Information Security and Electronic Evidence Policy
INDEX
- Purpose
- Scope
- Information security and electronic evidence principles
- Moove Cars commitments
- Risk management
- Electronic evidence management
- Compliance
- Review and update of this policy
1. Purpose
This Policy sets out the principles and commitments of MOOVE CARS MOBILITY SPAIN, S.L. regarding information security and electronic evidence management, within the framework of its Integrated Information Security and Electronic Evidence Management System.
It is defined in accordance with the requirements of the ISO/IEC 27001:2022 standard and the applicable requirements of the UNE 71505 standard, with the aim of protecting the information and electronic evidence associated with the processes included in the scope of the System.
2. Scope
This Policy applies to the people, areas, systems, applications, suppliers and third parties involved in the capture, processing, validation, modification, retention, consultation, extraction or provision of information and electronic evidence related to the working time recording and attendance control of drivers.
The scope covers the processes and systems related to working time recording and attendance control, as well as the management, processing, retention and protection of the associated electronic evidence.
3. Information security and electronic evidence principles
Moove Cars establishes the following as the basic principles of the Integrated System:
| PRINCIPLE | DESCRIPTION |
|---|---|
| Confidentiality | Information and evidence are only accessible to duly authorised persons, systems or third parties, according to their roles and access needs. |
| Integrity | Measures are established to preserve the integrity, accuracy and completeness of information and electronic evidence and to protect them against unauthorised or untraced modifications. Modifications, corrections or adjustments are subject to recording, traceability and justification mechanisms in accordance with the applicable procedures. |
| Availability | Moove Cars adopts measures aimed at ensuring that systems, information, records and electronic evidence are available when necessary in accordance with the applicable operational, legal, contractual and audit needs. |
| Traceability | Measures and controls are established to ensure the traceability of information and electronic evidence throughout their life cycle, in accordance with the applicable requirements. |
| Authenticity | Measures are applied to preserve the authenticity and reliability of electronic evidence and to enable it to be linked to its origin and to the corresponding events or processes. |
| Retention and custody | Information and electronic evidence are retained for the applicable periods and through appropriate security, access control, protection, availability and recovery measures. |
| Least privilege | Access to information, systems and electronic evidence is limited in accordance with the need-to-know and least privilege principles, based on the assigned roles and responsibilities. |
| Legal and contractual compliance | Information and evidence are managed in accordance with the applicable regulations on employment, personal data protection, information security and record retention, as well as contractual obligations. |
4. Moove Cars commitments
Moove Cars undertakes the following commitments:
- Protect the information associated with the working time recording and attendance control of drivers.
- Ensure that the electronic evidence used to prove facts related to working time is complete, traceable, available and reliable.
- Identify and manage the risks that may affect the confidentiality, integrity, availability, authenticity or traceability of the information included in the scope.
- Establish appropriate security controls over the systems, applications and suppliers involved in the process.
- Maintain an up-to-date inventory of information assets, source systems, electronic evidence and relevant suppliers.
- Regulate access according to the criteria of need, responsibility and least privilege.
- Record and manage information security incidents that may affect the data, systems or evidence included in the scope.
- Ensure the retention and recovery of electronic evidence for the applicable periods.
- Control modifications, validations or corrections of working time records, ensuring their traceability and justification.
- Train and raise awareness among the people involved in protecting information and in the proper management of electronic evidence.
- Periodically review the effectiveness of the system through indicators, internal audits, management review, monitoring of risks, nonconformities and corrective actions.
- Continuously improve the Integrated Information Security and Electronic Evidence Management System.
- All users of the systems included in the scope undertake to use the information, applications and electronic evidence appropriately, in accordance with this Policy and the applicable internal procedures.
5. Risk management
Moove Cars maintains a process for identifying, analysing, evaluating and treating the risks that may affect information security and the management of electronic evidence included in the scope.
Identified risks are treated through the application of organisational, technical, physical and people-related measures, taking into account their nature, likelihood and impact, as well as the applicable requirements.
Risk management is reviewed periodically and whenever relevant changes occur that may affect the System.
6. Electronic evidence management
Moove Cars establishes measures and controls aimed at ensuring that the electronic evidence included in the scope is managed appropriately and reliably throughout its entire life cycle.
The management of electronic evidence comprises the measures necessary to preserve its origin, authenticity, integrity, traceability, retention, availability and authorised access, in accordance with the applicable legal, regulatory, contractual and security requirements.
Likewise, mechanisms are established for its proper recovery and, where appropriate, for making it available to duly authorised third parties.
7. Compliance
Moove Cars promotes compliance with the applicable requirements regarding information security and electronic evidence management and establishes the supervision, review and improvement mechanisms necessary to maintain the effectiveness of the System.
8. Review and update of this policy
This Policy has been approved by the Corporate Management of Moove Cars and is available to relevant interested parties.
The Policy is reviewed periodically and updated when necessary as a result of relevant changes in the System, the risks, the applicable requirements or the context of the organisation.
The public version of this Policy will be kept up to date to reflect the current principles and commitments of Moove Cars regarding information security and electronic evidence management.
Last Updated: 6 October 2026