New Feature: Multi Rater Feedback and 360 Appraisals
Back to blog

ANAC Internal Reporting Channels: Requirements for Written and Oral Reports

Guide to internal reporting channels aligned with ANAC Guidelines: written and oral requirements, DPIA, confidentiality, and process timelines.

29 July 202610 min readCompliance Guides

By Disclosurely Editorial

On this page

Compliance Guides

ANAC Internal Reporting Channels: Requirements for Written and Oral Reports

Disclosurely

The ANAC Guidelines No. 1 (Resolution No. 478 of 26 November 2025) represent the operational reference for configuring internal reporting channels. Their impact is direct: a channel that does not comply with Articles 4 and 5 of D.Lgs. 24/2023 exposes the entity to fines of €10,000 to €50,000.

In this guide, we examine the technical and organizational requirements that ANAC identifies for the two reporting modalities — written and oral — and their practical implications for those designing and managing the channel. For when the Italian obligation applies in the first place, see D.Lgs. 24/2023: the 50-employee rule and Model 231.

This guide is general information for software and process evaluation, not legal advice. Country rules change and should be checked with qualified local counsel before rollout.

The Fundamental Principle: Both Modalities Are Mandatory

ANAC is explicit: the internal channel must guarantee both written and oral forms. Adopting only one modality is not permitted. The channel must also be easily accessible to all persons entitled to report, including consultants, volunteers, and other non-employees (Art. 4(1), D.Lgs. 24/2023).

The organizational act or Model 231 must regulate the receipt and management of both types of reports.

Written Reports: IT Platforms, Email, and Paper Protocol

The Preferred Solution: Dedicated IT Platforms

ANAC expresses a preference for IT platforms because they enable the implementation of more robust security measures, including:

  • Encryption of data at rest
  • Confidential interaction with the reporter via an identification code (Key Code)
  • Documented traceability of receipt and management activities
  • Compliance with the principles of privacy by design and privacy by default (Art. 25 GDPR)

IT platforms also enable structured management of process deadlines (acknowledgement, feedback) and restrict access to authorized personnel only. For buyers comparing channel design choices, see How to Build Anonymous Reporting Channels at Work and Why Encryption Matters in Whistleblowing Systems.

Email Alone Is Not Sufficient

ANAC and the Italian Data Protection Authority (Garante) agree that email (ordinary or certified) is not adequate on its own to guarantee the confidentiality of the reporter's identity. Email systems generate logs that can indirectly reveal the identity of the person reporting, especially if a work email account is used. If email is employed, specific, justified countermeasures must be adopted as part of the DPIA.

Double-Envelope Paper Protocol

While digital tools are being adopted, or for entities not yet equipped with platforms, the double-envelope protocol may be used:

  1. First envelope: identifying data of the reporter
  2. Second envelope: content of the report
  3. Both placed in a third sealed envelope, marked "confidential," addressed to the channel manager

For entities subject to the Digital Administration Code (CAD), this solution should be considered an extrema ratio.

Non-Traceability from Internal Networks

If the channel is accessible from the entity's internal network, the non-traceability of the reporter must be guaranteed at the moment of connection, both at the platform level and on the devices involved in transmission (firewall, proxy).

Oral Reports: Telephone, Voice Messages, and In-Person Meetings

Permitted Modalities

The oral form may be exercised through three channels (Art. 4(3), D.Lgs. 24/2023):

  1. Dedicated telephone lines
  2. Voice messaging systems (voicemail)
  3. In-person meeting upon the reporter's request, to be held within a reasonable timeframe

The meeting may take place inside or outside the entity's premises, provided the confidentiality of the reporter and the report's content is ensured.

Traceability of Oral Reports

Oral reports must be traceable. ANAC indicates two main methods:

  • Recording the conversation on a dedicated device
  • Drafting detailed minutes by the channel manager

In both cases, the reporter must be informed of the recording or minute-taking methods, and the confidentiality of the recorded data must be guaranteed.

Who Manages the Channel: Autonomy and Training

The channel must be managed by an autonomous internal unit with specifically trained personnel, or by an autonomous external party also with trained personnel (Art. 4(2), D.Lgs. 24/2023). The manager's autonomy is an essential requirement: it must be free from hierarchical pressures that could compromise the impartiality of management.

If the manager is an external party (SaaS provider, consultant, law firm), the contract must address personal data processing aspects, with the provider acting as a data processor under Art. 28 GDPR.

Process Timelines

D.Lgs. 24/2023 establishes precise timelines that the channel must observe:

RequirementDeadlineLegal Reference
Acknowledgement of receipt to reporter7 days from receiptArt. 5(1)(a)
Feedback to reporter3 months from acknowledgement (or from expiry of the 7-day period)Art. 5(1)(b)
Forwarding to competent manager (if received by non-competent party)7 days from receiptArt. 4(6)

The 3-month feedback deadline is not peremptory, but the entity must still ensure timely and documented follow-up. An unjustified delay may constitute a violation of management procedures. Documented handling expectations are also covered in the EU-compliant whistleblowing software audit trail checklist.

Confidentiality as a Pillar

Confidentiality extends beyond the reporter's identity. The channel must protect (Art. 12, D.Lgs. 24/2023):

  • The identity of the reporter
  • The identity of the person involved or mentioned in the report
  • The content of the report and related documentation
  • Information enabling indirect identification of the reporter when third parties are involved in investigations

If a report is mistakenly received by a non-competent internal party, confidentiality must still be ensured during forwarding to the competent manager.

DPIA: A Non-Optional Obligation

Entities subject to the decree must conduct a Data Protection Impact Assessment (DPIA) under Art. 35 GDPR. The technology platform provider may support the entity by providing technical documentation, but responsibility for the DPIA remains with the entity. The DPIA must analyze the specific risks of the adopted channel and mitigation measures, in a process consistent with the principles of data protection by design and by default.

Privacy-focused procurement questions are covered in GDPR Questions to Ask Before Buying Whistleblowing Software. For the fuller Garante and anti-retaliation view once the channel is live, see whistleblowing privacy, confidentiality, and anti-retaliation.

Selecting a Technology Provider: Evaluation Criteria

Choosing the technology platform is one of the most important decisions in channel implementation. An inadequate provider can compromise overall compliance. Evaluation criteria should include:

Security and Encryption

The platform must guarantee encryption of data at rest and in transit (Art. 32 GDPR). It is advisable to verify which encryption standards are used (e.g., AES-256 for data at rest, TLS 1.2+ for communications) and whether they have been subject to independent security audits. The provider should be able to supply third-party certifications (e.g., ISO 27001, SOC 2 Type II).

Identity Management and Anonymity

The platform must enable confidential interaction with the reporter via an identification code (Key Code) that does not reveal the reporter's identity. The system must ensure that access is tracked and restricted to authorized personnel, with a roles and permissions framework that prevents unauthorized access to report data.

GDPR Role and Documentation

The provider acts as a data processor (Art. 28 GDPR). The contract must address: the purposes and methods of processing; technical and organizational security measures; confidentiality obligations; DPIA support arrangements; data retention and deletion terms. The provider should supply technical documentation in support of the DPIA, including residual risk analysis.

ANAC Compliance Support

The platform should natively implement the functionalities required by ANAC Guidelines: automatic acknowledgement within 7 days, feedback management within 3 months, documented traceability, support for oral reports (telephone line or voice messages), and automatic deletion upon expiry of the retention period.

Scalability and Support

For growing companies or multi-site operations, the platform must be scalable and support management of multiple entities or locations. The provider must offer timely support services with contractually defined SLAs, and a continuous update program to maintain regulatory compliance over time.

When shortlisting platforms more broadly, pair this Italy-specific view with How to Choose an EU-Compliant Whistleblowing Platform.

Integration with Existing Compliance Systems

The reporting channel does not operate in isolation: it must integrate with the company's compliance ecosystem. A well-designed integration strengthens Model 231's effectiveness and simplifies overall management.

Coordination with the OdV

If the channel is managed by a party other than the Supervisory Body, the organizational act must regulate the flow of information between the manager and the OdV. The OdV must be informed of reports relevant under D.Lgs. 231/2001, even if operational management is assigned to another party. The coordination must define: which information is transmitted to the OdV, at what frequency, and in which cases the OdV assumes direct management of the report.

Integration with Risk Management Systems

Reports received constitute a valuable source of information for the corporate risk management system. Emerging trends — recurring reports about specific areas or functions — can signal structural deficiencies requiring intervention. Integration with risk management systems transforms reports from isolated events into structured data for continuous improvement.

Training and Awareness

The channel's effectiveness depends on employee awareness. Training must cover not only how to report, but also what to report: the categories of relevant violations, the difference between internal and external reporting, and the protections available. Training should be periodic, not one-off, and should include specific modules for managers and function heads, who must know not only how to receive a report but also how to prevent retaliatory behavior.

Policy framing that supports this training layer is covered in Whistleblowing Policy Explained.

Common Pitfalls in Channel Configuration

1. Not Ensuring Non-Traceability from Internal Networks

If the channel is accessible from the corporate network, the reporter must be able to access it without their identity being traceable through network logs, firewalls, or proxies. Many entities overlook this technical aspect, exposing the reporter to the risk of indirect identification.

2. Assigning Management to Non-Autonomous Personnel

Channel management must be assigned to an autonomous office or party, free from hierarchical pressures. Assigning management to an employee subordinate to the reported person compromises impartiality and compliance.

3. Not Providing for In-Person Meetings

For oral reports, some companies configure only the telephone line, forgetting that the reporter has the right to request an in-person meeting. The organizational act must regulate how this request is handled, within what timeframe the meeting is scheduled, and how confidentiality is ensured.

4. Not Handling Anonymous Reports Correctly

Anonymous reports received through internal channels may be treated as ordinary reports if the entity has provided for their handling (Art. 16(4), D.Lgs. 24/2023). They must be registered and documentation preserved. However, if the anonymous reporter is subsequently identified and suffers retaliation, protection applies only if the report qualifies as whistleblowing and the connection to the report is established.

5. Not Properly Informing the Reporter

The reporter must be informed about the report management procedures, expected timelines, and available protections. Clear and accessible information — both in the privacy notice and in the acknowledgement communication — strengthens trust in the system and reduces the risk that the reporter turns directly to ANAC.

Channel Configuration Checklist

  • Ensure both modalities: written and oral
  • Prefer a dedicated IT platform with encryption and identification code
  • Avoid using email as the sole channel
  • Configure telephone lines / voice messages for oral reports
  • Provide for in-person meeting modality upon request
  • Guarantee non-traceability of reporters from internal networks
  • Designate an autonomous manager with trained personnel
  • Set up automatic acknowledgement within 7 days
  • Define the feedback workflow within 3 months
  • Prepare the DPIA and privacy notice

Final Take

A reporting channel that complies with ANAC Guidelines is a technical, legal, and organizational programme — not a single inbox or a written-only form.

For Italian entities, the practical test is whether both modalities work, confidentiality holds under real network and access conditions, deadlines are evidenced, and the DPIA matches the channel that is actually in use.

If you still need to confirm whether the obligation applies by size or Model 231, return to D.Lgs. 24/2023 and the 50-employee rule. For confidentiality, retention, and anti-retaliation once reports are flowing, continue with whistleblowing privacy, Garante guidance, and anti-retaliation. For broader European context, see EU Whistleblowing Directive by Country.

Disclosurely supports anonymous, secure, and documentable reporting channels with features designed for confidentiality, workflow traceability, and GDPR-ready governance. Request a demo if you want to see how that workflow operates in practice.

FAQs

Are both written and oral reporting modalities mandatory under ANAC Guidelines?
Yes. ANAC requires the internal channel to support both written and oral forms. Adopting only one modality is not permitted, and the organisational act or Model 231 must regulate receipt and management of both.
Is email enough as an internal whistleblowing channel in Italy?
No. ANAC and the Italian Data Protection Authority agree that ordinary or certified email alone is not adequate to guarantee confidentiality of the reporter's identity. If email is used, specific justified countermeasures must be documented in the DPIA.
What deadlines apply after a report is received?
Acknowledgement is due within 7 days of receipt. Feedback is due within 3 months from acknowledgement (or from expiry of the 7-day acknowledgement period). Reports received by a non-competent party must be forwarded to the competent manager within 7 days.
Who can manage the internal reporting channel?
An autonomous internal unit with specifically trained personnel, or an autonomous external party with trained personnel. Autonomy is essential to protect impartiality. External providers typically act as data processors under GDPR Art. 28.

Related solutions

Explore the related Disclosurely solution pages for implementation details and workflow context.

Need a secure whistleblowing platform?

Book a 10-minute walkthrough to see how Disclosurely supports secure reporting, investigations, and compliance workflows.

Related guides

Compliance Guides

D.Lgs. 24/2023: The 50-Employee Rule and Integration with Model 231

Disclosurely
29 Jul 20269 min read

D.Lgs. 24/2023: The 50-Employee Rule and Integration with Model 231

By Disclosurely Editorial

Understand when Italian entities must activate internal reporting channels under D.Lgs. 24/2023, how the 50-employee threshold works, and why Model 231 can trigger the obligation regardless of size.

Read article

Compliance Guides

Handling Confidential Reports: Privacy (Garante) and Protection Against Retaliation

Disclosurely

Understand how GDPR, Garante guidance, and D.Lgs. 24/2023 shape confidential report handling — from DPIA and retention to anti-retaliation protection and the reversed burden of proof.

Read article

Compliance Guides

How To Build Anonymous Reporting Channels At Work

Disclosurely
20 Jul 20264 min read

How To Build Anonymous Reporting Channels At Work

By Disclosurely Editorial

Learn how to build an anonymous reporting channel that employees will trust and that the organisation can actually operate well.

Read article
ANAC Reporting Channels: Written and Oral Requirements | Disclosurely