
CNMV Data Security: Guide for EAF and Fund Managers
CNMV compliance guide for financial advisory firms and fund managers. Insider information, insider lists and secure communications.
The CNMV has intensified its supervision with 71 fines totaling €19.46M in 2025. This article explains how EAF and fund managers can protect their communications to comply with CNMV obligations.
CNMV strengthens communications supervision
In 2025, the CNMV:
- Received over 70 million transaction records (35% more than 2024)
- Sent 39 million records to European authorities
- Initiated 15 sanctioning proceedings with 29 alleged violations
- Imposed 71 fines totaling €19.46M
The message is clear: reporting errors, delays, incomplete insider lists and poorly documented decisions are less likely to go unnoticed.
Communication obligations for regulated entities
Insider information
Insider information is any information that may affect the price of a listed security and is not yet public. Entities must:
- Establish procedures to identify and manage insider information
- Maintain up-to-date insider lists
- Ensure that communications about insider information are secure and auditable
Insider lists
Entities must maintain updated lists of persons with access to insider information, including:
- Person's name and position
- Date of access to information
- Description of information
- Reason for access
Continuous reporting
CNMV requires:
- Daily transaction reporting
- Executive transaction notifications
- Material facts
- Privileged information
The problem of insecure communications
Many regulated entities use channels that don't meet CNMV obligations:
| Channel | Archiving | Audit | Key Control | CNMV Compliance |
|---|---|---|---|---|
| No | No | No | No | |
| Signal | No | No | No | No |
| Telegram | No | No | No | No |
| Partial | Partial | No | Partial | |
| Traster Comms | Yes | Yes | Yes | Yes |
How Traster Comms helps comply with CNMV
- Communication archiving: All communications are archived and available for audits
- E2E encryption with own keys: The entity controls encryption keys
- Access lists: Granular control of who accesses what information
- Complete audit: Record of all communications for inspections
- Data sovereignty: Data remains under entity control
Use cases for EAF and fund managers
Client communications
EAF must ensure investment recommendations are transmitted through secure, archived channels.
Investment decisions
Fund managers need secure channels to communicate portfolio decisions between investment teams.
Insider information
Communications about material facts before publication must be protected against leaks.
Frequently asked questions
What penalties does CNMV impose for communication violations?
In 2025, CNMV imposed 71 fines totaling €19.46M. The most relevant violations relate to market abuse and illicit use of insider information.
How can an EAF protect its client communications?
By using communication platforms with end-to-end encryption, regulatory archiving and organization-controlled key management.
Is email sufficient to comply with CNMV?
Email provides partial archiving but not E2E encryption or key control. It is not sufficient for communications about insider information.


