Aptiv Global Operations Limited and its affiliates and related entities (“Aptiv”), as a Data Controller, is committed to protecting the privacy and security of your Personal Data. This Privacy Notice applies to all individuals whose Personal Data we process when we are contacted via Aptiv’s Drive Line, whether by phone or web, to speak up or to report any conduct that is believed, in good faith, to be improper, and which may violate our Policies, including but not limited to: workplace harassment, theft, fraud, bribery, corruption, kickbacks, improper sharing of confidential information, inaccurate financial reporting, anti-competitive conduct.
This Privacy Notice describes the use of this Drive Line Reporting Service, the Personal Data or Personal Information that we collect, how we use it, secure it, when we may disclose it to Third Parties, and when we may transfer it outside of your home jurisdiction. This Privacy Notice also describes Your Rights regarding the Personal Data that we hold about you and how you can exercise them.
We will only process your Personal Data as described in this Privacy Notice unless otherwise required by applicable law. We take steps to ensure that the Personal Data that we collect about you is adequate, relevant, not excessive, and processed for limited purposes.
Use of this service is entirely voluntary and can be done anonymously. All reports are handled by an independent, impartial Third-Party vendor (Navex) staffed by non-Aptiv employees. Aptiv’s Investigation process ensures a thorough and impartial investigation. Investigators will not be assigned to a case if they have a close relationship with any of the parties involved. For example, if a report alleges that local site leadership or Human Resources may be involved, then a case investigator outside of the site will be assigned.
The information you submit will be handled in accordance with our Policies and kept strictly confidential, to the extent allowed by applicable law, and discussed only with those directly involved in the investigation and those with a specific need-to-know.
As noted above, you can make your report anonymously (without disclosing any personal identifiable data), however, there are instances where you might disclose the following Personal Data:
We rely on either of the following lawful basis to process your Personal Data, where:
The Personal Data processed in the context of any filed report, where necessary may be shared with the following trusted Third Parties:
All our Third-Party service providers are required to take appropriate security measures to protect your Personal Data based on the associated risks including proper access controls. They will only process your Personal Data on our instructions and are subject to a duty of confidentiality. We require Third Parties to respect the security of your Personal Data and to treat it in accordance with the law.
We may require transferring your Personal Data across International borders, in line with applicable laws. To ensure that International Transfers of Personal Data are adequately protected, we have put in place appropriate safeguards with our group companies, service providers, contractors, distributors, business partners, and agents. We take appropriate contractual, technical, organizational measures, and conduct Transfer Impact Risk Assessments, as required, to protect your Personal Data by ensuring it is given adequate levels of protection and Your Rights are upheld.
For more information on the appropriate safeguards in place to protect your Personal Data, please contact us using the details at the end of this statement.
We will retain your Personal Data only as long as necessary to fulfil the purposes for which it was collected, bearing in mind that reports can take some time to investigate and conclude, or as required by law. Otherwise, we aim to keep our files current and will make reasonable efforts to remove Personal Data that is no longer relevant for the purposes for which it was collected.
Aptiv is committed to safeguarding the security of your Personal Data, and has implemented among others, the following technical and organizational measures:
In accordance with applicable law, in certain circumstances, you have the following rights with regard to the processing of your Personal Data:
If you wish to exercise any of your above rights, please submit your request through the link here.
You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is deemed to be unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it.
Depending on your jurisdiction, you also have a right to make a complaint at any time to your local Data Protection Supervisory Authority (find a list of EEA (European Economic Area) Authorities here). Aptiv Global Operations Limited is an Irish Company, and its lead EU (European Union) Regulator is the Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD 28, Ireland or (by email) info@dataprotection.ie.
We reserve the right to update this statement at any time. We may also notify you in other ways from time to time about the processing of your Personal Data.
If you have any questions about this statement, please submit a request through the link here.
Updated: 22 October 2024