All use cases Financial institution

Whistleblowing in a financial institution: data the vendor cannot see

The compliance department of a financial institution assesses a vendor by one question: what happens when the vendor is hacked or receives a demand from a foreign authority. The answer "nothing, because it has no key" is the only one that needs no further discussion.

min read
3 min read

The situation

A bank's compliance team judges vendors by one test: what happens if the vendor is breached, or receives a demand from a foreign authority. Whistleblower reports are the most sensitive data in the organisation.

How it works

Content and identity are encrypted with a key held on the client side, so the operator cannot read them even with full database access. Emergency access requires two parties at once: the operator and the client. Data never leaves the European Union, and every operation leaves a trace in the log.

  • E2E encryption
  • Audit log
  • Legal compliance
In this scenario 4
  1. What the Act says in this situation
  2. What to watch when implementing
  3. Features that make the difference
  4. Frequently asked questions

What the Act says in this situation

Entities operating in the field of financial services, products and markets and in anti-money laundering are obliged to have an internal reporting procedure regardless of headcount (Article 23(3) of the Whistleblower Protection Act of 14 June 2024). Here the Act overlaps with earlier sectoral obligations: procedures for anonymous reporting of breaches under the Banking Law, the Act on Trading in Financial Instruments, the AML Act and EU regulations. One channel should serve all these regimes, with the report classified by the person handling it.

A financial institution is also supervised by the Polish Financial Supervision Authority (KNF), which assesses breach-reporting procedures during inspections, and as a controller of high-risk data it is subject to outsourcing requirements and to DORA in respect of ICT services.

What to watch when implementing

  1. The vendor breach scenario. If the content of reports and the identity of whistleblowers are encrypted with a key held solely by the institution, a leak from the vendor's database is a leak of ciphertext. That changes the classification of the incident and the notification obligations.
  2. The demand scenario. A vendor that has no key has nothing to hand over. The demand goes to the institution, which decides together with its own legal department.
  3. Emergency access. Losing the key cannot mean losing the register. The recovery mechanism should require both parties at once, the operator and the institution, so that neither can use it alone.
  4. Location and sub-processors. Data exclusively in the European Union, a list of sub-processors with location and transfer basis, a data processing agreement ready to attach to the DPIA and to the outsourcing documentation.
  5. The audit log as evidence, not as a server log: who, when, what, with immutability that can be demonstrated to an auditor.

Features that make the difference

  • End-to-end encryption with the customer's key, with emergency access requiring two parties (confidentiality); the mode is described in the data processing agreement, section 3.
  • Data exclusively in the EU: Warsaw and Frankfurt, backups in the EEA (security).
  • Immutable audit log and export for inspections (compliance).
  • RBAC per form and per case: compliance, internal audit and HR see only their own categories.
  • Integrations: webhooks and API carrying metadata only to GRC systems, without report content (deployment and integrations).
  • Public list of sub-processors, with 14 days' notice of any change (sub-processors).

Frequently asked questions

Is the system operator a processor if it cannot read the data?

Yes. It processes ciphertext and metadata on behalf of the institution, so a data processing agreement is mandatory. The difference is that the risk on the operator's side is limited to data it cannot read, which matters in the impact assessment and in the classification of any incident.

How does the channel handle reports under the Banking Law and the AML Act?

As separate categories in the same register, with permissions for the appropriate people. The report is classified after it arrives, and the deadlines and the audit log work the same way regardless of the legal basis.

More in the article GDPR in whistleblower reports.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.