Privacy Policy*
Privacy policy for processing personal data in relation to Whistleblowing
Each public or private body, required to set up a Whistleblowing channel, must provide information on the processing of personal data to potential data subjects, i.e. whistleblowers, reported persons, persons affected by the whistleblowing and facilitators.
Reports inherently constitute data processing, therefore, according to Italian Legislative Decree 24/2023 for the regulation of Whistleblowing and the protections granted to whistleblowers and to EU Regulation no. 679/2016 on the protection of personal data, we inform you that:
The Data Controller LE DUE VALLI S.R.L. with registered office at Via Strada Argine Mezzano, 34 - 44020 OSTELLATO (FE) - e-mail info@leduevalli.com – certified email address (PEC): pec@pec.leduevalli.com
Purpose and legal basis of the processing
We process data based upon:
- legal obligations, to comply with the obligations relating to the regulations in force and tasks of public interest
- request for consent, for processing operations relating to the obtainment of the identity of the whistleblower and storage for documentation purposes
When the processing is based upon a legal obligation, the provision of data is optional but necessary. In the event that you refuse to provide the data or allow their processing, the consequences are the following:
- the impossibility of managing the whistleblowing and the operations connected thereto;
- the impossibility to carry out some operations that imply communicating data to subjects functionally involved in execution of the same.
In the event of processing based on consent, you may revoke it at any time, without prejudice to the lawfulness of the processing based on the consent given before the revocation.
Method of processing
The processing shall be carried out using paper, computer and electronic tools and media in compliance with the provisions of the law, ANAC guidelines, regulations and company policies aimed at guaranteeing the security, confidentiality, availability and integrity, as well as the accuracy, updating and relevance of the data relating to the whistleblowing. The processing shall take place in compliance with the principles of fairness, lawfulness and transparency.
The data shall be processed by specifically authorized and trained internal personnel, and in the event that an external party is involved for the management of whistleblowing, the subject in question shall be as appointed as Data Processor through a regular contract as provided for by Italian Legislative Decree 24/2023 and art. 28 of EU Regulation no. 679/2016.
Recipients and data protection
The whistleblowing, therefore your data, must be made confidential also by encryption, with respect to the entire content of the whistleblowing including the documentation and, in particular, the identity of the whistleblower and the other people involved.
Therefore, the only recipients of the whistleblowing are the internal or external subjects who deal with the management of the same whistleblowing.
Retention time in relation to whistleblowing
The whistleblowing shall be kept for the time necessary to process the whistleblowing itself and in any event no later than 5 years from the date of communication of the outcome of the whistleblowing procedure.
Rights of the data subject
In relation to the aforementioned processing and the relevant data subject to whistleblowing, the data subjects may exercise their right of defence where requested and may exercise their rights relating to data processing (Articles 15 to 22 of EU Regulation no. 679/2016)
Right to lodge a complaint with a supervisory authority
In order to exercise the rights referred to in the previous points, you may contact directly the data processor (subject(s) appointed for the management of whistleblowing), who must give a feedback in writing within 90 days.
These rights can be exercised with a request addressed to: Le Due Valli s.r.l., Strada Argine Mezzano no. 34, 44020 Ostellato – email address: diritti.segnalante@leduevalli.com
In the event that you believe that the processing did not take place in compliance with the Regulation and Italian Legislative Decree 196/2003, you can contact the Italian Data Protection Authority, pursuant to Article 77 of the same Regulation. Further information regarding your rights to the protection of personal data can be found on the website of the Italian Data Protection Authority at www.garanteprivacy.it.