Information Security Policy
Introduction and scope
This policy applies to all professionals at ROUSAUD COSTAS DURAN SLP, ROUSAUD COSTAS DURAN ABOGADOS SLP, GESTART ASSESSORS SL, and DWF-RCD ANDALUCIA S.L.P.U. (hereinafter referred to individually as “RCD”).
RCD recognises that information and the systems that manage it are strategic assets that are essential for the proper performance of its professional activities. These assets include the technological infrastructure, storage media, software, documentation, and external services that support the functioning of the firm. Adequate protection of these assets is essential to ensure operational continuity, internal efficiency, and the trust of clients, collaborators, and other parties interested in the legal services provided by RCD.
This Information Security Policy establishes guidelines for the proper management, use, and safeguarding of these assets, with the aim of minimising risks and ensuring regulatory compliance.
Framework and principles
The Information Security Policy establishes a framework for protecting information and the systems that manage it, preventing unauthorised access, misuse, inappropriate disclosure, interruptions, unauthorised modifications, and destruction. It also reflects the commitment of the firm to protecting information and complying with the applicable regulations.
All the guidelines contained in this policy form part of the Information Security Management System (ISMS), which RCD maintains, reviews, and updates at least once a year. This system is designed to comply with the ISO 27001 standard and to guarantee the fundamental principles of confidentiality, integrity, and availability.
In addition, this Policy is published on the Intranet and forms part of the mandatory training (Onboarding) that all professionals must complete during their onboarding process.
Commitment of RCD
To ensure compliance with this policy, RCD shall:
- Implement and continuously improve the ISMS in accordance with ISO 27001 and applicable regulations.
- Guarantee that all professionals understand and apply information security policies, protecting the data of the firm.
- Ensure that collaborators and suppliers who access or manage information comply with established security requirements and are informed of the necessary guidelines.
- Clearly define the roles and responsibilities of the individuals or teams responsible for implementing and maintaining security measures.
- Apply appropriate security controls to protect information against risks and incidents, in accordance with the needs of the business and with regulatory requirements.
Responsibilities and monitoring
RCD professionals must comply with security policies, protect information assets, and immediately report any incidents. The person responsible for security and the Security Committee oversee the ISMS, ensure its effectiveness, and review the policy at least once a year, ensuring its proper dissemination throughout the organisation.
Security controls
RCD applies technical and organisational measures in areas such as access control, information classification, physical and logical security, vulnerability management, backups, business continuity and internal training, among other controls, in accordance with industry best practices.
Communication and contact
For any additional information about our Information Security Policy or suggestions in this regard, please send an email to: compliance@rcd.legal.


