Skip to content

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Compliance Italian D.lgs. n. 24/2023 #3506

Closed
simonelucarellisoftec opened this issue Jun 29, 2023 · 5 comments
Closed

Compliance Italian D.lgs. n. 24/2023 #3506

simonelucarellisoftec opened this issue Jun 29, 2023 · 5 comments

Comments

@simonelucarellisoftec
Copy link

Proposal

Hi developers!

I'd like to know if developments in order to be compliant with the new italian law (D.lgs. n. 24/2023) are scheduled, and, if they are, when you plan to release them.

We are using your platform in several business environments and we're interested in particolar in 2 features mandatory in italian law:

  1. notify the user for received reports ("segnalazioni");
  2. alert the user for upcoming 90 days overdue date, starting from 7 days after report ("segnalazione") creation date.

Hope to receive good news!
Thank you,

Simone Lucarelli
Softec S.p.A.
www.softecspa.com

Motivation and context

Terms of law in Italian D.lgs. n. 24/2023

@gianlucagilardi
Copy link

gianlucagilardi commented Jun 29, 2023

Hi there!

  1. What do you mean with "notify the use for received reports"? If the "user" is the whistleblower, they get the receipt of the filed report immediately upon filing (it is the 16-digit code displayed upon filing); if the "user" is the recipient, they already receive an email notifying the report upon the submission itself has been completed.
  2. The platform does not alert the whistleblower (quite obviously), but it already has a reminder fore recipients set at 90 days after the report has been filed.

@simonelucarellisoftec
Copy link
Author

simonelucarellisoftec commented Jun 29, 2023 via email

@gianlucagilardi
Copy link

Cerchiamo di gettare un po' di luce :)

  1. l'art. 5 del D. Lgs 24/23 testualmente dice:
    " 1. Nell'ambito della gestione del canale di segnalazione interna,
    la persona o l'ufficio interno ovvero il soggetto esterno, ai quali
    e' affidata la gestione del canale di segnalazione interna svolgono
    le seguenti attivita':
    a) rilasciano alla persona segnalante avviso di ricevimento della
    segnalazione entro sette giorni dalla data di ricezione
    ; [...]"

In piattaforma l'"avviso di ricevimento della segnalazione" è, per l'appunto, il codice di 16 cifre che viene rilasciato al momento in cui la segnalazione "inviata al server" è "ricevuta dal server" ed acquisita al sistema.

  1. Il reminder non è un requisito di compliance: la norma prevede che entro 90 giorni debba essere notiziato il segnalante (" d) forniscono riscontro alla segnalazione entro tre mesi dalla data dell'avviso di ricevimento [che per noi è la data della segnalazione giusto quanto sopra N.d.R.] o, in mancanza di tale avviso, entro tre mesi dalla scadenza del termine di sette giorni dalla presentazione della segnalazione; ") ma nulla dice la norma su eventuali reminder ai riceventi. Detto questo, e' possibile impostare in piattaforma un reminder di scadenza.

Piu' in generale, la piattaforma e' al 99% conforme: sono in rilascio per il 15 luglio due funzionalità (messaggistica vocale e cancellazione selettiva del contenuto della segnalazione) che porteranno la compliance al 100%.

@simonelucarellisoftec
Copy link
Author

simonelucarellisoftec commented Jun 29, 2023 via email

@evilaliv3
Copy link
Member

Hello! I confirm this intepretation that is the same used in italy and other european countries by the different users of globaleaks and also implementors of other digital tools.

We consider the regulator wanted to ensure that in front of a postmail or a voice mail the whistleblower is informed by the confirmation of reception and have possibility to verify the status of the report (e.g. know the handling is overdue); Thes aspect are solved within a digital plaform by informing the user that the report was stored correctly and giving them access that enables them to continuously stay up to date with the handling of their report..

@evilaliv3 evilaliv3 removed their assignment Jun 30, 2023
@globaleaks globaleaks locked and limited conversation to collaborators Jun 30, 2023
@evilaliv3 evilaliv3 converted this issue into discussion #3507 Jun 30, 2023

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

Labels
None yet
Development

No branches or pull requests

3 participants