DISS-CO-Main-logo
  • Plataforma Smart Integrity
    • Software de canal de denuncias
    • Gestión de reclamaciones
    • Sistema de denuncia de irregularidades eLearning
  • Gestión de Servicios
    • Compliance Outsourcing
    • Implantación del canal de denuncias
    • Apoyo a la investigación
    • Sistemas de gestión de compliance
    • Diligencia debida reforzada
  • Recursos
    • Blog
    • Podcast
    • Libro Blanco
    • FAQ
    • Suscríbete
  • Acerca de
    • Nuestros directivos
    • Nuestra misión y visión
    • Noticias
    • Eventos
  • Hazte socio
  • ES
    • EN
    • DE
    • FR
  • Iniciar sesión

Contact Info

    • info@diss-co.tech
Symbolic picture Shortcomings of an internally developed whistleblowing system

21. mayo 2022

  • By  benjamin
  • 0 comments

Shortcomings of an internally developed whistleblowing system

What is the background of a feedback system?

Feeback systems are in the field of market research. The aim is to find out as much information as possible about the object and the person in order to adjust performance and services. In this context, answer options are often given, which means that the feedback provider “only” has to choose. Open-ended suggestive questions are asked, in which the answer is already contained in the question. The design and questioning process are also geared towards getting as many answers as possible and statistically evaluating the amount of answers afterwards. These systems are shaped by current trends, whose significance plays a much greater role than the exact results.

What data is collected in the background?

In the feedback system, the information provided by the feedback giver is additionally enriched by self-collected data about the feedback giver. Feedback providers are tracked and additional information is stored. The actual goal of tracking users is to obtain their identity. Through the IP, for example, the location is localised, mouse movements and clicks are analysed in order to divide the feedback givers into user groups. Various data sets are passed on to third parties and exchanged to obtain more complete tracking. Google products, such as Google Analytics and AdWords, are used in almost every area of marketing. In addition, data is shared with advertising and analytics companies. have suffered reprisals. Also, obligated parties do not have to set up anonymous reporting offices, which experience shows is essential for the protection of the whistleblower in the majority of whistleblower cases. In addition, it is up to the whistleblower to determine when and if he or she is liable or even punishable for obtaining and passing on information, and is not protected by not protected by the Whistleblower Protection Act. The red line becomes a legal problem and crossing the red line becomes a risk for the whistleblower.

Anonymity in feedback or complaint systems does not exist

The backend of feedback systems may be designed to be data protection compliant, but they do not fully respect anonymisation. It is generally assumed that due to the mass of data and the lack of interest in restoring complete profiles, anonymisation can be guaranteed by simple measures such as omitting the last digits of the IP. This also seems sufficient for an everyday feedback process. The use of a whistleblowing system, on the other hand, is not an everyday occurrence for reporters. The data collected remains manageable, which means that the anonymisation measures of a feedback or complaints system are not fully effective. It is also doubted whether individual, concrete measures, such as the shortening of the IP, could guarantee the protection of a whistleblower. The anonymisation measures usually used in marketing do not stand up to an IT forensic analysis, for example in the context of a criminal trial – and are of course not designed for this.

What characterises a good whistleblowing system?

Whistleblowing systems are characterised by the fact that they are closely adapted to the applicable regulations and take them into account in a holistic approach. This does not necessarily manifest itself in appearance. At first glance, there seem to be many solutions that could be considered as a whistleblowing system. The real know-how of regulatory compliance solutions is not in the outward design. There are many different solution steps, each of which is closely linked to regulations. These are combined into a holistic concept and reside in the backend of a system. This includes several security layers, encryption and well thought-out deletion and storage concepts. Whistleblowing systems are designed to be open and objective. The whistleblower should have the feeling of being able to decide freely. When submitting a report, he has already decided of his own accord to take the time. It is neither advisable nor necessary to “shuffle through” the form. Rather, the aim is to obtain high-quality information. This is achieved when the whistleblower feels safe and can be made to feel in a serious manner that he or she can help uncover wrongdoing. Every incoming tip must be processed and confirmed individually.

Conclusión

Whistleblowing systems should completely refrain from storing IPs and further tracking. Collecting user data – as well as sharing it – is far from the actual purpose of a whistleblowing system. Even if IP and other user data are not stored in self-developed software at a certain point in time, it is possible for developers to allow storage by changing the code. Many programmers also like to leave backdoors open in order to be able to act flexibly. Therefore, self-developed solutions in the area of anonymous whistleblower software should be avoided.

 

Read more about the possible solutions to deal with the new whistleblower protection law.

Plataforma Smart Integrity
Tags:
Compliance, Education, Homepage, Investigation, Legislation, Regulators/Authorities, SaaS, Canal de denuncias
  • Share:

Categorías

  • AML/CFT
  • Analytics
  • Artificial Intelligence
  • Blockchain
  • BPDD
  • Diligencia debida del socio comercial
  • Compliance
  • Education
  • EU measures
  • EU Sanction
  • GDPR
  • Homepage
  • Industrie 4.0
  • Internet of Things
  • Investigation
  • Know Your Customer
  • KYC
  • Legislation
  • Regulators/Authorities
  • SaaS
  • Science
  • Supplier Due Diligence
  • Cadena de suministro
  • Uncategorized
  • Canal de denuncias

Search

Categories

  • AML/CFT (1)
  • Analytics (1)
  • Artificial Intelligence (1)
  • Blockchain (5)
  • BPDD (1)
  • Diligencia debida del socio comercial (1)
  • Compliance (26)
  • Education (3)
  • EU measures (7)
  • EU Sanction (1)
  • GDPR (1)
  • Homepage (9)
  • Industrie 4.0 (1)
  • Internet of Things (1)
  • Investigation (8)
  • Know Your Customer (1)
  • KYC (1)
  • Legislation (3)
  • Regulators/Authorities (6)
  • SaaS (12)
  • Science (1)
  • Supplier Due Diligence (2)
  • Cadena de suministro (4)
  • Uncategorized (4)
  • Canal de denuncias (21)

Popular Tags

AI AML analytics anonymous Blockchain CFT cloud based platforms compliance digital transformation EU Authority EU Directive Hinweisgebersystem Industrie 4.0 internal investigation Internet of Things (IoT) protection act Referentenentwurf Regulator smart integrity platform Software Supplychain whistle whistleblower protection act whistleblower Software whistleblowing Whistleblowing system whistleblowing tool

iso_1

Enlace rápido

  • Blog
  • Contáctanos
  • Suscríbete
  • FAQ
  • Política de privacidad
  • Condiciones generales

Información de contacto

    Aviso legal
    Mail: info[at]diss-co.tech

DISS-CO ® © 2023 All Rights Reserved

Utilizamos cookies en nuestro sitio web para ofrecerle la experiencia más relevante recordando sus preferencias y visitas repetidas. Al hacer clic en "Aceptar todas", consiente el uso de TODAS las cookies. No obstante, puede visitar "Configuración de cookies" para dar un consentimiento controlado.
Aceptar todo Configuración de cookiesSeguir leyendo Reject All
Gestionar el consentimiento

Protección de datos

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necesario
Siempre activado
Las cookies necesarias son absolutamente esenciales para que el sitio web funcione correctamente. Estas cookies garantizan funcionalidades básicas y características de seguridad del sitio web, de forma anónima.
CookieDuraciónDescripción
cookielawinfo-checkbox-analytics11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Analytics".
cookielawinfo-checkbox-functional11 mesesLa cookie se establece por el consentimiento de cookies GDPR para registrar el consentimiento del usuario para las cookies en la categoría "Funcional".
cookielawinfo-checkbox-necessary11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. Las cookies se utilizan para almacenar el consentimiento del usuario para las cookies de la categoría "Necesarias".
cookielawinfo-checkbox-others11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Otros".
cookielawinfo-checkbox-performance11 mesesEsta cookie es establecida por el plugin GDPR Cookie Consent. La cookie se utiliza para almacenar el consentimiento del usuario para las cookies de la categoría "Rendimiento".
viewed_cookie_policy11 mesesLa cookie es establecida por el plugin GDPR Cookie Consent y se utiliza para almacenar si el usuario ha consentido o no el uso de cookies. No almacena ningún dato personal.
Funcional
Las cookies funcionales ayudan a realizar determinadas funciones, como compartir el contenido del sitio web en plataformas de redes sociales, recopilar opiniones y otras funciones de terceros.
Rendimiento
Las cookies de rendimiento se utilizan para comprender y analizar los índices de rendimiento clave del sitio web, lo que ayuda a ofrecer una mejor experiencia de usuario a los visitantes.
Analytics
Las cookies analíticas se utilizan para comprender cómo interactúan los visitantes con el sitio web. Estas cookies ayudan a proporcionar información sobre métricas el número de visitantes, la tasa de rebote, la fuente de tráfico, etc.
Publicidad
Las cookies de publicidad se utilizan para ofrecer a los visitantes anuncios y campañas de marketing relevantes. Estas cookies rastrean a los visitantes en todos los sitios web y recopilan información para ofrecer anuncios personalizados.
otros
Otras cookies no categorizadas son aquellas que están siendo analizadas y aún no han sido clasificadas en una categoría.
GUARDAR Y ACEPTAR
Funciona con CookieYes Logo
  • +4940226392510
  • Contáctanos
  • LinkedIn
  • Reserve una demostración gratuita