Information on processing
INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ARTICLES 13 AND 14 OF REGULATION (EU) 2016/679 AND LEGISLATIVE DECREE 196/2003 AS AMENDED BY LEGISLATIVE DECREE 101/2018 AND DECLARATION OF CONSENT
REPORTING PERSON (WHISTLEBLOWER)
INTRODUCTION
Pursuant to Regulation (EU) 2016/679 and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, containing provisions for the protection of individuals with regard to the processing of personal data, BIBIONE SPIAGGIA SRL, with registered office in Via del Mare 2 – 30020 San Michele al Tagliamento (VE), as Data Controller, is required to provide certain information regarding the processing of personal data provided by you.
SOURCE OF DATA, PURPOSES AND METHODS OF PROCESSING
The data acquired by BIBIONE SPIAGGIA SRL, as Data Controller, are provided directly by the data subject or requested by us.
The data you provide will be processed for purposes strictly related to the management of reports (internal channel) concerning unlawful conduct, relating to activities and/or behaviors that do not comply with the procedures implemented by the Entity/Company. Such conduct includes violations of professional conduct rules and/or ethical principles referred to in applicable legislation – internal and external – and/or unlawful or fraudulent behavior attributable to the subjects identified by the relevant regulations.
Processing will be carried out both by electronic means and manually by specifically authorized personnel.
LEGAL BASIS FOR DATA PROCESSING
The legal basis for this processing is Article 6(1)(c) of Regulation (EU) 2016/679 (compliance with a legal obligation to which the Data Controller is subject), in particular with reference to the legal obligations arising from Legislative Decree no. 24 of 10 March 2023 and any other applicable legislation in force concerning the Data Controller.
PROVISION OF DATA AND CONSEQUENCES OF FAILURE TO PROVIDE DATA
For the purposes indicated above, the provision of data is optional, as reports may be submitted anonymously. However, please note that anonymous reports will be considered only if the subject matter of the report is sufficiently detailed to allow the initiation of an investigation.
The Whistleblower is therefore required to specify whether they “consent to the disclosure of their identity to persons other than those competent to receive or follow up on the report.” This option is provided to the reporting person during the submission process.
If the reporting person chooses not to give such consent, the report will be shared (where applicable) only with the designated internal officer or facilitator.
Legal basis for this processing: the data subject has given consent to the processing of their personal data for one or more specific purposes – Article 6(1)(a) of Regulation (EU) 2016/679.
CATEGORIES OF DATA PROCESSED
For the purpose of managing reports, the following categories of data may be processed:
Identification data, address and other contact details, tax code, role/position;
Special categories of personal data;
Personal data relating to criminal convictions and offenses;
Any other information relating to the reported person that the reporting person decides to share with the Data Controller in order to better substantiate their report.
The data provided by the reporting person in order to describe alleged unlawful conduct of which they became aware in the context of their working relationship with the Data Controller will be processed for the purpose of carrying out the necessary investigative activities to verify the validity of the reported facts and to adopt any consequent measures, in compliance with applicable legislation.
The persons responsible for the preliminary assessment and management of the report will act in accordance with the principles of impartiality and confidentiality, carrying out any activity deemed appropriate, including personal interviews with the reporting person and any other individuals who may provide information regarding the reported facts.
SCOPE OF DISCLOSURE AND CATEGORIES OF RECIPIENTS
The data will not be disclosed to third parties.
If, following verification, elements supporting the validity of the reported facts are found, the person responsible for handling reports will transmit the outcome of the assessment to the competent body identified among the following, depending on specific needs, for further investigation or for the adoption of appropriate measures:
Company Management, so that, where applicable, disciplinary action or other necessary measures and/or actions may be taken, including for the protection of our company;
The Judicial Authority, the Court of Auditors, and ANAC (National Anti-Corruption Authority);
Any other subject provided for by applicable legislation.
TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANIZATIONS
The data will be stored on our company servers and in our paper archives and, in any case, within the European territory for processing entrusted to third parties or for data center outsourcing services.
No transfers of personal data to third countries or international organizations are envisaged.
DATA RETENTION PERIOD
Personal data collected for the purposes indicated above will be retained for 5 years, or for the time necessary to ascertain the validity of the report and, where applicable, to adopt consequent disciplinary measures and/or until the conclusion of any disputes initiated as a result of the report.
RIGHTS OF THE DATA SUBJECT
The rights referred to in Articles 15–22 of Regulation (EU) 2016/679 may be exercised within the limits provided for by Article 2-undecies, letter f), of Legislative Decree 30 June 2003, no. 196.
Article 2-undecies, entitled “Limitations to the Rights of the Data Subject,” establishes that the rights provided for in Articles 15–22 of Regulation (EU) 2016/679 may not be exercised by submitting a request to the Data Controller where exercising such rights could result in actual and concrete prejudice to “the confidentiality of the identity of the person reporting violations of which they became aware in the context of their employment relationship or the functions performed, pursuant to the legislative decree implementing Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019, concerning the protection of persons who report breaches of Union law, or who report violations pursuant to Articles 52-bis and 52-ter of Legislative Decree 1 September 1993, no. 385, or Articles 4-undecies and 4-duodecies of Legislative Decree 24 February 1998, no. 58.”
(This provision was introduced into the Privacy Code by Legislative Decree 24/2023 and became effective as of 15 July 2023.)
If you believe that your rights have been violated, you have the right to lodge a complaint with the Data Protection Authority: www.garanteprivacy.it
DATA CONTROLLER
The Data Controller is:
BIBIONE SPIAGGIA SRL
Registered office: Via del Mare 2 – 30020 San Michele al Tagliamento (VE)
Contactable using the details indicated in this notice.