Reporting Privacy Notice

LAST REVIEWED: June 24, 2026

Purpose

Purpose of this Notice. This Reporting Privacy Notice explains how personal data is collected and processed by the relevant Syngenta Group legal entity in connection with reports made through the reporting channels in accordance with Section 3.3. It is intended to ensure a high level of protection and transparency for all individuals whose personal data may be included in or otherwise connected to a report.

Scope of this Notice. This Notice applies where the processing of personal data in connection with a report is subject to EEA or Swiss data protection law. This may include, for example, where the reporting person or another individual concerned is located in the EEA or Switzerland, where the report concerns an EEA or Swiss Syngenta Group entity, business, site, employee, or operation, or where the report is received, handled, or investigated by an EEA or Swiss Syngenta Group entity.

References in this Notice to Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), should be read as including, where applicable, the corresponding requirements of the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”).

About Syngenta Group. Syngenta Group is a global leader in agricultural technology and innovation and consists of several business units (“Syngenta Group”, “we”, “us”). Syngenta Group includes Syngenta Crop Protection, Syngenta Seeds (together, “Syngenta”), Syngenta Group China, and ADAMA (“ADAMA”). References to “Syngenta Group” in this Notice include all these entities unless otherwise specified.

Voluntary reporting and data minimization. Reporting wrongdoing, misconduct, or legal violations is voluntary. You may submit a report without providing your name or other identifying information, if anonymous reporting is permitted in your country. If your report includes personal data, please ensure that it is limited to what is necessary to assess, process, and resolve the case. If you choose not to provide certain information, we may still be able to process your report, but our ability to investigate and take appropriate action may be limited.

Who will be responsible for processing your data?

Syngenta-related reports. If your report involves or affects a Syngenta entity in your country, that local Syngenta entity will act as controller of your personal data together with Syngenta Crop Protection AG, a Swiss corporation based in Basel, Switzerland (“Syngenta Parent”). As joint controllers, Syngenta Parent and the local Syngenta entity have determined their respective responsibilities for compliance with GDPR obligations. Syngenta Parent is responsible for responding to data subject rights requests, and you may exercise your rights by contacting either controller using the details in Section 11.

ADAMA-related reports. If your report involves or affects an ADAMA entity, the relevant ADAMA entity in your country will act as controller of your personal data. In some cases, that local ADAMA entity and ADAMA Agricultural Solutions Ltd, an Israeli corporation based in Airport City, Israel (“ADAMA Parent”), will act as joint controllers for the collection and use of personal data related to ADAMA. As joint controllers, ADAMA Parent and the local ADAMA entity have determined their respective responsibilities for compliance with GDPR obligations. ADAMA Parent is responsible for responding to data subject rights requests, and you may exercise your rights by contacting either controller using the details in Section 11.

What Personal Data do We collect and Process

If you decide to provide personal data in your report, we may process the following information:

Ordinary personal data

  • identification and contact details of the reporting person (where provided);

  • identification and contact details of individuals who are the subject of a report;

  • identification and contact details of witnesses and other individuals involved in the matter;

  • employment-related information, such as job title, department, reporting line and work location;

  • information contained in reports, complaints, allegations, supporting documents and evidence;

  • correspondence and communication relating to the report and investigation;

  • interview notes, witness statements and investigation records;

  • system, access and activity logs, CCTV recordings and other records relevant to the investigation, where applicable; and

  • any other information necessary to assess the report, conduct the investigation, take appropriate action and comply with legal and regulatory obligations.

Special categories of data

Special categories of data are data that reveal race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, physical or mental health, or that include genetic data or biometric data. In some cases, reports may contain special categories of personal data or information relating to alleged criminal offences where relevant to the matters reported. Processing of data relating to criminal offences is carried out only where authorized by applicable Union or Member State law, in accordance with Art. 10 GDPR.

Providing special categories of data in a report is voluntary. If any special categories of data included in a report are not relevant to the case, we will delete them promptly. Please do not include special categories of data about yourself or anyone else unless they are necessary for the report.

Sources of the personal data

Personal data provided by you. As a rule, we collect personal data directly from you through the Compliance Helpline, which is our designated reporting channel for submitting reports of wrongdoing, misconduct, or legal violations.

Personal data from third parties. We may also receive personal data from colleagues, supervisors, contractors, clients, or other third parties.

WHY DO WE COLLECT AND HOLD YOUR PERSONAL DATA AND WHY ARE WE ALLOWED TO DO SO

Personal data will be processed only to the extent necessary for the handling of the report, the conduct of any investigation, and compliance with applicable legal and regulatory requirements.

Purpose

Legal Basis

Handling reports and investigation

We process your personal data to manage all reports made under our Whistleblowing policy and Code of Conduct in a safe and efficient manner, including:

  • analysis, storage, and follow-up of reports;

  • identification and exclusion of irrelevant or false reports;

  • investigation of reported facts, where relevant;

  • taking necessary action to stop wrongdoing, misconduct, or legal violations, preserve evidence, and defend the rights of our employees or Syngenta’s rights and assets;

  • protecting the privacy, rights, and safety of the reporting person, witnesses, and third parties mentioned in the report, as well as the rights of the person concerned.

Depending on the case, the processing may be based on:

  • the need to comply with our legal obligations, given that implementing whistleblowing systems is mandatory in some countries where Syngenta operates (Art. 6(1)(c) GDPR);

  • our legitimate interests, specifically monitoring compliance with our Code of Conduct and other internal regulations (Art. 6(1)(f) GDPR).

Special Categories of Data
We may process special categories of data to carry out an investigation, confirm reported facts and allegations, and take action to stop detected wrongdoing, misconduct, or legal violations.

Depending on the case, processing may be necessary:

  • to perform obligations and/or exercise specific rights of the employer or employee in the field of employment and social protection law (Art. 9(2)(b) GDPR);

  • to establish, exercise, or defend a legal claim (Art. 9(2)(f) GDPR);

  • in exceptional cases, for reasons of substantial public interest, where authorized by applicable Union or Member State law that provides appropriate safeguards (Art. 9(2)(g) GDPR).

Sharing your Personal Data

We may share your personal data within the Syngenta Group or with selected external recipients in accordance with Section 5.2 where this is necessary for the purposes described in this Notice.

Intra-Group

We may share your personal data with other Syngenta Group affiliates for the purposes described in Section 4 of this Notice. Access is limited to those who need the information to perform their role, and all personal data remains confidential.

Other Recipients

We may also share your personal data with selected recipients where necessary, including:

  • service providers engaged by Syngenta to perform activities on our behalf, such as auditors, the provider of our Helpline, and technology companies providing software, computing, email, telecommunications, or information management services;

  • governmental or public authorities, where disclosure is required by law.

International Transfer of Personal Data

Transfers within and outside the EEA. We may transfer your personal data to Syngenta Parent or ADAMA Parent.

Adequate countries. Israel and Switzerland have been officially recognized by the European Commission as providing an adequate level of protection for personal data.

Transfers to other third countries. Where we transfer personal data to recipients in third countries outside the European Economic Area that have not been recognized by the European Commission as adequate, we use an acceptable transfer mechanism, such as the EU Standard Contractual Clauses. In exceptional circumstances, we may rely on applicable statutory exceptions.

How long Do we Keep your Personal data

Retention during and after an investigation. We keep personal data for the duration of the investigation. After the investigation is closed, we retain personal data for a period of up to five years, or longer where necessary to defend claims or comply with applicable legal retention obligations.

Confirmed misconduct or violations. If the investigation identifies misconduct or other violations, we may retain personal data for the period necessary to address the consequences of the misconduct or violation and to defend related claims.

Your Rights

Rights of individuals

Your data protection rights. Subject to applicable law, you may exercise the following rights in relation to your personal data:

  • access your personal data and obtain a copy of the information we hold about you;

  • correct inaccurate or incomplete personal data;

  • object to the processing of your personal data;

  • request restriction of processing in certain circumstances; and

  • request deletion of your personal data where there is no valid reason for us to continue processing it.

Limitations and exemptions. Some rights may be restricted or limited by law. We may also rely on applicable legal exemptions to refuse all or part of a request. If this happens, we will explain our decision when responding to you.

How to exercise your rights. To exercise any of these rights, please see Section 11 for the relevant contact details.

Right to lodge a complaint

Right to lodge a complaint. You may lodge a complaint with the competent supervisory authority in the EU Member State where you reside, work, or where the issue giving rise to the complaint occurred.

Complaints in Switzerland. Where FADP applies to the processing of your personal data, you may also raise the matter with the Swiss Federal Data Protection and Information Commissioner (FDPIC).

Information about the person concerned. If you are the person concerned by a report, meaning the person whose conduct is reported, we will inform you about the processing of your personal data in accordance with Art. 14 GDPR. We may delay this notification where necessary to avoid jeopardizing the investigation, in line with applicable law, including Directive (EU) 2019/1937 (“EU Whistleblowing Directive”) and its national implementing legislation. Throughout the process, the person concerned retains the presumption of innocence and the right to an effective remedy.

Protection of reporting persons. In accordance with the EU Whistleblower Directive and applicable national law, we are committed to protecting persons who report wrongdoing in good faith. Reporting persons are protected against retaliation, and their identity will be kept confidential to the extent permitted by law. For more information, please refer to the Syngenta Group Whistleblowing Policy.

Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include access controls, encryption, secure storage systems, and regular security assessments. Access to personal data relating to reports is strictly limited to authorized personnel who need the information to perform their role in handling or investigating the report. Where we engage third-party service providers, they are contractually required to maintain appropriate security measures.

Automated Decision Making

We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you in connection with the handling of reports or investigations.

Contact

Questions or rights requests. If you wish to exercise your data protection rights or have questions about this Reporting Privacy Notice, please contact the relevant team below:

Relationship with Local Privacy Notice

This Notice addresses processing governed by the GDPR and Swiss data protection law, as stated in Section 1. Local Syngenta or ADAMA entities may adopt their own reporting privacy notices. Such notices may address additional or different requirements under local law and apply to the extent required by that local law. Where both this Notice and a local notice address the same legal requirement under the same legal regime, for example GDPR and EU Member State law, the notice providing greater protection to data subjects shall prevail.

Updates to this Notice. You can see when this Reporting Privacy Notice was last amended by checking the “Last revised” date at the top of this page. You may print, download, or otherwise retain a copy of this Reporting Privacy Notice, including any revised version, for your records.