The German whistleblower law, the Hinweisgeberschutzgesetz, and the duties it creates
The German whistleblower law, the Hinweisgeberschutzgesetz, or HinSchG, creates duties for every employer with
50 or more staff. It carries the EU Whistleblower Directive into German law, and on several points it goes past
what the directive asks. The law has applied since 2 July 2023. It tells an employer to run a
reporting office with a named, qualified person in charge. That person has to work free of conflicts, which is a
heavier ask than most member states wrote.
Which employers must comply with the Hinweisgeberschutzgesetz?
Employers with 50 or more employees must comply with the Hinweisgeberschutzgesetz. Headcount decides it, whatever the
legal form. The duty binds companies, clubs, foundations and public bodies alike. Public employers sit on the
same 50 employee line as everyone else. Municipalities are the exception. Section 12(1) leaves them, their
associations and the employers they control to the law of the relevant Land. The answer there changes with the
address. Banks, insurers and investment firms owe the duty from their first employee. Size
never lets a finance business out. Mid sized employers got extra time, and those with 50 to 249 staff had until
17 December 2023. Larger ones were bound from day one. Several private employers in that band may also run a
joint office and share the work.
What does the internal reporting office have to do?
The internal reporting office has to take reports in writing and by voice, and offer a meeting in person on
request. Voice covers a phone call or a voice message. The office is open to your own staff and to agency
workers. You may open it wider to anyone who deals with the business through their work. Setting it up is not
the whole job. Staff need clear, easy information on how to use the office and on the external
routes, which you may never make harder to take. WeMoral runs the Meldestelle for employers that would rather not build one, and keeps the file ready if the
Federal Office of Justice ever asks. Access stays with the handlers you name. A law firm or a data protection
consultancy can hold the role for you instead.
What the Hinweisgeberschutzgesetz requires of an internal reporting office.
| Requirement | What it means in practice |
| Confidentiality | The identity of the reporter and of the people named stays secret |
| The person in charge | Qualified, working on their own, free of conflicts |
| Records | Every report logged, then deleted three years after the case closes |
| Phone reports | Recorded or transcribed word for word only with consent, otherwise summarised |
| The reporter's check | They may read, correct and confirm whatever was written down |
| Data | Personal data handled in line with the GDPR |
| Deadlines | Confirm within 7 days, give feedback within 3 months |
Are anonymous reports allowed in Germany?
Anonymous reports are allowed in Germany, and the office should handle one when it arrives. The law stops short
of forcing you to build the channel for anonymous use. That leaves the employer with a choice.
An employer that does open the anonymous route hears about problems earlier. Staff who fear
being identified either report anonymously or say nothing at all, and the second outcome is the expensive one.
German practice has drifted toward accepting them for that reason. A channel that ships with the anonymous route
open, and a name field as an option, leaves that decision to the employer.
Which breaches can be reported in Germany?
The breaches that can be reported in Germany go well past the EU baseline. All criminal offences are in. So are
offences carrying a fine, where the rule guards life, health or the rights of staff. Named subject fields follow
on top. They run from money laundering and product safety to the environment, data protection, food safety,
public tenders, tax and antitrust law. The list has kept growing since 2023, and it now takes in the
rules for digital markets. Crypto sits in its own corner. A firm supervised under the crypto markets
act runs an internal channel at any headcount. Crypto assets are still not a reportable subject on their own.
Some ground stays out. National security and classified files are excluded. So are lawyer and doctor confidence
and the secrecy of judges' rulings.
Who is a whistleblower in Germany?
A whistleblower in Germany is anyone who learns of a breach through their work and reports it. The permanent
employee is only one case among many. Cover also reaches third parties tied to the reporter who could
face payback at work, such as a close colleague or a relative at the same employer. A relative with
no work connection falls outside the wording. That is a narrower reach than several neighbours allow.
Who the Hinweisgeberschutzgesetz protects.
| Group | Detail |
| Employees | Trainees included |
| Public service | Civil servants, judges, members of the armed forces |
| Employee like persons | A home worker, for example |
| Sheltered employment | A person with a disability working in a sheltered workshop |
| Not on the payroll | Agency workers, and applicants on the way into a job |
How does German law protect a whistleblower from payback?
German law protects a whistleblower from payback from the moment the report is made. One condition sits under
it. At the time of reporting, the person needed good reason to believe the information was true and covered by
the act. Someone who reports false information on purpose, or through gross negligence, gets nothing and answers
for the damage. Payback itself means any unfair harm at work that follows a report. Dismissal, a written
warning, a blocked promotion, a transfer, a pay cut, bullying and a poor review are all named. Threatening one
counts as much as doing it. Section 36(2) presumes that harm following a report was payback, so the
employer has to prove other fair grounds. The remedy is money rather than a job. A breach gives no
right to a post, a training place, another contract or a promotion. You cannot contract any of it away either,
and a clause limiting these rights is void whether it sits in an employment contract, a confidentiality clause
or a settlement.
What are the reporting routes under German law?
The reporting routes under German law are the internal office, the external office and public disclosure.
Section 7(1) lets the reporter choose freely between the first two. The act suggests trying inside the company
first, and stops well short of requiring it. The Federal Office of Justice runs the central external office for
the whole country. Finance goes to BaFin, and antitrust to the Bundeskartellamt. The external office
confirms within seven days and gives feedback within three months, stretching to six for a complex
case. Public disclosure is the narrow one. Section 32 protects it only where the office failed to act
in time, or where an urgent danger faces the public.
What fines does the German whistleblower law set?
The German whistleblower law sets fines of up to €50,000, and the amount tracks how serious the breach was.
Lawmakers first drafted a €100,000 ceiling, and the mediation committee cut it in half.
The €500,000 figure that circulates is not in this act at all. It comes from a different
statute that the act merely points to. Section 30(2) of the Act on Regulatory Offences lets a fine against a
legal person rise tenfold. That turns the top tier into €500,000, for instance where managers block a report.
The reach is narrow, though. Section 40(6) applies the cross reference to some offences only. The tier for
having no internal office is not one of them, so that fine stays at €20,000.
The three fine tiers in the Hinweisgeberschutzgesetz.
| Breach | Maximum fine |
| Blocking a report, taking payback, or breaking confidentiality on purpose | €50,000 |
| Failing to set up an internal office, or knowingly disclosing false information | €20,000 |
| Breaking confidentiality through carelessness | €10,000 |
Which whistleblowing software meets the German rules?
Whistleblowing software meets the German rules when it takes written and voice reports, protects two sets of
identities, and deletes a case file three years after closure. WeMoral is encrypted whistleblowing software, a cloud
subscription built around that one job. Reports sit on EU hosted infrastructure in Frankfurt and stay in the bloc. Encryption wraps the report on
arrival, in storage, and along the whole thread back to the reporter. No IP address reaches the log, and
metadata comes off every attachment. The audit log carries a time and an account for every view and every edit.
WeMoral PRO is priced at €79 a month, net, and a 30 day trial covers the full feature set.
Reports are read and routed by people under fixed rules, with no AI anywhere in the reporting path, so nothing
here adds an EU AI Act question to a German compliance file.
What to do if your Meldestelle is still a mailbox
If your Meldestelle is still a mailbox, the missing pieces are the named person in charge and the record. The act
wants someone qualified in charge and a log that survives a check. One compliance officer can run the
whole channel through WeMoral, and a full team can share it with role based permissions that keep personal
data fields to the handlers who need them. PRO comes with five panel users, and Enterprise makes
that unlimited. Staff file in their own language, from 25 languages available, and a handler switches the panel
on their own. A German group with plants abroad therefore works from one system. Whatever you run today, the
open cases can be migrated over without the channel going dark. Three years past the deadline, the live question is whether your office
would survive the first complaint filed against it.