EU frameworkGDPRNIS 2DORAAI ActWhistleblowing
Recital 83

Recital 83

Directive on the protection of persons who report breaches of Union law · UE 2019/1937

(83)

Any processing of personal data carried out pursuant to this Directive, including the exchange or transmission of personal data by the competent authorities, should be undertaken in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (43) and with Directive (EU) 2016/680 of the European Parliament and of the Council (44). Any exchange or transmission of information by Union institutions, bodies, offices or agencies should be undertaken in accordance with Regulation (EU) 2018/1725 of the European Parliament and of the Council (45). Particular regard should be had to the principles relating to processing of personal data set out in Article 5 of Regulation (EU) 2016/679, Article 4 of Directive (EU) 2016/680 and Article 4 of Regulation (EU) 2018/1725, and to the principle of data protection by design and by default laid down in Article 25 of Regulation (EU) 2016/679, Article 20 of Directive (EU) 2016/680 and Articles 27 and 85 of Regulation (EU) 2018/1725.

Luxembourg specificity
loi luxembourgeoise du 16 mai 2023 relative a la protection des lanceurs d'alerte

In Luxembourg, the law of 16 May 2023 on whistleblower protection explicitly articulates the internal channel with the GDPR: the OFRS requires a prior DPIA and the CNPD considers the alert channel a high-risk processing by nature. The reporter's identity benefits from reinforced confidentiality enforceable even against Article 15 GDPR access requests by the accused person, save by court order.

Luxgap practice: document the DPIA consistently with CNPD guidelines on HR processing and implement strict technical partitioning between the reporter's identity and the alert content, demonstrable during a joint CNPD-OFRS inspection.