Whistleblowing Policy

Whistleblowing Disclosure for employees and other third parties

Employees and other individuals working with or on behalf of the LRC Group may, in properly carrying out their duties, have access to, or come into contact with, information of a confidential nature. Their terms and conditions provide that except in the proper performance of their duties, employees are forbidden from disclosing, or making use of in any form whatsoever, such confidential information. However, the law allows employees to make a ‘protected disclosure’ of certain information. In order to be ‘protected’, a disclosure must relate to a specific subject matter and the disclosure must also be made in an appropriate way. Whistleblowing protection is confined to a disclosure which, in the reasonable belief of the employee making the disclosure, is made in the public interest. All concerns will be handled independently by the Compliance function (or a designated impartial representative).

The LRC Group is committed to compliance with the relevant legislation in all jurisdictions within which it operates, including compliance with the EU Whistleblowing Directive (Directive (EU) 2019/1937), as transposed into national law;

  • Ireland; Protected Disclosures Act 2014, as amended by Protected Disclosures (Amendment) Bill 2021 and the Protected Disclosures (Amendment) Act 2022
  • UK; Public Interest Disclosure Act 1998 (PIDA)
  • Malta; Protection of the Whistleblower Act (Cap. 527), as amended by Act XXV of 2023
  • Cyprus; The Protection of people reporting infringement of European and National Laws Law - Ν.6(Ι)/2022
  • Luxembourg; Law of 30 July 2019 on the Protection of Whistleblowers
  • Germany; Law of June 2023, the Hinweisgeberschutzgesetz (WhistleBlower Protection Act)
  • Poland; As of January 2025, Poland has implemented the Whistleblower Protection Act, which came into force on 25 September 2024.

These national laws give effect to the EU Whistleblowing Directive, which sets a common minimum standard of protection for individuals reporting breaches of Union law. The Directive has now been transposed into law across all EU Member States.

The Group actively encourages a culture of honesty and openness and therefore all employees and other relevant stakeholders (such as contractors, consultants, interns and suppliers) are required to bring up to their line manager or other designated person any issue that, in the employee’s opinion, might constitute bribery or corruption. The LRC Group provides secure and confidential channels for reporting concerns. Reports can be submitted in writing, verbally, or via email. Upon request, whistleblowers may request a face-to-face meeting. All personal data collected during whistleblowing investigations will be handled in accordance with the General Data Protection Regulation (GDPR). Access will be strictly limited to authorised personnel, and records will be retained only as long as necessary to fulfil legal or compliance requirements.

Aims of the Whistleblowing policy

Our arrangements aim to;

  • Provide secure ways for employees and others who work with or on behalf of the LRC Group (such as contractors, consultants, suppliers and former workers) to raise concerns and, where appropriate, to receive feedback on any action taken
  • Acknowledgement of receipt will be provided within at least 7 days, and feedback within at least 3 months in line with the EU Whistleblowing Directive.
  • Provide reassurance that every effort will be made to protect anyone who makes a report from being victimised

There are procedures in place which allow employees and people who work for the LRC Group to lodge a grievance relating to their own employment, for example, bullying and harassment. Whistleblowing relates to concerns about wrongdoing that affect others (e.g. the public, company integrity, or legal violations), while grievances typically concern personal employment matters. These are covered in the employee handbook. Whistleblowing is intended to cover concerns that fall outside the range of these procedures.

Principles

  • All concerns raised will be treated fairly and properly
  • We will not tolerate the harassment or victimisation of anyone raising a genuine concern
  • Any individual making a disclosure will retain their anonymity unless they agree otherwise
  • We will ensure that any individual raising a concern is aware of who is handling the matter
  • We will ensure no one will be at risk of suffering some form of retribution as a result of raising a concern even if they are mistaken. We do not however extend this assurance to someone who maliciously raises a matter they know to be untrue.

Whistle-blowers are protected by legislation (in certain jurisdictions) if they whistle blow appropriately. For employees based in jurisdictions where there is no explicit whistleblowing protections the LRC Group will treat them as if they were based in a jurisdiction which does provide such protections.

  • Whistle-blowers are protected if they reasonably believe the information disclosed tends to show that one of the following has happened, is happening, or is likely to happen;
  • Make the disclosure in the public interest
  • Reasonably believes the information is true
  • Believe the whistleblowing is being made to the right person

Whistleblowing

All cases of actual or suspected fraud, corruption, bribery and theft must be reported immediately;

  • Information which an employee reasonably believes tends to show one or more of the above should promptly be disclosed to his/her line manager so that any appropriate action can be taken.
  • If it is inappropriate to make such a disclosure to the line manager, the employee should speak to the next highest or another level of management, including to the COO or the CEO.
  • Disclosures can also be made to whistleblowing@lrc-group.com (monitored solely by Compliance).
  • Individuals who make a disclosure under this policy will suffer no detriment of any sort for making such a disclosure in accordance with this procedure.
  • However, failure to follow this procedure may result in the disclosure of information losing its "protected status."
  • For further guidance in relation to this matter or concerning the use of the disclosure procedure generally, individuals should speak in confidence to theHead of Compliance.
  • A Whistle-blower who knowingly makes a false report may be subject to appropriate action, in line with applicable procedures.
  • Anyone who retaliates against a Whistle-blower (who reported an event in good faith) may be subject to disciplinary or contractual consequences, in line with relevant procedures.
  • Crimes against a person or property, such as assault, rape, burglary, etc., should immediately be reported to local law enforcement personnel.
  • Managers and/or Directors who receive the reports must promptly act to investigate and/or resolve the issue.
  • If the investigation of a report, that was done in good faith and investigated by internal personnel, is not to the Whistle-blower’s satisfaction, then he/she has the right to report the event to the appropriate legal or investigative agency.
  • Whistleblowers may also report directly to the appropriate external regulator or national authority if they reasonably believe internal channels are ineffective or unsafe, in accordance with Directive (EU) 2019/1937.
  • The identity of the Whistle-blower, if known, shall remain confidential to those persons directly involved in applying this policy, unless the issue requires investigation by law enforcement, in which case members of the organisation are subject to subpoena. All personal data collected will be handled in compliance with the General Data Protection Regulation (GDPR). Records will be retained only as long as necessary.
  • Acknowledgement of receipt will be issued within seven (7) days of submission, and a response outlining the outcome or next steps will be provided within three (3) months, extendable to six (6) months where justified.
  • External reporting channels include relevant regulators such as the Standards in Public Office Commission (Ireland), the Financial Conduct Authority (UK), or the European Banking Authority (EU).

Data Protection and Record Retention

  • All personal data processed in connection with whistleblowing shall be retained for no longer than five (5) years after closure of the case, or as required by law.
  • Data will be minimised, access-restricted, and securely deleted thereafter, consistent with relevant GDPR legislation.
  • Access to whistleblowing records will be restricted to Compliance only.