SUSTAINABILITY REPORT 2024

For several years, PRT has established a Privacy and Cybersecurity Office, dedicated to managing information security and the Company’s IT systems. This office consists of four highly specialised professionals responsible for assessing and implementing the actions required to ensure the efficiency and security of technological infrastructure. CIO (Chief Information Officer) Head of the IT Department. Ensures that the Company’s technological infrastructure is efficient, secure and able to support the organisation’s strategic objectives. Key areas of responsibility include: IT strategy, IT resource management, technological innovation, cybersecurity, IT budget, IT project management (Infrastructure, Development and Production), and coordination with other departments. CISO (Chief Information Security Officer) Head of information security. Responsible for protecting the integrity, confidentiality and availability of the Company’s information, as well as ensuring that the organisation is prepared to address cyber threats. Key areas of responsibility include: security strategy, risk management, security policies, incident response, awareness and training, security monitoring, regulatory compliance, and coordination with other departments. DPO (Data Protection Officer) Role responsible for overseeing the management of personal data processing and its protection within the Company, in compliance with the GDPR Regulation. The DPO’s responsibilities include verifying that data is stored appropriately and that risks are managed in line with the requirements set out in the European Regulation. System Administrator Responsible for the management, configuration, maintenance and support of the organisation’s IT systems, reporting to the CIO. Ensures that the IT infrastructure is reliable, secure and able to support day-today business operations. Key areas of responsibility include: server and network management, system maintenance and security, technical support, system monitoring, backup and recovery, documentation management, and user management. Sustainability Report 2024 Page 53 2.3.2. The governance structure for Privacy and Cybersecurity management

RkJQdWJsaXNoZXIy NDUyNTU=