Workplace Investigations

Contributing Editors


Workplace investigations are growing in number, size and complexity. Employers are under greater scrutiny as of the importance of ESG rises. Regulated industries such as finance, healthcare and legal face additional hurdles, but public scrutiny of businesses and how they treat their people across the board has never been higher. Conducting a fair and thorough workplace investigation is therefore critical to the optimal operation, governance and legal exposure of every business.

IEL’s Guide to Workplace Investigations examines key issues that organisations need to consider as they initiate, conduct and conclude investigations in 29 major jurisdictions around the world.  

Learn more about the response taken in specific countries or build your own report to compare approaches taken around the world.

Choose countries

 

Choose questions

Choose the questions you would like answering, or choose all for the full picture.

09. What additional considerations apply when the investigation involves whistleblowing?

09. What additional considerations apply when the investigation involves whistleblowing?

Flag / Icon

Australia

  • at People + Culture Strategies
  • at People + Culture Strategies
  • at People + Culture Strategies

A complaint will be a whistleblowing complaint where a complainant has reasonable grounds to suspect that the information they are disclosing about the organisation concerns misconduct or an improper state of affairs or circumstances. The information can be about the organisation or an officer or employee of the organisation engaging in conduct that:

  • breaches the Corporations Act 2001 (Cth);
  • breaches other financial sector laws;
  • breaches any other law punishable by 12 months’ imprisonment; or
  • represents a danger to the public or the financial system.

Since 2020, all public companies, large proprietary companies and trustees of registrable superannuation entities in Australia are required to have a whistleblower policy. Employers conducting an investigation will need to follow the processes outlined in their policy.

One of the key differences when conducting an investigation that involves whistleblowing is identity protection and the ability of the whistleblower to disclose anonymously and remain anonymous.

Last updated on 15/09/2022

Flag / Icon

Austria

  • at GERLACH
  • at GERLACH Rechtsanwälte

The provisions of the Whistleblowing Directive must be respected. In Austria, these have been implemented through the Whistleblower Protection Act (HSchG). If the whistleblower or the persons concerned fall within the scope of the Directive, their identity must be protected. Only authorised persons may access the report. Retaliatory measures are invalid or must be reversed. Within a maximum of seven days, the whistleblower must receive a confirmation of his or her complaint. Feedback to the whistleblower must then be provided within a maximum of three months.

Last updated on 29/09/2023

Flag / Icon

Belgium

  • at Van Olmen & Wynant

If the investigation is based on a whistleblower report that falls under the scope of the upcoming rules, the investigators are bound by a strict duty of confidentiality, especially regarding the identity of the report. The rules also provide some procedural deadlines for feeding back to the reporter. Within seven days of receiving the report through an internal reporting channel, the reporting manager needs to send a receipt to the whistleblower. From that moment, the reporting manager has three months to investigate the report and give feedback and an adequate follow-up to the report. Next, the rules offer strong protection against any retaliatory measures the reporter may experience. Regardless, these rules are mostly intended to offer the necessary protection for whistleblowers and to ensure that companies take necessary investigative steps following a report, but they do not include much information about the actual procedure of the investigation besides certain deadlines, nor do they deal with other employees involved (or under investigation).

Last updated on 15/09/2022

Flag / Icon

Brazil

  • at CGM
  • at CGM

If the investigation involves matters within the scope of a specific whistleblowing policy, the policy rules should prevail against the general investigation rules if there is a conflict.

Last updated on 14/09/2023

Flag / Icon

China

  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng

In practice, the following factors to be considered will be: (1) verification of the informant's identity; (2) whether the informant has any conflict of interest with the reported employee or whether it will affect the objectivity of their reporting; (3) how to persuade the informant to provide more information or evidence, or to cooperate in court as a witness; (4) how to increase the admissibility of evidence when the informant refuses to cooperate in court as a witness or fails to provide original evidence; (5) how to improve the evidence chain and protect the informant from being attacked or retaliated by the informant, etc.

Last updated on 29/11/2023

Flag / Icon
Finland

Finland

  • at Roschier
  • at Roschier

In respect of data protection, the processing of personal data in whistleblowing systems is considered by the Finnish Data Protection Ombudsman (DPO) as requiring a data protection impact assessment (DPIA).

Last updated on 15/09/2022

Flag / Icon

France

  • at Bredin Prat
  • at Bredin Prat

Evidence obtained in the context of an investigation must specify who provided it and the date it was provided. No retaliatory measures may be taken against the whistleblower for the act of whistleblowing.

In certain cases, the whistleblower report must be forwarded to the judicial authorities (eg, when there is an obligation to assist persons in imminent danger, for serious offences or a disclosure that a vulnerable person is in danger (ie, minors under 15 or a person who is unable to protect themselves)).

Last updated on 15/09/2022

Flag / Icon

Germany

  • at Hengeler Mueller
  • at Hengeler Mueller
  • at Hengeler Mueller

In 2023, Germany has implemented the EU Whistleblowing Directive into national law with the German Whistleblower Protection Act (HinSchG).

The German Whistleblower Protection Act provides that companies with at least 50 employees must establish internal reporting channels as further set out in the law. Among other things, the confidentiality of the whistleblower as well as of the individuals affected by the report must be protected.

Further, whistleblowers must be protected from negative consequences that may arise from their reports. If the employment of a whistleblower were terminated or if the whistleblower were to be denied promotion after reporting a violation, the employer would have to prove that this was not related to the whistleblowing but was based on justified reasons.

Employers should  familiarise themselves with the provisions of the new law.

Last updated on 15/09/2022

Flag / Icon

Greece

  • at Karatzas & Partners
  • at Karatzas & Partners
  • at Karatzas & Partners
  • at Karatzas & Partners

L. 4990/2022 includes specific requirements regarding, among other things, the procedure of receiving and investigating respective reports, confidentiality issues (especially regarding the identity of the whistleblower), data protection issues (including restrictions to the right of access) and the employer’s right to keep a record of the relevant complaint and investigation. Such provisions are expected to be further detailed by Ministerial Decisions in future.

Last updated on 03/04/2023

Flag / Icon

Hong Kong

  • at Slaughter and May
  • at Slaughter and May
  • at Slaughter and May

Hong Kong does not have a comprehensive legislative framework relating to whistleblowing. Therefore, in general, employers are free to establish whistleblowing policies and procedures and confer such protections on whistleblowers as they see fit. That said, companies listed on the Main Board of the SEHK are expected to establish a whistleblowing policy and system for employees to voice concerns anonymously about possible improprieties in the companies’ affairs. If a listed issuer deviates from this practice, it must explain the deviation.[1]

When an investigation involves whistleblowing, the employer needs to comply with the relevant policy and system and provide the whistleblower with such protections as stated in the policy. The employer should not ignore a complaint simply because it was made anonymously, and should ascertain the substance of the complaint to decide whether a full-blown investigation is warranted.

In addition, the employer should seek to establish a secure communication channel with the whistleblower to gather more information about the complaint or misconduct while maintaining the confidentiality of his or her identity. If the complaint is serious, the employer may consider referring the complaint to a law enforcement agency or regulator as they would be better placed in protecting the anonymity of the whistleblower while proceeding with the investigation. That said, employers generally have no obligation to report internal wrongdoing to any external body (please see question 25 for exceptions). The employer may assess whether it is appropriate to do so on a case-by-case basis.


[1] The Corporate Governance Code, Appendix 14 of the Rules Governing the Listing of Securities on the Stock Exchange of Hong Kong Limited.

Last updated on 27/11/2023

Flag / Icon

India

  • at Trilegal
  • at Trilegal
  • at Trilegal

Indian labour legislation does not stipulate any additional considerations or requirements concerning whistleblower complaints in private organisations and these are only available if there are complaints against public servants. Further, under the Companies Act, 2013, certain companies are required to establish a “vigil mechanism” for directors and employees to report genuine concerns regarding the affairs of the company. The vigil mechanism should provide adequate safeguards against the victimisation of persons using it.

Last updated on 15/09/2022

Flag / Icon
Ireland

Ireland

  • at Ogier
  • at Ogier

Most whistleblowing policies will include a section that provides for an initial assessment of the complaint as to whether it meets the definition of a protected disclosure. This assessment, which ought to be carried out by a designated person who has been appointed to deal with disclosures, is a useful tool as some matters which may be labelled as whistleblowing may fall under the grievance procedure.

Where there are grounds, an investigation will be commenced. Under the Protected Disclosures (Amendment) Act 2022, whistleblowers are protected from penalisation for having made a protected disclosure, under the Act.

Penalisation may include; suspension, lay-off or dismissal; demotion, loss of opportunity for promotion or withholding of promotion; transfer of duties, change of location or place of work; reduction in wages or change in working hours; the imposition or administering of any discipline, reprimand or other penalty (including a financial penalty); coercion, intimidation, harassment or ostracism; or discrimination, disadvantage or unfair treatment.

If an employee (which includes trainees, volunteers, and job applicants) alleges that they have suffered penalisation as a result of making a protected disclosure, they may apply to the Circuit Court for interim relief within 21 days of the date of the last act of penalisation by the employer.

A claim for penalisation may also be brought before the WRC within six months of the alleged act of penalisation. If an employee alleges that they were dismissed for having made a protected disclosure, the potential award that the WRC can make increases from the usual unfair dismissal cap of two years’ pay to up to five years’ gross pay, based on actual loss.

Where a complaint of whistleblowing is made, employers should ensure that they appoint investigators with the appropriate knowledge and expertise to deal with such a matter and comply with the time limits set by legislation.

Last updated on 11/10/2023

Flag / Icon

Italy

  • at BonelliErede
  • at BonelliErede

The regulations on whistleblowing in the private sector were originally outlined in article 6 of Italian Legislative Decree No. 231 of 2001 (as amended by Law No. 179 of 2017), which state that the models of organisation must provide for one or more channels that allow persons in positions of representation, administration and management of the entity (and persons subject to their direction or supervision) to report unlawful conduct according to Italian Legislative Decree No. 231 of 2001 and violations of the entity’s organisational and management rules.

Currently, Italy has implemented Directive (EU) No. 1937 of 2019, which provides for the adoption of new standards of protection for whistleblowers, through the Italian Legislative Decree No. 24 of 2023 (WB Decree)[1].

In line with the Directive, the WB Decree states, inter alia, that[2]:

  • an internal whistleblowing reporting channel must be put in place by all private legal entities (and legal entities in the public sector) that have employed, during the previous year, an average of 50 employees or, even below this threshold, operate in certain industries[3] or have adopted an organizational model in accordance with Legislative Decree no. 231 of 2001;
  • the WB Decree prescriptions apply to reports concerning breaches of certain national/EU[4] legal provisions (varying depending on features such as the private or public nature of the employer and its dimensions), and not to claims or requests linked to interests of a personal nature of the reporting individuals (pertaining to their individual employment contracts or to relations with their superiors)[5];
  • whistleblowers’ reporting may take place through:
    • the company’s internal reporting channels and internal reporting procedures (with the possibility – for entities employing up to 249 employees, even if not part of the same group – to share whistleblowing reporting channels); or
    • external reporting channels and external reporting procedures established by the member states’ competent authorities (in Italy, ANAC, i.e. the National Anticorruption Authority); or
    • in certain circumstances, public disclosure;
  • whistleblowing systems must provide:
    • a duty of confidentiality regarding the whistleblowers’ identity (which generally may not be disclosed to persons other than those competent to receive or investigate on the reports, except in specific case and with the whistleblower’s consent; see also answer to question 12 below); and
    • ways of protecting collected data according to the GDPR, as well as tight deadlines for communication with whistleblowers[6]; and
    • an integrated system of protection of whistleblowers against any retaliatory action directly or indirectly linked to their reports or declarations, with a reversal of the burden of proof (meaning the employer must give proof of the non-retaliatory nature of measures adopted vis-à-vis whistleblowers); and
    • the procedures to be taken in case of anonymous whistleblowing report.

[1] The provisions of the Decree are binding since July 15, 2023, for larger companies, and as of Dec. 17, 2023, for entities employing an average of from 50 to 249 employees.

[2] This is only a brief and non-exhaustive summary of some of the main provisions under the WB Decree.

[3] In particular, companies that fall within the scope of application of EU acts listed in Annex (part I.B and II) of the WB Decree (for instance, financial services, products and markets; money laundering/terrorism prevention; transportation security; etc.)

[4] Listed in art. 2 and in Annex 1 of the WB Decree (for instance, regarding financial services, products and markets sector) or  protecting the EU financial interests or internal market.

[5] Listed in art. 2 and in Annex 1 of the WB Decree (for instance, regarding financial services, products and markets sector) or protecting the EU financial interests or internal market.

[6] In greater detail: (i) a notice acknowledging the receipt of the WB report must be released within seven days; (ii) contacts must be kept with the whistleblower for any additions needed (if the identity is known); and (iii) within three months of the notice of receipt of the report, a follow-up notice must be given to the whistleblower (which may also be non-definitive, with a status update on activities in progress).

Last updated on 10/01/2024

Flag / Icon

Japan

  • at Mori Hamada & Matsumoto

See question 4 regarding amendments to the Whistleblower Protection Act.

The person designated as a whistleblower response service employee must not divulge the name, employee ID number, or other information that would allow a whistleblower to be identified without a justifiable reason, and there is a criminal penalty of up to 300,000 yen for violating this duty of confidentiality.

Last updated on 15/09/2022

Flag / Icon

Netherlands

  • at De Brauw Blackstone Westbroek
  • at De Brauw Blackstone Westbroek
  • at De Brauw Blackstone Westbroek

The former Act on the House for Whistleblowers already provided for several preconditions that a whistleblowing procedure must meet. For example, internal reporting lines must be laid down, as well as how the internal report is handled, and an obligation of confidentiality and the opportunity to consult an advisor in confidence must be applied. Employers are obliged to share the whistleblowing policy with employees, including information about the employee's legal protection. The employee who reports a suspicion of wrongdoing in good faith may not be disadvantaged in their legal position because of the report (section17e/ea Act House of Whistleblowers).

The starting point is that an employee must first report internally, unless this cannot reasonably be expected. If the employee does not report internally first, the House for Whistleblowers does not initiate an investigation. The House for Whistleblowers was established on 1 July 2016 and has two main tasks: advising employees on the steps to take and conducting an investigation in response to a report.

The Act on the Protection of Whistleblowers, which entered into force in 2023, introduced several changes, of which the most relevant are:

  • Abolition of mandatory internal reporting: the obligation to report internally first is abolished. Direct external reporting is allowed, such as to the House for Whistleblowers or another competent authority. When reporting externally, the reporter retains his protection. However, reporting internally first remains preferable and will be encouraged by the employer as much as possible.
  • Expansion of prohibition on detriment: the prohibition on detriment already included prejudicing the legal position of the reporter, such as suspension, dismissal, demotion, withholding of promotion, reduction of salary or change of work location. It now also includes all forms of disadvantage, such as being blacklisted, refusing to give a reference, bullying, intimidation and exclusion. 
  • Stricter time limit requirements for internal reporting: the reporter must receive an acknowledgement of receipt of the report within seven days and the reporter must receive information from the employer on the assessment of their report within a reasonable period, not exceeding three months.
  • Extension of the circle of protected persons: not just employees, but third parties who are in a working relationship with the employer are now also protected, such as freelancers, interns, volunteers, suppliers, shareholders, job applicants and involved family members and colleagues.
Last updated on 27/11/2023

Flag / Icon
Nigeria

Nigeria

  • at Bloomfield LP

Consideration must be given to the confidentiality or anonymity of the whistleblower, when an investigation involves whistleblowing.

Last updated on 15/09/2022

Flag / Icon

Philippines

  • at Villaraza & Angangco

Since there is no specific law that governs whistleblowing, matters that involve whistleblowing will be governed by company policy.

Last updated on 26/01/2023

Flag / Icon

Poland

  • at WKB Lawyers
  • at WKB Lawyers
  • at WKB Lawyers

In principle, an internal investigation should be conducted in the same way, regardless of whether it is initiated following a whistleblowing report, an audit, or a monitoring result. This includes anything related to confidentiality, fairness, data privacy protection, etc.

If an internal investigation is initiated following a whistleblower report, the main characteristic that is imposed by the EU Directive on the protection of persons who report breaches of EU Law (Whistleblowers Directive) and that will also be available under the Draft Law is for the organisation (employer) to communicate (if practicable) the report to the whistleblower. Furthermore, the whistleblower should receive feedback as to whether follow-up actions were undertaken following the report and, if yes – what actions were taken – and if not – why the follow-up actions were not taken.

Last updated on 20/04/2023

Flag / Icon

Portugal

  • at Uría Menéndez - Proença de Carvalho

The treatment of whistleblowers and their reports is laid down in various specific laws in Portugal.

Law 93/2021

Under Law 93/2021, a whistleblower of work-related offences must not be retaliated against. Furthermore, imposing disciplinary penalties on the whistleblower within two years after their disclosure is presumed to be abusive. The whistleblower is entitled to judicial protection and may benefit from the witness protection programme within criminal proceedings. Additionally, reports will be recorded for five years and, where applicable, personal data that is not relevant for the handling of a specific report will not be collected or, if accidentally collected, will be deleted immediately.

Corruption and Financial Crime Law (Law 19/2008)

Under Law 19/2008, a whistleblower must not be hampered. Furthermore, the imposition of disciplinary penalties on a whistleblower within one year following the communication of the infraction is presumed to be unfair.

Additionally, whistleblowers are entitled to:

  • anonymity until the pressing of charges;
  • be transferred following the pressing of charges; and
  • benefit from the witness protection programme within criminal proceedings (remaining anonymous upon the verification of specific circumstances).

Money Laundering and Terrorism Financing Law (Law 83/2017)

Law 83/2017, which sets forth the legal framework to prevent, detect and effectively combat money laundering and terrorism financing, applies to financial entities and legal or natural persons acting in the exercise of their professional activities (eg, auditors and lawyers)(collectively, obliged entities).

According to article 20 of Law 83/2017, individuals who learn of any breach through their professional duties must report those breaches to the company's supervisory or management bodies. As a result, the obliged entities must refrain from threatening or taking hostile action against the whistleblower and, in particular, unfair treatment within the workplace. Specifically, the report cannot be used as grounds for disciplinary, civil or criminal action against the whistleblower (unless the communication is deliberately and clearly unjustified).

Legal Framework of Credit Institutions and Financial Companies (RGICSF)

Credit institutions must implement internal-reporting mechanisms that must guarantee the confidentiality of the information received and the protection of the personal data of the persons reporting the breaches and the persons charged. Under article 116-AA of RGICSF, persons who, while working in a credit institution, become aware of:

  • any serious irregularities in the management, accounting procedures or internal control of the credit institution; or
  • evidence of a breach of the duties set out in the RGICSF that may cause any financial imbalance, must communicate those circumstances to the company's supervisory body.

These communications cannot, per se, be used as grounds for disciplinary, criminal or civil liability actions brought by the credit institution against the whistleblower.

Moreover, article 116-AB of the RGICSF establishes that any person aware of compelling evidence of a breach of statutory duties may report it to the Bank of Portugal. Such communications cannot, per se, be used as grounds for disciplinary, criminal or civil liability actions brought by the credit institution against the whistleblower, unless the report is clearly unfounded.

The Bank of Portugal must ensure adequate protection of the person who has reported the breach and the person accused of breaching the applicable duties. It must also guarantee the confidentiality of the persons who have reported breaches at any given time.

Portuguese Securities Code (CVM)

Article 382 of the CVM states that financial intermediaries subject to the supervision of the Portuguese Securities Market Commission (CMVM), judicial authorities, police authorities, or respective employees must immediately inform the CMVM if they become aware of facts that qualify as crimes against the securities market or the market of other financial instruments, due to their performance, activity, or position.

Additionally, according to article 368-A of the CVM, any person aware of facts, evidence, or information regarding administrative offences under the CVM or its supplementary regulations may report them to the CMVM either anonymously or with the whistleblower's identity. The disclosure of the whistleblower's identity, as well as that of their employer, is optional. If the report identifies the whistleblower, their identity cannot be disclosed unless specifically authorised by the whistleblower, by an express provision of law or by the determination of a court.

Such communications may not be used as grounds for disciplinary, criminal, or civil liability action brought against the whistleblower, and they may not be used to demote the employee.

According to article 368-E of the CVM, the CMVM must cooperate with other authorities within the scope of administrative or judicial proceedings to protect employees against employer discrimination, retaliation or any other form of unfair treatment by the employer that may be linked to the communication to the CMVM. The whistleblower may be entitled to benefit from the witness-protection programme if an individual is charged in criminal or administrative proceedings because of their communication to the CMVM.

Last updated on 15/09/2022

Flag / Icon
Singapore

Singapore

  • at Rajah & Tann Singapore
  • at Rajah & Tann Singapore
  • at Rajah & Tann

Under the Prevention of Corruption Act 1960 and the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (CDSCA), in any civil or criminal proceeding, no witness is obliged to disclose the name or address of any informer, or disclose any information that might lead to his or her discovery concerning offences such as corruption, drug trafficking, and money laundering, save where:

  • in any proceeding for the offence, the Court, after a full inquiry into the case, is of the opinion that the informer wilfully made, in his complaint, a material statement that he knew or believed to be false or did not believe to be true; or
  • in any other proceeding, the court is of the opinion that justice cannot be fully done between the parties without the discovery of the informer.

In line with the above, employers should therefore keep the informer’s identity confidential upon receiving a complaint relating to corruption, drug trafficking, money laundering, and other serious offences prescribed in the second schedule of the CDSCA.

Last updated on 15/09/2022

Flag / Icon

South Korea

  • at Kim & Chang
  • at Kim & Chang
  • at Kim & Chang
  • at Kim & Chang

Aside from the legal obligations imposed on the company when dealing with a whistleblower who is subject to the WPA as discussed in question 1, there are also practical considerations the company should keep in mind when dealing with a whistleblower, regardless of whether the whistleblower falls under the WPA.

For example, there have been instances where an employee who raised allegations filed a complaint with Korean authorities (such as the Anti-Corruption and Civil Rights Commission (ACRC) or the Labour Office) that the company took retaliatory action against the whistleblower. The company should carefully review the legal risks before taking action, such as personnel action or civil or criminal action, against an employee who raises allegations if that employee was also involved in the wrongdoing.

Last updated on 15/09/2022

Flag / Icon

Spain

  • at Uría Menéndez
  • at Uría Menéndez

Directive (EU) 2019/1937 of the European Parliament and of the Council, of 23 October 2019, on the protection of persons who report breaches of Union law, has been implemented in Spain through Law 2/2023 (Ley 2/2023, de 20 de febrero, reguladora de la protección de las personas que informen sobre infracciones normativas y de lucha contra la corrupción). This law limits the capacity of companies to retaliate or to take any action against employees who report workplace violations or breaches of the law. Any action taken against an employee in such a position would be considered null and void if challenged in court.

Spanish law allows anonymous reports to protect whistleblowers from retaliation.

Last updated on 06/11/2023

Flag / Icon

Sweden

  • at Mannheimer Swartling
  • at Mannheimer Swartling
  • at Mannheimer Swartling

If the Swedish Whistleblowing Act governs the investigation, additional considerations apply relating to who may investigate a reported irregularity (see question 4) and the duty of confidentiality and restrictions on access to and disclosure of personal data in investigations (see questions 6, 10 and 11), as well as the rights and protections of whistleblowers.

As regards the rights and protections of whistleblowers, the following can be noted. A person reporting in a reporting channel governed by the Swedish Whistleblowing Act is protected against retaliation and restrictive measures. Thus, companies are prohibited from preventing or trying to prevent a person from reporting, and retaliating against a person who reports. Furthermore, a reporting person will not be held liable for breach of confidentiality for collecting the reported information if the person had reasonable grounds to believe that it was necessary to submit the report to expose irregularities. Under the Swedish Whistleblowing Act, any person reporting irregularities in a reporting channel established under the Swedish Whistleblowing Act may also report irregularities to designated Swedish authorities.

Last updated on 15/09/2022

Flag / Icon

Switzerland

  • at Bär & Karrer
  • at Bär & Karrer

If an employee complains to his or her superiors about grievances or misconduct in the workplace and is subsequently dismissed, this may constitute an unlawful termination (article 336, Swiss Code of Obligations). However, the prerequisite for this is that the employee behaves in good faith, which is not the case if he or she is (partly) responsible for the grievance.

Last updated on 15/09/2022

Flag / Icon

Thailand

  • at Chandler MHM
  • at Chandler MHM

It is down to the employer’s discretion and subject to the whistleblowing policy (if any) to commence the investigation resulting from a complaint from a whistleblower. Whistleblowers and those who cooperate with an investigation should be protected. Normally the employer would not try to identify the whistleblowers. Also, it is best not to reveal the identity of the witness or the source of information; otherwise, they may feel uncomfortable giving information or raising their concerns next time. Any allegations of retaliation that surface during the investigation should be treated as a new report of possible misconduct that could be subject to additional investigation.

Last updated on 15/09/2022

Flag / Icon

Turkey

  • at Paksoy
  • at Paksoy
  • at Paksoy
  • at Paksoy

Although there is no specific legislation in Turkish law on whistleblowing, necessary mechanisms need to be implemented to ensure that whistleblowers and the whistleblowing process are kept confidential. In addition, whistleblowers must be encouraged and supported to be open about raising their concerns in good faith. A whistleblowing activity, when it amounts to raising a concern in good faith, must not be mistreated by the employer. Employers should also put in place protection mechanisms against the mistreatment of whistleblowers or retaliation towards them by other employees.   

Last updated on 15/09/2022

Flag / Icon

United Kingdom

  • at Slaughter and May
  • at Slaughter and May

The employer should first identify which individuals may have protection as whistleblowers. This could be a current or former employee who raises the initial complaint, a co-worker who gives evidence as part of the investigation, or the accused employee.

In each case, consider whether a “protected disclosure” has been made (under Part IVA ERA 1996). This requires analysis of the subject matter of the disclosure, how it is made, and a reasonable belief that it is made in the public interest.

Employers must then ensure there is no detrimental treatment or dismissal of any worker on the grounds of their protected disclosure. Although the causation test for these purposes is not straightforward, as a general rule if the protected disclosure has a “material influence” on the decision to discipline or dismiss, there may be liability. Individual managers may be personally liable alongside the employer. Compensation for whistleblowing cases is uncapped, meaning businesses and individuals can face significant financial and reputational exposure.

What this means in practical terms is that the employer should promote a “speak-up” culture and, where protected disclosures are made, ensure they are handled by a team who are properly trained in how to do so.

Last updated on 15/09/2022

Flag / Icon

United States

  • at Cravath, Swaine & Moore
  • at Cravath, Swaine & Moore
  • at Cravath, Swaine & Moore

Several federal, state, and local employment laws prohibit retaliation against employees who come forward with complaints or participate in corporate investigations. Employees who possess information regarding corporate misconduct may also be considered whistleblowers protected from retaliation under federal and state whistleblower laws, including but not limited to the Sarbanes-Oxley Act of 2002, the Dodd-Frank Wall Street Reform and Consumer Protection Act, and the Consumer Financial Protection Act of 2010.

An employee generally does not need to show that he or she was terminated or demoted to bring a retaliation claim; other actions on the part of the employer may qualify if they could be seen to discourage employees from raising complaints. To protect against a potential retaliation claim, employers should make clear at the outset of an investigation that retaliation will not be tolerated and require the complaining employee (and potentially his or her manager) to bring any instances of retaliation to the investigator’s attention immediately.

Last updated on 15/09/2022

Flag / Icon

Vietnam

  • at Le & Tran Law Corporation
  • at Le & Tran Law Corporation

It is up to the employer to determine whether or not to open an investigation after a complaint from a whistleblower. It is very important that the identity of the whistleblower is protected and that the employer also should not reveal the identity of the witness or the source of information, as the sources and witnesses may fear retaliation and feel uncomfortable or hesitant in giving information or raising concerns again.

Last updated on 25/09/2023

26. How long should the outcome of the investigation remain on the employee’s record?

26. How long should the outcome of the investigation remain on the employee’s record?

Flag / Icon

Australia

  • at People + Culture Strategies
  • at People + Culture Strategies
  • at People + Culture Strategies

There are legal requirements related to the time you must keep certain employee records in Australia, such as pay slips and time sheets. However, there are no laws concerning disciplinary records.

Employers can rely on previous misconduct to justify an employee’s termination of employment where it can be shown it is part of a course of conduct. Accordingly, if complaints have been substantiated, and disciplinary action has been taken, these records should be maintained. However, if a significant period has elapsed since the misconduct, an employer should carefully consider whether it is appropriate to rely on this past behaviour to justify future disciplinary action for similar conduct.

Last updated on 15/09/2022

Flag / Icon

Austria

  • at GERLACH
  • at GERLACH Rechtsanwälte

Data protection law requires that personal data should not be kept longer than necessary for the purpose it was collected. Once the purpose of the internal investigation is fulfilled and the data is no longer needed, it should be deleted or anonymised. Regulations regarding this matter may also be subject to WCAs or internal policies. In any case, it is advisable to keep the results for as long as they may be needed in possible subsequent administrative or judicial proceedings.

Last updated on 29/09/2023

Flag / Icon

Belgium

  • at Van Olmen & Wynant

According to the GDPR, personal data should only be stored for a proportionate amount of time. Usually, this means that it can be stored as long as it is relevant for the employment contract, and even afterwards, if there is a risk of legal proceedings (ie, regarding the dismissal of the employee).

Last updated on 15/09/2022

Flag / Icon

Brazil

  • at CGM
  • at CGM

The existence of the investigation should be kept on file for at least five years from the date of its conclusion. All information related to the investigation should be kept on file for the same period, but not on the employee’s record, to avoid the risk of accidental access by unauthorised individuals.

Last updated on 14/09/2023

Flag / Icon

China

  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng
  • at Jingtian & Gongcheng

The relevant laws and regulations in the PRC have not clarified the retention period of the investigation findings. According to Article 19 of the Personal Information Protection Law of the PRC, unless otherwise required by laws or administrative regulations, the retention period of personal information shall be the shortest period necessary to achieve the purpose of handling the information. Since the employee's personal information is very likely to be involved in the investigation findings, such report should be retained for the shortest period necessary to achieve the purpose of handling the information. In general, once the investigation is completed, the purpose of the internal investigation has been achieved or it is no longer necessary to achieve the purpose, and the employer may, in accordance with Article 22 of the Administrative Regulations of the PRC on Network Data Security (Draft for Comments), delete or anonymize the personal information within fifteen (15) working days. If it is technically difficult to delete the personal information, or it is difficult to do so within fifteen (15) working days due to business complexity or other reasons, the employer shall not conduct any processing other than storing the personal information and adopting necessary security measures, and shall give reasonable explanations to the employee.

Last updated on 29/11/2023

Flag / Icon
Finland

Finland

  • at Roschier
  • at Roschier

Please see question 7. The outcome of the investigation involving personal data may be retained only for as long as is necessary considering the purposes of the processing. In general, the retention of investigation-related data may be necessary while the investigation is still ongoing and even then the requirements of data minimization and accuracy should be considered. The data concerning the outcome of an investigation should be registered to the employee's record merely to the extent necessary in light of the employment relationship or potential disciplinary measures. In this respect, the applicable retention time depends on labour law-related rights and limitations, considering eg, the applicable periods for filing a suit.

Last updated on 15/09/2022

Flag / Icon

France

  • at Bredin Prat
  • at Bredin Prat

If the outcome of the internal investigation has led to the sanctioning of an employee, this sanction may no longer be invoked to support a new sanction after three years. Moreover, under the GDPR principles, the duration of retention must be proportional to the use of the data. Therefore, the data must be retained only for a period that is “strictly necessary and proportionate”. If the employer wants to keep information about the investigation in the longer term, it is possible to archive the employee’s record even though the employer will no longer be able to use it against the employee after three years.

Last updated on 15/09/2022

Flag / Icon

Germany

  • at Hengeler Mueller
  • at Hengeler Mueller
  • at Hengeler Mueller

If there is no special statutory storage period (which is the case for investigative reports and findings), personal data may only be stored for as long as is necessary for the purposes for which they are collected. As soon as the data is no longer required, it must be deleted. In connection with workplace investigations, the question arises as to how this obligation to delete personal data relates to the company's corporate interests. From the company's perspective, there may well be legitimate interests that speak in favour of retaining existing data for as long as possible. Under the data protection regulations of the DSGVO and the BDSG, data can be stored for as long as it is required for the assertion, exercise or defence of (civil) legal claims. This means that the data can, in any event, be saved at least as long as any measures related to the workplace investigation have not yet been completed and any legal disputes have not yet been concluded.

Last updated on 15/09/2022

Flag / Icon

Greece

  • at Karatzas & Partners
  • at Karatzas & Partners
  • at Karatzas & Partners
  • at Karatzas & Partners

Under the General Data Protection Regulation, employees’ personal details and information must be kept in the business records for as long as is necessary for the purposes of the employment relationship. Otherwise, stored data must be deleted. However, under L.4990/2022[14], reports remain in the relevant record for a reasonable and necessary time, and in any case until the completion of investigations or proceedings before the courts that have been initiated as a consequence of a complaint against the employee under investigation, the complainant or any third parties.

 

[14] L.4990/2022 art.16 par.1

Last updated on 03/04/2023

Flag / Icon

Hong Kong

  • at Slaughter and May
  • at Slaughter and May
  • at Slaughter and May

There is no legal requirement in Hong Kong on this. However, since the investigation records will likely contain personal data, employers should be mindful of the requirement under the PDPO that personal data should not be kept for longer than necessary.[1]

According to the Code of Practice on Human Resources Management published by the Privacy Commissioner for Personal Data, generally, employment data about an employee can be kept for the entire duration of his or her employment, plus a recommended period of no more than seven years after the employee leaves employment unless there is a subsisting reason that justifies a longer retention period. A longer retention period may be justified where there is ongoing litigation or a parallel investigation. Even where it is deemed necessary to retain the outcome of the investigation concerning a departed employee, the employer should ensure that other personal data on the employee’s record (that is unrelated to the purpose of retention) are erased after the expiry of the recommended retention period.

 

[1] DPP2 (in Sch. 1) and PDPO section 26.

Last updated on 15/09/2022

Flag / Icon

India

  • at Trilegal
  • at Trilegal
  • at Trilegal

There is no statutory guidance on this. It is common for employers to retain details of disciplinary proceedings on an employee's record for the entire duration of their employment.

It is also advisable to retain the details of any investigations or disciplinary proceedings for at least three years after an individual has been dismissed on account of such proceedings, as this is the general limitation period for raising claims of unfair dismissal. In labour matters, courts in India often allow delays in filing suit after the limitation period, meaning organisations sometimes make a practical call to retain details of investigations and disciplinary proceedings for longer.

Last updated on 15/09/2022

Flag / Icon
Ireland

Ireland

  • at Ogier
  • at Ogier

Irrespective of the outcome of the investigation, the fact that an employee was subject to an investigation is not the key issue. The key concern is whether any further action was taken as a result of the investigation. If a disciplinary process ensued, then it is the outcome of that disciplinary record and any subsequent appeal that would or would not be noted on an employee's record. If a disciplinary sanction were imposed then the length of time the sanction remains on the employee's record would depend on what is specified in the disciplinary policy.

Last updated on 11/10/2023

Flag / Icon

Italy

  • at BonelliErede
  • at BonelliErede

The employer would normally keep the outcomes of the investigation for the entire duration of the employment relationship with the involved employee.

After the termination of the employment relationship, it appears reasonable to conclude that the employer would be entitled to retain this information for the time necessary to exercise its defence rights in litigation (taking into account that 10 years is the statute of limitations for contractual liability). Further requirements or restrictions under general privacy laws (and particularly the GDPR) should also be checked.

According to Art. 14 WB Decree, internal and external whistleblowing reports (including related documents) must be kept for as long as necessary for report processing, but no more than five years from the date of transmission of the procedure's final outcome.

Last updated on 10/01/2024

Flag / Icon

Japan

  • at Mori Hamada & Matsumoto

Records related to responses to whistleblowing must be kept for an appropriate period, but there is no legal stipulation on the retention period. Each entity is required to set an appropriate period after considering the need for evaluation and inspection, and the handling of individual cases. There is no legally stipulated retention period for other investigation results.

Last updated on 15/09/2022

Flag / Icon

Netherlands

  • at De Brauw Blackstone Westbroek
  • at De Brauw Blackstone Westbroek
  • at De Brauw Blackstone Westbroek

The outcomes are usually kept in the records until termination of the employment agreement and only deleted when personal records are deleted.

Last updated on 15/09/2022

Flag / Icon
Nigeria

Nigeria

  • at Bloomfield LP

The law does not provide for the time the outcome of the investigation may remain on the employee’s record. However, this will depend on the employer’s record-retention policies, which must comply with applicable data protection laws.

Last updated on 15/09/2022

Flag / Icon

Philippines

  • at Villaraza & Angangco

The outcome of the investigation should only remain on the employee’s record for as long as is necessary, but shall not be less than three years as this is the record-keeping requirement under the Philippine Labor Code. If circumstances deem that such a report ceases to have any purpose whatsoever, it should be struck out of the employee’s record.

Last updated on 26/01/2023

Flag / Icon

Poland

  • at WKB Lawyers
  • at WKB Lawyers
  • at WKB Lawyers

Neither Polish law nor the Draft Law specifically provide for a mandatory period during which the outcome of the investigation should be kept on the employee’s record.

At the same time, the Draft Law indicates that the register of whistleblowing reports, which should also contain information about follow-up actions undertaken as a result of the report, should be kept for 15 months starting from the end of the calendar year in which the follow-up actions have been completed, or the proceedings initiated by those actions have been terminated.

Also, while determining how long the outcome of an internal investigation should be kept, additional legal considerations can be taken into account, especially data privacy.

The GDPR does not specify precise storage time for personal data. The employer must assess what will be an appropriate time for storage of the data, taking into consideration the necessity of keeping personal data concerning the purpose of the processing in question. Employees' personal data should be kept for the period necessary for the performance of the employment relationship and may be kept for a period appropriate for the statute of limitations for claims and criminal deeds. A longer retention period may result from applicable laws. Following the Regulation of the Minister of Family, Labour and Social Policy on employee documentation, the employer may keep a copy of the notice of punishment and other documents related to the employee’s incurring of disciplinary responsibility in the employee record.

There are different retention periods for the data contained in employee files:

  • 10 years if the employee was hired on or after 1 January 2019;
  •  if the employment relationship began between 1 January 1999 and 1 January 2019, the retention period is 50 years, but may be reduced to 10 years if the employer provides the Polish Social Insurance Institution with certain mandatory information; and
  •  for 50 years if the employee was hired before 1 January 1999. It does not matter whether the person is still working or not.
Last updated on 20/04/2023

Flag / Icon

Portugal

  • at Uría Menéndez - Proença de Carvalho

There are no specific rules in the Portuguese Labour Code on this matter.

However, article 332 of the PLC states that the employer should keep an updated record of disciplinary sanctions, so the competent authorities can easily verify compliance with applicable provisions. Accordingly, it is advisable to maintain a record of disciplinary sanctions during the entire employment relationship.

Also, please note that some collective bargaining agreements state that the disciplinary register must be deleted from the employee’s record periodically.

Last updated on 15/09/2022

Flag / Icon
Singapore

Singapore

  • at Rajah & Tann Singapore
  • at Rajah & Tann Singapore
  • at Rajah & Tann

This depends on the company’s internal disciplinary policy and the severity of the offence. For instance, a written warning issued against an employee for minor misconduct is usually kept in the respondent employee’s file for one year and if the employee does not commit any further breaches during this time, the written warning will be expunged. However, if there is a finding of serious misconduct, particularly if such a determination results in the dismissal of the employee, these records are generally kept in the employee’s file for the duration of time such records are statutorily required to be maintained.  

Last updated on 15/09/2022

Flag / Icon

South Korea

  • at Kim & Chang
  • at Kim & Chang
  • at Kim & Chang
  • at Kim & Chang

There is no legal requirement on how long the records of the investigation (eg disciplinary action) should be maintained by the company. Many companies maintain a record of disciplinary action throughout the employment period.

Last updated on 15/09/2022

Flag / Icon

Spain

  • at Uría Menéndez
  • at Uría Menéndez

The outcome of the investigation will contain personal data of the affected employee. For this reason, this information should only be kept for as long as a legal obligation or liability in connection with the information could arise for the company. Since the general statute of limitations for employment liability is one year, this is a good guideline.

In addition to the above, two specific rules apply:

  • once the information becomes irrelevant for the purpose for which it was obtained and processed, the information should no longer be stored on the employee’s record or elsewhere; and
  • the employees’ information (including those of the reporter and the affected employees) should only be stored in whistleblower systems during the time that is necessary to decide on whether the facts need to be investigated or not and, in any case, for a maximum period of three months.
Last updated on 15/09/2022

Flag / Icon

Sweden

  • at Mannheimer Swartling
  • at Mannheimer Swartling
  • at Mannheimer Swartling

Under the GDPR personal data may not, according to the general principle on storage limitation, be retained for longer than is necessary for the purposes for which the personal data are processed. The GDPR does not stipulate a generally applicable storage limitation period. Such a regulation is, on the other hand, included in the Swedish Whistleblowing Act. If the Swedish Whistleblowing Act applies, the outcome of the investigation and all personal data should be retained for as long as necessary, but not for longer than two years after the investigation has been closed.

Last updated on 15/09/2022

Flag / Icon

Switzerland

  • at Bär & Karrer
  • at Bär & Karrer

From an employment law point of view, there is no statute of limitations on the employee's violations. Based on the specific circumstances (eg, damage incurred, type of violation, basis of trust or the position of the employee), a decision must be made as to the extent to which the outcome should remain on the record.

From a data protection point of view, only data that is in the interest of the employee (eg, to issue a reference letter) may be retained during the employment relationship. In principle, stored data must be deleted after the termination of the employment relationship. Longer retention may be justified if rights are still to be safeguarded or obligations are to be fulfilled in the future (eg, data needed regarding foreseeable legal proceedings, data required to issue a reference letter or data in relation to a non-competition clause).[1]

 

[1] Wolfgang Portmann/Isabelle Wildhaber, Schweizerisches Arbeitsrecht, 4. Edition, Zurich/St. Gallen 2020, N 473.

Last updated on 15/09/2022

Flag / Icon

Thailand

  • at Chandler MHM
  • at Chandler MHM

There is no period required by law for keeping the outcome of the investigation on the employee’s record. However, if termination of employment is the outcome of the investigation, an employer should keep details of the investigation for at least 10 years, in line with the prescribed period for an employee to file an unfair dismissal claim against an employer. An employer may use the details of an investigation to defend such a claim. For other disciplinary action, the retention of investigation details on the employee’s record is at the employer’s discretion.

Last updated on 15/09/2022

Flag / Icon

Turkey

  • at Paksoy
  • at Paksoy
  • at Paksoy
  • at Paksoy

There is no provision in the legislation setting forth a specific duration for keeping the outcome of the investigation findings in personnel files. However, based on general principles, the outcome of the investigation can remain on the employee’s personnel files as long as the employer has a lawful interest in such processing without unnecessarily harming the privacy rights of the employee.

Last updated on 15/09/2022

Flag / Icon

United Kingdom

  • at Slaughter and May
  • at Slaughter and May

The investigation outcome may not need to be noted on the accused employee’s record at all. Usually only the outcome of any subsequent disciplinary or grievance process would be noted, rather than the prior investigation.

The employer should keep the investigation report for as long as it remains relevant. This would usually be no longer than six years, unless regulatory obligations dictate otherwise. The report along with all documentation and witness statements gathered during the investigation should be retained securely and confidentially but for no longer than is absolutely necessary under the requirements of the DPA 2018 and the employer's data protection policies and procedures. There may be additional retention requirements in a regulated context; the position for each particular business and employee should be checked.

Last updated on 15/09/2022

Flag / Icon

United States

  • at Cravath, Swaine & Moore
  • at Cravath, Swaine & Moore
  • at Cravath, Swaine & Moore

There is no requirement for the results of a workplace investigation to remain on an employee’s record for any specific period. It is often helpful, however, for information relating to the outcome of such an investigation (regardless of whether the allegations are substantiated) to be accessible to the human resources or legal functions such that during the initial complaint intake process described above, any prior complaints and investigations relating to the same individual or group of individuals can be taken into account to identify any recurring issues or systemic violations.

Last updated on 15/09/2022

Flag / Icon

Vietnam

  • at Le & Tran Law Corporation
  • at Le & Tran Law Corporation

Vietnamese law does not provide for a period during which the outcome of the investigation should remain on the employee’s records and files. However, this will depend on the employer’s record-retention policies, which must comply with applicable data protection laws.

Last updated on 25/09/2023