Anti- Bribery and Corruption Policy- Version 4.1 - February 2026
1. Introduction
1.1 Terms and Definitions
“We”, “us” and “our” refer to Data Zoo. “You” means you and includes everyone who works under our control, including all our employees, contractors, associates, agents, interns, and may also extend to the category and obligations of Associates as addressed and articulated throughout this policy.
1.2 Purpose and Scope
This Policy sets out Data Zoo’s Anti-Bribery and Corruption (“AB&C”) zero risk appetite and outlines the principles that form the foundation for our AB&C framework that enables us to prevent, detect and respond to Bribery and Corruption risks and to comply with AB&C laws in the jurisdictions in which we operate. This Policy applies to all Staff working for or on behalf of the Data Zoo Group. In this policy “Staff” is defined to include the Board of Directors (Executive and non-Executive), Employees and Third Parties acting for or on behalf of the Group. The Policy covers any activity or behaviour undertaken during the course of, or in connection with, employment or acting on behalf of the Group, regardless of the geographical location in which that activity or behaviour occurs. This Policy applies to all Group entities, including those that have delegated operational responsibility. For those parts of the Group that are impacted by foreign or local laws, regulatory requirements or contractual obligations that conflict with this Policy must comply with the more stringent standard and ensure that local laws are not contravened.
1.3 Users and Responsibilities
The Senior Leadership Team (SLT) are responsible for all aspects of the implementation and management of these arrangements, unless noted otherwise. The Data Zoo Group, its Directors, its Employees, and Third Parties, must be aware of and understand the AB&C obligations and requirements in order to address, and protect the Group and its people from Bribery and Corruption risks. Managers and supervisors are responsible for the implementation of these arrangements within the scope of their responsibilities and must ensure that all staff under their control understand and undertake their responsibilities accordingly.
2. Overview
We actively oppose and condemn bribery and corruption in all its forms. We conduct all our business in an honest and ethical manner, while acting professionally, fairly and with integrity in all business dealings and relationships. We do not permit the making of any inappropriate promises, gifts, or excessive hospitality to Foreign Public Officials in order to achieve unfair advantage or benefit and resist any efforts made by others (including suppliers, customers or clients) to unfairly affect any official decision-making process in order to achieve unfair advantage or benefit.
Data Zoo is represented by its staff, who must at all times adhere to this policy and the underlying values.
We do not encourage contributions to political parties and strictly prohibit facilitation payments as a means of doing business. We do encourage charitable donations and sponsorships provided they are ethical and legal under local laws and practices.
Our business partners and Agents are expected to implement and enforce effective systems to counter bribery. Through the reporting mechanism provided by Australian authorities, we will always document and report any breach or contravention of the law that is brought to our attention.
3. Associates
“Associates” include any third party who may do business on behalf of or for another person and includes employees, agents, clients, contractors, subcontractors, suppliers, consultants, subsidiaries, controllers, lawyers, accountants, lobbyists, sales agents, brokers, or franchisees. This is effectively anyone performing services on our behalf.
3.1 Information gathering
Our staff are required to undertake properly documented, reasonable and proportionate AB&C due diligence prior to entering into a relationship with agents. All staff engaging with a prospective agent should gather and record sufficient information to ensure adequate due diligence is conducted. Consideration should be given to the following:
The context of the introduction: How do you know the (prospective) associate? Who referred or introduced them? When, where, and why did this occur?
The associate's skill set or service offering: What skills or services does the agent offer and how are they relevant to the organisation?
Ultimate Beneficial Owners: Who is/are the associates ultimate beneficial owner/s? who else is the associate accountable to?
Foreign Public Official: Is the associate a Foreign Public Official (i.e. are they part of the security arrangements in-country)?
3.2 Documenting the Associate Agreement
3.2.1 Minimum requirements
Our staff are required to document the arrangement with the associate clearly, and in writing. With specific consideration to address as a minimum the following requirements from the associate:
acknowledgement and agreement to consistently comply with statements of intent and policies;
cooperation to assist in meeting due diligence requirements;
work scope; accounting; payment and expenses; training; record-keeping;
Associate accountability/ liability; our right to be indemnified and to terminate the contract; and
to agree to be periodically audited by us or an independent auditor.
3.2.2 Independent Legal Advice
Where necessary, our staff are advised to seek and fully document independent legal advice in the preparation of the agency agreement.
3.3 Our staff must carefully consider all payments to Agents.
Prior to making a payment to an Associate, staff should take steps to:
understand the link between the commissions and the business transaction/venture;
document the calculation or basis of all proposed commissions to ensure they are reasonable and consistent with local practice;
ensure that all expenses are reasonable, justifiable and relate legitimately to the services provided;
ensure that all expenses are properly claimed, recorded, and paid; and
be aware of changes to the payee/recipient.
3.4 Monitoring and Red Flag Alerts
We require our staff to monitor Associate action and behaviour throughout the life of the business arrangement and immediately alert our CCIO to any red flags. As a minimum, staff should be aware of the following Common Red Flags when working with agents:
Associate operates in locations perceived to have high levels of local corruption;
Associates operate in a sector with a high risk of corruption, for example mining, defence, currency, security or aerospace;
The business engagement with the Associate requires us to deal with Foreign Public Officials (including close relations or associates);
Associate’s documentation of payments made is often incomplete or inaccurate;
Associate’s meetings with Foreign Public Officials or their agents are held in luxury restaurants or holiday locations;
extravagant travel, entertainment and incidental benefits appear to be an incentive to Associate’s decision making;
We are requested to make political donations or donations to particular charities or social programs; and/or
We are told to keep dealings secret and out of the media or not recorded as official.
4. Due Diligence on Corporate Social Responsibility (CSR) Programs
We recognise that social or charitable works done to build goodwill with a government or community may also be perceived as an attempt to enhance the personal interests of a Foreign Public Official and may be considered a form of Bribery. We therefore conduct, reasonable and proportionate Anti-Bribery due diligence on any CSR programs the company engages in, prior to entering into a relationship with a beneficiary of a CSR program.
The types of CSR programs permitted by the company are dependent upon individual review and approval by the CCIO and CEO and where required Legal Counsel. CSR programs may have a limitation placed on their value to demonstrate our accountability for such programs, as well as to assist with reporting processes. We take the same care and cautious approach when considering local gift-giving practices and contributing to CSR programs.
The due diligence is conducted via a comprehensive assessment of a beneficiary and involves a process of research of independent and publicly available sources of information, together with a series of meetings and interviews. As a prerequisite, the beneficiary, its relatives, and associates must not be Foreign Public Officials. Once this is confirmed and verified, the staff member(s) undertaking the assessment must consider:
The context in which the program/sponsorship/donation was solicited or offered;
Whether the beneficiary is approved as a charity under its local laws;
The beneficiary’s history/ origin and whether it is/was subject to a criminal investigation;
The Members of the Board, their qualifications and possible conflicts; and
The level of transparency and clarification around the use of its budget;
We understand it is not sufficient to merely conduct a background check or to rely on the due diligence undertaken by anyone else. Therefore, we take full and complete responsibility for ensuring CSR due diligence is conducted with rigour and caution and monitor the beneficiaries’ behaviour during the life of the CSR program to ensure the program is not used as a subterfuge for Bribery.
Additional ongoing measures and controls include monitoring and requesting:
Who, and how many people, the program benefits;
the amount and timing of any political donations, while ensuring that any political donations comply with local laws on public disclosure;
signed declarations by the recipient beneficiary confirming that it is not violating anti-corruption laws and will only use the money for the specified purpose;
To ensure that all payments are transparent, we may:
Require two management signatures on claims and payments;
set a cash limit and not pay cash over that limit;
pay all expenses directly to providers or reimburse them after verifiable invoices and other documentation; and
request the recipient beneficiary to keep records and provide periodic written reports on the use of the proceeds.
5. Speaking Up and Whistleblowing
We foster a culture of speaking up to encourage reporting of any suspicion of a Bribery and/or Corruption incident, or other concerns relating to AB&C without fear of reprisal. We promote and encourage our employees and clients to uphold their ethical integrity to call out and report any corrupt practices. We work to ensure all Eligible Persons understand:
how to report a Bribery and/or Corruption incident, or other concern relating to AB&C;
their right to remain anonymous and what happens when they report their concerns; and
how they will be supported so that they can feel safe in expressing their concerns and not be subject to reprisals in response to expressing their concerns.
All allegations of Bribery and Corruption or other related concerns are to be reported at the earliest opportunity or upon the concern being discovered via the relevant Bribery and Corruption reporting channels listed in Table 5.1 below. If staff have concerns about their own wellbeing, treatment at work or career prospects as a result of speaking up, they may report via the relevant Whistleblowing reporting channels, to protect Eligible Persons who make disclosures and to provide support to people speaking up in relation to Bribery and Corruption and other related matters.
Whistleblowing is positively approached. We strive to create an environment where people feel comfortable in sharing any concerns or comments in relation to ethics and practices conducted by our business. Staff are informed during the onboarding process (Code of Conduct) that whistleblowing is not considered “dobbing in a mate”, but rather “doing the right thing” – and will be supported in the greatest and truest sense by senior management.
We strive to protect whistleblowers from any reprisal. To protect the eligible whistleblower, we advise reports to be made anonymously. They should not try to conduct their own investigations nor contact the target of the legal complaint. We highlight that there will be no reprisal for reporting and the identity and contact details will not be disclosed unless formally required and consented. Any perceived threat to an individual or organisation’s ability to report a concern or to exercise their whistleblowing rights will be thoroughly examined with appropriate legal and/or disciplinary action taken against anyone found to be inhibiting the ability of an individual or organisation to report Bribery and Corruption concerns or exercise their whistleblowing rights, internally or externally.
Whistleblowing and Bribery and Corruption Reporting Channels | |
|---|---|
Internal | External |
Primary Contact: Chief Compliance & Innovation Officer (CCIO) Alternative Internal Contacts: People & Culture Director, CEO, CRO, VPE, Head of CSM, or other member of Senior Management. Anonymous Whistleblowing Channel: (https://forms.office.com/r/JsLL0x9xC4) | NSW Police Force; Australian Federal Police (AFP) (+61 131 444) OR - AFP online https://www.afp.gov.au/contact-us/report-commonwealth-crime. Form: https://forms.afp.gov.au/online_forms/report_a_crime. -The Australian Securities and Investments Commission (ASIC), the Australian Prudential Regulation Authority (APRA), a prescribed Commonwealth authority, or an “eligible recipient” such as an officer, a senior manager, an auditor, or a person authorised by the regulated entity to receive disclosures whether that be an internal or external person. - For allegations of corrupt conduct in the Public Sector contact the Independent Commission Against Corruption (1800 463 909) |
Additional Contact details for Whistleblowing and reporting Bribery and Corruption concerns both in and out of Australia can be provided upon request. |
Table 5.1: Reporting Channels |
6. Hospitality, Gift Giving, Sponsored Travel, and Entertainment
Our employees are educated on the acceptable practices surrounding hospitality, gift giving, sponsored travel and entertainment. Our employees are required to report any hospitality/entertainment, gift giving, or sponsored travel they have been offered to their reporting manager immediately. Outside of reasonable hospitality, our employees are not permitted to provide gifts, sponsored travel, or entertainment to anyone external to the business without prior consent. Our staff are required to declare when they are asked to pass on gifts on behalf of another and will report this immediately to their reporting manager, as well as the CCIO and CEO. Data Zoo expects that reasonable judgement will be exercised by employees for the purpose of giving and receiving gifts. All gifts given and received by employees must be reported to the CCIO and CEO, or their reporting manager, so that these can be documented appropriately. In any cases where the employee does not feel as though a gift received is within the reasonable threshold, they are required to report this immediately to the CEO and CCIO, or their reporting manager – and may be required to assist with further investigation if necessary.
7. Conflicts of Interest, Solicitation and Extortion
We require all current and proposed employees to disclose all potential conflicts of interests to their reporting manager immediately. This manager is then required to report these conflicts of interests, at the soonest possible time, to the CEO and CCIO. We require our employees to declare any potential conflicts of interest to the CCIO and CEO, or their reporting manager, at the commencement of their employment. Should any potential conflicts of interest arise during their tenure, employees are asked to flag these immediately with the CCIO and CEO, or their reporting manager. If no new conflicts of interests have arisen throughout the year, the employee will be asked to renew or update their declarations on an annual basis. This will be either annually on the anniversary of their employment start date, or in line with the financial or calendar year.
8. Adequate Procedures to Prevent Foreign Bribery
Data Zoo maintains a zero-tolerance approach to bribery and corruption. In line with the Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 and the corporate offence of “Failure to Prevent Foreign Bribery,” Data Zoo implements and maintains “Adequate Procedures” designed to prevent bribery by employees, directors, contractors, agents, subsidiaries, and all other associates performing services for or on behalf of Data Zoo.
8.1 Top‑Level Commitment
The Board, Chief Executive Officer (CEO), Chief Compliance & Innovation Officer (CCIO), and Senior Leadership Team (SLT) provide clear, visible, and continuous support for Data Zoo’s Anti‑Bribery and Corruption (AB&C) framework. Leadership ensures:
this policy is embedded across the Data Zoo Group globally;
adequate resourcing for compliance, training, monitoring, and investigations;
periodic review of the ABC risk environment and control effectiveness;
accountability for ensuring high standards of integrity in commercial and governmental interactions.
8.2 Bribery & Corruption Risk Assessment
Where applicable, Data Zoo conducts structured, periodic ABC risk assessments that include:
geographic risks (e.g., high‑risk jurisdictions, weak rule‑of‑law environments);
sector and client risks (government, regulated industries, security‑sensitive environments);
transaction risks (onboarding, procurement, consultancy arrangements, licensing, customs, CSR, gifts, hospitality, travel);
associate risks (third‑party agents, introducers, distributors, contractors, data suppliers, and any party performing services on behalf of Data Zoo);
operational and organisational changes (new markets, mergers/acquisitions, product expansion).
Risk assessments are performed annually or when a material operational change occurs, with outcomes documented and actioned through internal risk registers.
8.3 Due Diligence on Associates
Data Zoo applies a risk‑based due diligence framework to all associates, including employees, contractors, intermediaries, subsidiaries, and any individual or organisation performing services on our behalf.
Minimum Requirements
Identification and verification of the associate’s identity, beneficial ownership, qualifications, and purpose of engagement.
Screening for enforcement actions, sanctions, corruption‑related allegations, politically exposed persons (PEPs), and adverse media.
Confirmation that the associate has not, and is not reasonably likely to, engage in bribery or related unethical conduct
Enhanced Due Diligence (higher‑risk scenarios)
Detailed assessment of bribery risk, business justification, compensation structure, and interaction with foreign public officials.
Review of anti‑corruption policies and control frameworks of the associate.
CCIO/Legal approval before onboarding.
Ongoing Monitoring
Periodic reviews;
Re‑assessment when red flags arise;
Audit rights to review records and payment flows.
8.4 Proportionate and Integrated Controls
Data Zoo implements internal controls proportionate to the bribery risk profile of each business activity, including:
segregation of duties;
documented approval processes for payments, gifts, hospitality, travel, charitable contributions, and sponsorships;
maintenance of accurate books and records that reflect transparent and legitimate transactions;
financial controls (no unrecorded accounts, no cash payments above authorised thresholds, invoice validation).
These controls apply across all global business units and legal entities within the Data Zoo Group.
8.5 Communication, Training & Awareness
Data Zoo ensures all employees and associates understand their anti‑bribery obligations by providing:
mandatory induction training for all new employees;
annual refresher training for employees, directors, and high‑risk roles (e.g., sales, procurement, government‑facing teams, international operations);
tailored training for associates such as consultants or third‑party agents where appropriate;
communication of legal updates, emerging risks, and policy changes through internal channels.
Training must be completed as a condition of employment or engagement.
8.6 Reporting, Whistleblowing & Protected Disclosures
Data Zoo maintains safe, accessible, and confidential internal and external reporting channels.
Employees, clients, contractors, and associates may report concerns anonymously without fear of retaliation.
Reports may relate to suspected bribery, corruption, improper influence, facilitation payments, or any breach of this policy.
Whistleblower protections under the Corporations Act 2001 apply to eligible disclosures.
Data Zoo commits to impartial investigation, confidentiality, and fair treatment of individuals raising concerns.
All concerns are triaged by the CCIO or People & Culture Director in accordance with the Whistleblowing Policy.
8.7 Monitoring, Auditing & Continuous Improvement
To maintain compliance and program effectiveness, Data Zoo undertakes:
periodic internal audit reviews of ABC controls;
testing of high‑risk transactions, associate engagements, and payment flows;
ongoing review of policies, risk assessment outcomes, and incident findings;
incorporation of lessons learned from investigations, regulatory updates, and whistleblower disclosures.
Audit findings are reported to the SLT and Board (or relevant committees), with corrective actions tracked to completion.
8.8 Recordkeeping Obligations
Data Zoo maintains comprehensive records demonstrating adherence to Adequate Procedures, including:
risk assessments, training logs, due diligence documentation, approval decisions, contract terms, monitoring outcomes, and audit findings;
gift, hospitality, travel, CSR and political donation registers;
whistleblowing and investigation records, kept securely and confidentially.
Records must be retained in accordance with Data Zoo’s Document Control Framework and local legal requirements.
8.9 Investigation & Response
Allegations or suspicions of bribery are handled promptly and fairly.
CCIO (or delegate) leads investigations with Legal oversight.
Investigations may include review of records, interviews, system analysis, and escalation to external authorities where required.
Disciplinary action may include warnings, retraining, contract termination, or referral to law enforcement/regulators.
Outcomes and controls are reviewed to prevent recurrence.
8.10 Alignment with Legal and International Standards
Data Zoo’s ABC framework is designed to comply with:
Criminal Code Act 1995 (Cth), Division 70 (Bribery of Foreign Public Officials)
Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024
Attorney‑General’s Adequate Procedures Guidance
Corporations Act 2001 whistleblower protections
OECD Convention on Combating Bribery of Foreign Public Officials
U.S. Foreign Corrupt Practices Act (FCPA) (where relevant to cross‑border operations)
Data Zoo will review this section regularly to remain consistent with global regulatory developments and best practice.
9. Breach of Policy
We will take all necessary measures to remedy any breach of this policy including the use of our disciplinary or contractual processes where appropriate.
9. Records
Records retained in support of this policy are listed in the Change History section below. For earlier versions of this policy please contact the Compliance Team on Compliance@datazoo.com or send an email to info@datazoo.com noting your request in the subject field.
Glossary
Agent: Any third party who may do business on behalf of or for another person and includes clients, contractors, subcontractors, suppliers, consultants, lawyers, accountants, lobbyists, sales agents, brokers, and franchisees.
Beneficial Owner: The natural person who controls an organisation.
Benefit: Any advantage, which is not limited to property, including: financial or non-financial, for example employment, scholarships or favours; and intangibles, for example business advantages, new business, and retention of business. The advantage can be offered by anyone, either directly or indirectly through another person such as an Agent. The recipient of the advantage could be a relative or associate of a Foreign Public Official.
Bribery: A crime under Division 70 of the Criminal Code Act 1995 (Commonwealth). Section 70.2 of the Criminal Code Act 1995 provides that a person commits an offence of Bribery of a Foreign Public Official if: the person provides or offers to another person (either directly or indirectly); a Benefit that is not legitimately due to the other person; with the intention of influencing a Foreign Public Official in the exercise of their duties; in order to obtain a Benefit.
Eligible Whistleblower: An eligible whistleblower includes current or former officers, employees, contractors (including employees of contractors) and individual associates of the regulated entity or a related body corporate, or their current or former relatives or dependents, which includes a spouse or former spouse. A regulated entity includes companies, other constitutional corporations as well as the entities that are covered by the existing regimes in the banking, insurance, and superannuation sectors.
Foreign Public Official: Defined in section 70.1 of the Criminal Code Act 1995 (Commonwealth) and includes: employees, contractors or officials of a foreign government department, agency, state owned or controlled entity; employees, contractors, or officials of a public international organisation; members of foreign military or police; and members of the executive military or court system of a foreign country. Australia’s anti money laundering laws and AUSTRAC use the Financial Action Task Force’s concept of ‘politically exposed persons' (PEPs). Authorities such as the AFP use an analysis of ‘ownership, control, status, and function’ to determine whether a particular entity is an agency or instrumentality of a foreign government. No single factor is determinative.
Facilitation Payment: One of the two defences to Bribery in Division 70 of the Criminal Code Act 1995 (Commonwealth). Defined under section 70.4 of the Criminal Code Act 1995 as: a Benefit of a minor nature; provided or offered to another person (directly or indirectly); for the sole or dominant purpose of expediting or securing the performance of a Routine Government Action of a minor nature. Examples of Facilitation Payments include: passport clearance at frontiers; access to the ‘fast lane’; help speed up issue of documents; port entry for vehicles; release of goods from customs; loading and unloading cargo; obtaining services such as telephone, power, water, mail collection; processing work permits; and planning permissions. Section 70.4(1) of the Criminal Code Act 1995 (Cth) requires the person who provided or offered the Facilitation Payment to make a record of the transaction as soon as practicable after the Facilitation Payment was provided or offered. Section 70.4(3) provides that records must include all the following: the value of the Benefit concerned; the date on which the conduct occurred; the identity of the Foreign Public Official in relation to whom the conduct occurred; if that Foreign Public Official is not the other person, the identity of that other person; particulars of the Routine Government Action that was sought to be expedited or secured by the conduct; and the person’s signature or some other means of verifying the person’s identity.
Routine Government Action: Defined in section 70.4(2) of the Criminal Code Act 1995 (Cth) as an action of a Foreign Public Official that: (a) is ordinarily and commonly performed by the official; and (b) is covered by any of the following: granting a permit, licence or other official document that qualifies a person to do business in a foreign country or in a part of a foreign country; processing government papers such as a visa or work permit; providing police protection or mail collection or delivery; scheduling inspections associated with contract performance or related to the transit of goods; providing telecommunications services, power or water; loading and unloading cargo; protecting perishable products, or commodities, from deterioration; any other action of a similar nature; and (c) does not involve a decision or encouraging a decision about whether to award new business, whether to continue existing business with a particular person or the terms of new business or existing business.
REFERENCES
Standard/ Legislation/ Policy |
Criminal Code Act 1995 (Commonwealth); Division 70 |
Corporations Act 2001 (Commonwealth) |
The Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 (AU Cth) |
U.S. Foreign Corrupt Practices Act 1977 |
United States Strategy on Countering Corruption (whitehouse.gov) |