On 24 July 2023, the new Hungarian whistleblowing legislation came into force, introducing significant obligations for companies with more than 50 employees.

The Whistleblowing Protection Act allows companies to outsource the operation of their internal whistleblowing system to a whistleblowing lawyer or an external organisation. Members of our legal team offer whistleblower protection advocacy services and work closely with Reportee‘s whistleblower protection software developers to provide the most comprehensive and professional service to our clients.

The Whistleblower Protection Act is the Act XXV of 2023 on complaints, notifications of public interest and rules on the notification of abuse, which serves the domestic implementation of Directive 2019/1937 of the European Parliament and of the Council (EU). Under the Act, employers who employ more than 50 employees (by employees we mean natural persons who perform activities for and under the direction of the employer within the framework of an employment relationship for remuneration, including temporary agency workers) are required to establish and operate an internal abuse reporting system. The Act sets out a number of important requirements for internal abuse reporting systems and requires that potential whistleblowers be provided with clear and easily understandable information on how the system works. An important element of the Act is also the strict requirements for the protection of whistleblowers to ensure that whistleblowers do not suffer labour and other disadvantages as a result of reporting.

What are the legal requirements for an internal whistleblowing system?

The Whistleblower Protection Act outlines several mandatory procedural requirements for operating an internal whistleblowing system. Companies must adhere to the following obligations:

•          offer the option of whistleblowing in writing or verbally,

•          check the pertinence of the subject of the report and the validity of the allegations made, contact the whistleblower and, if necessary, request further information,

•          maintain the confidentiality of the whistleblower and the person/people affected by the whistleblowing,

•          comply with documentation obligations, including recording the content of the verbal reports in writing and acknowledging receipt of the whistleblowing report within seven days,

•          take follow-up measures (e.g. internal investigation, discontinuation of investigation, forwarding the information to authorities),

•          provide information on the operation of its own reporting channel, the related procedure and the main provisions of the Whistleblower Protection Act in an easily accessible manner. In practice, this means that a policy on the operation of the internal reporting channel is to be prepared and communicated by e-mail or on the company’s website.

Why does the whistleblowing system benefit companies, in addition to fulfilling their legal obligations?

An effective and secure system encourages whistleblowers to use the company’s internal reporting channels first, rather than taking action against the company with the authorities. If there are whistleblowing channels available to whistleblowers that whistleblowers trust and that work effectively, whistleblowers will generally prefer to use internal channels. This is particularly true if the whistleblower believes that the breach can be dealt with effectively within the organisation concerned, even in a completely anonymous way, and without risk of exposure or retaliation. A well-functioning system is also useful for company managers and owners, as it can provide them with important information about problems and risks affecting the operation of their business. By taking appropriate and rapid action, a business can avoid significant legal risks and in some cases save unnecessary costs simply by reorganising its processes, reorganising its staff, introducing additional controls, etc. Therefore, the proper operation of an abuse reporting system can also reduce costs and optimise business costs.

Who is obliged to set up an abuse reporting system?

Under the Whistleblower Protection Act, all companies with 50 or more employees are required to have an internal abuse reporting system. Employees are natural persons who perform activities for and under the direction of an employer in the context of an employment relationship for remuneration. It is important to include temporary agency workers in the number of employees. For other businesses carrying out specific activities as defined in the law (including credit institutions, financial service providers, auditors, accountants, tax advisors, law firms, real estate firms, oil and gas companies), regardless of the number of employees, a mandatory abuse reporting system is required.

Which companies with less than 50 employees are required to set up an abuse reporting system?

In certain cases, companies are required to operate a whistleblowing system even if they have fewer than 50 employees.. The Whistleblower Protection Act does not contain this list, the list can be found in Article 1(1) and (1a) of Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (known by its abbreviation: Pmt.). This includes, among others, credit institutions, financial service providers, auditors, accountants, tax advisors, law firms, real estate companies, oil and gas companies.

How long has the Whistleblower Protection Act been in force?

The Whistleblower Protection Act entered into force on 24 July 2023 and became applicable to companies with 250 or more employees immediately from the date of entry into force of the Act. For companies with fewer than 250 employees, the established a grace period: it will apply from 17 December 2023 for organisations with between 50 and 249 employees.

What happens if a company does not comply with the regulations?

The investigation of compliance with the Whistleblowing Protection Act is carried out by the employment supervisory authority and, if it determines that the whistleblowing system does not meet the requirements set out in the legislation, it may impose a warning as a sanction or, in the case of an infringement discovered during the administrative procedure, an order to cease the infringement or a finding of fact. Demonstration of a compliant  whistleblowing system may also be relevant in a number of other areas, e.g. in the context of ESG legal compliance, supplier rating and customer rating audits. The use of systems and solutions that raise data security concerns or do not meet the GDPR’s principle-level requirements (e.g. purpose limitation, data minimisation, limited storage, integrity and confidentiality) carries a significant risk of data protection fines.

How should potential whistleblowers be informed and what should the information contain?

Clear and easily accessible information should be provided on the functioning of the internal whistleblowing system, the whistleblowing process, and the whistleblowing systems and procedures. Importantly, the information should not only be made available to employees, as the company also has an obligation to inform other potential whistleblowers. Information is considered to be easily accessible if, for example, it is placed on the company’s website. The information should not only cover the functioning of the internal whistleblowing system, but also the functioning of the separate (i.e. external) whistleblowing systems set up by the public authorities. Moreover, the information on data management required by the GDPR should not be overlooked. Reportee‘s team can help you produce legally compliant notices.

Who can report?

Employees, sole traders and sole traders with a contractual relationship with the business, persons with an ownership interest in the business, and persons on the administrative, management or supervisory bodies of the business (including where the contractual relationship has been initiated or has ended), trainees and volunteers working for the business may notify. In addition, contractors, subcontractors, suppliers and persons working under their direction who have a contractual relationship with the enterprise may also be notified. These persons may also submit a declaration even if they are still in the process of establishing a legal relationship or if their legal relationship has already ended.

What can be the subject of a notification?

Under the Whistleblower Protection Act, a report can be made in relation to any unlawful or suspected unlawful act or other abuse. For example, data breaches, cybersecurity breaches, suspected fraud, economic corruption, tax violations, competition law violations, suspected cartel agreements, discrimination, workplace harassment, etc. In the context of product safety, suppliers can play a key role in identifying possible unfair and illegal manufacturing, importing and distribution practices involving unsafe products. An interesting feature of the Hungarian legislation is that it allows for a much wider scope of whistleblowing than the EU legislation. The Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report infringements of EU law only applies to reports of infringements of certain areas of EU law (e.g. product safety, product liability, transport safety, environmental protection, consumer protection, privacy and personal data protection, cyber security, corporate tax). The different scope of the reporting is one of many arguments for Hungarian companies to set up a separate reporting system from other foreign companies in the business-to-business sector.

What are the data protection requirements for an internal whistleblowing system?

The operation of an internal whistleblowing system involves the processing of data of both the whistleblower and the person who is the subject of the whistleblowing. The company operating the whistleblowing system, as the data controller, is obliged to prepare a privacy notice on the data processing related to the operation of the system and to communicate it to the data subjects, i.e. the (potential) whistleblowers and the persons potentially affected by the whistleblowing. The processing activity should also be recorded in the company’s register of processing activities.

The Whistleblower Protection Act strictly regulates the possible purposes of the processing, the recipients to whom the personal data may be transferred and the controller’s obligations to erase the data. In addition, specific rules apply to the transfer of personal data to countries outside the EU.

Why is it preferable to have an external organisation or a whistleblower protection lawyer in charge of receiving and investigating notifications, rather than having a person or unit within the organisation in charge of this task?

Practical experience shows that whistleblowers have much more confidence in whistleblowing schemes where whistleblowers are investigated by an external party and where it is ensured that the whistleblower’s details are not disclosed to the organisation’s management. This is because potential whistleblowers fear negative consequences, such as changes in their perception within the organisation and possible indirect negative discrimination at work, despite the legal requirements.