Project plan for the introduction of a whistleblowing system
Under the German Whistleblower Protection Act, companies with 50 or more employees need an internal reporting office with fixed deadlines for acknowledgement and feedback. Besides the technology, confidentiality, data protection and the works council matter. This plan shows the rollout at a manufacturer with 250 employees.
No sign-up · opens instantly · 12 Weeks · 6 Phases · 29 Tasks · Budget approx. €42,650
This is how the plan looks in PathHub — click through the tabs or tick off tasks.
German Whistleblowing System Implementation
This project will establish an internal reporting office and secure digital whistleblowing channel for a German manufacturing company with 250 employees. The operating model will comply with the German Whistleblower Protection Act, including confidentiality, restricted access, acknowledgement within seven days and feedback within three months and seven days. GDPR requirements, including retention rules, DPIA screening and an Article 28 data processing agreement where applicable, will be completed before processing begins. Works council consultation, role-based training and accessible communication for office, non-desk and shift employees will support the week-12 launch.
Phases
Phase 1: Mobilization and Scope Definition
Establish project ownership, confirm the implementation scope and align all decision-making roles. The phase creates the approved foundation for a week-12 go-live.
Phase 2: Legal and Process Requirements Baseline
Translate the German Whistleblower Protection Act and GDPR requirements into an approved reporting process. This includes statutory response deadlines, initial confidentiality controls and the formal assessment of whether a DPIA is required.
Phase 3: Operating Model and Works Council Consultation
Define how reports will be handled independently and confidentially, including investigation responsibilities, substitutes and anti-retaliation safeguards. Obtain the Works Council’s input and complete the required consultation or agreement before technical implementation proceeds.
Phase 4: Vendor Selection and Solution Design
Select or confirm the digital reporting channel or external ombudsperson and translate the approved requirements into a secure implementation design. The phase also determines whether an external processor will require a GDPR Article 28 data processing agreement.
Phase 5: Compliance Finalization, Configuration and Readiness
Complete the statutory privacy and confidentiality controls, configure the channel and validate the solution before employee launch. All external processing prerequisites must be completed no later than Week 8, providing approximately four weeks before the planned Week-12 go-live.
Phase 6: Training, Go-Live and Stabilization
Prepare the reporting office and relevant managers, inform all employees and launch the channel in Week 12. Early-case monitoring verifies confidentiality, accessibility and compliance with statutory response deadlines.
Timeline
Budget
| Item | Qty | Unit price | Total |
|---|---|---|---|
| HinSchG Legal and Compliance Consultant — reporting workflow, seven-day acknowledgement, three-month-and-seven-day feedback deadline, escalation and anti-retaliation requirements (Phase 2) | 4 Person days | €1,100 | €4,400 |
| Data Protection Consultant / DPO Support — confidentiality, access rights, retention rules, legal basis, data subject handling and DPIA screening or completion (Phases 2–5) | 4 Person days | €1,000 | €4,000 |
| GDPR Article 28 Data Processing Agreement Counsel — vendor contract review, negotiation and signature before processing starts, targeted for Week 8 (Phases 4–5) | 2 Person days | €1,000 | €2,000 |
| Works Council Consultant — consultation preparation, employee-monitoring assessment, access-log review and agreement support (Phase 3) | 3 Person days | €900 | €2,700 |
| Operating Procedure Documentation Consultant — investigation roles, confidentiality procedures, case handover, substitute arrangements and deadline-monitoring instructions (Phases 2–3) | 2 Person days | €900 | €1,800 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Project Manager — mobilization, governance, schedule and go-live coordination (Phases 1–6) | 7 Person days | €850 | €5,950 |
| Internal Reporting Office Lead — case ownership, escalation model, substitutes and statutory deadline controls (Phases 1–6) | 8 Person days | €700 | €5,600 |
| IT and Information Security Administrator — identity and access setup, notifications, logging and technical readiness (Phases 4–5) | 3 Person days | €750 | €2,250 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Digital Whistleblowing Platform License and Provider Onboarding — secure reporting channel, first-year subscription and standard configuration support | 1 Flat rate | €7,500 | €7,500 |
| Platform Configuration and User Acceptance Testing Specialist — role-based access, restricted routing, notifications, statutory deadline reminders and test cases (Phases 4–5) | 3 Person days | €850 | €2,550 |
| Security, Availability and Accessibility Validation — authentication, audit logging, mobile access, shift-worker access and outage workaround review | 1 Flat rate | €1,000 | €1,000 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Reporting Office and Manager Training Facilitator — intake, confidentiality, investigation handoff, anti-retaliation and deadline management (Phase 6) | 2 Person days | €900 | €1,800 |
| Employee Information Package — multilingual notices, intranet content, posters and communication materials for 250 employees, including non-desk and shift workers | 1 Flat rate | €1,100 | €1,100 |
Risks
Statutory response deadlines are missed
If the internal reporting office lacks a named case owner, substitute, timestamped workflow and automated reminders by Week 10, the company may fail to acknowledge reports within seven days or provide feedback within three months and seven days after go-live.
Confidentiality or restricted-access controls fail
If platform administrators, managers or email recipients receive unnecessary report details, or if role-based access and audit logging are not approved by Week 8 and tested by Week 10, the identity of a reporter or reported person could be exposed.
DPIA or external-provider contract is incomplete
If an external platform or ombudsperson is selected in Weeks 6–7 and the DPIA assessment remains unresolved or the GDPR Article 28 data processing agreement is not signed by the end of Week 8, processing of report data may begin without the required privacy controls and delay go-live.
Works council consultation delays implementation
If the works council has unresolved concerns about employee monitoring, access logs, investigation workflows or employee rights by the end of Week 5, required consultation or co-determination may prevent configuration or launch of the digital channel.
Shift workers and production employees cannot use or trust the channel
If non-desk employees, shift workers or employees with language or mobile-access needs have not received accessible instructions and anti-retaliation assurances by Week 11, reporting volumes may be suppressed and employees may use unsafe informal escalation routes.
Platform outage or operational failure disrupts reporting
If the provider fails user acceptance testing, lacks an agreed service level, or has no manual fallback and escalation route by Week 10, employees may be unable to submit reports or statutory deadlines may be missed during an outage.
Stakeholders
Executive Sponsor / Managing Director
Approves scope, budget, risk acceptance and the final go-live decision.
Internal Reporting Office Lead
Owns report intake, case assessment, confidentiality, investigation coordination and statutory deadline compliance.
Legal and Compliance
Interprets the German Whistleblower Protection Act and defines compliant workflows, escalation paths and investigation procedures.
Data Protection Officer
Reviews legal basis, access restrictions, retention, data-subject handling, DPIA requirements and provider processing arrangements.
Works Council
Evaluates employee-monitoring implications and participates in consultation or co-determination concerning the system and operating model.
IT and Information Security
Assesses platform security, authentication, access controls, audit logging, configuration and technical readiness.
Platform Provider or External Ombudsperson
Supplies the reporting channel or intake service, supports configuration and signs the required Article 28 agreement where applicable.
HR, Communications and Employee Representatives
Coordinate training, anti-retaliation messaging and accessible, multilingual communication for office and shift-based employees.
Compliance
Establish and document the internal reporting office, including its mandate, impartial case handling, conflict-of-interest rules, substitute arrangements and escalation responsibilities under the German Whistleblower Protection Act (HinSchG).
Define confidentiality, role-based access, identity protection, permitted disclosures, audit logging and retention/deletion rules for reports and investigation records in accordance with the HinSchG and GDPR.
Screen the reporting channel and investigation process for a GDPR Article 35 data protection impact assessment and complete the DPIA if the processing is likely to create a high risk to individuals. Record the decision before production processing begins.
Where an external digital platform or ombudsperson processes personal data on the company’s behalf, complete due diligence and sign the GDPR Article 28 data processing agreement before processing starts and no later than the end of Week 8, two to four weeks before go-live.
Complete works council consultation and any required co-determination for the digital reporting channel, access logs, employee information and related technical facility, including documented resolution of open points.
Implement GDPR privacy-by-design and security controls, including least privilege, strong authentication, secure transmission and storage, provider incident notification, backup/recovery and breach-response procedures, aligned with the company information-security policy and applicable ISO 27001 or BSI controls.
Provide all 250 employees with clear, accessible information on the internal reporting channel, confidentiality, anti-retaliation protections, permitted report subjects, external reporting options and how to use the channel, with multilingual and shift-worker delivery; train the reporting office and designated investigators.
Define confidentiality, access rights and retention of reports, check whether a DPIA is needed
Sign a data processing agreement with the platform provider or ombudsperson
Milestones
- Week 1
Approved project charter naming the sponsor and reporting office lead, with confirmed scope, budget and week-12 go-live date.
Depends on: Sponsor appointment, governance confirmation and initial scope approval - Week 3
Approved requirements baseline containing the statutory process, deadline controls, preliminary access and retention model, and documented DPIA screening decision.
Depends on: Approved project charter and Legal, Compliance and DPO input - Week 5
Approved operating model and documented Works Council consultation outcome, including closure of required process and co-determination actions.
Depends on: Approved requirements baseline and completed works council consultation - Week 7
Selected provider or ombudsperson with approved solution design, configuration blueprint and documented determination of the applicable data-processing contract model.
Depends on: Approved operating model, vendor assessment and security review - Week 10
Compliance and technical readiness gate passed: confidentiality and retention rules approved, DPIA completed or documented as not required, Article 28 agreement signed by Week 8 where applicable, and user acceptance testing passed.
Depends on: Provider selection, finalized privacy documentation, completed configuration and successful testing - Week 12
Digital reporting channel live in Week 12, required personnel trained, all 250 employees informed and an initial monitoring log established for statutory deadlines and confidentiality incidents.
Depends on: Readiness-gate approval, completed training and employee communication
How this plan was created
This plan was created by PathHub AI from a single description: “Set up a whistleblowing system under the German Whistleblower Protection Act at a manufacturing company with 250 employees: internal reporting office, digital reporting channel, deadlines and process, data protection, works council and employee information. Start in three months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.
Obligations with lead time: what many think of too late
These obligations are typically triggered by the introduction of a whistleblowing system (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.
Rule & evidence
Why: The channel must work independently, confidentially and with fixed deadlines.
Legal basis: HinSchG: internal reporting channel from 50 employees; acknowledgement within 7 days, feedback within 3 months (Sec. 17); a missing channel is subject to fines.
- Internal reporting office set up — written, phone, in-person on request
- Acknowledgement within 7 days, feedback within 3 months
- Confidentiality of whistleblower identity guaranteed
- Case files retained for 3 years
If breached: Fines up to €50,000 for missing reporting office. Obstructing a report or retaliation up to €500,000. Plus damages liability.
Rule & evidence
Why: Reports contain highly sensitive data about whistleblowers and accused persons.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: External channels process the reports on your behalf.
Applies: if an external platform or ombudsperson is used
Legal basis: GDPR Art. 28: contract before processing starts.
- Data Processing Agreement (DPA) with cloud provider
- SLA with availability, RPO, RTO
- Exit and portability clause
- Data localisation and transfer mechanism (SCC / adequacy)
If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.
Rule & evidence
Why: Procedural rules affect workplace conduct.
Applies: only if a works council exists
Legal basis: Depending on the design (conduct rules, technical platform), co-determination rights under Sec. 87(1) No. 1 and 6 BetrVG may apply.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Frequently asked questions
More project plan examples
Adapt this plan to your company
Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.
Open plan →