All use cases Newsroom and investigative journalism

A secure channel for journalistic sources: a conversation without revealing identity

Journalistic privilege protects a source from the question of who they are. It does not protect an email inbox from a demand or a messaging app from its logs. A channel for sources must ensure there is nothing to hand over, because the newsroom alone holds the key.

min read
3 min read

The situation

Someone with documents from inside an institution approaches a newsroom. They want to hand them over but will not identify themselves, because doing so could cost them their job, or worse. Email and messaging apps leave traces that can be recovered on demand.

How it works

The source hands over files and talks to the journalist through a case number and PIN, with no account, no address and no IP record. Content and identity are encrypted with a key held by the newsroom, so the operator has no key and nothing to hand over on demand. Source protection stops depending on a vendor's goodwill.

  • E2E encryption
  • Anonymity
  • Multiple channels
In this scenario 4
  1. What the law says in this situation
  2. What to watch when implementing
  3. Features that make the difference
  4. Frequently asked questions

What the law says in this situation

A journalist is obliged to keep confidential any data that would allow the identification of a person who has asked for it not to be disclosed (Article 15 of the Press Law). The protection has procedural limits, however: release from the obligation of confidentiality in criminal proceedings is possible in specified cases, and demands directed at service providers do not require the newsroom's consent.

A person passing to a newsroom information about a breach of law obtained in a work-related context may benefit from the protection of the Whistleblower Protection Act as someone making a public disclosure (Article 51), if they had earlier reported the matter without result or had reasonable grounds to believe that a report to an authority would be ineffective or that the breach threatens the public interest. Protection against retaliation by the employer then works the same way as with an internal report.

The newsroom is the controller of the sources' data within the meaning of the GDPR, with the right to limit its information obligations in the field of journalistic activity, but with no exemption from the duty to secure the data.

What to watch when implementing

  1. No data held by third parties. The page for sources cannot use external fonts, scripts, analytics or a CDN that logs addresses. Each such element is data outside the newsroom's control.
  2. The key held only by the newsroom. Content, attachments and any identity of the source encrypted with a key the vendor does not have. A demand to the vendor ends with ciphertext.
  3. File metadata. A document from inside an institution carries the author, the network path and the change history in its metadata. A printout photographed with a phone carries the location. Stripping before saving, automatically.
  4. A conversation stretched over time. The source returns after days or weeks through a case number and PIN, with no account, no address, from a different device.
  5. Access in the newsroom on a need-to-know basis. The case is seen by the journalist handling it and the editor, not the whole newsroom. The audit log shows who opened it.

Features that make the difference

  • End-to-end encryption with the newsroom's key; the vendor has no key and nothing to hand over (confidentiality).
  • A page with no IP logging, no external resources and no tracking, under the newsroom's domain.
  • Metadata stripped from attachments.
  • Case number and PIN instead of an account and email.
  • Per-case permissions and an audit log: access only for the people handling the case (compliance).
  • Multiple forms and languages: a separate channel for sources and a separate one for newsroom staff, if the publisher is subject to the Act as an employer.

Frequently asked questions

Does this replace SecureDrop?

Not in the highest-risk environments, where the source uses the Tor network and dedicated hardware. sygnadesk is a channel for newsrooms that need a secure way, accessible from a phone, to receive documents and conduct a conversation, with no infrastructure on the source's side. The key difference from email and messaging apps: no logs at the vendor and the key held only by the newsroom.

What if the newsroom loses the key?

Emergency access requires both parties at once, the operator and the newsroom, so neither can recover the data alone. The recovery procedure and the people authorised should be agreed at deployment, before they are needed.

More on roles and responsibility in the article GDPR in whistleblower reports.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.