Skip to Main content

Procedure for Reporting Information on Breaches

I. Introduction

  1. The Company adopts this Procedure in connection with the Whistleblower Protection Act (ustawa o ochronie sygnalistów), which was passed on 14 June 2024 and formally promulgated on 24 June 2024. It implements the EU Whistleblower Directive (2019/1937) in Poland.
  2. Reporting information on Breaches is an expression of social responsibility and concern for the good of the Company, as well as for the good of its employees and associates, and of loyalty towards them.
  3. Any person in a professional relationship with the Company who has witnessed or has knowledge of a Breach should make a Report in accordance with the Procedure. Using the Procedure does not preclude the possibility of pursuing the same purpose through official line-management channels.
  4. Making a Report is a right of the Company’s employees and associates. A person who witnesses an obvious Breach, in particular a person employed by the Company in a managerial position, who fails to report it, may be held liable under employment law. Such a person may bear liability in particular if, through their omission, they endanger the life and health of others or contribute to material, social or reputational damage of significant proportions.

II. Purpose

  1. The Procedure is addressed to all employees, associates and contractors of the Company, persons bound to the Company by a civil-law contract, as well as other persons who wish to make a report concerning the Company’s activities.
  2. This Procedure has the following objectives:
    1. to ensure the receipt of Reports containing information on breaches of legal provisions and of the provisions of the Company’s internal regulations, as well as of the provisions of external regulations which the Company has undertaken to comply with, through the reporting channels indicated in the Procedure,
    2. to guarantee that every Report will be examined in a confidential manner, with full protection of the identity of the Reporting Person, of the persons concerned by the Report and of third parties indicated in the Report, inter alia by virtue of the fact that the Report reaches a limited circle of persons who guarantee such confidentiality,
    3. to introduce protective mechanisms designed to prevent the risk of retaliatory actions,
    4. to ensure that every Report will be examined in a reliable manner, based on the transparent rules described in this Procedure,
    5. to prepare a summary of each investigation in the form of a report which will make it possible to take specific actions leading to the removal of the effects of the Breach as well as to the prevention of further Breaches of the same kind.

III. Definitions

  1. Company – Next Film sp. z o.o. with its registered office in Warsaw, at ulica Czerska 8/10, 00-732 Warsaw.
  2. Compliance Officer – the person appointed, by resolution of the Company’s Management Board, to perform the function of the Company’s Compliance Officer.
  3. Breach Committee – a committee appointed for the purpose of examining a Report, operating on the basis of the principle of confidentiality.
  4. Breach – an act or omission of persons connected with the Company, within the scope of or related to their professional activity, which violates legal provisions, the provisions of the Company’s internal regulations or of external regulations which the Company has undertaken to apply.
  5. Person assisting in making a Report – a natural person who assists the Reporting Person in making the report and whose assistance should not be disclosed.
  6. Person associated with the Reporting Person – a natural person who may experience retaliatory actions, including a co-worker or a person closest to the Reporting Person within the meaning of Article 115 § 11 of the Polish Criminal Code (Kodeks karny).
  7. Procedure – this Procedure for Reporting Information on Breaches at Next Film sp. z o.o.
  8. Reporting Person – a natural person who has made a Report.
  9. Report – information about a Breach or a suspected Breach.
  10. Retaliatory actions – direct or indirect acts or omissions in a work-related context which are prompted by a Report and which violate or may violate the rights of the Reporting Person, or cause or may cause unjustified harm to the Reporting Person.
  11. External report – information about a breach of law falling within the catalogue set out in Article 3 of the Whistleblower Protection Act (ustawa o ochronie sygnalistów), addressed directly to the Commissioner for Human Rights (Rzecznik Praw Obywatelskich), bypassing this Procedure.

IV. Who may make a Report

  1. Any person who has information about a Breach may make a Report.
  2. In particular, a Report may come from:
    1. an employee (including a temporary employee),
    2. a person employed on a basis other than an employment relationship, including under a civil-law contract,
    3. an entrepreneur,
    4. a shareholder,
    5. a member of a governing body of the Company,
    6. a person performing work under the supervision and direction of a contractor, subcontractor or supplier of the Company (including under a civil-law contract),
    7. an intern,
    8. a volunteer,
    9. a trainee.
  3. The Reporting Person may make a Report concerning a Breach of which they became aware before entering into a relationship with the Company (e.g. at the recruitment stage), as well as after such a relationship has ended.
  4. A Report should concern an act or omission related to the Reporting Person’s work for, or cooperation with, the Company.

V. What may be the subject of a Report

  1. The subject of a Report may be information about any Breach connected with the activities of the Company or of its employees or associates.
  2. A Report may concern a breach of legal provisions, of the provisions of the Company’s internal regulations, as well as of external regulations which the Company has undertaken to comply with.
  3. The Reporting Person does not have to indicate which legal provision or which regulation has been breached. A description of the act or omission which, in the Reporting Person’s assessment, constitutes a Breach is sufficient.
  4. Examples of information that may be reported:
    1. corruption,
    2. public procurement,
    3. prevention of money laundering and terrorist financing,
    4. product safety and compliance with requirements,
    5. environmental protection,
    6. public health,
    7. consumer protection,
    8. protection of privacy and personal data,
    9. security of networks and ICT systems,
    10. fraud,
    11. breach of the principles of integrity,
    12. food safety.
  5. Reports concerning the occurrence at Next Film sp. z o.o. of incidents such as:
    1. unequal treatment,
    2. harassment,
    3. mobbing,
    4. discrimination,
    5. making offensive comments,
    Note: The above incidents must be reported exclusively in the manner set out in the Anti-Discrimination and Anti-Mobbing Policy at Next Film sp. z o.o.
  6. Should a report concerning the violations described in item 5 above be received through the channels described in this Procedure, it will be forwarded to the Officer for Counteracting Discrimination and Mobbing at Next Film sp. z o.o.
  7. Where a report concerns both Breaches within the meaning of this Procedure and the incidents described in item 5 above, it will be examined in its entirety in accordance with the provisions of this Procedure, with the proviso that selected members of the Committee for Counteracting Discrimination and Mobbing of Next Film sp. z o.o. may additionally be appointed to the composition of the Breach Committee.

VI. How to make a Report

  1. All channels used for receiving Reports ensure confidentiality. Confidentiality covers the identity of the Reporting Person, the content of the Report, as well as the very fact that a Report has been received.
  2. A Report may be made in writing:
    1. by sending a message to the e-mail address: naruszenia.next-film@helios.pl, to which the Compliance Officer has access,
    2. by post to the Company’s address, addressed to the Compliance Officer, with the annotation „poufne” (“confidential”).
  3. The Report should contain all information concerning the Breach that may help clarify the matter – a description of the incident, the date, the place, and the details of persons who may know about it or who witnessed it. If the Reporting Person has any evidence or documents relating to the Report, providing them will be helpful.
  4. The decision whether to provide their personal data rests with the Reporting Person. If the Reporting Person decides not to provide their personal data, the Report will be treated as anonymous.
  5. A report of an observed irregularity falling within the catalogue provided for in Article 3 of the Whistleblower Protection Act (ustawa o ochronie sygnalistów) may also be made, bypassing this Procedure, directly to the Commissioner for Human Rights (Rzecznik Praw Obywatelskich) or to another public authority whose competence covers the subject matter of the report (External report). In appropriate cases, an External report may also be made to institutions, bodies or organisational units of the European Union.
  6. An External report may be made through the channels indicated on the website of the Commissioner for Human Rights (https://bip.brpo.gov.pl/).
  7. In case of doubt as to which public authority the information about a breach should be addressed to, the matter should be reported to the Commissioner for Human Rights, who will, if necessary, refer the matter to the appropriate authority.

VII. Confidentiality

  1. Maintaining confidentiality consists in ensuring that the personal data of the Reporting Person and other information allowing their identity to be established will not be disclosed to unauthorised persons, except with the Reporting Person’s express consent, subject to the exception referred to in item 2 below.
  2. The Reporting Person’s data may be disclosed only where this is a necessary and proportionate obligation arising from legal provisions in connection with investigations conducted by public authorities or with pre-trial or judicial proceedings conducted by courts, including with a view to safeguarding the right of defence of the person concerned by the Report. In such a case, the Reporting Person is informed of the planned date of the transfer of the data.
  3. The protection of confidentiality also covers the data of third parties indicated in the Report and of the person whose acts or omissions the Report concerns.
  4. The protection of confidentiality also means that a minimal circle of persons will be involved in clarifying the matter. All persons participating in this process will be required to submit a written declaration undertaking to maintain secrecy with respect to the information obtained in the course of receiving and verifying the report and conducting the investigation.
  5. If the Reporting Person does not provide their personal data and their identity is established in the course of the investigation, their personal data will be protected in accordance with the rules described above.

VIII. What will happen to the Report

  1. The Reporting Person receives confirmation of receipt of the Report no later than within 7 days of the date of receipt of the Report, unless the Reporting Person has not provided data enabling such confirmation to be delivered.
  2. Upon receipt, the Report is analysed by the Compliance Officer. If necessary, and if the Reporting Person has left data enabling contact with them, actions will also be taken to supplement the content of the Report.
  3. The Compliance Officer undertakes preliminary steps consisting in registering the Report in the register of internal reports and opening an investigation.

IX. General rules of the investigation

  1. The investigation is conducted by the Compliance Officer (or a person authorised by them) or by the Breach Committee – depending on the subject matter of the Report.
  2. The Compliance Officer initially verifies the Report by determining whether it is manifestly unfounded. If the Report is found to be manifestly unfounded, the Compliance Officer provides appropriate feedback to the Reporting Person and closes the investigation.
  3. The investigation is also closed where the information contained in the Report does not allow the investigation to be continued, and the Reporting Person has not answered clarifying questions or has not left their contact details and it is impossible to supplement the content of the Report.
  4. In less complex cases, the investigation is conducted by the Compliance Officer (or a person authorised by them). In other cases, the investigation is conducted by the Breach Committee.
  5. The Breach Committee consists of the Compliance Officer (or a person authorised by them) and, additionally, one or two persons appointed by them whose knowledge will be useful for examining the Report.
  6. The Compliance Officer or the Breach Committee conducts a reliable investigation, the basic principles of which are as follows:
    1. striving to establish the actual facts of the case,
    2. gathering and taking evidence in a reliable manner – both evidence confirming and evidence challenging the fact of the Breach,
    3. ensuring the confidentiality of personal data – where necessary, personal data is anonymised or deleted.
  7. Upon completion of the steps taken as part of the investigation, the Compliance Officer (or a person authorised by them) or the Breach Committee draws up a report in which it finds that a Breach has or has not occurred. The report may also contain a finding of a Breach that was not indicated in the Report. The report may also contain recommended actions in connection with the findings made in the course of the investigation.
  8. The report is submitted to the Management Board and, for information, to the Compliance Officer (if the Compliance Officer is not a member of the Breach Committee). If the Report concerns a Breach committed by a Member of the Management Board, the report is submitted:
    1. where the Management Board consists of more than one member:
      1. to the remaining Members of the Management Board – if the report does not find that a Breach has occurred,
      2. to the remaining Members of the Management Board and, for information, to the Management Board of Helios S.A. – if the report finds that a Breach has occurred;
    2. where the Management Board consists of one member – for information, to the Management Board of Helios S.A. – regardless of whether the report finds that a Breach has occurred.
  9. The Compliance Officer, or a person authorised by them, provides feedback to the Reporting Person. The feedback must be provided within a period not exceeding 3 months from the confirmation of receipt of the Report (or, if no confirmation was sent, 3 months from the expiry of 7 days from the making of the Report), unless the Reporting Person has not provided data enabling such feedback to be delivered.

X. Detailed rules for conducting investigations

This Chapter sets out the detailed rules for conducting investigations, including in particular the principles, rights and obligations aimed at ensuring that the Report is examined in a reliable manner.

Receipt of the report
  1. The Compliance Officer registers the Report (in the register of internal reports) and verifies it for completeness of data. If the Report is incomplete, the Compliance Officer asks the Reporting Person to supplement it.
  2. The Compliance Officer is obliged to confirm to the Reporting Person that the Report has been received within 7 days of the date of its receipt.
  3. The information and requests referred to in items 1-2 above are sent to the Reporting Person provided that the Reporting Person has left data enabling such information to be sent to them.
  4. The Compliance Officer verifies the Report by determining whether it is manifestly unfounded. If the Report is found to be manifestly unfounded, the Compliance Officer provides appropriate feedback to the Reporting Person and closes the case concerning the Report. Feedback on the closure of the case due to the manifest unfoundedness of the Report should be provided to the Reporting Person within 21 days of the date of receipt of the Report.
  5. The case concerning the Report is also closed where the information contained in the Report does not allow the investigation to be continued, and the Reporting Person has not answered clarifying questions or has not left their contact details and it is impossible to supplement the content of the Report.
  6. If the analysis carried out by the Compliance Officer does not show that the Report is manifestly unfounded, the Compliance Officer continues the investigation.
Preliminary analysis of the Report and determination of the competent body
  1. Based on the preliminary analysis of the Report, the Compliance Officer assesses whether the matter to which the Report relates requires the appointment of the Breach Committee, or whether the Compliance Officer will be competent to examine it. The decision must be based on an analysis of the following elements:
    1. whether the content of the Report constitutes a Breach,
    2. the type of Breach described in the Report,
    3. the date on which the Breach was committed and its duration,
    4. the number of persons concerned by the Report,
    5. the number of persons affected by the Breach,
    6. the number of persons indicated by the Reporting Person as potential witnesses.
  2. In the case of Reports whose examination will not be time-consuming and will not require the hearing of numerous witnesses, and where the type of Breach indicates that no breach of legal provisions has occurred, the investigation may be conducted by the Compliance Officer. In all other cases, the investigation is conducted by the Breach Committee.
  3. Where the preliminary assessment led to the conclusion that the Compliance Officer is competent to examine the case, but in the course of the investigation it becomes necessary to change that decision, the Compliance Officer appoints the Breach Committee. In such a case, the Breach Committee takes into account the steps already carried out by the Compliance Officer and endeavours to avoid repeating them, unless this is necessary from the point of view of implementing the principle of a reliable investigation.
Breach Committee
  1. The Breach Committee is appointed by the Compliance Officer, who acts as its Chairperson and who appoints its remaining members. The Breach Committee may consist of two to three members. In justified cases, the Breach Committee may decide to expand its composition.
  2. Only persons whose knowledge will be useful for examining the Report may be members of the Breach Committee.
  3. Should circumstances arise which raise reasonable doubts as to the impartiality of a member of the Breach Committee, that member is obliged to refrain from taking part in the proceedings and to notify the Chairperson of the Breach Committee of those circumstances. The Chairperson may, on their own initiative or at the request of another member, remove from the proceedings a person in respect of whom there are reasonable doubts as to their impartiality.
  4. Before commencing any steps within the investigation, the members of the Breach Committee:
    1. receive a written authorisation from the Company to process personal data, and
    2. submit a declaration in which they undertake to maintain confidentiality in connection with the proceedings being conducted, which undertaking will remain valid also after the termination of the legal relationship between that person and the Company.
Steps within the investigation
  1. The task of the Compliance Officer or the Breach Committee within the investigation is:
    1. to verify the content of the Report,
    2. to gather information intended to lead to the clarification of the matter, by means of, inter alia, hearing witnesses, analysing documentation, and requesting persons involved in the matter to provide documents or information,
    3. to prepare a report on the investigation together with recommendations as to the further actions that need to be taken.
  2. The Compliance Officer or the Breach Committee conducts the investigation on the basis of the following principles:
    1. striving to establish the actual facts of the case,
    2. gathering and taking evidence in an exhaustive manner – both evidence confirming and evidence challenging the merits of the Report,
    3. the inadmissibility of disregarding a piece of evidence on the grounds that it is intended to demonstrate a circumstance contrary to the findings made so far,
    4. doubts which cannot be resolved are decided in favour of the person concerned by the Report,
    5. ensuring the confidentiality of personal data – where necessary, personal data is anonymised or deleted,
    6. respecting the rights of the participants in the investigation, in particular the rights of the Reporting Person and of the person concerned by the Report,
    7. carrying out the steps of the investigation in such a way that it is completed within a reasonable time.
  3. The Breach Committee and the Compliance Officer may make use of the support of an external or internal expert.
  4. The Compliance Officer or the Breach Committee informs the person concerned by the Report of the opening of the investigation, whereby this information is provided at an appropriate moment, taking into account the need for the undisturbed gathering of evidence, the prevention of the destruction or concealment of evidence, as well as the interests of the Reporting Person, the aggrieved party and the witnesses.
  5. In the course of the investigation, the Compliance Officer or the Breach Committee is entitled to hear witnesses and to request the provision of documents or information. Every person working for or cooperating with the Company is obliged to comply with the requests of the Compliance Officer or the Breach Committee.
  6. The parties to the proceedings (the Reporting Person and the person concerned by the Report) as well as persons appearing as witnesses undertake, in the form of a written declaration, to keep secret everything they learn in connection with the pending proceedings.
  7. The declarations referred to in Chapter VII item 4, Chapter X item 13.2 and Chapter X item 19 above are kept in the case files.
  8. Hearings of witnesses, parties to the proceedings and experts (internal and external) do not have to be recorded in minutes. Where minutes are taken, unrestricted access to the minutes is granted exclusively to the Compliance Officer or the members of the Breach Committee.
  9. The parties to the proceedings (the Reporting Person and the person concerned by the Report) may participate in a hearing together with one representative. The representative may be a family member of the party to the proceedings, an advocate, an attorney-at-law or a psychologist. The cost of the representative’s remuneration is borne by the party which appointed them.
  10. The parties to the proceedings have the right to submit evidentiary motions in order to demonstrate that the allegation of a Breach is founded or unfounded. The body conducting the investigation is not bound by an evidentiary motion and may decide not to take the evidence. A decision not to take evidence must be justified.
  11. All documents created in the course of the work of the Breach Committee are confidential.
Completion of the investigation
  1. Upon completion of the steps taken within the investigation, the Compliance Officer or the Breach Committee draws up a report in which it may find:
    1. that a Breach has occurred or that it has not occurred,
    2. that, on the basis of the available evidence, it is unable to determine whether a Breach has occurred,
    3. that a Breach has occurred which was not indicated in the Report.
  2. The report may also contain recommended actions in connection with the findings made in the course of the investigation, in particular where a Breach has been found to have occurred.
  3. The report is submitted by the Compliance Officer or the Chairperson of the Breach Committee to the Company’s Management Board and, for information, to the Compliance Officer (if the Compliance Officer is not a member of the Breach Committee). If the Report concerns a Breach committed by a Member of the Management Board, the report is submitted:
    1. where the Management Board consists of more than one member:
      1. to the remaining Members of the Management Board – if the report does not find that a breach has occurred,
      2. to the remaining Members of the Management Board and, for information, to the Management Board of Helios S.A. – if the report finds that a breach has occurred;
    2. where the Management Board consists of one member – for information, to the Management Board of Helios S.A. – regardless of whether the report finds that a Breach has occurred.
  4. Making the report or any part thereof available to other persons requires the consent of the Management Board.
  5. After the report has been submitted, the Chairperson of the Breach Committee or the Compliance Officer closes the investigation.
  6. The Compliance Officer, or a person authorised by them, provides the Reporting Person with feedback on the planned or taken follow-up actions (or on the conduct of the investigation if it has not been completed) and the reasons for such actions.
  7. The feedback must be provided within a period not exceeding 3 months from the confirmation of receipt of the Report (or, if no confirmation was sent, 3 months from the expiry of 7 days from the making of the Report), unless the Reporting Person has not provided data enabling such feedback to be delivered.
  8. The Compliance Officer, or a person authorised by them, informs the person concerned by the Report of the outcome of the investigation.
Follow-up actions
  1. The Company’s Management Board is obliged to take actions aimed at eliminating the irregularities found as a result of the investigation and counteracts their recurrence. The Management Board designates the persons responsible for carrying out these actions.
  2. Where a Breach is found to have been committed by a person in respect of whom the Company is the employer, the Management Board decides on taking disciplinary measures, which may consist in particular of:
    1. order penalties under the Polish Labour Code (Kodeks pracy),
    2. termination of the employment relationship with the employee (including termination of the employment relationship without notice through the fault of the employee).
  3. With respect to persons bound to the Company by a form of cooperation other than an employment relationship, the Management Board may apply the measures provided for under the relevant legal provisions and the concluded contracts, up to and including the immediate termination of cooperation.
  4. Where the actions and measures referred to in items 34 and 35 above are applied, the Management Board informs the Compliance Officer of their application.
  5. The Compliance Officer is obliged to check the status of the implementation of the recommendations (if any were included in the report) after the expiry of 6 months from the submission of the report to the Company’s Management Board. The Compliance Officer presents to the Company’s Management Board a report on the status of the implementation of the recommendations.

XI. Protection of the Reporting Person and other persons against retaliatory actions

  1. The Company protects the Reporting Person against retaliatory actions taken in connection with the Reporting Person’s exercise of the rights set out in the Procedure. Taking retaliatory actions, as well as attempts or threats to apply retaliatory actions, are prohibited, and a violation of this prohibition will result in disciplinary or contractual liability. The prohibition of retaliatory actions will be strictly enforced.
  2. The provisions of the Procedure concerning protection against retaliatory actions apply accordingly to a Person assisting in making a Report and to a Person associated with the Reporting Person, provided that they are in a professional relationship with the Company.
  3. The Company prohibits hindering, or attempting to hinder, the making of Reports, in particular through violence, threats or deception.
  4. Exercising the rights set out in the Procedure may not constitute grounds for unfavourable treatment and may not result in any negative consequences; in particular, it may not constitute a reason justifying the employer’s termination of the employment relationship with notice, its termination without notice, or the ending of cooperation.
  5. The Reporting Person is protected against retaliatory actions provided that they had reasonable grounds to believe that the information contained in the Report was true at the time of making the Report and that such information constitutes information about a Breach.
  6. Notwithstanding the protection against retaliatory actions, the Reporting Person may be held liable to the appropriate extent, in particular under employment law, if they themselves participated in the Breach.
  7. In the event of knowingly reporting false information or assisting in making such a report, such persons are not entitled to the protection referred to in this Chapter. The Company may initiate disciplinary proceedings or make use of the available instruments of legal protection against persons who knowingly reported false information.

XII. Protection of the rights of the person concerned by the Report

  1. Until the investigation has been completed and a determination has been made as to whether a Breach has occurred, allegations concerning the commission of a Breach are treated as unconfirmed.
  2. The person concerned by the Report has the right to a reliable investigation, in particular:
    1. the right to be informed of the opening of the investigation in accordance with the provision of Chapter X, item 17;
    2. the right to appoint a representative and to submit evidentiary motions, in accordance with the provisions of Chapter X, items 22 and 23;
    3. the right to be informed of the outcome of the investigation in accordance with Chapter X, item 31.
  3. The rights described in item 2, in particular items 2.2 and 2.3, are also vested in the Reporting Person.

XIII. Procedure in the event of a Breach committed by the Compliance Officer or where the Compliance Officer is the Reporting Person

  1. Where the Report concerns an act or omission of the Compliance Officer:
    1. the Report should be made to the Company’s Management Board, which informs the Company’s lawyer of this fact,
    2. the duties of the Compliance Officer arising from the Procedure are performed by the Company’s lawyer, who is informed of this fact by the Company’s Management Board.
  2. Where the person reporting a Breach is the Compliance Officer:
    1. the Compliance Officer makes the Report to the Company’s lawyer,
    2. the duties of the Compliance Officer arising from the Procedure are performed by the Company’s lawyer.

XIV. Special powers of the Compliance Officer and the Breach Committee

  1. The Compliance Officer and the Breach Committee are entitled to submit requests for actions to be taken with a view to avoiding the risk of retaliatory actions. The requests are addressed to the Management Board, which takes the final decision based on the content of the request.
  2. The Compliance Officer may authorise another person to perform their duties arising from the Procedure, subject to obtaining the approval of the Management Board. Where the Compliance Officer is unable to authorise another person (e.g. a sudden fortuitous event), these duties are taken over by the Company’s lawyer.
  3. The Compliance Officer has the right to open an investigation which is not based on a Report made by a third party, but on information which the Compliance Officer has obtained by virtue of performing their function.
  4. In justified cases, in particular where necessary to ensure the proper course of the investigation, the Compliance Officer may submit a request to the Management Board for the suspension from the performance of official duties of the person against whom the investigation is being conducted.

XV. Register of internal reports

  1. The Compliance Officer keeps a register of internal reports.
  2. The Company is the controller of the data collected in the register.
  3. The following information is entered in the register of reports:
    1. the internal number of the Report,
    2. the date and manner of receipt of the Report and the date of sending the confirmation of receipt of the Report,
    3. the personal data of the Reporting Person (if the Reporting Person has left such data) and of the person concerned by the Report, necessary to identify those persons,
    4. the contact address of the Reporting Person (if the Reporting Person has provided it),
    5. the subject matter of the Report,
    6. the follow-up actions taken,
    7. the date of sending the feedback,
    8. the date of closing the case.
  4. The information contained in the register of reports is confidential and subject to the obligation of confidentiality. Access to the register of reports is granted to:
    1. the Compliance Officer,
    2. persons holding a written authorisation to process personal data, obtained in accordance with the provisions of Chapter X, item 13, exclusively within the scope of the case for which the authorisation was granted.
  5. The template of the register of reports constitutes Annex 1 to this Procedure.

XVI. Duties of selected organisational units within the Company

  1. The Company’s Management Board:
    1. strives to implement organisational and technical solutions enabling the prevention of Breaches and, should they occur, ensuring their early detection,
    2. takes actions aimed at eliminating the irregularities found as a result of the investigation and counteracts their recurrence,
    3. informs the Compliance Officer of the disciplinary measures or other measures taken against a person found to have committed a Breach,
    4. authorises the Compliance Officer to process personal data for the purpose of performing their duties and activities arising from this Procedure.
  2. The Compliance Officer:
    1. ensures that the Procedure is kept up to date, including its periodic review (no less frequently than once every two years),
    2. coordinates the activities of the Company’s organisational units responsible for implementing the Procedure,
    3. receives Reports,
    4. appoints the Breach Committee and directs its work,
    5. supervises the process of handling reports and the keeping of the register of reports in accordance with the provisions of the Procedure,
    6. informs the Director of the Personnel, Payroll and HR Department of Helios S.A. of the need to conclude an agreement on release from the obligation to perform work, subject to obtaining the prior consent of the Management Board,
    7. submits periodic reports (no less frequently than once every six months) to the Management Board on the implementation of the provisions of the Procedure,
    8. archives (including deletes) the data and documents created and generated as a result of the activities covered by this Procedure, in the manner and within the time limits provided for in the Whistleblower Protection Act (ustawa o ochronie sygnalistów).
  3. The Director of the Personnel, Payroll and HR Department of Helios S.A.:
    1. organises training and other activities aimed at raising the awareness of employees and associates with regard to the process of reporting irregularities.
  4. The Personnel, Payroll and HR Department of Helios S.A.:
    1. prepares the content of the declaration confirming that a new employee, associate or member of a statutory body has read the Procedure before being admitted to work, commencing cooperation or taking up their function, and keeps the signed declaration in the personnel files.
  5. The Director of an organisational unit:
    1. carries out the activities leading to informing a job applicant about the Procedure for Reporting Information on Breaches at Next Film sp. z o.o. upon the commencement of recruitment or of negotiations preceding the conclusion of a contract,
    2. ensures that a new employee, associate or member of a statutory body has read the Procedure before being admitted to work, commencing cooperation or taking up their function,
    3. collects from a new employee, associate or member of a statutory body a declaration confirming that they have read the Procedure and forwards it to the Personnel, Payroll and HR Department.

XVII. Final provisions

  1. The Procedure has undergone the consultation with employee representatives required by law.
  2. This Procedure enters into force upon the expiry of 7 days from the date of sending the internal information on the adoption of this Procedure by the Management Board, in the manner customary in the Company.
  3. The owner of the Procedure is the Compliance Officer.

Version history

Version Date of the order Effective from Introducing unit Reason for and scope of changes
1.0 ………. ………………. Compliance Officer Adoption of the original text in accordance with the Whistleblower Protection Act of 14 June 2024 (ustawa o ochronie sygnalistów; formally promulgated on 24 June 2024)

Annex 1 – Template of the register of internal reports

Internal report number Manner of receipt of the report Date of receipt of the report Date of sending the confirmation of receipt of the report Personal data of the reporting person (address – if provided by the Reporting Person) Data of the person concerned by the report Subject matter of the report Follow-up actions Date of sending the feedback Date of closing the case