Regulations for reporting via the "Whistleblowing" protocol

Issued December 2025 - Download the PDF Make a report
The Legislature approved Law No. 179 of November 30, 2017, "Provisions for the protection of those who report crimes or irregularities of which they have become aware in the context of a public or private employment relationship," subsequently amended by Legislative Decree 24/23 "Provisions for the protection of those who report crimes or irregularities of which they have become aware in the context of a public or private employment relationship" (the so-called "Whistleblowing Law"), which defined:
  • the protection aspects of those who make a report;
  • the obligations of Entities and Companies; in terms of non-discrimination and protection of whistleblowers, related parties (e.g., colleagues and family members within the fourth degree), and so-called facilitators, with protection of their confidentiality;
  • the need for one or more channels (using electronic means) that allow reporting parties to submit reports while guaranteeing the confidentiality of the whistleblower's identity;
  • the prohibition of retaliatory or discriminatory acts against the whistleblower, related parties, and so-called facilitators for reasons related to the report;
  • the need to include sanctions in the disciplinary system against those who violate the whistleblower's protection measures, as well as of those who, with intent or gross negligence, make reports that prove to be unfounded;
  • the right to public reporting, in the cases specified.
The law also reiterates that reports of significant unlawful conduct or violations of the Company's organizational and management model, of which they have become aware by virtue of their duties, made by the reporting employee must be detailed and based on precise and consistent facts, of which they have become aware by virtue of their duties.
This instruction incorporates the requirements of Legislative Decree no. 24/2023, which implements Directive (EU) 2019/1937 and repeals certain provisions of Legislative Decree no. 231/2001 and Law no. 179/2017, broadening the potential scope of reporting.
Whistleblowing is the reporting of an internal matter or, in regulated cases, an external matter to the company who, in the performance of their duties, discovers the types of unlawful conduct identified by Legislative Decree 24/23, as specified below.
The Whistleblowing Law identifies:
  • the persons who can initiate a report;
  • the acts or facts that can be the subject of a report, as well as the requirements that reports must meet in order to be taken into consideration;
  • the methods through which to report alleged violations and the persons responsible for receiving reports;
  • the investigation and, where applicable, investigation process when a report is made;
  • the guarantee of confidentiality and protection of the personal data of the reporting party and any reported party, of the persons involved in the report, and of other persons protected by law;
  • the prohibition of retaliation and the prohibition of discrimination against the reporting party and other persons protected by law.
Reporting, protected by law, is a right of the reporting party.
The purpose of this document is to define the methods Operational procedures for managing reports and any resulting investigations, based on objective, precise, and consistent evidence, of unlawful conduct that has come to our attention as a result of our functions and/or duties.
By way of example and certainly not limited to, these may include acts or facts relating to conduct or behavior such as:
  • administrative, accounting, civil, or criminal offenses;
  • offenses relating to the application of certain national and EU acts, with reference to Annex 1;
  • acts or omissions that harm the EU's financial interests;
  • acts or omissions concerning the internal market;
  • acts or behaviors that frustrate the object and purpose of laws and regulations as well as those protecting the EU's financial interests and regulating the internal market.
  • False representation, falsification/concealment/destruction of financial, accounting/tax records, and other serious administrative or tax violations;
  • Payments and settlements to unauthorized parties and/or in violation of the internal authorization process, including for the purpose of internal fraud, theft, and embezzlement;
  • False signature on contractual documentation or dispositive forms;
  • Violations of provisions on corporate and financial transparency;
  • Violations of risk prevention rules and procedures in the fields of food safety, workplace safety, environmental protection, and data privacy;
  • Irregularities – These are not intended as actual violations, but rather situations or events that may constitute "concrete elements" (symptomatic indicators) – pursuant to art. 2, paragraph 1, letter b) of Legislative Decree 24/2023 – such as to lead the reporting party to believe that one of the violations provided for by the decree may be committed.
The following are excluded from the scope of the procedure:
  • reports of personal situations involving claims or complaints relating to relationships with superiors or colleagues, as well as relating to the performance of one's work;
  • reports based on mere suspicions or rumors concerning personal matters that do not constitute an offense: this is because it is It is necessary to take into account the interests of third parties subject to the information reported in the report, and to prevent the Company from carrying out internal inspections that risk being of little use and, in any case, costly.
The purpose of this document is to combat incidents of irregularity within the Company by clarifying and facilitating internal control through the use of protected reporting and by removing any factors that may hinder or discourage recourse to this procedure.
The objective of the procedure is therefore, on the one hand, to provide clear operational instructions regarding the subject, content, recipients, and methods of transmitting reports and, on the other, to disclose the protection and confidentiality, which are recognized and guaranteed.
The offices and functions involved in the activities The following are covered by this procedure:
  • All employees, including probationary employees, who may report violations pursuant to Legislative Decree 24/2023, of which they have become aware by virtue of their roles/duties;
  • Candidates (if information on violations was acquired during the selection process or other pre-contractual phases)
  • Former employees (if information on violations was acquired during the employment relationship);
  • Self-employed workers, collaborators, interns, and volunteers (including unpaid ones);
  • Chief Executive Officer, General Manager, shareholders, and persons with administrative, management, control, supervisory, or representation roles (including de facto);
  • Suppliers of goods and services and consultants;
  • Clients.
Legislative Decree 24/2023 requires the procedures for transmitting reports regarding conduct that could constitute the possible commission of unlawful acts to the persons responsible for monitoring the channel and the subsequent investigation.
To facilitate reporting, the following channels have been defined:
  • through the My Whistleblowing platform (see operating procedures in section 10), as the primary reporting channel suitable for guaranteeing, through electronic means, the confidentiality of the whistleblower's identity, in compliance with the legislation (hereinafter, the "Software"), in the manner indicated. specified at the bottom of this instruction;
  • via a dedicated voice messaging service, included in the IT platform;
  • via a double sealed envelope, inserting the reporting person's identifying information in the first envelope, along with an identity document (if the report is not anonymous);
in the second envelope, the subject of the report; both envelopes must then be placed inside a third envelope, sent to the Company with the name "PRIVATE PERSONAL - WHISTLEBLOWING REPORT," which the function responsible for sorting the mail must immediately and confidentially deliver to Progesa S.p.A. Viale Italia 21 46100 Mantua (external entity responsible for monitoring the canal), without opening the original packaging;
  • By requesting a direct meeting with the individuals responsible for managing the report. The responsible entity must Ensure that the meeting is held within a reasonable timeframe (within 10-15 days), prioritizing the hearing of the reporting party who has requested it in premises other than company premises (for example, those of the external manager).
Our Company will also consider anonymous reports, provided they are adequately detailed with regard to locations, times, and methods of execution, and are made in such a way as to highlight specific contexts (e.g., documentary evidence, indication of specific names or qualifications, mention of specific offices, particular proceedings or events, etc.).
The report—even if not anonymous—must be detailed and as complete and exhaustive as possible. The reporting party is therefore required to provide all available and useful information to allow the competent parties to proceed with the necessary and appropriate checks and investigations. Confirmation of the validity of the reported facts, such as:
  • a clear and complete description of the reported facts;
  • the circumstances of the time and place in which the reported facts were committed;
  • personal details or other information that allow identification of the individual(s) who committed the reported facts (e.g., qualification, place of employment where the activity was carried out);
  • any documents supporting the report;
  • the indication of any other individuals who can provide information on the reported facts;
  • any other information that may provide useful confirmation of the existence of the reported facts.
For a report to be substantiated, these requirements do not necessarily need to be present simultaneously. at the time of reporting, given that the reporting person may not have full access to all the requested information.
It is essential that the information indicated be known directly by the reporting person, having learned it in the workplace, and not reported or referred to indirectly by other parties.
Through the electronic channel and therefore via the software, the reporting person will be guided through each stage of the report and will be asked, in order to best substantiate the report, to fill out a series of mandatory fields that comply with the required requirements.
It should be emphasized that the software is designed to completely "anonymize" all the reporting person's data, allowing the reporting person to communicate with the individuals responsible for monitoring and any subsequent investigation in the strictest confidence: no company employee, including the company IT department and the platform manager itself (My Go S.r.l., the software provider), can have access to it. to the report data.
Limitations of the reporting party's liability
Further protection granted by the Decree to the reporting party is the limitation of their liability with respect to the disclosure and dissemination of certain categories of information, which would otherwise expose them to criminal, civil, and administrative liability.
In particular, the reporting party will not be held liable either under criminal, civil, or administrative law:
  • for disclosure and use of official secrecy (Article 326 of the Criminal Code);
  • for disclosure of professional secrecy (Article 622 of the Criminal Code);
  • for disclosure of scientific and industrial secrets (Article 623 of the Criminal Code);
  • for violation of duty of fidelity and loyalty (Article 2105 of the Italian Civil Code);
  • violation of the provisions relating to the protection of copyright;
  • violation of the provisions relating to the protection of personal data;
  • disclosure or dissemination of information on violations that damage the reputation of the person involved.
However, the Decree imposes two conditions on the application of the aforementioned limitations of liability:
  1. at the time of disclosure or dissemination, there are reasonable grounds to believe that the information is necessary to uncover the reported violation;
  2. the report is made in compliance with the conditions set forth in the Decree to benefit from protection against retaliation.
Where the acquisition constitutes a crime, If you suspect unauthorized access to a computer system or an act of computer piracy, the reporting person remains subject to criminal liability and any other civil, administrative, and disciplinary liability.
Progesa S.p.A., which has been entrusted with managing the reporting channel, will issue the reporting person, if channeled through the My Whistleblowing® platform or through methods that allow for a response, an acknowledgement of receipt of the report within 7 days of receipt.
The procedure initiated following receipt of the report must be concluded, with a response provided, within 3 months of the date of the acknowledgement of receipt.
The investigation may be entrusted to different parties, even in a sequential phase, with an initial "triage" phase and initial qualification of the reported case, and a second phase of formal investigation and assessment of the specific case.
If it is not possible to entrust this activity to internal functions while guaranteeing the independence requirements, it will be performed by the competent authorities. The report will be entrusted to competent external professionals to ensure independent assessment.
Once the report has been received through the channels established in this procedure, the appointed party will initiate a preliminary investigation, which aims to verify the report's relevance to the circumstances governed by Legislative Decree 24/23 and the validity of the received report.
An initial screening will then be performed and:
  • If it is immediately determined that the report is clearly unfounded or not in compliance with the provisions of Legislative Decree 24/23, the appointed party will report it to the relevant corporate bodies or supervisory bodies, informing the reporting party and thus ensuring the appropriate action is taken. closing the preliminary assessment process;
  • If the report appears to be well-founded but not well-substantiated, the company requests, where possible, further information from the reporting party. If it is not possible to gather sufficient information to substantiate the report and initiate an investigation, due to the reporting party's failure to respond or cooperate, the report is archived, informing the reporting party accordingly, thus closing the preliminary assessment process;
  • If the report appears to be within its jurisdiction and substantiated with precise and consistent factual elements, the company will proceed with a formal investigation.
The investigation is the set of activities aimed at verifying the content of the reports received and acquiring useful information for the subsequent assessment phase, ensuring maximum confidentiality regarding the identity of the reporting party. of the reporting party and the subject of the report. The purpose of the investigation is to verify the reliability of the information investigated, providing a detailed description of the facts ascertained through audit procedures.
A final report must be prepared for each investigation containing:
  • the facts ascertained;
  • the evidence collected;
  • to the extent possible to verify, the causes and deficiencies that allowed the reported situation to arise.
Following the investigation, the appointed person:
  • As mentioned in the previous point, when the report received is found to be unfounded or irrelevant, the report is archived, where possible, and the reporting party is notified. In the event of a confirmed violation of internal rules and/or procedures that do not fall within the scope of Legislative Decree 24/23, the reporting party may be advised to file a subsequent report through ordinary hierarchical channels. In more serious cases, where legal risks are identified, even if they fall outside the scope of Legislative Decree 24/23, the person in charge of the investigation must nevertheless file a report to the Board of Directors and the Board of Statutory Auditors.
  • If the report is found to be well-founded, the person in charge completes the investigation and transmits the results to the Chief Executive Officer or the Board of Directors for further action. appropriate mitigating and/or corrective actions, as well as the possible initiation of disciplinary proceedings aimed at imposing, if necessary, disciplinary sanctions in line with the provisions of the applicable legislation and the Internal Disciplinary and Sanctioning Regulations, with reference to the provisions of the National Collective Bargaining Agreement;
  • provides a report to the Board of Statutory Auditors, respecting the institution's confidentiality, also in order to allow the Corporate Bodies to evaluate the appropriateness of filing a complaint with the judicial authorities, in the manner established by law.
In order to guarantee the traceability, confidentiality, preservation, and retrievability of data throughout the proceedings, documents are stored and archived both in digital format, via the software, and in password-protected network folders, as well as in paper format, in a dedicated archive. Except in special cases (for example, the initiation of criminal or administrative proceedings), all documentation will be retained for five years from the date of filing and will subsequently be destroyed.
Pursuant to applicable law and company privacy procedures, the processing of personal data of persons involved and/or cited in reports is managed not only in accordance with the provisions of this Regulation, but also in general compliance with the GDPR pursuant to EU Regulation 679/16, by performing an impact analysis. The Company will also prepare a specific "Privacy Policy for Whistleblowing Reporting" for reporting parties and appoint "Data Processors."
If the company uses a shared reporting channel by law, a "data protection" agreement will be formalized by the Joint Data Controllers pursuant to art. 13, paragraph 5 of Legislative Decree no. 24/2023 and art. 26 of Regulation (EU) 679/2016 and 23 of Legislative Decree 51/2018.
If a violation is reported, the report must be submitted primarily through the internal channel (according to the procedures indicated in paragraph 6 and only under the conditions set forth in Legislative Decree 24/2023), with external disclosure.
In accordance with Legislative Decree no. 24 of 2023 (Article 6), the reporting person may make an external report (to the National Anti-Corruption Authority – ANAC) if at least one of the following conditions is met:
a) when the internal report has not been followed up, or the reporting person has reasonable grounds to believe that it will not be effectively followed up or will entail a risk of retaliation;
b) when the subject of the report may be of interest to the public. Constitute an imminent or manifest danger to the public interest.
External reporting may be made by accessing the dedicated electronic channel introduced by the National Anti-Corruption Authority (ANAC), available at the following link: https://whistleblowing.anticorruzione.it
The whistleblower is also entitled to make a public disclosure (e.g., through the press) if an internal or external report has already been filed but has not been followed up, or in the event of imminent or manifest danger to the public interest, or in the presence of a risk of retaliation or a risk that the report will not be followed up.
  1. Access the dedicated "Whistleblowing" section by filling out the form with your name, surname, and a personal email address (please do not use your company email address, as required by the Privacy Guarantor). This email address will be used only to verify the actual existence of the whistleblower, but will be "anonymized" by the platform. This way, the whistleblower will be able to communicate with the appropriate individuals in an absolutely confidential manner.
  2. Follow the instructions received in the email containing your Unique Access Credentials
  3. Log in to your account with your credentials
  4. Proceed by clicking the "CREATE REPORT" button
  5. You will be notified immediately. At this point, it is possible to proceed with the report.
(a) anonymously using the appropriate option:
(b) or, non-anonymously, but in any case with the confidentiality guarantees set out above.
6. Once the reporting method has been established, the reporting person will proceed by filling out the form. Fields marked with * are mandatory. Some fields are open and must have a minimum number of characters.

Annex 1
List of Union acts and national implementing provisions to which the private sector entities indicated in Article 2, paragraph 1, letter q) n. 2 of Legislative Decree 24/2023 must refer to for the purposes of their inclusion within the subjective scope of application of the decree.
List of EU acts and national implementing provisions to which the private sector entities indicated in Article 2, paragraph 1, letter q) no. 2 of Legislative Decree 24/2023 must be referenced for the purposes of their inclusion within the scope of application of the decree.
Private sector entities required to apply the EU acts and national implementing provisions indicated in Parts I.B and II of Annex 1 to Legislative Decree 24/2023, regardless of the number of workers employed, fall within the scope of application of Legislative Decree 24/2023.
To allow for the identification of these entities, the European Union acts and national implementing provisions relating to the two aforementioned Sections I.B and II are listed below in schematic form.
It should be noted, however, that the reference to the aforementioned acts is to be understood as "dynamic."
It follows that if the act is amended or replaced, the reference refers to the amended act or the new act.
The sectors of interest, the European Union acts, and the national implementing provisions are listed below in a schematic form.

Part I B Annex to Legislative Decree 24/2023
SECTOR SECTORS, EU ACTS AND RELATED NATIONAL IMPLEMENTING PROVISIONS
Financial services, products, and markets and prevention of money laundering and terrorist financing
Consumer and investor protection: Regulations specified in Annex 1, Part I,
lett. B
  • in the financial services and capital markets of the Union;
of Legislative Decree 24/2023
Protection in the sectors:
  • Banking
  • Credit
  • Investment
  • Insurance and reinsurance
  • Occupational pensions or individual pension products,
  • Securities
  • Investment funds,
  • Payment services and financial services benefiting from mutual recognition (Annex 1 of Directive 2013/36/EU).

Part II Annex to Legislative Decree 24/2023
SECTOR EU ACTS AND RELATED NATIONAL IMPLEMENTING PROVISIONS
Financial Services
I. Legislative Decree No. 47 of 16 April 2012, implementing Directive 2009/65/EC on the coordination of laws, regulations, and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS); Article 8 of Legislative Decree No. 24 February 1998. 58 of 27 January 2010, containing the consolidated text of the provisions on financial intermediation, pursuant to Articles 8 and 21 of Law No. 52 of 6 February 1996;
II. Legislative Decree No. 147 of 13 December 2018, implementing Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision;
III. Legislative Decree No. 39 of 27 January 2010, implementing Directive 2006/43/EC on statutory audits of annual accounts and consolidated accounts, amending Directives 78/660/EEC and 83/349/EEC, and repealing Directive 84/253/EEC;
IV. Regulation (EU) No. 596/2014 of the European Parliament and of the Council of 16 April 2014 on market abuse (Market Abuse Regulation) and repealing Directive 2003/6/EC of the European Parliament and of the Council and Commission Directives 2003/124/EEC, 2003/125/EEC, and 2004/72/EC (OJ L 173, 12.6.2014, p. 1);
See Legislative Decree No. 72 of 12 May 2015 implementing Directive 2013/36/EU, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC, as regards access to the activity of financial intermediaries. of credit institutions and the prudential supervision of credit institutions and investment firms.
Amendments to Legislative Decree No. 385 of September 1, 1993, and Legislative Decree No. 58 of February 24, 1998;
VI. Legislative Decree No. 18 April 2016 71, implementing Directive 2014/91/EU, amending Directive 2009/65/EC on the coordination of laws, regulations, and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS), with regard to depositary functions, remuneration policies, and sanctions, and implementing, with regard to certain sanctioning provisions, Directive 2014/65/EU on markets in financial instruments and amending Directives 2002/92/EC and 2011/61/EU.
VII. Legislative Decree 3 August 2017, no. 129, implementing Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU, as amended
by Directive 2016/1034/EU of the European Parliament and of the Council of 23 June 2016, and adapting national legislation to the provisions of Regulation (EU) No. 600/2014 of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Regulation (EU) No. 648/2012, as amended by Regulation (EU) 2016/1033 of the European Parliament and of the Council of 23 June 2016;
VIII. Regulation (EU) No. 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 (OJ L 257, 28.8.2014, p. 1);
IX. Regulation (EU) No 1286/2014 of the European Parliament and of the Council of 26 November 2014 on key information documents for packaged retail and insurance-based investment products (OJ L 352, 9.12.2014, p. 1);
X. Regulation (EU) No 2365/2015 of the European Parliament and of the Council of 25 November 2015, on transparency of securities financing transactions and reuse and amending Regulation (EU) No. 648/2012 (OJ L 337, 23.12.2015, p. 1);
XI. Legislative Decree No. 68 of 21 May 2018, implementing Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution;
XII. Regulation (EU) No. 1129/2017 of the European Parliament and of the Council of 14 June 2017 on the prospectus to be published when securities are offered to the public or admitted to trading on a regulated market and repealing Directive 2003/71/EC (OJ L 168, 30.6.2017, p. 12).
Prevention of money laundering and terrorist financing:
I. Legislative Decree No. 90 of 25 May 2017, implementing Directive (EU) 2015/849 on the prevention of the use of the financial system for the purpose of money laundering and terrorist financing, amending Directives 2005/60/EC and 2006/70/EC and implementing Regulation (EU) No. 2015/847 on information accompanying transfers of funds and repealing Regulation (EC) No. 1781/2006;
II. Regulation (EU) No. 847/2015 of the European Parliament and of the Council of 20 May 2015 on information accompanying transfers of funds and repealing Regulation (EC) No. Regulation (EC) No 1781/206 (OJ L 141, 5.6.2015, p. 1).
Transport safety
I. Regulation (EU) No 376/2014 of the European Parliament and of the Council of 3 April 2014 on the reporting, analysis and follow-up of occurrences in civil aviation, amending Regulation (EU) No 996/2010 of the European Parliament and of the Council and repealing Directive 2003/42/EC of the European Parliament and of the Council and Commission Regulations (EC) No 1321/2007 and (EC) No 1330/2007 (OJ L 122, 24.4.2014, p. 18);
II. Legislative Decree of 15 February 2016, No. 32,
implementing Directive 2013/54/EU of the European Parliament and of the Council of 20 November 2013 on certain flag State responsibilities for compliance with and enforcement of the Maritime Labour Convention, 2006;
III. Legislative Decree No. 53 of 24 March 2011 implementing Directive 2009/16/EC laying down international standards for ship safety, pollution prevention, and onboard living and working conditions for ships using Community ports and sailing in waters under the jurisdiction of the Member States.
Environmental Protection
I. Legislative Decree No. 145 of 18 August 2015 implementing Directive 2013/30/EU on safety of offshore oil and gas operations and amending Directive 2004/35/EC.

Technological Revamping 4.0 project, code C85H22001440008, funded as part of the Union's response to the COVID-19 pandemic