Draft bill for the HinSchG: What became of the draft and what applies today
The draft bill for the HinSchG from April 2022 was changed several times during the legislative process. The article reconstructs the most important changes, shows the current legal situation and explains how you can set up an internal reporting office that complies with the HinSchG.
The Federal Ministry of Justice's first draft of the Whistleblower Protection Act (HinSchG) is dated April 13, 2022 and implemented the EU Whistleblower Directive 2019/1937 into German law. The draft was the subject of intensive consultation with associations, went through several changes, initially failed at the Federal Council, was revised in the Mediation Committee and the final version came into force on July 2, 2023 as the Whistleblower Protection Act of May 31, 2023. For companies with 50 to 249 employees, a transition period until December 17, 2023 applied. Anyone who sets up an internal reporting office or modernizes existing procedures today benefits from the historical classification because many questions of interpretation can be explained from the justifications of the draft bill and the later Bundestag printed matter.
This article reconstructs the most important stages of the legislative process, classifies the changes between the draft bill, government draft, Bundestag version and Mediation Committee and explains which obligations apply today. You will receive a plan for setting up a HinSchG-compliant reporting office, an overview of the protection claims of whistleblowers, a classification of interfaces to LkSG and GDPR as well as an audit scheme for management. The article also shows how the CIVAC workspace, as a compliance platform and officer-as-a-service, transfers the obligations into documented workflows and which deadlines must be adhered to today. The appointment certificate, signed, filed, verifiable.
Key Takeaways
- The draft bill from April 2022 envisaged, among other things, anonymous reporting channels and a fine of up to 100,000 euros; the final version softened the anonymity requirement.
- The current HinSchG has been in effect since July 2, 2023, with a transition period for companies with 50 to 249 employees until December 17, 2023.
- CIVAC operates a HinSchG-compliant internal reporting office as a compliance platform and officer-as-a-service with EU data residency.
The EU Directive 2019/1937 as a starting point
The EU Whistleblower Directive 2019/1937 was passed on October 23, 2019 and had to be implemented into national law by December 17, 2021. Germany missed this deadline by over 18 months. The directive requires Member States and companies with 50 or more employees to set up secure reporting channels for violations of EU law in twelve areas: public procurement, financial services, product and traffic safety, radiation protection, food safety, animal health, consumer protection, privacy and personal data, network and information security, violations of the Union's financial interests, violations in the internal market and violations of EU competition law.
Whistleblowers who receive information about violations in a professional context are protected. Protection against reprisals (termination, transfer, bullying, career blocking) is a central element. The reversal of the burden of proof according to Article 21 Paragraph 5 of the Directive means: Anyone who is disadvantaged must demonstrate the disadvantage; the employer must prove that the measure was not repressive. The federal government presented the draft bill on April 13, 2022 and went beyond the minimum requirements of the directive by also including violations of national law. This extension is now Section 2 HinSchG. The compatibility with Article 21 of the Basic Law (right to informational self-determination) was intensively debated in the legislative process. The CIVAC Role Reporting Office documents today's framework of obligations with tools and templates. Anyone who understands the meaning of the directive will avoid the most common misunderstandings: HinSchG is not just a reporting portal, but a protective regime with a reversal of the burden of proof that can discipline management in a tangible way. This is exactly why supervisors are increasingly focusing on workflow quality and reporting channels. A sample from the Federal Financial Supervisory Authority in 2025 showed that breaches of confidentiality and missed deadlines are the most common complaints, followed by a lack of independence of the internal reporting office.
Contents of the draft bill from April 2022
The draft bill of April 13, 2022 comprised 60 paragraphs and provided for the following key points. First: Valid from the first day after the announcement for companies with 250 or more employees, transition period for 50 to 249 employees until December 17, 2023. Second: Obligation to set up internal reporting points with anonymous reporting options as a duty, not as a choice. Third: external reporting offices at the Federal Office of Justice, BaFin and the Federal Cartel Office. Fourth: Protection of whistleblowers from reprisals, including claims for damages according to Section 37 of the draft. Fifth: Fines of up to 100,000 euros for violations of the obligation to set up an internal reporting system or to refrain from retaliation.
Sixth: Confirmation of receipt of a report within 7 days, feedback to the whistleblower within 3 months. Seventh: Obligation to provide documented follow-up action. Eighth: the whistleblower's right to choose between an internal and external reporting agency. Ninth: Scope expanded to include violations of national law, such as criminal offenses and certain administrative offenses. Tenth: no obligation to forward anonymous tips to external bodies, but obligation to process them. The association hearing in May 2022 produced over 100 statements, primarily from business associations (BDA, DIHK, BDI), trade unions (DGB, IG Metall), legal organisations and NGOs (Transparency International, Whistleblower Network). The criticism was directed at the implementation effort, the amount of the fine, the obligation to remain anonymous and the protection of professional secrets, such as legal confidentiality. Medium-sized companies in particular complained that an identical requirement for 50 or more employees would disproportionately increase the costs for small houses. The legal associations demanded clear exceptions for those subject to professional secrecy in order not to bring client relationships into conflict with the reporting obligation. Trade unions pointed out the need for a claim for damages with non-material damages, which was ultimately included in Section 37 of the HinSchG.
From draft to law: amendments 2022 and 2023
The government draft of July 27, 2022 softened some points of the draft bill. The mandatory anonymity option for internal reporting offices has been reduced to a target requirement; Employers were only obliged to process anonymous reports when they were received, not necessarily to set up an anonymous input channel. The amount of the fine was reduced from 100,000 euros to 50,000 euros, and the claim for damages was specified. The Bundestag passed the law on December 16, 2022 with 375 votes to 252. The Federal Council refused approval on February 10, 2023; The Mediation Committee met and agreed on a compromise version on May 9, 2023.
In the compromise version, the anonymity requirement was reduced again: Section 16 HinSchG requires that anonymous reports should be accepted, not necessarily. The amount of the fine remained at 50,000 euros for reprisals, 20,000 euros for obstructing reports and 10,000 euros for breaching confidentiality obligations. The Federal Council agreed on May 12, 2023, the law was announced on May 31, 2023 and came into force on July 2, 2023. Companies with 250 or more employees had to set up a reporting centre immediately, companies with 50 to 249 employees by December 17, 2023. Others run compliance like a filing cabinet. We run it like software., with documented confirmation of receipt and deadline calendar. Anyone who knows the genesis understands why today's legal text is formulated in a compromised manner in several places. These compromises give rise to the typical interpretation questions that arise today in audits and inquiries from authorities. Particularly noteworthy are the processing of anonymous reports, the interface between the internal reporting office and external reports to the authorities, as well as the protective effect of reversing the burden of proof for reports made a long time ago.
What applies today: Structure and duties of the internal reporting office
§ 12 HinSchG obliges employers with 50 or more employees to set up an internal reporting office. This must be confidential, accessible verbally and in writing, and anonymous reports should be able to be processed (§ 16 HinSchG). Section 14 allows a third person (e.g. an external service provider or lawyer) to be appointed as a reporting point. The reporting office must be independent in position and function, have the necessary specialist knowledge, maintain the confidentiality of the whistleblower's identity (§ 8) and have a direct reporting channel to management.
The processing steps are regulated in § 17 HinSchG: confirmation of receipt to the whistleblower within 7 days, checking the validity, follow-up measures (internal investigation, transmission to the responsible body, discontinuation of the procedure due to lack of sufficient suspicion), feedback to the Whistleblower within 3 months. Section 11 requires documentation of all steps, with storage for 3 years after completion of the procedure, up to 5 years at the most. Section 9 protects the identity of the whistleblower; exceptions only exist in the case of a court order or compelling reasons for the criminal proceedings. The CIVAC Reporting Office fully covers these obligations as a platform module with a workflow engine, deadline calendar, role-based access and EU data residency. Pseudonymous communication, automated confirmation of receipt, multilingual intake and an audit-proof file logbook are included. In the audit, a report from the workspace shows the date of receipt, step, person responsible and deadline for each process on a timeline. The obligation to substitute during vacation and illness is regulated organizationally and documented in the appointment certificate. This means that the reporting office remains able to act, even if the person primarily responsible is absent, and the 7-day deadline is reliably adhered to. Training for representatives and regular practice cases are part of the minimum standard of a resilient company.
Protecting whistleblowers from reprisals
§ 33 HinSchG protects whistleblowers from reprisals. Retaliation is any unjustified act or omission in a professional context that is prompted by a report or disclosure and causes disadvantages to the whistleblower. Classic examples are termination, warning, transfer, suspension, withdrawal of tasks, bullying, career blocks, failure to provide training, poorer appraisals, financial disadvantages, blacklists, psychiatric examinations or refusal to extend the contract.
§ 36 HinSchG reverses the burden of proof: Anyone who claims retaliation must explain the measure, the employer must prove that the measure was not repressive. This reversal of the burden of proof takes effect as soon as a report is received and applies to internal and external reports. Section 37 HinSchG grants compensation, including non-material damages. Fines according to § 40 HinSchG affect the employer for reprisals (up to 50,000 euros), for obstructing reports (up to 20,000 euros) and for breaches of confidentiality (up to 10,000 euros). Practice in 2024 shows: Labour courts consistently recognise the reversal of the burden of proof. In the case of LAG Mecklenburg-Western Pomerania (5 Sa 152/24), a termination was deemed ineffective because the defendant could not prove an objective reason for termination regardless of the previous report. The deadline expires as soon as it is known, here too, because any delay shifts the chain of documents to the detriment of management. The CIVAC reporting office documents the date of receipt, group of people and communication status in an audit-proof manner. So the reversal of the burden of proof remains an opportunity, not a risk: those who document have the factual reasons for the measure at hand in a comprehensible manner. Personnel files, performance reviews, employee interviews and HR decisions are linked to the date and person responsible so that any suspicion of retaliation can be refuted with reliable evidence. The clock starts on awareness.
External reporting offices and whistleblower protection under EU law
In addition to the internal reporting office, there are external reporting offices. Section 19 HinSchG designates the Federal Office of Justice as the central external reporting point for all violations that are not expressly assigned to other bodies. Section 21 designates BaFin as an external reporting office for violations of financial services law. Section 22 allocates the Federal Cartel Office for violations of antitrust law. Whistleblowers can freely choose between internal and external reporting offices (Section 7 Paragraph 1); there is no obligation to report internally. However, Section 7 Paragraph 1 recommends internal reporting as a first step, provided effective processing is possible internally.
Disclosure to the public (whistleblowing in the narrower sense) is only protected to a limited extent under Section 32 HinSchG: It is privileged if there is no effective internal or external processing, if there is an immediate danger to the public interest or if the whistleblower has important reasons for disclosure. In practical terms, this means for companies: A functioning, visible and low-threshold internal reporting point reduces the likelihood that whistleblowers will go directly to regulators or the media. With the CIVAC reporting point, you licence the workspace for your internal processing, or have our representatives appointed as a reporting point. In both models, the reversal of the burden of proof under Section 36 HinSchG can be managed by management through complete documentation. External reporting offices relieve the burden on the whistleblower, but are slower and less close to the case; A well-managed internal channel is therefore usually the wish of both sides. The supervisory authorities expect documented internal procedures with clear escalation channels, otherwise external processing with the associated reputational and procedural costs is getting closer.
Interfaces: LkSG, GDPR and HinSchG
The reporting office according to HinSchG actually forms the backbone of several compliance procedures. Section 8 LkSG requires a complaint procedure for supply chain risks, which is integrated into the HinSchG reporting office in many companies. The requirements differ in some cases: LkSG requires global accessibility for affected third parties (e.g. employees at suppliers in Bangladesh), HinSchG primarily for employees. Multilingual skills (English, Mandarin, Turkish, Hindi, Bengali) are regularly required. The processing deadlines differ: LkSG without a rigid deadline (proportionate deadline), HinSchG with 7 days for confirmation of receipt and 3 months for feedback.
The GDPR interface is delicate. Art. 6 GDPR requires a legal basis for the processing of personal data in the reporting office. Section 10 HinSchG only allows the processing of sensitive data (e.g. health and religious data) to the extent necessary for processing. Retention is limited to 3 years after completion, with a maximum of 5 years. The EU AI Act requirements also apply to automated processing tools (AI-supported analysis), as whistleblowing procedures can be classified as potential high-risk applications. The DSB interface is also important because many reports touch on data protection issues. The CIVAC role DSB therefore works closely with the reporting office. The platform maintains the retention periods automatically and deletes logs after expiry. Interfaces to LkSG complaint procedures, BAFA reports and ESRS disclosures are managed consistently so that an incident does not result in contradictory statements to supervisory authorities. This also applies to interface work, because delays between the receipt of the report and the data protection check can otherwise alert supervisors and undermine trust in the compliance system. Clean interfaces are often more valuable than a perfectly developed individual discipline. Audit-proof, documented, § 11 HinSchG-proof. With clear data flows, you retain full control over processing steps, deadlines and reporting channels, even if you have multiple responsibilities.
Common mistakes when setting up a HinSchG reporting office
In practice, HinSchG reporting centres fail due to six typical errors. First: confidentiality without technical separation. A shared mailbox with other HR functions violates Section 8 HinSchG. Second: lack of anonymous reporting option. § 16 HinSchG is intended to provide anonymous processing; Practice in 2024 shows that supervisors increasingly see this as de facto mandatory, because otherwise the whistleblower will actually be forced to externalize. Third: deadlines are not met. 7 days confirmation of receipt, 3 months feedback are non-negotiable; a violation is an indication of an ineffective reporting centre and triggers externalization.
Fourth: lack of multilingualism. Global companies with supply chains in Asia or Latin America require English, Mandarin, Spanish, Turkish, Hindi and Bengali as a minimum standard. Fifth: unclear responsibility. When compliance, HR, legal and IT security are involved at the same time without clear roles, multiple interventions and confidentiality breaches arise. Sixth: poor documentation. § 11 HinSchG requires written documentation of all steps; Pure email correspondence does not meet this requirement because it is not versioned. CIVAC addresses all six errors with a dedicated reporting point module: confidentiality via encryption, anonymous intake options, workflow with automated deadline reminders, multilingualism, clear role matrix with four-eyes principle and versioned documentation. The auditor calls, the evidence is ready. This is how you transform the reporting office from a risk item into a control instrument for your internal control system. They recognise early warning indicators, identify clusters per department or location and objectify the discussion with the works council, management and supervisory board using reliable key figures. A purely mandatory task becomes a control instrument that simultaneously ensures the protection of whistleblowers and transparency towards supervisory authorities. Audit-proof, documented, § 40 HinSchG-proof. Anyone who has experienced how a reporting office comes under pressure without tools will appreciate the structural relief provided by a platform with clear workflows.
Turn reading into an assignment
The draft bill for the HinSchG has been history since 2023; the current whistleblower protection law now determines the obligations of employers with 50 or more employees. If you want to set up an effective internal reporting office, you must systematically interlink confidentiality, independence, processing deadlines, reversal of the burden of proof and documentation. CIVAC bundles these requirements as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives appointed as reporting points. In the first case, your employees receive a workflow module with a deadline calendar, anonymous intake, multilingualism, role-based access and versioned documentation. In the second case, CIVAC provides an externally appointed reporting officer (lawyer or certified compliance officer) within 2 working days, with an appointment certificate, reporting line and 490 audit templates.
In a 30-minute initial meeting, we record the number of employees, language profile of the workforce and supply chain, existing procedures and audit dates. We show you the workspace, the confirmation of receipt, the escalation matrix and the BAFA/BfJ reporting schema. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. A HinSchG reporting office without a documented workflow is the most expensive booking rate in your financial year in the retaliation process. With CIVAC, it is the cheapest insurance against Section 40 HinSchG and at the same time an early warning system for strategic compliance risks. Once the platform has been put into operation, the reporting office can be rolled out to subsidiaries and foreign units without any additional effort and the evaluation can be displayed in a consistent format for the board of directors and supervisory board. This means you comply with the HinSchG, LkSG complaint procedures and ESRS disclosure from one database. The investment often pays off from the first serious incident because evidence and documentation are available without any search effort and procedures are therefore shorter and more predictable.
FAQ
What was the difference between the draft bill and the final HinSchG?
The draft bill from April 2022 included, among other things, an obligation to set up anonymous reporting channels and fines of up to 100,000 euros. In the final version of May 31, 2023, the anonymity requirement in Section 16 HinSchG was reduced to a target regulation and the fines were reduced to 50,000 euros for reprisals, 20,000 euros for obstructing reports and 10,000 euros for breaches of confidentiality.
Since when does the HinSchG apply to my company?
For companies with 250 or more employees, the HinSchG has been in effect since July 2, 2023. For companies with 50 to 249 employees, a transition period until December 17, 2023 applied. Companies with fewer than 50 employees are not obliged, but benefit from the voluntary institution in the sense of early risk detection and insurability against internal breaches of duty.
Does my internal reporting office have to accept anonymous reports?
Section 16 HinSchG requires that anonymous reports be accepted. Practice in 2024 shows that supervisors actually view this as mandatory because without an anonymity option, whistleblowers are pushed to the external reporting office and trust in internal processing decreases. CIVAC offers configurable anonymous intake options with pseudonyms for follow-up communication and multilingual access.
Who can be an internal reporting point?
Any person who is independent in position and function and has the necessary specialist knowledge, who can maintain confidentiality and has a direct reporting line to management. Section 14 HinSchG allows the commissioning of third parties, such as lawyers or specialised compliance service providers. In the officer-as-a-service model, CIVAC provides an external reporting point within 2 working days, with an appointment certificate, reporting line, representation regulations and workspace access.
What deadlines do we have to adhere to when processing?
Confirmation of receipt to the whistleblower within 7 days, feedback on follow-up measures within 3 months (Section 17 HinSchG). All steps must be documented in writing (§ 11 HinSchG), retained for 3 years after completion, a maximum of 5 years. The CIVAC workspace automatically manages these deadlines, sends reminders to those responsible and logs every step in an audit-proof manner.
What fines are there for violations of the HinSchG?
Up to 50,000 euros for reprisals against whistleblowers, up to 20,000 euros for obstructing reports, up to 10,000 euros for violating the confidentiality of identity (Section 40 HinSchG). In addition, there are civil law claims for damages in accordance with Section 37 of the HinSchG, including non-material damages. The reversal of the burden of proof according to Section 36 shifts the burden of proof in the event of suspicion of retaliation to the employer.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.