Internal Information System Policy
With the aim of promoting a culture of information and communication as a mechanism for preventing and detecting irregularities and acting immediately to ensure their effective handling, Grup Oliva Motor, within the framework of Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and the fight against corruption, approves this Internal Information System Policy, which sets out its general guidelines and is also implemented through the corresponding internal procedure.
The Internal Information System allows information on irregularities to be reported by all members of the Organisation, its stakeholders, and all persons referred to in Article 3 of Law 2/2023 of 20 February, provided that, in the latter case, the conditions and requirements established therein are met.
Good faith and the honest belief that serious harmful acts have occurred or may occur are essential requirements for the protection of the Reporting Person. Such good faith is an expression of civic-minded conduct and stands in contrast to other actions that must be excluded from protection, such as the submission of false or distorted information or information obtained unlawfully. False reports or accusations, defamatory statements, and reports made in bad faith are prohibited and may be subject to disciplinary or other measures. Likewise, the communication of false information concerning acts or omissions covered by Law 2/2023 may be subject to a very serious administrative penalty ranging from EUR 30,001 to EUR 300,000.
This Policy guarantees the rights of both the Reporting Person and the person affected by the report. In particular, the Reporting Person is protected against retaliation occurring internally within the work or professional environment. The person affected by the report is guaranteed the right to honour and the presumption of innocence, as well as the right of defence, while their identity is protected and the confidentiality of the facts and procedural data is guaranteed. In all cases, these rights are guaranteed subject to compliance with the applicable legal requirements, particularly those established under Law 2/2023.
The Internal Information System should preferably be used to channel information, since diligent and effective action within the Organisation itself may prevent or limit the harmful consequences of the conduct under investigation. Notwithstanding this preference, the Reporting Person may choose the channel to use, whether internal or external, depending on the circumstances and risks they consider relevant.
Acts or omissions may be reported where, within the personal and material scope of Law 2/2023, they may constitute infringements of European Union law or serious or very serious criminal or administrative offences. For written reports, the corresponding form is available at the bottom of the website, reports may be sent to the corporate email address [email protected], or by post, addressed to the person responsible for the Internal Information System at the Company's registered office: Carrer Josep M Folch i Torres, 2, 43006 Tarragona (Spain). Telephone: +34 606 727 806. Reports may also be made verbally by requesting an in-person meeting with the person responsible for the Internal Information System.
The Board of Directors has appointed a person responsible for the Internal Information System, who shall diligently and, in the absence of any conflict of interest, handle and resolve the procedures initiated as a result of the information received, ensuring the proper application of the Procedure with honesty and objectivity towards all persons involved.
Within seven (7) days of receiving the report, acknowledgement of receipt shall be provided to the Reporting Person, unless doing so could jeopardise the confidentiality of the report. The maximum period for responding to investigative actions shall not exceed three (3) months, except in cases of particular complexity, in which case it may be extended by a further three (3) months. Specific periods are established for the retention and deletion of personal data and reports, in accordance with personal data protection regulations.
Reports that are accepted for processing shall be subject to appropriate follow-up and internal investigation. Those that do not meet the requirements necessary for processing, follow-up, and investigation shall be archived.
The Internal Information System guarantees the confidentiality and secrecy of the information provided, the identity and protection of the personal data of the Reporting Person, any third parties mentioned in the report, and the person affected by the report throughout all stages of the handling and follow-up process, as well as during any subsequent internal investigation or proceedings carried out on the basis of the facts reported. Only persons duly authorised to do so, within the scope of their responsibilities and functions, may access the information contained in the Internal Information System.
Any breach of this Policy and of any procedures implementing it may be subject to disciplinary sanctions or other appropriate measures, depending on the legal relationship established and the circumstances involved, without prejudice to the possible application of the sanctioning regime under Law 2/2023, which provides for minor, serious, and very serious administrative infringements, with fines of up to EUR 300,000 for natural persons and up to EUR 1,000,000 for legal entities.
Grup Oliva Motor shall periodically review this Policy to ensure its effectiveness.
Version 00. Date: 13-08-2024
