EU frameworkGDPRNIS 2DORAAI ActWhistleblowing
Recital 92

Recital 92

Directive on the protection of persons who report breaches of Union law · UE 2019/1937

(92)

Where reporting persons lawfully acquire or obtain access to the information on breaches reported or the documents containing that information, they should enjoy immunity from liability. This should apply both in cases where reporting persons reveal the content of documents to which they have lawful access as well as in cases where they make copies of such documents or remove them from the premises of the organisation where they are employed, in breach of contractual or other clauses stipulating that the relevant documents are the property of the organisation. The reporting persons should also enjoy immunity from liability in cases where the acquisition of or access to the relevant information or documents raises an issue of civil, administrative or labour-related liability. Examples would be cases where the reporting persons acquired the information by accessing the emails of a co-worker or files which they normally do not use within the scope of their work, by taking pictures of the premises of the organisation or by accessing locations they do not usually have access to. Where the reporting persons acquired or obtained access to the relevant information or documents by committing a criminal offence, such as physical trespassing or hacking, their criminal liability should remain governed by the applicable national law, without prejudice to the protection granted under Article 21(7) of this Directive. Similarly, any other possible liability of the reporting persons arising from acts or omissions which are unrelated to the reporting or are not necessary for revealing a breach pursuant to this Directive should remain governed by the applicable Union or national law. In those cases, it should be for the national courts to assess the liability of the reporting persons in the light of all relevant factual information and taking into account the individual circumstances of the case, including the necessity and proportionality of the act or omission in relation to the report or public disclosure.

Luxembourg specificity
loi luxembourgeoise du 16 mai 2023 relative a la protection des lanceurs d'alerte

In Luxembourg, Article 18 of the law of 16 May 2023 on whistleblower protection enshrines civil, administrative and professional immunity for the lawful acquisition of information, but Article 509-1 of the Criminal Code continues to apply in full to fraudulent access to a computer system (penalties up to 2 years imprisonment and EUR 25,000 fine). The labour court and the Superior Court of Justice assess the necessary and proportionate nature on a case-by-case basis.

Luxgap practice: systematically document, from receipt of a report, the legitimate access scope of the reporter via a timestamped Azure AD snapshot, to distinguish what falls under Article 18 immunity from what may fall under Article 509-1.