
法律信息
举报不当行为
Whistleblowing policy
What can be reported, to whom it is sent, what the group does and by when, and the protection the law gives to the person who reports.
Purpose and who is protected
This policy applies to Parousia Group, to the regional holding companies — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America, Parousia Middle East — to Echad Technologies in Singapore, and to the six solutions the group operates. It is applied in every entity, whether or not the fifty-worker threshold of Article 8(3) of Directive (EU) 2019/1937 is reached in that entity. The Legal Department owns this policy and operates the internal reporting channel described below.
Protection does not depend on holding an employment contract. Following Article 4 of the Directive, it covers a person who acquires information on a breach in a work-related context, which includes:
- Workers, whatever the form or duration of the contract, and persons working under the supervision and direction of contractors, subcontractors and suppliers.
- Self-employed persons, consultants and freelancers engaged by an entity of the group.
- Shareholders and members of an administrative, management or supervisory body, including non-executive members.
- Volunteers and trainees, whether paid or unpaid.
- Persons whose work relationship has ended, and candidates whose information was acquired during recruitment or other pre-contractual negotiations.
- Facilitators who assist a reporting person, colleagues and relatives who could suffer retaliation in a work-related context, and legal entities that the reporting person owns, works for, or is otherwise connected with in that context.
What can be reported
Article 2 of the Directive sets a material scope that the group applies in full and extends to its own standards. A report is in scope where it concerns an act or omission that is unlawful, that defeats the object or purpose of the rules concerned, or that the group has prohibited in its own policies.
- Bribery, corruption, facilitation payments, kickbacks and influence peddling, including conduct caught by the UK Bribery Act 2010 or the US Foreign Corrupt Practices Act.
- Fraud, theft, misappropriation of assets, false invoicing, and any misstatement or falsification of accounting records.
- Public procurement irregularities, bid rigging, and breaches of competition or State aid rules.
- Money laundering, terrorist financing, and breaches of sanctions or export control rules.
- Forced labour, child labour, human trafficking or debt bondage in the operations of the group or in its supply chains — see the modern slavery statement for the diligence that surrounds this.
- Breaches of personal data protection, misuse of personal data, and incidents affecting the security of network and information systems.
- Conduct that endangers health and safety, consumer protection, food or product safety, transport safety, public health, or the environment.
- Conflicts of interest that are concealed, undeclared benefits, and abuse of a position for private gain.
- Retaliation, or the threat of retaliation, against a person who has reported or intends to report.
- Any attempt to conceal, destroy or alter evidence of the above, and any instruction to do so.
Where a report concerns conduct covered by the anti-bribery and anti-corruption policy, the Legal Department informs the Compliance Department, which holds the registers and the diligence records that policy requires. The transfer does not alter the deadlines, the confidentiality or the protection set out below.
What belongs to another route
The matters below have their own procedure and are handled under it. A request sent to the reporting channel that belongs to one of those procedures is redirected to it after an assessment of admissibility, and the person who sent it is informed of the redirection.
- An individual contractual dispute — an unpaid invoice, a contested delivery, a disagreement over the terms of a supplier or client contract — is handled under the dispute resolution clause of that contract.
- An individual employment grievance — pay, appraisal, working time, a management decision affecting one person — is handled under the grievance procedure of the employing entity, with Human Resources.
- A customer complaint about one of the six solutions is handled by the operator of that solution.
- A request to exercise data protection rights — access, rectification, erasure, objection — is addressed to the Data Protection Office at contact@parousiagroup.com.
- An accessibility barrier on the group websites is handled under the accessibility statement.
- A security vulnerability in the group websites is handled under the coordinated vulnerability disclosure policy, which sets its own timetable and its own protection for the researcher.
- A press enquiry is addressed to press@parousiagroup.com.
A matter that begins under one of those procedures falls within this policy from the moment it reveals a breach listed in the preceding section. Where a report is admissible in part, the admissible part is handled under this policy and the remainder is redirected, and the reporting person is told which part is handled where.
How to report internally
The internal channel is written and is operated by the Legal Department. A report is made in either of the two forms set out below, and both are received by the members of that department designated to receive and follow up reports.
A report is routed to the designated members of the Legal Department without being read for any other purpose, and access to it is restricted to those members from receipt. The confidentiality of the identity of the reporting person is protected on the terms set out below, and a breach of that confidentiality by a member of staff is a disciplinary matter. The group switchboard is not a reporting channel.
A report may also be made orally at a physical meeting, which the group arranges within a reasonable time of a request made through either written route, as Article 9(2) of the Directive requires. The meeting is documented either by a recording made with the consent of the reporting person, or by a written minute of the conversation; in both cases the reporting person may check, rectify and sign the record, and receives a copy.
Anonymous reports are accepted and are acted on. Without a means of reaching the reporting person, the group cannot acknowledge receipt, cannot put a question that the investigation may require, and cannot give feedback; a pseudonymous mailbox controlled by the reporting person alone preserves those steps. A person who reported anonymously and is subsequently identified keeps the full protection of the Directive under Article 6(3).
What happens next, and by when
A report is recorded by the Legal Department on receipt, assessed for admissibility, and where admissible investigated by a person or unit independent of the facts and of the persons concerned. Diligent follow-up means that the group establishes the facts, ends the breach where one is found, and states what it has done. Where a report concerns a member of the Legal Department or a member of a governing body, the file is transferred to the board’s ethics and compliance committee, and where every possible recipient is concerned the reporting person is told so and directed to the external channels described below.
| Stage | Deadline | Basis |
|---|---|---|
| Acknowledgement of receipt | Seven days from receipt | Directive (EU) 2019/1937, Article 9(1)(b) |
| Statement of whether the report is admissible and is being followed up | Thirty days from the acknowledgement | Group commitment |
| Feedback on the action envisaged or taken, and the grounds for it | Three months from the acknowledgement, or from the expiry of the seven-day period where no acknowledgement was sent | Directive (EU) 2019/1937, Article 9(1)(f) |
| Interim feedback where the investigation runs longer than three months | Every three months until the file is closed | Group commitment |
| Notice before the identity of the reporting person is disclosed where a legal obligation requires it | Before the disclosure, in writing, with reasons — unless the notice would jeopardise the related investigation or judicial proceedings | Directive (EU) 2019/1937, Article 16(3) |
| Physical meeting following a request to report orally | Within a reasonable time of the request | Directive (EU) 2019/1937, Article 9(2) |
Confidentiality of identity
Article 16(1) of the Directive requires that the identity of the reporting person is not disclosed, without that person’s explicit consent, to anyone beyond the staff authorised to receive and follow up reports. The same protection covers any third party named in a report and the person the report is about. Access to a report file is restricted to the designated members of the Legal Department and to those the investigation makes it necessary to involve, and the restriction is applied to the file itself.
There is one exception, and it is narrow: disclosure is possible where it is a necessary and proportionate obligation imposed by law in the context of an investigation by a national authority or of judicial proceedings, including to safeguard the rights of defence of the person concerned. In that case the group informs the reporting person in writing before the disclosure and explains the reasons, unless that information would jeopardise the investigation or the proceedings.
- The group does not seek to identify the author of an anonymous report, and does not use message headers, access logs or document metadata for that purpose.
- The group does not ask a reporting person to justify why they reported, or to disclose how they came by the information, beyond what the investigation of the facts requires.
- The group does not tell the person a report is about who reported it.
- A breach of this confidentiality duty by a member of staff is a disciplinary matter, and Article 23(1)(c) of the Directive requires that it be penalised.
Retaliation is prohibited, and presumed
Article 19 of the Directive prohibits retaliation, including the threat of it and the attempt at it, against a person protected by this policy. The prohibition is not limited to dismissal and covers each of the measures listed below.
- Suspension, dismissal, or the equivalent measure for a self-employed person or a supplier.
- Demotion, withholding of promotion, transfer of duties, change of place of work, reduction in wages, or change in working hours.
- Withholding of training, a negative performance assessment or employment reference.
- A disciplinary measure, reprimand or other penalty, including a financial one.
- Coercion, intimidation, harassment or ostracism.
- Discrimination, or unfavourable and unfair treatment.
- Failure to convert a temporary contract into a permanent one where the worker had legitimate expectations of it, and non-renewal or early termination of a temporary contract.
- Harm to reputation, particularly on social media, and blacklisting on an informal or formal sector-wide basis.
- Early termination or cancellation of a contract for goods or services, cancellation of a licence or permit, and referral for psychiatric or medical treatment.
The group adds one operational rule to the legal one. Where a decision affecting the employment, engagement or contract of a person known to have reported is proposed, Human Resources and the Legal Department review it against the report before it takes effect, and the grounds are recorded in writing. The review does not exempt that person from ordinary management decisions; it establishes the grounds of a measure at the time it is taken.
Reporting outside the group
Internal reporting is not a precondition. Article 10 of the Directive gives a right to report directly to a competent external authority, and the group does not treat the exercise of that right as a breach of any duty of loyalty, confidentiality or contract. The internal channel is offered in addition to the external channels, and does not condition access to them.
- In the European Union: the authority designated by the Member State under Article 11 of the Directive, and where relevant the Union institutions, bodies, offices and agencies named in Article 10, including the European Anti-Fraud Office and the European Public Prosecutor Office.
- In the United Kingdom: the employer, or a prescribed person listed in the Public Interest Disclosure (Prescribed Persons) Order 2014, under section 43F of the Employment Rights Act 1996. The Public Interest Disclosure Act 1998 inserted that Part IVA into the 1996 Act; a qualifying disclosure under section 43B must be made in the reasonable belief that it is in the public interest, and sections 47B and 103A give the remedies for detriment and for dismissal.
- In the United States: the Securities and Exchange Commission under Section 21F of the Securities Exchange Act, the Occupational Safety and Health Administration for a complaint under section 806 of the Sarbanes-Oxley Act, and the Department of Justice.
- Elsewhere the group operates: the competent authority of that jurisdiction — for example the Agence de prévention et de lutte contre la corruption in the Democratic Republic of the Congo, the Ethics and Anti-Corruption Commission in Kenya, the Economic and Financial Crimes Commission in Nigeria, and the Corrupt Practices Investigation Bureau in Singapore.
Public disclosure — to the press or otherwise to the public — is protected under Article 15 of the Directive where the person first reported externally, or internally and then externally, and no appropriate action was taken within the applicable timeframe; or where the person has reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest, or that external reporting carries a risk of retaliation or offers little prospect of the breach being effectively addressed. Where those conditions are met, the group brings no proceedings against the person who made the disclosure and supports none.
Personal data and records
A report is a processing of personal data. Processing is limited to what the handling of the report requires. Personal data that are manifestly not relevant to the handling of a report are not collected, and where they are collected accidentally they are deleted without undue delay, as Article 17 of the Directive and Article 5(1)(c) of the GDPR require. The Data Protection Office is consulted on the processing described in this section and on any change to it.
| Record | Purpose | Legal basis | Retention |
|---|---|---|---|
| The report and its attachments | Assessing admissibility, investigating, ending the breach | GDPR Article 6(1)(c) where the channel is a legal obligation; Article 6(1)(f) elsewhere, the interest being the detection of breaches | While the file is open, then five years from closure, unless proceedings or a legal retention duty require longer |
| Identity and contact details of the reporting person, where given | Acknowledging receipt, asking questions, giving feedback, protecting against retaliation | Same, with the confidentiality duty of Article 16 of the Directive | Same, held separately from the file with access restricted to the designated members of the Legal Department |
| Recording or written minute of an oral report | Establishing what was said, and allowing the reporting person to correct it | Consent for a recording, Article 18(2) of the Directive | Same as the file |
| Special category data, where a report unavoidably contains them | Investigating the facts reported | GDPR Article 9(2)(f) or 9(2)(g), depending on the matter | Same as the file, with access further restricted |
| Register of reports without identifying data — date, subject matter, outcome | Oversight of the channel, reporting to the governing body, publication of aggregate figures | GDPR Article 6(1)(f) | Ten years |
| Personal data manifestly not relevant to the handling of the report | None | None | Deleted without undue delay |
The rights of access, rectification, erasure and objection apply to a report file, and so does one restriction: the right of access does not extend to obtaining the identity of the reporting person, because Article 16 of the Directive protects it and Article 23 of the GDPR allows that restriction. In the Democratic Republic of the Congo, where the group has its registered office, the processing of personal data is governed by Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique. Requests and questions on the processing described here are addressed to the Data Protection Office at contact@parousiagroup.com.
The person a report is about
Article 22 of the Directive protects the person concerned by a report as well. That person keeps the presumption of innocence, the right to an effective remedy, the right to a fair trial and the rights of defence, including the right to be heard and to access the file. The identity of a person concerned is protected for as long as the investigation is ongoing, on the same terms as that of the reporting person.
The group takes no measure against a person on the basis of an unverified allegation. A report that its author knew to be false when making it is not protected: Article 23(2) of the Directive requires that such conduct be penalised, and the group treats it as a disciplinary matter and, where the law allows, as a matter for the courts. The distinction between a mistaken report and a false one rests on the standard of reasonable grounds set out in the first section of this policy.
Governance and review of this policy
The Legal Department owns this policy, operates the reporting channel, designates the members of the department who receive and follow up reports, and keeps the register of reports described above. The Compliance Department is informed where the facts fall under the anti-bribery and anti-corruption policy; Human Resources is involved where a measure affecting the employment of a protected person is proposed; the Data Protection Office is consulted on the processing of the data held in a report file.
The Legal Department reports to the board’s ethics and compliance committee on the operation of the channel, on the basis of the register kept without identifying data. It reviews this policy at least once a year, and whenever the law applicable in a country where the group operates, the organisation of the channel or a finding made under this policy requires an amendment. The version in force is the one published on this site, and the date it was last reviewed is carried at the head of this document.
The deadlines, the duty of confidentiality and the prohibition of retaliation set out above are obligations of law and of this policy, and they apply to every report from the day it is received.
监管依据
- Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law
- Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 9, 15 and 23
- Public Interest Disclosure Act 1998 (UK), inserting Part IVA into the Employment Rights Act 1996
- Employment Rights Act 1996 (UK), sections 43B, 43C, 43F, 47B and 103A
- Public Interest Disclosure (Prescribed Persons) Order 2014 (SI 2014/2418)
- Dodd-Frank Wall Street Reform and Consumer Protection Act 2010, section 922 — Securities Exchange Act section 21F (15 U.S.C. 78u-6)
- SEC Rule 21F-17(a) (17 C.F.R. 240.21F-17)
- Sarbanes-Oxley Act of 2002, section 806 (18 U.S.C. 1514A)
- Loi n° 2016-1691 du 9 décembre 2016 (Sapin II), modifiée par la loi n° 2022-401 du 21 mars 2022
- Hinweisgeberschutzgesetz of 31 May 2023 (Germany)
- Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique (DRC)
- UK Bribery Act 2010
- Foreign Corrupt Practices Act (15 U.S.C. 78dd-1 et seq.)
- United Nations Convention against Corruption (2003)
