When an organisation receives a qualifying whistleblower disclosure, strict confidentiality rules apply.
The organisation must not disclose:
- the whistleblower’s identity, or
- any information that is likely to lead to their identification.
This applies to everyone who becomes aware of the disclosure, including directors, responsible managers, compliance staff, HR, investigators, and external service providers.
When is disclosure allowed?
Confidentiality can only be broken in limited circumstances, such as:
- with the whistleblower’s consent, or
- where disclosure is made to ASIC, APRA, the AFP, or another prescribed regulator, or
- to a lawyer for legal advice/representation about the disclosure, or
- where a court or tribunal requires it.
Practical expectation for investigations:
Even if you don’t say the whistleblower’s name, you must take reasonable steps to avoid “back-door identification” — for example by limiting who sees the file, carefully redacting details, separating whistleblower data from HR files, and controlling interview processes.
Consequences of breach:
Unauthorised disclosure is a serious offence. It can attract significant civil penalties and even criminal liability. ASIC+1