Ashio whistleblowing software
🇪🇺 EU Whistleblowing Directive (EU) 2019/1937

EU Whistleblowing Directive 2019/1937 — Compliance Guide

Understand your obligations under the EU Whistleblowing Directive and how to comply with secure, confidential reporting channels.

Overview

What is the EU Whistleblowing Directive?

Adopted on 23 October 2019 and entered into force on 16 December 2019, the Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law is the first EU-wide legislation dedicated to whistleblower protection. It establishes common minimum standards ensuring that whistleblowers across all Member States enjoy the same level of protection when reporting breaches of EU law in areas such as public procurement, financial services, product safety, environmental protection, public health, and data protection.

Three-tier system

Three-tier reporting system

Internal reporting

Organisations must establish internal channels where employees can report breaches confidentially.

External reporting

Member States must designate competent authorities to receive and handle external reports.

Public disclosure

Under certain conditions, whistleblowers may make information publicly available.

Scope

Who must comply?

The directive applies to all legal entities in the EU with 50 or more employees. This includes private companies, public sector organisations, and local municipalities. Some sectors (such as financial services) must comply regardless of employee count.

Key obligations

Key requirements

Internal reporting channels

Organisations with 50+ employees must establish secure, confidential internal reporting channels for whistleblowers to report breaches of EU law.

Acknowledgment within 7 days

Reports must be acknowledged to the whistleblower within 7 days of receipt — no exceptions. Automated acknowledgment ensures compliance.

Follow-up within 3 months

Organisations must provide feedback to the whistleblower on the follow-up to their report within three months of acknowledgment.

Protection against retaliation

Whistleblowers are protected from dismissal, demotion, and other forms of retaliation. The burden of proof lies with the employer in retaliation cases.

Data confidentiality and GDPR compliance

Personal data must be processed in accordance with GDPR. The identity of the whistleblower must be kept confidential throughout the process.

Record keeping

Organisations must maintain comprehensive records of all reports received and actions taken, with strict access controls.

Deadlines

Timeline for compliance

Member states were required to transpose the directive into national law by 17 December 2021. Organisations with 50–249 employees had until 17 December 2023 to establish internal reporting channels.

🇪🇺 Built for compliance

How Ashio helps you comply

Ashio is purpose-built to help organisations meet every obligation under the EU Whistleblowing Directive — out of the box.

Secure, confidential intake

Anonymous and confidential reporting workflows that meet the directive's requirements for secure internal channels.

7-day acknowledgment tracking

Clear acknowledgment workflows help ensure every report receives a response within the mandated timeframe.

Audit-ready logging

Complete activity logs and case timelines provide the comprehensive records required by the directive.

🇨🇭 Swiss hostingGDPR compliantEU Directive 2019/1937 aligned

FAQ

Frequently asked questions

Do all companies need to comply?+

Legal entities with 50+ employees in the EU must comply. Some sectors (financial services, aviation, maritime) must comply regardless of size. Companies with fewer than 50 employees are exempt unless they operate in a regulated sector.

What deadlines apply?+

The transposition deadline for Member States was 17 December 2021. Large organisations (250+ employees) had to comply by then. Small and medium organisations (50–249 employees) had until 17 December 2023.

What are the penalties?+

Penalties vary by Member State but can include significant fines, regulatory action, reputational damage, and criminal liability for retaliating against whistleblowers.

Is anonymous reporting required?+

The directive mandates confidential reporting, not anonymous. However, it encourages accepting anonymous reports. Ashio supports both.

Ready to meet your obligations?

Set up secure, compliant reporting channels in minutes with Ashio.