DISS-CO
  • Plataforma Smart Integrity
    • Software de canal de denuncias
    • Gestión de reclamaciones
    • Sistema de denuncia de irregularidades eLearning
  • Gestión de Servicios
    • Compliance Outsourcing
    • Implantación del canal de denuncias
    • Apoyo a la investigación
    • Sistemas de gestión de compliance
    • Diligencia debida reforzada
  • Recursos
    • Blog
    • Podcast
    • Libro Blanco
    • FAQ
    • Suscríbete
  • Acerca de
    • Nuestros directivos
    • Nuestra misión y visión
    • Noticias
    • Eventos
  • Hazte socio
  • ES
    • EN
    • DE
    • FR
  • Iniciar sesión

Contact Info

    • info@diss-co.tech
symbolic picture web-based whistleblowing system by DISS-CO

2. noviembre 2022

  • By  benjamin
  • 0 comments

¿Qué es un sistema de denuncia por Internet?

A web-based software de canal de denuncias allows a whistleblower to submit a breach report digitally, anonymously or confidentially. A browser and an intact Internet connection are required.

What are the advantages of web-based whistleblowing software?

The so-called SaaS (Software as a Service) is cloud-based, does not require installation on the company’s end devices and enables simple and fast implementation. Further advantages are the reduced IT administration effort, as no own servers have to be operated and updates installed. The software ensures device- and location-independent access at all times. Data centres certified to the ISO 27001 standard guarantee data security through a professional IT security management system. Storage space can be expanded at any time. If requirements change, adjustments can be made to the software.

The high degree of flexibility, data security and protection of in-house IT resources make SaaS very attractive to companies and public authorities.

What are the advantages of a web-based whistleblowing system?

DISS-CO’s web-based whistleblowing system is a secure solution with many selectable modules, integrations and customisation options. The whistleblower software, which can also be used as complaint management software, offers dashboards and intuitive case management that store sensitive personal and case-related data centrally, is GDPR compliant and unmanipulable. Encrypted communication allows further information to be obtained from the whistleblower, who can choose between anonymous and confidential reporting. The anonymity of the whistleblowing system is essential and builds trust. By removing the metadata of the file attachments, the whistleblower system ensures technical anonymisation. Internal communication, as well as communication with advisors can also take place exclusively on the platform in encrypted form. This reduces the risk of data leakage. An individual authorisation concept can be used to regulate access within the organisation. If the internal reporting office is wholly or partially outsourced, external personnel have access to the information via an authorisation concept. Persons assisting in investigating a case can easily and quickly obtain permit for task management without having to view the entire case. This allows the person responsible for the case to maintain an overview of the tasks at all times and to define deadlines and dependencies. In addition, a Kanban board provides an overview of the status of pending and ongoing tasks. For audit security, all information is recorded and cannot be changed until the final deletion of the entire case. The software also reminds of the legal deadlines.

El tratamiento centralizado, seguro e inmanipulable de la información en relación con una comunicación segura, respetando al mismo tiempo el anonimato de la persona que facilita la información, permite una tramitación eficaz de los expedientes.

The disadvantages of the e-mail solution as a whistleblowing channel in companies

1) No control over data processing

Many companies still provide a general e-mail address for reporting violations.

Si la persona que da el chivatazo quiere permanecer en el anonimato, no hay forma de evitar una cuenta de correo electrónico anónima. Crear una cuenta de correo electrónico con un proveedor de correo privado es muy fácil y gratuito hoy en día. Sin embargo, este método tiene varias desventajas y riesgos.

The e-mails are usually unencrypted, which creates a security risk for the company. In addition, employees are practically forced to transmit internal company information via a private e-mail provider. The sensitive information could be tapped during transmission or afterwards. The usual US e-mail providers, such as Google and Yahoo, transmit the data to servers in the US or elsewhere, or to subcontractors or affiliates, who in turn process and transmit information to their subcontractors and affiliates. For users, the strand of data processing is not transparent. If, for example, US authorities are involved in external investigations, the providers are obliged to cooperate and must transmit the information and e-mails to the authorities. The data subjects are not informed about the transfer. In both cases, the consequence is that sensitive internal company information is passed on and processed in an uncontrolled manner.

2) Risks for the person providing the information

Employees also sometimes use their private devices, depending on the structure and IT policies of the company. Either because they do not need end devices such as laptops and smartphones for their work or because there is a bring-your-own policy or the use of private end devices for company purposes is not regulated. This poses a high risk for the data subject. In the past, there have repeatedly been whistleblower cases with criminal consequences for the whistleblower due to the transfer of company information into the private sphere. The data was transferred either physically or digitally for the purpose of transmission to external reporting bodies or to the press from the company environment, sometimes after the person suffered reprisals due to an internal report. It is not relevant whether, for example, one or more file folders are physically transferred or the data is transferred digitally to external storage media or by e-mail. What is relevant is the transfer itself. In addition, the scope of the transferred data is relevant.

Las transmisiones de datos a través de los dispositivos finales de la empresa y desde la red de la empresa pueden rastrearse utilizando varios métodos. Esto puede revelar la identidad del informador anónimo. Más seguro es el uso del software de alerta por Internet Smart Intergity Platfom por parte de DISS-CO y la aplicación de las directrices asociadas, que, entre otras cosas, prohíben el seguimiento del uso de la URL específica por parte de TI.

3) The importance of metadata

If file attachments are attached to the report, the identity of the whistleblower can be identified via the metadata. The metadata is attached to each file and provides information about the author, the users and the history of the file. If the whistleblower is skilled enough to remove the metadata him/herself, the information cannot be traced. We know from practice that only a small percentage of people who usually report whistleblowing have the technical knowledge or are willing to read up on it in detail. Therefore, DISS-CO’s whistleblowing software automatically removes the metadata from anonymous reports.

4) DLP Tools

In addition, for security reasons, some companies have so-called data loss prevention (DLP) tools in place that can record and monitor all actions. DLP tools can be used preventively to avoid data theft, but they are also very suitable for employee monitoring and can endanger the anonymity of the whistleblower. Whistleblowers are well advised to inform themselves in advance about the use of DLP tools if they wish to use the whistleblowing system for anonymous reporting.

5) Conclusión

Using an e-mail address as an internal whistleblowing channel offers many risks for the company and the denunciante. Sensitive information within the company is processed and forwarded externally in an uncontrolled manner, could be misused and cause financial and reputational damage. The possible negative consequences for the whistleblower reduce trust in the whistleblowing system, which leads to lower use of the whistleblowing system. This in turn leads to violations going undetected for longer.

By implementing a secure web-based whistleblowing system such as DISS-CO’s Smart Integrity Platform, companies and authorities can provide security to whistleblowers and uncover risks at an early stage.

Book a free demo now and get advice from our experts.

PRUEBA UNA DEMO GRATUITA
Tags:
Blockchain, Compliance, Education, Homepage, Investigation, SaaS, Uncategorized, Canal de denuncias
  • Share:

Categorías

  • AML/CFT
  • Analytics
  • Artificial Intelligence
  • Blockchain
  • BPDD
  • Diligencia debida del socio comercial
  • Compliance
  • Education
  • EU measures
  • EU Sanction
  • GDPR
  • Homepage
  • Industrie 4.0
  • Internet of Things
  • Investigation
  • Know Your Customer
  • KYC
  • Legislation
  • Regulators/Authorities
  • SaaS
  • Science
  • Supplier Due Diligence
  • Cadena de suministro
  • Uncategorized
  • Canal de denuncias

Search

Categories

  • AML/CFT (1)
  • Analytics (1)
  • Artificial Intelligence (1)
  • Blockchain (4)
  • BPDD (1)
  • Diligencia debida del socio comercial (1)
  • Compliance (25)
  • Education (3)
  • EU measures (7)
  • EU Sanction (1)
  • GDPR (1)
  • Homepage (8)
  • Industrie 4.0 (1)
  • Internet of Things (1)
  • Investigation (8)
  • Know Your Customer (1)
  • KYC (1)
  • Legislation (3)
  • Regulators/Authorities (6)
  • SaaS (11)
  • Science (1)
  • Supplier Due Diligence (2)
  • Cadena de suministro (4)
  • Uncategorized (3)
  • Canal de denuncias (21)

Popular Tags

AI AML analytics anonymous Blockchain CFT cloud based platforms compliance digital transformation EU Authority EU Directive Hinweisgebersystem Industrie 4.0 internal investigation Internet of Things (IoT) protection act Referentenentwurf Regulator smart integrity platform Software Supplychain whistle whistleblower protection act whistleblower Software whistleblowing Whistleblowing system whistleblowing tool

Enlace rápido

  • Blog
  • Contáctanos
  • Suscríbete
  • FAQ
  • Política de privacidad
  • Condiciones generales

Información de contacto

    Aviso legal
    Mail: info[at]diss-co.tech

DISS-CO ® © 2023 All Rights Reserved

Utilizamos cookies en nuestro sitio web para ofrecerle la experiencia más relevante recordando sus preferencias y visitas repetidas. Al hacer clic en "Aceptar todas", consiente el uso de TODAS las cookies. No obstante, puede visitar "Configuración de cookies" para dar un consentimiento controlado.
Aceptar todo Configuración de cookiesSeguir leyendo Reject All
Gestionar el consentimiento

Protección de datos

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necesario
Siempre activado
Las cookies necesarias son absolutamente esenciales para que el sitio web funcione correctamente. Estas cookies garantizan funcionalidades básicas y características de seguridad del sitio web, de forma anónima.
CookieDuraciónDescripción
cookielawinfo-checkbox-analytics11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Analytics".
cookielawinfo-checkbox-functional11 mesesLa cookie se establece por el consentimiento de cookies GDPR para registrar el consentimiento del usuario para las cookies en la categoría "Funcional".
cookielawinfo-checkbox-necessary11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. Las cookies se utilizan para almacenar el consentimiento del usuario para las cookies de la categoría "Necesarias".
cookielawinfo-checkbox-others11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Otros".
cookielawinfo-checkbox-performance11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Rendimiento".
viewed_cookie_policy11 mesesLa cookie es establecida por el plugin GDPR Cookie Consent y se utiliza para almacenar si el usuario ha consentido o no el uso de cookies. No almacena ningún dato personal.
Funcional
Las cookies funcionales ayudan a realizar determinadas funciones, como compartir el contenido del sitio web en plataformas de redes sociales, recopilar opiniones y otras funciones de terceros.
Rendimiento
Las cookies de rendimiento se utilizan para comprender y analizar los índices de rendimiento clave del sitio web, lo que ayuda a ofrecer una mejor experiencia de usuario a los visitantes.
Analytics
Las cookies analíticas se utilizan para comprender cómo interactúan los visitantes con el sitio web. Estas cookies ayudan a proporcionar información sobre métricas el número de visitantes, la tasa de rebote, la fuente de tráfico, etc.
Publicidad
Las cookies de publicidad se utilizan para ofrecer a los visitantes anuncios y campañas de marketing relevantes. Estas cookies rastrean a los visitantes en todos los sitios web y recopilan información para ofrecer anuncios personalizados.
otros
Otras cookies no categorizadas son aquellas que están siendo analizadas y aún no han sido clasificadas en una categoría.
GUARDAR Y ACEPTAR
Funciona con CookieYes Logo
  • +4940226392510
  • Contáctanos
  • LinkedIn
  • Reserve una demostración gratuita