The GDPR (Regulation (EU) 2016/679) does not stop you from investigating a whistleblower report — it defines how you must do it. You process the personal data of the reporter, the accused person and any witnesses on a lawful basis (almost always legitimate interests or a legal obligation), you collect only what the investigation actually needs, you keep the reporter's identity confidential, and you delete the data once it is no longer necessary. Getting this wrong is not a technicality: it can turn a legitimate investigation into a data protection breach in its own right.
The first mistake compliance teams make is trying to base an investigation on consent. You cannot: the person under investigation is not going to freely consent to being investigated, and consent that cannot be freely refused is invalid under GDPR. Instead, the processing rests on one of two grounds:
If a report touches special categories of data (health, trade-union membership, political opinions, data on criminal offences), you need an additional condition under Article 9 or Article 10 — for example that the processing is necessary for establishing, exercising or defending legal claims. This is exactly the kind of report — harassment, discrimination — where whistleblowing channels are used most.
The sharpest conflict in any investigation is this: the accused person is a data subject too, and under Article 15 they can ask for access to the personal data you hold about them — including what has been alleged. Handled naively, a subject access request becomes a way to unmask the whistleblower.
It does not have to. Confidentiality of the reporter's identity is protected by Article 16 of Directive (EU) 2019/1937, and GDPR itself limits the right of access where it would adversely affect the "rights and freedoms of others". In practice this means you disclose the substance of the allegation to the accused where required for fairness, but you redact anything that would identify the reporter — names, role, dates, or details only a specific person could know. National transpositions and data protection authorities reinforce this: the reporter's identity is not something the accused is entitled to obtain through a data request.
You may also postpone informing the accused that their data is being processed under Article 14(5) where notification would seriously impair the investigation — for instance by tipping off the subject before evidence is secured. This is a deferral, not a permanent exemption: the obligation revives once the risk has passed.
7-day free trial with full access, no credit card required
Two principles govern the lifecycle of investigation data:
The practical rule: reports that turn out to be unfounded or manifestly irrelevant should be deleted promptly, while substantiated cases are retained for the period needed to defend against legal claims or meet a statutory retention duty — then deleted. A defined retention schedule, applied automatically, is far safer than ad-hoc deletion.
A whistleblowing channel processes sensitive information about identifiable people, systematically, and often across an entire workforce. That profile typically meets the threshold in Article 35 for a Data Protection Impact Assessment — a documented analysis of the risks to individuals and the measures that mitigate them. Most data protection authorities treat a DPIA for a whistleblowing system as expected rather than optional, so build it before launch, not after an incident.
This is the same groundwork you need for the reporting channel itself. If you are still mapping who must comply and the legal deadlines involved, our guide to the EU Whistleblower Protection Directive covers the obligations that sit alongside these GDPR duties.
Vaelo is a hosted whistleblower platform designed around both the Directive and the GDPR. The reporter's identity is protected end-to-end with anonymous two-way messaging, so investigators can ask follow-up questions without ever unmasking the source. Access to each case is role-based and logged, evidence is encrypted, and configurable retention rules delete data on schedule so storage limitation is enforced automatically rather than left to memory. The result is an investigation workflow that is defensible under both laws at once — available in all 24 official EU languages.
What is the legal basis for processing personal data in an internal investigation? Almost always the organisation's legitimate interests (Article 6(1)(f) GDPR) or a legal obligation (Article 6(1)(c)) — for example the duty to operate a channel under Directive (EU) 2019/1937. A whistleblowing investigation should not rely on the accused person's consent.
Can the accused person access the whistleblower's report under GDPR? They have a right of access under Article 15 GDPR, but it does not extend to revealing the reporter's identity. Article 16 of Directive (EU) 2019/1937 and the "rights and freedoms of others" limitation let you redact information that would identify the whistleblower.
Do we need a DPIA for a whistleblowing channel? In most cases yes. A whistleblowing system processes sensitive data about identifiable people, often at scale, which typically meets the Article 35 GDPR threshold — so a Data Protection Impact Assessment is expected before go-live.
How long can we keep internal investigation data under GDPR? Only as long as necessary and proportionate (Article 5(1)(e) GDPR and Article 18 of Directive (EU) 2019/1937). Data from reports that turn out to be unfounded or manifestly irrelevant should be deleted promptly, not retained by default.
7-day free trial with full access, no credit card required