Crisis response protocol
Handling of situations that may affect the image or reputation of RAO SOCIAL, SL or its professionals
Contents
Definition, principles of action, protocol, personal data breaches and closing report and lessons learned.
1. Definition of crisis
For the purposes of this Protocol, a crisis is any situation or event that:
- may harm the image or reputation of RAO SOCIAL, its services or the people who work there;
- takes place or is spread through websites, media or any social network —blogs, X (formerly Twitter), Facebook, LinkedIn, etc.— belonging to RAO SOCIAL or to third parties; or
- arises from a security incident, a personal data breach or a complaint before an authority that may become public.
2. Principles of action
In the face of a crisis, professionals must act according to the following principles:
- Proportionality: assess and size up the situation correctly before taking decisions.
- Caution: verify the facts and avoid hasty actions that could make the situation worse.
- Honesty: face the crisis with transparency and give it the most appropriate response possible.
- Agility: act and respond as quickly as possible.
- Common sense and responsibility: direct every action towards a prudent, coherent and responsible handling of the crisis.
- Confidentiality: protect personal data and confidential information throughout the handling of the crisis.
3. Action protocol
Any professional who becomes aware of a possible crisis must act as follows:
- Report it immediately to their direct manager and to the person in charge of crisis management, providing, whenever possible, images, screenshots or any other evidence of the messages or facts that caused the crisis, with the date, time and link where they were obtained.
- Assessment and coordination: the person in charge of crisis management will assess the situation and decide whether action is needed, who must take it and how. From that moment on, they will coordinate the people and external providers who need to be involved (communication and social media, legal advice, IT and security, etc.).
- Follow-up: the person in charge of crisis management will keep gdsgw, gfsgqs, informed about the progress and handling of the crisis.
Person in charge of crisis management
This is the person appointed by gdsgw, gfsgqs. Until someone is appointed, this role is taken on directly by gdsgw.
4. Guidelines during the crisis
- Only the person in charge of crisis management, or whoever they appoint, may speak on behalf of RAO SOCIAL to the media, on social networks or to third parties.
- No professional should reply to, comment on or share, on an individual basis, the content that caused the crisis.
- Posts, emails or documents related to the crisis must not be deleted or modified without the authorisation of the person in charge, so as not to lose evidence.
- Public replies must be truthful, prudent and consistent, and must not include personal data of clients, professionals or third parties.
- All significant decisions and actions must be documented, with the date and the person who took them.
5. Crises involving personal data or arising from the Whistleblowing Channel
5.1. Personal data security breach
If the crisis involves a security breach affecting personal data, the internal breach management procedure will also be activated:
- the risk to the rights and freedoms of the persons concerned will be assessed, with the involvement of the Data Protection Officer if there is one;
- if the breach entails a risk, the Spanish Data Protection Agency will be notified without undue delay and, if possible, within 72 hours of becoming aware of it (Article 33 of the GDPR);
- if the risk is high, the persons concerned will also be informed without undue delay (Article 34 of the GDPR); and
- the breach will be recorded in the internal incident register, even if notification is not required.
5.2. Crises related to the Whistleblowing Channel
If the crisis relates to facts reported through the Internal Reporting System, its handling may in no case be used to try to identify the reporting person or to take any retaliation against them. The confidentiality guarantees of Law 2/2023 will be respected and action will be coordinated with the System Manager (Maria puig).
6. Closing report and lessons learned
Once the crisis is resolved, the person in charge of crisis management or the person ultimately responsible for its handling must prepare a complete report on the situation, to serve as a reference for future cases. The report must include, at a minimum, all available information on:
- how the crisis came to light;
- which areas were affected;
- what caused it;
- what solution or solutions were adopted;
- what the timetable for applying the measures was;
- who took part in managing and solving the crisis;
- what consequences it had;
- what the main lessons learned from the situation were; and
- where applicable, what notifications were made to authorities or to the persons concerned.
The report is confidential, must be kept with restricted access and, if it contains personal data, only those that are necessary.
Purpose of the closing report
To document the response, preserve organisational learning and improve the ability to act in future crises.
7. Approval and review
This Protocol is approved by gdsgw, gfsgqs, and will be reviewed at least once a year and whenever experience in applying it or organisational changes make it necessary. It supplements the Code of Ethics and Conduct of RAO SOCIAL, SL, especially its Article 15.
Version control
| Implementation | 8 October 2026 |
| Last review of the documentation | 8 October 2026 |
This Crisis Response Protocol is an internal document of RAO SOCIAL, SL and sets out the handling guidelines for situations that may affect the image or reputation of the organisation. It will be updated when organisational changes or experience in applying it make it necessary.