Whistleblowing
WHISTLEBLOWING: ORGANIZATIONAL ACT FOR THE MANAGEMENT OF REPORTS
See the Resolution approving the “Whistleblowing” Organizational Act to which this document applies.
1. PURPOSE
The purpose of this Organizational Act is to regulate, within Castel Monastero S.r.l., the practice of “whistleblowing”, understood as a system for reporting or denouncing unlawful conduct regulated by European Directive No. 193 of 23 October 2019.
The system provides for the reporting of alleged violations or threats to rights established under European Union law, carried out by workers (“whistleblowers” = reporting persons or their facilitators) who provide internal bodies, the Organization's supervisory bodies, or external supervisory Authorities with detailed information concerning actual or reasonably suspected facts of which they have become aware in the course of their employment relationship, which may be useful for initiating an investigation. Such practice is accompanied by protection measures for the reporting person.
In implementation of Directive (EU) 2019/1937, Legislative Decree No. 24 of 10 March 2023 was issued concerning the protection of persons who report breaches of Union law and national legislation.
These provisions do not concern disputes, claims or requests relating to a personal interest of the reporting person, or of the person who has filed a report with the judicial or accounting authorities, nor reports already regulated by European Union or national legislation.
2. DEFINITIONS
“Reports”: information, including reasonable grounds for suspicion, concerning violations that have already been committed or have not yet been committed (but which, on the basis of concrete evidence, could be committed), as well as conduct intended to conceal such violations (e.g. concealment or destruction of evidence).
Such reports must concern conduct, acts or omissions of which the reporting person or complainant has become aware in the context of public- or private-sector employment.
Within public- and private-sector entities, reports may be submitted by:
employees and self-employed workers;
collaborators, freelancers and consultants;
volunteers and interns/trainees;
shareholders and persons performing management, administrative and control functions.
Of particular importance is the existence of a qualified relationship between the reporting person and the public or private entity in which the reporting person operates, relating to current or even former work or professional activities.
“Internal report”: the written or oral communication of information concerning violations, submitted through the Organization's internal reporting channel.
“External report”: the written or oral communication of information concerning violations, submitted through the external reporting channels (platform, voice messaging, dedicated telephone lines) to the National Anti-Corruption Authority (ANAC).
“Violations”: conduct, acts or omissions that harm the public interest or the integrity of the public administration or private entity and that consist of:
administrative, accounting, civil or criminal offences;
unlawful conduct relevant under Legislative Decree No. 231 of 8 June 2001, or violations of the Organizational and Management Models;
offences falling within the scope of the European Union or national legislation listed in the annex to Legislative Decree No. 24 of 10 March 2023, or constituting implementation of the European Union legislation listed in the annex to Directive (EU) 2019/1937, relating to public procurement; financial services, products and markets and the prevention of money laundering and terrorist financing; product safety and compliance; transport safety; environmental protection; radiation protection and nuclear safety; food and feed safety and animal health and welfare; public health; consumer protection; protection of privacy and personal data and security of networks and information systems;
acts or omissions detrimental to the financial interests of the Union;
acts or omissions concerning the internal market, particularly violations of competition or taxation rules.
“Reporting person”: the natural person who makes a report or public disclosure of information concerning violations acquired in the context of their work environment.
“Facilitator”: a natural person who assists a reporting person in the reporting process, operating within the same work environment, whose assistance must be kept confidential.
“Person concerned”: the natural or legal person mentioned in the internal or external report or in the public disclosure as the person to whom the violation is attributed, or as a person otherwise involved in the violation reported or publicly disclosed.
“Retaliation”: any conduct, act or omission, including attempted or threatened conduct, carried out as a result of the report, the complaint to the judicial or accounting authorities, or the public disclosure, which directly or indirectly causes, or may cause, unjustified harm to the reporting person or to the person who filed the complaint.
3. APPLICABILITY
The Decree entered into force on 30 March 2023 and the provisions have been effective since 15 July 2023.
The Decree applies to public- and private-sector entities. With particular reference to the private sector, the legislation extends protection to Organizations that, during the previous year, employed an average of at least fifty subordinate workers or, even below this threshold, to entities operating in the so-called “Sensitive Sectors” (financial services, products and markets and the prevention of money laundering or terrorist financing, transport safety and environmental protection), as well as entities that adopt Organizational and Management Models pursuant to Legislative Decree 231/2001.
Only for private-sector entities that, during the previous year, employed an average of up to 249 subordinate workers under fixed-term or permanent employment contracts, there is an obligation to establish an internal reporting channel as of 17 December 2023.
Within the Company
The protection of reporting persons operating in the private sector, provided for by Legislative Decree 24/2023, requires reporting channels to be established by entities meeting at least one of the following conditions:
they employed, during the previous year, an average of at least fifty subordinate workers under permanent or fixed-term employment contracts;
they operate in certain specific sectors (financial services, products and markets and the prevention of money laundering or terrorist financing, transport safety and environmental protection), even if during the previous year they did not reach an average of at least fifty subordinate workers under permanent or fixed-term employment contracts;
they adopt the Organizational and Management Models referred to in Legislative Decree 231/2001, even if during the previous year they did not reach an average of at least fifty subordinate workers under permanent or fixed-term employment contracts.
What may be reported
Conduct, acts or omissions that harm the public interest or the integrity of the public Administration or private Entity and that consist of:
administrative, accounting, civil or criminal offences;
unlawful conduct relevant under Legislative Decree 231/2001, or violations of the Organizational and Management Models provided for therein;
offences falling within the scope of European Union or national legislation relating to the following sectors: public procurement; financial services, products and markets and the prevention of money laundering and terrorist financing; product safety and compliance; transport safety; environmental protection; radiation protection and nuclear safety; food and feed safety and animal health and welfare; public health; consumer protection; protection of privacy and personal data and security of networks and information systems;
acts or omissions detrimental to the financial interests of the Union;
acts or omissions concerning the internal market;
acts or conduct that frustrate the object or purpose of the provisions contained in Union legislation.
It is the Company's responsibility to:
ensure that its employees receive adequate training on whistleblowing legislation and the concept of a “report” (including through concrete examples), on the correct use of the channel and on sanctions in the event of violations;
inform employees (including through the website) of the existence of the channel;
properly retain documentation relating to reports.
Furthermore, the Company must always protect the confidentiality of reports and, in any event, must comply with information obligations (publication on the website, circulation of an internal notice, posting on the company notice board, etc.) and training obligations towards its personnel.
4. REFERENCES
Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law.
Legislative Decree No. 24 of 10 March 2023, implementing Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law and containing provisions concerning the protection of persons who report breaches of national regulatory provisions.
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 — General Data Protection Regulation, updated to reflect the corrections published in OJEU No. 127 of 23 May 2018.
Confindustria — New “Whistleblowing” Regulations, Operational Guide for Private Entities — October 2023.
ANAC — National Anti-Corruption Authority — Regulation governing the management of external reports and the exercise of ANAC's sanctioning powers pursuant to Legislative Decree No. 24 of 10 March 2023 — Resolution No. 301 of 12 July 2023.
5. RESPONSIBILITIES
ROLE RESPONSIBILITY
Company Management Having consulted the Workers' Representatives or Trade Union Organizations referred to in Article 51 of Legislative Decree 81/2015, it is responsible for activating its own reporting channels which guarantee, including through the use of encryption tools, the confidentiality of the reporting person, the person concerned and any person otherwise mentioned in the report, as well as the content of the report and related documentation. Company Management shall ensure adequate information and training regarding the contents of Legislative Decree No. 24 of 10 March 2023 and shall disseminate this Organizational Act.
Report Manager A properly trained person/group of persons or an autonomous internal office with personnel specifically trained to manage the reporting channel, or an autonomous external entity with personnel specifically appointed for this purpose. Responsible for managing reports.
Consultant --
RL --
Function Managers Responsible for providing their collaborators with adequate information regarding the contents of this Organizational Act.
6. OPERATING PROCEDURES
6.1 Prerequisites for submitting an internal report and related admissibility requirements
Within public- and private-sector entities, reports may be submitted by:
employees and self-employed workers;
collaborators, freelancers and consultants;
volunteers and interns/trainees;
shareholders and persons performing management, administrative and control functions.
It is important to note that reports concerning such offences or violations must be made in good faith and in compliance with the established procedures. Furthermore, in the context of Legislative Decree 231/01, the reporting of an offence may be relevant to the Organization in relation to the administrative liability of legal entities and companies. In this case, reporting internal violations could be fundamental in demonstrating that the Organization has adopted appropriate measures to prevent and combat such conduct, thereby avoiding potential legal liability. It is specified that, should the Company decide to adopt a Model pursuant to Legislative Decree 231/2001, it is essential that the report be shared with the Supervisory Body (“Organismo di Vigilanza” or “OdV”) and that said body be involved and informed of every subsequent stage of the investigation and analysis of the report.
Reports must be as detailed as possible, in order to allow the competent persons responsible for receiving and managing reports to assess the facts.
The following essential elements of the report must be clear, including for the purpose of assessing admissibility:
the identifying details of the reporting person (first name, surname, place and date of birth), as well as contact details to which subsequent updates may be communicated;
the circumstances of time and place in which the event subject to the report occurred and, therefore, a description of the facts being reported, specifying details relating to the circumstances and, where applicable, the manner in which the reporting person became aware of the facts;
the personal details or other information allowing identification of the person to whom the reported facts are to be attributed.
It is advisable that documents capable of providing evidence supporting the facts reported be attached to the report, together with an indication of other persons who may have knowledge of the facts.
In accordance with the provisions of the Confindustria Guidelines (October 2023, p. 17), an anonymous report must contain precise and detailed information and be supported by appropriate documentation in order to be considered an ordinary and valid report.
The Organization has appointed a “Whistleblowing Report Manager” at the company's registered office, Località Monastero D’Ombrone 19, 53019, Castelnuovo Berardenga (SI), who can be reached through a written communication submitted via an online platform*, to which reports may be submitted concerning information, including reasonable grounds for suspicion, relating to violations already committed or not yet committed (but which, on the basis of concrete evidence, could be committed), as well as conduct intended to conceal such violations.
(*) ANAC, taking into account the opinion of the Italian Data Protection Authority (“Garante Privacy”), points out that, for the purposes of establishing an internal reporting channel, “ordinary email and certified electronic mail (PEC) are considered tools that are not adequate to guarantee confidentiality.”
The Organization has established both a written — IT-based — channel and an oral channel (a meeting scheduled within a reasonable period upon request of the reporting person), and both must be made available to the reporting person.
By way of example only and without limitation, the following matters may be the subject of reports:
Financial fraud: Any fraudulent activity involving the company, such as document falsification, misappropriation of funds, manipulation of financial statements, etc.
Corruption: Offers, payments, gifts or other unlawful practices intended to obtain improper benefits or favors.
Violations of occupational health and safety regulations: Failure to comply with workplace health and safety regulations, exposure to inadequately managed risks, lack of training or appropriate equipment.
Workplace violence: Inappropriate conduct, harassment, discrimination or abuse in the workplace.
Privacy violations and improper data management: Unauthorized access to personal data, failure to protect sensitive information, or any other breach of data protection legislation.
Environmental violations: Company activities causing environmental damage, non-compliance with environmental regulations, pollution, improper waste disposal, etc.
Tax evasion: Unlawful practices intended to avoid the payment of taxes or circumvent tax laws.
Human rights violations: Involvement of the company in activities that violate human rights, such as child labor, human trafficking, exploitation, etc.
6.2 Procedures available to the Organization for using the internal/external reporting channel
(cases provided for by the Decree)
For PRIVATE-SECTOR ENTITIES that:
1. have not reached an annual average of 50 workers and have adopted the 231 Organizational and Management Model, reports may concern unlawful conduct or violations of the 231 Model and may be submitted through the internal channel.
2. have employed an average of at least 50 workers and have adopted the 231 Organizational and Management Model, reports may:
concern unlawful conduct or violations of the 231 Model and be submitted only through the internal channel;
concern breaches of EU law and be submitted through the internal channel, external channel, public disclosure or complaint.
3. have employed an average of at least 50 workers and do not have a 231 Model, or fall within the scope of the European Union legislation referred to in Parts I.B and II of the Annex (financial services, products and markets, prevention of money laundering and terrorist financing, transport safety and environmental protection), even if they have not reached an average of 50 subordinate workers, reports may concern breaches of EU law and be submitted through the internal channel, external channel, public disclosure or complaint.
6.3 Procedure for managing reports
Internal reports are normally submitted through an IT platform appropriately configured for reasons of confidentiality and security of the identity of the reporting person and of the contents of the communication, accessible at the following link:
https://whistleblowing.dataservices.it/CASTELMONASTERO
The choice between an online platform and an analogical/paper-based method is left to the individual company, depending on various considerations relating to the context, company size (see Section 6.2), functionality in relation to the purpose, and the level of security and confidentiality guaranteed by the solutions adopted.
Having chosen to use an IT platform, although the Decree and the ANAC Guidelines do not identify specific requirements to be fulfilled at the receipt stage, Company Management has arranged for the platform to be appropriately configured for reasons of confidentiality and security of the data transmitted and to ensure adequate training for the person/office entrusted with managing reports.
Reports received through an “irregular” channel
Reports potentially received through channels other than the Internal Channel established pursuant to Article 4 of Legislative Decree No. 24/2023 shall be processed on their merits and, in any event, the Company shall recognize the protections provided by the Decree in favor of the reporting person, both with regard to respect for privacy and confidentiality rights and with regard to the prohibition of discrimination and retaliatory actions against them.
In any event, should reports submitted through non-regulated channels be received by persons other than the person responsible for the internal channel, such persons are required to share the content with the same Responsible Person within seven days and subsequently delete without delay any sensitive data collected through the non-conventional channel that remains in their possession.
The person responsible for the internal channel shall ensure that the data processed are subsequently retained in accordance with Legislative Decree 24/2023, Legislative Decree 196/2003 and the GDPR.
6.4 Person entrusted with the management of reports, powers and obligations
Management of reports: this is entrusted to a dedicated group of trained personnel. In particular, responsibility for managing reports is assigned to:
the Head of Administration function (Director of Finance and Administration);
the Sole Director.
Please note that, should any of the persons responsible for managing reports identify a conflict of interest because they are involved in any way in the subject matter of the report (the person reported, the manager of a department involved in the reported conduct, closely connected to the reporting person, etc.), they are required to refrain from participating in the assessment activities concerning the report and in the entire procedure set out herein.
Activities required of persons managing reports
Persons managing reports shall:
1. issue the reporting person with an acknowledgment of receipt of the report within seven days of the date of receipt, solely to inform them that the report has been duly received. The acknowledgment of receipt certifies correct receipt, not that substantive investigative activities have been carried out.
2. ensure appropriate follow-up to reports received: eligibility, admissibility and investigation. This entails an assessment of:
compliance with the objective/subjective prerequisites (eligibility);
existence of the essential requirements (admissibility);
adequate investigation (requests for information, access to documents, etc.) to assess the merits of the reported facts (fumus of validity, i.e. the plausible/probable existence of the reported unlawful act).
If the report is not sufficiently detailed, the person managing the report may request additional information from the reporting person through the dedicated channel, or in person where the reporting person has requested a direct meeting.
3. provide feedback to the reporting person.
4. prepare a final report, which is submitted to the administrative body so that it may take any necessary decisions. The final report must contain:
a brief description of the reported facts;
an indication of the documentation collected and examined in relation to the report;
a summary of the investigative activities carried out and their respective findings;
any additional documentary attachments;
the conclusions reached by the responsible person regarding the admissibility or otherwise of the report and the related liability aspects.
Receipt of the report
The report manager shall issue the reporting person with an acknowledgment of receipt, sending it to the contact details indicated by the reporting person in the report. In the absence of such indication, the report may be considered unmanageable under the whistleblowing rules (leaving a record of the reasons) and may potentially be treated as an ordinary report.
In the event of receipt of anonymous reports, also in light of ANAC guidance, where such reports are precise, detailed and supported by appropriate documentation, the company may treat them as equivalent to ordinary reports and process them in accordance with internal regulations, where applicable.
In any event, anonymous reports shall be recorded by the report manager and the documentation received shall be retained. Indeed, the Decree provides that where an anonymous reporting person is subsequently identified and has suffered retaliation, the protections provided for whistleblowers must also be guaranteed to that person.
Eligibility of the report
In order to proceed with the process, the report manager shall first verify the existence of the objective and subjective prerequisites:
i) that the reporting person is entitled to make the report; and
ii) that the subject matter of the report falls within the scope of the legislation.
Where the report concerns a matter excluded from the objective scope of application, it may be treated as an ordinary report and therefore managed according to any procedures previously adopted by the entity for such violations, with the reporting person being informed accordingly.
Admissibility of the report
Once eligibility has been verified, the report is assessed for admissibility as a whistleblowing report.
In this regard, the following must be clear:
the circumstances of time and place in which the event subject to the report occurred and, therefore, a description of the facts reported, containing details relating to the circumstances and, where applicable, the means through which the reporting person became aware of the facts;
the personal details or other elements allowing identification of the person to whom the reported facts are to be attributed (the person reported).
A report may therefore be deemed inadmissible due to:
lack of data constituting the essential elements of the report;
manifest lack of grounds for the factual elements relating to the violations identified by the legislator;
presentation of generic facts that cannot be understood by the offices or persons responsible;
submission of documentation alone without an actual report of violations.
Where the report is found to be ineligible or inadmissible, the report manager shall archive it, while ensuring traceability of the reasons supporting such decision.
Investigation and verification of the report
The report manager shall ensure that all appropriate checks are carried out on the reported facts, ensuring promptness and compliance with the principles of objectivity, competence and professional diligence.
The purpose of the verification phase is to carry out specific checks, analyses and assessments concerning whether or not the reported facts are substantiated, for example:
directly acquiring the information necessary for the assessment through analysis of the documentation/information received;
involving other company departments or specialized external parties (e.g. IT specialists), taking into account the specific technical and professional expertise required;
interviewing any internal/external persons, etc.
Once the verification activities have been completed, the report manager may:
archive the report because it is unfounded, providing reasons;
declare the report substantiated and refer the matter to the competent internal bodies/functions for the appropriate follow-up (e.g. Company Management, Administrative Department, etc.).
The report manager is not responsible for assessing individual liability or any subsequent measures or proceedings arising therefrom. Therefore, at the conclusion of the report assessment process, the Responsible Person shall prepare a report summarizing the activities carried out, the information collected and the conclusions reached, and shall promptly submit it to the administrative body for any assessment concerning remedial and/or disciplinary actions that may need to be taken.
Feedback to the reporting person
Feedback must be provided to the reporting person within three months from the date of the acknowledgment of receipt or, in the absence of such acknowledgment, within three months from the expiry of the seven-day period following submission of the report.
It should be specified that the investigation does not necessarily have to be completed within three months, since circumstances may arise that require a longer period for verification purposes.
The feedback may be final or interim.
The report manager may inform the reporting person of:
the archiving of the report, providing the reasons;
the finding that the report is substantiated and its transmission to the competent internal bodies;
the activities carried out up to that point and/or the activities that the report manager intends to carry out.
In the latter case, it is advisable to also inform the reporting person of the subsequent final outcome of the investigation (archiving or confirmation that the report is substantiated and transmission to the competent bodies), in line with the ANAC Guidelines.
7. REQUIRED ADJUSTMENTS FOR THE PROCESSING OF PERSONAL DATA
Protection of the confidentiality of reporting persons
The identity of the reporting person may not be disclosed to persons other than those competent to receive or follow up on reports.
Protection concerns not only the reporting person's name but also all elements of the report from which the reporting person's identity may be inferred, even indirectly.
Protection of confidentiality extends to the identity of persons concerned and persons mentioned in the report until the conclusion of proceedings initiated as a result of the report, subject to the same safeguards provided for the reporting person.
Protection of personal data
The processing of personal data relating to the receipt and management of reports is carried out by public- and private-sector entities, acting as Data Controllers, in compliance with European and national principles concerning the protection of personal data, by providing appropriate information to reporting persons and persons concerned by reports and adopting appropriate measures to protect the rights and freedoms of data subjects.
Furthermore, the rights under Articles 15 to 22 of Regulation (EU) 2016/679 may be exercised within the limits provided for by Article 2-undecies of Legislative Decree No. 196 of 30 June 2003.
Internal and external reports and the related documentation shall be retained for the time necessary to process the report and, in any event, for no longer than five years from the date of communication of the final outcome of the reporting procedure, in compliance with the confidentiality obligations under European and national legislation on the protection of personal data.
8. REQUIREMENTS FOR RESORTING TO EXTERNAL REPORTING
Reporting persons may use the external channel (ANAC) when:
the mandatory activation of an internal reporting channel is not provided for in the relevant work context, or the channel, although mandatory, is not operational or, even if activated, does not comply with legal requirements;
the reporting person has already submitted an internal report and no follow-up has been given;
the reporting person has reasonable grounds to believe that, if an internal report were submitted, it would not be effectively followed up or that the report itself could result in a risk of retaliation;
the reporting person has reasonable grounds to believe that the violation may constitute an imminent or manifest danger to the public interest.
Reporting persons may directly make a public disclosure (through the press, electronic media or means of dissemination capable of reaching a large number of people) when:
the reporting person has previously made an internal and external report, or has directly made an external report, and no feedback has been provided within the established deadlines concerning the measures envisaged or adopted to follow up on the reports;
the reporting person has reasonable grounds to believe that the violation may constitute an imminent or manifest danger to the public interest;
the reporting person has reasonable grounds to believe that the external report may entail a risk of retaliation or may not be effectively followed up due to the specific circumstances of the case, such as where evidence may be concealed or destroyed or where there is a well-founded fear that the person who received the report may be colluding with or involved in the violation;
the report is exempt from access under administrative access rules and from the right of generalized civic access.
Reports to ANAC may be submitted through the services portal at:
https://whistleblowing.anticorruzione.it
Through the dedicated application, the ANAC portal issues the reporting person with a unique identification code, the “key code”, which must be used for communications in an anonymized manner and to remain constantly informed about the processing status of the submitted report.
9. PROHIBITION OF RETALIATORY ACTS
Retaliatory acts are prohibited (“retaliation” has the meaning defined in Section 2).
Examples of retaliatory conduct include:
dismissal, suspension or equivalent measures;
demotion or failure to promote;
change of duties, change of workplace, reduction in salary, change in working hours;
suspension of training or any restriction on access to training;
negative performance assessments or negative references;
disciplinary measures or other sanctions, including financial sanctions;
coercion, intimidation, harassment or ostracism;
discrimination or otherwise unfavorable treatment;
failure to convert a fixed-term employment contract into a permanent employment contract where the worker had a legitimate expectation of such conversion;
failure to renew or early termination of a fixed-term employment contract;
damage, including reputational damage, particularly on social media, or economic or financial prejudice, including loss of economic opportunities and loss of income;
inclusion on improper lists based on a formal or informal sectoral or industry agreement, which may result in the person being unable to find employment in the sector or industry in the future;
early termination or cancellation of a contract for the supply of goods or services;
cancellation of a license or permit;
requests to undergo psychiatric or medical examinations.
The reporting person may notify ANAC of retaliation they believe they have suffered. If committed in the private sector, ANAC informs the National Labour Inspectorate.
Retaliatory acts adopted in violation of the aforementioned legislation are null and void.
Authority competent to establish retaliation
The management of communications concerning retaliation in the public and private sectors falls within the competence of ANAC, which may avail itself, within their respective areas of competence, of the cooperation of the Public Administration Inspectorate and the National Labour Inspectorate.
The declaration of nullity of retaliatory acts falls within the jurisdiction of the judicial authorities.
Extension of protection to other persons
Protection is also extended to the following persons:
the facilitator (a natural person who assists the reporting person in the reporting process and operates within the same work context);
persons within the same work context as the reporting person, the person who filed a complaint or the person who made a public disclosure, who are connected to them by a stable emotional or family relationship up to the fourth degree of kinship;
colleagues of the reporting person or of the person who filed a complaint or made a public disclosure, who work in the same work context and have an ongoing and regular relationship with that person;
entities owned by the reporting person or for which the same persons work, as well as entities operating within the same work context as the aforementioned persons.
Loss of protection
Conditions for protection
Protection is granted when:
at the time of the report, the reporting person had reasonable grounds to believe (not rumors or assumptions) that the information concerning the violations was true and fell within the objective scope of the legislation;
the rules/procedure governing the use of the different channels have been complied with.
Protection is not guaranteed where the criminal liability of the reporting person has been established, even by a first-instance judgment, for the offences of defamation or false accusation, or for the same offences committed through a complaint to the judicial or accounting authorities, or where their civil liability has been established on the same grounds in cases of intent or gross negligence. In such cases, a disciplinary sanction may be imposed on the reporting or complaining person.
10. UPDATE OF THE ORGANIZATIONAL, MANAGEMENT AND CONTROL MODEL PURSUANT TO LEGISLATIVE DECREE 231/2001
Should the Organization decide to adopt an Organizational Model pursuant to Legislative Decree 231/01, the Model must be updated:
a) by indicating the internal reporting channels adopted by the entity;
b) by referring to the prohibition of any act of retaliation;
c) by ensuring compliance with confidentiality obligations in the processing of information relating to the management of reports;
d) by integrating the disciplinary system to provide for sanctions against persons responsible for violations for which ANAC imposes administrative monetary sanctions.
11. TRAINING AND INFORMATION
In order to ensure the conscious, accurate and professional management of reports, the Organization undertakes to provide:
training: the designated group entrusted with managing the reporting channel shall receive specific training concerning the management of the channel and the applicable legislation;
information: the designated group entrusted with managing the reporting channel shall provide the reporting person with clear information on the channel, procedures and requirements for making internal or external reports.
12. PROCESSING OF PERSONAL DATA
The Organization has established that all processing of personal data shall be carried out in accordance with Regulation (EU) 2016/679, Legislative Decree No. 196 of 30 June 2003 and Legislative Decree No. 51 of 18 May 2018.
The types of data processed include ordinary personal data, special categories of personal data (“sensitive data”) and judicial data (e.g. criminal convictions and offences) that may be contained in the report and related documents.
The data subjects are the persons to whom the personal data covered by the report relate (Reporting Person, Facilitator, Person Reported, and persons involved in various capacities in the report, e.g. potential witnesses to the reported event). All these persons benefit from the protections and rights provided for under personal data protection legislation, although with certain differences.
Reference is made in this regard to the General Principles of Data Protection to be given particular consideration for the purposes of this Organizational Act (Articles 5 and 25 GDPR), in particular: purpose limitation, relevance and data minimization; accuracy and updating of data; storage limitation (no longer than five years from communication of the outcome of the procedure); security (protection against risks relating to breaches of confidentiality, availability and integrity of data) based on the Data Protection Impact Assessment (DPIA) (the security measures adopted must in any event be periodically reviewed); transparency (providing an obligation to issue complete privacy notices to data subjects pursuant to Articles 13 and 14 GDPR, in addition to the obligation to publish information); data protection by design and by default regarding information on the channel, procedures and requirements for making internal or external reports (Article 25 GDPR); accountability (Article 24 GDPR — Accountability: it is the responsibility of the Data Controller to verify, ensure and be able to demonstrate that the implemented system complies with the protection requirements imposed by the GDPR, particularly in terms of correctness, security and clarity); protection of the confidentiality of the reporting person (the confidentiality of their identity is ensured through pseudonymization), the person reported and the other persons involved.
Responsibility for receiving and managing reports lies with the Data Controller.
The Organization considers a preliminary DPIA (Data Protection Impact Assessment) necessary (with reference to Article 13.6 of Legislative Decree No. 24/2023 and Article 35 GDPR), as a prerequisite for adopting appropriate technical and organizational security measures (criteria defining high risk include the vulnerable nature of the reporting person and the sensitivity of the information under Articles 9 and 10 GDPR).
Tracking of reporting channels is prohibited both on the platform and on any network equipment used (no retention of logs relating to the reporting person), whereas it is necessary to track the activities of those managing reports as a safeguard measure for compliance with the applicable obligations, within the limits established by the Workers' Statute.
Access to the dedicated platform shall take place through multi-factor authentication as an additional measure to strengthen protection measures.
The mapping of processing activities and updating of the Record of Processing Activities must be carried out dynamically, following any changes that occur.
The sanctions specifically provided for violations of the Whistleblowing Decree are in addition to the sanctions applicable in the field of Privacy and referred to by the Italian Data Protection Authority in orders issued prior to the Decree (e.g. absence of a privacy notice, failure to update the Record of Processing Activities, failure to regulate the relationship with the service provider and between the provider and its subcontractors, failure to carry out a DPIA, inadequacy of security measures such as encryption, inappropriate credential management procedures, etc.).
13. SHARING OF THE REPORTING CHANNEL
Where the company subject to this specific procedure decides to entrust the management of reports to the same external party, it shall be contractually guaranteed that each Entity may access only the reports pertaining to it, also taking into account the allocation of the relevant responsibility.
Accordingly, technical and organizational measures shall be adopted to ensure that each Entity has access only to the reports falling within its competence.
For this purpose, where the reporting channel is shared, agreements/conventions must be entered into between the Entities, defining the terms governing the management of reports, which must in any event take place without prejudice to the obligation to ensure confidentiality, provide feedback and manage the reported violation.

