The classic trap
Recital 85 opens a narrow but critical door: competent authorities handling reports (OFRS, CSSF, CNPD, ITM, judicial police in certain cases) may temporarily restrict the rights of access, information and rectification of the person identified by the report, when those rights would allow tracing back the whistleblower's identity or sabotaging the investigation. In practice, organisations receiving a GDPR Article 15 access request from a manager accused in a report often reflexively send back the full file, and thereby burn the whistleblower. The CNPD treats such disclosure as a direct breach of Article 16 of the Luxembourg law of 16 May 2023, which criminally sanctions any break of confidentiality.
The concrete arbitrage between GDPR access right and whistleblower confidentiality
Recital 85 authorises you to oppose a temporary and motivated refusal to access, information or rectification requests filed by the person targeted by the report, as long as the internal investigation is ongoing and lifting these restrictions would allow identifying the whistleblower. Rules to document:
- The restriction must be limited to what is necessary and lifted as soon as the investigation closes, unless identification remains possible afterwards.
- The restriction decision must be traced in writing, with the precise legal basis (GDPR Article 23 or equivalent in the LU law of 1 August 2018).
- The DPO must be consulted before each refusal, otherwise the decision qualifies as arbitrary.
- The data subject must be informed of their right to lodge a complaint with the CNPD, even though the substance of the report stays confidential.
- Pseudonymisation of witnesses and the whistleblower in the case file must be enabled at intake, not at the moment the access request arrives.
How Luxgap automates this risk
Our Luxgap Whistleblower Confidentiality Shield turns the manual and risky arbitrage between GDPR access right and whistleblower protection into a deterministic and traced workflow. The tool intercepts every access request filed by an employee identified as a target in an active report, and blocks transmission until a DPO + investigation lead arbitrage has been formally logged, leveraging connectors to M365, Odoo HR, Sage BOB 50 and your reporting platform (EQS, WhistleB, NAVEX).
- Automatically detects the overlap between an inbound GDPR Article 15 request and an active OFRS report targeting the same requester, in under 5 minutes.
- Pseudonymises every piece of the investigation file on the fly from creation, replacing direct identifiers of the whistleblower with a reversible token accessible only to the DPO and the investigation lead.
- Generates the motivated refusal letter under GDPR Article 23, pre-mapped to the recital 85 exceptions, citing Articles 13(3), 15(1), 16(4) and 31(5) of the transposed Directive 2016/680.
- Computes a re-identification risk score at every change in the investigation file and alerts if a newly added document allows inferring the whistleblower's identity by cross-referencing.
- Produces a cryptographically sealed timestamped PDF report, enforceable before the CNPD and the OFRS, demonstrating that every restriction was proportionate and lifted on time.
- Automatically triggers the lifting of restrictions as soon as the investigation status moves to closed, preventing abusive maintenance.
Available as a complement to a Luxgap DPO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual reporting platform, with a free 48h blank audit to measure your exposure before any commitment.