Call Me: +359 88 667 9838

Email: givanova@ivanovalegalsolutions.com

Nearly a year into its application for large companies, the Bulgarian Whistleblower Protection Act (referred to as “the Act”) continues to present specific challenges for internal HR and Compliance teams. One of the biggest hurdles is maintaining the delicate balance between protecting whistleblowers’ identities and ensuring effective internal investigations.

Below is a detailed overview of the key challenges and practical solutions for ensuring compliance with the Whistleblower Protection Act in Bulgaria.

  • Challenge: The Act mandates whistleblower identification, stating that if a report is submitted anonymously, the designated officer may decide not to proceed with an investigation. This presents a conflict for teams trying to encourage whistleblowing while still staying legally compliant.
  • Solution: Implement secure and confidential reporting channels such as dedicated hotlines and encrypted online portals. Access to the identity of the whistleblower must be strictly limited to authorized personnel, safeguarded by robust internal protocols that prevent unauthorized disclosures.
  • Challenge: Reports can range from financial misconduct to workplace harassment—each requiring a unique response strategy and different investigative expertise.
  • Solution: Introduce a system for classifying reports based on their nature and urgency. A multidisciplinary team supported by a detailed internal whistleblowing handbook ensures a consistent and professional approach to every case.
  • Challenge: Ensuring that investigations are both swift and in-depth without compromising legal or procedural fairness.
  • Solution: Develop predefined investigation protocols with clear timelines and step-by-step procedures. Provide ongoing training to responsible employees to ensure investigations are carried out efficiently and comprehensively.
  • Challenge: Employees must be well-informed about their rights and obligations under the Whistleblower Protection Act.
  • Solution: Conduct regular training sessions and use internal communication tools such as intranet platforms, posters, and email newsletters to promote awareness. Cultivating a transparent and ethical workplace culture is key.
  • Challenge: Handling whistleblower reports often involves processing personal data, which must comply with GDPR and national data privacy laws.
  • Solution: Adopt strict data protection measures, including obtaining explicit consent where required and limiting access to sensitive data. Conduct regular privacy impact assessments to evaluate and mitigate risks.
  • Challenge: Creating a safe environment where employees feel protected from retaliation when they report misconduct.
  • Solution: Implement a clear anti-retaliation policy and ensure all employees understand the legal consequences of such actions. Use anonymous reporting mechanisms and establish whistleblower protection programs as safeguards.
  • Challenge: Maintaining accurate and detailed records of reports and investigations is essential for legal compliance, especially for annual reporting to the Bulgarian Commission for Personal Data Protection.
  • Solution: Set up a secure and centralized case management system. Standardized documentation templates and regular internal audits ensure proper tracking and reporting of all whistleblowing-related activities.
  • Challenge: Adapting internal policies in line with evolving legislation and addressing new compliance risks as they arise.
  • Solution: Ensure continuous monitoring, conduct compliance audits, and provide ongoing training for HR and Compliance teams. Periodically review policies in response to legal or regulatory changes. Stay informed through the official portal of the Bulgarian Commission for Personal Data Protection, where new guidance, templates, and instructions are published regularly.

The insights provided here will also be discussed in an upcoming podcast episode hosted by Gabriela Ivanova, focusing on the application of the Bulgarian Whistleblowing Act, offering further understanding and strategies for compliance. Тhe podcast will be available here.

Share the post