Internal reporting
Organisations must establish internal channels where employees can report breaches confidentially.

Understand your obligations under the EU Whistleblowing Directive and how to comply with secure, confidential reporting channels.
Overview
Adopted on 23 October 2019 and entered into force on 16 December 2019, the Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law is the first EU-wide legislation dedicated to whistleblower protection. It establishes common minimum standards ensuring that whistleblowers across all Member States enjoy the same level of protection when reporting breaches of EU law in areas such as public procurement, financial services, product safety, environmental protection, public health, and data protection.
Three-tier system
Organisations must establish internal channels where employees can report breaches confidentially.
Member States must designate competent authorities to receive and handle external reports.
Under certain conditions, whistleblowers may make information publicly available.
Scope
The directive applies to all legal entities in the EU with 50 or more employees. This includes private companies, public sector organisations, and local municipalities. Some sectors (such as financial services) must comply regardless of employee count.
Key obligations
Organisations with 50+ employees must establish secure, confidential internal reporting channels for whistleblowers to report breaches of EU law.
Reports must be acknowledged to the whistleblower within 7 days of receipt — no exceptions. Automated acknowledgment ensures compliance.
Organisations must provide feedback to the whistleblower on the follow-up to their report within three months of acknowledgment.
Whistleblowers are protected from dismissal, demotion, and other forms of retaliation. The burden of proof lies with the employer in retaliation cases.
Personal data must be processed in accordance with GDPR. The identity of the whistleblower must be kept confidential throughout the process.
Organisations must maintain comprehensive records of all reports received and actions taken, with strict access controls.
Deadlines
Member states were required to transpose the directive into national law by 17 December 2021. Organisations with 50–249 employees had until 17 December 2023 to establish internal reporting channels.
🇪🇺 Built for compliance
Ashio is purpose-built to help organisations meet every obligation under the EU Whistleblowing Directive — out of the box.
Anonymous and confidential reporting workflows that meet the directive's requirements for secure internal channels.
Clear acknowledgment workflows help ensure every report receives a response within the mandated timeframe.
Complete activity logs and case timelines provide the comprehensive records required by the directive.
FAQ
Legal entities with 50+ employees in the EU must comply. Some sectors (financial services, aviation, maritime) must comply regardless of size. Companies with fewer than 50 employees are exempt unless they operate in a regulated sector.
The transposition deadline for Member States was 17 December 2021. Large organisations (250+ employees) had to comply by then. Small and medium organisations (50–249 employees) had until 17 December 2023.
Penalties vary by Member State but can include significant fines, regulatory action, reputational damage, and criminal liability for retaliating against whistleblowers.
The directive mandates confidential reporting, not anonymous. However, it encourages accepting anonymous reports. Ashio supports both.
Set up secure, compliant reporting channels in minutes with Ashio.