Data retention in whistleblowing systems presents a complex challenge: organisations must retain records long enough to investigate concerns thoroughly, demonstrate compliance with regulatory requirements, and preserve evidence for potential legal proceedings, yet they must also comply with the General Data Protection Regulation (GDPR)‘s principle of storage limitation, which requires that personal data be kept only for as long as necessary.
The EU Whistleblowing Directive adds further complexity by mandating specific processing requirements whilst delegating detailed retention rules to Member States. Understanding these overlapping requirements is essential for compliance officers implementing or managing whistleblowing arrangements.
For broader context on EU Directive compliance obligations, see our EU Whistleblowing Directive Compliance Hub.
GDPR Storage Limitation Principle
Article 5(1)(e) of the GDPR establishes the storage limitation principle: personal data must be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”
This creates immediate tension in whistleblowing contexts, where personal data includes:
Whistleblower identity data: Name, contact details, employment information, or any combination of data points that could identify the reporter – even when the reporter chose not to provide their name, metadata can enable identification.
Subject data: Information about individuals accused of misconduct or mentioned in reports.
Witness data: Details of colleagues, customers, or third parties who may have relevant information.
Investigation data: Records of interviews, evidence gathered, decisions made, and actions taken.
No Prescribed Retention Period
Critically, GDPR does not specify how long organisations may retain data. Retention periods must be determined based on:
Processing purposes: Why was the data collected? What legitimate objectives require its retention?
Legal obligations: Do other laws mandate retention for specific periods?
Legitimate interests: Are there justifiable business reasons for continued storage?
Data subject expectations: What did individuals reasonably expect when their data was collected?
For whistleblowing systems, these factors can point in different directions. A whistleblower reporting sexual harassment might expect their identity to be protected but their concern to be investigated and remediated. The subject of the allegation expects fair investigation but deletion of unfounded allegations. The organisation needs to preserve evidence of appropriate investigation to defend against employment claims or regulatory scrutiny.
EU Whistleblowing Directive Requirements
The EU Whistleblowing Directive addresses data retention briefly in Article 17, which states:
“Personal data manifestly not relevant for the handling of a specific report shall not be collected or, if accidentally collected, shall be deleted without undue delay.”
Beyond this, the Directive largely defers to GDPR whilst requiring Member States to ensure that whistleblowing processing complies with data protection law. This has resulted in varied national approaches.
Member State Variations
Different EU countries have implemented specific retention requirements:
Portugal: Law 93/2021 requires retention of whistleblowing records for a minimum of five years from the date of report closure. This provides clear certainty but may exceed GDPR’s “no longer than necessary” requirement in some contexts.
Germany: The Whistleblower Protection Act (Hinweisgeberschutzgesetz) does not specify retention periods, leaving organisations to determine appropriate durations based on GDPR principles.
France: Sapin II and subsequent implementing legislation require retention periods that enable demonstration of compliance with anti-corruption obligations, typically interpreted as 5-7 years.
Spain: Organisations must retain records for purposes of potential legal proceedings, with specific periods depending on limitation periods for relevant offences.
This fragmentation creates challenges for multinational organisations seeking consistent data retention policies across European operations.
Factors Determining Appropriate Retention Periods
Compliance officers must balance multiple considerations when establishing retention policies:
Investigation Requirements
Whistleblowing investigations can extend over months or even years, particularly for complex cases involving multiple witnesses, cross-border activity, or parallel regulatory investigations. Data must be retained throughout active investigation periods.
Even after investigations conclude, organisations may need to retain records to:
- Monitor that agreed remedial actions are implemented
- Ensure promised protections for whistleblowers are maintained
- Provide evidence if whistleblowers subsequently claim inadequate response or retaliation
Legal Proceedings Timeframes
Employment tribunal claims in the UK must generally be brought within three months of the act complained of, though this can be extended in continuing discrimination cases. However, whistleblowing claims can relate to conduct occurring years earlier if retaliation continues.
Civil claims and regulatory investigations may have longer limitation periods. Retaining whistleblowing records for 6-7 years provides coverage for most legal proceedings that might reference the reports or investigations.
Regulatory Expectations
Regulators examining organisations’ whistleblowing arrangements expect to see evidence of appropriate handling over time. The Financial Conduct Authority, when assessing firms’ whistleblowing procedures, may request data on:
- Number and types of reports received
- Investigation outcomes
- Protection measures implemented
- How concerns were addressed
Demonstrating this requires retaining summary data even after individual case details are deleted.
Pattern Recognition
Repeated reports about the same department, manager, or type of conduct may indicate systemic issues requiring remediation. Retaining sufficient data to recognise patterns serves legitimate organisational interests in preventing misconduct.
However, this must be balanced against data minimisation. Organisations might retain statistical summaries and themes whilst deleting detailed personal information once cases close.
Practical Data Retention Strategies
Organisations can implement retention policies that balance competing requirements:
Differentiated Retention Periods
Different types of whistleblowing data warrant different retention periods:
Active case data: Retained throughout investigation and follow-up implementation (typically 3-12 months).
Closed case files: Retained for 6-7 years to cover potential legal proceedings, then securely deleted unless litigation or investigation is ongoing.
Unsubstantiated allegations: Where investigations find no evidence of wrongdoing, consideration should be given to earlier deletion (potentially 2-3 years) to protect the reputations of those accused.
Statistical data: Anonymised summary statistics (report volumes, types, outcomes) can be retained longer than detailed case files, as they contain no personal data once properly anonymised.
Whistleblower identity data: Where anonymous reporting is offered, identity data should never be collected. Where identity is known, it requires the strongest protection and potentially shorter retention than other case data.
Progressive Data Minimisation
Rather than retaining complete case files indefinitely, organisations can progressively remove personal data whilst retaining essential records:
Year 0-2: Complete case file retained for active management and potential follow-up.
Year 2-7: Detailed personal information deleted; summary retained covering nature of concern, investigation outcome, actions taken.
Year 7+: All personal data deleted; statistical summaries only retained for pattern analysis and compliance demonstration.
Legal Hold Exceptions
Standard retention periods are superseded when data becomes relevant to legal proceedings, regulatory investigations, or subject access requests. Data retention policies must include procedures for identifying and implementing legal holds when required.
Technical Implementation Considerations
Effective data retention requires appropriate technical measures:
Secure Storage
Whistleblowing data must be stored with encryption and access controls limiting visibility to authorised personnel only. Article 32 GDPR requires appropriate technical and organisational measures to ensure security appropriate to the risk.
At Safecall, all case data is stored with:
- End-to-end encryption in transit and at rest
- Role-based access controls
- Comprehensive audit trails of who accessed what data when
- Regular security testing and certification to ISO 27001 standards
Automated Deletion
Manual data deletion processes are prone to error and inconsistency. Automated systems that flag data for deletion based on predefined criteria ensure consistent application of retention policies.
However, automated deletion must include safeguards:
- Manual review before deletion where cases might have ongoing implications
- Legal hold functionality preventing deletion of data relevant to proceedings
- Secure deletion methods ensuring data cannot be recovered
Anonymisation vs. Deletion
For some purposes, anonymisation provides an alternative to deletion. Genuinely anonymised data (where individuals can no longer be identified) is no longer personal data under GDPR and can be retained indefinitely for statistical analysis and pattern recognition.
However, true anonymisation is challenging. Simply removing names whilst retaining job titles, departments, dates, and specific allegations may still enable identification, particularly in smaller organisations or for unusual types of reports.
Cross-Border Data Transfers
Organisations with operations across multiple countries must consider data location requirements. GDPR restricts transfers of personal data outside the European Economic Area unless appropriate safeguards are implemented.
UK organisations operating whistleblowing systems for EU entities must ensure:
- Data from EU whistleblowers is processed and stored in compliance with GDPR
- Appropriate transfer mechanisms are in place if data is accessed from the UK
- Local data protection authorities’ guidance is followed in each Member State
Record-Keeping Obligations
Beyond retention of case files, organisations must maintain records demonstrating compliance:
Processing Records (Article 30 GDPR)
Organisations must document:
- Categories of personal data processed in whistleblowing systems
- Purposes of processing
- Recipients of data
- Retention periods
- Security measures implemented
These records must be available to data protection authorities on request.
Data Protection Impact Assessments
Whistleblowing systems typically require Data Protection Impact Assessments (DPIAs) because they involve:
- Systematic processing of special category data (allegations of criminal conduct, health information, etc.)
- Large-scale processing of personal data
- Processing that could result in high risk to individuals’ rights and freedoms
DPIAs must be reviewed and updated when processing operations change significantly.
Reporting to Competent Authorities
Some Member States require organisations to report statistics on whistleblowing to competent authorities. These reporting obligations necessitate retaining summary data demonstrating compliance with the Directive’s requirements, including:
- Number of reports received
- Types of concerns raised
- Investigation timelines
- Outcomes and actions taken
How Safecall Manages Data Retention
Safecall’s approach to data retention balances legal requirements with data protection principles:
Clear Retention Policies
Our case management software implements configurable retention policies that:
- Automatically flag data for review and deletion based on case closure dates
- Enable legal holds preventing deletion of data relevant to proceedings
- Maintain comprehensive audit trails of all data processing
- Support progressive data minimisation as cases age
UK and EEA Data Residency
All Safecall whistleblower data resides in the UK with full GDPR compliance. For organisations requiring EEA data residency, we ensure appropriate data location and transfer safeguards.
Security and Access Controls
Strict access controls limit data visibility to authorised personnel only, with comprehensive logging of all data access. This reduces risks of unauthorised disclosure whilst maintaining records demonstrating appropriate data handling.
Independent Review
As an external provider, Safecall offers independent oversight of data retention decisions, reducing risks of data being retained inappropriately due to internal pressures or conflicts of interest.
Next Steps
To establish GDPR-compliant data retention policies for whistleblowing systems:
- Document retention periods for different types of whistleblowing data based on processing purposes and legal requirements
- Implement technical measures enabling secure storage and automated deletion
- Establish legal hold procedures for data relevant to proceedings
- Review Member State requirements for organisations operating across multiple EU countries
- Conduct Data Protection Impact Assessments and update them when processing changes
For expert guidance on implementing data protection-compliant whistleblowing systems, contact Safecall on +44 (0) 191 516 7720 or visit our whistleblowing solutions page.
For broader compliance context, see our EU Whistleblowing Directive Compliance Hub and guidance on how whistleblowing services help reduce workplace liability.