Annual And Corporate Responsibility Report 2017

Data protection To complete its Cybersecurity Strategy, the Atresmedia Group has put in place an IT Security Model to comply with the Ley Orgánica de Protección de Datos , Spain’s Data Protection Act. The specification, construction and purpose of the model mean that it is relational, structured, parametrisable, scalable and capable of providing comprehensive solutions. It has its own organisational structure and is overseen by an IT security committee. In 2016, Regulation (EU) 2016/679, the General Data Protection Regulation, entered into force. It shall become applicable and replace the rules now prevailing on 25 May 2018. The Member States of the European Union and its institutions, companies and organisations must make their systems compliant before that deadline. Atresmedia is adapting its current IT Security Model so as to comply with the new regulatory requirements demanded by the RGPD. 6.5. Compliance system One of the control tools within Atresmedia’s GRC risk and control management system is the Compliance Model. The model must: • ensure compliance with all laws and regulations, whether specific to the sectors in which Atresmedia operates or generally applicable to listed companies and all businesses (employment, tax, environment, etc); • ensure compliance with the preventive requirements introduced by the recent reform of the Spanish Criminal Code as to the criminal liability of corporations; • set out procedures and approaches to prevent any offence contrary to the Criminal Code. • if a criminal offence were in the event committed, ensure that criminal liability does not attach to the corporation, or that such liability be attenuated by reason of appropriate control measures having been adopted. Atresmedia’s compliance function is the set of rules, stan- dards, procedures, IT tools and other technical and human resources the common purpose of which is that the Atres- media Group’s activities at all times comply with the law and remain consistent with the ethical principles that the Group itself has put in place to guide its business as a media group and as an enterprise. | 102 |  6. GOVERNANCE AND DECISION-MAKING PROCESSES ATRESMEDIA  |  ANNUAL AND CORPORATE RESPONSIBILITY REPORT 2017

RkJQdWJsaXNoZXIy OTI3MzU=