An online forum managed by the union is all that would be needed. But crucially, the union would need to be smart about who they give access to and also have good security people analysing usage/IP addresses and the like. Also make users agree to a declaration that they are legitimate users before granting access. If company spy does get access the union should send lawyers after them for accessing a computer system without permission. Of course it wouldn't be perfect, stuff will leak - but it would be a lot more secure that discussing union issues on company premises and on company equipment.
Maybe I'm looking at the issue too simplistically, but I find it odd that in this day and age unions still try to organise and discuss things the way they did decades ago.