Independent scored ranking of whistleblower-reporting tools for Italy under D.Lgs. 24/2023, the local transposition of EU Directive 2019/1937. 25-criterion rubric fixed before scoring; every score carries evidence.
Of the 12 platforms scored against D.Lgs. 24/2023, EthicsPortal ranks first with 52 of 56 points, ahead of Confidly at 47.
Platforms covering it
15
Sold only here
9
EU data centre
8
Self-serve sign-up
7
Scored against the rubric
12
The law a channel in Italy has to satisfy
Italy transposes EU Directive 2019/1937 through D.Lgs. 24/2023. A platform has to satisfy the national text, not only the Directive, so check obligations against the statute rather than against a vendor's compliance claim.
Italy has a wider addressable base than its headline threshold suggests. Alongside the standard 50-worker rule, any entity that has adopted a Model 231 organisational and management model needs an internal reporting channel regardless of headcount — so the Italian market reaches well below the size band that defines most of Europe.
That shapes the vendor field. Italian platforms compete on precise legal positioning — D.Lgs. 24/2023, Model 231 and the ANAC guidelines named together — rather than on a generic “EU Directive compliant” claim, and the ranking reflects that: every one of the 12 scored platforms earns full marks on the law criterion.
This edition uses two layers:
the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity;
the 6-point Italy modifier, which rewards an explicit D.Lgs. 24/2023 reference, a named hosting country or EU provider, and a genuine Italian-language surface.
Because the law criterion barely separates this field, hosting disclosure does the work instead. Italian vendors are strong on legal framing and weak on infrastructure transparency: of the 12 platforms scored, only two name a specific hosting provider and country — neither of them Italian — and four disclose nothing at all about where data sits. In a documentation-heavy regime where ANAC is the central reference point, that is the gap a procurement reviewer will hit first.
Poland · Whistleblowing channel hosted on Hetzner in Germany. Flat €60/month plan, with a published DORA evidence set.
52 / 56
Base 47 · Bonus 5 · Tier P+R+H
Legal
16/16
Reporter
0/10
Handler
10/10
Security
6/8
Commercial
5/6
Strengths
Article-level legal framing: /compliance/ enumerates Directive 2019/1937 Articles 4, 6, 8, 9, 16, 18, 19–21 and links to a dedicated page for each of the 27 EU transpositions
All 27 EU national whistleblower laws are named on public /whistleblower-laws/<country>/ pages with official source citations
Oral reporting (Art 9(2)(b)) is built into the portal as in-browser voice recording and is privacy-engineered: the raw audio is automatically pitch-shifted, only the anonymized clip is ever served, and the original recording is purged after processing (fail-closed — nothing is exposed to handlers until anonymization succeeds)
Report categories are tagged to specific Directive Art 2(1) Union-law domains, with the article reference shown as a handler-side badge while reporters pick plain-language categories
Structured intake: five optional, Directive-aligned questions (relationship to org per Art 4, source of knowledge, incident timing, prior reporting, retaliation concern per Art 19) presented as a skippable guided step, surfaced to handlers and the PDF export with retaliation flagged as an urgency badge — a built-in default set where most tools leave these to per-org custom-field configuration
Three role tiers (member / admin / viewer): viewer is a read-only seat for auditors and external counsel that sees every report plus the full audit trail without any write or management path
GDPR Art 20 portability: admins can export the full organization dataset (reports, messages, attachments, with encrypted fields decrypted for portability) as a ZIP; export and download are audit-logged and the ZIP auto-purges after 7 days
Real deadline tracking: 7-day acknowledgement and 3-month feedback deadlines with overdue/due-soon tracking and a lifecycle stepper in both reporter and handler views
Configurable retention (12/24/36/48/60 months) with automatic purge of expired closed reports; open reports left inactive for 18 months auto-close so the retention clock starts (GDPR Art 5(1)(e) storage limitation), closing the open-forever gap
Two-factor reporter access: case reference (WB-XXXX-XXXX) plus a reporter-chosen 6-digit passcode, session-gated inbox. Reporters can also download a PDF copy of their own report from the follow-up portal (audit-logged)
Audit log surfaced to handlers on each report; append-only at the database level
Modern stack with no end-of-life liabilities
Transparent monthly pricing (€60/mo) with 14 live product locales (13 EU official languages — bg, de, el, en, es, fr, hr, it, nl, pl, pt, ro, sl — plus Luxembourgish)
Multi-handler case assignment: each report can be assigned to a handler, admins see all reports and members see only assigned, assignment changes are audit-logged, and deactivated members are auto-unassigned from open reports
Handler-set case priority (low / normal / high / urgent) recorded at assessment as an audit-logged change and surfaced as a badge on the report list, plus a priority breakdown in the exportable compliance report
SCIM 2.0 provisioning so an identity provider (Okta, Microsoft Entra ID) can provision case handlers and — the core value — auto-deprovision them the moment someone leaves the directory; admins generate, rotate, and enable/disable a per-organization token and pick the default role
SAML 2.0 single sign-on so staff authenticate through the organization's identity provider (Okta, Microsoft Entra ID); configured per organization, covers one or more email domains, with optional enforcement (require SSO for those domains) and optional just-in-time account provisioning on first sign-in — the authentication half of the SSO + SCIM enterprise-identity pair
Published ISO 37002:2021 guidance-alignment map (/iso-37002/) walking the standard's operating clauses against shipped features, alongside the ISO 27001 Annex A self-assessment
Published DPA grants the Controller an explicit right to object to subprocessor changes (§6.4, 30-day notice + termination remedy) and commits to 72-hour breach notification (§6.6); /trust/ publishes contracting party, backups, RTO/RPO, and session lifecycle
DORA evidence set published for financial-entity buyers: /dora/ lists Article 30(2) and 30(3) provisions with status and location, supplies the register-of-information fields under Implementing Regulation (EU) 2024/2956 including the S19 (Cloud services: SaaS) classification, names the ICT service supply chain, and links a signable contractual addendum at /dora-addendum/
Zero-AI commitment codified contractually: DPA §6.10 prohibits transmission of personal data to any LLM or AI inference provider; /subprocessors/ lists no AI sub-processor
Weaknesses
Audit log is append-only but not hash-chained
Only 14 portal-facing languages (13 EU official languages + Luxembourgish) against 24 EU official languages
No ISO 27001 certification of EthicsPortal itself (only Hetzner infrastructure is certified)
Pay-first with 30-day money-back rather than an upfront self-serve free trial
Role tiers are org-scoped, not per-case ACLs: the viewer role adds the auditor seat, but a handler's report visibility is still governed by assignment/participant scoping rather than a per-case permission model
Standout
Article-level Directive framing paired with a 27-page country-law reference and privacy-engineered oral reporting, all surfaced in the live product alongside working deadline, retention, two-factor passcode, audit-log, voice-anonymization, and subprocessor-notification flows.
Tallinn, Estonia · EU-built anonymous whistleblowing channel from Confidly OU (Estonia), self-serve from EUR 39/month, EU-hosted with AI-assisted investigation.
Cagliari, Italy (offices in Milan, Rome, Sulmona, and Barcelona) · Italian whistleblowing platform from DigitalPA. Tiered pricing from €29/month for SMEs.
Italy (Avezzano + Roma) · Italian whistleblowing platform with dedicated public-administration and private-employer offers, ACN-qualified cloud delivery, and published private-sector pricing.
Monfalcone, Italy · Italian managed whistleblowing channel from Ambient7, activated online within 48 hours, from EUR 300/year for the base whistleblowing report type.
Rome, Italy · Italian whistleblowing platform from Laser Romae s.r.l., offered as an AgID-qualified SaaS or on-premise install and built for D.Lgs 24/2023, D.Lgs 231/01, and GDPR.
Italy · Italian legal-tech suite from the Zucchetti Group. My Whistleblowing is sold through Zucchetti Store for smaller employers and quoted for larger or group structures.
Milan, Italy · Italian whistleblowing software from Unione Fiduciaria S.p.A. (Milan), used by more than 200,000 users and widely adopted in the banking and insurance sectors.
25 criteria across 5 categories, weighted by criterion count. Each criterion scores 0, 1, or 2 — rendered as ○ / ◐ / ●. Maximum base score is 50. Italy-specific bonuses add up to 6 on top (modifier, not part of base).
Access tiers
Each tool carries an access tier reflecting what was testable:
P — public pages only (marketing, pricing, security, reporter URL).
P + R — above plus a test report submission.
P + R + H — above plus handler / admin dashboard (via free trial or demo).
Criteria that cannot be verified at the current tier score 0 with the evidence line "Requires handler tier" or "Not documented publicly". Scores depressed by tier, not by product quality, are explicitly flagged on each tool's profile.
Data residency
Every country modifier scores residency the same way:
2 — Data residency in the ranked country itself.
1 — EU or EEA residency is disclosed, but not in the ranked country.
0 — No EU or EEA residency is disclosed.
Integrity guarantees
The rubric was fixed before scoring. No criterion was added mid-test to favour or punish a specific tool.
Every score carries evidence — a URL, a quote, or a file path — visible in each tool's profile.
Tools operated by the publisher are scored by the same rubric. Placement is by score, not by construction.
Each tool carries a Last reviewed date and is re-tested at least annually.
Vendors can dispute a score or submit evidence of a shipped fix using the contact address in the site footer. Any resulting change is dated on the respective tool profile.
Law applied
Legislative Decree No. 24 of 10 March 2023 (D.Lgs. 24/2023) (the Italy transposition of EU Directive 2019/1937). Tools are scored against the Directive first and against the local law's specifics second.
Coverage note
This ranking covers 12 tools with a scoring block published. Additional tools are being added as scoring completes. Unscored tools will appear in the ranking once they have a published scoring block.
Private-sector pricing published: Small €40/month (€480/year), Medium €52/month (€624/year), Large €80/month (€960/year), each with a €160 activation cost. Public-administration procurement is sales/Cloud Marketplace led.
Cagliari, Italy (offices in Milan, Rome, Sulmona, and Barcelona)
Annual billing excluding VAT. Standard: from €29/month for <50 employees; Premium: from €41/month for <50 employees. Medium/Large/Enterprise tiers quote-based.
Exact online-cart totals were not publicly reproducible in the reviewed dynamic store page. An official Zucchetti Store price-list PDF lists My Whistleblowing Starter Pack at €219, Small companies up to 100 employees at €825, and Medium companies up to 300 employees at €1,650.
Whistleblowing base EUR 300/year; each additional report type (gender-equality PdR 125, SA 8000 ethics, ESG) adds EUR 200/year. Implementation and support included.
Starter €19/month or €190/year. Professional €39/month or €390/year. Voice €49/month or €490/year. Enterprise €119/month or €1,190/year. Annual billing is 17% cheaper than monthly.