Skip to main content

Sapin II Toolkit

The Sapin II whistleblowing channel, up and running in 5 minutes

Secure public form, password-protected confidential messaging, regulatory deadline tracking, alerts routed to each entity. Nothing to install, and your data is hosted in France and in Europe.

Free plan up to 5 reports per month. One email address for the ethics officer is enough to start.

Who this applies to

Two thresholds, two distinct obligations

The French Sapin II law, supplemented by the law of 21 March 2022 transposing the EU whistleblower directive, requires a procedure for collecting reports from 50 employees upwards. The anti-corruption programme targets companies with 500 employees or more and a turnover above 100 million euros.

In many organisations, the channel boils down to a shared mailbox, which guarantees neither anonymity, nor a timestamped register, nor deadline tracking. Employees do not trust it, and a legitimate report can get lost in it.

Sapin II Toolkit is set up by the compliance officer, the HR director, the CISO or the ethics officer, often after an inspection, a merger, a tender or a new appointment. Handling the alerts stays in your hands, and our partners can support you with that. Hosting on your own infrastructure is not offered.

Whistleblowing channel

From 50 employees

Companies and associations with at least 50 employees, public bodies and local authorities with at least 50 staff. Legal basis: Sapin II law, as amended by the law of 21 March 2022 (EU Directive 2019/1937).

Anti-corruption programme

500 employees and 100 million euros in turnover

Legal basis: Sapin II law (2016). Sanctions by the French Anti-Corruption Agency (AFA) of up to €200,000 for individuals and €1,000,000 for legal entities. The module dedicated to the eight pillars of the programme is under development.

Obligations

Five legal requirements, and Sapin II Toolkit’s answer to each

An accessible reporting channel

Internal, open to anonymous reports.

Secure public form, accessible without an account or an app, on mobile, with preset categories and attachments. Anonymous or named reporting.

An acknowledgement within 7 working days

From receipt of the report.

Automatic alert to the ethics officer, deadline tracking in the dashboard.

Feedback to the whistleblower within 3 months

On the measures envisaged or taken.

Automatic reminders at day 6 and day 80, built-in secure messaging.

Confidentiality of the whistleblower’s identity

And of any person implicated.

Password-protected messaging, no identifying data in notifications.

A traceable register of alerts

For your audits and controls.

Timestamped history of every action, CSV export.

Dashboard

The ethics officer’s register, deadlines included

  • Overview of reports, tracking of regulatory deadlines, overdue alerts highlighted. Timestamped register, filters by status, category and entity, CSV export for your audits.
  • Each alert is attached to the entity or site concerned. A group sets up its legal entities as separate sites, and the dashboard aggregates everything.
  • If the ethics officer leaves the company, access is transferred from the settings: the new officer receives an invitation and takes over the existing cases.

Confidentiality

The whistleblower’s confidentiality, guaranteed technically

The whistleblower chooses a password when filing. Exchanges with the ethics officer are protected by that password, which nobody else holds, including at the vendor. That password cannot be reset, and that is intentional: it is the only way to access the messaging.

The system is aligned with the CNIL reference framework of 10 January 2019. The legal basis for processing is legal obligation (article 6.1.c of the GDPR) and consent is not required. The form displays the GDPR notice, the DPO address is configurable, and retention periods are automated: two months if the alert is not pursued, five years in case of disciplinary follow-up.

Each organisation has its own data space, and the public form is protected against automated submissions. A security audit report under NDA, a data protection impact assessment, the record of processing activities and a CNIL compliance grid are available on request. The details of the measures is published on the application’s Security and compliance page.

Identity and content kept apart

The whistleblower’s identity, if given, and the content of the alert are processed separately. The ethics officer accesses the content of the alert but not the whistleblower’s identity, unless they hold the confidentiality guarantor role.

No sensitive data by email

Notifications contain neither the description of the alert, nor the whistleblower’s identity, nor attachments. Only a case reference and a link to the platform.

An unguessable URL

Each organisation’s form address includes a random identifier. It cannot be found by enumeration or from the company name.

Plans

A free plan, a Pro plan on request

Free

€0

Up to 5 reports per month, one site or entity, the public form and the secure messaging, email support.

Start for free

Pro

Quote on request

Unlimited reports, sites and entities, CSV export, automatic email notifications, form customisation (logo, colours, wording), priority support.

Get in touch

Already a customer of the Make IT Safe platform? Contact your usual account manager to activate your access.

The Make IT Safe suite

The GRC platform and the dedicated solutions

Set up your whistleblowing channel

A free space and a public form ready to share. The messaging can only be read by the whistleblower and the officer.