HinSchG duties and what OpenWhistle covers

Germany's Whistleblower Protection Act (Hinweisgeberschutzgesetz) has been in force since 2 July 2023. It implements the EU directive. This page is a summary, not legal advice.

Who must run a reporting office

The binding text is on gesetze-im-internet.de.

Section Rule
§ 12 Abs. 1 Employers set up at least one internal reporting office. Municipalities follow their state law.
§ 12 Abs. 2 The duty applies from 50 employees.
§ 12 Abs. 3 Some financial-sector firms need one at any size, for example banks and insurers.
§ 12 Abs. 4 The office must have the powers to examine reports and take follow-up measures.
§ 14 Abs. 1 The office can be one employee, a team, or a third party such as an ombudsperson. A third party does not relieve the employer of remedying a breach.
§ 14 Abs. 2 Private employers with 50 to 249 employees may run a shared office. Remedy and feedback stay with each employer.
§ 42 Abs. 1 Private employers with 50 to 249 employees have had to set up their office since 17 December 2023. This grace period did not apply to the financial firms of § 12 Abs. 3.

Duty by duty

Section Duty OpenWhistle The organisation Shown in
§ 8 Abs. 1 Keep the identity of the reporter and of named persons confidential No IP address is stored; access by role; identity shown only with an audited reason Who may see reports, and their training Anonymity layers, Managing reports
§ 9 Exceptions to confidentiality, e.g. criminal proceedings or the reporter's written consent Every identity reveal is audited Deciding each exception Managing reports
§ 10 Process personal data only as far as the office's tasks need it Only the fields a report needs Record of processing, privacy notice Whistleblower guide
§ 11 Abs. 1 Document every report in a durably retrievable form Every report and message is stored, encrypted; PDF export — Managing reports
§ 11 Abs. 2 Record a telephone report only with consent; otherwise write a summary A telephone guide on /admin/telephone-channel Running the telephone channel Telephone channel
§ 11 Abs. 5 Delete the documentation three years after the procedure ends Retention: closed reports deleted after 1,095 days by default Keeping it longer only where a law requires it Data retention
§ 13 Abs. 2 Clear, easily accessible information on external reporting procedures not covered Publishing it —
§ 15 Independent, competent staff without conflicts of interest not covered Appointing and training them Roles
§ 16 Abs. 1 Channels for employees; anonymous reports should be processed Anonymous and confidential submission Who else may report Anonymity layers
§ 16 Abs. 2 Only the responsible persons access reports Roles and per-organisation scope Assigning the roles Roles
§ 16 Abs. 3 Reports orally and in text form; a personal meeting on request The text channel; a guide for the telephone channel The oral channel and meetings Telephone channel
§ 17 Abs. 1 Nr. 1 Confirm receipt within seven days The 7-day deadline on every case Confirming in time Deadline tracking
§ 17 Abs. 1 Nr. 3 Stay in contact with the reporter Two-way messages via case number and PIN Answering Whistleblower guide
§ 17 Abs. 1 Nr. 6 Take appropriate follow-up measures not covered: the case page records them Deciding and taking the measures Managing reports
§ 17 Abs. 2 Feedback within three months of the confirmation The 3-month deadline on every case The feedback itself Deadline tracking

Deadlines

Event Deadline Section Shown in
Confirmation of receipt 7 days after the report § 17 Abs. 1 Nr. 1 Deadline tracking
Feedback to the reporter 3 months after the confirmation; without one, 3 months and 7 days after the report § 17 Abs. 2 Deadline tracking
Deletion of the documentation 3 years after the procedure ends § 11 Abs. 5 Data retention

Fines

Section Fine
§ 40 Abs. 1 Knowingly disclosing false information to the public, contrary to § 32 Abs. 2: up to €20,000.
§ 40 Abs. 2 Nr. 2 No internal reporting office set up and run: up to €20,000. Fines have applied since 1 December 2023 (§ 42 Abs. 2).
§ 40 Abs. 2 Nr. 1, 3, Abs. 3 Obstructing a report, taking a reprisal, or breaching confidentiality intentionally or recklessly: up to €50,000.
§ 40 Abs. 4 Breaching confidentiality negligently: up to €10,000.
§ 40 Abs. 5 An attempt to obstruct a report or to take a reprisal: up to €50,000.
§ 40 Abs. 6 For a company, § 30 Abs. 2 Satz 3 OWiG raises the maximum tenfold for obstruction, reprisals and confidentiality breaches: up to €500,000 (€100,000 for a negligent breach).

The amounts are maximums from § 40 Abs. 6; the authority sets the actual fine.

GDPR alongside the HinSchG

Requirement Article OpenWhistle Shown in
Data minimisation Art. 5(1)(c) No IP logging, no fields a report does not need Anonymity layers
Privacy by design Art. 25 Self-hosted; no third-party requests from the reporter's pages Outbound requests, Security headers
Lawful basis Art. 6(1)(c) not covered: your basis is the legal duty of § 12 HinSchG, with § 10 HinSchG —
Erasure Art. 17 Reports can be deleted for good; § 11 Abs. 5 sets the regular deadline Data retention, Managing reports
Security of processing Art. 32 Encryption at rest and TLS in transit Encryption at rest, in transit
Breach notification Art. 33 not covered: you notify the authority within 72 hours Incident response template

Fonts, styles and scripts are served by the instance itself; its Content-Security-Policy allows no other host. A German court (LG München I, January 2022) held that loading Google Fonts without consent breached the GDPR. Loading them sends the visitor's IP address to a third party.