Japan's amended Whistleblower Protection Act (公益通報者保護法) sets a headcount threshold that changes what is legally required, not just what is recommended. Companies with more than 300 employees must establish an internal reporting system and designate specific individuals - 従事者 (jujisha), often translated as designated handlers - to receive and handle reports. Companies below that threshold are under a best-efforts obligation to do the same.
"Required" versus "best efforts" changes what a compliance officer needs to be able to demonstrate, and what happens if they cannot.
What crossing 300 employees obligates a company to do
- Establish an internal whistleblowing system that is genuinely accessible to workers.
- Designate specific individuals as handlers of whistleblower reports - named people with the role formally assigned, not a department in the abstract.
- Take appropriate measures to protect whistleblowers from retaliatory treatment.
- Keep designated handlers bound by confidentiality obligations, with criminal penalties attached to unauthorized disclosure of a whistleblower's identity.
That last point is the part that surprises companies used to Western frameworks. Under the EU Directive or PIDA, confidentiality is a strong expectation with civil and reputational consequences for getting it wrong. In Japan's framework, for a designated handler specifically, it is a criminal matter.
Why this changes what a reporting system needs
A system that treats "who can see this report" as a loose permissions question - an "investigator" role any manager could theoretically be assigned - does not reflect the legal weight of the designated handler role once a company crosses 300 employees. The people in that role need to be formally and trackably designated, and access has to follow that designation rather than a generic case-handler permission that happens to be reused for Japan.
How Rectifia handles it
The Designated Handler register exists as a distinct feature, dormant until JP appears in a company's configured jurisdictions. It is not a relabelled version of the generic case-handler role: it exists because this is a distinct legal designation carrying its own confidentiality weight. Reporter identity sits behind the encrypted vault with split-key access, so identity exposure is a deliberate, logged act rather than a side effect of a broad permission.
For a company approaching 300 employees, jurisdiction configuration is worth revisiting before headcount crosses the line and the obligation stops being best-efforts.