Compliance

    According to the art. 22 of the European System of Central Banks (ESCB) Statute, the European Central Bank (ECB) has adopted rules regulating payment systems’ functions and facilitates their application so that their effectiveness is assured. The Eurosystem has issued rulebooks and guidelines concerning oversight standards, assessment criteria and payment systems’ obligations. These rules regulate DIAS’s function and its compliance with them is assessed by the BoG and the Eurosystem.

    For further information you may find here the Protocol No 4 on the Statute of the European System of Central Banks and of the European Central Bank.

    On a national level, DIAS as a payment system is overssen directly by the Bank of Greece (BoG) and indirectly by the European Central Bank (ECB). DIAS is conformed to the directions and rules pointed by the BoG concerning payment systems. The Bank of Greece monitors the credibility, effectiveness and transparency of DIAS’s payment system and oversees the efficiency of its technical, functional and organizational infrastructure. Thus, any security or other risk concerning its Payment System is timely prevented.

    For further information, you may follow the present link.  

    DIAS follows these principles, specialized in payment systems. Their range of application varies according to the category each payment system belongs to (SIPSs, PIRPSs, ORPSs). These principles were adopted by the European Central Bank in June 2013 and focus on risk prevention (legal, operational, business, liquidity, credit, custody, and investment risks). Furthermore, they set precise rules and procedures for collateral acceptance, access and participation to the payment system. Finally, they impose on payment systems the obligation of fees and discount policies, to assure their efficiency.

    As an ORPS, DIAS has endorsed the relevant principles and has adopted transparent policies and procedures.

    For further information, you may follow the present link.  

    SEPA constitutes an initiative of the European Union in the payment sector aiming at the integration of the European internal market as well as the monetary integration. DIAS has already adhered to the EPC- SEPA payment schemes and conforms to rulebooks and guidelines issued in this context.

    The European Directive 2015/2366 (PSD2) on payment services and the Greek Law No 4537/2018 under which the Directive was incorporated into domestic legislation set the regulatory framework for payment systems, including the requirements for payment systems authorization and further obligations imposed to them, concerning transaction security and fair pricing.

    DIAS respects its obligations imposed to it by the applicable legal framework. In order to ensure its compliance and harmonization with the European practices concerning the PSD2, DIAS participates in the Convenient Access to PSD2/Payment-related Services (CAPS) initiative since 2016.

    For further information, you may follow the present link.  

    DIAS remains highly aware of any incident that may cause a malfunction to its system. In this context, it applies various technical and organizational measures and has developed a meticulous recovery plan. All these measures are included in DIAS’s Business Continuity Plan structured according to its ISO 22301:2019 certification.

    DIAS has issued transparent policies for information security concerning both its payment system and the Company’s governance and structure. These policies are periodically updated, so that they remain in accordance with the guidelines of  BoG. DIAS is also certified under ISO/IEC 27001:2022 and PCI DSS (Payment Card Industry Data Security Standard). The compliance of DIAS with the PCI DSS is validated on an annual basis through assessment by an Independent Qualified External Auditor.

    DIAS has taken a large variety of technical and organizational measures, in order to successfully recover from any malfunctions or security gaps to its system and to arm it against cybersecurity attacks.

    Code of Ethics & Conduct

    DIAS, with a strong sense of responsibility, ensures that its operations, the services it provides, and its organizational structure comply with applicable legislation and are governed by explicit rules of ethics and professional conduct. These rules regulate its relationships with its shareholders, Management, employees, and all other stakeholders. To this end, DIAS has adopted and implements a Code of Ethics and Conduct.

    To read the Code of Ethics and Conduct: Click here

    Personal Data

    For DIAS, personal data protection is of high concern throughout its operational circle. In this framework, it is fully complied with the domestic and international legislation concerning personal data protection, especially with the European General Data Protection Regulation 2016/679 (GDPR) as well as the Greek Law Νo 4624/2019.Furthermore, it continuously monitors and aligns its practices with the guidelines and decisions of the Hellenic Data Protection Authority (HDPA) and the data protection authorities of other EU Member States, while ensuring the regular training and awareness of its employees and business partners to ensure that the protection of the personal data it processes is safeguarded.

     Reporting of Concerns

    To strengthen its corporate governance framework, ensure compliance with applicable legislation, and uphold the highest standards of ethics, integrity, and transparency, DIAS has established procedures for the submission of anonymous and confidential reports by its employees and external stakeholders regarding workplace violations. Reports may relate to breaches of internal policies, procedures, the Code of Ethics & Conduct, or applicable laws and regulations.

    All reports are treated with the utmost seriousness and are investigated objectively, independently, and impartially. The Company ensures that whistleblowers are protected against any form of retaliation and that the personal data of all parties involved are safeguarded through the implementation of appropriate technical and organizational security measures.

    The Company is committed to maintaining the highest standards of ethical and professional conduct and adopts a zero-tolerance approach to unlawful actions or practices that are contrary to the principles of sound corporate governance and that could harm its reputation and credibility.

     Reporting Channels

    a) By post, to the following address:

    DIAS Interbanking Systems S.A.

    2 Alamanas Street

    15125 Maroussi, Greece

    Attention to the Whistleblowing Officer (WO) (marked "Confidential")

     b) By e-mail, at: speakup@dias.com.gr

     c) Directly to the Company's Whistleblowing Officer (WO), by prior appointment at the Company's premises or through an oral report by telephone at +30 210 6106740.

    When submitting a report through any of the above channels, whistleblower may use the designated reporting form provided by the Company. The use of the form is recommended; otherwise, the report should include, at a minimum, the identity of the individual(s) who may have committed the alleged misconduct (or, where their identity is unknown, their position and any other information that may assist in identifying them), the date or period and location of the incident, the nature of the alleged misconduct (as assessed by the whistleblower), and as detailed a description of the incident as possible, without including unnecessary information.

    In addition, the whistleblower may request a private meeting or telephone conversation with the WO in order to submit an oral report. In such cases, written minutes of the meeting or conversation will be prepared and maintained by the WO.

    The operation of the reporting channels, as well as the receipt, monitoring, handling, and archiving of reports, is further governed by the provisions of the Whistleblowing Policy, as amended from time to time (see the summary of the Policy below).

    Every whistleblower also has the right to submit an external report to the National Transparency Authority (NTA). Further information is available on the NTA's website under the Contact section (aead.gr).

    Personal Data Processing Terms

    Whistleblowing Policy

    Anti-Fraud and Anti-Corruption Policy

    To read the Anti-Fraud and Anti-Corruption Policy, click here