Ownware
Guide · Aug 23, 2026

Is a Shared Email Inbox Enough for the EU Whistleblowing Directive?

The question nearly everyone asks first, usually hoping for a yes. The honest answer is sometimes — and it turns on six specific properties the Directive asks of a channel, not on the inbox. Each one held against the Directive's own text, with what it genuinely does not require stated just as plainl

It is the question nearly everyone asks first, usually hoping for a yes. The honest answer is sometimes — and it turns much less on the inbox than on six specific things the Directive asks a channel to do. Here they are, against the actual text.

The short answer

A shared mailbox is not banned. Directive (EU) 2019/1937 never mentions email, never mentions software, and never prescribes a technology. It prescribes properties. A mailbox has some of them by default, some only if you deliberately configure them, and one or two it structurally cannot have.

By the end of this page you should be able to put your own mailbox into one of those three buckets. If the answer comes out as "configure them", then the honest recommendation is: configure them. That is cheaper than buying anything, and it is a real answer, not a consolation prize.

Everything quoted below is from the Directive's own text or, where marked, from Germany's transposing statute. National transpositions differ — sometimes substantially — and this page is not legal advice. Check your own country's law, and if the stakes are real, check it with someone qualified to advise on it.

What the Directive actually asks of a channel

The obligation to have one sits in Article 8. Paragraph 1 requires member states to ensure that legal entities "establish channels and procedures for internal reporting and for follow-up"; paragraph 3 applies that to private-sector entities "with 50 or more workers". Article 26(2) set the deadline for entities with 50 to 249 workers at 17 December 2023 — a date that has passed everywhere in the Union.

What the channel must do is Article 9(1). In full:

(a) channels for receiving the reports which are designed, established and operated in a secure manner that ensures that the confidentiality of the identity of the reporting person and any third party mentioned in the report is protected, and prevents access thereto by non-authorised staff members;

(b) acknowledgment of receipt of the report to the reporting person within seven days of that receipt;

(c) the designation of an impartial person or department competent for following-up on the reports […];

(d) diligent follow-up by the designated person or department referred to in point (c);

(e) diligent follow-up, where provided for in national law, as regards anonymous reporting;

(f) a reasonable timeframe to provide feedback, not exceeding three months from the acknowledgment of receipt or, if no acknowledgement was sent to the reporting person, three months from the expiry of the seven-day period after the report was made;

(g) provision of clear and easily accessible information regarding the procedures for reporting externally to competent authorities […]

Notice what is not in that list: no technology, no vendor, no encryption standard, no anonymity requirement. Six of the seven points are about procedure. Only point (a) is about how the channel is built — and point (a) is where the trouble is.

Six things to hold your inbox against

1. Anonymity — the weakest argument against an inbox

This is usually the first objection raised, and on its own it is not a good one. The Directive does not require you to accept anonymous reports:

Without prejudice to existing obligations to provide for anonymous reporting by virtue of Union law, this Directive does not affect the power of Member States to decide whether legal entities in the private or public sector and competent authorities are required to accept and follow up on anonymous reports of breaches.

Germany, for example, declined to require it. § 16(1) of the Hinweisgeberschutzgesetz says the internal reporting office should also process reports that arrive anonymously, then adds: "Es besteht allerdings keine Verpflichtung, die Meldekanäle so zu gestalten, dass sie die Abgabe anonymer Meldungen ermöglichen" — there is, however, no obligation to design the reporting channels so that they enable anonymous reports to be submitted. (Our translation; the German is authoritative.) Other member states were free to decide differently — Article 6(2) puts that choice squarely in national hands — so this is a question about your national law rather than about the Directive. Check yours before you conclude anything.

So "you cannot send an anonymous email" is not, by itself, a breach of anything. Two related duties do survive, though:

  • Article 9(1)(e) requires diligent follow-up on anonymous reports "where provided for in national law". An anonymous report can arrive at a channel that never invited one — a letter, a note, a message from a throwaway address — and if your national law provides for it, you owe it the same follow-up.
  • Article 6(3) protects people who reported anonymously and were "subsequently identified and suffer retaliation". Anonymity you did not offer does not remove your obligations to someone who took it anyway.

What an inbox really costs you here is not legal exposure. It is use. A person deciding whether to report knows their name is attached before they type the first word, and the Directive's whole architecture depends on that person choosing the internal channel — Article 7(2) has member states encouraging internal reporting ahead of going to a regulator. A permissible channel nobody uses produces no reports, which looks like a clean record right up until the first one goes straight to the authority or the press.

2. The seven-day clock — the one an inbox handles well

Article 9(1)(b): "acknowledgment of receipt of the report to the reporting person within seven days of that receipt."

An inbox is genuinely good at this, and it deserves the credit. The reporter has an address, so acknowledgment is deliverable. An auto-responder sends it in zero seconds. No software purchase improves on that.

What an inbox cannot do is let you see the clock. Seven days is a per-report countdown starting at receipt, and in a mailbox day six of report A and day two of report B look identical — an unread bold line in a list. The arithmetic is being done in someone's head, or in a spreadsheet beside the mailbox. That holds at three reports a year. It stops holding at thirty, or the first time the person who does it is on leave.

Two practical wrinkles. An auto-reply on the address acknowledges everything that lands, including spam, and announces to anyone who writes that this is the whistleblowing channel — fine, unless the address does double duty. And it is worth asking whether an automatic confirmation, sent by a server that has not yet seen the report, is "acknowledgment of receipt of the report". The Directive does not say. The duty is framed around receipt rather than assessment, so an automatic confirmation is a defensible reading — but it is a reading, not a certainty.

3. The three-month clock — where an inbox starts producing wrong dates

Article 9(1)(f) again, and read the anchor carefully:

a reasonable timeframe to provide feedback, not exceeding three months from the acknowledgment of receipt or, if no acknowledgement was sent to the reporting person, three months from the expiry of the seven-day period after the report was made

The deadline hangs off the acknowledgment, not the report. In a mailbox that date lives in the Sent folder, attached to one specific message — not the four replies that followed it, not the one somebody sent from their phone and never saved. And if you never acknowledged at all, the anchor becomes the expiry of the seven-day window, which means missing the first duty quietly re-dates the second.

Then the months. "Three months" is calendar months, so a report acknowledged on 30 November is due on 28 February, and 29 February in a leap year. That is not a subtraction email can do for you.

One widely held belief worth dismantling here: three months is not a deadline to finish anything. What is owed is feedback, which the Directive defines precisely:

'feedback' means the provision to the reporting person of information on the action envisaged or taken as follow-up and on the grounds for such follow-up

An investigation may reasonably run past three months. What may not run past three months is telling the reporter what is being done, and why.

The inbox failure here is arithmetic performed by a human under no prompting. And it is fixable: two columns in a spreadsheet — received, acknowledged — plus a date formula gets you most of the way there. What that does not get you is anyone noticing when nobody updates the spreadsheet.

4. Confidentiality and access control — the failure that is structural

This is the serious one. Article 9(1)(a) requires channels

designed, established and operated in a secure manner that ensures that the confidentiality of the identity of the reporting person and any third party mentioned in the report is protected, and prevents access thereto by non-authorised staff members

and Article 16(1) adds the duty itself:

Member States shall ensure that the identity of the reporting person is not disclosed to anyone beyond the authorised staff members competent to receive or follow up on reports, without the explicit consent of that person. This shall also apply to any other information from which the identity of the reporting person may be directly or indirectly deduced.

Three phrases carry the weight. "Designed, established and operated" — the obligation attaches to the design, so it is not enough that no unauthorised person happened to read it. "Prevents access" — prevents, not discourages. And "directly or indirectly deduced" — the protected thing is not only the name.

Now hold a shared mailbox against that. In a default corporate mail tenant, the population that can reach it is larger than the two people you named in the policy:

  • anyone with Full Access or delegate permission, current or historical — and permission grants are rarely reviewed
  • administrators, who can grant themselves that permission, and often do so routinely for ordinary support work
  • whatever is subscribed to the mail flow: journaling, eDiscovery and retention holds, archiving, DLP, backup products, security tooling that quarantines a message and lets an analyst open it
  • every device the mailbox is open on, and those devices' backups
  • anyone the message gets forwarded to, deliberately or by a rule — carrying the reporter's address with it

None of this is scandalous. It is what a mailbox is for. But it turns "prevents access by non-authorised staff members" into a claim you have to construct deliberately and be able to evidence, rather than one you get for free.

And there is a sharper version in a small company: the person a report is about may be the person who administers the mail system, or one of the two people with mailbox access. No configuration of a shared inbox stops a director asking IT for access to a mailbox the company owns.

Where an inbox can be made to work. This requirement is meetable with mail primitives, and it is worth being specific about what that takes: a dedicated mailbox rather than an alias on someone's personal one; access restricted to named individuals, with the permission set reviewed and the review recorded; mailbox auditing switched on so access leaves a trace; the mailbox scoped out of journaling, archiving and eDiscovery; no forwarding rules; controlled access on mobile devices. Do all of that and keep the evidence, and you have a defensible answer to Article 9(1)(a). Note the length of the list. That is a channel assembled from mail parts — not "just use the inbox".

5. The record — required, but less than people assume

Member States shall ensure that legal entities in the private and public sector and competent authorities keep records of every report received, in compliance with the confidentiality requirements provided for in Article 16. Reports shall be stored for no longer than it is necessary and proportionate in order to comply with the requirements imposed by this Directive, or other requirements imposed by Union or national law.

Read that narrowly, because a lot of marketing reads it broadly. The Directive requires records of reports, kept confidentially, and not kept longer than necessary. It does not require an access log, an append-only ledger, or tamper-evident storage. Nobody has to buy immutability to satisfy Article 18(1). (The "durable storage" wording in Article 12(1)(b) applies to external channels operated by competent authorities, not to you.)

National law adds texture. Germany's § 11(1) HinSchG requires documentation of all incoming reports "in dauerhaft abrufbarer Weise" — in a durably retrievable manner — observing the confidentiality duty, and § 11(5) has that documentation deleted three years after the procedure concludes, kept longer only where necessary and proportionate.

So the inbox problem here is not "no audit trail". It is these three:

  • Mail is mutable. It can be deleted, moved or purged by the people who hold it — including, in the worst case, someone a report concerns.
  • Retention policies destroy records silently. A tenant-wide 24-month auto-delete will remove a report at roughly the moment it becomes evidence, and nobody receives an alert when it does.
  • "Durably retrievable" and "delete three years after conclusion" pull in opposite directions, and a mailbox has no concept of a procedure concluding. Mail retention counts from the date of the message; the legal clock counts from the end of the case.

An audit trail is still worth having — but for a different reason than Article 18. It answers "who opened this" when someone alleges a leak, which is Article 16 evidence, not Article 18 evidence.

6. Attachment metadata — the failure nobody plans for

The relevant text is the second paragraph of Article 17:

Personal data which are manifestly not relevant for the handling of a specific report shall not be collected or, if accidentally collected, shall be deleted without undue delay.

Put that beside Article 16(1)'s "directly or indirectly deduced", then think about what actually arrives attached to an email:

  • a phone photo, carrying GPS coordinates, capture time, camera make and model, and sometimes a device identifier in its EXIF block
  • a Word file or PDF, carrying an author name, a company name, revision history, and sometimes tracked changes and comments nobody meant to send
  • a screenshot, carrying a username in the window title, a browser profile, an open taskbar
  • the message itself: display name, corporate signature block, mail client, and routing headers

A mailbox stores all of it, unmodified. That is not a defect — fidelity is what mail is for. But Article 17's second paragraph is not phrased as a preference, and metadata a reporter never intended to send is close to a textbook instance of "accidentally collected" and "manifestly not relevant".

Can an inbox comply? In principle: a person opens every attachment, strips the metadata, saves the clean copy, then deletes the original from the mailbox and from deleted items and from the recovery store. Realistically, that does not happen at 4pm on a Friday.

The honest counterpoint is that this cuts against portals too. A web form that accepts uploads and files them as received has exactly the same problem, with a better-looking interface. The question to ask of any channel — ours included — is whether it strips metadata on ingest or merely stores the file.

What the Directive genuinely does not require

A fair amount of what gets sold as "Directive compliance" is not in the Directive. For balance:

  • It does not require software. Article 8(5): "Reporting channels may be operated internally by a person or department designated for that purpose or provided externally by a third party." A named, trained person can be the channel.
  • It does not require anonymous reporting. Article 6(2), quoted above, leaves that to member states.
  • It does not require a phone line. Article 9(2): "The channels provided for in point (a) of paragraph 1 shall enable reporting in writing or orally, or both." A written-only channel is a permitted design under the Directive. (One caveat below.)
  • It does not require you to open the channel to non-employees. Article 8(2): the channel shall enable the entity's workers to report; it may enable contractors, suppliers and others in work-related contact.
  • It does not require every company to have its own. Article 8(6) lets private-sector entities with 50 to 249 workers share resources for receiving reports and investigating them — without sharing away the duties of confidentiality, feedback and addressing the breach.
  • It does not require an investigation to finish in three months. Article 9(1)(f) is a feedback deadline; Article 5(13) defines what feedback is.
  • It does not require a tamper-proof audit trail. Article 18(1) requires records, kept confidentially, not kept too long.
  • It does not itself require a fine for having no channel. Article 23(1) requires penalties for hindering reporting, retaliation, vexatious proceedings, and breach of the confidentiality duty. A penalty for simply not having a channel is a national addition, not a Union one.

The caveat on written-only channels

Article 9(2)'s second sentence: "Oral reporting shall be possible by telephone or through other voice messaging systems, and, upon request by the reporting person, by means of a physical meeting within a reasonable timeframe." On the Directive's own structure that sentence describes what oral reporting must include if you offer it.

National law can be tighter, and Germany's is a good illustration. § 16(3) HinSchG reads: internal reporting channels must enable reports "in mündlicher oder in Textform" (in oral form or in text form); oral reports must be possible by telephone or another form of voice transmission; and then, in its own sentence, "Auf Ersuchen der hinweisgebenden Person ist für eine Meldung innerhalb einer angemessenen Zeit eine persönliche Zusammenkunft […] zu ermöglichen" — at the request of the reporting person, a personal meeting must be made possible within a reasonable time. That sentence is not, on its face, conditioned on having chosen an oral channel.

The practical upshot: if you run a written-only channel in Germany, you still need an answer ready for a reporter who asks to meet someone. That answer can be a line in your procedure naming who will meet them and within how many days — it does not have to be a product feature. But do not take our reading of a German sentence as advice; take the sentence to someone who gives advice.

Penalties, stated exactly

The Directive sets no amounts. Article 23(1) requires "effective, proportionate and dissuasive penalties" for the four categories of conduct listed there, and leaves the numbers to member states. Germany, as a worked example (§ 40 HinSchG, with § 30 of the Ordnungswidrigkeitengesetz):

ConductProvisionMaximumAgainst a legal person
Failing to ensure an internal reporting office is established and operated§ 40(2) no. 2€20,000€20,000 — the tenfold multiplier is not applied to this offence
Obstructing a report; retaliation; intentional or reckless breach of confidentiality§ 40(2) nos. 1 and 3; § 40(3)€50,000up to €500,000 — § 40(6) sentence 2 applies § 30(2) sentence 3 OWiG, which decuples the maximum
Negligent breach of confidentiality§ 40(4)€10,000up to €100,000, on the same mechanism

It is worth noticing which figure is largest, because the usual sales pitch gets this backwards. The expensive risk in German law is not the absence of a channel. It is what happens to the report and to the reporter after one arrives — obstruction, retaliation, and a leaked identity. That is an argument for a channel that genuinely controls access. It is a poor argument for buying anything in a hurry to tick a box.

Two dates, for completeness: § 40(2) no. 2 has only applied since 1 December 2023 (§ 42(2) HinSchG), and the obligation itself has bound German employers with 50–249 workers since 17 December 2023 (§ 42(1)), mirroring Article 26(2) of the Directive. Other member states transposed on their own timetables and with their own numbers.

Shared inbox vs a purpose-built channel

Plainly, with no thumb on the scale:

Shared email inboxPurpose-built channel
Cost to startZeroA licence or a subscription, plus setup time
Time to startMinutesHours to days
Anonymous reportsNot from a work address; a throwaway address is the reporter's own workaround, not your channel's featureCase code and passphrase, with no identity collected in the first place
Acknowledging within 7 daysTrivial to send; hard to see comingSent by a person, but counted and surfaced by the system
The 3-month clock, anchored on the acknowledgmentManual, and quietly wrong whenever the anchor date is misrememberedDerived from the recorded acknowledgment date
Restricting access to named peoplePossible, with deliberate configuration — and administrators remain above itRole-based; some products add a two-person rule for sensitive cases
Evidence of who read a reportMailbox auditing, if it was switched on beforehandAn audit log, if the product keeps one — ask
Surviving a retention policyOften not; deletion is silentRetention can run per case, from case closure
Attachment metadataStored exactly as receivedStripped on ingest in products that do it, stored as received in those that do not — ask
Two-way contact with an anonymous reporterNot possibleA message thread keyed to the case code
Who can read it at infrastructure levelMail administrators, as a matter of routineThe server or database administrator, as an exception
Oral reports and meetingsNeitherRarely; most are written intake only
Who carries the consequence of getting it wrongYouYou

That last row is not a throwaway. No tool transfers the obligation. It can only make the obligation easier to discharge and easier to demonstrate.

If you decide you need something, here is the ladder

  • Nothing yet — if you are under 50 workers and outside the sectors where the threshold does not apply (Article 8(4), and note that Article 8(7) lets member states extend the duty to smaller entities after a risk assessment; Germany's § 12(3) already binds much of the financial sector regardless of headcount).
  • A named person plus a properly locked-down mailbox — the configuration listed under point 4 above, written into a procedure, with the permission review recorded. Free, legitimate, and enough for a small organisation that will receive a handful of reports.
  • A shared channel with other companies — Article 8(6), if you are between 50 and 249 workers and know the others well enough.
  • A hosted whistleblowing platform — someone else runs it, patches it, and holds your reports. Convenient; recurring; and your most sensitive records live on their infrastructure.
  • A self-hosted portal — you run it, patch it, and hold the reports yourself. Cheaper over time, more work, and the admin problem moves from your mail provider to your own server.

Where Confida fits — and where it does not

Confida is our take on option 5: a self-hosted whistleblowing portal you buy once, install on your own server, and run without a subscription. Reports are anonymous by case code and passphrase — no name, email, phone number or IP address is recorded, so there is no identity in the database to leak. The seven-day and three-month clocks are configurable and tracked, with the feedback deadline anchored on the acknowledgment date exactly as Article 9(1)(f) describes; if you switch on the working-day rule and enter your own closure days, the register also shows when a deadline landing on a weekend or holiday is observed — and that adjustment can only ever move a date later, never earlier. Photo attachments are rebuilt without their metadata before storage and encrypted at rest. There is a two-way anonymous message thread, an append-only audit log, and a two-person rule you can apply to sensitive cases.

What it does not do, in the same breath:

  • Written intake only. There is no telephone or voice-message intake, and no meeting scheduling. Under Article 9(2) a written-only channel is permitted — but see the German caveat above, and check your own transposition before you assume it is enough.
  • One organisation per install. It is single-tenant. If you advise several clients, that is a separate install each.
  • Photos only for attachments. JPEG and PNG. Documents are refused on purpose, because author history inside a PDF or Word file cannot be reliably stripped.
  • Anonymity is application-level. The application never asks for or stores an IP address — but your web server or reverse proxy will log visitor IPs unless you turn that off for this host. If you install it and leave access logging on, you have undone the main thing you installed it for.
  • Acknowledgment is a human action. Confida tracks the clock and shows you what is due; it does not send the acknowledgment for you.
  • It does not make anyone compliant. Compliance is your policy, your procedure, your trained handlers, your record-keeping and your national law. Confida is a channel and a case register. Any vendor telling you their product makes you compliant is selling you a sentence that cannot be true.

And if, having read all of the above, your conclusion is that a locked-down mailbox and a spreadsheet will do for your organisation — that is a legitimate conclusion, and you should reach it without buying anything from us.

Look at Confida honestly

Questions people actually ask

Can we just use our existing HR or compliance email address as the reporting channel?

You can use email as the medium. Using an existing address is the harder part, because that address already has a permission history, sits inside your normal mail flow, is probably in scope for journaling and retention, and may be readable by people who are not authorised staff members for the purposes of Article 9(1)(a). If you want to do it with mail, make a dedicated mailbox, restrict and record who has access, switch on mailbox auditing, and scope it out of the tooling that would otherwise sweep it up.

Do we have to accept anonymous reports?

Under the Directive, no — Article 6(2) puts that choice in national hands, and Germany, for instance, declined to require it. Others were free to decide differently, so the real question is what your own transposition says. And note Article 9(1)(e): where national law provides for it, anonymous reports that arrive must still be followed up, whether or not your channel invited them.

Do we need a phone hotline as well as a web form?

Article 9(2) says channels "shall enable reporting in writing or orally, or both" — so written-only is permitted at Directive level. Whether it is permitted where you are is a national question, and even where it is, a request for a physical meeting may need an answer. In Germany, § 16(3) HinSchG states the meeting duty in an unconditional sentence.

We have fewer than 50 employees. Do we need anything at all?

Usually not, under Article 8(3). Two exceptions matter: Article 8(4) removes the threshold for entities covered by the financial-services, anti-money-laundering, transport-safety and environmental acts listed in the Annex — Germany's § 12(3) HinSchG spells out a long list of firms bound regardless of headcount — and Article 8(7) lets member states extend the duty to smaller entities after a risk assessment. Public-sector bodies are covered separately under Article 8(9).

Does the three-month deadline mean the investigation has to be finished?

No. Article 9(1)(f) is a deadline for feedback, and Article 5(13) defines feedback as information on "the action envisaged or taken as follow-up and on the grounds for such follow-up". An investigation can properly still be running. What cannot still be running is your silence.

Has anyone actually been fined for not having a channel?

We do not have reliable public figures on enforcement volume, and we are not going to invent one to sell you something. What is verifiable is the exposure written into national law — in Germany, up to €20,000 for not operating an internal reporting office, and up to €500,000 against a company for obstruction, retaliation or an intentional or reckless breach of confidentiality. Treat any vendor who quotes you an enforcement statistic without a source the way you would treat any other unsourced number.

Before you act on any of this

Everything above is the Directive's own wording plus one member state's transposition, quoted so you can check it. Transpositions genuinely differ — on anonymity, on oral channels, on retention periods, on penalties, and on which small entities are caught. The Directive is a floor, and Article 25(1) expressly lets member states be more favourable to reporting persons than it is.

This page is not legal advice, and reading it does not make you compliant any more than installing software would. If the decision matters, put the question to someone qualified in your jurisdiction — and bring the article numbers with you.

Own your tools

Stop renting your own business.

Every tool in this store is a one-time purchase: install it on your own server, keep your own data, and never see a renewal invoice.

Affiliate program
Recommend tools people own — earn 35% on every sale. 90-day tracking, instant delivery, payouts by Lemon Squeezy.
Become an affiliate →