77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Understand § 2 HinSchG: Which violations fall within the scope of application
Whistleblower Protection

Understand § 2 HinSchG: Which violations fall within the scope of application

18 August 202612 min readBy Dr. Henrik Bauer
CIVAC

Section 2 HinSchG decides whether a reference is protected or not. The article explains the factual scope of application, classifies criminal offenses and fines and shows how the internal reporting office implements the distinction in a documented manner.

Section 2 of the Whistleblower Protection Act (HinSchG) has regulated the material scope of protection for whistleblowers since July 2, 2023. The standard lists exhaustively which violations trigger a protected report and is narrower than the popular notion of general whistleblower rights. Anyone who does not clearly delineate the facts risks two things at the same time: on the one hand, the rejection of legitimate reports with the consequence of personal liability for employees in the internal reporting office, and on the other hand, the acceptance of reports for which the law does not provide protection, with the corresponding consequences in labour and data protection law.

This article explains the structure of Section 2 HinSchG, translates the reference chains into an auditable checklist and shows how a professionally managed internal reporting office documents the initial inspection. The addressees are compliance officers, management and supervisory boards who want to set up their reporting office without gaps in accordance with Section 12 ff. HinSchG. The text assumes that your organisation has a fundamental obligation and that the question of WHAT, not OB, must be answered. At the end you will receive a concrete subsumption matrix that you can incorporate into your procedural rules, as well as a reference to the interfaces to GDPR, NIS-2 and LkSG.

Key Takeaways

  • § 2 HinSchG is formulated conclusively and only protects references to violations that are expressly listed.
  • Criminal offenses are always covered; administrative offenses are only covered where the life, health and rights of employees or representative bodies are protected.
  • The internal reporting office must document the scope check in a comprehensible manner, otherwise whistleblower protection will no longer apply for formal reasons.

Material scope of application according to Section 2 Paragraph 1 HinSchG

§ 2 Paragraph 1 HinSchG names three major categories that fall under whistleblower protection. Firstly, all violations that are punishable by law, i.e. crimes within the meaning of the Criminal Code and all ancillary criminal law, from white-collar criminal law to environmental criminal law to criminal tax law. Secondly, certain violations are subject to fines, provided that the violated regulation serves to protect life, limb or health or to protect the rights of employees or their representative bodies. Thirdly, a long catalogue of reference standards under EU law, which ranges from money laundering prevention to financial services, product safety, traffic safety, food safety, public health, consumer, data protection and competition law to nuclear safety.

This tripartite division is crucial because it decides the question of whether a reference deserves protection. A reference to a purely labour law conflict that is neither punishable nor falls under the catalogue of fines in Section 2 Paragraph 1 Number 2 HinSchG is not a protected reference within the meaning of the law. The internal reporting office according to HinSchG must make this distinction for every incoming report and document the results of the check. § 11 HinSchG requires a documentation obligation, which usually ends with deletion after three years, but the process must be audit-proof by then. In practice, we recommend attaching a subsumption note to every incoming report, which justifies the assignment to numbers 1, 2 or 3 to 10 and cites the relevant standard. These notes are stored encrypted in the workspace; only the reporting centre manager and the documented representative have access. The list in Section 2 HinSchG is exhaustive, which means that a reference to a situation that is morally problematic but does not fall under one of the three categories does not trigger any legal protection. This harsh consequence is underestimated in many house instructions and leads to unnecessary conflicts between the reporting office, the human resources department and the whistleblower.

Which crimes fall under Section 2 Paragraph 1 Number 1

Section 2 paragraph 1 number 1 HinSchG covers all violations that are punishable by law. This includes classic economic crimes such as fraud according to § 263 StGB, breach of trust according to § 266 StGB, corruption and bribery in commercial transactions according to §§ 299, 300 StGB, tax evasion according to § 370 AO, subsidy fraud according to § 264 StGB as well as all offenses of secondary criminal law. This also includes violations of foreign trade law, the Banking Act, the Securities Trading Act, the Money Laundering Act and the Medicines Act, provided they are punishable by law. In addition, there are environmental crimes according to §§ 324 ff. StGB, violations of the Chemicals Act and the Narcotics Act, if they are prosecuted under criminal law.

In practical terms, this means: As soon as a report gives rise to the suspicion of a crime, the entry hurdle of § 2 HinSchG has been cleared. The reporting office does not have to conclusively check whether criminal liability actually exists. It is sufficient that the reported facts, if reasonably assessed, at least allow a criminal offense to be considered. Section 33 HinSchG expressly protects whistleblowers even if the suspicion later turns out to be incorrect, as long as the report was made in good faith. Deadline begins as soon as we become aware of it. According to Section 17 HinSchG, the reporting office confirms receipt within seven days and provides feedback on the follow-up measures taken after three months. Anyone who misses this deadline risks loss of trust on the part of the whistleblower and, in repeated cases, a fine in accordance with Section 40 of the HinSchG. The workspace displays these deadlines in the dashboard and sends automatic reminders to the person responsible. An initial triage is helpful, in which the suspicion is classified into three levels of severity: firstly, an indication of minor violations, secondly, an indication of structural violations within the company, and thirdly, an indication of systemic violations with an external impact on customers, authorities or the capital market. The last category regularly triggers additional ad hoc obligations according to Section 26 MAR.

Violations punishable by fines: the hurdle of protection

Section 2 paragraph 1 number 2 HinSchG is much narrower than number 1. Violations that are subject to a fine are only covered if the violated regulation serves to protect life, limb or health or to protect the rights of employees or their representative bodies. This includes numerous administrative offenses from the Occupational Safety and Health Act, the Working Hours Act, the Maternity Protection Act, the Youth Employment Protection Act, the Works Constitution Act and the General Equal Treatment Act. Violations of Section 130 OWiG, i.e. the duty of supervision in the company, are also included if the underlying duty serves the protected group of people. Violations of § 17 ArbSchG, § 22 JArbSchG or § 21 MuSchG are also regularly recorded.

Pure traffic offenses without personal reference, violations of the provisions of the trade regulations without the protection of employees or mere administrative violations are not recorded. In these cases, the reporting office must specifically check the protective nature of the violated standard and record it in the file. Compliance officers use a standardised application area matrix that links each standard under consideration with the associated protection direction. The appointment certificate, signed, filed, verifiable. Without this matrix, gaps arise in the audit, which the data protection officer and the supervisory authority alike criticize. A pragmatic rule of thumb: If the standard protects people, notices of fines are covered by the HinSchG, if it only protects public order or administrative efficiency, then it doesn't. This rule of thumb does not replace subsumption in individual cases, but it does help with quick triage in incoming mail. A typical example is the violation of Section 17 Paragraph 1 ArbSchG, the obligation to appoint an occupational safety specialist. This standard serves the direct purpose of protecting employees and is therefore covered by Section 2 Paragraph 1 Number 2 HinSchG; an indication of this is a protected report with all the legal consequences from Sections 33 to 39 HinSchG.

The catalogue under Union law in Section 2 Paragraph 1 Numbers 3 to 10

Numbers 3 to 10 of Section 2 Paragraph 1 HinSchG adopt the catalogue of the EU Whistleblower Directive 2019/1937 and expand it to include national specifics. This includes violations of the Money Laundering Act and of EU regulations to prevent money laundering and terrorist financing. There are also regulations on product safety and product conformity, safety in road, rail, sea and air transport, environmental protection, radiation protection and nuclear safety, food and feed safety, animal health and welfare, public health including patient rights and the fight against antibiotic resistance.

Furthermore covered are violations of consumer protection, data protection and the security of network and information systems, competition and state aid law as well as violations in the area of corporate taxes and the financial interests of the company Union. This list is cumbersome, but conclusive. In practice, this means: A reference to a data protection violation according to Art. 5 or Art. 32 GDPR is recorded in number 7. An indication of a violation of the provisions of the NIS 2 Directive is recorded in number 8. A reference to a violation of the Supply Chain Due Diligence Act is recorded in number 9, provided that the offenses are punishable by a fine. The reporting office must master these referral chains or use a platform that it has provided. In the workspace, the catalogue is displayed as a data model; each report is automatically checked against the categories upon receipt and provided with a suggestion for subsumption, which the reporting centre management verifies. Important: Section 2 paragraph 2 of the HinSchG also expressly mentions violations of the requirements for determining remuneration in the bodies of stock corporations and of the requirements of stock corporation law and GmbH law, insofar as they are punishable by law. This extension is overlooked in practice and is particularly relevant for listed corporations and larger family businesses.

Exceptions according to § 5 HinSchG: what is not covered

§ 5 HinSchG expressly excludes certain situations from the scope of application, although they would fall under § 2 HinSchG. Information that is subject to national security, classified information, processes of the Office for the Protection of the Constitution, the Federal Intelligence Service and the Military Counterintelligence Service are recorded. Also excluded is information that is subject to medical or legal confidentiality or consultation secrecy, as well as confessional and pastoral secrecy. The confidentiality of judicial deliberations also remains unaffected. These exceptions must be interpreted narrowly; any extension would undermine the protective purpose of the law.

§ 5 paragraph 2 HinSchG is practically relevant: information that is subject to the obligation to maintain the secrecy of judicial advice is excluded. This means that internal notes from supervisory board meetings, which are subject to confidentiality in accordance with Section 116 AktG, are problematic if a whistleblower quotes them in full. Section 6 HinSchG also keeps the relationship to other proceedings open: official or judicial hearing rights, for example under Sections 33, 33a OWiG or Section 28 VwVfG, remain unaffected. The reporting office documents these interfaces clearly so that the auditor can classify the process. Audit-proof, documented, § 2-proof. A special constellation arises in banks and insurance companies, where the reporting obligations under the KWG, WpHG and AMLA run parallel. The workspace brings together these parallel obligations in a uniform process file without mixing the respective confidentiality areas, so that the BaFin and BAFA supervisors can trace the complete path at any time. The relationship with criminal prosecution is also regulated in Section 7 HinSchG: whistleblowers may go directly to law enforcement authorities under the conditions stated there without losing protection. The internal reporting office must present this option transparently in its information to the workforce.

Entry check of the registration office: the practical procedure

The operational implementation of § 2 HinSchG requires a structured entrance examination in a maximum of three steps. Step one is to record the facts and clarify the formal requirements: Is there a report within the meaning of Section 3 HinSchG? Is the person providing the information registered under Section 1 Paragraph 2 of the HinSchG? Was receipt confirmed within seven days? Step two is the legal subsumption under Section 2 HinSchG: Which norm could be violated if it falls under numbers 1, 2 or 3 to 10? Step three is the decision on protection status and the initiation of follow-up measures in accordance with Section 18 HinSchG, such as internal investigations, forwarding to authorities or completion of the process with justification.

These three steps are documented in an auditable note, which can be presented to the Federal Financial Supervisory Authority, the Federal Office of Justice or the Federal Cartel Office if necessary. The auditor calls, the evidence is ready. The Compliance platform and Officer-as-a-Service from CIVAC stores these subsumption steps as a workflow in the workspace and guides the reporting office securely through the check. Fines according to Section 40 of the HinSchG can be up to 50,000 euros for intentionally obstructing a report and up to 20,000 euros for intentional violation of the confidentiality requirement of Section 8 of the HinSchG. The platform represents 25 officer roles, so that parallel duties of DPO, ISB and money laundering officer are not duplicated. Licence the workspace for your internal representatives or have our representatives order it. In both models, the ISO/IEC 27001:2022 hosting environment with EU data residency ensures the protection of whistleblowers' identity data.

Differentiation from information outside of Section 2 HinSchG

A particular challenge are reports that appear legitimate but lie outside the scope of Section 2 of the HinSchG. Examples from practice include an indication of bullying behaviour without criminal relevance, an indication of a purely civil contract dispute, an indication of internal dissatisfaction with managers or an indication of strategic decisions that the whistleblower considers to be economically unwise. Such reports are not protected information within the meaning of the HinSchG, but they can fall under other protection regimes: the AGG complaint procedure according to § 13 AGG, the co-determination rights of the works council according to §§ 84 ff. BetrVG or general employment law complaint channels according to the respective works agreement.

The reporting office may not simply reject such reports, but must forward them to the responsible office or inform the whistleblower which route is open. This forwarding will only take place with the express consent of the person providing the information, so that the confidentiality requirement in accordance with Section 8 of the HinSchG is maintained. Others run compliance like a filing cabinet. We run it like software. In the workspace, the forwarding is stored as an encrypted transfer with consent documentation, so that neither the whistleblower is disadvantaged nor the company is confronted with unjustified allegations of obstruction. According to Section 12 Paragraph 2 of the HinSchG, anyone who has more than 50 employees is obliged to set up an internal reporting office, regardless of how many reports are actually received. The appointment certificate, signed, filed, verifiable. Even a low input frequency does not relieve you of the obligation to document every single message in an audit-proof manner and classify it in a comprehensible manner. A common mistake is the verbal trivialization of information that is not formally recorded: This can be interpreted as reprisal according to Section 36 HinSchG if the whistleblower subjectively acted in good faith. The only thing that is safe is a written, politely justified notification of the non-recording and referral to other complaint channels.

Interfaces to GDPR, NIS-2 and LkSG

§ 2 HinSchG refers to data protection via number 7, to the security of network and information systems via number 8 and to the Supply Chain Due Diligence Act via number 9. In practice, these regimes merge at several points. A data protection violation can simultaneously trigger a report in accordance with Art. 33 GDPR to the supervisory authority within 72 hours and constitute a protected report under the HinSchG. An NIS 2 security incident can require an early warning to the BSI within 24 hours and a follow-up report within 72 hours and can be received in parallel as a HinSchG matter. The deadlines run independently of each other, both must be served seamlessly, otherwise double liability arises.

This parallelism makes an integrated platform attractive. Licence the workspace for your internal representatives or have our representatives order it. In both models, the NIS-2 reporting paths are interlinked with the HinSchG reporting office: incoming reports are classified, the responsible officers are notified and the parallel deadlines are automatically monitored. Reports under the Supply Chain Due Diligence Act, which requires a separate complaints office in accordance with Section 8 LkSG, can also be linked to the HinSchG reporting office if the entrance door is identical. The platform differentiates in the background according to legal basis, the whistleblower does not notice this. Clean, separate files with the necessary evidence are created for the responsible supervisory authorities, the Federal Office of Justice, the BSI and the BAFA. The auditor calls, the evidence is ready., regardless of which regime sends it. This multiple checking will increase from 2026 because the BSI is digitizing NIS 2 incident recording and the state data protection authorities are standardizing the GDPR reporting channels. Anyone who sets up an integrated platform today avoids the later migration from three isolated solutions running side by side and saves documentation and training effort with the same number of staff.

Turn Section 2 of the HinSchG into an audit-proof reporting office

§ 2 HinSchG is the entry hurdle for every internal reporting office. Those who do not master them either lose the protection of legitimate whistleblowers or tie resources to tips that are not covered by the law. The solution is not a thick manual, but a workflow that carries out the review: confirmation of receipt in seven days, subsumption under Section 2 HinSchG with a documented matrix, protection decision and follow-up measures according to Section 18 HinSchG, feedback in three months. The 490 ready-to-use audit templates in the CIVAC workspace cover each of these steps, as well as the interfaces to GDPR, NIS-2 and LkSG. The whole thing is supplemented by the appointment certificate from the reporting office management, the reporting line to the management and the annual effectiveness test in accordance with Section 18 Paragraph 3 HinSchG.

CIVAC is a compliance platform and officer-as-a-service: you licence the workspace for your internal representatives or you have our representatives appointed, depending on the maturity of your organisation. In both models you receive the appointment certificate, the reporting line to management, the EU data residency and the ISO/IEC 27001:2022 hosting environment with 93 controls. The CIVAC SLA is two working days instead of the industry standard two to six weeks, so that even complex information is included in the follow-up process in a timely manner. Turn reading into an assignment. Write to info@civac.de or use the contact form if you want to check your HinSchG reporting office, set it up again or completely outsource it. The initial check of your existing reporting office is free of charge and leads to a concrete action plan with effort and timeline. You will then receive an application area matrix that supplements your internal guidelines with the § 2 subsumption, and you can coordinate the model with your existing HR and legal processes before a final assignment is made.

FAQ

What exactly does Section 2 HinSchG regulate?

Section 2 HinSchG defines the material scope of application of the Whistleblower Protection Act. Reports of crimes under the Criminal Code and secondary criminal law, certain violations that are subject to fines and protect life, health or employee rights, as well as a final catalogue of reference standards under EU law from the EU Whistleblower Directive and national subsequent law are protected. Other matters are not covered by protection, but can be processed via AGG, the works council or other complaint channels.

Do labour law conflicts fall under Section 2 of the HinSchG?

Only if they are punishable by law or if the violated norm serves to protect employees or their representative bodies, such as provisions of the Occupational Safety and Health Act or the Works Constitution Act. Pure contractual or bullying disputes without a criminal connection are not protected information under the HinSchG; they are processed via the AGG complaints office, the works council or general complaint channels. The reporting office documents the demarcation in a note.

What happens if the reporting office incorrectly applies Section 2 HinSchG?

An incorrect subsumption can destroy the whistleblower's protected status and trigger fines according to Section 40 HinSchG of up to 50,000 euros in the event of obstruction and up to 20,000 euros in the event of a violation of the confidentiality requirement. A verifiable application area matrix with a documented decision is therefore mandatory and is the first document checked in the audit. The reporting centre manager is personally liable if intentional action is determined.

Are data protection violations covered by Section 2 HinSchG?

Yes, Section 2 Paragraph 1 Number 7 HinSchG covers violations of the protection of privacy and personal data. A report can simultaneously trigger the 72-hour deadline according to Art. 33 GDPR to the supervisory authority and the HinSchG procedure. Both methods are documented in the workspace and have separate deadlines, so that neither the data protection report is missed nor the HinSchG feedback is delayed.

What deadlines does the reporting office have to adhere to?

Confirmation of receipt within seven days in accordance with Section 17 Paragraph 1 Number 1 HinSchG, feedback on follow-up measures within three months in accordance with Section 17 Paragraph 1 Number 3 HinSchG. Deadline begins as soon as we become aware of it. An extension is only possible with justified notification to the whistleblower, for example due to the complexity of the matter or the involvement of external bodies. The workspace automatically monitors deadlines and sends reminders.

Can CIVAC take over the internal reporting office?

Yes. You licence the workspace with a stored Section 2 HinSchG matrix and manage the reporting office internally, or you commission Officer-as-a-Service and CIVAC provides the person responsible for managing the reporting office, including an appointment certificate, reporting line to management and an SLA of two working days for follow-up measures. Both models use the same ISO/IEC 27001:2022 hosting environment with EU data residency and immutable audit log.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles