Start/Blog/The new Whistleblower Directive – what companies should do now
Whistleblowing

The new Whistleblower Directive – what companies should do now

With the new EU Whistleblower Directive, Brussels aims to regulate and harmonize whistleblowing across the EU for the first time. Its stated objective is better protection for whistleblowers. Anyone who reports breaches of Union law or unethical conduct in or by a company should not have to fear sanctions. To achieve this, companies must create appropriate structures and preserve whistleblowers’ anonymity. We explain what this means for companies and how they can overcome the challenges.

24. Februar 2022 · Patrick Agostini · 7 min read

The new Whistleblower Directive – what companies should do now

Key points at a glance

  • The EU Whistleblower Directive protects people who report and expose legal violations by or within companies.
  • Companies must establish suitable reporting channels and take measures to protect whistleblowers against sanctions and retaliation.
  • The EU Directive applies to all companies and public bodies with more than 49 employees.
  • The Directive officially entered into force at the end of 2021. Germany has not yet transposed it into national law.
  • The EU has therefore initiated infringement proceedings against Germany.
  • A German Whistleblower Protection Act is expected to enter into force shortly.

What is the EU Whistleblower Directive, and when does it apply?

Unlike EU regulations, EU directives do not have direct legal effect. To become effective, they must first be transposed into national law by EU Member States. EU directives generally set a binding deadline for implementing these legal acts. Within this period, all Member States must incorporate the directives’ requirements into their national legislation. This also applies to Whistleblower Directive (EU) 2019/1937.

The European Parliament and European Council enacted the Whistleblower Directive (WB Directive) on 23 October 2019. The deadline for transposition expired on 17 December 2021. Germany and several other countries have so far failed to pass corresponding legislation. In January 2022, the European Commission consequently called for implementation and initiated infringement proceedings.

A draft national Whistleblower Protection Act (HinSchG) is available and is expected to enter into force soon. Until then, courts will refer to the EU Directive in disputes, meaning its requirements effectively already apply. Companies that have not yet established a suitable whistleblowing system should therefore act urgently.

What is the new Whistleblower Directive intended to achieve?

With the EU directive protecting whistleblowers, European lawmakers acknowledge both the vital role whistleblowers play in maintaining a fair and transparent society and the fact that whistleblowers in companies often face retaliation for their actions. This is explicitly stated in the very first recital of the introduction to the EU Whistleblower Directive.

EU Whistleblower Directive, introduction, recital 1

“Persons who work for a public or private organization or are in contact with such an organization in the context of their work-related activities are often the first to become aware of threats or harm to the public interest arising in that context. By reporting breaches of Union law that are harmful to the public interest, such persons act as whistleblowers and thereby play a key role in exposing and preventing such breaches. However, potential whistleblowers are often discouraged from reporting their concerns or suspicions for fear of retaliation. In this context, the importance of providing balanced and effective whistleblower protection is increasingly acknowledged at both Union and international level.”

The new Directive aims to effectively protect whistleblowers against retaliation throughout Europe. Those who have the courage to expose misconduct in companies should not have to fear demotion, bullying or even dismissal. Under the EU Directive, whistleblowers may no longer be held liable under civil, criminal or administrative law for disclosing legal violations and misconduct. The new rules are intended to help uncover more breaches of applicable EU law. To make this possible, companies are required to establish secure and confidential reporting systems.

What requirements does the new Whistleblower Directive impose on companies?

The new Whistleblower Directive requires companies to establish a suitable internal reporting channel. To achieve the primary protection objective, the following requirements must be met:

  • The system must preserve the confidentiality of the whistleblower’s identity.
  • The reporting channel must be protected and secure.
  • Personal data must be processed in compliance with the GDPR.
  • The prescribed processing and response deadlines for whistleblowers must be observed (receipt must be acknowledged within seven days at the latest).
  • Companies must inform all stakeholders about reporting options and the reporting process. The information must be easily accessible and understandable.

Why does the Directive also provide for external reporting channels, and what does this mean for companies?

Because companies, organizations or public institutions may fail to meet—or adequately meet—the requirements for establishing internal reporting channels, the EU Directive also provides for external reporting channels. Member States must establish these channels and equip them with appropriate resources. External reporting channels could, for example, be located with public prosecutors or the police.

Good to know: in Article 7(2), the EU Whistleblower Directive explicitly gives internal reporting channels priority over external channels, provided that “the breach can be addressed effectively internally and the reporting person considers that there is no risk of retaliation.” It is therefore in companies’ interests to install a reporting system that functions as effectively as possible in line with lawmakers’ intentions. Otherwise, they risk violations being immediately disclosed externally and investigated by official bodies, with correspondingly high risks to their reputation and corporate image.

Which companies must comply with the EU Whistleblower Directive?

The new EU Directive has applied to companies with 250 or more employees since 17 December 2021—in principle, as the German Bundestag has not yet passed and enacted the already drafted Whistleblower Protection Act. There are therefore currently neither government inspections nor sanctions against companies that have not established reporting channels or implemented the required whistleblower protection measures. If necessary, however, whistleblowers could already assert their rights in court.

The EU Whistleblower Directive grants a longer transition period to companies with more than 50 and fewer than 250 employees. These businesses have until 17 December 2023 to introduce reporting channels and whistleblowing measures. The Directive also applies to financial service providers of every size, public-sector institutions and municipalities with more than 10,000 residents.

Which violations should be reported?

The EU Whistleblower Directive primarily focuses on EU law, particularly violations in the following areas and of the following rules:

  • Public procurement
  • Financial services and insurance
  • Money laundering and terrorist financing
  • Consumer protection and product safety
  • Data protection
  • Environmental protection
  • Competition and state aid law

Member States are nevertheless free to go beyond EU law in their national legislation and include breaches of national law. The German Whistleblower Protection Act (HinSchG), which has not yet been passed, provides general protection for whistleblowers who report serious misconduct whose disclosure is of particular public interest.

How can the requirements be implemented, and which internal reporting channels meet the EU Directive’s requirements?

There is no single correct answer to this question. Many approaches can lead to success, and it is both possible and permissible to establish several reporting channels in parallel. Ultimately, the important thing is that the identity of the whistleblower and any third parties named remains confidential. This requires a central, independent contact person to process reports—for example, the external data protection officer. The system should also be available around the clock, protected against unauthorized access and enable dialogue—in multiple languages, depending on the company structure.

Reporting channels such as a traditional mailbox or an email inbox are possible in principle, but on closer examination are not very suitable. Take a whistleblower mailbox: anyone posting something could be observed, the report reaches its recipient with a delay, and there is no opportunity for dialogue. The situation is similar with an email inbox. Here too, reporters’ anonymity is at risk, and secure exchanges of information and documents can only be implemented to a limited extent. External options, such as a third-party call center or an ombudsman as contact person, are relatively expensive alternatives that are not integrated into the company’s own structures.

Nuviax therefore recommends establishing a digital whistleblowing system. Specifically, we work with a partner to install a cloud-based whistleblowing system. The advantages of this solution:

  • Available worldwide 24/7 for receiving and processing reports
  • Secure encryption
  • Two-way communication
  • Saves time and money
  • 100% compliant with the EU Directive

Conclusion: what should companies do now?

There will soon be no way around an internal whistleblowing system. If they have not already done so, companies should address the issue and take action sooner rather than later—in their own interests, too. Reporting systems are a highly effective tool for identifying violations and suspected misconduct within a company at an early stage. This is essential for proactively uncovering violations and retaining control of the response. In short: with a professional whistleblowing system, you strengthen every stakeholder’s trust in your company’s integrity and ability to act.

Weiterlesen

Verwandte Artikel

01
AI Regulation · 01. August 2026 · 7 min read

How to label AI content correctly: A practical guide for websites and social media

Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have applied. Anyone using chatbots, AI images, AI voices or AI-generated text has since been asking: Do I now have to label all of it? The short answer is no. The AI Act does not require companies to label every piece of AI-generated content—the obligations apply to clearly defined situations, not every use of an AI tool. This is precisely where the practical problem arises: some companies label everything out of uncertainty and therefore appear unprofessional. Others label too little and risk a violation. This article explains the four cases governed by Article 50, the applicable exceptions and exactly how to label content on websites and social media.

02
NIS2 · 06. März 2024 · 7 min read

NIS2 from 2026: These obligations are coming for SMEs.

The NIS2 Directive (EU 2022/2555) is the European Union's most far-reaching cybersecurity regulation to date - and it affects significantly more companies than its predecessor. Many SMEs still assume that ‘cybersecurity obligations’ apply only to large corporations or critical infrastructure. That misconception can be costly. As transposition into national law is taking effect gradually in several Member States, 2026 will be the year of practical application for many companies. Those who do not start now will come under time pressure. This article summarises who is affected, which obligations apply and where management bears personal responsibility.

03
AI Regulation · 02. Februar 2026 · 4 min read

ISO 42001 & AI policy template: Your guide through the EU AI Act—pragmatic and efficient

The EU AI Act requires companies to establish systematic governance structures for the legally compliant use of artificial intelligence. But where do you start? How can these complex requirements be implemented in practice without bringing business operations to a standstill? ISO 42001 is the first international standard for AI management systems and translates many abstract AI Act requirements into 38 concrete controls—a field-tested blueprint that helps you: In this article, we show you how to use the structure of ISO 42001 to comply with the AI Act pragmatically—and implement it efficiently with our policy template. This integrated approach not only saves time but also significantly reduces your AI compliance costs.