Skip to main content
Data protection review of whistleblower systems
Back to all Insights

Insights · Data protection

Data protection review of whistleblower systems

The German Whistleblower Protection Act (HinSchG), which entered into force in July 2023, requires numerous companies to set up an internal whistleblower system.

Published
2 April 2024
Reading time
7 min read

Share this article

The German Whistleblower Protection Act (HinSchG), which entered into force in July 2023, requires numerous companies to set up an internal whistleblower system. And as is usual with new obligations, the market already offers numerous products with which companies can meet the requirements of the Act. When making their selection, companies look at price-performance, user-friendliness, compatibility with existing systems and much more. Whistleblower systems process personal data and should therefore undergo a comprehensive data protection review before they are introduced.

The protection of personal data is of the greatest importance in today’s digital world. Once a whistleblower system has been introduced, personal data are collected, processed and stored in it. To ensure the confidentiality and integrity of this sensitive information, companies must make sure that they comply with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

It cannot automatically be assumed that this legal certainty exists for every software provider, because of course it also depends on the individual circumstances of the company. To avoid the sometimes substantial penalties for data protection breaches from the outset, it is advisable to involve your data protection officer directly when introducing the system and to have the systems under consideration reviewed.

A data protection review consists of various steps. After a threshold analysis has been carried out, it is examined whether a data protection impact assessment by the software manufacturer already exists and, if not, whether one is required in your case at all, or whether a comprehensive review report alone is to be prepared. If a data protection impact assessment is considered necessary, or if an existing data protection impact assessment is reviewed, those results too are addressed in a review report.

The threshold analysis

In the threshold analysis it is first examined whether the form of data processing is in principle subject to a high risk, Art. 35 GDPR. The threshold analysis is in essence a risk analysis that determines whether a data protection impact assessment (DPIA) is necessary. The possible risk is determined by assessing the likelihood of occurrence and establishing the severity of the possible harm of an event. When implementing a new technology in the form of a whistleblower platform in a company, it can always be assumed that whistleblowers among the workforce would, for example, have to expect sensitive, possibly even existence-threatening reprisals if the content of their reports became known to the wrong people because the newly deployed technology is incomplete, for instance because it does not include an adequate rights-and-roles concept or because technical and organisational measures are not properly implemented.

In the case of such a high risk, a DPIA must always be carried out.

The data protection impact assessment

As soon as software can be expected to pose a high risk to the rights and freedoms of natural persons, companies must carry out a risk assessment of the data processing when introducing it. The DPIA serves to identify and assess data protection risks and to develop suitable measures to reduce those risks. It is usually prepared by the data protection officer and is accordingly often part of the data protection review. If a data protection impact assessment for the chosen whistleblower system already exists on the side of the software service provider, a second one of course does not have to be prepared. In that case, however, the reviewer should examine it thoroughly and incorporate any necessary additions or changes.

The review report

The review report summarises the data protection review for your company and shows which measures have already been implemented, which are still being implemented, and where there is still a need to make improvements. In the following we present a few of the most important points covered by our review reports.

Conformity with the law

In principle, it is examined whether all relevant statutory requirements are met. That concerns, on the one hand, all applicable provisions of the GDPR, the BDSG and regularly the German Telecommunications and Telemedia Data Protection Act (TTDSG), and, on the other hand, the requirements of the HinSchG. Of particular relevance are the sections that deal with the processing of personal data, the duty of confidentiality and the tasks of internal and external reporting offices.

Rights-and-roles concept

Highly relevant and sensitive data can be received in the whistleblower system, so it is essential to use a well-thought-out rights-and-roles concept to prevent the recipient of the report from easily facing a conflict of interest. It goes without saying that it is unfortunate if, for example, an employee reports grievances in the department and their head of department is responsible for receiving the reports. This problem is best solved through technical measures such as encryption mechanisms, pseudonymisation and through an external ombuds office.

Response mechanisms

Particularly in the field of data protection there are tight deadlines that companies must meet. For example, as soon as a company internally becomes aware of a data leak, it has 72 hours under Art. 33 GDPR to report the data breach or incident to the competent supervisory authority, and must even inform the data subject without undue delay of the infringement of their rights, Art. 34 GDPR. This time passes more quickly than some companies would like. To be able to act as quickly and efficiently as possible if the case arises, it is essential to implement the response mechanisms cleanly in technical terms from the outset and to define clearly which person has which responsibilities.

Data processing agreement

As always when data are processed, a data processing agreement (AVV) is mandatory. The provider of the software solution must ensure that all data its software can access are protected in a manner that complies with the GDPR. That includes, for example, that a secure firewall exists or that the software provider does not knowingly pass data on. As a rule these requirements are self-evident for most companies; nevertheless it is important to fix even self-evident points in the contract. Whether the AVV meets the data protection requirements for processing is also reviewed and explained in the review report.

Implementation of technical and organisational measures (TOMs)

Of course not only the software provider, but also the company itself must take suitable technical and organisational measures (TOMs) pursuant to Art. 32 GDPR. These include, for example, access restrictions or the use of secure passwords. These measures are standard in most companies and should not present a challenge.

And then?

After completion of the data protection review, the ideal result is: “Overall, this is a data-protection-appropriate implementation of the requirements under EU Directive 2019/1937, the GDPR, the BDSG and the Whistleblower Protection Act.” From a data protection perspective, that is the starting signal for the rollout of the chosen solution. It becomes more difficult if the reviewer raises concerns. Where possible, companies should take measures without delay to remedy the deficiencies noted. This could include adapting the system architecture, implementing additional security measures or revising the data protection policies and procedures. Particular attention should be paid here to technical and organisational measures. Working with data protection experts can help companies assess the data protection concerns and minimise risks without losing sight of the cost-benefit ratio.

To prevent the data protection review from taking place too late and leading to unwanted results, the data protection officer or adviser should ideally already be involved at the start of the selection process. That certainty is offered by our whistleblower system, which was developed by lawyers and legal professionals with data protection expertise in close cooperation with IT specialists.

If you are interested, you are welcome to book a no-obligation demo appointment. But even if you have already established or selected a whistleblower system, we are here for you and can take on the data protection review.

Request a demo

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email