Privacy Policy
Information pursuant to articles. 13 and 14 of the European Regulation 2016/679 on the Processing of Personal Data within the Reporting System of Alleged Offenses (“Whistleblowing”)
In implementation of the current legislation on the matter ( Legislative Decree 24/2023 – ” Implementation of Directive (EU) 2019/1937 of the European Parliament and of the Council, of 23 October 2019, concerning the protection of persons who report violations of Union and containing provisions regarding the protection of persons who report violations of national regulatory provisions “) MARBO Italia srl (hereinafter referred to as the “Company” or the “Owner”) has implemented a system for the reception and management of reports of alleged offences, which allows the management of the report (“Report”) submitted by you to the Company through a specific dedicated channel of the Company itself. The system is dedicated to the reception and management of reports, even anonymously, received by the Company from company personnel and/or third parties and relating to possible violations of national or European Union regulatory provisions, violations of internal regulations (rules of conduct contemplated in the Code of Ethics, in the Anti-Corruption Guideline, in Model 231 and more generally in the corporate regulatory corpus), illicit conduct and irregularities regarding the conduct of the Company’s business activities.
Pursuant to articles 13 and 14 of the European Regulation 2016/679 (hereinafter “GDPR”), the Company, as independent data controller, provides information on the processing of personal data/information (“Data”) concerning you (as “Reporter”), acquired directly or otherwise acquired, in reference to the “Report” made by you, as well as on the processing of data/information of the subjects affected by the Report itself (hereinafter also “Whistleblowing”).
This information is made available and made known to potential interested parties by publication on the owner’s institutional website.
The Owner reserves the right, at its discretion, to change, modify, add or remove any part of this Policy at any time. In order to facilitate the verification of any changes, this Information will contain an indication of the update date at the bottom.
DATA CONTROLLER
MARBO Italia srl, to which the Report is addressed, is the independent Data Controller of your personal data, as Reporter, and/or of other subjects interested in the Report for Whistleblowing management activities.
For further information on the Company that acts as Data Controller for the Report you have made, you can write to MARBO Italia srl – Whistleblowing Privacy Policy – with headquarters in Pogliano Milanese (MI), Via Torquato Tasso n. 25/27.
TYPES OF DATA PROCESSED
As part of the “Whistleblowing” procedure, the personal data/information being processed are the data of the “Reporter” (or “Interested Party”), of the “Reported Person” and of the people involved and/or connected to the facts which are the subject of the Report”. , such as, for example, any witnesses (hereinafter “Interested Parties”).
Such Data, collected and processed by the Data Controller, includes “common” personal data of the Interested Party/Reporter, of the Interested Parties (personal data, the job position held in the Company to which they belong, contact details such as: email address, postal address, telephone number), any other information present in your report, and, possibly, in some cases, where necessary, also data belonging to particular categories pursuant to art. 9 GDPR or data relating to criminal convictions and crimes pursuant to art. 10 of the GDPR for the reasons of significant public interest referred to in the Whistleblowing Decree and in any case within the limits of what is permitted by the relevant legislation, including articles 9 and 10 of the GDPR.
The Data may be collected either directly from the interested party or through other subjects involved in the Report, through the specific “internal reporting channel” indicated above or through the other communication channels indicated in point 4 below.
The data is provided voluntarily by the Interested Party/Reporter, even anonymously, to the Data Controller, who will not process data that is not strictly necessary for the purposes referred to in point 3 below.
By way of example and not exhaustively, the “report” can take place by: employees of the Owner and/or third parties who have a relationship with the Owner.
PURPOSE AND LEGAL BASIS OF THE PROCESSING
Personal data are processed exclusively for the purposes of investigating and ascertaining the facts covered by the Report and adopting any consequent measures, in accordance with the provisions of Legislative Decree 24/2023.
In particular, the Personal Data collected is only that which is necessary and relevant to achieve the purposes indicated above, based on the “minimization principle”.
With respect to these data, their provision is voluntary and the interested party is asked to provide only the data necessary to describe the facts covered by the Report without communicating redundant personal data in addition to those necessary for the purposes indicated above. If they are provided, the Owner will refrain from using such Data and will delete them.
Personal data are processed on the legal basis of legal obligation, pursuant to art. 6, co.1 lett. b) ( Legislative Decree 24/2023 – Legislative Decree 231/01), and of the legitimate interest of the Data Controller, pursuant to art. 6, co. 1, letter. f) of the GDPR (provided that the interests or fundamental rights and freedoms of the interested party do not prevail), to manage the Reports of unlawful acts, of which the Reporter has become aware for work reasons, within the context of his/her work context or for other reasons, as well as to protect internal and external interested parties involved in the “Whistleblowing” process.
PROCESSING METHODS
The data is collected, in compliance with current regulations, by means of electronic, telematic and manual tools, with logic strictly connected to the purposes indicated above, in order to guarantee the security and confidentiality of the data themselves.
In particular, they are collected through the following electronic/telematic tools:
- Web page https://www.ethicpoint.eu, ex art. 4 Legislative Decree 24/2023, provided by a selected external provider that adopts a system for reporting corporate offenses compliant with Directive (EU) 2019/1937, which guarantees the security and protection of data as well as the confidentiality of the information, through an advanced communications and database encryption system, in line with the provisions of the relevant legislation. This platform allows the sending of reports in written form, both anonymously and non-anonymously, and allows conversations to be maintained with the Reporter and to provide feedback to the Report, in compliance with the deadlines established by law. The report is promptly managed by internal offices equipped with dedicated and specifically trained independent staff in order to guarantee the management of the reported case in accordance with the provisions of the relevant legislation, as indicated in the following paragraph. 6;
- Email address: marbo@ethicpoint.eu;
- Registered telephone line, in accordance with the provisions of art. 14, paragraph 2 of Legislative Decree 24/2023: 800.985.231;
- Post office box address ( po box).
The data collected by means of electronic/telematic tools will not be subject to fully automated processing as specified in the art. 22 GDPR.
Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.
Furthermore, specific technical-organizational measures, such as encryption, are adopted, pursuant to art. 32 GDPR, to guarantee the protection of the identity of the interested parties, as well as the possible anonymity of the Reporter and complete anonymity in accessing the platform (no log).
DATA RETENTION TIMES
Personal data will be kept only for the time necessary for the purposes for which they are collected in compliance with the principle of minimization pursuant to art. 5.1.c) GDPR and, in particular, for the purposes of managing the investigation, concluding the activity of defining the Report and adopting the related measures, in the event of an investigation, and in any case no later than 5 years from the date of communication of the final outcome of the reporting procedure, in compliance with the provisions of the art. 14, paragraph 1 of Legislative Decree 24/2023 and art. 5, paragraph 1 of the GDPR.
RECIPIENTS OF THE DATA
Within the Company, the Personal Data provided may only become known to the subjects in charge of the processing by the Data Controller and authorized to carry out the processing operations within the scope of the aforementioned activities in accordance with the provisions of the art. 4, paragraph 2 of Legislative Decree 24/2023.
The supplier who manages the operation, as well as the maintenance of the IT tools on which it is possible to enter the Report, may become aware of the aforementioned Data, as indicated in the previous paragraph. 4, required to process the data for the same purposes referred to in the previous point 3, who is, for this purpose, appointed “Data Controller”, pursuant to art. 28 GDPR.
The assistance and management activities of the Reports are carried out on behalf of the Data Controller by the Data Controller’s Supervisory Body, for the performance of its duties in the context of Whistleblowing tasks, pursuant to art. 13 Legislative Decree 24/2023, the Anac, the judicial authority and other competent bodies/bodies in relation to the reported case.
Under no circumstances will personal data be disclosed.
RIGHTS OF INTERESTED PARTIES
The articles 15-22 GDPR give interested parties the possibility to exercise specific rights, such as, for example, the right of access, rectification, cancellation, limitation of processing.
The above rights can be exercised with a request made without formalities, by sending an email to contact@gruppomarbo.com .
The interested party may lodge a complaint pursuant to art. 57 lett. f) GDPR to the Personal Data Protection Authority.
In the event that the exercise of the above rights by the Reported Party may result in an actual and concrete prejudice to the protection and confidentiality of the Reporting Party’s personal data, the Data Controller may limit, delay or exclude such exercise, pursuant to art. 2-undecies, co. 1, letter. f) of the Privacy Code ( Legislative Decree 196/2003), and not follow up on the request.
In such cases, the rights of the interested party, pursuant to art. 2-undecies, co. 3 of the Privacy Code, can be exercised through the Guarantor in the manner set out in art. 160 of the Privacy Code.
POSSIBLE TRANSFER OF PERSONAL DATA ABROAD
The management and storage of data takes place on the servers of a third-party company appointed as Data Controller, as indicated in the previous paragraph. 6, located in Italy and within the European Union.
Personal data is not transferred outside the European Union.
Pogliano Milanese, 13 December 2023