Privacy Policy*
Privacy policy pursuant to EU Regulation 2016/679 and applicable reference legislation
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “Regulation”), in addition to the reference legislation on Privacy, the Company, as Data Controller, informs you that the processing of your personal data or special categories of data (Article 9 EU Regulation) provided by you will be carried out in a relevant and transparent way and in compliance with the principles of legality and necessity according to the provisions in force.
Purpose and obligatory nature of data conferment:
The Data Controller will process personal data for the following purposes:
- management of the report at every phase, including that of ascertaining the facts reported and taking any resulting measures, as described in the Whistleblowing Procedure, which is available on the company’s website and intranet;
- compliance with legal or regulatory obligations to which the Company is subject regarding whistleblowing.
Legal basis of the processing for the purposes described above: (i) the requirement to fulfil the legal obligation to enforce the whistleblowing legislation to which the Company is subject (Articles 6(1)(c), 9(2)(b) and 10, in addition to Article 88 of Reg (EU) 2016/679, in relation to Legislative Decree No. 24/2023; (ii) the requirement to perform the task of public interest as provided for by the legal system, related to the whistleblowing legislation (Article 6, paragraph 1(e), Article 9, paragraph 2(e), of the Regulation).
Legal basis of the processing
The legal basis for the processing resides in Legislative Decree No. 24/2023 and in the related Procedure adopted as a supplement to the Organisation and Management Model pursuant to Legislative Decree 231/2001.
Categories of personal data processed
As part of its role, the Company may process special categories of data in order to allow it to fulfil its obligations under this Procedure.
As part of the process of handling reports of violations pursuant to Legislative Decree No. 24/2023, on the protection of persons who report violations of EU law and the protection of persons who report violations of national regulatory provisions (whistleblowing), the Data Controller will process the personal data of the reporters, the reported parties, the parties otherwise mentioned in the report, the parties involved in the process of handling the report, and in any case the parties covered by the protections under Legislative Decree No. 24/2023.
This data will include personal identifying data, such as biographical, contact and work-related information about the data subject and - to the extent strictly necessary - personal data belonging in the special categories referred to in Article 9 of EU Regulation 2016/679. This includes data relating to the data subject’s health, trade union membership, racial origin, political opinions, religious or philosophical beliefs or data relating to criminal convictions and offences referred to in Article 10 of the Regulation.
Personal data will be collected directly from the person concerned or from third parties. The data will be contained in the report of wrongdoing and attached documentation or collected during the process of handling the report.
Data retention
In compliance with the principles of proportionality and necessity, the data will not be kept for longer periods than those indispensable to the fulfilment of the aforementioned purposes.
Recipients of personal data
The data may be communicated to: third parties, including the companies of the BasicNet Group. In such an event, these subjects will be identified as autonomous Data Controllers, in accordance with the provisions of privacy law.