Skip to main content
PRACTICE GUIDE · WHISTLEBLOWER

Receiving Reports: Why a Mailbox Does Not Hold Up

A compliance mailbox, a notice on the bulletin board and a phone number – that is how the internal reporting office is set up in many organizations. We show where that approach breaks down, which five problems it creates and how the same process runs with a digital reporting channel.

How it works today in most organizations

When the German Whistleblower Protection Act (HinSchG) had to be implemented, the decision was often quick and pragmatic: a mailbox will be set up. The compliance officer has an address created – "compliance@company.com" or "report@company.com" – IT sets up a forwarding rule, and a paragraph headed "Internal reporting office" appears on the intranet. On the bulletin board next to the canteen hangs a notice with the same address and an extension for anyone who would rather call.

Formally the obligation is met: there is an internal reporting channel, it has been made known, and there are people who consider themselves responsible. The process behind it consists of three building blocks. First the mailbox, which one or two people can access, plus the stand-in during vacation season. Second a folder on the drive where incoming reports are filed as mail exports or as PDFs printed and scanned again. Third the telephone: notes end up on a pad and later – sometimes – move into a memo.

As long as nothing happens, that holds. Reports are rare, and the mailbox comes to mind exactly when there is a mail in it. Nobody needs an overview of deadlines because no deadline is running, and nobody opens a case file because there is no case.

What happens with the first real report

Then comes the report that matters. It arrives from a private address, it contains a photo as an attachment, and it ends with the sentence: "Please do not pass on my name under any circumstances."

From that moment the construction no longer works. The sender address is visible in the mailbox – to everyone with access. The mail header carries technical details about the sender. The attached photo carries metadata that, depending on the camera, names the device and the place it was taken. On the mail server, logs are created that system administration can inspect, and the message sits in the backups. The promise of confidentiality was meant honestly. Technically it was not covered.

The moment it becomes visible

In day-to-day work this rarely shows. It shows up in three situations: when the reporting person asks about the status and nobody can prove when an acknowledgment of receipt went out; when a customer asks about the internal reporting office and its case statistics during a supplier review; or when the responsible person leaves the organization and the mailbox has to be handed over. At that point at the latest, the question is no longer "Do you have a reporting channel?" but "How do you make sure the reporting person cannot be identified – and where is that documented?"

The analysis

Five Problems a Compliance Mailbox Creates

They arise regardless of how conscientiously the reporting office works – they are properties of the channel, not of the person.

View the Digital Reporting Channel in preeco

Anonymity cannot be produced by email

The sender address, the mail header and the metadata of attached documents and photos name the reporting person or narrow them down far enough for an attribution to become possible. Anyone who wants to stay anonymous has to improvise – and in case of doubt drops the report instead.

Confidentiality ends at system administration

The mailbox sits on a mail server, it is backed up and it leaves logs behind. IT administration has technical access, even without any interest in the case. That circumstance is exactly what keeps employees from filing a report through the internal channel.

The statutory deadlines run unmanaged

The German Whistleblower Protection Act (HinSchG) requires an acknowledgment of receipt within seven days and feedback to the reporting person within three months. A mailbox knows no deadlines. It reminds nobody of anything, and afterwards there is no way to prove when which deadline was met.

Without an identity there is no follow-up question

Almost every serious report raises follow-up questions: which period, which department, which document? Anyone reporting anonymously cannot be reached by email. The case stays unresolved even though the reporting person would answer – they simply have no protected way to do so.

The case handling is not documented

Reports made by phone are not recorded, the steps taken sit in memos by different authors, and the measures decided on are scattered across mail threads. If an auditor asks how a specific case was handled, the handling has to be reconstructed after the fact.

The target process in six steps

A workable reporting channel differs from a mailbox not by more effort, but by a defined process. These six steps describe it.

1. Separate the channel from the mailbox. The report no longer goes to a mail address but to a publicly reachable form under its own URL – no login, no registration, reachable from any browser. For the notice on the bulletin board and for sites without office computers, a QR code can be generated. The form comes in up to 26 languages – in mixed workforces the difference between knowing about it and using it.

2. Make anonymity technically possible instead of promising it. Reporting persons decide for themselves whether to leave contact details. For an anonymous report, a protected access is created from a system-generated report ID and a password the person chooses, without any personal detail. preeco | whistleblower is its own platform for exactly this: no IP addresses or access data allowing conclusions about the identity are logged – to protect reporting persons, the application deliberately does not even write system log files.

3. Open the return channel. Through the same protected area, the reporting office and the reporting person stay in dialogue. Follow-up questions, interim updates and the final feedback run encrypted and in both directions – even for fully anonymous reports, without lifting the anonymity. Reusable text blocks speed up the correspondence.

4. Have the deadlines calculated instead of keeping them in your head. With the receipt, the clock starts automatically: seven days until the acknowledgment of receipt, three months until the feedback. The dashboard warns about deadlines falling due in the next 14 days and highlights reports not yet assigned to anyone.

5. Document the handling while it is running. For each area of application the system activates the matching checklist, mandatory fields prevent incomplete closures, and comments can be attached permanently to every check point. A 4×4 risk matrix of probability of occurrence and extent of damage makes the prioritization traceable. Reports received by phone or in person are created as reports too and become part of the same file.

6. Limit access and evaluate. A role model separates administration, ombudspersons and case handling; case handlers see only the reports assigned to them. For evidence there are exports per report as PDF, DOCX or ZIP with all attachments, for key figures filterable XLSX overviews – statistics on case numbers, categories and handling times that allow no conclusion about individual people.

Why the anonymous return channel makes the difference

In the debate about reporting systems, the anonymity of submission is usually in the foreground. In practice the second step counts: the anonymous follow-up question. For the reporting office, an anonymous report without a return channel is often useless, because the decisive detail is missing – the period, the unit involved, the evidence. Where a protected area exists in which the reporting person reads and answers under their report ID, an anonymous suspicion turns into a matter that can be clarified. The same area is where the acknowledgment of receipt and the feedback demonstrably arrive – two steps that regularly fail to happen in mailbox operation.

Before and after in direct comparison

Criterion Before: mailbox and notice After: digital reporting channel
Anonymity Sender, header and file metadata give the person away Report ID and a self-chosen password, no logging of access data
Protection from your own IT Mail server, backups and logs can be inspected Encrypted storage, deliberately no system log files on reporting persons
Follow-up questions Impossible with an anonymous report Encrypted dialogue in the protected area, anonymously as well
Deadlines Kept in someone's head or missed Seven days and three months monitored automatically per report
Reports by phone A note on a pad, no record Recorded as a report, documented in the same file
Documentation Memos and mail threads in several places Checklists, comments per check point and a timeline in the case
Access rights Whoever has the mailbox sees everything Role model, case handlers see only assigned reports
Reporting Compiled by hand for every request Export per report and filterable evaluation without personal data

In practice

What this looks like in preeco | whistleblower

The three building blocks that carry the process described above.

What the switch means in practice

The most common objection is that a system of its own is oversized for the two reports a year. That argument misjudges where the burden lies. The load is not the number of reports but what happens when a single one of them is serious – and whether the promise of confidentiality holds then. Setting it up is manageable: record the organization details, adjust the introductory texts, choose languages and areas of application, publish the URL and the QR code. The real part of the work is not technical but organizational: deciding who staffs the reporting office, who stands in, and who stays out in case of a conflict.

Three mistakes that devalue the reporting channel

Leaving the old mailbox running alongside. Two channels mean two deadline clocks and two states of documentation. If the mailbox is to stay, the rule has to be clear: reports arriving there are recorded in the system without delay.

Promising anonymity without checking it technically. A form on your own website is not yet an anonymous channel as long as IP addresses, access data or system logs are running in the background. When comparing systems, ask explicitly what is logged – not only what the form says.

Setting up the channel and not making it known. A reporting channel nobody knows about produces no reports, only the impression that there is nothing to report. A notice with a QR code, a paragraph on the intranet and a brief mention during onboarding cost little and decide whether it is used.

How to tell that it is time

As an entry point a mailbox is not a mistake. It becomes a risk as soon as at least one of these points applies:

  • You cannot prove when you sent an acknowledgment of receipt.
  • A reporting person asked for anonymity and you had to disappoint them.
  • More people have access to the mailbox than should be working on the case.
  • Reports made by phone exist only as a handwritten note.
  • Customers or auditors ask for case numbers and you count mails.

If none applies, the situation is in order. If two or more apply, the channel protects neither the reporting persons nor your organization.

FAQ

Frequently asked questions about the internal reporting channel

The German Whistleblower Protection Act (HinSchG) does not prescribe a particular tool; reports must be possible orally, in writing or, on request, in person. A mail address therefore does meet the formal requirement in principle. It meets the substantive requirements only to a limited extent: protecting the identity of reporting persons, handling anonymous reports including follow-up questions, and proving that the acknowledgment of receipt and the feedback were given on time can hardly be demonstrated with a mailbox.

Under the HinSchG there is no obligation to design reporting channels so that anonymous reports can be submitted. Anonymous reports that do come in should, however, be processed. In practice, anonymous submission is the decisive factor for uptake: anyone who fears reprisals only reports if the channel does not technically reveal their identity. In preeco | whistleblower the reporting person decides for themselves whether to leave contact details.

Receipt of the report has to be acknowledged to the reporting person within seven days. Within three months of the acknowledgment of receipt, they have to be given feedback on which follow-up measures are planned or have already been taken. Both deadlines are monitored automatically per report, and the dashboard warns about deadlines falling due within the next 14 days.

Under Section 12 (1) and (2) HinSchG, organizations with as a rule at least 50 employees have to set up an internal reporting office. Municipalities, districts and public institutions are subject to their own rules; they are affected from 10,000 inhabitants. The reporting office can be staffed internally or assigned to an ombudsperson or a service provider – the responsibility for setting it up stays with the organization.

Through a protected area that the reporting person enters with their report ID and a password they chose themselves. There they see the acknowledgment of receipt, read follow-up questions and answer them without revealing their identity. The correspondence is stored encrypted and is visible only to authorized case handlers. To protect reporting persons, preeco | whistleblower deliberately does not write system log files that would allow conclusions about their identity.

Go through your reporting channel together

Bring the process you use today. In 30 minutes we will show you how the digital reporting channel is set up and where the gaps are.