
GOVERNANCE INFORMATION
ETHICAL BEHAVIOR AND MORAL STANDARDS
We are strongly committed to running our activities in accordance with local regulatory frameworks and with the highest ethical and moral standards, thus actively working to prevent any type of unethical business practice.
Zero tolerance for corruption
We have a policy of zero tolerance towards corruption and, in 2017, the group Anti-Corruption Policy was approved, intending to ensure daily activities are carried out ethically, protecting value creation and those core values on which the Company's activities are founded. The provisions and guidelines contained in the Policy are inspired by our corporate culture and by the behavioural principles stated in our Code of Ethics, which have been developed by analysing the activities potentially exposing Amplifon to corruption risk.
To support this, during 2020 a new Whistleblowing System was introduced with the aim to guarantee a safe, respectful and protected workplace. It constitutes a set of rules and means of communication to report, with the guarantee of confidentiality, any breach or well-founded suspicion of a breach, as well as any behavior that does not comply with the Code of Ethics, the Anti-Corruption Policy, internal policies and procedures (such as, for example, the Organizational Model 23 for the Parent Company), as well as laws and regulations applicable to each company of the Group.
Business ethics and fair competition
All our people and those representing us in various ways are required to uphold the high standards established in our Code of Ethics.
We have an internal control and risk management system, a set of rules, procedures and organizational structures to identify, measure, manage and constantly monitor the main risks.
Lastly, as stipulated in our Code of Ethics, people in direct contact with customers must provide full and accurate information about products and services, as well as any other information necessary to be able to make an informed decision.
In addition, we respond to competition by constantly monitoring market developments and guiding its investments primarily towards differentiating the service we offer and making new acquisitions, always maintaining a fair competition approach.
TAX-RELATED TRANSPARENCY
SUPPLIERS QUALIFICATION AND STANDARDS OF BEHAVIOR
CYBERSECURITY AND DATA PRIVACY
Privacy and data protection are increasingly in the spotlight. Protecting the data we hold is more than a priority for us: it is an essential condition to earn the trust people place in us every day. Collecting and processing information is not only vital for us to provide our services, but it also enables us to innovate and guarantee the most advanced solutions.
THE HIGHEST PRIVACY STANDARDS
We continually invest in data protection through a set of management tools for the application of the requirements as foreseen by national and international legislation. Upon the entry into force of EU Regulation 2016/679 (GDPR), we have implemented all the necessary steps to be fully compliant with legislation throughout Europe.
During 2024, in order to improve Amplifon's privacy posture and cybersecurity, numerous activities were implemented including: training courses on cybersecurity issues, internal communication campaigns to increase awareness on the subject, guidelines for the management of cross-border transfers of personal data and on the use of artificial intelligence, and the performance of impact assessments on more sensitive processing. The main objective of the Global Privacy Policy is to ensure the fair, secure and lawful processing of personal data of employees, customers, prospects and others. The monitoring process includes regular audits, risk assessments and continuous updates to ensure that the protection measures remain effective.
PRIVACY & SECURITY BY DESIGN
GOVERNANCE AND SECURE BEHAVIORS
In 2021 we created a dedicated cybersecurity team, furtherly reinforced, to ensure increasing coverage of cyber issues, to create shared responsibilities and strengthen active collaboration across functions.
Specific training is provided to all employees to enhance their awareness of risks and cyber threats as well as foster secure behavior throughout the organization, in a continuous learning process. Particularly, our hearing care professionals and in-store staff are trained to correctly handle customers’ sensitive data. Furthermore, our Code of Ethics prohibits any data disclosure and utilization for purposes other than those established
IT SECURITY
Initiatives were continuously implemented to reduce cybersecurity risks, with a particular focus on the security of networks, services and endpoint equipment, improvement of monitoring, detection activities as well as increasing the awareness of all collaborators. Investments in the ICT architecture and security protection/detection/response against new IT security threats continued, thereby contributing to Amplifon’s digital transformation.
Moreover, the activities to obtain the ISO27001 (Corporate) certification and HiTrust continued, in the light of the SOC2 certification already valid in the United States. Moreover, we continued the process to formalize the Information Security Document Framework, aimed at regulating the security processes involving people and technologies.
In addition to these activities, Amplifon focused on the adaptation to the requirements of the new European Network and Information Systems Directive 2 (NIS2).