Whistleblowing, handled properly

A reporting channel people are willing to use

Kaja gives an organisation the internal reporting channel the EU Whistleblower Directive requires, and gives the person raising the concern a way to do it without putting themselves at risk.

Reports are opened through your organisation's own link

There is no company picker on this page, by design. Each organisation publishes its own reporting address in its whistleblowing policy, its legal notices or its intranet, and that link is what connects your report to the right legal entity, in the right country, under the right law. If you mean to raise a concern, start from the link your organisation published. If you cannot find it, ask for the reporting channel by name; an organisation covered by the directive is required to have one.

How it works

  1. 1

    Arrive through your organisation

    You open the reporting link your organisation published, pick the entity your concern relates to, and see which law protects you before you write anything down.

  2. 2

    Report named or anonymously

    Choose whether to give your identity. Describe what happened, when, and whether it is still going on, and attach any evidence you hold.

  3. 3

    Follow it with a code

    You receive a private tracking code. It is shown once, it cannot be recovered, and it is the only way back to your case, including if you stayed anonymous.

What it does

Written around the directive

Directive (EU) 2019/1937 sets the floor: receipt acknowledged within seven days, feedback within three months, and confidentiality for the reporter's identity. The flow states the rules that apply to the entity being reported on, at the point they matter.

Anonymity that holds

An anonymous report carries no name and no contact details. The tracking code is the only link back, so a case handler can ask questions and the reporter can answer without ever identifying themselves.

In the reporter's language

The intake flow runs in English, French, Polish and Spanish, chosen by the person reporting rather than by the organisation.

Structured from the start

Concern categories, the reporter's relationship to the organisation, dates, whether the conduct is ongoing, who else was told, and attached evidence: the case arrives ready to assess instead of as a paragraph of free text.

A case view for handlers

Reports land in an administrator panel with status and priority, separated into identified and anonymous, so nothing sits unacknowledged past its deadline.

Confidential by default

Identity is shown only to the people handling the case, and the reporter is told exactly what is stored about them before they submit it.

Compliance

GDPR

A report is personal data, often about the reporter and about the people they name, so it is handled under Regulation (EU) 2016/679. Reporters are told what is collected and why before they submit, an anonymous report holds no identifying details at all, and identity is disclosed only to the people handling the case.

Privacy and security policy

Anti-bribery and anti-corruption

Norn Labs operates under anti-bribery and anti-corruption rules, and does not offer, accept or facilitate improper payments in any form. Kaja is part of how an organisation meets the same standard: bribery, corruption and public procurement irregularities are first-class reporting categories, and every case carries a record of how it was handled.

For organisations

If you need a reporting channel for your own organisation, Kaja gives you one reporting address per entity, a case view for the people who handle what comes in, and a record of how each report was dealt with.

Talk to Norn Labs

Kaja provides a reporting channel and general information about Directive (EU) 2019/1937. It is not legal advice. Member states transpose the directive into national law, sometimes with stricter requirements, and an organisation should confirm its own obligations.