Reporting Without Exposing Yourself: A Guide to Anonymous Whistleblowing When You Find a Data Leak

Back to the blog
24 August 202612 min read

Introduction: a bad moment to be curious

There's a strikingly common experience that rarely gets told: that of the employee, the volunteer, the customer or the ordinary internet user who, in the middle of a perfectly routine task, stumbles onto something they were never meant to see.

A misconfigured shared folder containing the payslips of an entire department. A URL where changing the number at the end is all it takes to display the next patient's medical record. A spreadsheet emailed as an attachment to fifty recipients with, on tab number three, the full contact details of three thousand people. A piece of software installed on workstations that logs far more than the internal memo ever announced.

Three white CCTV cameras mounted on a pole, against a blurred background of green vegetation

At that precise moment, an unpleasant mechanism kicks in. To report is to identify yourself. It means explaining how you saw it, and therefore sometimes confessing to a curiosity that can be turned against you. In a small organisation, it means being identifiable within three seconds. And the statistics are brutal: the Maison des lanceurs d'alerte and the Défenseur des droits have been documenting for years that the majority of people who report wrongdoing see their professional situation deteriorate, even when the alert is well founded.

This guide doesn't preach heroism. It describes a method: who to talk to, in what order, with what level of exposure, and which legal protections genuinely exist under French law since the Act of 21 March 2022.


Step 0: do nothing for twenty-four hours

The worst decision is the one made within the hour of discovery, in the heat of outrage. A message sent from your work email, a screenshot posted on social media, a call to the local journalist: each of these reactions closes doors permanently.

What you can do immediately, on the other hand:

  • Write down the facts, outside the systems of the organisation concerned. Date, time, what you saw, how you got there, in plain language. A paper notebook remains the least traceable medium; an A5 hardcover notebook fits in a pocket and leaves no logs.
  • Don't download in bulk. Exfiltrating an entire database "to have evidence" legally turns you from a whistleblower into the author of a fraudulent extraction. French case law draws a clear line between accidental viewing and organised harvesting.
  • Don't probe the flaw any further. Checking once that a modified identifier does indeed display someone else's record is fact-finding. Doing it a hundred times amounts to fraudulent access to and continued presence within an automated data-processing system, under Article 323-1 of the French Criminal Code.
  • Don't talk about it around you. Your alert almost always leaks by the coffee machine, never through metadata.

The golden rule: your value lies in what you saw, not in what you took.


Mapping the possible recipients

There is no single "right" contact, but rather a hierarchy — from least exposing to most exposing, and from most effective to most uncertain.

1. The data controller itself

It's counter-intuitive, but it's often the fastest route. A configuration flaw can be fixed within hours once the right team is warned. Many organisations have a dedicated address such as security@ or a security.txt file published at the root of their website — a convention standardised by RFC 9116 for exactly this scenario.

Upside: the flaw gets closed. Downside: you're speaking to the party with a vested interest in keeping it quiet.

2. The data protection officer (DPO)

Every organisation subject to the requirement must appoint one, and their contact details have to be public. The DPO has a legal duty of independence and cannot be penalised for carrying out their duties (Article 38 of the GDPR). In a serious organisation, this is the best internal entry point: they know the 72-hour CNIL notification procedure and can properly qualify what you describe.

3. The CNIL

The French authority has an online complaint form and accepts reports. An important point that is often overlooked: you can refer a matter to the CNIL even if you are not yourself one of the data subjects, and it does handle third-party reports. Each year its activity report publishes the volume of complaints received, which has comfortably exceeded fourteen thousand a year for several reporting periods.

4. Other sector-specific authorities

Depending on the context: ANSSI and its reporting mechanism for incidents affecting sensitive systems, the labour inspectorate for unlawful surveillance of employees, the Autorité des marchés financiers, ARCOM. The Défenseur des droits also plays a role in guiding and protecting whistleblowers since the Waserman Act.

5. Civil society and the press

La Quadrature du Net, the Ligue des droits de l'Homme, trade unions and certain specialist newsrooms operate secure intake channels. This is the most effective route in terms of public impact, the riskiest in terms of exposure, and — legally speaking — the one that must come after internal channels and the authorities, except in cases of serious and imminent danger.


What French law actually protects

The French regime was substantially overhauled by the Act of 21 March 2022 (known as the Waserman Act), which transposes European Directive 2019/1937. Here's what matters, in plain terms:

ElementWhat the law says
Who is protectedAny natural person who reports, without financial consideration and in good faith, information about a crime, an offence, a threat to the public interest or a breach of EU law
DisinterestednessThe "disinterestedness" condition was removed in 2022: it is enough to act without direct financial consideration
Order of channelsInternal reporting is no longer mandatory before external reporting. You can go straight to the competent authority
Public disclosurePossible where there is no follow-up within the deadlines, a risk of retaliation, or serious and imminent danger
RetaliationDismissal, sanctions, discrimination, sidelining: automatically null and void, with the burden of proof reversed before the court
ImmunityThe whistleblower incurs no criminal liability for the removal or handling of documents to which they had lawful access

That last line deserves a second read. The protection covers documents obtained lawfully in the course of your duties. It does not cover intrusion. That is exactly the boundary described above.

One more concept is too rarely mentioned: Article 122-9 of the Criminal Code establishes a ground of criminal immunity for whistleblowers who follow the proper procedures. And the people around them — colleagues, relatives, unions — now enjoy the status of "facilitator", and are protected too.


Building a contact channel that won't betray you

Man in a black t-shirt sitting on a bed, using a laptop in a bedroom

Let's assume you've chosen your recipient. That leaves the practical question: how do you write to them without the sender being you.

What you must never use

  • Employer-owned equipment. Workstation, work phone, company Wi-Fi, remote-access VPN: everything is logged, often for six months or a year, and those logs are the first thing consulted in an internal investigation.
  • Your usual personal email address. It's linked to your identity through a dozen cross-references.
  • An account created five minutes before sending, from your home connection. The creation IP address and the timestamp are enough.
  • A raw office document. Word files, PDFs and photos carry metadata: username, printer name, GPS coordinates of the shot, device serial number. Systematic cleaning is essential before any transmission.

The channels to favour

Anonymous SMS. For a short initial contact — "your customer portal is exposing the files in the /exports directory, check urgently" — a text message sent through an anonymous gateway is remarkably well suited: no account to create, no message history, and a message that reliably lands on a work phone. It isn't suitable for transferring documents, but it excels at triggering awareness and proposing a follow-up channel. The trade-off to be aware of: for legal reasons, the gateway retains technical logs. Anonymity is real vis-à-vis the recipient, but not absolute in the face of a judicial request.

Postal mail. Underrated, almost perfect. A letter printed at a public print shop, with no letterhead, dropped into a postbox far from your home, carries no digital metadata whatsoever. The Défenseur des droits, the CNIL and most newsrooms accept paper mail.

Secure submission platforms. Several French media outlets run a SecureDrop instance or equivalent, designed so that the newsroom itself doesn't know the source. Use it from a network that is neither your home nor your office.

An encrypted messaging app on a separate device. If the exchange is going to last, a second phone bought second-hand and paid for in cash, paired with a dedicated prepaid SIM card, creates a clean separation. That's the logic of compartmentalisation: one device, one purpose, no contacts shared with your ordinary life. An entry-level refurbished smartphone is more than enough for this.

The detail that gives everyone away

Writing style. Internal investigations aren't looking for IP addresses, they're looking for turns of phrase. If only three people know about the file and your message reuses the exact vocabulary from a meeting, technical anonymity counts for nothing. Write short, factual sentences, with no irony and no detail that only a small circle could know. Reread it asking yourself: "how many people could have written this?"


The content of the report: what makes it credible

An anonymous report starts with a handicap: nobody can call you back to check. It therefore has to stand on its own.

Recommended structure, one page maximum:

  1. The organisation concerned, named precisely.
  2. The facts, dated, described without interpretation. "On 12 August, the address [X] displayed, without authentication, a list of 4,000 rows containing name, address and social security number."
  3. The nature of the data, noting whether it falls within the special categories of Article 9 of the GDPR (health, opinions, sexual orientation, biometrics) — which radically changes the severity.
  4. Minimal evidence: a cropped, anonymised screenshot, sufficient to verify without disclosing anything further.
  5. What you are asking for: correction, notification of the data subjects, an investigation.
  6. A channel for follow-up contact, if you're willing to accept one.

What not to include: your theories about who's responsible, your personal grievances, your analysis of motives. A report that reads like a score-settling exercise gets filed away with no action taken.


When the data subjects must be informed

Man wearing glasses typing on a laptop keyboard in a dark room

The GDPR imposes two distinct obligations on the data controller, and it's useful to know them in order to assess the answer you're given:

  • Article 33: notification to the CNIL within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk.
  • Article 34: informing the data subjects themselves, without delay, where the breach is likely to result in a high risk to their rights and freedoms.

In other words: if you're told "it's been fixed, there's no need to alarm people" when social security numbers have been circulating, that response is not compliant. That's precisely the sort of element that justifies escalating to an external channel.

For the data subjects, the CNIL sets out the useful reflexes: change any reused passwords, monitor bank accounts, and be wary of the approaches that follow — targeted phishing systematically exploits recent leaks. A password manager makes it easy to spot reused credentials at a glance, and a physical FIDO2-compatible security key neutralises most account takeovers, even with a compromised password.


Three scenarios, three strategies

You're an employee and the flaw comes from your employer. Go to the DPO first, in writing, then to the staff representative. Keep a dated copy of your report at home: it will serve as proof of precedence should retaliation follow. If your situation deteriorates, refer the matter to the Défenseur des droits, who can issue an opinion and point you towards financial support.

You're a customer or user and you discover the flaw from the outside. Report it to security@ or the DPO, then to the CNIL within a fortnight if nothing happens. Here you have no relationship of subordination: the main risk is a complaint for fraudulent access, which is why it's absolutely essential not to have "explored".

You discover an unlawful surveillance system. Cameras filming workstations, undeclared screen-capture software, vehicle geolocation outside any proper framework. These are areas where the CNIL has issued sanctions on several occasions, and where the labour inspectorate and the works council are powerful allies. Documenting with photos is legitimate here — you're documenting what is being done to you.


Conclusion: anonymity as a precondition for reporting

Anonymity is often set against responsibility, as though concealing your identity meant running from the consequences of what you say. Reporting data leaks proves the opposite. Without the possibility of speaking up without identifying yourself, a considerable share of vulnerabilities would never be fixed, and a considerable share of unlawful processing would never be stopped.

This isn't an activist opinion: it is the very reasoning of the European legislator, who built a protection regime precisely because it had observed that fear of retaliation was blocking the flow of information. Anonymity tools — SMS gateways, secure drops, paper mail, dedicated devices — are simply the technical expression of a right that has already been recognised.

What remains is discipline. Document without exfiltrating, alert without exploiting, write short and factual, choose the right recipient before the right channel. Technology protects your identity; method protects the alert.

Further reading: the CNIL website (section on "data breaches"), the Défenseur des droits guide on the guidance and protection of whistleblowers, the Maison des lanceurs d'alerte, and the text of Act No. 2022-401 of 21 March 2022 on Légifrance.

#Anonymat#Confidentialité#Cadre légal#RGPD#CNIL#Sécurité#Cas d'usage

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme