Compliance guide · Updated 2026

EU Whistleblower Directive 2019/1937 - complete guide

EU Directive 2019/1937 - also called the EU Whistleblower Directive - has been in force across all 27 member states since December 2023 (for companies with 50+ employees). It requires every mid-sized company in Europe to set up an internal reporting channel, investigate every report within 90 days, and protect reporters from retaliation. This guide covers what it means in practice, who's covered, what the fines look like, and how to comply.

What the directive actually requires

Three obligations sit at the centre of the directive:

  1. Maintain an internal reporting channel that lets employees, contractors, suppliers, shareholders, and former staff report breaches of EU law. The channel must be confidential, separate from regular HR, and allow anonymous reports if the local transposing law permits.
  2. Acknowledge every report within 7 days and provide feedback to the reporter within 3 months on what was done. Both timeframes start from the date the channel receives the submission.
  3. Protect reporters from retaliation - dismissal, demotion, harassment, and reputational harm tied to their report. Tribunals across the EU now place the burden of proof on the employer to show retaliation didn't happen.

Who's covered

The threshold is 50 or more workers, counted as headcount (full-time equivalents in some jurisdictions). Some sectors are covered regardless of size: financial services, anti-money-laundering, transport safety, food safety, and a few others. Public bodies are covered from 50 workers (no SMB exemption).

Three groups, three deadlines

Group Threshold Deadline
Large companies + public sector 250+ workers 17 December 2021
Medium-sized companies 50–249 workers 17 December 2023
Financial / AML / transport, regardless of size 1+ worker 17 December 2021

How each EU country transposed it

The directive sets the floor; each member state can be stricter. Click any country on the map for the local transposing law + enforcement authority, or scroll past for the full reference list.

Deep-dive guides per jurisdiction (in the local language): HinSchG (DE) · Loi Sapin 2 (FR) · Ley 2/2023 (ES) · D.Lgs. 24/2023 (IT) · Wbk (NL).

What happens if you don't comply

Fines for missing or non-compliant channels range from a few thousand euros to €1,000,000 in Spain, with Italy, Germany, and France clustering in the €20,000–€60,000 range per violation. Beyond fines, regulators can require remediation, and tribunals routinely award damages to retaliated reporters (uncapped in many jurisdictions).

The bigger risk is reputational. A botched whistleblower report that surfaces in the press (or via an external channel like a national authority) creates the kind of scandal that destroys customer trust for years. Tools like Confidly prevent that by keeping reports internal long enough for the company to actually solve the underlying problem.

What a compliant channel looks like

The directive doesn't mandate a specific technology. It mandates a set of guarantees:

You can build this yourself with a Google Form + a spreadsheet + an inbox + a paralegal - and many companies tried that in 2021–2023. The problem isn't the form. The problem is the audit trail, confidentiality (Google Forms is owned by the company), anonymity (the form sees the user's Google account), and retention. By the time the auditor visits, the spreadsheet has gaps and the Google Form has changed shape.

How Confidly handles each requirement

Directive requirementConfidly
Anonymous intakeNo email, no IP, no fingerprint. Server-issued case code + reporter's own 6-digit secret.
ConfidentialityMulti-tenant Postgres with row-level org scoping enforced by every authenticated endpoint.
7-day acknowledgementBuilt-in dashboard SLA timer + email reminder to the assigned investigator.
3-month feedbackSame SLA timer escalates if a case sits 90 days without status change.
Designated handlerCases are assigned to a named investigator; role separation (owner / admin / investigator / viewer).
Records of every reportAppend-only audit log - never UPDATE, never DELETE. CSV/JSON export on Enterprise tier.
Configurable retentionPer-channel retention policy (days). Cases auto-purged with audit-stub left behind.
Multiple submission methodsWeb form (default) + email forwarding + in-person logged via admin UI.

The 15-minute compliance path

  1. Sign up with your work email
  2. Create your organisation (you become the owner)
  3. Confidly auto-creates a default channel with the standard categories
  4. Customise categories if needed (e.g. add "research misconduct" for a university)
  5. Copy the public link (confidly.eu/your-slug)
  6. Paste it into your careers page, intranet, and HR handbook
  7. Done. You're directive-compliant.

The next employee who has something to report knows where to go. The next compliance audit, you'll have the trail. Most importantly: when something real does happen, you'll hear about it from your own employee first - not from a journalist.

Comply in 15 minutes

14-day free trial. EU-hosted. No credit card.

Multi-entity? Talk to us →