BlackTree Security · Infrastructure · Automation · AI

Belgium’s Whistleblower Law Makes Confidential Case Handling a System Requirement

Belgium’s private-sector whistleblower law is not satisfied by publishing an ethics address. Covered employers need an accessible reporting route, independent follow-up and confidentiality that survives the entire case.

Belgium’s Law of 28 November 2022 on protection of persons who report breaches in a private-sector legal entity was published on 15 December 2022 and entered into force on 15 February 2023. It created internal and external reporting routes and protection against retaliation.

Private companies with at least 50 workers generally need an internal reporting channel, with special rules and sectoral obligations capable of applying below that threshold. The people who can report extend beyond current employees to others who obtained information in a professional context.

Intake is only the visible edge

A reporting channel may accept written or oral reports, and Belgian law permits anonymous reporting in the relevant framework. But the compliance system begins after the message arrives.

The organisation must restrict access, acknowledge receipt, assess scope, investigate or refer the matter, communicate feedback and protect the reporting person. A secure form that exports the case into a shared compliance mailbox loses its value immediately.

The case design should separate three kinds of information: the reporting person’s identity, the allegation and evidence, and the investigation record. Different users may need access to different parts. A technical investigator may need a log extract without knowing who reported; a small authorised team may need to contact the person without giving the broader investigation group access to identity.

Independence has to work in a conflict

The person or department following up a report must act independently and without conflicts of interest. That requirement should be tested against difficult cases, not the normal organisation chart.

Who receives a report about the compliance director, chief executive or local HR team? Can a group-level channel route a case away from the implicated subsidiary? Does an external provider have authority to escalate when the internal contact does not respond?

Routing rules should be documented before a report arrives. They should also be kept confidential: a broad automated notification to senior managers can expose the allegation and the reporter to the very people the law is designed to control.

Confidentiality is different from anonymity

A named report can be handled confidentially. An anonymous report can still reveal identity through document metadata, work schedules or narrative detail. The system needs protection for both.

Users should be told how to submit safely and what information is genuinely necessary. Attachments should be quarantined, scanned and stripped of avoidable metadata where appropriate, while preserving evidential integrity. Case notifications should contain a neutral reference rather than allegation details.

Anonymous reporting should support two-way contact. A random identifier or protected mailbox allows the case handler to ask questions and give feedback without learning identity. Without that function, an organisation may be unable to investigate a credible but incomplete report.

Deadlines need an accountable workflow

The external process overseen by the Federal Ombudsman illustrates the statutory rhythm: acknowledgement within seven working days and follow-up generally within three months. Internal procedures need corresponding timers and communication controls under the law.

The system should record when a report was received, when acknowledgement was sent, who accepted responsibility, why a case was transferred, when feedback is due and whether protection concerns were raised. It should support absence and reassignment without opening access to a general queue.

Metrics should be used carefully. Fast closure is not always success, and low volume is not proof of an ethical culture. Better indicators include awareness, safe contact, time to first assessment, remediation completion and substantiated retaliation concerns.

One channel can support several laws—but not blur them

Employers may want one speak-up platform for Belgian whistleblower law, harassment, fraud, supply-chain complaints and data-protection concerns. A common front door can reduce confusion, provided the back end applies the correct scope, confidentiality, investigation team, deadline and external route to each report.

The triage record should explain the classification without forcing the reporter to choose a legal category. It should also identify mixed cases, such as an allegation that contains a personal-data breach requiring separate notification analysis.

Belgium’s law makes trust an operational property. People need to know the channel exists, but the organisation must also prove that reports are contained, investigated independently and converted into action without exposing the person who spoke up.

Official sources

Continue the series

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *