77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
HinSchG draft bill: history, current status, what the upcoming amendment means for internal reporting points
Whistleblower Protection

HinSchG draft bill: history, current status, what the upcoming amendment means for internal reporting points

7 July 202614 min readBy Dr. Henrik Bauer
CIVAC

The draft bill for the Whistleblower Protection Act from 2022 has had a significant impact on today's legal situation. Anyone who knows the history of its origins understands the scope for interpretation and can set up their internal reporting office in such a way that it can survive a future amendment.

The draft bill for the Whistleblower Protection Act (HinSchG-RefE) was published by the Federal Ministry of Justice on April 13, 2022 and triggered intensive association participation with over 80 statements from business, trade unions and civil society. The law finally came into force on July 2, 2023, significantly late compared to the implementation deadline of EU Directive 2019/1937 of December 17, 2021. The European Commission therefore initiated infringement proceedings against Germany and brought an action before the European Court of Justice on February 15, 2023, which significantly increased the political urgency of its adoption. The delay has made the draft bill a central document in legislative history because many of its justification elements live on in today's interpretation practice and will become relevant again in the event of a foreseeable amendment after the EU assessment in 2025/2026.

This article places the draft bill in the legislative history, shows the main changes between the draft and the passed law, describes the current status of the obligations for internal reporting offices and evaluates which adjustments can be expected in 2026. It is aimed at compliance officers, human resources managers and management in companies with 50 or more employees who are obliged to set up an internal reporting office in accordance with Section 12 Paragraph 2 of the HinSchG. As a compliance platform and officer-as-a-service, CIVAC delivers the appointment certificate for the internal reporting office, the procedural instructions and, if requested, the external reporting office function within two working days.

Key Takeaways

  • The draft bill from April 2022 is the template for the current HinSchG from July 2023, with substantial changes to the Federal Council procedure in terms of scope and anonymous reports.
  • Companies with 50 or more employees must have an internal reporting point with documented procedures, deadlines and confidentiality protection, otherwise they face fines of up to 50,000 euros.
  • CIVAC delivers the <a href="https://civac.de/de/roles/hinweisgeberschutz-meldestelle">internal reporting point</a> as an officer-as-a-service within two working days and integrates it into the compliance workspace with EU data residency.

The EU Whistleblower Directive 2019/1937 as a starting point

The EU Whistleblower Directive 2019/1937 was adopted by the European Parliament and the Council on October 23, 2019 and had to be transposed into national law by the member states by December 17, 2021, which only a few member states managed to do on time. It goes back to the experiences with whistleblower scandals such as Luxembourg Leaks, Panama Papers, Cambridge Analytica and Dieselgate, in which those who reported suffered personal and professional disadvantages and sometimes had to fight for their rights in court for years. The aim of the directive is to provide uniform protection for people who report violations of Union law, with clearly defined reporting channels, deadlines and protection against reprisals. The material scope covers twelve legal areas of Union law, including public procurement, financial services, anti-money laundering, product safety, traffic safety, environmental protection, consumer protection, data protection and protection of the Union's financial interests, as well as tax law and competition law.

The directive is formulated as a minimum harmonisation. Member States are free to extend the scope of application to other areas of national law, which most European states have done to varying degrees. Germany has made precisely this expansion in the HinSchG and expanded the scope of application to include violations that are punishable by law and certain violations of national law that are subject to fines, insofar as they serve to protect life, limb or health or to protect the rights of employees or their representative bodies. At this point, the draft bill from April 2022 was worded much more conservatively than the later law, which explains the later debate. The expansion of the scope of application by the Bundestag in December 2022 triggered key points of contention that led to rejection in the Bundesrat and necessitated a conciliation procedure in which the scope of application was partially withdrawn.

Draft speaker April 2022: Key points and association participation

The draft bill of the Federal Ministry of Justice of April 13, 2022 (BMJ-RefE) originally envisaged the following key points: Obligation to apply from 50 employees (with a transition period until December 17, 2023 for companies with 50 to 249 employees), internal reporting point with confidentiality obligation and deadlines (confirmation of receipt within seven days, feedback within three months), external reporting point at the Federal Office of Justice with its own Obligation to process, protection against reprisals with reversal of the burden of proof, fines of up to 100,000 euros for intentional violations. Anonymous reports were expressly not required to be processed in the draft bill, which later became a central point of contention and contributed to the Federal Council's rejection. The assumption of the entire costs by the employer was not yet clearly regulated in the RefE.

In the association participation, business associations (BDI, BDA, DIHK) criticized the scope of application because it went well beyond the EU directive and would have meant a considerable bureaucratic burden for small and medium-sized companies. Trade unions and NGOs (DGB, Transparency International, Whistleblower Network) have criticized the lack of protection for anonymous reports, the unclear regulation of the burden of proof and the low level of fines. The Federal Council rejected the draft law on February 10, 2023 because, despite several changes, it continued to go beyond the EU directive and had a distorting effect on competition for German companies. In the mediation process, the scope of application was limited to national violations that were subject to criminal penalties and certain violations that were subject to fines, the obligation to process anonymous reports was eliminated, and the fine was halved to 50,000 euros. The HinSchG was passed again by the Bundestag on May 11, 2023 and came into force on July 2, 2023. The transition period for companies with 50 to 249 employees ended on December 17, 2023, and since then the obligation has applied without restriction to all 50-plus companies.

From the draft to the current law: What has specifically changed

The changes between the 2022 draft bill and the current HinSchG 2023 are significant in practice and shape the interpretation of today's obligations. First: scope. The RefE covered violations of all standards subject to fines, which affected practically every administrative offense procedure and the burden on reporting offices would have been enormous. The current law limits the scope of application to violations that are punishable by law and those violations that are subject to fines and that serve to protect life, limb, health or employee rights. Second: anonymous reports. The RefE provided for a target regulation for processing, the current law waives an obligation to process, but allows the possibility, with a clear recommendation in Section 16 Paragraph 1 Sentence 4 HinSchG.

Third: amount of fine. The RefE stipulated fines of up to 100,000 euros, the current law up to 50,000 euros according to Section 40 HinSchG, which was criticized because the deterrent character remained low compared to the EU. Fourth: reversal of the burden of proof. The RefE provided for a comprehensive reversal of the burden of proof in the event of allegations of retaliation, while the current law in Section 36 HinSchG provided for a presumption rule with the possibility of counter-evidence for the employer. Fifth: transition period. The RefE granted a transition period until December 17, 2023 for companies with 50 to 249 employees, and the current law until December 17, 2023 according to Section 42 of the HinSchG without any significant changes. The interpretation practice of the Federal Office of Justice and BaFin is based on the reasons for the law and the materials from the mediation process. Anyone who is familiar with the draft bill will recognise the scope for interpretation and can document the internal reporting office accordingly. In the CIVAC workspace, the procedural templates are designed in such a way that they will remain valid even under a stricter interpretation of a future amendment. The auditor calls, the evidence is ready.

Current obligations of the internal reporting office according to Section 12 ff. HinSchG

Companies that generally have at least 50 employees are obliged to set up an internal reporting office according to Section 12 Paragraph 1 of the HinSchG. The reporting point must be confidential, independent and adequately resourced in terms of staff, training, IT infrastructure and escalation channels. It can be staffed internally (e.g. compliance department, human resources department, representative) or outsourced to external third parties, such as lawyers, ombudspersons or specialised platforms with their own advisory expertise. Section 14 paragraph 1 sentence 1 HinSchG allows several companies, each with up to 249 employees, to merge into a common reporting office, for example within a group or an association structure. The requirement of independence prohibits the combination with functions that conflict with the activities of the reporting office, such as a supervisory function over reporting employees.

The mandatory deadlines for the reporting office are tight. According to Section 17 Paragraph 1 HinSchG, receipt of a report must be confirmed within seven days unless this jeopardizes the protection of identity. No later than three months after the confirmation of receipt, the person providing the information will receive feedback about planned or taken follow-up measures and the reasons for them, which may include interim information about the processing status. The report is documented in accordance with Section 11 of the HinSchG with a retention period of three years after completion of the procedure. Violations are punished in accordance with Section 40 of the HinSchG, for example with a fine of up to 20,000 euros if reports are obstructed or up to 50,000 euros if the confidentiality requirement is violated. An overview of the obligations is stored in the CIVAC workspace as a procedural instruction with version status, so that any adaptation to later amendments is carried out without any transition risks.

Channels and confidentiality: Written, oral, personal

According to Section 16 Paragraph 1 HinSchG, the internal reporting channels must enable both oral and written reports, in the communication languages ​​that are relevant for the workforce. At the request of the reporting person, a personal meeting must be offered within a reasonable period of time, which practically means that the reporting office must be reachable by telephone or video conference and can also facilitate on-site appointments. The written report is typically made via a web-based whistleblower system, which transmits the identity of the reporting person in encrypted form and makes it confidentially available to the reporting office, ideally with the possibility of dialogue without revealing their identity. A mere email address is not enough because it does not guarantee sufficient confidentiality and does not enable a structured case file.

Confidentiality is the whistleblower's core protection. Section 8 HinSchG prohibits the disclosure of the identity of the person providing the information to persons outside the reporting office, with narrow exceptions for law enforcement authorities upon court order or with the consent of the person providing the information. Confidentiality also includes persons who are the subject of the report and other persons named in the report, which includes data protection for the accused. According to Section 40 Paragraph 2 Number 5 HinSchG, a breach of confidentiality is a fine of up to 50,000 euros and can also trigger claims for damages. Anonymous reports are permitted under applicable law, but are not required to be processed. In practice, processing is recommended because anonymous reports often lead to valuable information and not processing them in claims or criminal proceedings can be viewed as a breach of supervisory duty. In the CIVAC workspace, the channels including anonymous input are provided as an integrated function with EU data residency and audit trail.

Protection against reprisals and regulation of the burden of proof in accordance with Section 36 of the HinSchG

Protection against reprisals is the material heart of the HinSchG. Section 36 paragraph 2 of the HinSchG makes a presumption: If a person providing the information suffers discrimination in connection with their professional activity, it is presumed that this disadvantage is reprisal and is therefore prohibited under Section 36 paragraph 1 of the HinSchG. In the event of a dispute, it is the employer's responsibility to demonstrate that the measure is based on sufficiently justified reasons or that it is not based on the report. This burden of proof regulation is significantly stricter compared to general labour law and is relevant in dismissal protection processes, transfer disputes, wage reductions, refusals of promotion and comparable human resources decisions.

In practical terms, this means: If an employer terminates, transfers or refuses to promote an employee who has previously submitted a report, the employer must be able to derive the measure from documented, understandable reasons. The appointment certificate, signed, filed, verifiable. Without consistent documentation of the performance or behavioral assessment before and after the report, providing counter-evidence is difficult and will typically fail in the labour court. The compliance officer should therefore agree in writing with the human resources department on how personnel-related measures following a whistleblower report will be documented without violating the protection of confidentiality. The reporting office's procedural instructions contain clear rules, such as separating the reporting office file from the personnel file and determining access rights. These separation rules are technically implemented in the CIVAC workspace, so that no access to notifications by superiors or human resources managers is possible. Others run compliance like a filing cabinet. We run it like software. This technical separation is crucial in the process against the accusation of retaliation because it proves that the person responsible for human resources could have had no knowledge of the report.

Which amendment is pending: EU assessment 2026 and national adjustments

In accordance with Article 27 of Directive 2019/1937, the EU Commission submitted a report on the application of the directive by December 17, 2025 at the latest, which comparatively assessed the national implementations and contained recommendations for further development. On the basis of this report, adjustments to the directive can follow, which in turn require German implementation. The ongoing evaluation focuses in particular on the effectiveness of national implementation, the processing of anonymous reports, the level of sanctions, the burden of proof and the protective effect in practice. Anyone who follows the status of the reports can predict the direction in which a future amendment will go and prepare their internal reporting office accordingly without being surprised by a sudden change in the law.

There are several calls for reform at the national level. Firstly, the extension of the processing obligation to anonymous reports is being discussed, which would mean eliminating one of the main differences between RefE and the current law. Secondly, there is a call for the level of fines to be raised to the level of other EU member states, in France up to 60,000 euros for obstructing whistleblowers, in Belgium up to 250,000 euros for intentional violations. Thirdly, clearer regulations are required to maintain confidentiality towards parent companies, for example in internationally active companies with a holding structure and cross-border reports. An amendment is unlikely to be passed before the end of 2026. Anyone who aligns their internal reporting office with the stricter standard today (anonymous reports are processed, confidentiality towards the company is guaranteed, documentation of the burden of proof is systematically maintained) is prepared for every variant of an amendment. Deadline begins as soon as we become aware of it. This means that the reporting office does not become a reactive compliance element, but rather a structural function with a long half-life.

Interfaces to data protection, money laundering and compliance

The internal reporting office has numerous interfaces with other compliance functions, which can lead to conflicts and breaches of duty without clear regulations. Data protection: The processing of the personal data of the person providing the information and those affected by the report is based on a legal obligation under Section 10 HinSchG in accordance with Article 6 Paragraph 1 Letter c GDPR. The processing must be entered in the register in accordance with Art. 30 GDPR; an order processing contract in accordance with Art. 28 GDPR with an external reporting office or platform provider is required. Data protection impact assessments in accordance with Art. 35 GDPR must be carried out when the risk is high, which is regularly the case with reporting centres with particularly sensitive content. The data protection officer must be involved in the set-up process.

Money laundering: Suspicious activity reports according to Section 43 of the GwG have their own strict confidentiality rules. A report to the internal reporting office that discloses a money laundering-relevant matter must be checked by the money laundering officer without violating the reporting obligation or the tipping-off ban, which requires a clear delineation of responsibilities. Compliance: The reporting office must be integrated into the general CMS, with a reporting line to the management and supervisory board (if there is one), at regular reporting intervals. Reports should contain anonymized aggregates (number of reports, subject areas, processing status) and should not identify individuals. If you also appoint a compliance officer, he or she will coordinate the reporting lines of all specialised officers. In the CIVAC workspace, 25 representative roles are managed in one platform, with separate rights, common reporting line and EU data residency. Audit-proof, documented, § 8 HinSchG-proof. The central platform turns parallel officer silos into a consistent compliance function with uniform reporting and escalation logic. This means that reports that affect several legal areas can be routed smoothly to the responsible representative function, with a complete audit trail and without breach of confidentiality.

Turn reading into a mandate.: Internal reporting office with CIVAC

If you want to set up an internal reporting point or bring an existing one up to date, start with a clear starter package: appointing the internal reporting point with an appointment certificate, defining the reporting line to management, drawing up procedural instructions with deadlines and confidentiality rules, setting up an encrypted reporting channel (written and verbal), training all employees about the existence and function of the reporting point. A verifiable reporting centre can be set up within 30 to 60 days, which fulfils the obligations according to Section 12 ff. HinSchG and is protected against fine proceedings.

CIVAC accompanies this development as a compliance platform and officer-as-a-service in two models. In the workspace model, you licence the platform for your internal reporting office and use the 490 audit templates, the appointment certificate template, the procedural instructions and the encrypted reporting channel as an immediately usable framework with EU data residency. In the officer-as-a-service model, we provide the external reporting point within two working days, instead of the classic two to six weeks for law firms or ombudsman offices. Both models use the same workspace, reporting line and templates, allowing for later switching without data migration. If you would like to know which solution is appropriate for your company size and how you can set up the reporting office robustly for a future amendment, write to info@civac.de or use the contact form on civac.de/faq. Within one business day you will receive an initial assessment with concrete next steps, a recommendation for the right model and an indicative timeline for the 30 to 60 day setup. This turns the obligation into a structured function that can withstand fine proceedings. Turn reading into an assignment.

FAQ

What significance does the draft bill have for the current interpretation?

The BMJ's draft bill from April 2022 is part of the legal materials and is used for the historical-systematic interpretation of the HinSchG. Anyone who knows the differences between the draft and the final version will recognise the scope for interpretation when it comes to the scope of application, the processing of anonymous reports and the assessment of fines. The materials are available in juris and in the Bundestag's documentation and are regularly quoted in comments.

At what size company is the internal reporting office mandatory?

According to Section 12 Paragraph 1 of the HinSchG, employers with at least 50 employees are obliged to set this up. A transition period until December 17, 2023 applied to companies with 50 to 249 employees. In certain sectors (financial services, anti-money laundering), the obligation applies under special laws regardless of the number of employees, for example under the KWG, WpHG or AMLA.

Does the reporting office have to process anonymous reports?

According to Section 16 Paragraph 1 Sentence 4 HinSchG, anonymous reports should be processed, but there is no mandatory obligation. In practice, processing is recommended because anonymous reports often provide valuable information and failure to do so can be viewed as a breach of supervisory duty in claims or criminal proceedings. A future amendment could make editing mandatory, so preparing today makes sense.

What fines are there for violations of the HinSchG?

According to Section 40 of the HinSchG, there are fines of up to 50,000 euros for violations of the confidentiality requirement or for reprisals, up to 20,000 euros for obstruction of reports and up to 10,000 euros for violations of organisational obligations. In addition, claims for damages under civil law can be made in accordance with Section 37 of the HinSchG, with no upper limit.

Can the internal reporting office be staffed externally?

Yes, according to Section 14 Paragraph 1 HinSchG, the internal reporting office can be outsourced to third parties, such as lawyers, ombudspersons or specialised platform providers such as CIVAC. The employer remains responsible for fulfilling the obligations and must provide the external representative with an appointment document, task description and reporting line. An order processing contract in accordance with Art. 28 GDPR is required.

How long do reports have to be kept?

According to Section 11 Paragraph 5 HinSchG, the documentation of the reports must be retained for three years after the completion of the procedure, but no longer than if this is necessary and proportionate to fulfil the requirements under this or another law. The data must then be deleted unless other retention obligations apply, for example for tax, accounting or law enforcement reasons.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles