How Is Whistleblower Data Stored and Protected?

Whistleblower data is among the most sensitive information an organisation will hold.

A single case file may contain the whistleblower’s identity (or the technical data that could reveal it), the name of the person accused of wrongdoing, witness details, investigation findings, financial records and potentially special category data such as health information or evidence of criminal conduct. How this data is stored – where it resides, who can access it, how long it is retained and what happens when it is no longer needed – is not a technical afterthought. It is a governance decision with direct regulatory, legal and reputational consequences.

For compliance officers, understanding the storage and protection architecture of their whistleblowing system is essential – both for meeting data protection obligations and for maintaining the reporter trust on which the entire programme depends.

Where Whistleblowing Data Is Stored

The physical and legal location of whistleblowing data determines which data protection laws apply, which regulatory authorities have jurisdiction, and how complex the compliance picture becomes for multinational organisations.

Data Residency

Data residency refers to the geographic location where personal data is physically stored. For whistleblowing systems, this matters because the GDPR and UK GDPR impose restrictions on transferring personal data outside the European Economic Area (EEA) or the UK unless appropriate safeguards are in place. Hosting whistleblowing data within the organisation’s own jurisdiction – for example, UK data residency for UK-based organisations – eliminates the need for international transfer mechanisms for domestic data and provides a clear, auditable answer to the question regulators and data subjects will ask: where is my data?

For multinational organisations, data residency decisions become more complex. Some organisations choose to host all whistleblowing data in a single jurisdiction with strong data protection standards. Others use geographically distributed hosting to comply with local data residency requirements. The key principle is that wherever data is stored, the protections applied must meet the highest applicable standard – and the organisation must be able to demonstrate this to any regulator with jurisdiction.

Hosting Model: Internal vs External

Whistleblowing data can be hosted on the organisation’s own infrastructure, on a third-party cloud platform, or on infrastructure managed by the whistleblowing service provider. Each model carries different risk characteristics.

Internally hosted systems place the organisation in direct control of the data but also expose it to internal access risks. IT administrators, database managers and potentially other staff with broad system permissions may be able to access whistleblowing records – a significant concern when the channel is intended to handle reports about senior personnel. Externally hosted systems managed by an independent provider create a structural separation: the organisation’s own technical staff do not have administrative access to the platform, and the provider’s security controls operate independently of the organisation’s internal IT environment.

This structural independence is one of the strongest arguments for external hosting. It does not require the organisation to trust that its own IT policies will prevent unauthorised access – it removes the access pathway entirely.

How Whistleblowing Data Is Protected

Encryption

Encryption is the foundational protection for whistleblowing data. Data must be encrypted both in transit (as it moves between the reporter’s device and the platform) and at rest (while stored on servers). Transport Layer Security (TLS) protects data in transit, while AES-256 encryption is the widely accepted standard for data at rest. Together, these ensure that even in the event of a breach or interception, the contents of whistleblowing reports remain unintelligible without the appropriate decryption keys.

The Italian data protection authority’s €40,000 fine against Bologna airport for operating a whistleblowing system without adequate encryption is a practical illustration of the regulatory expectation. Encryption is not a premium feature – it is a baseline requirement that regulators will assess when evaluating compliance.

Access Controls

Role-based access controls restrict who can view, edit and act on whistleblowing data. In a properly configured system, access is limited to specifically authorised personnel: the designated compliance officer, assigned investigators and, where required, legal counsel. Senior management, HR generalists, IT administrators and other employees should not have access unless specifically granted for a defined, documented purpose.

Multi-factor authentication adds a further layer of protection for all users with case management access, ensuring that a compromised password alone is not sufficient to access the system. Granular permission settings enable different levels of access to be assigned: a case handler might have full access to their assigned cases while the compliance director has oversight of programme-level data without necessarily viewing individual case details.

Audit Trails

Every interaction with whistleblowing data should be recorded in a comprehensive audit trail: who accessed which case, when, what actions they took, and what data they viewed. This logging serves a dual purpose. For compliance, it provides evidence that the confidentiality obligations of the EU Whistleblowing Directive and the GDPR have been maintained. For security, it enables detection of anomalous access patterns – such as a user viewing cases they are not assigned to, or accessing the system at unusual times – that may indicate a compromise or an insider threat.

Anonymity Protections

Protecting the identity of anonymous reporters requires specific technical measures beyond standard access controls. The platform must avoid logging IP addresses for anonymous submissions, strip metadata from uploaded documents (removing author names, device identifiers and GPS coordinates), and ensure that browser or device fingerprinting data is not collected. Without these protections, a reporter who believes they are anonymous may be inadvertently identifiable through technical data the system has captured.

The decision not to audio record telephone reports is a related storage consideration. Voice recordings constitute personal data and may qualify as biometric data under certain processing conditions. Providers that do not record calls eliminate this category of sensitive data from storage entirely – reducing both the protection burden and the risk associated with a potential breach.

How Long Whistleblowing Data Is Retained

The GDPR’s storage limitation principle requires that personal data is not kept longer than necessary for the purpose for which it was collected. For whistleblowing data, this means applying differentiated retention schedules based on case outcomes.

Best practice, supported by the European Data Protection Supervisor’s guidelines on whistleblowing, is to retain reports that do not lead to an investigation for a shorter period – typically two to three months – and to retain data from substantiated investigations for longer, where necessary to support disciplinary proceedings, regulatory action or litigation. Several EU national transpositions impose specific requirements: Austria, for example, requires records of all processing operations related to internal reporting channels to be retained for three years beyond the applicable retention period.

Technology enables these differentiated schedules to be applied consistently and automatically. Configurable retention policies within the case management platform can flag cases for review, archive or deletion based on their outcome and the applicable retention period – removing reliance on manual review cycles that are prone to oversight and inconsistency.

What Happens When Data Is Deleted

Deletion of whistleblowing data must be secure and verifiable. Simply deleting a case file from the case management interface may not remove it from the underlying database, backup systems or archive storage. Secure deletion requires that data is overwritten or cryptographically erased in a way that prevents recovery, and that the deletion is applied across all storage locations – including backups and replicated environments.

The organisation should be able to demonstrate, if required by a regulator or data subject, that data has been deleted in accordance with the applicable retention schedule. This means the deletion process itself must be logged and auditable – another area where technology enforces a discipline that manual processes struggle to maintain.

Questions Compliance Officers Should Ask

When evaluating how whistleblowing data is stored and protected – whether reviewing an existing system or selecting a new provider – compliance officers should seek clear answers to the following:

  • In which jurisdiction is data physically stored, and does this meet all applicable data residency requirements?
  • Is data encrypted to current standards (TLS in transit, AES-256 at rest)?
  • Who has access to the system, and are role-based controls enforced with multi-factor authentication?
  • Does the organisation’s own IT team have administrative access to the platform?
  • Are audit trails comprehensive, covering all access events and actions?
  • Are anonymity protections in place, including IP suppression and metadata stripping?
  • Are telephone calls audio recorded, and if so, how are recordings stored, protected and deleted?
  • Are retention schedules configurable by case outcome, and is deletion secure and verifiable?
  • Is the provider ISO 27001 certified, and is the certification current?

A provider that can answer each of these questions clearly – and provide documentation to support a Data Protection Impact Assessment – gives the compliance officer confidence that the storage and protection of whistleblowing data meets the standard that regulators, reporters and the board expect.

Related Resources

How Safecall Can Help

Safecall stores and protects whistleblowing data to the highest standards. Our platform is hosted on UK-resident servers, ISO 27001 certified and GDPR compliant, with end-to-end encryption, role-based access controls, comprehensive audit logging and metadata stripping for anonymous submissions. We do not audio record telephone calls – eliminating an entire category of sensitive data from storage. Because Safecall operates independently of our clients’ IT infrastructure, their internal technical staff have no administrative access to the system. With over 25 years’ operational experience and a 95% client retention rate, Safecall provides the storage and protection architecture that compliance officers can document in their DPIA and present to their board with confidence.

To discuss how Safecall protects your organisation’s whistleblowing data, contact our team or call +44 (0) 191 516 7720.

Sources and Further Reading

  • EU General Data Protection Regulation (GDPR), Articles 5, 25, 32, Chapter V  –  gdpr-info.eu
  • European Data Protection Supervisor (EDPS), Guidelines on Processing Personal Information within a Whistleblowing Procedure (2019)  –  edps.europa.eu
  • EU Directive 2019/1937 on the Protection of Persons Who Report Breaches of Union Law  –  eur-lex.europa.eu
  • ISO/IEC 27001:2022, Information Security Management Systems  –  iso.org
  • Morgan Lewis, EU and UK Data Protection Implications of Whistleblowing Procedures (2024)  –  Bologna airport enforcement, retention practices  –  lexology.com
  • Morrison Foerster, Whistleblowing Implementing Laws At-a-Glance  –  Austrian retention requirements  –  mofo.com