11.10.2022

It is advisable to start preparing a whistleblowing channel now

The government proposal for the whistleblower legislation obligates large and medium-sized enterprises as well as public sector actors to establish an internal reporting channel through which, for example, the personnel can report suspected misconduct. The legislation is based on the EU Whistleblowing Directive.

As a general rule, the whistleblowing channel must be established in companies that employ at least 50 people

The new whistleblower legislation that is being drafted mainly obligates companies or public sector actors that employ at least 50 people to establish an internal reporting channel. Through the channel, the company’s employees, for example, can report suspected misconduct that concerns the violation of certain legislation, such as consumer protection, environmental protection, data protection or public procurement. When submitting a report, the whistleblower is protected in the manner required by the Act. The Act also provides a period during which the company can exclusively examine the reports.

At the moment, the Act is being discussed by Parliament, and it is to enter into force within three months from its approval. By then, companies that employ at least 250 people will have to adopt an internal whistleblowing channel. The government bill, however, includes a transitional period under which private sector organisations that regularly employ 50–249 people must adopt a whistleblowing channel by 17 December 2023 at the latest.

The whistleblower legislation is based on the EU Whistleblowing Directive, which must be implemented into national legislation by the EU Member States. In Finland, the drafting of the whistleblower legislation has been delayed from the original timetable. In some EU Member States, the Directive has already been implemented into national legislation.

Establishing an internal whistleblowing channel

The main purpose of the new regulation is to protect the whistleblower from retaliation and to provide the organization receiving the report an opportunity to appropriately investigate the suspected misconduct internally. Furthermore, the new legislation will set minimum requirements for the establishment of the whistleblowing channel and for the procedures for processing notifications, such as the processing times and confidentiality. The organisation can largely decide the technical implementation itself, and under certain boundary conditions, it is also possible to outsource the maintenance of the channel to a service provider. According to the proposal, companies that belong to the same group can under certain conditions establish a common reporting channel.

The regulation also creates new obligations to inform for the organisations. Stakeholders that are entitled to report suspected misconduct must, among other things, be informed of the internal whistleblowing channel, the possibility to report through an external reporting channel maintained by the authorities and of the requirements for protecting the whistleblower. In addition, the persons responsible for processing the reports must be appointed and trained in the processing.

Data protection obligations must be taken into account

Requirements based on data protection legislation and, with respect to the personnel, also on the Co-operation Act, must be taken into account so that the reports submitted through the reporting channel and personal data included in them can legally be processed. A whistleblowing channel that meets data protection obligations along with proper data protection documentation are key tools for an organisation to demonstrate that they are in compliance with legislation. 

The processing of personal data collected through the whistleblowing channel is subject to the same privacy obligations as the processing of other personal data. For example, the legal basis and purposes for processing personal data as well as how long the data is stored must be defined in accordance with statutory requirements and any unnecessary personal data must be deleted. The individuals whose data is processed must also be informed of the processing, and the organisation must make sure that the statutory data subjects’ rights are respected. It is important to keep in mind that the new legislation sets certain exceptional limits to the rights of the data subjects. In addition, the Finnish data protection authority: Data Protection Ombudsman has ruled that controllers must conduct a data protection impact assessment on data processing relating to whistleblowing channels.

How to prepare for the new obligations?

A whistleblowing channel that meets the requirements of the new legislation protects the company as well as the whistleblower, because a whistleblowing channel makes it possible for the company to uncover misconduct and provides a period during which the company can exclusively process reports. Though the legislation is still being drafted, it is advisable to prepare for the adoption of a channel now. First, it is advisable to make an assessment of the necessary measures.

Latest references

We advised Valio Oy in its acquisition of Raisio Oyj’s plant protein business, related fixed assets and the Härkis® and Beanit® fava bean brands. The fixed assets include, among other things, the production equipment of the factory that makes plant protein products in Kauhava. The transaction supports Valio’s strategy to grow from a dairy company to a food company. This business acquisition will make us an even more significant developer and producer of plant-based protein products. The demand for these products will grow in the long term, and a great deal of growth potential still remains. In 2022, we acquired the Gold&Green® business and, since then, we have been carrying out strong product development and renewed the brand. Following successful product launches, sales in the last quarter of 2024 increased by about 50% from the previous quarter. With this acquisition, we are building our own production capacity. The production equipment of the Kauhava factory is just right for our needs and situation. says Kimmo Luoma, Valio’s Senior Vice President. Valio is a Finnish dairy and food company founded in 1905 and owned by Finnish dairy cooperatives. Valio has subsidiaries in Sweden, Estonia, the United States and China. In 2023, the Group had a turnover of EUR 2 278 million and more than 4 000 employees.
Case published 14.2.2025
We advised WithSecure Corporation in the sale of its cybersecurity consulting business to Neqst. WithSecure is a global cyber security company (listed on NASDAQ OMX Helsinki). Neqst is a Swedish investment firm, focusing on technology companies. The closing of the transaction remains subject to customary conditions and regulatory approvals.
Case published 24.1.2025
We advised 24 Pesula group in a transaction where Juuri Partners made an investment in Finland’s largest self-service laundry chain, 24 Pesula. Juuri Partners’ investment supports 24 Pesula’s strategy of strengthening its domestic market leadership, developing digital services, and expanding internationally. 24 Pesula, founded in 1999, has established a strong market position in the self-service laundry market with over 50 locations in Finland. The company has its own production facilities in Nokia, Finland. In the UK, 24 Pesula currently operates in four locations, and the company plans to expand into other international markets in the coming years. Juuri Partners is a Finnish private equity company, which invests in Finnish growth focused SMEs and offers financing to established and profitable SMEs in Finland.
Case published 20.12.2024
We are acting as a counsel to Fortum in a transaction in which Fortum is strengthening its renewable power project pipeline through the acquisition of a project development portfolio from Enersense. The debt-and-cash free purchase price is approximately EUR 9 million, with the potential for project-specific earn-outs subject to projects successfully reaching a final investment decision in the future. The transaction is subject to customary closing conditions and is expected to be completed during the first quarter of 2025. Fortum is a leading Nordic energy company with the purpose to power a world where people, businesses and nature thrive together. Fortum’s core operations comprise of efficient, CO2-free power generation as well as reliable supply of electricity and district heat to private and business customers. The company is listed on Nasdaq Helsinki. One of Fortum’s strategic targets is to develop at least 800 MW of ready-to-build onshore wind and solar projects by the end of 2026.
Case published 19.12.2024