Legal information

Ethics Channel — Documentation and policy of the whistleblowing channel

← Back to the index

Code of Ethics and Conduct

Internal Reporting System of RAO SOCIAL, SL · Law 2/2023 of 20 February and related legislation

Introduction

Integrity is not only a matter of legal compliance: it is a way of working, of making decisions and of relating to people. RAO SOCIAL, SL is committed to carrying out its activity with legality, honesty, responsibility, respect, transparency and professional diligence.

This Code of Ethics and Conduct sets out the principles and guidelines that must guide the conduct of persons linked to the organisation and provides a common framework to prevent improper conduct, manage compliance risks and make it easier for any possible irregularity to be reported safely.

The Code incorporates the essential principles of the Internal Reporting System provided for in Law 2/2023 of 20 February, and distinguishes between the Code of Ethics, the general Policy or strategy of the Internal Reporting System and the Report Management Procedure. These documents complement each other, but do not replace one another.

Drafting criterion

The terms «reporting person» and «report» are preferred over «whistleblower» and «complaint», without prejudice to the expression «whistleblowing channel» being kept as an informative or commercial name.

When a matter has a mandatory or especially suitable specific channel —for example, harassment, risk prevention, data protection, consumer matters, anti-money-laundering or other sector procedures— this Code does not replace it.

I. General provisions

Article 1. Purpose and aim

The purpose of this Code of Ethics and Conduct is to define the principles and standards of behaviour that must guide the activity of RAO SOCIAL, SL and of the persons within its scope.

Its main aims are:

This Code does not try to anticipate every possible situation. When in doubt, one must act with prudence, good faith and proportionality, and in accordance with the applicable rules and internal procedures.

Article 2. Scope of application

This Code applies, to the extent appropriate for each relationship, to members of the administrative or governing body, management, employees, temporary staff, trainees, collaborators and other persons acting in the name or on behalf of RAO SOCIAL.

RAO SOCIAL will also encourage suppliers, contractors, subcontractors, external professionals and business partners to know and respect equivalent principles where the nature, duration or risk of the relationship makes it appropriate.

Persons who lead teams have a reinforced responsibility: they must lead by example, promote knowledge of this Code, prevent risks within their area of responsibility and act on possible breaches without tolerating retaliation, concealment or orders that are manifestly contrary to the law.

When RAO SOCIAL is part of a group of companies or exercises management functions over other entities, the scope of this Code will be adapted to the group's governance system and to the powers actually exercised. In non-controlled entities, the persons representing RAO SOCIAL will promote, where possible and compatible with their functions, the adoption of equivalent integrity principles.

II. Ethical principles and working environment

Article 3. General ethical principles

Article 4. Human rights, equality and non-discrimination

RAO SOCIAL is committed to respecting the human rights and public freedoms recognised by law, as well as the principles of equal treatment, dignity, diversity and inclusion in its professional and business relationships.

No direct or indirect discrimination will be accepted on grounds of birth, racial or ethnic origin, nationality, sex, sexual orientation, gender identity or expression, age, disability, marital status, family situation, religion or beliefs, opinion, language, socioeconomic situation or any other condition or circumstance protected by applicable law.

Selection, hiring, training, promotion, pay and professional development will be based on objective criteria linked to merit, ability, suitability, responsibility and performance, with the reasonable adjustments required by law.

RAO SOCIAL rejects forced or compulsory labour, child labour contrary to applicable law and any practice that violates freedom of association or collective bargaining.

Article 5. Respect, harassment, health, safety and work-life balance

RAO SOCIAL promotes a safe, respectful and healthy professional environment. Sexual harassment, harassment on grounds of sex, workplace or psychological harassment, intimidation, humiliation, abuse of authority, violence, retaliation or any other conduct that undermines people's dignity will not be tolerated.

Situations of harassment or psychosocial risk will be handled through the specific employment or prevention protocols that apply. Where the facts may also fall within the material scope of Law 2/2023, the reporting person may use the channels provided in the Internal Reporting System.

The organisation will take the measures required on occupational risk prevention and health and safety at work, and will encourage the responsible use of resources, digital disconnection where applicable and an appropriate balance between professional and personal life, without prejudice to legitimate organisational needs.

Article 6. Sustainability and the environment

RAO SOCIAL will carry out its activity seeking to prevent and reduce negative environmental impacts that are reasonably avoidable, complying with environmental law and the specific commitments it has made.

Efficient use of energy, water and resources, reduction and proper management of waste, responsible purchasing and, where relevant to the activity, selection of suppliers using proportionate and verifiable environmental criteria will be encouraged.

No environmental or sustainability commitment may be communicated in a misleading way or without sufficient basis. Public statements on this subject must be verifiable and consistent with the organisation's actual practices.

III. Integrity in professional activity

Article 7. Regulatory compliance, internal control and records

All persons within the scope of this Code must carry out their activity with professional diligence, respect for the rules and a focus on the legitimate interest of RAO SOCIAL, without prejudice to the rights of third parties.

Financial, accounting, tax, employment, commercial and operational information must be truthful, sufficient, clear and recorded properly and at the right time. It is forbidden to falsify documents, create fictitious transactions, deliberately omit relevant information, keep unauthorised parallel records or manipulate data in order to hide an irregularity.

Persons in charge of areas or processes must apply the internal controls that apply to them, keep the required documentation for the applicable periods and facilitate legitimately agreed internal or external checks, audits or reviews.

When a material error or a control weakness is detected, it must be reported to the responsible function and corrected diligently, preserving the traceability of the actions taken.

Persons in charge of areas or processes must know the legal, sector, professional and internal rules that affect their functions and make sure that the people under them have the information, instructions and training needed to comply with them properly.

Article 8. Conflicts of interest

A conflict of interest exists when a personal, family, professional, associative or financial interest may interfere, or appear to interfere, with the objectivity, impartiality or loyalty with which a person must carry out their duties.

RAO SOCIAL respects the private activities and interests of persons linked to the organisation, as long as they are compatible with their professional obligations and do not compromise the organisation's legitimate interests, confidentiality, impartiality or reputation.

For the purpose of assessing a possible conflict, the following may be considered related persons, where relevant to the case: the spouse or partner in an analogous relationship, children or other relatives who live with or depend financially on the person, as well as entities, companies or businesses controlled directly or indirectly by that person or their related persons, or in which they hold management, administration or executive roles.

By way of example, the following may create a conflict of interest: taking part in a transaction in which the person or a related person has a financial or personal interest; negotiating or deciding on contracts with related persons or entities; taking part in the selection, supervision or evaluation of a relative or related person; holding significant shareholdings or management roles in clients, suppliers or competitors; or using information, influence or opportunities known because of one's position for one's own benefit or that of third parties.

Faced with a real, potential or apparent conflict, the person concerned must report it, as soon as they become aware of it and before taking part in the decision or transaction, to the person or function determined by the organisation. The report must allow the conflict to be assessed proportionately and, as far as possible, preserve the confidentiality of unnecessary personal information.

The person concerned will refrain from taking part in decisions related to the conflict until the proper way of managing it has been determined. Measures may include temporary replacement of the decision-maker, separation of duties, independent review, limiting access to certain information, conditional authorisation or any other proportionate measure that preserves independence and trust.

Persons linked to RAO SOCIAL may maintain ordinary commercial relationships with the organisation itself when they are part of its activity, take place on market terms or on general terms set in advance and involve no favourable treatment, use of inside information or improper participation by the person concerned in the decision.

Article 9. Use of resources, cybersecurity, artificial intelligence and intellectual property

Equipment, devices, accounts, applications, credentials, information, premises and other resources provided by RAO SOCIAL will be used in a professional, secure way and in proportion to the purpose for which they were provided, respecting internal policies and legal limits.

Each person is responsible for protecting their credentials, preventing unauthorised access, acting with caution with suspicious emails, links, files or requests and reporting without delay any security incidents or possible breaches they detect through the established internal channels.

The use of digital tools and artificial intelligence systems must respect confidentiality, data protection, intellectual property, information security, internal instructions, usage limits and, where necessary, human oversight. Confidential information, trade secrets or personal data must not be entered into unauthorised tools.

Software, content, images, texts, databases, trademarks or other protected assets will not be used without the necessary licence, authorisation or legal basis. Likewise, the intellectual and industrial property rights of RAO SOCIAL and of third parties will be respected.

Article 10. Confidential information, data protection and trade secrets

Non-public information known because of professional activity must be treated discreetly and used only for legitimate purposes linked to the duties entrusted. This obligation continues after the professional relationship ends, under the terms required by law.

Confidential or reserved information must only be shared with authorised persons and on a need-to-know basis. It is forbidden to use it to obtain personal benefits, favour third parties or harm RAO SOCIAL or other persons.

Personal data will be processed in accordance with the General Data Protection Regulation (GDPR), Organic Law 3/2018 and other applicable legislation, following the principles of lawfulness, fairness, transparency, minimisation, purpose limitation, accuracy, storage limitation, integrity and confidentiality.

When information is considered a trade secret or is subject to contractual or legal confidentiality obligations, the specific protection measures that apply will be used, which may not be used to prevent legally protected reports.

Article 11. Gifts, invitations, corruption and influence peddling

It is forbidden to offer, promise, request or accept payments, advantages, gifts, invitations, commissions, favours or benefits intended to improperly influence a decision, obtain preferential treatment, speed up a procedure unlawfully or create an improper obligation.

Only courtesy gestures of moderate value that are occasional, transparent, lawful and compatible with internal rules will be acceptable. Cash or equivalents, facilitation payments and any form of bribery are prohibited.

Where there is a threshold, register or internal procedure for authorising gifts and invitations, it is mandatory. In case of doubt, the person concerned must ask before accepting or offering the gesture.

Any form of influence peddling, hidden commissions, fictitious intermediation or use of a personal or institutional relationship to obtain an undue advantage is also rejected.

Gifts, invitations or gestures that do not meet the above criteria must be refused or returned. If this is not reasonably possible, they will be handed over to the organisation or managed under the applicable internal procedure. Where there is an obligation to report, authorise or register, the person concerned must comply with it beforehand or immediately, as appropriate.

Article 12. Fraud, money laundering and payment irregularities

RAO SOCIAL rejects any form of fraud, misappropriation, forgery, evasion of obligations, money laundering, terrorist financing or irregular use of means of payment.

Where the rules on the prevention of money laundering and terrorist financing apply to the activity of RAO SOCIAL, the due diligence, identification, control, special examination, retention and reporting measures required by law will be observed, without this Code replacing the specific procedures or obligations towards SEPBLAC or the competent authority.

Particular attention must be paid, among other signs, to unusual transactions or transactions with no apparent economic justification; cash payments, bearer cheques or unforeseen currencies when they are anomalous; payments to or from third parties outside the contractual relationship; unusual accounts or sudden changes in payment instructions; extraordinary or urgent transactions with no justification; transactions with high-risk jurisdictions or opaque structures; unjustified difficulty in identifying the beneficial owner; or any other pattern that, given the activity and risk, requires additional verification.

Suspicions of fraud or payment irregularities must be reported through the appropriate internal channels. If sector rules impose a specific channel, professional secrecy or a duty of non-disclosure, that regime will apply first.

Article 13. Outside activities, non-competition and business opportunities

Professional, business, academic, associative or other activities carried out outside RAO SOCIAL must be compatible with the obligations undertaken, working hours and rest, confidentiality and the ban on conflicts of interest.

Where there is a legal, contractual or internal obligation to report or obtain authorisation for certain outside activities, the person concerned must comply with it before starting them. The name, brand, resources, information or professional position of RAO SOCIAL will not be used to obtain an unauthorised private benefit.

No unfair competition will be carried out, and clients, suppliers, opportunities, resources or information of the organisation will not be diverted for one's own benefit or that of third parties. Any non-competition or exclusivity agreement will be interpreted within the applicable legal and contractual limits.

Business opportunities known because of one's position or of information obtained at RAO SOCIAL will not be taken up personally when they rightfully belong to the organisation, unless the organisation has expressly passed on the opportunity or authorised its use.

Participation in political, trade union, associative, ideological or civic activities will take place strictly in a personal capacity, unless there is express authorised representation. The name, brand, resources or professional position of RAO SOCIAL will not be used in a way that could attribute to the organisation an affiliation, opinion or support that has not been approved.

IV. Relations with third parties and reputation

Article 14. Relations with third parties and stakeholders

Relations with clients, users, suppliers, contractors, collaborators, business partners, competitors, administrations, authorities and other stakeholders will be based on professionalism, transparency, confidentiality, good faith and respect for free competition.

When a third party acts in the name or on behalf of RAO SOCIAL in activities of significant risk, proportionate due diligence measures, contractual compliance commitments, checks or controls may be applied.

Shareholders, investors or members of the entity, where applicable: RAO SOCIAL will provide adequate, truthful and sufficient information through the established channels, respecting equal treatment, confidentiality and the applicable legal or statutory obligations.

Article 15. Communication, reputation and the digital environment

The reputation of RAO SOCIAL is a collective asset. Public communications on behalf of the organisation must be truthful, respectful, consistent with the roles and authorisations established and respect the rights of third parties.

Unauthorised persons will not speak on behalf of RAO SOCIAL to the media, on social networks, in forums, at public events or on other channels. When expressing personal opinions in public spaces, they will avoid creating confusion about whether they are speaking institutionally.

In the digital environment, confidential information, personal data, intellectual property and security must be protected. Trademarks, logos or corporate identity elements will not be used in a way that could mislead, unjustifiably harm third parties or compromise the organisation's reputation.

If incorrect public information, impersonation, a leak, a reputational crisis or an incident that may require a coordinated response is detected, it must be reported to the competent internal function before acting individually where possible.

Significant external communications will be prepared with diligence and, where required by the nature of the information, on verified data. Material errors detected must be corrected quickly and traceably. Rumours, false information or manipulated content will not be deliberately spread in the name of RAO SOCIAL.

V. Governance and Internal Reporting System

Article 16. Governance, compliance and responsibilities

The administrative or governing body of RAO SOCIAL (gdsgw, gfsgqs) is responsible for promoting a culture of compliance and, when legally mandatory, for implementing the Internal Reporting System, after prior consultation with the legal representation of employees where appropriate, approving its general Policy or strategy and the Report Management Procedure, and appointing the System Manager.

When RAO SOCIAL has a compliance, integrity or control function, committee or body, that function will monitor this Code within the powers assigned to it, promote the identification and mitigation of compliance risks, handle or channel queries and promote awareness and training activities. These functions will be exercised without confusing or replacing the powers legally reserved to the System Manager, the Data Protection Officer, Human Resources or other specialised bodies.

In entities subject to Law 2/2023, the administrative or governing body will also be the controller of the personal data of the Internal Reporting System under the terms of the applicable rules.

The System Manager (Maria puig) will perform the functions assigned by the rules independently and autonomously from the other bodies of the entity, may not receive instructions of any kind in carrying out their duties and must have the necessary personal and material resources. In the case of a collegiate body, it will delegate to one of its members the powers to manage and process investigation files under the terms provided by law.

When legally permissible, RAO SOCIAL may use an external third party to manage the Internal Reporting System under the terms of the applicable rules. For this purpose, external management of the System covers the receipt of reports and is instrumental in nature; it may not entail attributing responsibility to a person other than the System Manager nor reduce the guarantees of independence, confidentiality, data protection and secrecy of reports.

The external third party that manages the receipt of reports will, for data protection purposes, be a data processor under the terms provided by law, and the required contractual guarantees must be put in place. Outsourcing may not reduce the independence, confidentiality or internal responsibility of the System. The technology platform of the channel is provided by PROTECDATUS Consultors, SL, which acts there as data processor.

The appointment and removal of the System Manager will be notified to the competent authority within ten working days, under the terms provided by law; in case of removal, the reasons that justified it will be stated. RAO SOCIAL will also keep the register of the information received and of the resulting internal investigations, with the confidentiality and restricted-access guarantees required by law.

Article 17. Internal Reporting System and protection of the reporting person

Terminology

The «Internal Reporting System» includes the receiving channel or channels, the System Manager, the Policy or strategy for the protection of the reporting person and the Report Management Procedure. The channel is only one part of the system.

17.1. Purpose and preferred nature of the internal system

The Internal Reporting System is a safe route to report facts or conduct that may constitute regulatory infringements or significant breaches known in an employment or professional context. Its aim is to make it easier to detect and correct irregular conduct early and to protect those who report under the legally established conditions.

The internal channel is the preferred route when the infringement can be dealt with effectively within the organisation and the reporting person considers that there is no risk of retaliation. This preference does not prevent going directly to the external channels of the competent authorities.

17.2. Who can report

The Internal Reporting System may be used by persons who have obtained information in an employment or professional context, including, among others, employees or public employees, self-employed persons, shareholders or participants, members of administrative, management or supervisory bodies, persons working for contractors, subcontractors or suppliers, as well as persons whose relationship has ended, volunteers, trainees, persons in training and candidates when the information was obtained during a selection or pre-contractual negotiation process.

Legal protection measures may extend, where the requirements are met, to the legal representatives of employees who advise or support the reporting person, to natural persons who assist them, to colleagues or relatives who may suffer retaliation and to certain legal entities related to the reporting person.

17.3. What can be reported

Acts or omissions falling within the material scope of Law 2/2023 may be reported, especially certain infringements of European Union law and facts that may constitute a serious or very serious criminal or administrative infringement, including in any case those involving economic loss to the Public Treasury or Social Security under the terms of the law.

RAO SOCIAL may enable the same channel to receive other breaches of this Code or of internal rules. In these cases, the report will be handled in accordance with the applicable internal rules, but the specific protection of Law 2/2023 will only apply when the requirements and scope of protection established by law are met.

Purely interpersonal complaints, ordinary management disagreements or conflicts affecting exclusively private interests must use, where they exist, the employment, human resources, harassment, prevention, consumer, data protection or other specific channels or procedures, without prejudice to an analysis of the case determining that the facts also fall within the scope of Law 2/2023.

17.4. Forms of reporting and practical information

The internal channel will allow reports to be submitted in writing or verbally under the terms set by the rules and the configuration of the system. Reports may be identified or anonymous. When the reporting person requests an in-person meeting, it will be arranged within the legal maximum of seven days.

When a verbal report is recorded or documented, the reporting person will be informed beforehand about the processing of the data and, with their prior consent, it will be documented by a recording in a secure, durable and accessible format or by a complete and accurate transcript. In the case of a transcript, they will be offered the chance to check, correct and accept it by signing where appropriate.

It is not necessary to report the facts to a line manager first. Any report received by a person who is not authorised to handle it must be forwarded immediately to the System Manager, strictly preserving its confidentiality and without keeping unnecessary copies. Persons who, because of their duties, may accidentally receive such reports must receive specific training or instructions on this obligation and on the consequences of an improper breach of confidentiality.

Name of the entityRAO SOCIAL, SL
Web channelhttps://codifosc3.canaletic-test.protecdatus.com
Voice recordingOn the same web channel, when enabled
Postal mailC/BHFUIS FHIS
Telephone and in-person meeting972 65984648
System ManagerMaria puig
Competent external channelOficina Antifrau de Catalunya. Anti-Fraud Office of Catalonia if the facts are confined to Catalonia; Independent Authority for Whistleblower Protection (AIPI), an independent administrative authority (A.A.I.), if they have effects outside Catalonia

17.5. Guarantees of the system

The identity of a reporting person who has identified themselves will not be disclosed to the person concerned by the facts. It may only be disclosed to the legally authorised authorities and with the safeguards provided by the rules, including prior notice to the reporting person, unless this could jeopardise the investigation or the court proceedings.

17.6. Rights of the person concerned

The person concerned by a report fully keeps their rights to the presumption of innocence, honour, defence, to be heard and to the confidential treatment of their data. They will receive information about the facts at the time and in the way that preserves the effectiveness of the investigation and prevents evidence from being concealed, destroyed or altered.

Access to the file or to the investigation information will be arranged so as not to reveal the identity of the reporting person or third-party data that must remain protected, without prejudice to the legally recognised rights of defence.

17.7. Handling of reports

Handling will follow the Report Management Procedure approved by RAO SOCIAL. In general, and where compatible with confidentiality, a receipt will be sent within seven calendar days of receipt of the report.

The ordinary maximum period to respond to the investigation will be three months. In cases of special complexity, the period may be extended by no more than an additional three months. During handling, communication with the reporting person may be maintained and additional information requested.

When the facts may show signs of a criminal offence, the information will be sent to the Public Prosecutor's Office immediately; if it may affect the financial interests of the European Union, it will be sent to the European Public Prosecutor's Office where appropriate.

Decisions on admission, investigation, closure, adoption of measures or referral to other bodies will be documented sufficiently and proportionately, preserving confidentiality and traceability.

17.8. External channels and public disclosure

The reporting person may go directly, or after using the internal channel, to the external channels of the competent authorities. At state level, the Independent Authority for Whistleblower Protection, A.A.I. (AIPI), acts as the external channel within its sphere of competence; the autonomous communities may have their own authorities. In Catalonia, the Anti-Fraud Office of Catalonia performs the functions of independent authority for the protection of the reporting person and of external channel in the cases within its competence.

When the facts affect private entities, determining the competent external authority will depend, among other factors, on the territorial scope in which the breach produces its effects. Up-to-date information on the external channels must be provided clearly and accessibly on the corresponding website or information area, without relying exclusively on this Code.

When RAO SOCIAL has a website, information on the use of the internal channel and the essential principles of the management procedure must appear on the home page, in a separate and easily identifiable section.

Public disclosure of information may be protected in the cases and under the conditions provided by law. This Code neither extends nor restricts the requirements established by Law 2/2023 for this form of reporting.

17.9. Data protection, register and retention

The personal data of the Internal Reporting System will only be accessible to legally authorised persons and will be processed exclusively to the extent necessary to decide on admission, investigate the facts, adopt the appropriate measures and meet legal obligations.

Within the scope of Law 2/2023, personal data that are not necessary to know and investigate the facts will not be processed and, if collected accidentally, will be deleted without delay. Likewise, if the information received contains personal data in special categories that are not necessary for the investigation, they will be deleted immediately; when necessary, the processing will be based on Article 9.2.g of the GDPR, in accordance with Article 30.5 of Law 2/2023. Reports outside the material scope of the Law that RAO SOCIAL decides to accept through the same channel must be separated and handled, where appropriate, under the legal regime that applies.

If it is proven that the information provided, or part of it, is not true, it will be deleted immediately from the moment this becomes known, unless the lack of truthfulness may constitute a criminal offence; in that case, the information will be kept for as long as the court proceedings last.

If, three months after receipt, no investigation has started, the data must be deleted from the system under the terms provided by law, without prejudice to anonymised evidence of the system's operation being kept. Data needed for an investigation that has started may be kept outside the system for the necessary time, with the corresponding safeguards.

RAO SOCIAL will keep a register of the information received and of the internal investigations to which it has given rise. This register will not be public and access to it will be subject to the limits set by law. The personal data included in the register will be kept only for the necessary and proportionate period and, in no case, for more than ten years, without prejudice to the specific deletion rules that apply to the receiving and handling system.

17.10. Good faith, reasonable truthfulness and false reports

The reporting person is not required to have conclusive evidence. To access legal protection, they must have reasonable grounds to believe that the information is true at the time of reporting or disclosing it and that it falls within the scope of protection of the law.

A knowingly false, manipulated or bad-faith report is not covered by legal protection and may give rise to the corresponding liability. This provision will not be used to discourage reports made in good faith or about facts that ultimately cannot be proven.

17.11. Protection against retaliation and support measures

Retaliation, including threats and attempted retaliation, against persons who submit a report or make a public disclosure under the legally established conditions is prohibited. This protection may extend to related persons and entities provided for by law.

Protected persons may access, under the terms of the law, information and advice on available procedures and remedies, assistance from the competent authorities against retaliation and the other support measures provided for in Law 2/2023, including certain forms of legal assistance and, exceptionally, financial or psychological support when agreed by the competent authority.

VI. Compliance, dissemination and validity

Article 18. Breach and disciplinary regime

This Code is mandatory for persons within its scope, to the extent appropriate for each relationship. When RAO SOCIAL establishes mandatory training linked to the risks, responsibilities or duties of each post, the persons concerned must take part under the terms of the applicable internal and employment rules.

A breach of this Code may lead to corrective or disciplinary measures in accordance with the applicable employment law, collective agreement, contracts and internal rules, always respecting the principles of proportionality, legal certainty, adversarial procedure and the right of defence.

When the facts may constitute an administrative or criminal infringement, RAO SOCIAL will act in accordance with its legal obligations and may bring them to the attention of the competent authorities.

Having submitted a report in good faith or with reasonable grounds through the channels provided will not be considered a breach. Any retaliation against a reporting person or a protected person will be treated as especially serious conduct, without prejudice to any legal liability that may arise.

No one may justify conduct contrary to this Code by an order from a superior, by the tolerance of past practices or by avoidable ignorance of the rules that apply to them. Faced with a manifestly unlawful order, they must refrain from carrying it out and report the situation through the appropriate channels.

Article 19. Dissemination, training, queries and interpretation

RAO SOCIAL will ensure that this Code is accessible to the persons to whom it applies and will promote communication, training and awareness activities proportionate to the risks and responsibilities of each function.

Persons who, because of their duties, may accidentally receive reports from the Internal Reporting System or access especially sensitive information will receive specific instructions on confidentiality, immediate referral, data protection and the ban on retaliation.

Doubts about the interpretation of the Code may be raised with the internal manager determined by the organisation, the compliance department or function, Human Resources, the Data Protection Officer when privacy is concerned, or the System Manager when the query concerns the Internal Reporting System. General queries do not replace the specific channels for reporting irregularities when it is necessary to preserve confidentiality guarantees. The internal interpretation of this Code may not reduce rights or guarantees recognised by applicable law.

Article 20. Review, approval and validity

This Code will be reviewed regularly and whenever legal, organisational, technological or risk changes make an update advisable, as well as when experience from its application or from internal investigations shows a need for improvement.

Approval and amendments will be the responsibility of the competent administrative or governing body of RAO SOCIAL. The current version must be identified, dated and accessible, and superseded versions will be kept when necessary for traceability or as proof of compliance.

Where there is a compliance, integrity or control function or body, it will regularly inform the competent body about significant incidents detected in the application of the Code, the risks observed, training activities and proposals for improvement. The frequency and content of this report will be adapted to the size, activity and governance system of the organisation.

Implementation date8 October 2026
Last review of the documentation8 October 2026
Approving bodygdsgw, gfsgqs of RAO SOCIAL, SL
Scheduled reviewAt least every year

Main legal framework of reference

Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and on the fight against corruption; Directive (EU) 2019/1937; Regulation (EU) 2016/679 (GDPR); Organic Law 3/2018; Royal Decree 1101/2024 of 29 October approving the Statute of the Independent Authority for Whistleblower Protection, A.A.I., as currently worded; Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 of 8 July 2026; and the employment, criminal, administrative, data protection, risk prevention, competition, intellectual property, anti-money-laundering and sector-specific rules that apply in each case.

Where territorially relevant, regional rules on competent authorities and the protection of reporting persons will also apply. In Catalonia, the designation of the Anti-Fraud Office of Catalonia as an independent authority under the applicable Catalan rules must be taken into account.

The current recommendations and guidance of the competent authorities are used as implementation guidance, without replacing the applicable rules.


This Code of Ethics and Conduct applies to RAO SOCIAL, SL and to the persons within its scope. It is supplemented by the Internal Reporting System Policy and the Report Management Procedure, without replacing them. The current version will be identified, dated and accessible.