Whistleblower Hotline Provider in Germany: How to Pick an English-Capable Reporting Channel
German subsidiaries with 50 or more employees must run a confidential reporting channel under HinSchG. International groups need an English-capable provider that also meets BfJ supervision. This guide explains the legal floor, the must-have features, and how CIVAC delivers both.
The German Hinweisgeberschutzgesetz (HinSchG), in force since 2 July 2023, requires every legal entity with 50 or more employees to operate an internal reporting channel that accepts oral and written reports, including anonymous ones since 17 December 2023. For international groups, that channel must also work for non-German speakers, which makes an English-capable provider a procurement requirement, not a nice-to-have.
This article maps the legal floor under HinSchG, the EU Whistleblower Directive (EU) 2019/1937, and Section 8 HinSchG case-handling duties to a practical vendor checklist. You will see what to evaluate (data residency, acknowledgement clocks, case management, supervisor access), which providers cluster around which segments, and how CIVAC closes the gap with a Compliance-Plattform und Officer-as-a-Service approach.
Auf einen Blick
- Every German entity with 50+ employees must run an internal reporting channel that acknowledges receipt within 7 days and gives substantive feedback within 3 months (Section 17 HinSchG).
- An English-capable hotline is mandatory in practice for any group whose workforce is not fully German-speaking; UI, intake forms, and case dialogue must all be available in English.
- CIVAC offers both models: license the workspace for your internal HinSchG officer, or appoint CIVAC as your external reporting office under Section 14 HinSchG.
The Legal Floor: HinSchG, EU Directive 2019/1937, BfJ Supervision
HinSchG transposes the EU Whistleblower Directive (EU) 2019/1937 into German law. Article 8 of the directive and Section 12 HinSchG set the baseline: a confidential reporting channel for employees and, optionally, for third parties such as suppliers and applicants.
Section 17 HinSchG fixes two clocks. Acknowledgement of receipt is due within 7 days. Substantive feedback on follow-up measures is due within 3 months of acknowledgement. The Frist läuft ab Kenntnis, so your intake timestamp matters and must be evidentiable.
The Bundesamt für Justiz (BfJ) supervises external reporting offices and may impose fines up to 50,000 Euro under Section 40 HinSchG for failing to operate a compliant channel. Retaliation against whistleblowers is sanctioned separately and reverses the burden of proof under Section 36 HinSchG.
Group privilege under Section 14 (1) HinSchG allows shared reporting offices across companies up to 249 employees, but the German Ministry of Justice has narrowed this for entities of 250+ employees: each must have its own channel. This single rule eliminates many cheap group-wide setups.
For English-speaking workforces, the channel must accept reports in English without forcing a translation step that could chill reporting. Practical compliance means an English UI, English case dialogue, and English documentation for the reviewer. See the official outline at CIVAC Hinweisgeberschutz for the German-language pendant.
Must-Have Features in an English-Capable Provider
Start with language depth. The provider must offer a full English UI plus English intake forms, plus a case-management workspace in which the reviewer can converse in English with an anonymous reporter. Many German tools only translate the landing page.
Next, evaluate the acknowledgement and feedback clocks. The platform must produce a tamper-evident timestamp on intake, a 7-day acknowledgement reminder, and a 3-month feedback reminder. These are not optional features, they are direct mappings of Section 17 HinSchG.
Data residency is the third filter. The provider must store reports inside the EU, preferably in Germany, and must be able to evidence subprocessor chains under Article 28 GDPR. International groups routinely lose audits because the case database sat on a US-region cloud.
Anonymity is the fourth must-have. Since 17 December 2023, Section 16 (1) HinSchG requires that anonymous reports be processed as well. The provider must therefore allow a fully anonymous channel, a postbox-style dialogue, and a documentation trail that does not leak metadata.
Access controls round it off. The reporting office staff, the compliance officer, and the works council each need scoped roles. Audit logs must show every read and write, because the 3-year retention duty under Section 11 (5) HinSchG ends in a deletion log, not in a folder cleanup.
CIVAC delivers all five through the Workspace, with English UI, EU-Datenresidenz, and an audit-ready Bestellurkunde for the appointed reporting office.
Provider Landscape: Who Fits Which Segment
The German provider landscape splits into four broad clusters. Pure SaaS tools, such as EQS Integrity Line and LegalTegrity, focus on the digital intake and case workflow. They are strong for groups that already have a trained internal officer.
Law-firm hotlines, often run by labor and compliance boutiques, bundle the SaaS with case triage by lawyers. They are expensive on a per-case basis but useful for highly regulated industries where every report risks litigation.
Telephony-first hotlines, such as those operated by international call centers, are the legacy model. They tend to lack English-language case management on the back end and rarely meet the EU-residency bar without a custom contract.
Officer-as-a-Service providers, such as CIVAC, combine the platform with a named external reporting office under Section 14 HinSchG. The Bestellurkunde, unterschrieben, abgelegt, belegbar covers both the appointment and the workflow.
Segment fit is the key procurement question. A 60-person SaaS startup with English as a working language needs an English-first SaaS plus an external officer. A 5,000-employee industrial group with works councils in multiple countries needs the bundle. A foundation with 80 employees and a hands-off board needs Officer-as-a-Service in full.
The 25 Beauftragten-Rollen in the CIVAC workspace let you bundle HinSchG with related duties (DSB, AGG-Beschwerdestelle) without buying four tools. See the role overview at civac.de/roles.
Internal Channel vs. External Reporting Office (Section 14 HinSchG)
Section 14 HinSchG lets you appoint an external third party as the operator of your reporting channel. The accountability stays with the employer, but the case intake, triage, and confidentiality safeguards move outside.
For groups with no German-speaking compliance team, this is often the cleanest setup. The external office speaks German with the works council, English with the international reporters, and writes the case documentation in a single accepted language for the management board.
The decision usually comes down to four factors. First, the risk of conflict of interest inside HR. Second, the volume of reports, since below 10 cases per year an external office is cheaper. Third, the multilingual depth needed. Fourth, the substitution risk: who picks up the channel when the internal officer is on parental leave for nine months.
Both choices need a Bestellurkunde and a signed scope-of-work, plus an information notice to the workforce under Section 13 (2) HinSchG. The notice must list the channel, the contact details, and the rights of the reporter, in a language the workforce understands.
CIVAC offers the dual model explicitly: lizenzieren Sie den Workspace für Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. The CIVAC-SLA is 2 Werktage from appointment to live channel, versus 2 bis 6 weeks for classic setups.
For the legal mapping of officer duties, see the Compliance-Beauftragter role page.
Data Protection, EU Residency, and the GDPR Overlay
Whistleblower data is among the most sensitive personal data a company processes. Reports often contain allegations against named individuals, which engages Article 6 (1)(c) and (f) GDPR plus Section 10 HinSchG as the legal basis. The data minimization principle applies hard.
EU data residency is therefore a procurement filter, not a marketing claim. The provider must store case data inside the EU, must contract subprocessors under Article 28 GDPR, and must allow you to evidence the transfer chain in your Article 30 GDPR register.
For US-headquartered groups, the EU-US Data Privacy Framework is a possible bridge, but the German data protection authorities have repeatedly flagged whistleblower data as a category where the additional safeguards under Article 46 GDPR should be considered. A pure US-cloud setup is increasingly an audit finding.
The 72h Datenpannen-Frist of Article 33 DSGVO applies to whistleblower channels just like any other system. If the case database is breached, the controller, your German entity, must notify the lead supervisory authority within 72 hours of becoming aware.
CIVAC hosts the Workspace inside the EU with German-region defaults, runs an ISO/IEC 27001:2022 ISMS with 93 Controls, and gives the controller a ready-made Article 30 GDPR record entry. The integration with the externer Datenschutzbeauftragter role keeps both duties on one platform.
Procurement Checklist: 12 Questions for Every RfP
The following 12 questions cut through marketing copy in any RfP. Treat them as the minimum viable due diligence for an English-capable HinSchG provider.
One, is the full UI available in English, German, and at least three more EU languages? Two, can the reporter remain anonymous from intake to closure? Three, does the case dialog timestamp survive a vendor switch?
Four, where is the case data stored, and which subprocessors touch it? Five, what is the deletion workflow at the end of the 3-year retention under Section 11 (5) HinSchG? Six, does the provider deliver an Article 30 GDPR record entry on request?
Seven, does the provider support both internal-channel and external-reporting-office models? Eight, what is the SLA from contract to live channel? Nine, who signs the Bestellurkunde if the external model is chosen?
Ten, what is the audit trail format, and is it export-ready for a forensic review? Eleven, does the provider hold ISO/IEC 27001 certification under the 2022 control set? Twelve, what is the fee model: flat, per-employee, or per-case?
CIVAC answers each of these with documented evidence: 490 einsatzbereite Audit-Vorlagen, 93 Controls nach ISO/IEC 27001:2022, EU-Datenresidenz, and a CIVAC-SLA of 2 Werktage. The procurement file lands closed, audit-fest, dokumentiert, Section-17-fest.
Fines, Liability, and the Real Cost of Non-Compliance
The headline fine under Section 40 HinSchG is up to 50,000 Euro for failing to operate a compliant channel. That is the floor, not the ceiling. The cost stack runs much higher in practice.
First, the personal liability of the managing directors under Section 130 OWiG. A missing reporting channel is a textbook organizational duty failure, and the fine can reach 1 million Euro per individual.
Second, the reversed burden of proof in retaliation cases under Section 36 HinSchG. If a whistleblower can show that disadvantage followed a report, the employer must prove it was not retaliation, a high evidentiary bar.
Third, the parallel exposure under the EU Whistleblower Directive in cross-border groups. A French or Italian subsidiary may invoke the directive in its local court, and the German parent may carry joint liability through the chain.
Fourth, the reputational damage. A failed channel is rarely a quiet finding. The works council, the supervisory authority, and increasingly the press all amplify the event.
The honest comparison is the cost of a fit-for-purpose provider against the expected value of the above. A bundled CIVAC contract runs at a fraction of a single 130 OWiG fine, and the Bestellurkunde, unterschrieben, abgelegt, belegbar gives the board its documented organizational duty discharge.
Implementation Plan: From RfP to Go-Live in 14 Days
A clean implementation runs in five phases. Phase one is scoping, in week one. Define the entities in scope, the workforce languages, the case taxonomy, and the works council touchpoints.
Phase two is vendor selection, also in week one. Run the 12-question RfP against two or three providers, weight EU residency and English depth, and shortlist. Phase three is contracting, in week two. Sign the Auftragsverarbeitung under Article 28 GDPR, the Bestellurkunde under Section 14 HinSchG, and the works council notice.
Phase four is configuration, in week two. Set up the case taxonomy, the role matrix, the reminder clocks, and the multilingual intake. Configure the audit log retention to match the 3-year duty under Section 11 (5) HinSchG.
Phase five is rollout, end of week two. Publish the channel URL on the intranet, send the Section 13 (2) HinSchG information notice in all workforce languages, and brief the works council. Train the reporting office on the case workflow. Monitor the first 30 days closely.
The CIVAC-SLA of 2 Werktage compresses phases three and four for clients who pick the platform plus officer bundle. The 490 einsatzbereite Audit-Vorlagen cover the notices, the Article 30 GDPR record, and the operating handbook.
For groups with a SiFa or AGG overlay, the same workspace handles those roles. See AGG-Beschwerdestelle for the typical bundle.
Turn Reading Into Action: CIVAC for English-Speaking HinSchG Cases
The shortest path from this article to a compliant English-capable channel runs in two CIVAC variants. Both close the procurement file inside two weeks.
Variant one is the workspace license. Your internal HinSchG officer logs into the Workspace, configures the channel in English and German, and runs cases with the audit log, the timestamps, and the reminders built in. Lizenzieren Sie den Workspace für Ihre internen Beauftragten.
Variant two is Officer-as-a-Service. CIVAC names an external reporting office under Section 14 HinSchG, runs the channel end-to-end, and reports into your management board. Oder lassen Sie unsere Beauftragten bestellen. The Bestellurkunde, unterschrieben, abgelegt, belegbar is delivered on day one.
Both variants come with EU-Datenresidenz, ISO/IEC 27001:2022 controls, the 490 audit templates, and direct integration with your DSB, AGG, and CO workflows. Andere führen Compliance wie einen Aktenschrank. Wir führen sie wie Software.
The CIVAC-SLA is 2 Werktage from signed contract to live channel. Der Prüfer ruft an, der Nachweis liegt bereit. The platform makes the 7-day acknowledgement and the 3-month feedback clocks self-policing.
Aus dem Lesen einen Auftrag machen: contact info@civac.de or use the contact form at civac.de/faq to schedule a 30-minute scoping call. We will return a fitted scope-of-work the same week.
FAQ
Does HinSchG apply to a German subsidiary if the parent is outside the EU?
Yes. HinSchG attaches to the German legal entity, not to the group. If your German GmbH or AG has 50 or more employees, you must operate a compliant internal reporting channel even if the parent sits in the US, UK, or Switzerland. The English-language requirement follows from your workforce composition, not from the parent location.
Can we run one group-wide hotline for all subsidiaries?
Only up to 249 employees per entity under Section 14 (1) HinSchG. The German Ministry of Justice has stated that entities of 250 or more employees must operate their own reporting channel; a shared service is permitted only for resources, not as the channel itself. Confirm the current interpretation with your DSB and CO.
What is the deadline to acknowledge a report and to provide feedback?
Section 17 HinSchG sets 7 days for acknowledgement of receipt and 3 months for substantive feedback on follow-up measures. Both clocks start from the intake timestamp. The CIVAC Workspace runs the reminders automatically, so the Frist läuft ab Kenntnis becomes a self-policing workflow rather than a calendar risk.
Is an anonymous reporting channel mandatory under HinSchG?
Yes since 17 December 2023. Section 16 (1) HinSchG requires that anonymous reports be processed as well. The provider must allow fully anonymous intake, an anonymous case dialog, and a documentation trail that does not de-anonymize the reporter. CIVAC supports this end-to-end inside the Workspace.
Where must the case data be stored?
There is no explicit residency mandate, but Article 28 and Article 46 GDPR plus the special sensitivity of whistleblower data make EU residency the safe default. German data protection authorities flag pure US-cloud setups as a risk. CIVAC stores case data inside the EU with German-region defaults and ISO/IEC 27001:2022 controls.
How fast can CIVAC put a live channel in place?
The CIVAC-SLA is 2 Werktage from signed contract to live channel for both the workspace-license and the Officer-as-a-Service variants. Classic setups run 2 to 6 weeks. Send a short scope to info@civac.de and you receive a fitted statement of work the same week.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.