New Feature: Multi Rater Feedback and 360 Appraisals
Back to blog

Handling Confidential Reports: Privacy (Garante) and Protection Against Retaliation

Best practices for confidential reports: GDPR and Garante requirements, DPIA, data retention, anti-retaliation protection, and burden of proof under D.Lgs. 24/2023.

29 July 202611 min readCompliance Guides

By Disclosurely Editorial

On this page

Compliance Guides

Handling Confidential Reports: Privacy (Garante) and Protection Against Retaliation

Disclosurely

Managing a whistleblowing report is a process that intertwines two regulatory dimensions: personal data protection (GDPR and Garante prescriptions) and the legal protection of the reporter against retaliation. Both are governed by D.Lgs. 24/2023, but operational guidance comes from the ANAC Guidelines No. 1 and the opinion of the Italian Data Protection Authority (Garante).

In this guide, we examine best practices for managing confidential reports in compliance with the regulatory framework, with a focus on DPIA, GDPR roles, data retention, and anti-retaliation protection. For when the Italian channel obligation applies, start with D.Lgs. 24/2023 and Model 231. For channel modality requirements, see ANAC written and oral reporting requirements.

This guide is general information for software and process evaluation, not legal advice. Country rules change and should be checked with qualified local counsel before rollout.

The Privacy Framework: GDPR and the Garante

Personal Data and Special Categories

Managing a reporting channel involves processing personal data, including potentially special categories of data (Art. 9 GDPR) and data relating to criminal convictions (Art. 10 GDPR). The data concerns identified or identifiable persons: the reporter, the person indicated as responsible for the unlawful conduct, and other persons involved in the reported events.

The Garante emphasizes that processing must comply with the general GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity.

DPIA: An Explicit Obligation

Entities subject to D.Lgs. 24/2023 must conduct a Data Protection Impact Assessment (DPIA) under Art. 35 GDPR. The Garante specifies that:

  • The DPIA must be conducted by the entity itself, even with support from the technology provider
  • The reliability of the IT tool used must be assessed during the DPIA
  • Security measures adopted must ensure an adequate level, consistent with the principles of data protection by design and by default (Art. 25 GDPR)
  • The provider may supply supporting documentation, but responsibility remains with the entity

Privacy-focused procurement questions are covered in GDPR Questions to Ask Before Buying Whistleblowing Software.

GDPR Roles: Controller, Processor, and Joint Controller

The regulatory framework clearly defines roles:

  • Data controller: the public or private entity that receives and manages reports
  • Data processor (Art. 28 GDPR): the external provider of the infrastructure or channel management
  • Joint controller (Art. 26 GDPR): entities sharing the channel (50–249 employees) must define responsibilities through an internal agreement
  • In a corporate group context, the parent company managing the channel acts as a data processor

Technical Security Measures

The Garante specifically recommends:

  • Encryption of data at rest and in transit, including dedicated cryptographic tools
  • Restricted access to expressly authorized personnel (Arts. 29 and 32(4) GDPR)
  • Non-traceability of the reporter when the channel is accessible from the entity's internal network
  • Strong authentication (e.g., OTP), where appropriate, for platform access
  • Specific training for personnel handling reports

For a buyer-focused view of encryption claims, see Why Encryption Matters in Whistleblowing Systems.

Data Minimization and Deletion

Personal data that is manifestly not relevant to processing a specific report must be deleted. The Garante specifies that when proceedings arising from the report generate acts and documents, these may be retained within legal limits, but should not normally contain specific references to the reporter.

Data Retention: The 5-Year Limit

Art. 14 of D.Lgs. 24/2023 provides that documentation relating to internal and external reports must be retained for the time necessary for management and, in any case, no longer than 5 years from the date of communication of the final outcome of the reporting procedure.

Acts and documents relating to proceedings initiated as a result of the report (e.g., disciplinary proceedings, transmissions to competent authorities) may be retained within applicable legal time limits as an exception.

Best Practices for Data Lifecycle Management

  • Implement automatic deletion upon expiry of the retention period
  • Maintain a retention register documenting dates of receipt, outcome, and deletion
  • Separate report management data from data from derived proceedings
  • Ensure that deletion is documented and verifiable

For cross-border retention comparisons, continue with Whistleblowing Retention Periods By Country.

Right of Access and Limitations

The Garante recalls that data subject rights (Arts. 15–22 GDPR) are limited in the whistleblowing context, pursuant to Art. 2-undecies of the Italian Privacy Code. This means that:

  • Access to data by the reported person may be restricted when access could compromise the reporter's confidentiality or the effectiveness of investigations
  • Disclosure of the reporter's identity is prohibited except in specific cases provided by law (e.g., necessity of legal defense)
  • Even when a report does not qualify as whistleblowing under the decree, confidentiality should still be ensured, considering the reasonable expectation of protection of a person who mistakenly believed they could benefit from those safeguards

Protection Against Retaliation: The Reversal of the Burden of Proof

Note: Channel anonymity does not coincide with the statutory confidentiality obligation. The law mandates confidentiality of the reporter's identity; anonymity is a channel design choice that can strengthen trust and system effectiveness.

Who Is Protected

Protection extends to a broad range of individuals (Art. 3, D.Lgs. 24/2023):

  • Employees (including former employees)
  • Freelancers and consultants
  • Volunteers and trainees
  • Shareholders and persons with administrative, management, control, supervisory, or representative functions
  • Facilitators (persons who assist the reporter in the reporting process)
  • Persons in the same work context linked by a stable emotional bond or kinship up to the fourth degree, colleagues with an habitual and current relationship, and entities connected to the reporter

The Reversal of the Burden of Proof

Art. 17 of D.Lgs. 24/2023 introduces a fundamental mechanism: the burden of proving that an act or conduct is motivated by reasons unrelated to the report falls on the person who carried it out.

In practice, if the reporter demonstrates a prima facie case of having made a report and having suffered harm (dismissal, demotion, disciplinary sanction, exclusion from professional opportunities), it is up to the entity to prove that the measure adopted is in no way connected to the report.

Retaliatory Acts Are Null and Void

Retaliatory acts — dismissals, transfers, disciplinary sanctions, professional marginalization — are null and void if carried out in retaliation for a report. Retaliatory acts may be challenged in the competent forums; ANAC can determine the retaliatory nature of a measure and impose administrative fines of €10,000 to €50,000.

Definition of Retaliation

The decree defines retaliation as any conduct, act, or omission — even attempted or threatened — carried out because of a report, complaint, or public disclosure that causes or could cause unjust harm, direct or indirect. The definition is broad and includes not only overt measures but also subtle and structural conduct.

DPIA in Practice: Steps and Considerations

The DPIA is not a static document: it is an analytical process that should guide channel design and be updated over time. Below are the main steps an entity should follow.

1. Description of Processing

The first step is to map the complete data flow: what personal data is collected (reporter identity, reported person, witnesses, report content, attachments), through which channels (IT platform, telephone, in-person meeting), with what technical tools, and for how long data is retained. This description should also include ancillary data generated by the system (access logs, metadata, receipts).

2. Assessment of Necessity and Proportionality

The entity must assess whether processing is necessary for the stated purpose (report management) and whether the data collected is proportionate. This includes verifying that unnecessary data is not collected — for example, health or biometric data not relevant to report management — and that the retention period is limited to the minimum necessary.

3. Risk Assessment

The entity must identify specific risks to the rights and freedoms of data subjects. The main risks in the whistleblowing context include:

  • Indirect identification of the reporter through metadata, logs, or contextual information
  • Unauthorized access to report data by unauthorized internal personnel
  • Information leakage through insecure channels (email, chat, unsecured printing)
  • Breach of confidentiality during internal forwarding or communication to the OdV
  • Retention beyond limits resulting in unlawful processing

4. Mitigation Measures

For each identified risk, the entity must define adequate mitigation measures: encryption, role-based access control, non-traceability from internal networks, personnel training, automatic deletion, periodic audits. Measures must be proportionate to the risk level and the entity's size.

5. Documentation and Review

The DPIA must be fully documented and kept available for the supervisory authority. It must be reviewed periodically — at least annually — and updated in case of significant changes to the channel, technology platform, or organization.

Documented handling expectations are also covered in the EU-compliant whistleblowing software audit trail checklist.

Handling Cross-Border Reports

Companies with an international presence face an additional challenge: managing reports involving entities located in multiple jurisdictions. D.Lgs. 24/2023 applies to conduct occurring in Italy, but reports may concern violations of EU law or national legislation of other Member States.

Cross-Jurisdictional Coordination

A multinational group headquartered in Italy must ensure that reports received through the Italian channel are managed in compliance with D.Lgs. 24/2023, even when they involve foreign entities. This requires careful definition of information flows between different jurisdictions, taking into account the different national transpositions of EU Directive 2019/1937.

For the wider European baseline, see EU Whistleblowing Directive by Country.

Data Transfers

If report data is accessible by entities located outside the European Union, international data transfer rules apply (GDPR Chapter V). The entity must ensure that adequate safeguards exist — such as adequacy decisions, standard contractual clauses, or Binding Corporate Rules (BCRs) — and that the transfer is documented in the DPIA.

The Provider's Role in an International Context

If the technology platform is managed by a provider with cloud infrastructure located outside the EU, the entity must verify the transfer safeguards adopted by the provider. The provider should offer transparent documentation on data localization and the safeguards implemented for international transfers.

Documenting Compliance: What to Keep

Documentability is a key element of D.Lgs. 24/2023 compliance. In case of an ANAC audit or legal challenge, the entity must be able to demonstrate not only that it adopted a compliant channel, but that it managed each individual report correctly.

Organizational Documents

  • Model 231 or organizational act with channel provisions
  • Contract with external provider (if applicable)
  • DPIA and supporting documentation
  • Privacy notice for reporters
  • Channel operating regulations

Operational Documents per Report

  • Acknowledgement of receipt (with date, within 7 days)
  • Feedback communication to reporter (with date, within 3 months)
  • Access logs for the report (who accessed the data and when)
  • Documentation of internal investigations conducted
  • Communication of final outcome to the reporter
  • Documentation of data deletion (with date, within 5 years of outcome)

Training Documents

  • Attendance records for whistleblowing training sessions
  • Training materials used
  • Training certificates for personnel handling reports

A structured documentation system not only satisfies GDPR accountability obligations but also serves as evidence of organizational diligence in case of retaliation or confidentiality breach claims.

Best Practices for Managing Confidential Reports

1. Designate an Autonomous and Trained Manager

The channel manager must be autonomous and equipped with specifically trained personnel, including on personal data protection. Autonomy ensures impartiality; training ensures technical competence.

2. Implement and Maintain the DPIA

The DPIA is not a one-time exercise: it must be reviewed periodically, especially when the channel is modified, new technologies are integrated, or organizational changes occur.

3. Ensure End-to-End Confidentiality

From receipt to deletion, every phase of the process must ensure confidentiality: data encryption, restricted access, non-traceability from internal networks, and identity protection even during internal forwarding.

4. Document Every Phase

Documentability is essential to demonstrate compliance in case of ANAC audits or legal challenges: acknowledgement within 7 days, feedback within 3 months, access logs, activity logs.

5. Establish a Sanctioning System

The Model 231 or organizational act must provide disciplinary sanctions for those who breach confidentiality or commit retaliatory acts. The sanctioning system must be proportionate and applied concretely.

6. Train Personnel

Training must extend not only to the channel manager but to all individuals who may come into contact with reports or reporters: management, HR, Legal, OdV.

Policy framing that supports this training layer is covered in Whistleblowing Policy Explained.

Compliance Management Checklist

  • Conduct and keep updated the DPIA
  • Define GDPR roles (controller, processor, joint controller)
  • Implement data encryption at rest and in transit
  • Restrict access to authorized and trained personnel
  • Guarantee non-traceability from internal networks
  • Prepare the privacy notice for reporters
  • Set up automatic deletion within 5 years of final outcome
  • Document receipt, management, and outcome of every report
  • Integrate the retaliation prohibition into the sanctioning system
  • Train management, HR, Legal, and OdV on whistleblowing procedures

Final Take

Compliant report management requires adequate technological infrastructure, specialized privacy expertise, and documentable processes. Inadequate implementation exposes the company to ANAC fines up to €50,000, retaliation litigation, and GDPR violations.

For Italian entities, the practical test is whether confidentiality holds from intake through deletion, whether the DPIA matches the channel actually in use, and whether anti-retaliation controls are evidenced in policy, training, and case handling.

If you still need to confirm whether the obligation applies, return to D.Lgs. 24/2023 and the 50-employee rule. To configure the channel itself, continue with ANAC written and oral reporting requirements.

Disclosurely supports anonymous, secure, and documentable reporting channels with features designed for confidentiality, workflow traceability, and GDPR-ready governance. Request a demo if you want to see how that workflow operates in practice.

FAQs

Is a DPIA mandatory for Italian whistleblowing channels?
Yes. Entities subject to D.Lgs. 24/2023 must conduct a DPIA under GDPR Art. 35. The entity remains responsible even when a technology provider supplies supporting documentation.
How long can whistleblowing reports be retained in Italy?
Documentation relating to internal and external reports must be retained for the time necessary for management and, in any case, no longer than 5 years from communication of the final outcome. Acts from derived proceedings may follow separate legal retention limits.
Who bears the burden of proof in a retaliation claim?
Under Art. 17 of D.Lgs. 24/2023, once the reporter shows a prima facie case of having reported and suffered harm, the burden shifts to the person who carried out the contested act to prove it was motivated by reasons unrelated to the report.
Does anonymity replace the legal confidentiality duty?
No. The law mandates confidentiality of the reporter's identity. Anonymity is a channel design choice that can strengthen trust, but it is not the same as the statutory confidentiality obligation.

Related solutions

Explore the related Disclosurely solution pages for implementation details and workflow context.

Need a secure whistleblowing platform?

Book a 10-minute walkthrough to see how Disclosurely supports secure reporting, investigations, and compliance workflows.

Related guides

Compliance Guides

ANAC Internal Reporting Channels: Requirements for Written and Oral Reports

Disclosurely
29 Jul 202610 min read

ANAC Internal Reporting Channels: Requirements for Written and Oral Reports

By Disclosurely Editorial

Understand what ANAC expects from internal reporting channels — including mandatory written and oral modalities, confidentiality controls, DPIA duties, and acknowledgement timelines.

Read article

Compliance Guides

D.Lgs. 24/2023: The 50-Employee Rule and Integration with Model 231

Disclosurely
29 Jul 20269 min read

D.Lgs. 24/2023: The 50-Employee Rule and Integration with Model 231

By Disclosurely Editorial

Understand when Italian entities must activate internal reporting channels under D.Lgs. 24/2023, how the 50-employee threshold works, and why Model 231 can trigger the obligation regardless of size.

Read article

Buyer Guides

GDPR Questions to Ask Before Buying Whistleblowing Software

Disclosurely
15 Jul 20266 min read

GDPR Questions to Ask Before Buying Whistleblowing Software

By Disclosurely Editorial

GDPR questions matter because a whistleblowing platform handles sensitive personal data from the first report onwards. Buyers should test the operating model, not just the contract language.

Read article
Whistleblowing Privacy: Confidentiality, Garante, and Anti-Retaliation | Disclosurely