SECURITY POLICY FOR THE PROCESSING OF PERSONAL DATA

1. PURPOSE AND SCOPE OF APPLICATION

This Policy sets forth the rules, obligations, and best practices that must be understood and followed by anyone who accesses the organization’s systems, data, facilities, or information, regardless of their contractual relationship (employees, interns, contractors, service providers, or external collaborators). It must be made available to all staff, who may access it at any time and must ensure compliance with it in the performance of their duties.

Failure to comply with the guidelines set forth herein may result in disciplinary, civil, and/or criminal liability in accordance with applicable regulations.

2. RESPONSIBILITIES

2.1. Address

Management is responsible for approving this policy, providing the necessary resources, and ensuring compliance. It designates the Security Officer as the internal point of contact.

2.2. Security Officer

Manages security incidents, keeps this manual up to date, provides training, and answers staff questions.

2.3. All staff

Any person who has access to the organization’s information and systems is responsible for fully complying with the provisions set forth in this manual, as well as for acting in accordance with the established internal policies and procedures regarding security and data protection.

Furthermore, all equipment, devices, applications, and corporate systems must be used with the utmost diligence, responsibility, and confidentiality; their use for purposes other than those strictly related to work or professional activities authorized by the organization is prohibited.

3. PROTECTED RESOURCES

In order to ensure the security, integrity, availability, and confidentiality of the personal data processed by the organization, all assets, elements, systems, and environments that are directly or indirectly involved in the processing of such data are considered protected resources.

The following is a list of the main protected resources:

  • Data processing centers, offices, facilities, and premises where files, records, equipment, or storage media containing personal data are located, including both physical and electronic documentation.
  • Storage media, whether physical or digital, that contain personal data, such as hard drives, servers, USB drives, backup copies, network storage systems, laptops, mobile devices, and any other medium capable of storing personal information.
  • Workstations—whether on-site, mobile, or remote—from which personal data can be accessed or any processing operations involving such data can be performed, including computers, terminals, company phones, and devices used for telework.
  • The servers, technological infrastructure, and operating system and communications environments on which the files, databases, or applications that contain or process personal data are hosted.
  • Computer systems, applications, programs, platforms, and technological tools used for the collection, recording, organization, storage, retrieval, modification, transmission, blocking, deletion, or any other processing operation involving personal data.
  • Internal and external communication networks, cloud services, remote connections, information-sharing systems, and other telecommunications infrastructure used for the processing or transmission of personal data.
  • Authentication systems, access control, monitoring, activity logging, and other security mechanisms implemented to protect access to and use of personal data.
  • Any other resource, asset, physical or logical element, infrastructure, or service that, even if not expressly identified in this document, is involved or may be involved in the processing of personal data and whose protection is necessary to ensure compliance with current data protection regulations.

4. REGULATORY FRAMEWORK

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
  • Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights.
  • Law 34/2002, of July 11, on Information Society Services and Electronic Commerce.
  • Royal Legislative Decree 2/2015, dated October 23, approving the consolidated text of the Workers' Statute Act.

5. PRINCIPLES RELATING TO DATA PROCESSING

The principles governing the processing of personal data are set forth in Article 5 of the GDPR and in Articles 4 et seq. of the LOPDGDD. They constitute the fundamental pillar upon which any data processing operation carried out by the organization must be based and, therefore, must be understood and applied by all employees who, in the course of their duties, process personal data of employees, customers, suppliers, or any other natural person.

The following provides an overview of the six principles set forth in Article 5 of the GDPR, as well as the principle of proactive accountability, which are discussed in detail in the sections below:

LEGAL BASIS

PRINCIPLE

SUMMARY DESCRIPTION

Art. 5.1.a) GDPR

Legality, Integrity, and Transparency

The processing must have a valid legal basis, and the data subject must be informed.

Art. 5.1.b) of the GDPR

Purpose Limitation

The data will be used only for the purposes stated at the time of collection.

Art. 5.1.c) of the GDPR

Minimization

Only the data that is strictly necessary will be collected.

Art. 5.1.d) GDPR

Accuracy

The data will be kept up to date and corrected without delay.

Art. 5.1.e) GDPR

Limitation on the Retention Period

The data will not be retained any longer than necessary.

Art. 5.1.f) of the GDPR

Integrity and Confidentiality

Technical and organizational measures will be implemented to protect the data.

Art. 5.2 of the GDPR

Proactive Responsibility

The person in charge must be able to demonstrate compliance with the principles.

5.1 Principle of Lawfulness, Fairness, and Transparency

As set forth in Article 5.1.a) of the GDPR, this principle requires that all processing of personal data simultaneously meet three requirements:

  • Lawfulness: The processing must be based on one of the legal grounds set forth in Article 6(1) of the GDPR.
  • Fairness: Data must not be used in a manner that is contrary to the data subject's reasonable expectations.
  • Transparency: The data subject must have access to clear, accessible, and complete information about the processing.

5.1.1 Legal Basis for Processing (Art. 6.1 of the GDPR)

For a processing activity to be lawful, it must be based on at least one of the following grounds:

P.O. Box

Legal Basis

Contents

Art. 6.1.a)

Consent

The data subject has given consent for one or more specific purposes.

Art. 6.1.b)

Contract Performance

The processing is necessary for the performance of a contract or for precontractual measures.

Art. 6.1.c)

Legal Obligation

The processing is necessary to fulfill a legal obligation of the data controller.

Art. 6.1.d)

Vital Interests

The processing is necessary to protect the vital interests of the data subject or another person.

Art. 6.1.e)

Public Interest

The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

Art. 6.1.f)

Legitimate Interest

Processing is necessary to meet the legitimate interests of the controller or a third party, unless the fundamental rights of the data subject take precedence.

⚠️ Note

The legal basis must be determined before processing begins and must be documented in the Record of Processing Activities (Art. 30 GDPR). A retroactive selection of a legal basis is not permitted.

5.1.2 Duty to Provide Information: Two-Tier System (Articles 13–14 of the GDPR and Article 11 of the LOPDGDD)

When the LOPDGDD applies, the information may be provided in two tiers to make it easier for the data subject to understand. In all other cases, the provisions of Articles 13 or 14 of the GDPR must be complied with directly, depending on whether the data was provided by the data subject or by a third party.

First Tier (Art. 11 of the LOPDGDD)

• Identity of the data controller and its representative (if applicable).

• Purpose of the processing.

• The right to exercise the rights set forth in Articles 15 et seq. of the GDPR.

• Whether profiling is used, if applicable.

• [If the data does not come from the data subject] Categories of data and sources.

Second Tier (Articles 13–14 of the GDPR)

• Full identification and contact information for the data controller and its representative.

• Contact information for the DPO, if applicable.

• Purposes of the processing and legal basis.

• Legitimate interests of the data controller or third parties (if the legal basis is Article 6(1)(f)).

• Recipients or categories of recipients.

• International data transfers, if applicable.

• Retention periods.

• Data subject rights (Articles 15–22 of the GDPR) and the right to withdraw consent.

• Right to file a complaint with the AEPD.

• Disclosure of personal data to third parties and the use of automated decision-making or profiling.

• [If the data comes from third parties] Data categories and source.

Timeframes for Providing Information (Art. 14 of the GDPR): When the data is not obtained directly from the data subject, the information must be provided within one month of its collection. If the data is used to contact the data subject, the information must be provided at that time. If the data is to be disclosed to a third party, the information must be provided prior to such disclosure.

📋Form

The information must be presented in a concise, transparent, intelligible, and easily accessible manner, using clear and plain language. It may be provided electronically when the technological complexity of the processing so warrants (Recital 58 of the GDPR).

5.2 Principle of Purpose Limitation

As provided for in Article 5.1.b) of the GDPR, this principle prohibits the processing of personal data for purposes that are different from or incompatible with those for which the data was originally collected.

In practice, this principle imposes the following obligations:

  • Explicitly determine and document the purpose of the processing before beginning to collect data.
  • Do not use the data for subsequent purposes that are incompatible with the original purpose without an additional legal basis.
  • Notify the data subject and, when necessary, obtain their consent if it is decided to expand or change the purposes of the processing.

ℹ️ Compatibility

To assess whether a new purpose is compatible with the original one, Article 6(4) of the GDPR stipulates that the following factors, among others, must be taken into account: the connection between the purposes, the context in which the data was collected, the nature of the data, and the potential consequences for the data subject.

5.3 Principle of Data Minimization

Article 5.1.c) of the GDPR requires that the data being processed be adequate, relevant, and limited to what is strictly necessary in relation to the purposes of the processing.

This principle requires that:

  • Determine in advance which data are essential to fulfill the stated purpose.
  • Exclude any data that may be considered excessive, irrelevant, or unnecessary for that purpose.
  • Periodically review data collection forms, systems, and processes to identify and eliminate unnecessary fields.

🔍Practical Application

Before designing any form or data collection process, you should assess whether the data is necessary: Is this data essential to achieving the purpose? If the answer is not a clear “yes,” the data should not be collected.

5.4 Principle of Accuracy

As provided for in Article 5.1.d) of the GDPR, this principle requires the data controller—and, where applicable, the data processor—to take all reasonable measures to ensure that personal data is accurate and up to date.

The main obligations arising from this principle are:

  • To rectify or erase, without undue delay, any data that is inaccurate or incomplete in relation to the purposes of the processing.
  • Implement mechanisms that allow data subjects to report and correct errors in their data.
  • Establish internal procedures for periodically reviewing the accuracy of the data.

This principle is implemented through two rights recognized by the GDPR:

Right to Rectification

Art. 16 of the GDPR

The right to request the correction or completion of personal data when it is inaccurate or incomplete for the purposes of processing.

Right to erasure

Art. 17 of the GDPR

The right to have data erased without undue delay when any of the following grounds apply:

• Withdrawal of consent given for data processing.

• Exercising the right to object without there being any overriding legitimate grounds.

• Unlawful processing of data.

• Legal obligation to delete.

• Data collected in the context of information society services.

5.5 Principle of Limiting the Retention Period

Article 5.1.e) of the GDPR stipulates that personal data must not be retained for longer than is necessary to fulfill the purposes for which it was collected.

This principle imposes the following obligations:

  • Determine specific retention periods for each category of data and each purpose of processing, and ensure they are properly documented.
  • Apply deletion or anonymization procedures once the retention period has expired.
  • Comply with the statutory retention periods established by sector-specific regulations (labor, tax, commercial, etc.), which may coexist with the general retention period.

📌Exception

Article 5.1.e) of the GDPR itself provides that data collected for archiving purposes in the public interest, scientific or historical research, or statistical purposes may be retained for longer periods, provided that appropriate technical and organizational safeguards are in place (Article 89 of the GDPR).

📋Best practice

The entity must maintain a document retention schedule that specifies, for each processing activity, the applicable retention period, the regulations on which it is based, and the secure destruction procedure to be followed upon expiration of the retention period.

5.6 Principle of Integrity and Confidentiality

As set forth in Article 5.1.f) of the GDPR, this principle requires that personal data be processed in a manner that ensures its security through the implementation of appropriate technical and organizational measures.

Article 32(1) of the GDPR specifies the security obligations related to data processing:

  • Pseudonymization and encryption of personal data.
  • The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • The ability to quickly restore access to and availability of data in the event of a physical or technical incident.
  • Regular verification, evaluation, and assessment of the effectiveness of the technical and organizational measures implemented.

Unlike the previous regulations, the GDPR adopts an approach based on risk and on privacy by design and by default (Articles 25 and 32 of the GDPR): it does not establish an exhaustive list of measures, but rather requires the controller to assess the risks associated with the processing and to implement measures commensurate with the identified level of risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing.

⚠️Proactive Obligation

Security measures must be implemented before processing begins, not afterward. Their effectiveness must be reviewed and updated periodically. Failure to comply with security obligations may result in the notification of a data breach to the AEPD (Art. 33 of the GDPR) and to the data subjects themselves (Art. 34 of the GDPR).

5.7 Principle of Proactive Accountability

Article 5.2 of the GDPR adds a seventh cross-cutting principle: the data controller must not only comply with the preceding principles, but must also be able to demonstrate compliance at all times.

The main accountability tools are:

  • Record of Processing Activities (Art. 30 of the GDPR).
  • Data Protection Impact Assessment (DPIA) (Art. 35 of the GDPR), where applicable.
  • Appointment of a Data Protection Officer (DPO) (Articles 37–39 of the GDPR and Articles 34–37 of the LOPDGDD), whether mandatory or voluntary.
  • Internal data protection policies, ongoing training, and periodic audits.
  • Compliance with codes of conduct or certifications (Articles 40–43 of the GDPR).

📌Key

The principle of accountability makes compliance an ongoing and documented process. It is not enough to comply on a one-time basis; the entity must be able to demonstrate at all times—to the AEPD or to any data subject—that its data processing activities comply with the regulations.

6. INFORMATION AFFECTED

The organization processes different types and categories of personal data depending on the activities it carries out.

For the purposes of this Policy, “personal data” means any information relating to an identified or identifiable natural person. Any person whose identity can be determined, directly or indirectly, by means of an identifier, piece of data, or set of data—such as first and last names, identification document, mailing or email address, phone number, IP address, location data, online identifiers, images, voice recordings, signature, physical, economic, cultural, or social characteristics, as well as any other information that allows for their identification—shall be considered identifiable.

The personal data processed by the organization may include, among others, the following categories:

  • Identifying and contact information.
  • Academic, professional, and employment information.
  • Economic, financial, and revenue data.
  • Browsing data and use of computer systems.
  • Data relating to customers, suppliers, employees, partners, and third parties associated with the organization's activities.
  • Sensitive personal data or special categories of data, when their processing is necessary and duly authorized in accordance with applicable regulations.

The processing of each category and type of personal data will involve the implementation of specific technical and organizational measures, taking into account the nature of the information, the associated level of risk, and the applicable legal obligations in each case.

Consequently, all users, employees, contractors, or authorized third parties involved in any data processing activities must comply with the obligations and security measures set forth in this policy and in applicable data protection regulations throughout the entire lifecycle of personal data—from its collection or access through its retention, blocking, and permanent deletion.

Furthermore, personal data may only be processed for the purposes expressly authorized, ensuring at all times compliance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, purpose limitation, integrity, confidentiality, and proactive accountability.

7. INTERNATIONAL TRANSFERS OF PERSONAL DATA

Should it be necessary to carry out international data transfers, the level of protection in the destination country will be verified, and the safeguards required by the regulations will be adopted. First, it will be determined whether there is an adequacy decision approved by the Commission. In the absence of such a decision, one of the mechanisms set forth in Article 46 of the GDPR will be used, with the signing of standard contractual clauses being the preferred option. Only in exceptional cases will one of the exceptions contained in Article 49 of the GDPR be invoked. In any case, none of this shall apply when the transfer is necessary as part of international cooperation with third-country authorities and where no international treaty or convention applies, nor Directive (EU) 2016/680, nor Articles 43 through 47 of Organic Law 7/2021 of May 26, on the protection of personal data processed for the purposes of preventing, detecting, investigating, and prosecuting criminal offenses and enforcing criminal sanctions.

8. RECORD OF PROCESSING ACTIVITIES

In accordance with Article 30 of the GDPR, a record must be kept of the activities carried out under the organization’s responsibility, and this record must be kept up to date to reflect any changes that occur. This record must contain all of the information listed below:

  1. (a) the name and contact information of the controller and, where applicable, the joint controller, the controller’s representative, and the data protection officer;
  2. b) the purposes of the processing;
  3. (c) a description of the categories of data subjects and the categories of personal data;
  4. d) the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organizations;
  5. e) where applicable, transfers of personal data to a third country or international organization, including the identification of the country or organization and the safeguards applied;
  6. f) where possible, the time limits for the erasure of the various categories of data;
  7. (g) where possible, a general description of the technical and organizational security measures.

Likewise, when acting as a data processor, a record shall also be kept of all categories of processing activities carried out on behalf of a data controller, containing:

  1. (a) the name and contact information of the processor or processors and of each controller on whose behalf the processor acts, and, where applicable, of the representative of the controller or the processor, and of the data protection officer;
  2. (b) the categories of processing carried out on behalf of each controller;
  3. (c) where applicable, transfers of personal data to a third country or international organization, including the identification of the country or organization and the safeguards applied;
  4. (d) where possible, a general description of the technical and organizational security measures.

Such records shall be kept in writing, including in electronic format.

9. EXERCISE OF DATA SUBJECTS' RIGHTS

Data protection regulations allow data subjects to exercise the following rights with the data controller: the right of access, rectification, objection, erasure (“right to be forgotten”), restriction of processing, data portability, and the right not to be subject to automated individual decision-making.

To this end, the organization has established the channels listed below so that interested parties may submit the corresponding requests to exercise their rights by contacting the organization via email, postal mail, or any other internal channel that has been established and communicated to staff.

Furthermore, with the aim of regulating and establishing in detail the protocol for responding to the exercise of rights, the organization has developed this response protocol.

This protocol outlines the established procedure for addressing the rights of data subjects and applies both to employees authorized to handle requests for the exercise of rights submitted by data subjects and the staff under their supervision, as well as to other third parties with access to data and to the organization’s data processors, including the staff under their supervision, all of whom are subject to the provisions of the aforementioned protocol and must act at all times in accordance with the established instructions.

10. SAFETY GUIDELINES

10.1 PASSWORD POLICY

Password-based access control is one of the primary security measures for protecting an organization’s systems and information. The use of strong, secure passwords is essential, as a weak or compromised password can jeopardize the confidentiality, integrity, and availability of the data being processed.

Access to personal data and the organization’s confidential information will be limited based on the responsibilities and duties assigned to each employee. To this end, access permissions and profiles will be established for each position or role, ensuring that each user can access only the information strictly necessary for the performance of their duties.

Each user will be provided with unique, personal, and non-transferable login credentials. Sharing passwords or allowing third parties to use one’s own credentials is expressly prohibited.

Passwords must meet the security criteria established by the organization and be kept strictly confidential.

10.1.1 Password Requirements

Every password must meet ALL of the following criteria:

• At least 10 characters.

• Combine uppercase letters, lowercase letters, numbers, and symbols (!@#$%)

• Maximum validity of 3 months.

• One per service: never reuse across different platforms.

• Do not reuse any of your last 5 passwords.

10.1.2. Rules of Use

DO

DO NOT DO

Use a different password for each system or application

Writing down passwords on sticky notes, pieces of paper, or unencrypted files

Change your password every 3 months, or immediately if you suspect it has been compromised

Sharing passwords with coworkers—not even with the IT team

Use an encrypted password manager with two-factor authentication (2FA)

Use of personal data: name, date of birth, ID number, pet's name

Enable 2FA on all services that support it

Use keyboard patterns: qwerty, 123456, asdf, etc.

Immediately notify the Security Officer if you suspect that your password has been compromised

Enable "Remember Password" in browsers on shared computers

11. USE OF DEVICES AND WORKSTATION

11.1. Clean Desktop Policy

The physical workspace must be kept tidy to prevent unauthorized access to documents or devices.

DO

DO NOT DO

Remove printed documents from the printer immediately

Leaving confidential documents out in the open on the table when you step away

Lock away sensitive physical documents at the end of the workday

Placing beverages without airtight lids next to equipment or documents

Store corporate mobile devices (laptops, cell phones, tablets) in a secure location

Leaving USB drives or external hard drives plugged in and unattended

Shred obsolete documents with a paper shredder

Throwing documents containing data into the regular trash without shredding them

11.2. Clean Screen Policy

The device's screen may expose sensitive information to unauthorized individuals. It is mandatory to implement the following measures:

  • Set the screen to lock automatically after 10 minutes of inactivity.
  • For short absences (up to 30 minutes): Lock the screen using Windows + L or the equivalent.
  • During long absences or at the end of the workday: log out and turn off the computer.
  • Orient the screen so that only the user can see its content.
  • Do not leave sensitive information in plain sight when you step away from your workstation.

12. ELECTRONIC DEVICES AND CORPORATE RESOURCES

All electronic devices, computer equipment, and other corporate resources made available to employees must be used in accordance with the minimum security measures established by the organization, which include, but are not limited to, the following:

DO

DO NOT DO

If an employee wishes to use the device for personal purposes, he or she must obtain prior written authorization from the organization

Using such devices for purposes unrelated to work.

Devices must have the latest patches and operating system updates installed, in accordance with the periodic updates provided by the system developer.

Do not use any devices other than those provided by the organization for work-related purposes.

Security settings must be configured by default by the company's IT manager.

Any device that contains critical or confidential information, or special categories of data as defined by the GDPR, must have appropriate safeguards in place to ensure the security of the information and prevent unauthorized access.

In the event of loss, theft, or unauthorized access to the device, staff must immediately report the incident to the person in charge of security.

Do not connect corporate devices to the internet via public Wi-Fi networks without using the corporate VPN.

Report any security incidents that have occurred.

Do not store any of the organization's data or confidential information on removable media.

Use only the tools, applications, and corporate systems authorized and provided by the organization for the performance of work duties.

Do not install, use, or store on-premises any software, applications, or tools that have not been authorized by the organization, nor use unauthorized alternatives for processing corporate or personal information.

13. EMAIL

Corporate email is a work tool. Its improper use is one of the main entry points for threats (phishing, malware) and data breaches.

DO

DO NOT DO

Always verify the sender before opening attachments or links

Using corporate email for personal or private purposes

Encrypt emails that contain personal data or confidential information

Sending databases, personal data, or confidential information without encryption

Use BCC (blind carbon copy) when sending emails to multiple recipients

Opening attachments or clicking on links from unknown senders

Report suspicious emails to the Security Officer

Forwarding chain emails or emails containing unauthorized commercial content

Sign out of your email account when using shared or public computers

Set up corporate email on unauthorized devices

ALERT: Phishing

If you receive an email asking for login credentials, bank information, or urging you to take immediate action, DO NOT click on any links or reply. Report it immediately to the Security Officer.

14. USE OF THE INTERNET AND THE CORPORATE NETWORK

DO

DO NOT DO

Browse only websites necessary for work-related tasks

Connecting to Public Wi-Fi Networks Without Using the Corporate VPN

Use the corporate VPN when connecting from external or public networks

Downloading software, music, movies, or other content without authorization

Report any unusual behavior in the network or on the equipment

Scan ports, test for vulnerabilities, or carry out internal/external attacks

Disconnect unauthorized USB devices immediately

Access the guest network using corporate devices

 

Installing Unauthorized Browser Extensions

 

Engaging in any activity that compromises the availability or integrity of the network

15. SOFTWARE AND FACILITIES

Installing unauthorized software can introduce malware, vulnerabilities, or licensing issues with serious legal and technical consequences.

DO

DO NOT DO

Request prior authorization in writing before installing any software.

Installing software, applications, or extensions without written authorization

Verify that the software has a valid license before installing it.

Using pirated or unlicensed versions of any software

Always keep your operating system and applications up to date.

Disable the antivirus software or automatic system updates

Verify that the software is compatible with the corporate system.

Conducting tests or development using real personal data without authorization

16. USE OF ARTIFICIAL INTELLIGENCE TOOLS

The use of generative AI systems (chatbots, assistants, content generators, etc.) requires special caution to protect the confidentiality of corporate and personal information.

DO

DO NOT DO

Request prior authorization from the responsible office or department to use AI tools

Entering personal data of customers, employees, or third parties into AI systems

Use AI exclusively for authorized work tasks

Sharing confidential information, trade secrets, or intellectual property with external AI tools

Approach AI-generated results with a critical eye and verify them

Publishing or distributing AI-generated content without prior review and authorization

 

Using unauthorized AI tools to make decisions that affect people

Remember:

Any information you enter into an external AI tool may be processed and stored by third parties. Never enter information that you would not post on a public channel.

17. PHYSICAL AND LOGICAL ACCESS CONTROL

17.1. Physical Access to the Facilities

  • Keys, access cards, and codes are for personal use only and are non-transferable.
  • It is prohibited to make copies of keys or grant access without express authorization.
  • Lock offices, cabinets, and rooms containing sensitive information when you are away.
  • The server room is accessible only to personnel authorized by the Security Manager.
  • Report the loss of any access item immediately.

17.2. Logical Access to Systems

  • Each user has access only to the systems and data necessary for their role (principle of least privilege).
  • You are prohibited from accessing information that is not related to your job responsibilities.
  • User accounts are revoked immediately upon termination of the contractual relationship.
  • Permissions are reviewed periodically to remove unnecessary access rights.

18. MEDIA MANAGEMENT AND SECURE DELETION

18.1. Use of Removable Storage Media

Removable devices (USB drives, external hard drives, SD cards) are a common source of data leaks and malware infections.

DO

DO NOT DO

Request authorization to remove any data storage device from the premises

Removing storage media containing personal or confidential information without authorization

Always encrypt the contents of removable media that contain sensitive data

Connecting USB devices from unknown sources to corporate computers

Record the assignment and return of removable media

Disposing of or discarding hard drives, USB drives, or other storage media without secure destruction

Hand over any media that must be disposed of to the Security Officer

 

18.2. Secure Deletion

Simply pressing the “Delete” key or dragging a file to the trash does NOT securely delete the information. It only removes the reference to the file; the content remains on the disk.

  • Empty the recycling bin at the end of each workday.
  • For files containing sensitive data, use secure deletion tools authorized by the IT department.
  • Equipment that has been decommissioned must be turned over to the Safety Officer for certified destruction.
  • Paper documents containing personal information must be shredded; they should never be thrown away whole.

19. SECURITY INCIDENT MANAGEMENT

A security incident is any event that compromises or could compromise the confidentiality, integrity, or availability of information.

Examples of incidents that MUST be reported to the Security Officer:

• Loss or theft of devices or documents containing information

• Unauthorized access to systems or data

• Received a phishing email or clicked on a malicious link

• Virus or malware detected on the computer

• Accidental transmission of personal data to the wrong recipient.

Password exposed or compromised

19.1. Action Protocol

  1. Do not act rashly: do not turn off the equipment or destroy evidence.
  2. Immediately notify the Security Officer, providing details of what happened, when it happened, and which data or systems may be affected.
  3. Collaborate with the investigation by providing all available information.
  4. The Security Officer will assess the scope of the matter together with the Data Protection Attorney and, if appropriate, notify the Spanish Data Protection Agency (AEPD) and/or the affected data subjects.
  5. The incident will be documented, and corrective measures will be implemented to prevent it from happening again.

20. BACKUPS

Backups ensure that the organization can recover its data in the event of an incident. It is everyone's responsibility to ensure that they function properly.

  • The IT department establishes the backup policy and frequency.
  • All employees must store information in the designated corporate locations and systems, not on their local computer desktops.
  • It is not permitted to store corporate information exclusively on personal devices or unauthorized cloud services.
  • If you have any questions about whether data is being backed up, please contact the IT department.

Version

Date

Description

V.1.0

2026

Initial version