Features Pricing Our AI AI Project Plan Generator
Industries Internal projects Use Cases Case Studies
Blog Knowledge library Comparisons PM Templates Free Tools Integrations AI Project Management API & Developers
Login Get started free
Example project plan

Project plan for the introduction of a whistleblowing system

Under the German Whistleblower Protection Act, companies with 50 or more employees need an internal reporting office with fixed deadlines for acknowledgement and feedback. Besides the technology, confidentiality, data protection and the works council matter. This plan shows the rollout at a manufacturer with 250 employees.

No sign-up · opens instantly · 12 Weeks · 6 Phases · 29 Tasks · Budget approx. €42,650

This is how the plan looks in PathHub — click through the tabs or tick off tasks.

app.pathhub.ai/try?example=hin-enOpen live
Example plan

German Whistleblowing System Implementation

This project will establish an internal reporting office and secure digital whistleblowing channel for a German manufacturing company with 250 employees. The operating model will comply with the German Whistleblower Protection Act, including confidentiality, restricted access, acknowledgement within seven days and feedback within three months and seven days. GDPR requirements, including retention rules, DPIA screening and an Article 28 data processing agreement where applicable, will be completed before processing begins. Works council consultation, role-based training and accessible communication for office, non-desk and shift employees will support the week-12 launch.

Total Progress0%
12Weeks
0/6Phases
0/29Tasks
€42,650Budget
AI Recommendations KIAI Chat KIAI Tools KI

Phases

1

Phase 1: Mobilization and Scope Definition

Pending · 1W · 0/4
Executive Sponsor / Managing Director
0

Establish project ownership, confirm the implementation scope and align all decision-making roles. The phase creates the approved foundation for a week-12 go-live.

Timeline

Timeline 6 PhasesStart: Oct 6, 2026
Phase / Task
Oct 2026
Nov 2026
Dec 2026
W 1Oct 6
W 2Oct 13
W 3Oct 20
W 4Oct 27
W 5Nov 3
W 6Nov 10
W 7Nov 17
W 8Nov 24
W 9Dec 1
W 10Dec 8
W 11Dec 15
W 12Dec 22
Mobilization and Scope DefinitionOct 6 – Oct 12 · 1 wk · 0/4
Mobilization and Scope Definition
Legal and Process Requirements BaselineOct 13 – Oct 26 · 2 wk · 0/5
Legal and Process Requirements Baseline
Operating Model and Works Council ConsultationOct 27 – Nov 9 · 2 wk · 0/5
Operating Model and Works Council Consultation
Vendor Selection and Solution DesignNov 10 – Nov 23 · 2 wk · 0/5
Vendor Selection and Solution Design
Compliance Finalization, Configuration and ReadinessNov 24 – Dec 14 · 3 wk · 0/5
Compliance Finalization, Configuration and Readiness
Training, Go-Live and StabilizationDec 15 – Dec 28 · 2 wk · 0/5
Training, Go-Live and Stabilization
PlannedIn progressCompletedBlockedMilestones

Budget

Budget: €42,650
Legal, Privacy and Works Council Services · €14,900Internal Personnel · €13,800Digital Platform and Technical Implementation · €11,050Training and Employee Communications · €2,900
Legal, Privacy and Works Council Services€14,900
ItemQtyUnit priceTotal
HinSchG Legal and Compliance Consultant — reporting workflow, seven-day acknowledgement, three-month-and-seven-day feedback deadline, escalation and anti-retaliation requirements (Phase 2)4 Person days€1,100€4,400
Data Protection Consultant / DPO Support — confidentiality, access rights, retention rules, legal basis, data subject handling and DPIA screening or completion (Phases 2–5)4 Person days€1,000€4,000
GDPR Article 28 Data Processing Agreement Counsel — vendor contract review, negotiation and signature before processing starts, targeted for Week 8 (Phases 4–5)2 Person days€1,000€2,000
Works Council Consultant — consultation preparation, employee-monitoring assessment, access-log review and agreement support (Phase 3)3 Person days€900€2,700
Operating Procedure Documentation Consultant — investigation roles, confidentiality procedures, case handover, substitute arrangements and deadline-monitoring instructions (Phases 2–3)2 Person days€900€1,800
Internal Personnel€13,800
ItemQtyUnit priceTotal
Project Manager — mobilization, governance, schedule and go-live coordination (Phases 1–6)7 Person days€850€5,950
Internal Reporting Office Lead — case ownership, escalation model, substitutes and statutory deadline controls (Phases 1–6)8 Person days€700€5,600
IT and Information Security Administrator — identity and access setup, notifications, logging and technical readiness (Phases 4–5)3 Person days€750€2,250
Digital Platform and Technical Implementation€11,050
ItemQtyUnit priceTotal
Digital Whistleblowing Platform License and Provider Onboarding — secure reporting channel, first-year subscription and standard configuration support1 Flat rate€7,500€7,500
Platform Configuration and User Acceptance Testing Specialist — role-based access, restricted routing, notifications, statutory deadline reminders and test cases (Phases 4–5)3 Person days€850€2,550
Security, Availability and Accessibility Validation — authentication, audit logging, mobile access, shift-worker access and outage workaround review1 Flat rate€1,000€1,000
Training and Employee Communications€2,900
ItemQtyUnit priceTotal
Reporting Office and Manager Training Facilitator — intake, confidentiality, investigation handoff, anti-retaliation and deadline management (Phase 6)2 Person days€900€1,800
Employee Information Package — multilingual notices, intranet content, posters and communication materials for 250 employees, including non-desk and shift workers1 Flat rate€1,100€1,100

Risks

High

Statutory response deadlines are missed

If the internal reporting office lacks a named case owner, substitute, timestamped workflow and automated reminders by Week 10, the company may fail to acknowledge reports within seven days or provide feedback within three months and seven days after go-live.

Countermeasure: The Internal Reporting Office Lead and Legal/Compliance will define the statutory workflow and escalation rules in Weeks 2–3, configure deadline alerts by Week 9, test them during Week 10 user acceptance testing, and monitor every live case daily during the first month.
High

Confidentiality or restricted-access controls fail

If platform administrators, managers or email recipients receive unnecessary report details, or if role-based access and audit logging are not approved by Week 8 and tested by Week 10, the identity of a reporter or reported person could be exposed.

Countermeasure: The DPO and IT Security will approve a least-privilege access matrix, confidential notification design, authentication controls and audit logging by Week 8; the Reporting Office Lead will complete access testing and remove inappropriate permissions before the Week 12 go-live.
High

DPIA or external-provider contract is incomplete

If an external platform or ombudsperson is selected in Weeks 6–7 and the DPIA assessment remains unresolved or the GDPR Article 28 data processing agreement is not signed by the end of Week 8, processing of report data may begin without the required privacy controls and delay go-live.

Countermeasure: The DPO and Legal/Compliance will start provider due diligence during Week 6, document the DPIA screening decision or complete the DPIA by Week 8, and sign the Article 28 agreement by the end of Week 8; IT will block production use until the compliance gate is passed.
High

Works council consultation delays implementation

If the works council has unresolved concerns about employee monitoring, access logs, investigation workflows or employee rights by the end of Week 5, required consultation or co-determination may prevent configuration or launch of the digital channel.

Countermeasure: HR, Legal/Compliance and the Internal Reporting Office Lead will provide the process and technical design to the works council at the start of Week 4, document all monitoring implications and required safeguards, and escalate unresolved issues to the Managing Director before the Week 5 approval milestone.
Medium

Shift workers and production employees cannot use or trust the channel

If non-desk employees, shift workers or employees with language or mobile-access needs have not received accessible instructions and anti-retaliation assurances by Week 11, reporting volumes may be suppressed and employees may use unsafe informal escalation routes.

Countermeasure: HR and Communications will prepare multilingual, mobile-accessible and on-site information for all 250 employees by Week 10, deliver shift-based briefings in Week 11, and have the Reporting Office Lead test the channel with representative manufacturing employees before launch.
Medium

Platform outage or operational failure disrupts reporting

If the provider fails user acceptance testing, lacks an agreed service level, or has no manual fallback and escalation route by Week 10, employees may be unable to submit reports or statutory deadlines may be missed during an outage.

Countermeasure: IT and Information Security will assess availability, backup, incident notification and recovery controls during Weeks 6–8, require an outage procedure and fallback intake route in the provider contract, and test the fallback during Week 10 before approving go-live.

Stakeholders

ES

Executive Sponsor / Managing Director

Approves scope, budget, risk acceptance and the final go-live decision.

Involve: From Phase 1 and at each governance or readiness gate
IR

Internal Reporting Office Lead

Owns report intake, case assessment, confidentiality, investigation coordination and statutory deadline compliance.

Involve: From Phase 1 through stabilization
LA

Legal and Compliance

Interprets the German Whistleblower Protection Act and defines compliant workflows, escalation paths and investigation procedures.

Involve: From Phase 1, with continued review through go-live
DP

Data Protection Officer

Reviews legal basis, access restrictions, retention, data-subject handling, DPIA requirements and provider processing arrangements.

Involve: From Phase 2 and before configuration or processing begins
WC

Works Council

Evaluates employee-monitoring implications and participates in consultation or co-determination concerning the system and operating model.

Involve: From Phase 3, before technical and procedural decisions are finalized
IA

IT and Information Security

Assesses platform security, authentication, access controls, audit logging, configuration and technical readiness.

Involve: From Phase 4 through testing and go-live
PP

Platform Provider or External Ombudsperson

Supplies the reporting channel or intake service, supports configuration and signs the required Article 28 agreement where applicable.

Involve: From Phase 4 and before any personal data is processed
HC

HR, Communications and Employee Representatives

Coordinate training, anti-retaliation messaging and accessible, multilingual communication for office and shift-based employees.

Involve: From Phase 5 through launch and stabilization

Compliance

Mandatory

Establish and document the internal reporting office, including its mandate, impartial case handling, conflict-of-interest rules, substitute arrangements and escalation responsibilities under the German Whistleblower Protection Act (HinSchG).

Legal/Compliance and Internal Reporting Office Lead Weeks 1–5; operate from go-live
Mandatory

Define confidentiality, role-based access, identity protection, permitted disclosures, audit logging and retention/deletion rules for reports and investigation records in accordance with the HinSchG and GDPR.

DPO, Internal Reporting Office Lead and IT Security Weeks 2–3 design; finalize by end of Week 8, four weeks before go-live
Mandatory

Screen the reporting channel and investigation process for a GDPR Article 35 data protection impact assessment and complete the DPIA if the processing is likely to create a high risk to individuals. Record the decision before production processing begins.

Data Protection Officer Weeks 2–3 screening; complete or approve outcome by end of Week 8
Mandatory

Where an external digital platform or ombudsperson processes personal data on the company’s behalf, complete due diligence and sign the GDPR Article 28 data processing agreement before processing starts and no later than the end of Week 8, two to four weeks before go-live.

Legal/Compliance, DPO and Procurement/Managing Director Weeks 6–8
Mandatory

Complete works council consultation and any required co-determination for the digital reporting channel, access logs, employee information and related technical facility, including documented resolution of open points.

HR, Legal/Compliance and Works Council Weeks 4–5
Mandatory

Implement GDPR privacy-by-design and security controls, including least privilege, strong authentication, secure transmission and storage, provider incident notification, backup/recovery and breach-response procedures, aligned with the company information-security policy and applicable ISO 27001 or BSI controls.

IT and Information Security with DPO Weeks 6–10; monitor after go-live
Mandatory

Provide all 250 employees with clear, accessible information on the internal reporting channel, confidentiality, anti-retaliation protections, permitted report subjects, external reporting options and how to use the channel, with multilingual and shift-worker delivery; train the reporting office and designated investigators.

HR, Communications and Internal Reporting Office Lead Weeks 10–11; refresh after stabilization
Mandatory

Define confidentiality, access rights and retention of reports, check whether a DPIA is needed

Data protection officer
Optional

Sign a data processing agreement with the platform provider or ombudsperson

Compliance / data protection

Milestones

  1. Week 1

    Approved project charter naming the sponsor and reporting office lead, with confirmed scope, budget and week-12 go-live date.

    Depends on: Sponsor appointment, governance confirmation and initial scope approval
  2. Week 3

    Approved requirements baseline containing the statutory process, deadline controls, preliminary access and retention model, and documented DPIA screening decision.

    Depends on: Approved project charter and Legal, Compliance and DPO input
  3. Week 5

    Approved operating model and documented Works Council consultation outcome, including closure of required process and co-determination actions.

    Depends on: Approved requirements baseline and completed works council consultation
  4. Week 7

    Selected provider or ombudsperson with approved solution design, configuration blueprint and documented determination of the applicable data-processing contract model.

    Depends on: Approved operating model, vendor assessment and security review
  5. Week 10

    Compliance and technical readiness gate passed: confidentiality and retention rules approved, DPIA completed or documented as not required, Article 28 agreement signed by Week 8 where applicable, and user acceptance testing passed.

    Depends on: Provider selection, finalized privacy documentation, completed configuration and successful testing
  6. Week 12

    Digital reporting channel live in Week 12, required personnel trained, all 250 employees informed and an initial monitoring log established for statutory deadlines and confidentiality incidents.

    Depends on: Readiness-gate approval, completed training and employee communication

How this plan was created

This plan was created by PathHub AI from a single description: “Set up a whistleblowing system under the German Whistleblower Protection Act at a manufacturing company with 250 employees: internal reporting office, digital reporting channel, deadlines and process, data protection, works council and employee information. Start in three months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.

Obligations

Obligations with lead time: what many think of too late

These obligations are typically triggered by the introduction of a whistleblowing system (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.

Set up the internal reporting channel, appoint the responsible persons and define the process with deadlines (HinSchG)
Required 4–8 weeks before go-livestatutory
Rule & evidence

Why: The channel must work independently, confidentially and with fixed deadlines.

Legal basis: HinSchG: internal reporting channel from 50 employees; acknowledgement within 7 days, feedback within 3 months (Sec. 17); a missing channel is subject to fines.

Rule from the compliance library
Whistleblower Protection Act
Criteria
  • Internal reporting office set up — written, phone, in-person on request
  • Acknowledgement within 7 days, feedback within 3 months
  • Confidentiality of whistleblower identity guaranteed
  • Case files retained for 3 years

If breached: Fines up to €50,000 for missing reporting office. Obstructing a report or retaliation up to €500,000. Plus damages liability.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Define confidentiality, access rights and retention of reports, check whether a DPIA is needed
Required 2–4 weeks before go-liveguide value
Rule & evidence

Why: Reports contain highly sensitive data about whistleblowers and accused persons.

Rule from the compliance library
GDPR (General Data Protection Regulation)
Criteria
  • Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
  • Complete record of processing activities (Art. 30) for all processes
  • Data Processing Agreements (DPA) with all sub-processors
  • Data Protection Impact Assessment (DPIA) for high-risk processing
  • Technical and organisational measures (TOM) documented

If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Sign a data processing agreement with the platform provider or ombudsperson
Important 2–4 weeks before go-livestatutory
Rule & evidence

Why: External channels process the reports on your behalf.

Applies: if an external platform or ombudsperson is used

Legal basis: GDPR Art. 28: contract before processing starts.

Rule from the compliance library
Cloud Contract Law
Criteria
  • Data Processing Agreement (DPA) with cloud provider
  • SLA with availability, RPO, RTO
  • Exit and portability clause
  • Data localisation and transfer mechanism (SCC / adequacy)

If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Involve the works council in the reporting procedure and platform
Important 4–8 weeks before go-liveguide value
Rule & evidence

Why: Procedural rules affect workplace conduct.

Applies: only if a works council exists

Legal basis: Depending on the design (conduct rules, technical platform), co-determination rights under Sec. 87(1) No. 1 and 6 BetrVG may apply.

Rule from the compliance library
Works Constitution Act (BetrVG)
Criteria
  • Enable works council election from 5 eligible employees upward
  • Co-determination on working time, monitoring systems, IT rollouts (§87)
  • Hearing before every dismissal (§102) — written with reasons
  • Balance-of-interests and social plan on operational changes (§111)

If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
All typical initiatives and their obligations: planning internal projects

Frequently asked questions

How long does the introduction of a whistleblowing system take?
In the example plan, the introduction of a whistleblowing system takes 12 weeks in 6 phases. The actual duration depends on company size, starting point and available resources — with your company context PathHub adjusts the schedule accordingly.
What does the introduction of a whistleblowing system cost?
The example plan estimates about €42,650, split into 13 budget line items with quantity and unit price. The largest items are Legal, Privacy and Works Council Services, Internal Personnel. This is an AI estimate as a starting point, not a quote.
What are the risks of the introduction of a whistleblowing system?
The plan lists 6 risks with countermeasures. Rated highest: Statutory response deadlines are missed; Confidentiality or restricted-access controls fail; DPIA or external-provider contract is incomplete.
Who needs to be involved in the introduction of a whistleblowing system?
Among others, the plan includes these people: Executive Sponsor / Managing Director, Internal Reporting Office Lead, Legal and Compliance, Data Protection Officer, Works Council, IT and Information Security. For each role it states why and from when to involve them.
Can I adapt the plan to my company?
Yes. Open the plan in PathHub without signing up, adjust phases and tasks or describe your own initiative — with company context (departments, approval processes, works council, compliance requirements) every further plan gets more precise.

More project plan examples

Adapt this plan to your company

Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.

Open plan →