PRIVACY POLICY

Iberdrola, S.A. has developed a tool to manage its relations with suppliers interested in participating in a bidding process for the award of contracts with Iberdrola S.A., or any of the companies of the Iberdrola Group in accordance with mercantile legislation. This tool (hereinafter, indistinctly, the "Portal" or the "Register of Potential Suppliers and Suppliers" or "Register") is managed by Iberdrola S.A. and the information that is contained at any time on the occasion of its interlocution with third parties (interested suppliers, approved suppliers and contracted suppliers) is accessible to all these companies, some of which are outside the European Economic Area. The list of these companies can be accessed through https://www.iberdrola.com/documents/20125/42388/IB_Annual_Financial_Information.pdf [PDF] External link, opens in new window. Therefore, for the purposes of the regulations on personal data protection, we inform you that any information about suppliers or potential suppliers obtained as a result of a request for registration in the Portal or any preliminary treatment or initiative with Iberdrola S.A. or any of the companies of the Iberdrola Group to qualify as a supplier, involves the incorporation of such information in the Portal and its subsequent access and knowledge by any of the expressed companies belonging to the Iberdrola Group.

Iberdrola, S.A. and the companies that form part of the Iberdrola Group accordance with mercantile legislation (hereinafter, any of them, "Iberdrola") are committed to protect your privacy and guarantee compliance with the legislation on the protection of personal data and, in particular the General Data Protection Regulations ("GDPR") and the Organic Law on the Protection of Personal Data and guarantee of digital rights ("LOPDGDD"). Your personal data will be processed in a lawful, loyal and transparent manner; in accordance with specific explicit and legitimate purposes; only if it is adequate, relevant and limited to what is necessary in relation to the processing. In addition, we will keep your data accurate and up to date, retaining it in a form that allows your identification only for as long as necessary to fulfill the purposes of the processing.

Iberdrola has implemented the necessary technical and organizational measures to protect your data from accidental loss or unauthorized alteration, access, use or disclosure, and has also established procedures to react to any security incident that could affect your personal data.

By means of this Privacy Policy we inform you about the way in which your personal data will be treated during the process for its inclusion in the Register of Potential Suppliers and Suppliers of Iberdrola and during your stay in it.

In the case of updating this privacy notice we will notify you in writing in due course.

In the event that, as a consequence of your registration in the Register of Potential Suppliers and Suppliers of Iberdrola, you provide us with data from third parties, such as names, positions and contact details of your employees, administrators, shareholders or representatives, you must, prior to providing us with said data, inform said third parties of the treatment thereof in the terms set out in this Privacy Policy.

Who is responsible for the processing of your personal data?

IBERDROLA, S.A.
Plaza Euskadi 5, Bilbao

Iberdrola, S.A., has appointed a Data Protection Officer to facilitate compliance with the obligations of the GDPR and the LOPDGDD to whom it may address in relation to any matter relating to this Privacy Policy:

- By post to the following address: C/ Tomás Redondo 1, 28033 Madrid
- By e-mail, sent to dpo@iberdrola.com

Likewise, any of the companies of the Iberdrola Group is or may become responsible for the processing of the data to the extent that (i) the information incorporated in the Portal of Suppliers and Potential Suppliers is produced through the same or (ii) said companies access the content of the Portal.

What personal data do we collect and process from you?

The personal data that we may treat of you are your name and surname, postal and/or electronic address, telephone, NIF or passport, annual financial statements and activity or business. Likewise, Iberdrola, in the context of its rules and procedures for compliance and risk control and management may obtain information from third parties (such as news services) regarding potential suppliers and their representatives, representatives or contact persons.

How do we collect your personal data?

You provide us with your personal data through your registration in the Register of Potential Suppliers and Suppliers of Iberdrola, filing the form provided for this purpose and, additionally, Iberdrola may obtain other information from third parties in the terms indicated in the previous section.

If you do not provide us with your requested personal data, we may not be able to qualify you as an Iberdrola supplier.

In order to fulfil the purposes described below, please update your personal data as they change and always provide accurate information, as we must have your current information.

For what purposes do we process your data?

The information requested will be that necessary to fulfill the following purposes:

a) Participation in the qualification process as a potential supplier of the Iberdrola Group, in the context of its Compliance rules and procedures.

b) Invitation to participate in tenders for the award of contracts with companies of the Iberdrola Group.

c) Internal management of potential suppliers.

d) Elaboration of surveys and internal statistics and reports.

e) Sending of communications related to sustainability, ethics and compliance.

In relation to the purpose indicated in section a), we can make analysis of possible conflicts of interest and analysis of solvency, anti-corruption, fraud or related risks. In relation to risk analysis, it is reported that in order to carry out said analysis it is possible that personal data of individuals (representatives, directors or shareholders) linked to the supplier company of the Iberdrola Group company legitimately obtained from public registers or some companies as o de algunas empresas como Refinitiv https://www.refinitiv.com/en/products/world-check-kyc-screening/privacy-statement External link, opens in new window., Dow Jones https://djlogin.dowjones.com/privacy/default.aspx?fcpil=en External link, opens in new window. o Informa may be used. You agree to inform such persons in accordance with these privacy notices and to indemnify the Iberdrola Group company with which you have a contractual relationship from any damages that may result from failure to comply with this obligation.

What is the legitimacy for the processing of your data?

The legal basis for the processing of your data for the purposes a) and b), if the data corresponds to contact persons, administrators, agents or representatives of a potential legal entity, is the legitimate interest of Iberdrola to check whether such potential supplier meets the requirements to be registered as a supplier of Iberdrola and, if so, to include it in the Register. If the data belong to a potential natural person provider, the legitimate basis for the processing of your data for these purposes will be your application to register as a supplier of Iberdrola and your eventual registration in the Register.

The legal basis for the processing of your data for purposes c), d) and e) is the legitimate interest of Iberdrola in, respectively, (i) maintaining a record of potential suppliers who have applied to become Iberdrola suppliers and the result of their qualification process, (ii) improving its relationship with potential suppliers and obtaining statistics and producing reports on the subject and (iii) promoting awareness of sustainability, ethics and regulatory compliance.

How long do we keep your data?

If you pass the Iberdrola supplier qualification process, your personal data will be included in the Register of Suppliers and Potential Suppliers of Iberdrola for one year. After this period your data will be cancelled, unless you renew the application.

If Iberdrola does not pass the supplier qualification process, the personal data will be kept, duly blocked, for a period of three years, in order to attend to the eventual responsibilities derived from its treatment.

To whom will your information be communicated?

Your data may be communicated to the companies of the Iberdrola Group that are interested in hiring you. These Iberdrola Group companies are listed on the corporate website https://www.iberdrola.com/wcorp/gc/prod/es_ES/corporativos/docs/IB_Informe_Financiero_Anual.pdf [PDF] External link, opens in new window.

In this context, in the event that communication of your personal data occurs to Iberdrola Group companies located outside the European Economic Area other than those in which there is no legal framework on protection of personal data similar to that established in the European Union, Iberdrola will ensure that such communication is made in accordance with the GDPR, i.e. through any of the mechanisms enabled by the European text for these cases. Consequently, Iberdrola will ensure that it has the appropriate measures to protect your data in the country and destination organization in identical or similar terms to those provided for in European and Spanish law.

In any case, these data communications will be carried out with the appropriate legal basis (for example, attending your request for registration in the Register of Suppliers and Potential Suppliers of Iberdrola to be invited to participate in tenders for the award of contracts with companies of the Iberdrola Group) and respecting the principles of legality, loyalty, transparency and limitation of purpose, among others. You may, at any time, contact Iberdrola to find out the specific guarantees that have been implemented for the adequate and appropriate protection of your personal data, as well as the fact that they have been adopted.

Likewise, your data may be accessible by external service providers, such as computer services, with which we have signed the contracts required by the GDPR and the LOPDGDD, under which they guarantee compliance with their obligations as data processors.

What are your rights?

You have the right to access your personal data subject to processing, as well as to request the rectification of inaccurate data or, where appropriate, to request its deletion when the data are no longer necessary for the purposes for which they were collected, in addition to exercising the right to oppose and limit the processing and portability of the data. If you have given your consent, you have the right to revoke it at any time.

You may submit your requests for the exercise of your rights free of charge by sending an e-mail to desarrollosuministradores@iberdrola.es.

You may file a complaint with the Spanish Data Protection Agency or another equivalent supervisory authority.