The classic trap
Many organisations limit their whistleblowing scheme to breaches in the strict sense: a law broken, an article violated, a clear-cut infringement. Recital 42 deliberately broadens the scope to abusive practices, meaning arrangements that are formally legal but defeat the purpose of the law. The OFRS and the CNPD have already stressed that rejecting a report on the ground that the reported act is not stricto sensu unlawful exposes the employer to a reclassification as retaliation, criminally sanctioned in Luxembourg.
The 'abusive practice' test: how not to wrongly dismiss a report
The legal reflex of an ethics committee is to filter alerts by criminal qualification. This is exactly what CJEU case law (notably Halifax, Cadbury Schweppes) prohibits. The right test combines four criteria:
- Does the act formally comply with the rule (yes = do not stop there)?
- Does it run counter to the objective pursued by the rule (tax, environmental, prudential, sanitary)?
- Is the advantage obtained essentially to circumvent the purpose (artificial arrangement, aggressive optimisation, contract splitting)?
- Is the public interest seriously harmed (diffuse but real harm to competition, tax, health, environment)?
If three out of four criteria are met, the report falls within the scope of the directive, even though no article of the Code is breached. Refusing to investigate then constitutes a fault of the internal recipient.
How Luxgap automates this risk
Our Luxgap Whistleblowing Triage Agent eliminates the number one risk of a poorly calibrated internal channel: dismissing a legitimate report because the in-house lawyer did not spot the abusive practice behind the appearance of legality. The tool deploys a specialised AI agent, trained on CJEU case law and OFRS guidance, which qualifies each incoming alert against the recital 42 grid in less than 60 seconds, before any human intervention.
- Analyses the content of each report (form, encrypted email, transcribed voice message) and proposes a reasoned qualification: direct breach, abusive practice, out of scope, or ambiguous.
- Detects indicators of artificial arrangement (contract splitting, intermediate structures, aggressive tax optimisation, circumvention of regulatory thresholds) by cross-checking the factual elements of the report.
- Automatically cites the relevant CJEU rulings (Halifax, Cadbury Schweppes, Emsland-Starke) to support the qualification proposed to the ethics committee.
- Alerts the DPO and the whistleblowing officer in real time via Teams or Slack as soon as a report crosses the severity threshold calibrated for the sector (CSSF, ITM, environment, health).
- Produces a timestamped, cryptographically sealed log of each qualification, enforceable before the OFRS in case of audit or retaliation litigation.
- Generates the 7-day acknowledgement letter and the 3-month reasoned feedback required by the law of 16 May 2023.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a demonstration on your real data and our teams will run a free 48h blank audit of your current channel to measure the rate of wrongly qualified reports before any engagement.