INFORMATION ON THE PROCESSING OF PERSONAL DATA IN
WHISTLEBLOWING REPORTS

IN ACCORDANCE WITH THE PROVISIONS OF EU REGULATION No. 2016/679 (GDPR) AND LEGISLATIVE DECREE No. 196/2003

  1. Data controller

The data controller is SENZANI BREVETTI S.p.A., with registered office in Viale Risorgimento 13/15, VAT no. 00082770397, (hereinafter also referred to as ‘Senzani Brevetti’ or ‘Data Controller’).

  1. Categories of personal data subject to processing

As part of the process of managing reports of violations pursuant to Legislative Decree No. 24/2023 (the so-called ‘whistleblowing’ decree), Senzani Brevetti may process the personal data of individuals who make reports, individuals who are reported, individuals who are mentioned or involved in the report in any way, and individuals to whom the protections provided for in Legislative Decree No. 24/2023 apply, as detailed in the Whistleblowing Procedure published on the Data Controller’s website.

The processing involves the voluntary provision of data by filling in a form on a specific online procedure, sending the report by ordinary post or through a direct meeting with the whistleblowing officer identified by the Data Controller and indicated in the specific procedure ‘Whistleblowing Reporting Procedure’. The processing may therefore concern general personal data, such as personal details, contact details and data relating to the data subject’s job and, only to the extent strictly necessary, personal data belonging to the special categories referred to in Article 9 of EU Regulation 2016/679 (hereinafter: Regulation or GDPR), i.e. data relating to health, trade union membership, data revealing ethnic origin, political opinions, religious or philosophical beliefs of the data subject, or data relating to criminal convictions and related security measures referred to in Article 10 of the GDPR.

  1. Purpose and legal basis of processing

Personal data may be processed for the following purposes:

  • management of the report in all its phases, including the investigation of the facts reported and the adoption of any consequent measures, as described in the Whistleblowing Procedure published on the Data Controller’s website;

  • compliance with the Data Controller’s legal obligations regarding whistleblowing.

For the aforementioned purposes, the legal basis for processing is the need to comply with a legal obligation to which the Data Controller is subject, namely Legislative Decree No. 24/2023, and to apply the procedures necessary to comply with the provisions of the aforementioned decree, pursuant to Articles 6(1)(c), 9(2)(b) and 10 of the GDPR, as well as Article 88 of the same Regulation.

The legal basis for the processing operations indicated below is consent, pursuant to Article 6(1)(a) of the GDPR:

  • the disclosure of the identity of the whistleblower and any other information from which their identity can be inferred, directly or indirectly, to persons other than those competent to receive or follow up on reports, in any case in the circumstances provided for by applicable law;

  • disclosure of the identity of the whistleblower in disciplinary proceedings where the complaint is based, in whole or in part, on the report, and knowledge of the identity is essential for the defence of the accused.

In the aforementioned cases, the Data Controller, or the individuals appointed by the Data Controller for this purpose, shall be responsible for obtaining the consent of the reporting person using the appropriate form.

  1. Provision of data

The provision of personal data is optional. However, failure to provide such data could compromise the investigation of the report: anonymous reports will only be taken into consideration if they are adequately detailed and provide sufficient information to highlight facts and situations related to specific contexts, in accordance with the Whistleblowing Procedure published on the Data Controller’s website.

  1. Methods of processing personal data

The processing will be carried out using an IT platform equipped with encryption tools to ensure the confidentiality of the identity of the whistleblower and the content of the reports and related documentation, adopting appropriate technical and organizational measures to protect them from unauthorized or unlawful access, destruction, loss of integrity and confidentiality, even accidental. The processing of personal data may also be carried out with the support of paper-based means, using methods designed to ensure security and confidentiality, in accordance with the provisions of Legislative Decree 24/2023.

  1. Recipients of personal data

In addition to people specifically authorized by the Data Controller, personal data may also be processed by people who perform outsourced activities on behalf of the Data Controller, in their capacity as Data Processors. Furthermore, in the cases provided for by law, personal data may be disclosed to the National Anti-Corruption Authority (ANAC), the ordinary judicial authority or the accounting judicial authority.

  1. Transfers outside the EU

At present, there are no plans to transfer personal data to countries outside the European Economic Area (EEA).

  1. Retention period for personal data

Personal data will be retained for a maximum period of 5 years from the date of notification of the final outcome of the reporting procedure and, in any case, until the proceedings initiated by the offices or entities receiving the report have been concluded. In any case, personal data transmitted by the reporter that are not useful for processing the report will be immediately deleted.

  1. Rights of data subjects

In the cases provided for by the Regulation, whistleblowers have the right to obtain access to personal data, rectification, integration, cancellation or restriction of processing, or to object to processing (Articles 15 et seq. of the GDPR). The request may be submitted by contacting the whistleblowing manager via the online platform used for whistleblowing. Data subjects who believe that the processing of their personal data violates the provisions of the Regulation also have the right to lodge a complaint with the Data Protection Authority, using the forms published at the following link: https://www.garanteprivacy.it/i-miei-diritti.

Furthermore, for processing operations that require it, you have the right to withdraw your consent at any time, without prejudice to the lawfulness of the processing carried out while your consent was not withdrawn.