Skip to content
Accessibility features

Compliance

Compliance
and accountability

For over 35 years, we have been supplying medicines on which patients’ health and lives depend. This responsibility obliges us to operate in accordance with the highest standards, make transparent decisions and adhere to the principles of business ethics.

B2B consultation

The Pillars of Compliance

Our compliance with the law and standards is built on four pillars

Acting in accordance with the law

We operate in accordance with national and international regulations governing the trade and distribution of medicinal products.

Ethical standards

In our dealings with employees, partners and institutions, we are guided by our Code of Ethics, integrity and transparent principles of cooperation.

Cybersecurity

We protect personal data and business information in accordance with the GDPR and our internal security procedures.

Audit readiness

We are equipped to carry out a thorough verification of compliance with applicable rules and standards.

Code of Ethics

Rules of conduct

The Code of Ethics translates our values into principles that guide our day-to-day work, decision-making and relationship-building:

  • concern for patients’ health and safety
  • honest and transparent relationships with partners
  • fair competition and the fight against corruption
  • respect, equal treatment and a safe working environment
Discover our Code of Ethics

Regulatory compliance

Compliance with industry regulations

01 Combating corruption and bribery

Regulations concerning the prevention of corruption, the offering and acceptance of benefits, and the rules governing business dealings.

02 Conflict of interest

Principles for identifying, disclosing and managing situations in which a personal interest may conflict with the Company’s interests.

03 Fair competition

The Act of 16 February 2007 on the Protection of Competition and Consumers and the Act of 16 April 1993 on Combating Unfair Competition.

04 Protection of personal data

GDPR – Regulation (EU) 2016/679 and the Polish Act on the Protection of Personal Data.

05 Protection of whistleblowers

The Act of 14 June 2024 on the protection of whistleblowers and Directive (EU) 2019/1937.

06 Economic sanctions

EU and national legislation on economic sanctions, trade restrictions and due diligence on business partners.

07 Due diligence towards business partners

Policies on the verification of business partners, compliance risk assessment, beneficial owners and the reputation of partners.

08 Combating money laundering and the financing of terrorism

AML/CFT regulations and the principles for identifying and mitigating the risks associated with the illicit movement of funds.

09 Ethics in relations with the healthcare sector

Policies governing dealings with healthcare professionals, public bodies and other stakeholders, including policies on gifts, hospitality and benefits.

10 Transparency and corporate responsibility

Principles governing the conduct of business in a transparent, honest and responsible manner, including compliance with internal policies, procedures and the Code of Ethics.

Cybersecurity

Information security

  • 01

    Cybersecurity management

    Cybersecurity is an important part of risk management and compliance within the Company. We protect information, systems and business continuity – we implement and develop policies, procedures and best IT practices.

     

  • 02

    Standards and compliance

    We adhere to the recognised ISO/IEC 27001 and ISO 22301 standards, as well as legal requirements, including the GDPR, the National Cybersecurity System Act (UKSC) and the AI Act. These principles help us manage risk, protect information and ensure business continuity.

  • 03

    Staff awareness and skills

    We teach staff to recognise cyber threats, protect information and use systems, technology and artificial intelligence safely. To this end, we run training courses and educational initiatives.

     

  • 04

    Resilience and continuous improvement

    We are developing our organisational and technical solutions and responding to new threats and changes in legislation. We manage risk, improve our security measures, ensure business continuity and strengthen our resilience to digital threats.

01 / 04

whistleblowing

Reporting irregularities

The system guarantees the confidentiality of those reporting breaches.

Information clause for whistleblowers

A report may concern an act or omission that breaches, or may breach, the law, internal procedures or ethical standards.

We treat every report with due seriousness, investigate it thoroughly and impartially, and ensure the confidentiality and protection of whistleblowers in accordance with applicable regulations.

The system operates in accordance with the Act of 14 June 2024 on the protection of whistleblowers (Journal of Laws 2024, item 928) and Directive (EU) 2019/1937 of the European Parliament and of the Council.

Electronic channel

You can submit a report via the Sygnanet platform – a whistleblower service.

Go to Sygnanet

Mail channel

You can send your application by post to the following address:

Urtica Sp. z o.o.
ul. Krzemieniecka 120
54-613 Wrocław

To ensure confidentiality, we recommend placing your report in a sealed envelope marked ‘Confidential’, and then placing this inside a second sealed envelope marked ‘Report of a breach’.