Tsallake zuwa babban abun ciki
Parousia Group

Shari’a

Ɗaga murya

Whistleblowing policy

What can be reported, where to send it, what the group must do and by when, and the protection the law gives to the person who reports.

Ana bitar shari’aAn rubuta wannan takarda kuma an buga ta a fili, sai dai har yanzu ba a amince da ita ba, ko daga hukumar gudanarwa ko daga sashen shari’a na ƙungiyar. Ba ta ƙarshe ba ce.
Harsunan da ke da ƙarfin dokaWannan takarda tana da ƙarfin doka a Turanci da Faransanci. An gabatar da ita a nan cikin Turanci ne domin har yanzu babu sigar da aka duba a wannan harshe — fassarar na’ura ta rubutun da ke haifar da sakamako na doka za ta fi wannan sanarwar muni.

Purpose and who is protected

This policy applies to Parousia Group, to the regional holding companies — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America, Parousia Middle East — to Echad Technologies in Singapore, and to the six solutions the group operates. The group does not publish headcount figures; the policy is applied in every entity whether or not the fifty-worker threshold of Article 8(3) of Directive (EU) 2019/1937 is reached in that entity.

Protection does not depend on holding an employment contract. Following Article 4 of the Directive, it covers a person who acquires information on a breach in a work-related context, which includes:

  • Workers, whatever the form or duration of the contract, and persons working under the supervision and direction of contractors, subcontractors and suppliers.
  • Self-employed persons, consultants and freelancers engaged by an entity of the group.
  • Shareholders and members of an administrative, management or supervisory body, including non-executive members.
  • Volunteers and trainees, whether paid or unpaid.
  • Persons whose work relationship has ended, and candidates whose information was acquired during recruitment or other pre-contractual negotiations.
  • Facilitators who assist a reporting person, colleagues and relatives who could suffer retaliation in a work-related context, and legal entities that the reporting person owns, works for, or is otherwise connected with in that context.
You do not need proofArticle 6(1)(a) of the Directive sets the standard: protection is owed to a person who had reasonable grounds to believe, at the time of reporting, that the information was true and fell within the scope of the policy. A report made on reasonable grounds keeps its protection even if the investigation concludes that no breach occurred. What is not protected is a report the author knows to be false when making it.

What can be reported

Article 2 of the Directive sets a material scope that the group applies in full and extends, because a breach does not become less serious for falling outside a list. A report is in scope if it concerns an act or omission that is unlawful, that defeats the object or purpose of the rules concerned, or that the group has prohibited in its own standards.

  • Bribery, corruption, facilitation payments, kickbacks and influence peddling, including conduct caught by the UK Bribery Act 2010 or the US Foreign Corrupt Practices Act.
  • Fraud, theft, misappropriation of assets, false invoicing, and any misstatement or falsification of accounting records.
  • Public procurement irregularities, bid rigging, and breaches of competition or State aid rules.
  • Money laundering, terrorist financing, and breaches of sanctions or export control rules.
  • Forced labour, child labour, human trafficking or debt bondage in the operations of the group or in its supply chains — see the modern slavery statement for the diligence that surrounds this.
  • Breaches of personal data protection, misuse of personal data, and incidents affecting the security of network and information systems.
  • Conduct that endangers health and safety, consumer protection, food or product safety, transport safety, public health, or the environment.
  • Conflicts of interest that are concealed, undeclared benefits, and abuse of a position for private gain.
  • Retaliation, or the threat of retaliation, against a person who has reported or intends to report.
  • Any attempt to conceal, destroy or alter evidence of the above, and any instruction to do so.

What belongs to another route

This channel is not a general complaints box. Sending a matter here that has its own route does not make it move faster; it makes it wait behind an admissibility assessment before being redirected. The following are handled elsewhere.

  • An individual contractual dispute — an unpaid invoice, a contested delivery, a disagreement over the terms of a supplier or client contract — is handled under the dispute resolution clause of that contract. It is not a whistleblowing report.
  • An individual employment grievance — pay, appraisal, working time, a manager decision affecting one person — is handled under the grievance procedure of the employing entity.
  • A customer complaint about one of the six solutions is handled by the operator of that solution.
  • A request to exercise data protection rights — access, rectification, erasure, objection — goes to contact@parousiagroup.com, for the attention of the data protection officer.
  • An accessibility barrier on the group websites is handled under the accessibility statement.
  • A security vulnerability in the group websites is handled under the coordinated vulnerability disclosure policy, which sets its own timetable and its own protection for the researcher.
  • A press enquiry goes to press@parousiagroup.com.

The line is not always where it first appears. A matter that begins as an individual dispute becomes a report the moment it reveals a breach in the list above: an unpaid invoice is not a report, an instruction to falsify one is. Where a report is admissible in part, the admissible part is handled here and the rest is redirected, and the person who reported is told which is which.

How to report internally

The internal channel is written, and it has two forms. Both reach the persons designated to receive reports; only the second guarantees that no one else sees the message first.

Where to send a reportBy email to contact@parousiagroup.com, with REPORT as the first word of the subject line, for the attention of the person designated to receive reports. By post to Parousia Group, 157 avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo, in a sealed envelope marked CONFIDENTIAL — REPORT, TO BE OPENED BY THE ADDRESSEE ONLY. Say what happened, when, where, who was involved and how you know; attach documents if you have them lawfully. A report that lacks detail is still received and still assessed.
The known limit of the email routecontact@parousiagroup.com is a general mailbox: more than one person reads what arrives there before it is routed. Anyone who reads it is bound by the duty of confidentiality stated in this policy and by the sanction that attaches to breaching it, but the group states the fact rather than hiding it. If you need your identity to reach the designated recipient and no one else, use the postal route, which is opened by the addressee alone. The switchboard number +243 892 844 000 is not a reporting channel: it is answered by staff who are not designated to receive reports and not trained to handle one.

A report may also be made orally at a physical meeting, which the group arranges within a reasonable time of a request made through either written route, as Article 9(2) of the Directive requires. The meeting is documented either by a recording made with your consent, or by a written minute of the conversation; in both cases you may check, rectify and sign the record, and you receive a copy.

Anonymous reports are accepted and are acted on. The limit is practical rather than legal: without a means of reaching you, the group cannot acknowledge receipt, cannot ask the one question that often decides an investigation, and cannot give you feedback. A pseudonymous mailbox that you alone control solves this. A person who reported anonymously and is subsequently identified keeps the full protection of the Directive under Article 6(3).

What happens next, and by when

A report is recorded on receipt, assessed for admissibility, and where admissible investigated by a person or unit independent of the facts and of the persons concerned. Diligent follow-up means the group establishes the facts, ends the breach where one is found, and states what it has done. Where a report concerns a designated recipient, or a member of a governing body, the file is transferred to a member of that body who is not concerned by it; where every possible recipient is concerned, the reporting person is told so and directed to the external channels described below.

Deadlines that apply to a report, and what each one rests on
StageDeadlineBasis
Acknowledgement of receiptSeven days from receiptDirective (EU) 2019/1937, Article 9(1)(b)
Statement of whether the report is admissible and is being followed upThirty days from the acknowledgementGroup commitment
Feedback on the action envisaged or taken, and the grounds for itThree months from the acknowledgement, or from the expiry of the seven-day period where no acknowledgement was sentDirective (EU) 2019/1937, Article 9(1)(f)
Interim feedback where the investigation runs longer than three monthsEvery three months until the file is closedGroup commitment
Notice before the identity of the reporting person is disclosed where a legal obligation requires itBefore the disclosure, in writing, with reasons — unless the notice would jeopardise the related investigation or judicial proceedingsDirective (EU) 2019/1937, Article 16(3)
Physical meeting following a request to report orallyWithin a reasonable time of the requestDirective (EU) 2019/1937, Article 9(2)

Confidentiality of identity

Article 16(1) of the Directive requires that the identity of the reporting person is not disclosed, without that person explicit consent, to anyone beyond the staff authorised to receive and follow up reports. The same protection covers any third party named in a report and the person the report is about. Access to a report file is restricted to those persons, and the restriction is enforced on the file itself rather than by instruction.

There is one exception, and it is narrow: disclosure is possible where it is a necessary and proportionate obligation imposed by law in the context of an investigation by a national authority or of judicial proceedings, including to safeguard the rights of defence of the person concerned. In that case the group informs the reporting person in writing before the disclosure and explains the reasons, unless that information would jeopardise the investigation or the proceedings.

  • The group does not seek to identify the author of an anonymous report, and does not use message headers, access logs or document metadata for that purpose.
  • The group does not ask a reporting person to justify why they reported, or to disclose how they came by the information, beyond what the investigation of the facts requires.
  • The group does not tell the person a report is about who reported it.
  • A breach of this confidentiality duty by a member of staff is a disciplinary matter, and Article 23(1)(c) of the Directive requires that it be penalised.

Retaliation is prohibited, and presumed

Article 19 of the Directive prohibits retaliation, including the threat of it and the attempt at it, against a person protected by this policy. The prohibition is not limited to dismissal, and the forms it takes are usually quieter than that.

  • Suspension, dismissal, or the equivalent measure for a self-employed person or a supplier.
  • Demotion, withholding of promotion, transfer of duties, change of place of work, reduction in wages, or change in working hours.
  • Withholding of training, a negative performance assessment or employment reference.
  • A disciplinary measure, reprimand or other penalty, including a financial one.
  • Coercion, intimidation, harassment or ostracism.
  • Discrimination, or unfavourable and unfair treatment.
  • Failure to convert a temporary contract into a permanent one where the worker had legitimate expectations of it, and non-renewal or early termination of a temporary contract.
  • Harm to reputation, particularly on social media, and blacklisting on an informal or formal sector-wide basis.
  • Early termination or cancellation of a contract for goods or services, cancellation of a licence or permit, and referral for psychiatric or medical treatment.
The burden of proof is reversedUnder Article 21(5) of the Directive, where a person who reported suffers a detriment and brings proceedings about it, the detriment is presumed to have been made in retaliation for the report. It is then for the person who took the measure to prove that it was based on duly justified grounds. Article 21(2) provides that a reporting person incurs no liability for acquiring or accessing the information reported, where that acquisition or access did not constitute a self-standing criminal offence; Article 21(7) limits liability for defamation, breach of copyright, breach of secrecy and breach of data protection rules where reporting was necessary to reveal the breach. Article 24 makes any waiver of these rights void: no employment contract, confidentiality clause, settlement agreement or supplier term of the group is applied to prevent a report or to penalise one.

The group adds one operational rule to the legal one: where a decision affecting the employment, engagement or contract of a person known to have reported is proposed, it is reviewed against the report before it takes effect, and the grounds are recorded in writing. The purpose is not to make that person immune from ordinary management; it is to make the reasons for a measure written down at the time, rather than reconstructed two years later before a tribunal.

Reporting outside the group

You are not required to report internally first. Article 10 of the Directive gives a right to report directly to a competent external authority, and the group does not treat the use of that right as a breach of any duty of loyalty, confidentiality or contract. Internal reporting is offered because a breach that can be stopped internally is stopped faster; it is not a filter placed in front of the authorities.

  • In the European Union: the authority designated by the Member State under Article 11 of the Directive, and where relevant the Union institutions, bodies, offices and agencies named in Article 10, including the European Anti-Fraud Office and the European Public Prosecutor Office.
  • In the United Kingdom: the employer, or a prescribed person listed in the Public Interest Disclosure (Prescribed Persons) Order 2014, under section 43F of the Employment Rights Act 1996. A qualifying disclosure under section 43B must be made in the reasonable belief that it is in the public interest; sections 47B and 103A give the remedies for detriment and for dismissal.
  • In the United States: the Securities and Exchange Commission under Section 21F of the Securities Exchange Act, the Occupational Safety and Health Administration for a complaint under section 806 of the Sarbanes-Oxley Act, and the Department of Justice.
  • Elsewhere the group operates: the competent authority of that jurisdiction — for example the Agence de prévention et de lutte contre la corruption in the Democratic Republic of the Congo, the Ethics and Anti-Corruption Commission in Kenya, the Economic and Financial Crimes Commission in Nigeria, and the Corrupt Practices Investigation Bureau in Singapore.
No clause of the group stands between you and a regulatorNo confidentiality agreement, employment contract, settlement, severance or supplier term of any entity of the group restricts a person from communicating directly with a competent authority about a possible breach, and none requires prior notice to the group or its permission. This states expressly what SEC Rule 21F-17(a) requires of any such agreement and what Article 24 of the Directive makes void in any event, and it applies whether or not the authority concerned is a securities regulator. Nothing in this policy limits an award a person may be eligible to receive under Section 21F of the Securities Exchange Act.

Public disclosure — to the press or otherwise to the public — is protected under Article 15 of the Directive where the person first reported externally, or internally and then externally, and no appropriate action was taken within the applicable timeframe; or where the person has reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest, or that external reporting carries a risk of retaliation or offers little prospect of the breach being effectively addressed. Where those conditions are met, the group will not bring or support proceedings against the person who made the disclosure.

Personal data and records

A report is a processing of personal data, and it is one of the most sensitive the group carries out. Processing is limited to what the handling of the report requires. Personal data that are manifestly not relevant to the handling of a report are not collected, and where they are collected accidentally they are deleted without undue delay, as Article 17 of the Directive and Article 5(1)(c) of the GDPR require.

What is kept for a report, why, on what basis and for how long
RecordPurposeLegal basisRetention
The report and its attachmentsAssessing admissibility, investigating, ending the breachGDPR Article 6(1)(c) where the channel is a legal obligation; Article 6(1)(f) elsewhere, the interest being the detection of breachesWhile the file is open, then five years from closure, unless proceedings or a legal retention duty require longer
Identity and contact details of the reporting person, where givenAcknowledging receipt, asking questions, giving feedback, protecting against retaliationSame, with the confidentiality duty of Article 16 of the DirectiveSame, held separately from the file with access restricted to designated recipients
Recording or written minute of an oral reportEstablishing what was said, and allowing the reporting person to correct itConsent for a recording, Article 18(2) of the DirectiveSame as the file
Special category data, where a report unavoidably contains themInvestigating the facts reportedGDPR Article 9(2)(f) or 9(2)(g), depending on the matterSame as the file, with access further restricted
Register of reports without identifying data — date, subject matter, outcomeOversight of the channel, reporting to the governing body, publication of aggregate figuresGDPR Article 6(1)(f)Ten years
Personal data manifestly not relevant to the handling of the reportNoneNoneDeleted without undue delay

The rights of access, rectification, erasure and objection apply to a report file, and so does one restriction: the right of access does not extend to obtaining the identity of the reporting person, because Article 16 of the Directive protects it and Article 23 of the GDPR allows that restriction. In the Democratic Republic of the Congo, where the group has its registered office, the processing of personal data is governed by Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique. Questions on the processing described here go to contact@parousiagroup.com, for the attention of the data protection officer.

The person a report is about

Article 22 of the Directive protects the person concerned by a report as well. That person keeps the presumption of innocence, the right to an effective remedy, the right to a fair trial and the rights of defence, including the right to be heard and to access the file. The identity of a person concerned is protected for as long as the investigation is ongoing, on the same terms as that of the reporting person.

The group does not take a measure against a person on the basis of an unverified allegation. A report that its author knew to be false when making it is not protected: Article 23(2) of the Directive requires that such conduct be penalised, and the group treats it as a disciplinary matter and, where the law allows, as a matter for the courts. Being mistaken is not the same as lying, and the difference is the standard of reasonable grounds stated at the head of this policy.

What is not yet in place

This document is in reviewThe group operates no dedicated telephone hotline and uses no external reporting provider. Writing that it did would send a person who needs the channel to a number that no one answers. The written routes described above are the channel, and they work today. An independent line, reachable without passing through a group mailbox, is being set up; the person designated to receive reports will be identified here by name or by function once appointed. This document carries the status "in review" until both are done, and the version published then will carry the date of its approval.

None of this suspends anything. The deadlines, the duty of confidentiality and the prohibition of retaliation set out above are obligations of law and of this policy from the first report received, whatever remains to be built around them.

Tushen ƙa’ida

  • Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law
  • Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 9, 15 and 23
  • Public Interest Disclosure Act 1998 (UK), inserting Part IVA into the Employment Rights Act 1996
  • Employment Rights Act 1996 (UK), sections 43B, 43C, 43F, 47B and 103A
  • Public Interest Disclosure (Prescribed Persons) Order 2014 (SI 2014/2418)
  • Dodd-Frank Wall Street Reform and Consumer Protection Act 2010, section 922 — Securities Exchange Act section 21F (15 U.S.C. 78u-6)
  • SEC Rule 21F-17(a) (17 C.F.R. 240.21F-17)
  • Sarbanes-Oxley Act of 2002, section 806 (18 U.S.C. 1514A)
  • Loi n° 2016-1691 du 9 décembre 2016 (Sapin II), modifiée par la loi n° 2022-401 du 21 mars 2022
  • Hinweisgeberschutzgesetz of 31 May 2023 (Germany)
  • Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique (DRC)
  • UK Bribery Act 2010
  • Foreign Corrupt Practices Act (15 U.S.C. 78dd-1 et seq.)
  • United Nations Convention against Corruption (2003)