An external reporting centre in accordance with the Protection of Whistleblowers Act (HSchG; Hinweisgeber:innenschutzgesetz)
The most likely source for identifying irregularities in an entity is through employees or persons who were or are otherwise associated with the entity. Relevant information about such irregularities occurring in supervised entities form a useful source of information for the Austrian Financial Market Authority (FMA).
By providing accordingly specific reports, you can ensure that irregularities and legal breaches may be brought to light and action taken. As a result, damages may be restricted or even prevented from occurring. By doing so, persons reporting such circumstances assume responsibility for the entity in question and for society, and therefore deserve a particular degree of protection against any form of adverse treatment that they might be threatened with for having made such a report.
A special IT-based whistleblowing system has been operational at the Austrian Financial Market Authority (FMA) since 01 February 2014 that allows it to receive confidential information anonymously about possible instances of malpractice within the legal area of its supervision. In so doing, the FMA has not only created a central point of contact that is responsible for receiving reports, but has also established a secure tool and a special procedure to protect whistleblowers as well as persons who are affected by the report from the outset.
On 24 February 2023 the Protection of Whistleblowers Act (HSchG; HinweisgeberInnenschutzgesetz) was published in the Austrian Federal Law Gazette. The purpose of this law is to prove particular protection for whistleblowers while also ensuring their rights of information at national level.
Is your report a case for the FMA?
Should be reported to the FMA
- Financial services
- Financial products
- Financial markets
- Prevention of money laundering and terrorist financing
- Financial sanctions
Not to be reported to the FMA
Evasion of tax and social security contributions are not to be reported to the FMA, but should instead be reported to Austria’s tax investigation unit.
+43 (0) 50 233 553The following communications channels are available for submitting a tip-off to the FMA:
-
IT-based whistleblowing system
For receiving anonymous reports and for anonymous communications, accessible via the FMA website
-
00800 249 900
Telephone calls are not recorded
-
Orally
In person at the FMA’s premises
-
In writing
Austrian Financial Market Authority, Whistleblowing point of contact, Otto-Wagner-Platz 5, 1090 Vienna
Further information and answers to frequently asked questions (FAQs)
Further information and answers to frequently asked questions (FAQs)
To protect you as a whistleblower in a technically effective manner, we have made a communications platform available to allow you make reports anonymously. The security of communications is guaranteed thanks to the use of modern, certified encryption technologies.
We specifically use the high-security Whistleblower Software system. It has been certified in accordance with European data protection law, and prevents unauthorised access to stored data. The effectiveness of these security measures are regularly subject to and confirmed by independent audits and certifications.
Every report made through the whistleblowing system is encrypted, backed up using dedicated secured network routes and stored in an external data bank in a high-security data centre. It is not possible to technically trace messages back to their source, and personal data is not required to be entered at any point in the reporting process. You are able to remain completely anonymous.
The system we use also sets up a personal protected postbox, which allows you to communicate anonymously with the FMA, thereby ensuring that your anonymity is also preserved by technical means during such communications. As long as you do not enter any details that allow information to be traced back to you, the whistleblowing system also preserves your anonymity on a technical level for communications conducted using the postbox.
If adequate grounds exist at the time of submitting the report based on the actual circumstances and the information available to you adequate grounds that substantiate that the reports you have made are true, and where they fall within the scope of the HSchG, then as a reporting person you are afforded legal protection.
However, such protection under the HSchG only extends to a specific personal and material scope (Article 2 and Article 3 HSchG). This means that not all reporting persons are provided protection, and that not all thematic areas about which reports are made are covered by the HSchG, and therefore also do not fall under its scope of protection.
This means that protection under the HSchG is only afforded, if all conditions are met, i.e. if you are legally worthy of protection and fall under the protected group of persons (see “Who is protected?”, personal scope) and the report relates to a sector that is covered by the HSchG (see “What can be reported”, material scope).
Reports that are patently incorrect may trigger damages claims, and may be pursued by courts or as administrative offences.
Caution over your anonymity: Please note that your personal data, where they have become known, or are able to be found out, may in certain cases set out under law may be disclosed. In particular, the provisions of the Code on Criminal Procedure 1975 (StPO; Strafprozessordnung 1975) shall apply once an initial suspicion exists under criminal law pursuant to Article 1 para. 3 StPO.
Anyone who learns or learned of certain breaches in the course of their ongoing or previous professional activity may be a protected person under the HSchG.
Protected persons do not only include employees, but for example also include:
- applicants
- trainees
- volunteers
- the self-employed
- members of management bodies (e.g. administrative board or the supervisory board)
- temporary contracted workers
- contractors from (sub-)enterprises
- suppliers
Since the personal scope of the HSchG does not extend to cover all natural persons, and especially as its protective rules do not apply for all natural persons, when submitting your report that you we require to you state whether you learned of the breaches described in your report during the course of your ongoing or past professional activity. We request you to provide this information, so that we are able to assess whether your interests require protecting under the HSchG, so that we are able to make information available to you about the outcomes and follow-up measures.
In particular, you may submit reports to the FMA about the following areas that are in the scope of protection of the HSchG:
- Financial services
- financial products and financial markets, as well as
- the prevention of money laundering and terrorist financing
- and related collective consumer protection issues.
The HSchG grants protection against retaliatory measures for a natural person belonging to the personal scope listed in the law that occur in conjunction with a justified report (see “When does a report constitute a justified report”).
Protection against retaliatory measures in particular, but not exclusively relates to unfair dismissal, a temporary employment contract not being extended, being given a proof reference, disciplinary measures or have a licence removed.
The HSchG stipulates that measures that occur in retaliation for a justified report are legally invalid. In the event that you experience such a retaliatory measure as a reaction to your justified report, you are entitled to have such measures repealed, to the restoration of legal compliance, as well as in any case claims for damages for financial losses and any personal impairments sustained. In addition, you also have the right to confidential treatment of your identity. If this is not possible for any reason whatsoever, then you must be informed in advance that this is the case. Should you have further questions in this regard, you may address them to the FMA’s whistleblowing point of contact.
A report is considered to be justified, if at the time of submitting the report based on the actual circumstances and the information available to you adequate grounds exist to substantiate that the report you have made is true, and falls within the scope of the HSchG.
The protection available under the HSchG applies from the time of submitting the report based on the actual circumstances and the information available to you provides adequate grounds to substantiate that the report you have made is true.
You are protected by the HSchG if you submit information that is classified as “confidential”, “secret”, or “top secret” as a report as defined in the HSchG, if
- the justified report could not be pursued effectively without disclosing or analysing such information,
- if they are passed on in observance of the regulations for safeguarding classified information, especially Article 7 of the Information Security Regulation (Informationssicherheitsverordnung) published in Federal Law Gazette II No. 548/2003 as amended in Federal Law Gazette II No. 268/2022, and
- you are able to assume that the whistleblowing point of contact is qualified to observe rules on safeguarding classified information, especially in the case of their being passed on to another internal or external body.
A justified report that has been submitted in relation to internal as well as external reports while observing the provisions of the HSchG, and which discloses facts or information, which the reporting person is obliged to keep confidential based on a legal regulation or on the basis of a contract, does not breach confidentiality requirements,
- where the report is justified,
- the reporting person has an adequate reason to assume that the report is necessary to uncover or prevent a legal breach, and
- no reasons for exclusion exist, for which this federal act does not apply.
This Directive does not apply to the following:
- the confidentiality requirements of legally regulated health professions;
- Information covered by the right to confidentiality of attorneys, notaries as well as those practising tax advising and related professions (Article 9 of the Lawyers Code (Rechtsanwaltsordnung), published in Reich Law Gazette No. 96/1868, Article 37 of the Notarial Code (Notariatsordnung), published in Reich Law Gazette No. 75/1871, Article 80 of the Tax Advising and Related Professions Act 2017 (Wirtschaftstreuhandberufsgesetz 2017), published in Federal Law Gazette I No. 137/2017), including contractual agreements for maintaining confidentiality with partners or supervisory bodies of a law company as well as employees or assistants of lawyers, notaries or tax advisers;
- procurement procedures that are excluded from the following federal acts in relation to procurement:
- procurement procedures that are excluded from the Purchase Contract Awards Act (Bundesvergabegesetz 2018), published in Federal Law Gazette I No. 65/2018, pursuant to Article 9 para. 1 nos. 3, 4 and 5 as well as Article 178 para. 1 nos. 3, 4 and 5 thereof,
- procurement procedures that are excluded from the Federal Procurement Act for Concessions 2018 (Bundesvergabegesetz Konzessionen 2018), published in Federal Law Gazette I No. 65/2018, pursuant to Article 8 para. 1 nos. 2, 3 and 4 thereof,
- procurement procedures that are excluded from the Purchase Contract Awards Act for Defence and Security 2012 (Bundesvergabegesetz Verteidigung und Sicherheit 2012), published in Federal Law Gazette I No. 10/2012, pursuant to Article 9 para. 1 nos. 1 and 5 thereof,
- the application of the provisions of the Code on Criminal Procedure 1975 (StPO; Strafprozeßordnung 1975), published in Federal Law Gazette no. 631/1975, once an initial suspicion exists (Article 1 para. 3 StPO);
- information that is provided to clerics of a legally recognised church or religious society or registered religious denomination during a pastoral conversation.
These provisions regarding the disclosure of classified information (e.g. Information classified as “confidential”, “secret” or “top secret”) shall apply subject to the proviso that the report could not be objectively pursued further without passing on or evaluating this information, that it is passed on in the observance of the standards for protection classified information, and where the reporting person was able to assume, that the reporting centre that receives the report, is qualified to observe this standard.
The FMA is required to protect your identity as the reporting person, which also appears for any information from which it is possible to deduce your identity. It is forbidden to disclose the content of the report or the identity of the reporting person to anyone other than the competent members of staff. Forwarding the report to the competent body is excluded from this rule.
By way derogation from this rule, your identity as well as the information from which your identity may be deducted, may only be disclosed, where an administrative authority, court, or the Public Prosecutor’s Office (Staatsanwaltschaft) deems this to be essential within the scope of administrative proceedings or a proceedings in front of a court of law, or in the case of an investigation under the Code on Criminal Procedure (StPO; Strafprozessordnung). At the same time the danger you are placed in as the reporting person must be considered, and deemed to be proportionate with regard to the veracity and severity of the allegations raised.
Where doing so does not jeopardise the respective procedure, and where there is a possibility to contact you (such as through a personal mailbox), we are required to inform you prior to disclosure, and to presents the reasons for the disclosure in writing.
Business secrets that are disclosed on the basis of a report, are only allowed to be processed or disclosed for the purposes of that law and for the extent that is necessary.
Protection is also given to persons affected by a report, since the provisions on disclosure, consideration of the threat caused and weighing up its proportionality are also equally valid for any person that is affected by a report.
The processing of personal data contained in reports is permissible for the purposes of the HSchG. This covers personal data of
- whistleblowers,
- persons concerned as a result of a report,
- natural persons supporting the reporting persons in making the report,
- natural persons closely association to the reporting persons, who without assisting the report, could be affected by detrimental consequences of the report such as retaliatory measures, as well as
- persons affected by or involved in follow-up measures.
Processing must
- be in the public interest for preventing or pursuing legal breaches and for making reports for this purpose and to check their veracity, and
- be limited to information that is required for determining the occurrence of and pursuing a legal breach.
The following shall be authorised to process information:
- reporting persons regarding the information that is required for their report,
- internal and external bodies regarding the information that is submitted to them by a reporting person,
- authorities for processing information that was submitted to them as a consequence of a report, to the extent that the information is required for further investigations or for the initiation of a procedure.
The named natural persons, the internal and external borders or authorities are also considered as controllers pursuant to Article 4 no. 7 of the General Data Protection Regulation (GDPR) or Article 36 para. 1 no. 8 of the Data Protection Act (DSG; Datenschutzgesetz).
As long as and to the extent necessary for protecting the identity of a reporting person, a person pursuant to Article 2 para. 3 no. 1 or no. 2 or pursuant to Article 2 para. 1 no. 4 HSchG and for achieving the purposes stated in Article 1 and para. 2 no. 1 HSchG, the rights listed in nos. 1 to 7 of a natural person affected by a report and the rights of a legal person affected by a legal person affected by a report contained in nos. 1 to 5 and 7 in the DSG shall not apply.
The purposes in particular include, for example, thwarting attempts to prevent, impede, frustrate or slow down reports or follow-up measures related to reports. Such protection is especially necessary for the duration of a procedure being conducted by an administrative authority or a court, or an investigative procedure under the Code on Criminal Procedure (StPO; Strafprozessordnung).
In this context the following rights shall not apply to a concerned legal person affected by a report:
- The right to information (Article 43 DSG, Articles 13 and 14 GDPR),
- The right to access (Article 1 para. 3 no. 1 and Article 44 DSG, Article 15 GDPR),
- The right to access (Article 1 para. 3 no. 1 and Article 45 DSG, Article 16 GDPR),
- The right to erasure (Article 1 para. 3 no. 2 and Article 45 DSG, Article 17 GDPR),
- The right to restriction of processing (Article 45 DSG, Article 18 GDPR),
- The right to object (Article 21 GDPR) as well as
- The right to the communication of a personal data breach (Article 56 DSG and Article 34 GDPR).
Report pursuant to Article 37 DSG
Personal data
- must be processed in a lawful and fair manner,
- must be collected for specific, clear and lawful purposes and not be processed in a way that is incompatible with such purposes,
- must correspond to the purpose of processing and be relevant and not be permitted to be excessive in relation to the purposes for which they are processed,
- must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate regarding the purposes for which they are processed, are erased or rectified without delay,
- must not be kept in a form for longer than is necessary for the purposes for which it is processed that permits identification of data subjects,
- must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
If you would like to submit a report (either stating your name or anonymously) then click on the link to the “IT-based whistleblowing system” in the section about communications channels for whistleblowing” above.
First, you will be asked to read a brief information text. Please click on the respective links for further information. At the bottom of the first page of information you will find an orange button “Neue Meldung erstellen” (“Create new report”) and a white button “Meldung weiterverfolgen” (“Follow up report”). Detailed instructions about submitting a report and following it up can be found directly in the whistleblowing system (Link to instructions – available in German only).
A separate protected postbox will be set up for you in our system. A secure password will be generated for you for accessing your postbox directly after you submit your report. It is essential that you store this password to be able to follow up your report. Please note that it is not possible to reset the password for security reasons. Make sure that you download the password or save it in a safe place.
This protected postbox is your personal channel for communicating with the FMA. You will also remain anonymous, provided that you do not enter any personal data, that allows you to be personally identified. Our whistleblowing system also uses suitable technical means to preserve your anonymity when communicate via your postbox.
We are able to make enquiries with you about the reported factual circumstances as well as to submit responses about your report via the protected postbox.
In the event that you already have a protected postbox, you will be directed to your postbox once you have entered your password via the “Meldung weiterverfolgen” (“Follow up report”) button. The whistleblowing system will also ensure that your anonymity is preserved by technical security means when you communicate via the postbox as long as you do not divulge any information that allows you to be personally identifiable.
If you lose your login information, then it is no longer possible to access your postbox and previous communications. If you subsequent submit a new report, please state the reference number and where possible some keywords from the original report, to allow us to try to match them.
The FMA’s whistleblowing point of contact is the central point for receiving external reports through the IT-based whistleblowing system. The point of contact is staffed by persons with the necessary personal and professional qualifications, who have been specially trained for handling reports.
You may submit reports either in written form, e.g. via the FMA’s IT-based whistleblowing system, or orally, by phone or in person (see the section on “Channels of communication for whistleblowing”). If you wish to make your report in person at the FMA’s premises, then you have a right to be given an appointment within 14 days to discuss the report.
All reports are handled in a diligent, comprehensive, impartial, honest and confidential manner, and will be reviewed regarding their veracity. Further processing of the report may be stopped, if necessary once further information has been obtained, in the event that we conclude that the report:
- does not fall in the HSchG’s material scope, or
- does not contain any indications that prove its veracity, or
- where it only clearly constitutes a very minor legal breach, or
- where the same information has already been submitted.
You may submit additional information or correct reports made at any time. Blatantly false tip-offs will be rejected, where it is possible for us to establish contact. Where a report does not fall in the FMA’s competence, then the information must be passed on to another reporting centre, where possible to do so. Where an option for communication exists, we are required to inform you about it.
Tip-offs that are within the FMA’s scope of competence, will be forwarded by the whistleblowing point of contact to the respective specialist division. That division will then review the reported factual circumstances and take further steps accordingly. If the specialist division considers that supervisory measures are necessary, then they will be duly initiated.
You will only be afforded rights and protection under the Whistleblowers Protection Act (HSchG; Hinweisgeber:innenschutzgesetz) where you meet legal conditions (see “Who is protected? (Personal scope of the HSchG)”) This especially affects persons, who became aware of certain legal breaches during the course of their current or previous professional activity either at the entity in question or in relation to that entity. Where a protected person is able to be reached, we will generally inform you within three months of receipt of the report, or in justified instances within 6 months,
- about the findings we arrived at
- what follow-ups were taken or are intended to be taken
- or the reasons for not pursuing a report further.
Follow-ups are the measures we have taken following and as a result of the report, such as reviewing the report’s veracity, carrying out subsequent research and investigations, as well as instigating, initiation, conducting or ending a procedure or other measures for pursuing the breach further, for prosecution, or for restoring legal compliance.