Gross Negligence in Bank Fraud: How Spanish Case Law Has Shifted (STS 571/2025 and Provincial Courts 2024-2026)
When a bank refuses to refund a fraud victim it almost always alleges the customer's "gross negligence". Supreme Court Judgment 571/2025 of 9 April and recent Provincial Court rulings have raised that threshold sharply: being deceived is not the same as being grossly negligent. We analyse when the bank pays and when the customer loses.
The essentials in thirty seconds
If your account has been emptied through *phishing*, *smishing* (fake SMS) or *vishing* (a call impersonating your bank), the legal starting point is that the bank must refund you immediately. The exception is where the bank proves you acted fraudulently or with gross negligence. That exception is the real battleground in every cyber-fraud case, and recent case law has narrowed it considerably.
Supreme Court Judgment 571/2025 of 9 April sets the standard now applied by the Provincial Courts: the fact that a third party obtained your credentials does not, on its own, mean you were grossly negligent. Gross negligence requires inexcusable conduct, not simple human error in the face of a sophisticated deception.
1. What the statute says before you look at the judgments
The framework is Royal Decree-Law 19/2018 on payment services (implementing the PSD2 Directive):
- Art. 36: you must report the unauthorised transaction without undue delay and, at the latest, within 13 months of the debit.
- Art. 44: where you deny having authorised the transaction, the burden is on the bank to prove the payment was authenticated, recorded and correctly accounted for. And the authentication record is not in itself sufficient to prove the customer authorised it, acted fraudulently or was grossly negligent.
- Art. 45: the bank must refund the amount immediately and no later than the end of the following business day after notification, restoring the account as if the debit had never happened.
- Art. 46: the customer only bears the loss where they acted fraudulently or with gross negligence in safeguarding their credentials.
Two practical consequences that are routinely forgotten:
- The burden of proof lies with the bank, not the customer. You do not have to prove you were careful.
- The refund must be immediate; the bank cannot sit on the money "while it investigates" for months.
2. The Supreme Court standard: STS 571/2025 of 9 April
This is the leading decision on the meaning of gross negligence, and it yields four criteria:
- A third party gaining access to your credentials does not amount to gross negligence. That is a fact, not a legal conclusion.
- Gross negligence requires inexcusable conduct. Human error against an elaborate scam is not enough: today's phishing techniques deceive even cautious users.
- The standard of care owed by the bank is not that of the "reasonable family man" under art. 1104 of the Civil Code, but that of an orderly and expert trader. A payment service provider is a professional with technical resources: more is required of it than of the customer.
- Generic allegations by the bank will not do. It must show, with the specific transaction record and objective data, that gross negligence occurred.
That fourth point decides most cases: banks turn up with a standard internal report saying "transaction authenticated by digital signature and OTP code", and the courts answer that this proves the payment was executed, not that the customer was grossly negligent.