THE EU WHISTLEBLOWING DIRECTIVEHow to get compliant
with whistleblowing laws

Download our free whitepaper:

How to get compliant with the Whistleblowing Law

The EU Whistleblowing Directive (2019/1937) was introduced to protect individuals who report work-related misconduct. This regulation requires organisations to establish secure, confidential reporting systems that safeguard whistleblowers from retaliation.

DIRECTIVE REQUIREMENTSHow the EU Whistleblowing Directive impacts organisations

Organisations with 50 or more employees and municipalities with over 10,000 inhabitants are required to implement secure and effective reporting channels. These systems must be designed to ensure the safety and confidentiality of whistleblowers while meeting legal obligations.

To comply with the directive, reporting channels must:

Be secure

Guarantee confidentiality

Have a designated owner

Adhere to timeframes

Meet GDPR guidelines

Allow for written and/or verbal reports

IMPORTANT DETAILSKey aspects of the EU Whistleblowing Directive

Who can report misconduct?

Any individual who becomes aware of work-related misconduct can submit a report. Protection extends beyond current employees to include former employees, job applicants, contractors and suppliers, and supporters of the whistleblower.

What types of misconduct can be reported?

Whistleblowing reports can cover violations of EU law related to various issues, including but not limited to:

  • Money laundering and tax fraud

  • Product and transport safety

  • Data protection and privacy violations

  • Public health concerns

  • Animal welfare violations

  • Environmental protection breaches

Whistleblower protection against retaliation

Whistleblowers are legally protected from any form of retaliation when submitting a report through the designated reporting channel. To qualify for protection, the whistleblower must have reasonable belief that the information they are providing is true at the time of reporting.

INTERNAL REPORTING CHANNELSPenalties for non-compliance

While the EU Whistleblowing Directive does not establish specific minimum penalties, it requires member states to implement national laws that impose sanctions on organisations that:

  • Obstruct or prevent whistleblowing by discouraging or blocking reports.
  • Breach confidentiality by disclosing a whistleblower’s identity without consent.

  • Retaliate against whistleblowers through actions such as dismissal, harassment, or discrimination.

Failure to comply with national whistleblower protection laws can result in significant financial penalties, legal action, and reputational damage for organisations. Ensuring proper internal reporting channels and protective measures is essential for compliance and maintaining trust within your organisation.

HOW TO COMPLY6 essential steps to meet whistleblowing requirements

Follow these steps to ensure your organisation complies with the EU Whistleblowing Directive.

Respond in a timely manner

Implement a procedure to acknowledge receipt of the report within seven days, and provide feedback to the whistleblower within three months.

Align whistleblowing procedures with GDPR

Continue to comply with GDPR requirements by carefully managing personal data, and ensuring that data is stored securely within the EU.

Implement secure reporting channels

Establish reporting channels that guarantee confidentiality and protect the identity of whistleblowers and any individuals named in reports. Secure your system against unauthorised access and maintain safe records.

Provide multiple reporting options

Provide flexible reporting options. Accept written reports via an online platform, verbal reports through phone or voice messages, and offer personal meetings upon request.

Designate a responsible owner

Appoint a qualified person or department to handle incoming reports. Their responsibilities should include managing the reporting process, maintaining ongoing communication with the whistleblower, and providing timely feedback

Make reporting channels accessible

Ensure your reporting channels are easily accessible to all employees and extend access to external stakeholders such as suppliers, contractors, shareholders, trainees, and job applicants.

Is your whistleblowing solution compliant?

When selecting a system, ensure it meets all legal requirements and complies with GDPR. It’s essential that your chosen solution includes the necessary functions to keep you compliant and protect whistleblower confidentiality.

We’ve compiled a checklist of key features to help you choose a provider that meets both whistleblower law and GDPR standards – use it as a guide during your procurement process.

TRY WHISTLELINKAre you compliant?
You can be in 10 minutes.

EU Whistleblowing Directive & ComplianceFrequently asked questions

What is whistleblowing?

Whistleblowing occurs when someone reports illegal, unethical, or harmful activities within a public, private, or government organisation. Common issues reported include fraud, corruption, misconduct, harassment, discrimination, and violations related to health, safety, or environmental regulations.

The EU Whistleblowing Directive protects whistleblowers from retaliation, such as dismissal, harassment, or discrimination, when they report breaches of EU law.

Protected violations include:

  • Financial services, money laundering, and terrorist financing
  • Public procurement and public health
  • Product, food, and transport safety
  • Environmental protection and radiation safety
  • Animal health and welfare
  • Consumer rights and data protection
  • Network and information systems security

To qualify for protection, whistleblowers must use designated reporting channels and believe their information is accurate at the time of reporting.

Employers must establish secure and effective internal reporting channels that allow employees and other stakeholders to report misconduct confidentially.

These channels must:

  • Be easily accessible
  • Have clear ownership and management
  • Guarantee confidentiality
  • Meet GDPR compliance
  • Allow for written and/or verbal reports

The EU Whistleblowing Directive was introduced to combat corruption and ensure better protection for individuals who report misconduct or breaches of EU law. It aims to encourage transparency and accountability within organisations.

To comply, organisations must implement secure, confidential reporting channels that meet the directive’s requirements. These systems must:

  • Guarantee confidentiality of the whistleblower
  • Be easily accessible to employees and stakeholders
  • Meet GDPR guidelines for data protection
  • Ensure reports can be submitted both in writing and verbally

The directive applies to:

  • Public and private organisations in the EU with 50 or more employees
  • Municipalities with more than 10,000 inhabitants
  • Certain private organisations in high-risk sectors (e.g., financial services or those vulnerable to money laundering and terrorist financing)

While the directive does not set specific penalties, it requires member states to implement laws that penalise organisations for:

  • Preventing reports from being made
  • Breaching confidentiality of the whistleblower’s identity
  • Retaliating against whistleblowers

National penalties may include fines, legal action, and reputational damage for non-compliance.

No. The directive also applies to municipalities in the EU with over 10,000 inhabitants, in addition to all public and private organisations with more than 50 employees.

WEBINARTHE WHISTLEBLOWING LAW

Annelie DemredVP, Strategy and Growth

Are you up to date?

Wednesday   |   11:00 – 11:30

HAPPY TO MEET YOU!

Get in touch

Our team is ready to answer your questions.
Fill out the form below and we'll be in touch as soon as possible.

Talk with Territory Manager
Annelie Demred

annelie.demred@whistlelink.com

Whistlelink resources

Download your free Whitepaper

Nice to meet you!

Get in touch

Our team would like to offer you a free demo of Whistlelink.
Please select a suitable time in our calendar.

Talk with Territory Manager
Annelie Demred

0046 (0)706 83 82 88

HAPPY TO MEET YOU!

Get in touch

Our team is ready to answer your questions. Find the answer by visiting our support centre, or fill out the form below and we'll be in touch as soon as possible. Or simply give us a call!

Talk with Territory Manager
Annelie Demred

annelie.demred@whistlelink.com