Photo by Aakriti Raina on Unsplash
Most compliance officers can name three whistleblowing cases: Edward Snowden, Frances Haugen, and whichever local scandal the national press is chewing on this month. The EU Whistleblower Directive was not written for any of those. It was written for the ten cases below. Each of them changed a specific rule of European corporate life: how banks are supervised, how tax rulings are disclosed, how HR handles retaliation claims, how boards protect the identity of a reporter. If you build or run an internal whistleblowing channel in 2026, these are the cases whose lessons are baked into the framework you have to operate. This guide walks through each, then extracts what they collectively teach about running a channel that actually works.
Direct answer
Ten whistleblowing cases sit at the base of modern EU compliance law: LuxLeaks (Antoine Deltour, 2014, PwC/Luxembourg), SwissLeaks (Hervé Falciani, 2015, HSBC), Panama Papers (John Doe, 2016, Mossack Fonseca), Volkswagen Dieselgate (multiple sources, 2015), Cambridge Analytica (Christopher Wylie, 2018, Facebook), Danske Bank Estonia (Howard Wilkinson, 2018), Barclays CEO whistleblower unmasking (2018, Jes Staley), Wirecard (Pav Gill / Financial Times, 2020), Frances Haugen (Facebook / Meta, 2021), and the NHS Mid Staffordshire scandal (Julie Bailey, Helene Donnelly, 2013). Each triggered a specific legal or regulatory change, from the EU Whistleblower Directive 2019/1937 itself (pushed forward by LuxLeaks and the Panama Papers) to the UK Senior Managers Regime whistleblower rules (Barclays), the German HinSchG (Wirecard, Cum-Ex), and the reversal of the burden of proof in Article 21(5) of the Directive. Reading them together tells you what “good” looks like for an internal channel: confidentiality that is actually kept, a case handler who is independent of the people being reported on, feedback within three months, an audit trail that survives litigation, and anti-retaliation protections written directly into the reporter’s employment terms.
LuxLeaks (Antoine Deltour, 2014)
Antoine Deltour was a junior auditor at PricewaterhouseCoopers in Luxembourg. In 2011 he copied around 28,000 pages of tax rulings issued to more than 340 multinationals and eventually passed them to the French journalist Édouard Perrin. The International Consortium of Investigative Journalists (ICIJ) published the analysis in November 2014, showing effective corporate tax rates of 0.25 to 2 percent negotiated for Amazon, IKEA, Pepsi, and FedEx. The political fallout hit Jean-Claude Juncker (then European Commission president and former Luxembourg prime minister) and became one of the two case files most cited by MEPs during the drafting of what became EU Directive 2019/1937.
Deltour was prosecuted in Luxembourg for theft, breach of professional secrecy, and money-laundering violations, and initially convicted. The Luxembourg Court of Cassation set the conviction aside in 2018 on the reasoning from the European Court of Human Rights (Guja v. Moldova, 2008; Heinisch v. Germany, 2011) that public-interest disclosure cannot be criminalised. That reasoning is now codified in Article 21(2) of the Directive.
Lesson for compliance teams. A credible internal channel that had responded to Deltour would have kept the story inside PwC. Not offering one is the single biggest reason concerns leak outside.
SwissLeaks (Hervé Falciani, 2015)
Hervé Falciani, an IT engineer at HSBC Private Bank in Geneva, copied client files covering more than 100,000 accounts and 200 billion dollars in assets in 2008. He handed them to French tax authorities in 2009; ICIJ published in February 2015. The disclosure led to recovered taxes in the low billions across France, Spain, the UK, Belgium, and Argentina, criminal prosecutions of HSBC in France and Belgium, and a French administrative penalty of 300 million euros.
Falciani was convicted of industrial espionage by a Swiss court in 2015 and remains under a Swiss arrest warrant. Every EU state that received the files declined to extradite him, on the basis that public-interest disclosure protection applied. The Directive’s cross-border provisions in Article 6 codify exactly this: a reporter cannot be safely extradited over disclosing breaches of EU law, even where the secrecy law they broke sits in a strict jurisdiction.
Lesson for compliance teams. Financial-services groups with EU subsidiaries cannot rely on one member state’s stricter banking-secrecy regime as a shield. The Directive’s minimum standard applies everywhere.
Panama Papers (John Doe, 2016)
The reporter behind the Panama Papers has never been publicly identified and uses the pseudonym “John Doe”. In late 2014 they contacted Süddeutsche Zeitung and eventually shared 11.5 million documents from the Panamanian law firm Mossack Fonseca. Publication in April 2016 named heads of state, ministers, footballers, and a wide slice of European corporate life. The Icelandic prime minister resigned within a week; the EU Council added Panama to its list of non-cooperative tax jurisdictions.
More important for the Directive: John Doe published a manifesto explaining why they had chosen anonymous disclosure through journalists rather than any internal or official channel. Neither Mossack Fonseca nor any national regulator offered a credible confidential route. This is exactly the failure the Directive’s Article 6 three-tier reporting model (internal, external, public) is designed to prevent, with public disclosure protected only when the earlier tiers have failed.
Lesson for compliance teams. Anonymous submission is the design assumption of a modern channel, not a feature. A channel that requires email or SSO will not receive the Deltour or John Doe cases. Confidly issues a server-side case code plus a reporter-only six-digit secret, with no email, IP, or browser identifier stored.
Volkswagen Dieselgate (multiple sources, 2015)
Dieselgate did not begin with one whistleblower. It began with the West Virginia University research team commissioned by the International Council on Clean Transportation, which noticed the emissions gap in 2014 and forced Volkswagen to admit the defeat device to the US Environmental Protection Agency in September 2015. The internal history that emerged during the German criminal proceedings showed at least a dozen VW engineers had raised the defeat device internally over a decade. Their concerns were logged as engineering disputes, not compliance escalations, and never reached the executive board. VW’s total exposure eventually exceeded 30 billion euros.
Germany’s HinSchG (see our Germany country page) makes explicit in section 2 that emissions-standards compliance falls under the reportable EU-law categories, and the Federal Ministry of Justice cited Dieselgate alongside Cum-Ex when defending the law’s scope during parliamentary debate.
Lesson for compliance teams. Concerns raised as engineering, safety, or product-quality issues need a routing rule that pulls them into compliance when they engage a legal obligation. Confidly’s intake form categorises the report at submission time so the case handler can triage regardless of what the reporter called it.
Photo by AbsolutVision on Unsplash
Cambridge Analytica (Christopher Wylie, 2018)
Christopher Wylie, a former research director at Cambridge Analytica, surfaced publicly in March 2018 in a joint investigation by The Guardian, The Observer, and The New York Times, explaining how the firm had harvested Facebook user data through a personality-quiz app and used it for political targeting. Consequences: the FTC’s 5 billion dollar Facebook settlement, the collapse of Cambridge Analytica, the UK Information Commissioner’s Office fine of 500,000 pounds against Facebook (the pre-GDPR maximum), and the first serious cross-border test of the GDPR’s cooperation mechanism.
Wylie disclosed through journalists rather than a formal channel because he was under a non-disclosure agreement and feared civil litigation. NDAs that purport to prevent disclosure of a breach of EU law are void under Article 24 of Directive 2019/1937.
Lesson for compliance teams. An NDA cannot silence a whistleblower where the disclosure is protected under the Directive. HR should audit standard employment and severance agreements against Article 24 and update template clauses.
Danske Bank Estonia (Howard Wilkinson, 2018)
Howard Wilkinson, head of markets for Danske Bank’s Baltic operations, raised internal concerns in 2013 and 2014 that the Estonian branch was processing suspicious transactions on an implausible scale. His concerns were escalated within Danske but not to any national regulator. He left in 2014. By the time Berlingske and the Financial Times broke the story in 2018, transaction volume through the Estonian branch had reached around 200 billion euros, most plausibly linked to money-laundering originating in the former Soviet Union. Danske paid 2.5 billion dollars in US settlements in 2022; the Estonian branch closed; the chief executive resigned.
Wilkinson’s testimony to the European Parliament in November 2018 asked for two things: EU-level whistleblower protection with a reversed burden of proof, and mandatory bank-to-regulator escalation on internal money-laundering reports. The Directive delivered on the first (Article 21(5)); the second sits in the AMLD5/AMLR framework.
Lesson for compliance teams. Concerns raised in the second-line of defence should trigger a regulator-escalation rule when a severity threshold is met. Build the escalation path into the channel workflow; do not leave it to case-handler judgement.
The Barclays / Jes Staley whistleblower unmasking (2018)
In 2016 the Barclays board received two anonymous letters raising concerns about a senior hire, Tim Main, and his conduct at his previous role at JPMorgan. Jes Staley, Barclays chief executive and a personal friend of Main, ordered the group’s information-security team to identify the author. The FCA and PRA fined Staley a combined 642,430 pounds in May 2018 for breaching the individual accountability regime; Barclays itself was placed under enhanced supervisory monitoring.
The Barclays case is the reference incident behind the FCA’s SYSC 18 whistleblowing rules (updated 2021, further tightened 2024): a firm’s chief executive is now the “whistleblowers’ champion” by default at any deposit-taker or PRA-designated investment firm, personally accountable under the Senior Managers Regime and specifically prohibited from any attempt to identify a confidential reporter.
Lesson for compliance teams. Confidentiality is a rule the CEO can be personally fined for breaking. Technical architecture should make identity-inference difficult even for the channel operator. Confidly’s dashboard separates identity data from case body so a case handler working the file cannot casually look it up.
Wirecard (Pav Gill / Financial Times, 2020)
Pav Gill, head of legal for Wirecard’s Asia-Pacific operations from 2017 to 2018, compiled an internal report documenting round-tripping of revenue in Singapore, Dubai, and the Philippines, and escalated it to the board of management. The report was not investigated externally; Gill was dismissed. His mother approached the FT journalist Dan McCrum, whose 2019 series (based partly on Gill’s evidence) eventually forced KPMG’s special audit and the June 2020 collapse of the company after 1.9 billion euros of purported cash on its balance sheet turned out not to exist.
Wirecard became the German legislative reference case (with Cum-Ex) for the HinSchG. The specific provisions targeted at it are section 8 (mandatory independence of the internal reporting office from the reported subject), section 9 (obligation to investigate rather than merely document), and section 12 (equipping the office with sufficient authority and resources). BaFin was restructured in 2021 with a dedicated whistleblower unit.
Lesson for compliance teams. Wirecard’s board did technically have a channel. What it did not have was a duty to investigate what came through it. The Directive and HinSchG both fix this with an explicit duty to act, and require that the person triaging cannot report to the person the case is about.
Frances Haugen (Facebook / Meta, 2021)
Frances Haugen, a data-product manager on Facebook’s civic-integrity team, copied tens of thousands of internal documents before leaving in May 2021 and filed complaints in September with the US SEC, the US Senate, and (in parallel) The Wall Street Journal. The documents showed internal research that Instagram harmed teenagers’ mental health, that Facebook’s algorithm amplified divisive content, and that the company’s own trust-and-safety staff had flagged both without leadership action.
Haugen is legally important in Europe because she was the first major test of the Directive’s Article 15 (protection where the reporter goes to Union institutions or bodies). She filed simultaneously with US regulators, the European Parliament, and the UK Online Safety Bill process. Multi-track disclosure is protected as long as the reporter had reasonable grounds to believe each disclosure was necessary to secure the public interest.
Lesson for compliance teams. Reporters increasingly file to multiple recipients in parallel. The channel workflow should assume the case is not the only place the reporter is telling the story. Document decisions inside the audit log as if a national parliament might read them.
NHS Mid Staffordshire (Julie Bailey, Helene Donnelly, 2013)
Between 2005 and 2009, Mid Staffordshire NHS Foundation Trust had significantly higher mortality rates than expected. The scandal that eventually forced the 2013 Francis Inquiry started with two whistleblowers: Julie Bailey, a member of the public whose mother died at Stafford Hospital and who founded Cure the NHS, and Helene Donnelly, a nurse in the A and E department who had been raising concerns internally since 2007. Donnelly’s manager response, on her own testimony, was to warn her to watch her back in the car park.
The Francis Report recommendations reshaped clinical whistleblowing in England: the National Guardian’s Office, the Freedom to Speak Up Guardian in every NHS trust (see the freedom-to-speak-up guardian role in 2026), and the statutory duty of candour under regulation 20 of the Health and Social Care Act 2008 Regulated Activities Regulations 2014.
Lesson for compliance teams. Public-sector regulated services face parallel duties: a general whistleblowing channel, sector-specific reporting to the regulator (CQC, Ofsted, FCA), and a statutory duty of candour to the affected patient or family. Every regulated employer needs the sector rails wired in.
What these ten cases teach about running a channel
Read together, the ten cases produce a checklist that is now the practical standard for an EU internal whistleblowing channel. It is worth reading against your current setup.
Anonymous submission is the default, not a feature. Deltour, John Doe, the Barclays letters, and Wirecard all involved reporters who could not use a route that required their identity.
Case-handler independence is a legal obligation. HinSchG section 8 and Directive Article 9(1)(c) both require it. The person triaging cannot report to the person the case is about.
Retaliation prohibition reverses the burden of proof. Article 21(5) puts the onus on the employer to prove any adverse action was unconnected to the disclosure. Documentation inside the channel is your evidentiary base.
Confidentiality is a rule the CEO can be fined for breaking. Barclays made this literal in the UK; every EU state has equivalent power under Article 21(2) plus national administrative-fine provisions.
Multi-track disclosure is the modern norm. Haugen, Wilkinson, Wylie, and Gill all filed to multiple recipients. Every action must be defensible as an audit-log entry a national parliament might one day read.
Categorisation at intake is what makes engineering, product, and finance concerns visible. VW Dieselgate and Wirecard both had internal concerns that never reached compliance because they were tagged as something else. Route by content, not by the reporter’s labelling.
A working internal channel is the single strongest defence against public escalation. In every one of the ten cases, the reporter first tried, or explicitly rejected as unusable, the internal route.
Photo by Markus Spiske on Unsplash
What the numbers say about outcomes
Two data points contextualise the ten cases. The Association of Certified Fraud Examiners’ Report to the Nations (2024 edition) finds that reports through a formal channel are the source of 43 percent of occupational fraud detections, and that organisations with a formal channel detect fraud in a median 12 months versus 18 months without. Financial impact per case at those organisations is roughly half. The European Commission’s own impact assessment for Directive 2019/1937 estimated that undetected corruption and non-compliance cost the EU public finances between 5.8 and 9.6 billion euros per year, largely in the sectors where the cases above sit.
You can estimate your own exposure under the national transposition using our fines calculator, which cross-references the national administrative-fine caps and the ACFE median loss data by industry and headcount.
FAQ
What is the most famous whistleblowing case in the EU?
Two contenders: LuxLeaks (Antoine Deltour, 2014) is the case most cited in the preparatory work for EU Directive 2019/1937 itself, and Wirecard (Pav Gill and the Financial Times, 2020) is the case most cited in Germany’s national transposition (HinSchG). Both are legally more important than the more famous US cases (Snowden, Manning) for a European compliance audience because they directly shaped the framework you now operate under. Cambridge Analytica (Christopher Wylie, 2018) has the widest general recognition because of the Facebook overlap.
Do EU whistleblowers get paid?
No. Unlike the US False Claims Act, SEC and IRS whistleblower programs, and the DOJ Corporate Whistleblower Awards Pilot rolled out from 2024 (which pay claimants 15 to 30 percent of the sums recovered), the EU and UK do not pay whistleblowers a monetary reward. The Directive grants only legal protection: prohibition of retaliation, reversal of the burden of proof, reinstatement if dismissed, compensation for detriment, and free legal advice through the national competent authority. See our country pages for the national fine caps that apply.
Can a company sue a whistleblower for taking documents?
Not for information covered by the Directive’s material scope, per Article 21(2) and (7). Deltour’s Luxembourg conviction was set aside on this principle, and Falciani’s Swiss conviction is unenforceable in any EU member state that received the SwissLeaks data. NDAs that purport to prevent disclosure of a breach of EU law are void under Article 24. The Court of Justice has not yet ruled on the specific question of whether taking large volumes of general corporate data (beyond the specific breach evidence) is protected; national courts have gone both ways.
Which EU whistleblowing case had the biggest financial consequence?
Volkswagen Dieselgate, at more than 30 billion euros of aggregate settlements, fines, and buyback costs across the US and Europe by 2024. Danske Bank Estonia is second, at around 2.5 billion dollars in US settlements alone, before further pending European proceedings. Wirecard’s collapse wiped roughly 24 billion euros of listed market capitalisation but the criminal-recovery figure is much smaller because the underlying cash never existed.
How do I set up an internal whistleblowing channel that meets the Directive?
Four things a working channel needs on day one: an anonymous submission path with a reporter-side secret and no identity capture, a designated case handler who is independent of the reported subject and has the authority to investigate, an SLA workflow that acknowledges within seven days and gives substantive feedback within three months, and an append-only audit log that survives litigation. Confidly ships all four out of the box. See our whistleblowing procedure end-to-end guide for the operational detail.
What is the difference between a whistleblower and a witness?
A witness gives evidence about someone else’s report or investigation; a whistleblower makes the disclosure that starts it. Article 4(4) of the Directive extends anti-retaliation protection to “facilitators” (natural persons who assist the reporter, confidentially) and to third parties connected to the reporter, but the reporter themselves gets the fuller package including reversed burden of proof under Article 21(5) and access to national support measures under Article 20.