EU Whistleblowing Directive: A Practical Compliance Guide
The EU Whistleblowing Directive, formally Directive (EU) 2019/1937, sets common minimum standards for protecting people who report breaches of Union law. For many organisations it has turned “speak-up” from a good-practice idea into a legal duty, with fixed deadlines, confidentiality rules and strong protections against retaliation.
The directive has now applied in full for several years, yet many organisations still run reporting channels that were set up in a hurry. Some cannot show they meet the response deadlines or have not aligned whistleblowing with data protection.
This guide explains who must set up internal reporting channels, what the directive requires, how it interacts with GDPR and national law, and how to build a programme that stands up to scrutiny.
What the directive is and who it applies to
The directive protects people who report information on breaches they have obtained in a work-related context. Member States had to transpose it into national law by 17 December 2021. For private sector entities with 50 to 249 workers, the obligation to set up internal channels could be deferred until 17 December 2023.
Which breaches are covered
The directive covers breaches of EU law in a defined list of areas. These include public procurement, financial services and anti-money laundering, product safety, transport safety, environmental protection, food safety, public health, consumer protection, protection of privacy and personal data, security of network and information systems, the EU’s financial interests, and internal market rules such as competition and state aid. Many Member States have gone further and extended protection to breaches of national law too.
Who is protected
Protection is not limited to employees. It extends to self-employed people, shareholders, members of management and supervisory bodies, volunteers, paid and unpaid trainees, and people working for contractors, subcontractors and suppliers. Job applicants and former workers are also covered, as are facilitators who help a reporting person and colleagues or relatives who could suffer retaliation.
Who must set up internal reporting channels
Under Article 8, the following organisations must establish internal channels and procedures for reporting and follow-up:
- Private sector entities with 50 or more workers. Those with 50 to 249 workers may share resources for receiving reports and carrying out investigations, but they remain responsible for confidentiality, feedback and addressing the breach.
- Entities in scope of certain EU financial services, anti-money laundering and transport safety rules, listed in the directive’s annex, regardless of their size.
- All public sector entities, including entities owned or controlled by them. Member States may exempt municipalities with fewer than 10,000 inhabitants or fewer than 50 workers, and may allow municipalities to share channels.
Member States can also require smaller private entities to set up channels after a risk assessment, for example where activities pose environmental or public health risks.
Key requirements of the EU Whistleblowing Directive
Secure internal channels
Channels must allow reports in writing, orally or both. Oral reporting should be possible by telephone or other voice messaging and, on request, through a physical meeting within a reasonable timeframe. Channels can be run internally or by an external third party, but they must be designed so that unauthorised staff cannot access the reporter’s identity.
Deadlines for acknowledgement and feedback
Article 9 sets two deadlines that regulators and courts will look at closely:
- Acknowledgement within seven days of receiving the report.
- Feedback within a reasonable timeframe, not exceeding three months from the acknowledgement or, if none was sent, from the end of the seven-day period after the report was made.
You must also designate an impartial person or department to follow up on reports, carry out diligent follow-up (including on anonymous reports where national law provides for it), and give clear information on how to report externally to competent authorities.
Protection against retaliation
Reporting persons qualify for protection if they had reasonable grounds to believe the information was true at the time and within scope, and they reported internally, externally or, in specific conditions, by public disclosure. Article 19 prohibits any form of retaliation, including dismissal, demotion, withheld promotion, negative performance reviews, intimidation and blacklisting. Threats and attempts are covered too.
In legal proceedings, the burden of proof shifts. Once a reporting person shows they made a report and suffered a detriment, it is presumed that the detriment was retaliation, and the employer must prove otherwise. Member States must also set effective, proportionate and dissuasive penalties, including for hindering reports or breaching confidentiality.
Confidentiality
Article 16 requires that the reporting person’s identity is not disclosed, without their explicit consent, to anyone beyond the authorised staff handling the report. The same applies to information from which their identity could be deduced. Disclosure is only permitted where it is a necessary and proportionate obligation under EU or national law, for example in investigations or judicial proceedings, and normally the reporter must be told first.
Record keeping
Every report must be recorded in line with confidentiality rules and kept no longer than necessary and proportionate. Where a report is made orally, you may keep a recording or accurate transcript or minutes, and the reporting person must be offered the chance to check, rectify and agree them by signing.
How whistleblowing interacts with GDPR
A whistleblowing channel processes personal data about reporters, the people named in reports and witnesses. Article 17 of the directive confirms that this processing must comply with GDPR. In practice, that means:
- Data minimisation. Personal data that is manifestly not relevant to a report should not be collected or, if collected by accident, should be deleted without undue delay.
- Records of processing. Add your whistleblowing process to your record of processing activities, with the legal basis, categories of data, recipients and retention periods.
- DPIA. Whistleblowing often involves sensitive allegations and possibly special category or criminal offence data. A data protection impact assessment is often advisable.
- Data subject rights. People named in reports have GDPR rights, but these may be restricted where national law allows, to protect the investigation and the reporter’s identity. Document how you handle such requests.
- Vendors. If a third party receives reports, you need a processing agreement and a security assessment.
National transposition: why local law matters
The directive sets minimum standards, so Member States’ laws differ in important ways. Several countries transposed late. In March 2025 the Court of Justice of the EU ordered Germany, Luxembourg, Czechia, Estonia and Hungary to pay financial penalties for failing to transpose the directive on time. The European Commission’s July 2024 report confirmed that all Member States had transposed it, while identifying shortcomings in areas such as material scope, conditions for protection and retaliation safeguards.
Differences you should check country by country include:
- Whether reports on breaches of national law are covered.
- Whether you must accept and follow up anonymous reports.
- Whether group-level channels are acceptable or each subsidiary with 50 or more workers needs its own.
- Language requirements, retention periods and any registration or reporting duties.
- The competent authorities for external reporting and the penalties that apply.
The European Commission’s whistleblower protection page is a useful starting point, but multinational groups should map requirements for every country where they employ 50 or more workers.
Implementation checklist
Use this checklist to set up a new programme or test an existing one.
- Confirm scope. List every legal entity, its headcount and the national law that applies. Flag entities covered by the annex regardless of size.
- Assign ownership. Appoint an impartial, competent person or team to receive and follow up on reports, with independence from the business lines they may investigate.
- Design the channels. Offer written and oral reporting, and a meeting on request. Decide whether to accept anonymous reports, taking national law into account.
- Secure access. Restrict access to authorised case handlers, log access and protect identifying information throughout the case.
- Write the policy and procedure. Cover scope, how to report, confidentiality, non-retaliation, investigation steps, deadlines and external reporting routes.
- Track deadlines. Build the seven-day acknowledgement and three-month feedback deadlines into your case workflow, with alerts before they expire.
- Complete GDPR documentation. Update your ROPA, carry out a DPIA where needed, set retention periods and review any processor agreements.
- Train and communicate. Train case handlers and managers, and publish clear, easily accessible information for workers and external stakeholders.
- Monitor for retaliation. Check in with reporters and review HR decisions affecting them after a report.
- Report and review. Give the board anonymised statistics and review the programme regularly.
Common mistakes to avoid
- Treating a mailbox as a channel. A shared email address rarely provides access control, audit trails or deadline tracking.
- Missing the feedback deadline. Feedback does not require a finished investigation, but it must explain what action is planned or taken and why.
- Overlooking non-employees. Contractors, suppliers and former staff are protected, so they must be able to reach the channel.
- Ignoring local law. A single group policy that ignores national differences can leave subsidiaries non-compliant.
How Enactia helps
Enactia is a governance, risk and compliance platform. It does not replace legal advice on national law, but it gives you the tools to run and evidence a compliant programme.
- Whistleblowing Management. Our whistleblowing management module supports confidential intake, case handling and deadline tracking, so acknowledgement and feedback timeframes are visible to your team.
- Policy Management. Draft, approve, publish and review your speak-up policy with policy management, with version history for audits.
- ROPA and DPIAs. Record whistleblowing processing in your record of processing activities and run a DPIA on the channel.
- Ticketing and evidence. Assign follow-up tasks and keep supporting documents in one repository with controlled access.
Frequently asked questions
Does the EU Whistleblowing Directive apply to companies with fewer than 50 workers?
Generally no, unless the company falls within the financial services, anti-money laundering or transport safety rules listed in the annex, or national law extends the obligation after a risk assessment.
What are the deadlines for responding to a report?
You must acknowledge receipt within seven days and give feedback within a reasonable timeframe of no more than three months from the acknowledgement, or from seven days after the report if no acknowledgement was sent.
Must we accept anonymous reports?
The directive leaves this to Member States. Some national laws require organisations to accept and follow up anonymous reports, while others do not. Anonymous reporters who are later identified and suffer retaliation are still protected.
Can a group use one central whistleblowing channel?
Private entities with 50 to 249 workers may share resources. For larger subsidiaries, the position depends on national law, so many groups keep a local channel per entity alongside a group-level option.
Can we outsource the reporting channel?
Yes. A third party can operate the channel, provided it offers appropriate guarantees of independence, confidentiality, data protection and secrecy. You remain responsible for follow-up and compliance.
Conclusion: build a channel people trust
Compliance with the EU Whistleblowing Directive comes down to three things: a secure channel that people can reach, a process that meets the seven-day and three-month deadlines, and real protection for those who speak up. Get those right, align them with GDPR and your national law, and your programme becomes an early warning system rather than a legal risk.
Want to see how Enactia can help you run a confidential, well-documented whistleblowing programme? Contact us or book a demo with our team.
