{"id":16468,"date":"2023-12-13T13:42:54","slug":"whistleblowing-systems-and-the-eu-whistleblowing-directive-the-3-essential-criteria","title":{"rendered":"Whistleblowing systems and the EU Whistleblowing Directive: The 3 Essential Criteria"},"content":{"rendered":"<p><span style=\"font-weight: 300\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-16470 alignleft\" src=\"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-300x240.jpg\" alt=\"whistleblowing system\" width=\"326\" height=\"261\" srcset=\"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-300x240.jpg 300w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-150x120.jpg 150w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-768x615.jpg 768w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-640x513.jpg 640w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-400x320.jpg 400w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope-367x294.jpg 367w, https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope.jpg 1000w\" sizes=\"auto, (max-width: 326px) 100vw, 326px\" \/>A whistleblowing system is an effective tool for detecting and uncovering illegal and fraudulent activities. However, the effectiveness of a whistleblowing system is determined by a few key factors that must be met by the company.<\/span><\/p>\n<p><span style=\"font-weight: 300\">Communication and raising awareness about, guaranteeing confidentiality, and easy access to the reporting system are the main, commonly known factors. In addition to these three factors, several other requirements need to be met to ensure the reporting system can run effectively.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32019L1937\"><span style=\"font-weight: 300\">The EU Whistleblower Directive<\/span><\/a><span style=\"font-weight: 300\"> stipulates various provisions that European Union (EU) member states must comply with to create a minimum level of protection for whistleblowers and encourage individuals to report violations and misconduct. These provisions include:<\/span><b><\/b><\/p>\n<p><b>1. Facilitating reporting in oral and written form<\/b><\/p>\n<p><span style=\"font-weight: 300\">Organizations are required to establish diverse channels for reporting, enabling whistleblowers to submit reports either orally, in writing, or both. Among the most <\/span><a href=\"https:\/\/www.acfe.com\/fraud-resources\/whistleblower-hotline-report\/-\/media\/24e0af95c7aa4b76918bbc1ed4217fac.ashx\"><span style=\"font-weight: 300\">prevalent options<\/span><\/a><span style=\"font-weight: 300\"> are dedicated telephone hotlines and web-based online reporting systems.<\/span> <span style=\"font-weight: 300\">Other channels include SMS, postal mail, and online chat.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 300\">In addition, these channels must also be easily accessible and user-friendly. For example, incorporating a multilingual reporting feature.<\/span><b><\/b><\/p>\n<p><b>2. Ensuring the security and confidentiality of the identities of the parties involved<\/b><\/p>\n<p><span style=\"font-weight: 300\">Should an organization employ a third-party service to provide a whistleblowing system, it must ensure that the third party has the capacity to support anonymous reporting without hindering the investigation process.\u00a0<\/span><b><\/b><\/p>\n<p><b>3. Data processing under the GDPR<\/b><\/p>\n<p><span style=\"font-weight: 300\">The whistleblowing system must ensure that the data security and retention policies are in accordance with the General Data Protection Regulation (GDPR), which governs how the personal data of individuals in the EU may be processed and transferred.<\/span><\/p>\n<p><span style=\"font-weight: 300\">Although the EU Whistleblower Directive targets EU member states, this regulation also impacts companies from countries outside the jurisdiction. For instance, Indonesian or Swiss companies with a presence in the EU can become subject to this regulation if they meet the specified threshold requirements. The requirement is that companies with 50 or more employees must have a whistleblowing system. However, companies in the financial sector and other sectors vulnerable to money laundering or terrorist financing are required to have a whistleblowing system regardless of the number of employees.<\/span><\/p>\n<p><span style=\"font-weight: 300\">Similarly, if a China-based company serves as a primary vendor to an EU-based company, it is likely the company must establish a whistleblowing system that complies with the criteria stipulated in the EU Whistleblower Directive.<\/span><\/p>\n<p><span style=\"font-weight: 300\">The establishment of a compliant reporting system is not an easy feat. The absence of infrastructure for an integrated reporting platform and the lack of experience and expertise can significantly hinder a company\u2019s ability to establish a compliant whistleblowing system.<\/span><\/p>\n<p><span style=\"font-weight: 300\">One surefire solution is to work with a third-party that provides an integrated and compliant reporting platform. One such example is the <\/span><a href=\"https:\/\/www.canary-whistleblowing.com\/en\/channels\/\"><span style=\"font-weight: 300\">Canary Whistleblowing System<\/span><\/a><span style=\"font-weight: 300\">.<\/span><\/p>\n<p><a href=\"https:\/\/www.canary-whistleblowing.com\/en\/channels\/\"><span style=\"font-weight: 300\">Canary WBS<\/span><\/a><span style=\"font-weight: 300\"> enables two-way communication between whistleblowers and operators without the whistleblower needing to provide any personal information (e.g. email or phone number). Whistleblowers can submit reports, receive updates, and converse with operators anonymously, without the need to create an account\u2014using a set password and report identifier number.<\/span><\/p>\n<p><span style=\"font-weight: 300\">Canary WBS, as a provider of a web-based whistleblowing hotline system, uses end-to-end encryption (E2EE) and is SSL-certified for maximum user data protection. Moreover, the <\/span><a href=\"https:\/\/www.canary-whistleblowing.com\/en\/privacy-policy\/\"><span style=\"font-weight: 300\">data retention policy<\/span><\/a><span style=\"font-weight: 300\"> is GDPR-compliant.<\/span><\/p>\n<p><span style=\"font-weight: 300\">The Canary Whistleblowing System enables companies to comply with the EU Directive with features that accommodate all the elements required in a reporting system. Moreover, by using a reliable third-party service, organizations can save time, money, and resources in implementing a compliant whistleblowing system.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>Image by <a href=\"https:\/\/www.freepik.com\/free-photo\/woman-holding-european-union-envelope_5316023.htm#page=2&amp;query=EU%20flags&amp;position=35&amp;from_view=search&amp;track=ais&amp;uuid=36d0c804-2a7e-4cae-bcc9-bb0a963b31a0\">Freepik<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A whistleblowing system is an effective tool for detecting and uncovering illegal and fraudulent activities. However, the effectiveness of a whistleblowing system is determined by a few key factors that must be met by the company. Communication and raising awareness about, guaranteeing confidentiality, and easy access to the reporting system are the main, commonly known [&hellip;]<\/p>\n","protected":false},"acf":[],"featured_image_url":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2023\/12\/woman-holding-european-union-envelope.jpg","_links":{"self":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts\/16468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/comments?post=16468"}],"version-history":[{"count":0,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts\/16468\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/media\/16470"}],"wp:attachment":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/media?parent=16468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/categories?post=16468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/tags?post=16468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}