77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Setting up a whistleblower hotline in medium-sized companies: duties, channels, reporting line
Equality & AGG

Setting up a whistleblower hotline in medium-sized companies: duties, channels, reporting line

6 July 202612 min readBy Dr. Henrik Bauer
CIVAC

The obligation to have an internal reporting office under the HinSchG has also applied to companies with 50 to 249 employees since December 17, 2023. This article shows how medium-sized companies set up the whistleblower hotline in a legally secure manner, combine the complaints office and data protection and present evidence in the audit.

Since December 17, 2023, the Whistleblower Protection Act has required companies with 50 to 249 employees to have an internal reporting office; above 249 employees, the obligation has been in effect since July 2, 2023. § 12 HinSchG requires confidential reporting channels, § 13 HinSchG names the obligations of the reporting office, § 14 HinSchG allows outsourcing to third parties, and § 17 HinSchG sets the deadlines for confirmation of receipt within seven days and feedback to the reporting person within three months. The fines according to Section 40 HinSchG range up to 50,000 euros, and there are also possible consequences of reversal of the burden of proof in labour law disputes, which significantly increase the risk in practice.

This article shows how medium-sized companies set up the whistleblower hotline so that it not only exists formally, but also functions reliably in audits, disputes and incidents. You will find out which reporting channels are mandatory, which reporting line connects the HinSchG requirements with the GDPR and ISMS requirements, how the interface to the AGG complaints office is clearly defined in accordance with Section 13 AGG and when external ordering is economically viable. CIVAC offers the internal reporting office as a compliance platform and officer-as-a-service with a service level of 2 working days from the order to the operational reporting channel.

Key Takeaways

  • The internal reporting office according to HinSchG has been mandatory for companies with 50 to 249 employees since December 17, 2023, with deadlines of seven days for confirmation of receipt and three months for feedback.
  • The whistleblower hotline, AGG complaint centre and data protection must be brought together technically and organizationally because the same incident can trigger several obligations at the same time.
  • External reporting offices according to Section 14 HinSchG with officer-as-a-service are economical in medium-sized companies because the independence of the function is maintained and the reporting line to management is documented.

Who is obliged to set it up and when?

Section 12 Paragraph 1 HinSchG obliges all employers with at least 50 employees to set up an internal reporting office. According to Section 3 Paragraph 8 of the HinSchG, employees within the meaning of this standard are not only permanent employees, but also trainees, temporary workers, freelancers under certain conditions and civil servants. The obligation has been in effect for companies with 50 to 249 employees since December 17, 2023, and for larger companies with 250 or more employees since July 2, 2023. Certain sectors such as financial services, investment services and money laundering prevention are subject to the obligation regardless of the number of employees because the relevant sector laws independently mandate the reporting point requirement.

Violations of the obligation to set up a reporting office are in accordance with Section 40 Paragraph 2 No. 2 HinSchG imposes a fine of up to 20,000 euros, violations of the ban on reprisals up to 50,000 euros. In addition, there is the civil law risk from Section 36 of the HinSchG, which provides for a reversal of the burden of proof in favor of the person making the report: if a professional situation is worsened after a report is made, the company must prove that this worse situation is not related to the report. In disputes over transfers, terminations or warnings, this reversal of the burden of proof is often more economically consequential than the fine itself. The establishment of a reliable reporting office is therefore not only mandatory, but at the same time a protective measure for management against later lack of evidence in labour law proceedings, which are difficult to conduct without documented reporting channels. The counting of employees is carried out according to general labour law principles, whereby the threshold values ​​must be viewed consistently over the calendar year, not selectively. If the company changes the threshold up or down, a transition consideration applies that is applied pragmatically in supervisory practice, but must be reliably documented in the event of a dispute. Group structures can also trigger a separate reporting point requirement for each subsidiary, which is why the collective reporting point in the group must be carefully designed in accordance with Section 14 HinSchG.

Which reporting channels the law specifically requires

§ 16 HinSchG requires at least one reporting channel in oral and written form. At the request of the person providing the information, a personal meeting must also be made possible within a reasonable period of time. Anonymous reports must be received and processed since the 2023 amendment to the HinSchG, even if the obligation to process anonymous reports was initially restricted by the legislature. In practice, anonymous reporting capacity is effectively standard because most whistleblowers only report when their identity is protected. A pure email address or postal address formally fulfils the obligation, but is actually a deterrent.

A reliable reporting office in medium-sized businesses therefore combines at least three channels. Firstly, a web-based reporting channel with encrypted transmission and the option for anonymous correspondence. Secondly, a telephone hotline with documented recordings. Thirdly, the opportunity to meet in person, usually with the appointed reporting office representative or a person authorised by him. The confidentiality of the identity of the informing person according to Section 8 HinSchG must be guaranteed across all channels, which creates independent technical requirements for telephone systems. CIVAC provides these three channels in the workspace, with separate encryption levels and a documented processing trace that can be proven in the audit to the data protection officer and to the supervisory authority. In addition, the platform offers multilingual reporting channels, which significantly improves the actual usability of the hotline for international workforces and corporations with subsidiaries outside German-speaking countries. Without multilingualism, reports from areas with a different working language are virtually non-existent, which creates a gap in the supervisory picture. The written and oral channels must be such that the person providing the information can actually maintain the confidentiality of their identity, which is usually not the case with classic telephone systems using caller ID or tape recording.

Deadlines and reporting obligations

§ 17 HinSchG norms a precise deadline regime, which is often underestimated in practice. Within seven days of receipt of the report, the reporting office must confirm receipt to the person who provided the information, provided there is a communication channel. Within three months of the confirmation of receipt, but no later than three months and seven days after receipt of the report, the reporting office must provide the reporting person with feedback on the follow-up measures taken or planned and the reasons for the follow-up measures. This obligation to provide feedback must also be adhered to in the case of anonymous reports, provided that the person providing the information has set up a communication channel, for example via the mailbox in the reporting system.

Manual deadline management in Excel or Outlook is structurally inadequate here. The reporting office must automatically trigger the confirmation of receipt, document the processing status and systemically monitor the three-month deadline for the response. In addition, there is an obligation to document the report in accordance with Section 11 of the HinSchG, with a retention period of at least three years after completion of the procedure. CIVAC maps the deadline regime in the workspace as a workflow that contains the confirmation of receipt, the processing phases and the feedback with a time stamp. The clock starts on awareness. Audit-proof, documented, Section 17-proof, and regardless of which person operates the reporting office on a specific day. Escalations when a deadline is imminent are sent automatically to a pre-appointed representative, so that even a sudden staff interruption does not disrupt the deadline. In the quarterly report to the management, adherence to deadlines appears as a separate key figure, which the supervisory authority can see immediately if necessary and provides the management with an ongoing control basis.

Who is allowed to occupy the registration office: appointment and independence

§ 15 HinSchG requires that the people entrusted with the tasks of the internal reporting office be independent. In addition to their work for the reporting office, they may carry out other tasks and duties as long as this does not give rise to conflicts of interest. The union of personnel with operational management functions, such as human resources management or management, is therefore critical and often criticized in supervisory practice. A personal union with the data protection officer is also not excluded, but it requires a careful separation of the procedural paths because the obligations under the GDPR and HinSchG are not always the same.

In practice, medium-sized companies use two models. In the first model, an internal person is appointed, typically from the legal or compliance department, who performs the function as a sub-role. In the second model, the reporting office is outsourced to an external third party in accordance with Section 14 HinSchG, usually a law firm or a specialised provider. The external solution is often economically and regulatory preferable in medium-sized companies because it structurally ensures independence and at the same time lowers the inhibition threshold for whistleblowers who report more frequently to external bodies than to internal superiors. CIVAC offers the external reporting point in the officer-as-a-service model with a signed appointment certificate, a documented reporting line to management and a representation mechanism so that vacation or sick leave does not jeopardize the seven-day deadline for confirmation of receipt. The appointment certificate, signed, filed, verifiable. When choosing the model, it is advisable to conduct an honest self-examination: can an internal person act with sufficient distance from management, or is the constellation structurally so close that the workforce would not perceive the independence. In practice, the answer to this question determines whether the hotline is actually used.

Interfaces to GDPR, AGG and ISMS

A report within the meaning of the HinSchG almost always contains personal data, both of the person making the report and of the persons affected by the report. This means that Articles 5, 6, 9 and 13 GDPR as well as Article 32 GDPR apply to the technical and organisational measures. The reporting office is a processing activity within the meaning of Art. 30 GDPR and must be included in the directory, with a legal basis typically in accordance with Art. 6 Paragraph 1 Letter c GDPR in conjunction with the HinSchG. § 10 HinSchG contains its own data protection processing basis, which specifies the relationship to the GDPR and sets the six-month deadline for processing reports without evidence of factual clarification.

The interface to the AGG Complaints Office according to § 13 AGG is organizationally crucial. A complaint about discrimination in the workplace falls under the AGG if it relates to disadvantageous actions for the reasons stated in Section 1 AGG. It can also be a report under the HinSchG if it concerns a legal violation within the meaning of Section 2 of the HinSchG. In these cases, both procedures must be carried out in parallel or in a coordinated manner. Finally, the ISMS follows ISO/IEC 27001:2022 because the reporting office processes data and Annex A.5.34 and A.8.10 standardise corresponding protection requirements. CIVAC integrates the three regimes in the workspace so that a report is automatically included in the register of processing activities, the AGG interface is activated when necessary and the ISMS risk assessment takes the reporting office into account as a control. Others run compliance like a filing cabinet. We run it like software. The integration is also relevant under labour law because a proper interface between the HinSchG and the AGG makes it considerably easier to provide evidence in discrimination disputes.

Anonymous reporting, confidentiality and protection from reprisals

Anonymous reports have been accepted since the amendment to the HinSchG of June 2, 2023, and the reporting office must process them unless this is excluded by other legal provisions. The greatest technical challenge lies in the practical processing of anonymous reports, because the reporting office has to ask questions without a direct communication channel and adhere to the three-month deadline according to Section 17 of the HinSchG. It is common practice to set up a mailbox in the reporting system, which remains accessible to the reporting person via an anonymized token without their identity being revealed. This token-based return channel cannot be represented in a pure email solution, but requires a specialised platform.

The confidentiality of the identity of the person providing the information in accordance with Section 8 of the HinSchG is a separate obligation, the violation of which is subject to a fine in accordance with Section 40 of the HinSchG. It requires access control to reporting data that only grants access to those people who are necessary for processing. The company's IT administrator is generally not allowed to have access to the plain text of the messages. The ban on reprisals according to Section 36 of the HinSchG prohibits any discrimination against the person providing the information, with the burden of proof reversing in favor of the person providing the information. A reliable reporting office therefore documents the time of the report, the group of people who are aware of the report and all personnel-related decisions that affect the person who provided the report after the report. This documentation is structured in a binding manner in the CIVAC workspace and can be exported, so that the reversal of the burden of proof in a dispute does not lead to documentary defeat. Communication with the whistleblower via the anonymized mailbox is also fully logged, including the times of the notifications and the follow-up measures taken.

External reporting office according to Section 14 HinSchG: Economic efficiency and selection

§ 14 HinSchG allows third parties to be commissioned with the tasks of the internal reporting office. The employer's responsibility remains, i.e. the order does not constitute a shift in liability, but rather an operational outsourcing. For medium-sized businesses, the external reporting office is in many cases the economically superior solution because it structurally ensures independence in accordance with Section 15 of the HinSchG, reliably adheres to the seven-day deadline for confirmation of receipt by a well-rehearsed team and lowers the inhibition threshold for whistleblowers. Studies by the EU Whistleblowing Monitor consistently show that external channels are used more frequently than internal ones because the fear of internal reprisals is empirically real.

Six criteria are relevant when selecting the external reporting body. Firstly, the qualifications of the person appointed, ideally with legal training and experience in compliance or labour law. Secondly, the EU data residency of the reporting system, because the data of the reporting persons is particularly worthy of protection. Thirdly, the provider's ISO/IEC 27001:2022 certification, because the confidentiality requirements must be independently audited. Fourth, the replacement mechanism so that vacation or sick leave does not jeopardize deadlines. Fifth, the reporting line to management with a documented quarterly report. Sixth, the contractual conditions for the retention of reports after the end of the contract. CIVAC meets these criteria as an external reporting point with an appointment certificate, EU hosting, ISO/IEC 27001:2022 implementation and a service level of 2 working days from the order. The quarterly report to the management follows a standardised format that shows the number of reports, the processing status, compliance with deadlines and the identified topic areas without identifying the people who provided the information. This provides the management with an ongoing situation report without violating the confidentiality obligation in accordance with Section 8 of the HinSchG.

Costs and economic viability of the three models

A medium-sized company with 200 employees has three options. Firstly, the purely internal reporting office with a part-time role in the legal or compliance department. The personnel costs for this sub-role are around 20,000 to 30,000 euros per year, plus the purchase and maintenance costs of reporting software between 8,000 and 15,000 euros per year. The function is dependent on personnel, is prone to failure during vacation and illness, and is often perceived by the workforce as not being independent enough to receive reports from their own line.

Secondly, the hybrid solution with internal ordering and external software service providers. The costs are between 25,000 and 40,000 euros per year and combine the weaknesses of both worlds because independence still depends on internal staffing. Thirdly, the external reporting office according to Section 14 HinSchG with Officer-as-a-Service. The costs range between 12,000 and 25,000 euros per year and include the order, the platform, the representation mechanism and the quarterly report. The model is economically superior, regulatoryally clearer and easier to communicate to the workforce. Licence the workspace for your internal representatives or let our representatives appoint them and make the choice based on your HR strategy and your independence requirements. Turn reading into an assignment as soon as the economic analysis makes the three options transparent and the structural weaknesses of the hybrid model become visible. The issue of reputation must also be taken into account: experience shows that an externally appointed reporting point is used more by the workforce, which provides management with relevant information earlier and more accurately and reduces serious escalations. Empirically, the follow-up costs of undetected violations are significantly higher than the annual costs of an external reporting office, which is why the profitability calculation remains incomplete without this risk component.

How to start the setup with CIVAC

The establishment of a reliable whistleblower hotline begins with three pieces of information: the current number of employees with differentiation according to Section 3 Para. 8 HinSchG, the previous practice for dealing with tips including possible AGG complaints office procedures and the management's risk assessment of sector-specific obligations, for example under the AMLA or WpHG. The scope of the required reporting channels, the choice between internal and external orders and the interfaces to GDPR, AGG and ISMS are derived from this information. A 60-minute scoping discussion with a qualified reporting office representative is sufficient to clarify these points and prepare a reliable offer.

Commissioning takes place at a service level of 2 working days from the signed order to the operational reporting channel with three activated channels, documented reporting line and issued appointment certificate. Employee communication, GDPR directory entry and the quarterly report standard will be established within 30 days. Licence the workspace for your internal representatives or have our representatives order it and decide on the model again after the first 30 days have been completed and you have seen the platform in operation. Turn reading into an assignment. You can reach the team at info@civac.de or via the contact form on civac.de. The initial response will be made within one working day, the offer within two working days, including a fixed price for the first twelve months and a documented transitional arrangement for any reports already in progress. If requested, the CIVAC team will support staff information with standardised notices, intranet texts and a Q-and-A overview so that the introduction of the reporting office is perceived as a serious measure. This accompanying communication is regularly the decisive factor for the usage rate in the first few months and thus for the actual protective effect of the hotline.

FAQ

At what number of employees is an internal reporting office mandatory?

According to Section 12 Paragraph 1 HinSchG, employers with at least 50 employees are obliged to do so. For companies with 50 to 249 employees, the obligation has been in effect since December 17, 2023, and for companies with 250 employees or more since July 2, 2023. The obligations apply in a sector-specific manner regardless of the number of employees, for example under the AMLA, WpHG and KWG.

Do anonymous reports have to be processed?

Yes. Since the amendment of June 2, 2023, anonymous reports must be received and processed. In practice, this requires an anonymized return channel via a token-based mailbox, because otherwise the three-month deadline for feedback in accordance with Section 17 of the HinSchG cannot be met. In practice, a pure email address does not meet this requirement.

What deadlines does the reporting office have to adhere to?

Confirmation of receipt must be made within seven days of receipt of the report. Feedback on follow-up measures taken or planned must be provided within three months of the confirmation of receipt, but no later than three months and seven days after receipt of the report. Both deadlines result from Section 17 HinSchG and are binding in the audit.

Can the HR manager also be the reporting office representative?

Only limited. Section 15 HinSchG requires independence, and the union of personnel with operational management functions typically creates conflicts of interest because the personnel law consequences of the report are in the same hands. Supervisory authorities regularly criticize this situation. An external reporting office in accordance with Section 14 HinSchG avoids the structural problem and is therefore often preferred in medium-sized companies because it also improves perception among the workforce.

How does the reporting office relate to the AGG complaints office?

The AGG complaints office according to Section 13 AGG is an independent obligation for discrimination complaints. It can be organizationally linked to the HinSchG reporting office, but must adhere to its own procedural paths. One complaint can trigger both regimes at the same time. The interfaces are mapped in the CIVAC workspace, so that no double entry is necessary and the deadline obligations of both regimes are maintained.

How quickly is an external reporting point productive?

At the CIVAC service level, the operational reporting channel with three activated channels is available two working days after the order is placed. The appointment certificate is signed during the same period, the GDPR directory entry follows within 30 days. Classic implementations via separate software providers and external law firms typically take between four and twelve weeks, which is at the expense of the person responsible in the event of an ongoing supervisory inquiry.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles