The classic trap
Recital 77 targets a very specific leak: one that originates from the competent authority itself, not from the company's internal channel. In practice, when a report reaches the OFRS, the CSSF, the CNPD or the ITM, and these authorities open an investigation, transmit evidence to a prosecutor or request information from the employer, the reporting person's identity passes through several hands. The trap: the authority requests documents from the employer without sufficiently masking the context, and the reporter's identity becomes deducible by cross-referencing (date, scope, subject). The recipient of the report remains bound by professional secrecy even towards their own colleagues not authorised on the file.
What this recital concretely changes for you
Even if you are not the authority, this recital directly impacts how you respond to an information request coming from an authority following a report:
- Any authority request mentioning or suggesting a report must be tracked in a dedicated register, separate from the HR file of the employee potentially concerned.
- The response to the authority must never reveal that you have identified or suspected the reporter's identity, even if it is obvious internally.
- Exchanges with the authority must be encrypted, time-stamped, and limited to a restricted named circle (DPO, HR director, legal counsel, external counsel).
- Internal investigations triggered in parallel must be compartmentalised: investigation team distinct from operational managers, restricted committee, encrypted storage of evidence.
- Lifting professional secrecy can only occur on formal judicial requisition, never on a simple administrative request.
How Luxgap automates this risk
Our Luxgap Authority Liaison Vault turns the handling of authority requests into a compartmentalised vault where every exchange with OFRS, CSSF, CNPD or ITM linked to a report lives in an isolated space, cryptographically sealed and accessible only to nominatively authorised individuals. The tool intercepts all incoming correspondence via a dedicated mailbox, classifies the request through a specialised LLM agent, and triggers a response workflow where the reporter's identity is masked by default, even from the HR director.
- Automatically detects incoming authority requests (scanned mail, official email, MyGuichet platform) linked to a report and isolates them from the standard HR information system.
- Classifies each request according to its legal basis (administrative investigation, criminal requisition, simple information request) and proposes the appropriate response level.
- Generates automatically redacted responses, where any element allowing re-identification of the reporter by cross-referencing is detected and masked before sending.
- Tracks every access to file evidence with time-stamp, business justification and consultant electronic signature, producing an opposable chain of custody.
- Alerts instantly via Teams or Signal when an unauthorised access is attempted, and automatically blocks exports to unencrypted destinations.
- Produces a sealed time-stamped PDF report, opposable to OFRS and prosecutors, demonstrating that professional secrecy was respected throughout the procedure.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual flows with Luxembourg authorities, with a free 48-hour blank audit to measure your exposure before any engagement.