<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Blog — EthicsPortal</title><link>https://ethicsportal.eu/blog/</link><description>EthicsPortal is a secure, anonymous whistleblower reporting platform that helps organizations comply with EU Directive 2019/1937.</description><language>en</language><lastBuildDate>Mon, 25 May 2026 01:23:15 +0000</lastBuildDate><atom:link href="https://ethicsportal.eu/blog/index.xml" rel="self" type="application/rss+xml"/><image><url>https://ethicsportal.eu/images/logo.svg</url><title>EthicsPortal</title><link>https://ethicsportal.eu/</link></image><item><title>Whistleblower reports do not belong inside an LLM</title><link>https://ethicsportal.eu/blog/whistleblower-reports-do-not-belong-inside-an-llm/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblower-reports-do-not-belong-inside-an-llm/</guid><description>Seven whistleblower platforms sold into the EU now process report content through large language models. Six of them won&amp;#39;t tell you whose. EthicsPortal does neither. Screenshots and sources inside.</description><content:encoded>&amp;lt;h1 id=&amp;#34;whistleblower-reports-do-not-belong-inside-an-llm&amp;#34;&amp;gt;
Whistleblower reports do not belong inside an LLM
&amp;lt;a href=&amp;#34;#whistleblower-reports-do-not-belong-inside-an-llm&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Seven whistleblower platforms sold into the EU run report content through large language models. They summarise reports, transcribe voice intake, run AI agents that talk to whistleblowers, and produce &amp;amp;ldquo;insights&amp;amp;rdquo; across case archives. Only one of the seven names which AI provider does the work.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal does none of this. Our &amp;lt;a href=&amp;#34;/dpa/#610-no-ai-or-llm-processing-of-report-content&amp;#34;&amp;gt;DPA §6.10&amp;lt;/a&amp;gt;
and our &amp;lt;a href=&amp;#34;/subprocessors/&amp;#34;&amp;gt;sub-processor list&amp;lt;/a&amp;gt;
say so.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Every claim below is quoted from the vendor&amp;amp;rsquo;s own live page or public DPA, captured 24 May 2026. Translation and categorisation can run on-prem, so we did not include vendors whose only AI claim is &amp;amp;ldquo;AI translation&amp;amp;rdquo; or &amp;amp;ldquo;AI categorisation&amp;amp;rdquo;. The seven below claim more than that.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;navex--ai-supported-case-briefs-and-suggested-rewrites&amp;#34;&amp;gt;
NAVEX — &amp;amp;ldquo;AI-supported case briefs and suggested rewrites&amp;amp;rdquo;
&amp;lt;a href=&amp;#34;#navex--ai-supported-case-briefs-and-suggested-rewrites&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;NAVEX is the largest enterprise whistleblowing vendor in the world. EthicsPoint sits inside most Fortune 500 compliance programs.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;From the &amp;lt;a href=&amp;#34;https://www.navex.com/en-us/platform/whistleblowing-software-solutions/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;whistleblowing platform page&amp;lt;/a&amp;gt;
:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Summarize complex cases with &amp;lt;strong&amp;gt;AI-supported case briefs and suggested rewrites&amp;lt;/strong&amp;gt;&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Spot recurring themes earlier through higher-level insights and analytics&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/navex-ai-case-briefs-rewrites.png&amp;#34; alt=&amp;#34;NAVEX whistleblowing platform — “Summarize complex cases with AI-supported case briefs and suggested rewrites”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;To suggest a rewrite, the model has to read the original report. NAVEX does not name the model on any public page.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;eqs-integrity-line--ai-powered-summaries-and-transcription-in-80-languages&amp;#34;&amp;gt;
EQS Integrity Line — &amp;amp;ldquo;AI-powered summaries and transcription&amp;amp;rdquo; in 80+ languages
&amp;lt;a href=&amp;#34;#eqs-integrity-line--ai-powered-summaries-and-transcription-in-80-languages&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EQS Group (Munich-listed) runs the largest whistleblower platform in continental Europe. From their &amp;lt;a href=&amp;#34;https://www.eqs.com/en-us/platform-compliance-ethics/integrity-line-whistleblower-software/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Integrity Line page&amp;lt;/a&amp;gt;
:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;AI that works for you.&amp;lt;/strong&amp;gt; Handle reports in over 80 languages with AI-powered summaries and transcription, and transform voice recordings into searchable texts. Get helpful insights from past cases for faster resolution including suggestions for case categories and priorities.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/eqs-integrity-line-ai-summaries-transcription.png&amp;#34; alt=&amp;#34;EQS Integrity Line — “AI that works for you”: AI-powered summaries, transcription of voice recordings, case-category suggestions&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Summaries, voice transcription, and cross-case insights. 4,000+ organisations on the platform. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;speakup--sienna-ai-a-whole-ai-product-line&amp;#34;&amp;gt;
SpeakUp — &amp;amp;ldquo;Sienna AI&amp;amp;rdquo;: a whole AI product line
&amp;lt;a href=&amp;#34;#speakup--sienna-ai-a-whole-ai-product-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;SpeakUp&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://www.speakup.com/sienna-ai&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Sienna AI&amp;lt;/a&amp;gt;
is not a feature, it is a sub-brand:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Sienna AI. Compliance reimagined.&amp;lt;/strong&amp;gt; The intelligence layer behind the future of compliance and ethics.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/speakup-sienna-ai-compliance-reimagined.png&amp;#34; alt=&amp;#34;SpeakUp Sienna AI hero — “Compliance reimagined. The intelligence layer behind the future of compliance and ethics.”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The page markets an &amp;lt;strong&amp;gt;AI Voice Agent&amp;lt;/strong&amp;gt; that has reporters &amp;amp;ldquo;speak freely and safely&amp;amp;rdquo; through a &amp;amp;ldquo;guided, conversational intake&amp;amp;rdquo;, &amp;lt;strong&amp;gt;Sienna Insights&amp;lt;/strong&amp;gt; (&amp;amp;ldquo;AI does the digging. You get the insight.&amp;amp;rdquo;), and AI translation, transcription, and routing of submissions into the case management system. Reporters in SpeakUp&amp;amp;rsquo;s flow are talking to a model. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;whispli--use-ai-to-capture-clearer-more-complete-hotline-reports&amp;#34;&amp;gt;
Whispli — &amp;amp;ldquo;Use AI to capture clearer, more complete hotline reports&amp;amp;rdquo;
&amp;lt;a href=&amp;#34;#whispli--use-ai-to-capture-clearer-more-complete-hotline-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;From Whispli&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://www.whispli.com/whistleblowing-hotline&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Voice AI hotline page&amp;lt;/a&amp;gt;
(the page title is literally &amp;amp;ldquo;AI Whistleblowing Hotline&amp;amp;rdquo;):&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Use AI to capture clearer, more complete hotline reports.&amp;lt;/strong&amp;gt; Manage global whistleblowing hotline reporting with an AI-powered voice intake agent that captures, structures and routes cases securely across jurisdictions.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/whispli-voice-ai-hotline.png&amp;#34; alt=&amp;#34;Whispli hotline hero — “Use AI to capture clearer, more complete hotline reports” with a Voice transcribed / Case created flow&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The flow diagram on the page shows it plainly: Incoming Voice Report → Voice transcribed → Case created. The most exposed reporter, the one who picked up a phone, is talking to an AI agent. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;faceup--voice-based-ai-conducts-natural-conversations-with-whistleblowers&amp;#34;&amp;gt;
FaceUp — &amp;amp;ldquo;Voice-based AI conducts natural conversations&amp;amp;rdquo; with whistleblowers
&amp;lt;a href=&amp;#34;#faceup--voice-based-ai-conducts-natural-conversations-with-whistleblowers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;FaceUp is a Czech-EU platform with 3,500+ organisations across 70+ countries. Their &amp;lt;a href=&amp;#34;https://www.faceup.com/en/whistleblowing/hotline&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;whistleblower hotline page&amp;lt;/a&amp;gt;
offers three tiers: a Live Hotline staffed by human agents, an Automated Hotline with a scripted flow, and the new AI-Powered Hotline in the middle:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Voice-based AI conducts natural conversations, asks follow-ups, and converts calls into structured, actionable reports.&amp;lt;/strong&amp;gt; Multilingual, 24/7.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/faceup-ai-powered-hotline.png&amp;#34; alt=&amp;#34;FaceUp three-tier hotline comparison — “AI-Powered Hotline” (centre, marked “new”) with “Voice-based AI conducts natural conversations, asks follow-ups, and converts calls into structured, actionable reports”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;The AI agent guides the reporter and follows up where needed to capture complete and accurate information.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;FaceUp&amp;amp;rsquo;s three-card layout is the clearest framing of the choice in the category: a human handles the call, a scripted flow handles the call, or an AI handles the call. They sell all three and mark the AI option &amp;amp;ldquo;new&amp;amp;rdquo;. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;whistlelink--mistral-ai-france-and-deepl-germany-named-in-the-public-dpa&amp;#34;&amp;gt;
Whistlelink — Mistral AI (France) and DeepL (Germany) named in the public DPA
&amp;lt;a href=&amp;#34;#whistlelink--mistral-ai-france-and-deepl-germany-named-in-the-public-dpa&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Whistlelink is the only vendor of the seven that publicly names its AI providers. Their &amp;lt;a href=&amp;#34;https://www.whistlelink.com/ro/contract-de-prelucrare-a-datelor/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Romanian DPA&amp;lt;/a&amp;gt;
, Section 5.5:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Sub-Imputerniciți: Swerolab AB (Suedia), SMSAPI (Polonia), Brevo (Franța), OPSWAT (Germania), Glesys (Suedia), T-Systems International (Germania), Friendly Captcha (Germania), &amp;lt;strong&amp;gt;DeepL (Germania), Mistral AI (Franța)&amp;lt;/strong&amp;gt;.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/whistlelink-dpa-mistral-deepl.png&amp;#34; alt=&amp;#34;Whistlelink DPA Section 5.5 — sub-processor list naming DeepL (Germany) and Mistral AI (France)&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;#34;https://www.whistlelink.com/product/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;product page&amp;lt;/a&amp;gt;
explains what the AI Assistant does: &amp;amp;ldquo;AI Assistant automatically generates concise case summaries.&amp;amp;rdquo; Mistral is the only LLM provider on the sub-processor list above.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Article 16 confidentiality concern still applies. But an operator signing this DPA knows what they are signing. Operators signing the other six don&amp;amp;rsquo;t.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;ethicontrol--ai-intake-agent-on-the-pricing-page&amp;#34;&amp;gt;
Ethicontrol — &amp;amp;ldquo;ai intake agent&amp;amp;rdquo; on the pricing page
&amp;lt;a href=&amp;#34;#ethicontrol--ai-intake-agent-on-the-pricing-page&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ethicontrol&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://ethicontrol.com/en/pricing&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;pricing page&amp;lt;/a&amp;gt;
lists &amp;lt;code&amp;gt;+ ai intake agent for web portal and WhatsApp&amp;lt;/code&amp;gt; as a paid feature starting at the Standard tier (€174/month):&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/ethicontrol-pricing-ai-intake-agent.png&amp;#34; alt=&amp;#34;Ethicontrol pricing — Standard tier includes “&amp;amp;#43; ai intake agent for web portal and WhatsApp”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In 2026, an &amp;amp;ldquo;intake agent&amp;amp;rdquo; for whistleblower reports is a conversational LLM. The privacy policy and Trust Center do not name the provider.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;six-of-the-seven-wont-tell-you-whose-ai&amp;#34;&amp;gt;
Six of the seven won&amp;amp;rsquo;t tell you whose AI
&amp;lt;a href=&amp;#34;#six-of-the-seven-wont-tell-you-whose-ai&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Of the seven above, only Whistlelink names the AI providers (Mistral, DeepL). The other six say &amp;amp;ldquo;AI&amp;amp;rdquo;, &amp;amp;ldquo;AI-powered&amp;amp;rdquo;, &amp;amp;ldquo;Sienna AI&amp;amp;rdquo;, or &amp;amp;ldquo;Voice-based AI&amp;amp;rdquo; without naming the model, the provider, the jurisdiction, or whether the inference call leaves the operator&amp;amp;rsquo;s encryption boundary.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We searched every vendor&amp;amp;rsquo;s privacy policy, DPA, sub-processor page, and trust center we could reach on 24 May 2026. For six, the provider is not disclosed. The feature is in the marketing copy. The disclosure is not in the legal pages.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is the harder problem. An operator running a Data Protection Impact Assessment cannot disclose a sub-processor they cannot name, cannot assess GDPR Chapter V transfer mechanisms for a provider that has not been disclosed to them, and cannot offer the reporter a meaningful privacy notice when the architecture has a box labelled &amp;amp;ldquo;AI&amp;amp;rdquo; and no further detail.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;why-a-whistleblower-reporting-channel-is-the-wrong-place-for-ai&amp;#34;&amp;gt;
Why a whistleblower reporting channel is the wrong place for AI
&amp;lt;a href=&amp;#34;#why-a-whistleblower-reporting-channel-is-the-wrong-place-for-ai&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Article 16 of Directive 2019/1937 says the identity of the reporting person, and information from which it can be deduced, must not be disclosed to anyone beyond authorised case-handling staff. Member-state laws (HinSchG, Sapin II / Loi Waserman, Law 361/2022, the 2024 Polish Act) lift that into criminal or administrative penalties. An LLM API provider is not authorised case-handling staff. Their engineers can read prompts. Their abuse-detection systems are designed to read prompts. The Directive has no &amp;amp;ldquo;but it was just for a summary&amp;amp;rdquo; carve-out.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener noreferrer&amp;#34;&amp;gt;Art. 22&amp;lt;/a&amp;gt;
of the GDPR sits on top of that. AI categorisation, &amp;amp;ldquo;suggested rewrites&amp;amp;rdquo; of a report body, AI case briefs that an investigator reads instead of the original, and &amp;amp;ldquo;insights&amp;amp;rdquo; that decide investigative priority are exactly the automated decision-making the article is written about. Disclosure, DPIA, sub-processor listing with notice and objection rights, and reporter-facing transparency all attach.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A no-AI commitment removes the entire disclosure tree. The privacy notice is shorter, the DPIA is shorter, the sub-processor list is shorter, and the reporter&amp;amp;rsquo;s expectation matches the architecture.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;our-commitment&amp;#34;&amp;gt;
Our commitment
&amp;lt;a href=&amp;#34;#our-commitment&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/dpa/#610-no-ai-or-llm-processing-of-report-content&amp;#34;&amp;gt;DPA §6.10&amp;lt;/a&amp;gt;
: report content, reporter identity, handler messages, attachments, and audit logs are not transmitted to any large language model, generative AI service, or AI-based classifier, whether operated by us or by a third party. OpenAI, Anthropic, Google, and Mistral are named in the DPA as examples of providers we do not transmit to. A change to this would be a material change to the service, notified 30 days in advance with an objection right.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Our &amp;lt;a href=&amp;#34;/subprocessors/&amp;#34;&amp;gt;sub-processor list&amp;lt;/a&amp;gt;
has six entries: Hetzner (EU hosting), Cloudflare (marketing-site CDN only), Mailjet (email), Stripe (billing), AppSignal (handler-side error monitoring), Crisp (handler-side chat). No AI sub-processor appears.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;if-you-are-evaluating-a-vendor&amp;#34;&amp;gt;
If you are evaluating a vendor
&amp;lt;a href=&amp;#34;#if-you-are-evaluating-a-vendor&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ask in writing: is any large language model, generative AI service, or AI-based classifier — operated by you or by a third party — a sub-processor of report content, reporter identity, handler messages, attachments, or audit logs? Name the provider, the jurisdiction, the function, and whether it is on by default. And will you contractually commit that this answer cannot change without 30 days&amp;amp;rsquo; notice and an objection right?&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We answered both in our DPA before anyone had to ask.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Best whistleblower software in 2026: an honest comparison</title><link>https://ethicsportal.eu/blog/best-whistleblower-software/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/best-whistleblower-software/</guid><description>An independent comparison of the top whistleblower reporting platforms in 2026, including pricing, features, and who each tool is best for.</description><content:encoded>&amp;lt;h1 id=&amp;#34;best-whistleblower-software-in-2026-an-honest-comparison&amp;#34;&amp;gt;
Best whistleblower software in 2026: an honest comparison
&amp;lt;a href=&amp;#34;#best-whistleblower-software-in-2026-an-honest-comparison&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;If you are looking for whistleblower software to comply with EU Directive 2019/1937, you have probably noticed that every vendor publishes a &amp;amp;ldquo;best whistleblower software&amp;amp;rdquo; article &amp;amp;mdash; and ranks themselves first. We are not going to do that. This is an honest, side-by-side comparison of the platforms we evaluated before building EthicsPortal, plus EthicsPortal itself.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We looked at pricing transparency, setup speed, EU hosting, feature depth, and how well each tool serves small-to-mid-sized companies versus enterprises.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;quick-comparison-table&amp;#34;&amp;gt;
Quick comparison table
&amp;lt;a href=&amp;#34;#quick-comparison-table&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Platform&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Starting price&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Free trial&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;EU hosting&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Setup time&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Best for&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EthicsPortal&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€49/mo flat&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Minutes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;SMEs, fast compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Hintbox&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€49&amp;amp;ndash;€149+/mo (+VAT)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;German-speaking markets&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;LegalTegrity&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€49&amp;amp;ndash;€166/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;German SMEs, phone included&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Vispato&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€79/mo flat&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;DACH flat-rate alternative&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;DigitalPA (Legality Whistleblowing)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;From €29/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Italy)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Italian market, ISO 37001/37002&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;ithikios&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;From €29/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Spain)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Spanish SMEs, modular compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Canal Etico App&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€96/mo flat&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Spain)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Spanish Ley 2/2023 compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Whistlelink&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€79&amp;amp;ndash;€299/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (30 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Sweden)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Nordic companies, mid-market&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Sygnanet&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;4,000&amp;amp;ndash;10,000 zł/yr&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Poland)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Polish market&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Trusty Compliance&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Credit-based&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (7 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Switzerland)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Swiss/DACH, broader compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Formalize (whistleblowersoftware.com)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (request quote)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (14 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Denmark)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Mid-market EU companies&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;FaceUp&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (request quote)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Czech Republic)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Schools, multilingual orgs&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Whispli&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (~€3,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (optional)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Enterprises, complex workflows&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;SpeakUp (People Intouch)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;~€3,000/yr&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Netherlands)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Mid-to-large EU companies&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EQS Integrity Line&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (~€3,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Essential)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Large enterprises&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;NAVEX Global&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (€5,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (optional)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Large US/EU enterprises&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;detailed-reviews&amp;#34;&amp;gt;
Detailed reviews
&amp;lt;a href=&amp;#34;#detailed-reviews&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;eqs-integrity-line&amp;#34;&amp;gt;
EQS Integrity Line
&amp;lt;a href=&amp;#34;#eqs-integrity-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;EQS is the heavyweight of European compliance software. Their Integrity Line is used by banks, insurers, and listed companies across the EU.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Deep integration with broader GRC (governance, risk, compliance) suites. Excellent audit trails. Strong brand recognition among enterprise compliance teams. Supports 70+ languages.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing is opaque &amp;amp;mdash; you will not find a number on their website. Expect to spend several thousand euros per year, and you will need to go through a sales process. Implementation typically takes weeks with dedicated onboarding. Overkill for a 50-person company.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Large enterprises (500+ employees) in heavily regulated sectors that need a full GRC ecosystem.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;formalize-whistleblowersoftwarecom&amp;#34;&amp;gt;
Formalize (whistleblowersoftware.com)
&amp;lt;a href=&amp;#34;#formalize-whistleblowersoftwarecom&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Formalize, marketed as WhistleblowerSoftware.com, is a Danish platform backed by a €15M Series A with 500+ consultancy partners including PwC and Baker McKenzie. They have rebranded and expanded into broader compliance (NIS2, DORA, ISO 27001).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; 80+ languages. ISO 27001 and ISAE 3000 certified. Strong partner ecosystem. 14-day free trial.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No longer publishes pricing — requires requesting a custom quote. Expanding beyond whistleblowing into NIS2/DORA compliance may dilute focus. Setup involves a demo/sales process, not instant self-serve.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Mid-sized EU companies (50&amp;amp;ndash;500 employees) that want a polished product and do not mind per-employee pricing.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;whistlelink&amp;#34;&amp;gt;
Whistlelink
&amp;lt;a href=&amp;#34;#whistlelink&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Swedish platform with a strong presence in the Nordics. Whistlelink positions itself as easy to use and EU-compliant.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Available in 50+ languages. Good case management. Hosted in Sweden. Straightforward UI for reporters. All pricing tiers include the same feature set. 30-day free trial.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Starting at €79/month (billed annually) is reasonable but still above the flat-rate options. Per-employee pricing scales to €299/month for larger organizations. Scaling past 1,000 employees requires contacting sales.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Nordic and Northern European companies looking for a regional vendor with solid language support.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;faceup&amp;#34;&amp;gt;
FaceUp
&amp;lt;a href=&amp;#34;#faceup&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;FaceUp is a Czech-founded whistleblower platform that has expanded from its original focus on schools into corporate compliance, now serving organizations across 70+ countries. They support 113 languages and offer a mobile app for reporters.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Available in 113 languages — among the highest in the market. Mobile app for reporters. ISO 27001 certified. Strong presence in the education sector alongside corporate compliance.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing is not published — all plans show &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; buttons despite listing tier names (Starter, Professional, Enterprise). Pricing is in US dollars, which adds currency risk for European companies. The school-oriented origin shows in some of the UX.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Organizations that need 113 languages, want a mobile reporting app, or operate in both education and corporate sectors.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;navex-global&amp;#34;&amp;gt;
NAVEX Global
&amp;lt;a href=&amp;#34;#navex-global&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;NAVEX is the 800-pound gorilla of ethics and compliance, primarily in North America but increasingly in Europe. Their EthicsPoint product has been around for decades.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Massive feature set. Benchmarking data from thousands of clients. Hotline services (phone-based reporting). Strong analytics.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Enterprise pricing &amp;amp;mdash; expect custom quotes well above €5,000/year. Long implementation cycles. The platform can feel dated compared to newer entrants. North American DNA means EU-specific requirements sometimes feel bolted on rather than native.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Large multinationals (1,000+ employees) that want a single vendor for their entire ethics and compliance program, including hotlines.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;whispli&amp;#34;&amp;gt;
Whispli
&amp;lt;a href=&amp;#34;#whispli&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An Australian-founded company that has expanded into Europe. Whispli emphasizes anonymous two-way communication.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Strong anonymous messaging system. Good mobile experience. Supports voice and video reporting. Flexible workflow builder.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Custom pricing with no public numbers &amp;amp;mdash; reports suggest starting around €3,000/year. Implementation involves onboarding calls and configuration. Smaller European presence compared to EU-native vendors.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Organizations that prioritize anonymous two-way communication and need multimedia reporting (voice, video).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;speakup-people-intouch&amp;#34;&amp;gt;
SpeakUp (People Intouch)
&amp;lt;a href=&amp;#34;#speakup-people-intouch&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Dutch platform that has been in the whistleblower space since before the EU Directive made it mandatory. SpeakUp offers both software and managed services (outsourced case handling).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Long track record. Option to outsource case handling entirely. Hosted in the Netherlands. Phone reporting included.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing starts at €3,000/year for companies under 1,000 employees, custom for larger. The managed services model means you are paying for humans, not just software. Interface is functional but not modern.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Mid-to-large EU companies that want the option to outsource report handling to a third party.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;hintbox&amp;#34;&amp;gt;
Hintbox
&amp;lt;a href=&amp;#34;#hintbox&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A German platform (part of lawcode Suite) with 1,000+ customers including Rewe, s.Oliver, and FC Bayern. ISO 27001 certified, hosted on Hetzner in Germany. Expanding into LkSG (Supply Chain Act) and CSRD compliance beyond whistleblowing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Mature product with large customer base. ISO 27001 certified. 30+ languages with AI translation. 2FA, metadata stripping, virus scanning all included. Starting at €49/month — the cheapest tier alongside EthicsPortal. Free trial available.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Per-employee pricing scales to €149+/month for larger companies. Add-on costs pile up: voice bot (+€49/mo), email integration (+€29/mo), custom domain (+€29/mo). DACH-centric — limited presence outside German-speaking markets. Expanding into multiple compliance frameworks may dilute whistleblower focus.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; German, Austrian, and Swiss companies that want a local vendor with ISO 27001, deep HinSchG expertise, and a proven track record.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;legaltegrity&amp;#34;&amp;gt;
LegalTegrity
&amp;lt;a href=&amp;#34;#legaltegrity&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Frankfurt-based platform founded by Dr. Thomas Altenbach, hosted on Deutsche Telekom&amp;amp;rsquo;s Open Telekom Cloud. Positioned for German SMEs with transparent tiered pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Phone reporting channel included on every plan &amp;amp;mdash; even the €49/month Essential tier. 40+ languages available. Hosted on Deutsche Telekom Open Telekom Cloud (ISO 27001-certified infrastructure). 3-month money-back guarantee. OmbuTegrity add-on offers an external ombudsperson service for companies that need an independent reporting office.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Essential tier limits customization (standard form, LegalTegrity branding, 2 admin accounts). Additional languages cost €29/month each beyond the 2 included. No public API. Primarily German-market focused.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; German and DACH-region SMEs (under 1,000 employees) that want phone reporting included at a competitive price.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;vispato&amp;#34;&amp;gt;
Vispato
&amp;lt;a href=&amp;#34;#vispato&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A German whistleblowing platform from the HR WORKS group, hosted on DATEV-managed servers. Vispato is notable for its flat-rate pricing regardless of company size.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat €79/month with unlimited users, cases, and storage &amp;amp;mdash; no per-employee scaling. 18 languages. ISO 27001-certified hosting (DATEV). WCAG 2.1 AA accessibility compliance. No setup costs, no consulting upsells. 12-month minimum term.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No free trial &amp;amp;mdash; demo required before signup. No public API. 18 languages is fewer than most mid-market competitors. Enterprise features (SSO, custom domain, custom branding) require a custom-quote Enterprise plan.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; DACH-region companies of any size that want predictable flat pricing without employee-count tiers or add-on fees.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;digitalpa-legality-whistleblowing&amp;#34;&amp;gt;
DigitalPA (Legality Whistleblowing)
&amp;lt;a href=&amp;#34;#digitalpa-legality-whistleblowing&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An Italian platform operated by DigitalPA with offices in Cagliari, Milan, Rome, and Barcelona. Holds four ISO certifications (27001, 37001, 37002, 37301) &amp;amp;mdash; more than any other platform in this comparison.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Starting at €29/month &amp;amp;mdash; the cheapest published price in this comparison. ISO 27001, 37001 (anti-bribery), 37002 (whistleblowing management), and 37301 (compliance management) certified. Multi-channel intake including phone reports and in-person meeting requests. Mobile app. AI translation between handler and reporter. 1,000+ customers.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing beyond the €29 small-business tier requires a custom quote. Annual billing only. Italian-market focused. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Italian companies and organizations that need a locally certified platform, especially public sector entities required to comply with D.Lgs. 24/2023.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;ithikios&amp;#34;&amp;gt;
ithikios
&amp;lt;a href=&amp;#34;#ithikios&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Spanish modular compliance suite from Digital Products Development SL. Whistleblowing is one of six modules alongside policy, incident, rights, third-party, and trust-center management.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Starting at €29/month. ISO 27001 certified. 1,000+ companies across 10 countries. Free trial available. 7 interface languages (ES, EN, FR, DE, IT, PT, CA). Modular: buy the whistleblowing channel, add NIS2/DORA/policy modules later. Partner program for lawyers and consultants.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Primarily Spanish-market focused. Limited to 7 languages &amp;amp;mdash; the fewest among multi-market vendors. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Spanish SMEs that need Ley 2/2023 compliance and may want to add policy management, incident management, or third-party risk modules over time.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;canal-etico-app&amp;#34;&amp;gt;
Canal Etico App
&amp;lt;a href=&amp;#34;#canal-etico-app&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Spanish platform from Smart Dev Technology with flat €96/month pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat pricing regardless of company size. Unlimited reports. Written and voice reporting channels. Anonymous bidirectional communication. No IP storage, encrypted content. Implementation in 1&amp;amp;ndash;2 business days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No ISO 27001 certification published. Spanish-language support only. No public API. Higher price point than ithikios and DigitalPA for the same Spanish market.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Spanish companies that want simple flat pricing for Ley 2/2023 compliance without per-employee scaling.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;sygnanet&amp;#34;&amp;gt;
Sygnanet
&amp;lt;a href=&amp;#34;#sygnanet&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Polish platform from SpecFile Project Sp. z o.o. Built specifically for the Polish Act on Protection of Whistleblowers (in force 25 September 2024).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; End-to-end encryption with zero vendor access to report content. 12-language reporting form. Free trial. Pricing in Polish zloty (4,000&amp;amp;ndash;10,000 zł/year). Public bodies buying the internal-reporting licence get an external-reporting channel bundled free. Periodic penetration testing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Polish-market focused. Pricing in PLN only. No ISO 27001 certification published. No public API. Admin panel limited to 4 languages (PL, EN, DE, FR).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Polish organizations that need a local vendor compliant with the Act of 14 June 2024.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;trusty-compliance&amp;#34;&amp;gt;
Trusty Compliance
&amp;lt;a href=&amp;#34;#trusty-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Swiss platform (Trusty AG, Hünenberg, Zug) offering whistleblowing as one module in a broader compliance suite covering risk screening, EUDR, policy management, and training.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; 4,000+ companies. 7-day free trial. Credit-based pricing &amp;amp;mdash; buy credits and allocate them across any Trusty product. Quick setup (vendor claims under 5 minutes). 6 interface languages. Broader compliance coverage (EUDR, NIS2, third-party risk, training) in addition to whistleblowing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No ISO 27001 certification published. Credit-based pricing makes cost comparison difficult. Whistleblowing is one module of many &amp;amp;mdash; breadth may come at the expense of depth. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Swiss and DACH companies that want a single platform covering whistleblowing, risk screening, EUDR, and compliance training.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;ethicsportal&amp;#34;&amp;gt;
EthicsPortal
&amp;lt;a href=&amp;#34;#ethicsportal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is our product. We designed it to deliver full EU Directive 2019/1937 compliance with transparent pricing and immediate deployment.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat €49/month pricing regardless of employee count. No sales calls &amp;amp;mdash; sign up and configure your portal in minutes. EU-hosted. Covers the core Directive requirements: encrypted anonymous reporting, two-way messaging via access codes, case management, 7-day acknowledgment and 3-month feedback tracking, QR code generation, and multilingual portals. Open, transparent pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No phone hotline. No outsourced case handling. Limited integrations (no HRIS connectors yet). Not suitable for organizations that need a full GRC suite.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; SMEs, startups, and mid-sized companies (50&amp;amp;ndash;1,000 employees) that need Directive compliance without enterprise complexity or pricing.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-we-chose&amp;#34;&amp;gt;
How we chose
&amp;lt;a href=&amp;#34;#how-we-chose&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;We evaluated each platform across five criteria:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Pricing transparency.&amp;lt;/strong&amp;gt; Can you find the price on the website without requesting a demo? Bonus points for flat-rate pricing.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Setup speed.&amp;lt;/strong&amp;gt; How quickly can a non-technical compliance officer get from sign-up to a working reporting channel?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU Directive coverage.&amp;lt;/strong&amp;gt; Does the platform natively support the key requirements of Directive 2019/1937 &amp;amp;mdash; anonymous reporting, two-way communication, acknowledgment deadlines, confidentiality?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data residency.&amp;lt;/strong&amp;gt; Is data hosted in the EU by default, or is it an add-on?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Target audience fit.&amp;lt;/strong&amp;gt; Is the platform designed for your company size, or are you paying for features built for organizations ten times larger?&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;We used publicly available pricing where possible and contacted sales teams where pricing was not published. Prices cited are as of Q1 2026 and may vary by region, contract length, and negotiation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;No affiliate links. No sponsorships. We built EthicsPortal because we saw a gap &amp;amp;mdash; this article explains where that gap is, and where other tools may be the better choice for your situation.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Top whistleblower software for EU Directive 2019/1937 compliance</title><link>https://ethicsportal.eu/blog/top-whistleblower-software-eu-directive-2019-1937/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/top-whistleblower-software-eu-directive-2019-1937/</guid><description>A ranked comparison of whistleblower platforms that meet the requirements of EU Directive 2019/1937. Evaluated on Article 8–16 coverage, pricing, EU hosting, and setup speed.</description><content:encoded>&amp;lt;h1 id=&amp;#34;top-whistleblower-software-for-eu-directive-20191937-compliance&amp;#34;&amp;gt;
Top whistleblower software for EU Directive 2019/1937 compliance
&amp;lt;a href=&amp;#34;#top-whistleblower-software-for-eu-directive-20191937-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937, now transposed into national law in all 27 member states (e.g., &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
in France, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
in Germany, &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
in Spain), requires every organization with 50 or more employees to operate a secure internal reporting channel. The law is specific about what that channel must do: accept written and oral reports, protect reporter confidentiality, acknowledge receipt within 7 days, provide feedback within 3 months, and maintain records without exposing the reporter&amp;amp;rsquo;s identity.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is what is strange about this market: whistleblower reporting is a simple tool. A reporter submits a report. A handler reads it and responds. The system tracks deadlines and keeps an audit trail. That is the entire product.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Yet most vendors hide their pricing behind &amp;amp;ldquo;contact us for a demo&amp;amp;rdquo; forms, require weeks-long sales processes, and pad their feature lists with AI-powered analytics, sentiment analysis, and other additions that have nothing to do with what the Directive actually requires. The result is that a compliance officer at a 100-person company ends up on a sales call for a tool that should take ten minutes to set up.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This article ranks the top whistleblower software specifically by how well each platform meets the Directive&amp;amp;rsquo;s legal requirements &amp;amp;mdash; not by brand recognition, AI feature count, or how impressive the sales deck looks.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-we-scored&amp;#34;&amp;gt;
How we scored
&amp;lt;a href=&amp;#34;#how-we-scored&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every platform was evaluated against the six core requirements of Directive 2019/1937:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Directive articles&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;What the law demands&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure reporting channel&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 8&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Encrypted, accessible to all workers, no account required&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter confidentiality&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 16&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Identity not disclosed without consent, access restricted to authorized staff&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Receipt acknowledgment&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Written confirmation within 7 days&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Feedback deadline&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(f)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Substantive feedback within 3 months&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Ability to communicate with the reporter, including anonymous reporters&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 18&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Reports stored securely, retained per legal requirements, deletable when no longer needed&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;We also considered practical factors: pricing transparency, EU data residency, setup speed, and whether the platform requires a sales call to get started.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-ranking&amp;#34;&amp;gt;
The ranking
&amp;lt;a href=&amp;#34;#the-ranking&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;1-ethicsportal--best-for-smes-that-need-fast-affordable-compliance&amp;#34;&amp;gt;
1. EthicsPortal &amp;amp;mdash; best for SMEs that need fast, affordable compliance
&amp;lt;a href=&amp;#34;#1-ethicsportal--best-for-smes-that-need-fast-affordable-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; EthicsPortal was built specifically for EU Directive 2019/1937. Every feature maps to an article.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;How EthicsPortal handles it&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Encrypted web portal, unique URL per organization, no app required&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No IP logging, file metadata stripping (EXIF, GPS, author), encrypted data at rest&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Automatic deadline tracking with handler notifications&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Automatic deadline tracking with overdue alerts&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Anonymous message thread via access code &amp;amp;mdash; handler names never revealed&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Append-only audit trail, PDF export for auditors&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; €49/month flat. No per-employee fees, no add-ons.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Hetzner, Nuremberg, Germany.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Minutes. Self-serve signup, no sales call.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks first:&amp;lt;/strong&amp;gt; Whistleblower reporting is not a complex problem. The Directive tells you exactly what the tool needs to do, and EthicsPortal does exactly that &amp;amp;mdash; nothing more, nothing less. No AI sentiment analysis, no &amp;amp;ldquo;risk scoring,&amp;amp;rdquo; no features that exist to justify a higher price tag. Full Art. 8&amp;amp;ndash;18 compliance at €49/month, visible on the website, no sales call required.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The trade-off is that EthicsPortal is newer and does not yet have ISO 27001 certification or phone hotline services.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is our product. We designed it to deliver full Directive compliance with transparent pricing and immediate deployment.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;2-formalize-whistleblowersoftwarecom--best-for-mid-market-companies-wanting-a-polished-product&amp;#34;&amp;gt;
2. Formalize (WhistleblowerSoftware.com) &amp;amp;mdash; best for mid-market companies wanting a polished product
&amp;lt;a href=&amp;#34;#2-formalize-whistleblowersoftwarecom--best-for-mid-market-companies-wanting-a-polished-product&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Built in Denmark with the EU Directive as the primary design driver.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web portal with encryption&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; access controls, data encryption&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Custom quote required. Previously published per-employee pricing; no longer public.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Denmark.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days &amp;amp;mdash; involves a demo/sales process.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Strong Directive compliance, ISO 27001 and ISAE 3000 certified, and 80+ languages. Formalize used to publish pricing on their website &amp;amp;mdash; they no longer do, which tells you something about the direction they are heading. You now need to request a quote and go through a sales process to learn what it costs. If you need certifications and a partner ecosystem (PwC, Baker McKenzie), Formalize is a strong choice &amp;amp;mdash; but be prepared to negotiate pricing you cannot see upfront.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;3-hintbox--best-for-german-speaking-markets&amp;#34;&amp;gt;
3. Hintbox &amp;amp;mdash; best for German-speaking markets
&amp;lt;a href=&amp;#34;#3-hintbox--best-for-german-speaking-markets&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; German platform with 1,000+ customers. Part of the lawcode suite.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, hosted on Hetzner (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; metadata stripping, 2FA, virus scanning&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging, optional voice bot (+€49/mo)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at €49/month. Scales to €149+/month with employee count. Add-ons: voice bot (+€49/mo), email integration (+€29/mo), custom domain (+€29/mo).
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Hetzner, Germany. ISO 27001 certified.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Mature product, large customer base (Rewe, s.Oliver, FC Bayern), ISO 27001 certified. The per-employee pricing and add-on costs mean the effective price is significantly higher than the €49 starting point for most organizations. DACH-focused &amp;amp;mdash; limited presence outside German-speaking markets.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;4-legaltegrity--best-for-german-smes-that-want-phone-reporting-included&amp;#34;&amp;gt;
4. LegalTegrity &amp;amp;mdash; best for German SMEs that want phone reporting included
&amp;lt;a href=&amp;#34;#4-legaltegrity--best-for-german-smes-that-want-phone-reporting-included&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Frankfurt-based, hosted on Deutsche Telekom Open Telekom Cloud.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, Deutsche Telekom hosting (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; role-based access&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking with reminders&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging, phone channel on all plans&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail, reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Essential €49/month (&amp;amp;lt;50 employees), Professional €99/month (&amp;amp;lt;250), Professional €166/month (&amp;amp;lt;1,000), Enterprise on request. Annual billing.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Deutsche Telekom Open Telekom Cloud, Germany. ISO 27001-certified hosting.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. 3-month money-back guarantee.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; LegalTegrity includes a phone reporting channel on every plan, including the €49 Essential tier. That is unusual &amp;amp;mdash; most competitors charge extra for phone intake or do not offer it at all. 40+ languages available. The trade-off: per-employee tiered pricing means costs rise as your organisation grows, and additional languages cost €29/month each beyond the two included.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;5-vispato--best-flat-rate-alternative-in-dach&amp;#34;&amp;gt;
5. Vispato &amp;amp;mdash; best flat-rate alternative in DACH
&amp;lt;a href=&amp;#34;#5-vispato--best-flat-rate-alternative-in-dach&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; German platform, part of the HR WORKS group.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, DATEV-hosted (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; role-based access, ISO 27001 hosting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; €79/month flat. Unlimited users, cases, and storage. Enterprise tier with SSO and custom domain is quote-based.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; DATEV-managed servers, Germany.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. No free trial, demo required.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Flat €79/month regardless of company size, with no add-on fees. 18 languages. WCAG 2.1 AA accessibility. For DACH-region companies that want predictable costs without employee-count tiers, Vispato is the cleanest alternative. The trade-off: fewer languages than competitors (18 vs. 30&amp;amp;ndash;80), and no free trial.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;6-digitalpa-legality-whistleblowing--best-for-italy&amp;#34;&amp;gt;
6. DigitalPA (Legality Whistleblowing) &amp;amp;mdash; best for Italy
&amp;lt;a href=&amp;#34;#6-digitalpa-legality-whistleblowing--best-for-italy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Italian platform with four ISO certifications.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web, voice, phone, and in-person intake&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; 2FA, anonymous and confidential modes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging with AI translation&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail, investigation reports&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Standard from €29/month (&amp;amp;lt;50 employees). Premium from €41/month. Medium/Large/Enterprise tiers require a quote. Annual billing only.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Italy.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; The cheapest starting price in this comparison (€29/month) and the most ISO certifications (27001, 37001, 37002, 37301). Multi-channel intake including phone and in-person meeting requests. 1,000+ customers. The trade-off: pricing beyond the small-business tier is quote-based, and the platform is Italian-market focused.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;7-ithikios--best-for-spanish-smes&amp;#34;&amp;gt;
7. ithikios &amp;amp;mdash; best for Spanish SMEs
&amp;lt;a href=&amp;#34;#7-ithikios--best-for-spanish-smes&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Spanish modular compliance suite.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted cloud portal, ISO 27001 servers&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous and confidential modes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; case management with documentation&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; From €29/month. Free trial available.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Spain. ISO 27001 certified.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Budget-friendly at €29/month with ISO 27001 and a free trial. 1,000+ companies across 10 countries. Modular platform: buy the whistleblower channel now, add policy management or NIS2 modules later. 7 interface languages. The trade-off: primarily Spanish-focused, and 7 languages is limited for cross-border organisations.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;8-faceup--best-for-multilingual-organizations-113-languages&amp;#34;&amp;gt;
8. FaceUp &amp;amp;mdash; best for multilingual organizations (113 languages)
&amp;lt;a href=&amp;#34;#8-faceup--best-for-multilingual-organizations-113-languages&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; access controls&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Not public. Three tiers (Starter, Professional, Enterprise) but all require &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; — no prices shown on the website. Priced in USD.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Czech Republic.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; FaceUp supports 113 languages &amp;amp;mdash; among the highest in the market &amp;amp;mdash; and offers a mobile app for reporters. Originally built for schools in the Czech Republic, they have expanded into corporate compliance across 70+ countries. Pricing is in US dollars and not publicly displayed &amp;amp;mdash; all three tiers (Starter, Professional, Enterprise) show &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; buttons rather than prices, making it impossible to budget without a sales conversation.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;9-whistlelink--best-for-nordic-companies&amp;#34;&amp;gt;
9. Whistlelink &amp;amp;mdash; best for Nordic companies
&amp;lt;a href=&amp;#34;#9-whistlelink--best-for-nordic-companies&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at €79/month (billed annually). Scales by employee count: €79 → €99 → €149 → €199 → €299/month. 1,000+ employees: contact sales.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Sweden.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. 30-day free trial available.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Solid Directive compliance with 50+ languages and good case management. All pricing tiers include the same feature set &amp;amp;mdash; no feature gating. Starting at €79/month, pricing is higher than the cheapest options but transparent. Strong regional presence in the Nordics.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;10-speakup-people-intouch--best-for-outsourced-case-handling&amp;#34;&amp;gt;
10. SpeakUp (People Intouch) &amp;amp;mdash; best for outsourced case handling
&amp;lt;a href=&amp;#34;#10-speakup-people-intouch--best-for-outsourced-case-handling&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; One of the longest-running European whistleblower platforms (Netherlands).&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web + phone reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at ~€3,000/year for companies under 1,000 employees. Custom for larger.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Netherlands.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Unique value proposition: outsourced case handling by trained professionals. If your organization does not have internal resources to manage reports, SpeakUp handles it for you. The trade-off is price &amp;amp;mdash; you are paying for human operators, not just software.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;11-eqs-integrity-line--best-for-large-enterprises&amp;#34;&amp;gt;
11. EQS Integrity Line &amp;amp;mdash; best for large enterprises
&amp;lt;a href=&amp;#34;#11-eqs-integrity-line--best-for-large-enterprises&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; The European enterprise standard.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; 70+ languages&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; enterprise-grade access controls&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; integrates with GRC suites&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Not published. Estimated €2,000+/month. Requires sales process.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Weeks.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; If you are a bank, insurer, or listed company with 5,000+ employees, EQS is the safe enterprise choice. For everyone else, you are paying for features and scale you do not need. Implementation takes weeks, not minutes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;12-navex-global--best-for-us-multinationals-with-eu-operations&amp;#34;&amp;gt;
12. NAVEX Global &amp;amp;mdash; best for US multinationals with EU operations
&amp;lt;a href=&amp;#34;#12-navex-global--best-for-us-multinationals-with-eu-operations&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete, but EU compliance feels bolted on.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web + phone hotline&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; strong analytics&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Custom. Typically €5,000+/year. Requires sales process.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Available as an option, not default.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Weeks.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; NAVEX is the dominant US compliance platform with decades of history and thousands of clients. Their EthicsPoint product covers the Directive, but the platform was designed for US regulatory frameworks first. EU hosting is available but not the default. Enterprise pricing and long implementation cycles put it out of reach for SMEs.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;which-platform-should-you-choose&amp;#34;&amp;gt;
Which platform should you choose?
&amp;lt;a href=&amp;#34;#which-platform-should-you-choose&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Your situation&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Best choice&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;SME or startup, need compliance fast, budget-conscious&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;EthicsPortal&amp;lt;/strong&amp;gt; (€49/mo, minutes to set up)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;German SME, want phone reporting included&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;LegalTegrity&amp;lt;/strong&amp;gt; (€49+/mo, phone on all plans)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;DACH region, want flat pricing with no add-ons&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Vispato&amp;lt;/strong&amp;gt; (€79/mo flat)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Italian company, need local certifications&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;DigitalPA&amp;lt;/strong&amp;gt; (from €29/mo, ISO 27001/37001/37002)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spanish company, need Ley 2/2023 compliance&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;ithikios&amp;lt;/strong&amp;gt; (from €29/mo, ISO 27001)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Mid-market, want certifications and partner ecosystem&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Formalize&amp;lt;/strong&amp;gt; (custom pricing, ISO certified)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;German-speaking market, need ISO 27001 at scale&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Hintbox&amp;lt;/strong&amp;gt; (€49+/mo, ISO 27001)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Need 113 languages or mobile reporting app&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;FaceUp&amp;lt;/strong&amp;gt; (custom quote)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Nordic company, prefer regional vendor&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Whistlelink&amp;lt;/strong&amp;gt; (€79+/mo)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Need outsourced case handling&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;SpeakUp&amp;lt;/strong&amp;gt; (~€3,000/yr)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Large enterprise (500+ employees), full GRC suite&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;EQS Integrity Line&amp;lt;/strong&amp;gt; (custom pricing)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;US multinational with EU subsidiary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;NAVEX Global&amp;lt;/strong&amp;gt; (custom pricing)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-most-platforms-are-overpriced-for-what-they-do&amp;#34;&amp;gt;
Why most platforms are overpriced for what they do
&amp;lt;a href=&amp;#34;#why-most-platforms-are-overpriced-for-what-they-do&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every platform on this list covers the core requirements of Directive 2019/1937. That is worth repeating: the basic compliance functionality is the same across all of them. A reporter submits a report. A handler reads it and responds. The system tracks deadlines and logs an audit trail.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The price difference between €49/month and €5,000+/year is not explained by the Directive&amp;amp;rsquo;s requirements. It is explained by sales teams, enterprise packaging, AI features that no compliance officer asked for, and the assumption that &amp;amp;ldquo;compliance software&amp;amp;rdquo; can be priced like enterprise SaaS.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Many platforms on this list do not publish their pricing. You have to fill out a form, get on a call, sit through a demo, and then &amp;amp;mdash; maybe &amp;amp;mdash; receive a quote. For a tool that does what a spreadsheet could do (badly), this is absurd.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you are evaluating platforms, focus on three things:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Does it cover Art. 8&amp;amp;ndash;18?&amp;lt;/strong&amp;gt; All platforms above do, at their paid tiers.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is data hosted in the EU?&amp;lt;/strong&amp;gt; Non-negotiable for GDPR and Directive compliance.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Can you see the price and sign up today?&amp;lt;/strong&amp;gt; If a vendor will not show you the price, ask yourself what they are optimizing for.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;No whistleblower platform can make your organization compliant by itself. Compliance also requires internal policies, designated handlers, training, and documented procedures. The software is the reporting channel &amp;amp;mdash; one piece of a larger compliance framework. It should not be the most expensive or time-consuming piece.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For a detailed article-by-article breakdown of how EthicsPortal meets each requirement, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>What to look for in whistleblower compliance software</title><link>https://ethicsportal.eu/blog/whistleblower-software-is-a-form-and-a-database/</link><pubDate>Sun, 05 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblower-software-is-a-form-and-a-database/</guid><description>What a whistleblower reporting tool actually needs to do under EU Directive 2019/1937 — and what features matter vs. what&amp;#39;s just marketing.</description><content:encoded>&amp;lt;h1 id=&amp;#34;what-to-look-for-in-whistleblower-compliance-software&amp;#34;&amp;gt;
What to look for in whistleblower compliance software
&amp;lt;a href=&amp;#34;#what-to-look-for-in-whistleblower-compliance-software&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;The EU Whistleblower Protection Directive requires your organization to operate a secure internal reporting channel. But not all tools that claim Directive compliance actually deliver it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here&amp;amp;rsquo;s how to evaluate what matters.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-a-whistleblower-reporting-tool-actually-needs-to-do&amp;#34;&amp;gt;
What a whistleblower reporting tool actually needs to do
&amp;lt;a href=&amp;#34;#what-a-whistleblower-reporting-tool-actually-needs-to-do&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive&amp;amp;rsquo;s requirements translate into five core functions:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;A reporter submits a report through a secure channel.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The report is stored confidentially in an encrypted system.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;A designated case handler reviews it and responds.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The system tracks the 7-day acknowledgment and 3-month feedback deadlines.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Every action is recorded in an append-only audit trail.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;These five functions are the compliance baseline. Any tool you evaluate should demonstrate how it handles each one.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;features-that-matter-for-compliance&amp;#34;&amp;gt;
Features that matter for compliance
&amp;lt;a href=&amp;#34;#features-that-matter-for-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;When evaluating platforms, focus on what the Directive actually requires:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymous reporting&amp;lt;/strong&amp;gt; — Article 6(1) requires confidentiality. The strongest implementation means no IP logging, no tracking, and automatic stripping of file metadata (EXIF, GPS, author info) that could reveal identity.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Two-way communication&amp;lt;/strong&amp;gt; — Article 9(1)(b) requires follow-up with the reporter. This means secure messaging without requiring the reporter to create an account or reveal their identity.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deadline tracking&amp;lt;/strong&amp;gt; — Articles 9(1)(b) and 9(1)(f) set the 7-day acknowledgment and 3-month feedback deadlines. Automated tracking with notifications prevents compliance failures.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Audit trail&amp;lt;/strong&amp;gt; — Article 18 requires documentation. An append-only log of all actions provides the evidence regulators and auditors expect.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU data residency&amp;lt;/strong&amp;gt; — GDPR applies to all report data. Hosting within the EU simplifies compliance and avoids cross-border transfer questions.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data retention controls&amp;lt;/strong&amp;gt; — Article 17(1)(d) requires defined retention periods. Configurable auto-deletion ensures data isn&amp;amp;rsquo;t kept longer than necessary.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;features-that-sound-impressive-but-arent-in-the-directive&amp;#34;&amp;gt;
Features that sound impressive but aren&amp;amp;rsquo;t in the Directive
&amp;lt;a href=&amp;#34;#features-that-sound-impressive-but-arent-in-the-directive&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Some platforms emphasize capabilities that go beyond what compliance requires:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;AI-powered risk scoring&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Sentiment analysis&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Predictive analytics dashboards&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Benchmarking against 10,000+ organizations&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;These features may serve larger organizations with mature compliance programs. But they are not Directive requirements, and their presence doesn&amp;amp;rsquo;t make a tool more compliant. Evaluate whether they serve your actual needs before paying for them.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;pricing-transparency-as-a-signal&amp;#34;&amp;gt;
Pricing transparency as a signal
&amp;lt;a href=&amp;#34;#pricing-transparency-as-a-signal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive applies to organizations of very different sizes — from 50-person companies to multinational enterprises. The tool you choose should match your scale.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Some platforms publish their pricing openly. Others require a sales process to learn the cost. Neither approach is inherently better, but transparent pricing lets you evaluate fit faster and avoids committing time to demos before knowing whether the budget works.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-to-ask-during-evaluation&amp;#34;&amp;gt;
What to ask during evaluation
&amp;lt;a href=&amp;#34;#what-to-ask-during-evaluation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;When reviewing any whistleblower platform, ask:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Where is data stored?&amp;lt;/strong&amp;gt; Confirm EU hosting and data residency.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;How are reporters protected?&amp;lt;/strong&amp;gt; Verify IP anonymization and metadata stripping.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;How are deadlines tracked?&amp;lt;/strong&amp;gt; Confirm automatic 7-day and 3-month tracking with notifications.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is the audit trail append-only?&amp;lt;/strong&amp;gt; Ensure entries cannot be edited after creation.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;What happens when we cancel?&amp;lt;/strong&amp;gt; Understand data export and deletion policies.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is a DPA available?&amp;lt;/strong&amp;gt; Required for GDPR compliance as a data processor relationship.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-addresses-these-requirements&amp;#34;&amp;gt;
How EthicsPortal addresses these requirements
&amp;lt;a href=&amp;#34;#how-ethicsportal-addresses-these-requirements&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://ethicsportal.eu&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is built specifically for EU Directive 2019/1937 compliance:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;€49/month, all features included&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Anonymous reporting with IP anonymization and file metadata stripping&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Secure two-way messaging via access code&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Automatic deadline tracking with overdue notifications&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Append-only audit trail and PDF case export&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Hosted on Hetzner in Nuremberg, Germany — all data stays in the EU&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;See our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
for an article-by-article breakdown of how each requirement is met.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>If employees have to ask where the whistleblowing channel is, you don't have one</title><link>https://ethicsportal.eu/blog/if-employees-have-to-ask-you-dont-have-a-channel/</link><pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/if-employees-have-to-ask-you-dont-have-a-channel/</guid><description>EU law requires employers to inform workers about their reporting channel. But if finding it requires asking someone, the channel is already compromised.</description><content:encoded>&amp;lt;h1 id=&amp;#34;if-employees-have-to-ask-where-the-whistleblowing-channel-is-you-dont-have-one&amp;#34;&amp;gt;
If employees have to ask where the whistleblowing channel is, you don&amp;amp;rsquo;t have one
&amp;lt;a href=&amp;#34;#if-employees-have-to-ask-where-the-whistleblowing-channel-is-you-dont-have-one&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;An employee suspects fraud. They want to report it. Their first step should not be walking up to HR and asking &amp;amp;ldquo;do we have a whistleblowing channel?&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The act of asking is itself a signal. In the exact kind of workplace the Directive exists to address &amp;amp;mdash; where misconduct is happening and someone wants to report it &amp;amp;mdash; asking around about a reporting channel tells people that you are thinking about reporting something. Before you have typed a single word, you are exposed.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-law-is-clear-you-must-inform-employees&amp;#34;&amp;gt;
The law is clear: you must inform employees
&amp;lt;a href=&amp;#34;#the-law-is-clear-you-must-inform-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937 and its national transpositions (&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
in France, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
in Germany, the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
in Poland, and others) do not just require organizations to set up a reporting channel. They require them to make sure workers know about it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Article 9(1)(g)&amp;lt;/strong&amp;gt; mandates &amp;amp;ldquo;clear and easily accessible information&amp;amp;rdquo; about reporting procedures &amp;amp;mdash; both internal and external. This is not optional. If you have a reporting channel but your employees do not know it exists, you are not compliant with your national law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;National transpositions go further:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
§7(3), §13(2)):&amp;lt;/strong&amp;gt; Employers must provide &amp;amp;ldquo;clear and easily accessible information&amp;amp;rdquo; about both internal reporting procedures (§7(3)) and external reporting options (§13(2)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Loi Waserman, 2022-401&amp;lt;/a&amp;gt;
):&amp;lt;/strong&amp;gt; Companies must inform employees about reporting procedures and publish this information via accessible means.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Poland&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240000928&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Ustawa o ochronie sygnalistów&amp;lt;/a&amp;gt;
):&amp;lt;/strong&amp;gt; Employers must establish internal reporting procedures and publish them to all employees. The procedure takes effect 7 days after publication.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The pattern is the same everywhere: setting up the channel is half the job. Making employees aware of it is the other half.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-design-problem-nobody-talks-about&amp;#34;&amp;gt;
The design problem nobody talks about
&amp;lt;a href=&amp;#34;#the-design-problem-nobody-talks-about&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Most compliance discussions stop at &amp;amp;ldquo;inform employees&amp;amp;rdquo; and assume a company-wide email or an intranet page solves it. It does not.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Think about what actually happens:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 1: The channel is on the company intranet.&amp;lt;/strong&amp;gt;
The employee has to use their work computer, log into the corporate network, navigate to the compliance section, and click through to the reporting portal. Every step leaves a digital trail on a device their employer controls. The IT department can see what pages you visit on the intranet.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 2: The channel requires a company app.&amp;lt;/strong&amp;gt;
The employee has to download an app, possibly through a corporate MDM (mobile device management) system, and create an account. The act of installing a whistleblower app on your work phone is itself a statement.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 3: The channel is mentioned once in the employee handbook.&amp;lt;/strong&amp;gt;
Page 47, section 12.3, between the parking policy and the dress code. Nobody remembers it exists. When someone needs it, they have to ask. And asking is the problem.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-easily-accessible-actually-means&amp;#34;&amp;gt;
What &amp;amp;ldquo;easily accessible&amp;amp;rdquo; actually means
&amp;lt;a href=&amp;#34;#what-easily-accessible-actually-means&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you take the Directive&amp;amp;rsquo;s intent seriously &amp;amp;mdash; protecting people who report wrongdoing &amp;amp;mdash; then &amp;amp;ldquo;easily accessible&amp;amp;rdquo; means:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;The employee should be able to access the channel without:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Using a company device&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Being on the company network&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Installing an app&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Creating an account&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Asking anyone where to find it&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Leaving any trace that they looked for it&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This narrows the options considerably. The channel needs to be a &amp;lt;strong&amp;gt;public URL&amp;lt;/strong&amp;gt; that works in any browser on any device &amp;amp;mdash; including a personal phone on mobile data, completely outside the employer&amp;amp;rsquo;s infrastructure.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-to-make-the-channel-truly-accessible&amp;#34;&amp;gt;
How to make the channel truly accessible
&amp;lt;a href=&amp;#34;#how-to-make-the-channel-truly-accessible&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;1. A public URL, not an intranet page.&amp;lt;/strong&amp;gt;
The reporting portal should be accessible from any browser, on any device, without authentication. An employee at home, on their personal phone, at 11pm, should be able to type in a URL and start a report. No VPN, no login, no company email required.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;2. QR codes in private spaces.&amp;lt;/strong&amp;gt;
Print the QR code and put it where people can scan it without being watched: bathroom stalls, break rooms, locker rooms, the back of elevator doors. An employee scanning a QR code on a bathroom wall leaves no digital trail and draws no attention.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;3. Physical posters, not just emails.&amp;lt;/strong&amp;gt;
A company-wide email about the whistleblowing channel is easily missed and hard to find six months later. A poster on the wall of every office kitchen with a QR code and a URL is always there when someone needs it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;4. Mention it during onboarding &amp;amp;mdash; every time.&amp;lt;/strong&amp;gt;
New employee orientation should include the reporting channel URL and a printed card with the QR code. Not buried in a handbook. Handed to them directly.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;5. No account required.&amp;lt;/strong&amp;gt;
If the reporting tool requires the employee to create an account with their email address to file a report, it is not anonymous and it is not safe. The reporter should be able to submit without providing any identifying information and receive an access code to check back later.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;this-is-how-ethicsportal-works&amp;#34;&amp;gt;
This is how EthicsPortal works
&amp;lt;a href=&amp;#34;#this-is-how-ethicsportal-works&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every EthicsPortal organization gets a public reporting URL. It works on any browser, any device. No app, no account, no company network.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The portal generates a &amp;lt;strong&amp;gt;QR code&amp;lt;/strong&amp;gt; that can be printed and posted anywhere. Scan it, and you are on the reporting page. No login, no trail.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Reporters submit anonymously &amp;amp;mdash; no name, no email, no IP logging. They receive an access code to check back for updates. The entire interaction happens in a browser window that can be closed and leaves nothing behind.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The handler never sees the reporter&amp;amp;rsquo;s identity. The reporter never sees the handler&amp;amp;rsquo;s name. The system counts to 7 days, counts to 3 months, and logs everything.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is what &amp;amp;ldquo;easily accessible&amp;amp;rdquo; looks like when you take the Directive seriously.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;If your organization&amp;amp;rsquo;s whistleblowing channel requires employees to ask someone where to find it, you have a compliance checkbox. You do not have a reporting channel. &amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Set up a real one in ten minutes.&amp;lt;/a&amp;gt;
&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>GDPR and whistleblower reporting: what you need to know</title><link>https://ethicsportal.eu/blog/gdpr-and-whistleblower-reporting/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/gdpr-and-whistleblower-reporting/</guid><description>How GDPR applies to whistleblower reports. Legal basis for processing, anonymous vs. pseudonymous data, retention periods, and the right to erasure.</description><content:encoded>&amp;lt;h1 id=&amp;#34;gdpr-and-whistleblower-reporting-what-you-need-to-know&amp;#34;&amp;gt;
GDPR and whistleblower reporting: what you need to know
&amp;lt;a href=&amp;#34;#gdpr-and-whistleblower-reporting-what-you-need-to-know&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every whistleblower report contains personal data. The reporter may include their name. The report will likely name the person accused of wrongdoing. The handler&amp;amp;rsquo;s actions are logged. All of this is personal data under GDPR.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This creates a tension that compliance officers deal with every day: the Whistleblower Directive (2019/1937) requires you to collect and store reports, and GDPR requires you to have a lawful basis for doing so, minimize what you collect, and delete it when you no longer need it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is how the two frameworks interact, and what it means in practice.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-personal-data-does-a-whistleblower-report-contain&amp;#34;&amp;gt;
What personal data does a whistleblower report contain?
&amp;lt;a href=&amp;#34;#what-personal-data-does-a-whistleblower-report-contain&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;More than you might think:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Data&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;GDPR category&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;amp;rsquo;s name (if provided)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Voluntary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;amp;rsquo;s contact details (if provided)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Voluntary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Name of the accused person&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Report content&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data (third party)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Details of the alleged misconduct&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Report content&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;May include special category data (Art. 9) or criminal offence data (Art. 10)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Uploaded files (documents, photos)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;May contain metadata (GPS, author, timestamps)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Handler actions and notes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Case management&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data (handler)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Timestamps and audit trail&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;System&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;If a report describes harassment, discrimination, or health issues, it may contain &amp;lt;strong&amp;gt;special category data&amp;lt;/strong&amp;gt; under GDPR Article 9 &amp;amp;mdash; which triggers stricter processing conditions. Reports involving criminal allegations fall under &amp;lt;strong&amp;gt;Article 10&amp;lt;/strong&amp;gt; (criminal convictions and offences), which has its own restrictions.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-is-the-legal-basis-for-processing&amp;#34;&amp;gt;
What is the legal basis for processing?
&amp;lt;a href=&amp;#34;#what-is-the-legal-basis-for-processing&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;You need a lawful basis under GDPR Article 6 to process personal data in whistleblower reports. The most commonly used bases:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61c--legal-obligation&amp;#34;&amp;gt;
Article 6(1)(c) &amp;amp;mdash; Legal obligation
&amp;lt;a href=&amp;#34;#article-61c--legal-obligation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This is the primary basis. EU Directive 2019/1937 and its national transpositions impose a legal obligation to operate a reporting channel. Processing personal data is necessary to comply with that obligation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This covers:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Receiving the report&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Storing it securely&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Investigating the allegations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Communicating with the reporter&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Maintaining an audit trail&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61f--legitimate-interest&amp;#34;&amp;gt;
Article 6(1)(f) &amp;amp;mdash; Legitimate interest
&amp;lt;a href=&amp;#34;#article-61f--legitimate-interest&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Some organizations use legitimate interest as a secondary basis, particularly for processing that goes beyond the Directive&amp;amp;rsquo;s minimum requirements (e.g., internal analysis, trend reporting). This requires a legitimate interest assessment (LIA) and balancing test.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61e--public-interest-public-sector&amp;#34;&amp;gt;
Article 6(1)(e) &amp;amp;mdash; Public interest (public sector)
&amp;lt;a href=&amp;#34;#article-61e--public-interest-public-sector&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Public sector organizations may rely on the public interest basis, particularly where national law explicitly authorizes processing for whistleblower protection.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;what-about-consent&amp;#34;&amp;gt;
What about consent?
&amp;lt;a href=&amp;#34;#what-about-consent&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Do not rely on consent.&amp;lt;/strong&amp;gt; The reporter-employer power imbalance means consent is unlikely to be freely given (GDPR Recital 43). A reporter cannot meaningfully consent when their job may depend on the outcome. Use legal obligation (Art. 6(1)(c)) instead.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;anonymous-reports-and-gdpr&amp;#34;&amp;gt;
Anonymous reports and GDPR
&amp;lt;a href=&amp;#34;#anonymous-reports-and-gdpr&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This is the question compliance officers ask most: if a report is truly anonymous, does GDPR apply?&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;if-the-reporter-is-unidentifiable-gdpr-does-not-apply-to-them&amp;#34;&amp;gt;
If the reporter is unidentifiable: GDPR does not apply to them
&amp;lt;a href=&amp;#34;#if-the-reporter-is-unidentifiable-gdpr-does-not-apply-to-them&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;GDPR applies to personal data relating to an identified or identifiable person (Art. 4(1)). If a reporter submits without providing a name, email, or any identifying information &amp;amp;mdash; and the system does not log their IP address or any other identifier &amp;amp;mdash; the report content is not personal data &amp;lt;em&amp;gt;with respect to the reporter&amp;lt;/em&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;However:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;The &amp;lt;strong&amp;gt;accused person&amp;lt;/strong&amp;gt; named in the report is still identifiable. GDPR fully applies to their data.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;If the report content contains details that could indirectly identify the reporter (&amp;amp;ldquo;I am the only woman on the third floor&amp;amp;rdquo;), it may still constitute personal data.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;what-anonymous-requires-technically&amp;#34;&amp;gt;
What &amp;amp;ldquo;anonymous&amp;amp;rdquo; requires technically
&amp;lt;a href=&amp;#34;#what-anonymous-requires-technically&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;For anonymity to hold up under GDPR scrutiny, your reporting tool must:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not log IP addresses.&amp;lt;/strong&amp;gt; Any IP logging makes the reporter pseudonymous, not anonymous.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not require an account or email.&amp;lt;/strong&amp;gt; If the reporter authenticates, they are identifiable.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Strip file metadata.&amp;lt;/strong&amp;gt; Uploaded photos and documents contain EXIF data (GPS coordinates, author name, device information) that can identify the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not use analytics or tracking cookies&amp;lt;/strong&amp;gt; on the reporting portal.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;If your tool does any of these things, you are collecting pseudonymous data, not anonymous data, and GDPR applies in full.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;data-minimization-art-51c&amp;#34;&amp;gt;
Data minimization (Art. 5(1)(c))
&amp;lt;a href=&amp;#34;#data-minimization-art-51c&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive requires a reporting channel. It does not require collecting more data than necessary.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In practice:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reporter identity must be optional.&amp;lt;/strong&amp;gt; The reporter should be able to submit without providing their name or contact details.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Intake forms should collect only what is needed.&amp;lt;/strong&amp;gt; A description of the misconduct, the category, and optional supporting files. Do not require department, employee ID, or other identifiers unless the reporter chooses to provide them.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Handler notes should be relevant to the investigation.&amp;lt;/strong&amp;gt; Do not log extraneous personal details about the reporter or accused.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-accused-persons-rights&amp;#34;&amp;gt;
The accused person&amp;amp;rsquo;s rights
&amp;lt;a href=&amp;#34;#the-accused-persons-rights&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This is where it gets complicated. The person accused in a whistleblower report has GDPR rights &amp;amp;mdash; including the right to be informed (Art. 14), the right of access (Art. 15), and the right to erasure (Art. 17).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;But exercising those rights cannot compromise the reporter&amp;amp;rsquo;s confidentiality (Directive Art. 16).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;right-to-be-informed-art-14&amp;#34;&amp;gt;
Right to be informed (Art. 14)
&amp;lt;a href=&amp;#34;#right-to-be-informed-art-14&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Under GDPR, you must inform people when you process their data. But Directive Art. 16(1) requires protecting the reporter&amp;amp;rsquo;s identity. The solution:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;You &amp;lt;strong&amp;gt;may&amp;lt;/strong&amp;gt; inform the accused person that a report has been made &amp;amp;mdash; but only when doing so does not risk identifying the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Timing matters.&amp;lt;/strong&amp;gt; Many member states allow delaying notification until it would no longer jeopardize the investigation. Germany&amp;amp;rsquo;s HinSchG explicitly restricts disclosure during the investigation period.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;National data protection authorities generally accept that the Directive&amp;amp;rsquo;s confidentiality requirements override the immediate notification obligation.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;right-of-access-art-15&amp;#34;&amp;gt;
Right of access (Art. 15)
&amp;lt;a href=&amp;#34;#right-of-access-art-15&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The accused person can request access to data held about them. You must provide it &amp;amp;mdash; but you must redact any information that would identify the reporter. This includes the reporter&amp;amp;rsquo;s name, but also contextual details that could reveal them indirectly.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;right-to-erasure-art-17&amp;#34;&amp;gt;
Right to erasure (Art. 17)
&amp;lt;a href=&amp;#34;#right-to-erasure-art-17&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The accused person cannot demand deletion of a report that is part of an ongoing investigation or that must be retained under legal obligations. GDPR Art. 17(3)(b) and (e) provide exceptions for legal obligations and legal claims.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;retention-periods&amp;#34;&amp;gt;
Retention periods
&amp;lt;a href=&amp;#34;#retention-periods&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive (Art. 18) requires maintaining records of reports. GDPR (Art. 5(1)(e)) requires not keeping personal data longer than necessary.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;how-long-should-you-retain-reports&amp;#34;&amp;gt;
How long should you retain reports?
&amp;lt;a href=&amp;#34;#how-long-should-you-retain-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive does not prescribe a specific retention period. National transpositions vary:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Country&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Retention period&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;5 years after case closure&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000046357368&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Decree 2022-1284&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;5 years from date of report&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;D.Lgs. 24/2023, Art. 14&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;3 years after case closure (unless ongoing proceedings)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG §11&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Spain&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Not specified (general GDPR minimization applies)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;h3 id=&amp;#34;best-practice&amp;#34;&amp;gt;
Best practice
&amp;lt;a href=&amp;#34;#best-practice&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Set a configurable retention period (e.g., 12, 24, 36, or 60 months after case closure).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Automatically delete closed cases when the retention period expires.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Allow manual deletion by admins for cases where retention is no longer necessary.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Document your retention policy and be prepared to justify it to a regulator.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;international-data-transfers&amp;#34;&amp;gt;
International data transfers
&amp;lt;a href=&amp;#34;#international-data-transfers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Whistleblower data must stay in the EU unless you have a valid transfer mechanism under GDPR Chapter V.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This matters when choosing a reporting tool:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU-hosted platforms&amp;lt;/strong&amp;gt; (data stored in Germany, France, Netherlands, etc.): no transfer issue.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;US-hosted platforms&amp;lt;/strong&amp;gt; or platforms using US cloud providers (AWS US, Azure US, Google Cloud US): require reliance on Standard Contractual Clauses (SCCs) or the &amp;lt;a href=&amp;#34;https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU-US Data Privacy Framework&amp;lt;/a&amp;gt;
&amp;amp;mdash; both of which have been &amp;lt;a href=&amp;#34;https://curia.europa.eu/juris/liste.jsf?num=C-311/18&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;legally challenged&amp;lt;/a&amp;gt;
.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The simplest path: choose a platform that hosts all data in the EU. This eliminates the transfer question entirely.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;data-protection-impact-assessment-dpia&amp;#34;&amp;gt;
Data Protection Impact Assessment (DPIA)
&amp;lt;a href=&amp;#34;#data-protection-impact-assessment-dpia&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;GDPR Article 35 requires a DPIA when processing is &amp;amp;ldquo;likely to result in a high risk to the rights and freedoms of natural persons.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Whistleblower reporting likely qualifies because:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;It involves sensitive allegations about identified individuals&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reports may contain special category data (Art. 9)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;There is an inherent power imbalance between reporter and organization&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Confidentiality failures could lead to retaliation&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Most data protection authorities recommend conducting a DPIA before implementing a whistleblower reporting system.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-your-reporting-tool-must-do&amp;#34;&amp;gt;
What your reporting tool must do
&amp;lt;a href=&amp;#34;#what-your-reporting-tool-must-do&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Based on the GDPR requirements above, your whistleblower software should:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Why&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Optional reporter identity&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Data minimization (Art. 5(1)(c))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;No IP logging&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Preserve anonymity, avoid creating pseudonymous data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;File metadata stripping&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Prevent accidental identification via EXIF/GPS data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Encryption at rest&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Integrity and confidentiality (Art. 5(1)(f))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Configurable retention periods&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Storage limitation (Art. 5(1)(e))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Automatic deletion of expired cases&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Storage limitation enforcement&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Role-based access controls&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Directive Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Append-only audit trail&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Accountability (Art. 5(2))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EU data hosting&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Avoid international transfer complications (Chapter V)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Privacy notice on the reporting form&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Transparency (Art. 13/14)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-handles-gdpr&amp;#34;&amp;gt;
How EthicsPortal handles GDPR
&amp;lt;a href=&amp;#34;#how-ethicsportal-handles-gdpr&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal was designed with both the Directive and GDPR as constraints from day one:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Legal basis:&amp;lt;/strong&amp;gt; Processing is based on legal obligation (Art. 6(1)(c)) &amp;amp;mdash; compliance with EU Directive 2019/1937.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymity by default:&amp;lt;/strong&amp;gt; No IP logging, no accounts, no tracking. File metadata (EXIF, GPS, author) stripped automatically.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data minimization:&amp;lt;/strong&amp;gt; Reporter name and contact are optional fields. Only essential data is collected.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Encryption at rest:&amp;lt;/strong&amp;gt; All report descriptions, names, contact details, and messages encrypted in the database.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Configurable retention:&amp;lt;/strong&amp;gt; Organizations set their own retention period (12, 24, 36, or 60 months). Expired closed cases are deleted automatically.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU hosting for core report data:&amp;lt;/strong&amp;gt; Report content and attachments are stored on Hetzner servers in Nuremberg, Germany. The marketing site is delivered via Cloudflare (CDN, United States); the reporting and handler portals are not. Transfer safeguards for the marketing site are documented in the published subprocessor list and DPA.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Access controls:&amp;lt;/strong&amp;gt; Only admins and assigned handlers can view reports. Handler names are never revealed to reporters.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Audit trail:&amp;lt;/strong&amp;gt; Append-only log of every action for accountability and regulatory review.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;DPA available:&amp;lt;/strong&amp;gt; GDPR Article 28 &amp;lt;a href=&amp;#34;/dpa/&amp;#34;&amp;gt;Data Processing Agreement&amp;lt;/a&amp;gt;
available for all customers.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;For the full article-by-article breakdown, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Free whistleblower policy template for EU Directive 2019/1937</title><link>https://ethicsportal.eu/blog/whistleblower-policy-template/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblower-policy-template/</guid><description>A ready-to-use whistleblower policy template that meets EU Directive 2019/1937 requirements. Copy, adapt, and implement in your organization.</description><content:encoded>&amp;lt;h1 id=&amp;#34;free-whistleblower-policy-template-for-eu-directive-20191937&amp;#34;&amp;gt;
Free whistleblower policy template for EU Directive 2019/1937
&amp;lt;a href=&amp;#34;#free-whistleblower-policy-template-for-eu-directive-20191937&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every organization with 50 or more employees in the EU needs a written whistleblower policy. This is not optional &amp;amp;mdash; it is required under national transposition laws like &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland), all implementing EU Directive 2019/1937. Penalties for non-compliance vary by country &amp;amp;mdash; see our &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties page&amp;lt;/a&amp;gt;
for details.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A whistleblower policy does two things: it tells employees how to report wrongdoing, and it tells your organization how to handle those reports. Without a clear policy, reports fall through the cracks, handlers improvise, and your organization risks both legal exposure and reputational damage.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Below is a complete policy template you can copy and adapt. Replace the bracketed placeholders with your organization&amp;amp;rsquo;s details. The template covers every element the Directive requires.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;whistleblower-policy-template&amp;#34;&amp;gt;
Whistleblower policy template
&amp;lt;a href=&amp;#34;#whistleblower-policy-template&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;[ORGANIZATION NAME]&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Whistleblower protection policy&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Effective date:&amp;lt;/strong&amp;gt; [DATE]&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Approved by:&amp;lt;/strong&amp;gt; [NAME / TITLE]&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Version:&amp;lt;/strong&amp;gt; 1.0&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;1-purpose-and-scope&amp;#34;&amp;gt;
1. Purpose and scope
&amp;lt;a href=&amp;#34;#1-purpose-and-scope&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This policy establishes a framework for reporting suspected breaches of law, regulation, or internal rules within [ORGANIZATION NAME]. It implements the requirements of EU Directive 2019/1937 on the protection of persons who report breaches of Union law, as transposed into [MEMBER STATE] national law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This policy applies to all operations, subsidiaries, and business units of [ORGANIZATION NAME] within the European Union.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;2-who-can-report&amp;#34;&amp;gt;
2. Who can report
&amp;lt;a href=&amp;#34;#2-who-can-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;In accordance with Article 4 of the Directive, the following persons may submit a report through the channels described in this policy:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Current and former employees, including those on probation or notice periods&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Job applicants who obtained information during the recruitment process&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Contractors, subcontractors, and suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Shareholders and members of the administrative, management, or supervisory body&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Volunteers and trainees, whether paid or unpaid&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Any person working under the supervision and direction of contractors, subcontractors, or suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Persons whose work-based relationship has not yet begun, where information on breaches was acquired during the recruitment process or pre-contractual negotiations&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Protection also extends to facilitators, third persons connected with the reporting person (such as colleagues or relatives), and legal entities that the reporting person owns, works for, or is otherwise connected with in a work-related context (Article 4(4)).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;3-what-can-be-reported&amp;#34;&amp;gt;
3. What can be reported
&amp;lt;a href=&amp;#34;#3-what-can-be-reported&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports may concern breaches of Union law in the areas covered by the Directive (Article 2), including but not limited to:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Public procurement irregularities&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Financial services, anti-money laundering, and counter-terrorist financing violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Product safety and compliance breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Transport safety violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Environmental protection breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Radiation protection and nuclear safety issues&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Food and feed safety, animal health and welfare concerns&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Public health violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Consumer protection breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Privacy and personal data protection violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Security of network and information systems&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Competition and state aid rule breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Corporate tax arrangements that undermine the object or purpose of applicable tax law&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Fraud, corruption, or other criminal offenses affecting the financial interests of the EU&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Reports may also concern breaches of internal company policies, codes of conduct, and applicable national law, provided [MEMBER STATE] national transposition law extends protection to such reports.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;4-how-to-report&amp;#34;&amp;gt;
4. How to report
&amp;lt;a href=&amp;#34;#4-how-to-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;h4 id=&amp;#34;internal-reporting-channel&amp;#34;&amp;gt;
Internal reporting channel
&amp;lt;a href=&amp;#34;#internal-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] provides a secure, confidential internal reporting channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Online portal:&amp;lt;/strong&amp;gt; [URL OF REPORTING PORTAL]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designated person:&amp;lt;/strong&amp;gt; [NAME / TITLE OF DESIGNATED PERSON OR DEPARTMENT]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Alternative methods:&amp;lt;/strong&amp;gt; [POSTAL ADDRESS / EMAIL / IN-PERSON MEETING REQUEST PROCESS, as applicable]&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Reports can be submitted anonymously. Reporters who choose to remain anonymous will receive an access code to check the status of their report and communicate securely with the case handler.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] encourages the use of the internal reporting channel as a first step, as this allows the organization to investigate and address breaches promptly.&amp;lt;/p&amp;gt;
&amp;lt;h4 id=&amp;#34;external-reporting-to-competent-authorities&amp;#34;&amp;gt;
External reporting to competent authorities
&amp;lt;a href=&amp;#34;#external-reporting-to-competent-authorities&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;Reporting persons have the right to report externally to the relevant competent authority at any time, as provided under Article 10 of the Directive. Reporting persons are not required to use the internal channel before reporting externally.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The competent authority in [MEMBER STATE] is: [NAME AND CONTACT DETAILS OF NATIONAL AUTHORITY].&amp;lt;/p&amp;gt;
&amp;lt;h4 id=&amp;#34;public-disclosure&amp;#34;&amp;gt;
Public disclosure
&amp;lt;a href=&amp;#34;#public-disclosure&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;In exceptional circumstances defined in Article 15 of the Directive, reporting persons may make a public disclosure and still receive protection &amp;amp;mdash; for example, where they have reasonable grounds to believe that the breach constitutes an imminent or manifest danger to the public interest, or where there is a risk of retaliation.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;5-confidentiality&amp;#34;&amp;gt;
5. Confidentiality
&amp;lt;a href=&amp;#34;#5-confidentiality&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person will not be disclosed to anyone beyond the authorized staff members competent to receive or follow up on reports, without the explicit consent of the reporting person (Article 16).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This confidentiality obligation applies to all information from which the identity of the reporting person may be directly or indirectly deduced.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person may only be disclosed where this is a necessary and proportionate obligation imposed under Union or national law in the context of investigations by national authorities or judicial proceedings, including with a view to safeguarding the rights of defense of the person concerned.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Any person who discloses the identity of a reporting person in violation of this policy will be subject to disciplinary action.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;6-prohibition-of-retaliation&amp;#34;&amp;gt;
6. Prohibition of retaliation
&amp;lt;a href=&amp;#34;#6-prohibition-of-retaliation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] strictly prohibits any form of retaliation against reporting persons, in accordance with Articles 19 to 21 of the Directive. Retaliation includes, but is not limited to:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Suspension, dismissal, or equivalent measures&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Demotion, withholding of promotion, or change of duties or work location&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reduction of wages or changes to working hours&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Withholding of training&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Negative performance assessment or employment reference&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Coercion, intimidation, harassment, or ostracism&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Discrimination or unfavorable treatment&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Failure to convert a temporary employment contract into a permanent one&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Non-renewal or early termination of a temporary employment contract&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Harm, including to reputation or financial loss&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Blacklisting&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Early termination or cancellation of a contract for goods or services&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Cancellation of a license or permit&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Psychiatric or medical referrals&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The burden of proof in retaliation proceedings is reversed: where a reporting person establishes that they made a report and subsequently suffered a detriment, it is presumed that the detriment was made in retaliation. The person who took the detrimental action must prove it was based on duly justified grounds unrelated to the report (Article 21(5)).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Any employee found to have engaged in retaliation will be subject to disciplinary action, up to and including termination.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;7-investigation-process&amp;#34;&amp;gt;
7. Investigation process
&amp;lt;a href=&amp;#34;#7-investigation-process&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Upon receipt of a report, [ORGANIZATION NAME] will:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Acknowledge receipt&amp;lt;/strong&amp;gt; within seven calendar days of receiving the report (Article 9(1)(b)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Assess the report&amp;lt;/strong&amp;gt; to determine whether it falls within the scope of this policy and warrants investigation.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Investigate diligently&amp;lt;/strong&amp;gt; by gathering relevant information, interviewing witnesses as necessary, and reviewing documents, while maintaining confidentiality throughout.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Provide feedback&amp;lt;/strong&amp;gt; to the reporting person within three months of acknowledgment. Feedback will include information on the status of the investigation and, where possible, the outcome and any measures taken or envisaged (Article 9(1)(f)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Close the case&amp;lt;/strong&amp;gt; with documented findings and, where appropriate, recommend corrective actions, disciplinary measures, or referral to competent authorities.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;Where a report is assessed as falling outside the scope of this policy, the reporting person will be informed and, where appropriate, redirected to the relevant procedure.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;8-data-protection&amp;#34;&amp;gt;
8. Data protection
&amp;lt;a href=&amp;#34;#8-data-protection&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports and all related data will be processed in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Personal data that is manifestly not relevant to the handling of a specific report will not be collected or, if accidentally collected, will be deleted without undue delay (Article 17(3)).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Report data will be retained for no longer than is necessary and proportionate to comply with the requirements of this policy and applicable law. [ORGANIZATION NAME] will define and document specific retention periods in accordance with national transposition law.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;9-training-and-awareness&amp;#34;&amp;gt;
9. Training and awareness
&amp;lt;a href=&amp;#34;#9-training-and-awareness&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] will:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Train all designated case handlers on their obligations under this policy and applicable law&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Inform all employees and other persons covered by Section 2 about the availability and use of the internal reporting channel&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Make this policy easily accessible, including on the company intranet and as part of the onboarding process for new employees&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;10-review&amp;#34;&amp;gt;
10. Review
&amp;lt;a href=&amp;#34;#10-review&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This policy will be reviewed at least annually and updated as necessary to reflect changes in applicable law, organizational structure, or best practices.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;11-contact&amp;#34;&amp;gt;
11. Contact
&amp;lt;a href=&amp;#34;#11-contact&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;For questions about this policy or the reporting channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designated person:&amp;lt;/strong&amp;gt; [NAME / TITLE]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Email:&amp;lt;/strong&amp;gt; [EMAIL ADDRESS]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reporting portal:&amp;lt;/strong&amp;gt; [URL]&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;End of policy document.&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;using-this-template&amp;#34;&amp;gt;
Using this template
&amp;lt;a href=&amp;#34;#using-this-template&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Copy the text above into your company&amp;amp;rsquo;s document format, replace every bracketed placeholder, and have it reviewed by your legal team. The template covers the requirements of Directive 2019/1937, but national transposition laws in your member state may impose additional obligations &amp;amp;mdash; check with local counsel.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Once your policy is in place, you need a technical channel to receive reports. &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
provides a secure, anonymous reporting portal that meets the Directive&amp;amp;rsquo;s requirements for internal channels &amp;amp;mdash; set up in minutes, starting at €49/month.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Who must comply with the EU Whistleblower Directive?</title><link>https://ethicsportal.eu/blog/who-must-comply-eu-whistleblower-directive/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/who-must-comply-eu-whistleblower-directive/</guid><description>Which companies need a whistleblowing channel under EU Directive 2019/1937? The 50-employee threshold, who counts as a worker, deadlines, and what &amp;#34;comply&amp;#34; actually means in practice.</description><content:encoded>&amp;lt;h1 id=&amp;#34;who-must-comply-with-the-eu-whistleblower-directive&amp;#34;&amp;gt;
Who must comply with the EU Whistleblower Directive?
&amp;lt;a href=&amp;#34;#who-must-comply-with-the-eu-whistleblower-directive&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Short answer: if your organization has 50 or more employees and operates in the EU, you almost certainly need an internal whistleblower reporting channel. This is not optional. It is law in all 27 EU member states.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is everything you need to know to determine whether you must comply, what compliance actually requires, and what happens if you do not.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-threshold-50-employees&amp;#34;&amp;gt;
The threshold: 50 employees
&amp;lt;a href=&amp;#34;#the-threshold-50-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937, Article 8(3)-(4), establishes the obligation:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;250+ employees:&amp;lt;/strong&amp;gt; Must have had an internal reporting channel since December 17, 2021 (the original transposition deadline per &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Art. 26(1)&amp;lt;/a&amp;gt;
).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;50&amp;amp;ndash;249 employees:&amp;lt;/strong&amp;gt; Must have had an internal reporting channel since December 17, 2023 (extended deadline per &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Art. 26(2)&amp;lt;/a&amp;gt;
).&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;If you have 50 or more employees in the EU, the deadline has already passed. You should have a channel in place now.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;how-employees-are-counted&amp;#34;&amp;gt;
How employees are counted
&amp;lt;a href=&amp;#34;#how-employees-are-counted&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive does not define &amp;amp;ldquo;employee&amp;amp;rdquo; narrowly. Member states count:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Full-time and part-time employees (part-time may be counted proportionally in some countries)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Fixed-term and temporary workers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;In some member states: posted workers, trainees, and apprentices&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The count is based on your legal entity, not your group. If you are part of a corporate group, each entity with 50+ employees needs its own channel &amp;amp;mdash; though entities of 50&amp;amp;ndash;249 employees may share resources for receiving and investigating reports (Art. 8(6)).&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;who-is-covered-beyond-headcount&amp;#34;&amp;gt;
Who is covered beyond headcount
&amp;lt;a href=&amp;#34;#who-is-covered-beyond-headcount&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Several categories of organizations must comply regardless of employee count:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;financial-services-art-84&amp;#34;&amp;gt;
&amp;lt;a href=&amp;#34;/industries/financial-services/&amp;#34;&amp;gt;Financial services&amp;lt;/a&amp;gt;
(Art. 8(4))
&amp;lt;a href=&amp;#34;#financial-services-art-84&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;All entities operating in financial services &amp;amp;mdash; banks, investment firms, insurance companies, payment institutions, crypto-asset providers &amp;amp;mdash; must have a reporting channel irrespective of size. This applies even if you have 5 employees. The Directive defers to the sector-specific EU legislation listed in Part I.B and Part II of the Annex.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;public-sector-art-89&amp;#34;&amp;gt;
&amp;lt;a href=&amp;#34;/industries/public-sector/&amp;#34;&amp;gt;Public sector&amp;lt;/a&amp;gt;
(Art. 8(9))
&amp;lt;a href=&amp;#34;#public-sector-art-89&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Member states may require municipalities and other public bodies to establish internal channels. Many have done so, often with lower thresholds or no threshold at all.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;national-extensions&amp;#34;&amp;gt;
National extensions
&amp;lt;a href=&amp;#34;#national-extensions&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Some member states go beyond the Directive&amp;amp;rsquo;s minimum:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; Organizations with a &amp;amp;ldquo;Model 231&amp;amp;rdquo; compliance program must comply regardless of size. &amp;lt;a href=&amp;#34;https://www.nortonrosefulbright.com/en-it/knowledge/publications/5ff4d59b/whistleblowing-i-nuovi-obblighi-per-le-imprese&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Source: Norton Rose Fulbright&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/belgium/&amp;#34;&amp;gt;Belgium&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; Companies with 250+ employees must accept anonymous reports (stricter than the Directive&amp;amp;rsquo;s baseline). &amp;lt;a href=&amp;#34;https://www.vow.be/en/node/358&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Source: Van Olmen &amp;amp;amp; Wynant&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; The &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Loi Waserman (2022-401)&amp;lt;/a&amp;gt;
transposing the Directive removed the requirement to use internal channels before going to external authorities &amp;amp;mdash; reporters can now choose either path. &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/loda/id/JORFTEXT000033558528&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Sapin II&amp;amp;rsquo;s&amp;lt;/a&amp;gt;
broader anti-corruption compliance obligations (separate from the whistleblower channel) still apply to companies with 500+ employees and €100M+ revenue.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;who-can-report&amp;#34;&amp;gt;
Who can report
&amp;lt;a href=&amp;#34;#who-can-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive protects a broad category of &amp;amp;ldquo;reporting persons&amp;amp;rdquo; &amp;amp;mdash; not just employees. Under Article 4, the following people are protected when they report through your channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Workers&amp;lt;/strong&amp;gt; (employees, civil servants, interns, trainees)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Self-employed persons&amp;lt;/strong&amp;gt; (contractors, freelancers)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Shareholders and board members&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Volunteers&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Suppliers and their workers&amp;lt;/strong&amp;gt; (anyone in your supply chain)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Job applicants&amp;lt;/strong&amp;gt; (people who learned of wrongdoing during the recruitment process)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Former workers&amp;lt;/strong&amp;gt; (people who learned of wrongdoing during a previous employment)&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Your reporting channel must be accessible to all of these groups, not just current employees.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-compliance-actually-requires&amp;#34;&amp;gt;
What compliance actually requires
&amp;lt;a href=&amp;#34;#what-compliance-actually-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Having a channel means meeting the requirements in Articles 8, 9, and 16 of the Directive. Here is the minimum:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;1-a-secure-reporting-channel-art-8&amp;#34;&amp;gt;
1. A secure reporting channel (Art. 8)
&amp;lt;a href=&amp;#34;#1-a-secure-reporting-channel-art-8&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An internal channel that allows reporting in writing (and optionally orally). It must:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Be accessible to all persons covered by the Directive (employees, contractors, suppliers, etc.)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Protect the confidentiality of the reporter&amp;amp;rsquo;s identity&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Not require the reporter to identify themselves (anonymous reporting is permitted in most member states)&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;2-a-documented-procedure-art-9&amp;#34;&amp;gt;
2. A documented procedure (Art. 9)
&amp;lt;a href=&amp;#34;#2-a-documented-procedure-art-9&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The channel must follow a defined procedure:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Deadline&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Article&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Acknowledge receipt of the report&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Within 7 days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Assign an impartial person or department to handle it&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Upon receipt&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(a)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Follow up diligently&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Ongoing&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(c)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Provide feedback to the reporter&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Within 3 months&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(f)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Inform the reporter of external reporting options&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;At submission&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(g)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;h3 id=&amp;#34;3-confidentiality-protections-art-16&amp;#34;&amp;gt;
3. Confidentiality protections (Art. 16)
&amp;lt;a href=&amp;#34;#3-confidentiality-protections-art-16&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity must not be disclosed to anyone beyond the staff handling the report, without the reporter&amp;amp;rsquo;s explicit consent. This means:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Access controls: only authorized handlers see reports&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;No IP logging or tracking that could identify anonymous reporters&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Data encrypted at rest&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;4-record-keeping-art-18&amp;#34;&amp;gt;
4. Record-keeping (Art. 18)
&amp;lt;a href=&amp;#34;#4-record-keeping-art-18&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports must be stored securely and retained in compliance with national law. You need an audit trail that can demonstrate compliance to regulators.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;5-anti-retaliation-measures-art-1921&amp;#34;&amp;gt;
5. Anti-retaliation measures (Art. 19&amp;amp;ndash;21)
&amp;lt;a href=&amp;#34;#5-anti-retaliation-measures-art-1921&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;You must not retaliate against reporters. This includes dismissal, demotion, withholding promotion, changing duties, or any other form of disadvantage. Reporters must be informed of this protection.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-does-not-count-as-compliance&amp;#34;&amp;gt;
What does NOT count as compliance
&amp;lt;a href=&amp;#34;#what-does-not-count-as-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Some things organizations try that do not meet the Directive&amp;amp;rsquo;s requirements:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A generic email address&amp;lt;/strong&amp;gt; (e.g., &amp;lt;a href=&amp;#34;mailto:compliance@company.com&amp;#34;&amp;gt;compliance@company.com&amp;lt;/a&amp;gt;
). This does not protect confidentiality, does not track deadlines, and does not create an audit trail.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;An anonymous suggestion box.&amp;lt;/strong&amp;gt; No two-way communication, no acknowledgment, no feedback mechanism.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A page in the employee handbook.&amp;lt;/strong&amp;gt; The channel must be operational, not just documented.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A third-party hotline with no case management.&amp;lt;/strong&amp;gt; If reports come in by phone but are not tracked through a system with deadlines and audit trails, you are not compliant with Art. 9.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-happens-if-you-do-not-comply&amp;#34;&amp;gt;
What happens if you do not comply
&amp;lt;a href=&amp;#34;#what-happens-if-you-do-not-comply&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every member state has defined penalties. They vary widely:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Country&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Penalty for no reporting channel&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spain&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Up to €1,000,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Belgium&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€24,000&amp;amp;ndash;€576,000 + up to 3 years prison&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://cms.law/en/int/expert-guides/whistleblower-protection-and-reporting-channels/belgium&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;CMS Expert Guide&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Germany&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€20,000&amp;amp;ndash;€500,000 (legal entities)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/hinschg/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG §40&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Italy&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€10,000&amp;amp;ndash;€50,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;D.Lgs. 24/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Poland&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Up to PLN 1,080,000 (~€250,000)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240000928&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;Enforcement is not theoretical. In March 2025, the &amp;lt;a href=&amp;#34;https://eucrim.eu/news/ecj-ordered-several-member-states-to-financial-penalties-for-failing-to-transpose-whistleblowers-directive/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU Court of Justice fined five member states a combined €39 million&amp;lt;/a&amp;gt;
for being late to transpose the Directive. National enforcement authorities are now operational in most countries and actively issuing fines.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;See our full &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties by country&amp;lt;/a&amp;gt;
page for all 27 member states.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-fastest-path-to-compliance&amp;#34;&amp;gt;
The fastest path to compliance
&amp;lt;a href=&amp;#34;#the-fastest-path-to-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If your organization has 50+ employees, the deadline has passed. Here is how to get compliant:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Set up a reporting channel.&amp;lt;/strong&amp;gt; &amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
takes minutes &amp;amp;mdash; sign up, configure your portal, share the link. €49/month, everything included.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designate a handler.&amp;lt;/strong&amp;gt; Assign at least one impartial person to receive and investigate reports.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Inform employees.&amp;lt;/strong&amp;gt; Share the portal URL and QR code via posters, onboarding materials, and internal communications.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Document your procedure.&amp;lt;/strong&amp;gt; Adopt an internal whistleblower protection policy that describes the process, deadlines, and anti-retaliation protections.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;The software is the easy part. The entire setup &amp;amp;mdash; channel, configuration, QR code &amp;amp;mdash; can be done in a lunch break. The organizational steps (handler designation, policy, training) take longer but are straightforward.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For an article-by-article breakdown of how EthicsPortal meets the Directive&amp;amp;rsquo;s requirements, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Anonymous vs. confidential whistleblower reporting: what's the difference?</title><link>https://ethicsportal.eu/blog/anonymous-vs-confidential-reporting/</link><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/anonymous-vs-confidential-reporting/</guid><description>Understand the difference between anonymous and confidential whistleblower reporting, what the EU Directive requires, and how to support both.</description><content:encoded>&amp;lt;h1 id=&amp;#34;anonymous-vs-confidential-whistleblower-reporting-whats-the-difference&amp;#34;&amp;gt;
Anonymous vs. confidential whistleblower reporting: what&amp;amp;rsquo;s the difference?
&amp;lt;a href=&amp;#34;#anonymous-vs-confidential-whistleblower-reporting-whats-the-difference&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Compliance officers frequently use &amp;amp;ldquo;anonymous&amp;amp;rdquo; and &amp;amp;ldquo;confidential&amp;amp;rdquo; interchangeably when discussing whistleblower reporting. They are not the same thing, and the distinction matters &amp;amp;mdash; both legally and practically.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Getting this wrong can undermine trust in your reporting channel, expose your organization to liability, or make investigations harder than they need to be. Here is what each term means, what the EU Directive says, and how to handle both in practice.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;definitions&amp;#34;&amp;gt;
Definitions
&amp;lt;a href=&amp;#34;#definitions&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;anonymous-reporting&amp;#34;&amp;gt;
Anonymous reporting
&amp;lt;a href=&amp;#34;#anonymous-reporting&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity is unknown to everyone, including the case handler. The organization receives the report but has no way to determine who submitted it. The reporter does not provide their name, email, or any identifying information.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;True anonymity means that even if the organization wanted to identify the reporter, it could not &amp;amp;mdash; the system is designed to prevent it.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;confidential-reporting&amp;#34;&amp;gt;
Confidential reporting
&amp;lt;a href=&amp;#34;#confidential-reporting&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity is known to the case handler (or a limited number of authorized persons), but it is protected from disclosure to anyone else. The handler knows who made the report but is legally and organizationally obligated not to reveal that identity.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Confidentiality is a promise backed by legal protections. Anonymous reporting removes the need for that promise entirely.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-eu-directive-says&amp;#34;&amp;gt;
What the EU Directive says
&amp;lt;a href=&amp;#34;#what-the-eu-directive-says&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937 addresses both concepts, though it gives member states flexibility on anonymous reporting.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Confidentiality (Article 16):&amp;lt;/strong&amp;gt; The Directive is unambiguous here. The identity of the reporting person must not be disclosed to anyone beyond authorized staff without the reporter&amp;amp;rsquo;s explicit consent. This applies to all reports, whether the reporter identifies themselves or not. Confidentiality is mandatory.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Anonymous reporting (Article 6(2&amp;amp;ndash;3), Recital 34):&amp;lt;/strong&amp;gt; The Directive does not require member states to accept anonymous reports through internal channels. However, it explicitly states that member states &amp;lt;em&amp;gt;may&amp;lt;/em&amp;gt; decide to allow or require anonymous reporting. Where anonymous reports are accepted, they must be handled with the same diligence as identified reports.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In practice, the majority of member states that have transposed the Directive now require or strongly encourage anonymous reporting. &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
, and several others mandate it. Even where it is not legally required, allowing anonymity is considered best practice because it increases reporting rates.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Two-way communication (Article 9(1)(b)):&amp;lt;/strong&amp;gt; The Directive requires that reporting channels allow communication with the reporter, including providing acknowledgment and feedback. For anonymous reporters, this means the channel must support two-way messaging without requiring identity disclosure &amp;amp;mdash; typically through an access code or case reference number.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;pros-and-cons&amp;#34;&amp;gt;
Pros and cons
&amp;lt;a href=&amp;#34;#pros-and-cons&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;anonymous-reporting-1&amp;#34;&amp;gt;
Anonymous reporting
&amp;lt;a href=&amp;#34;#anonymous-reporting-1&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pros:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Removes the fear barrier entirely &amp;amp;mdash; reporters do not risk being identified&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Higher reporting rates, especially for sensitive issues like fraud by senior management&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Protects reporters even if the organization&amp;amp;rsquo;s confidentiality measures fail&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Builds trust in the reporting channel&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Cons:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Follow-up is harder &amp;amp;mdash; the handler cannot call the reporter for clarification unless two-way messaging is available&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Risk of lower-quality reports if the reporter knows they cannot be contacted&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Some organizations worry about frivolous or malicious reports (in practice, the &amp;lt;a href=&amp;#34;https://www.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE Report to the Nations&amp;lt;/a&amp;gt;
and &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=SWD:2018:0116:FIN&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU Commission impact assessment&amp;lt;/a&amp;gt;
found this is rare)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Investigation may be more difficult without knowing the reporter&amp;amp;rsquo;s vantage point&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;confidential-reporting-1&amp;#34;&amp;gt;
Confidential reporting
&amp;lt;a href=&amp;#34;#confidential-reporting-1&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pros:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Easier follow-up &amp;amp;mdash; the handler can contact the reporter directly for additional information&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The reporter&amp;amp;rsquo;s perspective and role can help focus the investigation&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reports tend to be more detailed when the reporter knows they can be contacted&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The handler can assess credibility more easily&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Cons:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Requires the reporter to trust that confidentiality will be maintained&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;A single data breach, careless email, or unauthorized access can expose the reporter&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Some reporters will not use the channel if identification is required&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The organization bears the legal risk of maintaining confidentiality&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-anonymous-reporting-works-in-practice&amp;#34;&amp;gt;
How anonymous reporting works in practice
&amp;lt;a href=&amp;#34;#how-anonymous-reporting-works-in-practice&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Anonymous reporting does not mean the reporter submits a message into a void and never hears back. Modern whistleblower platforms solve the communication problem with access codes.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is how it typically works:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter submits a report&amp;lt;/strong&amp;gt; through the portal without entering any personal information.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The system generates a unique access code&amp;lt;/strong&amp;gt; (or case reference number) and displays it to the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter saves the access code.&amp;lt;/strong&amp;gt; This is their key to the case.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The case handler reviews the report&amp;lt;/strong&amp;gt; and can post follow-up questions or status updates to the case.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter returns to the portal&amp;lt;/strong&amp;gt;, enters the access code, and sees any messages from the handler. They can reply, provide additional documents, or answer questions &amp;amp;mdash; all without revealing who they are.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;This approach satisfies the Directive&amp;amp;rsquo;s two-way communication requirement while preserving anonymity. The handler gets the information they need for the investigation; the reporter stays protected.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The access code model also supports the seven-day acknowledgment and three-month feedback requirements, because the reporter can check the portal at any time to see if acknowledgment or feedback has been provided.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-offering-both-options-is-the-right-approach&amp;#34;&amp;gt;
Why offering both options is the right approach
&amp;lt;a href=&amp;#34;#why-offering-both-options-is-the-right-approach&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The strongest reporting channels give reporters the choice: submit anonymously, or provide your identity with the assurance of confidentiality.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is why:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Different situations call for different approaches.&amp;lt;/strong&amp;gt; A junior employee reporting a senior executive&amp;amp;rsquo;s fraud may choose anonymity. A department head flagging a safety issue may prefer to identify themselves so the investigation can move faster.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Choice builds trust.&amp;lt;/strong&amp;gt; When reporters see that anonymity is genuinely available, they trust the channel more &amp;amp;mdash; even the ones who ultimately choose to identify themselves.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Legal coverage.&amp;lt;/strong&amp;gt; In member states that require anonymous reporting, you are compliant. In those that do not, you exceed the minimum standard.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Better reporting rates.&amp;lt;/strong&amp;gt; The &amp;lt;a href=&amp;#34;https://www.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE Report to the Nations (2024)&amp;lt;/a&amp;gt;
found that tips are the most common fraud detection method (43% of cases), and anonymous hotlines significantly increase tip volume.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The EU Directive&amp;amp;rsquo;s own recitals acknowledge this: allowing anonymous reporting &amp;lt;em&amp;gt;encourages&amp;lt;/em&amp;gt; reporting and makes channels more effective.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-handles-this&amp;#34;&amp;gt;
How EthicsPortal handles this
&amp;lt;a href=&amp;#34;#how-ethicsportal-handles-this&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal supports both anonymous and confidential reporting:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymous by default.&amp;lt;/strong&amp;gt; Reporters are never required to provide their identity. No name, no email, no account.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Optional identity disclosure.&amp;lt;/strong&amp;gt; Reporters can choose to share their name or contact information if they want to. This is entirely voluntary.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Access code messaging.&amp;lt;/strong&amp;gt; Every report generates a unique access code. The reporter uses it to check for updates and communicate with the case handler, without revealing who they are.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality enforced.&amp;lt;/strong&amp;gt; When a reporter does share their identity, access controls ensure only designated case handlers can see it.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This gives reporters full control over their level of exposure, while giving case handlers the tools they need to investigate effectively.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-bottom-line&amp;#34;&amp;gt;
The bottom line
&amp;lt;a href=&amp;#34;#the-bottom-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Anonymous means the handler does not know who you are. Confidential means the handler knows but is legally bound not to tell anyone else. Both serve the goal of protecting reporters, but they do so differently.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The EU Directive mandates confidentiality. It leaves anonymous reporting to member states, most of which now require or recommend it. The safest approach &amp;amp;mdash; for your reporters and your compliance posture &amp;amp;mdash; is to offer both.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>How to set up a whistleblower reporting channel in 5 minutes</title><link>https://ethicsportal.eu/blog/how-to-implement-whistleblower-channel/</link><pubDate>Sun, 01 Feb 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/how-to-implement-whistleblower-channel/</guid><description>A step-by-step guide to setting up a compliant whistleblower reporting channel quickly, without weeks of onboarding or enterprise sales calls.</description><content:encoded>&amp;lt;h1 id=&amp;#34;how-to-set-up-a-whistleblower-reporting-channel-in-5-minutes&amp;#34;&amp;gt;
How to set up a whistleblower reporting channel in 5 minutes
&amp;lt;a href=&amp;#34;#how-to-set-up-a-whistleblower-reporting-channel-in-5-minutes&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every EU member state now requires organizations with 50 or more employees to operate an internal whistleblower reporting channel &amp;amp;mdash; through national laws like &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland), all transposing EU Directive 2019/1937. The requirement is clear, but most implementations take far longer than they should.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This guide explains what the law actually requires from the channel itself, why enterprise tools make the process unnecessarily slow, and how to get a working channel live in minutes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-directive-requires&amp;#34;&amp;gt;
What the Directive requires
&amp;lt;a href=&amp;#34;#what-the-directive-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Article 8 and Article 9 specify what an internal reporting channel must do:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Accept reports in writing or orally&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Allow anonymous reporting (required in some member states, strongly recommended everywhere)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Enable two-way communication with the reporter, even if they are anonymous&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Ensure only authorized persons can access reports&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Acknowledge receipt within seven calendar days&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Provide feedback within three months&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;That is the legal minimum. No specific technology is mandated &amp;amp;mdash; the Directive is technology-neutral. A web portal, a phone line, or even a locked physical mailbox can qualify, as long as the requirements above are met.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-most-implementations-take-weeks&amp;#34;&amp;gt;
Why most implementations take weeks
&amp;lt;a href=&amp;#34;#why-most-implementations-take-weeks&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Enterprise whistleblower platforms are designed for large organizations with complex procurement processes. A typical implementation looks like this:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Request a demo&amp;lt;/strong&amp;gt; &amp;amp;mdash; fill out a form, wait for a sales rep to call you back&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attend the demo&amp;lt;/strong&amp;gt; &amp;amp;mdash; a 30&amp;amp;ndash;60 minute call where the vendor walks you through features you may not need&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Receive a proposal&amp;lt;/strong&amp;gt; &amp;amp;mdash; custom pricing based on employee count, modules, and add-ons&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Negotiate the contract&amp;lt;/strong&amp;gt; &amp;amp;mdash; legal review, DPA signing, procurement approval&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Onboarding kickoff&amp;lt;/strong&amp;gt; &amp;amp;mdash; a project manager is assigned, another call is scheduled&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Configuration&amp;lt;/strong&amp;gt; &amp;amp;mdash; the vendor configures your portal, categories, and branding (or trains you to do it)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Testing and launch&amp;lt;/strong&amp;gt; &amp;amp;mdash; review, approve, and go live&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;For a 100-person company that just needs a compliant channel, this process is weeks of elapsed time and hours of meetings. It is designed for enterprises where a six-week procurement cycle is normal. For an SME, it is friction that delays compliance.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-5-minute-setup-with-ethicsportal&amp;#34;&amp;gt;
The 5-minute setup with EthicsPortal
&amp;lt;a href=&amp;#34;#the-5-minute-setup-with-ethicsportal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is built for the opposite scenario: you need a compliant channel, and you need it today.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-1-sign-up-1-minute&amp;#34;&amp;gt;
Step 1: Sign up (1 minute)
&amp;lt;a href=&amp;#34;#step-1-sign-up-1-minute&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Go to &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;ethicsportal.eu&amp;lt;/a&amp;gt;
and create an account. No demo request, no sales call, no &amp;amp;ldquo;contact us for pricing.&amp;amp;rdquo; You enter your email, set a password, and you are in.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-2-configure-your-portal-2-minutes&amp;#34;&amp;gt;
Step 2: Configure your portal (2 minutes)
&amp;lt;a href=&amp;#34;#step-2-configure-your-portal-2-minutes&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;From the dashboard, set up your reporting portal:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Organization name&amp;lt;/strong&amp;gt; &amp;amp;mdash; appears on the portal so reporters know they are in the right place&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Report categories&amp;lt;/strong&amp;gt; &amp;amp;mdash; define what types of issues can be reported (fraud, harassment, safety violations, etc.). Sensible defaults are provided.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Welcome text&amp;lt;/strong&amp;gt; &amp;amp;mdash; the message reporters see when they land on the portal. A clear, reassuring default is pre-filled.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Logo&amp;lt;/strong&amp;gt; &amp;amp;mdash; match your organization&amp;amp;rsquo;s visual identity&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Language&amp;lt;/strong&amp;gt; &amp;amp;mdash; choose the portal language for your reporters&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The portal is live at a unique URL as soon as you save. No deployment, no waiting.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-3-share-the-portal-with-employees-1-minute&amp;#34;&amp;gt;
Step 3: Share the portal with employees (1 minute)
&amp;lt;a href=&amp;#34;#step-3-share-the-portal-with-employees-1-minute&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Every portal gets a shareable link and a QR code. You can:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Email the link to all employees&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Print the QR code and post it in break rooms, offices, or common areas&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Add the link to your intranet or employee handbook&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Include it in your written whistleblower policy&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;step-4-start-receiving-and-managing-reports-1-minute&amp;#34;&amp;gt;
Step 4: Start receiving and managing reports (1 minute)
&amp;lt;a href=&amp;#34;#step-4-start-receiving-and-managing-reports-1-minute&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;When someone submits a report through the portal, you receive a notification. From the dashboard, you can:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Read the report&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Communicate with the reporter via secure two-way messaging (even if they are anonymous &amp;amp;mdash; they use an access code)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Track the seven-day acknowledgment deadline&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Track the three-month feedback deadline&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Update the case status and add internal notes&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Close the case with a documented outcome&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;That is it. Your channel is live, compliant, and ready to receive reports.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-to-do-after-setup&amp;#34;&amp;gt;
What to do after setup
&amp;lt;a href=&amp;#34;#what-to-do-after-setup&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;A reporting channel is the technical foundation, but compliance requires organizational steps too:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;designate-a-case-handler&amp;#34;&amp;gt;
Designate a case handler
&amp;lt;a href=&amp;#34;#designate-a-case-handler&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Appoint one or more persons to receive and investigate reports. This person should be impartial and not likely to be the subject of reports. A compliance officer, legal counsel, or senior HR person typically fills this role. For small organizations, the managing director can serve as handler.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;train-your-handlers&amp;#34;&amp;gt;
Train your handlers
&amp;lt;a href=&amp;#34;#train-your-handlers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Case handlers need to understand: how to use the platform, confidentiality obligations, the seven-day and three-month deadlines, basics of conducting an internal investigation, and anti-retaliation rules.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;write-a-whistleblower-policy&amp;#34;&amp;gt;
Write a whistleblower policy
&amp;lt;a href=&amp;#34;#write-a-whistleblower-policy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Document how your organization handles reports. Cover scope, who can report, confidentiality, anti-retaliation, and the investigation process. See our &amp;lt;a href=&amp;#34;/blog/whistleblower-policy-template/&amp;#34;&amp;gt;free policy template&amp;lt;/a&amp;gt;
for a ready-to-use document.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;inform-employees&amp;#34;&amp;gt;
Inform employees
&amp;lt;a href=&amp;#34;#inform-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive requires you to proactively tell employees about the channel. Send an email, post on the intranet, mention it in team meetings, and include it in onboarding. The QR code makes this easy &amp;amp;mdash; print it and put it where people will see it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;common-mistakes-to-avoid&amp;#34;&amp;gt;
Common mistakes to avoid
&amp;lt;a href=&amp;#34;#common-mistakes-to-avoid&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Using a generic email address.&amp;lt;/strong&amp;gt; An email like &amp;lt;a href=&amp;#34;mailto:compliance@company.com&amp;#34;&amp;gt;compliance@company.com&amp;lt;/a&amp;gt;
does not meet the Directive&amp;amp;rsquo;s requirements in most cases. Email lacks encryption, does not support anonymous reporting, and does not provide two-way communication with anonymous reporters.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Requiring reporters to identify themselves.&amp;lt;/strong&amp;gt; While the Directive does not uniformly require anonymous reporting, several national laws do (e.g., &amp;lt;a href=&amp;#34;/whistleblower-laws/belgium/&amp;#34;&amp;gt;Belgium&amp;lt;/a&amp;gt;
mandates anonymous reporting for companies with 250+ employees). Making identification mandatory discourages reporting. Allow anonymity by default.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Forgetting the deadlines.&amp;lt;/strong&amp;gt; Seven days for acknowledgment, three months for feedback. These are not suggestions &amp;amp;mdash; they are legal requirements. Missing them is a compliance failure. Use a system that tracks these deadlines automatically.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Not designating a handler.&amp;lt;/strong&amp;gt; The channel is a mailbox. Someone needs to open it, read the reports, and act on them. If no one is designated, reports go unanswered and deadlines pass.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Over-engineering the setup.&amp;lt;/strong&amp;gt; You do not need a full GRC suite, custom integrations, or a six-month rollout to comply. A working channel with anonymous reporting, two-way communication, and deadline tracking covers the legal requirements. Start simple, add complexity only if you need it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;get-started&amp;#34;&amp;gt;
Get started
&amp;lt;a href=&amp;#34;#get-started&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is €49/month flat &amp;amp;mdash; no per-employee pricing, no annual contracts, no sales calls. Set up your compliant reporting channel in minutes and focus on what matters: protecting the people who speak up.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>EU whistleblower directive compliance checklist for companies</title><link>https://ethicsportal.eu/blog/compliance-checklist/</link><pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/compliance-checklist/</guid><description>A practical 12-step checklist to comply with EU Directive 2019/1937 and national transposition laws, with article references, tips, and implementation guidance.</description><content:encoded>&amp;lt;h1 id=&amp;#34;eu-whistleblower-directive-compliance-checklist-for-companies&amp;#34;&amp;gt;
EU whistleblower directive compliance checklist for companies
&amp;lt;a href=&amp;#34;#eu-whistleblower-directive-compliance-checklist-for-companies&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;All 27 EU member states have transposed EU Directive 2019/1937 into national law &amp;amp;mdash; including &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;D.Lgs. 24/2023&amp;lt;/a&amp;gt;
(Italy), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland). Your organization must comply with the national law in your country of operation, and enforcement is active.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This checklist walks you through the twelve steps to full compliance. For each item, we cite the relevant Directive article, share practical tips, and note where tooling can help. See our &amp;lt;a href=&amp;#34;/whistleblower-laws/&amp;#34;&amp;gt;whistleblower laws by country&amp;lt;/a&amp;gt;
reference for your country&amp;amp;rsquo;s specific requirements.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-checklist&amp;#34;&amp;gt;
The checklist
&amp;lt;a href=&amp;#34;#the-checklist&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;1-determine-if-your-organization-is-in-scope&amp;#34;&amp;gt;
1. Determine if your organization is in scope
&amp;lt;a href=&amp;#34;#1-determine-if-your-organization-is-in-scope&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 8(3&amp;amp;ndash;4)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;All legal entities in the private sector with 50 or more workers must establish internal reporting channels. &amp;lt;a href=&amp;#34;/industries/public-sector/&amp;#34;&amp;gt;Public sector&amp;lt;/a&amp;gt;
entities, municipalities, and entities in certain regulated sectors (&amp;lt;a href=&amp;#34;/industries/financial-services/&amp;#34;&amp;gt;financial services&amp;lt;/a&amp;gt;
, aviation safety, maritime, etc.) are in scope regardless of size.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Count all workers, not just full-time employees. Part-time staff, contractors working on-site, and temporary agency workers may count toward the threshold depending on your national law. Some countries go further &amp;amp;mdash; &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
requires a channel for all companies with a Model 231 compliance program regardless of size, and &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Spain&amp;lt;/a&amp;gt;
covers all public entities.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;2-establish-an-internal-reporting-channel&amp;#34;&amp;gt;
2. Establish an internal reporting channel
&amp;lt;a href=&amp;#34;#2-establish-an-internal-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 8(1), Article 9(1)(a)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The channel must allow reporting in writing (online form, email, postal) or orally (phone, voice messaging system), or both. On request, it must also allow in-person meetings within a reasonable timeframe.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; A web-based portal is the most practical option &amp;amp;mdash; it is accessible 24/7, creates an automatic record, and supports anonymous two-way communication. Avoid using generic email addresses; they lack encryption, anonymity, and audit trails.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Provides a branded web portal with encrypted anonymous reporting and two-way messaging, ready in minutes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;3-designate-an-impartial-person-or-department-to-handle-reports&amp;#34;&amp;gt;
3. Designate an impartial person or department to handle reports
&amp;lt;a href=&amp;#34;#3-designate-an-impartial-person-or-department-to-handle-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(c)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must designate a person or department competent to follow up on reports. This person must be impartial &amp;amp;mdash; they should not have a conflict of interest with the subject matter of reports.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Common choices include a compliance officer, a legal counsel, an HR director, or an external ombudsperson. For smaller organizations, the managing director can serve this role if they are not likely to be the subject of reports. Consider designating a backup handler.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;4-set-up-the-acknowledgment-process-7-day-deadline&amp;#34;&amp;gt;
4. Set up the acknowledgment process (7-day deadline)
&amp;lt;a href=&amp;#34;#4-set-up-the-acknowledgment-process-7-day-deadline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(b)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must acknowledge receipt of a report within seven calendar days. This applies to all reports, including anonymous ones.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Automate this. A manual process risks missing the seven-day window during holidays or absences.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Tracks the acknowledgment deadline for each report and shows case handlers which reports need attention.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;5-define-the-feedback-process-3-month-deadline&amp;#34;&amp;gt;
5. Define the feedback process (3-month deadline)
&amp;lt;a href=&amp;#34;#5-define-the-feedback-process-3-month-deadline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(f)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must provide feedback to the reporting person within three months of the acknowledgment. Feedback includes: whether the report is being assessed, is under investigation, or has been closed, and the outcome of any investigation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; &amp;amp;ldquo;Feedback&amp;amp;rdquo; does not require disclosing the full investigation outcome. Informing the reporter that the matter was investigated and appropriate action was taken is sufficient. For anonymous reporters, feedback must be available through the reporting channel (for example, via an access code).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Tracks the three-month feedback deadline per case and supports two-way messaging with anonymous reporters via access codes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;6-implement-confidentiality-measures&amp;#34;&amp;gt;
6. Implement confidentiality measures
&amp;lt;a href=&amp;#34;#6-implement-confidentiality-measures&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 16&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person must not be disclosed to anyone beyond authorized case handlers without the reporter&amp;amp;rsquo;s explicit consent. This also covers information from which the reporter&amp;amp;rsquo;s identity could be indirectly deduced.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Limit access to reports strictly. Do not share report details in meetings where unauthorized persons are present. When referring cases internally, redact identifying information about the reporter. Ensure your IT systems enforce access controls.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Role-based access ensures only designated case handlers can view reports. Reporter identity is never exposed unless the reporter voluntarily shares it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;7-establish-anti-retaliation-protections&amp;#34;&amp;gt;
7. Establish anti-retaliation protections
&amp;lt;a href=&amp;#34;#7-establish-anti-retaliation-protections&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Articles 19, 20, 21&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Reporting persons, facilitators, and connected third parties must be protected from retaliation. The Directive defines retaliation broadly: dismissal, demotion, intimidation, blacklisting, and more. The burden of proof is reversed &amp;amp;mdash; if a reporter suffers a detriment after reporting, the employer must prove the detriment was unrelated to the report.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Document this protection in your whistleblower policy. Train managers on what constitutes retaliation. Track personnel actions involving anyone who has made a report, so you can demonstrate that decisions were made on legitimate grounds.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;8-train-case-handlers&amp;#34;&amp;gt;
8. Train case handlers
&amp;lt;a href=&amp;#34;#8-train-case-handlers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(c&amp;amp;ndash;f) (implied)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Directive does not prescribe specific training, but case handlers must be competent to fulfill the obligations it creates: maintaining confidentiality, providing acknowledgment within seven days, conducting diligent follow-up, and providing feedback within three months.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; At a minimum, train case handlers on: how to use the reporting channel, confidentiality obligations, investigation basics, anti-retaliation rules, and data protection. Document the training. Refresh annually.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;9-inform-employees-about-the-reporting-channel&amp;#34;&amp;gt;
9. Inform employees about the reporting channel
&amp;lt;a href=&amp;#34;#9-inform-employees-about-the-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(g)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must provide clear and easily accessible information about how to use the internal reporting channel. You must also inform employees about their right to report externally to competent authorities.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Publish the information on your intranet, include it in onboarding materials, and display it in common areas. A QR code linking to the reporting portal is an effective way to make the channel discoverable.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Generates a QR code and shareable link for your portal that you can print and distribute.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;10-set-up-data-retention-and-deletion&amp;#34;&amp;gt;
10. Set up data retention and deletion
&amp;lt;a href=&amp;#34;#10-set-up-data-retention-and-deletion&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 17(1&amp;amp;ndash;3)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Personal data in reports must not be kept longer than necessary. Data that is manifestly not relevant must be deleted promptly. Specific retention periods depend on your member state&amp;amp;rsquo;s law, but the principle is: retain as long as needed for the investigation and any resulting proceedings, then delete.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Define a retention period in your policy. National laws vary &amp;amp;mdash; for example, &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000046357368&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 5 years&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 3 years&amp;lt;/a&amp;gt;
(HinSchG §11), and &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 5 years&amp;lt;/a&amp;gt;
(D.Lgs. 24/2023). See our &amp;lt;a href=&amp;#34;/blog/gdpr-and-whistleblower-reporting/&amp;#34;&amp;gt;GDPR and whistleblower reporting guide&amp;lt;/a&amp;gt;
for a full comparison. Set calendar reminders to review and delete closed cases.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;11-prepare-a-written-whistleblower-policy&amp;#34;&amp;gt;
11. Prepare a written whistleblower policy
&amp;lt;a href=&amp;#34;#11-prepare-a-written-whistleblower-policy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Articles 8, 9 (implied), plus most national transposition laws&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;While the Directive does not explicitly mandate a standalone policy document, most national transposition laws do, and it is practically necessary to fulfill the information obligations in Article 9(1)(g).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Your policy should cover: scope, who can report, what can be reported, how to report, confidentiality, anti-retaliation, investigation process, feedback timelines, and data protection. See our &amp;lt;a href=&amp;#34;/blog/whistleblower-policy-template/&amp;#34;&amp;gt;free whistleblower policy template&amp;lt;/a&amp;gt;
for a ready-to-use document.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;12-document-compliance-for-regulatory-review&amp;#34;&amp;gt;
12. Document compliance for regulatory review
&amp;lt;a href=&amp;#34;#12-document-compliance-for-regulatory-review&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 11(2) (external channels), national transposition laws (internal)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Several member states require organizations to document that they have fulfilled their obligations and to make this documentation available to regulators on request.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Keep records of: when the reporting channel was established, who the designated case handlers are, training records, the whistleblower policy (with version history), and aggregate statistics on reports received and handled. Do not store individual case details longer than your retention period allows.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;next-steps&amp;#34;&amp;gt;
Next steps
&amp;lt;a href=&amp;#34;#next-steps&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you have checked every box above, your organization is compliant with the core requirements of the Directive and its national transposition. Compliance is not a one-time event &amp;amp;mdash; review your setup annually, retrain handlers, and update your policy as national law evolves. Check our &amp;lt;a href=&amp;#34;/whistleblower-laws/&amp;#34;&amp;gt;whistleblower laws by country&amp;lt;/a&amp;gt;
reference for country-specific requirements that may go beyond the Directive&amp;amp;rsquo;s baseline.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Need a reporting channel? &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
gives you a compliant, anonymous reporting portal in minutes &amp;amp;mdash; €49/month flat, no per-employee pricing, no sales calls. &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;Get started today&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>EU Directive 2019/1937 on whistleblower protection adopted</title><link>https://ethicsportal.eu/blog/eu-whistleblower-directive-2019-1937-adopted/</link><pubDate>Wed, 23 Oct 2019 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/eu-whistleblower-directive-2019-1937-adopted/</guid><description>The European Parliament and the Council formally adopt Directive (EU) 2019/1937, establishing EU-wide protection for persons who report breaches of Union law.</description><content:encoded>&amp;lt;h1 id=&amp;#34;eu-directive-20191937-on-whistleblower-protection-adopted&amp;#34;&amp;gt;
EU Directive 2019/1937 on whistleblower protection adopted
&amp;lt;a href=&amp;#34;#eu-directive-20191937-on-whistleblower-protection-adopted&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;On 23 October 2019, the European Parliament and the Council formally adopted &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/eli/dir/2019/1937/oj/eng&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Directive (EU) 2019/1937&amp;lt;/a&amp;gt;
on the protection of persons who report breaches of Union law. The plenary vote passed with 591 votes in favour, 29 against, and 33 abstentions.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Directive requires every organization with 50 or more employees to establish secure internal reporting channels, protect reporters from retaliation, and provide feedback within three months. Member states had until 17 December 2021 to transpose it into national law.&amp;lt;/p&amp;gt;
&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/video/protecting-democracy-by-protecting-whistleblowers_N01-PUB-190408-BLOW&amp;#34; style=&amp;#34;display: block; padding: 1.5rem; border: 1px solid #ddd; border-radius: 0.5rem; text-decoration: none; color: inherit; margin: 2rem 0;&amp;#34;&amp;gt;
&amp;lt;strong&amp;gt;&amp;amp;#9654; Watch: Protecting democracy by protecting whistleblowers&amp;lt;/strong&amp;gt;&amp;lt;br&amp;gt;
&amp;lt;span style=&amp;#34;color: #666; font-size: 0.875rem;&amp;#34;&amp;gt;European Parliament Multimedia Centre · 1:28&amp;lt;/span&amp;gt;
&amp;lt;/a&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-directive-requires&amp;#34;&amp;gt;
What the directive requires
&amp;lt;a href=&amp;#34;#what-the-directive-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Internal reporting channels&amp;lt;/strong&amp;gt; (Art. 8) &amp;amp;mdash; secure, confidential channels accessible to all workers, including contractors and suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;7-day acknowledgment&amp;lt;/strong&amp;gt; (Art. 9) &amp;amp;mdash; organizations must confirm receipt of a report within seven calendar days&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;3-month feedback deadline&amp;lt;/strong&amp;gt; (Art. 9) &amp;amp;mdash; reporters must receive feedback on actions taken within three months&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anti-retaliation protection&amp;lt;/strong&amp;gt; (Art. 19&amp;amp;ndash;21) &amp;amp;mdash; dismissal, demotion, intimidation, and other forms of retaliation are prohibited&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reversed burden of proof&amp;lt;/strong&amp;gt; (Art. 21(5)) &amp;amp;mdash; once a reporter shows they made a report and suffered a detriment, the employer must prove the measure was unrelated&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;External and public reporting&amp;lt;/strong&amp;gt; (Art. 10, 15) &amp;amp;mdash; reporters retain protection when reporting to competent authorities or, as a last resort, making public disclosures&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;plenary-debate&amp;#34;&amp;gt;
Plenary debate
&amp;lt;a href=&amp;#34;#plenary-debate&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The European Parliament debated the directive during its plenary session in Strasbourg. Extracts from the debate are available on the European Parliament Multimedia Centre:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/video/protection-of-whistle-blowers-extracts-from-the-debate_I123987&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Watch the plenary debate on whistleblower protection&amp;lt;/a&amp;gt;
&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;official-resources&amp;#34;&amp;gt;
Official resources
&amp;lt;a href=&amp;#34;#official-resources&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/eli/dir/2019/1937/oj/eng&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Full text of Directive (EU) 2019/1937&amp;lt;/a&amp;gt;
&amp;amp;mdash; EUR-Lex&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://commission.europa.eu/aid-development-cooperation-fundamental-rights/your-fundamental-rights-eu/protection-whistleblowers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Protection for whistleblowers&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Commission&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.europarl.europa.eu/news/en/press-room/20190410IPR37529/protecting-whistle-blowers-new-eu-wide-rules-approved&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;New EU-wide rules approved&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament press release&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/topic/protection-of-whistleblowers-8th-parliamentary-term_9901&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;All whistleblower protection multimedia&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament Multimedia Centre&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.europarl.europa.eu/legislative-train/theme-area-of-justice-and-fundamental-rights/file-whistle-blower-protection-proposal&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Legislative train schedule&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item></channel></rss>