Appendix No. 1 to the Resolution

of the Management Board of Donegal Sp. z o.o.

dated 14-10-2024

Procedure for Reporting Violations of Law and Taking Follow-up Actions
applicable at Donegal Sp. z o.o. in Rzeszów

Pursuant to Article 24(1), Article 24(3)(2), and Article 25(1) of the Act of 14 June 2024 on the Protection of Whistleblowers (Journal of Laws 2024, item 928), after consultations with representatives of persons performing work for Donegal Sp. z o.o. in Rzeszów, the following Procedure is established.

Chapter I – General Provisions

§ 1

  1. This Procedure regulates the rules for reporting violations of law and taking follow-up actions in accordance with the Act on the Protection of Whistleblowers.
  2. Internal reports are accepted, meaning oral or written communication of information about a violation.
  3. Anonymous reports are not accepted.

§ 2

Whenever this Procedure refers to:

  1. Whistleblower – a natural person referred to in Article 4(1) and (2) of the Act.
  2. Donegal – Donegal Sp. z o.o., ul. Krakowska 154, 35-506 Rzeszów, Poland, KRS: 0000248060, NIP: 813-013-97-81, REGON: 690637480, share capital PLN 600,000.00.

Chapter II – Subject of the Report

§ 3

  1. A violation of law means an act or omission inconsistent with the law, including:
    1. corruption
    2. public procurement
    3. financial services, products and markets
    4. anti-money laundering and counter-terrorism financing
    5. product safety and compliance
    6. transport safety
    7. environmental protection
    8. radiation protection and nuclear safety
    9. food and feed safety
    10. animal health and welfare
    11. public health
    12. consumer protection
    13. privacy and personal data protection
    14. network and IT system security
    15. financial interests of the State Treasury, local government units and the EU
    16. EU internal market rules, including competition and state aid
    17. constitutional rights and freedoms
  2. The procedure applies to reporting such violations.
  3. The whistleblower may report violations obtained in a work-related context (past, present, or future).

Chapter III – Responsible Unit

§ 4

  1. The HR Department is responsible for receiving reports and follow-up actions.
  2. The HR Department maintains the register of reports.
  3. Authorized personnel act based on written authorization from the Management Board.

Chapter IV – Reporting Methods

§ 5

  1. Reports may be submitted:
    • orally – during a meeting within 14 days
    • in writing – in a sealed envelope marked “Confidential – HR Department”
  2. Oral reports are documented in a meeting protocol approved by the whistleblower.
  3. The report should include:
    • personal data of the whistleblower and concerned person
    • contact details
    • description of the violation
    • work-related context
    • grounds for believing the information is true

§ 6

  1. Confirmation of receipt is provided within 7 days (if contact details are provided).
  2. Information about personal data processing is also provided.

Chapter V – Handling Reports

§ 7

  1. Initial verification is conducted by the HR Department.
  2. Anonymous reports are not processed.
  3. Additional information may be requested if necessary.
  4. Valid reports are forwarded for further action.

Chapter VI – Follow-up Actions

§ 8

  1. Actions aim to verify the report and prevent violations.
  2. They include internal investigations.
  3. Results include an assessment and recommendations.
  4. Legal proceedings may be initiated if necessary.

§ 9

  1. Feedback is provided within 3 months.
  2. It includes actions taken or planned.

Chapter VII – Register of Reports

§ 10

  1. Each report is registered.
  2. The register includes:
    • report number
    • subject
    • personal data
    • contact details
    • date
    • actions taken
    • closure date
  3. Data is stored for 3 years.

Chapter VIII – Personal Data Protection

§ 11

  1. Whistleblower data is protected.
  2. Only authorized persons have access.
  3. Identity is confidential unless consent is given.
  4. Irrelevant data is deleted within 14 days.
  5. Data is stored for 3 years and then deleted.

Chapter IX – External Reporting

§ 12

  1. Reports may also be submitted to:
    • Ombudsman
    • public authorities
    • EU institutions
  2. No prior internal report is required.

Chapter X – Final Provisions

§ 13

  1. The procedure is published internally and on the website.
  2. It enters into force on 22-10-2024.

Management Board of Donegal Sp. z o.o.

  • President of the Management Board – Jerzy Chrzanowski
  • Vice President – Grażyna Chrzanowska
  • Board Member – Paweł Chrzanowski
  • Board Member – Marcin Chrzanowski