1. Controlo de versões

EmpresadoValue Spain Servicing, S.A.U.
TítuloPolítica de Conformidade Penal
VersãoV.6.2
DocumentoPolítica 1
Elaborado porResponsável pela Conformidade
Data de aprovação24/09/2026
Responsável pela aprovaçãoResponsável pela Conformidade
Data de ratificação11/2026
Responsável pela ratificaçãoConselho de Administração da DVSP
Política ou normas alteradas / revogadasPolítica de Cumplimiento Penal v.6.1
Alterações nesta versãoInclusión expresa de TEAM 4 COLLECTION AND CONSULTING, S.L.U. en el alcance de la política.
Data da última atualização24/09/2026

Histórico de versões

Versão Motivo da alteração Responsável Data de aprovação Data de ratificação
1.0 Versão inicial 18/09/2018 20/09/2018 NA
Comité Cumplimiento Consejo Altamira Asset Management NA
2.0 Versão 2 15/01/2019 16/01/2019 NA
Comité Cumplimiento Consejo Altamira Asset Management NA
3.0 Versión 3 (Introducción de cambios en el ámbito de aplicación) Conformidade regulamentar 07/10/2020 NA
Comité Control NA
4.0 Versión 4 (Cambio de denominación social y actualización de nuevas políticas y procedimientos) Conformidade regulamentar 07/10/2020 NA
Comité Control NA
5.0 Versión 5 (Cambio en la referencia al Modelo de Cumplimiento por Marco de Cumplimiento e incorporación de un párrafo en el punto 5) Conformidade regulamentar 10/03/2025 NA
Comité Control NA
6.0 Atualização integral da Política para a sua harmonização com a norma UNE 19601, adaptação ao Sistema Integrado de Gestão, revisão do âmbito de aplicação, atualização da governação do sistema de conformidade penal e adaptação à Política do Sistema Interno de Informação Responsável pela Conformidade 31/07/2026 NA
Responsável pela Conformidade NA
6.1 Atualização da secção de controlo de versões com correção de erros ortográficos Responsável pela Conformidade 04/08/2026 09/2026
Responsável pela Conformidade Consejo Administración DVSP
6.2 Inclusión expresa de TEAM 4 COLLECTION AND CONSULTING, S.L.U. en el alcance de la política Responsável pela Conformidade 24/09/2026 11/2026
Responsável pela Conformidade Consejo Administración DVSP

2Introdução

Mediante la presente Política de Cumplimiento Penal de DOVALUE SPAIN SERVICING, S.A.U. (en adelante, "doValue" o "DVSP" o "DOVALUE") y sus filiales incluidas en el alcance del SIG y, en concreto, su filial en España, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (en adelante, "Team4" o "T4"), manifiestan su compromiso con el desarrollo de una cultura de cumplimiento, integridad y ética empresarial que inspire la actuación de todos los integrantes de la Organización y de aquellas personas que actúen en su nombre o representación.

A los efectos de la presente Política, se entenderá por "la Organización" o "la Compañía" el conjunto formado por doValue y por las demás sociedades que se encuentren incluidas en el alcance del Sistema. A la fecha de aprobación de la presente Política, dicho perímetro está integrado por doValue Spain Servicing, S.A.U. y Team 4 Collection and Consulting, S.L.U. Cualquier referencia en la presente Política a "las filiales" o "sus filiales" se entenderá realizada exclusivamente a las sociedades filiales de doValue incluidas en el alcance del Sistema.

El cumplimiento normativo y la prevención de delitos constituyen elementos esenciales del modelo de gobierno y control de la Organización. En este sentido, la Organización ha implantado su propio Sistema Integrado de Gestión (en adelante, SIG o Sistema), que incorpora los principios, controles y mecanismos necesarios para prevenir, detectar y gestionar los riesgos penales derivados de sus actividades, alineándose con la normativa vigente en materia de responsabilidad penal de las personas jurídicas, así como con los requisitos de la Norma UNE 19601: Sistemas de Gestión de Compliance Penal.

La Dirección y el Consejo de Administración de la Organización asumen un compromiso expreso con la promoción de una cultura de cumplimiento basada en el respeto a la legalidad, la tolerancia cero frente a la comisión de ilícitos y la mejora continua de los sistemas de control interno.

La Organización ha logrado una posición de liderazgo y referencia en el mercado. Para ello ha sido y es fundamental el comportamiento ético y responsable de los miembros del órgano de administración, directivos, empleados, colaboradores y demás personas sujetas a la presente Política (en adelante, el "Personal"), persiguiendo la implantación de un SIG robusto y promoviendo una cultura de cumplimiento en toda la organización. Por ello, esta Política de Cumplimiento Penal constituye el marco de referencia del Sistema, que es conocido y de obligado cumplimiento por todo el Personal e impulsado por la Dirección.

3Âmbito de aplicação

La presente Política es de aplicación a los miembros del órgano de administración, directivos, empleados, trabajadores cedidos, becarios, personal en formación y, en general, a todas las personas que desarrollen su actividad profesional para doValue y sus filiales, con independencia de la naturaleza, duración o modalidad de su relación con la Organización.

Asimismo, esta Política resulta de aplicación a aquellas personas físicas o jurídicas que actúen en nombre o en representación de doValue y/o sus filiales, así como a quienes ejerzan funciones de administración, dirección, gestión, supervisión o control dentro de la Organización o de las entidades que formen parte de su grupo.

A Organização promoverá igualmente o conhecimento e o cumprimento dos princípios contidos na presente Política por parte dos seus parceiros de negócio, fornecedores, contratados, colaboradores externos, consultores e outros terceiros com quem mantenha relações profissionais ou comerciais, sempre que tal seja aplicável de acordo com a legislação em vigor, das obrigações contratuais assumidas ou dos sistemas internos de controlo e conformidade da Organização.

4Finalidade e objetivos

A presente Política de Conformidade Penal tem como objetivo promover e consolidar uma cultura de conformidade, integridade e comportamento ético no seio da doValue e das suas filiais, reforçando o compromisso da Organização com a prevenção, deteção e gestão dos riscos penais decorrentes do exercício da sua atividade.

Asimismo, esta Política manifiesta el compromiso de tolerancia cero frente a la comisión de cualquier conducta ilícita o contraria a la normativa aplicable, al Código Ético o a los principios que inspiran el Sistema Integrado de Gestión, sin que en ningún caso la obtención de un beneficio económico, operativo o estratégico pueda justificar un incumplimiento normativo.

Para alcançar essa finalidade, a presente Política visa os seguintes objetivos:

  • Estabelecer os princípios gerais que regem o Sistema Integrado de Gestão da Conformidade Penal da Organização.
  • Promover uma atuação profissional diligente, íntegra e respeitadora da legalidade por parte de todas as pessoas abrangidas pela presente Política.
  • Promover a prevenção, a deteção precoce e a gestão adequada dos riscos penais.
  • Facilitar o conhecimento das obrigações, responsabilidades, controlos e procedimentos que constituem o Sistema Integrado de Gestão da Conformidade Penal.
  • Reforçar a cultura de comunicação e consulta em caso de dúvidas ou possíveis incumprimentos, incentivando a utilização dos canais disponibilizados pela Organização.
  • Contribuir a la mejora continua del Sistema Integrado de Gestión de Compliance Penal y a la protección de la reputación, sostenibilidad y buen gobierno de la Organización.

5 Princípios gerais de atuação

O Sistema Integrado de Gestão da doValue e das suas filiais inspira-se nos seguintes princípios gerais, que constituem a base fundamental, tanto da regulamentação interna da doValue e das suas filiais, como da atuação do Pessoal:

Tolerância zero face à prática de crimes

A doValue e as suas filiais proíbem todas as pessoas referidas no n.º 3 da presente Política de cometerem atos criminosos e obrigam-nas a comunicar esses atos ou qualquer outro comportamento suspeito suscetível de constituir uma infração penal através dos canais estabelecidos para o efeito.

Prevenção e gestão de riscos penais

Para o efeito, e tendo em conta a natureza da atividade da doValue e das suas filiais — centrada na gestão e consultoria de carteiras de ativos financeiros (incluindo NPLs e REOs), na recuperação e gestão de crédito e na gestão e comercialização de ativos imobiliários —, identificam-se como áreas de especial atenção as seguintes: a gestão e negociação com devedores e terceiros em processos de cobrança; a contratação e relação com fornecedores, intermediários e parceiros de negócio; a avaliação, aquisição e alienação de ativos financeiros e imobiliários; ou a gestão de informação confidencial e de dados de caráter pessoal. Essas atividades são objeto de análise e avaliação periódica de riscos penais no âmbito do Sistema Integrado de Gestão, cujos resultados são registados no respetivo mapa de riscos penais. Tudo isto em conformidade com as normas, princípios, valores e objetivos estabelecidos em matéria de conformidade penal e com o objetivo de minimizar a exposição da doValue e das suas filiais aos riscos penais.

Compromisso com a legalidade

La Organización, y especialmente su Consejo de Administración y la Dirección, se comprometen a cumplir con la normativa penal vigente que resulte de aplicación, así como con los requisitos establecidos en el Sistema Integrado de Gestión de Compliance Penal y Calidad. A tal efecto, actuarán y exigirán que se actúe en todo momento conforme a lo dispuesto en dicha normativa y en el Sistema, y que en todo caso se cumpla con los requisitos de esta Política.

Dever de comunicação

La Organización promueve el deber de comunicar, a través del Sistema Interno de Información (SII), cualquier conducta irregular o potencial incumplimiento de la normativa aplicable o de la normativa interna de la Organización del que se tenga conocimiento o sospecha razonable. La Organización garantiza la confidencialidad de las comunicaciones, la protección de la identidad del informante y la prohibición de represalias o conductas perjudiciales en los términos previstos en la normativa aplicable y en la Política del Sistema Interno de Información.

Regime disciplinar

doValue y sus filiales difunden entre todo el Personal el régimen disciplinario aplicable en caso de incumplimiento del Sistema Integrado de Gestión o de la normativa interna de aplicación, o en el supuesto de comisión de hechos o conductas que pudieran ser calificadas de delictivas, en virtud de lo establecido en los convenios colectivos de aplicación.

Quadro para a concretização de objetivos

A doValue e as suas filiais estabelecem, supervisionam e revêem periodicamente os objetivos do Sistema Integrado de Gestão de Conformidade Penal, assegurando a sua adequação aos riscos penais identificados e à estratégia da organização. Para o efeito, dotam-se dos recursos financeiros, humanos e tecnológicos necessários para a sua adequada concretização e acompanhamento.

Divulgação e acesso

O Sistema é divulgado de forma adequada e contínua a todo o pessoal. Além disso, os princípios e normas que o compõem estarão à disposição de todos os membros da organização. Esta Política é disponibilizada a todas as partes interessadas através dos canais internos de comunicação e do site corporativo.

Órgão de Conformidade Penal

A função de conformidade penal, exercida pelo Responsável pela Conformidade, encarrega-se de supervisionar, gerir e manter atualizado o Sistema Integrado de Gestão, velando pela sua eficácia. Esta função é desempenhada com autonomia e independência, e com plenas competências e autoridade para o exercício das suas atribuições. O Responsável pela Conformidade reporta diretamente ao Conselho de Administração, informando-o periodicamente sobre o estado do Sistema, e dispõe de acesso direto ao mesmo, independentemente da linha hierárquica, quando as circunstâncias assim o exigirem. Esta estrutura de reporte garante a sua independência funcional em relação às áreas de negócio e a qualquer órgão ou pessoa sujeita à sua supervisão.

Melhoria contínua

O Sistema Integrado de Gestão é objeto de revisão periódica e melhoria contínua, informando o Órgão de Direção e o Órgão de Governo (Conselho de Administração), de forma recorrente, sobre as suas atividades de supervisão e acompanhamento, sobre as alterações estruturais e normativas que possam ter ocorrido, bem como sobre as medições do desempenho em matéria de conformidade penal e os resultados da sua avaliação.

6. Normas que definem o quadro de conformidade penal

A doValue e as suas filiais dispõem de um conjunto de normas fundamentais, aplicáveis a todo o pessoal, nas quais se baseia e se desenvolve o Sistema Integrado de Gestão:

  • Código de Ética: constitui o quadro de referência e orientação de caráter geral para o desenvolvimento das atividades da doValue e das suas filiais. Este documento contém, com base nos princípios empresariais da doValue e das suas filiais, os princípios éticos que devem reger o comportamento de todos os colaboradores. O conhecimento deste documento é obrigatório para todos os membros e colaboradores externos da doValue e das suas filiais.
  • Manual do Sistema Integrado de Gestão: estabelece as diretrizes de atuação da doValue e das suas filiais para assegurar o exercício do controlo adequado e do dever de vigilância sobre a sua atividade empresarial, cumprindo assim os requisitos legais do Código Penal espanhol e os deveres de controlo de riscos impostos pela Lei das Sociedades de Capital (RD 1/2010).
  • Política do Sistema Interno de Informação: a doValue e as suas filiais disponibilizam um Canal de Comunicação ou Canal Ético, através do qual os colaboradores ou terceiros que tenham relação com a doValue e as suas filiais podem comunicar infrações ou suspeitas relacionadas com o incumprimento da legislação no âmbito da atividade empresarial da doValue e das suas filiais. Desta forma, reforça-se a transparência e o controlo do cumprimento correto das leis e do Código de Ética.
  • Procedimento Corporativo de Gestão do Sistema Interno de Informação: estabelece as diretrizes de atuação para os casos em que se verifique que, no seio da doValue e das suas filiais, estão a ser cometidos atos potencialmente constitutivos de infrações ao direito da União Europeia, ou de infrações penais ou administrativas graves ou muito graves.
  • Política Global de Conflitos de Interesses e Operações Relacionadas: estabelece o compromisso da doValue e das suas filiais de implementar as medidas e políticas globais que permitam identificar os potenciais conflitos de interesses que possam surgir no âmbito da prestação de serviços.
  • Política de Presentes: estabelece a proibição expressa de oferecer ou receber qualquer tipo de presente ou comissão financeira com a intenção de obter qualquer tipo de vantagem que beneficie a organização.
  • Política Anticorrupção: reflete o compromisso da doValue e das suas filiais com a tolerância zero face a qualquer forma de corrupção, tanto no setor público como no privado, incluindo o suborno, o peculato, o tráfico de influências e qualquer outra prática corrupta.
  • Formación en materia de compliance y prevención de riesgos penales: se establece anualmente un plan de formación, comunicación, sensibilización y difusión donde se detallan los aspectos prácticos sobre la prevención de delitos para que todos los miembros de doValue y sus filiales sean conocedores de sus derechos y obligaciones en relación al compliance penal.
  • Regime disciplinar: o qual será aplicável em caso de incumprimento do Sistema Integrado de Gestão ou da regulamentação interna aplicável, bem como nos casos de prática de atos ou condutas irregulares, de acordo com o regime de infrações e sanções previsto nos Convenções Coletivas aplicáveis à doValue e às suas filiais, no Estatuto dos Trabalhadores e em quaisquer outras normas laborais ou internas que sejam aplicáveis. Nos casos em que os factos possam constituir infração penal, a doValue e as suas filiais poderão proceder à sua comunicação às autoridades competentes, sem prejuízo dos casos em que tal comunicação seja legalmente obrigatória. As consequências do regime disciplinar serão aplicáveis a todo o Pessoal sujeito à presente Política, independentemente do seu cargo ou nível hierárquico, incluindo administradores e dirigentes, de acordo com a legislação laboral, comercial ou contratual aplicável em cada caso. Tudo isto sem prejuízo do disposto no n.º 8 da presente Política.

7. Compromisso do Conselho de Administração e do Órgão de Direção

Os Conselhos de Administração e os Órgãos de Direção da doValue e das suas filiais reafirmam, através da presente Política, o seu compromisso com a ética, a integridade, o cumprimento normativo e a prevenção de crimes, promovendo uma cultura de conformidade que faça parte dos valores e da atividade quotidiana da Organização.

El Consejo de Administración, como órgano de gobierno de la Organización, asume un liderazgo visible, activo y efectivo en relación con el Sistema Integrado de Gestión de Compliance Penal, impulsando su implantación, supervisando su funcionamiento y promoviendo su mejora continua. Asimismo, aprueba la presente Política y vela por que el Sistema disponga de los recursos humanos, tecnológicos y financieros necesarios para alcanzar sus objetivos.

Por seu lado, o Órgão de Direção é responsável por promover a aplicação efetiva dos princípios e requisitos estabelecidos no Sistema Integrado de Gestão, incentivando comportamentos coerentes com a cultura de conformidade e integrando os objetivos de conformidade penal na gestão corrente da Organização.

O Conselho de Administração e o Órgão de Direção apoiam expressamente o exercício independente da função de Conformidade Penal, confiada ao Responsável pela Conformidade, garantindo a sua autonomia, autoridade, acesso à informação necessária ao desempenho das suas funções e acesso direto aos órgãos de governo sempre que as circunstâncias assim o exijam.

Asimismo, ambos órganos promueven la comunicación, difusión y conocimiento de esta Política, así como del resto de elementos que integran el Sistema Integrado de Gestión de Compliance Penal, impulsando la formación, sensibilización y concienciación de todas las personas sujetas a la misma.

8Comunicação de irregularidades

Todas as pessoas abrangidas pela presente Política têm a obrigação de comunicar qualquer incumprimento ou suspeita razoável de incumprimento da regulamentação aplicável, do Código de Ética, da presente Política ou das restantes normas que integram o Sistema Integrado de Gestão, de que tenham conhecimento no exercício das suas atividades profissionais.

Para o efeito, a Organização dispõe de um Sistema Interno de Informação (SII) gerido em conformidade com a Política do Sistema Interno de Informação e o Procedimento Corporativo de Gestão do Sistema Interno de Informação, garantindo a confidencialidade da informação comunicada, a proteção da identidade do denunciante e a proibição de retaliações nos termos previstos na legislação aplicável.

O Sistema Interno de Informação é supervisionado pela Comissão do Sistema Interno de Informação (CSII), nomeada pelo Conselho de Administração como Responsável pelo Sistema.

As comunicações poderão ser efetuadas através dos canais disponibilizados pela Organização, acessíveis através das seguintes ligações:

Todo lo relativo al funcionamiento del Sistema Interno de Información, las modalidades de comunicación, las garantías aplicables a los informantes, personas afectadas y terceros relacionados, así como la tramitación de las comunicaciones recibidas, se regula en la Política del Sistema Interno de Información y en el Procedimiento de Gestión del Sistema Interno de Información.

9Casos de incumprimento da Política de Conformidade Penal

O cumprimento da presente Política é da responsabilidade de todas as pessoas abrangidas pelo seu âmbito de aplicação. Além disso, o Conselho de Administração, o Órgão de Direção e as pessoas que exercem funções de direção ou supervisão na Organização devem promover ativamente o seu conhecimento, aplicação e cumprimento nos respetivos âmbitos de responsabilidade.

Sin perjuicio de lo anterior, corresponde al Compliance Officer, en el ejercicio de la función de Compliance Penal, supervisar la adecuada implantación, mantenimiento y eficacia del Sistema Integrado de Gestión de Compliance Penal, así como informar de su funcionamiento a los órganos de gobierno y dirección de la Organización.

El incumplimiento de lo dispuesto en la presente Política podrá dar lugar a la adopción de las medidas disciplinarias, contractuales o legales que resulten procedentes en cada caso, de conformidad con la normativa vigente, los convenios colectivos aplicables, la normativa interna de la Organización y las obligaciones contractuales asumidas.

A aplicação dessas medidas será feita tendo em conta a natureza e a gravidade dos factos, garantindo, em todos os casos, os direitos das pessoas afetadas e o respeito pelos procedimentos legalmente estabelecidos.

10. Publicação e entrada em vigor

La presente Política forma parte del Sistema de Gestión del Compliance Penal de doValue y constituye información documentada del mismo. La Política será objeto de revisión periódica y mejora continua, con el fin de garantizar su adecuación a la normativa aplicable, a la evolución de los riesgos penales de la Organización, a los cambios organizativos que puedan producirse y a las necesidades derivadas del funcionamiento del Sistema Integrado de Gestión.

Além disso, a presente Política será disponibilizada às partes interessadas através do site corporativo da doValue, dos sites das suas filiais e de quaisquer outros meios que a Organização considere adequados para garantir a sua divulgação e acessibilidade.

A presente Política entrará em vigor na doValue e nas suas filiais na data da sua aprovação pelo órgão competente, permanecendo em vigor até ser substituída, alterada ou revogada por uma nova versão.

1Version control

CompanydoValue Spain Servicing, S.A.U.
TitleCriminal Compliance Policy
VersionV.6.2
DocumentPolicy 1
Prepared byCompliance Officer
Approval Date24/09/2026
Person responsible for approvalCompliance Officer
Ratification date11/2026
Person responsible for ratificationBoard of Directors of DVSP
Policy or rules amended / repealedCriminal Compliance Policy v.6.1
Amendments to the versionExpress inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy.
Date of last update24/09/2026

Version history

Version Reason for the Change Owner Approval date Ratification date
1.0 Initial Version 18/09/2018 20/09/2018 NA
Compliance Committee Altamira Asset Management Board NA
2.0 Version 2 15/01/2019 16/01/2019 NA
Compliance Committee Altamira Asset Management Board NA
3.0 Version 3 (Introduction of changes to the scope of application) Regulatory Compliance 07/10/2020 NA
Control Committee NA
4.0 Version 4 (Change of corporate name and update of new policies and procedures) Regulatory Compliance 07/10/2020 NA
Control Committee NA
5.0 Version 5 (Change of the reference to the Compliance Model to Compliance Framework and addition of a paragraph in point 5) Regulatory Compliance 10/03/2025 NA
Control Committee NA
6.0 Comprehensive update of the Policy to align it with UNE 19601, adapt it to the Integrated Management System, review the scope of application, update the governance of the criminal compliance system and align it with the Internal Information System Policy Compliance Officer 31/07/2026 NA
Compliance Officer NA
6.1 Update of the version control section with correction of typos Compliance Officer 04/08/2026 09/2026
Compliance Officer DVSP Board of Directors
6.2 Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy Compliance Officer 24/09/2026 11/2026
Compliance Officer DVSP Board of Directors

2Introduction

By means of this Criminal Compliance Policy of DOVALUE SPAIN SERVICING, S.A.U. (hereinafter, "doValue" or "DVSP" or "DOVALUE") and its subsidiaries included in the scope of the IMS and, specifically, its subsidiary in Spain, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (hereinafter, "Team4" or "T4") express their commitment to the development of a culture of compliance, integrity and business ethics that inspires the conduct of all members of the Organisation and of those persons acting in its name or on its behalf.

For the purposes of this Policy, "the Organisation" or "the Company" shall mean doValue together with the other companies included in the scope of the System. As at the date of approval of this Policy, that perimeter comprises doValue Spain Servicing, S.A.U. and Team 4 Collection and Consulting, S.L.U. Any reference in this Policy to "the subsidiaries" or "its subsidiaries" shall be understood to refer exclusively to the subsidiaries of doValue included in the scope of the System.

Regulatory compliance and the prevention of offences are essential elements of the governance and control model of the Organisation. In this regard, the Organisation has implemented its own Integrated Management System (hereinafter, the IMS or the System), which incorporates the principles, controls and mechanisms necessary to prevent, detect and manage the criminal risks arising from its activities, in line with the legislation in force on the criminal liability of legal persons, as well as with the requirements of standard UNE 19601: Criminal Compliance Management Systems.

The Management and the Board of Directors of the Organisation assume an express commitment to promoting a culture of compliance based on respect for the law, zero tolerance of the commission of unlawful acts and the continual improvement of the internal control systems.

The Organisation has achieved a position of leadership and benchmark status in the market. To that end, the ethical and responsible conduct of the members of the administrative body, managers, employees, collaborators and other persons subject to this Policy (hereinafter, the "Personnel") has been and remains fundamental, pursuing the implementation of a robust IMS and promoting a culture of compliance throughout the organisation. For this reason, this Criminal Compliance Policy constitutes the frame of reference for the System, which is known to and mandatory for all Personnel and is driven by Management.

3Scope of application

This Policy applies to the members of the administrative body, managers, employees, assigned workers, interns, trainees and, in general, to all persons who carry out their professional activity for doValue and its subsidiaries, irrespective of the nature, duration or form of their relationship with the Organisation.

Likewise, this Policy applies to those natural or legal persons who act in the name of or on behalf of doValue and/or its subsidiaries, as well as to those who perform administration, management, supervision or control functions within the Organisation or within the entities forming part of its group.

The Organisation shall likewise promote awareness and observance of the principles contained in this Policy among its business partners, suppliers, contractors, external collaborators, advisers and other third parties with which it maintains professional or commercial relationships, where this is applicable in accordance with the legislation in force, the contractual obligations assumed or the internal control and compliance systems of the Organisation.

4Purpose and objectives

The purpose of this Criminal Compliance Policy is to promote and consolidate a culture of compliance, integrity and ethical conduct within doValue and its subsidiaries, reinforcing the commitment of the Organisation to the prevention, detection and management of the criminal risks arising from the performance of its activity.

Likewise, this Policy expresses the commitment to zero tolerance of the commission of any unlawful conduct or conduct contrary to the applicable legislation, to the Code of Ethics or to the principles underpinning the Integrated Management System, and in no case may the obtaining of an economic, operational or strategic benefit justify a regulatory breach.

In order to achieve that purpose, this Policy pursues the following objectives:

  • To establish the general principles governing the Criminal Compliance Integrated Management System of the Organisation.
  • To foster diligent, honest and law-abiding professional conduct on the part of all persons subject to this Policy.
  • To promote the prevention, early detection and proper management of criminal risks.
  • To facilitate awareness of the obligations, responsibilities, controls and procedures that make up the Criminal Compliance Integrated Management System.
  • To reinforce the culture of communication and consultation in the event of doubts or possible breaches, encouraging the use of the channels made available by the Organisation.
  • To contribute to the continual improvement of the Criminal Compliance Integrated Management System and to the protection of the reputation, sustainability and good governance of the Organisation.

5General principles of conduct

The Integrated Management System of doValue and its subsidiaries is based on the following general principles, which constitute the fundamental basis both of the internal regulations of doValue and its subsidiaries and of the conduct of the Personnel:

Zero tolerance of the commission of offences

doValue and its subsidiaries prohibit all persons covered by section 3 of this Policy from committing criminal acts and require them to report such acts, or any other suspicious conduct liable to constitute a criminal offence, through the channels established for those purposes.

Prevention and management of criminal risks

To this end, and having regard to the nature of the activity of doValue and its subsidiaries —focused on the management of and advisory services for portfolios of financial assets (including NPLs and REOs), credit recovery and management, and the management and marketing of real estate assets— the following are identified as areas requiring particular attention: the management of, and negotiation with, debtors and third parties in debt collection processes; the contracting of, and relationship with, suppliers, intermediaries and business partners; the valuation, acquisition and transfer of financial and real estate assets; and the management of confidential information and personal data. Those activities are subject to periodic criminal risk analysis and assessment within the framework of the Integrated Management System, the results of which are recorded in the corresponding criminal risk map. All of the foregoing is in line with the standards, principles, values and purposes established in the field of criminal compliance and with the objective of minimising the exposure of doValue and its subsidiaries to criminal risks.

Commitment to legality

The Organisation, and in particular its Board of Directors and Management, undertake to comply with the criminal legislation in force that is applicable, as well as with the requirements established in the Integrated Criminal Compliance and Quality Management System. To that end, they shall act, and shall require that action be taken, at all times in accordance with the provisions of that legislation and of the System, and that the requirements of this Policy be complied with in all cases.

Duty to report

The Organisation promotes the duty to report, through the Internal Information System (IIS), any irregular conduct or potential breach of the applicable legislation or of the internal regulations of the Organisation of which the person is aware or reasonably suspects. The Organisation guarantees the confidentiality of reports, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation and in the Internal Information System Policy.

Disciplinary regime

doValue and its subsidiaries disseminate among all Personnel the disciplinary regime applicable in the event of breach of the Integrated Management System or of the applicable internal regulations, or in the event of the commission of acts or conduct that may be classified as criminal, pursuant to the provisions of the applicable collective bargaining agreements.

Framework for the achievement of objectives

doValue and its subsidiaries establish, monitor and periodically review the objectives of the Criminal Compliance Integrated Management System, ensuring their alignment with the criminal risks identified and with the strategy of the organisation. To that end, they allocate the financial, human and technological resources necessary for their proper achievement and monitoring.

Dissemination and access

The System is disseminated properly and on an ongoing basis among all Personnel. Likewise, the principles and rules comprising it shall be made available to all members of the organisation. This Policy is made available to all interested parties through the internal communication channels and the corporate website.

Criminal Compliance Body

The criminal compliance function, performed by the Compliance Officer, is responsible for supervising, managing and keeping the Integrated Management System up to date, ensuring its effectiveness. This function is performed with autonomy and independence, and with full powers and authority for the exercise of its role. The Compliance Officer reports directly to the Board of Directors, informing it periodically of the status of the System, and has direct access to it, irrespective of the hierarchical line, where circumstances so require. This reporting structure guarantees its functional independence from the business areas and from any body or person subject to its supervision.

Continual improvement

The Integrated Management System is subject to periodic review and continual improvement, with the Management Body and the Governing Body (Board of Directors) being informed, on a recurring basis, of its supervision and monitoring activities, of the structural and regulatory changes that may have occurred, as well as of the criminal compliance performance measurements and the results of their evaluation.

6Rules that make up the criminal compliance framework

doValue and its subsidiaries have a series of fundamental rules, applicable to all Personnel, on which the Integrated Management System is structured and developed:

  • Code of Ethics: constitutes the general frame of reference and guidance for the conduct of the activities of doValue and its subsidiaries. Based on the business principles of doValue and its subsidiaries, it sets out the ethical principles that must govern the conduct of all employees. Knowledge of this document is mandatory for all members and external collaborators of doValue and its subsidiaries.
  • Manual of the Integrated Management System: establishes the guidelines for action of doValue and its subsidiaries in order to comply with the exercise of due control and the duty of oversight over their business activity, thereby complying with the legal requirements of the Spanish Criminal Code and with the risk control duties imposed by the Spanish Companies Act (Royal Legislative Decree 1/2010).
  • Internal Information System Policy: doValue and its subsidiaries make available a Reporting Channel or Ethics Channel, through which employees or third parties having a relationship with doValue and its subsidiaries may report breaches or suspicions concerning legal non-compliance within the business activity of doValue and its subsidiaries. This enhances transparency and the monitoring of proper compliance with the law and with the Code of Ethics.
  • Corporate Procedure for the Management of the Internal Information System: establishes the guidelines for action in those cases where it is established that, within doValue and its subsidiaries, conduct is being carried out that potentially constitutes breaches of European Union law, or serious or very serious criminal or administrative offences.
  • Global Policy on Conflicts of Interest and Related-Party Transactions: establishes the commitment of doValue and its subsidiaries to implement the global measures and policies enabling the identification of potential conflicts of interest that may arise in the provision of services.
  • Gifts Policy: establishes the express prohibition on making or receiving any type of gift or financial commission with the intention of obtaining any kind of advantage benefiting the organisation.
  • Anti-Corruption Policy: sets out the commitment of doValue and its subsidiaries to zero tolerance of any form of corruption, in both the public and the private sector, including bribery, corrupt payments, influence peddling and any other corrupt practice.
  • Training in compliance and the prevention of criminal risks: A training, communication, awareness and dissemination plan is established annually, setting out the practical aspects of the prevention of offences so that all members of doValue and its subsidiaries are aware of their rights and obligations in relation to criminal compliance.
  • Disciplinary regime: which shall apply in the event of breach of the Integrated Management System or of the applicable internal regulations, as well as in cases of the commission of irregular acts or conduct, in accordance with the regime of infringements and sanctions provided for in the Collective Bargaining Agreements applicable to doValue and its subsidiaries, in the Workers’ Statute and in any other applicable labour or internal rules. In cases where the acts may constitute a criminal offence, doValue and its subsidiaries may report them to the competent authorities, without prejudice to those cases in which such reporting is legally mandatory. The consequences of the disciplinary regime shall apply to all Personnel subject to this Policy, irrespective of their position or hierarchical level, including directors and senior managers, in accordance with the labour, commercial or contractual rules applicable in each case. All of the foregoing is without prejudice to the provisions of section 8 of this Policy.

7Commitment of the Board of Directors and of the Management Body

The Boards of Directors and the Management Bodies of doValue and its subsidiaries reaffirm, by means of this Policy, their commitment to ethics, integrity, regulatory compliance and the prevention of offences, promoting a culture of compliance that forms part of the values and of the day-to-day activity of the Organisation.

The Board of Directors, as the governing body of the Organisation, assumes visible, active and effective leadership in relation to the Criminal Compliance Integrated Management System, driving its implementation, supervising its operation and promoting its continual improvement. It also approves this Policy and ensures that the System has the human, technological and financial resources necessary to achieve its objectives.

For its part, the Management Body is responsible for promoting the effective application of the principles and requirements established in the Integrated Management System, fostering conduct consistent with the culture of compliance and integrating the criminal compliance objectives into the ordinary management of the Organisation.

The Board of Directors and the Management Body expressly support the independent exercise of the Criminal Compliance function, entrusted to the Compliance Officer, guaranteeing its autonomy, authority, access to the information necessary for the performance of its duties and direct access to the governing bodies where circumstances so require.

Likewise, both bodies promote the communication, dissemination and awareness of this Policy, as well as of the other elements comprising the Criminal Compliance Integrated Management System, driving the training, awareness-raising and engagement of all persons subject to it.

8Reporting of irregularities

All persons subject to this Policy are obliged to report any breach or reasonable suspicion of breach of the applicable legislation, of the Code of Ethics, of this Policy or of the other rules comprising the Integrated Management System of which they become aware in the course of their professional activities.

To this end, the Organisation has an Internal Information System (IIS) managed in accordance with the Internal Information System Policy and the Corporate Procedure for the Management of the Internal Information System, guaranteeing the confidentiality of the information reported, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation.

The Internal Information System is supervised by the Internal Information System Committee (IISC), appointed by the Board of Directors as the Person Responsible for the System.

Reports may be made through the channels made available by the Organisation, accessible via the following links:

All matters relating to the operation of the Internal Information System, the methods of reporting, the safeguards applicable to reporting persons, persons concerned and related third parties, as well as the handling of the reports received, are governed by the Internal Information System Policy and the Procedure for the Management of the Internal Information System.

9Breaches of the Criminal Compliance Policy

Compliance with this Policy is the responsibility of all persons within its scope of application. Likewise, the Board of Directors, the Management Body and the persons performing management or supervisory functions in the Organisation shall actively promote awareness, application and compliance within their respective areas of responsibility.

Notwithstanding the foregoing, it is incumbent on the Compliance Officer, in the exercise of the Criminal Compliance function, to supervise the proper implementation, maintenance and effectiveness of the Criminal Compliance Integrated Management System, as well as to report on its operation to the governing and management bodies of the Organisation.

Breach of the provisions of this Policy may give rise to the adoption of such disciplinary, contractual or legal measures as may be appropriate in each case, in accordance with the legislation in force, the applicable collective bargaining agreements, the internal regulations of the Organisation and the contractual obligations assumed.

The application of such measures shall be carried out having regard to the nature and seriousness of the acts, guaranteeing in all cases the rights of the persons concerned and respect for the legally established procedures.

10Publication and entry into force

This Policy forms part of the Criminal Compliance Management System of doValue and constitutes documented information thereof. The Policy shall be subject to periodic review and continual improvement, in order to ensure its adequacy to the applicable legislation, to the evolution of the criminal risks of the Organisation, to the organisational changes that may occur and to the needs arising from the operation of the Integrated Management System.

Likewise, this Policy shall be made available to interested parties through the corporate website of doValue, the websites of its subsidiaries and such other means as the Organisation considers appropriate to ensure its dissemination and accessibility.

This Policy shall enter into force at doValue and its subsidiaries on the date of its approval by the relevant competent body, and shall remain in force until it is replaced, amended or repealed by a new version.