Whistleblowing
Paper Service S.r.l.
To combat and prevent corruption, maladministration and, more generally, breaches of the law, Paper Service S.r.l., in compliance with the provisions of Italian Legislative Decree No. 24 of 10 March 2023, entitled “Implementation of Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law and laying down provisions concerning the protection of persons who report breaches of national regulatory provisions”, as well as with the guidance issued by ANAC, has established dedicated internal reporting channels.
These channels allow stakeholders to report, securely and confidentially, conduct, acts or omissions that may constitute breaches of the Company’s internal policies or applicable external laws and regulations.
Persons working within the Company’s professional context are entitled to submit a report, including:
- employees;
- self-employed workers;
- collaborators, freelancers and consultants;
- paid and unpaid interns and trainees;
- shareholders and persons performing administrative, management, control, supervisory or representative functions, even where such functions are exercised on a de facto basis.
A report may be submitted:
- while the legal or professional relationship is ongoing;
- during the probationary period, where the information was obtained during the recruitment process or other pre-contractual stages;
- before the legal or professional relationship has begun, where the information concerning the breach was obtained during the recruitment process or other pre-contractual stages;
- after the legal or professional relationship has ended, where the information concerning the breach was obtained before its termination, including by retired workers.
Anonymous reports are permitted, provided they contain sufficiently detailed information, and are handled in the same way as reports submitted by identified individuals.
In such cases, protection against retaliation will apply only if the reporting person is subsequently identified.
Breaches of National Law
Offences relating to the matters specifically listed in Article 2, paragraph 1, letter (a), points 3–6 of Italian Legislative Decree No. 24/2023, including breaches of consumer protection legislation, personal data protection rules and environmental regulations.
Breaches of European Union Law
- Offences falling within the scope of European Union acts concerning the following sectors: public procurement; financial services, products and markets; prevention of money laundering and terrorist financing; product safety and compliance; transport safety; environmental protection; radiation protection and nuclear safety; food and feed safety; animal health and welfare; public health; consumer protection; privacy and personal data protection; and the security of network and information systems.
- Acts or omissions affecting the financial interests of the European Union, including fraud, corruption and any other unlawful activity relating to Union expenditure.
- Acts or omissions concerning the internal market, including, for example, breaches of competition and State aid rules.
- Acts or conduct that undermine the purpose or objective of the provisions contained in European Union acts, such as conduct that infringes the principle of free competition.
The following matters cannot be reported through the whistleblowing channel:
- information that is clearly unfounded, information already entirely in the public domain, and information obtained solely from unreliable rumours or hearsay;
- complaints, claims or requests relating to the reporting person’s personal interests, or to those of a person who has filed a report with the judicial or accounting authorities, where they concern exclusively their individual employment or public-sector employment relationship, including relationships with their direct superiors. This includes, for example, reports concerning employment disputes and pre-litigation proceedings, discrimination between colleagues, interpersonal conflicts between the reporting person and another employee or a manager, and personal data processing carried out within an individual employment relationship where there is no harm to the public interest or to the integrity of a public administration or private entity;
- breaches already mandatorily regulated by European Union or national acts listed in Part II of the Annex to the Decree, or by national provisions implementing the European Union acts listed in Part II of the Annex to Directive (EU) 2019/1937, even where they are not listed in Part II of the Annex to the Decree. This includes, for example, reports governed by Italian Legislative Decree No. 385 of 1 September 1993, the Consolidated Banking Act, and Italian Legislative Decree No. 58 of 24 February 1998, the Consolidated Law on Financial Intermediation;
- breaches concerning national security, as well as procurement relating to defence or national security matters, unless those matters fall within the relevant secondary legislation of the European Union;
- issues relating to services provided by the Company, such as customer complaints.
Reports must be as detailed and specific as possible and should include all information useful to the body responsible for handling the report, enabling it to carry out the necessary checks and investigations and assess whether the report is well founded.
For this purpose, reporting persons should provide at least the following information:
- the time and place in which the reported event occurred;
- a description of the event, including all known circumstances relating to how, when and where it occurred;
- the personal details or any other information that may allow the person responsible for the reported conduct to be identified;
- unless the report is anonymous, the personal details of the reporting person, together with their position or role within the Company;
- confirmation that there are no personal interests connected with the report and that it is being submitted in good faith;
- any information or evidence, together with the relevant supporting documents, that may help verify the reported facts, including the names of any other persons who may be able to provide information about them;
- where the report is not anonymous, the reporting person’s identification details, such as their first name, surname and job title. As explained below, these details are protected by specific technical and organisational security measures designed to ensure the complete confidentiality of the reporting person’s identity.
Where a written report is submitted through the Whistleblowing Portal, the reporting person will be guided in providing this information by the questions included in the reporting form.
Where a report does not contain sufficient detail, the body responsible for handling it may request additional information from the reporting person through the Whistleblowing Portal or in person, where the reporting person has requested a direct meeting.
Reports must not contain excessive personal data and should include only the information necessary to demonstrate that the report is well founded. As a general rule, special-category personal data and personal data concerning health or criminal matters should therefore not be included.
The reporting person may submit a written or oral report using the following internal reporting channels:
Through the Whistleblowing Portal
https://whistlesblow.it/c/paper-service-srl/1
Paper Service has implemented an online platform that allows reports to be submitted either in writing, by completing a questionnaire, or orally, by using a voice mailbox.
The Portal will ask the reporting person whether they wish to disclose their identity. In any case, the reporting person may provide their personal details at a later stage, including through the Portal’s messaging system.
When the report is submitted, the Portal will issue the reporting person with a unique identification code, or ticket. This code is known only to the reporting person and cannot be recovered if it is lost.
The ticket allows the reporting person to access their report through the Portal in order to:
- monitor its progress;
- provide additional information or evidence;
- disclose their personal details;
- respond to any requests for further clarification.
Through a Direct Meeting
A direct meeting may be requested by contacting the dedicated email address of the body responsible for handling reports:
The reporting person may choose to seek assistance from a trusted individual who, acting as a “Facilitator” under the applicable legislation, is entitled to the same protections as the reporting person.
When a report is submitted through the Whistleblowing Portal, the reporting person receives a code that can be used to access the report through the Portal in order to:
- monitor its progress;
- provide additional information to support and further substantiate the report;
- provide their personal details;
- respond to any requests for further clarification.
In all cases, the body responsible for handling the report:
- issues an acknowledgement of receipt to the reporting person within seven days of receiving the report;
- responds promptly to any requests submitted by the reporting person through the reporting channels, including the messaging system available on the platform;
- provides feedback on the report within three months of the date of the acknowledgement of receipt or, where no acknowledgement was issued, within three months from the expiry of the seven-day period following submission of the report.
The body responsible for handling reports consists of an internal Company representative, namely the Quality Manager.
As the recipient of the report, the body responsible for handling it:
- operates autonomously and independently;
- ensures a fair and impartial assessment of every report received;
- complies with confidentiality obligations, particularly regarding the identity of the reporting person, the reported person and any other individuals involved, including facilitators, family members, colleagues and witnesses;
- manages the report by assessing its admissibility and conducting the necessary investigation into the reported facts or conduct;
- communicates with the reporting person, including by issuing acknowledgements of receipt, closure notices and requests for or exchanges of information;
- informs the reporting person of the outcome, including the measures planned, adopted or to be adopted in response to the report and the reasons for the decision;
- ensures that this procedure and the other reporting channels provided for under Italian Legislative Decree No. 24/2023—including external reporting, public disclosure and reporting to the competent authorities—are adequately publicised, with particular reference to the conditions for accessing them, the competent bodies and the applicable procedures.
Where a report is submitted to a person other than the individual identified and authorised by the Company, that person must forward it to the competent body within seven days of receipt and simultaneously inform the reporting person that it has been transferred.
Only in the event of the prolonged unavailability of the primary body will an alternate body be appointed, consisting of the internal Head of the Secretariat.
Where the reporting person believes that the body responsible for handling the report has a conflict of interest, the report may be submitted through the external reporting channel managed by ANAC.
The Company guarantees the confidentiality of the reporting person’s identity from the moment the report is received, in accordance with applicable legal requirements.
For this purpose, the reporting person’s identifying personal data are not directly visible within the report and are stored in such a way that they can be accessed only by the body responsible for handling the report.
The Company adopts all safeguards and technical and organisational measures required by law to protect the confidentiality of the reporting person’s identity, ensuring that it is not disclosed to third parties without the reporting person’s express consent, except in cases involving reports made in bad faith or reports of a defamatory nature.
These measures include the redaction of personal data, particularly those relating to the reporting person, as well as to other individuals whose identity must remain confidential under Italian Legislative Decree No. 24/2023, including the facilitator, the reported person and any other persons mentioned in the report.
Such data will also be redacted where, for investigative purposes, other individuals need to be informed of the contents of the report or of any documentation attached to it.
In disciplinary proceedings, the reporting person’s identity may not be disclosed where the disciplinary charge is based on findings that are separate from and additional to the report, even where those findings result from it.
The reporting person’s identity may be disclosed only where:
- the charge is based, in whole or in part, on the report itself, and knowledge of the reporting person’s identity is strictly necessary for the defence of the person concerned; and
- the reporting person has given their consent.
In such cases, the Company will always inform the reporting person in advance, in writing, of the reasons requiring the disclosure of their identity.
No direct or indirect retaliation or discrimination may be taken against anyone who has submitted a report in good faith, regardless of whether the report is ultimately found to be substantiated.
Penalties may be imposed on anyone who breaches the measures protecting the reporting person or the confidentiality of their identity.
Protection is not guaranteed where a report is submitted intentionally or with gross negligence, or where it proves to be false, unfounded, defamatory, or made solely for the purpose of harming the Company, the reported person, or any other individuals involved.
Where the reporting person can be identified, penalties may be imposed in cases involving reports submitted intentionally or with gross negligence, or reports that are false, unfounded, defamatory, or intended solely to harm the Company, the reported person, or other persons concerned.
The Company may also take any appropriate legal action.
ANAC is the authority responsible for managing the external reporting channel. A report may be submitted to ANAC where one of the following conditions applies:
- The mandatory activation of an internal reporting channel is not required within the relevant work-related context, or, although mandatory, the channel has not been activated or does not comply with Article 4 of Italian Legislative Decree No. 24/2023.
- The reporting person has already submitted a report through the internal channel, but no appropriate follow-up action has been taken.
- The reporting person has reasonable grounds to believe that an internal report would not be effectively followed up or that submitting it could expose them to a risk of retaliation.
- The reporting person has reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest.
For further information, please refer to the institutional website of the Authority under the Whistleblowing section at www.anticorruzione.it.

