Management procedure
Whistleblowing Channel · Internal Reporting System of RAO SOCIAL, SL
Contents
Internal operation of the Channel: governance, submission routes, stages, deadlines, guarantees and data processing.
1. Purpose and scope
This Procedure regulates the internal operation of the Whistleblowing Channel of RAO SOCIAL, SL (hereinafter, «RAO SOCIAL»), part of its Internal Reporting System, in accordance with Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and on the fight against corruption, and with Directive (EU) 2019/1937.
The Channel is available to persons who have obtained information in an employment or professional context: employees, managers, members of administrative or supervisory bodies, shareholders or participants, self-employed persons, contractors, subcontractors and suppliers, as well as persons whose relationship has ended, volunteers, trainees, persons in training or who obtained the information during a selection or pre-contractual negotiation process.
RAO SOCIAL may also accept reports concerning possible breaches of its Code of Ethics and Conduct or of other internal rules. When the reported facts fall outside the material scope of Article 2 of Law 2/2023, their internal handling will not, in itself, entail the application of the specific protection regime provided for in that Law.
Protection criterion
Legal protection is tied to the material and personal scope of Law 2/2023 and to the existence of reasonable grounds to consider the reported information true.
2. Governance of the System
gdsgw, gfsgqs, appoints the natural person who is the Internal Reporting System Manager (hereinafter, the «System Manager»), who carries out their duties independently and autonomously, without receiving instructions of any kind and with the necessary personal and material resources. The current System Manager is: Maria puig.
In the private sector, the person appointed must meet the requirements of Article 8 of Law 2/2023. Where compatible with the structure of the entity, this function may fall to the person in charge of regulatory compliance or integrity, as long as conflicts of interest are avoided.
The appointment and removal of the System Manager must be notified to the competent authority (Oficina Antifrau de Catalunya) within ten working days; in case of removal, the reasons must be stated.
For each admitted report an investigator may be appointed, who may be the System Manager themselves or another duly authorised person with no conflict of interest.
If the report concerns the System Manager or they have a conflict of interest, they will refrain from taking part and gdsgw will appoint another person, internal or external, to handle it.
When the nature or complexity of the facts so advises, certain investigation actions may be entrusted to external professionals subject to strict duties of confidentiality, secrecy and data protection, without this outsourcing altering the responsibility of the System Manager.
3. Routes for submitting reports
Reports may be submitted, identified or anonymously, through the following routes:
- through the secure form of the web channel, at https://codifosc3.canaletic-test.protecdatus.com;
- where the channel has it enabled, by recording a voice message on the same web channel;
- where the channel has it enabled, by postal mail, to C/BHFUIS FHIS, for the attention of the System Manager; and
- through an in-person meeting, when the reporting person requests it, within the legal maximum of seven days.
To report anonymously it is enough not to provide identifying data on the web channel or to send the postal mail without a sender. RAO SOCIAL will in no case try to find out their identity. Access to the reports of the channel is restricted to the System Manager.
When a verbal report is documented by recording or transcription, the reporting person will be informed beforehand about the processing of their data and, where appropriate, their consent will be obtained. If a transcript is made, they will be offered the chance to check, correct and accept it.
On all routes, equivalent guarantees of confidentiality, integrity, information security and protection of identity must apply.
4. Stages of the procedure
4.1 Receipt and acknowledgement of receipt
Once the report is received, it is entered in the Register, given a reference number and receipt is acknowledged to the reporting person within a maximum of seven calendar days, unless they have not provided any contact route or the acknowledgement could compromise confidentiality or the protection of their identity.
4.2 Preliminary analysis and decision on admission
The System Manager carries out a preliminary analysis of the facts and decides, diligently and without undue delay, whether the report is admitted, rejected, referred to another authority or requires additional information. The decision is communicated to the reporting person whenever possible and where they have provided a safe means of contact.
4.3 Investigation
If the report is admitted, the investigator carries out the actions necessary to verify the facts, including collecting documents, interviews and any other lawful and relevant means of evidence.
The investigation respects at all times the presumption of innocence, honour, the right of defence and confidentiality. The person concerned will be informed of the facts attributed to them and will have the right to be heard at the time and in the way that preserves the success of the investigation, without being told the identity of the reporting person.
4.4 Closing the file and communicating the outcome
Once the investigation is finished, the investigator prepares a report setting out the facts analysed, the actions taken, the conclusions and, where applicable, the proposed corrective, disciplinary or legal measures.
The reporting person receives information about the end of the proceedings and the main conclusions, within the limits arising from confidentiality, data protection and the rights of the persons concerned.
5. Deadlines
The maximum period to respond to the investigation is three months from receipt of the report. If no acknowledgement of receipt was sent, the period starts when the seven calendar days following the report have elapsed.
In cases of special complexity, and provided the extension is duly justified, the period may be extended by up to three additional months.
6. Confidentiality and protection of identity
The identity of the reporting person and any data that allow their direct or indirect identification will be kept confidential. They will not be disclosed to the person concerned or to third parties not involved in the handling.
The identity may only be disclosed to the judicial authority, the Public Prosecutor's Office or the competent administrative authority in the context of a criminal, disciplinary or sanctioning investigation, with the safeguards established by law. Before disclosing it, the reporting person will be informed, unless this could jeopardise the investigation or the court proceedings.
If a report arrives through a channel other than those provided, or is received by a person who is not responsible for handling it, that person must strictly preserve its confidentiality and forward it immediately, unaltered, to the System Manager.
Access to the information is limited to the System Manager and to persons who, because of their functions and in the cases provided by law, must take part in the handling, investigation, adoption of measures or legal advice.
7. Protection against retaliation
RAO SOCIAL expressly prohibits any retaliation, threat of retaliation or attempted retaliation against persons who report information covered by Law 2/2023 and have reasonable grounds to believe that, at the time of reporting, the information was true and fell within its scope.
This protection extends, where appropriate, to persons who assist the reporting person, colleagues or relatives who may suffer retaliation and certain related legal entities in an employment or professional context.
Retaliation includes, among others, unjustified dismissal or non-renewal, demotion, denial of training or promotion, unjustified negative assessments and any employment or professional harm motivated by the report.
8. Grounds for rejection
A report may be rejected, by reasoned decision, when any of the following circumstances applies:
- the facts described manifestly lack plausibility or minimum grounds;
- the facts have no relation to the scope of the Channel or to any breach that RAO SOCIAL has decided to handle internally;
- the report refers exclusively to an interpersonal conflict with no relevance to the material scope of the System;
- the information is merely rumour, is entirely available to the public or lacks the minimum elements to allow any action;
- it repeats a previous report that has already been resolved without adding new and significant information; or
- the information was obtained by committing a crime; in this case, the matter will be referred to the Public Prosecutor's Office.
The lack of conclusive evidence is not, in itself, a ground for rejection when the reporting person has reasonable grounds to consider the reported information true.
9. Referral and external channels
When the facts may show signs of a criminal offence, the information is sent immediately to the Public Prosecutor's Office. If they may affect the financial interests of the European Union, it is sent to the European Public Prosecutor's Office.
The reporting person may go directly to an external channel, without having to use RAO SOCIAL's internal Channel first.
In Catalonia, the Anti-Fraud Office of Catalonia performs the functions of external channel and competent authority within its territory, including reports concerning private-sector entities when the breach is confined to Catalonia. The Independent Authority for Whistleblower Protection (AIPI), an independent administrative authority (A.A.I.), operating since 1 September 2025, exercises the state-level powers and those corresponding to the cases provided for in Law 2/2023, among others when a private-sector infringement has effects in more than one autonomous community. The reference supervisory authority is: Oficina Antifrau de Catalunya.
Accessible information
Information on the competent external channels must be available clearly and easily accessibly to those who use the internal Channel, in the document «External reporting channels» of RAO SOCIAL.
10. Processing of personal data and retention
The processing of personal data within the Channel is governed by Law 2/2023, Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD) and the Privacy Policy of the Internal Reporting System of RAO SOCIAL.
Data that are not adequate, relevant and necessary to analyse the facts will not be collected or kept. Data obtained accidentally that are not necessary will be deleted without undue delay.
Special categories of data that are not necessary for the investigation will be deleted immediately; when necessary, the processing will be based on Article 9.2.g of the GDPR, in accordance with Article 30.5 of Law 2/2023.
If it is proven that the information provided, or part of it, is not true, it will be deleted immediately from the moment this becomes known, unless that lack of truthfulness may constitute a criminal offence; in that case, it will be kept for the time needed for the court proceedings.
Data included in the management system will be kept only for the time strictly necessary to decide whether an investigation should be started. If three months pass from receipt without any investigation having started, they must be deleted from the system, unless keeping them is necessary to leave evidence of how the System works; in that case, information that has not led to any action may only be kept in anonymised form.
RAO SOCIAL keeps a Register of the information received and of the internal investigations to which it has given rise, on a confidential and non-public basis. The personal data in the register will be kept only for the necessary and proportionate period and, in no case, for more than ten years.
11. Corrective measures and disciplinary regime
When the investigation confirms the reported facts, RAO SOCIAL will adopt the measures necessary to correct them, end the conduct and prevent it from recurring. Where appropriate, it will apply the disciplinary measures provided for in the applicable collective agreement, employment law and internal rules.
A report that is ultimately not confirmed will not create liability for the reporting person when they acted with reasonable grounds to consider the information true. By contrast, a deliberately false report, or one made knowing it to be false, may lead to the measures provided by law.
12. Review and updating
This Procedure will be reviewed regularly and, in any case, when there are changes in law, criteria of the competent authorities, organisational changes or incidents in the operation of the System that make an update necessary.
Legal and guidance framework of reference
Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and on the fight against corruption.
Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019.
Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
Royal Decree 1101/2024 of 29 October approving the Statute of the Independent Authority for Whistleblower Protection, A.A.I.
Order PJC/908/2025 of 8 August setting 1 September 2025 as the start date of the AIPI.
AIPI Recommendation 1/2026 (v2) for the design and implementation of an Internal Reporting System (non-binding guidance).
13. Approval and version control
In accordance with Article 5.2.h of Law 2/2023, this Procedure is approved by gdsgw, gfsgqs, after prior consultation with the legal representation of employees where there is one.
| Implementation date | 8 October 2026 |
| Last review of the documentation | 8 October 2026 |
| Approving body | gdsgw, gfsgqs of RAO SOCIAL, SL |
| System Manager | Maria puig |
| Scheduled review | At least every year and whenever there are legal or organisational changes |
This Procedure regulates the internal operation of the Whistleblowing Channel of RAO SOCIAL, SL and must be read together with the Internal Reporting System Policy, the Code of Ethics and Conduct and the Privacy Policy. The current version will be identified and accessible.