Whistleblower Protection Act for Law Firms: Professional Rules + Confidentiality

Practitioner note: This is not legal advice. For specific situations, consult a qualified attorney or compliance officer.

TL;DR

  • Law firms with 50+ employees fall under the Whistleblower Protection Act (HinSchG) — partners and non-lawyer staff count toward the threshold
  • Section 203 Criminal Code (StGB) confidentiality overrides whistleblower disclosure for client-related information
  • External reporting channel recommended — an independent law firm reduces insider risk
  • beA (lawyer's electronic mailbox) is not a valid reporting channel — its purpose differs; separate software required
  • BRAO Section 43a professional duties remain unaffected — lawyers may only whistleblow within tight limits

1. 50-Employee Threshold

Under Section 12 of the Whistleblower Protection Act (HinSchG), an internal reporting channel is mandatory from 50 employees. Both qualified lawyers and non-lawyer staff count. In practice, mid-sized and large German law firms are almost always within scope.

2. Section 203 Criminal Code vs. Whistleblower Duty

Client confidentiality under Section 203 of the German Criminal Code (StGB) remains protected. A whistleblower at a law firm cannot disclose client secrets through the HinSchG channel — the duty of professional secrecy prevails. Reports may concern internal misconduct (e.g. billing fraud, money laundering compliance gaps) without naming clients.

3. External Reporting Channel Recommended

For law firms in particular, an external reporting channel run by an independent specialist law firm reduces insider risk and increases trust among employees. Section 14 of the German Federal Lawyers' Act (BRAO) on professional independence supports this allocation.

4. beA Integration

The "besonderes elektronisches Anwaltspostfach" (beA, special electronic lawyer mailbox) must NOT be used as a HinSchG reporting channel. It serves a different purpose (court communication) and lacks anonymous return-channel functionality. Use dedicated whistleblower software instead.

5. BRAO Section 43a Professional Duties

Lawyers' professional duties under BRAO Section 43a remain untouched. A lawyer-employee may only "whistleblow" within narrow professional limits — disclosure of client mandates is generally barred even when reporting internal violations.

6. Practical Implementation

  1. Engage an external reporting channel at a specialist law firm
  2. Train lawyers and non-lawyer staff on the dual regime (HinSchG + BRAO)
  3. BRAO-compliant investigation workflow with privilege safeguards
  4. Consult the regional Bar Association (Rechtsanwaltskammer / RAK) on professional-rules concerns

Summary

Law firms must implement the HinSchG regime once they reach 50 employees, but Section 203 StGB and BRAO professional duties carve out client information from the scope of disclosure. An external reporting channel run by independent specialist counsel is the cleanest setup; beA cannot substitute for compliant software.

View Whistleblower Kit →

Frequently Asked Questions

Whistleblower protection for lawyers?
Yes, as employees. However, client confidentiality may limit protection.
Is BeA sufficient?
No. Different purpose. A separate reporting channel is required.

Sources

Tools & self-assessments

Fining Calculator Calculate the potential fining risk for your organisation. Whistleblower Act Self-Assessment Check your whistleblower reporting office for conformity with the 2026 amendment.