Whistleblowing

Privacy Policy

INFORMATION PURSUANT TO ARTICLES 13-14 GDPR ON THE PROCESSING OF PERSONAL DATA - WHISTLEBLOWING

  1. Data Controller 

COMPAGNIA TECNICA MOTORI Ltd (hereinafter also "CTM" or "the Company") in the person of its legal representative, in its capacity as Data Controller, informs you that EU Regulation no. 2016/679 (so-called GDPR) and Legislative Decree 196/2003 and subsequent amendments govern the protection of personal data. CTM bases the processing of data on the principles of correctness, lawfulness, transparency and necessity, as required by the aforementioned legislation. To this end, pursuant to Articles 13-14 of the GDPR, we provide you with the following information.

  1. Type of data processed

The receipt and management of reports gives rise to the processing of so-called personal data. "common" (name, surname, job role, any other information related to the unlawful conduct, founded or presumed, as well as may give rise, depending on the content of the reports and the deeds and documents attached to them, to the processing of so-called "particular" personal data (data relating to health conditions, sexual orientation or trade union membership, pursuant to art. 9 GDPR) and personal data relating to criminal convictions and offences (pursuant to art. 10 GDPR).

  1. Purpose and legal basis of the processing 

Personal data are collected and processed for purposes strictly related to the management of reports of unlawful conduct, in violation of national/European regulations and, if adopted, of the Company's Code of Ethics and the Organization, Management and Control Model. Taking into account the relevant legislation (EU Directive no. 1937/2019 and Legislative Decree no. 24/2023), the legal basis for such processing is therefore represented by:

  • For the processing of common data, from art. 6.1 letter c) of the GDPR ("fulfilment of a legal obligation to which the data controller is subject"). 
  • For the processing of special and judicial data, from art. 9.2. letter g) of the GDPR.
  1. Methods of processing 

It is represented that the Data Controller undertakes to process, in a lawful, correct and transparent manner, only the data necessary to achieve the purposes indispensable for carrying out the activities covered by the report.
The processing is carried out by the Data Controller also with the aid of electronic means, including automated tools, and tools suitable for receiving reports in oral form equipped with appropriate security measures (file encryption), organizational, technical and physical, to protect the information from alteration, destruction, loss, theft or improper or illegitimate use. The reports and the documentation relating to their management will be retained for five years from the date of communication of the final outcome of the reporting procedure.
The identity of the reporting person and any other information from which such identity can be deduced, directly or indirectly, will be processed exclusively by persons authorised to process data pursuant to Article 29 of the GDPR and will not be disclosed to other parties without the specific consent of the same, as required by Article 12 no. 2 of the Decree. Consent is optional and is given when reporting via the platform.

  1. Communication and transfer of data

Your data will not be disclosed, but will be processed by the following parties, indicated by way of example and not limited to: 

  • public authorities in compliance with specific legal obligations and judicial authorities operating as independent data controllers 
  • external companies entrusted with the reporting management services and IT service providers, operating as Data Processors pursuant to art. 28 GDPR subject to confidentiality and only for purposes functional to the task assigned to them
  • Supervisory Body
  • Legal consultants possibly involved in the investigation phase
  • Any functions possibly involved in the preliminary investigation and investigation phase, specifically and for this purpose authorized and bound to confidentiality

The list of external Data Processors for the processing of personal data is available at the registered office of the Company.

  1. Rights of the interested party 

It is specified that, pursuant to articles 15 to 22 of the GDPR, it is possible to exercise, within the limits of article 2-undecies of the Privacy Code, the right to: 
a) access to personal data;
b) their rectification in case of inaccuracy;
c) the deletion of data;
d) the limitation of processing;
e) the right to data portability, i.e. to receive the personal data provided in a structured, commonly used and machine-readable format and to obtain the transfer to another Data Controller without impediments;
f) the right to object to processing, where the conditions are met. Furthermore, it is possible for the interested party to lodge a complaint with the Personal Data Protection Authority located in Piazza Venezia 11, 00187 Rome. For further clarifications regarding this information or on any privacy issue, or if you wish to exercise your rights, you can contact: ctm@ctm.it