Legal requirements
EU Whistleblower Protection Directive 2019/1937
Since 17 December 2021 every EU employer with 50 or more employees must operate a confidential internal reporting channel under Directive (EU) 2019/1937. Each Member State has transposed the directive into national law with its own deadlines and penalties.
Every EU member state has transposed the directive with its own regulator and penalties — from Germany's Hinweisgeberschutzgesetz to France's loi Waserman and Italy's Legislative Decree 24/2023. What stays constant is the core: a confidential internal channel, acknowledgement within 7 days, feedback within 3 months, and protection from retaliation backed by a reversed burden of proof. Whistlechannel is EU-incorporated and hosted exclusively in the EU, with no US sub-processors — so your reporting data stays beyond the reach of the US CLOUD Act and FISA Section 702, the laws that led the Court of Justice to strike down Privacy Shield in Schrems II.
What the directive requires
- An internal reporting channel guaranteeing anonymity and confidentiality
- Acknowledgement to the reporter within 7 days
- Feedback on follow-up actions within 3 months
- Protection against retaliation for reporters, facilitators and family
- Documentation and case-tracking compliant with GDPR
- An external reporting route to the competent national authority
Frequently asked questions
Does my organization need a whistleblower channel?
What deadlines apply once a report comes in?
What is the reversed burden of proof?
Where must whistleblower data be stored to stay GDPR-compliant?
Can we outsource the reporting channel to a third party?
What does a compliant whistleblowing channel cost?
Ready to comply with EU Directive 2019/1937?
Get started in minutes. No installation, no commitment, no credit card required for trial.