Traster Comms
Blog
CNMV Data Security: Guide for EAF and Fund Managers
CNMVdata securityEAFfund managersinsider information

CNMV Data Security: Guide for EAF and Fund Managers

CNMV compliance guide for financial advisory firms and fund managers. Insider information, insider lists and secure communications.

The CNMV has intensified its supervision with 71 fines totaling €19.46M in 2025. This article explains how EAF and fund managers can protect their communications to comply with CNMV obligations.

CNMV strengthens communications supervision

In 2025, the CNMV:

  • Received over 70 million transaction records (35% more than 2024)
  • Sent 39 million records to European authorities
  • Initiated 15 sanctioning proceedings with 29 alleged violations
  • Imposed 71 fines totaling €19.46M

The message is clear: reporting errors, delays, incomplete insider lists and poorly documented decisions are less likely to go unnoticed.

Communication obligations for regulated entities

Insider information

Insider information is any information that may affect the price of a listed security and is not yet public. Entities must:

  • Establish procedures to identify and manage insider information
  • Maintain up-to-date insider lists
  • Ensure that communications about insider information are secure and auditable

Insider lists

Entities must maintain updated lists of persons with access to insider information, including:

  • Person's name and position
  • Date of access to information
  • Description of information
  • Reason for access

Continuous reporting

CNMV requires:

  • Daily transaction reporting
  • Executive transaction notifications
  • Material facts
  • Privileged information

The problem of insecure communications

Many regulated entities use channels that don't meet CNMV obligations:

ChannelArchivingAuditKey ControlCNMV Compliance
WhatsAppNoNoNoNo
SignalNoNoNoNo
TelegramNoNoNoNo
EmailPartialPartialNoPartial
Traster CommsYesYesYesYes

How Traster Comms helps comply with CNMV

  1. Communication archiving: All communications are archived and available for audits
  2. E2E encryption with own keys: The entity controls encryption keys
  3. Access lists: Granular control of who accesses what information
  4. Complete audit: Record of all communications for inspections
  5. Data sovereignty: Data remains under entity control

Use cases for EAF and fund managers

Client communications

EAF must ensure investment recommendations are transmitted through secure, archived channels.

Investment decisions

Fund managers need secure channels to communicate portfolio decisions between investment teams.

Insider information

Communications about material facts before publication must be protected against leaks.

Frequently asked questions

What penalties does CNMV impose for communication violations?

In 2025, CNMV imposed 71 fines totaling €19.46M. The most relevant violations relate to market abuse and illicit use of insider information.

How can an EAF protect its client communications?

By using communication platforms with end-to-end encryption, regulatory archiving and organization-controlled key management.

Is email sufficient to comply with CNMV?

Email provides partial archiving but not E2E encryption or key control. It is not sufficient for communications about insider information.

Related articles

AES 256 Encryption: Enterprise Data Protection
AES 256 encryptionenterprise data protectionend-to-end encryptionGDPR compliancemilitary-grade security

AES 256 Encryption: Enterprise Data Protection

Protect your enterprise with AES 256 encryption. GDPR compliance, end-to-end encryption, and military-grade security for your data.

Read more

Ready for truly secure communications?

Contact us for a personalized, no-obligation consultation.

Request information