The Fondazione Compagnia di San Paolo (hereinafter referred to as the “Compagnia”), together with its Auxiliary Bodies and the consortium companies PR.I.S.MA and Xké? ZeroTredici, provides an internal reporting channel through which illicit conduct and/or violation of regulations can be reported in a confidential and reserved manner (i.e. whistleblowing).

The internal reporting channel, adopted in accordance with the provisions of Legislative Decree 24/2023 (hereinafter also the “Decree”), allows illicit conduct/violations to be reported through the channel both in written form or orally by a digital platform that can be reached at the following link:

https://whistleblowing-gruppofcsp.integrityline.com/

 

Reports may concern offences falling within the scope of Legislative Decree No. 231/2001 (see attached updated list of 231 offences) as well as breaches of European Union law as defined by the Decree (see attached explanatory note). Reports may also relate to violations of Model 231 and the Company’s Code of Ethics, both of which are available on the Company’s website. Please note that workplace harassment, discrimination and violence constitute breaches of the Code of Ethics and may therefore always be reported through this channel.

In accordance with the provisions contained in the Decree, reports may be submitted by employees, self-employed workers, collaborators, freelancers, consultants, volunteers, and trainees who work at the Compagnia, as well as by people who hold administrative, management, control, supervisory or representative positions within the Compagnia (i.e. whistleblowers).

The internal reporting channel allows reports to be submitted even in anonymous form, which will be processed only where they are found to be adequately detailed and capable of clearly bringing out facts and situations. Anonymous reports that appear to be groundless or unsubstantiated will not be processed.

Whistleblowers are protected by law against any form of retaliation related directly or indirectly to their reports.

The processing of personal data as part of the process of handling reports is carried out in compliance with the requirements of the Decree and the GDPR.

 

More information can be found in the “Procedure for handling reports (whistleblowing) according to Legislative Decree 24/2023” provided in an annex, together with the guide for the use of the digital platform.