Glossary
Whistleblowing and compliance terms, in plain language.
The vocabulary you meet in the EU Whistleblowing Directive, in procurement questionnaires and in your own DPA conversations. Short definitions, no jargon.
Why this list
One word, one meaning.
Whistleblowing vocabulary drifts between the directive, national law, auditors and vendors. These are the definitions we use, and the ones we hold ourselves to in our own product and documentation.
Terms
Definitions.
- Whistleblower
- A person who reports a breach of law or serious wrongdoing they learned about in a work-related context. Under Directive (EU) 2019/1937 that covers employees, contractors, suppliers, shareholders and volunteers.
- Whistleblowing
- Reporting that breach through an internal channel, an external channel, or both.
- Internal reporting channel
- The confidential route inside an organisation for receiving reports. Mandatory in the EU for organisations with 50 or more employees.
- External reporting channel
- A route outside the organisation, such as a supervisory authority or an ombudsman. Reporters may use it instead of, or after, the internal channel.
- Directive (EU) 2019/1937
- The EU Whistleblowing Directive. It requires member states to protect reporters and to oblige organisations to run internal channels. Transposition deadline: 17 December 2021.
- Acknowledgment
- Written confirmation to the reporter that their report was received. Due within 7 days under the Directive.
- Feedback
- The information given to the reporter about the follow-up to their report. Due within 3 months of the acknowledgment.
- Follow-up
- Every step taken after a report arrives: assessment, investigation, decision and the response to the reporter.
- Retaliation
- Any detriment suffered because someone reported, such as dismissal, demotion or harassment. Prohibited by the Directive.
- Anonymous reporting
- A report submitted without identifying details. Ashio's reporting pages set no cookies and record no IP addresses.
- Confidential reporting
- A report where the organisation knows who reported, but their identity is protected from wider disclosure.
- End-to-end encryption
- Encryption performed in the reporter's browser, so the server only ever stores ciphertext and cannot read the report.
- Zero-access architecture
- A design in which the operator cannot decrypt customer content at all, even with direct database access.
- Audit trail
- The immutable, timestamped record of every event on a case: created, assigned, acknowledged, answered, closed.
- Pseudonymisation
- Replacing identifying data with a reference, so it can no longer be attributed to a person without additional information.
- Retention period
- How long personal data is kept before it is deleted. Set by your organisation, within the limits of the law.
- ISO 37002
- The international standard for whistleblowing management systems. It describes how a channel should be governed, operated and reviewed.
- ISO 27001
- The information security standard. The servers Ashio runs on are ISO 27001 certified, in Switzerland.
See the definitions in a running channel.
The 7-day and 3-month deadlines, the audit trail and end-to-end encryption are all in the product. 14-day free trial, no card.
