|

Compliance


Information Security

1. Information Security at METZ CONNECT GmbH

The protection of information is our highest priority. If you identify an information security incident or suspect a security-relevant impairment, please report it immediately.

2. What Constitutes an Information Security Incident

An incident can be anything that indicates a possible threat to the information security of METZ CONNECT GmbH. This includes obvious security-critical events as well as suspicions or unusual occurrences that you notice. Please report all observations that could indicate possible misuse or a vulnerability, so that we can quickly assess the situation and take action if necessary.

Possible examples of an incident (list not exhaustive):

  • Unauthorised access to systems or data

  • Suspected phishing or other attack attempts

  • Loss or theft of METZ CONNECT GmbH devices / information

  • Technical disruptions with security-critical effects on METZ CONNECT GmbH data

3. Contact Options

METZ CONNECT GmbH
Im Tal 2
78176 Blumberg

Phone: +49 (0) 7702 533-0
E-Mail: datasec@metz-connect.com


Requirements for Compliance with Information Security in Collaboration with Suppliers

1. General

This document describes the basic handling of information security for suppliers, the handling of sub-suppliers and the IT security regulations to be observed by suppliers of METZ CONNECT GmbH when using information and IT devices (e.g. desktop computers, notebooks, smartphones, tablets).

The requirements are directed at the management of our suppliers, their employees and their vicarious agents (hereinafter referred to as contractors).

The management is obliged to independently pass on this document to its employees, vicarious agents and, if applicable, to any sub-suppliers.

2. Exchange of Information

In all discussions involving confidential or secret information of METZ CONNECT GmbH, including telephone conversations, care must be taken to ensure that unauthorised persons cannot overhear them.

All necessary and appropriate precautions must be taken (e.g. encryption) to protect information against inspection, modification and deletion by unauthorised persons (including family members and friends) during transport.

3. Physical Transport of Media

As a general rule, media containing information of METZ CONNECT GmbH must be protected against unauthorised access, misuse or falsification during transport, even across organisational boundaries.

All necessary and appropriate precautions must be taken (e.g. encryption) to protect information against inspection, modification and deletion by unauthorised persons (including family members and friends) during transport. Data carriers must be transported in a concealed manner. Data carriers containing secret information are generally transported under escort by an employee of the supplier/contractor. Documents must be transported with visual protection, e.g. in a non-transparent folder.

4. Physical Transport of Notebooks

Notebooks on which information of METZ CONNECT GmbH is stored must be transported so that they are not visible from the outside. In addition, when used in public, care must be taken to ensure that others cannot read information on the screen and/or spy on the entry of secret authentication information.

5. Handling of Information Security Incidents and Communication

Serious information security events (e.g. disruptions, data loss, unlawful actions, cybercrime attacks) must be reported immediately to the information security contact at datasec@metz-connect.com or by phone at +49 (0) 7702 533-0. If there is suspicion of loss of confidential or secret information, this must also be reported to the information security contact.

6. Audit Rights Regarding Information Security

The supplier/contractor grants METZ CONNECT GmbH the right, exercisable at any time after prior notification, to inspect and review all data on business transactions relating to information security between the supplier/contractor and METZ CONNECT GmbH at the supplier's/contractor's premises, as well as to review IT and data security measures.

Employees of METZ CONNECT GmbH or third parties commissioned by METZ CONNECT GmbH may enter the premises of the supplier/contractor during normal business hours for this purpose. The costs of the review shall be borne by the supplier/contractor if violations of information security and/or agreements of the respective assignment are identified, unless such violations are not attributable to the fault of the contractor.

7. Confidentiality Agreement between the Supplier/Contractor and its Employees

The supplier/contractor of METZ CONNECT GmbH undertakes to conclude a confidentiality agreement (separately or as part of the employment contract) with all its employees who, in the course of the collaboration, receive or can access information of METZ CONNECT GmbH. Proof of compliance is the responsibility of the supplier/contractor and must be provided at any time upon request by METZ CONNECT GmbH.

8. Subcontractors

If the supplier/contractor engages further subcontractors, it bears full responsibility for passing on and implementing all information security-relevant requirements. The supplier is obliged to ensure that the requirements are complied with by the subcontractor.

Upon request by METZ CONNECT GmbH, the supplier must demonstrate compliance with the requirements.

In the event of demonstrably serious breaches of duty or material misconduct by the subcontractor or its vicarious agents, METZ CONNECT GmbH reserves the right to reject the subcontractor.

In addition, METZ CONNECT GmbH may terminate the contract for good cause and/or assert claims for damages.

9. Compliance with Information Security (Supply Chain)

When engaging subcontractors, the supplier/contractor must ensure that METZ CONNECT GmbH's requirements for compliance with information security are also met by the subcontractor. This also includes the conclusion of confidentiality agreements with sub-suppliers. Proof of compliance is the responsibility of the supplier/contractor and must be provided at any time upon request by METZ CONNECT GmbH.

If the supplier/contractor is entitled to place subcontracts, it shall be fully liable for this, regardless of any contractual or statutory limitations or exclusions of liability.


Whistleblower Protection Act

1. Reporting Tips under the Whistleblower Protection Act

Are you aware of possible violations or questionable activities at METZ CONNECT GmbH? Are you an employee, intern, freelancer, contractor, business partner or supplier? Then we encourage you to submit your report.

Your voice matters to us.

2. Safe and Confidential

We guarantee that your identity will be protected and your information treated confidentially. In accordance with the Whistleblower Protection Act, we assure you that no retaliatory measures will be taken against you. We would like to encourage you to provide your name so that we can give you feedback on the reports submitted.

3. Reporting Violations

Here you can submit a report:
E-Mail: datasec@metz-connect.com


What violations can you report?

The Whistleblower Protection Act is designed to protect you when you report certain grievances at METZ CONNECT GmbH. The types of violations you can report include:

  • Financial irregularities: Fraud, corruption, embezzlement, financial manipulation.

  • Violations punishable by a fine: These include regulatory violations that are particularly important for the safety and well-being of employees. Examples include:

  • Violations of occupational health and safety rules.

  • Non-compliance with the Minimum Wage Act.

  • Violations of criminal law: If you identify that laws are being broken within the company, you can and should report this. This covers all types of criminal offences under German law.

Important to know: If the issue involves problems that constitute neither a criminal offence nor a violation subject to a fine, this generally does not fall under the Whistleblower Protection Act. This means that in such cases the law provides no special protection for the report.


What happens after your report?

Confirmation: Once the report has been sent without an error message, successful receipt is assured.

Investigation: Every report is taken seriously. If necessary, an internal investigation will be initiated.

Feedback: Within a reasonable period of no more than 3 months, you will be informed about the progress and outcome of the investigation. This is only possible if you have provided us with your contact details when submitting the report.


× Do you have any questions?