Do you need ISO 27001 for a whistleblowing tool? #
Short answer: no. EU Directive 2019/1937 does not require ISO/IEC 27001, and neither does any national transposition of it. ISO 27001 is a voluntary information-security management standard. It is useful evidence that a vendor takes security seriously, but it is not a legal prerequisite for operating a compliant internal reporting channel.
This matters because several procurement checklists treat “ISO 27001 certified” as a hard gate. For a whistleblowing channel, that gate filters on the wrong thing. What the Directive actually requires is confidentiality and security of processing — and those can be met, and verified, independently of any certificate.
What does the Directive actually require? #
The Directive’s security obligations are specific and functional:
- Confidentiality of the reporter’s identity (Article 16). The identity of the reporting person must not be disclosed to anyone beyond authorized staff, without consent.
- Secure channels (Article 9). Internal reporting channels must be designed, established, and operated in a secure manner that protects the confidentiality of the reporter and any third party mentioned.
- Security of processing under the GDPR (Article 32). Because reports contain personal data, the channel inherits the GDPR’s requirement for technical and organizational measures appropriate to the risk — encryption, access control, confidentiality, integrity, and resilience.
None of these name a certification. They describe outcomes. A tool either protects reporter identity and secures the data, or it does not.
What is ISO 27001, and when does it help? #
ISO 27001 certifies that an organization runs an information-security management system (ISMS) against a defined set of controls, audited by an accredited body. It is genuinely meaningful — but two distinctions decide whether a given certificate is relevant to you:
- Scope. A certificate covers a defined boundary. A vendor whose hosting infrastructure is ISO 27001 certified is not the same as a vendor whose application and operations are certified. Always read the scope statement.
- Certified vs aligned. “Certified” means an accredited body audited and issued the certificate. “Aligned with” or “built to” means the vendor self-assesses against the controls. Both can be reasonable; they are not the same claim.
ISO 27001 is most worth insisting on when you are a large or heavily regulated organization whose own ISMS requires certified suppliers, or when your risk assessment specifically calls for it. For most SMEs meeting a Directive obligation, it is a useful signal — not a legal requirement.
How to evaluate whistleblowing-tool security without relying on a certificate #
Ask for evidence of the outcomes the Directive and GDPR require:
- Where is the data hosted? A named EU data center keeps processing inside the EU and avoids third-country transfer questions under GDPR Chapter V.
- Is report content encrypted? Encryption in transit (TLS) is table stakes; ask whether sensitive fields are also encrypted at rest.
- Can reporters stay anonymous? Check that no reporter account or identifying field is mandatory, and that follow-up works without revealing identity.
- Are reporter IP addresses stored? They should not be. Ask how the tool prevents re-identification via metadata and uploaded files.
- Is there a tamper-resistant audit trail? An append-only log of who accessed what, when, is both a security control and an accountability record.
- Is there a Data Processing Agreement, and who are the sub-processors? A published DPA and sub-processor list let you verify the data chain — including whether any AI provider is in it.
A vendor that answers these clearly gives you more assurance than a certificate logo with an unread scope statement.
How EthicsPortal approaches this #
EthicsPortal is direct about its certification posture. The hosting infrastructure (Hetzner, Nuremberg, Germany) holds ISO/IEC 27001 certification; the EthicsPortal application is not separately ISO 27001 certified, and we say so rather than implying otherwise. Our ISO/IEC 27001:2022 Annex A control map is a published, control-by-control self-assessment against the same 93 controls an external auditor would evaluate.
What the platform does provide against the Directive’s actual requirements: EU hosting, encryption of sensitive fields at rest plus TLS in transit, fully anonymous reporting with no required reporter account, no storage of reporter IP addresses, automatic stripping of metadata from uploads, an append-only audit log, and a published Data Processing Agreement and sub-processor list. Report content is never sent to any AI or LLM provider.
If your organization’s policy genuinely requires a certified application, a vendor with an in-scope application certificate is the right call. If your requirement is a secure, confidential, Directive-compliant channel, evaluate the outcomes above — and treat ISO 27001 as a signal, not a substitute for them.
Need a compliant reporting channel? EthicsPortal is €41.67/month billed annually with no per-employee pricing, EU-hosted, and anonymous by default. Deploy your reporting channel .
Last updated: