GDPR in whistleblower reports: controller, processor, retention
A whistleblower report is the most sensitive dataset in an organisation, because it contains the identity of the person making the accusation and of the person accused. The Whistleblower Protection Act and the GDPR overlap here, and in several places the Act expressly modifies the general rules.
In this article 10
- Who is the controller
- Legal basis for processing
- Minimisation and 14 days for erasure
- Information obligation towards the person concerned by the report
- Data subject rights versus whistleblower confidentiality
- Retention: 3 years counted per case
- Authorisations and confidentiality
- Data transfers and sub-processors
- Data protection impact assessment (DPIA)
- How this works in sygnadesk
Who is the controller
The legal entity that keeps the register of internal reports is, under the Polish Act of 14 June 2024 on the Protection of Whistleblowers (Journal of Laws 2024, item 928), the controller of the personal data collected in that register (Article 29(1)). It is the organisation where the whistleblower works that determines the purposes and means of processing: it receives the report, conducts the proceedings and answers to the whistleblower, to the person concerned by the report and to the President of the Personal Data Protection Office (UODO).
The vendor of the system used to handle reports acts on behalf of the client and on its instructions, which makes it a processor within the meaning of Article 28 GDPR. This requires a data processing agreement that sets out the subject matter and duration of the processing, its nature and purpose, the type of data, the categories of data subjects and the obligations and rights of the controller. A vendor who claims that a data processing agreement is unnecessary because it "does not see the data" is right only if it genuinely has no technical access to them; in every other case the agreement is mandatory.
A separate situation is an external entity to which the legal entity has entrusted the receipt of reports, for example a law firm (Article 28 of the Whistleblower Protection Act). A law firm receiving reports on behalf of the client is also a processor, and the agreement with it must cover confidentiality, deadlines and access rules.
Legal basis for processing
The processing of the data of the whistleblower, the person concerned by the report and third parties named in the report takes place for the purpose of compliance with a legal obligation to which the controller is subject (Article 6(1)(c) GDPR in conjunction with the Whistleblower Protection Act). For categories extended by the procedure (internal regulations, ethical standards), the basis is legitimate interest (Article 6(1)(f)). Special categories of data that appear in a report, for example concerning health, are processed on the basis of Article 9(2)(b) or (f) GDPR, to the extent necessary to examine the case.
Consent is not an appropriate basis: the whistleblower cannot effectively withdraw it during the proceedings, and the person concerned by the report does not give it.
Minimisation and 14 days for erasure
The Act introduces its own minimisation rule: personal data that are not relevant to the examination of the report are not collected, and if collected accidentally they must be erased without delay, no later than 14 days from establishing that they are not relevant (Article 8(4)). A report in which the whistleblower describes the private lives of several people therefore requires a decision by the case handler and a record of what was erased and when. A system that allows the content of a report to be redacted while keeping the change history in the log fulfils this obligation without destroying the evidence.
Information obligation towards the person concerned by the report
Here the Act modifies the GDPR. As a rule, the controller informs a person whose data were obtained from another source about the processing (Article 14 GDPR), including the source of the data. The Whistleblower Protection Act provides that Article 14(2)(f) GDPR, that is the obligation to indicate the source, does not apply, unless the whistleblower has consented to the disclosure of their identity (Article 8(5) in conjunction with Article 8(2)). The person concerned by the report is therefore informed that their data are being processed in connection with a report, but not who made it.
The procedure may specify when and how the person concerned by the report is informed (Article 25(2)(3)). Reasonable practice: no earlier than the proceedings allow, so that evidence is not destroyed, but no later than the right of defence requires.
Data subject rights versus whistleblower confidentiality
The person concerned by the report has the right of access to their own data (Article 15 GDPR), but not to the whistleblower's identity and not to the data of third parties. Handling an access request requires extracting from the case file what concerns the applicant, with the rest anonymised. The right to object and the right to erasure are limited by the controller's legal obligation and by the need to establish, exercise or defend legal claims: one cannot demand the erasure of a report because one disagrees with it.
The whistleblower also has the right of access to the data they provided and to information about follow-up actions, but this stems mainly from the Act (feedback), not from the GDPR.
Retention: 3 years counted per case
Data in the register of internal reports are kept for 3 years after the end of the calendar year in which the follow-up actions, or the proceedings initiated by those actions, were completed (Article 29(5)). Longer retention requires another basis, for example an ongoing dispute; shorter retention breaches the Act. Retention is counted separately for each case, so the mechanism should give a reminder when the period expires and require deliberate erasure, with an entry in the log.
Authorisations and confidentiality
Only persons holding a written authorisation from the legal entity, and bound by an obligation of confidentiality, may be admitted to receiving and verifying reports and taking follow-up actions (Article 8(6)). This is the same construct as the authorisation to process data under Article 29 GDPR, except that the Act makes it mandatory and written. A register of authorisations with acknowledgement of receipt by the employee is the document an inspection asks for first.
Data transfers and sub-processors
The controller is responsible for where the data physically are. A vendor that hosts the system outside the European Economic Area or uses subcontractors from outside the EEA must have a transfer basis (an adequacy decision, standard contractual clauses) and indicate this in its list of sub-processors. The data processing agreement should oblige the vendor to give advance notice of changes to sub-processors, with a right to object.
A separate category is end-to-end encryption: if the content of the report and the whistleblower's identity are encrypted with a key held only by the client, the vendor processes only ciphertext and metadata. From the GDPR perspective it is still a processor, but the risk of a breach on its side is limited to data it cannot read. This is an argument a data protection officer understands without explanation.
Data protection impact assessment (DPIA)
The processing of whistleblower reports meets the criteria of high risk: it concerns persons in a relationship of dependence, involves data about breaches of law and may lead to serious consequences for individuals. The President of the Personal Data Protection Office (UODO) includes whistleblowing on the list of operations requiring a data protection impact assessment. The DPIA should be ready before the channel is launched and updated when the vendor or the scope of the procedure changes. The vendor's documentation (description of safeguards, data location, list of sub-processors, data processing agreement) is an annex to it.
How this works in sygnadesk
The client is the controller and the operator is the processor under a publicly available data processing agreement, with a list of sub-processors and data located exclusively in the European Union. The authorisation repository issues and records written authorisations with acknowledgement of receipt. Retention is counted per case, with a reminder and erasure confirmed by a human. In end-to-end mode, content and identity are encrypted with the client's key, so the operator technically has no access to the data it protects.
This text is for information only and describes the legal position on the stated date. It does not replace legal advice in a specific case.
Related articles
- The Polish Whistleblower Protection Act: who it applies to and from when 50-person threshold on 1 January and 1 July, sectors with no threshold, small-municipality exemptions, who is a whistleblower and what the Act covers.
- The internal reporting procedure step by step What the internal reporting procedure must contain under Article 25, how to consult it in 5 to 10 days, when it takes effect and how to announce it.
- Statutory deadlines: 7 days, 3 months and a register kept for 3 years When the 7 days for acknowledgement and 3 months for feedback start, what if the whistleblower gives no address, 14 days for a meeting, 3-year retention.
Where it matters
- Financial institution Whistleblowing in a financial institution: data the vendor cannot see
- IT company as an MSP partner Whistleblowing for an MSP partner: channels for many clients from one panel
- Newsroom and investigative journalism A secure channel for journalistic sources: a conversation without revealing identity
A procedure is a document. A channel is the system that carries it out.
sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.