All articles Article

Anonymous reports: do you have to accept them and how to do it safely

Anonymity and confidentiality are two different things, and the Act treats them differently. Confidentiality is always mandatory. Anonymity is the entity's choice, but the choice has consequences for how many reports arrive at all.

min read
5 min read
Updated
Legal status as of
In this article 7
  1. Confidentiality is an obligation, anonymity a choice
  2. What the decision "we do not accept them" means
  3. What the decision "we accept them" means
  4. Protection of the anonymous whistleblower
  5. When confidentiality ends: the disclosure request
  6. What anonymity is not
  7. How this works in sygnadesk

Confidentiality is an obligation, anonymity a choice

The Polish Act of 14 June 2024 on the Protection of Whistleblowers (Journal of Laws 2024, item 928) requires the legal entity to ensure that the procedure and the way data are processed prevent unauthorised persons from gaining access to the information covered by a report and ensure protection of the confidentiality of the identity of the whistleblower, the person the report concerns and third parties named in the report (Article 8(1)). The whistleblower's identity may not be disclosed without their express consent, unless disclosure is a necessary and proportionate obligation arising from provisions of law in connection with proceedings conducted by authorities (Article 8(2) and (3)).

This is confidentiality: the organisation knows who reported, but only a narrow group of authorised persons knows it, and they may not pass that knowledge on.

Anonymity is a situation in which the organisation does not know who reported. The Act mentions it in one place: the internal reporting procedure may define the handling of anonymous reports (Article 25(2)(1)). The decision belongs to the legal entity and must be recorded in the procedure.

What the decision "we do not accept them" means

If the procedure does not provide for anonymous reports, an anonymous report does not trigger the obligations under the Act: there is no need to acknowledge it, take follow-up actions or provide feedback within 3 months. It can, however, and usually should, be examined under general rules, because information about a breach does not become any less true just because it is not known who provided it.

This decision has a price, though, which is not visible in the procedure. Data from studies of reporting channels in Europe are consistent: organisations that accept anonymous reports receive significantly more of them, and the share of reports concerning people in management positions is higher. An employee who is afraid of their manager will not report a matter under their own name no matter how robust the confidentiality clause is, because in a small company and in a small branch "confidential" in practice means "a few people know".

What the decision "we accept them" means

Accepting anonymous reports requires three things that an ordinary e-mail inbox does not provide:

  1. A channel that genuinely does not collect identity. An e-mail inbox records the sender's address. A form on the company intranet records the login. A page that loads analytics scripts records a browser identifier. A report is anonymous only if the reporter page does not record the IP address, does not use tracking tools and does not require an account, and strips from attachments the metadata (file author, phone model, GPS coordinates of a photo) that can identify the author more precisely than a signature.
  2. A way to communicate back without disclosure. The Act requires acknowledgement and feedback if the whistleblower has provided a contact address. An anonymous whistleblower will not provide one, but can return to the case using the report number and an access code, read the reply and answer the case handler's questions. Without such a mechanism an anonymous report is a one-off and usually incomplete.
  3. A provision in the procedure on how anonymous reports are verified. Anonymity increases the risk of malicious reports. The procedure should state that anonymous reports are verified with the same diligence, and that action against the person they concern is taken only after the facts have been confirmed from other sources.

Protection of the anonymous whistleblower

A person who reported anonymously and whose identity was later established is protected against retaliation on the same terms as a whistleblower who reported openly (Article 6 in conjunction with the definition of a report). Identity may be established, for example, from the content of the report, which shows that only one person could have written it. An organisation that takes action against the presumed author in such a situation is liable for retaliation just as if the whistleblower had signed the report.

When confidentiality ends: the disclosure request

Even in a confidential (non-anonymous) channel, access to the whistleblower's identity should be the exception. A good practice that some organisations write into their procedure is separating the content of the report from the identity: the case handler sees the content, and the identity becomes available only on a request approved by a second authorised person, with the purpose and date recorded. Disclosure at the demand of an authority is then documented, and an accidental "peek" out of curiosity is impossible.

What anonymity is not

Anonymity does not relieve the whistleblower of liability for a knowingly false report. Anyone who makes a report knowing that no breach occurred is liable to a penalty (Article 57), and a person who has suffered damage may claim compensation or redress (Article 15). Anonymity makes enforcing this liability harder, but does not remove it.

Nor does anonymity mean that a report is less credible. The Act does not differentiate evidential weight. If anything, the content differentiates it: a report with documents and specifics carries the same weight without a signature as with one.

How this works in sygnadesk

The reporter page runs under the customer's domain, does not record the IP address, loads no external resources and does not require an account. The whistleblower receives a case number and PIN, which they use to return to the conversation with the case handler; the acknowledgement and feedback wait in the case. Metadata are automatically stripped from attachments. If the whistleblower has provided their identity, it is stored separately from the content, and revealing it requires a request approved by a second authorised person and is entered in the register of disclosure requests. In end-to-end mode the content and identity are additionally encrypted with the customer's key, so the system operator has no access to them, even technically.

This text is for information only and describes the legal position on the stated date. It does not replace legal advice in a specific case.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.