Business Partner Code Of Conduct
Version 2.0 · Published 10 August 2026
1. Applicability & Scope
DataOne (“DATAONE”) is a leading company committed and striving for conducting all aspects of its business with honesty and integrity towards its partners, customers, suppliers, competitors, representatives, sponsors, joint venture, consortium, equity partners, stakeholders, and its service providers such as suppliers, vendors,
consultants, subconsultants, contractors and subcontractors, and their employees or persons acting on their behalf (collectively, “Business Partner(s)”). For purposes of this Code of Conduct, “DATAONE” means DataOne and its applicable subsidiaries and affiliated entities. DATAONE recognizes that legal requirements
vary in a global market and promotes the highest standards of conduct, ethics, integrity, and sustainability in line with all the applicable laws, regulations, and standard measures (including but not limited to anti-corruption, AML-CFT, labour, data-protection, environmental, and tax compliance requirements). DATAONE expects all
Business Partners to act with the same fairness, honesty, responsibility, and dedication in all aspects of their business. This Business Partner Code of Conduct (“Code of Conduct”) sets out the minimum ethical, legal, social, environmental and compliance standards that DATAONE expects each Business Partner to comply with
throughout its relationship with DATAONE.
Each Business Partner shall communicate and flow down equivalent requirements to its subcontractors, subconsultants, suppliers and other third parties involved, directly or indirectly, in providing goods or services to DATAONE. Each Business Partner shall implement reasonable and documented measures to monitor
compliance throughout its relevant supply chain.
Acceptance of this Code of Conduct is a mandatory condition of onboarding and registration for all suppliers, contractors, subcontractors and service providers. No such Business Partner may be activated in DATAONE’s systems or receive a purchase order unless this Code of Conduct has been duly accepted or acknowledged in
accordance with DATAONE’s applicable onboarding procedures.
DATAONE may require the Business Partner to re-acknowledge this Code of Conduct following any material amendment to it, upon renewal of the business relationship, or otherwise upon reasonable request.
2. Compliance With Laws & Regulations
Business Partners shall comply with this Code of Conduct as well as with all applicable laws, regulations, regulatory requirements and industry standards in every jurisdiction in which they operate or provide goods or services to DATAONE. Business Partners shall take reasonable and documented measures to ensure that equivalent standards and principles apply throughout the relevant portions of their supply chain.
Business Partners shall maintain appropriate traceability regarding the origin of materials, components and products incorporated into goods supplied to DATAONE and shall provide supporting documentation upon DATAONE’s reasonable request. Business Partners shall provide complete, accurate and non-misleading
information in connection with DATAONE’s onboarding, qualification, audit, due diligence, screening and compliance processes.
Where goods, components or materials are supplied directly or indirectly for importation into, delivery to, or use in the United States, Business Partners shall cooperate fully with DATAONE regarding forced-labour due diligence requirements, including requirements arising under the Uyghur Forced Labor Prevention Act (“UFLPA”), and shall provide all reasonably requested supply-chain and origin documentation.
Business Partners represent that they do not knowingly source goods, materials or components from any entity included on the UFLPA Entity List and shall notify DATAONE in writing within five (5) Business Days if any supplier, manufacturer or other participant in their relevant supply chain becomes listed or otherwise subject to
equivalent forced labour restrictions.
Business Partners shall exercise appropriate due diligence concerning conflict minerals and other minerals or raw materials originating from conflict-affected or high-risk areas and shall provide relevant declarations, certifications or traceability information upon DATAONE’s reasonable request.
The Business Partners shall never act in a way that could cause DATAONE to violate laws, regulations, and associated requirements and industry standards, or expose it to any penalties. In the event of any actual or suspected non-compliance with this Code of Conduct, DATAONE may require the Business Partner to implement a corrective action plan within a specified period, provide additional supporting information, undergo enhanced monitoring or audit, suspend affected activities, suspend or withdraw supplier approval or registration, or terminate the applicable business relationship, purchase order or agreement, subject to the terms of the applicable contract and applicable law. These rights are without prejudice to any other rights or remedies available to DATAONE.
3. Competition And Antitrust Laws
DATAONE engages in open and fair procurement practices where Business Partners are selected on a competitive basis and establish a mutually beneficial relationship based on close cooperation and open communications. Therefore, each Business Partner shall:
a. carry out their activities in a manner that safeguards fair, open, and transparent competition;
b. comply with applicable competition and antitrust laws and regulations;
c. never participate in illegal practices such as price fixing, market sharing, bid rigging, monopolistic conduct
or customer allocation; and
d. never propose or enter into any agreement with a competitor to fix margins, prices or contractual terms, or
to divide up the market in any way.
4. Anti-bribery And Corruption Laws
DATAONE is fully committed to instilling a strong anti-corruption culture and is fully dedicated to compliance with all anti-bribery and anti-corruption legislation, and in return, DATAONE expects each Business Partner to:
a. comply with all applicable anti-bribery and corruption laws, including but not limited to the U.S. Foreign Corrupt Practices Act (“FCPA”) and the U.K. Bribery Act;
b. never accept, request, promise, offer, give, or authorize a bribe, kickback, or other improper payment or anything of value (financial or otherwise) to obtain an unfair or improper advantage, retain business, or influence a third party’s actions or decisions, or for any other reason;
c. never offer or accept business courtesies of more than modest value, offer cash or cash equivalents or exchange any benefit with a public official or other recipient involved in an active procurement process or that would otherwise appear to reward preferential treatment or create an obligation;
d. refrain from making facilitation payments on behalf of DATAONE or for its intended benefit, even where legal; and
e. ensure that these standards of integrity extend to any third party engaged by the Business Partner in relation to DATAONE.
5. Anti-money Laundering, Sanctions, And Fair Dealing
DATAONE expects the Business Partners to:
a. prevent and monitor for potential money laundering, terrorist financing, or any activity violating applicable sanctions or export control regulations;
b. ensure they are conducting business only with reputable business partners, for legitimate business purposes, with funds derived from legitimate sources;
c. comply with all applicable statutes governing the prevention of money laundering and not to participate in any money laundering activity; and
d. comply with all applicable anti-money laundering, counter-terrorist financing, economic sanctions, export control and anti-bribery laws, regulations and related compliance requirements applicable to the Business Partner, the relevant transaction and the applicable DATAONE contracting entity.
Business Partners represent that neither they, nor their directors, officers or, to the best of their knowledge, their ultimate beneficial owners are subject to applicable sanctions administered by the United Nations, the European Union, OFAC, OFSI or other competent sanctions authorities, and shall promptly notify DATAONE of any material change affecting such representation.
6. Data Protection And Privacy
DATAONE is strongly committed to protecting privacy and complying with data protection laws. At DATAONE personal and non-personal information is collected in accordance with the highest privacy and data protection standards adopted worldwide. DATAONE maintains a robust and effective data protection program in place which complies with applicable law and abides by the data protection principles.
DATAONE expects the Business Partners to:
a. comply with all applicable data protection laws in collecting, processing, storing or otherwise handling personal data of any individuals, including, without limitation, to their own employees and employees of their customers, suppliers and Business Partners;
b. respect individuals in a manner consistent with the rights to privacy and data protection; and
c. to use at all times information about people appropriately for necessary business purposes and protect it from misuse in order to prevent harm to individuals such as discrimination, stigmatization or other damage to reputation and personal dignity, impact on physical integrity, fraud, financial loss or identity theft.
Where a Business Partner processes personal data on behalf of DATAONE, they shall enter into a written
Data Processing Agreement that meets the requirements of applicable data protection laws.
8. Audit
While Business Partners are expected to self-monitor and demonstrate their compliance with this Code of Conduct as well as all applicable laws, regulations, and standard measures, DATAONE reserves the right to audit Business Partners to verify compliance.
The scope of such audits shall include, without limitation, an examination of books, records, and facilities related to the Business Partner’s business with DATAONE. Business Partners shall bear the reasonable costs of any audit which reveals a material violation of this Code or any applicable law.
Business Partners are expected to cooperate with DATAONE’s periodic requests for documents and/or information made in connection with DATAONE’s partner onboarding and due diligence processes. To ensure that our partners adhere to DATAONE’s policies, Business Partners may be asked to provide certain information identifying the company structure, the potential existence of conflicts of interest, and compliance with all applicable laws. Business Partners are obligated to provide truthful and accurate
responses to such requests for information. DATAONE reserves the right to request additional information at any time. DATAONE may terminate its business relationship with any Business Partner that fails to provide truthful and accurate information or cooperate with compliance requests.
Business Partners shall retain records reasonably necessary to demonstrate compliance with this Code of Conduct for a minimum period of five (5) years following the termination or expiration of their business relationship with DATAONE, or such longer period as required by applicable law or the applicable agreement.
DATAONE may conduct documentary or on-site audits directly or through an appointed independent third party. Audits shall be conducted on reasonable notice, except where immediate access is reasonably required due to a suspected material breach, regulatory requirement, safety concern, human-rights risk, environmental incident or other urgent compliance matter.
Business Partners shall promptly notify DATAONE upon becoming aware of any actual or suspected breach of this Code of Conduct, any applicable law, or any matter that may materially impair their ability to comply with this Code of Conduct.
Business Partners shall cooperate with DATAONE’s supplier qualification, compliance screening, sustainability assessments, ESG reviews, lender due diligence and other verification processes applicable to DATAONE’s projects or operations.
Where non-compliance is identified, DATAONE may require the implementation of a corrective action plan within a reasonable period, request additional supporting documentation, suspend the Business Partner’s approval status, suspend ongoing activities, suspend or withdraw the Business Partner’s approval or registration, or terminate the applicable business relationship, purchase order or agreement, subject to the terms of the applicable agreement and applicable law.
9. Ethical Business Practices
DATAONE’s business practices are based on honesty, integrity and compliance with all applicable laws, regulations, and standard measures. DATAONE is committed to dealing fairly and honestly with all our Business Partners, regardless of where they are located or the type of products or services they provide.
9. Conflicts Of Interests
DATAONE believes that personal interests should never affect business decisions made. DATAONE expects
that Business Partners shall:
a. Avoid any real, apparent, or potential conflict of interest;
b. disclose in writing to DATAONE any actual, apparent, or potential conflict of interest that may affect, or reasonably appear to affect, any decision in which they are asked to participate or any service they are asked to perform;
c. promptly disclose to DATAONE any personal, family, financial or other relationship with a DATAONEemployee, officer, consultant or representative that could create, or reasonably appear to create, an improper influence over any procurement, selection, evaluation, approval or payment decision;
d. consider potential conflicts of interest at the earliest stage possible and declare any interest promptly;
e. never participate in any decision or perform any other service until the potential conflict is resolved; and
f. adequately document any activity that has been approved to proceed notwithstanding an identified conflict of interest, together with the applicable mitigation measures.
9. Employment Practices And Workplace
DATAONE promotes inclusion, diversity, equity, and a congenial working environment in which all individuals are treated with dignity and respect, free from harassment, discrimination, bullying, racism, violence, or injustice. DATAONE expects that Business Partners shall:
a. ensure a respectful and safe workplace;
b. prohibit all forms of child labour and shall not employ any individual below the minimum legal working age applicable in the relevant jurisdiction and, in any event, below the age of fifteen;
c. prohibit all forms of forced labour, bonded labour, involuntary servitude, slavery and human trafficking;
d. comply with applicable requirements concerning working hours, rest periods, minimum wages and other mandatory employment entitlements;
e. respect workers’ lawful rights to raise grievances and organize or be represented in accordance with applicable law;
f. provide a safe and healthy working environment that complies with applicable occupational health and safety laws and standards;
g. never engage in any form of discrimination, harassment or demeaning behavior against any individual or group;
h. provide employees and supply chain with a work environment that is free of verbal, physical, or mental harassment (including sexual harassment) and any discriminatory, violent, harsh, or inhumane treatment;
i. offer fair compensation without discrimination and in compliance with local labour laws and regulations; and
j. adopt and enforce policies which effectively prohibit Discrimination, harassment, or demeaning behaviour.
“Discrimination” includes adverse treatment based on race, perceived race, ancestry, ethnic origin, citizenship, creed, colour, religion, age, sex, sexual orientation, gender identity, gender expression, marital or family status, physical or mental disability, political belief, political affiliation or activity, social condition, lawful source of income, association, military status, genetic information, or pardoned conviction.
9. Environmental Compliance
Business Partners shall:
a. comply with all applicable environmental laws, regulations, permits, licences and authorisations;
b. obtain and maintain all environmental permits, approvals and licences required for their operations and for the provision of goods or services to DATAONE;
c. manage waste, wastewater, emissions, hazardous substances and other environmental impacts in accordance with applicable law and accepted industry practices;
d. refrain from illegal dumping, unlawful discharges, unlawful deforestation and any other activity that may cause material environmental harm;
e. promptly notify DATAONE of any actual or suspected environmental incident, breach, investigation or enforcement action that may affect DATAONE, its sites, projects, customers or reputation; and
f. provide, upon reasonable request, environmental and sustainability information relevant to DATAONE’s supplier qualification, ESG assessment, lender reporting or project-compliance requirements.
9. Dataone Site Safety
Where Business Partners perform work on DATAONE premises, they shall comply with all applicable DATAONE health, safety, security and site-access requirements.
Business Partners shall immediately report any accident, injury, environmental incident or serious safety event occurring on a DATAONE site and cooperate fully with any investigation.
DATAONE reserves the right to require the immediate removal from its premises of any personnel who fail to comply with applicable health, safety or security requirements.
9. Dataone Site Safety
DATAONE values the protection and respects the intellectual property rights and information of its employees,
clients, and Business Partners.
DATAONE expects the Business Partners to:
a. act with vigilance when handling DATAONE’s Confidential Information;
b. limit the use of DATAONE’s Confidential Information to individuals who require it to perform their work and their contractual obligations or as required by the applicable laws;
c. protect DATAONE’s Confidential Information from unauthorized access, improper use, and disclosure with third parties, even after the termination of their business relationship with DATAONE;
d. comply with applicable data privacy and data protection laws, regulations, information security policies and contractual requirements when processing, collecting, storing, accessing, modifying, sharing or transferring DATAONE’s Confidential Information;
e. not process, store, upload or transmit DATAONE’s Confidential Information through any public or consumer-facing system, including any public or consumer-facing artificial intelligence tool, unless DATAONE has provided prior written approval and appropriate contractual and security protections are in place;
f. obtain DATAONE’s prior written approval before using DATAONE’s Confidential Information for any purpose other than the performance of the applicable agreement;
g. keep DATAONE’s Confidential Information safe and secure and use the same standard of care used to safeguard its own information of a confidential nature, but which shall at all times be no less than a reasonable standard of care, and taking all reasonable steps to prevent any unauthorized disclosure; and
h. report without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of, any actual or suspected unauthorized access, use, disclosure, compromise or loss of DATAONE’s Confidential Information.
Upon termination of the business relation or upon DATAONE’s written request, the Business Partner shall immediately return, delete, or destroy all Confidential Information and provide written certification of compliance.
“DATAONE’s Confidential Information” includes all information provided by DATAONE and pertaining to DATAONE, its clients, employees, and Business Partners.
9. Intellectual Property
DATAONE’s Business Partners may only use DATAONE’s intellectual property, such as trade secret information, copyrights, patents and trademarks, in a manner permitted under their contract with DATAONE and may not misappropriate or infringe the intellectual property rights of others. DATAONE’s Business Partner shall not misuse any trade secrets or proprietary or confidential information of DATAONE or of others for their own purposes or disclose such information to unauthorized third parties. DATAONE’s Business Partner shall notify DATAONE if they become aware of any unauthorized use of the DATAONE brands, trademarks or logos by a third party.
Business Partners shall warrant that any materials or services provided to DATAONE do not infringe upon the intellectual property rights of any third party. To the extent provided in the applicable agreement, the Business Partner shall indemnify DATAONE against any losses, damages, and costs arising from a breach of this warranty.
9. Acknowledgement And Continuing Compliance
By entering into or continuing a business relationship with DATAONE, the Business Partner acknowledges that it has reviewed this Code of Conduct and agrees to comply with its requirements.
Where this Code of Conduct is referenced in, attached to, or incorporated into a purchase order, framework agreement, master agreement or other contract with DATAONE, it shall form an integral part of such agreement and shall be legally binding upon the Business Partner. In the event of any inconsistency between this Code of Conduct and the applicable agreement, the provision imposing the more stringent compliance obligation shall prevail, unless the applicable agreement expressly states that it overrides this Code of Conduct in respect of the relevant matter.
Compliance with this Code of Conduct does not create any entitlement to receive orders, remain an approved Business Partner or continue any business relationship with DATAONE.
The Business Partner shall remain responsible for ensuring ongoing compliance with this Code of Conduct throughout its relationship with DATAONE and shall provide written confirmation of compliance upon DATAONE’s reasonable request.
DATAONE Business Partners and other stakeholders may report suspected violations (anonymously and confidentially) by sending an email to contact.legal@dataone.eu