Whistleblowing EU

Open-source whistleblowing software (Ireland)

Is your organisation in Ireland looking for a secure, ethical whistleblowing platform that meets the Protected Disclosures Act and the EU Directive?

GlobaLeaks is the free and open-source software built to:

Read more in the official documentation.

Documentation Demo

The EU Whistleblowing Directive

The EU Directive on the protection of persons who report breaches of Union law obliges organisations to operate secure, confidential reporting channels and to shield reporting persons from penalisation.

In Ireland the Directive is transposed by the Protected Disclosures (Amendment) Act 2022, which amends the Protected Disclosures Act 2014. Public bodies and private employers with 50 or more workers must operate internal reporting channels. The Office of the Protected Disclosures Commissioner oversees external reports.

Legal obligations and compliance

Reference Obligation How GlobaLeaks satisfies it
s. 6A(1)(a) Establish secure internal reporting channels designed and operated to protect the confidentiality of the identity of the reporting person and any third party mentioned in the report, preventing access by unauthorised staff members. GlobaLeaks provides a dedicated, self-hosted internal reporting channel for whistleblowing under the Protected Disclosures Act that is free and open source and independently auditable. Reports and attachments are protected by strong encryption, and the reporting person's identity is protected at every stage. Granular need-to-know access control ensures that only authorised recipients can view a case. Full anonymity is possible thanks to the integration of Tor technology.
s. 6A(2) Allow reports to be made in writing and/or orally, and where requested, by means of a physical meeting within a reasonable time. Reporters can submit written protected disclosures with attachments as well as voice messages, and can request an in-person meeting. An asynchronous two-way channel lets the reporting person and the handler communicate while preserving anonymity.
s. 6A(1)(b) Acknowledge receipt of the report to the reporting person within 7 days of receipt. On submission a receipt of acknowledgement is issued immediately, and structured whistleblowing case management with deadlines, timers and reminders ensures acknowledgement is delivered within the 7-day limit.
s. 6A(1)(c)-(d) Designate an impartial person or department to maintain communication with the reporting person and, where necessary, request further information and diligently follow up on the report. The asynchronous two-way channel keeps the designated person in contact with the reporting person while preserving anonymity, and the whistleblowing case management dashboard supports diligent follow-up with the ability to request further information.
s. 6A(1)(e) Provide feedback to the reporting person within a reasonable period not exceeding 3 months from the acknowledgement of receipt. Built-in timers, reminders and the case management dashboard track the statutory three-month feedback deadline, and feedback is delivered to the reporting person through the anonymity-preserving two-way whistleblowing channel.
s. 16(1) Not disclose to any other person information that might identify the reporting person without their consent. The reporting person's identity is protected at every stage through anonymous or confidential reporting (configurable), granular need-to-know access control, no IP logging and metadata minimisation, so information identifying the whistleblower is never disclosed without consent.
s. 16B Personal data processing compliant with the GDPR, following data minimisation. Self-hosting, no third-party components, no IP logging, metadata minimisation.
s. 16C Keep records of every report received in compliance with confidentiality requirements. Every protected disclosure is retained within structured case management, and a privacy preserving audit log documents each report and the actions taken while enforcing confidentiality through granular need-to-know access control.

Beyond legal compliance: standards and recognitions

GlobaLeaks is likewise built to sit within a whistleblowing management system that follows the ISO 37002:2021 guidelines, and to underpin the reporting-channel requirements of certifiable standards such as ISO 37001 (anti-bribery) and ISO 37301 (compliance management).

Built to slot into an information security management system that follows ISO/IEC 27001:2022, GlobaLeaks protects disclosures and their attachments with encryption and confines access to expressly authorised handlers. The platform likewise puts the GDPR principles of data protection by design and by default (Regulation (EU) 2016/679) into practice: minimal data collection, no logging of IP addresses and metadata kept to the bare minimum.

The design of GlobaLeaks takes into account compatibility with the WCAG 2.1 AA guidelines and the European standard EN 301 549 - the technical baseline behind both the European Accessibility Act (Directive (EU) 2019/882) and Directive (EU) 2016/2102 on public sector websites - so that anyone can make a disclosure safely and without assistance. In Ireland the reference instruments are S.I. No. 358/2020 (accessibility of public sector websites) and S.I. No. 636/2023, which gives effect to the European Accessibility Act.

The Digital Public Goods Alliance also lists GlobaLeaks as a Digital Public Good, attesting to its character as free and open-source software in the service of the public interest.