Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Comparison

Whistleblowing Platforms for Swiss Companies Compared

Switzerland has no general whistleblower protection statute — the revision failed definitively in 2020 — so what drives Swiss procurement is the EU Directive, the group parent, and the fact that an abusive dismissal stays valid with compensation capped at six months' salary. We compare dedicated case-management suites, external ombuds services and encrypted form platforms, and say plainly which parts of the job we do not do.

Whistleblowing Platforms for Swiss Companies Compared

Start with the fact that shapes every Swiss decision here: Switzerland has no general whistleblower protection statute. The revision of the Code of Obligations that would have created one failed definitively in March 2020 after roughly seventeen years of work — and it failed from both sides, with the Swiss Trade Union Confederation among those welcoming its defeat. What exists instead is case law derived from the duty of loyalty in Art. 321a CO, which sets a cascade: report internally first, then to the competent authority, and only then, in narrow circumstances, publicly.

So Swiss companies buy whistleblowing systems for three reasons, none of which is a Swiss statutory mandate: an EU entity brings them into scope of Directive (EU) 2019/1937, a group parent or a customer requires one, or management has concluded that finding out about problems internally is cheaper than reading about them elsewhere. This page compares the three ways to build that channel — a dedicated case-management platform, an external reporting office, and an encrypted intake form — and is explicit about which parts of the job we do not do.

Status: July 2026

Vendor features, hosting and pricing below were checked against publicly available vendor material on 25 July 2026 and change frequently in this market. Legal points are summaries of the position as we understand it and are not advice. Verify both with the vendor and with counsel before you commit.

What the Channel Actually Has to Do

If Directive (EU) 2019/1937 applies to you — through an EU entity with 50 or more workers, or in the financial sector regardless of headcount — the channel has hard requirements, and they are what separate a form from a system:

  1. Acknowledge receipt within seven days. Which means you need a way to reach a reporter who may have given you no contact details.
  2. Provide feedback within three months. Same problem, at a longer interval, and it is the requirement that most often forces a dedicated tool.
  3. Keep confidentiality of the reporter's identity, including from the people implicated — an access-control question inside your own organisation.
  4. Accept reports in the languages your staff actually speak. For a Swiss employer that usually means DE, FR, IT and EN at minimum.
  5. Maintain a record of reports and of what was done about them, with retention that is defined rather than indefinite.

Two structural details are worth having in view. Entities of 50–249 workers may share investigation resources, but each local entity keeps its own intake channel. And the deadlines above are why anonymous two-way dialogue is the single most important capability in this category: a report that cannot be clarified frequently cannot be investigated, and a reporter who cannot be reached cannot be given feedback. The full obligations are in the EU Whistleblowing Directive; the Swiss legal position is in whistleblowing in Switzerland.

The number that decides whether anyone uses your channel

Under Art. 336a CO an abusive dismissal in Switzerland remains valid — the employment relationship ends — and compensation is capped at six months' salary, with awards in practice usually well below that. An employee deciding whether to report their manager is weighing that number against their mortgage. This is why Swiss employees insist on genuine anonymity rather than a policy promise, and why the technical properties of the channel are not a procurement detail.

The Three Ways to Build the Channel

1. A dedicated case-management platform

EQS Integrity Line is the reference product in this market and describes itself as the most-used whistleblowing software in Europe and Switzerland. It supports reporting in 60+ languages, offers anonymous reporting with follow-up, multi-stage investigation workflows with automated routing, and hosting in Europe; EQS names ISO 27001 and SOC 2 among its certifications. Third-party review directories put its subscription models from around EUR 100 per month at the entry level, which for a mid-sized company is entirely reasonable for what it does. Other vendors — including Whistleblower Software and other EU-based entrants — occupy the same shape at various price points.

What you are buying is the case-management half: deadline tracking against the seven-day and three-month clocks, an anonymous mailbox the reporter can return to, role-separated investigator access, documented decisions, and reporting to your audit committee. If Directive compliance is the driver, this is the category to shortlist, and we say so without qualification.

2. An external reporting office — a law firm, an ombuds service or an audit firm

The Directive expressly allows a third party to operate the channel, and in Switzerland this route is common and frequently underrated. An external lawyer or ombuds office receives reports, triages them, and hands the organisation a case rather than a raw allegation. The advantage is independence: for a 200-person Swiss company where everyone knows everyone, an external intake point is often the only arrangement employees believe. The disadvantage is cost per case and the fact that you now have a professional-secrecy relationship to manage on top of everything else.

3. An encrypted intake form

The third route is a general encrypted form platform used as the intake layer, with case handling done by the responsible people using their existing tools. This is the cheapest route by a wide margin and the strongest on one specific property — nobody outside the named recipients, including the platform operator, can read a report. It is also the route that most obviously lacks case management, and we will be precise about that below rather than gloss it.

Head-to-Head

Dedicated platform (e.g. EQS Integrity Line)External reporting officeEncrypted intake (Schweizerform)
Anonymous two-way dialogueYes — core featureYes, mediated by the officeNo — one-way intake unless the reporter leaves a contact route
7-day / 3-month deadline trackingYes, built inYes, part of the serviceNo — you track it yourself
Case management and investigation workflowYes — routing, stages, documentationYes, performed for youNo
Multilingual reportingExtensive — 60+ languages on EQSDepends on the office's staffEN, DE, FR, IT from one form definition
Who can read a reportYour case handlers, and the platform operator technicallyThe office, then whoever it briefsOnly the Vault key holders — not us
HostingEurope; EQS names ISO 27001 and SOC 2The office's own systemsEncrypted submissions stored in Switzerland
Indicative costFrom roughly EUR 100/month upward, by sizeRetainer plus per-case feesCHF 0 / 19 / 49 per month
Best forDirective compliance at scale, group-wide programmesSmall companies needing visible independenceMaximum confidentiality of the intake itself

Read the first three rows together. They are the honest reason a dedicated platform exists, and no amount of encryption substitutes for them.

Where We Are Not the Answer — Stated Plainly

Schweizerform is an encrypted intake layer, not a whistleblowing case-management system. Concretely: we do not provide an anonymous mailbox the reporter can return to, we do not track the seven-day acknowledgement or three-month feedback deadlines, and we have no investigation workflow, no case states and no reporting pack for your audit committee. If Directive (EU) 2019/1937 applies to your entity and you have no other way to satisfy those obligations, a dedicated platform or an external office is the correct purchase and you should make it.

There is one honest workaround and it is not a full substitute: a report submitted through us can include a contact route the reporter chooses — a throwaway e-mail address, a pseudonymous account — which lets you acknowledge and follow up while keeping identity out of your hands. That is a pattern, not a feature, and it depends on the reporter's own operational security. Say so in the form rather than implying a dialogue capability we do not have.

Where an Encrypted Form Is Genuinely Stronger

One property, and it is the property Swiss employees actually care about. On a conventional platform — dedicated whistleblowing suites included — case handlers open readable reports, which means the system holds readable reports, which means the operator can technically reach them and can be compelled to produce them. That is not a criticism: a case-management suite must be able to show a handler the case, so it cannot be zero-knowledge in the way an intake form can. The question to put to any vendor in this category is precise: «Can your staff, or anyone holding your infrastructure, technically read a submitted report — and if so, under what controls?»

With an end-to-end encrypted intake, the answer is architectural rather than procedural: reports are encrypted in the reporter's browser, the server holds ciphertext, and only the holders of the Vault key can decrypt — a named compliance officer, a board committee, an external counsel, whoever your policy designates. Nobody at the platform can, including under a court order addressed to us, because there is nothing readable to produce. The mechanism is in zero-knowledge architecture explained, and the compulsion question in subpoenas, warrants and your form data.

Two supporting properties matter more here than in any other use case. No trackers on the reporting page: a reporter arriving from a work device should not encounter a consent banner or a third-party script, and our public form pages mount neither. And no IP address stored with the submission — which, together with the metadata we deliberately do not keep, is set out in IP addresses and form metadata. A timestamp plus an office IP address has ended more anonymity promises than any cryptographic failure.

The Data Protection Layer Everyone Forgets

In Switzerland, data protection law is the part of whistleblowing that is actually enforceable, and it applies to all three routes. Reports concern proceedings and sanctions, which makes them sensitive personal data under Art. 5 lit. c nDSG. A whistleblowing system is the textbook case for a data protection impact assessment under Art. 22. And the awkward one: the accused person has an access right under Art. 25 — which can be restricted under Art. 26 to protect the reporter, a position taken by cantonal data protection authorities, but only as a documented case-by-case decision, never as a blanket clause in your policy.

Practical consequences for procurement: your processing record needs the platform and its sub-processors named, your retention rule needs to cover closed cases as well as open ones, and your DPIA should be written before the channel launches rather than after the first report. Our explainer on processing agreements is in do you need a DPA for your form tool, and the retention framework is in form data retention.

The Public-Sector Counter-Example

Federal employees are the one Swiss group with a statutory framework, and it is worth knowing because it sets the expectation others compare against. Art. 22a of the Federal Personnel Act obliges federal employees to report ex-officio offences, gives them the right to report other irregularities to the Federal Audit Office — anonymously, through its platform — and protects them in para. 5 against professional disadvantage for having reported in good faith. That is federal personnel law only: cantonal personnel law varies, and there is no national answer for cantonal or communal employees. A cantonal body building a channel is designing under cantonal data protection law, which is why the hosting question tends to be decided differently there.

Which Route Fits Which Company

Buy a dedicated platform when

  • Directive (EU) 2019/1937 applies through an EU entity, or a group parent mandates a common system
  • You need deadline tracking, case states and audit-committee reporting as a product rather than a spreadsheet
  • Reports arrive in many languages and from many countries
  • Compliance has the budget and the mandate, and the programme needs to look like a programme

Use an external reporting office when

  • The company is small enough that internal independence is not credible to employees
  • You want triage and investigation performed by people who do it professionally
  • The likely subject matter is legally sensitive from the first sentence

Use an encrypted intake form when

  • No Directive obligation applies and you are building the channel because it is the right thing to do
  • The decisive requirement is that no platform operator can read a report
  • You need the same channel in EN, DE, FR and IT without a procurement project
  • The organisation is small, the recipients are few and named, and case handling can be done by those people directly
  • You are supplementing an existing programme with a maximally confidential route for the hardest reports

The Combination Most Swiss Companies Should Consider

For a Swiss company inside the Directive's scope: a dedicated platform for the programme, and an encrypted intake as a named alternative route for reports where the reporter's fear is specifically about the systems. For a Swiss company outside its scope — which is most of them — start with the encrypted form and an external counsel on call, because a channel that exists and is trusted beats a procurement project that is still being scoped. Whichever you choose, publish who reads reports, in what timeframe, and what happens next; the technology matters less than that sentence being true.

If you need case management and deadline tracking, buy a dedicated platform — that is what it is for, and we would rather you did that than misuse a form for it. If what you need is an intake channel that nobody, including us, can read: reports encrypted in the reporter's browser, encrypted submissions stored in Switzerland, no trackers and no IP stored on the reporting page, and one form live in EN, DE, FR and IT. The HR and whistleblower use case shows how organisations set it up, and the Free plan is enough to test it properly.

Disclaimer: This comparison is general information and marketing content, not legal, regulatory or compliance advice. Vendor features, certifications, hosting and pricing for EQS Integrity Line and other named providers reflect publicly available vendor material as checked on 25 July 2026 and may change — verify directly with the vendor. Indicative prices from third-party review directories are indicative only. References to Art. 321a, 328b and 336a CO, to Art. 22a of the Federal Personnel Act, to the DSG and to Directive (EU) 2019/1937 are summaries of a contested and developing area; whistleblower protection in Switzerland rests largely on case law, and cantonal personnel and data protection law varies. Obtain advice from qualified Swiss counsel before designing or operating a reporting channel. All product and company names are trademarks of their respective owners and are used here for factual comparison only.