The interplay between the GDPR and new whistleblowing laws strikes a delicate balance between protecting data and promoting disclosure. While the GDPR protects personal data, recent whistleblowing legislation encourages individuals to disclose misconduct.
Organisations need to align these frameworks by ensuring that reporting channels comply with GDPR principles.
Privacy, data minimisation and lawful processing become essential to protect both the identity of whistleblowers and the personal data involved, and ultimately to foster a culture of accountability.