Germany compliance
Internal Reporting Channel for Germany — HinSchG
Compliant with the Hinweisgeberschutzgesetz (HinSchG). Secure whistleblower channel with electronic register, deadline automation and German legal templates.
Built for EU Whistleblower Directive 2019/1937 and GDPR: encryption in transit and at rest, EU data residency, and a reporting channel designed so designated persons can meet statutory deadlines.
Hinweisgeberschutzgesetz (HinSchG) · In force since 2 July 2023
This page is for organisations under the German Hinweisgeberschutzgesetz (HinSchG), in force since 2 July 2023. It is not legal advice and does not replace Betriebsrat consultation where that is required.
Since 2 July 2023: German companies with 250+ employees must run HinSchG internal procedures (50+ since 17 December 2023).
Controls CISOs, DPOs and general counsel can verify
- Row Level Security
- Organisation data is isolated in Postgres with row-level access rules. Officers only see cases for companies they are authorised to handle.
- Mandatory TOTP MFA
- Administrators and designated persons must enrol an authenticator app (Google Authenticator, Microsoft Authenticator or Authy) before using the dashboard.
- Immutable consent & audit trail
- Clickwrap acceptance of Terms, Privacy Policy and DPA is stored with timestamp, version and client metadata — not a silent checkbox.
- Private evidence vault
- Report attachments sit in private object storage, downloaded only by authorised officers over authenticated sessions — not public URLs.
Scope under HinSchG
- Private employers with more than 50 employees
- Public sector employers as defined in the Act
- Certain regulated sectors regardless of headcount
Core HinSchG requirements
German law mandates secure internal reporting channels, documentation in an electronic register, works council involvement where applicable, and strict protection against retaliation.
- Written, oral and in-person reporting channels
- 7-day acknowledgement, 3-month feedback
- Hinweisgeber-Register (electronic record)
- GDPR and BDSG data protection compliance
- Prohibition of retaliation with burden of proof reversal
QReportly for German organisations
German-language interface, EU hosting, GDPR-compliant architecture, automatic deadline management and free HinSchG-aligned Word templates. Email alerts to the designated officer, multi-organisation dashboard for consultants and groups. From €79/month.
How report data is handled
Case content is processed only to operate the internal reporting channel for your organisation.
We do not use whistleblowing reports for advertising or product marketing. Your organisation remains the controller of the cases. Officers open files only after authentication; dashboard users must complete TOTP. Attachments stay in a private vault, not on public links.
Encryption and EU hosting
- TLS 1.3 in transit
- Browser and API traffic is encrypted in transit with modern TLS. The public reporting channel does not load advertising cookies.
- AES-256-GCM at rest
- Application secrets and stored payloads use authenticated encryption at rest. TOTP secrets are stored encrypted, not as plaintext.
- EU region (Frankfurt / Supabase)
- Primary application database is hosted in the EU (Frankfurt via Supabase). We do not advertise a second production region we do not operate.
Contracting entity
QReportly is operated by Qreportly LLC, a Wyoming (USA) limited liability company (30 N Gould St Ste R, Sheridan, WY 82801). Cross-border SaaS contracts and an EU-hosted production database give enterprise buyers a clear operator, a clear processor location, and a signed DPA.
What the platform automates
- 7-day acknowledgement
- The product can send the statutory acknowledgement of receipt automatically. The legal duty still sits with the organisation.
- Electronic reporting register
- Closed cases can be exported as a register PDF and as an individual official case file — without the whistleblower’s secret access key.
- Secure channel & QR poster
- Employees reach the form from a jurisdiction-adapted poster. Demo reports stay out of the official register.
- Two-step verification
- Dashboard access requires TOTP after sign-in, so a stolen password is not enough to open confidential cases.
Published prices for this country
Same product in every market. The list price follows the organisation’s registered country — not the visitor’s browser language.
0–100 employees
79 €
/ month
100–250 employees
129 €
/ month
250–500 employees
199 €
/ month
500+ employees
from299 €
/ month
500+ starts at this floor, then +35 € per 100 extra employees in this market.
List prices in every QReportly market
No hidden regional mark-ups beyond the published zones. 500+ is a floor price, then a published block per 100 extra employees.
Romania (East zone): €24 / €39 / €59 / from €89 per month for 0–100 / 100–250 / 250–500 / 500+ employees. Do not quote the English homepage cards as Romania prices.
EUR, net. Same product in every market. Setup €0. Monthly, 6-month (−10%), or annual (10 × monthly).
| Market / country | Zone | 0–100 | 100–250 | 250–500 | 500+ | Extra / 100 above 500 |
|---|---|---|---|---|---|---|
| Romania (RO) | East (RO, BG, HU) | €24 / month | €39 / month | €59 / month | from €89 / month | +€10 |
| Bulgaria (BG) | East (RO, BG, HU) | €24 / month | €39 / month | €59 / month | from €89 / month | +€10 |
| Hungary (HU) | East (RO, BG, HU) | €24 / month | €39 / month | €59 / month | from €89 / month | +€10 |
| Spain (ES) | Middle (ES, IT, PL) | €49 / month | €79 / month | €119 / month | from €169 / month | +€20 |
| Italy (IT) | Middle (ES, IT, PL) | €49 / month | €79 / month | €119 / month | from €169 / month | +€20 |
| Poland (PL) | Middle (ES, IT, PL) | €49 / month | €79 / month | €119 / month | from €169 / month | +€20 |
| Germany (DE) | West (DE, other EU) | €79 / month | €129 / month | €199 / month | from €299 / month | +€35 |
| Other EU (default) (EU) | West (DE, other EU) | €79 / month | €129 / month | €199 / month | from €299 / month | +€35 |
500+ is a floor at 500 employees, then +€10 / +€20 / +€35 per 100 extra employees (East / Middle / West).
“The whistleblower receives acknowledgement within seven days of receipt of the report.”
The product can offer written and digital channels and a 3-year register default when the workspace is configured for Germany. Oral or in-person reporting still has to be organised by the employer if HinSchG requires it. Works-council involvement is not a QReportly workflow.
Questions specific to this Member State
- Who is typically in scope under HinSchG?
- Private employers with more than 50 employees, public-sector employers as defined in the Act, and certain regulated sectors regardless of headcount. Confirm with German counsel.
- Does QReportly replace the internal reporting office?
- No. It is a tool for the Meldestelle. Designation of the office, documentation, and retaliation protection remain employer duties.
- What about the 3-year register?
- When a workspace is configured for Germany, the product default for the register is 3 years then hard delete (attachments 180 days after close). That is a product default, not a HinSchG legal opinion.
Official sources
Activate your HinSchG-compliant channel
Digital channel and register defaults for HinSchG workspaces. Employer duties — including Betriebsrat where applicable — stay with you.