HinSchG duties and what OpenWhistle covers
Germany's Whistleblower Protection Act (Hinweisgeberschutzgesetz) has been in force since 2 July 2023. It implements the EU directive. This page is a summary, not legal advice.
Who must run a reporting office
The binding text is on gesetze-im-internet.de.
| Section | Rule |
|---|---|
| § 12 Abs. 1 | Employers set up at least one internal reporting office. Municipalities follow their state law. |
| § 12 Abs. 2 | The duty applies from 50 employees. |
| § 12 Abs. 3 | Some financial-sector firms need one at any size, for example banks and insurers. |
| § 12 Abs. 4 | The office must have the powers to examine reports and take follow-up measures. |
| § 14 Abs. 1 | The office can be one employee, a team, or a third party such as an ombudsperson. A third party does not relieve the employer of remedying a breach. |
| § 14 Abs. 2 | Private employers with 50 to 249 employees may run a shared office. Remedy and feedback stay with each employer. |
| § 42 Abs. 1 | Private employers with 50 to 249 employees have had to set up their office since 17 December 2023. This grace period did not apply to the financial firms of § 12 Abs. 3. |
Duty by duty
| Section | Duty | OpenWhistle | The organisation | Shown in |
|---|---|---|---|---|
| § 8 Abs. 1 | Keep the identity of the reporter and of named persons confidential | No IP address is stored; access by role; identity shown only with an audited reason | Who may see reports, and their training | Anonymity layers, Managing reports |
| § 9 | Exceptions to confidentiality, e.g. criminal proceedings or the reporter's written consent | Every identity reveal is audited | Deciding each exception | Managing reports |
| § 10 | Process personal data only as far as the office's tasks need it | Only the fields a report needs | Record of processing, privacy notice | Whistleblower guide |
| § 11 Abs. 1 | Document every report in a durably retrievable form | Every report and message is stored, encrypted; PDF export | — | Managing reports |
| § 11 Abs. 2 | Record a telephone report only with consent; otherwise write a summary | A telephone guide on /admin/telephone-channel |
Running the telephone channel | Telephone channel |
| § 11 Abs. 5 | Delete the documentation three years after the procedure ends | Retention: closed reports deleted after 1,095 days by default | Keeping it longer only where a law requires it | Data retention |
| § 13 Abs. 2 | Clear, easily accessible information on external reporting procedures | not covered | Publishing it | — |
| § 15 | Independent, competent staff without conflicts of interest | not covered | Appointing and training them | Roles |
| § 16 Abs. 1 | Channels for employees; anonymous reports should be processed | Anonymous and confidential submission | Who else may report | Anonymity layers |
| § 16 Abs. 2 | Only the responsible persons access reports | Roles and per-organisation scope | Assigning the roles | Roles |
| § 16 Abs. 3 | Reports orally and in text form; a personal meeting on request | The text channel; a guide for the telephone channel | The oral channel and meetings | Telephone channel |
| § 17 Abs. 1 Nr. 1 | Confirm receipt within seven days | The 7-day deadline on every case | Confirming in time | Deadline tracking |
| § 17 Abs. 1 Nr. 3 | Stay in contact with the reporter | Two-way messages via case number and PIN | Answering | Whistleblower guide |
| § 17 Abs. 1 Nr. 6 | Take appropriate follow-up measures | not covered: the case page records them | Deciding and taking the measures | Managing reports |
| § 17 Abs. 2 | Feedback within three months of the confirmation | The 3-month deadline on every case | The feedback itself | Deadline tracking |
Deadlines
| Event | Deadline | Section | Shown in |
|---|---|---|---|
| Confirmation of receipt | 7 days after the report | § 17 Abs. 1 Nr. 1 | Deadline tracking |
| Feedback to the reporter | 3 months after the confirmation; without one, 3 months and 7 days after the report | § 17 Abs. 2 | Deadline tracking |
| Deletion of the documentation | 3 years after the procedure ends | § 11 Abs. 5 | Data retention |
Fines
| Section | Fine |
|---|---|
| § 40 Abs. 1 | Knowingly disclosing false information to the public, contrary to § 32 Abs. 2: up to €20,000. |
| § 40 Abs. 2 Nr. 2 | No internal reporting office set up and run: up to €20,000. Fines have applied since 1 December 2023 (§ 42 Abs. 2). |
| § 40 Abs. 2 Nr. 1, 3, Abs. 3 | Obstructing a report, taking a reprisal, or breaching confidentiality intentionally or recklessly: up to €50,000. |
| § 40 Abs. 4 | Breaching confidentiality negligently: up to €10,000. |
| § 40 Abs. 5 | An attempt to obstruct a report or to take a reprisal: up to €50,000. |
| § 40 Abs. 6 | For a company, § 30 Abs. 2 Satz 3 OWiG raises the maximum tenfold for obstruction, reprisals and confidentiality breaches: up to €500,000 (€100,000 for a negligent breach). |
The amounts are maximums from § 40 Abs. 6; the authority sets the actual fine.
GDPR alongside the HinSchG
| Requirement | Article | OpenWhistle | Shown in |
|---|---|---|---|
| Data minimisation | Art. 5(1)(c) | No IP logging, no fields a report does not need | Anonymity layers |
| Privacy by design | Art. 25 | Self-hosted; no third-party requests from the reporter's pages | Outbound requests, Security headers |
| Lawful basis | Art. 6(1)(c) | not covered: your basis is the legal duty of § 12 HinSchG, with § 10 HinSchG | — |
| Erasure | Art. 17 | Reports can be deleted for good; § 11 Abs. 5 sets the regular deadline | Data retention, Managing reports |
| Security of processing | Art. 32 | Encryption at rest and TLS in transit | Encryption at rest, in transit |
| Breach notification | Art. 33 | not covered: you notify the authority within 72 hours | Incident response template |
Fonts, styles and scripts are served by the instance itself; its Content-Security-Policy allows no other host. A German court (LG München I, January 2022) held that loading Google Fonts without consent breached the GDPR. Loading them sends the visitor's IP address to a third party.