Whistleblower Protection Act: Key Data-Related Issues.

Author
Elzaburu
Date
February 22, 2023

After months of uncertainty following the release of the draft bill and several amendments in the Senate, the Whistleblower Protection Act was published in the Official State Gazette on February 21, 2023, as Law 2/2023 of February 20, regulating the protection of individuals who report regulatory violations and combat corruption. Thus, Directive 2019/1937 on the protection of persons who report breaches of Union law—commonly known as the WhistleblowingDirective—has finally been transposed into Spanish law.

This Law, which takes effect 20 days after its publication in the Official State Gazette (BOE), provides for the proper implementation of a whistleblower system—or, in the terms of the Law, an “internal reporting system”—as an essential tool for companies to provide adequate protection to whistleblowers. By their very nature, these systems involve the processing of personal data that presents certain specific considerations that must be taken into account; for this reason, the Act devotes its entire Title VI to the protection of personal data.

In this post, we analyze the most significant legislative developments regarding data protection in whistleblower systems following the publication of this law in the Official State Gazette (BOE):

  • Data Limited to the Intended Purposes: Personal data that is not relevant to the investigation of the complaint within the scope of this law must not be collected; if such data is collected by mistake, it must be deleted without undue delay.
  • Lawfulness of Data Processing: Data processing that is necessary to comply with this Act is presumed to be lawful. The appropriate legal bases are legal obligation and public interest. For these purposes, special category data may be processed in the complaint system, as it is necessary for the purposes of the corresponding investigation and in accordance with Article 9.2.g) of the GDPR: because it is necessary for reasons of substantial public interest, provided that the processing of the data is proportionate to the objective pursued, essentially respects the right to data protection, and appropriate and specific measures have been taken to protect the fundamental rights and interests of the data subject.
  • Duty to Provide Information: Data subjects (including both the organization’s own employees and third parties) must be provided with information regarding the processing of their data in accordance with the provisions of the GDPR; however, confidentiality must be maintained regarding the complainant’s data, whose identity must remain confidential and under no circumstances may be disclosed to the respondent. The identity of the whistleblower—when known because the complaint was not filed anonymously—may only be disclosed to the judicial authority, the Public Prosecutor’s Office, or the competent administrative authority in the context of a criminal, disciplinary, or sanctioning investigation.
  • Exercising Rights: Individuals whose data is processed in the complaint system have all the rights provided for in the GDPR, with the sole exception that if the person against whom the complaint is filed exercises the right to object, it is presumed—unless proven otherwise—that there are compelling legitimate grounds justifying the processing of their data; therefore, their request may be denied.
  • Access to Personal Data: Only the following individuals may access personal data in the reporting system:
  • The person responsible for the system itself and who manages it directly.
  • The human resources manager or the appropriate authority when disciplinary action may be taken against an employee.
  • The head of the legal department when legal action is warranted.
  • Data controllers who need the data to provide their services.
  • The Data Protection Officer.

In addition, the information may be shared with other individuals or third parties when necessary to implement corrective measures within the organization or to carry out any applicable disciplinary or criminal proceedings.

  • Data Retention Period in the Reporting System: The general rule is that personal data contained in the reporting system shall be retained therein only for as long as necessary to determine whether an investigation should be opened. In any case, if three months have passed without an investigation having been initiated, the data must be deleted from the reporting system, unless it has been anonymized or the purpose of retention is to provide evidence of the system’s operation.
  • Data Protection Officer: Notwithstanding the provisions set forth above in the Draft Bill, it is confirmed that the requirement to appoint a Data Protection Officer has ultimately been eliminated for companies that were required to implement an internal reporting system solely because they were subject to this obligation, without prejudice to the fact that they will have to appoint one if it applies to them in accordance with the provisions of the General Data Protection Regulation and/or the Organic Law on Data Protection and the Guarantee of Digital Rights.
  • Joint Control. In cases where there is joint control over the management of a complaint-handling system (for example, because a group of companies shares a single system that they manage jointly), the Law expressly mentions the obligation to enter into a joint control agreement in accordance with the provisions of Article 26 of the GDPR.
  • Security Measures: Obviously, every reporting channel must have robust security measures in place to ensure, to the greatest extent possible, above all the confidentiality of data, as well as its integrity and availability.

 

Eduardo Oliveros Caballero, attorney at ELZABURU.