Whistleblower protection and internal reporting
Setting up the channel is quick. What follows is the demanding part: confidentiality across the whole handling, deadlines, and evidence that a detriment did not follow from the report.
Reports about security holes, about how data is handled or about breaches inside a company often reach management only once they are already somewhere else. The German Whistleblower Protection Act reverses the order, so that reporting internally is protected, and for that there has to be a route that works.
What the reporting channel has to deliver
- ReachabilityOrally and in text form, and on request in a personal meeting. A mailbox alone will not do.
- ConfidentialityThe identity of the reporting person may only become known to a tightly limited circle, and that holds across the entire handling.
- IndependenceThe person entrusted with the task must be able to perform it independently. Conflicts with other roles have to be excluded.
- DocumentationReports and steps taken must be documented, and deleted once the matter is closed. Both are duties, not options.
The deadlines
7 days
Confirm receipt
To the reporting person, where contact is possible at all.
then
Check the substance
Ask questions, establish the facts, initiate follow-up.
3 months
Report back
On follow-up planned and taken, as far as the investigation allows.
Reprisals and the burden of proof
What is prohibited
- Dismissal, warning or transfer because of a report
- Promotion or training withheld
- Damage to reputation and exclusion
- Attempts and threats as well
Why that weighs heavily
- If the reporting person suffers a detriment after a report, it is presumed to follow from it
- The employer has to prove the opposite
- That only succeeds with documentation created before the report
- Personnel decisions should therefore carry reasons that stand on their own
How we help
We set the channel up or take it on as an external body, draft the procedural rules and put data protection and confidentiality into a relationship that holds when it matters. Where reports come in, we support the investigation.
Set up or outsource the channel?
We take on the role or build it with you.
Discuss the channelFrequently asked questions
From when do we need an internal reporting channel?
The duty follows headcount and regularly applies from fifty staff. Independently of that, there are fields where it applies regardless of size. Smaller units may join forces or outsource the task, while responsibility stays with them.
Do we have to accept anonymous reports?
The duty to design the channel for anonymity is not stated as firmly as the other requirements, but anonymous reports that do arrive should be handled. In practice there is much to be said for allowing anonymity: refusing it pushes reports outside, and an external report can no longer be resolved internally.
How does this sit with data protection?
A report contains personal data of both the reporting person and the person concerned. Both have rights that can conflict: access on one side, confidentiality on the other. The precedence of confidentiality has to be built into the procedure, otherwise an access request discloses the identity.