🇩🇪 Germany compliance
Hinweisgebersystem für Deutschland
In Deutschland setzt Hinweisgeberschutzgesetz (HinSchG) die EU-Hinweisgeber-Richtlinie 2019/1937 in nationales Recht um. Unternehmen mit 50+ Mitarbeitenden (seit 17. Dezember 2023) müssen ein vertrauliches internes Hinweisgebersystem betreiben, Meldungen innerhalb von 7 Tagen bestätigen und innerhalb von 3 Monaten substantiell beantworten. Bußgelder bei Nichteinhaltung erreichen bis zu €50,000.
Confidly is a GDPR-compliant whistleblowing channel built for companies in Germany (Deutschland) operating under Hinweisgeberschutzgesetz (HinSchG) (HinSchG). The intake form is auto-configured with the categories and disclosures HinSchG requires. Reporters can attach audio or video oral statements to a web submission; a native phone-hotline or voicemail channel is on roadmap. The mandatory 7-day acknowledgement and 3-month feedback updates are automated. Set up in 15 minutes. Hosted in the EU. Used by compliance teams from 50 to 5,000 employees.
| Law | Hinweisgeberschutzgesetz (HinSchG) |
| In force since | 2 July 2023 |
| Who must comply | 50+ employees (since 17 Dec 2023) |
| Enforcement | Bundesamt für Justiz |
| Max fine | €50,000 |
| Companies affected | ~75,000 companies with 50+ employees |
What HinSchG requires you to do
Hinweisgeberschutzgesetz (HinSchG) transposes the EU Whistleblower Directive 2019/1937 into Germany national law. The core obligations for companies above the threshold (50+ employees (since 17 Dec 2023)):
- Maintain a confidential internal reporting channel
- Acknowledge every report within 7 days
- Provide feedback to the reporter within 3 months
- Designate a person or unit to handle reports
- Protect the reporter from retaliation
- Keep records for the case duration + the audit window
In Germany, enforcement sits with Bundesamt für Justiz. Maximum fines for non-compliance reach €50,000.
Estimate your exposure under HinSchG with the fines calculator.
How Confidly covers HinSchG
- Country-specific intake template for HinSchG: the form is auto-configured with the categories, disclosures and fields the Germany transposition requires. No manual setup per channel.
- Anonymous intake available where Germany law permits. Reporters get a server-issued case code and their own 6-digit secret. No email, no IP, no identifier stored.
- Oral-statement attachments on every plan: reporters upload audio or video oral statements directly into the web form, with EXIF/metadata stripping. A staffed phone hotline or AI-transcribed voicemail channel is on roadmap, in support of the oral-reporting requirement that HinSchG carries from EU Directive 2019/1937 Art. 16.
- Form pre-translated into DE, EN. AI translates incoming reports to your working language on the admin side.
- Auto reporter status updates at 7 days (acknowledgement) and 3 months (status), in the reporter's language. HinSchG feedback obligation satisfied by default.
- AI investigation copilot (Pro): AI summarises, classifies severity, drafts neutral replies, and clusters multi-reporter patterns to surface systemic issues.
- Append-only audit log required for Bundesamt für Justiz audits. Every action recorded with actor, timestamp and metadata.
- EU data residency: all data stored in EU data centres. Per-channel residency on Enterprise (data for Germany entities stays in Germany). No third-country transfers.
- Native HRIS sync (Pro): Personio, BambooHR. Auto-revoke channel access on offboarding; flag when a named-in-report person leaves the company.
What does Confidly cost in Germany?
Three plans, EUR-priced (VAT reverse-charged for EU B2B). Pick a tier by company size; everything else is included.
Frequently asked questions: HinSchG
- Wie funktioniert ein Hinweisgebersystem?
- A whistleblowing channel works in three steps: (1) the reporter submits a confidential report through a public-facing form, receiving a server-issued case code plus their own 6-digit secret to follow up. (2) The designated case handler triages the report inside the admin dashboard, acknowledging within 7 days as required by HinSchG. (3) Investigation, communication, and resolution are tracked in an append-only audit log that satisfies Bundesamt für Justiz inspections.
- Was ist ein Hinweisgebersystem?
- Ein Hinweisgebersystem (whistleblowing system) is a confidential channel through which employees, suppliers, and other persons connected to a company can report violations of EU or national law without fear of retaliation. In Germany, Hinweisgeberschutzgesetz (HinSchG) (HinSchG) makes such a channel mandatory for companies with 50+ employees (since 17 Dec 2023).
- Wer braucht ein Hinweisgebersystem?
- Under HinSchG, the channel must accept reports from current and former employees, applicants, suppliers, contractors, shareholders, and members of administrative or supervisory bodies. Any person who acquired the information in a work-related context is protected. Confidly's reporter UI requires no email, no IP capture, and no account, so anyone in scope can submit.
- Was passiert nach einer Hinweisgebermeldung?
- After receipt, the designated internal reporting office in Germany reviews the report for plausibility and credibility within 7 days, then opens an investigation if warranted. The reporter receives substantive feedback within 3 months of acknowledgement. Confidly's dashboard runs both SLA timers automatically and logs every action to an append-only audit trail for Bundesamt für Justiz.
- Was ist ein Hinweisgeber?
- Ein Hinweisgeber (englisch: whistleblower) ist eine natürliche Person, die im beruflichen Kontext erlangte Informationen über Rechtsverstöße (etwa Korruption, Betrug, Verstöße gegen Datenschutz-, Geldwäsche- oder Produktsicherheitsvorschriften) über eine interne oder externe Meldestelle weitergibt. Geschützt sind Beschäftigte, ehemalige Mitarbeitende, Bewerber:innen, Lieferanten, Auftragnehmer:innen und Anteilseigner:innen. In Germany schützt Hinweisgeberschutzgesetz (HinSchG) (HinSchG) Hinweisgeber:innen ausdrücklich vor jeglichen Repressalien wie Kündigung, Versetzung oder Mobbing.
- Is a whistleblowing channel mandatory in Germany?
- Yes. Hinweisgeberschutzgesetz (HinSchG) (HinSchG), the Germany transposition of EU Directive 2019/1937, requires companies with 50+ employees (since 17 Dec 2023) to operate a confidential internal whistleblowing channel. The law has been in force since 2 July 2023.
- What are the fines for non-compliance with HinSchG?
- Maximum administrative fines under HinSchG reach €50,000. Enforcement is carried out by Bundesamt für Justiz. Fines apply both for failing to establish a channel and for retaliation against reporters.
- Does HinSchG require anonymous reporting?
- HinSchG permits anonymous reporting where Germany national law allows. Confidly's reporter UI issues a server-side case code and reporter-only secret (no email, IP address, or browser identifier is stored), so reporters can submit and follow up entirely anonymously.