Β·6 min read

The EU Whistleblower Directive (2019/1937), explained

Directive (EU) 2019/1937 β€” the EU Whistleblower Protection Directive β€” requires employers across the European Union to give people a safe, confidential way to report breaches of EU law, and to protect them from retaliation when they do. This guide covers who is in scope, the deadlines, and the specific obligations an internal reporting channel has to meet.

Who needs a whistleblower channel?

Any EU employer with 50 or more employees must operate a confidential internal reporting channel. The directive applies to both private and public sector organisations. Companies in regulated sectors β€” financial services or aviation safety, for example β€” are covered regardless of how many people they employ.

The deadlines

The directive has been in force since 17 December 2021 across the EU. The obligation was extended to organisations with 50 to 249 employees on 17 December 2023. Each Member State has transposed the directive into its own national law, with its own deadlines and penalties.

Internal vs external reporting

The directive requires two reporting routes to be available. Internal reporting goes to the employer’s own channel β€” that is what a platform like Whistlechannel provides. External reporting goes to the competent national authority. Internal reporting is preferred, but a reporter is never obliged to use it before going external.

What the directive requires

  • An internal reporting channel guaranteeing anonymity and confidentiality
  • Acknowledgement to the reporter within 7 days
  • Feedback on follow-up actions within 3 months
  • Protection against retaliation for reporters, facilitators and their family
  • Documentation and case-tracking compliant with GDPR
  • An external reporting route to the competent national authority

What happens if you don’t comply?

National sanctions vary by Member State. In several countries they include fines of up to €1 million and personal liability for management. Beyond the penalties, an organisation without a credible channel loses the early warning that internal reporting is meant to provide.

Ready to comply with EU Directive 2019/1937?

Get started in minutes. No installation, no commitment, no credit card required for trial.