🇫🇷 France compliance

Plateforme lanceur d'alerte pour France

En France, la Loi Waserman (modifiée Sapin II) transpose la Directive UE 2019/1937 et impose aux entreprises de 50+ salariés la mise en place d'un canal interne de signalement confidentiel. Les signalements doivent être accusés réception sous 7 jours et recevoir un retour substantiel sous 3 mois. Les sanctions administratives en cas de non-conformité atteignent €60,000.

Confidly is a GDPR-compliant whistleblowing channel built for companies in France (France) operating under Loi Waserman (modifiée Sapin II) (Loi Sapin II). The intake form is auto-configured with the categories and disclosures Loi Sapin II requires. Reporters can attach audio or video oral statements to a web submission; a native phone-hotline or voicemail channel is on roadmap. The mandatory 7-day acknowledgement and 3-month feedback updates are automated. Set up in 15 minutes. Hosted in the EU. Used by compliance teams from 50 to 5,000 employees.

Law Loi Waserman (modifiée Sapin II)
In force since 1 September 2022
Who must comply 50+ employees
Enforcement Défenseur des droits
Max fine €60,000
Companies affected ~50,000 companies with 50+ employees

What Loi Sapin II requires you to do

Loi Waserman (modifiée Sapin II) transposes the EU Whistleblower Directive 2019/1937 into France national law. The core obligations for companies above the threshold (50+ employees):

In France, enforcement sits with Défenseur des droits. Maximum fines for non-compliance reach €60,000.

Estimate your exposure under Loi Sapin II with the fines calculator.

How Confidly covers Loi Sapin II

What does Confidly cost in France?

Three plans, EUR-priced (VAT reverse-charged for EU B2B). Pick a tier by company size; everything else is included.

Frequently asked questions: Loi Sapin II

Is a whistleblowing channel mandatory in France?
Yes. Loi Waserman (modifiée Sapin II) (Loi Sapin II), the France transposition of EU Directive 2019/1937, requires companies with 50+ employees to operate a confidential internal whistleblowing channel. The law has been in force since 1 September 2022.
What are the fines for non-compliance with Loi Sapin II?
Maximum administrative fines under Loi Sapin II reach €60,000. Enforcement is carried out by Défenseur des droits. Fines apply both for failing to establish a channel and for retaliation against reporters.
Does Loi Sapin II require anonymous reporting?
Loi Sapin II permits anonymous reporting where France national law allows. Confidly's reporter UI issues a server-side case code and reporter-only secret (no email, IP address, or browser identifier is stored), so reporters can submit and follow up entirely anonymously.
What are the timelines under Loi Sapin II?
Companies must acknowledge a report within 7 days of receipt and provide substantive feedback to the reporter within 3 months. Confidly's dashboard tracks both SLAs with automatic reminders.
Is GDPR satisfied by Loi Sapin II compliance?
Loi Sapin II compliance and GDPR are complementary, not equivalent. Confidly is hosted entirely in the EU, signs a GDPR-compliant Data Processing Agreement, and runs an append-only audit log that satisfies both Défenseur des droits inspections and Article 30 GDPR records.
How long does it take to deploy a whistleblowing channel for France?
15 minutes for the channel itself. Branding, FR, EN translations, and policy import take an additional 1-2 hours. Most France customers go live the same day they sign up.

Starter

Legally compliant on day one. For up to 100 employees.

39 /mo
Billed annually (€468/yr)
  • 1 channel, up to 100 employees
  • Country-specific intake (HinSchG, Loi Sapin II, D.lgs 24, Ley 2, Wbk)
  • Audio and video attachments (oral statements upload alongside documents)
  • Auto reporter status updates at 7 days and 3 months (Directive Art. 9)
  • AI summary + severity hint, anonymous two-way chat
  • EU data hosting, GDPR DPA, metadata-stripped uploads
Start free trial
Most popular

Pro

Investigations, not just intake. For 100 to 500 employees.

124 /mo
Billed annually (€1488/yr)
  • Everything in Starter
  • Up to 500 employees, AI in 25+ languages, SSO (SAML / Google / M365)
  • AI case clustering: surfaces when multiple anonymous reports describe the same pattern
  • Custom investigation playbooks + auto-escalation rules + conflict-of-interest detector
  • Native HRIS sync (Personio, BambooHR) + Slack and Teams alerts
  • WhatsApp + SMS intake, auto-generated annual compliance report (country-tailored PDF)
Start free trial

Enterprise

Group structures, sovereign data, your brand.

332 /mo
Billed annually (€3984/yr)
  • Everything in Pro
  • Up to 5 channels, 2,000 employees, per-channel EU residency (DE→DE, FR→FR) + custom retention
  • White-label intake on your domain (speakup.acme.com) with custom DPA and branding
  • Multi-entity console for holdings: isolated audit trails per subsidiary
  • External ombudsperson seats: time-boxed lawyer or auditor access per case
  • SCIM, REST API, webhooks, BYOK encryption, dedicated CS, 99.9% SLA
Start free trial

Other EU countries

Compliance guides for the other 26 EU + EEA member states:

Get Loi Sapin II-compliant in 15 minutes

14-day free trial. EU-hosted. No credit card. Cancel anytime.

Multi-entity? Talk to us →