Skip to main content Required by EU law for organizations with 50+ employees

Do you need ISO 27001 for a whistleblowing tool? #

Short answer: no. EU Directive 2019/1937 does not require ISO/IEC 27001, and neither does any national transposition of it. ISO 27001 is a voluntary information-security management standard. It is useful evidence that a vendor takes security seriously, but it is not a legal prerequisite for operating a compliant internal reporting channel.

This matters because several procurement checklists treat “ISO 27001 certified” as a hard gate. For a whistleblowing channel, that gate filters on the wrong thing. What the Directive actually requires is confidentiality and security of processing — and those can be met, and verified, independently of any certificate.

What does the Directive actually require? #

The Directive’s security obligations are specific and functional:

None of these name a certification. They describe outcomes. A tool either protects reporter identity and secures the data, or it does not.

What is ISO 27001, and when does it help? #

ISO 27001 certifies that an organization runs an information-security management system (ISMS) against a defined set of controls, audited by an accredited body. It is genuinely meaningful — but two distinctions decide whether a given certificate is relevant to you:

ISO 27001 is most worth insisting on when you are a large or heavily regulated organization whose own ISMS requires certified suppliers, or when your risk assessment specifically calls for it. For most SMEs meeting a Directive obligation, it is a useful signal — not a legal requirement.

How to evaluate whistleblowing-tool security without relying on a certificate #

Ask for evidence of the outcomes the Directive and GDPR require:

A vendor that answers these clearly gives you more assurance than a certificate logo with an unread scope statement.

How EthicsPortal approaches this #

EthicsPortal is direct about its certification posture. The hosting infrastructure (Hetzner, Nuremberg, Germany) holds ISO/IEC 27001 certification; the EthicsPortal application is not separately ISO 27001 certified, and we say so rather than implying otherwise. Our ISO/IEC 27001:2022 Annex A control map is a published, control-by-control self-assessment against the same 93 controls an external auditor would evaluate.

What the platform does provide against the Directive’s actual requirements: EU hosting, encryption of sensitive fields at rest plus TLS in transit, fully anonymous reporting with no required reporter account, no storage of reporter IP addresses, automatic stripping of metadata from uploads, an append-only audit log, and a published Data Processing Agreement and sub-processor list. Report content is never sent to any AI or LLM provider.

If your organization’s policy genuinely requires a certified application, a vendor with an in-scope application certificate is the right call. If your requirement is a secure, confidential, Directive-compliant channel, evaluate the outcomes above — and treat ISO 27001 as a signal, not a substitute for them.


Need a compliant reporting channel? EthicsPortal is €41.67/month billed annually with no per-employee pricing, EU-hosted, and anonymous by default. Deploy your reporting channel .

Last updated: