This Policy sets forth the rules, obligations, and best practices that must be understood and followed by anyone who accesses the organization’s systems, data, facilities, or information, regardless of their contractual relationship (employees, interns, contractors, service providers, or external collaborators). It must be made available to all staff, who may access it at any time and must ensure compliance with it in the performance of their duties.
Failure to comply with the guidelines set forth herein may result in disciplinary, civil, and/or criminal liability in accordance with applicable regulations.
Management is responsible for approving this policy, providing the necessary resources, and ensuring compliance. It designates the Security Officer as the internal point of contact.
Manages security incidents, keeps this manual up to date, provides training, and answers staff questions.
Any person who has access to the organization’s information and systems is responsible for fully complying with the provisions set forth in this manual, as well as for acting in accordance with the established internal policies and procedures regarding security and data protection.
Furthermore, all equipment, devices, applications, and corporate systems must be used with the utmost diligence, responsibility, and confidentiality; their use for purposes other than those strictly related to work or professional activities authorized by the organization is prohibited.
In order to ensure the security, integrity, availability, and confidentiality of the personal data processed by the organization, all assets, elements, systems, and environments that are directly or indirectly involved in the processing of such data are considered protected resources.
The following is a list of the main protected resources:
The principles governing the processing of personal data are set forth in Article 5 of the GDPR and in Articles 4 et seq. of the LOPDGDD. They constitute the fundamental pillar upon which any data processing operation carried out by the organization must be based and, therefore, must be understood and applied by all employees who, in the course of their duties, process personal data of employees, customers, suppliers, or any other natural person.
The following provides an overview of the six principles set forth in Article 5 of the GDPR, as well as the principle of proactive accountability, which are discussed in detail in the sections below:
LEGAL BASIS | PRINCIPLE | SUMMARY DESCRIPTION |
Art. 5.1.a) GDPR | Legality, Integrity, and Transparency | The processing must have a valid legal basis, and the data subject must be informed. |
Art. 5.1.b) of the GDPR | Purpose Limitation | The data will be used only for the purposes stated at the time of collection. |
Art. 5.1.c) of the GDPR | Minimization | Only the data that is strictly necessary will be collected. |
Art. 5.1.d) GDPR | Accuracy | The data will be kept up to date and corrected without delay. |
Art. 5.1.e) GDPR | Limitation on the Retention Period | The data will not be retained any longer than necessary. |
Art. 5.1.f) of the GDPR | Integrity and Confidentiality | Technical and organizational measures will be implemented to protect the data. |
Art. 5.2 of the GDPR | Proactive Responsibility | The person in charge must be able to demonstrate compliance with the principles. |
As set forth in Article 5.1.a) of the GDPR, this principle requires that all processing of personal data simultaneously meet three requirements:
For a processing activity to be lawful, it must be based on at least one of the following grounds:
P.O. Box | Legal Basis | Contents |
Art. 6.1.a) | Consent | The data subject has given consent for one or more specific purposes. |
Art. 6.1.b) | Contract Performance | The processing is necessary for the performance of a contract or for precontractual measures. |
Art. 6.1.c) | Legal Obligation | The processing is necessary to fulfill a legal obligation of the data controller. |
Art. 6.1.d) | Vital Interests | The processing is necessary to protect the vital interests of the data subject or another person. |
Art. 6.1.e) | Public Interest | The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. |
Art. 6.1.f) | Legitimate Interest | Processing is necessary to meet the legitimate interests of the controller or a third party, unless the fundamental rights of the data subject take precedence. |
| The legal basis must be determined before processing begins and must be documented in the Record of Processing Activities (Art. 30 GDPR). A retroactive selection of a legal basis is not permitted. |
When the LOPDGDD applies, the information may be provided in two tiers to make it easier for the data subject to understand. In all other cases, the provisions of Articles 13 or 14 of the GDPR must be complied with directly, depending on whether the data was provided by the data subject or by a third party.
First Tier (Art. 11 of the LOPDGDD) | • Identity of the data controller and its representative (if applicable). • Purpose of the processing. • The right to exercise the rights set forth in Articles 15 et seq. of the GDPR. • Whether profiling is used, if applicable. • [If the data does not come from the data subject] Categories of data and sources. |
Second Tier (Articles 13–14 of the GDPR) | • Full identification and contact information for the data controller and its representative. • Contact information for the DPO, if applicable. • Purposes of the processing and legal basis. • Legitimate interests of the data controller or third parties (if the legal basis is Article 6(1)(f)). • Recipients or categories of recipients. • International data transfers, if applicable. • Retention periods. • Data subject rights (Articles 15–22 of the GDPR) and the right to withdraw consent. • Right to file a complaint with the AEPD. • Disclosure of personal data to third parties and the use of automated decision-making or profiling. • [If the data comes from third parties] Data categories and source. |
Timeframes for Providing Information (Art. 14 of the GDPR): When the data is not obtained directly from the data subject, the information must be provided within one month of its collection. If the data is used to contact the data subject, the information must be provided at that time. If the data is to be disclosed to a third party, the information must be provided prior to such disclosure.
| The information must be presented in a concise, transparent, intelligible, and easily accessible manner, using clear and plain language. It may be provided electronically when the technological complexity of the processing so warrants (Recital 58 of the GDPR). |
As provided for in Article 5.1.b) of the GDPR, this principle prohibits the processing of personal data for purposes that are different from or incompatible with those for which the data was originally collected.
In practice, this principle imposes the following obligations:
| To assess whether a new purpose is compatible with the original one, Article 6(4) of the GDPR stipulates that the following factors, among others, must be taken into account: the connection between the purposes, the context in which the data was collected, the nature of the data, and the potential consequences for the data subject. |
Article 5.1.c) of the GDPR requires that the data being processed be adequate, relevant, and limited to what is strictly necessary in relation to the purposes of the processing.
This principle requires that:
| Before designing any form or data collection process, you should assess whether the data is necessary: Is this data essential to achieving the purpose? If the answer is not a clear “yes,” the data should not be collected. |
As provided for in Article 5.1.d) of the GDPR, this principle requires the data controller—and, where applicable, the data processor—to take all reasonable measures to ensure that personal data is accurate and up to date.
The main obligations arising from this principle are:
This principle is implemented through two rights recognized by the GDPR:
Right to Rectification Art. 16 of the GDPR | The right to request the correction or completion of personal data when it is inaccurate or incomplete for the purposes of processing. |
Right to erasure Art. 17 of the GDPR | The right to have data erased without undue delay when any of the following grounds apply: • Withdrawal of consent given for data processing. • Exercising the right to object without there being any overriding legitimate grounds. • Unlawful processing of data. • Legal obligation to delete. • Data collected in the context of information society services. |
Article 5.1.e) of the GDPR stipulates that personal data must not be retained for longer than is necessary to fulfill the purposes for which it was collected.
This principle imposes the following obligations:
| Article 5.1.e) of the GDPR itself provides that data collected for archiving purposes in the public interest, scientific or historical research, or statistical purposes may be retained for longer periods, provided that appropriate technical and organizational safeguards are in place (Article 89 of the GDPR). |
| The entity must maintain a document retention schedule that specifies, for each processing activity, the applicable retention period, the regulations on which it is based, and the secure destruction procedure to be followed upon expiration of the retention period. |
As set forth in Article 5.1.f) of the GDPR, this principle requires that personal data be processed in a manner that ensures its security through the implementation of appropriate technical and organizational measures.
Article 32(1) of the GDPR specifies the security obligations related to data processing:
Unlike the previous regulations, the GDPR adopts an approach based on risk and on privacy by design and by default (Articles 25 and 32 of the GDPR): it does not establish an exhaustive list of measures, but rather requires the controller to assess the risks associated with the processing and to implement measures commensurate with the identified level of risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing.
| Security measures must be implemented before processing begins, not afterward. Their effectiveness must be reviewed and updated periodically. Failure to comply with security obligations may result in the notification of a data breach to the AEPD (Art. 33 of the GDPR) and to the data subjects themselves (Art. 34 of the GDPR). |
Article 5.2 of the GDPR adds a seventh cross-cutting principle: the data controller must not only comply with the preceding principles, but must also be able to demonstrate compliance at all times.
The main accountability tools are:
| The principle of accountability makes compliance an ongoing and documented process. It is not enough to comply on a one-time basis; the entity must be able to demonstrate at all times—to the AEPD or to any data subject—that its data processing activities comply with the regulations. |
The organization processes different types and categories of personal data depending on the activities it carries out.
For the purposes of this Policy, “personal data” means any information relating to an identified or identifiable natural person. Any person whose identity can be determined, directly or indirectly, by means of an identifier, piece of data, or set of data—such as first and last names, identification document, mailing or email address, phone number, IP address, location data, online identifiers, images, voice recordings, signature, physical, economic, cultural, or social characteristics, as well as any other information that allows for their identification—shall be considered identifiable.
The personal data processed by the organization may include, among others, the following categories:
The processing of each category and type of personal data will involve the implementation of specific technical and organizational measures, taking into account the nature of the information, the associated level of risk, and the applicable legal obligations in each case.
Consequently, all users, employees, contractors, or authorized third parties involved in any data processing activities must comply with the obligations and security measures set forth in this policy and in applicable data protection regulations throughout the entire lifecycle of personal data—from its collection or access through its retention, blocking, and permanent deletion.
Furthermore, personal data may only be processed for the purposes expressly authorized, ensuring at all times compliance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, purpose limitation, integrity, confidentiality, and proactive accountability.
Should it be necessary to carry out international data transfers, the level of protection in the destination country will be verified, and the safeguards required by the regulations will be adopted. First, it will be determined whether there is an adequacy decision approved by the Commission. In the absence of such a decision, one of the mechanisms set forth in Article 46 of the GDPR will be used, with the signing of standard contractual clauses being the preferred option. Only in exceptional cases will one of the exceptions contained in Article 49 of the GDPR be invoked. In any case, none of this shall apply when the transfer is necessary as part of international cooperation with third-country authorities and where no international treaty or convention applies, nor Directive (EU) 2016/680, nor Articles 43 through 47 of Organic Law 7/2021 of May 26, on the protection of personal data processed for the purposes of preventing, detecting, investigating, and prosecuting criminal offenses and enforcing criminal sanctions.
In accordance with Article 30 of the GDPR, a record must be kept of the activities carried out under the organization’s responsibility, and this record must be kept up to date to reflect any changes that occur. This record must contain all of the information listed below:
Likewise, when acting as a data processor, a record shall also be kept of all categories of processing activities carried out on behalf of a data controller, containing:
Such records shall be kept in writing, including in electronic format.
Data protection regulations allow data subjects to exercise the following rights with the data controller: the right of access, rectification, objection, erasure (“right to be forgotten”), restriction of processing, data portability, and the right not to be subject to automated individual decision-making.
To this end, the organization has established the channels listed below so that interested parties may submit the corresponding requests to exercise their rights by contacting the organization via email, postal mail, or any other internal channel that has been established and communicated to staff.
Furthermore, with the aim of regulating and establishing in detail the protocol for responding to the exercise of rights, the organization has developed this response protocol.
This protocol outlines the established procedure for addressing the rights of data subjects and applies both to employees authorized to handle requests for the exercise of rights submitted by data subjects and the staff under their supervision, as well as to other third parties with access to data and to the organization’s data processors, including the staff under their supervision, all of whom are subject to the provisions of the aforementioned protocol and must act at all times in accordance with the established instructions.
Password-based access control is one of the primary security measures for protecting an organization’s systems and information. The use of strong, secure passwords is essential, as a weak or compromised password can jeopardize the confidentiality, integrity, and availability of the data being processed.
Access to personal data and the organization’s confidential information will be limited based on the responsibilities and duties assigned to each employee. To this end, access permissions and profiles will be established for each position or role, ensuring that each user can access only the information strictly necessary for the performance of their duties.
Each user will be provided with unique, personal, and non-transferable login credentials. Sharing passwords or allowing third parties to use one’s own credentials is expressly prohibited.
Passwords must meet the security criteria established by the organization and be kept strictly confidential.
Every password must meet ALL of the following criteria: • At least 10 characters. • Combine uppercase letters, lowercase letters, numbers, and symbols (!@#$%) • Maximum validity of 3 months. • One per service: never reuse across different platforms. • Do not reuse any of your last 5 passwords. |
✓ DO | ✗ DO NOT DO |
Use a different password for each system or application | Writing down passwords on sticky notes, pieces of paper, or unencrypted files |
Change your password every 3 months, or immediately if you suspect it has been compromised | Sharing passwords with coworkers—not even with the IT team |
Use an encrypted password manager with two-factor authentication (2FA) | Use of personal data: name, date of birth, ID number, pet's name |
Enable 2FA on all services that support it | Use keyboard patterns: qwerty, 123456, asdf, etc. |
Immediately notify the Security Officer if you suspect that your password has been compromised | Enable "Remember Password" in browsers on shared computers |
The physical workspace must be kept tidy to prevent unauthorized access to documents or devices.
✓ DO | ✗ DO NOT DO |
Remove printed documents from the printer immediately | Leaving confidential documents out in the open on the table when you step away |
Lock away sensitive physical documents at the end of the workday | Placing beverages without airtight lids next to equipment or documents |
Store corporate mobile devices (laptops, cell phones, tablets) in a secure location | Leaving USB drives or external hard drives plugged in and unattended |
Shred obsolete documents with a paper shredder | Throwing documents containing data into the regular trash without shredding them |
The device's screen may expose sensitive information to unauthorized individuals. It is mandatory to implement the following measures:
All electronic devices, computer equipment, and other corporate resources made available to employees must be used in accordance with the minimum security measures established by the organization, which include, but are not limited to, the following:
✓ DO | ✗ DO NOT DO |
If an employee wishes to use the device for personal purposes, he or she must obtain prior written authorization from the organization | Using such devices for purposes unrelated to work. |
Devices must have the latest patches and operating system updates installed, in accordance with the periodic updates provided by the system developer. | Do not use any devices other than those provided by the organization for work-related purposes. |
Security settings must be configured by default by the company's IT manager. | Any device that contains critical or confidential information, or special categories of data as defined by the GDPR, must have appropriate safeguards in place to ensure the security of the information and prevent unauthorized access. |
In the event of loss, theft, or unauthorized access to the device, staff must immediately report the incident to the person in charge of security. | Do not connect corporate devices to the internet via public Wi-Fi networks without using the corporate VPN. |
Report any security incidents that have occurred. | Do not store any of the organization's data or confidential information on removable media. |
Use only the tools, applications, and corporate systems authorized and provided by the organization for the performance of work duties. | Do not install, use, or store on-premises any software, applications, or tools that have not been authorized by the organization, nor use unauthorized alternatives for processing corporate or personal information. |
Corporate email is a work tool. Its improper use is one of the main entry points for threats (phishing, malware) and data breaches.
✓ DO | ✗ DO NOT DO |
Always verify the sender before opening attachments or links | Using corporate email for personal or private purposes |
Encrypt emails that contain personal data or confidential information | Sending databases, personal data, or confidential information without encryption |
Use BCC (blind carbon copy) when sending emails to multiple recipients | Opening attachments or clicking on links from unknown senders |
Report suspicious emails to the Security Officer | Forwarding chain emails or emails containing unauthorized commercial content |
Sign out of your email account when using shared or public computers | Set up corporate email on unauthorized devices |
ALERT: Phishing If you receive an email asking for login credentials, bank information, or urging you to take immediate action, DO NOT click on any links or reply. Report it immediately to the Security Officer. |
✓ DO | ✗ DO NOT DO |
Browse only websites necessary for work-related tasks | Connecting to Public Wi-Fi Networks Without Using the Corporate VPN |
Use the corporate VPN when connecting from external or public networks | Downloading software, music, movies, or other content without authorization |
Report any unusual behavior in the network or on the equipment | Scan ports, test for vulnerabilities, or carry out internal/external attacks |
Disconnect unauthorized USB devices immediately | Access the guest network using corporate devices |
Installing Unauthorized Browser Extensions | |
Engaging in any activity that compromises the availability or integrity of the network |
Installing unauthorized software can introduce malware, vulnerabilities, or licensing issues with serious legal and technical consequences.
✓ DO | ✗ DO NOT DO |
Request prior authorization in writing before installing any software. | Installing software, applications, or extensions without written authorization |
Verify that the software has a valid license before installing it. | Using pirated or unlicensed versions of any software |
Always keep your operating system and applications up to date. | Disable the antivirus software or automatic system updates |
Verify that the software is compatible with the corporate system. | Conducting tests or development using real personal data without authorization |
The use of generative AI systems (chatbots, assistants, content generators, etc.) requires special caution to protect the confidentiality of corporate and personal information.
✓ DO | ✗ DO NOT DO |
Request prior authorization from the responsible office or department to use AI tools | Entering personal data of customers, employees, or third parties into AI systems |
Use AI exclusively for authorized work tasks | Sharing confidential information, trade secrets, or intellectual property with external AI tools |
Approach AI-generated results with a critical eye and verify them | Publishing or distributing AI-generated content without prior review and authorization |
Using unauthorized AI tools to make decisions that affect people |
Remember: Any information you enter into an external AI tool may be processed and stored by third parties. Never enter information that you would not post on a public channel. |
Removable devices (USB drives, external hard drives, SD cards) are a common source of data leaks and malware infections.
✓ DO | ✗ DO NOT DO |
Request authorization to remove any data storage device from the premises | Removing storage media containing personal or confidential information without authorization |
Always encrypt the contents of removable media that contain sensitive data | Connecting USB devices from unknown sources to corporate computers |
Record the assignment and return of removable media | Disposing of or discarding hard drives, USB drives, or other storage media without secure destruction |
Hand over any media that must be disposed of to the Security Officer |
Simply pressing the “Delete” key or dragging a file to the trash does NOT securely delete the information. It only removes the reference to the file; the content remains on the disk.
A security incident is any event that compromises or could compromise the confidentiality, integrity, or availability of information.
Examples of incidents that MUST be reported to the Security Officer: • Loss or theft of devices or documents containing information • Unauthorized access to systems or data • Received a phishing email or clicked on a malicious link • Virus or malware detected on the computer • Accidental transmission of personal data to the wrong recipient. Password exposed or compromised |
Backups ensure that the organization can recover its data in the event of an incident. It is everyone's responsibility to ensure that they function properly.
Version | Date | Description |
V.1.0 | 2026 | Initial version |