Skip to content

Whistleblower reports: how to protect identities in documents

EU, French and German law all require confidentiality for whistleblower reports. Here is what to mask, and who should never see a reporter's name.

By Alexis de ONYRI

A company that receives a whistleblower report must keep the reporter's identity confidential. EU law requires this from the moment a report arrives until the case closes. The same duty covers the person accused and anyone else named in the report, such as a witness. Only a short list of people should ever know who wrote it.

Take Jane Example, a compliance officer at a mid-size logistics firm. She receives a report naming a manager for falsifying safety checks. The file mentions two colleagues by name, plus dates and shift schedules. Before Jane forwards it to an external auditor, she has to decide who really needs to see each detail.

What does EU law require?

Member States shall ensure that the identity of the reporting person is not disclosed to anyone beyond the authorised staff members competent to receive or follow up on reports, without the explicit consent of that person. (Directive 2019/1937, Article 16)

Article 16 of Directive 2019/1937 sets this baseline for the reporting person's identity. The directive also tells reporting channels to protect any other person named in the report. A separate rule keeps the person accused confidential while the investigation runs. Disclosure is allowed only when a law requires it, in particular to protect someone's right to a defence. If the reporting person makes their own identity public, the protection no longer applies to that choice. Staff who handle the file must also keep it secret from colleagues who do not need it.

How do France and Germany apply it?

France first passed the loi Sapin II in 2016 to protect whistleblowers. A 2022 law, the loi Waserman, then changed it to transpose the EU directive. The Défenseur des droits, an independent authority, now guides reporters and sets out their rights in a public guide. The CNIL's rules for alert systems add a data protection layer: only people in charge of investigating or deciding a case may access the file. An anonymous report stays anonymous, and nobody may try to work out who sent it.

Germany's Hinweisgeberschutzgesetz, in force since 2023, is even more precise. Its Section 8 states that the reporting office must protect the identity of the reporter, the person accused, and anyone else named in the report. Only staff who receive reports or follow up on them, plus people directly assisting them, may know who is who. Everyone else in the organisation, including most managers, has no right to that information.

What can give away a reporter's identity?

A masked name is not enough on its own. Small details often point straight back to one person. Watch for these four kinds of clues before you share a file.

  • A precise date or time, when only a handful of people were on shift or in the building
  • A small team or department, where the pool of possible authors is short
  • A distinctive turn of phrase, a typo, or wording that matches an earlier email
  • A job title held by only one person in the company
  • File metadata, such as an author name or a creation date left inside the document

Who should see the file, and what should you mask?

RecipientWhat they needWhat to mask
Line managerThat a report exists, and its general subjectThe reporter's name, contact details, and exact wording
External auditorThe facts to check, such as invoices or datesNames, emails, phone numbers, and any employee ID
Authority or regulatorThe full file, once a legal basis appliesOnly what the law does not require it to see
Outside counselEnough detail to assess legal riskDirect identifiers, unless the case truly needs them

A tool can help with the document side of this. ONYRI Sanitize masks names, emails and phone numbers in a report inside the browser, so the file itself is never uploaded. Custom rules can also catch internal employee numbers. Its limit: indirect clues, such as a team name or a date, still need a human review before the file goes out.

Confidentiality is a process, not a single click. A masked document protects the names on the page. The rest depends on who receives the file, and how carefully you have thought through indirect clues.

What happens when confidentiality fails?

  • The reporting person can face retaliation, from exclusion to dismissal, which the directive and national laws both forbid
  • The organisation can lose the trust that makes people report a problem early, before it grows bigger
  • In France, breaking this duty can mean up to two years in prison and a €30,000 fine. Germany's HinSchG allows a fine of up to €50,000 for the same kind of breach.

Frequently asked questions

Does a company have to keep a whistleblower's identity secret?
Yes. The EU Whistleblower Directive requires protecting that identity at every stage. Only a small number of staff assigned to the report may know who sent it, and any disclosure needs a legal basis.
Can colleagues work out who reported, even without a name?
Often, yes. A precise date, a small team, or a writing style can point to one person. That is why reviewers should check indirect clues, not just the name field, before sharing a file.
Does the protection also cover the person accused in a report?
Yes. Article 22 of the directive keeps the person accused confidential too, for as long as the investigation runs. Reporting channels must also protect any other person named in the report, such as a witness, under Article 9.
Who is legally allowed to know a whistleblower's identity?
Only staff assigned to receive or follow up on reports, under both the German HinSchG and the French rules. Wider disclosure needs a legal basis, such as a court case, limited to what it requires.
Does an anonymous report still need this protection?
Yes. French data protection guidance treats an anonymous alert as its own category. It tells organisations not to try to re-identify the person who sent it.

Sources & references

On this siteAnonymize HR documents

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.

Read next