§12 HinSchG-compliant

HinSchG-compliant whistleblower channel for SMEs

Anonymity by default. GDPR-aligned. Free starting at €0. Meet §12 HinSchG requirements in under 10 minutes.

  • HinSchG §12-compliant
  • GDPR + EU-hosted
  • Anonymous 2-way dialogue
  • No annual contracts
Canal de signalement interne
Scannez pour signaler Zum Melden scannen Scan to report Отсканируйте, чтобы сообщить
anonymeter.com/f/...
100% anonyme.

What does the German Whistleblower Protection Act require?

Since December 17, 2023, every company with 50+ employees must operate an internal reporting channel. Here are the core requirements.

§

50+ employees → mandatory

All companies with 50 or more employees - sector-wide - since December 17, 2023.

§

Anonymity allowed + recommended

§7 HinSchG: anonymous reports may not be ignored. The law explicitly recommends anonymous channels to lower the reporting threshold.

§

7-day acknowledgment

§17 HinSchG: whistleblowers must receive an acknowledgment of receipt within 7 days.

§

3-month feedback

§17 HinSchG: feedback on action taken must be provided within 3 months.

§

Confidentiality + anti-retaliation

§8 HinSchG: whistleblower identity must be protected. §36: protection from retaliation (dismissal, transfer, etc.).

§

Documentation + retention

§11 HinSchG: reports must be documented persistently, at least 3 years after case closure.

⚠️ Violations can result in fines up to €50,000 (§40 HinSchG).

Why Anonymeter for HinSchG?

Anonymeter was built ground-up for anonymous feedback - not retrofitted as a feature. That makes us the right choice for HinSchG-compliant whistleblower channels.

Real anonymity - not a marketing slogan

We store no IP addresses and no user-agent fingerprinting from respondents, and public form pages set no cookies by default - the only one is optional, and only if the respondent asks for a reply channel. Verified in our code (`schema.sql` - `// No user_id, no IP address`).

Anonymous two-way dialogue

You can ask follow-up questions and the whistleblower can reply - both stay anonymous. Satisfies §17 HinSchG (3-month feedback) without breaking anonymity.

Free = HinSchG-compliant

Our free plan includes 1 reporting channel with unlimited reports - meets §12 HinSchG (internal reporting channel). For SMEs 50-249 employees who don't want to pay €70-99/month.

GDPR rights, honoured

Data hosted in Toronto, Canada. GDPR Art. 17 (erasure), Art. 20 (portability) and Art. 28 (DPA) implemented. We sign a DPA on request.

Monthly cancellable - no lock-in

Unlike Formalize (annual prepay + 30-day cancellation notice) or hintbox (€99/month from day one): we're monthly. Try it out without commitment.

Ready in 5 minutes - no consultants

Self-service setup. No consulting hours, no implementation workshops. You sign up, pick the HinSchG template, share the link - done.

HinSchG-Vorlage

HinSchG template: ready to use

Pre-configured form with the mandatory fields per §17 HinSchG. Use it with one click and customize as needed.

  • Confidential report content
  • Date / time period of incident
  • Attachments (evidence) - up to 10 MB
  • Optional: anonymous pseudonym for follow-up dialogue
  • Auto-acknowledgment within 7 days (§17 HinSchG)
  • Retention period: 3 years (configurable)
Use template - 1 click

Anonymeter vs Formalize vs hintbox - the honest SME comparison

Three of the most-known HinSchG solutions compared directly. As of April 2026 - all data from public pricing pages.

  Anonymeter Formalize hintbox
Entry price Free (1 channel) €70/month €99/month
Pro plan starts at €9/month €80/month €99/month
Monthly billing ❌ (annual only)
Cancellation notice Immediate 30 days 30 days
Anonymous 2-way dialogue
Slack / Teams integration ✅ (webhook)
Setup without consultant ✅ (5 min) ⚠️ (45 min consulting) ⚠️
ISO 27001 / ISAE 3000 🟡 in process
EU hosting Canada (Toronto)

Two rows above do not go our way, and we leave them in. If an EU-only hosting location or a certificate on file is a procurement requirement for you, we are not your tool today - better you read that here than three weeks into a DPA review. What we do instead is hold less: no respondent IP address is ever written down, so there is less data to locate in the first place.

Sources: whistleblowersoftware.com/en/pricing, hintbox.de - as of April 2026.

HinSchG whistleblower channel - frequently asked questions

When does HinSchG apply to my company?
HinSchG has been in effect since December 17, 2023 for all companies with 50 or more employees - sector-wide. Larger companies (>249 employees) were obligated since July 2, 2023.
What happens if we don't have a reporting channel?
Violations can be fined up to €50,000 per case (§40 HinSchG). Additionally, whistleblowers have the right to use external reporting offices (BfDI, BaFin, etc.) - which can mean external escalation.
Must we accept anonymous reports?
§7 HinSchG says: anonymous reports may not be ignored, but the law explicitly recommends anonymous channels because they lower the reporting threshold. Practically: employers who want to protect against whistleblower retaliation use anonymous channels.
Who can manage the reporting channel?
§14 HinSchG requires a "person obligated to confidentiality". This can be an internal compliance officer, an HR manager, a data protection officer - or an external provider like Anonymeter. Important: the person must be free of conflicting instructions for this task.
Can we use Anonymeter as a third-party provider under §14 HinSchG?
Yes. Anonymeter acts as a data processor (GDPR Art. 28). We provide the AVV contract. You remain the controller for HinSchG compliance. We handle the technical infrastructure.
Where is our data stored?
Data is hosted in Toronto, Canada - not in the EU. Canada holds an adequacy decision from the European Commission, which is the basis we rely on for transfers from the EU; your own counsel should confirm it fits your case. Our sub-processors are listed at /subprocessors, and we sign a DPA on request.
How is anonymity technically ensured?
Three layers: (1) We store no IP addresses or user-agents from respondents - verified in our code (publicly inspectable). (2) Cookies are opt-in, off by default. (3) Anonymous two-way dialogue uses hash-based pseudonyms - we cannot identify the whistleblower, not even internally.
How long must we retain reports?
§11 HinSchG: at least 3 years after the case is closed. On forms with case management switched on, Anonymeter enforces this for you - closing a case starts the 3-year clock, and a daily job then purges the whole record: report, audit trail and follow-up thread. There is nothing to configure. Do not put a per-form auto-delete window on a reporting channel - those windows (30 / 90 / 365 days) are meant for ordinary feedback forms and are shorter than the statutory minimum.

Become HinSchG-compliant - in under 10 minutes

Free plan + HinSchG template = ready to publish. No credit card required. No consulting calls.

Start free →

Next: the printable staff notice for the channel