The Public Interest Disclosure Act 1998 protects workers who make a qualifying, public-interest disclosure from dismissal or detriment as a result. It does not, in its text, mandate that employers run a specific reporting channel. That gap - between what PIDA actually requires and what most vendor content implies it requires - is worth being precise about before evaluating software against it.
What PIDA actually does
PIDA creates two protections: an automatically unfair dismissal claim where the reason, or principal reason, for dismissal was a protected disclosure, with no qualifying service period and uncapped compensation; and a detriment claim, available from day one of employment, covering anything short of dismissal - demotion, increased scrutiny, hostile treatment a workplace failed to prevent.
Once a worker shows they made a protected disclosure and then suffered a detriment or dismissal, the burden shifts to the employer to show the disclosure played no part in that treatment. That burden-shifting mechanic is the part most compliance content undersells. Every adverse action following a protected disclosure needs a documented, independently defensible rationale that would hold up if the disclosure were removed from the picture entirely.
Where a reporting channel helps, and where it stops
A channel that makes anonymous or confidential disclosure genuinely accessible does real work: the harder it is to identify who disclosed, the harder it is - practically, not just legally - to retaliate, and the fewer detriment claims arise in the first place.
What a channel alone does not produce is the documentation trail that wins a PIDA dispute after the fact: a demonstrable, consistent pattern showing that whatever happened to the worker afterward - a performance review, a restructuring decision, a disciplinary action - would have happened regardless of the disclosure, because it matches how comparable situations were handled for people who never disclosed anything.
How Rectifia handles it
Reasonable-time tracking runs on every case with a full timestamped audit trail: messages, evidence, manual investigator log entries, and any Consistency & Bias Engine flags along with how they were resolved. The compliance risk under PIDA is not really in the intake - it is in whether the organization can show consistent treatment afterward, on demand, without reconstructing it from memory.