EU Regulatory Domain
Directive (EU) 2019/1937: secure reporting channels and effective protection for persons who report breaches of EU law.
Key facts
Private entities with 50 or more workers and, subject to limited exemptions, all public-sector entities must operate internal channels.
Reports must be acknowledged within seven days of receipt and followed up diligently by an impartial person or department.
The reporting person must receive feedback within a reasonable period not exceeding three months.
Retaliation is prohibited, and in proceedings the burden of proof shifts to the person who took the detrimental measure.
The Whistleblower Protection Directive sets common minimum standards for protecting persons who report breaches of EU law that they have learned about in a work-related context. It covers areas such as public procurement, financial services and anti-money laundering, product and transport safety, environmental protection, public health, consumer protection, privacy and network security, the Union's financial interests, and the internal market, including competition and corporate tax. Several Member States, including Portugal, extended national protection beyond EU law.
private sector: legal entities with 50 or more workers;
public sector: all public-sector entities, although Member States may exempt municipalities with fewer than 10,000 inhabitants or fewer than 50 workers, and other public entities with fewer than 50 workers;
regulated sectors: entities covered by EU financial-services and anti-money laundering rules, regardless of size.
confidentiality: the identity of the reporting person and of any third party mentioned must be protected;
accessibility: reports in writing or orally and, on request, in a physical meeting;
acknowledgement: within seven days of receipt;
follow-up: by an impartial person or department, with diligence;
feedback: within a reasonable period not exceeding three months;
records and information: reports must be documented, and clear information on external reporting channels must be provided.
The Directive leaves to Member States the decision on whether anonymous reports must be accepted. Portugal and Spain admit them.
Any form of retaliation is prohibited, including threats and attempts. In proceedings, the burden of proof shifts to the person who took the detrimental measure. Protection also extends to facilitators, colleagues and relatives of the reporting person, and to legal entities connected to them. Member States set penalties for obstructing reports, retaliating or breaching confidentiality.
The Court of Justice imposed financial penalties on five Member States in March 2025 for late transposition. The Commission's evaluation of the Directive is under way and its report is expected by the end of 2026.
Portugal: Law 93/2021 of 20 December, applicable to public and private entities with 50 or more workers;
Spain: Law 2/2023 of 20 February.
Compliance Assessment: a review of the channel, procedures and protection measures;
Implementation Kits: the reporting procedure, case register and communication templates;
Compliance Secretariat: independent administration of reports and statutory deadlines;
Training & Capacity: training for channel managers and awareness for staff.
Related domains: Anti-Corruption · Anti-Money Laundering · Data Protection · Corporate Governance
Official text: Directive (EU) 2019/1937 on EUR-Lex
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free review of your channel, procedures and protection against retaliation.