The classic trap
Recital 106 reminds that the material scope of the Directive (public procurement, financial services, product safety, environment, public health, data protection, etc.) is a minimum floor, open to extension. In practice, many organisations restrict their internal scheme to the listed domains and dismiss reports on tax fraud, harassment, internal corruption or ethical breaches as 'out of scope'. This is a strategic mistake: the Luxembourg law of 16 May 2023 explicitly extended the scope to any breach of national law, and the OFRS, like the CNPD, sanctions the absence of a channel accepting these 'extra-directive' reports.
Why a narrow whistleblowing scope exposes you
- A report rejected as 'out of scope' that later surfaces in the press or via a union triggers an OFRS investigation on the overall quality of your scheme.
- The whistleblower benefits from protection even when the domain is not in the EU Directive, provided LU law of 16 May 2023 covers it (broader scope than EU).
- Future revisions of the Directive (evaluation clause, article 27) will likely add direct taxation and labour law: anticipating avoids a costly overhaul.
- Restricting the internal channel mechanically pushes reports towards the external channel (OFRS) or public disclosure, with disproportionate reputational risk.
- The 'out of scope' qualification must be written and traced: an arbitrary decision constitutes an indirect retaliation measure (article 21 of the Directive).
How Luxgap automates this risk
Our Luxgap Whistleblowing Scope Sentinel eliminates the risk of rejecting a legitimate report on the wrongful ground that it falls outside the material scope. The tool deploys a specialised AI agent that analyses each incoming report in real time, cross-checks it against the EU 2019/1937 scope, the broader LU law of 16 May 2023, ILO conventions, the LU Criminal Code and the Labour Code, then automatically qualifies admissibility with a legally enforceable motivation.
- Classifies each incoming report against a multi-source matrix (EU Directive, LU law 2023, criminal law, labour law, GDPR, AML/CFT) in under 30 seconds.
- Detects 'grey' reports (harassment, internal fraud, conflicts of interest) that standard schemes wrongly reject and automatically reclassifies them under the correct legal basis.
- Generates a timestamped legal motivation for each admissibility or inadmissibility decision, enforceable before the OFRS during an inspection.
- Instantly alerts the whistleblowing officer via Teams or Slack whenever a report touches an emerging domain likely to be included in a future revision of the Directive.
- Produces a compliance dashboard demonstrating the absence of selection bias in report handling over a rolling 12-month window.
- Automatically updates its qualification matrix with every LU or EU legislative change, without intervention from the DPO or compliance officer.
Available as an add-on to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your real historical reports, with a free blind audit within 48h to measure your wrongful-rejection rate before any engagement.