The classic trap
Recital 36 defines the scope of beneficiaries: only persons in a situation of economic vulnerability linked to work are covered. In practice, many Luxembourg organisations wrongly restrict their scheme to permanent employees, overlooking interns, temporary workers, freelancers, former employees and job applicants. The OFRS and the CNPD sanction this restrictive reading of the personal scope, which deprives legitimate whistleblowers of anti-retaliation measures and exposes the organisation to civil compensation claims.
Who must be covered by your internal channel
- Employees on permanent, fixed-term, part-time, probation or apprenticeship contracts.
- Former employees, where the information was obtained during the work relationship.
- Job applicants, where the information was obtained during the recruitment process.
- Temporary agency workers, posted workers, and staff of subcontractors operating on site.
- Self-employed persons, consultants, freelancers and service providers on mission.
- Shareholders, members of the administrative, management or supervisory body, including non-executive members.
- Volunteers, paid and unpaid trainees.
- Facilitators, third parties connected to the reporting person (colleagues, relatives) and legal entities owned by the reporting person.
Conversely, a citizen bystander or a dissatisfied customer with no economic dependency link to your organisation falls outside the scheme: their reports follow ordinary channels (mediation, sectoral complaint), which does not authorise ignoring them but changes the applicable legal qualification.
How Luxgap automates this risk
Our Luxgap Whistleblower Eligibility Gate eliminates the risk of misqualifying the reporting person upon receipt of the report. The tool automatically queries your HR sources (Sage BOB 50, Sopra Steria HR Suite, Workday LU, Odoo HR, Microsoft Entra ID) and procurement repositories (Odoo Purchase, SAP Ariba) to determine within seconds whether the person falls within the scope of article 4 of the law of 16 May 2023, without exposing their identity to the HR chain.
- Automatically verifies the current or past professional link between the reporting person and the organisation, by cross-checking payroll, supplier contracts and access registries.
- Qualifies the exact status (employee, former employee, applicant, contractor, trainee, facilitator, shareholder) according to the grid of article 4 of the Luxembourg law of 16 May 2023.
- Detects reporting persons outside the scope (citizen bystander, ordinary customer) and proposes an appropriate redirection channel without abruptly rejecting the report.
- Generates a timestamped qualification record, cryptographically sealed, enforceable against the OFRS in the event of an inspection on the application of protection measures.
- Alerts the alert officer via Teams or email as soon as a reporting person falls into a sensitive category (former employee in litigation, rejected applicant, third-party facilitator) requiring enhanced protection measures.
- Produces an annual anonymised report of qualified statuses, usable for OFRS reporting and the compliance review of the scheme.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual scope, with a free 48h white audit to measure your exposure before any commitment.