Security23 Sep 20268 min read

The internal reporting channel: what German companies have to run

Germany has had the Hinweisgeberschutzgesetz, the Whistleblower Protection Act, since 2023. It puts EU Directive 2019/1937 into German law, and for most mid-sized employers it comes down to one concrete duty: run an internal channel where people can report certain violations, and deal properly with what arrives there.

This article is general information for HR and compliance teams, not legal advice. For your specific situation, ask a lawyer.

Which companies have to run one

The duty applies to employers with 50 or more employees. Larger companies had to be ready first, and since 17 December 2023 it covers everyone from 50 upwards. Some sectors, in particular parts of financial services, have to run a reporting channel regardless of headcount.

Companies with 50 to 249 employees may share resources for the reporting channel with other companies, which makes a joint solution inside a group or between smaller firms possible. Responsibility for following up on a report and for remedying the problem stays with the company the report concerns.

What can be reported

The law does not cover every complaint about the workplace. Its scope is criminal offences, a defined set of administrative offences, in particular those that protect life, limb or health or the rights of employees and their representative bodies, and breaches of a listed range of EU rules, for example in data protection, product safety, environmental protection, public procurement and financial services. Protection is not limited to permanent staff: applicants, former employees, temporary workers and people working for suppliers are covered too.

In practice most companies accept a wider range of reports anyway. Somebody who has just witnessed something cannot be expected to classify the legal basis first. Sorting that out is the job of the people who handle the case.

What the channel has to be able to do

  • Accept reports in writing or orally, and on request in a personal meeting within a reasonable time.
  • Confirm receipt to the reporting person within seven days.
  • Be operated by a person or unit that is independent in this function and free of conflicts of interest.
  • Check whether the report falls within the scope of the law, stay in contact with the reporting person and ask for further information where needed.
  • Take follow-up action: an internal investigation, referral to the responsible internal unit, closing the case, or handing it to the competent authority.
  • Give the reporting person feedback within three months of the confirmation of receipt, covering the follow-up action planned or already taken and the reasons for it.

The deadlines are what most companies miss. Seven days and three months are short once a case has to be scheduled around holidays and sick leave, so name a deputy before the first report, not after it.

Confidentiality of the reporting person

The identity of the reporting person has to be kept confidential. The same protection applies to the people named in the report and to others affected by it. Only the people who run the reporting channel, and those supporting them in that work, may learn who reported. The law allows confidentiality to be lifted only in narrow, defined cases, for example towards criminal prosecution authorities.

In day-to-day operation this is mostly an access problem rather than a policy problem. A shared mailbox that the IT team can open, a case list on a network drive, a printout left on a desk: each of these is a route by which the name reaches somebody who is not allowed to have it.

The ban on reprisals

Anyone who reports in line with the law may not be disadvantaged for it. Reprisals include dismissal, a warning, a transfer, a withheld promotion, a worse performance rating or a refused training request. The law also shifts the burden of proof: if a reporting person suffers a disadvantage at work and claims it is a reprisal, the employer has to show that the measure had other reasons.

That single rule has a practical consequence for HR. Ordinary personnel decisions about a person who has reported need to be documented and dated as they happen. A decision that was in preparation long before the report is easy to defend if the file shows it, and very hard to defend if it does not.

Documentation and deletion

Reports have to be documented in a way that can be retrieved later, while respecting confidentiality. An oral report may be recorded only with the consent of the reporting person. Otherwise it is written up as a transcript or a summary, and the reporting person gets the chance to check the record and confirm it.

The documentation is to be deleted three years after the procedure has been closed. It may be kept longer where that is necessary and proportionate, for example while a legal dispute is still running. Decide and write down your retention rule before the first case arrives. Deciding it afterwards, with one specific person's file in front of you, is much harder to do neutrally.

Anonymous reports

German law does not require companies to design their channel so that anonymous submissions are technically possible. It does say that anonymous reports should be processed. Most companies go further and allow anonymous submission, for two reasons.

The first is simply that people who are afraid of being identified either report anonymously or not at all, and a report that never arrives cannot be investigated. The second is that reporting persons may also go to the external reporting channel at the Federal Office of Justice, and they are free to choose. A company that would rather hear about a problem itself, first, has to be the easier and safer route.

The usual objection is that you cannot ask an anonymous reporter follow-up questions. That only holds if the channel has no way back to them. A channel that lets an anonymous reporter return, read a question and answer it removes most of the objection, and it is also what makes the three-month feedback possible in an anonymous case.

Internal team, ombudsperson or software

The law lets you run the channel with your own people or entrust it to a third party. Three set-ups are common, and many companies combine them.

An internal unit

Cheapest to start and closest to the business. It works where somebody can genuinely be independent in that role and where the company is big enough that the handler is not investigating their own manager. Compliance, legal or HR usually take it on. If HR takes it on, plan for the cases that are about HR.

An external ombudsperson

Usually a lawyer who receives reports and passes on the substance. Strong on distance and on trust, and a sensible choice for smaller companies with no compliance function. It costs money per case, and you still need an internal process for everything that happens after the report is handed over.

Reporting software

A portal covers intake, deadlines, case documentation and the access trail, and of the three options it is the one that reliably produces the evidence you need later. It decides nothing by itself. You still need named, trained handlers and a deputy.

A short set-up checklist

  • Decide who the reporting office is and name a deputy.
  • Fix the channels: written, oral, and a personal meeting on request.
  • Write the process down, with the seven-day and three-month deadlines in it.
  • Decide whether anonymous reports are possible, and say so publicly.
  • Set the retention and deletion rules.
  • Involve the works council early where one exists, since a reporting system normally touches its co-determination rights.
  • Tell employees that the channel exists, what it is for and what happens to a report.
  • Train the handlers and run one test case before going live.

How Persohap handles this

Reports in Persohap can be submitted anonymously. The reporter's account stays linked to the case, which is how they can follow it and answer a handler's questions, but their name is never shown to handlers and never appears in any response. At submission the reporter names exactly who beyond the administrators may see the case, and that grant is fixed at that moment: a later reorganisation or a new manager never gains access.

A request for a case somebody may not see returns "not found", because "forbidden" would already confirm that the case exists. Every view, including passive ones, is written to an append-only access log that administrators can read. Evidence files are scanned for malware and filed under the case rather than under a person. The data is hosted in Frankfurt, Germany.

See the Speak-Up channel

Get started

See it working, not just described.

Every decision in these posts is visible in the product. We will walk you through whichever one you care about.