The classic trap
Recital 30 excludes from the directive's scope paid informants registered in dedicated databases (customs, police, enforcement authorities). The trap: assuming that anyone reporting fraud automatically falls under the whistleblower regime. In practice, organisations confuse the two statuses and apply the wrong protection regime, which can lead the OFRS or the CNPD to sanction either the absence of a suitable internal channel, or conversely a disproportionate data processing on reports that should have followed a specific procedure.
Distinguishing paid informant from whistleblower: the qualification grid
A report falls under directive 2019/1937 (and therefore the Luxembourg law of 16 May 2023) if, and only if, the author acts in a work-related context without direct financial counterpart. Criteria to check in your internal channel:
- Does the author have a professional link with the entity (employee, intern, supplier, candidate)?
- Is the report made in exchange for a reward formalised by an authority (customs, tax, competition)?
- Is the author already registered as informant in an enforcement authority database?
- Does the report target a Union law breach listed in article 2 of the directive?
- Has the author given informed consent to an anonymous informant programme?
If the answer leans toward the paid programme, your internal channel must redirect the author to the competent authority without collecting personal data, otherwise the physical anonymity protected by specific procedures may be compromised.
How Luxgap automates this risk
Our Luxgap Whistleblowing Triage Agent turns your whistleblowing inbox into an AI agent that qualifies each report in under 60 seconds and closes the risk of confusion between the directive 2019/1937 regime and the paid informant programme. The tool analyses incoming reports via your internal channel (web form, phone line, dedicated platform) and cross-checks the signals with the OFRS, CSSF, ITM and CNPD qualification grid to automatically route to the right treatment.
- Classifies each incoming report between whistleblower regime, paid informant programme, customer complaint or HR conflict, using a specialised LLM trained on CJEU case-law and OFRS doctrine.
- Automatically detects signals of a paid programme (mention of reward, reference to customs or tax authority, request for physical anonymity) and suggests redirection to the competent authority without collecting nominative data.
- Generates an acknowledgement compliant with article 9 of the directive within 7 days, with cryptographic timestamp and case number opposable to the OFRS in case of audit.
- Alerts the whistleblowing officer in real time via Teams or Slack when a report crosses the severity threshold (physical integrity attack, corruption, CSSF financial fraud).
- Produces a pseudonymised report register, compliant with article 18 of the directive and article 30 GDPR, exportable as a timestamped PDF opposable to the CNPD.
Available as an add-on to a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on anonymised real cases, with a free 48h blank audit of your current internal channel to measure your exposure before any engagement.