Whistleblowing: a reporter’s confidentiality is a sanctioned duty, and the proof sits in six places
7 min read
A typical scenario, not our own case. A two-hundred-employee metalworking company receives an internal report: a department head allegedly falsified inspection records. Three months later the reporting employee is called in by their own manager, who quotes back a sentence from the report almost word for word. Nobody leaked it on purpose: the channel runs on an outside platform, the list of who can access it sits in the contract with that supplier, who is authorised to process the data sits in a separate legal-office document — two lists that were never cross-checked. When ANAC asks who read that name, the company finds it cannot prove it with a single document.
The decree missing from our articles, and who it covers
Legislative Decree No. 24 of 10 March 2023 — Official Gazette No. 63 of 15 March 2023, drafting code 23G00032, transposing Directive (EU) 2019/1937 — has not appeared in any of our articles so far: it is data protection in its purest form, the thing protected is a person’s identity. Under Article 2(1)(q), an entity counts as a “private-sector entity” if it “employed, on average over the past year, at least fifty employees under fixed-term or open-ended contracts” (number 1) — an annual average, not a headcount: it is proven with payslips, not a staff register. Below that threshold, entities are still covered if they fall within “the Union acts listed in parts I.B and II of the annex” (number 2) — a cross-reference we do not describe here. Number 3 is the point almost nobody connects: entities are covered too, regardless of size, if they are “within the scope of Legislative Decree No. 231 of 8 June 2001 and adopt the organisational and management models provided for therein.” A twenty-person company that adopted a 231 model to win a tender — common practice among suppliers — thereby carries the channel obligation too, often without knowing it.
Confidentiality is a written duty, not a promise
Article 4(1) requires private entities, “having consulted the workers’ representatives or trade unions referred to in Article 51 of Legislative Decree No. 81 of 2015,” to set up channels that “guarantee […] the confidentiality of the identity of the reporting person, of the person concerned and of any person mentioned in the report, as well as of the content of the report” — it covers the person concerned and the content too, not just the reporter. Management of the channel, under paragraph 2, falls to a dedicated internal office or to “an external party, likewise autonomous and with specifically trained staff.”
The core protection is Article 12(2): the identity of the reporting person, “and any other information from which that identity may be inferred, directly or indirectly,” cannot be disclosed, without express consent, to people other than those “expressly authorised to process such data under Articles 29 and 32(4) of Regulation (EU) 2016/679 and Article 2-quaterdecies of the data-protection code.” What is needed is a named list, not a generically designated office.
Paragraph 5: if a disciplinary charge “is based, wholly or in part, on the report, and knowledge of the reporting person’s identity is indispensable to the accused’s defence,” the report can be used only with the reporter’s express consent; if instead it is “based on separate and further findings than the report […],” the identity stays protected. Either the disciplinary office builds independent findings, or it risks not being able to use the evidence it is holding.
A deadline that moves, not a fixed date
Article 13(2) requires minimisation: “Personal data manifestly not useful to handling a specific report shall not be collected or, if collected by accident, shall be deleted immediately.” Article 14(1) sets a moving retention term: reports and related documentation “are kept for as long as necessary to handle the report and in any case no longer than five years from the date the final outcome of the reporting procedure is communicated.” Not five years from the report — five years from communicating the final outcome. Whoever has not recorded that date precisely does not know when to delete.
The penalties, and the point almost everyone gets wrong
ANAC applies the penalties: Article 21(1) sets “€10,000 to €50,000 where it finds that retaliation has occurred […] or that the confidentiality duty under Article 12 has been breached,” the same range where “no reporting channels have been set up […].” The point almost everyone gets wrong: breaching confidentiality alone is enough, no proven retaliation required.
For entities covered only through the 231 model (number 3), the duty does not stop at the channel: Article 21(2) requires them to include, “in the disciplinary system adopted under Article 6(2)(e) of Decree No. 231 of 2001, penalties against anyone found responsible for the offences under paragraph 1” — another document, in another binder, that has to stay consistent with all the others.
The one piece of data no corporate system holds in full
Proof that a company has met all this sits split across at least six places that do not talk to each other: the channel platform, often an outside supplier’s (Art. 4(2)), holding the record of who opened which report and when, visible only if the contract guarantees it; the authorisation records under Arts. 29 and 2-quaterdecies (Art. 12(2)), the list of who can read an identity, held by the privacy or legal office, not the platform; the 231 model and disciplinary system, with the internal penalties of Art. 21(2), held by the supervisory body; the impact assessment and privacy notices under Art. 13, for the “external suppliers that process personal data on their behalf,” held by the DPO or privacy adviser; the record of union consultation under Art. 51 of Legislative Decree 81/2015 (Art. 4(1)), held by industrial relations; and the disciplinary case file, where Art. 12(5) decides whether the report needs express consent, held by HR and legal.
None of the six holds the date the final outcome was communicated, from which Article 14 counts the five years, nor the record linking an authorised person to a specific report at a precise moment — the data ANAC would ask for first over a breach of Article 12.
If ANAC asked you tomorrow to prove, with a dated document, who read a reporting person’s name and when — not whether you know, but whether you can show it — how many of these six places would you need to search?
See the service · Talk to an engineer
What we do not know
We give no legal advice. We read the thresholds in full in Article 2(1)(q) and Article 3: we have not opened parts I.B and II of the annex referenced by number 2. ANAC has adopted whistleblowing guidelines: resolution No. 311 of 12 July 2023 on the external channel, amended by No. 479 of 26 November 2025, and No. 478 of 26 November 2025 on internal channels. We verified their title, number and date on anticorruzione.it, not the full text, and we did not open the opinion the Data Protection Authority issued on those guidelines. We have not checked specific enforcement decisions on whistleblowing. The opening scenario is a stated, typical model.
The two axes, applied to whistleblowing
Complying. The file the decree demands becomes a control running on the client’s documents and systems: for each of the six places listed above, which data proves it, where it sits, who last updated it. Not a register meant to identify who reported: the opposite — a dated trail proving only expressly authorised people saw that name, ready for an ANAC or Data Protection Authority inspection.
Deciding. The same system holds the six places together in a single operating model, on which AI agents execute decisions with an operator in command — for large and mid-sized private companies. Always on-premises, on autonomous machines needing no deep integration into the client’s network, or on a dedicated cloud, with a dedicated VPN and a data centre resident in Italy, always with shared management: whoever protects a reporter’s identity should not also have to staff an AI administrator in-house. This is the method behind our platform, not an added line item.
From the first session, at no cost, you get a dated list of what stands for your whistleblowing channel: who is authorised, where it is written down, when it was last updated — blanks included. It stays yours even if we do not go on to work together. Talk to one of our engineers.