PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
pursuant to art. 13 and 14 of Regulation (EU) 2016/679
(General Data Protection Regulation so-called "GDPR")
Dompé farmaceutici S.p.A., in its capacity as "Data Controller” (hereinafter "Dompé", "Company" or "Data Controller"), wishes to inform data subjects on how the personal information contained in the whistleblowing report is collected through a platform (hereinafter the "Platform"), both via telephone line and online, at the disposal of Dompé employees and third parties (e.g. contractors, consultants, suppliers, etc.) in order to report any suspected unlawful conduct, irregularities and/or violations related to business activities specified in Dompé's Code of Conduct, policies, procedures, laws and regulations and on how the personal information collected is processed by Dompé.
Data Controller: Dompé farmaceutici S.p.A., with registered office in Via San Martino 12, 20122 Milan (MI); tel.: 02583831, email: privacy@dompe.com
Data Protection Officer: the Company employs a data protection officer (also known as a Data Protection Officer "DPO"). The DPO can be contacted via the following communication channel: dpo@dompe.com.
Categories of personal data
Personal data are contained in the report and in any documents attached thereto, and may relate to the whistleblower himself, to the natural persons to whom the alleged unlawful conduct is ascribed and / or other natural persons in any case mentioned in the report or whose identity can be inferred, as well as possibly to other subjects such as the Manager assisting the whistleblower.
Personal data are as follows:
Common data: identifiers (first name, surname), contact details (e-mail, telephone number), job role, other elements of personal identification.
Special categories of personal data: data that may reveal racial or ethnic origin, religious or philosophical beliefs, political opinions, membership of parties or trade unions, data relating to health and sex life.
Judicial data: judicial data, such as hypotheses of crime, pending charges, criminal records, integrity requirements, status of suspect/accused, pending charges of administrative offenses dependent on crime, pursuant to art. 10 GDPR.
Sources of personal data
The data are collected from the whistleblower through the Platform, both the reporting web platform and the telephone channel, by virtue of which the report will be received and transcribed.
Purpose, legal basis of processing and retention period of personal data
1) Reporting management
The processing of personal data will take place to manage the report carried out pursuant to Legislative Decree no. 24/2023, and in particular in order to:
- acquiring, receiving and managing reports, including those concerning offences falling within the scope of Legislative Decree no. 24/2023, also through the Dompé Internal Committee specifically set up to manage reports and carry out investigations and/or the Supervisory Body;
- carry out the investigation, verification, supervision and in-depth activities necessary to ascertain the validity of the reports, also through collaboration with the competent public authorities where required by law;
- adopt, where necessary, appropriate disciplinary measures and take appropriate administrative, civil, criminal and/or judicial action against those responsible for the unlawful conduct;
- carry out the communications and obligations required by applicable legislation, including those provided for by art. 5, paragraph 1, of Legislative Decree no. 24/2023;
- guarantee the protection of the whistleblower and other protected persons pursuant to Legislative Decree no. 24/2023, in compliance with the confidentiality measures provided for by law.
Legal basis: the processing is necessary to comply with a legal obligation to which the controller is subject (Art. 6.1 (c) GDPR).
The processing of special data is necessary for the fulfilment of the obligations and exercise of the specific rights of the controller or the data subject in the field of labour and social security and social protection law, insofar as it is authorised by Union or Member State law or by a collective agreement, where appropriate safeguards are in place for the fundamental rights and interests of the data subject (Art. 9.2(b) GDPR).
Retention period: Personal Data will be processed for the time strictly necessary to pursue the purposes indicated or required by law. In any case, the storage of such data will not exceed a period of 5 years from the date of communication of the final outcome of the reporting procedure (pursuant to Article 14, Legislative Decree No. 24/2023), unless the law or judicial protection requirements impose a longer term.
2) Compliance with legal and regulatory obligations
The data will be processed to meet legal and regulatory obligations.
Legal basis: the processing is necessary to comply with a legal obligation to which the controller is subject (Art. 6.1 (c) GDPR).
Retention period: the data will be retained for the duration specified by the applicable legislation.
3) Establishing and safeguarding the legal interests of the Data Controller both judicially and extrajudicially
Your personal data may be processed when necessary to establish or protect the Data Controller’s rights—both in and out of court.
Legal basis: the processing of personal data is necessary for the purposes of the legitimate interest pursued by the Controller, such as in the possible legal defense of the rights and interests of the Company (art. 6.1 (f) GDPR).
Retention period: the data will be kept for as long as necessary for the preparation and conduct of legal action, including appeals, until a final ruling is made or the limitation period of the rights and/or actions expires, including any terms provided for in the insurance contracts.
Nature of the provision of data
The provision of this information is optional, as the Platform allows you to send reports anonymously.
If the whistleblower communicates personal data, the Data Controller will process them for the pursuit of the purposes indicated above.
Persons authorised to process
Personal data will be processed, in accordance with articles 29 of the GDPR and 2-quaterdecies of Legislative Decree 196/2003 (Privacy Code) by authorized personnel of the Company who have been given adequate operating instructions in order to avoid loss, destruction, unauthorized access or unauthorized processing.
Personal data may also be processed by external parties, specifically appointed as data processors, pursuant to art. 28 GDPR, such as the company that provides and manages the web and telephone platform as well as the database in which the data are stored, consulting firms, information system providers, companies of the Dompé Group.
Recipients of the data
Your personal data may be communicated to the following categories of third parties, independent data controllers, by virtue of legal obligations or specific contractual agreements in place, such as, by way of example, law firms and public authorities competent in the exercise of their powers.
The updated list of recipients is available upon request to privacy@dompe.com.
Data transfers outside the EU or EEA
The Data Controller acknowledges that your personal data may be processed by companies of the Dompé Group or by third parties, located in countries also outside the European Union, such as the United States of America and Albania. In these circumstances, the transfer will take place on the basis of standard contractual clauses as approved by the European Commission.
The updated list of recipients of the data and appropriate safeguards is available upon request to privacy@dompe.com
Rights of Data Subjects
At any time, the interested party may obtain confirmation of the existence or otherwise of the processing of your personal data and to know its content and origin, request its integration or correction or, in the cases provided for by law, portability, limitation of processing, erasure of processed data, anonymization, as well as to object, for legitimate reasons, to their processing. To exercise your rights, you may contact privacy@dompe.com
Complaint to the Data Protection Authority
The data subject also has the right to lodge a complaint with the Data Protection Authority if he/she believes that his/her rights have not been respected or that he/she has not received a response to his/her requests.
Updated Version: September, 2026