Research Article

Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches

Volume: 10 Number: 2 June 30, 2023
TR EN

Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches

Abstract

This study compares the laws in the United States and the European Union protecting cybersecurity whistleblowers from employer retaliation. Similarities and differences exist regarding the scope of laws, the definition of “retaliation,” and required reporting procedures to be eligible for legal protection. In the US, no anti-retaliation federal statute directly addresses cybersecurity whistleblowing, but whistleblowers may still be protected when they disclose cybersecurity-related violations of laws falling within the scope of protected activity under the current laws. In the EU, the Directive (EU) 2019/1937 directly protects employees who report breaches falling within the scope of the EU acts, including the protection of privacy and personal data and the security of network and information systems. The two approaches also differ concerning the confidentiality of the reporting person’s identity. This study provides a brief foundation for understanding how the US and EU’s approaches differ in providing legal protection against retaliation for whistleblowers.

Keywords

References

  1. Bishara N. D., Callahan E. S., & Dworkin T. M. (2013). The mouth of truth. New York University Journal of Law & Business, 10, 37-43.
  2. Directive (EU) 2016/680. On the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA. URL:https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016L0680.
  3. Directive (EU) 2019/1937. On the protection of persons who report breaches of Union law. URL:https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32019L1937&from=en.
  4. Eisenstadt, L. F. and Pacella, J. M. (2018). Whistleblowers need not apply. American Business Law Journal, 55(4), 665-719.
  5. European Data Protection Supervisor. (2016, July 18). Guidelines on Processing Personal Information within a Whistleblowing Procedure. URL:https://edps.europa.eu/sites/default/files/publication/16-07-18_whistleblowing_guidelines_en.pdf, (Retrieval: 15.01.2023).
  6. Exmeyer, P. C., & Jeon, S. H. (2022). Trends in state whistleblowing laws following the Whistleblower Protection Enhancement Act of 2012. Review of Public Personnel Administration, 42(2), 287-311.
  7. Hammer, D. and Bundschuh, E. (29 December 2016). “The Rise of Cybersecurity Whistleblowing”, Compliance & Enforcement. URL: https://wp.nyu.edu/compliance_enforcement/2016/12/29/the-rise-of-cybersecurity-whistleblowing/. (Retrieval: 13.01.2023).
  8. Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191 (1996). URL:https://www.govinfo.gov/app/details/PLAW-104publ191.

Details

Primary Language

English

Subjects

Business Administration

Journal Section

Research Article

Publication Date

June 30, 2023

Submission Date

April 12, 2023

Acceptance Date

June 23, 2023

Published in Issue

Year 2023 Volume: 10 Number: 2

APA
Dolma, Ö. (2023). Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches. Pamukkale Üniversitesi İşletme Araştırmaları Dergisi, 10(2), 615-631. https://doi.org/10.47097/piar.1281937
AMA
1.Dolma Ö. Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches. Pamukkale Business Research. 2023;10(2):615-631. doi:10.47097/piar.1281937
Chicago
Dolma, Özlü. 2023. “Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches”. Pamukkale Üniversitesi İşletme Araştırmaları Dergisi 10 (2): 615-31. https://doi.org/10.47097/piar.1281937.
EndNote
Dolma Ö (June 1, 2023) Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches. Pamukkale Üniversitesi İşletme Araştırmaları Dergisi 10 2 615–631.
IEEE
[1]Ö. Dolma, “Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches”, Pamukkale Business Research, vol. 10, no. 2, pp. 615–631, June 2023, doi: 10.47097/piar.1281937.
ISNAD
Dolma, Özlü. “Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches”. Pamukkale Üniversitesi İşletme Araştırmaları Dergisi 10/2 (June 1, 2023): 615-631. https://doi.org/10.47097/piar.1281937.
JAMA
1.Dolma Ö. Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches. Pamukkale Business Research. 2023;10:615–631.
MLA
Dolma, Özlü. “Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches”. Pamukkale Üniversitesi İşletme Araştırmaları Dergisi, vol. 10, no. 2, June 2023, pp. 615-31, doi:10.47097/piar.1281937.
Vancouver
1.Özlü Dolma. Cybersecurity Whistleblower Protection: A Comparison of the US and the EU Approaches. Pamukkale Business Research. 2023 Jun. 1;10(2):615-31. doi:10.47097/piar.1281937

Cited By

The articles in this journal are licensed under a Creative Commons Attribution 4.0 (CC BY- 4.0) international license. https://creativecommons.org/licenses/by/4.0/

download?token=eyJhdXRoX3JvbGVzIjpbXSwiZW5kcG9pbnQiOiJqb3VybmFsIiwib3JpZ2luYWxuYW1lIjoiaW1hZ2UucG5nIiwicGF0aCI6Ijg2MDcvNTdlYi81MGIxLzZhMGRhMjNmNjlkZGQ2LjY4MjU5MzQyLnBuZyIsImV4cCI6MTc3OTI4MTk5OSwibm9uY2UiOiI1NTMyNTA1ZTBhNzQ1OGI1MGM4OGE2YWNlNzAzMzNiNyJ9.7VV3eaBIIEohCCfOQxkYYaeDKn295YIt5MfLMs_C72M