Transparency and confidentiality can appear to pull in opposite directions when it comes to whistleblowing. Employees want to know that concerns are taken seriously and that the programme is active – that requires a degree of openness.
At the same time, those raising concerns need to know that their identity and the details of their report will be protected – that requires strict confidentiality. Managing both, simultaneously, is one of the more nuanced governance challenges in running an effective speak-up programme.
The tension is real but resolvable. Organisations that handle it well understand that transparency and confidentiality operate at different levels: transparency at the programme level, confidentiality at the case level. Conflating the two – or sacrificing one entirely for the other – undermines both the integrity of the programme and the trust of those it is meant to serve.
What Transparency Means in a Whistleblowing Context
Transparency in whistleblowing does not mean disclosing the contents of individual reports. It means being open with employees, stakeholders and, where relevant, regulators about how the programme operates, what protections are in place and what the programme is achieving at an aggregate level.
Effective programme-level transparency typically includes:
- Publishing a clear whistleblowing policy that explains what can be reported, through which channels, and what happens next
- Communicating the existence and accessibility of reporting channels to all employees, including those in remote, frontline or international roles
- Reporting aggregate data – number of concerns received, categories, outcomes – in annual reports, ethics disclosures or staff communications
- Explaining how the programme is governed and how its integrity is maintained
This level of transparency serves a dual purpose. It demonstrates to employees that the programme is active and that their organisation takes misconduct seriously. It also provides assurance to boards, audit committees and external stakeholders that oversight arrangements are functioning as intended.
What Confidentiality Means in a Whistleblowing Context
Confidentiality at the case level is the counterpart to programme-level transparency. It means that the identity of the reporter, the specific details of their concern and the identities of those implicated are handled with strict access controls throughout the life of the case.
This is not simply about protecting the reporter – though that is the primary obligation. It also protects the integrity of any investigation that follows, ensures that those implicated are not subject to informal consequences before any finding is reached, and preserves the organisation’s legal position. Under UK employment law, including the Public Interest Disclosure Act 1994 and the Employment Rights Act 2025, workers who make qualifying disclosures are entitled to protection from detriment. Maintaining confidentiality at the case level is part of how organisations discharge that duty.
Practical confidentiality controls include restricting access to case information to those directly involved in handling it, using systems that separate reporter identity from report content, documenting the rationale for every access decision, and ensuring that those involved in case handling are not in a position to share information with colleagues who may have an interest in the outcome.
Where the Tension Arises
The tension between transparency and confidentiality typically arises in three situations.
The first is when employees ask what happened to a concern they raised. They want to know their report made a difference; the organisation needs to protect the confidentiality of the case. The answer is usually general rather than specific – confirming that the concern was reviewed and addressed, without disclosing what action was taken or who was involved.
The second is when aggregate reporting inadvertently identifies individuals. Reporting that a specific category of concern was raised by one employee in a team of four is not meaningfully aggregate. Organisations need to apply sufficient aggregation – across time periods, business units or concern types – to ensure that no individual can be identified from the data that is published.
The third is when a serious concern requires regulatory disclosure. Under certain legislative frameworks – including the EU Whistleblowing Directive and sector-specific obligations in financial services – organisations may be required to report concerns to external authorities. The Freshfields Whistleblowing Survey 2023 identified regulatory reporting obligations as an area of increasing compliance complexity. These obligations do not override confidentiality protections for reporters, but they do require careful navigation.
How ISO 37002 Frames the Balance
ISO 37002:2021, the international standard for whistleblowing management systems, provides a useful framework for thinking about this balance. The standard establishes principles of impartiality, protection and confidentiality as the foundation of a trustworthy programme, while also requiring that organisations demonstrate governance and accountability – which implies a level of programme-level transparency.
Organisations aligned to ISO 37002 are, in effect, already operating with this distinction in place: governance transparency at the programme level, strict confidentiality at the case level. The standard does not resolve every tension, but it provides a principled basis for the decisions that arise.
The Role of Independent Provision
An externally operated reporting channel makes the balance between transparency and confidentiality significantly easier to manage. When case handling sits with an independent third party, the organisation receives aggregate, anonymised information about what has been reported and how cases have been handled – without direct access to case-level detail that could compromise confidentiality. The structural separation is built into the operating model.
Safecall has operated independent whistleblowing programmes for organisations across the UK and internationally since 1999, supporting the kind of programme-level transparency that builds stakeholder confidence while maintaining the case-level confidentiality that protects reporters. All call handlers are former UK police officers with 25 or more years of interview experience – over 800 years of combined expertise – bringing the disciplined, professional approach that sensitive cases require. Calls are never audio-recorded, removing one of the more significant confidentiality risks at source.
Related Resources
Whistleblowing Security & Anonymity – safecall.co.uk/resources/whistleblowing-security-anonymity/
ISO 37002 Whistleblowing Standards – safecall.co.uk/resources/iso-37002-whistleblowing-standards/
How Can Organisations Ensure Transparency in Reporting Channels? – safecall.co.uk/resources/how-can-organisations-ensure-transparency-in-reporting-channels/
Whistleblowing Data Privacy & GDPR – safecall.co.uk/resources/whistleblowing-data-privacy-gdpr/
Speak to Safecall
Safecall provides independent, confidential whistleblowing services to organisations across the UK and internationally. If you are reviewing how your programme balances transparency with reporter protection, we can help you assess your current approach and identify where independent provision adds value.
Contact us: safecall.co.uk/en/contact-us/ | +44 (0) 191 516 7720
Sources and Further Reading
Freshfields Whistleblowing Survey 2023 – Freshfields Bruckhaus Deringer
ISO 37002:2021 Whistleblowing Management Systems – iso.org
Public Interest Disclosure Act 1994 – legislation.gov.uk
Employment Rights Act 2025 – legislation.gov.uk
EU Whistleblowing Directive (2019/1937) – eur-lex.europa.eu