Whistleblowing EU

Open-source whistleblowing software (Malta)

Does your organisation in Malta need a secure, ethical whistleblowing solution aligned with the Protection of the Whistleblower Act (Cap. 527)?

GlobaLeaks is the free, open-source software created to:

Find out more in the official documentation.

Documentation Demo

The EU Whistleblowing Directive

The EU Whistleblowing Directive requires organisations to maintain secure, confidential reporting channels and to protect whistleblowers from detrimental action.

In Malta the Directive is implemented through amendments to the Protection of the Whistleblower Act (Chapter 527 of the Laws of Malta). Public bodies and private employers with 50 or more workers must operate internal reporting channels; external reports are handled by the designated Whistleblowing Reports Units.

Legal obligations and compliance

Reference Obligation How GlobaLeaks satisfies it
art. 12(1)(a) Establish secure internal reporting channels for receiving written or oral reports, and a meeting on request, designed to protect the confidentiality of the reporting person and to prevent access by unauthorised staff members. Deployed on the organisation's own servers and released under a free, open-source licence that anyone can audit, GlobaLeaks gives each employer a dedicated channel for whistleblowing reports under Cap. 527. Written submissions with file attachments, voice recordings and requests for a face-to-face meeting are all supported; encryption shields reports and attachments, and access is restricted to authorised handlers only, keeping the reporting person's identity out of unauthorised hands. Full anonymity is possible thanks to the integration of Tor technology.
art. 12(1)(b)-(c) Designate an impartial reporting officer to maintain communication with the reporting person, request further information where needed, and diligently follow up on the report. The whistleblowing reporting officer stays in touch with the reporting person over an asynchronous two-way exchange that never exposes who they are, making it possible to ask clarifying questions, gather additional evidence and pursue every report diligently.
art. 13(1) Acknowledge receipt of the report to the reporting person within 7 days of that receipt. An acknowledgement of receipt is generated the moment a report is filed - well inside the statutory 7 days - and doubles as the credential the reporting person uses to return to their case.
art. 13(1) Provide feedback to the reporting person within a reasonable time not exceeding 3 months from the acknowledgement of receipt. Configurable deadlines with countdown timers, automatic reminders and an overview dashboard keep the 3-month feedback obligation on schedule, with updates reaching the whistleblower through the same identity-shielding exchange.
art. 6(1) and 6(4) Ensure absolute non-disclosure of the identity of the reporting person, which cannot be compelled even by court order. Reports may be filed fully anonymously - with no IP logging and minimal metadata, no identifying record then exists to be disclosed - while for confidential reports access to the reporting person's identity remains locked to expressly authorised handlers.
art. 6A Personal data processing compliant with the GDPR, following data minimisation. Running entirely on the organisation's own infrastructure with no external services or dependencies - and with no IP records and minimal metadata - puts the GDPR data-minimisation principle into practice.
art. 21A(1) Keep a register of reports received and retain records for no longer than is necessary and proportionate. Each report is entered into an organised register with configurable retention periods, and a privacy-respecting audit trail documents its handling while entry to the records remains limited to authorised staff.
art. 21A(2)-(4) Document oral reports in a durable and retrievable form, including recordings or minutes of meetings where applicable. Voice recordings and the notes of requested meetings are stored alongside the case file in a durable, retrievable format, so oral whistleblowing reports can be documented, reviewed and kept confidential.

Beyond legal compliance: standards and recognitions

The platform is likewise conceived to form part of a whistleblowing management system following the ISO 37002:2021 guidelines, and to back the reporting-channel requirements of certifiable standards such as ISO 37001 (anti-bribery) and ISO 37301 (compliance management).

On the security side, the software is conceived to operate as part of an information security management system following ISO/IEC 27001:2022: whistleblowing reports and any attachments are safeguarded with encryption, and only expressly authorised operators may access them. The GDPR principles of data protection by design and by default (Regulation (EU) 2016/679) are likewise built in: minimal data, no IP address records and as little metadata as possible.

Accessibility, too, has been engineered in: the design keeps compatibility with the WCAG 2.1 AA guidelines and European standard EN 301 549 in mind - the technical baseline of both the European Accessibility Act (Directive (EU) 2019/882) and Directive (EU) 2016/2102 on public sector websites - allowing anyone to submit a whistleblowing report securely and unaided. In Malta the reference instruments are S.L. 418.03 (accessibility of public sector websites) and the Accessibility Measures (European Accessibility Act) Regulations (S.L. 627.03).

A listing in the Digital Public Goods Alliance registry as a Digital Public Good further attests that this is free, open-source software working for the public good.