All use cases IT company as an MSP partner

Whistleblowing for an MSP partner: channels for many clients from one panel

For an IT provider a whistleblowing channel is a service its clients will order anyway; the only question is from whom. The condition is that the partner must not become a person who knows the content of its clients' reports, because then it enters the chain of confidentiality and liability itself.

min read
3 min read

The situation

An IT provider serves dozens of companies, most of which have just crossed the 50-employee threshold. Each needs a channel, none wants to set one up itself, and the provider does not want responsibility for the content of other people's reports.

How it works

The partner creates client accounts in one panel, under its own brand and domain, with a discount that grows with the number of clients. It sees metadata only: case counts and deadlines. It will never see report content or reporter identities, which it can put in writing for its clients.

  • White-label
  • E2E encryption
  • Legal compliance
In this scenario 4
  1. What the Act says in this situation
  2. What to watch when implementing
  3. Features that make the difference
  4. Frequently asked questions

What the Act says in this situation

A legal entity may entrust the receipt of reports to an external entity (Article 28 of the Whistleblower Protection Act), but responsibility for the procedure, the deadlines and confidentiality remains with the entity. An IT provider that sells clients a channel does not receive reports on their behalf unless the contract says so. Its role is to supply and maintain the tool, which makes it a processor within the meaning of the GDPR towards each client separately.

Each client counts the 50-person threshold on its own and establishes its own procedure: consults it, announces it, designates the case handlers. The partner can supply templates and configure the channel, but it cannot "have the procedure on the client's behalf".

What to watch when implementing

  1. The partner does not see the content. If it can technically read clients' reports, it is a person the client must authorise in writing and bind to secrecy (Article 8), and a breach of confidentiality by a partner's employee falls on both parties. A model in which the partner sees only case counts and deadlines, and the content is encrypted with the client's key, removes the problem at source.
  2. A separate account and a separate register for each client. A shared database "for convenience" is a shared set of data belonging to different controllers, a construction that cannot be defended before an inspector.
  3. The partner's and the client's own brand and domain. A whistleblower employed by the client should see their employer's brand, not the IT provider's.
  4. A data processing agreement along the chain: client → partner → platform operator, with a list of sub-processors the client can show its own data protection officer.

Features that make the difference

  • Partner panel: creating client accounts, billing, a discount that grows with the number of clients, with no access to cases (partner model).
  • End-to-end encryption with the client's key: neither the partner nor the operator can read the content or the identity, even with full access to the database (confidentiality).
  • White-label and own domain for each client (implementation and channels).
  • Implementation wizard and document templates: the partner launches a client's channel in an hour, the client adapts the procedure.
  • Tenant export: a client that leaves takes its entire register with it (JSON/CSV with attachments).

Frequently asked questions

Can the partner receive reports on the client's behalf?

It can, if the client expressly entrusts this to it in the contract, with confidentiality rules and deadlines (Article 28). The partner's employees who receive reports then need written authorisations from the client. Most IT partners deliberately do not do this and stay with supplying the tool.

Who is responsible for the 7-day and 3-month deadlines?

Always the client as the legal entity. The partner is responsible for the tool counting the deadlines and sending reminders, and the platform operator for its availability, on the terms set out in the terms of service and the data processing agreement.

More on the roles in the article GDPR in whistleblower reports.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.