Whistleblowing & Whistleblower Protection

Your internal reporting office. Operated by us.

Since December 17, 2023, all companies with 50 or more employees must operate an internal reporting mechanism under the Whistleblower Protection Act (HinSchG). In addition, there are certain employers for whom the obligation exists regardless of the number of employees (§ 12, paragraph 3, HinSchG). We provide this service as an external service provider for you, with secure reporting channels, fixed deadlines, and complete documentation. Your internal reporting mechanism is operated by data protection officers and lawyers.

The HinSchG at a glance
50+

Employees. In addition, there are certain employers for whom the obligation exists regardless of the number of employees (§ 12, paragraph 3, HinSchG).

7 days

Deadline for the initial confirmation to the person who has been notified

3 months

Deadline for providing feedback on planned or already taken follow-up measures and their reasons.

3 years

Storage of documentation after the completion of the procedure

Violations can cost up to €20,000 if there is no reporting office, and up to €50,000 in the case of reprisal or breach of confidentiality. The individual regulations for fines and the fines framework are determined in detail in § 40 HinSchG. The possible increase for legal entities follows from the interplay with the OWiG.

ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ from Berlin, operating worldwide ✓ Data protection officer and lawyers ✓ ISO 9001 certified
The legal situation

What the Whistleblower Protection Act requires of you

The Whistleblower Protection Act implements the EU Whistleblower Directive (EU 2019/1937) in Germany. It came into force on July 2, 2023, and has been in effect since December 17, 2023, also for companies with 50 to 249 employees.

Safe reporting channels

Section 16, paragraph 3 of the HinSchG requires reporting channels that allow for reports in written form or verbally. Upon request, a personal meeting must also be arranged. Anonymous reports are to be processed; however, there is no obligation to provide anonymous reporting channels.

Confidentiality

The identity of the person reporting the information and the persons affected must remain confidential. The confidentiality requirement also protects other persons mentioned in the report. In addition, there are statutory exceptions under § 9 HinSchG.

Fixed deadlines

The initial confirmation is issued within 7 days, and the response regarding follow-up measures is issued within 3 months of the confirmation.

Documentation

Each incoming report must be documented and kept in accordance with data protection regulations for three years after the completion of the procedure.

The process

From the first report to feedback

Each step has a clear responsibility, a deadline, and a proof of compliance. This way, you comply with the HinSchG without your team having to stand between the whistleblower, management, and authorities themselves.

Step 01

Whistleblowers

A person from the professional sphere becomes aware of a suspected violation. This could be employees, service providers, suppliers, applicants, or business partners.

Step 02

Report

The report is submitted through the channel that is most convenient for the person: verbally, by mail, in person, by telephone, or through the online form of the whistleblower system.

Step 03

Analysis

We send the initial confirmation within 7 days and, in the Whistleblowing Team, we check whether the report is credible, whether it falls within the scope of application, and what needs to be done.

Step 04

Assessment

We initiate appropriate follow-up actions, from internal investigations to referral to the competent authorities, if necessary.

Step 05

Closure

The person who provided the information will receive a response within 3 months regarding the planned or taken follow-up measures.

Step 01

Whistleblower

A person from the professional environment – employees, service providers, suppliers, applicants, or business partners – becomes aware of a suspected fact that warrants reporting.

Step 02

Report

The report is submitted through the channel that is most convenient for the person: verbally, by mail, in person, by telephone, or through the online form of the whistleblower system.

Step 03

Analysis

We send the receipt of the report within 7 days and the Whistleblowing Team examines the report: If it is credible, it falls within the scope of application; what should be done?

Step 04

Assessment

We will initiate appropriate follow-up actions – from internal investigations to referral to investigative authorities if necessary.

Step 05

Closure

The person who provided the information will receive a response within three months regarding the planned or taken follow-up measures.

Our solution

Independent, on time, documented.


Section 14 of the HinSchG explicitly allows a third party to be entrusted with the tasks of the internal reporting office. That is exactly what we offer.

We cooperate with the secure reporting channel Hinweismeldeportal.de. It is an IT-based whistleblowing system with an online form and a hotline that ensures technical confidentiality and also allows anonymous reports. We offer all of this at conditions that are also affordable for smaller companies.

Recruiting internal staff As the reporting office, HR or the management quickly become embroiled in a conflict of interest. Deadlines are compromised in daily operations, and there is no representation for leave and illness.
Reporting office with sofortdatenschutz

An independent team of data protection officers and lawyers receives reports, confirms receipt in a timely manner, thoroughly examines them from a legal perspective, and documents them in a comprehensive manner. Representation on the team is available 365 days a year.

The performance package

Everything required by the HinSchG.

External reporting office

We take over the tasks of your internal reporting unit in accordance with § 14 HinSchG. As a supplement to your external data protection officer or on your own initiative.

  • Receiving all reports: in writing, by phone, in person
  • Receipt of order within 7 days
  • Legal review and assessment by the Whistleblowing Team
  • Feedback to the person who reported the issue within 3 months
  • Information to employees about reporting channels and procedures

Reporting office + Whistleblower system

The complete implementation. A secure online reporting system via our partner Hinweismeldeportal.de plus operation of the reporting station by us.

  • Everything from the „External Reporting“ package“
  • IT-based whistleblower system with online form and hotline
  • Anonymous reports and protected dialogue with the reporting person
  • Confidentiality is technically secured, hosted in compliance with the GDPR
  • Set up within a few days, without your own IT resources
  • Whistleblowing policy and model for internal communication

Prices are based on company size and the chosen scope. Contact us for a free initial consultation and a personalized quote.

20.000 €

Penalty payment if no internal reporting system is established and operated (Section 40 HinSchG).

50.000 €

Fines for reprisal actions, hindering the reporting of a crime or violating confidentiality – up to ten times for legal entities.

0 €

Costs for your initial consultation. We will clarify in 15 minutes whether and how the HinSchG applies to you.

Frequently asked questions about whistleblower protection

When do we need an internal reporting office?

Since December 17, 2023, all companies with at least 50 employees must operate an internal reporting system. For companies with 250 or more employees, the obligation has been in effect since July 2, 2023. Certain companies in the financial sector, such as securities service providers, are required regardless of their size.


Can our data protection officer take over the reporting function?

Basically, yes, but it depends on the individual case. § 14, paragraph 1 of the HinSchG does allow the appointment of a third party, but it does not provide a blanket answer as to whether the data protection officer can also perform the tasks of the internal reporting unit. What is crucial is that independent action is guaranteed and that no conflicts of interest arise (§ 15 of the HinSchG).


Do we have to process anonymous reports?

1 HinSchG states that anonymous incoming reports should be processed; at the same time, there is explicitly no obligation to provide a reporting channel for the submission of anonymous reports. In practice, we recommend accepting and processing anonymous tips. They significantly increase the reporting rate, and an IT-based whistleblowing system enables protected dialogue even without naming names.

Which violations can be reported?

The HinSchG covers, among other things, offenses, misdemeanor violations of regulations protecting the life, health, or rights of employees, as well as violations of certain federal, state, and EU regulations, such as those regarding data protection, product safety, environmental protection, or procurement law. In the first step, we determine whether a report falls within the scope of application.


What deadlines apply to the reporting office?

The reporting office must confirm receipt of a report within seven days and provide a response to the reporting person no later than three months after the receipt of the confirmation, for example by providing planned or already taken follow-up measures. Each report must be documented; the documentation will be deleted three years after the completion of the procedure.


How quickly is the reporting office set up?

Usually within a few days: We set up the reporting channels, provide the Whistleblowing Policy and information for your employees, and start receiving reports from the agreed-upon date. If you are already a client of our external data protection officer, you will benefit from knowing that we already know your company.

Jan Käding • Senior Consultant

Is your reporting office
in compliance with the law?

Non-binding · 15 minutes · Free

more SERVICES

Data protection services that are available
It fits your company.