How to protect the confidentiality and personal data of whistleblowers? We provide a DPIA template.

20 December 2021

Directive (EU) 2019/1937 of the European Parliament and of the Council on the protection of persons reporting breaches of Union law imposes an obligation on organizations to establish appropriate mechanisms and procedures that will protect whistleblowers from various forms of retaliation. Whistleblowers reporting specific irregularities within the organization should be ensured confidentiality and protection of their personal data. Only in this responsible manner will the organization be able to obtain relevant information from them.

Data controllers who are in the process of designing and establishing processing procedures and personal data protection policies for whistleblowers may benefit from substantive support in the form of guidelines from the European Data Protection Supervisor (EDPS) regarding the processing of personal data within the whistleblowing procedure, as well as the standard from the French supervisory authority (Commission nationale de l'informatique et des libertés, CNIL), which pertains to the processing of personal data in the context of reporting irregularities.

Due to the prolonged work on the act on the protection of persons reporting breaches of law, which would transpose Directive 2019/1937 into Polish law, this article will directly refer to the provisions of the directive and contextualize them
within the requirements of personal data protection regulations.

Safe Reporting of Irregularities in the Organization

For a whistleblower reporting abuses, it is crucial for the organization to ensure the protection of their identity, especially since, according to CNIL and EDPS, reporting irregularities should generally not be anonymous. A whistleblower reporting cases of violations is required to provide information about themselves for two reasons: due to the potential for misuse of the whistleblowing procedures and to enable their effective protection against reprisals.

In the opinion of CNIL, an anonymous report of a violation may be considered if:

  • the description of the violation is sufficiently detailed,
  • specific precautions have been taken, such as prior analysis by the first recipient of the report regarding the justification for its dissemination within the whistleblowing notification management system.

Data controllers should therefore implement internal and external procedures for reporting breaches and ensure the protection of the information received. The whistleblower should also be provided with protection against any form of retaliation, which is why their identity must be treated as confidential and not disclosed, except in situations specified by the Directive, when:

  • the whistleblower has given explicit consent,
  • such disclosure is a necessary and proportionate obligation arising from EU law or national law in the context of investigations conducted by national authorities or judicial proceedings, including to guarantee the right to defense of the person to whom the report pertains,
  • the person making the report has intentionally disclosed their identity in the context of public disclosure.

Importantly, according to the guidelines of the European Data Protection Supervisor, a person against whom allegations have been made should be protected within the organization similarly to the whistleblower, due to the risk of their stigmatization and victimization, before they become aware that they have been accused and until the facts of the case have been verified.

Reports of irregularities may also contain personal data of third parties: witnesses, victims, or individuals who may confirm specific facts. The management procedure for the report should guarantee the protection of data concerning these individuals as well.

Maciej Kaczmarski

EDITION I, YEAR 2022

ODO 24 Ranking

Best Applications for Whistleblowers

We have thoroughly tested the applications available on the Polish market. The results of our research along with reviews are published in the ranking.

Check the ranking

In light of the above, access to whistleblower reports should be governed by the following principles:

  • necessary knowledge – individuals analyzing reports should have access only to the information they need to perform their tasks (different tasks/roles imply different necessary knowledge for their execution, and thus a different level of access),
  • necessary needs – individuals analyzing reports should have access only to those means of processing information (devices, applications, premises) that are necessary for them to perform their duties.

The guidelines from the EIOD recommend that personnel with access to personal data contained in whistleblower reports have an enhanced obligation to maintain confidentiality. Access to reports, regardless of the method of processing – whether traditional or electronic – should be continuously monitored.

It should be noted that maintaining the confidentiality of personal data disclosed by the whistleblower does not preclude the data controller from using the services of a data processor, e.g., an IT system provider. The CNIL only recommends using the services of a provider that guarantees the implementation of appropriate personal data protection measures, both technical and organizational, and entering into a data processing agreement that regulates the issues mentioned in Article 28 of the GDPR.

Different purposes of processing personal data

Directive 2019/1937 in Article 2(1) regulates the protection of individuals reporting breaches covered by the scope of EU law, particularly in the following areas: public procurement, environmental protection, food safety, public health, and consumer protection. The decision to extend this scope to breaches of national law has been left to the individual member states.

The EIOD emphasizes that the reporting procedure should only cover those matters that fall within the subject matter of the Directive. Other matters, such as those related to harassment or mobbing, should be reported to the employer or authorized bodies through separate channels from those designated for whistleblowers.

According to the CNIL, several purposes of processing can be pursued simultaneously within the management of breach reports, e.g., breaches of EU law or the internal ethical codes of the data controller. In such cases, each processing operation must have a separate legal basis. In the opinion of the CNIL, the following provisions will apply:

  • Article 6(1)(c) of the GDPR – where processing is necessary for compliance with a legal obligation to which the data controller is subject and related to the implementation of the provisions of the Directive,
  • Article 6(1)(f) of the GDPR – where processing is necessary for the purposes of the legitimate interests pursued by the data controller and related to breaches of the internal ethical codes of the data controller.

It should be emphasized that any personal data related to reporting irregularities, stored for statistical purposes, should be anonymized. Data controllers are advised to exercise particular caution regarding any information that could lead to the indirect identification of the whistleblower, such as their nationality.

 E-learning for whistleblowers

Appropriate data processing

In the process of managing breaches, it may occur that the data controller comes into possession of personal data that is unrelated to the breach and does not affect its resolution. Of course, such information should not be further processed. This is particularly significant in the case of special categories of personal data. According to the recommendation of the DPO, all individuals authorized to process personal data within the breach management process should be informed of this principle.

Furthermore, according to the recommendations of CNIL, the data controller should be obliged to remind whistleblowers that the information they provide must be based on facts and have a direct connection to the subject of the report. CNIL also recommends the following scope of information to be processed in the management of irregularity reports:

  • the identity, position, and contact details of the whistleblower,
  • the identity, position, and contact details of the individuals who are the subject of the report,
  • the identity, position, and contact details of individuals involved in the collection or processing of data related to the report,
  • the content of the report,
  • collected evidence,
  • report on control actions,
  • follow-up actions taken in connection with the report.

FREE

Whistleblower protection - what and how to implement?

Watch the webinar

How to fulfill information obligations related to irregularities?

According to the recommendation of the European Data Protection Supervisor (EDPS), the information obligation regarding the reporting of irregularities should be generally accessible within the organization, e.g., as part of the privacy policy on the data controller's website or in the intranet.

Regardless, the individuals whose data are being processed should receive the required information in accordance with Articles 12-14 of the GDPR.  At the same time, the EDPS recommends that the data protection notice inform about the consequences of abusing the reporting procedure for irregularities (e.g., if the whistleblower makes a false statement), such as disciplinary or criminal measures. In turn, the CNIL emphasizes that making a report in good faith should not expose the reporter to any disciplinary actions, even if it later turns out that the information provided did not constitute grounds for taking any action.  

Fulfilling the information obligation towards the whistleblower

The data controller's information obligation towards the whistleblower when collecting personal data arises from Article 13 of the GDPR. It may appear on the website designated for reporting violations in full or as information provided progressively during the completion of the application. According to the CNIL, the data controller may condition the submission of the report on the selection of a checkbox indicating that the person making the report has acknowledged the information obligation.  

CNIL recommends that in the event of a report being made, the whistleblower should be provided with confirmation of its receipt, thereby allowing them to benefit from the protection system available to them. The confirmation should summarize all information and include  
all attachments submitted as part of the report. Providing confirmation to the whistleblower should not depend on the presentation of information that would allow for their identification (email address, postal address, etc.), if the individual wishes to remain anonymous.

Fulfilling the information obligation towards the alleged perpetrator of the violation

Article 14(3) of the GDPR indicates that the data controller should inform the person to whom the entry pertains (e.g., as a witness, victim, or alleged perpetrator) within a reasonable time after obtaining the personal data, but no later than one month from the receipt of the report.

Whistleblower Protection

Nevertheless, there is no need to fulfill the indirect information obligation arising from  Article 14(5)(b) GDPR,  when it may prevent or seriously hinder the achievement of the processing purposes, when disclosing such information to the person subject to the investigation would seriously jeopardize the needs of the investigation, for example, through the risk of destruction of evidence. CNIL recommends that in such cases, information should be provided as soon as the risk has been avoided.  In this case, the DPO recommends documenting the reasons for any limitations related to the fulfillment of the information obligation (for the purposes of any actions by the supervisory authority). These reasons should confirm the high risk that providing the information referred to in Article 14 GDPR would hinder the procedure or violate the rights and freedoms of others.

Informing about the sources of personal data, as part of the obligation under Article 14 GDPR, must not result in the disclosure of personal data of the whistleblower or third parties. CNIL points out that after a report has been made, if disciplinary or judicial proceedings are initiated against a given person, they may obtain the specified information in accordance with common law (in particular, the right to defense).

Retention period for personal data contained in reports

Pursuant to Article 18 of the Directive, legal entities in the private and public sectors and the relevant authorities are required to maintain a register of reports and to retain them no longer than is necessary and proportionate to ensure compliance with the requirements of EU or national law. Since the directive does not specify the retention period for reports, it is recommended that the national legislator indicate the retention period for the reports and the personal data contained therein in the implementing act (as of the date of publication of this article, the Polish legislator anticipated a period of 5 years).

Furthermore, the DPO indicates that personal data that are not related to the allegations should be  deleted without undue delay.  If, after a preliminary assessment, it turns out that a given case is not covered by the whistleblowing procedure, the report should be deleted as soon as possible (or directed to the appropriate channel, for example, regarding harassment). Anonymization may take place in accordance with the recommendations contained in Opinion 05/2014 of the Article 29 Working Party on anonymization techniques.

READ MORE: 10 errors and misunderstandings related to anonymization

Implementation of Security Measures

The implementation by the data controller of specific technical and organizational data protection measures should be preceded by a risk analysis for defined resources (personal data of whistleblowers and other individuals disclosed in breach reports), as well as threats to the rights and freedoms of the data subjects, taking into account the existing processing conditions (nature, scope, context, and purposes of processing). The security measures applied should consider the sensitive nature of the personal data processed within the breach management procedure.

According to CNIL recommendations, the risk analysis should be conducted at the stage of determining the methods of processing, as this is when the data controller assesses which resources will be used during the processing operations, what measures and safeguards to apply in order to effectively implement the principles of personal data processing and to fulfill the rights and freedoms of natural persons, considering elements such as the state of technical knowledge, implementation costs, nature, scope, context, purpose, and risk. The data controller should demonstrate that this assessment has been made concerning all measures applied in the processing operations. Furthermore, given the changing nature of risk, the data controller must conduct periodic reviews, especially regarding the effectiveness of the safeguards applied.

Finally, it should be noted that the President of the Polish Data Protection Authority has recognized that actions related to the operation of systems dedicated to reporting irregularities require conducting a Data Protection Impact Assessment. This is a correct position, as the processing process may involve, among others, the following violations of the rights and freedoms of whistleblowers:  

  • interference with access to employment through unjustified termination of employment, refusal to extend it, or blocking the possibility of employment with other employers on the basis of a so-called blacklist,
  • actions sabotaging career development paths, including withholding promotions or access to training,
  • actions leading to undermining the credibility of the whistleblower, e.g., by defaming them on social media or subjecting them to psychiatric evaluations;
  • revocation of licenses or permits.

In order to facilitate your compliance with this challenging obligation, we would like to provide a sample report of the Data Protection Impact Assessment authored by attorney Katarzyna Szczypińska, prepared as part of our application Dr RODO.

Download
Results of the Data Protection Impact Assessment (DPIA) and Risk Analysis

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.