Legal

Whistleblowing – Reporting breaches

Italimpianti S.r.l. provides a confidential internal channel for reporting breaches learned of in a work-related context, pursuant to Italian Legislative Decree No. 24 of 10 March 2023 (transposing Directive (EU) 2019/1937). Reporting persons are protected: their identity is protected and any form of retaliation is prohibited.

Procedure for managing reports of breaches (whistleblowing)

Version 2.0 – DA DEFINIRE – approved by DA DEFINIRE – replaces version 1.1.

2.1 Purpose and legal references

This procedure describes the internal reporting channel established by Italimpianti S.r.l., how to submit a report, how it is handled and the protections afforded to the reporting person, in accordance with:

- Italian Legislative Decree No. 24 of 10 March 2023 (protection of persons reporting breaches of Union law and national legislation);

- ANAC Guidelines on the protection of persons reporting breaches (Resolution No. 311 of 12 July 2023);

- Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003;

- DA DEFINIRE.

2.2 Who can report

People working in the work-related context of Italimpianti S.r.l. may submit a report, in particular:

- employees, including apprentices and workers on fixed-term, part-time or intermittent contracts;

- self-employed workers, collaborators, independent professionals and consultants providing services to the company;

- workers and collaborators of suppliers, subcontractors and businesses supplying goods or services or carrying out works for the company;

- volunteers and trainees, paid or unpaid;

- shareholders and persons with administrative, management, supervisory, oversight or representative functions, including those exercising such functions in practice.

Protection also applies where the relationship has not yet begun, if the information was obtained during recruitment or pre-contractual negotiations; during the probationary period; and after the relationship has ended, if the information was obtained during that relationship.

The protections extend to facilitators, people in the same work-related context linked to the reporting person by a stable emotional relationship or kinship up to the fourth degree, colleagues with whom there is a regular and ongoing relationship, and entities owned by the reporting person or for which they work.

2.3 What can be reported

Information, including reasonable suspicions, may be reported about breaches committed or likely to be committed within the organisation of Italimpianti S.r.l., of which the reporting person became aware in a work-related context, in particular:

1. breaches of European Union legislation and national implementing provisions in the following areas: public procurement; financial services, products and markets, and prevention of money laundering and terrorist financing; product safety and compliance; transport safety; environmental protection; radiation protection and nuclear safety; food and feed safety and animal health and welfare; public health; consumer protection; protection of privacy and personal data, and security of network and information systems;

2. acts or omissions affecting the financial interests of the European Union, for example fraud or irregularities in the use of European funds, including the LIFE AGHETA project;

3. acts or omissions relating to the internal market (competition, State aid, corporate tax);

4. acts or conduct that defeat the object or purpose of Union provisions in the areas indicated above;

5. DA DEFINIRE.

Breaches may also include conduct intended to conceal the above.

DA DEFINIRE

2.4 What is excluded

The procedure does not cover:

- disputes, claims or requests linked to a personal interest of the reporting person, relating exclusively to their own employment relationship or relationships with superiors (for example pay requests, transfers or appraisals), unless connected to breaches referred to in section 2.3;

- reports of breaches already subject to mandatory sector-specific legislation (for example anti-money laundering or financial services), to be handled under the specific procedures provided for by that legislation;

- reports concerning national security, defence and procurement in the defence and national security sectors;

- manifestly unfounded information, information in the public domain, or information obtained solely from unsubstantiated rumours.

For personal matters, requests for assistance or commercial complaints, the ordinary channels are available (human resources, the relevant manager, info@italimpiantisrl.eu).

2.5 Internal channel manager

The channel is managed by DA DEFINIRE (hereinafter the "Manager"), who operates independently, with specific training and in compliance with confidentiality requirements.

If the report concerns the Manager or there is a potential conflict of interest, it may be addressed to DA DEFINIRE through DA DEFINIRE.

2.6 How to report – internal channel

A report may be submitted:

a) In writing, through the confidential form available on this page, which ensures the confidentiality of the reporting person's identity and of the content, including through encryption tools. DA DEFINIRE

b) Orally, through DA DEFINIRE, available DA DEFINIRE. With the reporting person's prior consent, an oral report is documented by recording it on a device suitable for storage and playback, or by written minutes; in the latter case, the reporting person may check, correct and confirm the minutes by signing them.

c) At a direct meeting with the Manager, at the reporting person's request, arranged within a reasonable period and in any event within DA DEFINIRE days of the request. Minutes are drawn up or, with the reporting person's consent, the meeting is recorded.

The address whistleblowing@italimpiantisrl.eu is available exclusively to request information on how the channel works, request a direct meeting or report access problems. It must not be used to transmit the content of reports: ordinary email does not ensure the same level of confidentiality. DA DEFINIRE

If a report is submitted to a person other than the Manager, that person forwards it to the Manager within seven days of receipt and simultaneously informs the reporting person.

2.7 Content of a report

To allow an effective assessment, the report should contain:

- a clear and detailed description of the facts;

- periods, dates and places where the events occurred;

- the people or functions involved, if known;

- any documents, evidence or details of other people who can provide information about the facts;

- optional contact details for receiving updates.

Certainty about the facts is not required: reasonable grounds to believe that the information is true are sufficient. Personal data not necessary for the report should be avoided.

2.8 Handling reports and time limits

The Manager:

1. provides the reporting person with an acknowledgement of receipt within seven days of the date of receipt;

2. maintains communication with the reporting person and may request additional information if necessary;

3. diligently follows up on the report, carrying out the necessary investigations, including with the assistance of internal departments or external consultants bound by confidentiality;

4. provides feedback within three months of the acknowledgement of receipt or, if no acknowledgement was sent, of the expiry of the seven-day period following submission. Feedback may consist of notification that the case has been closed, that an internal investigation has started and its results, the measures taken, or referral to the competent authority.

At the end of the investigation, if the report is substantiated, the Manager reports to DA DEFINIRE for the necessary measures to be taken (corrective or disciplinary measures, referral to the judicial authorities). If it is unsubstantiated, the report is closed with reasons given.

2.9 Anonymous reports

Anonymous reports are considered if sufficiently detailed and supported by information suitable for carrying out checks. A person who reported anonymously and is subsequently identified and subjected to retaliation benefits from the same statutory protections. DA DEFINIRE

2.10 Confidentiality

The identity of the reporting person and any information from which it may be inferred, directly or indirectly, cannot be disclosed without their express consent to anyone other than those competent to receive and follow up on reports and authorised to process the data. Protection also covers the identity of the persons involved or mentioned, the content of the report and its documentation.

In any disciplinary proceedings, the reporting person's identity cannot be disclosed if the allegations are based on findings that are separate from and additional to the report. If the allegations are based wholly or partly on the report and knowledge of the identity is indispensable to the defence of the accused person, the report may be used only with the reporting person's express consent; the reporting person is informed in writing of the reasons for disclosure. In criminal proceedings, the identity is subject to secrecy in the manner and within the limits of Article 329 of the Italian Code of Criminal Procedure.

2.11 Protections

Prohibition of retaliation. No form of retaliation against the reporting person is permitted, including attempted or threatened retaliation. Retaliation includes, among other things: dismissal, suspension or equivalent measures; demotion or withholding of promotion; changes to duties, workplace, salary or working hours; withholding of training; negative performance assessments or references; disciplinary measures or penalties; coercion, intimidation, harassment or ostracism; discrimination or unfavourable treatment; failure to convert a fixed-term contract, non-renewal or early termination; harm, including reputational harm, or financial loss; blacklisting; early termination or cancellation of supply contracts; requests for medical or psychiatric examinations. In a dispute, the company must demonstrate that the act is not linked to the report. Retaliatory acts are null and void. The same protections apply to facilitators and to the persons and entities indicated in section 2.2.

Conditions for protection. The protections apply if, at the time of reporting, the reporting person had reasonable grounds to believe that the information was true and fell within the scope of the procedure, and if the report was made in accordance with the methods provided for by law. The motives for reporting are irrelevant.

Loss of protections. The protections are not guaranteed if the reporting person's criminal liability for defamation or false accusation, or civil liability for intentional wrongdoing or gross negligence, is established, including by a first-instance judgment; in such cases, a disciplinary penalty may be imposed.

Limitation of liability. A person who reports in accordance with the law incurs no liability for disclosing information covered by an obligation of secrecy (except legal and medical professional secrecy and deliberations of judicial bodies), copyright or personal data protection, or for lawful access to the reported information.

Support measures. The reporting person may contact third-sector entities on the list published by ANAC to receive free information, assistance and advice.

Penalties. ANAC may impose administrative fines of between EUR 10,000 and EUR 50,000 on anyone who retaliates, obstructs a report or breaches confidentiality, and on an entity that has not established compliant channels or procedures. Breaches are also relevant for disciplinary purposes.

2.12 ANAC external channel

The reporting person may submit an external report to the Italian National Anti-Corruption Authority (ANAC) if, at the time of submission, one of the following conditions applies:

- the internal channel is not active or does not comply with the law;

- they have already submitted an internal report that was not followed up;

- they have reasonable grounds to believe that an internal report would not be effectively followed up or would create a risk of retaliation;

- they have reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest.

External reports are submitted through the ANAC platform, in writing or orally. Information and access: https://www.anticorruzione.it/-/whistleblowing.

Reports concerning the use of European Union funds may also be submitted to the European Anti-Fraud Office (OLAF).

2.13 Public disclosure

A reporting person who makes information public through the press, electronic media or other means capable of reaching a large number of people benefits from the protections if: they made an internal and external report, or directly an external report, without receiving feedback within the statutory time limits; they have reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest; or they have reasonable grounds to believe that external reporting may involve a risk of retaliation or may not be effectively followed up because of the circumstances of the case.

2.14 Processing and retention of personal data

Personal data contained in reports are processed by Italimpianti S.r.l., as controller, in compliance with the GDPR and Italian Legislative Decree 196/2003, solely for the purpose of handling reports and following them up. The Manager is authorised to process data and bound by confidentiality. Data manifestly irrelevant to a report are not collected or, if collected accidentally, are deleted immediately. DA DEFINIRE

Reports and documentation are retained for the time necessary to handle them and in any event for no more than five years from the date on which the final outcome of the procedure is communicated.

The rights of persons involved in a report may be restricted in the cases provided for by Article 2-undecies of Italian Legislative Decree 196/2003, where exercising them may jeopardise the confidentiality of the reporting person's identity.

The full privacy notice concerning the processing of data for whistleblowing reports is available here: DA DEFINIRE.

2.15 Information and training

This procedure is published on the company website, displayed in workplaces and brought to the attention of employees, collaborators and suppliers. The Manager and the personnel involved receive specific training DA DEFINIRE.

2.16 Updating

The procedure is reviewed at least DA DEFINIRE and whenever legislation or the organisation changes. Previous versions are kept on file.

Submit a confidential report

The form is encrypted and accessible only to the channel Manager. IP addresses and device data are not recorded. Contact fields are optional: anonymous reporting is possible; in that case, to allow checks to be carried out, describe the facts in as much detail as possible. DA DEFINIRE

Italimpianti S.r.l. processes data to handle the report under Italian Legislative Decree 24/2023, Article 6(1)(c) GDPR. Contact details are optional; anonymous reports are possible. Manager: DA DEFINIRE. Retention: as necessary, no longer than five years after notification of the final outcome. Full notice: Privacy notice — Whistleblowing

By submitting, you confirm that you are making the report with reasonable grounds to believe that the information provided is true. Knowingly false reports may result in the loss of protections and disciplinary, civil or criminal liability.

Italimpianti Text