The classic trap
Recital 5 sets the principle of common minimum standards but allows Member States to extend protection beyond the areas listed in Article 2. In practice, many organisations restrict their reporting channel to EU matters only (public procurement, financial services, product safety, GDPR) and exclude reports on harassment, discrimination or purely national fraud. The result: the OFRS and ITM consider the internal channel undersized, and the whistleblower still benefits from protection where national law has extended it.
Why the material scope drives everything else
Recital 5 has a direct operational consequence: mapping the covered scope determines manager training, the content of the internal procedure, and whether a report qualifies as protected. Mis-calibrating this scope exposes the organisation to two symmetrical risks:
- Scope too narrow: the whistleblower goes directly to the OFRS, CNPD or the press, and the organisation loses control of internal handling.
- Scope too broad but poorly documented: managers wrongly reclassify HR grievances as protected reports, triggering unjustified protective measures and labour litigation.
- Scope unclear: impossible to prove to the OFRS during an inspection that the scheme covers the required matters plus those voluntarily added.
How Luxgap automates this risk
Our Luxgap Whistleblowing Scope Mapper definitively closes the material scope question by generating, from your real activity, the exact matrix of matters covered by your reporting scheme. The tool cross-references your NACE code, business systems (Odoo, SAP, Sage BOB 50), certifications (ISO 27001, ISAE 3402) and the regulators you fall under (CSSF, CAA, ILR, CNPD) to produce an opposable scope, distinguishing the mandatory EU core from Luxembourg national extensions.
- Automatically detects the applicable EU matters via analysis of your NACE code and your Odoo or SAP financial flows.
- Classifies each incoming report type (fraud, harassment, money laundering, data breach) as EU core, LU extension or out of scope.
- Generates the prefilled Article 8 internal procedure, explicitly listing covered matters and competent external authorities by topic.
- Alerts your managers and reporting officer in real time when an incoming report changes legal qualification.
- Produces a timestamped PDF report opposable to the OFRS and ITM, demonstrating scope consistency with the law of 16 May 2023.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your current scheme, with a free blind audit within 48h to measure your exposure before any commitment.