Who this applies to
Two thresholds, two distinct obligations
The French Sapin II law, supplemented by the law of 21 March 2022 transposing the EU whistleblower directive, requires a procedure for collecting reports from 50 employees upwards. The anti-corruption programme targets companies with 500 employees or more and a turnover above 100 million euros.
In many organisations, the channel boils down to a shared mailbox, which guarantees neither anonymity, nor a timestamped register, nor deadline tracking. Employees do not trust it, and a legitimate report can get lost in it.
Sapin II Toolkit is set up by the compliance officer, the HR director, the CISO or the ethics officer, often after an inspection, a merger, a tender or a new appointment. Handling the alerts stays in your hands, and our partners can support you with that. Hosting on your own infrastructure is not offered.
From 50 employees
Companies and associations with at least 50 employees, public bodies and local authorities with at least 50 staff. Legal basis: Sapin II law, as amended by the law of 21 March 2022 (EU Directive 2019/1937).
500 employees and 100 million euros in turnover
Legal basis: Sapin II law (2016). Sanctions by the French Anti-Corruption Agency (AFA) of up to €200,000 for individuals and €1,000,000 for legal entities. The module dedicated to the eight pillars of the programme is under development.
Dashboard
The ethics officer’s register, deadlines included
- Overview of reports, tracking of regulatory deadlines, overdue alerts highlighted. Timestamped register, filters by status, category and entity, CSV export for your audits.
- Each alert is attached to the entity or site concerned. A group sets up its legal entities as separate sites, and the dashboard aggregates everything.
- If the ethics officer leaves the company, access is transferred from the settings: the new officer receives an invitation and takes over the existing cases.
Confidentiality
The whistleblower’s confidentiality, guaranteed technically
The whistleblower chooses a password when filing. Exchanges with the ethics officer are protected by that password, which nobody else holds, including at the vendor. That password cannot be reset, and that is intentional: it is the only way to access the messaging.
The system is aligned with the CNIL reference framework of 10 January 2019. The legal basis for processing is legal obligation (article 6.1.c of the GDPR) and consent is not required. The form displays the GDPR notice, the DPO address is configurable, and retention periods are automated: two months if the alert is not pursued, five years in case of disciplinary follow-up.
Each organisation has its own data space, and the public form is protected against automated submissions. A security audit report under NDA, a data protection impact assessment, the record of processing activities and a CNIL compliance grid are available on request. The details of the measures is published on the application’s Security and compliance page.
Identity and content kept apart
The whistleblower’s identity, if given, and the content of the alert are processed separately. The ethics officer accesses the content of the alert but not the whistleblower’s identity, unless they hold the confidentiality guarantor role.
No sensitive data by email
Notifications contain neither the description of the alert, nor the whistleblower’s identity, nor attachments. Only a case reference and a link to the platform.
An unguessable URL
Each organisation’s form address includes a random identifier. It cannot be found by enumeration or from the company name.
The Make IT Safe suite