Legal information

Ethics Channel — Documentation and policy of the whistleblowing channel

← Back to the index

Privacy policy

Internal Reporting System · Whistleblowing Channel of RAO SOCIAL, SL

Purpose of this document

To inform, clearly and transparently, how RAO SOCIAL, SL processes the personal data associated with the reports received through its Internal Reporting System, as well as the guarantees of confidentiality, restricted access, retention and exercise of rights.

1. Introduction and legal framework

This Privacy Policy governs the processing of personal data carried out by RAO SOCIAL, SL (hereinafter, «RAO SOCIAL») when receiving, handling, analysing and, where applicable, investigating the reports submitted through its Internal Reporting System (hereinafter, the «System»), commonly known as the whistleblowing or alert channel.

The System has been set up in accordance with the applicable data protection and whistleblower protection rules, in particular:

The interpretive criteria of the Spanish Data Protection Agency (AEPD) on internal reporting systems and the defence of the reporting person are also taken into account.

2. Identity of the data controller

Data controllerRAO SOCIAL, SL
Tax ID (NIF)B55334106
AddressC/BHFUIS FHIS
Telephone972 65984648
Commercial RegisterRMN GIRONA HF UISHFIUSF
Whistleblowing channelhttps://codifosc3.canaletic-test.protecdatus.com
System ManagerMaria puig

The technology platform of the Channel is provided and maintained by PROTECDATUS Consultors, SL (Tax ID B55334106, C/ Pla de Dalt, 5 · 17840 Sarrià de Ter, Girona), which acts as data processor on behalf of RAO SOCIAL, SL, in accordance with Article 28 of the GDPR.

3. Purposes and legal basis of the processing

The personal data collected through the System are processed exclusively to receive and handle reports, assess their admissibility, keep in contact with the reporting person where possible and, where applicable, carry out or channel the investigation of the reported facts and adopt the appropriate measures.

The System of RAO SOCIAL is established as an internal compliance and integrity mechanism. In internal systems implemented voluntarily, Law 2/2023 presumes that the processing is covered by Article 6.1.e of the GDPR, as it is necessary for the performance of a task carried out in the public interest. If the processing arose from a legal obligation to have the System, the legal basis would be Article 6.1.c of the GDPR, in accordance with Article 30 of Law 2/2023.

Where a report includes special categories of data that are necessary for the investigation, the processing will be based on Article 9.2.g of the GDPR, in accordance with Article 30.5 of Law 2/2023. Data that are not necessary will be deleted immediately.

3.1. Categories of data and source

The data come from the report itself and from the handling and investigation activities, and may relate to the reporting person, the person concerned by the facts and third parties mentioned in them. The following categories of data may be processed:

Reports may be submitted anonymously. In that case, no identifying data of the reporting person will be processed and no attempt will be made to find out their identity.

Scope of the protection under Law 2/2023

The System may also be used to report internal breaches. However, the specific protection status of the reporting person under Law 2/2023 applies when the reported information falls within its material scope.

4. Data retention

Data will be kept within the System only for the time strictly necessary to decide whether an investigation of the reported facts should be started.

Key retention criterion

Three months is the general limit for data to remain in the System when no investigation has started. The ten-year maximum applies to the register regulated in Article 26 of Law 2/2023, not to the ordinary retention of the report within the channel.

5. Recipients and disclosure of data

Data will not be disclosed to third parties, unless necessary to handle the report, adopt corrective measures or conduct disciplinary, sanctioning or criminal proceedings, or where there is a legal obligation.

6. Exercise of rights

Data subjects may exercise, under Articles 15 to 22 of the GDPR and with the limitations necessary to preserve the identity of the reporting person, the rights of access, rectification, erasure, restriction of processing and objection, as well as any other rights that apply in each case.

To exercise their rights, data subjects can contact RAO SOCIAL by the following means:

The request must allow the data subject to be identified and specify the right they wish to exercise. RAO SOCIAL will only ask for additional information to verify identity where there are reasonable doubts about who is making the request.

If they consider that the processing does not comply with the rules, data subjects may lodge a complaint with the Spanish Data Protection Agency (AEPD), through www.aepd.es or the other officially available channels.

7. Data minimisation and quality

RAO SOCIAL applies the principles of minimisation, accuracy and purpose limitation. Accordingly, the data processed:

8. Restricted access to the information

Access to the personal data held in the System is limited, within their respective powers and functions, to the persons or functions expressly provided for in Law 2/2023:

Access or disclosure to other persons will also be lawful when strictly necessary to adopt corrective measures or conduct sanctioning or criminal proceedings.

9. Security, confidentiality and protection of identity

RAO SOCIAL applies appropriate technical and organisational measures to preserve the confidentiality, integrity and availability of the information, prevent unauthorised access and ensure the traceability of the management of the System. Reports received through the web channel are transmitted and stored encrypted.

Confidentiality commitment

Protecting the identity of the reporting person is a core guarantee of the System. Any disclosure of their identity is limited to the cases and authorities expressly provided for by Law 2/2023.

Version control

Implementation8 October 2026
Last review of the documentation8 October 2026
Review basisGDPR · LOPDGDD · Law 2/2023 · AEPD criteria

This document explains how personal data are processed in the Internal Reporting System of RAO SOCIAL, SL and does not constitute individual legal advice. Rights may be exercised before RAO SOCIAL and, where applicable, a complaint may be lodged with the Spanish Data Protection Agency (AEPD). The current version will be identified and accessible.