Internal procedure

Internal Information System Policy and Procedure

The approval of Law 2/2023, of February 20, Regulator of Protection of Persons who report on normative and anti-corruption infractions, (hereinafter “Law 2/2023”), obliges both the public sector and the private sector to have channels Internal information designed and implemented to protect people who detect potential infractions in a work or professional context. Specifically, as expressed in art. 13 of Law 2/2023 All entities that make up the public sector will be obliged to have an internal information system, including among them, the foundations of the public sector, as expressed in its section.1 letter f).

The Entity, through this Policy, undertakes to take the necessary measures to prevent any type of retaliation, including threats of retaliation and attempts at retaliation against people who file a communication, as a means to safeguard and protect the people who communicate good faith Information on acts or omissions that contravene the aforementioned law, the Code of Ethics and Conduct of the entity or the internal regulations and procedures of this institution.

General principles

The objective of this policy is to establish the principles that govern the entity’s actions in the implementation of the Internal Information System and Protection of the Informant, in accordance with the provisions of Law 2/2023.

  1. We guarantee accessibility to the Internal Information and Protection of the Informant System: The Internal Information System must allow, either in writing, verbally or in person, to communicate information on normative and anti-corruption violations to all persons included in its scope.
  2. We guarantee, through the independent action of the person in charge of the system, the completeness, integrity and confidentiality of the information, the prohibition of unauthorized access, the lasting storage of information and respect for good faith. The internal information system will be managed by the person in charge with total independence and autonomy from the rest of the entity’s areas.
  3. We guarantee the confidentiality of the identity of the informant person and any person mentioned in the communication, as well as the actions that are developed in the management and processing of the same. The internal information channel will allow even the presentation and subsequent processing of anonymous communications.
  4. We guarantee the protection of the personal data of the affected persons, in compliance with the current legislation in this matter.
  5. We guarantee the secret of communications.
  6. We guarantee the safety and protection of informants and affected persons.
  7. We guarantee the presumption of innocence and respect for the honor of the affected people.

Scope of application

(a) This Policy is applicable to all members of the Entity who report, through the procedures provided therein, to:

  • actions or omissions that may constitute a serious or very serious criminal or administrative infraction. In any case, all those serious or very serious criminal or administrative infractions against it will be understood to be understood or that imply an economic loss for the Public Treasury and for Social Security.
  • Conducts that may imply, by action or omission and by a member of the entity, facts that have an effective involvement in the professional relationship with the entity of the person to whom the communication refers, related to the Commission in an employment or professional context of an act contrary to the rules of action of the Code of Ethics of the entity or to the other provisions of the internal regulatory system.
  • any actions or omissions that may constitute infringements of the European Union’s law

Entity members are considered those who are employees and collaborators of the entity at all times.

b) This policy is also applicable to informants who, not being members of the entity, have obtained information on any of the actions or omissions referred to in the previous section in a work or professional context, comprising in any case:

  • Any person who works for or under the supervision and direction of the entity, its contractors, subcontractors and suppliers.
  • People who have been members of the entity in the past, having already terminated their employment or statutory relationship with the entity.
  • volunteers and fellows, regardless of whether or not they receive remuneration.
  • Persons whose employment relationship has not yet begun, in cases where the information on infringements has been obtained during the selection process or pre-contractual negotiation.

internal information system

The internal information system referred to in this Policy is the preferred channel to report on the actions or omissions provided for in Law 2/2023.

The internal information system consists mainly of the communication channel enabled for the reception of the communications planned in the scope of application of this policy, the person responsible for the system and the management procedure that must be followed for the processing of the aforementioned communications.

Creation of internal information channel

In the internal information system, it is integrated by the denunciation channel, which is the preferred channel for the communication of the behaviors provided for in section 3 of this Policy.

The aforementioned internal information channel allows:

  1. Make communications in writing or verbally, or in both ways, under the conditions provided for in Law 2/2023.
  2. When making the communication, the informant may indicate an address, email or safe place for the purpose of receiving notifications.
  3. the presentation and subsequent processing of anonymous communications.
  4. Inform those who make the communication through it, in a clear and accessible way, about external information channels before the competent authorities and institutions.
  5. At the reception of any other communications or information not included in the scope established in section 3 of this Policy, although said communications and their senders will be outside the scope of application and protection provided by it.
  6. Timely measures will be adopted to ensure the confidentiality of communications that are sent through channels that are not established or to members of the non-responsible staff (who must immediately send it to the person in charge of the SII).

The person in charge of the internal information system

  1. The persons responsible for the system will be a collegiate body or person, internally or externally, with the characteristics provided for in article 8 of Law 2/2023.
  2. The Independent Authority for the Protection of the Informant will be notified, in accordance with the provisions of article 8.3 of Law 2/2023, the appointments of the members of the collegiate body responsible for the system, within ten days of its appointment. They will also eventually notify, within the same period, their terminations, resignations and the reasons that justify them.
  3. In the exercise of their functions, the persons responsible for the system will not receive instructions from any superior, they will not be subject to hierarchy within the collegiate body, nor can they be removed from their positions for reasons related to their legitimate participation in the internal information system.

Protection of personal data

The processing of personal data arising from the application of Law 2/2023 will be governed by the provisions of the GDPR, and in Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDPGDD), in compliance with what, for such purposes, is determined in Law 2/2023.

The internal information system must prevent unauthorized access, preserve the identity and guarantee the confidentiality of the corresponding data to the affected persons and any third party that is mentioned in the information provided, with special attention to the identity of the informant if it has been identified.

The identity of the informant may only be communicated to the Judicial Authority, the Prosecutor’s Office or the competent administrative authority within the framework of a criminal, disciplinary or sanctioning investigation, and these cases will be subject to the safeguards established in the applicable regulations.

If the information received contains special categories of personal data, subject to special protection, its immediate deletion will be carried out, unless the treatment is necessary for reasons of an essential public interest in accordance with the provisions of article 9.2.g) of the GDPR, as provided in article 30.5 of Law 2/2023.

In any case, personal data will not be collected whose relevance is not manifest to process specific information or, if they are collected by accident, they will be deleted without undue delay.

Communications that have not been given may only be anonymized, without the blocking obligation provided for in article 32 of the LOPDPGDD being applicable.

Informant protection measures

Persons reporting infringements shall be entitled to the protection measures established in Law 2/2023, provided that the following circumstances are present:

  1. have reasonable grounds to think that the information referred to is truthful at the time of communication or disclosure, even when they do not provide conclusive evidence, and that the aforementioned information falls within the scope of application of this policy.
  2. The communication or disclosure has been carried out in accordance with the requirements set forth in this Policy and in Law 2/2023.

Those who communicate or reveal are expressly excluded from the protection provided for in Law 2/2023:

Information contained in communications that have been inadmissible by some internal information channel or for any of the following causes:

  • when the reported facts lack all plausibility.
  • When the facts reported are not constitutive of infringement of the legal system included in the scope of application of this policy.
  • When the communication manifestly lacks foundation or there are rational indications of having been obtained through the commission of a crime.
  • When the communication does not contain new and significant information on infringements compared to a previous communication with respect to which the corresponding procedures have concluded, unless there are new factual or legal circumstances that justify a different follow-up.
  • When the communication does not contain new and significant information on infringements compared to a previous communication with respect to which the corresponding procedures have concluded, unless there are new factual or legal circumstances that justify a different follow-up.

information that is already completely available to the public or that constitutes mere rumors.

information that refers to actions or omissions not included in the scope of this policy.

protection measures for affected people

During the processing of the file, the people affected by the communication will have the right to the presumption of innocence, the right of defense and the right of access to the file in the terms provided for in Law 2/2023, as well as the same protection established for the informants, preserving their identity and guaranteeing the confidentiality of the facts and data of the procedure.

Approval, entry into force and dissemination

This policy will be effective from the moment of its approval by the entity’s management, proceeding to its publication on the entity’s corporate web pages.

This Policy will be reviewed and updated as long as it is necessary to make any changes.

Objective

The purpose of managing the internal information system is to regulate those acts and procedures carried out by the entity as a result of the presentation of information referred to in Law 2/2023, of February 20, regulating the protection of people who report On regulatory infractions and anti-corruption (hereinafter, Law 2/2023).

Regulation and Legislation of Reference

  • Law 2/2023, of February 20, Regulator of the Protection of Persons who report on normative and anti-corruption infractions, by transposition of Directive 2019/1937 of the European Parliament and of the Council, of October 23, 2019, on the protection of persons reporting on violations of Union law.
  • Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation or GDPR).
  • Organic Law 3/2018, of December 5, Protection of Personal Data and Guarantee of Digital Rights (LOPD GDD).

Application scope

This regulation is applicable to the entire scope of action of the entity and its contents derive from the guidelines of a more general nature defined in the entity’s information security policy.

It will be mandatory by all personnel who, permanently or eventually, provide their services in the entity, including the personnel of external suppliers when they are users of the entity’s information systems.

Definitions

For the purposes of this regulation, it will be understood as:

  1. Informant: Natural or legal person who has obtained information on infringements in a work or professional context and who brings them to the attention of the entity, including in any case those provided for in article 3 sections 1 and 2 of Law 2/2023.
  2. Affected person: Natural person to whom the informant is attributed the commission of the infractions referred to in article 2 of Law 2/2023. Affected persons will also be considered, those who, without having been the object of information by the informant, through the acts of instruction of the procedure, had knowledge of the alleged commission by them of the aforementioned infractions.
  3. Third parties: Natural persons who may have knowledge of aspects related to the reported infringement, either as direct or indirect witnesses and who can provide information to the procedure.
  4. Internal Information System: It is the channel of information established in the entity to report on the actions or omissions provided for in article 2 of Law 2/2023, with the functions and contents contained in article 5.2 of said rule. It includes the internal information channel and the information management system.
  5. Internal information channel: It is the channel specifically enabled by the entity to receive the information related to the object of this procedure, under the administration of the person in charge of the entity’s internal information system.
  6. Information Management System: Technological platform integrated into the Internal Information System, whose purpose is the maintenance, registration and conservation of actions that take place as a result of the presentation of information to which Law 2/2023 is applicable.

Rights and guarantees of informants

Informant persons will be guaranteed the effective exercise of the following rights, without prejudice to any others recognized by the Constitution and the laws:

  1. to present information anonymously and to maintain anonymity during the procedure.
  2. to formulate communication verbally or in writing. In the case of presentation of the communication verbally, the informant will be offered the opportunity to verify, rectify and accept by signing the transcript of the message.
  3. To indicate an address, email or safe place to receive the communications made by the person in charge of the system.
  4. to appear before the person in charge of the system or the delegated manager on his own initiative.
  5. to the resignation to contact the person in charge of the system or the delegated manager who instructs the procedure and, where appropriate, to the revocation of said resignation at any time.
  6. to the preservation of their identity. The identity of the informant may not be disclosed without his express consent to any person who is not competent to receive and manage complaints, with the exceptions established by the law of the European Union or Spanish regulations in the context of investigations carried out by the authorities or in the course of judicial processes.
  7. to the protection of your personal data.
  8. to know the identity of the delegate manager who instructs the procedure.
  9. to the confidentiality of communications.
  10. to the measures of protection and support under the terms provided in Law 2/2023.
  11. to file a claim with the Independent Informant Protection Authority.
  12. Not to be subject to reprisals, even when the result of the investigations will be verified that there has been no breach of the applicable regulations or the Entity’s Code of Ethics, provided that it has not acted in bad faith.

Obligations of informants

The informants, with regard to the presentation of their communications through the internal information channel, will be subject to the following obligations:

  1. Have reasonable or sufficient indications about the certainty of the information they communicate, not being able to make generic communications, in bad faith or with abuse of rights, in which case they could incur civil, criminal or administrative liability
  2. Describe in the most detailed way possible the facts or behaviors they communicate, providing all available documentation on the described situation or objective indications to obtain the evidence.
  3. Abstract from forming communications for a purpose different from that provided for by the channel or that violate the fundamental rights to honor, image and personal and family privacy of third parties or that are contrary to the dignity of the person.

Rights of third parties

People considered as third parties in the procedure will have the following rights recognized, without prejudice to the possibility of extending to them, to the extent possible, the support and protection measures of the informant provided for in Law 2/2023.

  1. To indicate an address, email or safe place to receive the communications you make to the person in charge of the system.
  2. to appear before the person in charge of the system or the delegated manager on his own initiative.
  3. to the preservation of their identity. The identity of the third party may not be disclosed without their express consent to any person who is not competent to receive and manage complaints, with the exceptions established by the law of the European Union or Spanish regulations in the context of investigations carried out by the authorities or in the course of judicial processes.
  4. to the protection of your personal data.
  5. to the confidentiality of communications.
  6. not to be subject to retaliation.

Rights of affected people

The affected persons will have the rights recognized by the Constitution and the laws, for whose compliance they will have the obligation to ensure the person in charge of the system. In particular, they will have the following rights:

  1. to be informed as soon as possible of the information that affects them.
  2. to honor and privacy
  3. to the presumption of innocence and to use all valid means in law for his defense.
  4. to be assisted by a lawyer.
  5. access to the actions that are followed against them, without prejudice to the temporary limitations that may be adopted to guarantee the result of the actions.
  6. to know the identity of the delegate manager who instructs the procedure.
  7. to the preservation of their identity, against any person outside the person in charge of the system.
  8. to the protection of your personal data
  9. to the confidentiality of communications

The person in charge of the internal information system

  1. The person in charge of the system is the person or body referred to in article 8 of Law 2/2023, which will be designated by the Directorate.
  2. The person in charge of the system, in the exercise of its powers, cannot receive instructions from any other area of the entity, nor can it be removed from its positions for reasons related to its participation in the internal information system. Likewise, they are independent in the exercise of their functions and are not subject to hierarchy within said collegiate body.

Access to personal data in the internal information system

Access to personal data in the internal information system by the entity’s personnel will be limited, within the scope of its competences and functions, and regardless of the professional responsibilities of the people who are finally part of the collegiate body responsible for the system to:

  1. the person in charge of the system or in whom he delegates.
  2. The person in charge of management of people, when the adoption of disciplinary measures against a worker of the entity could proceed.
  3. The person in charge of the Legal Cabinet, should the adoption of legal measures in relation to the facts reported in the communication proceed.
  4. those in charge of the treatment that are eventually designated.
  5. The entity’s data protection delegate

The processing of data by other people, or even its communication to third parties, will be lawful when it is necessary for the adoption of corrective measures in the entity or the processing of sanctioning or criminal procedures that, where appropriate, proceed.

PROCEDURE DEADLINES

  1. The term to resolve the investigation actions to which the information management procedure gives rise cannot exceed 3 months, except for cases of special complexity in which case, in which case, the extension of said period by the person in charge of the system may be agreed upon, up to a maximum of three additional months.
  2. The calculation of the term referred to in the previous section begins from the receipt of the communication by the person in charge of the system or, if an acknowledgment of receipt is not sent to the informant, from the expiration of the term of seven days after the communication has been received.
  3. The terms expressed in months will be computed from date to date.
  4. The deadlines on days referred to in this rule will be considered skilled, unless expressly indicated that they are natural.
  5. The computation of the term in business days is excluded on Saturdays, Sundays and those declared holidays.

Protection of personal data

  1. The processing of personal data arising from the processing of this information management procedure will be carried out in accordance with the provisions of Title VI of Law 2/2023.
  2. The internal information system must prevent unauthorized access and preserve the identity and guarantee the confidentiality of the corresponding data to the affected persons and any third party that is mentioned in the information provided, especially the identity of the informant if it has been identified.
  3. The identity of the reporting persons may only be communicated to the judicial authority, the Public Prosecutor’s Office or the competent administrative authority within the framework of a criminal, disciplinary or sanctioning investigation, and these cases will be subject to the safeguards established in the applicable regulations.
  4. If the information received contains special categories of data, the immediate deletion will be carried out, unless the processing is necessary for reasons of an essential public interest in accordance with the provisions of article 9.2.g) of the General Data Protection Regulation, as provided in article 30.5 of the Law 2/2023.
  5. Personal data will not be collected whose relevance is not manifest to process specific information or, if collected by accident, will be deleted without undue delay.
  6. In any case, after 3 months from the receipt of the communication without having initiated investigative actions, its deletion must be carried out, unless the purpose of the conservation is to leave evidence of the functioning of the system.
  7. Communications that have not been given may only be anonymized, without the blocking obligation provided for in article 32 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights.

Procedure

Information reception phase

The information on the commission of infractions referred to in article 2.1 of Law 2/2023, as well as any other derived from the processing of this procedure, will be communicated in writing or verbally through the electronic means established for this purpose in the internal information channel enabled in the entity’s website.

At the request of the informant, it may also be presented through a face-to-face meeting within a maximum period of seven days.

Verbal communications, including those made through face-to-face meeting, by phone or through voice messaging system, must be documented in any of the following ways, with the consent of the informant:

  1. by recording the conversation in a safe, durable and accessible format, or
  2. through a complete and accurate transcript of the conversation made by the staff responsible for dealing with it.

Without prejudice to the rights that correspond to it, in accordance with the regulations on the protection of personal data, the informant will be offered the opportunity to verify, rectify and accept the transcript of the conversation by means of his signature.

In any case, the communication must contain at least the following information:

  • Identification of the informant, unless he chooses to present the information anonymously.
  • description of the facts and, where appropriate, determination of the affected norm.
  • identification of the person or persons affected.
  • Identification, where appropriate, of third parties who can provide relevant information.
  • If you exercise the right to give up contact with the person in charge of the system

The informant may indicate an address, email, or safe place for the purpose of receiving communications.

Once the communication has been received, within a period of seven calendar days following its receipt, a receipt will be acknowledged and the justification will be communicated to the informant, unless no contact has been provided or exercises the right to waive to communicate with the person in charge of the system or the delegated manager who Instruct the procedure.

Admission phase

Once the communication has been registered, the person in charge of the system must verify if it exposes facts or behaviors that are within the subjective scope of application provided for in article 3 of Law 2/2023 and, within ten business days from the date of entry of the information in the Registry may:

Inadmissible communication, in any of the following cases:

  • When the facts reported lack all plausibility
  • When the facts reported are not constitutive of infringement of the legal system in the scope of application of Law 2/2023.
  • When the communication is unfounded or there are rational indications of having been obtained through the commission of a crime. In the latter case, in addition to the inadmissibility, the Public Prosecutor’s Office will be sent a circumstantial list of the facts that are considered constitutive of a crime.
  • When the communication does not contain new and significant information on infringements compared to a previous communication with respect to which the corresponding procedures have concluded, unless there are new circumstances that justify a different follow-up.
  • The inadmissibility will be communicated to the informant within the following five business days, unless the communication was anonymous or the informant had waived to receive communications.

Admit the communication. Admission to processing will be communicated to the informant within the following five business days, unless the communication was anonymous or the informant had waived to receive communications.

Immediately send the information to the Public Prosecutor when the facts could be an indirectly constitutive of a crime or to the European Prosecutor’s Office in the event that the facts affect the financial interests of the European Union.

Send the communication to the authority, entity or body that is considered competent for its processing.

Instruction phase

The instruction will include all those actions aimed at verifying the plausibility of the reported facts.

The delegate manager designated by the person in charge of the system will be considered the instructor of the procedure.

Within a maximum period of 15 days from the resolution of admission, the person affected will be informed of the existence of the actions and the facts reported succinctly, unless said communication can facilitate the concealment, destruction and alteration of evidence, in which case, the delegated manager, in a way motivated, may modify said period until said circumstances disappear

In no case will the affected subjects be informed of the identity of the informant person or access to the communication will be given.

In order to guarantee the right of defense of the affected person, it will have access to the file without disclosing information that could identify the informant, being able to be heard at any time, and will be warned of the possibility of appearing assisted by a lawyer.

The affected person has the duty to maintain the confidentiality of the information to which he is aware as a result of access to the file, being prohibited any action aimed at identifying the informant or third parties, without prejudice to the obligations arising from compliance with the regulations on the protection of personal data.

Completion phase

Once the actions have been completed, the person in charge of the system will issue a report that will be transferred to the Director/Administrative of the entity and that will contain at least:

  1. A statement of the facts reported together with the file number, the date of registration and that of the admission agreement.
  2. The actions carried out in order to verify the plausibility of the facts that will collect, at least and in a succinct way, the allegations made by the affected person, including the interview, where appropriate, the documentation provided by him or collected by the person in charge of the system through third parties and how many other information on which the resolution adopted is based.
  3. the conclusions reached in the instruction and the assessment of the proceedings and the indications that support them.
  4. the decisions made.

Likewise, the report will be notified to the informant, to the extent that he is identified and has not made use of the right of resignation to communicate with the person in charge of the system and the affected person.

The deadline to finish the actions and respond to the informant, where appropriate, may not exceed three months from the entry into the Registry of the Information Management System, without prejudice to the extension of the term provided for in article 9 of Law 2/2023.