (C-604/11), Spector Photo Group (C-45/08), Geltl (C-19/11), Lafonta (C-628/13), Grøngaard and Bang (C-384/02), IMC Securities (C-445/09), the Spanish Supreme Court's Bankia IPO judgments of 3 February 2016, and Bankia v UMAS (C-910/19).

The Bankia litigation is especially significant for Spain because it demonstrates the potential consequences when a bank is itself the securities issuer and investors challenge the reliability of information supplied during a public offering.

Ultimately, the legal framework seeks to preserve:

accurate disclosure + fair markets + informed investors + controlled conflicts + protection of inside information + effective supervision.

A Spanish bank therefore needs to manage securities-fraud risk not merely as a criminal-law problem but as a comprehensive market-conduct, investor-protection, governance and compliance obligation.

LEAVE A COMMENT