Claude
Skills
Sign in
Back

whistleblower-policy-malik-taiar

Included with Lifetime
$97 forever

Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Covers EU Directive 2019/1937, the amended Sapin II law (Waserman 2022), Decree 2022-1284, CNIL guidelines, public sector requirements, and duty of vigilance.

Data & Analyticsassets

What this skill does


# Whistleblower Systems - Assessment & Drafting

## Overview
This Guide can help you (a) assess the compliance of an existing whistleblower system or (b) draft a reporting policy based on a provided template.

## Legal Framework Covered
- EU Directive 2019/1937
- Amended Sapin II Law (Waserman Law 2022)
- Decree No. 2022-1284
- CNIL Professional Alerts Framework

### Two Modes of Use

| Mode | Description | Output |
|------|-------------|--------|
| **A. Compliance Assessment** | Audit an existing system | Assessment report + action plan |
| **B. Policy Drafting** | Create a system based on referenced sources | Policy based on template |

### What This Skill Does / Does Not Do

| What this skill does | What it does not do |
|:---------------------|:---------------------|
| Assesses compliance of an existing system | Provide definitive legal conclusions |
| Drafts a reporting policy based on the provided template | Guarantee enforceability |

**Scope**: Internal reporting systems subject to the amended Sapin II Law and Decree No. 2022-1284.

> **Variation Callouts**:
> - **Public Sector**: Coordination with Art. 40 CPP
> - **Duty of Vigilance**: Companies with ≥ 5,000 / 10,000 employees

## Contents

```
/
├── SKILL.md
├── LICENSE.txt
├── README.md
├── assets/
    ├── Template_Politique_Lanceur_Alerte.docx ← Template for Mode B
    ├── [PDF sources]
└── references/
    ├── TEXTES_LEGAUX.md      ← Verbatim legal article citations
    ├── DECRET_PROCEDURE.md   ← Mandatory elements (Decree 2022-1284)
    ├── RGPD_CNIL.md          ← GDPR compliance and CNIL framework
    ├── FONCTION_PUBLIQUE.md  ← Public sector specifics + Art. 40 CPP
    └── VIGILANCE.md          ← Duty of vigilance coordination
```

## DISCLAIMER

**THIS IS NOT LEGAL ADVICE.** This skill is provided for informational and educational purposes only. Laws vary by jurisdiction and individual circumstances, and only a qualified lawyer can provide advice tailored to your specific situation. This does not constitute legal advice or opinion—it is a Claude skill intended for legal professionals. All outputs from this skill must be reviewed by a qualified legal professional before any legal use.

## Choosing the Mode of Use

### Mode A: Compliance Assessment
**When to use**: The client already has a system and wants to verify its compliance.

→ Go to **Section 3** (Inputs) then **Section 5** (Assessment Workflow)

### Mode B: Policy Drafting
**When to use**: The client does not have a system or wants to create a new one.

→ Go to **Section 3** (Inputs) then **Section 13** (Policy Drafting)

| Template | Format | Usage |
|:---------|:-------|:------|
| `Template_Politique_Lanceur_Alerte.docx` | Word | Internal reporting policy template |

> **IMPORTANT**: The template must be used **EXACTLY** as provided. Only variable elements should be adapted.

## Inputs to Collect (request before assessing)

### A. Organizational Context (mandatory)
- [ ] Legal form and headcount (threshold ≥ 50 employees/agents?)
- [ ] Business sector and status (private/public/mixed)
- [ ] Group structure (pooling possible?)
- [ ] Existing system: implementation date, post-Waserman update?

### B. Documentation to Request
- [ ] Internal reporting procedure
- [ ] Employee communication materials
- [ ] Templates used (acknowledgment, feedback, closure)
- [ ] Job description / designated officer appointment
- [ ] GDPR register / DPIA if existing

### C. Practical Constraints (recommended)
- [ ] Pooling with other entities considered?
- [ ] Outsourcing of reception channel?
- [ ] Coordination with other systems (duty of vigilance)?

## Deliverables - Mode A: Assessment

### Quick Start (default output)

ALWAYS produce:
1) **Executive Summary** (1 page)
2) **Phase-by-Phase Assessment Table** (8 phases)
3) **Recommended Action Plan**

### A. Executive Summary
- [ ] Overall compliance: Compliant / Partially Compliant / Non-Compliant
- [ ] Top 5 gaps identified (ranked by priority)
- [ ] Recommendation: "Compliant" / "Correct before deployment" / "Escalate"

### B. Detailed Assessment Table

| Phase | Checkpoint | Compliant | Gap Identified | Priority | Recommendation |
|-------|-----------|:--------:|----------------|:--------:|----------------|
| **1. Applicability** | | | | | |
| 1.1 | Headcount threshold met (≥ 50) | | | | |
| 1.2 | Entity type identified (private/public/mixed) | | | | |
| 1.3 | Pooling compliant if applicable (< 250, concurrent decision) | | | | |
| **2. Reception Channel** | | | | | |
| 2.1 | Written **OR** oral channel provided (entity's choice) | | | | |
| 2.2 | *If oral provided*: telephone or voicemail mentioned | | | | |
| 2.3 | *If oral provided*: video/in-person meeting on request (20 business days) | | | | |
| 2.4 | Ability to transmit any type of document | | | | |
| 2.5 | Written acknowledgment within 7 business days | | | | |
| **3. Designated Persons** | | | | | |
| 3.1 | Formal designation for receipt | | | | |
| 3.2 | Formal designation for processing | | | | |
| 3.3 | Sufficient competence | | | | |
| 3.4 | Sufficient authority | | | | |
| 3.5 | Sufficient resources | | | | |
| 3.6 | Impartiality safeguards in place | | | | |
| 3.7 | If outsourced: third-party obligations compliant | | | | |
| **4. Verification / Processing** | | | | | |
| 4.1 | Admissibility criteria defined (Art. 6 + Art. 8 I.A.) | | | | |
| 4.2 | Reporter informed if inadmissible | | | | |
| 4.3 | Follow-up for non-compliant reports specified | | | | |
| 4.4 | Follow-up for anonymous reports specified | | | | |
| 4.5 | Written feedback within 3 months | | | | |
| 4.6 | Feedback content compliant (measures + reasons) | | | | |
| 4.7 | Reasoned closure provided | | | | |
| 4.8 | Written closure notification to reporter | | | | |
| **5. Confidentiality** | | | | | |
| 5.1 | Information integrity guaranteed | | | | |
| 5.2 | Reporter identity confidentiality | | | | |
| 5.3 | Persons concerned confidentiality | | | | |
| 5.4 | Third parties mentioned confidentiality | | | | |
| 5.5 | Access restricted to authorized persons | | | | |
| 5.6 | Prompt transmission to designated persons | | | | |
| 5.7 | If oral: recording procedures defined | | | | |
| 5.8 | Reporter's right to verify/approve | | | | |
| 5.9 | Retention period limited | | | | |
| **6. Dissemination / Information** | | | | | |
| 6.1 | Procedure disseminated with sufficient publicity | | | | |
| 6.2 | Permanently accessible to eligible persons | | | | |
| 6.3 | Whistleblower status conditions | | | | |
| 6.4 | Categories of eligible persons | | | | |
| 6.5 | Reporting procedures (form, channels) | | | | |
| 6.6 | Processing timelines (7-day acknowledgment, 3-month feedback) | | | | |
| 6.7 | Confidentiality guarantees | | | | |
| 6.8 | Protections granted | | | | |
| 6.9 | Information on external channels | | | | |
| 6.10 | GDPR information | | | | |
| **7. GDPR Compliance (CNIL Ref. 06/07/2023)** | | | | | |
| 7.1 | Legal basis identified (legal obligation or legitimate interest) | | | | |
| 7.2 | Purposes defined with no incompatible reuse | | | | |
| 7.3 | Data minimization respected (by phase: collection, investigation, post-decision) | | | | |
| 7.4 | Anonymous reports possible, no re-identification | | | | |
| 7.5 | Authorized users documented, access logged | | | | |
| 7.6 | Disclosure rules followed (reporter: consent / subject: after substantiation) | | | | |
| 7.7 | Retention periods defined by phase and communicated | | | | |
| 7.8 | Data subject notification compliant (reporter at acknowledgment, subject within 1 month) | | | | |
| 7.9 | Data subject rights guaranteed (access, objection, rectification, restriction) | | | | |
| 7.10 | Security measures compliant (17 CNIL categories) | | | | |
| 7.11 | Processing register updated | | | | |
| 7.12 | DPIA completed (recommended) | | | | |
| **8. Sector-Specific Requirements** | | | | | |
| 8.1 | *Public sector*: Art. 40 CPP coordination documented | | | | |
| 8.2 | *Public sector*: Designated officer inform

Related in Data & Analytics