Contractual Liability of Banks in Phishing Cases: Articles 1101 and 1104 of the Spanish Civil Code after STS 571/2025

Beyond PSD2 and RDL 19/2018, Supreme Court Judgment STS 571/2025 opens the door to a purely contractual claim against the bank based on breach of its custody duty and the professional diligence required under articles 1101 and 1104 of the Spanish Civil Code. We analyse how to structure the claim, culpa in vigilando and the professional-risk doctrine.

1. One incident, two liability routes

When a client suffers a banking fraud through phishing, smishing, vishing or SIM swapping, practitioners tend to focus almost exclusively on the regulatory route: PSD2 (Directive 2015/2366) and its Spanish transposition through Royal Decree-Law 19/2018, which impose on banks a quasi-objective liability for unauthorised transactions unless there is fraud or gross negligence by the customer.

We already analysed that angle in our articles on [bank phishing liability in Spain](https://bufetepadillatorrevieja.com/en/blog/phishing-bancario-bank-liability-spain) and [CJEU case law on online banking fraud](https://bufetepadillatorrevieja.com/en/blog/tjue-ciberestafas-banca-responsabilidad-fraude-online-2026).

The recent Supreme Court Judgment STS 571/2025 of 9 April also reinforces a second, autonomous and complementary route: the contractual liability arising from articles 1101 and 1104 of the Spanish Civil Code. This article focuses exclusively on that second route.

2. The bank-customer relationship as a reinforced contract

Current accounts, deposits and payment services are, in essence, a complex banking contract combining custody, fund management and execution of payment orders. The bank is not a neutral intermediary: it is a financial professional paid for its services and inherently bound to preserve and protect the assets entrusted by the client.

Two Civil Code provisions govern the analysis:

  • Article 1101 CC: anyone who, in performing an obligation, incurs in fraud, negligence or delay, or in any manner contravenes its terms, is liable for the damages caused.
  • Article 1104 CC: negligence consists in failing to apply the diligence required by the nature of the obligation and the circumstances of person, time and place; absent a specific standard, the diligence of a "good family father" (*bonus pater familias*) is required.

Case law has for decades adjusted that "reasonable person" standard when the debtor is a qualified professional. In banking, the required standard of care is not that of an average citizen but of a financial-security expert with vastly superior technical, human and regulatory resources.

3. What STS 571/2025 adds on the contractual front

Although STS 571/2025 relies expressly on RDL 19/2018, its reasoning is fully transferable to article 1101 CC. The Supreme Court underlines:

  1. The bank holds a contractual position as guarantor of the security of operations and integrity of funds.
  2. The burden of proof as to authorisation, correct operation of its systems and absence of technical failures lies with the bank, not the customer.
  3. The mere internal record of the transaction is not sufficient to prove valid consent or exonerate the bank.
  4. Only exceptional cases of proven fraud or gross negligence by the user allow the bank to escape liability.