Instant Whistleblower Compliance for European Companies. GDPR compliant and anonymous reporting portal.
The metrics that actually show whether your whistleblowing channel works — usage rate, on-time deadline handling, resolution rates and retaliation tracking — and how often to report them to the board.
A practical breakdown of who's legally required to have an internal whistleblowing channel under Directive (EU) 2019/1937 — the 50-employee threshold, public-sector obligations, regulated sectors, and the shared-channel exception for corporate groups.
There's no single legal number of years to keep a whistleblower report — the practical retention calendar by case outcome, what to delete when a period expires, and the mistakes that trip up an audit.
Why most whistleblowing channels sit empty even after launch, and the concrete leadership habits, follow-through routines and metrics that turn a compliance requirement into a workplace where people actually speak up.
A DPIA isn't optional for a whistleblowing channel — it's expected under Article 35 GDPR. The seven-step checklist to make yours defensible, the mistakes that undermine it, and when to redo it.
GDPR doesn't stop you investigating a whistleblower report — it defines how. Legal basis, the accused's data rights vs. reporter confidentiality, retention limits, and when a DPIA is required.
The EU Whistleblower Directive sets one floor, but Germany's HinSchG, France's Loi Waserman, Spain's Ley 2/2023, and Portugal's Lei 93/2021 diverge sharply on deadlines, thresholds, and fines. A side-by-side comparison for compliance teams operating across borders.
A practical breakdown of Directive (EU) 2019/1937: who must comply, the 7-day and 3-month legal deadlines, anonymous reporting requirements, and penalties for getting it wrong.