acib GmbH is committed to a corporate culture of integrity, transparency and compliance with the law. To ensure adherence to the highest ethical standards and to identify potential legal violations, we have established an internal reporting system in accordance with the Whistleblower Protection Act (HSchG). This whistleblowing system serves to identify and address legally relevant breaches and serious misconduct at an early stage. It is available to all employees, applicants, interns, former employees and external partners

If you suspect that laws or important rules are being breached, you can report this confidentially via our whistleblowing platform.
In addition, we have set up additional reporting systems and points of contact for malpractices and issues that do not fall under the HSchG.

Who can submit a report?

The scope of protection under the HSchG extends to persons who have obtained information about breaches in the course of their professional activities for or with acib. This includes, in particular:
  • Current employees
  • Former employees
  • Applicants and interns
  • Students in cooperation with acib
  • External partners, contractors and service providers
  • Research partners and academic cooperation partners

Reporting channels

To ensure a comprehensive and legally compliant report, we offer various channels:
  • Digital reporting (written & voice message): Reports can be submitted securely, encrypted and, if desired, completely anonymously via our Integrity Line platform. This platform allows for both written submissions and the transmission of voice messages.
  • Verbal reporting: Verbal reporting is possible via the aforementioned portal (voice message function) or by appointment.
  • Face-to-face meeting: At the whistleblower’s request, a physical or virtual meeting with a designated trusted representative from our Compliance Board must be arranged within a reasonable timeframe.
Under the Whistleblower Protection Act (HSchG), you also have the right to report information regarding breaches to external bodies (e.g. the Federal Office for the Prevention and Combating of Corruption – BAK). However, we encourage you to use our internal reporting system in the first instance so that we can address any issues quickly and directly.

What can be reported?

The Whistleblower Protection Act defines the areas for which a report may be submitted. These are:
  • Public procurement
  • Financial services, prevention of money laundering and corruption
  • Product safety and environmental protection
  • Public health
  • Data protection and security of network and information systems
  • Breaches of the financial interests of the Union
  • Breaches of product safety and compliance
  • Certain criminal offences under Sections 302–309 of the German Criminal Code (StGB) (e.g. corruption, breach of trust)

Important note: General complaints, suggestions or personal conflicts in the workplace that do not constitute a legal violation within the meaning of the Whistleblower Protection Act (HSchG) should be addressed via the regular channels of communication (line managers, HR department or compliance@acib.at).

Procedure following a report

We take every report we receive very seriously and handle it in accordance with a clearly defined, strictly confidential process. To offer you maximum transparency and security, the investigation is conducted by our impartial Compliance Board strictly in accordance with the legal requirements of the Whistleblower Protection Act (HSchG). The processing procedure is as follows:
  1. Report: You submit your report – either completely anonymously or by name – via our Integrity Line or by email.
  2. Confirmation (max. 7 days): You will receive a formal acknowledgement of receipt from us no later than seven days after submission.
  3. Investigation: The Compliance Board examines the reported matter carefully, impartially and with the strictest confidentiality. If necessary, we will contact you via the secure platform to ask for further details.
  4. Feedback (max. 3 months): Within three months of the confirmation at the latest, we will inform you of the outcome of the investigation and of any follow-up measures already taken or planned.
Throughout the entire process, the protection of your identity and data security are our top priority. Should the investigation reveal that the content of a report does not fall within the scope of the law, it will – where possible and permitted under data protection law – be forwarded to the relevant internal department for processing.

You can rest assured in all cases:

if you report information to the best of your knowledge and belief, you have nothing to fear from acib in terms of professional disadvantages or reprisals.

If reported breaches are confirmed

acib will take appropriate measures – such as disciplinary action, organisational improvements, additional checks or training. The aim is not punishment for its own sake, but the sustainable prevention of similar breaches.

Protection of whistleblowers

Comprehensive protection against reprisals:

Whistleblowers who report information about misconduct to the best of their knowledge and belief are afforded special legal protection under the Whistleblower Protection Act (HSchG). acib GmbH guarantees that you will not suffer any professional or personal disadvantages as a result of a legitimate report. Any form of retaliation or reprisal – in particular dismissal, denial of promotion, transfer, withdrawal of duties, bullying, discrimination or intimidation – is prohibited by law and will not be tolerated by us under any circumstances. This protection applies without restriction even if a reported suspicion subsequently proves to be unfounded.

Strict confidentiality (protection of identity):

A central pillar of our system is the protection of your identity. Both the identity of the reporting person and that of individuals named in the report are protected by strict technical and organisational measures. Even in the case of reports naming individuals, your identity will not be disclosed to the accused or to uninvolved third parties. Access to case files is restricted exclusively to members of the Compliance Board, who are bound by strict confidentiality.

Prohibition of malicious reports:

To ensure the integrity of the system and the protection of all parties involved, the whistleblowing system must not be misused for the deliberate dissemination of falsehoods or defamation. Legal protection does not apply to malicious false reports. Anyone who intentionally reports false information is liable to prosecution under Section 24 of the Whistleblower Protection Act (HSchG) and must expect civil claims for damages as well as severe consequences under labour and disciplinary law.

Data protection, data security and retention

As sensitive and personal data may be processed via the whistleblowing system, data protection and data security are our top priority. All data is processed strictly in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Whistleblower Protection Act (HSchG).
  • Encryption & Anonymity: Our reporting platform (“Integrity Line”) is hosted by a specialised, market-leading external service provider acting as a data processor (EQS Integrity Line). The system is ISO 27001-certified and uses state-of-the-art encryption technologies. Neither IP addresses nor location or device information relating to the reporting person are stored. Even the platform operator has no access to the content of your report.
  • Access restriction: Internally, only expressly authorised members of the Compliance Board have access to the reports received and the personal data contained therein.
  • Retention periods: In accordance with Section 8(11) of the HSchG, personal data is generally retained for five years following the last processing or transmission of the report. Data is retained for a longer period only if this is strictly necessary for the conduct of administrative, judicial or criminal investigations that have already been initiated. Once these retention obligations cease to apply, the data is irrevocably deleted.

Other points of contact: Which channel is the right one?

Our whistleblowing system under the HSchG is primarily intended for reporting legal and compliance breaches (e.g. white-collar crime, fraud, data protection breaches). Regardless of this, we forward all reports, even if they do not fall under the HSchG, to the relevant internal (or external) bodies.
For important matters outside the scope of the HSchG, we have set up dedicated contact points at acib GmbH to provide you with the best possible, topic-specific support:

Research Misconduct (Research Integrity):

Do you have concerns regarding good scientific practice (e.g. plagiarism, data manipulation, unethical research conduct or improper authorship)? Please contact our Research Integrity Office confidentially at research-integrity@acib.at. We recommend that you use their email encryption function.

Equality & Diversity:

If you have any concerns, questions or incidents relating to gender equality, discrimination on the grounds of origin, religion or sexual orientation, or any diversity-related issues, our Gender & Diversity Officer is available to assist you at equality@acib.at. You can also find information on equality and diversity at link to the topic on the TTC website.

Workplace Culture & Interpersonal Relations (Bullying, Harassment):

Respectful interaction is important to us. In the event of workplace conflicts, bullying or inappropriate behaviour, please contact the HR department directly or the Works Council established at acib.

Central Compliance Point of Contact:

Are you unsure where to direct your concern, or would you like to report another issue covered by the Code of Conduct? At compliance@acib.at, our Compliance Board is always ready to listen and will forward your concern confidentially to the appropriate department.