EU Whistleblowing Directive (EU) 2019/1937

The internal reporting channel the law requires. The evidence your compliance model needs.

ICLex: end-to-end case management, with the confidentiality and rigor a whistleblowing report demands — from intake to closure, with a defensible audit trail.

A 30-minute consultative call. No commitment.

ICLex specialists reviewing a confidential case together

Every investigation, led by dedicated specialists

People: confidential investigation conducted by specialists, impartially.
Process: cases structured with an audit trail defensible under inspection.
Technology: Enterprise governance and multi-tenant isolation on every query.
Built to withstand audit and inspection
Acknowledgement of receipt within 7 daysFeedback to the reporter within 3 monthsRetention bounded and loggedGDPR by design (art. 25)
The obligation

The internal reporting channel is no longer optional. Can your organisation prove it actually works?

Directive (EU) 2019/1937, as transposed into national law, requires an internal channel with binding response deadlines — subject to inspection. Most channels treat a report as an isolated event, producing no evidence that the channel functioned as required.

01

The obligation is scope- and headcount-triggered

The internal channel becomes mandatory at a given headcount threshold, and for entities that have adopted a liability-prevention model regardless of size — confirm whether it applies to you before choosing a tool.

02

A report disconnected from your prevention model

A report handled outside your compliance/prevention model produces nothing the model's own periodic review can use.

03

A channel that can't prove it, doesn't count

Without a defensible record of intake, handling and outcome, the channel does not demonstrate effective implementation.

The differentiator

The report doesn't end at the investigation. It feeds your compliance model.

No generic channel builds this bridge. ICLex turns every report into a structured, traceable case, with a periodic report ready for your oversight body.

Step 1

Report received — channel with attached evidence, hashed the moment it's submitted.

Step 2

Traceable investigation — every action logged with author, timestamp and restricted access scope.

Step 3

Oversight report — ready to feed your compliance model's periodic review.

Platform

See how every case is run

A real preview of the case screen — status filters, search and the progress of each investigation, exactly as your team will use it.

iclex.app/cases
Illustrative example — sample data
Cases
Your cases

Every report, from intake to closure, with its own audit trail.

New case
CaseStatus
Suspected irregularity in a public tender
CASE-2026-00231
Reporting
Conflict of interest — supplier
CASE-2026-00229
Evidence
Environmental report — production site
CASE-2026-00224
Analysis
Suspected personal-data breach
CASE-2026-00219
Remediation
Misuse of company funds
CASE-2026-00201
Closed
Audit trail

Every step, logged — and verifiable.

This isn't a promise in copy. It's what happens, in the order it happens, with evidence hashed the moment it's submitted.

Mar 14 · 09:12

Report received

Acknowledgement started: the 7-day clock begins.

Mar 14 · 11:40

Intake by the designated channel manager

Access limited to the designated channel manager — no unauthorised access.

Mar 15 · 08:55

Evidence attached

File copied and hashed at upload time, preserving chain of custody.

sha256 · a13f…9e2c
Mar 22 · 17:30

Oversight report issued

Outcome documented and linked to the periodic review of your compliance model.

How it works

Guided rollout, no complex integration.

01

Channel configured

Reporting channel with your branding, categories and escalation flows.

02

Scoped investigation

Roles define who can access each case.

03

Documented conclusion

Evidence, comments and decisions — all with an end-to-end audit trail.

04

Oversight report generated

Consolidated report for your oversight body, ready for audit and inspection.

Data security

Data protection by design, not bolted on afterward.

Granular access control

Custom roles define exactly who sees each case.

Identity confidentiality

The reporter's identity is protected within the limits set by applicable law.

GDPR by design

Data minimisation and configurable retention, aligned with GDPR art. 25.

Encryption and isolation

Data encrypted in transit and at rest, with multi-tenant isolation on every query.

Ethics · Technical excellence · Discernment · Trust
Corporate integrity conducted with forensic rigor.

See the full cycle working with your own data

Confidentiality in the report. Rigor in the investigation. Traceability in the outcome.

Book a demo
Frequently asked questions

What compliance and legal teams ask first.

It depends on headcount and, independently of that, on whether you've adopted a liability-prevention model. We review your specific situation before activation — we don't replace a legal assessment, but the platform is ready the moment the obligation is confirmed.