The German whistleblower law, the Hinweisgeberschutzgesetz, and the duties it creates

The German whistleblower law, the Hinweisgeberschutzgesetz, or HinSchG, creates duties for every employer with 50 or more staff. It carries the EU Whistleblower Directive into German law, and on several points it goes past what the directive asks. The law has applied since 2 July 2023. It tells an employer to run a reporting office with a named, qualified person in charge. That person has to work free of conflicts, which is a heavier ask than most member states wrote.

Which employers must comply with the Hinweisgeberschutzgesetz?

Employers with 50 or more employees must comply with the Hinweisgeberschutzgesetz. Headcount decides it, whatever the legal form. The duty binds companies, clubs, foundations and public bodies alike. Public employers sit on the same 50 employee line as everyone else. Municipalities are the exception. Section 12(1) leaves them, their associations and the employers they control to the law of the relevant Land. The answer there changes with the address. Banks, insurers and investment firms owe the duty from their first employee. Size never lets a finance business out. Mid sized employers got extra time, and those with 50 to 249 staff had until 17 December 2023. Larger ones were bound from day one. Several private employers in that band may also run a joint office and share the work.

What does the internal reporting office have to do?

The internal reporting office has to take reports in writing and by voice, and offer a meeting in person on request. Voice covers a phone call or a voice message. The office is open to your own staff and to agency workers. You may open it wider to anyone who deals with the business through their work. Setting it up is not the whole job. Staff need clear, easy information on how to use the office and on the external routes, which you may never make harder to take. WeMoral runs the Meldestelle for employers that would rather not build one, and keeps the file ready if the Federal Office of Justice ever asks. Access stays with the handlers you name. A law firm or a data protection consultancy can hold the role for you instead.

What the Hinweisgeberschutzgesetz requires of an internal reporting office.
RequirementWhat it means in practice
ConfidentialityThe identity of the reporter and of the people named stays secret
The person in chargeQualified, working on their own, free of conflicts
RecordsEvery report logged, then deleted three years after the case closes
Phone reportsRecorded or transcribed word for word only with consent, otherwise summarised
The reporter's checkThey may read, correct and confirm whatever was written down
DataPersonal data handled in line with the GDPR
DeadlinesConfirm within 7 days, give feedback within 3 months

Are anonymous reports allowed in Germany?

Anonymous reports are allowed in Germany, and the office should handle one when it arrives. The law stops short of forcing you to build the channel for anonymous use. That leaves the employer with a choice. An employer that does open the anonymous route hears about problems earlier. Staff who fear being identified either report anonymously or say nothing at all, and the second outcome is the expensive one. German practice has drifted toward accepting them for that reason. A channel that ships with the anonymous route open, and a name field as an option, leaves that decision to the employer.

Which breaches can be reported in Germany?

The breaches that can be reported in Germany go well past the EU baseline. All criminal offences are in. So are offences carrying a fine, where the rule guards life, health or the rights of staff. Named subject fields follow on top. They run from money laundering and product safety to the environment, data protection, food safety, public tenders, tax and antitrust law. The list has kept growing since 2023, and it now takes in the rules for digital markets. Crypto sits in its own corner. A firm supervised under the crypto markets act runs an internal channel at any headcount. Crypto assets are still not a reportable subject on their own. Some ground stays out. National security and classified files are excluded. So are lawyer and doctor confidence and the secrecy of judges' rulings.

Who is a whistleblower in Germany?

A whistleblower in Germany is anyone who learns of a breach through their work and reports it. The permanent employee is only one case among many. Cover also reaches third parties tied to the reporter who could face payback at work, such as a close colleague or a relative at the same employer. A relative with no work connection falls outside the wording. That is a narrower reach than several neighbours allow.

Who the Hinweisgeberschutzgesetz protects.
GroupDetail
EmployeesTrainees included
Public serviceCivil servants, judges, members of the armed forces
Employee like personsA home worker, for example
Sheltered employmentA person with a disability working in a sheltered workshop
Not on the payrollAgency workers, and applicants on the way into a job

How does German law protect a whistleblower from payback?

German law protects a whistleblower from payback from the moment the report is made. One condition sits under it. At the time of reporting, the person needed good reason to believe the information was true and covered by the act. Someone who reports false information on purpose, or through gross negligence, gets nothing and answers for the damage. Payback itself means any unfair harm at work that follows a report. Dismissal, a written warning, a blocked promotion, a transfer, a pay cut, bullying and a poor review are all named. Threatening one counts as much as doing it. Section 36(2) presumes that harm following a report was payback, so the employer has to prove other fair grounds. The remedy is money rather than a job. A breach gives no right to a post, a training place, another contract or a promotion. You cannot contract any of it away either, and a clause limiting these rights is void whether it sits in an employment contract, a confidentiality clause or a settlement.

What are the reporting routes under German law?

The reporting routes under German law are the internal office, the external office and public disclosure. Section 7(1) lets the reporter choose freely between the first two. The act suggests trying inside the company first, and stops well short of requiring it. The Federal Office of Justice runs the central external office for the whole country. Finance goes to BaFin, and antitrust to the Bundeskartellamt. The external office confirms within seven days and gives feedback within three months, stretching to six for a complex case. Public disclosure is the narrow one. Section 32 protects it only where the office failed to act in time, or where an urgent danger faces the public.

What fines does the German whistleblower law set?

The German whistleblower law sets fines of up to €50,000, and the amount tracks how serious the breach was. Lawmakers first drafted a €100,000 ceiling, and the mediation committee cut it in half. The €500,000 figure that circulates is not in this act at all. It comes from a different statute that the act merely points to. Section 30(2) of the Act on Regulatory Offences lets a fine against a legal person rise tenfold. That turns the top tier into €500,000, for instance where managers block a report. The reach is narrow, though. Section 40(6) applies the cross reference to some offences only. The tier for having no internal office is not one of them, so that fine stays at €20,000.

The three fine tiers in the Hinweisgeberschutzgesetz.
BreachMaximum fine
Blocking a report, taking payback, or breaking confidentiality on purpose€50,000
Failing to set up an internal office, or knowingly disclosing false information€20,000
Breaking confidentiality through carelessness€10,000

Which whistleblowing software meets the German rules?

Whistleblowing software meets the German rules when it takes written and voice reports, protects two sets of identities, and deletes a case file three years after closure. WeMoral is encrypted whistleblowing software, a cloud subscription built around that one job. Reports sit on EU hosted infrastructure in Frankfurt and stay in the bloc. Encryption wraps the report on arrival, in storage, and along the whole thread back to the reporter. No IP address reaches the log, and metadata comes off every attachment. The audit log carries a time and an account for every view and every edit. WeMoral PRO is priced at €79 a month, net, and a 30 day trial covers the full feature set. Reports are read and routed by people under fixed rules, with no AI anywhere in the reporting path, so nothing here adds an EU AI Act question to a German compliance file.

What to do if your Meldestelle is still a mailbox

If your Meldestelle is still a mailbox, the missing pieces are the named person in charge and the record. The act wants someone qualified in charge and a log that survives a check. One compliance officer can run the whole channel through WeMoral, and a full team can share it with role based permissions that keep personal data fields to the handlers who need them. PRO comes with five panel users, and Enterprise makes that unlimited. Staff file in their own language, from 25 languages available, and a handler switches the panel on their own. A German group with plants abroad therefore works from one system. Whatever you run today, the open cases can be migrated over without the channel going dark. Three years past the deadline, the live question is whether your office would survive the first complaint filed against it.