Whistleblowing
Information on the protection of personal data
(Pursuant to Articles 13 and 14 of European Regulation 2016/679)
Dear Clients,
Without prejudice to the information already provided to you during our interactions, and in compliance with Article 13 of EU Regulation 2016/679 (the “GDPR”) and the principles established by the same GDPR, we hereby provide this notice to inform you about the characteristics and methods of processing (the “Processing”) of the information provided within the whistleblowing procedures introduced by Legislative Decree No. 24/2023 (the so-called “Whistleblowing Regulation”).
- Data Controller (the “Controller”)
The Data Controller is the company POINTEX S.P.A. (Tax Code 01588340974), based in Prato (PO), Via Cecchi no. 30, represented by Mr. Angelo Ranaldo.
Tel. +39 055 8979380; Fax +39 055 8966189; e-mail: info@pointexspa.com; Certified email (PEC): pointex@pec.it; website: www.pointexspa.com
- Types of personal data (“Personal Data”)
The Whistleblowing Regulation allows for the reporting of unlawful acts and detrimental conduct committed to the detriment of the Controller (the “Reports”).
Reports may include Personal Data concerning all natural persons – identified or identifiable – involved in the reported events (the “Data Subjects”).
Specifically, the Personal Data of the Data Subjects may fall into the following categories:
- common personal data as defined by Article 4, point 1, of the GDPR, such as: identification data (e.g. name, surname, date and place of birth), contact data (e.g. landline/mobile number, postal/email address), relationships with the Controller, job position, role/qualification;
- “special categories of data” pursuant to Article 9 of the GDPR (i.e. data “revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation”);
- judicial data relating to “criminal convictions and offences or related security measures” pursuant to Article 10 of the GDPR.
The receipt and handling of Reports entails the Processing of Personal Data by the Company for the Purposes set out below.
Personal Data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (see below). Personal Data that is clearly not useful for handling a specific report must not be collected and, if collected accidentally, must be promptly deleted (Art. 13, para. 2 of the Decree), provided the irrelevance to the report is evident, without prejudice to data retention regulations.
- Purposes of the Processing (the “Purposes”) and legal basis
The Personal Data collected within the Reports and/or in related documentation are strictly necessary for the following Purposes:
- compliance with legal obligations set forth by the Whistleblowing Regulation and EU law;
- receipt, analysis, and management of alleged unlawful conduct subject to the Reports;
- conducting investigations to assess the validity of the Report and adopting any necessary corrective measures ex Article 12, paragraph 1, Legislative Decree 24/2023;
- internal control and business risk monitoring;
- defending and/or asserting a legal right in court or for other legitimate interests of the Controller.
The legal basis for the Processing is based on the following provisions:
- processing of “common” data is based on legal obligation to which the Controller is subject (Art. 6, para. 1, letter c) GDPR), on the consent of the Whistleblower if given (Art. 6, para. 1, letter a) GDPR), and on the legitimate interest of the Controller (Art. 6, letter f) GDPR);
- processing of “special” data is based on the fulfillment of obligations and the exercise of specific rights of the Controller and the Data Subject in the field of employment law (Art. 9, para. 2, letter b), GDPR);
- processing of data relating to criminal convictions and offences is based on legal obligations of the Controller (Art. 6, para. 1, letter c), GDPR) and in compliance with Art. 10 GDPR.
- Processing methods
Processing is carried out using electronic and/or paper-based tools and, in any case, by adopting procedures and organizational and/or IT measures, in written and oral form, suitable for ensuring the security, confidentiality, relevance, and non-excessiveness of the Personal Data included in the Reports.
- Disclosure of Personal Data
Personal Data is accessible only to individuals within the Company who are authorized to receive or follow up on the Purposes.
In particular, Personal Data may be disclosed to the following parties:
- the body authorized to manage the reporting channel;
- external consultants and/or third parties with technical roles (e.g. IT platform provider, investigative agencies), acting as data processors/sub-processors pursuant to Article 28 GDPR;
- institutions and/or Public Authorities, Judicial Authorities, and Law Enforcement Bodies.
Personal Data is not shared or disclosed to parties other than those mentioned above.
These parties are appropriately instructed to prevent loss, unauthorized access, or unlawful processing of Personal Data and, more generally, in compliance with data protection obligations.
Personal Data is processed with the utmost confidentiality and is used solely for managing and evaluating the Reports to which this notice refers.
The identity of the whistleblower and any information from which their identity can be directly or indirectly inferred may be disclosed to individuals other than those competent to handle the Reports only with the whistleblower’s express consent, in accordance with Legislative Decree No. 24/2023.
Some processing may be performed by additional third parties to whom the Controller assigns certain tasks (or parts thereof) for the purposes stated in Art. 3); these parties will act as autonomous controllers or be designated as data processors.
- Dissemination of Personal Data
The Personal Data subject to Processing will never be published, displayed, or made available/accessible to unspecified persons.
Personal Data is processed within the European Union and is not transferred outside the European Economic Area. If, for technical and/or operational reasons, it becomes necessary to use subjects located outside this area, they will be appointed as external processors and the transfer of Personal Data will be limited to specific processing activities, in compliance with the GDPR, taking all necessary precautions to ensure full protection of Personal Data and based on appropriate safeguards.
In any case, the Data Subject may request more information from the Controller if Personal Data is processed outside the EU and may request evidence of the safeguards adopted.
- Data retention
Personal Data included in internal and external Reports and related documentation is retained for as long as necessary to pursue the Purposes and, in any case, no longer than five years from the date of the final outcome of the whistleblowing procedure (ex Art. 14 of Legislative Decree 24/2023), in accordance with confidentiality obligations under Article 12 of Legislative Decree 24/2023 and the principle in Article 5, paragraph 1, letter e) of Regulation (EU) 2016/679.
In order to manage possible disputes or litigation, and in any case for the establishment, exercise, or defense of legal claims, Personal Data may be retained for an additional period corresponding to the limitation period of such rights.
- Rights of the Data Subject
EU Regulation 2016/679 (Articles 15–22) grants the whistleblower and/or the person(s) involved in the report the right to exercise the rights provided for by the GDPR (the “Rights”), including:
- Right of access: the Data Subject has the right to access their Personal Data and related Processing. This includes the right to confirm whether or not Processing is taking place, to request and receive a copy of the data being processed, and to receive clarifications on the information in this notice;
- Right to rectification: the Data Subject has the right to obtain from the Controller the correction of inaccurate Personal Data without undue delay. Considering the Purposes, the Data Subject also has the right to have incomplete Personal Data completed, including by providing a supplementary statement;
- Right to erasure (“right to be forgotten”): the Data Subject has the right to request the deletion and cessation of Processing of their Personal Data, and in certain cases, to obtain the erasure without undue delay where the Processing purpose has expired, consent has been withdrawn, opposition has been raised, or Processing is otherwise non-compliant with the GDPR;
- Right to restriction of Processing: the Data Subject has the right to restrict the Processing of their Personal Data in the event of inaccuracies, objections, or as an alternative to deletion;
- Right to object: the Data Subject has the right to object at any time, for reasons related to their particular situation, to the Processing of their Personal Data, unless there are overriding legitimate grounds (e.g. for the establishment or defense of legal claims);
- Right to data portability: the Data Subject, unless the data is stored by non-automated means (e.g. paper format), has the right to receive their Personal Data in a structured, commonly used, and machine-readable format, when such data was provided by the Data Subject with explicit consent or based on a contract, and to request the transmission of that data to another controller, where technically feasible.
Where Processing is based solely on the Data Subject’s consent, and such consent has been provided, the Data Subject has the right to withdraw consent at any time by sending a written request to the Controller using the contact details above. Withdrawal of consent does not affect the lawfulness of Processing based on consent before withdrawal.
The response time for all Rights (including access rights), even in case of denial, is 1 month, extendable up to 3 months in particularly complex cases.
Furthermore, the Data Subject has the right to lodge a complaint with the Supervisory Authority if they believe their Rights have been violated. In Italy, this is the Italian Data Protection Authority. Pursuant to Article 2-undecies of Legislative Decree No. 196/2003 and subsequent amendments, and in implementation of Article 23 of the Regulation and Article 13, paragraph 2, of Legislative Decree 24/2023, Rights may be restricted if their exercise may result in actual and concrete harm to the confidentiality of the whistleblower’s identity.
In particular, the exercise of Rights may only take place in accordance with applicable law (Legislative Decree 24/2023) and may be delayed, limited, or excluded with a reasoned communication sent without delay to the Data Subject, in order to safeguard the confidentiality of the whistleblower’s identity.
