Skip to main content

Meeting the EU Whistleblowing Directive With an Anonymous Inbox

The Directive asks for acknowledgement in seven days and feedback within three months. Here is how an anonymous inbox with two-way reply and case status meets the shape of that, and what it cannot do.

The EU Whistleblowing Directive asks an internal reporting channel to acknowledge a report within seven days and give the reporter feedback within three months, and both are impossible for an anonymous report unless the channel has a way back. That way back is the feature this post is about: a return code the reporter keeps, a reply encrypted to it, and a coarse case status per report.

This is a description of how a product behaves, not legal advice. Whether any setup meets an obligation in your jurisdiction is a question for your counsel, and I'll say that once and then get on with the mechanics.

What the Directive actually asks for

Directive (EU) 2019/1937 obliges legal entities in the EU above a size threshold to run an internal reporting channel. Article 9 sets out what that channel must do, and two of its requirements have clocks attached. Receipt of a report is acknowledged within seven days. The reporter gets feedback within a reasonable period, not exceeding three months. Where national law permits anonymous reporting, those obligations don't evaporate because the reporter chose not to give a name.

Most of the compliance market answers this with case management: intake, an anonymous inbox with a ticket number, assignment, evidence, and a login for the reporter. The comparison of hotline vendors covers that lane. What it also covers is the column nobody publishes: whether the vendor could, technically, work out who filed a report. For most of them the honest answer is yes.

The problem anonymity creates

A channel that can acknowledge a report needs to reach the reporter. Reaching someone usually means an address, and an address is an identity. So the standard designs either collect an email and promise not to look, or issue a ticket number tied to a submission time the server recorded. Both leave a link between the report and a person somewhere in the system, held by someone who promises not to follow it. The hotline teardown lists six places that link tends to leak.

We wanted the acknowledgement and feedback without the link. That forces a different shape.

How the way back works

Before submitting, a reporter can take a return code: 26 characters in five groups, drawn in their browser. The code isn't a lookup token. It's the seed of a keypair, generated on the reporter's device, and the public half is sealed inside the encrypted report along with an unguessable mailbox identifier. The code is shown once, with copy, download and print, and a plain statement that it can't be recovered. It never reaches us.

Later, the reporter opens the reply page and types the code. Their browser re-derives the same keys, asks whether that mailbox has anything, and decrypts what's there. They can send a follow-up from the same page. The code is entered on a form and is never in a link, because links end up in browser history, proxy logs and chat previews.

On the organisation's side, a Speak-up inbox tab lists one row per report that carries a code. Each row shows the week the report was made, how many weeks ago that was, the status, the conversation so far, and a composer. A reply is encrypted to the reporter's key. Nobody who holds the poll's results key can read what the organisation wrote back, and that includes anyone holding a shared results link.

Case status, and why it's coarse

Each report carries one of four statuses: received, acknowledged, under review, closed. That's the whole vocabulary, and it's deliberately small.

Status is the one thing about a report the server holds in plain text. It contains no content, and it's what lets a reporter glance at the reply page and see whether there's news. Sending a reply marks the report acknowledged on its own, so there's no state where someone has been answered and the record says otherwise. A chip above the inbox counts reports still awaiting acknowledgement and names the oldest week.

That chip is where the seven-day clock lives, and it's worth being precise about what it's built from.

The clocks are yours, and here's why

Response records in InviziPoll carry no timestamp. A submission time is a correlation handle, and the product's whole design is to hold none. So the "three weeks ago" in the inbox comes from a week the reporter's own browser recorded and sealed inside their report. It's coarse, it's self-declared, and a reporter who edits it only weakens their own position.

The consequence: the seven days and the three months are counted by you, from the reporter's declared week. The product gives you the week and the status. It doesn't run a timer, because a timer would need a fact the server doesn't have.

The same logic explains the absence of notifications. There's no way to tell a reporter a reply is waiting, because that needs an address. Tell people when to check back when you publish the channel. "We answer within a week, check on Monday" does more for acknowledgement than any feature could.

What it maps to, and what it doesn't

Stated plainly:

  • Acknowledgement within seven days. A status the reporter can read, plus a reply in words. Reaches a reporter who kept the code and comes back.
  • Feedback within three months. A thread that outlives the survey, as long as retention is set to cover it.
  • Anonymous reporting where permitted. No identity is collected at any point, and none can be recovered.
  • A record of handling. A coarse status per report.

And the gaps you close yourself. The clocks, as above. Handling records beyond a status, such as who investigated and what was decided, which live in whatever case system you already have. And the channel's own discoverability: the Directive expects people to know the channel exists and how it protects them, which is a communication task no product does for you.

There is no case management here. No assignment, no due dates, no evidence uploads, no export for counsel. The wedge is the property the incumbents can't offer, which is that nobody in the chain, including the vendor, can work out who wrote a report. Feature parity with a full case system was never the point.

Where it sits in the product

The inbox is on Business and Enterprise plans, and on trial workspaces trying the Business features preview. The reporter side, the return code and the reply from a written answer, need an active plan or trial. An always-on speak-up template sets it up with one open question, an open link, and replies switched on.

One pairing to avoid: a public results link on a speak-up poll. A results link lets its holders decrypt responses, which means they can read reporters' follow-ups and post into an open thread. They still can't read what you wrote back. The app warns where the two toggles meet. Keep them apart.

FAQ

Does an anonymous inbox satisfy the EU Whistleblowing Directive? That's a question for counsel, and the honest product answer is "it fits the shape". Acknowledgement and feedback to an anonymous reporter are possible, a coarse handling record exists, and no identity is collected. The clocks and the wider handling records are yours to run.

How does a reporter get acknowledged without giving an email? They keep a return code created in their browser, and enter it on the reply page to read the status and any reply. Nothing notifies them, because nothing knows who they are.

What happens if the reporter loses the code? The report is still there and still readable by the organisation. The reporter can't read replies to it, and nobody can recover the code, because it was never sent anywhere. Say this plainly when you publish the channel.

Can the vendor identify a reporter? No. The report is ciphertext to us, the response record has no timestamp, and the mailbox identifier travels inside the ciphertext. The status is the only plaintext, and it names nobody.

Is this whistleblower case management software? No. It's an anonymous reporting channel with a two-way reply and a status per report. Assignment, evidence and legal export belong in a case system, and most organisations already have one.

The admin walkthrough is in The Speak-up inbox and case status, and the mechanism in Replying to an anonymous report.

#eu whistleblowing directive software#anonymous reporting channel#whistleblower case management#speak-up