Purpose
This policy explains how concerns about misconduct, compliance breaches, bribery, corruption, data protection risks, or other integrity matters can be reported.
It is intended to ensure that reports are taken seriously, treated confidentially, and reviewed appropriately. The goal is to identify risks early and prevent harm to affected people, clients, business partners, and Sternberg Consulting.
What can be reported
Reports may relate in particular to:
- Bribery, corruption, improper benefits, or conflicts of interest
- Breaches of data protection, information security, or confidentiality
- Modern slavery, forced labour, human trafficking, or serious labour rights abuse
- Fraud, theft, manipulation of records, or other criminal conduct
- Serious breaches of internal policies, contracts, or legal obligations
General client enquiries, service complaints, or contract-related questions should continue to use the normal contact channels unless a compliance concern is involved.
Reporting channels
Reports can be sent by email to info@sternberg-consulting.com. Please describe the matter as specifically as possible and include available evidence.
Helpful information includes involved people or organisations, dates or periods, locations, affected projects, available documents, and possible witnesses. You do not need complete proof in order to raise a concern.
Anonymous reports
Reports may be made anonymously where practically possible. Please note that anonymous reports can make follow-up questions more difficult. If you provide a contact option, we can clarify the matter more effectively and inform you about progress.
Confidentiality
Reports are treated confidentially. Information is shared only with people who need it to review and handle the matter.
The identity of reporting persons is protected as far as legally and practically possible. Disclosure may be required where legal obligations apply or where an effective investigation is not possible without disclosure.
Protection against retaliation
People who report concerns in good faith must not be disadvantaged for doing so. Knowingly false or abusive reports are not protected.
Retaliation may include dismissal, contract termination, demotion, pressure, threats, discrimination, or other disadvantages. Reports of retaliation are also reviewed.
Handling
We review reports promptly, document appropriate steps, and take required action.
- Receipt of the report and initial plausibility review
- Decision whether further information is needed
- Review of the matter while preserving confidentiality
- Decision on appropriate measures
- Documentation of the outcome and, where possible, feedback to the reporting person
Data protection and retention
Personal data connected with reports is processed only where necessary to review and document the matter and comply with legal obligations. Data is deleted once it is no longer needed for these purposes and no statutory retention duties apply.
Abusive reports
Knowingly false, defamatory, or abusive reports may have legal consequences. A report is not abusive merely because a suspicion is later not confirmed.
Review
This policy is reviewed annually. Last reviewed: March 2026.