New Feature: Multi Rater Feedback and 360 Appraisals
Back to blog

Before You Renew

This guide is part of Disclosurely’s series for organisations reviewing whistleblowing software before contract renewal.

How to Safely Migrate Whistleblowing Software

A practical guide for compliance and procurement teams on how to safely migrate whistleblowing software β€” covering data export, audit trails, anonymous conversations, contracts, and business continuity.

2 August 202628 min readBuyer Guides

By Disclosurely Editorial

On this page

Buyer Guides

How to Safely Migrate Whistleblowing Software

Disclosurely

The contract renewal email lands in your inbox. Your whistleblowing software subscription is up for renewal, and for a moment, you pause. The platform has been functional enough, but you've noticed limitations. Perhaps the interface feels dated, reporting features are clunky, or you've simply outgrown the solution.

The question that follows is one that many compliance officers, legal professionals, and procurement leads ask β€” often too late:

How do you safely migrate whistleblowing software without breaking compliance, investigations, or reporter trust?

It's a question that surfaces less often than it should. Yet for organisations bound by the EU Whistleblowing Directive (2019/1937), GDPR, and national transposing laws, the whistleblowing platform is not a peripheral tool β€” it's critical compliance infrastructure. And like any strategic asset, it should be subject to periodic review.

This guide is for teams planning a switch. It covers data migration, contract pitfalls, vendor lock-in, and how to plan a transition that protects your organisation's compliance position and investigative integrity. Pair it with Whistleblowing Software Pricing: Are You Paying Too Much? if your renewal question is commercial rather than operational, or Are You Paying for Features You’ll Never Use? if the question is whether enterprise scope still matches day-to-day need.

This guide is general information for procurement and compliance evaluation, not legal advice. Local obligations and contract terms should be verified with qualified counsel before you give notice or migrate.


Why Organisations Rarely Review Their Whistleblowing Software

Despite the strategic importance of whistleblowing systems, most organisations treat them as "set and forget" solutions. The reasons for this inertia are understandable β€” but worth examining.

The regulatory landscape has shifted. The EU Whistleblower Directive, which came into force in 2021, has fundamentally changed what is expected of internal reporting channels. Yet many organisations are still running platforms that were implemented before these requirements crystallised. A solution that was adequate for a voluntary reporting system may fall short of mandatory requirements for secure case management, data retention, and reporter anonymity.

The cost of switching feels high. There is a perception that migrating case data is complex, risky, and expensive. This perception is sometimes reinforced by incumbent providers who emphasise the difficulties of moving to a competitor.

There is no internal champion. Unlike core business systems like CRM or ERP, whistleblowing software often lacks a dedicated internal owner with budget and influence. It sits somewhere between legal, compliance, HR, and IT β€” each department assuming someone else is monitoring performance.

The fear of disruption. The thought of losing access to historical cases, breaking anonymous communication threads, or disrupting reporting channels during a transition is genuinely concerning. Business continuity is paramount, and any migration plan must address these risks head-on.

However, the commercial and compliance risks of staying with an underperforming platform can outweigh the perceived costs of switching. A platform that makes case management cumbersome, fails to provide adequate audit trails, or lacks modern security features can undermine your entire whistleblowing programme β€” whether you are a regulated enterprise, an SME, or a charity.

The hardest migration is the one you leave until after auto-renewal.


The Regulatory Framework: Why Your Provider Choice Matters

Before exploring the mechanics of migration, verify the regulatory obligations that govern whistleblowing data. These obligations should inform your decision-making at every stage.

EU Whistleblowing Directive (2019/1937)

The Directive requires public and private organisations with 50+ employees to establish internal reporting channels that meet specific criteria. These channels must:

  • Enable secure and confidential reporting (Article 9)
  • Acknowledge receipt of reports within seven days (Article 9)
  • Protect the identity of reporters (Article 16)
  • Keep records of each report (Article 18)
  • Support both confidential and anonymous reporting where permitted

National transposing laws in EU member states have added further requirements. In Italy, for example, public organisations are required by law to use encrypted reporting platforms β€” a requirement shaped by advocacy for open-source solutions like Globaleaks.

GDPR and Data Protection

Whistleblowing programmes generate some of the most sensitive personal data an organisation can process. Reports may contain:

  • Allegations of criminal conduct
  • Health information
  • Financial records
  • Details about witnesses and accused persons

Under GDPR and UK GDPR, every stage of this data's lifecycle must meet strict privacy standards. Key requirements include:

  • Lawful basis for processing: Usually legal obligation (Article 6(1)(c)) or legitimate interest (Article 6(1)(f))
  • Data Protection Impact Assessment (DPIA): Often mandatory for whistleblowing processing
  • Data minimisation: Collect only information relevant to the concern
  • Storage limitation: Differentiated retention schedules β€” shorter for unsubstantiated reports
  • Technical safeguards: Encryption, access controls, and anonymity protections

Data Portability Rights

Article 20 of the GDPR grants data subjects the right to data portability β€” the right to receive personal data they have provided to a controller in a structured, commonly used, and machine-readable format. However, this right is not unlimited. It applies only to data processed on the basis of consent or a contract, and its application to whistleblowing data is limited by the fact that whistleblowing processing typically relies on legal obligation or legitimate interest as the lawful basis.

From a provider-switching perspective, this means data portability rights alone are unlikely to force a provider to hand over data in a usable format. You will need to require data export as part of your exit arrangements β€” and verify those rights before you renew.


Understanding Vendor Lock-In in Whistleblowing Software

Vendor lock-in occurs when a customer becomes dependent on a provider and cannot switch without substantial switching costs or inconvenience.

In the whistleblowing software market, vendor lock-in can manifest in several ways:

Lock-in TypeHow It ManifestsImpact
Data lock-inProprietary data formats, limited export functionality, missing fields in exportsCases and attachments cannot be migrated without manual re-entry
Technical lock-inCustom workflows that cannot be replicated elsewhereTraining and configuration overhead increases migration complexity
Contract lock-inLong notice periods, auto-renewal clauses, early termination penaltiesSwitching windows are limited, and costs are inflated
Process lock-inStaff trained on a specific platform; processes built around its workflowsChange management and retraining are required
Relationship lock-inThe provider offers integrated services (advice lines, policy drafting)Switching the software also means switching the advisory relationship

As the European Data Protection Supervisor has noted, organisations must design whistleblowing systems that balance the rights of multiple data subjects β€” the reporter, the accused, and witnesses. A provider that makes it difficult to export this data is not just creating commercial barriers; they may also be failing to support your data protection obligations.

QuestionGood providerVendor lock-in warning
Machine-readable exportsJSON, XML, or CSV with a documented schemaPDF-only packs, screenshots, or undocumented proprietary formats
Audit logs includedFull access history included in the export packageAudit trails excluded, gated, or available only via support ticket
Attachments exportedOriginal files included and mapped to parent casesLinks expire, files missing, or attachments charged separately
Anonymous conversations preservedConversation history exportable and linkable to casesThreads cannot leave the platform, or history is discarded
Migration assistanceDocumented plan, field mapping, and go-live support"Contact support" with no published migration process
Clear notice periodMutual, transparent notice windowLong notice for the customer; short or none for the vendor
No export feesExport included in the contractBulk export sold as a professional service after notice is given
Published APIDocumented API for programme-driven extractionNo API, or API reserved for premium tiers you do not hold
Transparent deletion processWritten deletion confirmation after cutoverVague retention language; no proof of deletion

Data ownership is meaningless if you cannot retrieve your own data.


Who Owns the Whistleblowing Data?

This is perhaps the single most important question to clarify before signing any contract β€” and before you renew one.

The data within a whistleblowing system typically includes:

  • Case reports: Submissions from reporters
  • Attachments: Emails, documents, photos, audio files
  • Audit logs: Who accessed what, when
  • Two-way communications: Anonymous conversations between reporter and investigator
  • Case notes and decisions: Internal investigation notes

From a legal perspective, the data controller is almost always the organisation that receives the reports, not the software provider. The provider is the data processor. As the data controller, you have ultimate responsibility for the data and the right to access and retrieve it.

However, having the legal right to your data is not the same as having practical access to it in a usable format.

Some providers include clauses in their terms of service that claim rights to anonymised usage data or aggregate analytics. Others may restrict data export to specific formats that are difficult to import into competitor systems. Organisations that use in-house solutions may find that custom-built data structures create migration challenges, as one financial services firm discovered when migrating from a proprietary system to a commercial platform.

Your migration strategy should exist before you sign the contract.


Exporting Cases: What to Look For

When migrating whistleblowing software, the ability to export case data is paramount. Here is what you need to verify:

Data Completeness

A useful data export should include:

  • Full case metadata: Report ID, date of submission, report type/category, status, priority
  • Full case narrative: The reporter's description of the concern
  • All communications: Two-way anonymous messages, internal notes, investigator comments
  • Timeline of activity: Case creation, status changes, communications, closure details
  • Attachments: Linked files in their original format (more on this below)
  • Case closure documentation: Outcome, actions taken, rationale

Data Format

Require your current provider to answer:

  • What data export formats are available? (CSV, XML, JSON, proprietary?)
  • Is the schema documented?
  • Can I export data for all cases, or only closed cases?
  • Are there any data fields that are excluded from the export?

The ideal export format is JSON or XML with a well-documented schema β€” a standard structure of fields that can be mapped to a new platform. In the absence of a documented schema, a data mapping exercise becomes more complex and may require specialist expertise.

The Timeline

Data export can take time, especially if you have thousands of cases. Providers may:

  • Generate export files on request (allow 5–10 working days)
  • Charge a fee for bulk data export
  • Require you to export data through the platform interface on a case-by-case basis

A case-by-case export process is effectively a lock-in mechanism β€” it makes migration so laborious that switching becomes impractical. Insist on bulk export capability before you renew.

Sample Provider Data Export Policies

Based on market research, provider approaches vary widely. Some providers offer comprehensive data export capabilities as a standard feature; others treat it as a chargeable professional service or make it intentionally difficult. A structured vendor comparison spreadsheet β€” listing export formats, fees, timelines, and attachment handling β€” is a useful artefact for procurement to keep alongside pricing and commercial evaluation notes.

Exporting PDFs is not the same as exporting usable data.


Exporting Attachments

Attachments present specific challenges for migration. Whistleblowing reports frequently contain sensitive documents, emails, photos, and audio files. Unlike structured case data, attachments are binary files and require different handling.

Important Considerations

  • Attachment completeness: Are all attachments included in the data export, or are they stored separately? Require a complete export that includes the attachment files themselves, not just references or URLs.
  • Anonymisation: Some platforms automatically remove identifying information from attachments during processing. In a migration, you may need to preserve whatever anonymisation has been applied.
  • File integrity: File corruption during export can be catastrophic. Confirm that the export process verifies file integrity.
  • Links to case data: If attachments are exported separately, ensure you can map each attachment to its parent case. This is typically done via a unique file reference in the case export data.

Audit Trails: The Non-Negotiable Component

Audit trails document who accessed what, when, and why. They are essential for:

  • Demonstrating compliance with data protection requirements
  • Supporting internal investigations
  • Defending against allegations of impropriety or data leakage

What a Complete Audit Trail Looks Like

A comprehensive audit trail export should include:

  • Timestamp: Date and time of each activity
  • User ID: Who performed the action
  • Action type: View case, add note, change status, export data, etc.
  • Case reference: Which case was accessed
  • IP address (where relevant and compliant)

Export Formats

Audit trail exports are typically available as JSON, CSV, or XML files. Some providers restrict access to audit trail data to administrators only and may impose additional permissions requirements.

Retention Periods

Under GDPR, audit trails should be retained only as long as necessary for the purpose for which they are processed. The EDPS recommends differentiated retention: audit logs may be retained for a period that corresponds with the retention period of the case data itself. When switching providers, you need to ensure:

  1. The audit trail export covers the entire period of your use of the platform
  2. The new provider can accommodate your retention schedule

Anonymous Conversations: The Unique Challenge

One of the most complex aspects of migrating whistleblowing data is the handling of anonymous conversations.

Whistleblowing platforms typically support two-way anonymous communication: the reporter can receive follow-up questions from the investigator and respond without revealing their identity. These conversations are often encrypted and may be stored in a way that preserves the anonymity of the reporter. This capability sits at the heart of anonymous employee reporting and secure messaging workflows.

When switching providers:

  • Can this conversation history be exported? This depends on the provider. Some providers treat anonymous communications as separate data entities that require special handling.
  • Can it be re-established on the new platform? The new provider must be able to ingest conversation history and link it to the relevant case.
  • What about ongoing conversations? If a report is still open and anonymous communications are ongoing, the migration needs to preserve continuity.

In some cases, the best solution is to complete existing anonymous communications on the old platform before migrating, or to notify reporters that they will need to access the new platform going forward. The option to notify anonymous reporters depends on the platform's capabilities β€” some will have a broadcast message feature; others will not.


Open Investigations: The Balancing Act

Migrating while investigations are active introduces special considerations:

  • Continuity of investigative process: Ensure the new platform can support the workflow of open cases, including assigned investigators, deadlines, and statuses.
  • Reporter access: If the platform supports a reporting portal for secure communication, the reporter must be able to access their report on the new platform. This may require re-establishing secure channels.
  • Data integrity: Any migration of open cases must preserve data integrity β€” no loss of evidence, attachments, or audit information.

For open cases, consider a phased approach:

  1. Continue processing open cases on the old platform until they are closed
  2. Suspend new report intake on the old platform
  3. Start the new platform for new reports
  4. Once open cases are resolved, archive the old platform and complete the migration

This approach minimises operational disruption while allowing for a complete and accurate data migration.


Data Formats and Interoperability

The availability of standardised export and import formats significantly affects migration ease.

FormatProsCons
JSONWidely used, human-readable, programmable, good for complex data structuresRequires technical skills to process
XMLEstablished standard, well-defined schema possibleMore verbose than JSON, less developer-friendly for modern systems
CSVSimple, can be opened in Excel, easy for non-technical usersCan't handle nested data structures well; field limitations
Proprietary formatNo migration benefits; likely lock-inHigh risk of data loss; requires migration assistance from the provider

The Open-Source Advantage

Some whistleblowing software providers, such as Globaleaks, are open-source. This means the underlying code is publicly accessible, and data formats are non-proprietary. The European Commission expert group has recognised Globaleaks as a fully compliant solution for Directive (EU) 2019/1937 reporting channels.

Open-source platforms often provide better data portability because:

  • The data schema is documented and public
  • There is no commercial incentive to lock customers in
  • The community can help with data migration tools

Contract Clauses: Read Before You Sign

Contract terms are critical when planning for a potential exit. Review these clauses carefully β€” and insist on clarity before you renew.

Notice Periods

A notice period is the amount of time you must give the provider before you can terminate the contract. While one month's notice is common, some providers require longer periods, especially from enterprise customers.

What to verify:

  • What is the notice period? (30 days, 90 days, 6 months?)
  • Is the notice period mutual, or is the provider entitled to a longer notice period? Some providers reserve 6-month notice periods for themselves while requiring only one month from customers β€” a material imbalance in bargaining power.

Auto-Renewal Clauses

Many software contracts auto-renew for another term unless you actively terminate. For whistleblowing software, this can mean another 12 or 24 months of commitment.

What to verify:

  • Does the contract auto-renew?
  • If so, what is the renewal term length?
  • What is the deadline to give notice of non-renewal?
  • Is auto-renewal allowed under applicable law? (Some EU member states have restrictions on automatic renewal clauses in B2B contracts.)

Data Export and Deletion

Your contract should clearly specify:

  • The process for requesting data export
  • Any fees for data export
  • The timeline for export
  • The process for data deletion after termination

Early Termination Penalties

If you decide to switch before the contract term ends, you may face:

  • Early termination fees
  • Loss of volume discounts (potentially requiring repayment of discounts applied)
  • Remaining contract value charges

Allowed Usage

Your contract should specify that you are the data controller and have full rights to your data. Look for:

  • Ownership of intellectual property
  • Rights to data export
  • Any restrictions on transferring data to a third party (including a new software provider)

For commercial context on what you may be paying for during that locked-in term, see Whistleblowing Software Pricing Explained and the pricing buyer page.


Migration Planning: From Decision to Go-Live

Switching whistleblowing providers is a project that requires structured planning. Use this checklist as your roadmap β€” and treat a written migration planning template as a working document between compliance, procurement, legal, and IT.

Migration timeline

Decision
  ↓
Provider selection
  ↓
Contract review
  ↓
Data export
  ↓
Test migration
  ↓
Staff communication
  ↓
Go live
  ↓
Validation
  ↓
Old platform retired

Keep this timeline visible in your project pack. A one-page migration timeline is often enough to align stakeholders β€” and it becomes a useful artefact for boards or audit committees reviewing the switch.

Phase 1: Preparation

  • Conduct a needs assessment: What does the organisation need from a whistleblowing platform that it isn't getting?
  • Evaluate providers: Shortlist providers that meet regulatory requirements and your specific needs.
  • Review contracts: Understand existing contract terms and the new provider's contract terms.
  • Assess data: What data do you have? How much? In what format? What is the scope of data to be migrated? (All cases? Only active cases? Closed cases?)
  • Establish project team: Include legal, compliance, HR, IT, and procurement as required.

Phase 2: Selection

  • Verify compliance: Does the new provider support the EU Whistleblowing Directive and GDPR?
  • Review security: Is the provider ISO 27001 certified? What encryption standards are used?
  • Check data residency: Where is data hosted? For UK organisations, UK data residency may be preferred.
  • Validate data export: Does the new provider have an established migration process?
  • Get pricing: Understand the cost of the new platform and the cost of migration professional services.

Phase 3: Contractual Exit

  • Review notice period: Give formal notice to the incumbent provider in accordance with your contract.
  • Request data export: Submit a data export request and confirm the expected timeline.
  • Check auto-renewal: Ensure you have not inadvertently auto-renewed.

Phase 4: Data Migration

  • Map data fields: Compare the export schema from the old provider with the import schema of the new provider.
  • Perform test migration: Migrate a sample of data and verify it is accurate.
  • Validate attachments: Ensure all attachments are linked correctly.
  • Validate audit trails: Ensure audit trail data is available in the new system.
  • Validate open cases: Confirm open cases are fully represented in the new platform.

Phase 5: Go-Live and Cutover

  • Develop communication: Inform internal stakeholders about the new channel.
  • Suspend new reports on the old platform: Direct reporting to the new platform.
  • Complete open cases: Where possible, resolve open cases on the old platform before cutover. If this is not possible, migrate them as part of the data migration.
  • Launch the new platform: Announce to reporters, employees, and other stakeholders.
  • Keep the old platform accessible: Retain the old platform for a transition period for case look-up.

Phase 6: Post-Migration

  • Data deletion: Once all data is validated and fully available on the new platform, delete data from the old provider to comply with GDPR storage limitation principle.
  • User training: Provide training on the new platform for investigators, HR, legal, and compliance teams.
  • Audit the migration: Confirm all data is complete and accurate.
  • Document the migration: For audit and regulatory purposes, document the migration process and data handling.

Business Continuity: Keeping Your Reporting Channels Open

One of the most common concerns about switching whistleblowing providers is the risk of downtime. If the reporting channel goes dark, your organisation is non-compliant with the EU Whistleblowing Directive.

Best Practices for Business Continuity

  1. Overlap the systems: Maintain both the old and new platforms for a transitional period. The old platform remains the primary reporting channel; the new platform is configured and tested in parallel.

  2. Pause new report intake carefully: You do not have to pause reporting entirely. You can use an automatic redirect from the old platform to a landing page explaining the transition.

  3. Communicate the change: Notify all relevant stakeholders β€” employees, contractors, suppliers, and external reporters β€” that the reporting channel is changing.

  4. Maintain contact details: Ensure that any external reporting channels or outsourced helpdesks are aware of the change and can direct reporters appropriately.

  5. Run a parallel processing period: For a short period after go-live, process any new reports that still arrive through the old platform. These should be re-entered into the new platform manually.

  6. Monitor the new channel: After go-live, monitor the new channel for any issues. Run a batch of test reports to ensure the system is receiving and processing submissions correctly.


Questions to Require From Your Current Supplier Before Switching

When you decide to explore the market for a new whistleblowing provider, these are the questions to direct to your current supplier as part of your due diligence. Treat them as requirements β€” not informal requests.

Data Export

  1. What data export formats do you support? Can I export data in a machine-readable format with a documented schema?
  2. What is the process for requesting a data export? What is the typical timeline?
  3. Are there any data fields or records that cannot be exported? If so, which ones and why?
  4. How are attachments exported? Are they included in a single export package, or do I need to request them separately?
  5. Is there a fee for data export?
  6. Can I export data from open cases as well as closed cases?
  7. Are audit logs exported? In what format?

Contract

  1. What is the notice period for termination?
  2. Does the contract auto-renew? If so, what is the renewal term and the deadline for non-renewal?
  3. What happens to data after termination? Is there a process for data deletion?
  4. Are there any early termination penalties?
  5. Is there a data retention policy that applies to my organisation's data?

Technical

  1. Can the platform accommodate the migration of anonymous conversations? If not, how should these be handled during a migration?
  2. Can the platform support the migration of open investigations, or should they be closed before migration?
  3. Is there an API available that would allow programme-driven data extraction?

What a Good Migration Process Looks Like

Based on industry experience and best practices, a well-run migration should include these elements:

From the New Provider

  • A documented migration plan: The new provider should provide a clear plan outlining the scope, timeline, and responsibilities of all parties.
  • Data mapping: A defined process for mapping data from the old system to the new one. If the old provider uses a proprietary format, the new provider should be able to handle it.
  • Test migration: A full test migration before go-live, with verification of data completeness and integrity.
  • Go-live support: A transition team on standby during the go-live period.
  • Clear communication: For all parties involved β€” project team, investigators, administrators.

From the Old Provider

  • Transparency: A clear explanation of what is and is not included in the export.
  • Timeliness: Data export within a reasonable timeframe (5–10 working days for standard requests).
  • Data completeness: All relevant case data, attachments, audit trails, and communications.

From the Customer

  • Project leadership: A dedicated project manager with responsibility for the migration.
  • Data validation: A process to check the quality of the imported data.
  • Stakeholder communication: A communication plan to ensure all users are aware of the change.

When NOT to Switch Providers

While this article has focused on how to migrate safely, there are circumstances where staying with your current provider is the better option:

The Contract is Nearing Expiry and You Need to Act Fast

If your contract is up for renewal in a matter of weeks, switching may not be practical. The standard notice period for termination is often one to three months. It may be more prudent to negotiate a shorter-term renewal with your current provider while you take the time to run a proper selection process.

The Migration Risks Are Too Great

If you have thousands of open cases, a migration failure would be devastating. In such cases, a longer-term solution may be to invest in improving the current platform's performance or negotiating better terms with the existing provider.

The New Provider Doesn't Offer Significant Advantages

Switching costs β€” financial, time, training β€” are real. If a new provider offers only marginal improvements, it may not be worth the disruption. The key is to weigh the migration costs against the benefits of the new platform. For organisations comparing enterprise complexity with more focused platforms, whistleblowing for small businesses and the renewal checklist in Are You Paying Too Much? can help frame that trade-off.

Operational Constraints Make Migration Impossible

If you have a substantial volume of open cases requiring very specific handling, the migration may not be feasible immediately. In this situation, consider a phased approach β€” migrating closed cases first and only open cases after they are resolved.


How Disclosurely Approaches Migration

At Disclosurely, we understand that switching whistleblowing software is a significant decision with compliance implications. Our approach to migration is designed to minimise risk and ensure continuity β€” and to give procurement teams something concrete to benchmark against.

Comprehensive Data Migration

Our migration process supports the transfer of:

  • Case data: Full case narratives, metadata, statuses, categories
  • Attachments: All documents, photos, and files, with integrity verification
  • Audit trails: Complete access logs, supporting your compliance obligations
  • Anonymous conversations: Where technically feasible, we work to preserve the continuity of secure communications

Data Export Support

We are transparent about what can and cannot be exported. Our data export features are designed to be non-proprietary and machine-readable, supporting your right to retrieve usable data. We provide clear documentation of our data schemas.

Compliance-First Approach

Our platform is built to support GDPR and EU Whistleblowing Directive compliance. We support:

  • Data protection impact assessments (DPIAs): Our documentation supports your DPIA requirements
  • Data retention schedules: Configured to support differentiated retention policies
  • Data minimisation: Our system helps you collect only the data you need
  • Audit trails: Comprehensive, secure, and exportable

Migration Support

Our team provides dedicated migration support:

  • Migration planning and consultation
  • Data mapping and field mapping
  • Test migration and validation
  • Go-live support
  • Post-migration data validation and deletion support

For organisations considering switching, we offer a pre-migration assessment to identify potential obstacles and develop a tailored migration plan. You can contact the team or review pricing without committing to a sales process.


How Difficult Will Your Migration Be?

Before you run the full checklist, score your situation honestly.

FactorScore
More than 100 open cases+1
More than one legal entity+1
Multiple countries+1
Custom workflows+1
HRIS integrations+1
Anonymous conversations still active+1

Total score

ScoreComplexity
0–2Low migration complexity
3–4Moderate
5–6High

Low complexity does not mean zero risk β€” it means a shorter timeline and less specialist support. High complexity means you should insist on a documented plan, a test migration, and longer overlap between platforms.


Migration Checklist

Use this checklist to guide your migration project. Many teams also keep a printable migration checklist PDF and a shared planning template so compliance, procurement, and IT are working from the same document.

Pre-Migration Planning

  • Define the scope of migration: Which data? Which cases? What period?
  • Define the migration timeline: When does the old contract end? When does the new contract begin?
  • Establish project governance: Who is responsible for what?
  • Identify stakeholders: Who needs to be informed or involved?
  • Assess the data: How much data is there? What is the format?
  • Contact the new provider: Request a migration plan and pricing.
  • Contact the current provider: Request a data export.
  • Review contract terms: Confirm notice periods and auto-renewal deadlines.

Data Mapping and Validation

  • Map the old data fields to the new data fields.
  • Determine how attachments will be handled.
  • Determine how audit trails will be handled.
  • Determine how anonymous conversations will be handled.
  • Determine how open cases will be handled.

Migration Execution

  • Receive data export from old provider.
  • Validate the export: Is it complete? Are attachments present?
  • Import data into the new platform (test environment).
  • Validate the import: Is the data accurate and complete?
  • Fix any data issues: Field mapping mismatches, missing data, etc.
  • Run a test migration: Use a sample of data to test the full process.
  • Run the full migration.

Go-Live and Cutover

  • Suspend new reporting on the old platform.
  • Launch the new platform.
  • Communicate the change to all stakeholders.
  • Monitor the new platform for issues.

Post-Migration

  • Train users on the new platform.
  • Validate data on the new platform: Is all data present and correct?
  • Request deletion of data from the old provider.
  • Audit the migration: Is all data complete? Are audit trails available?
  • Document the migration: For regulatory and internal audit purposes.

FAQ

Do I actually own my whistleblowing data?

Yes, as the data controller, you own the data that you collect through a whistleblowing platform. The provider is the data processor. However, data ownership does not necessarily mean you have practical access to the data in a usable format. Always ensure that your contract gives you the right to export data in a machine-readable format.

Can I export anonymous conversations?

This depends on the provider. Some platforms treat anonymous conversations separately and may require special handling to export. Clarify this before signing a contract with a new provider β€” and before you give notice to your current one.

Does GDPR require me to keep whistleblowing data for a specific period?

The GDPR does not specify a fixed retention period for whistleblowing data. Instead, the principle of storage limitation requires that personal data is not kept longer than necessary. Best practice, supported by the EDPS, is to apply differentiated retention schedules: unsubstantiated reports may be deleted within a few months, while substantiated reports may be retained for longer.

Can I switch while I have open cases?

Yes, but it is more complex. A phased approach β€” where open cases are retained on the old platform until they are resolved β€” is often the best solution. Alternatively, the new provider may be able to support open case migration.

What happens to my data if I terminate my contract?

Your contract should specify what happens to data after termination. The GDPR requires that personal data must be deleted when it is no longer necessary for the purpose for which it was collected. Providers are required to cooperate with the data controller's deletion requirements. Ensure your contract includes a clear data deletion clause.

Can my new provider help with the migration?

Many providers offer migration support as part of their implementation services. This can include data mapping, data import, and validation. Some providers may charge additional fees for migration services. Require a documented plan before you commit.

What is vendor lock-in, and how does it affect whistleblowing software?

Vendor lock-in is the situation where a customer cannot switch to another provider without significant switching costs. In whistleblowing software, lock-in can be data-related (proprietary formats), contractual (long notice periods, auto-renewal), or process-related (workflows, training).

Is data export likely to be free?

Providers may charge for data export, especially for bulk exports or if the export requires significant work. Clarify these terms before signing a contract β€” and before renewal.


Stay Because It Fits β€” Not Because Leaving Feels Hard

Don't stay with a whistleblowing platform because migration feels difficult.

Stay because your current platform is genuinely the best fit for your organisation's risk, complexity, and usage.

If it is, renew confidently.

If it isn't, switching is entirely achievable with planning β€” a clear timeline, machine-readable exports, validated attachments and audit trails, and overlapping channels so reporting never goes dark.

The regulatory environment continues to evolve. The EU Whistleblowing Directive has set clearer expectations for security, confidentiality, and record-keeping. If your current provider cannot meet those standards β€” or cannot give you your own data in a usable form β€” migration is not just a commercial decision. It is a compliance and governance decision.

If you want a second opinion while you benchmark, Disclosurely is one provider organisations can compare against. No hard sell β€” just a focused platform with transparent export posture and migration support for teams that decide a switch is warranted. Contact us if a pre-migration assessment would help your procurement and compliance teams plan the work.

FAQs

Do I actually own my whistleblowing data?
Yes. As the data controller, you own the data collected through a whistleblowing platform. The provider is the data processor. Ownership does not automatically mean practical access in a usable format β€” insist on machine-readable export rights in the contract.
Can I export anonymous conversations?
It depends on the provider. Some platforms treat anonymous conversations separately and require special handling. Verify this before signing with a new provider, and require clarity from your current supplier before you give notice.
Does GDPR require me to keep whistleblowing data for a specific period?
GDPR does not set a fixed retention period. Storage limitation requires that personal data is not kept longer than necessary. Best practice, supported by the EDPS, is differentiated retention β€” shorter for unsubstantiated reports, longer for substantiated cases.
Can I switch while I have open cases?
Yes, but it is more complex. A phased approach β€” keeping open cases on the old platform until resolved β€” is often safest. Alternatively, verify that the new provider can support open-case migration with full audit history.
What happens to my data if I terminate my contract?
Your contract should specify post-termination handling. GDPR requires deletion when data is no longer necessary. Require a clear deletion clause and written confirmation once deletion is complete.
Can my new provider help with the migration?
Many providers offer migration support as part of implementation β€” data mapping, import, and validation. Some charge additional fees. Require a documented migration plan before you commit.
What is vendor lock-in in whistleblowing software?
Vendor lock-in is when switching involves significant switching costs. In whistleblowing software this can be data-related (proprietary formats), contractual (long notice periods, auto-renewal), or process-related (custom workflows and training).
Is data export likely to be free?
Providers may charge for bulk exports or professional-service exports. Clarify fees, timelines, and formats before signing β€” and before you renew.

Related solutions

Explore the related Disclosurely solution pages for implementation details and workflow context.

Need a secure whistleblowing platform?

Book a 10-minute walkthrough to see how Disclosurely supports secure reporting, investigations, and compliance workflows.

Related guides

Buyer Guides

Whistleblowing Software Pricing: Are You Paying Too Much?

Disclosurely
29 Jul 202620 min read

Whistleblowing Software Pricing: Are You Paying Too Much?

By Disclosurely Editorial

If report volume is low but pricing is high, it may be time to benchmark what you are actually paying for β€” and whether a simpler platform would meet the same requirements.

Read article

Buyer Guides

Are You Paying for Features You’ll Never Use?

Disclosurely
2 Aug 202620 min read

Are You Paying for Features You’ll Never Use?

By Disclosurely Editorial

Buying the biggest whistleblowing platform is not the same as buying the right one. This guide helps teams test whether enterprise scope still matches operational reality before renewal.

Read article

Buyer Guides

Whistleblowing Software Pricing Explained

Disclosurely
15 Jul 20267 min read

Whistleblowing Software Pricing Explained

By Disclosurely Editorial

Compare whistleblowing software pricing by workflow depth, rollout scope, support, and governance requirements rather than by monthly fee alone.

Read article
How to Safely Migrate Whistleblowing Software