There is no single legal retention period for whistleblowing reports — how long you keep a report depends on its outcome, not a fixed number of years. A report closed with no follow-up needs a different (usually shorter) retention period than one that led to a disciplinary process or a lawsuit still working its way through court.
Article 18 of the Whistleblower Protection Directive requires that records of reports be kept "only for as long as necessary and proportionate" to comply with the requirements the Directive itself imposes — it deliberately avoids setting a fixed number of years, leaving that judgment to the organization and to national transposition law. Layered on top of that, GDPR Article 5(1)(e) — the storage-limitation principle — requires that any personal data processed through the channel (a reporter's name if they chose to identify themselves, details about the person accused, witness statements) be kept "no longer than is necessary for the purposes for which the personal data are processed."
Read together, these two provisions mean a whistleblowing platform cannot simply keep every report forever "just in case," nor can it delete everything the moment a case closes if a limitation period for related legal claims is still running. The retention period has to be tied to a documented purpose — and that purpose changes depending on what happened to the report.
Rather than a single number, a defensible retention schedule assigns a different clock to each outcome:
Documenting these three tracks — with the trigger event that starts each clock — is what turns a vague "we delete data when no longer needed" line into a defensible policy a regulator or auditor can actually verify.
7-day free trial with full access, no credit card required
When a retention period lapses, the goal is removing what identifies people while preserving what the organization legitimately needs for compliance oversight:
A retention policy is only as good as its enforcement, which is exactly where a written schedule tends to fail in practice — nobody remembers to act on it once a case is a year old. Vaelo's case management dashboard lets compliance teams assign a retention track (no findings, disciplinary outcome, or legal hold) to each case at close-out, then automatically flags cases approaching their documented deletion date so nothing lingers past its justified retention period by accident. Legal holds can be applied per case to override the default clock without needing to remember which cases are exempt, and when a retention period does expire, identifying fields can be purged while the anonymized statistics needed for compliance reporting and audit trails stay fully intact.
Is there a legally mandated number of years to keep whistleblower reports? No single figure applies across the EU. Article 18 of the Directive requires records be kept "only for as long as necessary and proportionate," and GDPR's storage-limitation principle applies the same standard to personal data in the report — the actual duration depends on the case outcome and on any national transposition law or limitation periods that apply.
Should reports with no findings be deleted immediately after closing? Not immediately, but generally sooner than cases with a confirmed outcome — enough time should pass to demonstrate the report was properly triaged (commonly some months up to around two years), after which retaining identifying data typically has no remaining legal basis.
What happens to reports connected to a court case or regulatory investigation? They should be placed on a legal hold that suspends the default retention schedule until the proceeding — and any appeal period — concludes, since deleting evidence connected to active litigation can expose the organization to separate legal risk.
Can we keep report statistics after deleting the underlying case data? Yes — aggregate, non-identifying statistics (report volume, categories, average response time) can be retained indefinitely for compliance reporting and trend analysis once the identifying details of the individual case have been deleted or anonymized.
7-day free trial with full access, no credit card required
GDPR doesn't stop you investigating a whistleblower report — it defines how. Legal basis, the accused's data rights vs. reporter confidentiality, retention limits, and when a DPIA is required.
A DPIA isn't optional for a whistleblowing channel — it's expected under Article 35 GDPR. The seven-step checklist to make yours defensible, the mistakes that undermine it, and when to redo it.
A practical breakdown of Directive (EU) 2019/1937: who must comply, the 7-day and 3-month legal deadlines, anonymous reporting requirements, and penalties for getting it wrong.
The metrics that actually show whether your whistleblowing channel works — usage rate, on-time deadline handling, resolution rates and retaliation tracking — and how often to report them to the board.