Short answer:A whistleblower system that complies with the law must allow people to report safely and confidentially, protect their identity, confirm and follow up on cases within statutory times and handle personal data in accordance with the GDPR. All this must be able to be documented.

What does the whistleblower law say?

Sweden has a whistleblower law (the law on protection for people who report wrongdoing) which is based on an EU directive. It requires certain employers to have internal reporting channels where employees and others in the business can raise the alarm about serious misconduct - without risking losing their job or suffering reprisals.

The requirement for an internal channel applies above all to employers50 or more employees. If your company has more than that, you are usually covered by the requirement. If you are not sure exactly where your company ends up, you should find out - the rules and the threshold are something you want in black and white.

What must the system itself handle?

It is not enough to have an email address where people can write. The law places concrete demands on the channel:

  • Secure and confidential reporting.Whoever raises the alarm must be able to do so without unauthorized persons seeing who it is.
  • Protection of identity.Only specially appointed persons should be able to take part in the matter and who reported it.
  • Confirmation in time.The person who reports must receive a confirmation within seven days.
  • Feedback.Feedback on the follow-up must normally be given within three months.
  • Ability to report in writing and orally– and on request at a physical meeting.
  • Documentation.Matters and measures must be able to be documented and preserved.

How does it relate to GDPR?

A whistleblower case almost always contains sensitive personal data – about both the whistleblower and the person singled out. Therefore, the system must handle the data according to GDPR. This means, among other things:

  • Limited access- only those who are to investigate can see the data.
  • Thinning- data must be deleted when they are no longer needed.
  • PUB agreement with the supplier- because the system provider processes personal data for you (more about that in our article on PUB agreements).
  • Secure storage- preferably within the EU, with encryption.
A common pitfall is to buy a cheap form tool and think the law is being met. If you lack confidentiality, deadlines and proper data protection, you're out of luck - and that's when it gets expensive.

What questions should I ask the supplier?

  1. How is the notifier's identity protected technically?
  2. Does the system support confirmation within 7 days and feedback within 3 months?
  3. Where is the data stored, and is it encrypted?
  4. Will I get a PUB contract?
  5. Is it possible to report anonymously, and can we have a dialogue with an anonymous reporter?
  6. How is thinning of old cases handled?
  7. Can the role of case recipient be controlled so that only the right people see the case?

Build yourself or buy ready-made?

It is possible to build your own solution, but then it must fulfill all of the above – and that is often underestimated. For many companies, a well-thought-out, purpose-built portal is a safer route, as long as it is correctly set up and integrated with your routines.

Do you want a whistleblower portal that lasts?

ZORC builds and deploys whistleblower portals that are made to meet both the Whistleblower Act and GDPR - with secure reporting, protected identity and proper data protection. We will also help you find out if your company is covered by the requirement. Get in touch with ZORC, and we will go over what exactly your business needs.