WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Review

Six whistleblowing channels against one Belgian brief. Only one of them publishes a retention default, and the rule it has to meet is not written in days.

Article 22 keeps the report for as long as the working relationship; Article 21 keeps the names until the reported breach is time-barred. Every product here offers a period you configure, which is a different shape of answer.

A wall-mounted metal report box with a narrow slot and a small lock, bolted up beside a staff entrance. On a shelf beside it archive boxes stand square in a row, their printed spine labels reading 30 days, 90 days, 12 months and 5 years. The last box carries no printed label at all, only a handwritten paper strip long enough to run off the spine and curl under.

Draft, not yet edited. Written by Elin Sandberg, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

Article 22 of the Belgian whistleblowing law says how long a report is kept: for the duration of the contractual relationship the reporting person had with you. Article 21 says how long the names in it are kept: until the reported breach is time-barred.

Neither of those is a number. Every product built to hold those reports asks you for one.

That is not a small mismatch and it is not a drafting curiosity. It is the difference between a retention setting you can point at in an audit and a retention setting you will have to explain, and the explanation will be that the tool could not express the rule so somebody wrote a procedure beside it. Five products and one non-product were assessed against a single brief for this page. None of the six can express either Belgian rule. The ranking below is about everything else.

The brief, and who it is not for

A Belgian private-sector legal entity, 420 workers, head office in Brussels, one subsidiary in the Netherlands with sixty people. Regulated, in the sense that a supervisor may one day ask to see the internal reporting channel and the procedure around it. Two people in compliance, one of whom is the DPO, and an IT function of four that already owns more than it can patch.

Three consequences follow from the headcount alone. Above fifty workers the entity must have an internal channel at all: Article 8(3) of Directive (EU) 2019/1937, and Article 11 of the Belgian law of 28 November 2022. Above 250 workers it must accept anonymous reports and follow them up, under Article 8 §2 of the Belgian law — the derogation releasing smaller entities stops at 250, so a firm of 420 has no choice about a feature that vendors sell as a differentiator. And above 250 it loses the right, in Article 11 §4, to share the receipt of reports and any investigation with somebody else.

This page is not for the public sector, which the 28 November 2022 law does not cover. It is not for a firm below 250, whose specification is genuinely different and cheaper. And it is not for the Dutch subsidiary, whose own transposition was not opened for this piece; if the group's constraint is Dutch law rather than Belgian, stop reading here.

What was tested, and the five things that were not

The object under test is the documentation, not the software.

That needs saying plainly, because a comparison of marketing material is marketing. The defence is that the documentation is not a brochure in this purchase: it is the thing the buyer relies on, the thing that goes in the file, and the thing a supervisor asks to see when the question arrives three years later and nobody involved in the purchase still works there. So the test was this. Take the six questions Belgian law forces on the buyer, take each vendor's own current public pages, read them on 25 September 2026, and record what they answer, what they do not answer, and what they do not mention at all. Where a page does not say, this page says that it does not say, rather than filling the gap from a datasheet or a sales call.

What that leaves out, in order of how much it should bother you.

The software was not run. No case handler opened a case, nobody timed the seven-day acknowledgement against a real clock, and nothing here is a judgement about whether any of these products is pleasant or even workable to use. If your constraint is what the compliance officer's Tuesday looks like, this comparison is not for you and no page that has not watched somebody use the tool can be.

No data processing agreement and no ISO 27001 certificate was seen. None was publicly readable without a sales conversation or a login. Every sentence below about certification is a sentence about what a vendor's page claims, not about what a certificate covers, and the two differ most precisely where it matters: scope.

The telephone line was not tested, the language counts were not checked, and no price was negotiated. Published prices are published prices.

Sector rules were not followed. The Belgian law amends, among other things, the anti-money-laundering law of 18 September 2017; financial entities carry whistleblowing duties from more than one instrument and this page traces only one.

And no vendor was asked anything. Nobody was given the chance to answer in private what their page does not answer in public, which is a deliberate choice and a limitation at the same time: it measures disclosure, and disclosure is not the same as capability.

The shortlist, and what fell out before it

Six candidates. Five products whose documentation a buyer can read on a Sunday without speaking to anybody, and the option of not buying one.

What fell out fell out on that same test. The market for this software has dozens of sellers and a substantial number of them publish a landing page, a compliance claim and a demo form, and nothing else. Those were not carried forward, not because the products are bad — nothing here knows whether they are — but because there is nothing to assess. A vendor whose entire public artefact is a form has, for the purposes of this brief, declined to be compared.

The six criteria, and the weights

Weights are printed so you can disagree with them in a way that changes the answer.

CriterionThe rule behind itWeight
Retention expressible as the law writes itBelgian Articles 21 and 223
Oral reporting, and a record of the meetingArticle 12 §1, 1°; Article 22 §§2 to 43
Anonymous reports, with follow-up dialogueArticle 8 §2, compulsory above 250 workers2
Hosting and sub-processors named in publicGDPR Article 28, and Article 11 §42
Assurance you can read before signingNothing compels this. It is a procurement need1
A price visible without a sales callNothing compels this either1

One criterion is settled before the comparison starts and is therefore not scored. Article 11 §4 of the Belgian law says that where the channel is run internally or provided by a third party, "in both cases" the private-sector legal entity is regarded as the controller of the personal data. There is no procurement route out of controllership. Every vendor on this page is your processor, whatever its own materials imply about holding the data on your behalf, and the two vendors whose pages emphasise that they cannot technically read the reports are describing an engineering property, not a legal position.

The six, in the same order each time

None of the five vendors named on this page has a live sponsorship campaign with this publication. The campaign file was empty when this went up. If that changes while the page is still live, this paragraph changes with it, and the ranking does not.

GlobaLeaks. Publishes a retention default, which nobody else does: a per-channel policy configuring "automatic secure deletion of reports after a certain period of time", set to 90 days out of the box. What it does not publish is a price, because there is not one; the software is free and open source and you run it. Retention: the only documented default in the six, and expressed in days, which is the whole problem stated honestly rather than hidden. Where it would rank differently: last, immediately, if nobody in your four-person IT function wants to own a service whose failure mode is a confidentiality breach.

SpeakUp. Publishes the longest list of assurance artefacts — ISO 27001 certified, ISO 27002 and 27701 followed, ISAE 3000 Type II audited quarterly, SOC 2 and TISAX named — and is the only one whose public pages describe the oral limb of Article 12 in any detail: a web form, a phone line, a mobile app, an AI-powered voice agent, a proxy. What it does not publish, on the two pages read, is the hosting country, any sub-processor, any certificate scope, or the legal entity that would be countersigning your contract. Retention: "you set your own retention rules", with no unit, no default and no maximum. Where it would rank differently: first outright, if it named its hosting.

NAVEX WhistleB. Publishes the clearest supply-chain answer of the five: data stored in the EU, Microsoft Azure named as the hosting platform, a separate sub-processor page pointed at, and customer-controlled encryption such that "NAVEX and its suppliers are unable to access sensitive customer data". ISO 27001 and ISO 27018 named. What it does not publish on that page is any retention period, and it does not say where the vendor itself is incorporated, which for a sovereignty questionnaire is the second question and sometimes the first. Retention: not addressed. Where it would rank differently: first, if the criterion you weight at three is the named sub-processor rather than the retention rule.

EQS Integrity Line. Publishes the most specific physical answer: a named data centre in Munich East, ISO/IEC 27001 claimed for both the company and the data centres, ISAE 3000 Type I and II with the auditor named — PwC — plus CSA STAR and a WCAG bronze. The anonymity claim is explicit, with a dialogue function, and the site claims over 80 languages as standard. What it does not publish is a sub-processor list, any retention period, any certificate scope, or a price: the packages page returned a 404 on the day it was read. Telephone reporting is not mentioned on the pages read, which is not the same as absent, and this page does not claim it is. Retention: not addressed, though backups are described as kept "for several years", which is a different fact wearing the same coat.

Whistlelink. The only one of the five that prints prices, in bands by headcount: €79, €99, €149, €199, €299 a month as the workforce grows, and a conversation above a thousand. For a 420-person firm that is €199 a month, a figure you can put in a paper without three weeks of procurement. The pricing page also claims EU hosting, ISO 27001 certification, anonymous reporting, no IP logging, and "configurable retention times". What it does not publish is the detail behind any of that: the security page, requested the same day, returned a login prompt. Retention: configurable, unit unstated. Where it would rank differently: second, if the security material behind that password is as good as the pricing page implies — and a buyer can find that out in one email, which is more than can be said for the retention question.

The mailbox and the register. A named, independent recipient, a dedicated address, a written procedure, a diary that fires at seven days and at three months, and a register under Article 22. Costs nothing but somebody's attention and satisfies Article 12 on paper. What it does not do, at 420 workers, is accept anonymous reports in a way that survives contact with reality: an email channel identifies the sender, and building genuine anonymity yourself is the one part of this that is real engineering. Retention: perfect, and only here, because a procedure written by a person can say "until the breach is time-barred" and a dropdown cannot. Where it would rank differently: first, comfortably, below 250 workers, where the anonymity duty falls away and the whole purchase stops being necessary.

The verdict, with the situation attached

For this brief — 420 workers, Belgian, two compliance staff, four in IT — the order is GlobaLeaks, SpeakUp, NAVEX WhistleB, EQS Integrity Line, Whistlelink, and the mailbox last.

GlobaLeaks is first on the criteria as written and that result should be read as a warning rather than a recommendation. It wins because the criteria reward disclosure and self-hosting discloses everything by construction: you name the hosting because it is yours, there are no sub-processors because you engaged none, and the retention default is documented because the documentation is the product. It also hands a four-person IT team a confidentiality-critical service to run. If that team is already behind on patching, first place here is the wrong answer and the second-placed one is the right one.

SpeakUp is first among the things you can buy, on the strength of being the only vendor that publicly describes the oral reporting limb that Article 12 §1 actually requires and that the whole market quietly treats as optional. Fourth here, and second if the file you have to defend is the assurance file rather than the invoice: EQS names more artefacts, names its auditor, and names its building.

The retention criterion, weighted highest, was not won by anybody. Whatever you buy, somebody in your firm will write a document that says what the tool's number means in terms of Article 21 and Article 22, and that document — not the dropdown — is the thing the supervisor will read. Budget for writing it. It is the cheapest line in the purchase and the one most likely to be discovered missing.

What would make this page wrong

Four things, each of which would be a rewrite rather than an update.

A vendor publishing an event-based expiry — retention tied to the end of a working relationship, or to a limitation period, rather than to a count of days. That would move the highest-weighted criterion off zero for the first time and reorder everything below it.

Whistlelink opening its security page, or any of the four opening a certificate with a scope statement. Three of the six rankings here turn on what is not published, and publishing is cheap.

A Belgian court or the data protection authority saying what Article 22 §1 means for a report about a person who never worked for you, or for a reporter whose contract ended in 2019. The rule is drafted around a relationship and reports do not always arrive from inside one.

And the transposition changing. Belgium wrote the anonymity duty with a 250-worker cliff and the retention rules in events rather than periods; both are national choices, not Directive requirements, and the Directive itself says only that reports are stored "no longer than it is necessary and proportionate". A firm buying for four Member States is buying against four specifications, and this page has tested one.

Primary The document itself. Claims in this piece rest only on these.

  1. Directive (EU) 2019/1937 on the protection of persons who report breaches of Union lawOfficial Journal of the European Union, OJ L 305, 26.11.20192019-10-23Opened and read for this piece: Articles 6, 8, 9, 16, 17 and 18 in full, Article 26 for the transposition dates. Source for: the 50-worker threshold in Article 8(3); Article 8(5), that a channel may be operated internally or provided externally by a third party and that the Article 9(1) safeguards follow the third party; Article 8(6), that entities with 50 to 249 workers may share resources for receipt and investigation without shedding confidentiality, feedback or the duty to address the breach; Article 9(1)(b), acknowledgement within seven days of receipt; Article 9(1)(f), feedback within three months of the acknowledgement or of the expiry of the seven days; Article 9(2), that channels enable reporting 'in writing or orally, or both', that oral reporting is by telephone or other voice messaging, and that a physical meeting follows on the reporting person's request; Article 6(2), that whether anonymous reports must be accepted is left to Member States; Article 16(1), confidentiality of identity; Article 17, that personal data manifestly not relevant shall not be collected or shall be deleted without undue delay; Article 18(1), that reports are stored 'no longer than it is necessary and proportionate' with no period given, and 18(2) to (4) on recording calls and meetings. The Directive sets no retention period in months or years, and the body says so. National transposition law other than the Belgian act below was not opened.
  2. Loi du 28 novembre 2022 sur la protection des personnes qui signalent des violations au droit de l'Union ou au droit national constatées au sein d'une entité juridique du secteur privéMoniteur belge, numac 2022042980, published 15 December 20222022-11-28Read in the French consolidated text on the Moniteur belge site on 25 September 2026. Read closely: Article 6 §§1 to 3 (who counts as a reporting person, including relationships that have ended); Article 8 §§1 to 3, source for the duty on private-sector entities to accept anonymous reports and follow them up, and for the derogation releasing entities with fewer than 250 workers from it; Article 11 §§3 to 5, source for the statement that the channel may be run internally or provided by a third party and that 'in both cases the private-sector legal entity is regarded as the controller' of the personal data, and for resource-sharing below 250 workers; Article 12 §1, points 1 to 6, source for the channel taking reports in writing or orally or both, oral reporting by telephone or other voice messaging systems, the physical meeting on request within a reasonable time, the seven-day acknowledgement, diligent follow-up including of anonymous reports, and the three-month feedback; Article 21, source for the rule that the name, function and contact details of the reporting person, of anyone covered by protection and of the person concerned are kept until the reported breach is time-barred; Article 22 §1, source for the register of all reports received and for reports being kept 'for the duration of the contractual relationship referred to in Article 6 §§1 and 2'; Article 22 §§2 to 4 on recordings, transcripts and minutes of meetings. Not read closely: Chapter on external reporting, the sanctions provisions, and the sectoral amendments, of which Article 42 amending the anti-money-laundering law of 18 September 2017 was seen but not followed up. Article 11 §2 carries an exception that is disapplied for entities in financial services; it was not read closely enough to describe here and nothing in the body rests on it. The Dutch-language text was not compared against the French.
  3. Whistlelink pricing pageWhistlelink2026-09-25Read on 25 September 2026. Primary as to what the vendor published on that date, and not evidence that any claim on it is true. Source for the six price bands printed on the page, read as monthly figures in euro, and for the page's own phrases 'Data hosted in EU', 'ISO 27001 certified', 'Automatic data retention & deletion policies', 'Configurable retention times', 'Anonymous and confidential reporting' and 'No IP logging of whistleblowers'. The page names no retention period, no data centre, no sub-processor and no certificate scope. Contract length, invoicing terms and what a negotiated price looks like were not checked.
  4. Whistlelink security pageWhistlelink2026-09-25Requested on 25 September 2026 and returned a login prompt: 'this page contains private content. To view this page please enter your username and password below.' Source for one statement only, that the vendor's security documentation was not publicly readable on that date. Whether the material behind it is good was not assessed and cannot be.
  5. EQS Integrity Line security pageEQS Group2026-09-25Read on 25 September 2026. Primary as to what the vendor published that day. Source for: the named data centre in Munich East and its ISO 14001 certification; ISO/IEC 27001 held by EQS Group and by the data centres; ISAE 3000 Type I and Type II audited by PwC; Cloud Security Alliance STAR registry; WCAG bronze; the claim that report and case data are encrypted at all times such that 'EQS Group can at no time access your or your whistleblowers' data'; and daily backups stored for several years in geographically distributed data centres. The page states no certificate scope, publishes no sub-processor list, names no retention period and does not address IP logging.
  6. EQS Integrity Line product siteEQS Group2026-09-25Read on 25 September 2026. Source for 'Fully anonymous reporting with dialogue function', 'Available in over 80 languages as standard', and for the absence of any price: the routes offered are a free trial and a demo booking. The packages page at /product/packages/ returned HTTP 404 when requested the same day. Telephone or voice reporting is not mentioned on the page and the body says only that, not that the product lacks it.
  7. SpeakUp security, privacy and compliance assurances pageSpeakUp2026-09-25Read on 25 September 2026. Source for the assurance artefacts named: ISO 27001 certified; ISO 27002 and ISO 27701 followed; ISAE 3000 Type II audited quarterly; SOC 2 and TISAX also named. The page names no hosting country, no sub-processor, no certificate scope and no retention period, and the body says so.
  8. SpeakUp FAQSpeakUp2026-09-25Read on 25 September 2026. Source for the channels the vendor lists — 'a web form, a phone line, SpeakUp's mobile app (iOS and Android), an AI-powered voice agent, or a proxy' — and for the retention wording, 'Cases remove automatically after a defined retention period, and you set your own retention rules'. No unit, no default and no maximum is given. The FAQ names no hosting country, no legal entity that contracts with the customer, and no sub-processor.
  9. NAVEX WhistleB data privacy, security and legal compliance pageNAVEX2026-09-25Read on 25 September 2026. Source for: 'Data is stored in the EU with customer-controlled encryption, so NAVEX and its suppliers are unable to access sensitive customer data'; ISO 27001 and ISO 27018 named, and the Cloud Security Alliance; Microsoft Azure named as the hosting and development platform; a separate 'WhistleB Third Party Service Provider' page referenced as holding up-to-date sub-processor information; and Microsoft Translator described as not writing text to persistent storage. The page states no retention period and does not state where the vendor itself is incorporated. The referenced sub-processor page was not opened, and the body says so.
  10. GlobaLeaks project siteGlobaLeaks2026-09-25Read on 25 September 2026. Source for: free and open source, source code public, self-hosted with installation documentation, and the site's own claim of compliance with Directive (EU) 2019/1937. The site discusses no commercial hosted service and publishes no price. Whether the compliance claim holds was not assessed; a claim of compliance made by a vendor about its own product is not evidence, and the body treats it as a claim.
  11. GlobaLeaks administrator documentation, user interface sectionGlobaLeaks2026-09-25Read on 25 September 2026. Source for the per-channel data retention policy, described as making it possible 'to configure automatic secure deletion of reports after a certain period of time', and for the statement that 'by default a channel is configured with a report expiration of 90 days'. The documentation expresses retention only as a period; it offers no event-based expiry, which is the point the body rests on. The rest of the administrator documentation was not read.
  12. Vendor data processing agreements, ISO 27001 certificates and their scope statementsNot seen by this desk for any of the five products. None was publicly readable without a sales conversation or a login on 25 September 2026. Every statement in the body about certification is a statement about what a vendor's public page claims, not about what a certificate covers, and the body says so in the method.
  13. Wet bescherming klokkenluiders (Netherlands) and other national transpositionsNot opened. The brief includes a Dutch subsidiary and the body says plainly that the Dutch position was not tested. Nothing here should be read as advice about any Member State other than Belgium.

Elin Sandberg

Comparisons

I follow consumer tech and product launches, reviewing what is worth your money and what is just a press kit. I have strong opinions on battery life and even stronger ones on keyboards.