<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Guides — EU Whistleblower Directory</title><link>https://whistleblowertools.eu/guide/</link><description>Compliance guides for EU whistleblower legislation.</description><language>en</language><lastBuildDate>Fri, 17 Apr 2026 23:31:16 +0000</lastBuildDate><atom:link href="https://whistleblowertools.eu/guide/index.xml" rel="self" type="application/rss+xml"/><image><url>https://whistleblowertools.eu/favicon.svg</url><title>EU Whistleblower Directory</title><link>https://whistleblowertools.eu/</link></image><item><title>EU Directive 2019/1937 on whistleblower protection</title><link>https://whistleblowertools.eu/guide/eu-directive-2019-1937/</link><pubDate>Sat, 18 Apr 2026 01:29:45 +0200</pubDate><guid>https://whistleblowertools.eu/guide/eu-directive-2019-1937/</guid><description>Comprehensive guide to the EU Whistleblower Protection Directive (2019/1937). Understand who must comply, deadlines, requirements, and how to implement a compliant reporting channel.</description><content:encoded>&amp;lt;p class=&amp;#34;text-lg opacity-70 mb-8 leading-relaxed&amp;#34;&amp;gt;
A practical guide for organisations that need to understand and comply with the
European Union&amp;#39;s Whistleblower Protection Directive.
&amp;lt;/p&amp;gt;
&amp;lt;div class=&amp;#34;border-l-4 border-warning bg-base-200 px-4 py-3 mb-8&amp;#34;&amp;gt;
&amp;lt;h3 class=&amp;#34;font-bold text-base mb-2&amp;#34;&amp;gt;Key compliance deadlines&amp;lt;/h3&amp;gt;
&amp;lt;ul class=&amp;#34;text-sm mb-0 list-disc pl-5 space-y-1&amp;#34;&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;17 December 2021&amp;lt;/strong&amp;gt; — Deadline for member states with 250+ employee threshold&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;17 December 2023&amp;lt;/strong&amp;gt; — Deadline extended to organisations with 50–249 employees&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;All EU member states&amp;lt;/strong&amp;gt; have now transposed the Directive into national law&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;h2 id=&amp;#34;what-is-the-whistleblower-protection-directive&amp;#34;&amp;gt;What is the Whistleblower Protection Directive?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Directive (EU) 2019/1937 of the European Parliament and of the Council, adopted on 23 October 2019, establishes common minimum standards for the protection of persons reporting breaches of Union law. It requires organisations to set up secure, confidential reporting channels and prohibits retaliation against whistleblowers.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Directive covers a broad range of EU law areas, including public procurement, financial services, product safety, environmental protection, food safety, public health, consumer protection, data protection, and more.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;who-must-comply&amp;#34;&amp;gt;Who must comply?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive requires internal reporting channels for:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Private sector organisations&amp;lt;/strong&amp;gt; with 50 or more employees&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;All public sector entities&amp;lt;/strong&amp;gt;, including municipalities and government bodies&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Financial sector entities&amp;lt;/strong&amp;gt;, regardless of size (banks, insurance, investment firms)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Organisations in regulated sectors&amp;lt;/strong&amp;gt; covered by EU law (AML, aviation safety, etc.)&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Note that individual member states may set &amp;lt;strong&amp;gt;broader requirements&amp;lt;/strong&amp;gt; in their national transposition. Always verify the specific obligations in each jurisdiction where your organisation operates.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;core-requirements&amp;#34;&amp;gt;Core requirements&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Organisations subject to the Directive must:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;1-establish-internal-reporting-channels&amp;#34;&amp;gt;1. Establish internal reporting channels&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Provide secure channels that allow workers to report breaches confidentially. Channels must accept reports in writing (online platform, email, postal) and/or orally (telephone hotline, voice messaging). The channel must ensure the confidentiality of the reporting person&amp;amp;rsquo;s identity.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;2-designate-a-responsible-person-or-department&amp;#34;&amp;gt;2. Designate a responsible person or department&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Assign an impartial person or department to receive and follow up on reports. This function must have the authority to conduct investigations and must operate independently from management that could be subject to reports.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;3-follow-prescribed-timelines&amp;#34;&amp;gt;3. Follow prescribed timelines&amp;lt;/h3&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;7 days&amp;lt;/strong&amp;gt; — Acknowledge receipt of the report to the whistleblower&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;3 months&amp;lt;/strong&amp;gt; — Provide feedback to the whistleblower on the follow-up actions taken&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Maintain records of all reports in compliance with data protection requirements&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;4-protect-whistleblowers-from-retaliation&amp;#34;&amp;gt;4. Protect whistleblowers from retaliation&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive prohibits any form of retaliation, including dismissal, demotion, intimidation, damage to reputation, and blacklisting. Member states must provide effective remedies and support measures for reporting persons who suffer retaliation.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;5-ensure-data-protection-compliance&amp;#34;&amp;gt;5. Ensure data protection compliance&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;All personal data collected through the reporting channel must be processed in accordance with the General Data Protection Regulation (GDPR). Data must be stored only as long as necessary and access must be limited to authorised personnel.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;penalties-for-non-compliance&amp;#34;&amp;gt;Penalties for non-compliance&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Member states define their own penalty regimes in national transposition laws. Penalties may be imposed for:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Failing to establish reporting channels&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Obstructing or attempting to obstruct reporting&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Retaliating against reporting persons&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Breaching confidentiality obligations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Bringing vexatious proceedings against reporting persons&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;In Germany, for example, the Hinweisgeberschutzgesetz (HinSchG) provides for fines of up to &amp;lt;strong&amp;gt;€50,000&amp;lt;/strong&amp;gt; for failing to establish a reporting channel and up to &amp;lt;strong&amp;gt;€100,000&amp;lt;/strong&amp;gt; for retaliation. Other member states have similar penalty ranges.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;national-transpositions&amp;#34;&amp;gt;National transpositions&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Each EU member state has transposed (or is in the process of transposing) the Directive into national law, often with additional requirements:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Germany&amp;lt;/strong&amp;gt; — Hinweisgeberschutzgesetz (HinSchG), in force since July 2023&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;France&amp;lt;/strong&amp;gt; — Loi Sapin II (updated 2022), with broader scope than the Directive&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Sweden&amp;lt;/strong&amp;gt; — Visselblåsarlagen, in force since December 2021&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Denmark&amp;lt;/strong&amp;gt; — Lov om beskyttelse af whistleblowere, in force since December 2021&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Netherlands&amp;lt;/strong&amp;gt; — Wet bescherming klokkenluiders, updated February 2023&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Poland&amp;lt;/strong&amp;gt; — Ustawa o ochronie sygnalistów, in force since September 2024&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h2 id=&amp;#34;choosing-a-reporting-channel-solution&amp;#34;&amp;gt;Choosing a reporting channel solution&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;When selecting a digital reporting platform to meet the Directive&amp;amp;rsquo;s requirements, organisations should evaluate:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Compliance coverage&amp;lt;/strong&amp;gt; — Does the platform support all jurisdictions where you operate?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymous reporting&amp;lt;/strong&amp;gt; — Can reporters submit reports without identifying themselves?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Two-way communication&amp;lt;/strong&amp;gt; — Can the designated person communicate with the reporter while maintaining anonymity?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deadline tracking&amp;lt;/strong&amp;gt; — Does the platform enforce the 7-day and 3-month response deadlines?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data hosting&amp;lt;/strong&amp;gt; — Is data processed and stored within the EU, in compliance with GDPR?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Audit trail&amp;lt;/strong&amp;gt; — Does the platform maintain a complete record of all actions for compliance documentation?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deployment speed&amp;lt;/strong&amp;gt; — How quickly can the channel be operational?&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;div class=&amp;#34;card bg-base-200 border-2 border-primary mt-10 not-prose&amp;#34;&amp;gt;
&amp;lt;div class=&amp;#34;card-body&amp;#34;&amp;gt;
&amp;lt;h3 class=&amp;#34;card-title text-primary&amp;#34;&amp;gt;Compare reporting platforms&amp;lt;/h3&amp;gt;
&amp;lt;p class=&amp;#34;text-sm opacity-70&amp;#34;&amp;gt;
We maintain an independent directory of whistleblower reporting tools evaluated
against EU Directive 2019/1937 requirements.
&amp;lt;/p&amp;gt;
&amp;lt;div class=&amp;#34;card-actions&amp;#34;&amp;gt;
&amp;lt;a href=&amp;#34;/compare/&amp;#34; class=&amp;#34;btn btn-primary btn-sm&amp;#34;&amp;gt;View platform comparison →&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;/tools/&amp;#34; class=&amp;#34;btn btn-outline btn-primary btn-sm&amp;#34;&amp;gt;Browse all platforms →&amp;lt;/a&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;</content:encoded></item></channel></rss>