Compliance guide · Updated 2026
EU Whistleblower Directive 2019/1937 - complete guide
EU Directive 2019/1937 - also called the EU Whistleblower Directive - has been in force across
all 27 member states since December 2023 (for companies with 50+ employees). It requires every
mid-sized company in Europe to set up an internal reporting channel, investigate every report
within 90 days, and protect reporters from retaliation. This guide covers what it means in
practice, who's covered, what the fines look like, and how to comply.
What the directive actually requires
Three obligations sit at the centre of the directive:
- Maintain an internal reporting channel that lets employees, contractors,
suppliers, shareholders, and former staff report breaches of EU law. The channel must be
confidential, separate from regular HR, and allow anonymous reports if the local
transposing law permits.
- Acknowledge every report within 7 days and provide feedback to the reporter
within 3 months on what was done. Both timeframes start from the date the channel
receives the submission.
- Protect reporters from retaliation - dismissal, demotion, harassment,
and reputational harm tied to their report. Tribunals across the EU now place the burden of
proof on the employer to show retaliation didn't happen.
Who's covered
The threshold is 50 or more workers, counted as headcount (full-time
equivalents in some jurisdictions). Some sectors are covered regardless of size:
financial services, anti-money-laundering, transport safety, food safety, and a few others.
Public bodies are covered from 50 workers (no SMB exemption).
Three groups, three deadlines
| Group | Threshold | Deadline |
| Large companies + public sector | 250+ workers | 17 December 2021 |
| Medium-sized companies | 50–249 workers | 17 December 2023 |
| Financial / AML / transport, regardless of size | 1+ worker | 17 December 2021 |
How each EU country transposed it
The directive sets the floor; each member state can be stricter. Click any country on the map
for the local transposing law + enforcement authority, or scroll past for the full reference list.
Deep-dive guides per jurisdiction (in the local language):
HinSchG (DE) ·
Loi Sapin 2 (FR) ·
Ley 2/2023 (ES) ·
D.Lgs. 24/2023 (IT) ·
Wbk (NL).
What happens if you don't comply
Fines for missing or non-compliant channels range from a few thousand euros to
€1,000,000 in Spain, with Italy, Germany, and France clustering in the
€20,000–€60,000 range per violation. Beyond fines, regulators can require remediation, and
tribunals routinely award damages to retaliated reporters (uncapped in many jurisdictions).
The bigger risk is reputational. A botched whistleblower report that surfaces in the press
(or via an external channel like a national authority) creates the kind of scandal that
destroys customer trust for years. Tools like Confidly prevent that by keeping reports
internal long enough for the company to actually solve the underlying problem.
What a compliant channel looks like
The directive doesn't mandate a specific technology. It mandates a set of guarantees:
- Confidentiality - only the people investigating may see the report
- Anonymity option - where the national law allows it (most do)
- Acknowledgment within 7 days
- Feedback within 3 months
- A dedicated, designated person or unit handling reports
- Records of every report retained for the duration of the case + audit window
- Multiple submission methods - written, verbal, in-person on request
You can build this yourself with a Google Form + a spreadsheet + an inbox + a paralegal - and
many companies tried that in 2021–2023. The problem isn't the form. The problem is the
audit trail, confidentiality (Google Forms is owned by the company),
anonymity (the form sees the user's Google account), and retention. By the
time the auditor visits, the spreadsheet has gaps and the Google Form has changed shape.
How Confidly handles each requirement
| Directive requirement | Confidly |
| Anonymous intake | No email, no IP, no fingerprint. Server-issued case code + reporter's own 6-digit secret. |
| Confidentiality | Multi-tenant Postgres with row-level org scoping enforced by every authenticated endpoint. |
| 7-day acknowledgement | Built-in dashboard SLA timer + email reminder to the assigned investigator. |
| 3-month feedback | Same SLA timer escalates if a case sits 90 days without status change. |
| Designated handler | Cases are assigned to a named investigator; role separation (owner / admin / investigator / viewer). |
| Records of every report | Append-only audit log - never UPDATE, never DELETE. CSV/JSON export on Enterprise tier. |
| Configurable retention | Per-channel retention policy (days). Cases auto-purged with audit-stub left behind. |
| Multiple submission methods | Web form (default) + email forwarding + in-person logged via admin UI. |
The 15-minute compliance path
- Sign up with your work email
- Create your organisation (you become the owner)
- Confidly auto-creates a default channel with the standard categories
- Customise categories if needed (e.g. add "research misconduct" for a university)
- Copy the public link (
confidly.eu/your-slug) - Paste it into your careers page, intranet, and HR handbook
- Done. You're directive-compliant.
The next employee who has something to report knows where to go. The next compliance audit,
you'll have the trail. Most importantly: when something real does happen, you'll hear about
it from your own employee first - not from a journalist.