Banking Law And Economic Liberties Spain .

Banking Law and Economic Espionage – Spain

Introduction

Economic espionage in Spanish banking law refers to the unlawful acquisition, copying, disclosure or exploitation of confidential commercial or financial information for competitive or economic advantage. It may involve customer databases, pricing models, credit-scoring systems, investment strategies, algorithms, merger plans, cybersecurity information, trading strategies, risk models or other commercially valuable information.

Spain does not regulate economic espionage through one single banking statute. Instead, protection results from a combination of the Spanish Criminal Code, Law 1/2019 on Trade Secrets, banking confidentiality rules, data-protection legislation, cybersecurity requirements, employment duties and EU financial-services law.

For banks, the issue is particularly serious because they possess both commercial secrets belonging to the institution and confidential information concerning millions of customers.

Legal and Regulatory Framework

Law 1/2019 on Trade Secrets

Law 1/2019 implements Directive (EU) 2016/943 and provides Spain's principal civil framework for protecting business secrets.

Information qualifies as a trade secret where three essential requirements are satisfied:

it is secret and not generally known or readily accessible;

it possesses actual or potential commercial value because it is secret; and

its lawful holder has taken reasonable measures to preserve its secrecy.

For a bank, qualifying information could therefore include proprietary risk methodologies, internal financial models, strategic acquisition plans, confidential customer segmentation, non-public pricing strategies or protected software.

Simply marking material "confidential" does not automatically convert it into a legally protected trade secret.

Criminal Protection

Articles 278–280 of the Spanish Criminal Code establish particularly important criminal protections.

Article 278 addresses obtaining documents, electronic information, computer media or other material for the purpose of discovering a business secret. More serious consequences can arise when the information obtained is subsequently disclosed or transferred.

Article 279 deals particularly with persons who are already under a legal or contractual duty of confidentiality and nevertheless disclose, transfer or improperly exploit the information.

Article 280 addresses persons who did not themselves obtain the secret but knowingly exploit or disclose information originating from unlawful acquisition.

These provisions are highly relevant to employees, consultants, technology providers and executives of banks.

Economic Espionage by Employees

One of the most significant risks originates internally.

A bank employee may legitimately have access to:

customer portfolios;

lending strategies;

internal pricing;

credit-risk models;

acquisition targets;

treasury strategies;

proprietary algorithms;

cybersecurity architecture; and

confidential product-development information.

Authorised access does not mean that an employee is free to copy this information and transfer it to a competitor.

Where an employee is contractually or legally required to preserve confidentiality, deliberate disclosure can potentially trigger employment, civil and criminal consequences.

Cyber-Espionage Against Banks

Modern economic espionage frequently takes a digital form.

Cyber intrusions may seek commercially valuable information rather than simply money. Attackers can target strategic documents, customer databases, transaction information, technological systems or confidential communications.

Spanish criminal-law provisions governing unauthorised access to information systems and discovery of secrets can therefore operate alongside the specific business-secret offences.

From the banking-law perspective, cybersecurity has consequently become part of prudential risk management rather than merely an information-technology matter.

Banks must maintain appropriate governance, access controls, monitoring, incident management and operational-resilience systems to protect sensitive information.

Banking Confidentiality

Banking secrecy and trade-secret protection must be distinguished.

Banking confidentiality primarily protects information about customers and their financial relationships.

Trade-secret law principally protects economically valuable confidential information belonging to an undertaking.

A stolen customer database can involve both regimes simultaneously. The information may contain protected personal data while the structure and commercial value of the customer portfolio may constitute a business secret.

Consequently, one act of economic espionage can potentially create criminal, civil, data-protection, contractual and regulatory liability.

Important Case Laws

1. Spanish Supreme Court, STS 285/2008, 12 May 2008

This is an important Spanish authority concerning the meaning of a business secret.

The Supreme Court recognised that customer and supplier information can constitute protected business information because such information may provide an important competitive advantage.

A customer portfolio developed through commercial activity cannot necessarily be taken by an employee and transferred to a competing undertaking merely because the employee had access to it during employment.

The decision is especially relevant to banks because client lists and detailed customer relationships can represent valuable commercial assets.

2. Spanish Supreme Court, Judgment of 16 December 2008, Appeal No. 491/2008

This case involved a former worker who established a competing business and used customer information belonging to the previous undertaking.

The customer list of the new undertaking reportedly corresponded overwhelmingly with that of the former employer.

The Supreme Court regarded improper use of customer information as capable of falling within the criminal protection of business secrets.

For banking institutions, the principle applies particularly strongly to relationship-manager portfolios and confidential customer databases.

3. Spanish Supreme Court, Appeal No. 1467/2007

Another important decision involved a commercial director who moved to a competing undertaking and carried business information from the former company.

The relevant material included product information, acquisition and sale prices, suppliers and customers.

The court treated the transfer of commercially sensitive information by an individual subject to confidentiality obligations as capable of constituting unlawful disclosure of business secrets under Article 279 of the Criminal Code.

Applied to banking, an executive cannot simply transfer proprietary loan-pricing structures, customer portfolios or strategic commercial information to a competing financial institution.

4. Provincial Court of Madrid – Employee Information Case, 2015

This decision demonstrates the limits of the offence.

A dismissed employee used internal information in defending employment proceedings. The court concluded that the material concerned had not been sufficiently established as a genuine business secret and that the necessary criminal elements were absent.

The court distinguished information that is merely confidential or sensitive from information possessing the characteristics necessary to constitute a legally protected business secret.

This distinction is fundamental in economic-espionage litigation. A bank cannot merely state that information is confidential; it must establish why it genuinely deserves legal protection.

5. Spanish Supreme Court, Social Chamber, Judgment 1067/2021, 28 October 2021

This judgment provides one of the clearest modern explanations of the concept of a trade secret in Spain.

The dispute concerned confidential business material and whether judicial proceedings should have received additional protection to prevent disclosure.

The Supreme Court emphasised that not every piece of sensitive or confidential corporate information is automatically a trade secret.

The information must satisfy the statutory requirements of secrecy, commercial value arising from its secrecy and reasonable measures taken by its holder to preserve confidentiality.

For banks, this means practical protection is crucial. Access restrictions, confidentiality clauses, classification systems and cybersecurity controls can help demonstrate that reasonable secrecy measures existed.

6. Baumeister, Case C-15/16

The Court of Justice of the European Union considered confidentiality in financial supervision in Baumeister.

The case concerned information held by a financial supervisory authority and the interpretation of professional-secrecy obligations under EU financial-services legislation.

The Court rejected an unlimited concept under which every document obtained by a supervisory authority automatically remained confidential indefinitely.

Instead, the confidentiality assessment must consider the nature and sensitivity of the relevant information.

The decision is extremely important for Spanish banking because confidential information submitted to banking and financial regulators can fall within EU professional-secrecy rules.

7. Varec SA v Belgian State, Case C-450/06

The Court of Justice addressed the conflict between effective judicial protection and preservation of confidential business information.

It recognised that courts may need to protect trade secrets and commercially confidential information even while ensuring that parties receive a fair hearing.

The principle is relevant to Spanish banking litigation where supervisory proceedings, procurement disputes or commercial cases contain confidential banking technology, financial models or strategic information.

Economic-espionage protection would be weakened if bringing a legal action automatically required publication of the very secret the proceedings were intended to protect.

8. Bank Austria Creditanstalt AG v European Commission, Case T-198/03

This EU case is particularly relevant because it involved a banking institution and questions concerning confidentiality and publication of regulatory information.

The General Court examined when information contained in regulatory proceedings can legitimately retain confidential status and when publication may be permissible.

The case illustrates that professional secrecy does not create an unlimited right to suppress every piece of commercially undesirable information.

For Spanish banks, confidentiality claims therefore need to identify concrete commercial interests and genuine harm that disclosure could produce.

Reasonable Measures to Protect Banking Secrets

A significant feature of Law 1/2019 is that valuable information must have been subject to reasonable protective measures.

For banking institutions, appropriate measures can include internal information classification, limited employee access, confidentiality agreements, technical security controls, logging systems, segregation of sensitive databases and procedures governing employee departure.

The legal significance is substantial.

If a bank treats strategically valuable information as freely accessible throughout the organisation, it may encounter greater difficulty proving that the information constituted a protected trade secret.

Remedies for Economic Espionage

Spanish trade-secret legislation provides substantial civil remedies.

Depending on the circumstances, a holder may seek declarations that unlawful conduct occurred, cessation of use or disclosure, prohibition of future exploitation, removal of infringing material, compensation for damage and appropriate publication of the judgment.

Law 1/2019 also contains procedural mechanisms intended to preserve confidentiality during litigation itself.

This is particularly important in banking disputes because unrestricted disclosure during litigation could destroy the economic value of the protected information.

Economic Espionage and Personal Data

Where espionage concerns customer records, Spain's data-protection framework also becomes relevant.

Financial information may constitute personal data protected under the GDPR and Spain's Organic Law on Data Protection and Guarantee of Digital Rights.

An incident involving customer information can consequently become simultaneously:

a trade-secret incident, where commercially valuable confidential information is stolen;

a data-protection incident, where personal information is compromised;

a cybersecurity incident, where information systems are infiltrated; and

a banking-regulatory incident, where governance and operational safeguards prove inadequate.

Competition and Employee Mobility

Trade-secret protection must not be confused with a prohibition on legitimate competition.

Former employees ordinarily retain their general skills, knowledge and professional experience.

The law does not permit an employer to transform everything an employee learned during employment into proprietary information.

The critical distinction is between ordinary professional knowledge and identifiable secret information possessing commercial value and protected through reasonable secrecy measures.

This principle maintains a balance between protecting financial institutions and preserving lawful employee mobility and market competition.

Conclusion

Economic espionage in Spanish banking is regulated through an interconnected framework of trade-secret, criminal, banking, data-protection, cybersecurity and EU law.

Law 1/2019 protects secret information possessing economic value where reasonable measures have been adopted to preserve confidentiality, while Articles 278–280 of the Criminal Code provide criminal protection against unlawful acquisition, disclosure and exploitation of business secrets.

Cases including STS 285/2008, the Supreme Court judgments concerning former employees and customer information, STS 1067/2021, Baumeister, Varec and Bank Austria Creditanstalt demonstrate that courts distinguish genuine trade secrets from material that is merely labelled confidential.

For banks, the central principle is therefore that legal protection begins before espionage occurs. A financial institution must identify commercially sensitive information and establish genuine confidentiality, technical security and access controls. When those protections exist, Spanish and EU law provide substantial remedies against the unlawful acquisition, disclosure or exploitation of economically valuable banking information.

LEAVE A COMMENT