1Version control
| Company | doValue Spain Servicing, S.A.U. |
|---|---|
| Title | Criminal Compliance Policy |
| Version | V.6.2 |
| Document | Policy 1 |
| Produced by | Compliance Officer |
| Date of Approval | 24/09/2026 |
| Person responsible for approval | Compliance Officer |
| Date of ratification | 11/2026 |
| Responsible for ratification | DVSP Board of Directors |
| Amended or repealed policies or regulations | Criminal Compliance Policy v.6.1 |
| Changes in this version | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy. |
| Date of last update | 24/09/2026 |
Version history
| Version | Reason for the Change | Person in charge | Date of approval | Date of ratification |
|---|---|---|---|---|
| 1.0 | Initial Version | 18/09/2018 | 20/09/2018 | NA |
| Comité Cumplimiento | Consejo Altamira Asset Management | NA | ||
| 2.0 | Version 2 | 15/01/2019 | 16/01/2019 | NA |
| Comité Cumplimiento | Consejo Altamira Asset Management | NA | ||
| 3.0 | Version 3 (Introduction of changes to the scope of application) | Regulatory Compliance | 07/10/2020 | NA |
| Comité Control | NA | |||
| 4.0 | Versión 4 (Cambio de denominación social y actualización de nuevas políticas y procedimientos) | Regulatory Compliance | 07/10/2020 | NA |
| Comité Control | NA | |||
| 5.0 | Versión 5 (Cambio en la referencia al Modelo de Cumplimiento por Marco de Cumplimiento e incorporación de un párrafo en el punto 5) | Regulatory Compliance | 10/03/2025 | NA |
| Comité Control | NA | |||
| 6.0 | Comprehensive update of the Policy to bring it into line with UNE 19601, alignment with the Integrated Management System, review of the scope of application, update of the governance of the criminal compliance system, and adaptation to the Internal Reporting System Policy | Compliance Officer | 31/07/2026 | NA |
| Compliance Officer | NA | |||
| 6.1 | Update to the version control section, including typo corrections | Compliance Officer | 04/08/2026 | 09/2026 |
| Compliance Officer | Consejo Administración DVSP | |||
| 6.2 | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy | Compliance Officer | 24/09/2026 | 11/2026 |
| Compliance Officer | Consejo Administración DVSP |
2Introduction
By means of this Criminal Compliance Policy of DOVALUE SPAIN SERVICING, S.A.U. (hereinafter, "doValue" or "DVSP" or "DOVALUE") and its subsidiaries included in the scope of the IMS and, specifically, its subsidiary in Spain, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (hereinafter, "Team4" or "T4") express their commitment to the development of a culture of compliance, integrity and business ethics that inspires the conduct of all members of the Organisation and of those persons acting in its name or on its behalf.
For the purposes of this Policy, "the Organisation" or "the Company" shall mean doValue together with the other companies included in the scope of the System. As at the date of approval of this Policy, that perimeter comprises doValue Spain Servicing, S.A.U. and Team 4 Collection and Consulting, S.L.U. Any reference in this Policy to "the subsidiaries" or "its subsidiaries" shall be understood to refer exclusively to the subsidiaries of doValue included in the scope of the System
El cumplimiento normativo y la prevención de delitos constituyen elementos esenciales del modelo de gobierno y control de la Organización. En este sentido, la Organización ha implantado su propio Sistema Integrado de Gestión (en adelante, SIG o Sistema), que incorpora los principios, controles y mecanismos necesarios para prevenir, detectar y gestionar los riesgos penales derivados de sus actividades, alineándose con la normativa vigente en materia de responsabilidad penal de las personas jurídicas, así como con los requisitos de la Norma UNE 19601: Sistemas de Gestión de Compliance Penal.
The Management and the Board of Directors of the Organisation assume an express commitment to promoting a culture of compliance based on respect for the law, zero tolerance of the commission of unlawful acts and the continual improvement of the internal control systems.
La Organización ha logrado una posición de liderazgo y referencia en el mercado. Para ello ha sido y es fundamental el comportamiento ético y responsable de los miembros del órgano de administración, directivos, empleados, colaboradores y demás personas sujetas a la presente Política (en adelante, el "Personal"), persiguiendo la implantación de un SIG robusto y promoviendo una cultura de cumplimiento en toda la organización. Por ello, esta Política de Cumplimiento Penal constituye el marco de referencia del Sistema, que es conocido y de obligado cumplimiento por todo el Personal e impulsado por la Dirección.
3 Scope of application
La presente Política es de aplicación a los miembros del órgano de administración, directivos, empleados, trabajadores cedidos, becarios, personal en formación y, en general, a todas las personas que desarrollen su actividad profesional para doValue y sus filiales, con independencia de la naturaleza, duración o modalidad de su relación con la Organización.
Likewise, this Policy applies to those natural or legal persons who act in the name of or on behalf of doValue and/or its subsidiaries, as well as to those who perform administration, management, supervision or control functions within the Organisation or within the entities forming part of its group.
The Organisation shall also promote awareness of and compliance with the principles set out in this Policy amongst its business partners, suppliers, contractors, external collaborators, advisers and other third parties with whom it maintains professional or commercial relationships, where applicable in accordance with current legislation, the contractual obligations undertaken or the Organisation’s internal control and compliance systems.
4 Purpose and objectives
The purpose of this Criminal Compliance Policy is to promote and consolidate a culture of compliance, integrity and ethical behaviour within doValue and its subsidiaries, thereby reinforcing the Organisation’s commitment to the prevention, detection and management of criminal risks arising from the conduct of its business.
Likewise, this Policy expresses the commitment to zero tolerance of the commission of any unlawful conduct or conduct contrary to the applicable legislation, to the Code of Ethics or to the principles underpinning the Integrated Management System, and in no case may the obtaining of an economic, operational or strategic benefit justify a regulatory breach.
To achieve this aim, this Policy sets out the following objectives:
- To establish the general principles governing the Organisation’s Integrated Criminal Compliance Management System.
- To promote professional conduct characterised by diligence, integrity and respect for the law on the part of all persons subject to this Policy.
- To promote the prevention, early detection and appropriate management of criminal risks.
- To provide an understanding of the obligations, responsibilities, controls and procedures that make up the Integrated Criminal Compliance Management System.
- Strengthen the culture of communication and consultation in the event of queries or potential breaches, encouraging the use of the channels provided by the Organisation.
- To contribute to the continual improvement of the Criminal Compliance Integrated Management System and to the protection of the reputation, sustainability and good governance of the Organisation.
5 General principles of action
The Integrated Management System of doValue and its subsidiaries is based on the following general principles, which form the fundamental basis both for the internal regulations of doValue and its subsidiaries and for the conduct of staff:
Zero tolerance for criminal offences
doValue and its subsidiaries prohibit all persons referred to in section 3 of this Policy from committing criminal offences and require them to report such offences or any other suspicious behaviour that may constitute a criminal offence through the channels established for this purpose.
Prevention and management of criminal risks
To this end, and in view of the nature of the business carried out by doValue and its subsidiaries —which focuses on the management and advisory services relating to portfolios of financial assets (including NPLs and REOs), debt recovery and management, and the management and marketing of property assets— the following areas have been identified as requiring particular attention: the management of and negotiations with debtors and third parties in debt recovery processes; contracting and relations with suppliers, intermediaries and business partners; the valuation, acquisition and disposal of financial and property assets; and the management of confidential information and personal data. These activities are subject to periodic analysis and assessment of criminal risks within the framework of the Integrated Management System, the results of which are set out in the corresponding criminal risk map. All of this is in accordance with the standards, principles, values and objectives established in the field of criminal compliance, and with the aim of minimising the exposure of doValue and its subsidiaries to criminal risks.
Commitment to legality
La Organización, y especialmente su Consejo de Administración y la Dirección, se comprometen a cumplir con la normativa penal vigente que resulte de aplicación, así como con los requisitos establecidos en el Sistema Integrado de Gestión de Compliance Penal y Calidad. A tal efecto, actuarán y exigirán que se actúe en todo momento conforme a lo dispuesto en dicha normativa y en el Sistema, y que en todo caso se cumpla con los requisitos de esta Política.
Duty to communicate
La Organización promueve el deber de comunicar, a través del Sistema Interno de Información (SII), cualquier conducta irregular o potencial incumplimiento de la normativa aplicable o de la normativa interna de la Organización del que se tenga conocimiento o sospecha razonable. La Organización garantiza la confidencialidad de las comunicaciones, la protección de la identidad del informante y la prohibición de represalias o conductas perjudiciales en los términos previstos en la normativa aplicable y en la Política del Sistema Interno de Información.
Disciplinary procedure
doValue y sus filiales difunden entre todo el Personal el régimen disciplinario aplicable en caso de incumplimiento del Sistema Integrado de Gestión o de la normativa interna de aplicación, o en el supuesto de comisión de hechos o conductas que pudieran ser calificadas de delictivas, en virtud de lo establecido en los convenios colectivos de aplicación.
A framework for achieving objectives
doValue and its subsidiaries establish, monitor and periodically review the objectives of the Integrated Criminal Compliance Management System, ensuring that they are aligned with the identified criminal risks and with the organisation’s strategy. To this end, they allocate the necessary financial, human and technological resources to ensure these objectives are properly achieved and monitored.
Dissemination and access
The System is communicated accurately and on an ongoing basis to all staff. Furthermore, the principles and standards underpinning it will be made available to all members of the organisation. This Policy is made available to all interested parties via internal communication channels and the corporate website.
Criminal Compliance Body
The criminal compliance function, carried out by the Compliance Officer, is responsible for supervising, managing and keeping the Integrated Management System up to date, whilst ensuring its effectiveness. This function is carried out autonomously and independently, with full powers and authority to perform its role. The Compliance Officer reports directly to the Board of Directors, providing regular updates on the status of the System, and has direct access to the Board, regardless of the chain of command, whenever circumstances so require. This reporting structure guarantees the Compliance Officer’s functional independence from the business areas and from any body or individual subject to their supervision.
Continuous improvement
The Integrated Management System is subject to periodic review and continuous improvement, with reports being provided to the Management Body and the Governing Body (Board of Directors), on a regular basis, regarding its supervisory and monitoring activities, any structural and regulatory changes that may have occurred, as well as the performance metrics for criminal compliance and the results of its assessment.
6 Regulations forming the framework for criminal compliance
doValue and its subsidiaries have a set of fundamental standards, applicable to all staff, upon which the Integrated Management System is structured and implemented:
- Code of Ethics: this constitutes the general framework and guidance for the conduct of business by doValue and its subsidiaries. Based on the business principles of doValue and its subsidiaries, it sets out the ethical principles that must govern the conduct of all employees. All members and external collaborators of doValue and its subsidiaries are required to be familiar with this document.
- Integrated Management System Manual: this sets out the guidelines for doValue and its subsidiaries to ensure they exercise due control and fulfil their duty of supervision over their business activities, thereby complying with the legal requirements of the Spanish Criminal Code and the risk control obligations imposed by the Companies Act (Royal Decree 1/2010).
- Internal Reporting Policy: doValue and its subsidiaries provide a Communication Channel or Ethics Channel through which employees or third parties associated with doValue and its subsidiaries may report breaches or suspected breaches of the law in the course of doValue’s and its subsidiaries’ business activities. This promotes transparency and ensures proper compliance with the law and the Code of Ethics.
- Corporate Procedure for the Management of the Internal Reporting System: sets out the guidelines for action in cases where it is established that, within doValue and its subsidiaries, conduct is taking place that may constitute breaches of European Union law, or serious or very serious criminal or administrative offences.
- Global Policy on Conflicts of Interest and Related-Party Transactions: this sets out the commitment of doValue and its subsidiaries to implement global measures and policies designed to identify potential conflicts of interest that may arise in the course of providing services.
- Gifts Policy: this policy expressly prohibits the giving or receiving of any kind of gift or financial payment with the intention of obtaining any kind of benefit for the organisation.
- Anti-Corruption Policy: this sets out the commitment of doValue and its subsidiaries to a zero-tolerance approach towards any form of corruption, in both the public and private sectors, including bribery, kickbacks, influence peddling and any other corrupt practices.
- Formación en materia de compliance y prevención de riesgos penales: se establece anualmente un plan de formación, comunicación, sensibilización y difusión donde se detallan los aspectos prácticos sobre la prevención de delitos para que todos los miembros de doValue y sus filiales sean conocedores de sus derechos y obligaciones en relación al compliance penal.
- Disciplinary procedure: this shall apply in the event of non-compliance with the Integrated Management System or the applicable internal regulations, as well as in cases where irregular acts or conduct are committed, in accordance with the system of offences and sanctions set out in the Collective Agreements applicable to doValue and its subsidiaries, in the Workers’ Statute and in any other applicable labour or internal regulations. In cases where the acts may constitute a criminal offence, doValue and its subsidiaries may report them to the competent authorities, without prejudice to cases where such reporting is legally mandatory. The consequences of the disciplinary regime shall apply to all Staff subject to this Policy, regardless of their position or hierarchical level, including directors and senior managers, in accordance with the labour, commercial or contractual regulations applicable in each case. All of the above is without prejudice to the provisions of section 8 of this Policy.
7 Commitment of the Board of Directors and the Management Body
The Boards of Directors and Management Bodies of doValue and its subsidiaries hereby reaffirm, through this Policy, their commitment to ethics, integrity, regulatory compliance and the prevention of crime, whilst promoting a culture of compliance that forms part of the Organisation’s values and day-to-day activities.
<p>The Board of Directors, as the governing body of the Organisation, assumes visible, active and effective leadership in relation to the Criminal Compliance Integrated Management System, driving its implementation, supervising its operation and promoting its continual improvement. It also approves this Policy and ensures that the System has the human, technological and financial resources necessary to achieve its objectives.</p>
For its part, the Management Body is responsible for promoting the effective application of the principles and requirements set out in the Integrated Management System, fostering behaviour consistent with the culture of compliance and integrating criminal compliance objectives into the Organisation’s day-to-day management.
The Board of Directors and the Management Body expressly support the independent exercise of the criminal compliance function, entrusted to the Compliance Officer, guaranteeing their autonomy, authority, access to the information necessary for the performance of their duties, and direct access to the governing bodies when circumstances so require.
<p>Likewise, both bodies promote the communication, dissemination and awareness of this Policy, as well as of the other elements comprising the Criminal Compliance Integrated Management System, driving the training, awareness-raising and engagement of all persons subject to it.</p>
8Reporting of irregularities
All persons subject to this Policy are obliged to report any breach or reasonable suspicion of a breach of applicable legislation, the Code of Ethics, this Policy or any other rules forming part of the Integrated Management System, of which they become aware in the course of their professional activities.
To this end, the Organisation has an Internal Reporting System (IRS) managed in accordance with the Internal Reporting System Policy and the Corporate Procedure for the Management of the Internal Reporting System, ensuring the confidentiality of the information reported, the protection of the whistleblower’s identity and the prohibition of reprisals in accordance with the provisions of the applicable regulations.
The Internal Reporting System is overseen by the Internal Reporting System Committee (CSII), which is appointed by the Board of Directors as the system’s manager.
Communications may be made via the channels provided by the Organisation, which can be accessed via the following links:
- doValue: https://dovalue.whistlelink.com/
- TEAM4: https://team4.canalhelas.com/home
Todo lo relativo al funcionamiento del Sistema Interno de Información, las modalidades de comunicación, las garantías aplicables a los informantes, personas afectadas y terceros relacionados, así como la tramitación de las comunicaciones recibidas, se regula en la Política del Sistema Interno de Información y en el Procedimiento de Gestión del Sistema Interno de Información.
9Breaches of the Criminal Compliance Policy
Compliance with this Policy is the responsibility of all persons falling within its scope. Furthermore, the Board of Directors, the Management Body and those who hold management or supervisory roles within the Organisation must actively promote awareness of, and adherence to, this Policy within their respective areas of responsibility.
Sin perjuicio de lo anterior, corresponde al Compliance Officer, en el ejercicio de la función de Compliance Penal, supervisar la adecuada implantación, mantenimiento y eficacia del Sistema Integrado de Gestión de Compliance Penal, así como informar de su funcionamiento a los órganos de gobierno y dirección de la Organización.
Breach of the provisions of this Policy may give rise to the adoption of such disciplinary, contractual or legal measures as may be appropriate in each case, in accordance with the legislation in force, the applicable collective bargaining agreements, the internal regulations of the Organisation and the contractual obligations assumed.
These measures will be implemented in accordance with the nature and seriousness of the facts, whilst ensuring, in all cases, that the rights of those affected are upheld and that legally established procedures are respected.
10 Publication and entry into force
This Policy forms part of the Criminal Compliance Management System of doValue and constitutes documented information thereof. The Policy shall be subject to periodic review and continual improvement, in order to ensure its adequacy to the applicable legislation, to the evolution of the criminal risks of the Organisation, to the organisational changes that may occur and to the needs arising from the operation of the Integrated Management System.
Furthermore, this Policy will be made available to interested parties via doValue’s corporate website, the websites of its subsidiaries and any other channels that the Organisation deems appropriate to ensure its dissemination and accessibility.
This Policy shall come into force at doValue and its subsidiaries on the date of its approval by the relevant competent body, and shall remain in force until it is replaced, amended or repealed by a new version.
1Version control
| Company | doValue Spain Servicing, S.A.U. |
|---|---|
| Title | Criminal Compliance Policy |
| Version | V.6.2 |
| Document | Policy 1 |
| Prepared by | Compliance Officer |
| Approval Date | 24/09/2026 |
| Person responsible for approval | Compliance Officer |
| Ratification date | 11/2026 |
| Person responsible for ratification | Board of Directors of DVSP |
| Policy or rules amended / repealed | Criminal Compliance Policy v.6.1 |
| Amendments to the version | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy. |
| Date of last update | 24/09/2026 |
Version history
| Version | Reason for the Change | Owner | Approval date | Ratification date |
|---|---|---|---|---|
| 1.0 | Initial Version | 18/09/2018 | 20/09/2018 | NA |
| Compliance Committee | Altamira Asset Management Board | NA | ||
| 2.0 | Version 2 | 15/01/2019 | 16/01/2019 | NA |
| Compliance Committee | Altamira Asset Management Board | NA | ||
| 3.0 | Version 3 (Introduction of changes to the scope of application) | Regulatory Compliance | 07/10/2020 | NA |
| Control Committee | NA | |||
| 4.0 | Version 4 (Change of corporate name and update of new policies and procedures) | Regulatory Compliance | 07/10/2020 | NA |
| Control Committee | NA | |||
| 5.0 | Version 5 (Change of the reference to the Compliance Model to Compliance Framework and addition of a paragraph in point 5) | Regulatory Compliance | 10/03/2025 | NA |
| Control Committee | NA | |||
| 6.0 | Comprehensive update of the Policy to align it with UNE 19601, adapt it to the Integrated Management System, review the scope of application, update the governance of the criminal compliance system and align it with the Internal Information System Policy | Compliance Officer | 31/07/2026 | NA |
| Compliance Officer | NA | |||
| 6.1 | Update of the version control section with correction of typos | Compliance Officer | 04/08/2026 | 09/2026 |
| Compliance Officer | DVSP Board of Directors | |||
| 6.2 | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy | Compliance Officer | 24/09/2026 | 11/2026 |
| Compliance Officer | DVSP Board of Directors |
2Introduction
By means of this Criminal Compliance Policy of DOVALUE SPAIN SERVICING, S.A.U. (hereinafter, "doValue" or "DVSP" or "DOVALUE") and its subsidiaries included in the scope of the IMS and, specifically, its subsidiary in Spain, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (hereinafter, "Team4" or "T4") express their commitment to the development of a culture of compliance, integrity and business ethics that inspires the conduct of all members of the Organisation and of those persons acting in its name or on its behalf.
For the purposes of this Policy, "the Organisation" or "the Company" shall mean doValue together with the other companies included in the scope of the System. As at the date of approval of this Policy, that perimeter comprises doValue Spain Servicing, S.A.U. and Team 4 Collection and Consulting, S.L.U. Any reference in this Policy to "the subsidiaries" or "its subsidiaries" shall be understood to refer exclusively to the subsidiaries of doValue included in the scope of the System.
Regulatory compliance and the prevention of offences are essential elements of the governance and control model of the Organisation. In this regard, the Organisation has implemented its own Integrated Management System (hereinafter, the IMS or the System), which incorporates the principles, controls and mechanisms necessary to prevent, detect and manage the criminal risks arising from its activities, in line with the legislation in force on the criminal liability of legal persons, as well as with the requirements of standard UNE 19601: Criminal Compliance Management Systems.
The Management and the Board of Directors of the Organisation assume an express commitment to promoting a culture of compliance based on respect for the law, zero tolerance of the commission of unlawful acts and the continual improvement of the internal control systems.
The Organisation has achieved a position of leadership and benchmark status in the market. To that end, the ethical and responsible conduct of the members of the administrative body, managers, employees, collaborators and other persons subject to this Policy (hereinafter, the "Personnel") has been and remains fundamental, pursuing the implementation of a robust IMS and promoting a culture of compliance throughout the organisation. For this reason, this Criminal Compliance Policy constitutes the frame of reference for the System, which is known to and mandatory for all Personnel and is driven by Management.
3Scope of application
This Policy applies to the members of the administrative body, managers, employees, assigned workers, interns, trainees and, in general, to all persons who carry out their professional activity for doValue and its subsidiaries, irrespective of the nature, duration or form of their relationship with the Organisation.
Likewise, this Policy applies to those natural or legal persons who act in the name of or on behalf of doValue and/or its subsidiaries, as well as to those who perform administration, management, supervision or control functions within the Organisation or within the entities forming part of its group.
The Organisation shall likewise promote awareness and observance of the principles contained in this Policy among its business partners, suppliers, contractors, external collaborators, advisers and other third parties with which it maintains professional or commercial relationships, where this is applicable in accordance with the legislation in force, the contractual obligations assumed or the internal control and compliance systems of the Organisation.
4Purpose and objectives
The purpose of this Criminal Compliance Policy is to promote and consolidate a culture of compliance, integrity and ethical conduct within doValue and its subsidiaries, reinforcing the commitment of the Organisation to the prevention, detection and management of the criminal risks arising from the performance of its activity.
Likewise, this Policy expresses the commitment to zero tolerance of the commission of any unlawful conduct or conduct contrary to the applicable legislation, to the Code of Ethics or to the principles underpinning the Integrated Management System, and in no case may the obtaining of an economic, operational or strategic benefit justify a regulatory breach.
In order to achieve that purpose, this Policy pursues the following objectives:
- To establish the general principles governing the Criminal Compliance Integrated Management System of the Organisation.
- To foster diligent, honest and law-abiding professional conduct on the part of all persons subject to this Policy.
- To promote the prevention, early detection and proper management of criminal risks.
- To facilitate awareness of the obligations, responsibilities, controls and procedures that make up the Criminal Compliance Integrated Management System.
- To reinforce the culture of communication and consultation in the event of doubts or possible breaches, encouraging the use of the channels made available by the Organisation.
- To contribute to the continual improvement of the Criminal Compliance Integrated Management System and to the protection of the reputation, sustainability and good governance of the Organisation.
5General principles of conduct
The Integrated Management System of doValue and its subsidiaries is based on the following general principles, which constitute the fundamental basis both of the internal regulations of doValue and its subsidiaries and of the conduct of the Personnel:
Zero tolerance of the commission of offences
doValue and its subsidiaries prohibit all persons covered by section 3 of this Policy from committing criminal acts and require them to report such acts, or any other suspicious conduct liable to constitute a criminal offence, through the channels established for those purposes.
Prevention and management of criminal risks
To this end, and having regard to the nature of the activity of doValue and its subsidiaries —focused on the management of and advisory services for portfolios of financial assets (including NPLs and REOs), credit recovery and management, and the management and marketing of real estate assets— the following are identified as areas requiring particular attention: the management of, and negotiation with, debtors and third parties in debt collection processes; the contracting of, and relationship with, suppliers, intermediaries and business partners; the valuation, acquisition and transfer of financial and real estate assets; and the management of confidential information and personal data. Those activities are subject to periodic criminal risk analysis and assessment within the framework of the Integrated Management System, the results of which are recorded in the corresponding criminal risk map. All of the foregoing is in line with the standards, principles, values and purposes established in the field of criminal compliance and with the objective of minimising the exposure of doValue and its subsidiaries to criminal risks.
Commitment to legality
The Organisation, and in particular its Board of Directors and Management, undertake to comply with the criminal legislation in force that is applicable, as well as with the requirements established in the Integrated Criminal Compliance and Quality Management System. To that end, they shall act, and shall require that action be taken, at all times in accordance with the provisions of that legislation and of the System, and that the requirements of this Policy be complied with in all cases.
Duty to report
The Organisation promotes the duty to report, through the Internal Information System (IIS), any irregular conduct or potential breach of the applicable legislation or of the internal regulations of the Organisation of which the person is aware or reasonably suspects. The Organisation guarantees the confidentiality of reports, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation and in the Internal Information System Policy.
Disciplinary regime
doValue and its subsidiaries disseminate among all Personnel the disciplinary regime applicable in the event of breach of the Integrated Management System or of the applicable internal regulations, or in the event of the commission of acts or conduct that may be classified as criminal, pursuant to the provisions of the applicable collective bargaining agreements.
Framework for the achievement of objectives
doValue and its subsidiaries establish, monitor and periodically review the objectives of the Criminal Compliance Integrated Management System, ensuring their alignment with the criminal risks identified and with the strategy of the organisation. To that end, they allocate the financial, human and technological resources necessary for their proper achievement and monitoring.
Dissemination and access
The System is disseminated properly and on an ongoing basis among all Personnel. Likewise, the principles and rules comprising it shall be made available to all members of the organisation. This Policy is made available to all interested parties through the internal communication channels and the corporate website.
Criminal Compliance Body
The criminal compliance function, performed by the Compliance Officer, is responsible for supervising, managing and keeping the Integrated Management System up to date, ensuring its effectiveness. This function is performed with autonomy and independence, and with full powers and authority for the exercise of its role. The Compliance Officer reports directly to the Board of Directors, informing it periodically of the status of the System, and has direct access to it, irrespective of the hierarchical line, where circumstances so require. This reporting structure guarantees its functional independence from the business areas and from any body or person subject to its supervision.
Continual improvement
The Integrated Management System is subject to periodic review and continual improvement, with the Management Body and the Governing Body (Board of Directors) being informed, on a recurring basis, of its supervision and monitoring activities, of the structural and regulatory changes that may have occurred, as well as of the criminal compliance performance measurements and the results of their evaluation.
6Rules that make up the criminal compliance framework
doValue and its subsidiaries have a series of fundamental rules, applicable to all Personnel, on which the Integrated Management System is structured and developed:
- Code of Ethics: constitutes the general frame of reference and guidance for the conduct of the activities of doValue and its subsidiaries. Based on the business principles of doValue and its subsidiaries, it sets out the ethical principles that must govern the conduct of all employees. Knowledge of this document is mandatory for all members and external collaborators of doValue and its subsidiaries.
- Manual of the Integrated Management System: establishes the guidelines for action of doValue and its subsidiaries in order to comply with the exercise of due control and the duty of oversight over their business activity, thereby complying with the legal requirements of the Spanish Criminal Code and with the risk control duties imposed by the Spanish Companies Act (Royal Legislative Decree 1/2010).
- Internal Information System Policy: doValue and its subsidiaries make available a Reporting Channel or Ethics Channel, through which employees or third parties having a relationship with doValue and its subsidiaries may report breaches or suspicions concerning legal non-compliance within the business activity of doValue and its subsidiaries. This enhances transparency and the monitoring of proper compliance with the law and with the Code of Ethics.
- Corporate Procedure for the Management of the Internal Information System: establishes the guidelines for action in those cases where it is established that, within doValue and its subsidiaries, conduct is being carried out that potentially constitutes breaches of European Union law, or serious or very serious criminal or administrative offences.
- Global Policy on Conflicts of Interest and Related-Party Transactions: establishes the commitment of doValue and its subsidiaries to implement the global measures and policies enabling the identification of potential conflicts of interest that may arise in the provision of services.
- Gifts Policy: establishes the express prohibition on making or receiving any type of gift or financial commission with the intention of obtaining any kind of advantage benefiting the organisation.
- Anti-Corruption Policy: sets out the commitment of doValue and its subsidiaries to zero tolerance of any form of corruption, in both the public and the private sector, including bribery, corrupt payments, influence peddling and any other corrupt practice.
- Training in compliance and the prevention of criminal risks: A training, communication, awareness and dissemination plan is established annually, setting out the practical aspects of the prevention of offences so that all members of doValue and its subsidiaries are aware of their rights and obligations in relation to criminal compliance.
- Disciplinary regime: which shall apply in the event of breach of the Integrated Management System or of the applicable internal regulations, as well as in cases of the commission of irregular acts or conduct, in accordance with the regime of infringements and sanctions provided for in the Collective Bargaining Agreements applicable to doValue and its subsidiaries, in the Workers’ Statute and in any other applicable labour or internal rules. In cases where the acts may constitute a criminal offence, doValue and its subsidiaries may report them to the competent authorities, without prejudice to those cases in which such reporting is legally mandatory. The consequences of the disciplinary regime shall apply to all Personnel subject to this Policy, irrespective of their position or hierarchical level, including directors and senior managers, in accordance with the labour, commercial or contractual rules applicable in each case. All of the foregoing is without prejudice to the provisions of section 8 of this Policy.
7Commitment of the Board of Directors and of the Management Body
The Boards of Directors and the Management Bodies of doValue and its subsidiaries reaffirm, by means of this Policy, their commitment to ethics, integrity, regulatory compliance and the prevention of offences, promoting a culture of compliance that forms part of the values and of the day-to-day activity of the Organisation.
The Board of Directors, as the governing body of the Organisation, assumes visible, active and effective leadership in relation to the Criminal Compliance Integrated Management System, driving its implementation, supervising its operation and promoting its continual improvement. It also approves this Policy and ensures that the System has the human, technological and financial resources necessary to achieve its objectives.
For its part, the Management Body is responsible for promoting the effective application of the principles and requirements established in the Integrated Management System, fostering conduct consistent with the culture of compliance and integrating the criminal compliance objectives into the ordinary management of the Organisation.
The Board of Directors and the Management Body expressly support the independent exercise of the Criminal Compliance function, entrusted to the Compliance Officer, guaranteeing its autonomy, authority, access to the information necessary for the performance of its duties and direct access to the governing bodies where circumstances so require.
Likewise, both bodies promote the communication, dissemination and awareness of this Policy, as well as of the other elements comprising the Criminal Compliance Integrated Management System, driving the training, awareness-raising and engagement of all persons subject to it.
8Reporting of irregularities
All persons subject to this Policy are obliged to report any breach or reasonable suspicion of breach of the applicable legislation, of the Code of Ethics, of this Policy or of the other rules comprising the Integrated Management System of which they become aware in the course of their professional activities.
To this end, the Organisation has an Internal Information System (IIS) managed in accordance with the Internal Information System Policy and the Corporate Procedure for the Management of the Internal Information System, guaranteeing the confidentiality of the information reported, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation.
The Internal Information System is supervised by the Internal Information System Committee (IISC), appointed by the Board of Directors as the Person Responsible for the System.
Reports may be made through the channels made available by the Organisation, accessible via the following links:
- doValue: https://dovalue.whistlelink.com/
- TEAM4: https://team4.canalhelas.com/home
All matters relating to the operation of the Internal Information System, the methods of reporting, the safeguards applicable to reporting persons, persons concerned and related third parties, as well as the handling of the reports received, are governed by the Internal Information System Policy and the Procedure for the Management of the Internal Information System.
9Breaches of the Criminal Compliance Policy
Compliance with this Policy is the responsibility of all persons within its scope of application. Likewise, the Board of Directors, the Management Body and the persons performing management or supervisory functions in the Organisation shall actively promote awareness, application and compliance within their respective areas of responsibility.
Notwithstanding the foregoing, it is incumbent on the Compliance Officer, in the exercise of the Criminal Compliance function, to supervise the proper implementation, maintenance and effectiveness of the Criminal Compliance Integrated Management System, as well as to report on its operation to the governing and management bodies of the Organisation.
Breach of the provisions of this Policy may give rise to the adoption of such disciplinary, contractual or legal measures as may be appropriate in each case, in accordance with the legislation in force, the applicable collective bargaining agreements, the internal regulations of the Organisation and the contractual obligations assumed.
The application of such measures shall be carried out having regard to the nature and seriousness of the acts, guaranteeing in all cases the rights of the persons concerned and respect for the legally established procedures.
10Publication and entry into force
This Policy forms part of the Criminal Compliance Management System of doValue and constitutes documented information thereof. The Policy shall be subject to periodic review and continual improvement, in order to ensure its adequacy to the applicable legislation, to the evolution of the criminal risks of the Organisation, to the organisational changes that may occur and to the needs arising from the operation of the Integrated Management System.
Likewise, this Policy shall be made available to interested parties through the corporate website of doValue, the websites of its subsidiaries and such other means as the Organisation considers appropriate to ensure its dissemination and accessibility.
This Policy shall enter into force at doValue and its subsidiaries on the date of its approval by the relevant competent body, and shall remain in force until it is replaced, amended or repealed by a new version.

