Data protection in the reporting office
Data protection in the reporting office covers the privacy requirements for running internal and external whistleblowing channels: the legal basis for processing, how to handle data subject rights, and the retention limits where the German Whistleblower Protection Act and the GDPR meet.
Every reporting office processes personal data: about the whistleblower, about the person implicated, about witnesses, and frequently special categories under Art. 9 GDPR such as health or trade union data. The German Whistleblower Protection Act (HinSchG) provides its own processing permission in Section 10 HinSchG: reporting offices may process personal data insofar as this is necessary to perform their statutory tasks, expressly including special categories of data. For employers legally obliged to operate an internal reporting office, the legal basis is therefore Art. 6(1)(c) GDPR in conjunction with Section 10 HinSchG (compliance with a legal obligation); organisations running a channel voluntarily – for example below the 50-employee threshold – normally rely on legitimate interests under Art. 6(1)(f) GDPR. Consent is not a workable basis in an employment relationship, because it cannot be given freely.
The hardest question is how data subject rights coexist with the confidentiality requirement. The person implicated in a report has, in principle, a right of access under Art. 15 GDPR and must be informed about the processing under Art. 14 GDPR. Both collide with Section 8 HinSchG, which protects the identity of the reporting person. The reporting office must therefore separate the two layers: access is granted to the allegations recorded about the requester, but never to information that would reveal the identity of the whistleblower or of other protected individuals. The restrictions in Art. 14(5)(b) GDPR and Sections 29 and 34 BDSG apply here, because Section 8 HinSchG constitutes a statutory duty of secrecy. Notification of the implicated person may also be deferred for as long as it would jeopardise the internal investigation – for instance the risk of evidence being destroyed – but it must be given once that purpose no longer requires the delay.
For retention, Section 11(5) HinSchG sets the benchmark: documentation of a report must be deleted three years after the procedure has been concluded. It may be kept longer only to satisfy requirements under the HinSchG or other legislation, and only for as long as this remains necessary and proportionate – typically where employment or criminal proceedings are still pending. Anything not required to handle the case should not be stored in the first place (Art. 5(1)(c) and (e) GDPR). On top of that come the standard controller duties: an entry in the record of processing activities under Art. 30 GDPR, a data processing agreement under Art. 28 GDPR where an external whistleblowing platform or ombudsperson is used, robust technical and organisational measures under Art. 32 GDPR with access strictly limited to the designated case handlers, and as a rule a data protection impact assessment under Art. 35 GDPR, since whistleblowing systems appear on the German supervisory authorities' mandatory DPIA list.
Legal Basis
Sections 8, 10 and 11(5) HinSchG (German Whistleblower Protection Act); Art. 5, 6(1)(c) and (f), 9, 14(5)(b), 15, 28, 30, 32, 35 GDPR; Sections 29 and 34 BDSG
Practical Example
A mechanical engineering company with 400 employees receives a report through its internal channel alleging that a sales director paid kickbacks to a customer's buyer. The designated case handler documents the report in a durable but pseudonymised form, in a workspace only she and her deputy can open. When the sales director asks for access under Art. 15 GDPR weeks later, the reporting office discloses the allegations held about him but withholds every detail that could identify the reporting person, citing Section 8 HinSchG and Section 34 BDSG in a written reasoning. Notification under Art. 14 GDPR had been deferred until evidence was secured. Once the internal investigation and the disciplinary measure are closed, she sets a deletion date three years after conclusion of the procedure and records why the personnel file follows its own separate retention rules.