Digital forensics: when do you need us and how do we go about it?
ForensicsDigital forensics includes many different subdisciplines: from computer, mobile, and email forensics to more recent technological developments.
By: Ariën Oskam
23 Jul 2026 5 min read

Companies with 50 or more employees have long been required to have an internal reporting policy for whistleblowers. However, with the introduction of the Whistleblower Protection Act, the requirements for this reporting policy have been significantly expanded, meaning that many whistleblowing policies no longer comply with current legislation.
The definition of ‘employee’ has been expanded under the Wbk. The definition of employee is as follows: “the person who performs work under an employment contract governed by civil law or a public service appointment, or the person who otherwise performs work in a subordinate relationship for remuneration”. This means that not only people in paid employment are considered employees. Subcontractors, paid interns, temporary agency workers and self-employed persons must also be included in this assessment. These individuals must therefore be taken into account when determining whether the threshold of 50 employees has been reached. This concerns the number of working persons, not the number of FTEs within the organisation.
Fewer than 50 employees in your organisation? But do you operate as an employer in the field of financial services, products and markets, the prevention of money laundering and terrorist financing, civil aviation, maritime labour and port state control, and in the field of offshore oil and gas activities? In that case your organisation must also have a whistleblowing policy that complies with Wbk.
The law explicitly requires that employees be able to report to a designated independent officer. Designating an officer was already part of previous legislation. The officer must be demonstrably independent.
In practice, we regularly see the head of HR, a board member, the CFO or the compliance officer being designated as the reporting point. It also happens that reports can be made to former directors or individuals previously associated with the organisation. The concrete requirements for the independent officer will be further detailed through a General Administrative Order. However, the examples mentioned above are no longer expected to be considered sufficiently independent.
This was already mandatory in many surrounding countries. With the Wbk, the Netherlands must also comply. Organisations are required to provide a facility for anonymous reporting.
Until the introduction of this law, confidential handling of reports upon request was the only obligation. Due to this change, many reporting channels need to be redesigned. An organisation can no longer suffice with simply providing an email address for reporting misconduct, as anonymity cannot be guaranteed via email.
External hosting of an email address also does not provide a solution. The reporter must also remain anonymous to the independent officer. Email addresses, phone numbers and physical appointments can often be traced back to individuals. Even handwritten letters can be recognised by handwriting.
Reports must be documented in a register specifically designed for this purpose. The requirements of the General Data Protection Regulation (GDPR) must be borne in mind.
The data may not be stored longer than necessary. This obligation forces employers to carefully consider which data is stored, where it is stored and for how long it is retained.
Recording reports in an Excel file will likely not be considered as an appropriately dedicated register. The government will set additional requirements in the General Administrative Order to follow.
Protection against retaliation was already part of previous legislation. Under the Wbk, retaliation is presumed when it occurs during or after the processing of a report. This shifts the burden of proof to the employer and offers greater protection to the reporter than before.
The law defines retaliation in concrete terms. In addition to dismissal and demotion, this includes:
Whistleblowers can report directly to a designated and competent authority outside the organisation. In addition, organisations are required to inform employees about this option.
A competent authority is often the regulator within a specific sector or industry. Under the previous law, a reporter first had to follow the internal reporting process. If a good internal reporting channel is lacking, this can encourage whistleblowers to report externally immediately.
We offer an integrated approach to the whistleblowing policy:
In addition to the above services, we also offer this support as part of our broader integrity services. We assess aspects such as tone at the top, codes of conduct and their compliance, communication and the internal control of integrity-sensitive processes such as KYC and integrity screenings.
Are you curious whether your organisation meets all the requirements?
Get in touch with one of our experts.
Digital forensics includes many different subdisciplines: from computer, mobile, and email forensics to more recent technological developments.