The proposed Whistleblower Protection Act (HinSchG) is intended to ensure better protection for so-called “whistleblowers” in the interest of uncovering misconduct. The focus is on protecting employees so they can report problems within their own companies without the risk of sanctions. Less attention has been paid to the fact that the new law also affects the enforceability of NDAs with third parties outside the company and, in certain cases, renders NDAs unenforceable.
Example: When NDAs become worthless
We’ll begin this admittedly rather long post with an example to illustrate the absurdity of the situation:
A company holds a valid permit under environmental protection law to operate a facility. The company commissions an external engineering firm to examine whether – and under what conditions – exhaust emissions could be reduced. Naturally, the company and the engineering firm enter into an NDA, under which the engineering firm agrees to keep the results confidential. The assessment concludes that, with a certain financial investment, the company can reduce emissions by 90% using new filter technology. Management decides to install the filters only after the permit expires in order to save costs.
The highly motivated employee at the engineering firm is outraged, writes a long letter to the Federal Office of Justice (explanation to follow shortly), and, when there is no response, turns to the press. A media firestorm ensues, leading to a slump in orders and significant job cuts.
Consequences for the engineering firm and its highly motivated employees: None.
That can’t be right, can it? Then read on…
Background: The Whistleblower Protection Act
Information provided by internal whistleblowers plays an important role in uncovering misconduct. As is well known, the implementation of the “Whistleblower Directive” (Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law) is intended to strengthen the protection of whistleblowers. However, the provisions of the German draft law (HinSchG-E), as well as those of the Directive, contain several provisions that have received less attention in public debate and pose serious risks to the protection of sensitive information. This applies in particular to the protection of information in relation to external service providers, who – though this may seem surprising at first glance – are included within the scope of protection of these regulations.
Personal scope of application and protection
The central provision of the law is the prohibition on retaliation set forth in Section 36 HinSchG-E. This provision prohibits causing any detriment to a whistleblower or persons close to them on the basis of the disclosure of information regarding misconduct under the law. The legislature, in turn, defines who qualifies as a whistleblower in Section 1(1) of the HinSchG-E: Protection is afforded to anyone who, “in connection with their professional activities” (or in the lead-up to them), obtains information about misconduct and discloses it within the framework of the Act.
This definition encompasses not only events within an employee’s own company, that is, within the employer-employee relationship. The connection to professional activities extends far beyond this, as many employees also gain knowledge of events and, where applicable, irregularities at third-party companies. This is particularly evident in the case of individuals who, for example, work as independent management consultants or testing engineers and evaluate and assess processes or facilities at their clients’ sites, that is, third-party companies. Employees of maintenance companies or other service providers also gain knowledge of processes both within their own company and at their clients’ companies as part of their professional activities.
Crucially, the prohibition on retaliation also applies to these individuals (Section 34 no. 2 HinSchG-E). Thus, if a management consultant, test engineer, or employee of a maintenance company reports irregularities in the client’s operations, the imposition of sanctions is – in principle – prohibited by law.
Material scope of application
The material scope of application of the HinSchG extends far beyond the requirements of European law. It covers all violations that constitute (or may constitute) a violation of criminal law, as well as all violations punishable by a fine, provided that the provision imposing the fine serves to protect life, health, or employee safety. In addition, as provided for by the Directive, the scope of application includes violations of a very, very long list of European directives and regulations. This affects a wide variety of regulations, including those on product and food safety, environmental protection, consumer and data protection, tax law, and the protection of consumers against unfair advertising. Thus, the scope covers everything from systematic tax evasion to trivial misrepresentations regarding the characteristics of products (even those of low value).
Even more noteworthy is the definition of the term “violation” in the HinSchG. This term is of central importance because only “violations” may be reported. A “violation” is, first and foremost, an act or omission that is unlawful and falls within the scope of Section 2 of the HinSchG-E. Furthermore, a “violation” also exists when an act is “abusive” because it runs counter to the objective or purpose of the regulations listed in the catalog. This broad interpretation creates the risk of reports regarding conduct that is lawful but possibly (only) morally questionable and gives rise to significant risks of abuse (see example).
What types of reports are permitted under the HinSchG?
If a whistleblower has obtained information about violations in connection with their professional activities, they are not permitted – even under the HinSchG – to handle this information in any arbitrary manner. Rather, they are authorized only to contact an internal or external reporting office. An internal reporting office must be established at all companies with at least 50 employees (Section 12 (2) HinSchG-E) and is intended to provide a means of handling reports of violations through an orderly procedure. However, the internal reporting office is not obligated to accept reports from individuals outside the company. In our example above, the concerned employee of the engineering firm might therefore not even be able to voice his frustration within the company.
There is thus also a risk that the whistleblower will contact the external reporting office directly—the legislature has designated a separate department of the Federal Office of Justice for this purpose (Section 19 HinSchG-E). However, the whistleblower always has the right to choose whether to report to an internal or external reporting office. The prohibition on retaliation therefore also applies if an internal reporting office is generally willing to accept reports from non-employees, but the whistleblower nevertheless contacts the Federal Office of Justice directly as the external reporting office.
Section 28 of the HinSchG-E then governs the procedure before the reporting office. The reporting office must provide the whistleblower with feedback on the progress of the matter within three months, or six months at the latest (Section 28 (4) HinSchG-E). It is conceivable that the reporting office may request information from the company concerned as well as from all relevant authorities and/or take further follow-up measures. A typical follow-up measure would be, for example, forwarding the report to the competent market surveillance authority (which usually leads to further, unpleasant questions) or, in our case, to the wastewater authority. If the whistleblower does not receive feedback on the follow-up measures within the three- or six-month deadline, they are authorized to disclose the information (Section 32 (1) no.1b) HinSchG-E), i.e., to publish it, for example, through the press. The mere inaction of the Federal Office of Justice thus grants the whistleblower the right to release potentially highly sensitive information to the public.
This is where things get interesting: Since a permit has been issued in our example case, there is no longer any reason whatsoever for the Federal Office of Justice to provide any feedback at all. The matter may be forwarded to the competent environmental authority, which would then, however, refer back to the permit. It is quite conceivable that this procedure would then “fall by the wayside” at the authority. In that case, however, the motivated employee is then authorized to publish the information in the press.
The HinSchG eliminates enforceability of the NDA
Of particular interest in this section is, of course, the question of how the new law resolves the conflict between confidentiality obligations and the right to report and disclose violations. Unsurprisingly (though shocking to this extent), this comes at the expense of confidentiality.
Section 5 of the HinSchG-E clarifies that a report or disclosure may not be made if the information falls within the scope of various public-law confidentiality provisions. Furthermore, the activities of most professionals bound by professional secrecy- including their employees – are expressly excluded from the scope of the law (at least). Thus, information that a lawyer or a law firm’s assistant obtains in the course of their professional activities may not be the subject of a report or disclosure under the HinSchG-E. In this respect, professional confidentiality obligations remain unrestricted.
In Section 6(1) and (2) of the HinSchG-E, the legislature then stipulates that measures to protect trade secrets and all forms of confidentiality agreements are effectively worthless as soon as the information concerns a “violation” within the meaning of the law’s extremely broad definition. Pursuant to Section 6 (1) of the draft, trade secrets may be disclosed to the reporting office; Section 6 (2) of the HinSchG-E extends the authority to report or disclose to information that is subject to a contractual duty of confidentiality without constituting a trade secret. The only requirement for reporting is that the whistleblower has reasonable grounds to believe that the disclosure is necessary to uncover a violation, and that the reported information is truthful and falls within the scope of the law.
Practical implications
This creates the following situation for companies: Any company that engages third-party companies or service providers – for example, for consulting or for the maintenance, inspection, or improvement of production facilities – typically enters into a confidentiality agreement with those service providers. To the extent that the service provider’s employees discover indications of “violations” within the meaning of the HinSchG in the course of their work, this confidentiality agreement is unenforceable. Employees are permitted to report information about violations. The client may not take retaliatory action against its service provider, nor may the service provider itself sanction the employee. This also precludes the enforcement of contractual penalty claims for breach of the NDA, and the client may not even terminate the contract, as this would also constitute retaliation.
It is obvious that this – with the legislature’s approval – leads to a significant potential for blackmail. It is difficult to envision any legal recourse. It is unlikely to be possible to circumvent this undesirable legal situation – as is commonly done, for example, to avoid the strict German law governing general terms and conditions – by choosing a different legal system in contracts with service providers. Rather, at least for the time being, the only solution is likely to be to exercise even greater care in selecting contractual partners.