Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law
Whistleblowing: Confidentiality, Data Protection and Record-Keeping

Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law WB-Art.17: Processing of personal data

Any processing of personal data carried out pursuant to the Directive, including the exchange or transmission of personal data, shall be carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Directive (EU) 2016/680; personal data manifestly not relevant to a specific report shall not be collected or, if accidentally collected, deleted without undue delay.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

  • GDPR-Art.5 Principles relating to processing of personal data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Whistleblowing: Confidentiality, Data Protection and Record-Keeping

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.