> Regulators and courts have already ruled on how whistleblowing channels fail. Each decision below becomes one procurement question, with the primary source linked.

Source: https://ethicsportal.eu/blog/whistleblowing-vendor-questions-from-enforcement-cases/
Updated: 2026-09-28

---

# Eight questions for your whistleblowing vendor, taken from enforcement cases

Most vendor questionnaires ask whether reports are encrypted. The decisions below show that encryption is rarely where confidentiality breaks. In each case the reporter was exposed by something around the whistleblowing channel: a firewall, a hosting contract, a forwarded email, a security team acting on instructions.

Each question below comes from a published decision by a regulator or court. The full set of cases, with fines and primary sources, is kept in the [whistleblowing failures register](https://whistleblowertools.eu/guide/whistleblowing-failures-register/).

## 1. Does anything in the request path record who connected?

**The case:** In April 2022 Italy's data protection authority fined the Azienda Ospedaliera di Perugia €40,000. The hospital's whistleblowing app was reached through its firewall, and the firewall logged the IP address and username of every connection. The logs were kept until the file reached 150 GB. Anyone with access could see who had opened the channel. ([Garante order](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9768363))

**Ask the vendor:** Which layers between the reporter's browser and your application (CDN, load balancer, reverse proxy, web server, application logs, error tracking) record IP addresses or user agents on the reporter-facing pages? For how long?

**Ask yourself:** Is the online reporting form reachable only through your corporate network or VPN? If so, your own firewall and proxy logs are part of the channel, whatever the vendor does.

## 2. Who hosts the data, and did we authorise them in writing?

**The case:** The same decision fined the hospital's vendor, ISWEB S.p.A., €40,000. ISWEB had moved hosting to a third party without the hospital's written authorisation and without a data processing agreement. The hospital did not know where its whistleblowing data was. ([Garante order](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9768387))

**Ask the vendor:** Send the complete sub-processor list for the whistleblowing service, including hosting, email delivery, backups and support tooling. Does the contract require our prior written authorisation before a sub-processor is added or replaced?

## 3. Do you offer email as a reporting channel?

**The case:** In October 2025 the Italian data protection authority stated that email, ordinary or certified, is "in itself inadequate" to protect a reporter's identity, because mail systems keep transmission logs that can identify the sender. ([Garante opinion](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10184673))

**Ask the vendor:** Is email offered as an intake route? Do notifications to handlers contain report content or anything that identifies the reporter?

## 4. Can a named report leak when the case file is shared?

**The case:** Anthony Menendez reported accounting concerns to Halliburton under his own name, from his work email. When the SEC opened an inquiry, the general counsel emailed colleagues to preserve documents because "the SEC has opened an inquiry into the allegations of Mr. Menendez." His manager forwarded it to fifteen people in his team. In 2014 the US Court of Appeals for the Fifth Circuit upheld the finding that this disclosure was unlawful retaliation. ([Fifth Circuit opinion](https://www.ca5.uscourts.gov/Opinions/pub/13/13-60323-CV0.pdf))

**Ask the vendor:** Can handlers work a case without seeing the reporter's identity? Is identity held separately from the case content, and visible only to named roles?

## 5. Can a senior executive see or influence who reported?

**The case:** In 2016 Barclays CEO Jes Staley told the bank's security team to identify the author of an anonymous letter. The whistleblowing team objected, and he told security to carry on. UK regulators fined him £642,430 in 2018, and New York's financial regulator fined Barclays $15 million. ([FCA final notice](https://www.fca.org.uk/publication/final-notices/mr-james-edward-staley-2018.pdf), [NYDFS](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr1812181))

**Ask the vendor:** Can access to a case be restricted so that a person named in a report, however senior, cannot see it? Can an administrator grant themselves access to a case without leaving a record?

## 6. Is every access to a report logged, and can we read that log?

**Why it matters:** Regulators needed almost two years, from the June 2016 letters to the May 2018 final notices, to establish what happened at Barclays. When an organisation needs to show who accessed a report, and when, the only reliable evidence is a log that the people it records cannot edit.

**Ask the vendor:** Is every view, download and export of a case recorded with who and when? Can a case handler edit or delete those records?

## 7. Are former handlers' accounts removed?

**The case:** The Perugia decision also found that a department head's credentials stayed active for two months after they resigned in May 2019. ([Garante order](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9768363))

**Ask the vendor:** Can handler access be tied to our identity provider (SSO, SCIM) so that it ends when someone leaves? If not, who is responsible for removing it, and how would we notice a stale account?

## 8. Has the vendor documented the processing for a DPIA?

**The case:** The Perugia hospital had carried out no data protection impact assessment and had not given staff a privacy notice for the whistleblowing channel. Both were separate findings in the fine. ([Garante order](https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9768363))

**Ask the vendor:** Do you supply a DPIA template or the technical description we need to complete one? Is there a privacy notice for reporters we can publish?

## Using the list

These questions do not replace a security questionnaire. They cover the specific ways whistleblowing channels have failed in published decisions, which general security questionnaires tend to miss.

EthicsPortal publishes its own answers on the [security](/security/#ip-addresses), [sub-processors](/subprocessors/), [DPA](/dpa/) and [DPIA](/dpia/) pages.
