1Version control
| Company | doValue Spain Servicing, S.A.U. |
|---|---|
| Title | Internal Information System Policy |
| Version | V.3.1 |
| Document | Policy 6 |
| Produced by | Compliance Officer |
| Date of Approval | 15/09/2026 |
| Person responsible for approval | Compliance Officer |
| Date of ratification | 09/2026 |
| Responsible for ratification | Board of Directors of doValue Spain |
| Amended or repealed policies or regulations | Internal Information System Policy V.3.0 |
| Changes in this version | Update to the version control section, including typo corrections |
| Date of last update | 15/09/2026 |
Version history
| Version | Reason for the Change | Person in charge | Date of approval | Date of ratification |
|---|---|---|---|---|
| 1.0 | Initial Version | Regulatory Compliance | 16/06/2023 | NA |
| 2.0 | Version 2: - Replacement of the Head of the Internal Information System with a collegiate body to be known as the Internal Information System Committee (CSII), and consequential amendments. - Point 4 now sets out the purpose of the Internal Reporting System, access to and operation of the system, and external reporting channels. - Point 5 now sets out the principle prohibiting reprisals against whistleblowers and related third parties. | Regulatory Compliance | 16/03/2026 | NA |
| 3.0 | Various sections have been updated to bring them into line with the AIPI’s recommendations and certain details of Act 2/2023. In addition, the key time limits set out in Act 2/2023 have been incorporated. | Compliance Officer | 31/07/2026 | NA |
| 3.1 | Update to the version control section, including typo corrections | Compliance Officer | 15/09/2026 | 09/2026 |
2Purpose
The purpose of this Policy is to set out the principles, responsibilities and general rules governing the operation of the Internal Reporting System (hereinafter the “SII”) of doValue Spain Servicing, S.A.U. (hereinafter collectively referred to as “doValue”, “DVSP”, the “Organisation” or the “Company”) and its subsidiaries.
The SII is the preferred channel for reporting and managing information regarding acts or omissions that may constitute infringements of European Union law, serious or very serious criminal or administrative offences, breaches of the Code of Conduct or applicable internal regulations, as well as any other conduct contrary to the Organisation’s ethical and compliance principles.
Furthermore, this Policy sets out the guiding principles, safeguards for the protection of whistleblowers and other affected persons, as well as measures designed to ensure confidentiality, independence, freedom from reprisals and the proper handling of reports received through the Internal Reporting System.
This Policy sets out the requirements laid down in Act 2/2023 of 20 February, governing the protection of persons who report breaches of regulations and the fight against corruption, and is supplemented by the Internal Reporting System Management Procedure, which governs the operational functioning of the system and the handling of reports received.
3The Organisation’s Commitment
doValue and its subsidiaries are firmly committed to ethics, integrity, transparency and regulatory compliance as fundamental principles of their corporate governance model and organisational culture.
Within this framework, the Organisation promotes an environment in which everyone can report, in good faith and without fear of reprisal, any conduct, action or omission that may contravene applicable legislation, the Code of Conduct or the Organisation’s internal regulations.
In order to reinforce these principles and facilitate the early detection of potential breaches, the Board of Directors of doValue Spain Servicing, S.A.U. has implemented an Internal Reporting System and approved this Policy, providing stakeholders with appropriate channels for receiving and handling reports, whilst ensuring at all times the confidentiality, the protection of whistleblowers, impartiality in the conduct of investigations and respect for the rights of all those involved.
Furthermore, the Organisation reaffirms its commitment to prohibiting any form of retaliation against those who, acting in good faith and on reasonable grounds, report or disclose information regarding possible breaches, thereby promoting a culture based on accountability, trust and the continuous improvement of control and compliance systems.
The Organisation shall take the necessary measures to ensure the proper functioning of the Internal Information System, the availability of the resources required for its effective management, and compliance with the requirements set out in the regulations in force at any given time.
4 Scope of approval, implementation and updates
4.1 Approval
This Policy forms part of the Internal Reporting System of doValue and its subsidiaries, having been approved by the respective governing bodies of the companies required to implement it, in accordance with the provisions of Law 2/2023 of 20 February, which regulates the protection of persons reporting breaches of regulations and the fight against corruption.
Furthermore, it is the responsibility of the governing bodies to appoint and, where appropriate, remove the Head of the Internal Reporting System, as well as to exercise general oversight of its proper functioning.
4.2 Implementation
This Policy is binding on doValue and its subsidiaries, as well as on all members of the Organisation, including members of the governing bodies, senior management, employees, agency staff, interns, trainees and any other person carrying out their professional activities under the direction, supervision or control of the Organisation.
Furthermore, the Organisation will promote awareness of, and compliance with, the principles set out in this Policy amongst suppliers, contractors, external collaborators, business partners and any third parties with whom it maintains professional or commercial relationships.
All persons subject to this Policy must comply with its provisions, regardless of their position, role, type of employment relationship or geographical location from which they carry out their work.
4.3 Updates
This Policy will be reviewed periodically to ensure that it remains in line with applicable legislation, the Organisation’s organisational structure, the recommendations of the competent authorities and the requirements arising from the effective operation of the Internal Reporting System.
Substantial amendments must be approved by the relevant governing body. Amendments of a purely organisational, operational or documentary nature which do not alter the essential principles of this Policy may be proposed by the Internal Reporting System Committee (CSII) for approval by the Compliance Officer.
5Scope
The purpose of this Policy is to set out the principles, safeguards and operating rules of the Internal Reporting System of doValue and its subsidiaries, and to regulate the protection of individuals who report or publicly disclose information regarding breaches in accordance with the provisions of Law 2/2023.
The protective measures set out in this Policy shall apply, as appropriate, to:
- The Informants.
- Related third parties.
- The workers’ legal representatives when acting in an advisory and supportive capacity towards the whistleblower.
- Those affected by the Communication.
For the purposes of this Policy, ‘Whistleblowers’, ‘Related Third Parties’ and ‘Persons Affected by the Report’ shall be deemed to be those who meet the requirements and conditions set out in Law 2/2023 and in the following sections of this Policy.
6 Definitions
For the purposes of this Policy, the following definitions shall apply:
Communication
Information submitted via the Internal Reporting System concerning events, conduct or omissions that may constitute breaches falling within the scope of this Policy.
Internal Information System (SII)
An integrated set of principles, procedures, resources, personnel and channels established by the Organisation for the receipt, management, investigation and follow-up of communications made within the framework of this Policy.
Informant
An individual who publicly reports or discloses information regarding infringements obtained in a work or professional context and who meets the conditions set out in Law 2/2023. The following, amongst others, shall be regarded as whistleblowers: employees, self-employed persons, shareholders, members of the administrative, management or supervisory bodies, persons working for or under the supervision of business partners, volunteers, trainees, persons undergoing training, and those whose employment or professional relationship has ended or has not yet commenced.
Person affected by the Communication
A natural or legal person to whom the facts, acts or omissions described in a report received via the Internal Reporting System are attributed.
Related third parties
Individuals or legal entities associated with the Whistleblower who may face reprisals in a work or professional context as a result of a report, including, amongst others, colleagues, family members, employees’ legal representatives or organisations with which the Whistleblower has a significant professional relationship.
Head of the Internal Information System
The body responsible for the supervision and operation of the Internal Reporting System, appointed by the Board of Directors in accordance with Act 2/2023. At doValue, this role is carried out by the Internal Reporting System Committee (CSII).
Internal Information System Committee (CSII)
A collegiate body appointed as the Head of the Internal Information System, responsible for overseeing the proper functioning of the System, ensuring compliance with this Policy and taking any decisions necessary for its correct implementation.
System Representative
A member of the CSII appointed to carry out the day-to-day management of the Internal Information System, including the receipt and processing of communications, the coordination of investigations, the maintenance of the relevant records and the implementation of the measures entrusted to them by the CSII.
Public disclosure
Making information on infringements available to the public in accordance with the terms and conditions set out in Law 2/2023.
Retaliation
Any act or omission, threat or attempt, prohibited by the applicable legislation, which causes or is likely to cause unjustified harm to a person as a result of that person having made a protected public communication or disclosure.
Conflict of interest
A situation in which a person’s personal, professional or financial interests may compromise, or appear to compromise, their impartiality, independence or objectivity in the handling or resolution of a complaint.
Good faith and reasonable grounds
For the purposes of this Policy, a report shall be deemed to have been made in good faith where the whistleblower has reasonable grounds to believe that the information provided is true at the time it is submitted, regardless of whether the facts are subsequently substantiated or not.
7Head of the Internal Information System
The appointment of a System Manager fulfils the obligation set out in Article 8 of Law 2/2023 of 20 February, governing the protection of persons who report breaches of regulations and the fight against corruption.
The Board of Directors of doValue Spain Servicing, S.A.U. has appointed the Internal Reporting System Committee (CSII) as the body responsible for the Internal Reporting System. The CSII is a collegiate body which acts autonomously and independently in the performance of its duties and possesses the necessary expertise, integrity, authority and resources to ensure the proper functioning of the Internal Reporting System.
The CSII is the body responsible for the overall supervision of the Internal Information System, for monitoring its operation and for taking any decisions necessary to ensure compliance with this Policy and the applicable regulations.
The composition of the CSII will be as follows:
- Head of Legal Affairs and Data Protection Officer
- Head of Control & ERM and Compliance Officer
- Claims Management Coordinator
- Head of Labour Relations
- Senior Health and Safety Specialist
In order to facilitate the day-to-day management of the Internal Information System, the CSII shall appoint a delegate from amongst its members, who shall be responsible for the operational management of the system, receiving and processing communications, coordinating investigative actions and carrying out any other functions expressly entrusted to them by the Committee, without prejudice to the powers and responsibilities incumbent upon the CSII itself as the Data Controller of the system.
Where there is a conflict of interest, absence, vacancy or any other circumstance that could compromise the independence or impartiality of any of its members, that member must refrain from participating in the management or decision-making relating to the matter in question, and it shall be the responsibility of the remaining members of the Committee to take the necessary measures to ensure the proper handling of the case.
The appointment, dismissal and any changes to the composition of the CSII or to the person to whom the powers to manage the System are delegated shall be notified to the Independent Whistleblower Protection Authority (A.A.I.) in accordance with the terms and time limits laid down in the applicable regulations.
8SII and external information channels
8.1 doValue’s Internal Information System
Purpose. doValue has an internal reporting system comprising various channels set up to receive and manage reports concerning incidents or conduct that come to light in a work or professional context
The following types of behaviour, amongst others, may be reported via the Internal Reporting System:
- Infringements of European Union law falling within the scope of Directive (EU) 2019/1937 and Law 2/2023 of 20 February
- Serious or very serious criminal or administrative offences.
- Breaches of the Organisation’s Code of Conduct.
- Breaches of internal regulations, procedures, corporate policies or any other conduct that is irregular, fraudulent or contrary to the Organisation’s ethical and compliance principles.
The Internal Reporting System is the preferred channel for reporting this type of conduct and is designed to facilitate its early detection, assessment, investigation and, where appropriate, the adoption of the necessary corrective or disciplinary measures.
Notwithstanding the foregoing, not all reports received via the Internal Reporting System will fall within the scope of protection provided for by Law 2/2023. In particular, reports relating exclusively to breaches of the Code of Conduct or internal regulations which do not constitute infringements of European Union law or serious or very serious criminal or administrative offences will be handled through the System, but will not automatically trigger the protective measures specifically provided for in the aforementioned Act.
However, the Organisation shall in all cases ensure the confidentiality of the information received, the protection of the personal data processed, and the diligent and impartial handling of communications, in accordance with the provisions of this Policy and the applicable regulations.
The decision as to whether a communication falls within or outside the scope of protection under Act 2/2023 shall be taken by the Internal Whistleblowing Scheme Committee or by the person to whom the Committee has delegated responsibility for managing the Scheme, in accordance with the applicable internal procedure.
Access and operation. The Organisation has an Internal Reporting System comprising various channels set up to receive and handle reports concerning incidents or conduct occurring in a work or professional context.
Reports may be submitted either by name or anonymously; in all cases, the confidentiality of the identity of the reporter, the persons affected by the report and any related third parties will be guaranteed, as will the protection of any personal data processed.
Communications may be made in writing, verbally or by requesting a face-to-face meeting, in accordance with the provisions of this Policy and the Internal Information System Management Procedure.
The channels established by the Organisation for the submission of communications are as follows:
- doValue: https://dovalue.whistlelink.com/
- TEAM4: https://team4.canalhelas.com/home
Where a report is submitted via the platforms set up for this purpose, the system may generate reference numbers or tracking mechanisms that will enable the reporter to check the status of the report and respond to any requests for information addressed to them.
For cases relating to workplace harassment, sexual harassment or cyberbullying, the Organisation has specific channels in place, managed in accordance with the provisions of the Protocol on the Prevention of Workplace Harassment, Sexual Harassment and Cyberbullying. These channels form part of the Organisation’s overall control framework and shall be managed in accordance with the applicable specific procedure, without prejudice to the general oversight exercised by the Internal Reporting System Committee (CSII).
Furthermore, the whistleblower may request an in-person meeting with the person appointed by the CSII or with any other member designated by the CSII. The meeting must take place within the legally established time limit, that is, within a maximum of seven (7) days of the request, in accordance with Law 2/2023, and shall be documented either by means of a recording, subject to the whistleblower’s prior consent, or by means of a full and accurate transcript of its contents, which may be reviewed, corrected and accepted by the whistleblower themselves.
Where a report is received by any member of the CSII or by any other person within the Organisation other than the person designated to manage the System, it must be forwarded immediately and confidentially to that designated person, in order to ensure that the procedure is followed correctly and that the rights of whistleblowers, affected individuals and relevant third parties are protected.
All communications received will be handled in accordance with the provisions of the Internal Reporting System Management Procedure, ensuring compliance with the obligations regarding confidentiality, data protection, independence, objectivity and freedom from reprisals set out in the applicable regulations and in this Policy.
Reports may be submitted via the main channels of the Internal Reporting System or via other corporate channels specifically set up for certain matters. In all cases, communications falling within the scope of this Policy shall be incorporated into the Internal Information System and handled in accordance with the Internal Information System Management Procedure.
8.2 External information channels
Without prejudice to the use of the Organisation’s Internal Reporting System, whistleblowers may report breaches falling within the scope of Law 2/2023 directly to the Independent Whistleblower Protection Authority (A.A.I.) or to any other competent authorities or bodies that may be applicable in each case.
The Organisation will make up-to-date information available to potential whistleblowers regarding the external reporting channels established by the competent authorities, and will facilitate access to these channels through the appropriate corporate channels.
The following channels, amongst others, may be used:
- External channel of the Independent Whistleblower Protection Authority (A.A.I.): https://www.proteccioninformante.gob.es/canales-de-presentacion-de-informaciones
- External channels authorised by the relevant regional authorities: https://www.proteccioninformante.gob.es/informacion-sobre-otros-canales-externos-de-informacion
- External channels established by European Union bodies, institutions or authorities, where applicable.
The use of external information channels shall not require prior use of the Organisation’s Internal Information System.
9 Principles of the Internal Information System
This Policy has taken into account the most advanced standards in this field in order to affirm its commitment and determination to apply the highest standards of protection for whistleblowers, both in terms of safeguarding their identity and ensuring they are not subjected to reprisals.
For this reason, the Company’s internal reporting system will be operated in accordance with the following principles:
Independence
Autonomy and the avoidance of conflicts of interest are guaranteed in the operation of the internal reporting system, as well as throughout the various stages of managing the reports received – including their analysis, investigation and resolution – and, finally, in the potential application of response mechanisms or corporate defence measures, whilst always seeking to uphold two fundamental principles: The Organisation’s commitment to regulatory compliance. The entity’s legitimate corporate best interests, as opposed to any other personal, group or third-party interests.
Zero tolerance and respect
The Company has implemented the Internal Reporting System in line with its commitment to zero tolerance of conduct that contravenes the principles of ethics, compliance and the prevention of crime, which form part of its corporate compliance policy. To this end, in all communications and decisions relating to the operation of the Internal Reporting System, the role of the whistleblower will be respected and protected, ensuring that there is no retaliation, negative consequence or harmful conduct against them simply because they have made a report or lodged a complaint.
Confidentiality
In accordance with the provisions of Article 24 of Organic Law 3/2018 on data protection and the guarantee of digital rights, and in accordance with the criteria set out in Law 2/2023 of 20 February. In particular, the Company guarantees and safeguards confidentiality, particularly with regard to any data that may reveal the identity of the person concerned by the communication or, indeed, the content of the communications themselves. These guarantees apply not only to communications in which the whistleblower has chosen to be identified, but also to those in which the anonymous option has been selected.
Good faith, objectivity and honesty
In line with the requirement of good faith in the submission of communications, the Organisation shall endeavour, through the analysis and investigation of such communications, to gain a proper and objective understanding of their content. All of this is carried out with the sincere aim of protecting the legal rights at stake in the decisions and actions taken within the Organisation, as well as in the analysis of communications concerning the failure of such decisions and actions to comply with the Organisation’s existing ethical, regulatory and crime-prevention standards and obligations.
Prohibition of reprisals
doValue and its subsidiaries prohibit retaliation against any Whistleblower or related Third Party, including threats of retaliation and attempts at retaliation. This prohibition covers, in addition to retaliation in the strict sense, any adverse treatment or harmful conduct relating to the report. Should the Company become aware that retaliation is taking place or has taken place, the Organisation shall take the necessary protective measures to halt, address and remedy such a situation.
10Protection parameters
10.1 Persons in need of protection
The Company will provide protection to both whistleblowers acting in good faith and relevant third parties against any harm they may suffer as a result of reporting possible breaches of which they have become aware, as well as to those who have made a public disclosure regarding a breach falling within the scope of the internal reporting system.
Furthermore, the Organisation will extend protection, in accordance with the legal provisions applicable in this instance, to those affected by the notification.
However, as set out above, persons who report infringements not covered by Law 2/2023 of 20 February will fall outside the scope of protection provided by that Law.
10.2 Conditions of protection
A whistleblower acting in good faith is defined as someone who has reasonable grounds to believe that the information in question is true at the time of the report, even if they do not provide conclusive evidence. The protection afforded to the whistleblower shall not lapse merely because the report is ultimately unsuccessful or the facts are not substantiated, provided that such reasonable grounds existed, and such protection is recognised regardless of the channel used. Any protected person shall be entitled to the support measures provided for in Law 2/2023 (information, advice and assistance), and may not be required to waive these rights in advance.
Information contained in communications that have previously been rejected by any other corporate communication mechanism – where the communication containing precisely said information, provided that no additional or new facts or evidence are submitted.
Similarly, reports concerning matters that do not fall within the scope of the internal reporting system of DOVALUE and its subsidiaries will also be rejected.
10.3 Measures to protect whistleblowers and related third parties
The Company is responsible for ensuring the protection of Whistleblowers and related third parties, in accordance with Article 39 of Act 2/2023 of 20 February. The System Manager is responsible for ensuring that these protective measures are effectively implemented within the Organisation.
Prohibition of retaliation or harmful conduct. No member of DOVALUE is permitted under any circumstances to take retaliatory action against whistleblowers acting in good faith, including threats of retaliation and attempts at retaliation.
‘Retaliation’ means any act or omission, as well as any adverse treatment or harmful conduct, which is prohibited by law or which, directly or indirectly, results in unfavourable treatment that places those affected at a particular disadvantage compared with others in the workplace or professional context, either because of their status as Whistleblowers or Related Third Parties, or because they have made a public disclosure.
For the purposes of Article 36.2 of Law 2/2023, any adverse treatment suffered by the Whistleblower within two years of the report or disclosure shall be presumed to constitute retaliation, unless DOVALUE and its subsidiaries provide evidence to the contrary. In any proceedings, it shall be for the Company to prove that the measure taken was based on duly justified grounds unrelated to the report.
Attached as Annex 2 is an illustrative, non-exhaustive list of actions or acts that fall within the definition of retaliation.
If the Company becomes aware that retaliation is taking place or has taken place, it will take reasonable steps to stop and address it. In this regard, steps will be taken to remedy the situation of the Whistleblower or the Third Party involved in the relevant situation, as though they had not suffered the retaliation or harmful conduct. For example:
- To reinstate the person to the same post or an equivalent one, with the same salary, responsibilities, job status and reputation;
- To ensure equal access to promotion, training, opportunities, benefits and rights;
- To reinstate the individual to their previous commercial position in relation to the Organisation;
- To resolve or put an end to any internal conflict or dispute that may arise in relation to the individual (for example, regarding their attitude or the way they are treated);
- To apologise for any harm caused;
- To award damages.
Confidentiality and protection of personal data. DOVALUE is obliged to protect the identity of the Whistleblower and any related third parties, and to ensure that their data is treated confidentially.
In this regard, the Internal Reporting System is designed, established and managed in a secure manner, so as to guarantee the confidentiality of the Whistleblower’s identity and that of any third party mentioned in the Report, as well as the confidentiality of the actions taken in the handling and processing thereof, and to ensure data protection by preventing access by unauthorised personnel.
The Company undertakes not to process any personal data that is not necessary for the investigation of the actions or omissions reported in inappropriate communications within the internal reporting system and for which there is no appropriate legal justification; in which case such data will be deleted.
Furthermore, the Company undertakes to comply with the time limits set out in the applicable regulations and in the corporate procedure governing the Internal Reporting System. In particular, personal data relating to Reports and internal investigations shall be retained only for as long as is necessary and proportionate; three (3) months after receipt of the Report, if no investigation has been initiated, the data shall be deleted, unless the purpose of retention is to provide evidence of the System’s operation, in which case the data will be recorded in anonymised form; under no circumstances may it be retained for a period exceeding ten (10) years.
10.4 Measures to protect data subjects
In accordance with Article 39 of Law 2/2023 of 20 February, regulating the protection of persons who report breaches of regulations and the fight against corruption, the main protective measures to be implemented for persons affected by the report are as follows:
- Right to the presumption of innocence: those affected by the report may never be penalised without the facts contained in the report having first been verified.
- Right to a defence: those involved are given the opportunity to provide an explanation regarding the situation reported, either by being invited to an interview or by requesting clarification in order to establish the facts.
- Right of access to the file: the person concerned by the report must be informed of the acts or omissions attributed to them. The right of access to the file shall be subject to the need to respect the guarantees of confidentiality and protection of the Whistleblower’s identity enshrined in Article 31 of Law 2/2023. This information shall be provided within a reasonable timeframe, in accordance with the terms set out in Article 9.2.f, in such a way as to ensure that it is provided ‘at the time and in the manner deemed appropriate’ to guarantee the successful conclusion of the investigation.
- Protection of your identity, ensuring the confidentiality of the facts and details of the proceedings.
- Compliance with deadlines: compliance with the deadlines set out in the applicable regulations and in the Corporate Procedure for the Management of the Internal Reporting System. These deadlines are set out in section 10.5 of this Policy.
The scope of these measures will be limited by the specific provisions which, depending on the type of communication or its subject matter, apply under current legislation.
10.5 Meeting deadlines
The Organisation will process the communications received in accordance with the time limits set out in the applicable regulations, in particular Law 2/2023, and in the corporate procedure for managing the internal reporting system. The main time limits are as follows:
- Acknowledgement of receipt: this shall be sent to the whistleblower within a maximum of seven (7) calendar days of receipt of the report, unless this would jeopardise the confidentiality of the report.
- Response and closure of the case: the response to the whistleblower regarding the investigation and the closure of the case shall take place within a maximum period of three (3) months from receipt of the report or, where no acknowledgement of receipt has been sent, from the expiry of the seven (7) calendar day period following its submission. Where appropriate, the person concerned by the report will also be informed of the closure, whilst at all times complying with obligations regarding confidentiality and the protection of personal data.
- Extension: in particularly complex cases where an extension is required, the deadline may be extended by up to a further three (3) months. The extension must be justified, recorded in the file and the informant notified.
The foregoing is without prejudice to the time limit set for the in-person meeting, as set out in section 8.1.2, and to the time limits for the retention and erasure of personal data, as set out in section 10.3.
10.6 Activating protection
Measures to protect the Whistleblower, related third parties and those affected by the report will be activated and will come into effect as soon as the report is received, and will continue throughout and even after – where necessary – the conclusion of the investigation or the handling of the report.
11Consequences of non-compliance
All persons to whom this document applies are obliged to comply with its contents. Should any breach of this document be identified, it may and must be reported to the System Manager via the internal reporting system.
Where a breach of the provisions set out in these texts is confirmed, the appropriate measures will be taken, including disciplinary measures (in the workplace) or contractual measures (in commercial dealings with third parties), as deemed proportionate to the risk or damage caused.
Any measures adopted from an employment perspective shall comply with the applicable regulations, and shall be in accordance, depending on the nature and seriousness of the events, with the internal disciplinary regulations, the applicable Collective Agreement and, failing that, the Workers’ Statute, without thereby losing their firmness or proportionality in relation to the conduct in question. Where appropriate, the Workers’ Legal Representatives shall also be informed.
12Training
doValue will ensure that all persons falling within the scope of the Internal Reporting System receive appropriate training on its existence and operation. Such training shall include, at a minimum:
- Access routes to the canal and offences that may be reported.
- The guarantees of confidentiality and protection against reprisals enjoyed by the whistleblower.
- The possibility of making anonymous communications.
- The existence of external information channels (Independent Whistleblower Protection Authority, A.A.I.).
- The duty of confidentiality and the classification of any breach thereof as a very serious offence under Act 2/2023.
- The obligation to forward immediately any communication received through a channel other than the designated one to any member of the CSII, whilst maintaining confidentiality.
- The consequences of submitting communications that are found to be false or made in bad faith.
Training sessions will be held on a regular basis and will be updated whenever there are regulatory changes or significant modifications to the System. A written record will be kept of all training sessions carried out.
13Advertisement
This Policy is provided and made available to all Members of the Organisation, business partners and third parties through its publication on the Organisation’s website, in a separate and easily identifiable section of the home page:
It is also published on the DOVALUE intranet at: www.doconnect.dovalue.it
The Company undertakes to disseminate and bring to the attention of all Members of the Organisation the information necessary to understand the Organisation’s internal reporting system, its principles, safeguards and obligations, as well as its preventive purpose.
·Appendices
Appendix 1. Template for Drafting a Communication
| Name of the Informant | (or, where applicable, ‘Anonymous’) |
|---|---|
| Division or Department | (if you wish to identify yourself) |
| Person affected by the Communication | (or reported) |
| Date on which the events took place | |
| Facts | |
| Evidence provided with the Notice | |
| Any witnesses to the events | |
| Signature of the informant and date |
Appendix 2. Illustrative list of behaviours considered to be retaliation
- Dismissal, suspension, removal from post or equivalent measures relating to the employment contract, disciplinary measures or measures affecting one’s career;
- Early termination or cancellation of contracts for goods or services;
- Non-renewal or early termination of a fixed-term employment contract;
- A change of job or duties, a change in the location of the workplace, a reduction in salary, a change to working hours or other terms and conditions of employment;
- Demotion or refusal of promotion;
- Negative assessments or references regarding work or professional performance;
- The imposition of any disciplinary measure, reprimand or other sanction, including financial penalties;
- Denial of service;
- Refusal of training;
- Damage, including damage to your reputation, particularly on social media, or financial losses, including loss of business and income;
- Any act, whether deliberate or reckless, that causes physical or psychological harm;
- Medical or psychiatric referrals;
- Negative appraisals or references regarding their work performance;
- Coercion, intimidation, harassment, ostracism or isolation;
- Discrimination, or unfavourable or unfair treatment;
- Blacklisting on the basis of a sectoral agreement – whether informal or formal – which may mean that the person will be unable to find employment in that sector in the future;
- Disclosure of the informant’s identity;
- Financial loss;
- Revocation or refusal of a licence or permit.

