Skip to content
+370 5 212 1506 info@dat.lt

Whistleblowing channels and personal data: what the law requires

25 September 2026 · Good to know

An internal channel for reporting breaches is personal data processing from the first report: it holds data on the reporter, on the person reported on and on witnesses. The Law on the Protection of Whistleblowers (PAĮ) requires confidentiality for both the reporter and the persons concerned (Article 16(2) PAĮ). Data that can identify them may be given only to whoever is examining the information (Article 9(3) PAĮ). The information is kept for no less than five years from the last decision (Article 7(1) PAĮ), and data manifestly unrelated to the report is not collected (Article 7(4) PAĮ).

The head of the organisation is responsible for setting up and running the channel (Article 16(3) PAĮ). If confidentiality is breached, there is administrative liability under the Code of Administrative Offences (ANK) and there are GDPR consequences. This article covers what the law actually requires about the data, what the person reported on may learn and where organisations most often go wrong.

Who must have a channel and who is responsible for it

PAĮ provides that internal channels are set up in organisations on the conditions, procedure and requirements laid down by the Government (Article 16(1) PAĮ). So whether your organisation must have a channel also has to be checked against the conditions set by the Government. Directive (EU) 2019/1937, which PAĮ implements, makes an internal channel mandatory in the private sector for entities with 50 or more workers (Article 8(3) of the Directive). But that threshold does not apply to entities within the scope of the EU acts listed in Part I.B and Part II of the Annex: financial services and anti-money-laundering, and certain transport-safety and environmental acts (Article 8(4) of the Directive), and in the public sector the duty covers all entities; the State may exempt only municipalities with fewer than 10,000 inhabitants or fewer than 50 workers, and other entities with fewer than 50 workers (Article 8(9) of the Directive). So having fewer than 50 workers does not by itself mean there is no duty. Entities with 50 to 249 workers may share resources for receiving and investigating reports (Article 8(6) of the Directive).

The head of the organisation informs employees about the channel and makes the related information available to all of them at the workplace (Article 16(3) PAĮ). On receiving information, the organisation confirms receipt within 2 working days, and within 10 working days of that confirmation it tells the reporter how the examination is progressing or that it refuses to examine it (Article 4(2) PAĮ).

In data protection terms, the organisation itself is the controller of the channel. If the channel is mandatory for you, the statutory duty is also the legal basis: the processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) GDPR). If you run a channel voluntarily, the basis must be assessed separately, for example legitimate interest (Article 6(1)(f) GDPR). Where a report contains special categories of data, such as health data, or data on criminal offences, the conditions of Articles 9(1) and 10 GDPR must also be assessed.

What data ends up in the channel

The reporter states the facts, the person involved in the breach, and their own name, surname, personal code or date of birth and contact details (Article 4(8) PAĮ). The person concerned is the person named in the information as possibly having committed the breach or as linked to it (Article 2(11) PAĮ). Information can also be given anonymously; protection then applies if the identity is nevertheless revealed and the person needs protection from retaliation (Article 3(6) PAĮ).

The data minimisation principle is made concrete by the law. Data manifestly unrelated to the report is not collected, and data collected by accident is destroyed without delay (Article 7(4) PAĮ; Article 17 of the Directive). A conversation may be recorded, or minutes of a meeting drawn up, only with the reporter’s consent (Article 7(2) PAĮ). Where a phone call is not recorded, the reporter can check, correct and sign the minutes drawn up (Article 7(3) PAĮ).

Confidentiality: who may see a report

Confidentiality means that the reporter’s data and any other information that can identify them is processed only for the purpose of work functions and is not disclosed to third parties, except in the cases set out in the law (Article 2(5) PAĮ). Every organisation and every person that receives or examines the information has this duty (Article 9(2) PAĮ).

Data that can identify the reporter and the person concerned may be given only to the person or body examining the information. Before that, the reporter is told in writing why the data is being disclosed (Article 9(3) PAĮ). Such information may not be given to persons not taking part in the investigation (Article 9(6) PAĮ). Confidentiality no longer applies where the reporter asks for this in writing or has given knowingly false information (Article 9(5) PAĮ). In criminal and other statutory proceedings, the reporter’s confidentiality is protected in so far as objectively possible (Articles 1(2) and 9(1) PAĮ).

In practice this means that not every manager, the HR team or the IT administrator should see the reporting mailbox or system just because they have access to everything. Access rights must be restricted in advance, not left to trust.

What the person reported on may learn

The Directive requires Member States to ensure that the person concerned can exercise the rights of defence, including the right to be heard and to access their file, and requires competent authorities to protect their identity while investigations are ongoing (Article 22(1) and (2) of the Directive). This is a duty on the State and the authorities, not a right the person enforces directly against the employer in an internal inquiry. But where the inquiry may end in dismissal for the employee’s fault, the employer must first ask for their written explanation (Article 58(4) of the Labour Code, DK). In an organisation’s channel, PAĮ requires their confidentiality to be protected (Article 16(2) PAĮ).

They may make a request to access their data under Article 15 GDPR. They also have a right to any available information about the source of the data (Article 15(1)(g) GDPR). But PAĮ allows the reporter’s identity to be disclosed only to the person examining the report (Article 9(3) PAĮ). That can be regarded as a statutory restriction protecting the rights and freedoms of others (Article 23(1)(i) GDPR). The right to obtain a copy also must not adversely affect the rights and freedoms of others (Article 15(4) GDPR). So the answer normally gives them their own data, but not who reported them or how. The duty to inform them about data obtained is lifted only to the extent that informing them would seriously impair the achievement of the objectives of the processing, for example the investigation; the controller must then take other appropriate measures to protect their rights and interests (Article 14(5)(b) GDPR). Nor does it apply in so far as the data must remain confidential under an obligation of professional secrecy regulated by law (Article 14(5)(d) GDPR). Once the obstacle is gone, the exemption can no longer be relied on.

An important limit: rights can be restricted only by a legislative measure (Article 23(1) GDPR). PAĮ does not provide that the person reported on can never obtain their data. So a refusal must be assessed case by case and based on a specific provision, not on the answer “the investigation is confidential”. How and within what time to answer such a request is covered in Subject access requests: the deadline and the answer.

How long to keep it

PAĮ sets a minimum, not a maximum: the information is kept for no less than five years from the last decision taken, and the competent authority may give a reasoned instruction to keep it longer (Article 7(1) PAĮ). The Directive adds that reports are stored for no longer than is necessary and proportionate (Article 18(1) of the Directive), and the GDPR that data is kept for no longer than necessary for its purposes (Article 5(1)(e) GDPR).

So “let’s delete it as soon as we finish” is a mistake, and so is “let’s keep it forever”. The period must be set in your own procedure and counted from the last decision. How to set retention periods in general is covered in How long to keep personal data.

An external channel provider

The channel can be run by a designated employee or unit, or by an external third party, for example a platform provider or a law firm. The confidentiality requirements apply to that third party too (Article 8(5) of the Directive). Where the provider receives and stores reports on your behalf and on your instructions, it is usually a processor, so you need a contract setting out the subject matter, duration and other terms of the processing (Article 28(3) GDPR). When such a contract is required is covered in Data processing agreement: when required and the risk without one. But if the provider, for example a law firm, decides itself what information to use and how, it may be a separate controller: in Guidelines 07/2020 the EDPB treats a law firm that represents a client in a dispute and acts with a significant degree of independence as a controller. The role of a firm running a channel must be assessed on the facts. Responsibility for the channel stays with the head of the organisation (Article 16(3) PAĮ).

What a breach can cost

Administrative liability. A breach of the whistleblower protection requirements carries a fine of one hundred and forty to three hundred euros (Article 555¹(1) ANK). Where the breach revealed the reporter’s identity, or the ban on retaliation was not respected, the fine is one thousand to two thousand euros, and for a repeat offence up to four thousand euros (Article 555¹(3) and (4) ANK). These offences are investigated, and the reports drawn up, by prosecutors and the police (Article 589, points 6 and 49, ANK). Article 17 PAĮ adds that anyone breaching the law is liable as provided by law.

An employment dispute. Giving information under PAĮ is not treated as harming the employer’s interests, and an employee may not be persecuted for it (Article 31(3) of the Labour Code, DK). In a dispute, the employer must prove that the adverse consequences were not caused by the report (Article 10(4) PAĮ). A leaked reporter identity makes that proof much harder.

GDPR consequences. An unauthorised disclosure of a report may also be a personal data breach, because that term covers a breach of security leading to unauthorised disclosure of data (Article 4(12) GDPR). You may then need to assess whether to notify VDAI.

What most often goes wrong

  • reports arrive in a shared mailbox that several people can see;
  • during the investigation the report is forwarded to the person reported on “so they can explain”;
  • reports are deleted straight after the investigation, although the law requires keeping them for no less than five years;
  • there is no data processing agreement with the external channel provider;
  • the person reported on is refused any data at all, without assessing what can be disclosed.

When to call a lawyer

  • when you set up or change an internal channel and do not know whom to give access;
  • when a report concerns a manager or the person running the channel;
  • when the person reported on asks for their data or a copy of the report;
  • when the reporter’s identity may have been revealed;
  • when you are considering disciplinary action against an employee who made a report.

Frequently asked questions

Do we have to tell the person reported on who reported them?

No. Data that can identify the reporter may be given only to the person or body examining the information (Article 9(3) PAĮ), and the right to a copy must not affect the rights of others (Article 15(4) GDPR). In investigations and court proceedings they have the right of defence, but it does not normally entitle them to learn the reporter’s identity. The exceptions: the reporter asks for this in writing or has given knowingly false information (Article 9(5) PAĮ), or disclosure is required in criminal or other proceedings laid down by law, for example to protect their right of defence (Articles 1(2) and 9(1) PAĮ; Article 16(2) of the Directive).

Can reports be deleted straight after the investigation?

No. PAĮ requires the information to be kept for no less than five years from the last decision (Article 7(1) PAĮ). Only data manifestly unrelated to the report must be deleted at once (Article 7(4) PAĮ).

Can we hand the channel over to an external provider?

Yes, the Directive allows this, and the confidentiality requirements apply to the provider too (Article 8(5) of the Directive). A provider processing data on your behalf needs an Article 28 GDPR contract. The head of the organisation remains responsible for the channel (Article 16(3) PAĮ).

Do we need the reporter’s consent to process their data?

No. If the channel is mandatory for you, the data is processed to comply with a legal obligation (Article 6(1)(c) GDPR). If you run it voluntarily, the basis must be assessed separately, for example legitimate interest (Article 6(1)(f) GDPR). The reporter’s own choice matters only for certain steps, for example recording a conversation (Article 7(2) PAĮ) or where the reporter asks in writing for their identity to be disclosed (Article 9(5)(1) PAĮ).

How to start

Write down how you receive reports today: at what address or through what system, who has access, where records are kept and for how long. Send us your internal channel procedure and the contract with the provider, if there is one. We will tell you where confidentiality is not ensured and what needs to change.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles