Whistleblower Protection Act: operational implementation of obligations, deadlines and reporting point
The HinSchG requires companies with 50 or more employees to have an internal reporting office. There is a risk of fines of up to 50,000 euros. This guide shows how to set up a verifiable reporting channel, deadlines and documentation.
The Whistleblower Protection Act (HinSchG) has been in force since July 2, 2023 and requires companies with 50 or more employees to set up an internal reporting office (Section 12 HinSchG). Anyone who ignores the obligation risks fines of up to 50,000 euros according to Section 40 HinSchG, as well as reputational damage and consequences under labour law if reprisals are taken against reporting persons.
This article explains what specific obligations exist, how the 7-day confirmation and the 3-month feedback are to be documented and what role the internal reporting office plays HinSchG takes in interaction with data protection and compliance. You receive an implementation logic that fits CIVAC's compliance platform and Officer-as-a-Service.
Key Takeaways
- If you have 50 employees or more, an internal reporting office is mandatory; It has been in effect for 250 or more employees since July 2, 2023, and for those with 50 to 249 employees since December 17, 2023.
- Confirmation of receipt within 7 days, feedback to the person who provided the information within 3 months, both verifiably documented.
- Violations of confidentiality protection and prohibition of reprisals cost up to 50,000 euros; Intentional obstruction of reports up to 50,000 euros according to Section 40 HinSchG.
Who is obliged and from when does the HinSchG apply
Employers who generally have at least 50 employees are obliged (Section 12 Paragraph 1 HinSchG). For companies with 250 or more employees, the obligation has applied since July 2, 2023, and for companies with 50 to 249 employees since December 17, 2023. According to Section 14 (1) HinSchG, group structures can use a group-wide reporting office.
Certain sectors are affected regardless of the number of employees, including securities service providers, capital management companies, insurers and credit institutions. Industry-specific special laws apply here, such as Section 25a KWG for banks. These sectoral obligations overlay the HinSchG, but do not completely replace it.
In fact, the HinSchG covers violations of criminal law, regulations for the protection of life, limb or health that are subject to fines, as well as a broad list of European legal acts (§ 2 HinSchG). Data protection, money laundering, product safety and awarding are part of this.
Not only employees are personally protected, but also applicants, interns, self-employed people, shareholders and suppliers (§ 1 HinSchG). The protection takes effect as soon as there is sufficient reason to suspect a violation of the law.
The obligation does not end with the installation. It requires a permanently operational channel, trained processors and reliable documentation of each report for at least three years after completion of the procedure (§ 11 HinSchG).
Mandatory channels: oral, written, personal
According to Section 16 HinSchG, reporting offices must enable oral and written reports. Oral means by telephone or voice messaging system. At the request of the person providing the information, a personal meeting must be made possible within a reasonable period of time, which can also take place via video conference with their consent.
Anonymous reports should be processed, but there is no mandatory obligation to process them according to Section 16 Paragraph 1 Sentence 4 HinSchG. In practice, processing anonymous reports is recommended, as violations can otherwise reach external bodies or media.
The choice of channel must ensure the confidentiality of the identity of the person providing the information, the person affected and other persons named in the report (Section 8 HinSchG). Unencrypted Outlook mailboxes, shared functional mailboxes and non-segregated CRM systems are not sufficient.
Web forms with end-to-end encryption, separate telephone lines with recording locks and dedicated rooms for personal conversations have proven to be technically successful. The software used must log in an audit-proof manner without revealing identity.
CIVAC provides a multi-client reporting channel in the workspace that combines confidentiality, deadlines and documentation in one application. The appointment certificate, signed, filed, verifiable. Licence the workspace for your internal representatives or have our representatives order it.
Deadlines: 7 days, 3 months, 3 years
Three deadlines characterize the operational HinSchG activities. First: Confirmation of receipt to the person providing the information within seven days of receipt of the report (Section 17 Paragraph 1 No. 1 HinSchG). The deadline runs from the time the reporting office becomes aware of it, not from the date of dispatch.
Secondly: feedback to the person providing the information within three months of the confirmation of receipt (§ 17 Para. 2 HinSchG). The feedback includes planned or taken follow-up measures and their reasons, provided that internal investigations or the rights of third parties do not conflict with this.
Third: retention period of three years after completion of the procedure (Section 11 Para. 5 HinSchG). The documentation may be retained for longer periods if this is necessary and proportionate. Deletion obligations under data protection law under Article 5 Paragraph 1 Letter e of the GDPR remain unaffected.
Anyone who violates deadlines not only risks fines, but also the person providing the information moving to the external channel at the Federal Office of Justice (Section 19 HinSchG) or disclosure to the media (Section 32 HinSchG). The internal channel loses its protective effect.
An automated timer with escalation levels is therefore not a convenience, but a minimum standard. Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the inbox automatically triggers the 7-day clock.
Confidentiality, data protection and GDPR interface
The confidentiality requirement from Section 8 HinSchG protects three identities: the person reporting the information, the person affected and others named in the report. The identity may only be known to the people responsible for processing, as well as other employees who absolutely need it for follow-up measures.
The GDPR applies in parallel when processing personal data. What is required is a processing directory in accordance with Article 30 of the GDPR, a data protection impact assessment in accordance with Article 35 of the GDPR in cases of high risk and transparent information in accordance with Articles 13 and 14 of the GDPR. Order processing contracts according to Art. 28 GDPR are mandatory for external platform providers.
The exception under Art. 14 Para. 5 lit. b GDPR is tricky: informing the person concerned may be delayed if it jeopardizes the clarification. This consideration must be documented so that the data protection officer can understand it later.
The external data protection officer should be involved in the introduction of the reporting office at an early stage, ideally already in the conception phase. The interface between HinSchG confidentiality and GDPR transparency is the most common weak point in audits.
EU data residency is not a nice-to-have here. Whistleblower data belongs in European data centres with clear responsibility. The CIVAC workspace is hosted on German soil and is contractually auditable according to standard contractual clauses.
Protection against reprisals and reversal of the burden of proof
§ 36 HinSchG prohibits reprisals against people who provide information. This includes termination, warnings, transfers, bullying, cancellation of bonuses, non-renewal of fixed-term contracts and comparable disadvantages. The attempt and the threat are also covered.
The reversal of the burden of proof from Section 36 Paragraph 2 HinSchG is particularly effective. If the reporting person suffers discrimination in connection with their professional activity after making a report, it is presumed that this discrimination is reprisal. The employer must prove the opposite.
This presumption rule changes HR practice. Personnel decisions that are made after a report must be fully documented: performance evaluations, target agreements, reasons for transfers, decisions on fixed-term contracts. Without documentation, the employer loses the case.
Claims for damages according to Section 37 HinSchG include material damage, such as lost wages, and immaterial damage, such as satisfaction. The amount of damage is not capped by law. Labour courts are guided by Section 15 AGG with a tendency towards higher amounts.
Operationally, this means: anyone who receives a report should examine and document HR measures towards the person providing the information with increased care for at least twelve months. The auditor calls, the evidence is ready.
Fines, liability and supervision
§ 40 HinSchG standardises the fines. Failure to set up an internal reporting point is punishable by a fine of up to 20,000 euros. Violations of the confidentiality requirement up to 50,000 euros. Obstruction of a report and reprisals of up to 50,000 euros.
The legal entity according to Section 30 OWiG is important. An association fine can be set through the company, which supplements the personal fines against management personnel. Section 130 OWiG extends liability to supervisory violations: Anyone who fails to take supervisory measures is liable for operational-related breaches of duty.
The responsible supervisory authority for the external reporting office is the Federal Office of Justice in accordance with Section 19 HinSchG. BaFin, BSI or state authorities remain responsible for sectoral obligations. A reporting office can be subject to several supervisions.
In terms of insurance, D&O policies should be checked for HinSchG clauses. Standard policies often exclude fines but cover defence costs. An extension is possible and makes sense.
The CIVAC workspace documents the appointment certificate, reporting line and procedural files in an audit-proof, documented, § 40-proof manner. The CIVAC FAQ answers the most frequently asked detailed questions about the implementation of the HinSchG. Licence the workspace for your internal representatives or have our representatives order it.
Training, reporting line and escalation
Training is not optional. Section 15 HinSchG requires the necessary expertise of the persons entrusted with processing reports. This includes knowledge of HinSchG, GDPR, labour law, criminal procedure law and interviewing. An annual refresh is standard in the market.
The reporting line should ensure the independent performance of tasks (Section 15 Para. 1 HinSchG). Direct reporting to management or, in the case of co-determined companies, to a committee appointed by the supervisory board is common practice. A reporting line to the immediate superior of the reporting office would be fraught with conflict.
Escalation paths must be defined: When will internal audit be involved, when will the legal department be involved, when will external lawyers be involved, when will law enforcement authorities be involved? An escalation matrix with clear triggers prevents delays and diffusion of responsibility.
Reports against the management themselves are particularly sensitive. An alternative escalation path to the supervisory board or external body is required. Without this path, the credibility of the system fails at the first critical report.
The annual report on the number and type of reports, without identifying people, is part of the compliance reporting to the board. Trends, repeat patterns and systemic weak points become visible and controllable.
Common mistakes and how to avoid them
Mistake one: shared mailbox for HR and whistleblowers. This violates the confidentiality of Section 8 HinSchG because HR employees gain knowledge without being involved. Separate channels technically and organizationally.
Mistake two: no confirmation of receipt. The 7-day deadline is overlooked because receipts get lost in collection mailboxes. An automated confirmation of receipt with a process number is a mandatory function of every platform.
Mistake three: lack of documentation of the follow-up measures. The feedback after three months requires substance. Without documented test steps, all that remains is an empty phrase that has no bearing on a supervisory audit.
Mistake four: Retaliation due to ignorance. A transfer shortly after a report, even if it is factually justified, is presumed to be reprisal. HR decisions must be coordinated with the reporting office before implementation.
Mistake five: no emergency regulation in the event of absence. Vacation, illness or termination of the editor must not paralyze the channel. Substitution arrangements with equivalent training are necessary.
Mistake six: external platform without a data processing agreement. The GDPR interface is often forgotten because HinSchG is understood as a special law. Both apply in parallel.
Implementation with CIVAC: two ways, one platform
The HinSchG implementation requires three building blocks: a confidential reporting channel, trained processors and audit-proof documentation. All three can be covered in the traditional way via a law firm, a separate tool and Excel, but the interfaces cost weeks and disrupt deadlines.
CIVAC is a compliance platform and officer-as-a-service. The workspace bundles reporting channels, deadline clocks, process files, reporting lines and appointment certificates in one application with EU data residency and ISO 27001:2022 basis.
Model one: You licence the workspace for your internal representatives. Your HR or compliance officers manage the reporting office themselves, supported by 490 ready-to-use audit templates, training modules and automatic deadline monitoring.
Model two: You let our representatives appoint you. An experienced compliance officer takes on the role in accordance with Section 14 HinSchG, with an appointment certificate, reporting line to your management and an SLA of two working days instead of the industry standard two to six weeks.
Both models use the same workspace. You can change or combine at any time, for example Officer-as-a-Service for the first twelve months and then a licence model. The data stays with you.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de, we will get back to you within one working day with a concrete implementation proposal.
FAQ
From what number of employees is an internal reporting office mandatory according to the HinSchG?
The obligation generally applies to at least 50 employees (Section 12 HinSchG). It has been in effect since July 2, 2023 for those with 250 employees and since December 17, 2023 for those with 50 to 249 employees. Sectoral obligations, for example for banks and insurers, apply regardless of the number of employees.
What deadlines does the reporting office have to adhere to?
Confirmation of receipt within seven days, feedback on follow-up measures within three months (§ 17 HinSchG). The documentation for each report must be retained for at least three years after completion. The deadline begins as soon as the reporting office becomes aware of it.
Do anonymous tips need to be processed?
According to Section 16 Para. 1 HinSchG, there is no mandatory obligation to process data, but anonymous reports should be made possible. In practice, processing is recommended, otherwise whistleblowers will turn to external bodies or media.
How high are the fines for violations of the HinSchG?
According to Section 40 HinSchG, there is a risk of up to 20,000 euros for failure to set up the reporting office, up to 50,000 euros for breach of confidentiality and up to 50,000 euros for reprisals or obstruction of reports. Association fines against the company are possible under Section 30 OWiG.
What does the reversal of the burden of proof mean in the case of reprisals?
If a whistleblower suffers professional disadvantages after making a report, it is presumed that this is reprisal (Section 36 (2) HinSchG). The employer must prove the opposite, for example through complete documentation of the personnel decision.
Can I outsource the reporting office externally?
Yes, Section 14 Paragraph 1 HinSchG allows outsourcing to third parties, such as law firms or specialised service providers. The company's responsibility remains. CIVAC offers this outsourcing as an officer-as-a-service with certified compliance officers and an SLA of two business days.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.