Corruption prevention and data protection go together

A report should make investigation possible. That requires understandable facts and careful handling of the personal data they contain.

Updated September 13, 2026: This article has been rewritten to reflect Germany’s Whistleblower Protection Act and the current data protection framework.

Handle reports with a clear purpose

An effective procedure does not collect as much data as possible just in case. It seeks the information needed to assess a specific suspicion, documents the assessment, and limits access. Unverified allegations must not be treated as established facts.

Keep identity and substance separate

The organization often needs information about the events without needing all of the reporting person’s identifying details. Whether disclosure is lawful and necessary must be assessed at each stage. Simply removing a name does not always prevent identification.

Define the procedure from the outset

The HinSchG, data protection law, and attorneys’ duties of confidentiality must be considered together. This includes a defined group of recipients, clear information for those involved, and appropriate retention and deletion rules. Responsibility follows from the actual engagement and the organization of the reporting office.

For companies, it makes sense to resolve these questions before the first report. For whistleblowers, it is essential to agree on an appropriate channel with the confidential reporting contact before sending particularly sensitive documents.