Whistleblowing Reporting Procedure

PREMISES, REFERENCE LEGISLATION AND DOCUMENTS

Legislative Decree No. 24 of 10 March 2023, implementing EU Directive 2019/1937 (hereinafter the “Decree”), has significantly extended the scope of application of the rules on the reporting of unlawful conduct in the public and private sectors; in particular, it describes and regulates the obligations and safeguards that companies are required to implement and guarantee in order to manage reports.

Given that such activities necessarily involve the collection and processing of personal data, the relevant data protection legislation, Regulation (EU) 2016/679, fully and significantly applies.

In particular, the relevant national and international legislation is as follows:

• Legislative Decree No. 24 of 10 March 2023

• Directive (EU) 2019/1937

• Regulation (EU) 2016/679 (GDPR)

• Legislative Decree 30 June 2003, No. 196

• Legislative Decree 10 August 2018, No. 101

PURPOSE and SCOPE OF APPLICATION

This procedure relating to the reporting system (hereinafter the “Procedure”) is intended to describe and regulate the reporting system implemented by the Controller, providing clear and appropriate guidance for making a report and then outlining its management process and finalisation.

In particular, this document:

• defines the scope of application of the reporting system;

• identifies the persons who may submit reports;

• circumscribes the range of conduct, events or actions that may be the subject of a report;

• identifies the channels through which reports can be submitted, describing both internal and external channels available;

• defines the report management process in its various stages, identifying roles, responsibilities and operating procedures;

• guarantees the confidentiality of the personal data of the reporting person and of the reported person (without prejudice to the rules on investigations or proceedings initiated by the judicial authorities in relation to the facts reported, or in any case disciplinary proceedings in the event of reports made in bad faith).

DEFINITIONS

• Whistleblowing: the reporting of conduct, acts or omissions in breach of the provisions of the Organisation, Management and Control Model pursuant to Legislative Decree 231/2001 or of national or European Union provisions that harm the public interest or the integrity of a public administration or a private entity, made by a person who has become aware of such conduct in the context of his/her public or private work-related activities;

• Platform: strumento informatico per la gestione delle segnalazioni, in particolare la piattaforma in SaaS fornita da Isweb;

• Report: IT tool for managing reports, in particular the SaaS platform provided by Isweb;

• Anonymous report: when the identity details of the reporting person are not provided and are otherwise not identifiable;

• Open report: when the reporting person openly raises an issue with no limits relating to his/her confidentiality;

• Confidential report: when the identity of the reporting person is not disclosed, but it is nevertheless possible to trace it back in specific and defined cases as set out below;

• Report made in bad faith: a report made for the sole purpose of damaging or otherwise prejudicing the reported person, such as reports made with intent or gross negligence that prove to be unfounded;

• Reporting persons: persons who interact with the Company for the purpose of making a report;

• Reported persons: persons indicated in the report as those who have committed alleged findings, irregularities, violations, reprehensible conduct and events, or in any case any practice not in line with national and EU regulations, company procedures and contracts;

• Third Parties: contractual counterparties, both natural and legal persons (such as suppliers, consultants, etc.) with whom the Company enters into any form of contractually regulated cooperation and who are intended to cooperate with the Company in the context of risk-related activities.

RESPONSIBILITIES AND DISSEMINATION

This Procedure, as an integral part of the company organisation, is approved by the Board of Directors.

The Report Manager is responsible, with the possible support of other company functions deemed necessary, for updating and integrating it.

WHAT CAN BE REPORTED? (Objective scope)

Reports may be submitted concerning violations consisting of conduct, acts or omissions that harm the integrity of the Controller and of which the reporting person has become aware in the context of his/her work-related activities.

The Report concerns violations:

– committed or that may have been committed, on the basis of well-founded and detailed suspicions;

– not yet committed but which the Reporting person believes may be committed, on the basis of well-founded and detailed suspicions;

– conduct aimed at concealing the above-mentioned violations.

Specifically, relevant are the commission or attempted commission of:

• unlawful conduct relevant under Legislative Decree 8 June 2001 No. 231 and violations of the 231 Model, where adopted;

• unlawful acts falling within the scope of European or national legislation referred to in the Annex to the Decree or in the national implementing legislation of EU acts indicated in the Annex to Directive (EU) 2019/1937, with regard to the following sectors: public procurement; financial services, products and markets and prevention of money laundering and terrorist financing; product safety and compliance; transport safety; protection of the environment; radiation protection and nuclear safety; food and feed safety and animal health and welfare; public health; consumer protection; protection of privacy and personal data and security of network and information systems;

• acts or omissions that harm the financial interests of the European Union (such as fraud, corruption and any other illegal activity affecting EU expenditure);

• acts or omissions relating to the internal market.

The following are excluded:

– complaints, grievances or requests linked to a personal interest of the reporting person, relating exclusively to his/her individual employment relationship, including relations with hierarchical superiors;

– reports concerning national defence and security;

– reports relating to violations already governed by EU directives and regulations and by Italian implementing provisions, indicated in Part II of the Annex to the Decree, which already provide for specific reporting procedures in certain special sectors (financial services; prevention of money laundering and terrorist financing; transport safety; environmental protection).

To facilitate the identification of facts that may be subject to a Report, below is a non-exhaustive list of relevant conduct/behaviours, purely by way of example:

• promising or giving a sum of money or granting other benefits (gifts, hospitality, lunches, dinners, etc. not permitted under company procedures) to a public official or person in charge of a public service in return for the performance of his/her duties or for carrying out an act contrary to his/her official duties (e.g. expediting a procedure);

• tampering with documents by manipulating or falsifying company documents or official documents in order to obtain an unlawful advantage or mislead the competent authorities;

• promising or giving a sum of money or granting other benefits (gifts of significant value, hospitality, lunches, dinners, etc. not permitted under company procedures) in order to bribe suppliers or customers;

• agreements with suppliers or consultants to record as performed services that were never provided.

WHO CAN REPORT? (Subjective scope)

Any person who, in dealing with the Company, has a reasonable suspicion that one of the above violations has occurred or may occur, may submit a report.

From the moment the report is sent, such person becomes the “Reporting person” and the safeguards laid down by the relevant legislation apply to him/her.

HOW TO MAKE A REPORT

As required by law, and in order to facilitate the submission of reports, the Controller has activated internal channels.

External channels to which the reporting person may turn, under the conditions set out below, are also indicated.

• ACTIVE CHANNELS

• INTERNAL

For reports managed within the company organisation, the reporting person may use the channels described below and decide whether to act anonymously or not.

Please note that in the case of an anonymous report, only the dedicated platform accessible from the company website must be used (by selecting the “anonymous report” checkbox).

In general, reports can be submitted using the following channels:

• written form;

• oral form..

In both cases, the adopted platform, accessible from the institutional websites of each company, is used.

The procedure to be followed for correctly entering the necessary information is guided.

Please note that the online portal service is provided by a specialised service provider, which can guarantee:

• compliance with the principles of personal data protection and the highest level of confidentiality;

• specifically authorised access;

• 24/7 availability.

Access to the Platform is possible via the following URL:

https://riellointernational.wbisweb.it.

When the report is submitted, the Platform displays a protocol code to the reporting person, allowing him/her to subsequently retrieve the report submitted, check its status, obtain information on the outcome and communicate with the Report Manager.

a.2) The report may be made via a specific voice messaging system integrated into the platform, which includes, among the measures to protect confidentiality, voice alteration.

The report is documented by means of a recording.

a.3) The reporting person may request a direct meeting with the Manager. In this case too, the report is documented by the Manager through a recording on a device suitable for storage and replay, or by means of minutes. The document produced will be uploaded in digital form to the platform.

In any case, it is important that reports are detailed and based on precise and consistent elements, relate to verifiable facts known directly by the reporting person and therefore contain the following essential elements:

– a clear description of the violation being reported, indicating the time and place in which the facts/behaviours described occurred;

– any useful element (such as corporate position/role) that enables easy identification of the alleged perpetrator(s) of the reported violation or other persons potentially involved.

Furthermore, the reporting person may provide other elements, such as:

– his/her personal details;

– any documentation to support the alleged violation;

– any other information that may facilitate the collection of evidence regarding what is reported.

• EXTERNAL CHANNELS

The reporting person may submit an “external” report in the following cases: nei casi in cui:

– where an internal reporting channel has not been established or, although provided for, is not operational;

– where the internal channel adopted does not comply with the provisions of Article 4 of the Decree;

– where the internal report has not been followed up;

– where the reporting person has reasonable grounds – based on specific and consistent circumstances – to believe that, if he/she were to submit an internal report, it would not be effectively followed up or that such report may give rise to a risk of retaliation;

– where the reporting person has reasonable grounds – based on specific and consistent circumstances – to believe that the violation may constitute an imminent or obvious danger to the public interest.

This report can be submitted via one of the channels made available by ANAC, which guarantee, including through encryption tools, the confidentiality of the reporting person’s identity, of the reported person, as well as of the content of the report and related documentation.

The link to ANAC’s reporting procedures is:

Whistleblowing – Form for reporting unlawful conduct pursuant to Legislative Decree No. 24/2023 (anticorruzione.it)

WHO WILL HANDLE THE REPORT

The entity responsible for receiving and analysing reports is GRIG S.p.A., in the persons of the Human Resources Manager as Report Manager and the Administration Manager as custodian of identities.

These persons have received adequate and specific professional training, including in matters of personal data protection and security.

The tasks entrusted to the Report Manager include:

• providing timely acknowledgement of receipt and timely follow-up to the Report;

• taking measures to verify the completeness and soundness of the information;

• maintaining communication with the reporting person, requesting – where necessary – additional information or further discussions and insights, and keeping him/her informed of the progress and outcome of the report;

• liaising and/or cooperating with other company functions and with authorised external consultants for the proper conduct of investigation and verification activities.

THE REPORTING PROCESS

The report management process consists of the following stages:

• receipt and registration;

• preliminary assessment and classification;

• checks and investigations;

• feedback on the report;

• reporting and retention.

Receipt and registration of the report

Following the Report received through the Internal channels, the Report Manager will send the reporting person an acknowledgement of receipt within 7 (seven) days from the date of receipt of the Report.

Upon receipt of a report, if it has not been submitted via the platform, the Report Manager will enter the report into the platform and destroy the paper document.

Classification of the report

Following these analyses and preliminary assessment, the Report Manager classifies the Report as:

• not relevant: not falling within the admissible violations under this Procedure or submitted by persons not covered by the definition of reporting persons;

• not actionable: at the end of the examination phase and/or following a possible request for further information, it was not possible to gather sufficient information to proceed with further investigation;

• relevant and actionable: sufficiently detailed and within the scope of this Procedure.

In the latter case, the Report Manager initiates the verification and investigation phase.

Internal checks and investigations

Where the report received has been classified as “relevant and actionable”, the Report Manager carries out internal checks and investigations.

In this context, the Report Manager may seek the support of appropriately qualified company functions/structures and/or external consultants.

Feedback to the Report (outcomes)

Within 3 (three) months from the date of acknowledgement of receipt or, in the absence thereof, within 3 (three) months from the expiry of the 7 (seven) days following submission of the report, the Manager provides feedback to the reporting person via the platform or another suitable means.

The feedback contains the outcome of the investigation and the reasoned decisions adopted by the Manager, which may be:

• ARCHIVING

This decision is taken if the report:

• is not relevant; refers to facts so generic that no verification can be made;

• has been made in bad faith or the investigation has proven it to be unfounded.

• REQUEST FOR ASSESSMENT BY THE COMPANY BODIES FOR DISCIPLINARY/SANCTIONING PURPOSES

If the investigations reveal profiles of responsibility in the disciplinary employment sphere regarding the reported person, the competent internal body will adopt the sanctions provided for by law and proportionate to what has occurred.

• REPORT TO THE COMPETENT PUBLIC AUTHORITIES

Where the report concerns matters that may be criminally relevant, the competent company body will refer the matter to the public authority.

SUMMARY SCHEME

Report management is broken down into the following activities:

ACTIVITY

PARTIES INVOLVED

RECEIPT, REGISTRATION, INITIAL FEEDBACK

Platform, Manager

CLASSIFICATION

Manager

CHECKS AND INVESTIGATIONS

Manager, relevant company functions, external consultants

FEEDBACK (OUTCOME)

Manager

REPORTING

Platform, Manager

ARCHIVING

Platform

REPORTING AND RETENTION

The outcomes of the assessment of all reports received are collected in ad hoc reporting containing the outcome of any investigations carried out and the evaluations made in relation to reports found to be well-founded.

Reports and the related documentation are retained for the time necessary to process each one and, in any case, no longer than 5 (five) years from the date of communication of the final outcome of the reporting procedure, or from the conclusion of any judicial or disciplinary proceedings brought against the reported person or the reporting person, in compliance with confidentiality obligations and the storage limitation principle expressly regulated by law.

Electronic documents are stored within the platform or in a directory dedicated to whistleblowing, accessible only to the Report Managers.

Any paper documents created for the optimal management of the report are filed in the office of the Report Manager in locked cabinets, access to which is reserved exclusively to formally authorised persons.

SAFEGUARDS FOR THE PARTIES INVOLVED

• For the reporting person

The Company, in compliance with the applicable legislation and in order to promote a culture of legality and encourage the reporting of unlawful conduct, ensures the confidentiality of the reporting person’s personal data and the confidentiality of the information contained in the report and received from all parties involved in the procedure.

It is the duty of the Report Manager to guarantee the confidentiality of the reporting person from the moment the report is taken in charge, even in cases where the report later proves to be incorrect or unfounded.

Any breach of this obligation constitutes a violation of this Procedure and exposes the Manager to liability.

In particular, the Company guarantees that the identity of the reporting person cannot be disclosed without his/her explicit consent and that all those involved in managing the report are required to protect such confidentiality, except where:

– the report has been made with the intention of damaging or otherwise prejudicing the reported person (so-called report made “in bad faith”) and criminal liability for slander or defamation arises under the law;

– confidentiality cannot be invoked by law (e.g. criminal investigations, etc.).

With specific regard to the disciplinary procedure, the identity of the reporting person may not be disclosed where the disciplinary charge is based on findings separate and additional to the report, even if resulting from it.

If, for the management of the disciplinary charge and for the defence of the accused person, it is necessary to know the identity of the reporting person, the report may be used for disciplinary purposes only with the consent of the reporting person to the disclosure of his/her identity.

In such a case, the reporting person will be informed in writing of the reasons for disclosing confidential data and will be asked in writing whether he/she intends to give consent to the disclosure of his/her identity, with notice that – otherwise – the Report cannot be used in the disciplinary procedure. The reporting person will also be informed in writing of the reasons for disclosing confidential data when the disclosure of his/her identity and of the information from which such identity may be inferred, directly or indirectly, is indispensable for the defence of the reported person.

No form of retaliation or discriminatory measure, whether direct or indirect, relating to working conditions, is permitted or tolerated against the reporting person for reasons directly or indirectly connected with the report.

Furthermore, the reporting person is not punishable if he/she discloses or disseminates information on violations covered by a duty of confidentiality (other than information classified as secret, medical or professional secrecy and the deliberations of judicial bodies), or relating to copyright protection or personal data protection, or that harms the reputation of the person involved or reported, where, at the time of disclosure or dissemination, there were reasonable grounds to believe that such disclosure or dissemination was necessary to reveal the violation. In such cases, no further civil or administrative liability arises. In any case, criminal, civil or administrative liability is not excluded for conduct, acts or omissions not connected with the report, the notification to the judicial or accounting authorities or the public disclosure, or that are not strictly necessary to reveal the violation.

• For the reported person

In accordance with applicable legislation, the Company has adopted the same forms of protection for the personal data of the reported person as for the reporting person, without prejudice to any additional forms of liability laid down by law requiring the name of the reported person to be disclosed (e.g. requests from the judicial authorities, etc.).

The identity of the reported person and of persons in any way involved and mentioned in the report is protected until the conclusion of proceedings initiated as a result of the report, with the same safeguards as provided for the reporting person.

PRIVACY AND CONFIDENTIALITY

The Company guarantees the confidentiality of the identity of the Reporting person, of the Reported person, of the content of the Report and of the documentation provided. Reports may not be used beyond what is necessary to follow them up appropriately. The identity of the Reporting person and any other information from which such identity may be inferred – directly or indirectly – may not be disclosed without the explicit consent of the Reporting person to anyone other than those authorised to receive or follow up reports, as identified in this Procedure.

Furthermore, the identity of the Reporting person:

• in criminal proceedings, is protected by investigative secrecy under the terms and within the limits of Article 329 of the Italian Code of Criminal Procedure;

• in proceedings before the Court of Auditors, may not be disclosed until the end of the investigative phase;

• in disciplinary proceedings, may not be disclosed where the disciplinary charge is based on findings separate and additional to the Report, even if resulting from it.

In such a case, the reporting person will be informed in writing of the reasons for disclosing confidential data and will be asked in writing whether he/she intends to give consent to the disclosure of his/her identity, with notice that – otherwise – the Report cannot be used in the disciplinary procedure. The reporting person will also be informed in writing of the reasons for disclosing confidential data when the disclosure of his/her identity and of the information from which such identity may be inferred, directly or indirectly, is indispensable for the defence of the reported person.

For privacy notices, reference is made to the documents adopted by each individual company.

DISCIPLINARY SANCTIONS

The Controller confirms that any violation and/or abuse of this Procedure constitutes a disciplinary offence and, in compliance with the applicable employment legislation, including the relevant National Collective Bargaining Agreement, may be punished by the imposition of proportionate disciplinary sanctions.

In general, the Controller may impose disciplinary sanctions on anyone who obstructs or attempts to obstruct reports, acts with the intention of preventing or delaying activities related to the management of reports, breaches confidentiality obligations, or carries out retaliatory or discriminatory actions against the reporting person and/or the reported person.s

In particular, sanctions may be imposed:

• on the reporting person: in the event of reports made in bad faith, fraudulent, slanderous or defamatory reports – which may also entail criminal and civil liability – those that are manifestly opportunistic and/or made for the sole purpose of damaging the reported person or other parties, and any other improper use of this Procedure;

• on the Report Manager: in cases of breach of confidentiality obligations, delays or omissions in carrying out verification and investigation activities, delays or omissions in the definition of the report;

• on the reported person: where the unlawful conduct disclosed in the report is established and where he/she has engaged in retaliatory or discriminatory actions against the reporting person.