Skip to main content
Whistleblower Protection

Outsourcing the reporting office

Outsourcing the reporting office means delegating the operation of the internal reporting channel to an external third party, such as a law firm, ombudsperson or specialised provider, while legal responsibility remains with the employer.

Outsourcing the reporting office is expressly permitted under Section 14(1) of the German Whistleblower Protection Act (HinSchG): the employer may entrust the operation of the internal reporting office to a third party. Suitable external providers include law firms, external ombudspersons, specialised compliance service providers or vendors of digital whistleblowing systems. Outsourcing is often economically sensible for small and medium-sized enterprises, because building internal capacity, training case handlers professionally and ensuring the required independence involve considerable effort.

Despite delegating day-to-day operations, the employer remains responsible for complying with the obligations of the HinSchG (Section 14(1) sentence 2). Outsourcing does not relieve the company of the duty to take appropriate follow-up measures, to uphold the confidentiality requirement, or to meet the seven-day and three-month deadlines. The external third party must satisfy the same requirements regarding independence, confidentiality and professional competence as an internal designated person. The contract should precisely define responsibilities, escalation paths, data protection arrangements and the interface to the internal decision on follow-up measures.

From a data protection perspective, outsourcing typically qualifies as processing on behalf of the controller under Article 28 GDPR, requiring a data processing agreement; depending on the actual division of tasks, joint controllership or the third party acting as an independent controller may also apply. For companies with 50 to 249 employees, Section 14(2) HinSchG additionally permits several companies to operate a shared reporting office, a particular form of resource-efficient pooling. In every case, the decisive factor is that the outsourced office is integrated organisationally in such a way that whistleblowers are protected and reports are handled properly.

Legal Basis

Section 14 HinSchG; Section 13 HinSchG; Article 28 GDPR

Practical Example

A mechanical engineering company with 140 employees has no in-house compliance department. Management decides to outsource the operation of the internal reporting office to a specialised law firm acting as an external ombudsperson. Under the contract, the firm is responsible for receiving and acknowledging reports, conducting the plausibility check and communicating with the reporting person; the decision on concrete follow-up measures, such as an internal investigation, remains with the company. A data processing agreement under Article 28 GDPR is concluded in addition. This allows the company to meet its statutory obligation to establish an internal reporting office without building its own capacity, while ensuring the required independence and confidentiality.

FAQ

Yes. Section 14(1) HinSchG expressly allows the operation of the internal reporting office to be entrusted to a third party. Suitable providers include law firms, external ombudspersons or specialised service providers. However, legal responsibility for complying with the obligations remains with the employer.
The operational running of the reporting office, that is receiving, acknowledging and reviewing reports, can be outsourced. The decision on and implementation of follow-up measures, in particular internal investigations and employment-law consequences, generally remain with the company, as it bears responsibility and holds the necessary authority.
As a rule, yes. The external operator processes personal data on the company's instructions, so a data processing agreement under Article 28 GDPR is required. Depending on the division of tasks, an individual case may instead involve the third party acting as an independent or joint controller.

How preeco supports you

Learn how our software supports you with this topic.

Learn more