Atea ASA

Norway|Software & IT Services|Reporting year:FY2025FY2024|Auditor: Deloitte AS|View original report →

Sustainability statement, in full

The complete text of Atea ASA’s FY2025 sustainability statement is held here – 134 pages, captured from the published report. Every disclosure below also links to its own passage.

ESRS 2 – General Disclosures

GOV-1The role of the administrative, management and supervisory bodies
Reported

Reference: page 40

The Board oversees corporate governance and evaluates business strategy including risks and opportunities; the Audit and Compliance Committees focus on risk management and compliance; Corporate Management executes the strategy (page 40). The Board "formally approves the Group's sustainability strategies, monitor progress towards targets" and "formally approves Atea's Annual Report, including the sustainability statement", with ESG review delegated to the Audit Committee (page 41). Implementation sits with the Corporate Governance Department (data accuracy and completeness), the Sustainability Department (strategy and targets) and a Head of Sustainability at national level, with the CFO and COO "playing pivotal roles" (page 41).

Composition (page 41): nine Board members since 2023, all non-executive, three employee-elected; 78% independent of the largest shareholders and management; no change versus 2024.

Gender diversity at 31 December 2025 (page 42): Board 4 female (44%) / 5 male (56%); Corporate Management 0 female / 7 male (100%), after the Managing Director of Atea Denmark departed at the start of 2025, down from 13% female in 2024. A successor was appointed in March 2026.

Certifications include ISO 9001, 14001, 37001, 27001, 20000-1, 45001 and 50001 (page 42). The Statement of Corporate Governance is incorporated by reference for paragraph 22(b) (page 40).

GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies
Reported

Reference: page 42

Under the reformed governance structure the outcomes of the reviewed double materiality assessment "were presented directly to the Audit Committee. Unlike the previous year (when the initial DMA was reviewed by the CFO and COO before submission for approval), this year's process was shortened, as no new material impacts, risks or opportunities were identified" (page 42).

The Audit Committee was informed through the Corporate Governance Quarterly Report on material IROs in relation to the company's SBTi targets and evolving regulatory requirements, including ISO certification adjustments. The specific topics named (page 42) are:

  • Greenhouse gas emissions across the value chain
  • Energy use by Atea and in the use of sold products
  • Discrimination and/or harassment
  • Supply chain management and governance
  • Bribery risks for employees and across the value chain

Decisions made, "including actions taken or planned", formed part of the quarterly updates to both the Audit Committee and Corporate Management (page 42). The statement does not disclose how the bodies consider trade-offs between IROs, nor a schedule of specific agenda dates.

GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemes
Reported

Reference: page 43

Atea states that this disclosure "includes the GOV-3 disclosure requirement in E1" (page 43). The performance-based bonus system covers Corporate Officers and executives. Each year the Board meets the Corporate Officers to turn the long-term business strategy into business development plans and financial targets for the coming year.

"The cash bonus for the CEO is based on the Group's annual business results, supplemented by an evaluation of the Group's performance against specific objectives developed with the Chairman of the Board at the start of the year. These objectives include Atea's performance in sustainability, specifically with ratings such as EcoVadis (Platinum or Gold). The proportion of additional bonus for the CEO dependent on sustainability-related targets is 5%" (page 43).

"The Board does not have any performance-related remuneration" (page 43). Incentive scheme terms are approved by the General Meeting, with the Board, including the Chairman, leading the review and recommendation process. The Remuneration Report is incorporated by reference for GOV-3 paragraph 29(a-e) and S1-16 paragraph 97(b) (page 40). No climate-specific percentage of variable remuneration is separated out, and no GHG-reduction-linked portion is quantified.

GOV-3(was GOV-4)Statement on due diligence
Reported

Reference: page 43

Atea's due diligence process is "aligned with the OECD Guidelines for Multinational Enterprises, the OECD Due Diligence Guidance for Responsible Business Conduct, and the UN Guiding Principles on Business and Human Rights" (page 43). Risk identification draws on "the RBA Risk Assessment Platform, governmental and NGO reports, supplier insights, industry expertise, media monitoring, and aggregated findings from RBA audit non-conformities, most commonly related to working hours and emergency preparedness" (page 43).

The six-step cycle is set out on pages 44-45, and the mapping table required by GOV-4 appears on page 45, tying each core element to specific paragraphs, for example:

  • Embedding due diligence in governance, strategy and business model → ESRS 2 GOV-2, GOV-3
  • Engaging with affected stakeholders → GOV-2, SBM-2, IRO-1, MDR-P, S1-2, S2-2, S4-2
  • Identifying and assessing adverse impacts → IRO-1, SBM-3
  • Taking actions → MDR-A, E1-1, E1-3, E5-2, S1-4, S2-4, S4-4
  • Tracking effectiveness and communicating → MDR-M, MDR-T, E1-4/5/6, E5-3, E5-5, S1-5/6/7/9/13/14/15/16, S2-5, S4-5

A salient human rights issues assessment was conducted in 2023 by an external consultant, covering eight issue areas (page 45). Atea states engagement with rightsholders "remains an area for improvement" (page 43).

GOV-4(was GOV-5)Risk management and internal controls over sustainability reporting
Reported

Reference: page 46

"Atea uses a group‑wide internal control framework inspired by the COSO model. This framework currently supports financial reporting and is being progressively adapted to meet the sustainability reporting requirements under CSRD and ESRS" (page 46).

The Board conducts an annual review of the internal control guidelines as part of its assessment of risk exposure, covering financial reporting, communication, authorization, risk management, ethics and social responsibility. The Audit Committee oversees quality assurance of both financial and non-financial reporting and monitors the Group's internal control and risk management systems (page 46).

While the COSO-based controls are still being extended, Atea relies on interim measures: "documented reporting procedures, targeted training, ongoing monitoring of regulatory requirements, and controls embedded throughout data collection and validation" (page 46).

"Key risks relate to regulatory non‑compliance, incomplete or inaccurate disclosures, and the use of estimates" (page 46). The statement does not describe a separate internal audit function for sustainability data or report the results of any control testing.

SBM-1Strategy, business model and value chain
Reported

Reference: page 46

"The end of 2024 marked the conclusion of our previous business strategy and the beginning of a new chapter for Atea," with outcomes from the double materiality assessment integrated and the transition plan serving as "the central framework that connects materiality outcomes with business priorities". The plan "applies to the entire Atea Group covering all regions, products, services, markets and business relationships" (page 46).

Atea operates in the Information Technology Services sector across the Nordic and Baltic regions, with solutions in three areas: Digital Workplace, Hybrid Platforms and Information Management (page 46). Group revenue was NOK 37,376 million in 2025 and operating profit NOK 1,377 million (page 3).

"Although Atea is not engaged in manufacturing, its position in the value chain allows it to drive positive change" (page 47). The value chain diagram on page 47 runs from raw material extraction, component manufacturing and assembly/software development through brands and European distributors to Atea, its customers, used electronics, repair, downstream take-back partners and smelters/refiners. Upstream covers key hardware and software suppliers; downstream covers distribution channels, customers, resell/refurbish/reuse/recycling partners and end-users (page 47).

Market position, strategy, business model and value chain (paragraph 38) and revenue per segment (Note 4) are incorporated by reference (page 40).

SBM-2Interests and views of stakeholders
Reported

Reference: page 48

Atea states this "includes the SBM-2 disclosure requirement in S1, S2 and S4" (page 48). Key stakeholders are "customers, suppliers and business partners, employees, shareholders and investors, workers in the value chain, consumers and end-users, as well as affected communities" (page 48).

Dialogue was performed as part of the 2024 DMA, and "insights gathered through this stakeholder dialogue directly informed the 2025 review, where stakeholder feedback was systematically analyzed and incorporated to refine the assessment methodology, reassess IRO classifications and strengthen the overall quality and relevance of the DMA outcomes" (page 48). NGO and affected-stakeholder representatives were interviewed, and "investor representatives validated the DMA outcomes through interviews"; regulators and industry bodies were considered indirectly via published material (page 53).

Corporate Management and the Board have been informed of stakeholders' views, which "were used as input to the Group's new business strategy for 2025-2027" (page 48). Atea acknowledges "our limited direct influence" and works through partners and industry associations. The nearest potentially affected communities are "the Samiindigenous people in Norway, Sweden, and Finland", with credible proxies used because direct engagement "has not yet been established" (page 53).

SBM-3Material impacts, risks and opportunities and their interaction with strategy and business model
Reported

Reference: page 48

The material IRO table sits on page 49 and is repeated at the head of each topical chapter (pages 58, 73, 94, 109, 115, 120). Twelve material IROs are disclosed across six topical standards:

  • E1 greenhouse gas emissions across the value chain (actual negative); energy use by Atea and in the use of sold products (actual negative); customer requirements for sustainable data centers (opportunity)
  • E5 promotion of circular economy among customers (actual positive); unnecessary e-waste (actual negative); fully implementing the LCM strategy (opportunity)
  • S1 discrimination and/or harassment (actual negative)
  • S2 lack of living wage (actual negative); labor, health and safety concerns within the value chain (actual negative)
  • S4 insecure data handling and privacy breaches (potential negative)
  • G1 bribery risks for employees and across the value chain (actual negative); corporate culture to attract and retain talent (opportunity)

Each row is placed in the value chain (upstream, own operations, downstream) and across short, medium and long horizons. Atea states "No climate-related risk was assessed as material" (page 58), and no material risks or opportunities were found for own workforce (page 93) or consumers and end-users (page 115).

IRO-1Description of the processes to identify and assess material impacts, risks and opportunities
Reported

Reference: page 49

Atea states this "includes the IRO-1 disclosure requirements in E1, E5 and G1" (page 49). Materiality assessments have run since 2015; a Group-level ESRS DMA was completed in 2024 and reviewed in 2025. The DMA "covers the entire value chain, our own operations, upstream suppliers, and downstream partners", using region-specific workshops across the Nordics and Baltics; the December 2023 salient human rights assessment fed the impact workshops (page 49).

Four steps (pages 54-56): understand context (ESRS 1 AR 16, WEF Global Risk Outlook, MSCI ESG Industry Materiality Map, SASB, peer review); identify IROs; assess significance; prioritise. Impacts were scored on scale, scope and irremediability plus likelihood if potential; risks and opportunities on likelihood and magnitude, "primarily qualitative in nature". Both scales run 1-5 (page 55) and "Thresholds for materiality were set at an average score of four" (page 56).

2025 review (page 56): methodology refined with "enhanced stakeholder engagement, closer integration with the ERM framework, and the use of qualitative thresholds". All S3 impacts and certain E5 risks were removed, and S1/G1 positive impacts reclassified after the July 2025 ESRS 1 amendments. "The next comprehensive review... is scheduled for FY29 reporting."

Climate risk identification and scenario analysis is also presented under E1-2, and the resilience conclusion under E1-3 (2025 ESRS numbering).

IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reported

Reference: page 57

"Atea has used the results of its double materiality assessment, as well as an analysis of the materiality of information for stakeholders and readers of the report, when determining which standards, disclosure requirements and data points to disclose... We report on all the standards, disclosure requirements and data points that concern our material impacts, risks and opportunities. When it comes to metrics, we determined some disclosure requirements and data points were not material to report on" (page 57).

Two indexes are published and described as "integrated parts of the sustainability statement" (page 57):

  • Content index including a list of material Disclosure requirements (pages 127-130), covering ESRS 2 (BP-1 to IRO-2) and the DRs under E1, E5, S1, S2, S4 and G1 with a page reference each. E1-9 and E5-6 carry the note "Not reported for 2025 due to use of phase-in provision". Two entity-specific disclosures are listed: Atea-1 Reuse and recycling of products (page 81) and Atea-2 Potential savings through the reuse of equipment (page 82).
  • List of datapoints... that derive from other EU legislation (pages 131-135), with a Material / Not material column; three E1-9 datapoints are marked "Material but omitted due to phase-in option" (page 132).

E2, E3, E4 and S3 do not appear in the content index.

E1 – Climate Change

E1-1Transition plan for climate change mitigation
Reported

Reference: page 58

"Atea's Transition Plan outlines the company's pathway to achieving net-zero emissions by 2040 in alignment with the 1.5°C goal of the Paris Agreement" (page 58). "Approved by Corporate Management and the Board of Directors, the plan incorporates related initiatives and the outcomes of our double materiality assessment. The Chief Operating Officer is responsible for developing Atea's business strategy... Oversight of the plan's relevance and alignment is provided by the Chief Financial Officer, Chief Operating Officer, Director of Corporate Governance and Director of Sustainability" (page 59). In 2024 the updated near-term 1.5°C-aligned targets and the long-term net-zero target were approved by the SBTi.

Locked-in emissions (pages 59-60): the vehicle fleet is "approximately 82% of Atea's total Scope 1 and 2 emissions", offices and data centers the remaining 18%; the use phase of sold IT products is "approximately 20% of Atea's Scope 3 emissions". Atea projects operational locked-in emissions of 2,167 tCO₂e in 2030, declining to zero by 2050, and use-phase emissions of 421,745.8 tCO₂e in 2030, also reaching zero by 2050. Mitigation rests on tracking the absolute targets and on "not entering into new car lease agreements for fossil fuel vehicles".

Levers are cross-referenced to E1-3 and capital expenditure to the EU Taxonomy section (pages 60, 62).

E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysis
Reported

Identification of climate-related risks and scenario analysis

Back-filled from ESRS 2 IRO-1 (pages 49-52) and the E1 SBM-3 climate subsection (page 60). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

¶15 classification. Risks are presented as transition and physical. Transition risks are grouped on page 51 under policy and legal (carbon pricing, EU ETS), current regulations (the revised EU Energy Efficiency Directive), emerging regulations (e-waste), market (Guarantees of Origin prices, customer demand), technology and reputation. Physical risks on page 52 are acute supply chain disruption from extreme weather and nature loss, and chronic temperature and precipitation change raising cooling demand.

¶16 methodology. "We map each major site and business function for exposure and sensitivity to climate-related hazards and combine these with expected likelihood, severity, and duration to determine pre-mitigation physical risk across all horizons" (page 50).

¶17 scenario analysis. Conducted in 2024 with CEMAsys (page 60), following "TCFD and IFRS S2, applying IEA and IPCC pathways (SSP1-2.6 and SSP5-8.5) through 2060 across seven countries... and fifteen climate regions", using CMIP6 and IEA NZE data, with horizons of 0-3, 3-5 and 5-30 years (page 50). No global average temperature projection per scenario is stated, and scope is limited to "major offices and data centers".

E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate change
Reported

Resilience in relation to climate change

Back-filled from the E1 SBM-3 climate subsection (page 60) and ESRS 2 IRO-1 (page 50). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

¶19(a) results. "Atea assessed the resilience of its strategy and business model across short-, medium- and long-term time horizons" (page 60). Insights on "increased cooling demand, changing precipitation patterns and rising energy- and carbon-related costs" were weighed against Atea's capacity to manage its two material impacts, and "Atea demonstrates resilience through renewable electricity sourcing, continuous energy efficiency improvements, cooling system upgrades, and circular economy and product efficiency initiatives". The conclusion: "Atea's strategy and business model remain robust under all analyzed pathways. No climate-related risks exceeded the materiality threshold when considering Atea's adaptive capacity, while one opportunity was confirmed as material" (page 60).

¶19(b) uncertainty. No distinct uncertainty section; the stated scope limitation is that "the scenarios focus on major offices and data centers" (page 50).

¶19(c) capacity to adjust. Addressed qualitatively through the transition plan levers, not through financial flexibility or asset redeployment.

A 2025 TNFD-aligned assessment found "no new material risks or opportunities" (page 60).

E1-4(was E1-2)Policies related to climate change mitigation and adaptation
Reported

Reference: page 61

"Atea's Climate Policy aligns with the 1.5°C scenario of the Paris Agreement, the UN's Sustainable Development Goals and the Science Based Targets initiative. It outlines our actions to reduce emissions, enhance energy efficiency, promote low-carbon solutions and advance the transition to renewable energy sources across all our operations and value chain. This policy applies to all Atea Group companies, requiring all employees and business units to adopt and adhere to the Climate Policy in their business activities and decision-making processes" (page 61).

The policy covers mitigation and adaptation: it "specifies steps to reduce GHG emissions, improve energy efficiency, and support low-carbon solutions for our customers and stakeholders", commits Atea to tracking and reducing emissions across the whole value chain in line with the Greenhouse Gas Protocol, and to promoting renewable energy and energy efficiency "to adapt to the changing climate" (page 61).

Value chain reach comes through the Supplier Code of Conduct, which "emphasizes tracking, documenting and publicly reporting energy consumption and GHG emissions. Suppliers are encouraged to enhance energy efficiency and reduce their emissions" (page 61).

Accountability is cross-referenced to GOV-1, and both the Climate Policy and Supplier Code of Conduct are published on atea.com. The statement does not say whether third parties were consulted on the policy or how its effectiveness is monitored.

E1-5(was E1-3)Actions and resources in relation to climate change policies
Reported

Reference: page 61

Levers are applied Group-wide on an operational control basis, monitored annually against SBTi targets (page 61). Four levers are disclosed:

  • Fleet electrification. Mobile combustion fell 309 tCO₂e year on year and 748 tCO₂e versus the base year; to meet the 80% Scope 1 and 2 target "we must reduce emissions by 7% annually", with "further reductions of approximately 3,000 tCO₂e" expected by 2030.
  • Renewable energy. "We have achieved our short-term target set for 2025 by transitioning to 100% renewable electricity: a substantial increase from the 39% share in 2019. This transition is projected to deliver an annual reduction of approximately 6,000 tCO₂e." Renewable energy reached 74% of total energy consumption.
  • Data centre energy efficiency. Trondheim "has joined the European Code of Conduct on Data Centres as a Participant", with a roadmap for Oslo and Umeå (pages 61-62).
  • Circularity of IT equipment. Supports the 50% Scope 3 target. In 2025 "Scope 3 emissions increased by 7%... primarily due to higher sales of desktops and laptops linked to the Windows 10 end-of-life transition" (page 62).

On resourcing, the actions "will require careful planning to balance potential investments, primarily for infrastructure upgrades and renewable electricity certificates, without being dependent on the availability or allocation of significant resources" (page 62). No CapEx or OpEx amounts are attached.

E1-6(was E1-4)Targets related to climate change mitigation and adaptation
Reported

Reference: page 62

Targets set in 2018 were resubmitted in 2023 and "approved in 2024" by the SBTi, aligned with 1.5°C and including net-zero (page 62). "Atea's targets are set at the Group level... These are absolute reduction targets and Atea has not set any intensity targets", calculated under the GHG Protocol for all sites under operational control.

Validated targets (page 65): renewable electricity from 39% in 2019 to 100% by 2025, continuing through 2030; Scope 1 and 2 down 80% by 2030 from a 2019 base year; Scope 3 down 50% by 2030; all scopes down 90% by 2040, with "the remaining 10% balance... addressed through investments in actions to mitigate emissions beyond value chain".

Progress against the 2019 base year (page 64):

Target202320242025
100% renewable electricity by 202589%96%100%
80% reduction in Scope 1 and 253%63%69%
50% reduction in Scope 337%48%44%

Assumptions (page 62): "Notably, 99% of our emissions are from Scope 3... We evaluated our potential to reach these ambitious targets by considering changes in sales volumes, customer preferences, regulatory factors and the adoption of new technologies. No external stakeholders have been involved in the process." Progress "relies on the maturity of the industries in which we operate, advancements in product footprint measurements, and on the purchasing decisions of our customers".

E1-7(was E1-5)Energy consumption and mix
Reported

Reference: page 66

Energy is reported at Group level on an operational control basis; renewable energy covers self-generated sources, purchased Guarantee of Origin certificates and Power Purchase Agreements. "All of Atea's operations are in the following high climate-impact sectors: Wholesale of information and communication equipment (NACE G46.5), Wholesale of computers, computer peripheral equipment and software (NACE G46.5.1) and Wholesale of electronic and telecommunications equipment and parts (NACE G46.5.2)" (page 66).

Energy consumption and mix, MWh (page 66):

20242025
Fuel, natural gas163145
Fuel, other fossil12,23511,084
Purchased electricity/heat/steam/cooling, fossil3,8662,373
Total fossil16,26413,602
Share of fossil31%26%
Nuclear1610
Fuel, renewable incl. biomass1,050874
Purchased electricity/heat/steam/cooling, renewable35,53838,254
Self-generated non-fuel renewable387299
Total renewable36,97439,426
Share of renewable69%74%
Total energy consumption53,25453,038

Energy intensity on net revenue was 1.42 MWh/MNOK in 2025, down from 1.54 (page 66). Data comes from invoices and meters, with landlord allocation by square metres rented where exact consumption is unavailable; on-site solar is metered separately. Revenue used for the ratio is incorporated by reference to Note 5 (page 40).

E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissions
Reported

Reference: page 67

Emissions follow the WRI GHG Protocol for all sites under operational control; approximately 1% rests on primary data (page 69). Scope 3 covers 11 of 15 categories; 8, 10, 14 and 15 are not material "due to insignificant emissions" (page 71). "Currently none of our Scope 1 emissions are regulated under emission trading schemes", and in Scope 2 "99% of electricity consumption is covered using contractual instruments such as guarantees of origin, while the remaining 1% is generated using solar panels on site" (page 67).

tCO₂e (page 68):

2019 base20242025% 25/24
Gross Scope 13,7473,3173,028-9%
Scope 2 location-based2,9812,0691,863-10%
Scope 2 market-based7,088688316-54%
Total Scope 31,893,322993,9881,061,483+7%
Total, market-based1,904,157997,9931,064,826+7%

Largest 2025 Scope 3 categories: purchased goods and services 820,948, use of sold products 218,504, end-of-life treatment 4,901, upstream transport 4,509, business travel 4,236, capital goods 3,709, employee commuting 2,057.

Intensity fell to 28.49 tCO₂eq/MNOK market-based (2024: 28.86); Scope 3 is 99% of total emissions (page 68). Biogenic CO₂ from biofuels is reported separately at 204.5 tCO₂e and excluded from Scope 1.

E1-9(was E1-7)GHG removals and GHG mitigation projects financed through carbon credits
Reported

Reference: page 71

"Atea purchased and retired 190 tCO₂e carbon credits from the Delta Blue Carbon - 1 project in the Indus Delta, Pakistan, in 2025. All credits are third-party verified according to the Verified Carbon Standard and the Climate, Community & Biodiversity standards. No additional calculation methodologies were applied by Atea. These purchases are made as a complementary action due to customer requirements and are annually disclosed through the CDP questionnaire. They are not part of Atea's GHG emissions reduction strategy and are not included in the emissions reductions reported by Atea. For its net-zero target, Atea plans to invest in mitigation activities beyond its value chain only in the year when the net-zero target is reached, in line with SBTi guidelines. Atea does not currently plan further carbon credit cancellations beyond the reporting period" (page 71).

The project is a mangrove restoration project, with further detail on Verra's website (page 71).

No GHG removals or storage in Atea's own operations or value chain are reported, and no breakdown of credits by removal versus emission avoidance, by vintage, or by share of reduction and removal is given. The list of EU-legislation datapoints carries a page 71 reference against the E1-7 row (page 132).

E1-10(was E1-8)Internal carbon pricing
Not Material
E1-11(was E1-9)Anticipated financial effects from material physical and transition risks and potential climate-related opportunities
Omitted

E5 – Resource Use and Circular Economy

E5-1Policies related to resource use and circular economy
Reported

Reference: page 73

Three policies are disclosed. The Climate Policy "is dedicated to mitigating climate change by reducing GHG emissions and enhancing energy efficiency. It focuses on preventing waste generation and promotes the use of secondary (recycled) resources... The policy applies to both the upstream and downstream value chain" (page 73).

The Environmental Policy "emphasizes sustainable IT solutions and responsible waste management... It extends the lifecycle of IT products through reuse and refurbishment, prioritizing these actions before recycling or disposal... The policy encourages practices such as reuse, repair, refurbish, remanufacture and repurpose: treating waste as a valuable resource" (page 73).

The Responsible Minerals Policy "ensures the ethical sourcing of minerals, adhering to international due diligence frameworks... It requires suppliers to conduct due diligence and work towards the responsible sourcing of minerals" (page 74).

"These policies collectively ensure that Atea is transitioning away from virgin resources by increasing the use of secondary materials and is committed to sustainable sourcing and the use of renewable resources throughout its value chain. They apply across the entire Atea Group and cover all employees. Atea reviews and updates its policies annually as necessary. All policies are published on atea.com" (page 74).

E5-2Actions and resources related to resource use and circular economy
Reported

Reference: page 74

"In 2025, Atea focused on strengthening take-back solutions as part of our commitment to circular economy principles under the Transition Plan." Actions cover "take-back logistics, secure data sanitization, refurbishment, recycling, and reporting", reaching downstream customers and upstream refurbishers, recyclers and manufacturers across the Nordics and Baltics (page 74).

Named 2025 actions:

  • An investigation into partnerships "to enable reuse of returned devices that, until now, had always been recycled due to strict security requirements", which "will continue in 2026".
  • Integration of the 1:1 target, originally under Vision 2030, into the Transition Plan.
  • Launch of ONE for Good, "designed to strengthen circular IT by promoting device take-backs through the Goitloop service, where each returned device generates value for the ONE for Good fund supporting youth projects in local communities", supported by a roadshow "visiting 88 Atea offices across the Nordics and Baltics during 2026-2027" (pages 74-75).

Partnerships include RBA membership since 2016, the Atea Sustainability Focus initiative with "over 600 public and private sector customers" (page 75).

On funding: "actions are funded through internal budgets embedded in the business strategy and not presented as standalone investments. Developing a framework to separate and disclose these financial allocations will remain a task for upcoming years" (page 74).

E5-3Targets related to resource use and circular economy
Reported

Reference: page 76

"Atea's 1:1 circularity target aims to recover at least as many devices as are placed on the Nordic market annually. The target is intentionally defined around five high-impact customer device categories: mobile phones, laptops, monitors, tablets, and desktops" (page 76). It "applies to customer returns only", and is "absolute, long-term, outcome-oriented, and voluntary, not mandated by legislation".

It runs through 2040 in line with the net-zero commitment; "no interim milestones have been set", and it aligns with SDG 12. "Progress is tracked annually using same-year sales and asset recovery data... the metric does not rely on a fixed baseline year or baseline value, as it is recalculated each year" (page 76).

2025 performance (page 77): recovered volumes rose 12.8% and sold volumes 11.8%; "The overall 1:1 ratio remained stable at 28%".

CategoryRecoveredSold20242025
Laptops268,968831,39529%32%
Stationary computers44,520159,86736%28%
Mobile phones80,846252,14730%32%
Tablets68,134169,92548%40%
Monitors40,184378,94511%11%
Total502,6521,792,27928%28%

"Monitors remain the lowest-returned product category, consistent with 2024." 2025 is "the first reporting year, so trend analysis is limited".

E5-4Resource inflows
Reported

Reference: page 77

"Atea is a value-added IT reseller and service provider. It does not manufacture IT equipment nor subcontract manufacturing." Material inflows are operational resources, IT hardware purchased and resold, and used IT equipment collected through take-back. The most significant "by volume and environmental impact are the IT hardware products themselves, specifically user-specific devices such as laptops, desktop computers, mobile phones, tablets and monitors" (page 77).

Operational inflows (page 78): water 20,635 m³ in 2025 versus 22,530 m³ in 2024; facilities and car charging 41,081 MWh of electricity and natural gas, up from 39,969 MWh; vehicle fleet 11,958 MWh of diesel and petrol, down from 13,285 MWh.

Materials named (page 78): "plastics, steel, aluminum, glass, and critical minerals such as gold, cobalt, lithium, tantalum, tin, tungsten and neodymium" with acknowledged impacts "including deforestation, water pollution and labor rights violations". Supplier standards include REACH and RoHS compliance, preference for TCO Certified products, and the Responsible Minerals Policy.

Limitations: "Due to the scale of operations, over 1.9 million devices sold in 2025 compared with 1.7 million in 2024, and the complexity of the IT supply chain... collecting detailed data on total weight or material composition is not currently feasible." No total weight of materials, and no share of biological, secondary or reused materials, is disclosed.

E5-5Resource outflows
Reported

Reference: page 78

"Atea does not produce any products, nor does it hire anyone to manufacture them on its behalf. We are a supplier of IT infrastructure... We help our customers prolong the life of their various IT equipment, such as laptops, computers, mobile phones, and tablets, by selling spare parts, preparing equipment for reuse and selling refurbished products" (page 78). No rates of recyclable content in products and packaging are disclosed for own production.

"The majority of waste in our value chain is generated downstream, primarily by customers and end-users, especially at the end of the lifecycle when IT equipment becomes unusable, resulting in significant e-waste" (page 78).

The entity-specific disclosure Atea-1 quantifies recovered outflows (page 81): "During 2025, we recovered over 721 thousand units of IT equipment through our take-back services, a 15% increase compared to 629 thousand units in 2024. We also achieved a reuse rate of 55%" (2024: 54%). Total units recovered were 721,494, of which 393,803 repurposed and 327,691 recycled. The 2024 comparative was restated from 640,739 to 629,333 after an ERP-migration error (pages 39, 81).

Atea-2 reports avoided emissions on the IVL Swedish Environmental Research Institute methodology updated in December 2024: "the updated methodology resulted in 29,787 tCO₂e of avoided emissions from reuse and 5,458 tCO₂e from recycling, totaling 35,245 tCO₂e" (page 83).

E5-5(was E5-5-Waste)Waste
Reported

Reference: page 79

"In 2025, our operations generated 2,139 tons of waste, a slight increase from 2,110 tons in 2024. The share of hazardous waste decreased from 17% in 2024 to 9% in 2025... Recycling and reuse accounted for 78% of total waste in 2025, compared with 77% in 2024" (page 79). "All waste was treated using applicable methods: none ended up in landfill. No radioactive waste was generated by Atea."

Waste from own operations, tons (page 80):

20242025
Total generated2,1102,139
Hazardous352193
Hazardous, diverted from disposal351189
Hazardous, incineration without energy recovery04
Non-hazardous1,7591,946
Non-hazardous, recycling1,0661,157
Non-hazardous, EE waste recycling218323
Non-hazardous, diverted from disposal1,2841,480
Non-hazardous, incineration with energy recovery113118
Non-hazardous, incineration without energy recovery361348

Preparation for reuse of hazardous waste is nil. Note that the narrative states incineration had "energy recovery applied in all cases" (page 79) while the table records 352 tons incinerated without energy recovery in 2025.

Hazardous waste data is "obtained from reports from recycling partners"; estimates use the prior-year Atea Norway average (page 80). A 2024 restatement corrected a "2.6-ton difference in total waste generated" (pages 39, 80).

E5-6Anticipated financial effects from resource use and circular economy-related impacts, risks and opportunities
Omitted

S1 – Own Workforce

S1-1Policies related to own workforce
Reported

Reference: page 94

"Atea strictly prohibits discrimination based on gender, age, national origin, religion, sexual orientation, disability and other factors as stipulated in the Equality and Anti-Discrimination Act" (page 94). Four policies are described:

  • Diversity and Inclusion Policy, which "includes specific initiatives to promote equal opportunities, diversity, inclusion, and career development".
  • Anti-Discrimination and Harassment Policy, which "includes training programs, reporting mechanisms to address and prevent discrimination and harassment". "We have not identified any specific groups of employees that are at particular risk of vulnerability."
  • Human Rights Policy, which "includes mechanisms for addressing human rights impacts, such as grievance procedures and remediation processes".

Atea upholds "the Universal Declaration of Human Rights and the ILO Declaration on Fundamental Principles and Rights at Work", and states its policies "explicitly address issues such as trafficking, forced labor, child labor, and discrimination". On safety the report is candid: "While our policies may not directly address the prevention of workplace accidents, they indirectly do so through alignment with these international standards."

The policies apply "to all Atea Group entities and employees" and are on atea.com; accountability is cross-referenced to GOV-1.

S1-2Processes for engaging with own workforce and workers' representatives about impacts
Reported

Reference: page 95

Engagement runs through four named channels (page 95): annual surveys on the work environment and job satisfaction; monthly one-on-ones, as "Managers hold regular one-on-one meetings with their team members at least monthly to discuss individual progress, address concerns and set development goals"; annual development dialogues; and the Atea Workers Council (AWC), "with representatives from national trade Unions, Chief Executive Officer and Chief Human Resources Officer to discuss the economy of Atea, challenges and possibilities, significant employee matters. Those meetings are held quarterly, with additional sessions as needed to address urgent issues."

Stakeholder dialogues were also held with employees from various countries as part of the double materiality assessment.

On how engagement changes decisions: "insights from annual surveys have led to the implementation of new well-being initiatives and organizational improvements regarding communication, goal setting and support systems... Discussions in the AWC have resulted in a better understanding of the course of the company, the people strategy and a closer relationship between the Unions and the management of Atea" (page 95).

"Atea's Corporate Management is responsible for ensuring that stakeholder engagement occurs and that the insights gained inform our actions." No global framework agreement is disclosed.

S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concerns
Reported

Reference: page 95

"Atea encourages the reporting of discrimination, harassment and other forms of misconduct through multiple channels, ensuring confidentiality and protection against retaliation. Our Human Rights Policy includes measures to provide and/or enable remedy for human rights impacts. This involves clear reporting mechanisms, thorough investigations, and corrective actions" (page 95).

Two routes are described. Employees may report to their managers or HR, which "provides a way for employees to raise grievances that concern themselves, such as breaches by their employer of employment rights or their contract of employment". In parallel, "Atea also offers a confidential, anonymous, web-based whistleblower hotline provided by a third-party... All reports submitted through the hotline are managed by an external law firm to ensure impartiality and confidentiality."

On remediation: "The HR department plays a crucial role in this process by conducting thorough investigations to understand the issue, developing action plans to address it, implementing the remedies, and assessing their effectiveness by monitoring the situation and gathering feedback from the affected employees."

On awareness and trust: "Atea assesses employee awareness, trust and the effectiveness of these structures and processes through regular employee surveys", conducted by third parties. No survey score on channel awareness or trust is published.

S1-3(was S1-4)Taking action on material impacts on own workforce
Reported

Reference: page 96

Atea addresses its one material S1 impact, discrimination and/or harassment, through Group-wide policies, because "As Atea operates in seven different European countries, we face the challenge of creating solutions that are effective across diverse regions" (page 96).

Key actions performed in 2025 (page 96):

ActionHorizon
Review recruiting processes, job descriptions, job evaluations and total reward policies for gender-neutral criteria; ongoing reviews to comply with the Pay Transparency Directive by June 2027Ongoing
Webinars and training on mental health, burnout prevention and stress managementOngoing
eNPS surveys to assess employee satisfaction and loyaltyAnnually
Inclusion and diversity training for leaders and employeesOngoing
Employee survey including questions on perceived discrimination or harassmentAnnually

Effectiveness is monitored "through employee feedback, misconduct reports, and other relevant indicators" (page 97).

"No risks or opportunities were identified through the double materiality assessment related to own workforce... We have not allocated specific financial resources for each action: they are incorporated into our annual budgets. Therefore, we cannot provide the exact amount of current and future financial resources dedicated to these actions" (page 97).

S1-4(was S1-5)Targets related to own workforce
Reported

Reference: page 97

Atea discloses that it has not set targets and explains how it tracks effectiveness instead, which is the MDR-T alternative limb.

"Discrimination and harassment are complex issues that have a real negative impact on our employees. Currently, Atea has not set any measurable, time-bound and outcome-oriented targets regarding these issues. To address this, we will use our annual employee survey to measure progress through the Employee Net Promoter Score (eNPS), which indicates how likely employees are to recommend our workplace. For 2025, the recorded score is 39, representing an improvement from the 2024 baseline of 32. As this is only the second year of measurement, eNPS data continues to be collected at the Group level with the objective of maintaining or exceeding the initial 2024 benchmark. In the coming years, we will establish time-bound, outcome-oriented targets informed by these findings" (page 97).

No target value, target year or baseline year for a reduction in discrimination or harassment incidents is disclosed, and the statement does not describe whether workers or their representatives were involved in setting the eNPS objective. The related incident metrics are reported under S1-17, where two cases of discrimination or harassment were recorded in 2025 (page 107).

S1-5(was S1-6)Characteristics of the undertaking's employees
Reported

Reference: page 97

"Beginning in 2025, the metric used throughout this section has been revised from values measured at the end of the reporting period to values calculated as an average across the reporting period" (page 97); comparatives were restated only for employees per country, as restating the rest "is impracticable" (pages 39-40).

Headcount (page 98): employees averaged 8,388 in 2025 versus 8,399 in 2024; at year end the workforce "had grown to 8,460 employees compared with 8,359 in 2024". Average male 6,165 and female 2,223 (73% / 27%, against 74% / 26%); "we did not collect information about non-binary or other gender identities".

New hires were 1,163 (2024: 1,080), departures 1,173 (1,121), and turnover rose "slightly to 13.9% in 2025, compared with 13.4% in 2024".

By country, average 2025: Sweden 3,053, Norway 1,886, Denmark 1,492, Latvia 658, Lithuania 651, Finland 573, Estonia 75.

By contract type, average 2025 (page 99): permanent 8,218, temporary 124, non-guaranteed hours 55, full-time 7,943, part-time 425. "The vast majority (98%) of our employees are permanent... with only 2% being temporary."

The methodology change shifted country figures by Norway -11, Sweden -11, Denmark +69, Finland +7, Lithuania -16, Latvia +4, Estonia -2 (page 98). The IFRS full-time-equivalent figure is incorporated by reference to the Board of Directors' Report and Note 6; key figures show 8,165 FTEs at year end (page 3).

S1-6(was S1-7)Characteristics of non-employee workers
Reported

Reference: page 100

"Atea engages self-employed individuals for specific tasks or projects under contractual agreements. These contractors are not directly employed by Atea but provide essential services in various roles such as consultants, service engineers, managed services specialists and administrative and support functions" (page 100).

"During the reporting period, Atea engaged 267 non-employees, of whom 74% were male and 24% female. The increase from 190 (with 77% being male and 23% female) in 2024 should therefore be interpreted in light of the updated methodology, as well as improved reporting of non-employees, who are primarily engaged in Norway, Sweden, Denmark and Finland. This information is collected through HR and payroll systems and reported as head count figures for those who are still employed at the end of the year" (page 100).

As across S1, "the metric used in this section was revised from values measured at the end of the reporting period to values calculated as an average across the reporting period, meaning the figures are not fully comparable with those from previous years".

Non-employees are excluded from turnover, new-hire and leaver figures in S1-6 (page 101). The disclosure covers self-employed people only; no figure is given for agency workers, and the gender split as printed sums to 98%.

S1-7(was S1-8)Collective bargaining coverage and social dialogue
Reported

Reference: page 101

"We fully support employees' freedom of association and their right to be represented by a trade union for collective bargaining without interference. Across the reporting period, an average of approximately 40% of Atea's employees were covered by collective bargaining agreements and/or universally binding collective agreements. Collective bargaining is used in Denmark, Sweden and Finland. Where these agreements are not used, employment terms are similar to those in the collective bargaining agreements that exist elsewhere. The decrease from 48% in 2024 to 40% in 2025 is primarily due to changes in agreement coverage in Finland" (page 101).

"There are no collective bargaining agreements for headquarters in Norway, as well as other entities located in Norway, Lithuania, Latvia and Estonia."

The banded EEA table (page 101) places Denmark and Finland in the 20-39% collective bargaining band and Sweden in the 80-100% band; for workplace representation, Sweden, Denmark, Norway and Finland all fall in the 80-100% band.

"At the end of 2023, Atea established a works council for matters of transnational importance... The works council covers Sweden, Denmark, Norway and Finland. By the end of the reporting period, a member to represent the Baltic region, Lithuania, Latvia, and Estonia, had not yet been elected" (page 101). Social dialogue coverage was unchanged from 2024.

S1-8(was S1-9)Diversity metrics
Reported

Reference: page 101

"The definition of top management at Atea aligns with the Authority Matrix, as outlined in the Code of Conduct and includes the country leadership team. This team comprises employees who report directly to the Group or Country Managing Director. At the end of the reporting period, 55 employees were part of the country leadership teams. The decrease from 81 employees in 2024 reflects improved application of the reporting definition. The gender distribution in 2025 was 75% male and 25% female, compared with 68% male and 32% female in 2024" (page 102).

Board and Corporate Management gender diversity is cross-referenced to GOV-1, where the Board is 44% female and Corporate Management 0% female at year end (page 42).

An age-group distribution chart is presented on page 102 for the three ESRS bands. As printed, the average 2025 values are under 30: 1,352; 30-50: 4,542; over 50: 2,373, and the 2024 year-end values are 1,444, 4,644 and 2,391. Neither set sums to the corresponding total headcount reported in S1-6 (8,388 average for 2025 and 8,359 at the end of 2024), so the age bands are roughly 120 employees short in each year and should be treated with caution.

The disclosure notes the same year-end-to-average methodology change and that figures "are not directly comparable with those reported for the previous year" (page 102).

S1-9(was S1-10)Adequate wages
Reported

Reference: page 103

"All Atea employees receive wages that meet or exceed the applicable adequate wage as determined by legislation or collective bargaining agreements. During the annual salary review process, we ensure compliance with local legal requirements and align with peers and similar companies through regional benchmark analysis" (page 103).

This is a complete nil return against the disclosure requirement: all employees are stated to be paid at or above the applicable adequate wage benchmark, so there is no percentage of employees paid below it to report. The benchmark used is the statutory or collectively agreed wage in each of the seven countries of operation rather than an external living-wage benchmark.

The adequate-wage disclosure is confined to Atea's own workforce. Living wage in the value chain is a separate material impact under S2, where Atea reports that it "participates in RBAs Living Wage Task Force to gain a better understanding of the topic and the current state of the industry, as well as to collaborate on suggestions for the inclusion of living wage in the next update of RBA Code of Conduct" (page 112), and that only "10 suppliers publicly recognize the need to address living wage in supply chains, representing 27% of spend" (page 123).

Remuneration levels and the pay gap are reported separately under S1-16 (pages 106-107).

S1-10(was S1-11)Social protection
Reported

Reference: page 103

"We comply with local legislation and laws in all countries where we operate, adhering to international standards and collective agreements. We ensure all employees are protected against income loss due to significant life events such as sickness, unemployment, employment injury, parental leave and retirement, as stated in the national laws" (page 103).

This covers all five major life events listed in the disclosure requirement – sickness, unemployment from the date the employee worked for Atea, employment injury and acquired disability, parental leave, and retirement – and states that coverage is universal across the workforce, delivered through the statutory social protection systems of the seven Nordic and Baltic countries in which Atea operates rather than through company schemes.

No country-by-country breakdown is given, and no percentage of employees not covered is reported, which is consistent with a nil return: the disclosure requirement asks for the countries where employees are not covered, and Atea states that all are.

Family-related leave entitlement and uptake are reported separately under S1-15, where "100% of our employees can access family-related leave" and 12% took parental leave in 2025 (page 105).

S1-11(was S1-12)Persons with disabilities
Reported

Reference: page 103

Atea discloses the metric as deliberately not collected, and gives its reasons.

"Atea firmly believes in the equality of all individuals and is committed to ensuring equal opportunities for everyone to contribute diligently and pursue a rewarding career. To prevent potential mistreatment or discrimination and to protect privacy, Atea does not collect or disclose the number of employees with disabilities. This approach aligns with legal requirements in the Nordic and Baltic regions, where explicit consent is necessary for gathering and processing sensitive data, including disability information. These requirements are governed by national laws, such as the Non-Discrimination Act in Finland and the Equality and Anti-Discrimination Act in Norway. The General Data Protection Regulation (GDPR) mandates that employers must have a lawful basis for processing sensitive data and must obtain explicit consent from employees. By focusing on providing reasonable accommodations and preventing discrimination, Atea ensures all employees are supported and valued without compromising their privacy" (page 103).

The supporting commitment sits in S1-1: "We ensure a supportive work environment for employees with disabilities by adapting our workplace to meet individual needs" (page 94).

No percentage of employees with disabilities is therefore disclosed, and the legal-restriction exemption in ESRS S1 is invoked in substance rather than by paragraph reference.

S1-12(was S1-13)Training and skills development metrics
Reported

Reference: page 103

"In 2025, development dialogues were conducted with 82% of male employees and 80% of female employees. Using the previous methodology, participation in 2024 was 84% for male employees and 81% for female employees, with overall participation declining slightly from 84% to 82%" (page 103).

Average training hours per employee completed (page 104):

PeriodFemaleMaleTotal
2024 as originally reported212927
2024 recalculated on the new methodology222927
2025202423

"When compared with the previous year, the 2025 figures show a moderate reduction in average training hours per employee. The decrease reflects changes in workforce size and training allocation patterns... the decline in hours, while noticeable, is not considered marginally concerning, as it reflects a shift in training distribution rather than a reduction in learning opportunities" (page 104).

On measurement quality: "For training time calculations, we used internal training logs and estimated session durations, which involve certain assumptions and may not be exact... When actual time spent was not available, we estimated it by taking the length of the training video or, for full-day training sessions, assuming it to be 8 hours." Development-dialogue data comes from the HR system, with an estimate that "99% of the workforce at the end of the year participated in these dialogues" in some instances.

S1-13(was S1-14)Health and safety metrics
Reported

Reference: page 105

"We ensure our work conditions meet or exceed legal standards in every country where we operate, comply with local health and safety regulations, and cover 100% of our workforce through Atea's health and safety management system based on legal requirements. The only location where external certification is obtained... is in Atea Baltics, specifically for the Lithuania, due to legal requirements, covering 681 employees by head count at year end" (page 105).

2025 metrics (page 105): no fatalities from work-related injuries or ill health among employees or other workers at Atea's sites; 47 recordable work-related accidents, a recordable accident rate of 3.1 and 418 lost days, against 36 accidents, a rate of 2.4 and 210 lost days in 2024.

"Reported work-related incidents include falls from chairs, missed steps on stairs, bicycle accidents, and slips on ice while commuting to or from work. Reported injuries at construction sites... include improper lifting of toolboxes, entrapment in equipment and head injuries from low railings or pipes."

Two gaps are stated plainly: "Atea has not established a process for collecting or requesting information on other workers working at Atea's sites, such as value chain workers", and "Due to legal restrictions on data collection regarding ill health, Atea has not recorded any instances of work-related ill health".

S1-14(was S1-15)Work-life balance metrics
Reported

Reference: page 105

"All employees are entitled to family-related leave through national laws and/or collective bargaining agreements. This means 100% of our employees can access family-related leave, which includes parental leave (covering both maternity and paternity leave) and carers' leave" (page 105).

"During the reporting period, 12% of employees took parental leave (7% male and 5% female). While the methodological change limits year‑on‑year comparability, the data still indicates a shift in the gender distribution of parental‑leave uptake compared with the 2024 figures of 7% male and 3% female. In addition, 5% of employees took carers' leave (4% male and 1% female), which is consistent with the proportion reported for 2024, although this comparison is subject to the same methodological limitation. These figures are calculated based on the head count reported in S1-6" (pages 105-106).

The disclosure therefore covers both limbs of the requirement: entitlement coverage at 100% and actual uptake by gender. As elsewhere in S1, "the metric used throughout this section has been revised from values measured at the end of the reporting period to values calculated as an average across the reporting period. As a result, the figures presented for 2025 are not directly comparable with those reported for the previous year" (page 105). Atea reports the uptake in percentages only; no headcount of employees taking leave is given.

S1-15(was S1-16)Compensation metrics (pay gap and total compensation)
Reported

Reference: page 106

"Annual total compensation includes fixed compensation (base salary, fringe benefits), variable compensation (performance-based cash bonus, share-based compensation), and pension costs" (page 106).

"In 2025, the total compensation ratio (CEO vs. employee average) is 21.34, and the ratio of change in total compensation is 2.44. Compared to the previous reporting period (2024), the total compensation ratio was 21.76, and the ratio of change in total compensation was -1.73." "The ratio of change in total CEO compensation is lower than that of regular employees because a significant share of executive remuneration is variable pay."

The unadjusted gender pay gap is disclosed per legal entity rather than as a Group figure, in a 2024/2025 bar chart covering Atea Norway, Atea Sweden, Atea Denmark, Atea Finland, Atea Logistics, Atea Global Services, Atea Lithuania, Atea Latvia, Atea Estonia and AppXite (page 106). Values range from negative to above 30%, and two entities show a gap in favour of women. A prior-period error is restated: "The originally reported value of 9.4% has been corrected to 8.0%" for Atea Sweden (pages 39, 106).

Atea cautions that "It is difficult to assess the pay gap based on these figures alone, as they do not account for differences in management level, competencies or responsibilities. To address this, we are implementing a comprehensive job architecture across all countries and preparing external salary benchmarks" (page 107).

S1-16(was S1-17)Incidents, complaints and severe human rights impacts
Reported

Reference: page 107

"In 2025, a total of 21 complaints were reported to the whistleblower hotline, which is managed by an external law firm to ensure impartiality and confidentiality. Throughout the year, all cases received were investigated and appropriately handled within the Atea Group, with none remaining open at the end of the year. No fines, penalties or compensations were paid by Atea in 2025 due to cases of discrimination or harassment" (page 107).

"Among those 21 reports, some reports concerned the same issue. Excluding duplicate reports relating to the same or similar circumstances, there were 16 cases. Out of these, nine were HR matters, including two cases of discrimination or harassment and seven cases pertaining to issues of behavioral conduct, management style, privacy and social media activities."

"For comparison, in 2024 a total of 20 complaints were reported. Excluding reports concerning the same or similar circumstances, there were 16 cases during that period, of which 14 were HR matters, including three cases of discrimination or harassment and nine cases pertaining to issues of behavioral conduct, the use of workplace tools and privacy and social media activities."

No severe human rights incidents involving Atea's own workforce are reported, and no fines, penalties or compensation for severe human rights impacts are disclosed for own workforce; value chain human rights incidents are reported separately in S2-4 (pages 112-113).

S2 – Workers in the Value Chain

S2-1Policies related to value chain workers
Reported

Reference: page 109

"Atea's commitment to addressing negative impacts on value chain workers is anchored in three core policies: the Supplier Code of Conduct, the Human Rights Policy and the Responsible Minerals Policy" (page 109).

The Supplier Code of Conduct "sets clear expectations for Atea's core-business suppliers, their contractors, sub-suppliers, and other business associates... Compliance is monitored through periodic evaluations."

The Human Rights Policy "applies to our own operations and sets clear expectations for direct business partners to uphold human rights across their workforce and supply chains", aligned with the UDHR, the ILO Declaration, the OECD Guidelines, the UNGPs and "the UN Convention against Transnational Organized Crime and its protocol on preventing human trafficking". It "emphasizes the elimination of forced and child labor, the right to collective bargaining and non-discrimination in employment".

The Responsible Minerals Policy is "Aligned with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas", sets "technical requirements for mineral traceability", and is applied to "tin, tantalum, tungsten and gold (3TGs)" (page 110).

In countries that have ratified ILO Convention No. 169, including Norway and Denmark, "we are reviewing how our policies can better reflect national laws and international standards, including those related to indigenous peoples".

S2-2Processes for engaging with value chain workers about impacts
Reported

Reference: page 110

Atea states plainly that direct engagement is not happening, and why. "Engaging directly with value chain workers across all segments remains a significant challenge in Atea's sector, particularly in raw material sourcing. Due to the complexity and sensitivity of these interactions, direct engagement is currently not feasible. Direct engagement by each company could lead to a fragmented and overwhelming experience for workers" (page 110).

"To address this, we rely on credible proxies, such as interviews and dialogue with international organizations and NGOs, and publicly available information from trusted sources and media coverage... Through our supplier assessments we also assess how our suppliers engage with value chain workers by examining their approaches to worker participation, grievance mechanisms, and freedom of association... These efforts are embedded in our due diligence cycle and conducted regularly, with a focus on high-risk suppliers."

"As members of the Responsible Business Alliance (RBA), Atea also participates in the Responsible Minerals Initiative and the Responsible Labor Initiative."

Corporate Management oversees engagement, and "we are exploring structured approaches to enhance worker representation and feedback channels". No worker representative or trade union is named as a counterpart.

S2-2(was S2-3)Processes to remediate negative impacts and channels for value chain workers to raise concerns
Reported

Reference: page 111

"Atea's management systems and due diligence processes are implemented to identify, prevent, mitigate and account for any adverse human rights impacts caused or contributed to by our activities, or directly linked to us via business relationships. In the upcoming years, this process will be revised to correctly identify and contribute to remedy where we have directly caused or contributed to negative impacts on value chain workers" (page 111).

"We offer a confidential, anonymous, web-based whistleblower hotline provided by a third-party. All reports submitted through the hotline are managed by an external law firm to ensure impartiality and confidentiality and to protect against retaliation. Whilst the hotline is available to anyone for submission, we have not received any reports related to or submitted by workers in the value chain. As we are structurally distant from many at-risk value chain workers, we have not assessed whether they are aware of or trust our structures or processes" (page 111).

Atea places the primary grievance duty on suppliers: "In alignment with the OECD Due Diligence Guidance, we therefore expect our suppliers to establish and maintain their own grievance mechanisms and ensure they are accessible to value chain workers", and assesses "whether our prioritized suppliers have grievance mechanisms in place for their supply chain employees as part of our supplier assessment program".

S2-3(was S2-4)Taking action on material impacts on value chain workers
Reported

Reference: page 111

Action runs through the Supplier Assessment Program, a risk-based programme "aligned with OECD and UNGP expectations" covering "forced and child labor, responsible minerals sourcing, working conditions and the existence of grievance mechanisms", with corrective action plans and follow-up where heightened risks are found (pages 111-112). In 2025 Atea hosted the Atea Sustainability Forum on the theme "Focus on People" and joined the RBA Living Wage Task Force, and concedes that "While our efforts have primarily focused on prevention, we are expanding our approach to include mitigation and access to remedy" (page 112).

Allegation management (pages 112-113): "In 2025, Atea closely investigated four new allegations", and continued work on two severe human rights cases from 2024. In one, suppliers and the RBA confirmed "they have provided remediation for workers affected by recruitment fees" plus "unpaid wages and other related expenses", so "we consider this case closed". The second concerns mineral sourcing amid "escalations in parts of the Democratic Republic of the Congo, where armed groups have taken control of mining regions and trade routes", and remains ongoing. One allegation "resulted in a temporary and precautionary limitation on sales of certain products. However, no allegations have yet led to the termination or suspension of business relationships with suppliers." Three cases were closed and three remained open.

S2-4(was S2-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Reference: page 113

Atea discloses that it has set no targets and describes the tracking used instead, the MDR-T alternative limb.

"Atea has not yet developed any targets concerning workers in the value chain. We focus on assessing our suppliers, monitoring and measuring more than 50 criteria related to workers in the value chain related to our suppliers' governance system, policies regarding ESG and value chain as well as transparency. We also engage our suppliers in dialogue to gain additional insights into their efforts and potential corrective actions to address any gaps. It helps us track the progress on our actions to minimize our negative impact on value chain workers" (page 113).

"In the coming years, we plan to develop measurable, outcome-oriented targets as part of our implementation of the CSDDD... In parallel, the EU Forced Labour Regulation, which will apply from December 2027, will prohibit products made with forced labor from entering or being exported from the EU market" (page 113).

The supplier-assessment outputs serving in place of targets are quantified under G1-2: 139 suppliers assessed covering 87% of direct spend, 88 with a Supplier Code of Conduct, and 10 publicly recognising living wage in supply chains (27% of spend) (page 123).

S4 – Consumers and End-users

S4-1Policies related to consumers and end-users
Reported

Reference: page 116

"Atea has adopted four policies related to information security, data protection and data privacy that concern employees, customers, partners, suppliers as well as consumers and end-users. These policies cover our material impact on consumers and end-users, specified in SBM-3. Their scope applies to the entire Atea Group and all employees. The policies are supported by several processes and procedure documents, all of which are part of our Information Security Management System. This management system is certified according to the standard ISO 27001" (page 116).

  • Data Privacy Policy, to "explain and clarify how we treat the personal data of visitors, customers, and end-users in accordance with GDPR", limiting use "to necessary purposes" and describing "a user's rights to access, correct and erase their data".
  • Data Protection Policy, to "establish the standard for protecting and processing personal data within Atea and its business units", with mandatory employee training.
  • Information Security Policy, which "defines security strategies, management of security, continuous improvement and prevention of incidents".
  • Information Security Risk Management Policy, which "provides a framework for identifying and mitigating security risks".

"No cases of non-respect of these standards involving consumers and/or end-users have been reported in our downstream value chain" (page 116).

S4-2Processes for engaging with consumers and end-users about impacts
Reported

Reference: page 116

Atea engages through intermediaries rather than directly. "Atea collaborates with customers, vendors and suppliers, viewing them as key representatives of consumers and end-users, rather than engaging directly with these groups" (page 116).

"Dialogue with customers, vendors and suppliers is part of our double materiality assessment. We maintain conversations with customers and hold annual discussions with our vendors. Additionally, we engage with customers and vendors when signing data processing agreements (DPAs). The purpose of these DPAs is to ensure the secure, correct and legal processing of personal data, to comply with applicable legal requirements, and to ensure adequate protection of the personal data processed within the scope of the DPA" (page 117).

"Atea's Corporate Management is responsible for ensuring stakeholder engagement occurs and that the insights gained inform our actions" (page 117).

The position is consistent with SBM-3: "Even if Atea does not sell products and services directly to consumers and end-users, they are part of our value chain", and "We haven't identified any particularly vulnerable consumers or end-users who might be at greater risk of harm" (page 115). No direct engagement with consumers or end-users is disclosed.

S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concerns
Reported

Reference: page 117

"Atea has channels for consumers and end-users to raise concerns or act on their rights according to GDPR, including accessing, correcting and erasing personal data. We provide email addresses to our Data Protection Officers (DPOs), who are appointed for each business unit... Those email addresses can be found at atea.com/information-security/" (page 117). Anonymous complaints may go through the Whistleblower Hotline, and "complaints regarding the processing of personal data can be submitted to national supervisory authorities".

Atea states the limit of its assurance plainly: "Atea does not assess whether consumers and end-users are aware of or trust these channels" (page 117).

Remedy after a breach (page 117): "If a data breach involves personal information and results in a risk to the rights and freedoms of individuals, Atea must notify the national data protection authorities within 72 hours of becoming aware of the breach... Individuals whose personal information has been breached must also be notified if the breach is likely to result in a high risk to their rights and freedoms." "The Group Privacy Officer, together with the Chief Information Security Officer, evaluates the risk assessment and determines if the breach needs to be reported".

"Atea is subject to possible regulatory penalties and fines in the event of a data breach", and "The effectiveness of our processes and systems is tested annually".

S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actions
Reported

Reference: page 117

"Atea has measures and actions in place to prevent data breaches, as well as to mitigate and remediate any negative impacts on consumers and end-users if a breach involves personal data. These actions were determined through a comprehensive risk assessment process, ensuring alignment with legislative requirements such as GDPR and best practices outlined in ISO 27001" (pages 117-118).

Key actions performed in 2025 (page 118):

ActionHorizon
Monthly information security and GDPR training for employeesOngoing
Basic GDPR training for new employeesOngoing
ISO 27001 audits and re-certification of business units and Atea ASA every third year, with annual surveillance auditsEvery three years
Annual internal GDPR audit on Atea GroupAnnually
Preparations for NIS2 implementationShort-term

Supporting measures: "Critical services exposed on the internet are penetration tested annually by external party. These services are also vulnerability scanned internally every month", plus internal phishing campaigns. For NIS2, "Atea has established a dedicated project team".

"Atea has not allocated specific resources for each action: they are incorporated into our annual budgets. Therefore, we cannot provide the exact amount of current and future financial resources dedicated to these actions" (page 118).

S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Reference: page 118

Atea discloses that it has set no targets, gives its reasoning, and reports indicators in their place.

"Our primary goal is to implement all necessary processes and procedures to prevent sanctioned breaches... Atea does not have measurable, outcome-oriented, time-bound targets. Instead, we have overarching ambitions and objectives related to personal data processing and information security that align with our business strategy. Setting specific targets for data protection or breach reporting can be misleading: it may imply that achieving these targets is more important than the overall security and integrity of our systems. Such targets might also create a false sense of security" (pages 118-119).

Eight objectives are listed, including compliance with applicable laws, governing data processing agreements, "Enhancing employee security behavior and driving behavior maturity through awareness training", and maintaining ISO 27001 certification; each in-scope business unit "has established, maintained and updated measurable local sub-objectives" (page 119).

Outcome in 2025 (page 119): "Atea recorded zero sanctioned complaints or supervisory authority-notified breaches related to customer privacy, data leaks, or the theft/loss of consumers and end-users' personal data... These outcomes are consistent with the previous year." The phishing campaign success rate fell below 5% and the organizational risk level stood at 95% for low risk.

G1 – Business Conduct

G1-1Business conduct policies and corporate culture
Reported

Reference: page 121

"Atea has adopted three policies concerning business conduct in our own operations - the Code of Conduct, Business Ethics at Atea and the Whistleblower Policy. These policies as well as the Supplier Code of Conduct cover the identified impacts and opportunities in our double materiality assessment" (page 121).

The Code of Conduct "sets the principles and guidelines for ethical business practices and compliance with anti-corruption laws. It applies to all employees in the Group as well as contracted consultants... Corruption and bribery can take the form of both direct payments and indirect benefits, with the latter including activities such as sponsoring favored organizations, donating to political groups, as well as excessive hospitality, travel and entertainment expenses." "Every employee must review, sign, and adhere to the Code." Atea states openly that "While Atea's Code of Conduct currently aligns with several key aspects of the United Nations Convention against Corruption (UNCAC), we recognize there are areas for improvement".

The Business Ethics Policy covers gifts, entertainment, travel, events and sponsorships, and "is supported by an integrated management system that adheres to the ISO 37001 anti-bribery standard, is third-party certified".

The Whistleblower Policy "aligns with the EU Whistleblowing Directive". "We evaluate our corporate culture through annual employee survey".

G1-2Management of relationships with suppliers
Reported

Reference: page 122

"Our Supplier Code of Conduct is based on the Global Compact's Ten Principles, the OECD Due Diligence Guidance for Responsible Business Conduct, the UN Guiding Principles on Business and Human Rights, as well as the Responsible Business Alliance's (RBA) Code of Conduct", and requires suppliers to "Implement a zero-tolerance policy to prohibit bribery, corruption, extortion and embezzlement" (page 122). Policies are reviewed annually and the Board "is kept informed of any updates".

The Supplier Assessment Program consolidates results "across more than 50 criteria". A new quarterly Partner Sustainability Forum was created in 2025, and "five new criteria were added in 2025... three of which relate to living wage" (page 123).

2025 results (page 123): assessments "covered a total of 139 suppliers, representing 87% of our direct spend on hardware and software" (2024: 98 suppliers, also 87%). Of those assessed, 66 hardware suppliers have responsible minerals policies (78% of spend, from 83%), 88 have a Supplier Code of Conduct (82%, from 86%), 10 "publicly recognize the need to address living wage in supply chains, representing 27% of spend", and 53 have SBTi-validated near-term targets (71% of spend).

"Atea does not conduct audits in suppliers' supply chain facilities", relying on the RBA Validated Audit Program, and "did not nominate any suppliers for a VAP assessment in 2025" (page 124). Payment practices are not addressed.

G1-2(was G1-3)Prevention and detection of corruption and bribery
Reported

Reference: page 124

Prevention (page 124). Employees needing guidance "can contact their direct manager or their Human Resources manager", and may escalate to "Atea's Compliance officers in each national organization, as well as the Chief Compliance Officer", whose role "is to counsel employees on matters related to the Code of Conduct, relevant laws, and business ethics". "Atea also provides The Openness test, which helps our employees evaluate if an action (e.g., a dinner, trip or event) would withstand public scrutiny."

Investigation (pages 124-125). Whistleblower reports go to an external law firm: "Feedback on the investigation's progress is provided within three months, if possible." Results go to the Chief Compliance Officer then the Compliance Committee, which "decides on appropriate actions, such as a written warning, termination of employment contract or reporting the matter to the police". The Chief Compliance Officer reports case statistics quarterly to the Compliance Committee and the Audit Committee.

Training (page 125). "In 2025, 7,303 employees were enrolled in mandatory training... The completion rate for this training was 99.7%" (2024: 7,474 enrolled, 99.8%). "The members of the Board did not conduct this training in 2025, but we are considering including them as well." The functions most at risk are "front-line employees and those handling public sector tenders".

G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conduct
Reported

Targets related to business conduct

Back-filled from the business conduct chapter, where targets fall under the MDR-T/GDR-T disclosures rather than a numbered disclosure requirement. G1-3 became a standalone DR only in the 2025/2026 ESRS; Atea's statement is prepared under the 2023 ESRS, whose G1 ran G1-1 to G1-6 without a targets DR.

Atea discloses no measurable, outcome-oriented, time-bound business conduct target. No target value, target year for corruption, bribery, training or supplier conduct appears in the G1 chapter (pages 120-125).

Consistent with the other MDR-T limb, effectiveness is tracked in the absence of targets:

  • "The Compliance Committee is also responsible for monitoring key performance indicators. For example: training completion ratio, number of incidents investigated and number of whistleblower cases" (page 125).
  • The tracked 2025 outcome: 7,303 employees enrolled in mandatory annual Code of Conduct training with a 99.7% completion rate (2024: 7,474 enrolled, 99.8%) (page 125).
  • Quarterly statistics and anonymised case descriptions go to the Compliance Committee and the Audit Committee (pages 124-125).
  • The management system "adheres to the ISO 37001 anti-bribery standard, is third-party certified" (page 121).

The one forward commitment is qualitative: Atea is "committed to enhancing our policies to achieve full alignment" with the UN Convention against Corruption "in the near future" (page 121). No date is attached.

G1-4Incidents of corruption or bribery
Reported

Reference: page 125

"A total of 21 concerns were reported to Atea whistleblower channel in 2025. Excluding reports concerning the same or similar circumstances, there are in total 16 reports. Seven out of 16 reported concerns were classified as actual whistleblowing matters, while the remaining were categorized as human resources matters related to own workforce. Similarly, in 2024 a total of 20 concerns were reported... out of which four were classified as actual whistleblowing matters" (page 125).

"In both 2025 and 2024, none of the reported cases were related to corruption, bribery, or human rights violations. In both years, there were also no incidents involving dismissal or disciplinary action of own workers for corruption- or bribery-related misconduct, and no legal cases concerning corruption or bribery. Throughout the year, all whistleblower reports received were investigated and appropriately handled within Atea and none remained open at the end of the year" (page 125).

Incident metrics, 2025 (page 125): total submitted whistleblower reports 21; reported whistleblower cases 7; confirmed incidents of corruption or bribery 0; incidents in which own workers were dismissed or disciplined 0; legal cases regarding corruption and bribery 0. No fines for violation of anti-corruption or anti-bribery laws are reported.

G1-5Political influence and lobbying activities
Not Material
G1-6Payment practices
Not Material