<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Blog — EthicsPortal</title><link>https://ethicsportal.eu/blog/</link><description>EthicsPortal is a secure, anonymous whistleblower reporting platform that helps organizations comply with EU Directive 2019/1937.</description><language>en</language><lastBuildDate>Thu, 30 Jul 2026 15:26:44 +0000</lastBuildDate><atom:link href="https://ethicsportal.eu/blog/index.xml" rel="self" type="application/rss+xml"/><image><url>https://ethicsportal.eu/images/logo.svg</url><title>EthicsPortal</title><link>https://ethicsportal.eu/</link></image><item><title>Do you need ISO 27001 for a whistleblowing tool?</title><link>https://ethicsportal.eu/blog/do-you-need-iso-27001-whistleblowing-tool/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/do-you-need-iso-27001-whistleblowing-tool/</guid><description>EU Directive 2019/1937 does not require ISO 27001. Here is what the law actually requires of a reporting channel, and how to evaluate security without it.</description><content:encoded>&amp;lt;h1 id=&amp;#34;do-you-need-iso-27001-for-a-whistleblowing-tool&amp;#34;&amp;gt;
Do you need ISO 27001 for a whistleblowing tool?
&amp;lt;a href=&amp;#34;#do-you-need-iso-27001-for-a-whistleblowing-tool&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Short answer: no.&amp;lt;/strong&amp;gt; EU Directive 2019/1937 does not require ISO/IEC 27001, and neither does any national transposition of it. ISO 27001 is a voluntary information-security management standard. It is useful evidence that a vendor takes security seriously, but it is not a legal prerequisite for operating a compliant internal reporting channel.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This matters because several procurement checklists treat &amp;amp;ldquo;ISO 27001 certified&amp;amp;rdquo; as a hard gate. For a whistleblowing channel, that gate filters on the wrong thing. What the Directive actually requires is &amp;lt;strong&amp;gt;confidentiality and security of processing&amp;lt;/strong&amp;gt; &amp;amp;mdash; and those can be met, and verified, independently of any certificate.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;what-does-the-directive-actually-require&amp;#34;&amp;gt;
What does the Directive actually require?
&amp;lt;a href=&amp;#34;#what-does-the-directive-actually-require&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive&amp;amp;rsquo;s security obligations are specific and functional:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality of the reporter&amp;amp;rsquo;s identity&amp;lt;/strong&amp;gt; (Article 16). The identity of the reporting person must not be disclosed to anyone beyond authorized staff, without consent.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Secure channels&amp;lt;/strong&amp;gt; (Article 9). Internal reporting channels must be designed, established, and operated in a secure manner that protects the confidentiality of the reporter and any third party mentioned.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Security of processing&amp;lt;/strong&amp;gt; under the GDPR (Article 32). Because reports contain personal data, the channel inherits the GDPR&amp;amp;rsquo;s requirement for technical and organizational measures appropriate to the risk &amp;amp;mdash; encryption, access control, confidentiality, integrity, and resilience.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;None of these name a certification. They describe outcomes. A tool either protects reporter identity and secures the data, or it does not.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;what-is-iso-27001-and-when-does-it-help&amp;#34;&amp;gt;
What is ISO 27001, and when does it help?
&amp;lt;a href=&amp;#34;#what-is-iso-27001-and-when-does-it-help&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;ISO 27001 certifies that an organization runs an information-security management system (ISMS) against a defined set of controls, audited by an accredited body. It is genuinely meaningful &amp;amp;mdash; but two distinctions decide whether a given certificate is relevant to you:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scope.&amp;lt;/strong&amp;gt; A certificate covers a defined boundary. A vendor whose &amp;lt;em&amp;gt;hosting infrastructure&amp;lt;/em&amp;gt; is ISO 27001 certified is not the same as a vendor whose &amp;lt;em&amp;gt;application and operations&amp;lt;/em&amp;gt; are certified. Always read the scope statement.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Certified vs aligned.&amp;lt;/strong&amp;gt; &amp;amp;ldquo;Certified&amp;amp;rdquo; means an accredited body audited and issued the certificate. &amp;amp;ldquo;Aligned with&amp;amp;rdquo; or &amp;amp;ldquo;built to&amp;amp;rdquo; means the vendor self-assesses against the controls. Both can be reasonable; they are not the same claim.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;ISO 27001 is most worth insisting on when you are a large or heavily regulated organization whose own ISMS requires certified suppliers, or when your risk assessment specifically calls for it. For most SMEs meeting a Directive obligation, it is a useful signal &amp;amp;mdash; not a legal requirement.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;how-to-evaluate-whistleblowing-tool-security-without-relying-on-a-certificate&amp;#34;&amp;gt;
How to evaluate whistleblowing-tool security without relying on a certificate
&amp;lt;a href=&amp;#34;#how-to-evaluate-whistleblowing-tool-security-without-relying-on-a-certificate&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ask for evidence of the outcomes the Directive and GDPR require:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Where is the data hosted?&amp;lt;/strong&amp;gt; A named EU data center keeps processing inside the EU and avoids third-country transfer questions under GDPR Chapter V.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is report content encrypted?&amp;lt;/strong&amp;gt; Encryption in transit (TLS) is table stakes; ask whether sensitive fields are also encrypted at rest.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Can reporters stay anonymous?&amp;lt;/strong&amp;gt; Check that no reporter account or identifying field is mandatory, and that follow-up works without revealing identity.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Are reporter IP addresses stored?&amp;lt;/strong&amp;gt; They should not be. Ask how the tool prevents re-identification via metadata and uploaded files.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is there a tamper-resistant audit trail?&amp;lt;/strong&amp;gt; An append-only log of who accessed what, when, is both a security control and an accountability record.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is there a Data Processing Agreement, and who are the sub-processors?&amp;lt;/strong&amp;gt; A published DPA and sub-processor list let you verify the data chain &amp;amp;mdash; including whether any AI provider is in it.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;A vendor that answers these clearly gives you more assurance than a certificate logo with an unread scope statement.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-approaches-this&amp;#34;&amp;gt;
How EthicsPortal approaches this
&amp;lt;a href=&amp;#34;#how-ethicsportal-approaches-this&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is direct about its certification posture. The hosting infrastructure (Hetzner, Nuremberg, Germany) holds ISO/IEC 27001 certification; &amp;lt;strong&amp;gt;the EthicsPortal application is not separately ISO 27001 certified&amp;lt;/strong&amp;gt;, and we say so rather than implying otherwise. Our &amp;lt;a href=&amp;#34;/iso-27001/&amp;#34;&amp;gt;ISO/IEC 27001:2022 Annex A control map&amp;lt;/a&amp;gt;
is a published, control-by-control self-assessment against the same 93 controls an external auditor would evaluate.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;What the platform does provide against the Directive&amp;amp;rsquo;s actual requirements: EU hosting, encryption of sensitive fields at rest plus TLS in transit, fully anonymous reporting with no required reporter account, no storage of reporter IP addresses, automatic stripping of metadata from uploads, an append-only audit log, and a published Data Processing Agreement and sub-processor list. Report content is never sent to any AI or LLM provider.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If your organization&amp;amp;rsquo;s policy genuinely requires a certified application, a vendor with an in-scope application certificate is the right call. If your requirement is a secure, confidential, Directive-compliant channel, evaluate the outcomes above &amp;amp;mdash; and treat ISO 27001 as a signal, not a substitute for them.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;Need a compliant reporting channel? &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is €41.67/month billed annually with no per-employee pricing, EU-hosted, and anonymous by default. &amp;lt;a href=&amp;#34;/pricing/&amp;#34;&amp;gt;Deploy your reporting channel&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>EU Whistleblower Directive: statistics and enforcement data (2026)</title><link>https://ethicsportal.eu/blog/eu-whistleblower-directive-statistics/</link><pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/eu-whistleblower-directive-statistics/</guid><description>A sourced reference of statistics on EU Directive 2019/1937 — how many organizations it covers, the €38.9 million in fines the Court of Justice has already issued, transposition status across all 27 member states, and the evidence on why internal reporting channels reduce fraud and litigation risk.</description><content:encoded>&amp;lt;h1 id=&amp;#34;eu-whistleblower-directive-statistics-and-enforcement-data-2026&amp;#34;&amp;gt;
EU Whistleblower Directive: statistics and enforcement data (2026)
&amp;lt;a href=&amp;#34;#eu-whistleblower-directive-statistics-and-enforcement-data-2026&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;A reference page of checked statistics on EU Directive 2019/1937 — the EU Whistleblower Directive. Every number below links to its original source: the Court of Justice of the EU, the European Commission, Eurostat, the ACFE&amp;amp;rsquo;s annual fraud report, and peer-reviewed academic research. Each figure has a date, so you can see how recent it is.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you are a journalist, analyst, or compliance officer who needs a number you can quote, this page is built for that. See &amp;lt;a href=&amp;#34;#methodology-and-sources&amp;#34;&amp;gt;Methodology and sources&amp;lt;/a&amp;gt;
at the end for how it is put together and kept up to date.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;key-statistics-at-a-glance&amp;#34;&amp;gt;
Key statistics at a glance
&amp;lt;a href=&amp;#34;#key-statistics-at-a-glance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;~306,000&amp;lt;/strong&amp;gt; organizations in the EU meet the Directive&amp;amp;rsquo;s 50-employee threshold — 55,000 large enterprises (250+) plus roughly 251,000 medium ones (50–249). &amp;lt;a href=&amp;#34;https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20251209-2&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Eurostat, 2024&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;€38.9 million&amp;lt;/strong&amp;gt; in fines was ordered by the Court of Justice of the EU on 6 March 2025 against five member states for being late to put the Directive into national law. &amp;lt;a href=&amp;#34;https://curia.europa.eu/site/upload/docs/application/pdf/2025-03/cp250029en.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;CJEU, March 2025&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;3 of 27&amp;lt;/strong&amp;gt; member states had fully put the Directive into national law by the first deadline of 17 December 2021. &amp;lt;a href=&amp;#34;https://eucrim.eu/news/ecj-ordered-several-member-states-to-financial-penalties-for-failing-to-transpose-whistleblowers-directive/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;eucrim&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;43%&amp;lt;/strong&amp;gt; of occupational frauds are first detected by a tip — more than three times any other detection method. &amp;lt;a href=&amp;#34;https://legacy.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE, 2024&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;52%&amp;lt;/strong&amp;gt; of fraud tips come from employees — the people an internal reporting channel exists to reach. &amp;lt;a href=&amp;#34;https://legacy.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE, 2024&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;€1,000,000&amp;lt;/strong&amp;gt; is the highest fine for not running a reporting channel. It is in Spain, which has the strictest rules in the EU. &amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;€5.8–9.6 billion&amp;lt;/strong&amp;gt; a year is the European Commission&amp;amp;rsquo;s estimate of what the EU loses in public procurement &amp;lt;em&amp;gt;alone&amp;lt;/em&amp;gt; for the lack of whistleblower protection. &amp;lt;a href=&amp;#34;https://op.europa.eu/en/publication-detail/-/publication/8d5955bd-9378-11e7-b92d-01aa75ed71a1/language-en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;European Commission, 2017&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-scale-of-the-obligation&amp;#34;&amp;gt;
The scale of the obligation
&amp;lt;a href=&amp;#34;#the-scale-of-the-obligation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive requires every organization with &amp;lt;strong&amp;gt;50 or more employees&amp;lt;/strong&amp;gt; operating in the EU to run an internal reporting channel, plus all financial-services firms and many public bodies regardless of size (&amp;lt;a href=&amp;#34;/blog/who-must-comply-eu-whistleblower-directive/&amp;#34;&amp;gt;who must comply&amp;lt;/a&amp;gt;
).&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Organization size&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Count in the EU&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Employment&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Large (250+ employees)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;55,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;59.7 million&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Medium (50–249 employees)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;251,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;24.9 million&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Covered by the 50+ threshold&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;~306,000&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;~84.6 million&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;Source: &amp;lt;a href=&amp;#34;https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20251209-2&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Eurostat structural business statistics, 2024 reference year&amp;lt;/a&amp;gt;
(published December 2025). The ~306,000 figure counts private businesses only. It leaves out most public-sector bodies and financial firms, which must comply no matter how many employees they have — so the real number of organizations that must comply is higher.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-the-law-was-adopted-a-timeline&amp;#34;&amp;gt;
How the law was adopted: a timeline
&amp;lt;a href=&amp;#34;#how-the-law-was-adopted-a-timeline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;To &amp;amp;ldquo;transpose&amp;amp;rdquo; a directive means to turn the EU law into a country&amp;amp;rsquo;s own national law. Every member state had to do this for the Whistleblower Directive.&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;div style=&amp;#34;margin:2rem 0;&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;display:flex;gap:1rem;align-items:stretch;&amp;#34;&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;align-items:center;flex:none;width:1rem;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:0.875rem;height:0.875rem;border-radius:9999px;margin-top:0.3rem;flex:none;background:var(--color-primary);box-shadow:0 0 0 3px var(--color-base-100);&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;width:2px;flex:1 1 auto;background:var(--color-base-300);margin-top:0.25rem;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div style=&amp;#34;padding-bottom:1.75rem;&amp;#34;&amp;gt;
&amp;lt;time style=&amp;#34;display:block;font-size:0.875rem;font-weight:600;color:var(--color-primary);&amp;#34;&amp;gt;23 October 2019&amp;lt;/time&amp;gt;
&amp;lt;div style=&amp;#34;margin-top:0.25rem;color:var(--color-base-content);opacity:0.85;line-height:1.5;&amp;#34;&amp;gt;Directive (EU) 2019/1937 adopted. &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EUR-Lex&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;gap:1rem;align-items:stretch;&amp;#34;&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;align-items:center;flex:none;width:1rem;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:0.875rem;height:0.875rem;border-radius:9999px;margin-top:0.3rem;flex:none;background:var(--color-primary);box-shadow:0 0 0 3px var(--color-base-100);&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;width:2px;flex:1 1 auto;background:var(--color-base-300);margin-top:0.25rem;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div style=&amp;#34;padding-bottom:1.75rem;&amp;#34;&amp;gt;
&amp;lt;time style=&amp;#34;display:block;font-size:0.875rem;font-weight:600;color:var(--color-primary);&amp;#34;&amp;gt;17 December 2021&amp;lt;/time&amp;gt;
&amp;lt;div style=&amp;#34;margin-top:0.25rem;color:var(--color-base-content);opacity:0.85;line-height:1.5;&amp;#34;&amp;gt;First deadline, for organizations with 250+ employees. Only &amp;lt;strong&amp;gt;3 of 27&amp;lt;/strong&amp;gt; member states had fully put it into national law. &amp;lt;a href=&amp;#34;https://eucrim.eu/news/ecj-ordered-several-member-states-to-financial-penalties-for-failing-to-transpose-whistleblowers-directive/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;eucrim&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;gap:1rem;align-items:stretch;&amp;#34;&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;align-items:center;flex:none;width:1rem;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:0.875rem;height:0.875rem;border-radius:9999px;margin-top:0.3rem;flex:none;background:var(--color-primary);box-shadow:0 0 0 3px var(--color-base-100);&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;width:2px;flex:1 1 auto;background:var(--color-base-300);margin-top:0.25rem;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div style=&amp;#34;padding-bottom:1.75rem;&amp;#34;&amp;gt;
&amp;lt;time style=&amp;#34;display:block;font-size:0.875rem;font-weight:600;color:var(--color-primary);&amp;#34;&amp;gt;17 December 2023&amp;lt;/time&amp;gt;
&amp;lt;div style=&amp;#34;margin-top:0.25rem;color:var(--color-base-content);opacity:0.85;line-height:1.5;&amp;#34;&amp;gt;Extended deadline, for organizations with 50–249 employees (&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Art. 26(2)&amp;lt;/a&amp;gt;
).&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;gap:1rem;align-items:stretch;&amp;#34;&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;align-items:center;flex:none;width:1rem;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:0.875rem;height:0.875rem;border-radius:9999px;margin-top:0.3rem;flex:none;background:var(--color-primary);box-shadow:0 0 0 3px var(--color-base-100);&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;width:2px;flex:1 1 auto;background:var(--color-base-300);margin-top:0.25rem;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div style=&amp;#34;padding-bottom:1.75rem;&amp;#34;&amp;gt;
&amp;lt;time style=&amp;#34;display:block;font-size:0.875rem;font-weight:600;color:var(--color-primary);&amp;#34;&amp;gt;3 July 2024&amp;lt;/time&amp;gt;
&amp;lt;div style=&amp;#34;margin-top:0.25rem;color:var(--color-base-content);opacity:0.85;line-height:1.5;&amp;#34;&amp;gt;The European Commission&amp;amp;rsquo;s review finds gaps in protection, reporting channels, and safeguards against retaliation. &amp;lt;a href=&amp;#34;https://commission.europa.eu/document/download/7cc63350-88c9-4c0b-a46e-04fc11e673e7_en?filename=COM_2024_269_1_EN_ACT_part1_v6.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;COM(2024) 269&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;gap:1rem;align-items:stretch;&amp;#34;&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;align-items:center;flex:none;width:1rem;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:0.875rem;height:0.875rem;border-radius:9999px;margin-top:0.3rem;flex:none;background:var(--color-accent);box-shadow:0 0 0 3px var(--color-base-100);&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;div style=&amp;#34;padding-bottom:0;&amp;#34;&amp;gt;
&amp;lt;time style=&amp;#34;display:block;font-size:0.875rem;font-weight:600;color:var(--color-base-content);&amp;#34;&amp;gt;6 March 2025&amp;lt;/time&amp;gt;
&amp;lt;div style=&amp;#34;margin-top:0.25rem;color:var(--color-base-content);opacity:0.85;line-height:1.5;&amp;#34;&amp;gt;The Court of Justice fines five member states &amp;lt;strong&amp;gt;€38.9 million&amp;lt;/strong&amp;gt; for being late. &amp;lt;a href=&amp;#34;https://curia.europa.eu/site/upload/docs/application/pdf/2025-03/cp250029en.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;CJEU&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;p&amp;gt;By mid-2024 all 27 member states had adopted transposing laws — Estonia and Poland were the last, in May 2024. &amp;lt;a href=&amp;#34;https://commission.europa.eu/topics/human-rights/your-fundamental-rights-eu/protection-whistleblowers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;European Commission&amp;lt;/a&amp;gt;
&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;389-million-in-fines-for-being-late&amp;#34;&amp;gt;
€38.9 million in fines for being late
&amp;lt;a href=&amp;#34;#389-million-in-fines-for-being-late&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Each EU country had to turn the Directive into its own national law by a set deadline. Some countries were late. On &amp;lt;strong&amp;gt;6 March 2025&amp;lt;/strong&amp;gt;, the Court of Justice of the EU made five of them pay fines for the delay (cases C-149/23, C-150/23, C-152/23, C-154/23 and C-155/23):&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Member state&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Lump-sum penalty&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Notes&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Germany&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€34,000,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;The largest penalty&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Czech Republic&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€2,300,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Hungary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€1,750,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Estonia&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€500,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Plus &amp;lt;strong&amp;gt;€1,500 per day&amp;lt;/strong&amp;gt; until it transposes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Luxembourg&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€375,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Total&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;€38,925,000&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;Source: &amp;lt;a href=&amp;#34;https://curia.europa.eu/site/upload/docs/application/pdf/2025-03/cp250029en.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Court of Justice of the EU, press release 29/25&amp;lt;/a&amp;gt;
and &amp;lt;a href=&amp;#34;https://eucrim.eu/news/ecj-ordered-several-member-states-to-financial-penalties-for-failing-to-transpose-whistleblowers-directive/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;eucrim&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;
&amp;lt;figure style=&amp;#34;margin:2rem 0;border:1px solid var(--color-base-300);border-radius:0.5rem;background:var(--color-base-100);padding:1.25rem 1.25rem 1rem;&amp;#34;&amp;gt;
&amp;lt;figcaption style=&amp;#34;margin-bottom:1rem;font-size:0.875rem;font-weight:600;color:var(--color-base-content);&amp;#34;&amp;gt;CJEU transposition fines, March 2025 &amp;lt;span style=&amp;#34;font-weight:400;opacity:0.55;&amp;#34;&amp;gt;(million €)&amp;lt;/span&amp;gt;&amp;lt;/figcaption&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;gap:0.6rem;&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Germany&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Germany: €34M&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-accent);width:100.0%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;€34M&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Czech Republic&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Czech Republic: €2.3M&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:6.8%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;€2.3M&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Hungary&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Hungary: €1.75M&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:5.1%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;€1.75M&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Estonia&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Estonia: €500k&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:2.0%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;€500k&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Luxembourg&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Luxembourg: €375k&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:2.0%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;€375k&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;p style=&amp;#34;margin:1rem 0 0;font-size:0.72rem;opacity:0.55;&amp;#34;&amp;gt;Source: Court of Justice of the EU, press release 29/25&amp;lt;/p&amp;gt;
&amp;lt;/figure&amp;gt;
&amp;lt;p&amp;gt;Germany&amp;amp;rsquo;s fine is so much larger than the others that the rest are barely visible on the same scale — which is the point.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;These fines were paid by countries, not by companies. Companies face their own fines under each country&amp;amp;rsquo;s national law — and those can be high too.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;company-penalties-highest-national-maximums&amp;#34;&amp;gt;
Company penalties: highest national maximums
&amp;lt;a href=&amp;#34;#company-penalties-highest-national-maximums&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Country&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Maximum fine for no reporting channel&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Law&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spain&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€1,000,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Germany&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;up to €500,000 (legal entities)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/hinschg/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Poland&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;~€250,000 (obstruction)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240000928&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Portugal&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€125,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://diariodarepublica.pt/dr/detalhe/lei/93-2021-175659849&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 93/2021&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Italy&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€50,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;D.Lgs. 24/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;France and Poland attach &amp;lt;strong&amp;gt;criminal liability&amp;lt;/strong&amp;gt;, including prison time, for retaliating against or obstructing a whistleblower. See the full &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties by country&amp;lt;/a&amp;gt;
page for all 27 member states.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;a-working-internal-channel-lowers-litigation-risk&amp;#34;&amp;gt;
A working internal channel lowers litigation risk
&amp;lt;a href=&amp;#34;#a-working-internal-channel-lowers-litigation-risk&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The largest academic study of internal reporting — Stubben and Welch&amp;amp;rsquo;s analysis of close to &amp;lt;strong&amp;gt;2 million reports&amp;lt;/strong&amp;gt; across more than &amp;lt;strong&amp;gt;1,000 US-listed companies&amp;lt;/strong&amp;gt; — found that the more actively a firm used its internal whistleblowing system, the &amp;lt;strong&amp;gt;fewer material lawsuits&amp;lt;/strong&amp;gt; it faced and the &amp;lt;strong&amp;gt;lower the settlement amounts&amp;lt;/strong&amp;gt; it paid in later years. Heavier users were also more profitable. The mechanism is simple: an internal report surfaces a problem early, while management can still fix it, instead of surfacing later as a lawsuit or a press story. &amp;lt;a href=&amp;#34;https://doi.org/10.1111/1475-679X.12303&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Stubben &amp;amp;amp; Welch, &amp;lt;em&amp;gt;Journal of Accounting Research&amp;lt;/em&amp;gt;, 2020&amp;lt;/a&amp;gt;
&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This is the business case behind the legal obligation: the channel is not only a compliance requirement but a risk-reduction control.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-the-channel-matters-the-fraud-detection-evidence&amp;#34;&amp;gt;
Why the channel matters: the fraud-detection evidence
&amp;lt;a href=&amp;#34;#why-the-channel-matters-the-fraud-detection-evidence&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Association of Certified Fraud Examiners studies occupational fraud worldwide. Its 2024 &amp;lt;em&amp;gt;Report to the Nations&amp;lt;/em&amp;gt; makes the case for reporting channels in numbers:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;43%&amp;lt;/strong&amp;gt; of frauds are first detected by a &amp;lt;strong&amp;gt;tip&amp;lt;/strong&amp;gt; — more than three times any other method. &amp;lt;a href=&amp;#34;https://legacy.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE 2024&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Of those tips, &amp;lt;strong&amp;gt;52% come from employees&amp;lt;/strong&amp;gt;, 21% from customers, and 11% from vendors — all categories the Directive defines as protected reporting persons.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The next-best detection methods trail far behind: internal audit (&amp;lt;strong&amp;gt;14%&amp;lt;/strong&amp;gt;) and management (&amp;lt;strong&amp;gt;13%&amp;lt;/strong&amp;gt;).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;71%&amp;lt;/strong&amp;gt; of victim organizations had an anonymous fraud-reporting hotline in place — yet fraud still ran a median of &amp;lt;strong&amp;gt;~12 months&amp;lt;/strong&amp;gt; before detection.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;figure style=&amp;#34;margin:2rem 0;border:1px solid var(--color-base-300);border-radius:0.5rem;background:var(--color-base-100);padding:1.25rem 1.25rem 1rem;&amp;#34;&amp;gt;
&amp;lt;figcaption style=&amp;#34;margin-bottom:1rem;font-size:0.875rem;font-weight:600;color:var(--color-base-content);&amp;#34;&amp;gt;How occupational fraud is first detected &amp;lt;span style=&amp;#34;font-weight:400;opacity:0.55;&amp;#34;&amp;gt;(% of cases)&amp;lt;/span&amp;gt;&amp;lt;/figcaption&amp;gt;
&amp;lt;div style=&amp;#34;display:flex;flex-direction:column;gap:0.6rem;&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Tip (whistleblower)&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Tip (whistleblower): 43%&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-accent);width:100.0%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;43%&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Internal audit&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Internal audit: 14%&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:32.6%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;14%&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;#34;display:flex;align-items:center;gap:0.75rem;font-size:0.85rem;line-height:1.2;&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;width:8.5rem;flex:none;text-align:right;color:var(--color-base-content);opacity:0.8;&amp;#34;&amp;gt;Management review&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;position:relative;height:1.25rem;flex:1;overflow:hidden;border-radius:0.25rem;background:var(--color-base-200);&amp;#34; role=&amp;#34;img&amp;#34; aria-label=&amp;#34;Management review: 13%&amp;#34;&amp;gt;
&amp;lt;span style=&amp;#34;position:absolute;top:0;bottom:0;left:0;border-radius:0.25rem;background:var(--color-primary);width:30.2%;&amp;#34;&amp;gt;&amp;lt;/span&amp;gt;
&amp;lt;/span&amp;gt;
&amp;lt;span style=&amp;#34;width:3.5rem;flex:none;font-weight:600;color:var(--color-base-content);font-variant-numeric:tabular-nums;&amp;#34;&amp;gt;13%&amp;lt;/span&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&amp;lt;p style=&amp;#34;margin:1rem 0 0;font-size:0.72rem;opacity:0.55;&amp;#34;&amp;gt;Source: ACFE Report to the Nations, 2024&amp;lt;/p&amp;gt;
&amp;lt;/figure&amp;gt;
&amp;lt;p&amp;gt;The data shows the same thing again and again: the best way to catch fraud is to give people a safe way to report it. The Directive makes that a legal requirement.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;methodology-and-sources&amp;#34;&amp;gt;
Methodology and sources
&amp;lt;a href=&amp;#34;#methodology-and-sources&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This page is &amp;lt;strong&amp;gt;proof of work&amp;lt;/strong&amp;gt;. Every number can be traced back to its original, official source — not a second-hand summary.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Sources used, and what each supports:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://curia.europa.eu/site/upload/docs/application/pdf/2025-03/cp250029en.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Court of Justice of the EU, press release 29/25 (6 March 2025)&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — the €38.9 million in transposition fines and the per-country breakdown.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://commission.europa.eu/topics/human-rights/your-fundamental-rights-eu/protection-whistleblowers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;European Commission — Protection of whistleblowers&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://commission.europa.eu/document/download/7cc63350-88c9-4c0b-a46e-04fc11e673e7_en?filename=COM_2024_269_1_EN_ACT_part1_v6.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;COM(2024) 269&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — transposition status and the 2024 implementation review.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EUR-Lex — Directive (EU) 2019/1937&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — the legal text, deadlines, and article references.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20251209-2&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Eurostat&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — enterprise counts and employment by size class (2024 reference year).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://legacy.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE Report to the Nations 2024&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — fraud detection methods and tip sources.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://doi.org/10.1111/1475-679X.12303&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Stubben &amp;amp;amp; Welch, &amp;lt;em&amp;gt;Journal of Accounting Research&amp;lt;/em&amp;gt; (2020)&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — peer-reviewed evidence linking active internal reporting to fewer lawsuits, lower settlements, and higher profitability.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://op.europa.eu/en/publication-detail/-/publication/8d5955bd-9378-11e7-b92d-01aa75ed71a1/language-en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;European Commission — economic benefits of whistleblower protection in public procurement (2017)&amp;lt;/a&amp;gt;
&amp;lt;/strong&amp;gt; — the €5.8–9.6 billion annual EU procurement-loss estimate.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;National laws (linked inline) — company-level penalty figures, cross-checked against our maintained &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties by country&amp;lt;/a&amp;gt;
page.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How to read the figures.&amp;lt;/strong&amp;gt; EU institutional and Eurostat numbers are authoritative for the EU. The ACFE fraud figures and the Stubben &amp;amp;amp; Welch study are global and US datasets, flagged as such. Currency conversions are approximate and noted with &amp;lt;code&amp;gt;~&amp;lt;/code&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Last reviewed:&amp;lt;/strong&amp;gt; 14 June 2026. Spotted a figure that has moved? &amp;lt;a href=&amp;#34;/contact/&amp;#34;&amp;gt;Tell us&amp;lt;/a&amp;gt;
— corrections are welcome and we update the source links when laws or reports change.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;EthicsPortal is EU whistleblower compliance infrastructure: secure intake, deadline tracking under Article 9, confidentiality controls under Article 16, and audit-ready records under Article 18. See the &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
for an article-by-article breakdown, or &amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;set up your portal&amp;lt;/a&amp;gt;
.&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Whistleblowing report or grievance? How to tell the difference</title><link>https://ethicsportal.eu/blog/whistleblowing-vs-grievance/</link><pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblowing-vs-grievance/</guid><description>A whistleblowing concern and an HR grievance follow different legal routes under EU Directive 2019/1937. This guide explains how a case handler tells them apart, the grey areas that trip people up, and why misclassifying a report is a compliance risk.</description><content:encoded>&amp;lt;h1 id=&amp;#34;whistleblowing-report-or-grievance-how-to-tell-the-difference&amp;#34;&amp;gt;
Whistleblowing report or grievance? How to tell the difference
&amp;lt;a href=&amp;#34;#whistleblowing-report-or-grievance-how-to-tell-the-difference&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Most reports that reach an internal channel are easy to categorise. Some are not. An employee says a manager is bullying them — but the bullying is aimed at covering up falsified safety records. A finance clerk complains about their workload — and mentions, in passing, invoices that do not add up.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For the person receiving the report, the first decision is the most consequential one: &amp;lt;strong&amp;gt;is this a whistleblowing concern, or an ordinary grievance?&amp;lt;/strong&amp;gt; The two follow different routes and carry different legal duties. Getting it wrong is not a filing error: under &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU Directive 2019/1937&amp;lt;/a&amp;gt;
, a whistleblowing report triggers obligations a grievance does not — statutory deadlines, strict confidentiality, and protection from retaliation. Fail to recognise the report for what it is, and you fail to meet them.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This guide is written for the designated case handler who has to make that call.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-core-distinction&amp;#34;&amp;gt;
The core distinction
&amp;lt;a href=&amp;#34;#the-core-distinction&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;A &amp;lt;strong&amp;gt;grievance&amp;lt;/strong&amp;gt; is a personal complaint about the reporter&amp;amp;rsquo;s own employment — pay, workload, a manager, a missed promotion. The person wants redress &amp;lt;em&amp;gt;for themselves&amp;lt;/em&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A &amp;lt;strong&amp;gt;whistleblowing concern&amp;lt;/strong&amp;gt; is information about wrongdoing that affects &amp;lt;em&amp;gt;others&amp;lt;/em&amp;gt; — fraud, safety risks, environmental breaches, data-protection failures, corruption. The person is acting as a &amp;lt;strong&amp;gt;witness&amp;lt;/strong&amp;gt;, not a claimant. They want the wrongdoing stopped.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Grievance&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Whistleblowing concern&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;A personal concern&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Others or the public interest are affected&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Seeks redress for the individual&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;The reporter is a witness to wrongdoing&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Open, transparent process&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Information-sharing may be limited to protect confidentiality&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Investigation establishes the facts&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;May begin from suspicion alone&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Full feedback to the individual&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Feedback as far as confidentiality allows&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Internal appeal usually available&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;External reporting routes (a regulator) also available&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;The shorthand: &amp;lt;strong&amp;gt;a grievance is &amp;amp;ldquo;this happened to me&amp;amp;rdquo;; a whistleblowing concern is &amp;amp;ldquo;this is happening, and it&amp;amp;rsquo;s wrong.&amp;amp;rdquo;&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-the-classification-matters-legally&amp;#34;&amp;gt;
Why the classification matters legally
&amp;lt;a href=&amp;#34;#why-the-classification-matters-legally&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive attaches a specific set of obligations to a whistleblowing report that do not apply to a grievance:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deadlines.&amp;lt;/strong&amp;gt; You must acknowledge a whistleblowing report within &amp;lt;strong&amp;gt;seven days&amp;lt;/strong&amp;gt; and provide feedback within &amp;lt;strong&amp;gt;three months&amp;lt;/strong&amp;gt; (&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Article 9&amp;lt;/a&amp;gt;
). A grievance follows your ordinary HR timetable.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality.&amp;lt;/strong&amp;gt; The reporter&amp;amp;rsquo;s identity must be kept confidential and may not be disclosed without their consent, except where EU or national law requires it (&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Article 16&amp;lt;/a&amp;gt;
). A standard grievance process is usually open. For how that plays out in practice, see &amp;lt;a href=&amp;#34;/blog/anonymous-vs-confidential-reporting/&amp;#34;&amp;gt;anonymous vs confidential reporting&amp;lt;/a&amp;gt;
.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anti-retaliation.&amp;lt;/strong&amp;gt; A whistleblower is protected against dismissal, demotion, and other detriment (&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Article 19&amp;lt;/a&amp;gt;
); and if they suffer a detriment after reporting, the burden falls on the employer to prove it was not retaliation (&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Article 21(5)&amp;lt;/a&amp;gt;
). Handle the same facts as a routine grievance and those safeguards may never be triggered.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This is why &amp;amp;ldquo;we treated it as an HR matter&amp;amp;rdquo; is not a safe default. If a report contains a genuine public-interest concern, handling it purely as a grievance can itself become the compliance failure. See &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties by country&amp;lt;/a&amp;gt;
for what that exposure looks like across the 27 member states.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-grey-areas&amp;#34;&amp;gt;
The grey areas
&amp;lt;a href=&amp;#34;#the-grey-areas&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The hard cases sit between the two categories. A few rules of thumb:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Bullying or harassment that affects others.&amp;lt;/strong&amp;gt; A single personal complaint is a grievance. But widespread bullying, or misconduct by a senior person that puts customers, patients, or colleagues at risk, is often better handled as whistleblowing.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A grievance with a concern buried inside it.&amp;lt;/strong&amp;gt; People frequently raise a public-interest concern only once it has affected them personally. Look past the personal framing to the underlying issue.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;When in doubt, treat it as whistleblowing.&amp;lt;/strong&amp;gt; The protections are stronger and the deadlines are tighter. It is safer to apply the higher standard and step down than to under-protect a reporter and discover later that you should not have.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;You do not have to resolve the ambiguity alone or instantly. Acknowledge the report, tell the reporter which process you intend to use, and explain that you may revisit that decision as the facts develop.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-a-good-case-handler-does-on-intake&amp;#34;&amp;gt;
What a good case handler does on intake
&amp;lt;a href=&amp;#34;#what-a-good-case-handler-does-on-intake&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Whichever route applies, the handling discipline is the same:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Acknowledge promptly&amp;lt;/strong&amp;gt; and tell the reporter how you will treat the matter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Assume confidentiality.&amp;lt;/strong&amp;gt; Never reveal the reporter&amp;amp;rsquo;s identity without explicit consent; set out any legal limits in writing before you act on them.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Do not ask the reporter to investigate.&amp;lt;/strong&amp;gt; Coming forward is hard enough; turning the reporter into your investigator increases their exposure.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Separate the message from the messenger.&amp;lt;/strong&amp;gt; Whether the reporter has a personal axe to grind does not change whether the concern has substance. Act on the substance.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Keep the reporter informed&amp;lt;/strong&amp;gt;, and deliver feedback within three months — even if you can only confirm that the matter was investigated and acted on.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;For the full operating procedure, our case handler manual — generated automatically for every EthicsPortal channel — walks designated handlers through intake, the triage decision above, confidentiality, escalation, and the statutory deadlines.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-helps-you-get-the-routing-right&amp;#34;&amp;gt;
How EthicsPortal helps you get the routing right
&amp;lt;a href=&amp;#34;#how-ethicsportal-helps-you-get-the-routing-right&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;A purpose-built reporting channel makes the distinction operational rather than a judgment call made under pressure:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Report categories&amp;lt;/strong&amp;gt; prompt the reporter to frame the issue, so a public-interest concern is less likely to arrive disguised as a personal complaint.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Secure two-way messaging&amp;lt;/strong&amp;gt; lets you ask clarifying questions — even of an anonymous reporter — before you decide the route.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Automatic deadline tracking&amp;lt;/strong&amp;gt; holds the 7-day and 3-month clocks the moment a report is treated as whistleblowing, so the classification decision is enforced, not just recorded.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A documented policy and case handler manual&amp;lt;/strong&amp;gt; give your handlers a written basis for the call and an audit trail for the outcome.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;deploy-a-channel-that-handles-this-correctly&amp;#34;&amp;gt;
Deploy a channel that handles this correctly
&amp;lt;a href=&amp;#34;#deploy-a-channel-that-handles-this-correctly&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is EU whistleblower compliance infrastructure: secure intake, confidentiality controls under Article 16, deadline tracking under Article 9, and audit-ready records under Article 18 — €41.67/month billed annually. Deploy the channel, designate a handler, and give the people who speak up a process that protects them from the first day.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For the broader setup, see &amp;lt;a href=&amp;#34;/blog/how-to-implement-whistleblower-channel/&amp;#34;&amp;gt;how to deploy an internal reporting channel&amp;lt;/a&amp;gt;
and our &amp;lt;a href=&amp;#34;/blog/whistleblower-policy-template/&amp;#34;&amp;gt;free whistleblower policy template&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Whistleblower reports do not belong inside an LLM</title><link>https://ethicsportal.eu/blog/whistleblower-reports-do-not-belong-inside-an-llm/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblower-reports-do-not-belong-inside-an-llm/</guid><description>Seven whistleblower platforms sold into the EU now process report content through large language models. Six of them won&amp;#39;t tell you whose. EthicsPortal does neither. Screenshots and sources inside.</description><content:encoded>&amp;lt;h1 id=&amp;#34;whistleblower-reports-do-not-belong-inside-an-llm&amp;#34;&amp;gt;
Whistleblower reports do not belong inside an LLM
&amp;lt;a href=&amp;#34;#whistleblower-reports-do-not-belong-inside-an-llm&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Seven whistleblower platforms sold into the EU run report content through large language models. They summarise reports, transcribe voice intake, run AI agents that talk to whistleblowers, and produce &amp;amp;ldquo;insights&amp;amp;rdquo; across case archives. Only one of the seven names which AI provider does the work.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal does none of this. Our &amp;lt;a href=&amp;#34;/dpa/#610-no-ai-or-llm-processing-of-report-content&amp;#34;&amp;gt;DPA §6.10&amp;lt;/a&amp;gt;
and our &amp;lt;a href=&amp;#34;/subprocessors/&amp;#34;&amp;gt;sub-processor list&amp;lt;/a&amp;gt;
say so.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Every claim below is quoted from the vendor&amp;amp;rsquo;s own live page or public DPA, captured 24 May 2026. Translation and categorisation can run on-prem, so we did not include vendors whose only AI claim is &amp;amp;ldquo;AI translation&amp;amp;rdquo; or &amp;amp;ldquo;AI categorisation&amp;amp;rdquo;. The seven below claim more than that.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;navex--ai-supported-case-briefs-and-suggested-rewrites&amp;#34;&amp;gt;
NAVEX — &amp;amp;ldquo;AI-supported case briefs and suggested rewrites&amp;amp;rdquo;
&amp;lt;a href=&amp;#34;#navex--ai-supported-case-briefs-and-suggested-rewrites&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;NAVEX is the largest enterprise whistleblowing vendor in the world. EthicsPoint sits inside most Fortune 500 compliance programs.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;From the &amp;lt;a href=&amp;#34;https://www.navex.com/en-us/platform/whistleblowing-software-solutions/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;whistleblowing platform page&amp;lt;/a&amp;gt;
:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Summarize complex cases with &amp;lt;strong&amp;gt;AI-supported case briefs and suggested rewrites&amp;lt;/strong&amp;gt;&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Spot recurring themes earlier through higher-level insights and analytics&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/navex-ai-case-briefs-rewrites.png&amp;#34; alt=&amp;#34;NAVEX whistleblowing platform — “Summarize complex cases with AI-supported case briefs and suggested rewrites”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;To suggest a rewrite, the model has to read the original report. NAVEX does not name the model on any public page.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;eqs-integrity-line--ai-powered-summaries-and-transcription-in-80-languages&amp;#34;&amp;gt;
EQS Integrity Line — &amp;amp;ldquo;AI-powered summaries and transcription&amp;amp;rdquo; in 80+ languages
&amp;lt;a href=&amp;#34;#eqs-integrity-line--ai-powered-summaries-and-transcription-in-80-languages&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EQS Group (Munich-listed) runs the largest whistleblower platform in continental Europe. From their &amp;lt;a href=&amp;#34;https://www.eqs.com/en-us/platform-compliance-ethics/integrity-line-whistleblower-software/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Integrity Line page&amp;lt;/a&amp;gt;
:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;AI that works for you.&amp;lt;/strong&amp;gt; Handle reports in over 80 languages with AI-powered summaries and transcription, and transform voice recordings into searchable texts. Get helpful insights from past cases for faster resolution including suggestions for case categories and priorities.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/eqs-integrity-line-ai-summaries-transcription.png&amp;#34; alt=&amp;#34;EQS Integrity Line — “AI that works for you”: AI-powered summaries, transcription of voice recordings, case-category suggestions&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Summaries, voice transcription, and cross-case insights. 4,000+ organisations on the platform. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;speakup--sienna-ai-a-whole-ai-product-line&amp;#34;&amp;gt;
SpeakUp — &amp;amp;ldquo;Sienna AI&amp;amp;rdquo;: a whole AI product line
&amp;lt;a href=&amp;#34;#speakup--sienna-ai-a-whole-ai-product-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;SpeakUp&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://www.speakup.com/sienna-ai&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Sienna AI&amp;lt;/a&amp;gt;
is not a feature, it is a sub-brand:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Sienna AI. Compliance reimagined.&amp;lt;/strong&amp;gt; The intelligence layer behind the future of compliance and ethics.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/speakup-sienna-ai-compliance-reimagined.png&amp;#34; alt=&amp;#34;SpeakUp Sienna AI hero — “Compliance reimagined. The intelligence layer behind the future of compliance and ethics.”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The page markets an &amp;lt;strong&amp;gt;AI Voice Agent&amp;lt;/strong&amp;gt; that has reporters &amp;amp;ldquo;speak freely and safely&amp;amp;rdquo; through a &amp;amp;ldquo;guided, conversational intake&amp;amp;rdquo;, &amp;lt;strong&amp;gt;Sienna Insights&amp;lt;/strong&amp;gt; (&amp;amp;ldquo;AI does the digging. You get the insight.&amp;amp;rdquo;), and AI translation, transcription, and routing of submissions into the case management system. Reporters in SpeakUp&amp;amp;rsquo;s flow are talking to a model. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;whispli--use-ai-to-capture-clearer-more-complete-hotline-reports&amp;#34;&amp;gt;
Whispli — &amp;amp;ldquo;Use AI to capture clearer, more complete hotline reports&amp;amp;rdquo;
&amp;lt;a href=&amp;#34;#whispli--use-ai-to-capture-clearer-more-complete-hotline-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;From Whispli&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://www.whispli.com/whistleblowing-hotline&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Voice AI hotline page&amp;lt;/a&amp;gt;
(the page title is literally &amp;amp;ldquo;AI Whistleblowing Hotline&amp;amp;rdquo;):&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Use AI to capture clearer, more complete hotline reports.&amp;lt;/strong&amp;gt; Manage global whistleblowing hotline reporting with an AI-powered voice intake agent that captures, structures and routes cases securely across jurisdictions.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/whispli-voice-ai-hotline.png&amp;#34; alt=&amp;#34;Whispli hotline hero — “Use AI to capture clearer, more complete hotline reports” with a Voice transcribed / Case created flow&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The flow diagram on the page shows it plainly: Incoming Voice Report → Voice transcribed → Case created. The most exposed reporter, the one who picked up a phone, is talking to an AI agent. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;faceup--voice-based-ai-conducts-natural-conversations-with-whistleblowers&amp;#34;&amp;gt;
FaceUp — &amp;amp;ldquo;Voice-based AI conducts natural conversations&amp;amp;rdquo; with whistleblowers
&amp;lt;a href=&amp;#34;#faceup--voice-based-ai-conducts-natural-conversations-with-whistleblowers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;FaceUp is a Czech-EU platform with 3,500+ organisations across 70+ countries. Their &amp;lt;a href=&amp;#34;https://www.faceup.com/en/whistleblowing/hotline&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;whistleblower hotline page&amp;lt;/a&amp;gt;
offers three tiers: a Live Hotline staffed by human agents, an Automated Hotline with a scripted flow, and the new AI-Powered Hotline in the middle:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;&amp;lt;strong&amp;gt;Voice-based AI conducts natural conversations, asks follow-ups, and converts calls into structured, actionable reports.&amp;lt;/strong&amp;gt; Multilingual, 24/7.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/faceup-ai-powered-hotline.png&amp;#34; alt=&amp;#34;FaceUp three-tier hotline comparison — “AI-Powered Hotline” (centre, marked “new”) with “Voice-based AI conducts natural conversations, asks follow-ups, and converts calls into structured, actionable reports”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;The AI agent guides the reporter and follows up where needed to capture complete and accurate information.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;FaceUp&amp;amp;rsquo;s three-card layout is the clearest framing of the choice in the category: a human handles the call, a scripted flow handles the call, or an AI handles the call. They sell all three and mark the AI option &amp;amp;ldquo;new&amp;amp;rdquo;. Provider not named.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;whistlelink--mistral-ai-france-and-deepl-germany-named-in-the-public-dpa&amp;#34;&amp;gt;
Whistlelink — Mistral AI (France) and DeepL (Germany) named in the public DPA
&amp;lt;a href=&amp;#34;#whistlelink--mistral-ai-france-and-deepl-germany-named-in-the-public-dpa&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Whistlelink is the only vendor of the seven that publicly names its AI providers. Their &amp;lt;a href=&amp;#34;https://www.whistlelink.com/ro/contract-de-prelucrare-a-datelor/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Romanian DPA&amp;lt;/a&amp;gt;
, Section 5.5:&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;amp;ldquo;Sub-Imputerniciți: Swerolab AB (Suedia), SMSAPI (Polonia), Brevo (Franța), OPSWAT (Germania), Glesys (Suedia), T-Systems International (Germania), Friendly Captcha (Germania), &amp;lt;strong&amp;gt;DeepL (Germania), Mistral AI (Franța)&amp;lt;/strong&amp;gt;.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/whistlelink-dpa-mistral-deepl.png&amp;#34; alt=&amp;#34;Whistlelink DPA Section 5.5 — sub-processor list naming DeepL (Germany) and Mistral AI (France)&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;#34;https://www.whistlelink.com/product/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;product page&amp;lt;/a&amp;gt;
explains what the AI Assistant does: &amp;amp;ldquo;AI Assistant automatically generates concise case summaries.&amp;amp;rdquo; Mistral is the only LLM provider on the sub-processor list above.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Article 16 confidentiality concern still applies. But an operator signing this DPA knows what they are signing. Operators signing the other six don&amp;amp;rsquo;t.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;ethicontrol--ai-intake-agent-on-the-pricing-page&amp;#34;&amp;gt;
Ethicontrol — &amp;amp;ldquo;ai intake agent&amp;amp;rdquo; on the pricing page
&amp;lt;a href=&amp;#34;#ethicontrol--ai-intake-agent-on-the-pricing-page&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ethicontrol&amp;amp;rsquo;s &amp;lt;a href=&amp;#34;https://ethicontrol.com/en/pricing&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;pricing page&amp;lt;/a&amp;gt;
lists &amp;lt;code&amp;gt;+ ai intake agent for web portal and WhatsApp&amp;lt;/code&amp;gt; as a paid feature starting at the Standard tier (€174/month):&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/ethicontrol-pricing-ai-intake-agent.png&amp;#34; alt=&amp;#34;Ethicontrol pricing — Standard tier includes “&amp;amp;#43; ai intake agent for web portal and WhatsApp”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In 2026, an &amp;amp;ldquo;intake agent&amp;amp;rdquo; for whistleblower reports is a conversational LLM. The privacy policy and Trust Center do not name the provider.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;six-of-the-seven-wont-tell-you-whose-ai&amp;#34;&amp;gt;
Six of the seven won&amp;amp;rsquo;t tell you whose AI
&amp;lt;a href=&amp;#34;#six-of-the-seven-wont-tell-you-whose-ai&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Of the seven above, only Whistlelink names the AI providers (Mistral, DeepL). The other six say &amp;amp;ldquo;AI&amp;amp;rdquo;, &amp;amp;ldquo;AI-powered&amp;amp;rdquo;, &amp;amp;ldquo;Sienna AI&amp;amp;rdquo;, or &amp;amp;ldquo;Voice-based AI&amp;amp;rdquo; without naming the model, the provider, the jurisdiction, or whether the inference call leaves the operator&amp;amp;rsquo;s encryption boundary.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We searched every vendor&amp;amp;rsquo;s privacy policy, DPA, sub-processor page, and trust center we could reach on 24 May 2026. For six, the provider is not disclosed. The feature is in the marketing copy. The disclosure is not in the legal pages.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;img src=&amp;#34;/images/blog/no-ai-commitment/big-short-bragging-not-confessing.jpg&amp;#34; alt=&amp;#34;The Big Short meme — “I don’t get it. Why are they confessing?” / “They’re not confessing. They’re bragging.”&amp;#34;&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is the harder problem. An operator running a Data Protection Impact Assessment cannot disclose a sub-processor they cannot name, cannot assess GDPR Chapter V transfer mechanisms for a provider that has not been disclosed to them, and cannot offer the reporter a meaningful privacy notice when the architecture has a box labelled &amp;amp;ldquo;AI&amp;amp;rdquo; and no further detail.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;why-an-internal-reporting-channel-is-the-wrong-place-for-ai&amp;#34;&amp;gt;
Why an internal reporting channel is the wrong place for AI
&amp;lt;a href=&amp;#34;#why-an-internal-reporting-channel-is-the-wrong-place-for-ai&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Article 16 of Directive 2019/1937 says the identity of the reporting person, and information from which it can be deduced, must not be disclosed to anyone beyond authorised case-handling staff. Member-state laws (HinSchG, Sapin II / Loi Waserman, Law 361/2022, the 2024 Polish Act) lift that into criminal or administrative penalties. An LLM API provider is not authorised case-handling staff. Their engineers can read prompts. Their abuse-detection systems are designed to read prompts. The Directive has no &amp;amp;ldquo;but it was just for a summary&amp;amp;rdquo; carve-out.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener noreferrer&amp;#34;&amp;gt;Art. 22&amp;lt;/a&amp;gt;
of the GDPR sits on top of that. AI categorisation, &amp;amp;ldquo;suggested rewrites&amp;amp;rdquo; of a report body, AI case briefs that an investigator reads instead of the original, and &amp;amp;ldquo;insights&amp;amp;rdquo; that decide investigative priority are exactly the automated decision-making the article is written about. Disclosure, DPIA, sub-processor listing with notice and objection rights, and reporter-facing transparency all attach.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A no-AI commitment removes the entire disclosure tree. The privacy notice is shorter, the DPIA is shorter, the sub-processor list is shorter, and the reporter&amp;amp;rsquo;s expectation matches the architecture.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;our-commitment&amp;#34;&amp;gt;
Our commitment
&amp;lt;a href=&amp;#34;#our-commitment&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/dpa/#610-no-ai-or-llm-processing-of-report-content&amp;#34;&amp;gt;DPA §6.10&amp;lt;/a&amp;gt;
: report content, reporter identity, handler messages, attachments, and audit logs are not transmitted to any large language model, generative AI service, or AI-based classifier, whether operated by us or by a third party. OpenAI, Anthropic, Google, and Mistral are named in the DPA as examples of providers we do not transmit to. A change to this would be a material change to the service, notified 30 days in advance with an objection right.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Our &amp;lt;a href=&amp;#34;/subprocessors/&amp;#34;&amp;gt;sub-processor list&amp;lt;/a&amp;gt;
has five entries: Hetzner (EU hosting), Cloudflare (marketing-site CDN only), Mailjet (email), Stripe (billing), AppSignal (handler-side error monitoring). No AI sub-processor appears.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;if-you-are-evaluating-a-vendor&amp;#34;&amp;gt;
If you are evaluating a vendor
&amp;lt;a href=&amp;#34;#if-you-are-evaluating-a-vendor&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ask in writing: is any large language model, generative AI service, or AI-based classifier — operated by you or by a third party — a sub-processor of report content, reporter identity, handler messages, attachments, or audit logs? Name the provider, the jurisdiction, the function, and whether it is on by default. And will you contractually commit that this answer cannot change without 30 days&amp;amp;rsquo; notice and an objection right?&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We answered both in our DPA before anyone had to ask.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Best whistleblower software in 2026: an honest comparison</title><link>https://ethicsportal.eu/blog/best-whistleblower-software/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/best-whistleblower-software/</guid><description>16 EU whistleblower platforms compared: pricing from €29/month flat to €5,000+/year enterprise, EU hosting, and who each tool is best for.</description><content:encoded>&amp;lt;h1 id=&amp;#34;best-whistleblower-software-in-2026-an-honest-comparison&amp;#34;&amp;gt;
Best whistleblower software in 2026: an honest comparison
&amp;lt;a href=&amp;#34;#best-whistleblower-software-in-2026-an-honest-comparison&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;If you are looking for whistleblower software to comply with EU Directive 2019/1937, you will find many vendor-authored comparison articles. This article compares the platforms we evaluated before building EthicsPortal, plus EthicsPortal itself, against the same practical criteria.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We looked at pricing transparency, setup speed, EU hosting, feature depth, and how well each tool serves small-to-mid-sized companies versus enterprises.&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Need the compliance angle instead?&amp;lt;/strong&amp;gt; This guide compares tools on price, features, and fit. For a ranked, article-by-article view of how each platform meets EU Directive 2019/1937 (Articles 8 to 18), see &amp;lt;a href=&amp;#34;/blog/top-whistleblower-software-eu-directive-2019-1937/&amp;#34;&amp;gt;Top whistleblower software for EU Directive 2019/1937 compliance&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;h2 id=&amp;#34;what-does-eu-compliant-whistleblower-software-cost&amp;#34;&amp;gt;
What does EU-compliant whistleblower software cost?
&amp;lt;a href=&amp;#34;#what-does-eu-compliant-whistleblower-software-cost&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;For small and mid-sized companies, EU Directive 2019/1937 whistleblower software typically costs &amp;lt;strong&amp;gt;€29 to €96 per month&amp;lt;/strong&amp;gt; on flat or entry tiers, with most German and Spanish vendors clustered between €49 and €79. Enterprise platforms such as EQS Integrity Line, NAVEX Global, SpeakUp, and Whispli rarely publish a number and are quoted custom, usually &amp;lt;strong&amp;gt;€3,000 to €5,000 or more per year&amp;lt;/strong&amp;gt;. The lowest published entry price in this comparison is €29/month (DigitalPA, ithikios, Trusty Compliance).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Flat-rate pricing is worth singling out, because it does not scale with employee count and keeps budgeting predictable as you grow: EthicsPortal at €41.67/month billed annually, Vispato at €79/month, and Canal Etico App at €96/month all charge the same regardless of headcount.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;quick-comparison-table&amp;#34;&amp;gt;
Quick comparison table
&amp;lt;a href=&amp;#34;#quick-comparison-table&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Platform&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Starting price&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Free trial&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;EU hosting&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Setup time&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Best for&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EthicsPortal&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€41.67/mo billed annually&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Minutes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;SMEs, Directive channel&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Hintbox&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€49&amp;amp;ndash;€149+/mo (+VAT)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;German-speaking markets&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;LegalTegrity&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€49&amp;amp;ndash;€166/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;German SMEs, phone included&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Vispato&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€79/mo flat&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Germany)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;DACH flat-rate alternative&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;DigitalPA (Legality Whistleblowing)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;From €29/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Italy)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Italian market, ISO 27001/37001/37301&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;ithikios&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;From €29/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Spain)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Spanish SMEs, modular compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Canal Etico App&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€96/mo flat&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Spain)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Spanish Ley 2/2023 compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Whistlelink&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€79&amp;amp;ndash;€299/mo&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (30 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Sweden)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Nordic companies, mid-market&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Sygnanet&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;4,000&amp;amp;ndash;10,000 zł/yr&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Poland)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Polish market&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Trusty Compliance&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€29/mo (€348/yr in credits)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (7 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Undisclosed&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Swiss/DACH, broader compliance&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Formalize (whistleblowersoftware.com)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (request quote)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (14 days)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Denmark)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Mid-market EU companies&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;FaceUp&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (request quote)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Czech Republic)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Hours&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Schools, multilingual orgs&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Whispli&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (~€3,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (optional)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Enterprises, complex workflows&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;SpeakUp (People Intouch)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;~€3,000/yr&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Netherlands)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Mid-to-large EU companies&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EQS Integrity Line&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (~€3,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (Essential)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Large enterprises&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;NAVEX Global&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Custom (€5,000+/yr)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes (optional)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Weeks&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Large US/EU enterprises&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;detailed-reviews&amp;#34;&amp;gt;
Detailed reviews
&amp;lt;a href=&amp;#34;#detailed-reviews&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;eqs-integrity-line&amp;#34;&amp;gt;
EQS Integrity Line
&amp;lt;a href=&amp;#34;#eqs-integrity-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;EQS is the heavyweight of European compliance software. Their Integrity Line is used by banks, insurers, and listed companies across the EU.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Deep integration with broader GRC (governance, risk, compliance) suites. Excellent audit trails. Strong brand recognition among enterprise compliance teams. Supports 70+ languages.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing is opaque &amp;amp;mdash; you will not find a number on their website. Expect to spend several thousand euros per year, and you will need to go through a sales process. Implementation typically takes weeks with dedicated onboarding. This may exceed the needs of a 50-person company.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Large enterprises (500+ employees) in heavily regulated sectors that need a full GRC ecosystem.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;formalize-whistleblowersoftwarecom&amp;#34;&amp;gt;
Formalize (whistleblowersoftware.com)
&amp;lt;a href=&amp;#34;#formalize-whistleblowersoftwarecom&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Formalize, marketed as WhistleblowerSoftware.com, is a Danish platform backed by a €15M Series A with 500+ consultancy partners including PwC and Baker McKenzie. They have rebranded and expanded into broader compliance (NIS2, DORA, ISO 27001).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; 80+ languages. ISO 27001 and ISAE 3000 certified. Strong partner ecosystem. 14-day free trial.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No longer publishes pricing — requires requesting a custom quote. Expanding beyond whistleblowing into NIS2/DORA compliance may dilute focus. Setup involves a demo/sales process rather than self-service signup.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Mid-sized EU companies (50&amp;amp;ndash;500 employees) that want a polished product and do not mind per-employee pricing.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;whistlelink&amp;#34;&amp;gt;
Whistlelink
&amp;lt;a href=&amp;#34;#whistlelink&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Swedish platform with a strong presence in the Nordics. Whistlelink positions itself as easy to use and EU-compliant.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Available in 50+ languages. Good case management. Hosted in Sweden. Straightforward UI for reporters. All pricing tiers include the same feature set. 30-day free trial.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Starting at €79/month (billed annually) is reasonable but still above the flat-rate options. Pricing is tiered by employee count and scales to €299/month at 500&amp;amp;ndash;999 employees. Scaling past 1,000 employees requires contacting sales.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Nordic and Northern European companies looking for a regional vendor with solid language support.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;faceup&amp;#34;&amp;gt;
FaceUp
&amp;lt;a href=&amp;#34;#faceup&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;FaceUp is a Czech-founded whistleblower platform that has expanded from its original focus on schools into corporate compliance, now serving organizations across 70+ countries. They support 113 languages and offer a mobile app for reporters.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Available in 113 languages — among the highest in the market. Mobile app for reporters. ISO 27001 certified. Strong presence in the education sector alongside corporate compliance.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing is not published — all plans show &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; buttons despite listing tier names (Starter, Professional, Enterprise). Pricing is in US dollars, which adds currency risk for European companies. The school-oriented origin shows in some of the UX.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Organizations that need 113 languages, want a mobile reporting app, or operate in both education and corporate sectors.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;navex-global&amp;#34;&amp;gt;
NAVEX Global
&amp;lt;a href=&amp;#34;#navex-global&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;NAVEX is the enterprise incumbent in ethics and compliance, primarily in North America but increasingly in Europe. Their EthicsPoint product has been around for decades.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Massive feature set. Benchmarking data from thousands of clients. Hotline services (phone-based reporting). Strong analytics.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Enterprise pricing &amp;amp;mdash; expect custom quotes well above €5,000/year. Long implementation cycles. EU-specific requirements are one part of a broader global GRC platform rather than the sole product focus.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Large multinationals (1,000+ employees) that want a single vendor for their entire ethics and compliance program, including hotlines.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;whispli&amp;#34;&amp;gt;
Whispli
&amp;lt;a href=&amp;#34;#whispli&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An Australian-founded company that has expanded into Europe. Whispli emphasizes anonymous two-way communication.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Strong anonymous messaging system. Good mobile experience. Supports voice and video reporting. Flexible workflow builder.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Custom pricing with no public numbers &amp;amp;mdash; reports suggest starting around €3,000/year. Implementation involves onboarding calls and configuration. Smaller European presence compared to EU-native vendors.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Organizations that prioritize anonymous two-way communication and need multimedia reporting (voice, video).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;speakup-people-intouch&amp;#34;&amp;gt;
SpeakUp (People Intouch)
&amp;lt;a href=&amp;#34;#speakup-people-intouch&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Dutch platform that has been in the whistleblower space since before the EU Directive made it mandatory. SpeakUp offers both software and managed services (outsourced case handling).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Long track record. Option to outsource case handling entirely. Hosted in the Netherlands. Phone reporting included.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Pricing starts at €3,000/year for companies under 1,000 employees, custom for larger. The managed services model means you are paying for humans, not just software. Interface is functional but not modern.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Mid-to-large EU companies that want the option to outsource report handling to a third party.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;hintbox&amp;#34;&amp;gt;
Hintbox
&amp;lt;a href=&amp;#34;#hintbox&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A German platform (part of lawcode Suite) with 1,000+ customers including Rewe, s.Oliver, and FC Bayern. ISO 27001 certified, hosted on Hetzner in Germany. Expanding into LkSG (Supply Chain Act) and CSRD compliance beyond whistleblowing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Mature product with large customer base. ISO 27001 certified. 30+ languages with AI translation. 2FA, metadata stripping, virus scanning all included. Starting at €49/month. Free trial available.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Per-employee pricing scales to €149+/month for larger companies. Add-on costs pile up: voice bot (+€49/mo), email integration (+€29/mo), custom domain (+€29/mo). DACH-centric — limited presence outside German-speaking markets. Expanding into multiple compliance frameworks may dilute whistleblower focus.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; German, Austrian, and Swiss companies that want a local vendor with ISO 27001, deep HinSchG expertise, and a proven track record.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;legaltegrity&amp;#34;&amp;gt;
LegalTegrity
&amp;lt;a href=&amp;#34;#legaltegrity&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Frankfurt-based platform founded by Dr. Thomas Altenbach, hosted on Deutsche Telekom&amp;amp;rsquo;s Open Telekom Cloud. Positioned for German SMEs with transparent tiered pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Phone reporting channel included on every plan &amp;amp;mdash; even the €49/month Essential tier. 40+ languages available. Hosted on Deutsche Telekom Open Telekom Cloud (ISO 27001-certified infrastructure). 3-month money-back guarantee. OmbuTegrity add-on offers an external ombudsperson service for companies that need an independent reporting office.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Essential tier limits customization (standard form, LegalTegrity branding, 2 admin accounts). Additional languages cost €29/month each beyond the 2 included. No public API. Primarily German-market focused.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; German and DACH-region SMEs (under 1,000 employees) that want phone reporting included at a competitive price.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;vispato&amp;#34;&amp;gt;
Vispato
&amp;lt;a href=&amp;#34;#vispato&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A German whistleblowing platform from the HR WORKS group, hosted on DATEV-managed servers. Vispato is notable for its flat-rate pricing regardless of company size.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat €79/month with unlimited users, cases, and storage &amp;amp;mdash; no per-employee scaling. 18 languages. ISO 27001-certified hosting (DATEV). WCAG 2.1 AA accessibility compliance. No setup costs, no consulting add-ons. 12-month minimum term.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No free trial &amp;amp;mdash; demo required before account activation. No public API. 18 languages is fewer than most mid-market competitors. Enterprise features (SSO, custom domain, custom branding) require a custom-quote Enterprise plan.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; DACH-region companies of any size that want predictable flat pricing without employee-count tiers or add-on fees.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;digitalpa-legality-whistleblowing&amp;#34;&amp;gt;
DigitalPA (Legality Whistleblowing)
&amp;lt;a href=&amp;#34;#digitalpa-legality-whistleblowing&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An Italian platform operated by DigitalPA with offices in Cagliari, Milan, Rome, and Barcelona. Holds ISO certifications across 27001, 37001, and 37301 &amp;amp;mdash; and states alignment with ISO 37002 (one note on terminology: ISO 37002 &amp;lt;em&amp;gt;Whistleblowing management systems&amp;lt;/em&amp;gt; is a guidelines standard, so no organization can be &amp;lt;em&amp;gt;certified&amp;lt;/em&amp;gt; against it; the accurate claim for any vendor is alignment with its guidance, not certification).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Starting at €29/month &amp;amp;mdash; the lowest published price in this comparison. ISO 27001, 37001 (anti-bribery), and 37301 (compliance management) certified, with stated alignment to ISO 37002 (whistleblowing management). Multi-channel intake including phone reports and in-person meeting requests. Mobile app. AI translation between handler and reporter. 1,000+ customers.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Only the small-business band (under 50 employees) is publicly priced &amp;amp;mdash; €29/month Standard or €41/month Premium; everything larger requires a custom quote. Listed prices exclude VAT plus one-time activation and recurring service fees. Annual billing only. Italian-market focused. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Italian companies and organizations that need a locally certified platform, especially public sector entities required to comply with D.Lgs. 24/2023.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;ithikios&amp;#34;&amp;gt;
ithikios
&amp;lt;a href=&amp;#34;#ithikios&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Spanish modular compliance suite from Digital Products Development SL. Whistleblowing is one of six modules alongside policy, incident, rights, third-party, and trust-center management.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Starting at €29/month. ISO 27001 certified. 1,000+ companies across 10 countries. Free trial available. 7 interface languages (ES, EN, FR, DE, IT, PT, CA). Modular: buy the whistleblowing channel, add NIS2/DORA/policy modules later. Partner program for lawyers and consultants.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Primarily Spanish-market focused. Limited to 7 languages &amp;amp;mdash; the fewest among multi-market vendors. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Spanish SMEs that need Ley 2/2023 compliance and may want to add policy management, incident management, or third-party risk modules over time.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;canal-etico-app&amp;#34;&amp;gt;
Canal Etico App
&amp;lt;a href=&amp;#34;#canal-etico-app&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Spanish platform from Smart Dev Technology with flat €96/month pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat pricing regardless of company size. Unlimited reports. Written and voice reporting channels. Anonymous bidirectional communication. No IP storage, encrypted content. Implementation in 1&amp;amp;ndash;2 business days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No ISO 27001 certification published. Spanish-language support only. No public API. Higher price point than ithikios and DigitalPA for the same Spanish market.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Spanish companies that want simple flat pricing for Ley 2/2023 compliance without per-employee scaling.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;sygnanet&amp;#34;&amp;gt;
Sygnanet
&amp;lt;a href=&amp;#34;#sygnanet&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Polish platform from SpecFile Project Sp. z o.o. Built specifically for the Polish Act on Protection of Whistleblowers (in force 25 September 2024).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; End-to-end encryption with zero vendor access to report content. 12-language reporting form. Free trial. Pricing in Polish zloty (4,000&amp;amp;ndash;10,000 zł/year). Public bodies buying the internal-reporting licence get an external-reporting channel bundled free. Periodic penetration testing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; Polish-market focused. Pricing in PLN only. No ISO 27001 certification published. No public API. Admin panel limited to 4 languages (PL, EN, DE, FR).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Polish organizations that need a local vendor compliant with the Act of 14 June 2024.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;trusty-compliance&amp;#34;&amp;gt;
Trusty Compliance
&amp;lt;a href=&amp;#34;#trusty-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A Swiss platform (Trusty AG, Hünenberg, Zug) offering whistleblowing as one module in a broader compliance suite covering risk screening, EUDR, policy management, and training.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; 4,000+ companies. 7-day free trial. Whistleblowing published at €348/year in credits (marketed as from €29/month, billed annually). Credit-based pricing &amp;amp;mdash; buy credits at €1 each (€0.80 at volume) and allocate them across any Trusty product. Quick setup (vendor claims under 5 minutes). 6 interface languages. Broader compliance coverage (EUDR, NIS2, third-party risk, training) in addition to whistleblowing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No ISO 27001 certification published. Hosting location not disclosed. Credits are prepaid and non-refundable, and whistleblowing is billed annually even though the rest of the suite is pay-as-you-go. Whistleblowing is one module of many &amp;amp;mdash; breadth may come at the expense of depth. No public API.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; Swiss and DACH companies that want a single platform covering whistleblowing, risk screening, EUDR, and compliance training.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;ethicsportal&amp;#34;&amp;gt;
EthicsPortal
&amp;lt;a href=&amp;#34;#ethicsportal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is designed to deliver EU Directive 2019/1937 compliance with transparent pricing, self-service signup, and a portal that goes live the same day.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Strengths:&amp;lt;/strong&amp;gt; Flat €41.67/month pricing (billed annually) regardless of employee count. Operational in minutes. EU-hosted. Covers the core Directive requirements: encrypted anonymous reporting, two-way messaging via access codes, case management, 7-day acknowledgment and 3-month feedback tracking, QR code generation, and multilingual portals. Open, transparent pricing.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Weaknesses:&amp;lt;/strong&amp;gt; No phone hotline. No outsourced case handling. Limited integrations (no HRIS connectors yet). Not suitable for organizations that need a full GRC suite.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Best for:&amp;lt;/strong&amp;gt; SMEs and mid-sized companies (50&amp;amp;ndash;1,000 employees) that need Directive compliance without enterprise complexity or pricing.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;best-whistleblower-software-for-eu-listed-companies&amp;#34;&amp;gt;
Best whistleblower software for EU-listed companies
&amp;lt;a href=&amp;#34;#best-whistleblower-software-for-eu-listed-companies&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Listed companies and large regulated employers usually need more than a reporting channel. They need a defensible audit trail, third-party certifications, benchmarking against peers, and the ability to route cases across subsidiaries and jurisdictions. The platforms built for that profile are &amp;lt;strong&amp;gt;EQS Integrity Line&amp;lt;/strong&amp;gt;, &amp;lt;strong&amp;gt;NAVEX Global&amp;lt;/strong&amp;gt;, and &amp;lt;strong&amp;gt;SpeakUp (People Intouch)&amp;lt;/strong&amp;gt;, all with mature audit logging, enterprise GRC integration, and (for NAVEX and EQS) benchmarking data drawn from thousands of clients. Expect custom pricing and multi-week onboarding in return. Smaller listed companies that want a defensible audit trail without enterprise cost can also look at the ISO 27001-certified mid-market vendors such as Formalize, Hintbox, and Whistlelink.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;which-tools-include-a-phone-hotline&amp;#34;&amp;gt;
Which tools include a phone hotline?
&amp;lt;a href=&amp;#34;#which-tools-include-a-phone-hotline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you need a voice or telephone channel alongside the online reporting form, the options narrow. &amp;lt;strong&amp;gt;NAVEX Global&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;SpeakUp&amp;lt;/strong&amp;gt; include phone-based reporting as part of their enterprise offering, &amp;lt;strong&amp;gt;LegalTegrity&amp;lt;/strong&amp;gt; includes a phone channel on every plan (even its €49/month Essential tier), and &amp;lt;strong&amp;gt;DigitalPA&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;ithikios&amp;lt;/strong&amp;gt; support phone reports and in-person meeting requests. Most flat-rate SME tools, including EthicsPortal, are web-only. If a hotline is mandatory for your organization, filter to those five first.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;how-we-chose&amp;#34;&amp;gt;
How we chose
&amp;lt;a href=&amp;#34;#how-we-chose&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;We evaluated each platform across five criteria:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Pricing transparency.&amp;lt;/strong&amp;gt; Can you find the price on the website without requesting a custom quote? Bonus points for flat-rate pricing.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deployment path.&amp;lt;/strong&amp;gt; How quickly can a non-technical compliance officer move from account activation to a working reporting channel?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU Directive coverage.&amp;lt;/strong&amp;gt; Does the platform natively support the key requirements of Directive 2019/1937 &amp;amp;mdash; anonymous reporting, two-way communication, acknowledgment deadlines, confidentiality?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data residency.&amp;lt;/strong&amp;gt; Is data hosted in the EU by default, or is it an add-on?&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Target audience fit.&amp;lt;/strong&amp;gt; Is the platform designed for your company size, or are you paying for features built for organizations ten times larger?&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;We used publicly available pricing where possible and contacted vendors where pricing was not published. Prices cited are as of Q1 2026 and may vary by region, contract length, and negotiation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;No affiliate links. No sponsorships. EthicsPortal is the product operated by us; the same criteria are applied to each platform.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;frequently-asked-questions&amp;#34;&amp;gt;
Frequently asked questions
&amp;lt;a href=&amp;#34;#frequently-asked-questions&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;how-much-does-whistleblower-software-cost-in-the-eu&amp;#34;&amp;gt;
How much does whistleblower software cost in the EU?
&amp;lt;a href=&amp;#34;#how-much-does-whistleblower-software-cost-in-the-eu&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Entry and flat-rate plans for small and mid-sized companies run roughly €29 to €96 per month. Enterprise platforms are quoted custom, typically €3,000 to €5,000 or more per year. Flat-rate options such as EthicsPortal at €41.67/month billed annually do not scale with employee count, which keeps budgeting predictable.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;is-there-free-whistleblower-software&amp;#34;&amp;gt;
Is there free whistleblower software?
&amp;lt;a href=&amp;#34;#is-there-free-whistleblower-software&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;There is no credible free tier for EU Directive 2019/1937 compliance. Several vendors offer free trials of 7 to 30 days, including Hintbox, ithikios, Whistlelink, Formalize, Trusty Compliance, and Sygnanet. Free form builders exist, but they lack the encrypted anonymous channel, deadline tracking, and confidentiality controls the Directive requires, so they are rarely a safe basis for compliance.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;which-whistleblower-tools-provide-an-audit-trail&amp;#34;&amp;gt;
Which whistleblower tools provide an audit trail?
&amp;lt;a href=&amp;#34;#which-whistleblower-tools-provide-an-audit-trail&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;A complete audit trail is a core Directive expectation, so most compliance-grade platforms provide one. EQS Integrity Line is known for particularly detailed audit logging, and EthicsPortal records 7-day acknowledgment and 3-month feedback deadlines alongside case activity. Free form builders generally do not offer a tamper-evident trail.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;where-is-whistleblower-report-data-hosted&amp;#34;&amp;gt;
Where is whistleblower report data hosted?
&amp;lt;a href=&amp;#34;#where-is-whistleblower-report-data-hosted&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Most EU-native vendors host in the EU by default, across Germany, Sweden, the Netherlands, Italy, Spain, Poland, and the Czech Republic. Some global platforms treat EU hosting as an optional add-on, so confirm data residency before you buy if it matters for your jurisdiction.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Top whistleblower software for EU Directive 2019/1937 compliance</title><link>https://ethicsportal.eu/blog/top-whistleblower-software-eu-directive-2019-1937/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/top-whistleblower-software-eu-directive-2019-1937/</guid><description>A ranked comparison of whistleblower platforms that meet the requirements of EU Directive 2019/1937. Evaluated on Article 8–16 coverage, pricing, EU hosting, and setup speed.</description><content:encoded>&amp;lt;h1 id=&amp;#34;top-whistleblower-software-for-eu-directive-20191937-compliance&amp;#34;&amp;gt;
Top whistleblower software for EU Directive 2019/1937 compliance
&amp;lt;a href=&amp;#34;#top-whistleblower-software-for-eu-directive-20191937-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937, now transposed into national law in all 27 member states (e.g., &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
in France, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
in Germany, &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
in Spain), requires every organization with 50 or more employees to operate a secure internal reporting channel. The law is specific about what that channel must do: accept written and oral reports, protect reporter confidentiality, acknowledge receipt within 7 days, provide feedback within 3 months, and maintain records without exposing the reporter&amp;amp;rsquo;s identity.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The core workflow is narrow. A reporter submits a report. A handler reviews it and responds. The system tracks deadlines and keeps an audit trail.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Many platforms package that workflow inside broader ethics, GRC, or analytics suites. That may be appropriate for large enterprises, but organizations with a defined Directive obligation should still evaluate the reporting channel itself: coverage, confidentiality, deadlines, records, data residency, and procurement path.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This article ranks the top whistleblower software specifically by how well each platform meets the Directive&amp;amp;rsquo;s legal requirements &amp;amp;mdash; not by brand recognition, AI feature count, or how impressive the sales deck looks.&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Just comparing your options?&amp;lt;/strong&amp;gt; This guide ranks platforms by how well they meet the Directive&amp;amp;rsquo;s legal requirements. For pricing, free trials, phone-hotline options, and picks by company size, see &amp;lt;a href=&amp;#34;/blog/best-whistleblower-software/&amp;#34;&amp;gt;Best whistleblower software in 2026&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-we-scored&amp;#34;&amp;gt;
How we scored
&amp;lt;a href=&amp;#34;#how-we-scored&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every platform was evaluated against the six core requirements of Directive 2019/1937:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Directive articles&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;What the law demands&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure internal reporting channel&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 8&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Encrypted, accessible to all workers, no account required&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter confidentiality&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 16&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Identity not disclosed without consent, access restricted to authorized staff&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Receipt acknowledgment&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Written confirmation within 7 days&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Feedback deadline&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(f)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Substantive feedback within 3 months&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Ability to communicate with the reporter, including anonymous reporters&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 18&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Reports stored securely, retained per legal requirements, deletable when no longer needed&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;We also considered practical factors: pricing transparency, EU data residency, deployment path, and whether the commercial process is published before procurement starts.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-ranking&amp;#34;&amp;gt;
The ranking
&amp;lt;a href=&amp;#34;#the-ranking&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;1-ethicsportal--best-for-smes-that-need-a-focused-directive-channel&amp;#34;&amp;gt;
1. EthicsPortal &amp;amp;mdash; best for SMEs that need a focused Directive channel
&amp;lt;a href=&amp;#34;#1-ethicsportal--best-for-smes-that-need-a-focused-directive-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; EthicsPortal was built specifically for EU Directive 2019/1937. Every feature maps to an article.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;How EthicsPortal handles it&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Encrypted web portal, unique URL per organization, no app required&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;No IP logging, file metadata stripping (EXIF, GPS, author), encrypted data at rest&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Automatic deadline tracking with handler notifications&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Automatic deadline tracking with overdue alerts&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Anonymous message thread via access code &amp;amp;mdash; handler names never revealed&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Append-only audit trail, PDF export for auditors&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; €41.67/month billed annually (€500/year). No per-employee fees, no add-ons.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Hetzner, Nuremberg, Germany.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Minutes. Self-service signup on a published plan.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks first:&amp;lt;/strong&amp;gt; EthicsPortal is built specifically for the Directive workflow: secure intake, anonymous two-way communication, deadline tracking, record-keeping, and audit export. It does not add AI sentiment analysis, risk scoring, or adjacent GRC modules to the reporting channel. Full Art. 8&amp;amp;ndash;18 coverage is available at €41.67/month billed annually, published on the website.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The trade-off is that EthicsPortal is newer and does not yet have ISO 27001 certification or phone hotline services.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is the product operated by us. It is designed to deliver Directive compliance with transparent pricing, self-service signup, and a portal that goes live the same day.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;2-formalize-whistleblowersoftwarecom--best-for-mid-market-companies-wanting-a-polished-product&amp;#34;&amp;gt;
2. Formalize (WhistleblowerSoftware.com) &amp;amp;mdash; best for mid-market companies wanting a polished product
&amp;lt;a href=&amp;#34;#2-formalize-whistleblowersoftwarecom--best-for-mid-market-companies-wanting-a-polished-product&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Built in Denmark with the EU Directive as the primary design driver.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web portal with encryption&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; access controls, data encryption&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Custom quote required. Previously published per-employee pricing; no longer public.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Denmark.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days &amp;amp;mdash; involves a demo/sales process.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Strong Directive compliance, ISO 27001 and ISAE 3000 certified, and 80+ languages. Formalize used to publish pricing on their website; pricing now requires a quote and sales process. If you need certifications and a partner ecosystem (PwC, Baker McKenzie), Formalize is a strong choice, but budget confirmation requires procurement contact.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;3-hintbox--best-for-german-speaking-markets&amp;#34;&amp;gt;
3. Hintbox &amp;amp;mdash; best for German-speaking markets
&amp;lt;a href=&amp;#34;#3-hintbox--best-for-german-speaking-markets&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; German platform with 1,000+ customers. Part of the lawcode suite.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, hosted on Hetzner (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; metadata stripping, 2FA, virus scanning&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging, optional voice bot (+€49/mo)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at €49/month. Scales to €149+/month with employee count. Add-ons: voice bot (+€49/mo), email integration (+€29/mo), custom domain (+€29/mo).
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Hetzner, Germany. ISO 27001 certified.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Mature product, large customer base (Rewe, s.Oliver, FC Bayern), ISO 27001 certified. The per-employee pricing and add-on costs mean the effective price is significantly higher than the €49 starting point for most organizations. DACH-focused &amp;amp;mdash; limited presence outside German-speaking markets.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;4-legaltegrity--best-for-german-smes-that-want-phone-reporting-included&amp;#34;&amp;gt;
4. LegalTegrity &amp;amp;mdash; best for German SMEs that want phone reporting included
&amp;lt;a href=&amp;#34;#4-legaltegrity--best-for-german-smes-that-want-phone-reporting-included&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Frankfurt-based, hosted on Deutsche Telekom Open Telekom Cloud.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, Deutsche Telekom hosting (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; role-based access&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking with reminders&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging, phone channel on all plans&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail, reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Essential €49/month (&amp;amp;lt;50 employees), Professional €99/month (&amp;amp;lt;250), Professional €166/month (&amp;amp;lt;1,000), Enterprise on request. Annual billing.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Deutsche Telekom Open Telekom Cloud, Germany. ISO 27001-certified hosting.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. 3-month money-back guarantee.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; LegalTegrity includes a phone reporting channel on every plan, including the €49 Essential tier. That is unusual &amp;amp;mdash; most competitors charge extra for phone intake or do not offer it at all. 40+ languages available. The trade-off: per-employee tiered pricing means costs rise as your organisation grows, and additional languages cost €29/month each beyond the two included.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;5-vispato--best-flat-rate-alternative-in-dach&amp;#34;&amp;gt;
5. Vispato &amp;amp;mdash; best flat-rate alternative in DACH
&amp;lt;a href=&amp;#34;#5-vispato--best-flat-rate-alternative-in-dach&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; German platform, part of the HR WORKS group.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted portal, DATEV-hosted (Germany)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; role-based access, ISO 27001 hosting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; €79/month flat. Unlimited users, cases, and storage. Enterprise tier with SSO and custom domain is quote-based.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; DATEV-managed servers, Germany.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. No free trial, demo required.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Flat €79/month regardless of company size, with no add-on fees. 18 languages. WCAG 2.1 AA accessibility. For DACH-region companies that want predictable costs without employee-count tiers, Vispato is the cleanest alternative. The trade-off: fewer languages than competitors (18 vs. 30&amp;amp;ndash;80), and no free trial.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;6-digitalpa-legality-whistleblowing--best-for-italy&amp;#34;&amp;gt;
6. DigitalPA (Legality Whistleblowing) &amp;amp;mdash; best for Italy
&amp;lt;a href=&amp;#34;#6-digitalpa-legality-whistleblowing--best-for-italy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Italian platform with four ISO certifications.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web, voice, phone, and in-person intake&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; 2FA, anonymous and confidential modes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; deadline tracking&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging with AI translation&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail, investigation reports&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Standard from €29/month (&amp;amp;lt;50 employees). Premium from €41/month. Medium/Large/Enterprise tiers require a quote. Annual billing only, excluding VAT; one-time activation and recurring service fees apply on top.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Italy.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; The lowest starting price in this comparison (€29/month) and the broadest ISO coverage &amp;amp;mdash; certified to 27001, 37001, and 37301, with stated alignment to ISO 37002 (a guidelines standard no one can be &amp;lt;em&amp;gt;certified&amp;lt;/em&amp;gt; against, so &amp;amp;ldquo;ISO 37002 certified&amp;amp;rdquo; is, strictly, a misnomer for any vendor). Multi-channel intake including phone and in-person meeting requests. 1,000+ customers. The trade-off: pricing beyond the small-business tier is quote-based, and the platform is Italian-market focused.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;7-ithikios--best-for-spanish-smes&amp;#34;&amp;gt;
7. ithikios &amp;amp;mdash; best for Spanish SMEs
&amp;lt;a href=&amp;#34;#7-ithikios--best-for-spanish-smes&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Spanish modular compliance suite.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted cloud portal, ISO 27001 servers&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous and confidential modes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; case management with documentation&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; From €29/month. Free trial available.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Spain. ISO 27001 certified.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Published €29/month pricing with ISO 27001 and a free trial. 1,000+ companies across 10 countries. Modular platform: buy the whistleblowing channel now, add policy management or NIS2 modules later. 7 interface languages. The trade-off: primarily Spanish-focused, and 7 languages is limited for cross-border organisations.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;8-canal-etico-app--best-for-spanish-flat-rate-simplicity&amp;#34;&amp;gt;
8. Canal Etico App &amp;amp;mdash; best for Spanish flat-rate simplicity
&amp;lt;a href=&amp;#34;#8-canal-etico-app--best-for-spanish-flat-rate-simplicity&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Spanish platform from Smart Dev Technology.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; written and voice reporting, encrypted content&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; no IP storage, anonymous bidirectional communication&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; case management&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; €96/month flat, unlimited reports, regardless of company size.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Spain.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; 1&amp;amp;ndash;2 business days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Flat €96/month with unlimited reports makes budgeting simple for Spanish organisations that want Ley 2/2023 compliance without per-employee scaling. The trade-off: no published ISO 27001 certification, Spanish-language support only, and no public API. Higher priced than ithikios and DigitalPA for the same Spanish market.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;9-trusty-compliance--best-for-dach-companies-wanting-broader-compliance-coverage&amp;#34;&amp;gt;
9. Trusty Compliance &amp;amp;mdash; best for DACH companies wanting broader compliance coverage
&amp;lt;a href=&amp;#34;#9-trusty-compliance--best-for-dach-companies-wanting-broader-compliance-coverage&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Swiss platform (Trusty AG, Zug), with whistleblowing as one module in a broader compliance suite.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; encrypted web intake&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; case management&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Whistleblowing from €348/year in credits (marketed as from €29/month, billed annually). Credit-based across the wider suite.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Not disclosed.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours (vendor claims under 5 minutes). 7-day free trial.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; For DACH companies that want whistleblowing alongside EUDR, risk screening, and compliance training in one credit-based platform, Trusty is a broad option at a low entry price. The trade-offs weigh on Directive-specific fit: no published ISO 27001 certification, hosting location not disclosed, and whistleblowing billed annually as one module of many &amp;amp;mdash; breadth may come at the expense of depth.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;10-sygnanet--best-for-the-polish-market&amp;#34;&amp;gt;
10. Sygnanet &amp;amp;mdash; best for the Polish market
&amp;lt;a href=&amp;#34;#10-sygnanet--best-for-the-polish-market&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Polish platform from SpecFile, built for the Polish Act on Protection of Whistleblowers.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; 12-language reporting form&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; end-to-end encryption, zero vendor access to report content&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; 4,000&amp;amp;ndash;10,000 zł/year. Public bodies buying the internal-reporting licence get an external-reporting channel bundled free.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Poland.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours. Free trial available.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; End-to-end encryption with zero vendor access is a strong confidentiality posture, and the product is purpose-built for the Polish Act of 14 June 2024. Periodic penetration testing. The trade-offs: Polish-market focused, pricing in PLN only, no published ISO 27001 certification, and an admin panel limited to four languages.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;11-faceup--best-for-multilingual-organizations-113-languages&amp;#34;&amp;gt;
11. FaceUp &amp;amp;mdash; best for multilingual organizations (113 languages)
&amp;lt;a href=&amp;#34;#11-faceup--best-for-multilingual-organizations-113-languages&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; access controls&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; automated&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; audit trail&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Not public. Three tiers (Starter, Professional, Enterprise) but all require &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; — no prices shown on the website. Priced in USD.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Czech Republic.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Hours.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; FaceUp supports 113 languages &amp;amp;mdash; among the highest in the market &amp;amp;mdash; and offers a mobile app for reporters. Originally built for schools in the Czech Republic, they have expanded into corporate compliance across 70+ countries. Pricing is in US dollars and not publicly displayed &amp;amp;mdash; all three tiers (Starter, Professional, Enterprise) show &amp;amp;ldquo;Get a Quote&amp;amp;rdquo; buttons rather than prices, making it impossible to budget without a sales conversation.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;12-whistlelink--best-for-nordic-companies&amp;#34;&amp;gt;
12. Whistlelink &amp;amp;mdash; best for Nordic companies
&amp;lt;a href=&amp;#34;#12-whistlelink--best-for-nordic-companies&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at €79/month (billed annually). Scales by employee count: €79 → €99 → €149 → €199 → €299/month. 1,000+ employees: contact sales.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Sweden.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days. 30-day free trial available.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Solid Directive compliance with 50+ languages and good case management. All pricing tiers include the same feature set &amp;amp;mdash; no feature gating. Starting at €79/month, pricing is higher than the lowest-price options but transparent. Strong regional presence in the Nordics.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;13-speakup-people-intouch--best-for-outsourced-case-handling&amp;#34;&amp;gt;
13. SpeakUp (People Intouch) &amp;amp;mdash; best for outsourced case handling
&amp;lt;a href=&amp;#34;#13-speakup-people-intouch--best-for-outsourced-case-handling&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; One of the longest-running European whistleblower platforms (Netherlands).&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web + phone reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Starting at ~€3,000/year for companies under 1,000 employees. Custom for larger.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes &amp;amp;mdash; Netherlands.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Days.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Unique value proposition: outsourced case handling by trained professionals. If your organization does not have internal resources to manage reports, SpeakUp handles it for you. The trade-off is price &amp;amp;mdash; you are paying for human operators, not just software.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;14-whispli--best-for-anonymous-multimedia-reporting&amp;#34;&amp;gt;
14. Whispli &amp;amp;mdash; best for anonymous multimedia reporting
&amp;lt;a href=&amp;#34;#14-whispli--best-for-anonymous-multimedia-reporting&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; Australian-founded platform, expanded into Europe, focused on anonymous two-way communication.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web, voice, and video reporting&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; strong anonymous messaging&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; anonymous two-way messaging, its core strength&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; workflow builder&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Custom, no public numbers. Reports suggest starting around €3,000/year.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Available as an option, not default.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Weeks &amp;amp;mdash; onboarding calls and configuration.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; Whispli&amp;amp;rsquo;s anonymous two-way messaging and multimedia intake (voice, video) are among the best in the category for organisations that prioritise reporter dialogue. The trade-offs for Directive buyers: pricing is not published, EU hosting is an option rather than the default, and the European presence is smaller than EU-native vendors.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;15-eqs-integrity-line--best-for-large-enterprises&amp;#34;&amp;gt;
15. EQS Integrity Line &amp;amp;mdash; best for large enterprises
&amp;lt;a href=&amp;#34;#15-eqs-integrity-line--best-for-large-enterprises&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete.&amp;lt;/strong&amp;gt; The European enterprise standard.&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; 70+ languages&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; enterprise-grade access controls&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; integrates with GRC suites&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Not published. Estimated €2,000+/month. Requires sales process.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Yes.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Weeks.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; If you are a bank, insurer, or listed company with 5,000+ employees, EQS is the safe enterprise choice. For everyone else, you are paying for features and scale you do not need. Implementation takes weeks, not minutes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;16-navex-global--best-for-us-multinationals-with-eu-operations&amp;#34;&amp;gt;
16. NAVEX Global &amp;amp;mdash; best for US multinationals with EU operations
&amp;lt;a href=&amp;#34;#16-navex-global--best-for-us-multinationals-with-eu-operations&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive coverage: complete, but EU compliance feels bolted on.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Directive requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Coverage&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Secure channel (Art. 8)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; web + phone hotline&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;7-day acknowledgment (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;3-month feedback (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Two-way communication (Art. 9)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Record-keeping (Art. 18)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Yes &amp;amp;mdash; strong analytics&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pricing:&amp;lt;/strong&amp;gt; Custom. Typically €5,000+/year. Requires sales process.
&amp;lt;strong&amp;gt;EU hosting:&amp;lt;/strong&amp;gt; Available as an option, not default.
&amp;lt;strong&amp;gt;Setup time:&amp;lt;/strong&amp;gt; Weeks.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Why it ranks here:&amp;lt;/strong&amp;gt; NAVEX is the dominant US compliance platform with decades of history and thousands of clients. Their EthicsPoint product covers the Directive, but the platform was designed for US regulatory frameworks first. EU hosting is available but not the default. Enterprise pricing and long implementation cycles put it out of reach for SMEs.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;which-platform-should-you-choose&amp;#34;&amp;gt;
Which platform should you choose?
&amp;lt;a href=&amp;#34;#which-platform-should-you-choose&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Your situation&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Best choice&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;SME with a defined Directive obligation and limited procurement overhead&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;EthicsPortal&amp;lt;/strong&amp;gt; (€41.67/mo billed annually, operational in minutes)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;German SME, want phone reporting included&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;LegalTegrity&amp;lt;/strong&amp;gt; (€49+/mo, phone on all plans)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;DACH region, want flat pricing with no add-ons&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Vispato&amp;lt;/strong&amp;gt; (€79/mo flat)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Italian company, need local certifications&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;DigitalPA&amp;lt;/strong&amp;gt; (from €29/mo, ISO 27001/37001/37301)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spanish company, need Ley 2/2023 compliance&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;ithikios&amp;lt;/strong&amp;gt; (from €29/mo, ISO 27001)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spanish company, want simple flat pricing&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Canal Etico App&amp;lt;/strong&amp;gt; (€96/mo flat)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;DACH company, want whistleblowing plus broader compliance&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Trusty Compliance&amp;lt;/strong&amp;gt; (from €29/mo, credit-based)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Polish company, want end-to-end encryption&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Sygnanet&amp;lt;/strong&amp;gt; (4,000&amp;amp;ndash;10,000 zł/yr)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Prioritise anonymous voice/video reporting&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Whispli&amp;lt;/strong&amp;gt; (custom, ~€3,000/yr)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Mid-market, want certifications and partner ecosystem&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Formalize&amp;lt;/strong&amp;gt; (custom pricing, ISO certified)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;German-speaking market, need ISO 27001 at scale&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Hintbox&amp;lt;/strong&amp;gt; (€49+/mo, ISO 27001)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Need 113 languages or mobile reporting app&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;FaceUp&amp;lt;/strong&amp;gt; (custom quote)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Nordic company, prefer regional vendor&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;Whistlelink&amp;lt;/strong&amp;gt; (€79+/mo)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Need outsourced case handling&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;SpeakUp&amp;lt;/strong&amp;gt; (~€3,000/yr)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Large enterprise (500+ employees), full GRC suite&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;EQS Integrity Line&amp;lt;/strong&amp;gt; (custom pricing)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;US multinational with EU subsidiary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;NAVEX Global&amp;lt;/strong&amp;gt; (custom pricing)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-pricing-varies-across-platforms&amp;#34;&amp;gt;
Why pricing varies across platforms
&amp;lt;a href=&amp;#34;#why-pricing-varies-across-platforms&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every platform on this list covers the core requirements of Directive 2019/1937. A reporter submits a report. A handler reviews it and responds. The system tracks deadlines and logs an audit trail.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The price difference between €41.67/month billed annually and €5,000+/year is usually explained by scope: enterprise sales, managed services, global hotlines, adjacent GRC modules, advanced analytics, integrations, and procurement support. Some organizations need those capabilities. Others only need the Directive channel.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Many platforms on this list do not publish their pricing. Budget and implementation timelines may require procurement contact before the organization can compare options.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you are evaluating platforms, focus on three things:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Does it cover Art. 8&amp;amp;ndash;18?&amp;lt;/strong&amp;gt; All platforms above do, at their paid tiers.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is data hosted in the EU?&amp;lt;/strong&amp;gt; Non-negotiable for GDPR and Directive compliance.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is the price and activation path clear?&amp;lt;/strong&amp;gt; If pricing is not published, ask what information is needed before a quote can be issued.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;No whistleblower platform can make your organization compliant by itself. Compliance also requires internal policies, designated handlers, training, and documented procedures. The software is the reporting channel &amp;amp;mdash; one piece of a larger compliance framework. It should not be the most expensive or time-consuming piece.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For a detailed article-by-article breakdown of how EthicsPortal meets each requirement, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>What to look for in whistleblower compliance software</title><link>https://ethicsportal.eu/blog/what-to-look-for-in-whistleblower-compliance-software/</link><pubDate>Sun, 05 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/what-to-look-for-in-whistleblower-compliance-software/</guid><description>What a whistleblower reporting tool actually needs to do under EU Directive 2019/1937 — and what features matter vs. what&amp;#39;s just marketing.</description><content:encoded>&amp;lt;h1 id=&amp;#34;what-to-look-for-in-whistleblower-compliance-software&amp;#34;&amp;gt;
What to look for in whistleblower compliance software
&amp;lt;a href=&amp;#34;#what-to-look-for-in-whistleblower-compliance-software&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;The EU Whistleblower Protection Directive requires your organization to operate a secure internal reporting channel. But not all tools that claim Directive compliance actually deliver it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here&amp;amp;rsquo;s how to evaluate what matters.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-a-whistleblower-reporting-tool-actually-needs-to-do&amp;#34;&amp;gt;
What a whistleblower reporting tool actually needs to do
&amp;lt;a href=&amp;#34;#what-a-whistleblower-reporting-tool-actually-needs-to-do&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive&amp;amp;rsquo;s requirements translate into five core functions:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;A reporter submits a report through a secure channel.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The report is stored confidentially in an encrypted system.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;A designated case handler reviews it and responds.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The system tracks the 7-day acknowledgment and 3-month feedback deadlines.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Every action is recorded in an append-only audit trail.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;These five functions are the compliance baseline. Any tool you evaluate should demonstrate how it handles each one.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;features-that-matter-for-compliance&amp;#34;&amp;gt;
Features that matter for compliance
&amp;lt;a href=&amp;#34;#features-that-matter-for-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;When evaluating platforms, focus on what the Directive actually requires:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymous reporting&amp;lt;/strong&amp;gt; — Article 6(1) requires confidentiality. The strongest implementation means no IP logging, no tracking, and automatic stripping of file metadata (EXIF, GPS, author info) that could reveal identity.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Two-way communication&amp;lt;/strong&amp;gt; — Article 9(1)(b) requires follow-up with the reporter. This means secure messaging without requiring the reporter to create an account or reveal their identity.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deadline tracking&amp;lt;/strong&amp;gt; — Articles 9(1)(b) and 9(1)(f) set the 7-day acknowledgment and 3-month feedback deadlines. Automated tracking with notifications prevents compliance failures.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Audit trail&amp;lt;/strong&amp;gt; — Article 18 requires documentation. An append-only log of all actions provides the evidence regulators and auditors expect.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU data residency&amp;lt;/strong&amp;gt; — GDPR applies to all report data. Hosting within the EU simplifies compliance and avoids cross-border transfer questions.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data retention controls&amp;lt;/strong&amp;gt; — Article 17(1)(d) requires defined retention periods. Configurable auto-deletion ensures data isn&amp;amp;rsquo;t kept longer than necessary.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;features-that-sound-impressive-but-arent-in-the-directive&amp;#34;&amp;gt;
Features that sound impressive but aren&amp;amp;rsquo;t in the Directive
&amp;lt;a href=&amp;#34;#features-that-sound-impressive-but-arent-in-the-directive&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Some platforms emphasize capabilities that go beyond what compliance requires:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;AI-powered risk scoring&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Sentiment analysis&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Predictive analytics dashboards&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;amp;ldquo;Benchmarking against 10,000+ organizations&amp;amp;rdquo;&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;These features may serve larger organizations with mature compliance programs. But they are not Directive requirements, and their presence doesn&amp;amp;rsquo;t make a tool more compliant. Evaluate whether they serve your actual needs before paying for them.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;pricing-transparency-as-a-signal&amp;#34;&amp;gt;
Pricing transparency as a signal
&amp;lt;a href=&amp;#34;#pricing-transparency-as-a-signal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive applies to organizations of very different sizes — from 50-person companies to multinational enterprises. The tool you choose should match your scale.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Some platforms publish their pricing openly. Others require a sales process to learn the cost. Neither approach is inherently better, but transparent pricing lets you evaluate fit faster and avoids committing time to demos before knowing whether the budget works.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-to-ask-during-evaluation&amp;#34;&amp;gt;
What to ask during evaluation
&amp;lt;a href=&amp;#34;#what-to-ask-during-evaluation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;When reviewing any whistleblower platform, ask:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Where is data stored?&amp;lt;/strong&amp;gt; Confirm EU hosting and data residency.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;How are reporters protected?&amp;lt;/strong&amp;gt; Verify IP anonymization and metadata stripping.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;How are deadlines tracked?&amp;lt;/strong&amp;gt; Confirm automatic 7-day and 3-month tracking with notifications.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is the audit trail append-only?&amp;lt;/strong&amp;gt; Ensure entries cannot be edited after creation.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;What happens when we cancel?&amp;lt;/strong&amp;gt; Understand data export and deletion policies.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is a DPA available?&amp;lt;/strong&amp;gt; Required for GDPR compliance as a data processor relationship.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-addresses-these-requirements&amp;#34;&amp;gt;
How EthicsPortal addresses these requirements
&amp;lt;a href=&amp;#34;#how-ethicsportal-addresses-these-requirements&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://ethicsportal.eu&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is built specifically for EU Directive 2019/1937 compliance:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;€41.67/month billed annually (€500/year), all features included&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Anonymous reporting with IP anonymization and file metadata stripping&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Secure two-way messaging via access code&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Automatic deadline tracking with overdue notifications&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Append-only audit trail and PDF case export&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Hosted on Hetzner in Nuremberg, Germany — all data stays in the EU&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;See our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
for an article-by-article breakdown of how each requirement is met.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>If employees have to ask where the whistleblowing channel is, you don't have one</title><link>https://ethicsportal.eu/blog/if-employees-have-to-ask-you-dont-have-a-channel/</link><pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/if-employees-have-to-ask-you-dont-have-a-channel/</guid><description>EU law requires employers to inform workers about their reporting channel. But if finding it requires asking someone, the channel is already compromised.</description><content:encoded>&amp;lt;h1 id=&amp;#34;if-employees-have-to-ask-where-the-whistleblowing-channel-is-you-dont-have-one&amp;#34;&amp;gt;
If employees have to ask where the whistleblowing channel is, you don&amp;amp;rsquo;t have one
&amp;lt;a href=&amp;#34;#if-employees-have-to-ask-where-the-whistleblowing-channel-is-you-dont-have-one&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;An employee suspects fraud. They want to report it. Their first step should not be walking up to HR and asking &amp;amp;ldquo;do we have a whistleblowing channel?&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The act of asking is itself a signal. In the exact kind of workplace the Directive exists to address &amp;amp;mdash; where misconduct is happening and someone wants to report it &amp;amp;mdash; asking around about a reporting channel tells people that you are thinking about reporting something. Before you have typed a single word, you are exposed.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-law-is-clear-you-must-inform-employees&amp;#34;&amp;gt;
The law is clear: you must inform employees
&amp;lt;a href=&amp;#34;#the-law-is-clear-you-must-inform-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937 and its national transpositions (&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
in France, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
in Germany, the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
in Poland, and others) do not just require organizations to set up a reporting channel. They require them to make sure workers know about it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Article 9(1)(g)&amp;lt;/strong&amp;gt; mandates &amp;amp;ldquo;clear and easily accessible information&amp;amp;rdquo; about reporting procedures &amp;amp;mdash; both internal and external. This is not optional. If you have a reporting channel but your employees do not know it exists, you are not compliant with your national law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;National transpositions go further:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
§7(3), §13(2)):&amp;lt;/strong&amp;gt; Employers must provide &amp;amp;ldquo;clear and easily accessible information&amp;amp;rdquo; about both internal reporting procedures (§7(3)) and external reporting options (§13(2)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Loi Waserman, 2022-401&amp;lt;/a&amp;gt;
):&amp;lt;/strong&amp;gt; Companies must inform employees about reporting procedures and publish this information via accessible means.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Poland&amp;lt;/a&amp;gt;
(&amp;lt;a href=&amp;#34;https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240000928&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Ustawa o ochronie sygnalistów&amp;lt;/a&amp;gt;
):&amp;lt;/strong&amp;gt; Employers must establish internal reporting procedures and publish them to all employees. The procedure takes effect 7 days after publication.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The pattern is the same everywhere: setting up the channel is half the job. Making employees aware of it is the other half.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-design-problem-nobody-talks-about&amp;#34;&amp;gt;
The design problem nobody talks about
&amp;lt;a href=&amp;#34;#the-design-problem-nobody-talks-about&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Most compliance discussions stop at &amp;amp;ldquo;inform employees&amp;amp;rdquo; and assume a company-wide email or an intranet page solves it. It does not.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Think about what actually happens:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 1: The channel is on the company intranet.&amp;lt;/strong&amp;gt;
The employee has to use their work computer, log into the corporate network, navigate to the compliance section, and click through to the reporting channel. Every step leaves a digital trail on a device their employer controls. The IT department can see what pages you visit on the intranet.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 2: The channel requires a company app.&amp;lt;/strong&amp;gt;
The employee has to download an app, possibly through a corporate MDM (mobile device management) system, and create an account. The act of installing a whistleblower app on your work phone is itself a statement.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Scenario 3: The channel is mentioned once in the employee handbook.&amp;lt;/strong&amp;gt;
Page 47, section 12.3, between the parking policy and the dress code. Nobody remembers it exists. When someone needs it, they have to ask. And asking is the problem.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-easily-accessible-actually-means&amp;#34;&amp;gt;
What &amp;amp;ldquo;easily accessible&amp;amp;rdquo; actually means
&amp;lt;a href=&amp;#34;#what-easily-accessible-actually-means&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you take the Directive&amp;amp;rsquo;s intent seriously &amp;amp;mdash; protecting people who report wrongdoing &amp;amp;mdash; then &amp;amp;ldquo;easily accessible&amp;amp;rdquo; means:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;The employee should be able to access the channel without:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Using a company device&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Being on the company network&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Installing an app&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Creating an account&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Asking anyone where to find it&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Leaving any trace that they looked for it&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This narrows the options considerably. The channel needs to be a &amp;lt;strong&amp;gt;public URL&amp;lt;/strong&amp;gt; that works in any browser on any device &amp;amp;mdash; including a personal phone on mobile data, completely outside the employer&amp;amp;rsquo;s infrastructure.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-to-make-the-channel-truly-accessible&amp;#34;&amp;gt;
How to make the channel truly accessible
&amp;lt;a href=&amp;#34;#how-to-make-the-channel-truly-accessible&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;1. A public URL, not an intranet page.&amp;lt;/strong&amp;gt;
The reporting channel should be accessible from any browser, on any device, without authentication. An employee at home, on their personal phone, at 11pm, should be able to type in a URL and start a report. No VPN, no login, no company email required.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;2. QR codes in private spaces.&amp;lt;/strong&amp;gt;
Print the QR code and put it where people can scan it without being watched: bathroom stalls, break rooms, locker rooms, the back of elevator doors. An employee scanning a QR code on a bathroom wall leaves no digital trail and draws no attention.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;3. Physical posters, not just emails.&amp;lt;/strong&amp;gt;
A company-wide email about the whistleblowing channel is easily missed and hard to find six months later. A poster on the wall of every office kitchen with a QR code and a URL is always there when someone needs it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;4. Mention it during onboarding &amp;amp;mdash; every time.&amp;lt;/strong&amp;gt;
New employee orientation should include the reporting channel URL and a printed card with the QR code. Not buried in a handbook. Handed to them directly.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;5. No account required.&amp;lt;/strong&amp;gt;
If the reporting tool requires the employee to create an account with their email address to file a report, it is not anonymous and it is not safe. The reporter should be able to submit without providing any identifying information and receive an access code to check back later.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;this-is-how-ethicsportal-works&amp;#34;&amp;gt;
This is how EthicsPortal works
&amp;lt;a href=&amp;#34;#this-is-how-ethicsportal-works&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every EthicsPortal organization gets a public reporting URL. It works on any browser, any device. No app, no account, no company network.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The portal generates a &amp;lt;strong&amp;gt;QR code&amp;lt;/strong&amp;gt; that can be printed and posted anywhere. Scan it, and you are on the reporting page. No login, no trail.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Reporters submit anonymously &amp;amp;mdash; no name, no email, no IP logging. They receive an access code to check back for updates. The entire interaction happens in a browser window that can be closed and leaves nothing behind.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The handler never sees the reporter&amp;amp;rsquo;s identity. The reporter never sees the handler&amp;amp;rsquo;s name. The system counts to 7 days, counts to 3 months, and logs everything.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is what &amp;amp;ldquo;easily accessible&amp;amp;rdquo; looks like when you take the Directive seriously.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;If your organization&amp;amp;rsquo;s whistleblowing channel requires employees to ask someone where to find it, you have a compliance checkbox. You do not have a reporting channel. &amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Set up a real one in ten minutes.&amp;lt;/a&amp;gt;
&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>GDPR and whistleblower reporting: what you need to know</title><link>https://ethicsportal.eu/blog/gdpr-and-whistleblower-reporting/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/gdpr-and-whistleblower-reporting/</guid><description>How GDPR applies to whistleblower reports. Legal basis for processing, anonymous vs. pseudonymous data, retention periods, and the right to erasure.</description><content:encoded>&amp;lt;h1 id=&amp;#34;gdpr-and-whistleblower-reporting-what-you-need-to-know&amp;#34;&amp;gt;
GDPR and whistleblower reporting: what you need to know
&amp;lt;a href=&amp;#34;#gdpr-and-whistleblower-reporting-what-you-need-to-know&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every whistleblower report contains personal data. The reporter may include their name. The report will likely name the person accused of wrongdoing. The handler&amp;amp;rsquo;s actions are logged. All of this is personal data under GDPR.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This creates a tension that compliance officers deal with every day: the Whistleblower Directive (2019/1937) requires you to collect and store reports, and GDPR requires you to have a lawful basis for doing so, minimize what you collect, and delete it when you no longer need it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is how the two frameworks interact, and what it means in practice.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-personal-data-does-a-whistleblower-report-contain&amp;#34;&amp;gt;
What personal data does a whistleblower report contain?
&amp;lt;a href=&amp;#34;#what-personal-data-does-a-whistleblower-report-contain&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;More than you might think:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Data&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;GDPR category&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;amp;rsquo;s name (if provided)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Voluntary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;amp;rsquo;s contact details (if provided)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Voluntary&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Name of the accused person&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Report content&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data (third party)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Details of the alleged misconduct&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Report content&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;May include special category data (Art. 9) or criminal offence data (Art. 10)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Uploaded files (documents, photos)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Reporter&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;May contain metadata (GPS, author, timestamps)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Handler actions and notes&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Case management&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data (handler)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Timestamps and audit trail&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;System&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Personal data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;If a report describes harassment, discrimination, or health issues, it may contain &amp;lt;strong&amp;gt;special category data&amp;lt;/strong&amp;gt; under GDPR Article 9 &amp;amp;mdash; which triggers stricter processing conditions. Reports involving criminal allegations fall under &amp;lt;strong&amp;gt;Article 10&amp;lt;/strong&amp;gt; (criminal convictions and offences), which has its own restrictions.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-is-the-legal-basis-for-processing&amp;#34;&amp;gt;
What is the legal basis for processing?
&amp;lt;a href=&amp;#34;#what-is-the-legal-basis-for-processing&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;You need a lawful basis under GDPR Article 6 to process personal data in whistleblower reports. The most commonly used bases:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61c--legal-obligation&amp;#34;&amp;gt;
Article 6(1)(c) &amp;amp;mdash; Legal obligation
&amp;lt;a href=&amp;#34;#article-61c--legal-obligation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This is the primary basis. EU Directive 2019/1937 and its national transpositions impose a legal obligation to operate a reporting channel. Processing personal data is necessary to comply with that obligation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This covers:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Receiving the report&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Storing it securely&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Investigating the allegations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Communicating with the reporter&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Maintaining an audit trail&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61f--legitimate-interest&amp;#34;&amp;gt;
Article 6(1)(f) &amp;amp;mdash; Legitimate interest
&amp;lt;a href=&amp;#34;#article-61f--legitimate-interest&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Some organizations use legitimate interest as a secondary basis, particularly for processing that goes beyond the Directive&amp;amp;rsquo;s minimum requirements (e.g., internal analysis, trend reporting). This requires a legitimate interest assessment (LIA) and balancing test.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;article-61e--public-interest-public-sector&amp;#34;&amp;gt;
Article 6(1)(e) &amp;amp;mdash; Public interest (public sector)
&amp;lt;a href=&amp;#34;#article-61e--public-interest-public-sector&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Public sector organizations may rely on the public interest basis, particularly where national law explicitly authorizes processing for whistleblower protection.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;what-about-consent&amp;#34;&amp;gt;
What about consent?
&amp;lt;a href=&amp;#34;#what-about-consent&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Do not rely on consent.&amp;lt;/strong&amp;gt; The reporter-employer power imbalance means consent is unlikely to be freely given (GDPR Recital 43). A reporter cannot meaningfully consent when their job may depend on the outcome. Use legal obligation (Art. 6(1)(c)) instead.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;anonymous-reports-and-gdpr&amp;#34;&amp;gt;
Anonymous reports and GDPR
&amp;lt;a href=&amp;#34;#anonymous-reports-and-gdpr&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This is the question compliance officers ask most: if a report is truly anonymous, does GDPR apply?&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;if-the-reporter-is-unidentifiable-gdpr-does-not-apply-to-them&amp;#34;&amp;gt;
If the reporter is unidentifiable: GDPR does not apply to them
&amp;lt;a href=&amp;#34;#if-the-reporter-is-unidentifiable-gdpr-does-not-apply-to-them&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;GDPR applies to personal data relating to an identified or identifiable person (Art. 4(1)). If a reporter submits without providing a name, email, or any identifying information &amp;amp;mdash; and the system does not log their IP address or any other identifier &amp;amp;mdash; the report content is not personal data &amp;lt;em&amp;gt;with respect to the reporter&amp;lt;/em&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;However:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;The &amp;lt;strong&amp;gt;accused person&amp;lt;/strong&amp;gt; named in the report is still identifiable. GDPR fully applies to their data.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;If the report content contains details that could indirectly identify the reporter (&amp;amp;ldquo;I am the only woman on the third floor&amp;amp;rdquo;), it may still constitute personal data.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;what-anonymous-requires-technically&amp;#34;&amp;gt;
What &amp;amp;ldquo;anonymous&amp;amp;rdquo; requires technically
&amp;lt;a href=&amp;#34;#what-anonymous-requires-technically&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;For anonymity to hold up under GDPR scrutiny, your reporting tool must:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not log IP addresses.&amp;lt;/strong&amp;gt; Any IP logging makes the reporter pseudonymous, not anonymous.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not require an account or email.&amp;lt;/strong&amp;gt; If the reporter authenticates, they are identifiable.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Strip file metadata.&amp;lt;/strong&amp;gt; Uploaded photos and documents contain EXIF data (GPS coordinates, author name, device information) that can identify the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Not use analytics or tracking cookies&amp;lt;/strong&amp;gt; on the reporting channel.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;If your tool does any of these things, you are collecting pseudonymous data, not anonymous data, and GDPR applies in full.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;data-minimization-art-51c&amp;#34;&amp;gt;
Data minimization (Art. 5(1)(c))
&amp;lt;a href=&amp;#34;#data-minimization-art-51c&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive requires a reporting channel. It does not require collecting more data than necessary.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In practice:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reporter identity must be optional.&amp;lt;/strong&amp;gt; The reporter should be able to submit without providing their name or contact details.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Intake forms should collect only what is needed.&amp;lt;/strong&amp;gt; A description of the misconduct, the category, and optional supporting files. Do not require department, employee ID, or other identifiers unless the reporter chooses to provide them.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Handler notes should be relevant to the investigation.&amp;lt;/strong&amp;gt; Do not log extraneous personal details about the reporter or accused.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-accused-persons-rights&amp;#34;&amp;gt;
The accused person&amp;amp;rsquo;s rights
&amp;lt;a href=&amp;#34;#the-accused-persons-rights&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This is where it gets complicated. The person accused in a whistleblower report has GDPR rights &amp;amp;mdash; including the right to be informed (Art. 14), the right of access (Art. 15), and the right to erasure (Art. 17).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;But exercising those rights cannot compromise the reporter&amp;amp;rsquo;s confidentiality (Directive Art. 16).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;right-to-be-informed-art-14&amp;#34;&amp;gt;
Right to be informed (Art. 14)
&amp;lt;a href=&amp;#34;#right-to-be-informed-art-14&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Under GDPR, you must inform people when you process their data. But Directive Art. 16(1) requires protecting the reporter&amp;amp;rsquo;s identity. The solution:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;You &amp;lt;strong&amp;gt;may&amp;lt;/strong&amp;gt; inform the accused person that a report has been made &amp;amp;mdash; but only when doing so does not risk identifying the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Timing matters.&amp;lt;/strong&amp;gt; Many member states allow delaying notification until it would no longer jeopardize the investigation. Germany&amp;amp;rsquo;s HinSchG explicitly restricts disclosure during the investigation period.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;National data protection authorities generally accept that the Directive&amp;amp;rsquo;s confidentiality requirements override the immediate notification obligation.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;right-of-access-art-15&amp;#34;&amp;gt;
Right of access (Art. 15)
&amp;lt;a href=&amp;#34;#right-of-access-art-15&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The accused person can request access to data held about them. You must provide it &amp;amp;mdash; but you must redact any information that would identify the reporter. This includes the reporter&amp;amp;rsquo;s name, but also contextual details that could reveal them indirectly.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;right-to-erasure-art-17&amp;#34;&amp;gt;
Right to erasure (Art. 17)
&amp;lt;a href=&amp;#34;#right-to-erasure-art-17&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The accused person cannot demand deletion of a report that is part of an ongoing investigation or that must be retained under legal obligations. GDPR Art. 17(3)(b) and (e) provide exceptions for legal obligations and legal claims.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;retention-periods&amp;#34;&amp;gt;
Retention periods
&amp;lt;a href=&amp;#34;#retention-periods&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive (Art. 18) requires maintaining records of reports. GDPR (Art. 5(1)(e)) requires not keeping personal data longer than necessary.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;how-long-should-you-retain-reports&amp;#34;&amp;gt;
How long should you retain reports?
&amp;lt;a href=&amp;#34;#how-long-should-you-retain-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive does not prescribe a specific retention period. National transpositions vary:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Country&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Retention period&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;5 years after case closure&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000046357368&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Decree 2022-1284&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;5 years from date of report&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;D.Lgs. 24/2023, Art. 14&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;3 years after case closure (unless ongoing proceedings)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG §11&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Spain&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Not specified (general GDPR minimization applies)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;h3 id=&amp;#34;best-practice&amp;#34;&amp;gt;
Best practice
&amp;lt;a href=&amp;#34;#best-practice&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Set a configurable retention period (e.g., 12, 24, 36, 48, or 60 months after case closure).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Automatically delete closed cases when the retention period expires.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Allow manual deletion by admins for cases where retention is no longer necessary.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Document your retention policy and be prepared to justify it to a regulator.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;international-data-transfers&amp;#34;&amp;gt;
International data transfers
&amp;lt;a href=&amp;#34;#international-data-transfers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Whistleblower data must stay in the EU unless you have a valid transfer mechanism under GDPR Chapter V.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This matters when choosing a reporting tool:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU-hosted platforms&amp;lt;/strong&amp;gt; (data stored in Germany, France, Netherlands, etc.): no transfer issue.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;US-hosted platforms&amp;lt;/strong&amp;gt; or platforms using US cloud providers (AWS US, Azure US, Google Cloud US): require reliance on Standard Contractual Clauses (SCCs) or the &amp;lt;a href=&amp;#34;https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU-US Data Privacy Framework&amp;lt;/a&amp;gt;
&amp;amp;mdash; both of which have been &amp;lt;a href=&amp;#34;https://curia.europa.eu/juris/liste.jsf?num=C-311/18&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;legally challenged&amp;lt;/a&amp;gt;
.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The simplest path: choose a platform that hosts all data in the EU. This eliminates the transfer question entirely.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;data-protection-impact-assessment-dpia&amp;#34;&amp;gt;
Data Protection Impact Assessment (DPIA)
&amp;lt;a href=&amp;#34;#data-protection-impact-assessment-dpia&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;GDPR Article 35 requires a DPIA when processing is &amp;amp;ldquo;likely to result in a high risk to the rights and freedoms of natural persons.&amp;amp;rdquo;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Whistleblower reporting likely qualifies because:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;It involves sensitive allegations about identified individuals&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reports may contain special category data (Art. 9)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;There is an inherent power imbalance between reporter and organization&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Confidentiality failures could lead to retaliation&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Most data protection authorities recommend conducting a DPIA before implementing a whistleblower reporting system.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-your-reporting-tool-must-do&amp;#34;&amp;gt;
What your reporting tool must do
&amp;lt;a href=&amp;#34;#what-your-reporting-tool-must-do&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Based on the GDPR requirements above, your whistleblower software should:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Why&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Optional reporter identity&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Data minimization (Art. 5(1)(c))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;No IP logging&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Preserve anonymity, avoid creating pseudonymous data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;File metadata stripping&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Prevent accidental identification via EXIF/GPS data&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Encryption at rest&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Integrity and confidentiality (Art. 5(1)(f))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Configurable retention periods&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Storage limitation (Art. 5(1)(e))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Automatic deletion of expired cases&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Storage limitation enforcement&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Role-based access controls&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Confidentiality (Directive Art. 16)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Append-only audit trail&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Accountability (Art. 5(2))&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;EU data hosting&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Avoid international transfer complications (Chapter V)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Privacy notice on the reporting form&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Transparency (Art. 13/14)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-handles-gdpr&amp;#34;&amp;gt;
How EthicsPortal handles GDPR
&amp;lt;a href=&amp;#34;#how-ethicsportal-handles-gdpr&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal was designed with both the Directive and GDPR as constraints from day one:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Legal basis:&amp;lt;/strong&amp;gt; Processing is based on legal obligation (Art. 6(1)(c)) &amp;amp;mdash; compliance with EU Directive 2019/1937.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymity by default:&amp;lt;/strong&amp;gt; No IP logging, no accounts, no tracking. File metadata (EXIF, GPS, author) stripped automatically.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data minimization:&amp;lt;/strong&amp;gt; Reporter name and contact are optional fields. Only essential data is collected.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Encryption at rest:&amp;lt;/strong&amp;gt; All report descriptions, names, contact details, and messages encrypted in the database.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Configurable retention:&amp;lt;/strong&amp;gt; Organizations set their own retention period (12, 24, 36, 48, or 60 months). Expired closed cases are deleted automatically.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EU hosting for core report data:&amp;lt;/strong&amp;gt; Report content and attachments are stored on Hetzner servers in Nuremberg, Germany. The marketing site is delivered via Cloudflare (CDN, United States); the reporting and handler portals are not. Transfer safeguards for the marketing site are documented in the published subprocessor list and DPA.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Access controls:&amp;lt;/strong&amp;gt; Only admins and assigned handlers can view reports. Handler names are never revealed to reporters.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Audit trail:&amp;lt;/strong&amp;gt; Append-only log of every action for accountability and regulatory review.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;DPA available:&amp;lt;/strong&amp;gt; GDPR Article 28 &amp;lt;a href=&amp;#34;/dpa/&amp;#34;&amp;gt;Data Processing Agreement&amp;lt;/a&amp;gt;
available for all customers.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;For the full article-by-article breakdown, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Free whistleblower policy template for EU Directive 2019/1937</title><link>https://ethicsportal.eu/blog/whistleblower-policy-template/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/whistleblower-policy-template/</guid><description>A ready-to-use whistleblower policy template that meets EU Directive 2019/1937 requirements. Copy, adapt, and implement in your organization.</description><content:encoded>&amp;lt;h1 id=&amp;#34;free-whistleblower-policy-template-for-eu-directive-20191937&amp;#34;&amp;gt;
Free whistleblower policy template for EU Directive 2019/1937
&amp;lt;a href=&amp;#34;#free-whistleblower-policy-template-for-eu-directive-20191937&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every organization with 50 or more employees in the EU needs a written whistleblower policy. This is not optional &amp;amp;mdash; it is required under national transposition laws like &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland), all implementing EU Directive 2019/1937. Penalties for non-compliance vary by country &amp;amp;mdash; see our &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties page&amp;lt;/a&amp;gt;
for details.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A whistleblower policy does two things: it tells employees how to report wrongdoing, and it tells your organization how to handle those reports. Without a clear policy, reports fall through the cracks, handlers improvise, and your organization risks both legal exposure and reputational damage.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Below is a complete policy template you can copy and adapt. Replace the bracketed placeholders with your organization&amp;amp;rsquo;s details. The template covers every element the Directive requires.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;whistleblower-policy-template&amp;#34;&amp;gt;
Whistleblower policy template
&amp;lt;a href=&amp;#34;#whistleblower-policy-template&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;[ORGANIZATION NAME]&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Whistleblower protection policy&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Effective date:&amp;lt;/strong&amp;gt; [DATE]&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Approved by:&amp;lt;/strong&amp;gt; [NAME / TITLE]&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Version:&amp;lt;/strong&amp;gt; 1.0&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;1-purpose-and-scope&amp;#34;&amp;gt;
1. Purpose and scope
&amp;lt;a href=&amp;#34;#1-purpose-and-scope&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This policy establishes a framework for reporting suspected breaches of law, regulation, or internal rules within [ORGANIZATION NAME]. It implements the requirements of EU Directive 2019/1937 on the protection of persons who report breaches of Union law, as transposed into [MEMBER STATE] national law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This policy applies to all operations, subsidiaries, and business units of [ORGANIZATION NAME] within the European Union.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;2-who-can-report&amp;#34;&amp;gt;
2. Who can report
&amp;lt;a href=&amp;#34;#2-who-can-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;In accordance with Article 4 of the Directive, the following persons may submit a report through the channels described in this policy:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Current and former employees, including those on probation or notice periods&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Job applicants who obtained information during the recruitment process&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Contractors, subcontractors, and suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Shareholders and members of the administrative, management, or supervisory body&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Volunteers and trainees, whether paid or unpaid&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Any person working under the supervision and direction of contractors, subcontractors, or suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Persons whose work-based relationship has not yet begun, where information on breaches was acquired during the recruitment process or pre-contractual negotiations&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Protection also extends to facilitators, third persons connected with the reporting person (such as colleagues or relatives), and legal entities that the reporting person owns, works for, or is otherwise connected with in a work-related context (Article 4(4)).&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;3-what-can-be-reported&amp;#34;&amp;gt;
3. What can be reported
&amp;lt;a href=&amp;#34;#3-what-can-be-reported&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports may concern breaches of Union law in the areas covered by the Directive (Article 2), including but not limited to:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Public procurement irregularities&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Financial services, anti-money laundering, and counter-terrorist financing violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Product safety and compliance breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Transport safety violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Environmental protection breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Radiation protection and nuclear safety issues&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Food and feed safety, animal health and welfare concerns&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Public health violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Consumer protection breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Privacy and personal data protection violations&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Security of network and information systems&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Competition and state aid rule breaches&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Corporate tax arrangements that undermine the object or purpose of applicable tax law&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Fraud, corruption, or other criminal offenses affecting the financial interests of the EU&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Reports may also concern breaches of internal company policies, codes of conduct, and applicable national law, provided [MEMBER STATE] national transposition law extends protection to such reports.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;4-how-to-report&amp;#34;&amp;gt;
4. How to report
&amp;lt;a href=&amp;#34;#4-how-to-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;h4 id=&amp;#34;internal-reporting-channel&amp;#34;&amp;gt;
Internal reporting channel
&amp;lt;a href=&amp;#34;#internal-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] provides a secure, confidential internal reporting channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Online form:&amp;lt;/strong&amp;gt; [URL OF REPORTING FORM]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designated person:&amp;lt;/strong&amp;gt; [NAME / TITLE OF DESIGNATED PERSON OR DEPARTMENT]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Alternative methods:&amp;lt;/strong&amp;gt; [POSTAL ADDRESS / EMAIL / IN-PERSON MEETING REQUEST PROCESS, as applicable]&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Reports can be submitted anonymously. Reporters who choose to remain anonymous will receive an access code to check the status of their report and communicate securely with the case handler.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] encourages the use of the internal reporting channel as a first step, as this allows the organization to investigate and address breaches promptly.&amp;lt;/p&amp;gt;
&amp;lt;h4 id=&amp;#34;external-reporting-to-competent-authorities&amp;#34;&amp;gt;
External reporting to competent authorities
&amp;lt;a href=&amp;#34;#external-reporting-to-competent-authorities&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;Reporting persons have the right to report externally to the relevant competent authority at any time, as provided under Article 10 of the Directive. Reporting persons are not required to use the internal channel before reporting externally.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The competent authority in [MEMBER STATE] is: [NAME AND CONTACT DETAILS OF NATIONAL AUTHORITY].&amp;lt;/p&amp;gt;
&amp;lt;h4 id=&amp;#34;public-disclosure&amp;#34;&amp;gt;
Public disclosure
&amp;lt;a href=&amp;#34;#public-disclosure&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h4&amp;gt;
&amp;lt;p&amp;gt;In exceptional circumstances defined in Article 15 of the Directive, reporting persons may make a public disclosure and still receive protection &amp;amp;mdash; for example, where they have reasonable grounds to believe that the breach constitutes an imminent or manifest danger to the public interest, or where there is a risk of retaliation.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;5-confidentiality&amp;#34;&amp;gt;
5. Confidentiality
&amp;lt;a href=&amp;#34;#5-confidentiality&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person will not be disclosed to anyone beyond the authorized staff members competent to receive or follow up on reports, without the explicit consent of the reporting person (Article 16).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This confidentiality obligation applies to all information from which the identity of the reporting person may be directly or indirectly deduced.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person may only be disclosed where this is a necessary and proportionate obligation imposed under Union or national law in the context of investigations by national authorities or judicial proceedings, including with a view to safeguarding the rights of defense of the person concerned.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Any person who discloses the identity of a reporting person in violation of this policy will be subject to disciplinary action.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;6-prohibition-of-retaliation&amp;#34;&amp;gt;
6. Prohibition of retaliation
&amp;lt;a href=&amp;#34;#6-prohibition-of-retaliation&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] strictly prohibits any form of retaliation against reporting persons, in accordance with Articles 19 to 21 of the Directive. Retaliation includes, but is not limited to:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Suspension, dismissal, or equivalent measures&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Demotion, withholding of promotion, or change of duties or work location&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reduction of wages or changes to working hours&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Withholding of training&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Negative performance assessment or employment reference&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Coercion, intimidation, harassment, or ostracism&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Discrimination or unfavorable treatment&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Failure to convert a temporary employment contract into a permanent one&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Non-renewal or early termination of a temporary employment contract&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Harm, including to reputation or financial loss&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Blacklisting&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Early termination or cancellation of a contract for goods or services&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Cancellation of a license or permit&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Psychiatric or medical referrals&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The burden of proof in retaliation proceedings is reversed: where a reporting person establishes that they made a report and subsequently suffered a detriment, it is presumed that the detriment was made in retaliation. The person who took the detrimental action must prove it was based on duly justified grounds unrelated to the report (Article 21(5)).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Any employee found to have engaged in retaliation will be subject to disciplinary action, up to and including termination.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;7-investigation-process&amp;#34;&amp;gt;
7. Investigation process
&amp;lt;a href=&amp;#34;#7-investigation-process&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Upon receipt of a report, [ORGANIZATION NAME] will:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Acknowledge receipt&amp;lt;/strong&amp;gt; within seven calendar days of receiving the report (Article 9(1)(b)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Assess the report&amp;lt;/strong&amp;gt; to determine whether it falls within the scope of this policy and warrants investigation.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Investigate diligently&amp;lt;/strong&amp;gt; by gathering relevant information, interviewing witnesses as necessary, and reviewing documents, while maintaining confidentiality throughout.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Provide feedback&amp;lt;/strong&amp;gt; to the reporting person within three months of acknowledgment. Feedback will include information on the status of the investigation and, where possible, the outcome and any measures taken or envisaged (Article 9(1)(f)).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Close the case&amp;lt;/strong&amp;gt; with documented findings and, where appropriate, recommend corrective actions, disciplinary measures, or referral to competent authorities.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;Where a report is assessed as falling outside the scope of this policy, the reporting person will be informed and, where appropriate, redirected to the relevant procedure.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;8-data-protection&amp;#34;&amp;gt;
8. Data protection
&amp;lt;a href=&amp;#34;#8-data-protection&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports and all related data will be processed in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection law.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Personal data that is manifestly not relevant to the handling of a specific report will not be collected or, if accidentally collected, will be deleted without undue delay (Article 17(3)).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Report data will be retained for no longer than is necessary and proportionate to comply with the requirements of this policy and applicable law. [ORGANIZATION NAME] will define and document specific retention periods in accordance with national transposition law.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;9-training-and-awareness&amp;#34;&amp;gt;
9. Training and awareness
&amp;lt;a href=&amp;#34;#9-training-and-awareness&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;[ORGANIZATION NAME] will:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Train all designated case handlers on their obligations under this policy and applicable law&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Inform all employees and other persons covered by Section 2 about the availability and use of the internal reporting channel&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Make this policy easily accessible, including on the company intranet and as part of the onboarding process for new employees&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;10-review&amp;#34;&amp;gt;
10. Review
&amp;lt;a href=&amp;#34;#10-review&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;This policy will be reviewed at least annually and updated as necessary to reflect changes in applicable law, organizational structure, or best practices.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;11-contact&amp;#34;&amp;gt;
11. Contact
&amp;lt;a href=&amp;#34;#11-contact&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;For questions about this policy or the reporting channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designated person:&amp;lt;/strong&amp;gt; [NAME / TITLE]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Email:&amp;lt;/strong&amp;gt; [EMAIL ADDRESS]&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Online reporting form:&amp;lt;/strong&amp;gt; [URL]&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;End of policy document.&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;using-this-template&amp;#34;&amp;gt;
Using this template
&amp;lt;a href=&amp;#34;#using-this-template&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Copy the text above into your company&amp;amp;rsquo;s document format, replace every bracketed placeholder, and have it reviewed by your legal team. The template covers the requirements of Directive 2019/1937, but national transposition laws in your member state may impose additional obligations &amp;amp;mdash; check with local counsel.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Once your policy is in place, you need a technical channel to receive reports. &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
provides a secure internal reporting channel that meets the Directive&amp;amp;rsquo;s requirements, starting at €41.67/month billed annually.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Who must comply with the EU Whistleblower Directive?</title><link>https://ethicsportal.eu/blog/who-must-comply-eu-whistleblower-directive/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/who-must-comply-eu-whistleblower-directive/</guid><description>Which companies need a whistleblowing channel under EU Directive 2019/1937? The 50-employee threshold, who counts as a worker, deadlines, and what &amp;#34;comply&amp;#34; actually means in practice.</description><content:encoded>&amp;lt;h1 id=&amp;#34;who-must-comply-with-the-eu-whistleblower-directive&amp;#34;&amp;gt;
Who must comply with the EU Whistleblower Directive?
&amp;lt;a href=&amp;#34;#who-must-comply-with-the-eu-whistleblower-directive&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Short answer: if your organization has 50 or more employees and operates in the EU, you almost certainly need an internal reporting channel. This is not optional. It is law in all 27 EU member states.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is everything you need to know to determine whether you must comply, what compliance actually requires, and what happens if you do not.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-threshold-50-employees&amp;#34;&amp;gt;
The threshold: 50 employees
&amp;lt;a href=&amp;#34;#the-threshold-50-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937, Article 8(3)-(4), establishes the obligation:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;250+ employees:&amp;lt;/strong&amp;gt; Must have had an internal reporting channel since December 17, 2021 (the original transposition deadline per &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Art. 26(1)&amp;lt;/a&amp;gt;
).&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;50&amp;amp;ndash;249 employees:&amp;lt;/strong&amp;gt; Must have had an internal reporting channel since December 17, 2023 (extended deadline per &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L1937&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Art. 26(2)&amp;lt;/a&amp;gt;
).&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;If you have 50 or more employees in the EU, the deadline has already passed. You should have a channel in place now.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;how-employees-are-counted&amp;#34;&amp;gt;
How employees are counted
&amp;lt;a href=&amp;#34;#how-employees-are-counted&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive does not define &amp;amp;ldquo;employee&amp;amp;rdquo; narrowly. Member states count:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Full-time and part-time employees (part-time may be counted proportionally in some countries)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Fixed-term and temporary workers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;In some member states: posted workers, trainees, and apprentices&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The count is based on your legal entity, not your group. If you are part of a corporate group, each entity with 50+ employees needs its own channel &amp;amp;mdash; though entities of 50&amp;amp;ndash;249 employees may share resources for receiving and investigating reports (Art. 8(6)).&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;who-is-covered-beyond-headcount&amp;#34;&amp;gt;
Who is covered beyond headcount
&amp;lt;a href=&amp;#34;#who-is-covered-beyond-headcount&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Several categories of organizations must comply regardless of employee count:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;financial-services-art-84&amp;#34;&amp;gt;
&amp;lt;a href=&amp;#34;/industries/financial-services/&amp;#34;&amp;gt;Financial services&amp;lt;/a&amp;gt;
(Art. 8(4))
&amp;lt;a href=&amp;#34;#financial-services-art-84&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;All entities operating in financial services &amp;amp;mdash; banks, investment firms, insurance companies, payment institutions, crypto-asset providers &amp;amp;mdash; must have a reporting channel irrespective of size. This applies even if you have 5 employees. The Directive defers to the sector-specific EU legislation listed in Part I.B and Part II of the Annex.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;public-sector-art-89&amp;#34;&amp;gt;
&amp;lt;a href=&amp;#34;/industries/public-sector/&amp;#34;&amp;gt;Public sector&amp;lt;/a&amp;gt;
(Art. 8(9))
&amp;lt;a href=&amp;#34;#public-sector-art-89&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Member states may require municipalities and other public bodies to establish internal channels. Many have done so, often with lower thresholds or no threshold at all.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;national-extensions&amp;#34;&amp;gt;
National extensions
&amp;lt;a href=&amp;#34;#national-extensions&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Some member states go beyond the Directive&amp;amp;rsquo;s minimum:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; Organizations with a &amp;amp;ldquo;Model 231&amp;amp;rdquo; compliance program must comply regardless of size. &amp;lt;a href=&amp;#34;https://www.nortonrosefulbright.com/en-it/knowledge/publications/5ff4d59b/whistleblowing-i-nuovi-obblighi-per-le-imprese&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Source: Norton Rose Fulbright&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/belgium/&amp;#34;&amp;gt;Belgium&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; Companies with 250+ employees must accept anonymous reports (stricter than the Directive&amp;amp;rsquo;s baseline). &amp;lt;a href=&amp;#34;https://www.vow.be/en/node/358&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Source: Van Olmen &amp;amp;amp; Wynant&amp;lt;/a&amp;gt;
&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
:&amp;lt;/strong&amp;gt; The &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Loi Waserman (2022-401)&amp;lt;/a&amp;gt;
transposing the Directive removed the requirement to use internal channels before going to external authorities &amp;amp;mdash; reporters can now choose either path. &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/loda/id/JORFTEXT000033558528&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Sapin II&amp;amp;rsquo;s&amp;lt;/a&amp;gt;
broader anti-corruption compliance obligations (separate from the reporting channel) still apply to companies with 500+ employees and €100M+ revenue.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;who-can-report&amp;#34;&amp;gt;
Who can report
&amp;lt;a href=&amp;#34;#who-can-report&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The Directive protects a broad category of &amp;amp;ldquo;reporting persons&amp;amp;rdquo; &amp;amp;mdash; not just employees. Under Article 4, the following people are protected when they report through your channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Workers&amp;lt;/strong&amp;gt; (employees, civil servants, interns, trainees)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Self-employed persons&amp;lt;/strong&amp;gt; (contractors, freelancers)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Shareholders and board members&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Volunteers&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Suppliers and their workers&amp;lt;/strong&amp;gt; (anyone in your supply chain)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Job applicants&amp;lt;/strong&amp;gt; (people who learned of wrongdoing during the recruitment process)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Former workers&amp;lt;/strong&amp;gt; (people who learned of wrongdoing during a previous employment)&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Your reporting channel must be accessible to all of these groups, not just current employees.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-compliance-actually-requires&amp;#34;&amp;gt;
What compliance actually requires
&amp;lt;a href=&amp;#34;#what-compliance-actually-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Having a channel means meeting the requirements in Articles 8, 9, and 16 of the Directive. Here is the minimum:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;1-a-secure-internal-reporting-channel-art-8&amp;#34;&amp;gt;
1. A secure internal reporting channel (Art. 8)
&amp;lt;a href=&amp;#34;#1-a-secure-internal-reporting-channel-art-8&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;An internal channel that allows reporting in writing (and optionally orally). It must:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Be accessible to all persons covered by the Directive (employees, contractors, suppliers, etc.)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Protect the confidentiality of the reporter&amp;amp;rsquo;s identity&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Not require the reporter to identify themselves (anonymous reporting is permitted in most member states)&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;2-a-documented-procedure-art-9&amp;#34;&amp;gt;
2. A documented procedure (Art. 9)
&amp;lt;a href=&amp;#34;#2-a-documented-procedure-art-9&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The channel must follow a defined procedure:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Requirement&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Deadline&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Article&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Acknowledge receipt of the report&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Within 7 days&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(b)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Assign an impartial person or department to handle it&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Upon receipt&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(a)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Follow up diligently&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Ongoing&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(c)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Provide feedback to the reporter&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Within 3 months&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(f)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Inform the reporter of external reporting options&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;At submission&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Art. 9(1)(g)&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;h3 id=&amp;#34;3-confidentiality-protections-art-16&amp;#34;&amp;gt;
3. Confidentiality protections (Art. 16)
&amp;lt;a href=&amp;#34;#3-confidentiality-protections-art-16&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity must not be disclosed to anyone beyond the staff handling the report, without the reporter&amp;amp;rsquo;s explicit consent. This means:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Access controls: only authorized handlers see reports&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;No IP logging or tracking that could identify anonymous reporters&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Data encrypted at rest&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;4-record-keeping-art-18&amp;#34;&amp;gt;
4. Record-keeping (Art. 18)
&amp;lt;a href=&amp;#34;#4-record-keeping-art-18&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Reports must be stored securely and retained in compliance with national law. You need an audit trail that can demonstrate compliance to regulators.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;5-anti-retaliation-measures-art-1921&amp;#34;&amp;gt;
5. Anti-retaliation measures (Art. 19&amp;amp;ndash;21)
&amp;lt;a href=&amp;#34;#5-anti-retaliation-measures-art-1921&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;You must not retaliate against reporters. This includes dismissal, demotion, withholding promotion, changing duties, or any other form of disadvantage. Reporters must be informed of this protection.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-does-not-count-as-compliance&amp;#34;&amp;gt;
What does NOT count as compliance
&amp;lt;a href=&amp;#34;#what-does-not-count-as-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Some things organizations try that do not meet the Directive&amp;amp;rsquo;s requirements:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A generic email address&amp;lt;/strong&amp;gt; (e.g., &amp;lt;a href=&amp;#34;mailto:compliance@company.com&amp;#34;&amp;gt;compliance@company.com&amp;lt;/a&amp;gt;
). This does not protect confidentiality, does not track deadlines, and does not create an audit trail.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;An anonymous suggestion box.&amp;lt;/strong&amp;gt; No two-way communication, no acknowledgment, no feedback mechanism.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A page in the employee handbook.&amp;lt;/strong&amp;gt; The channel must be operational, not just documented.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;A third-party hotline with no case management.&amp;lt;/strong&amp;gt; If reports come in by phone but are not tracked through a system with deadlines and audit trails, you are not compliant with Art. 9.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-happens-if-you-do-not-comply&amp;#34;&amp;gt;
What happens if you do not comply
&amp;lt;a href=&amp;#34;#what-happens-if-you-do-not-comply&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Every member state has defined penalties. They vary widely:&amp;lt;/p&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;thead&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;th&amp;gt;Country&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Penalty for no reporting channel&amp;lt;/th&amp;gt;
&amp;lt;th&amp;gt;Source&amp;lt;/th&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/thead&amp;gt;
&amp;lt;tbody&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Spain&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Up to €1,000,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Law 2/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Belgium&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€24,000&amp;amp;ndash;€576,000 + up to 3 years prison&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://cms.law/en/int/expert-guides/whistleblower-protection-and-reporting-channels/belgium&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;CMS Expert Guide&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Germany&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€20,000&amp;amp;ndash;€500,000 (legal entities)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/hinschg/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;HinSchG §40&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Italy&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;€10,000&amp;amp;ndash;€50,000&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;D.Lgs. 24/2023&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr&amp;gt;
&amp;lt;td&amp;gt;Poland&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;Up to PLN 1,080,000 (~€250,000)&amp;lt;/td&amp;gt;
&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20240000928&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;/tbody&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;p&amp;gt;Enforcement is not theoretical. In March 2025, the &amp;lt;a href=&amp;#34;https://curia.europa.eu/site/upload/docs/application/pdf/2025-03/cp250029en.pdf&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU Court of Justice fined five member states a combined €38.9 million&amp;lt;/a&amp;gt;
for being late to transpose the Directive. National enforcement authorities are now operational in most countries and actively issuing fines.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;See our full &amp;lt;a href=&amp;#34;/penalties/&amp;#34;&amp;gt;penalties by country&amp;lt;/a&amp;gt;
page for all 27 member states.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-fastest-path-to-compliance&amp;#34;&amp;gt;
The fastest path to compliance
&amp;lt;a href=&amp;#34;#the-fastest-path-to-compliance&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If your organization has 50+ employees, the deadline has passed. Here is how to get compliant:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deploy a reporting channel.&amp;lt;/strong&amp;gt; &amp;lt;a href=&amp;#34;https://secure.ethicsportal.eu/session/new&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
provides portal configuration, secure intake, deadline tracking, and audit exports at €41.67/month billed annually.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Designate a handler.&amp;lt;/strong&amp;gt; Assign at least one impartial person to receive and investigate reports.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Inform employees.&amp;lt;/strong&amp;gt; Share the reporting channel URL and QR code via posters, onboarding materials, and internal communications.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Document your procedure.&amp;lt;/strong&amp;gt; Adopt an internal whistleblower protection policy that describes the process, deadlines, and anti-retaliation protections.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;The technical channel can be deployed quickly. The organizational steps — handler designation, policy, training, and internal communication — take longer but are straightforward.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;For an article-by-article breakdown of how EthicsPortal meets the Directive&amp;amp;rsquo;s requirements, see our &amp;lt;a href=&amp;#34;/directive-coverage/&amp;#34;&amp;gt;Directive 2019/1937 coverage map&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>Anonymous vs. confidential whistleblower reporting: what's the difference?</title><link>https://ethicsportal.eu/blog/anonymous-vs-confidential-reporting/</link><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/anonymous-vs-confidential-reporting/</guid><description>Understand the difference between anonymous and confidential whistleblower reporting, what the EU Directive requires, and how to support both.</description><content:encoded>&amp;lt;h1 id=&amp;#34;anonymous-vs-confidential-whistleblower-reporting-whats-the-difference&amp;#34;&amp;gt;
Anonymous vs. confidential whistleblower reporting: what&amp;amp;rsquo;s the difference?
&amp;lt;a href=&amp;#34;#anonymous-vs-confidential-whistleblower-reporting-whats-the-difference&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Compliance officers frequently use &amp;amp;ldquo;anonymous&amp;amp;rdquo; and &amp;amp;ldquo;confidential&amp;amp;rdquo; interchangeably when discussing whistleblower reporting. They are not the same thing, and the distinction matters &amp;amp;mdash; both legally and practically.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Getting this wrong can undermine trust in your reporting channel, expose your organization to liability, or make investigations harder than they need to be. Here is what each term means, what the EU Directive says, and how to handle both in practice.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;definitions&amp;#34;&amp;gt;
Definitions
&amp;lt;a href=&amp;#34;#definitions&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;anonymous-reporting&amp;#34;&amp;gt;
Anonymous reporting
&amp;lt;a href=&amp;#34;#anonymous-reporting&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity is unknown to everyone, including the case handler. The organization receives the report but has no way to determine who submitted it. The reporter does not provide their name, email, or any identifying information.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;True anonymity means that even if the organization wanted to identify the reporter, it could not &amp;amp;mdash; the system is designed to prevent it.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;confidential-reporting&amp;#34;&amp;gt;
Confidential reporting
&amp;lt;a href=&amp;#34;#confidential-reporting&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The reporter&amp;amp;rsquo;s identity is known to the case handler (or a limited number of authorized persons), but it is protected from disclosure to anyone else. The handler knows who made the report but is legally and organizationally obligated not to reveal that identity.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Confidentiality is a promise backed by legal protections. Anonymous reporting removes the need for that promise entirely.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-eu-directive-says&amp;#34;&amp;gt;
What the EU Directive says
&amp;lt;a href=&amp;#34;#what-the-eu-directive-says&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EU Directive 2019/1937 addresses both concepts, though it gives member states flexibility on anonymous reporting.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Confidentiality (Article 16):&amp;lt;/strong&amp;gt; The Directive is unambiguous here. The identity of the reporting person must not be disclosed to anyone beyond authorized staff without the reporter&amp;amp;rsquo;s explicit consent. This applies to all reports, whether the reporter identifies themselves or not. Confidentiality is mandatory.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Anonymous reporting (Article 6(2&amp;amp;ndash;3), Recital 34):&amp;lt;/strong&amp;gt; The Directive does not require member states to accept anonymous reports through internal channels. However, it explicitly states that member states &amp;lt;em&amp;gt;may&amp;lt;/em&amp;gt; decide to allow or require anonymous reporting. Where anonymous reports are accepted, they must be handled with the same diligence as identified reports.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;In practice, the majority of member states that have transposed the Directive now require or strongly encourage anonymous reporting. &amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000045388745&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
, and several others mandate it. Even where it is not legally required, allowing anonymity is considered best practice because it increases reporting rates.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Member states differ on how far the protection extends, too. &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Poland&amp;amp;rsquo;s 2024 act&amp;lt;/a&amp;gt;
accepts anonymous reports but, under Article 7(3), excludes anonymous reporters from procedural protections that identified reporters receive &amp;amp;mdash; acknowledgment of receipt, feedback on the outcome, and the certificate of whistleblower status. The lesson for organizations: accepting anonymous reports is the floor, not the ceiling &amp;amp;mdash; how you handle them afterward is what reporters actually experience.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Two-way communication (Article 9(1)(b)):&amp;lt;/strong&amp;gt; The Directive requires that reporting channels allow communication with the reporter, including providing acknowledgment and feedback. For anonymous reporters, this means the channel must support two-way messaging without requiring identity disclosure &amp;amp;mdash; typically through an access code or case reference number.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;pros-and-cons&amp;#34;&amp;gt;
Pros and cons
&amp;lt;a href=&amp;#34;#pros-and-cons&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;anonymous-reporting-1&amp;#34;&amp;gt;
Anonymous reporting
&amp;lt;a href=&amp;#34;#anonymous-reporting-1&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pros:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Removes the fear barrier entirely &amp;amp;mdash; reporters do not risk being identified&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Higher reporting rates, especially for sensitive issues like fraud by senior management&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Protects reporters even if the organization&amp;amp;rsquo;s confidentiality measures fail&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Builds trust in the reporting channel&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Cons:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Follow-up is harder &amp;amp;mdash; the handler cannot call the reporter for clarification unless two-way messaging is available&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Risk of lower-quality reports if the reporter knows they cannot be contacted&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Some organizations worry about frivolous or malicious reports (in practice, the &amp;lt;a href=&amp;#34;https://www.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE Report to the Nations&amp;lt;/a&amp;gt;
and &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=SWD:2018:0116:FIN&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;EU Commission impact assessment&amp;lt;/a&amp;gt;
found this is rare)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Investigation may be more difficult without knowing the reporter&amp;amp;rsquo;s vantage point&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;confidential-reporting-1&amp;#34;&amp;gt;
Confidential reporting
&amp;lt;a href=&amp;#34;#confidential-reporting-1&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Pros:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Easier follow-up &amp;amp;mdash; the handler can contact the reporter directly for additional information&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The reporter&amp;amp;rsquo;s perspective and role can help focus the investigation&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Reports tend to be more detailed when the reporter knows they can be contacted&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The handler can assess credibility more easily&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Cons:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Requires the reporter to trust that confidentiality will be maintained&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;A single data breach, careless email, or unauthorized access can expose the reporter&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Some reporters will not use the channel if identification is required&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The organization bears the legal risk of maintaining confidentiality&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This failure mode is not hypothetical. In its first annual whistleblower report &amp;amp;mdash; covering 27 December 2024 to 31 December 2025 &amp;amp;mdash; Poland&amp;amp;rsquo;s Commissioner for Human Rights documented cases at the University of Szczecin and the Pilecki Institute where a government ministry forwarded a confidential reporter&amp;amp;rsquo;s identity to the very people they had reported, allegedly triggering retaliation in one case and a dismissal in the other. Confidentiality held by a third party can be broken by that third party. Anonymous reporting removes the failure mode entirely.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-anonymous-reporting-works-in-practice&amp;#34;&amp;gt;
How anonymous reporting works in practice
&amp;lt;a href=&amp;#34;#how-anonymous-reporting-works-in-practice&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Anonymous reporting does not mean the reporter submits a message into a void and never hears back. Modern whistleblower platforms solve the communication problem with access codes.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is how it typically works:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter submits a report&amp;lt;/strong&amp;gt; through the portal without entering any personal information.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The system generates a unique access code&amp;lt;/strong&amp;gt; (or case reference number) and displays it to the reporter.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter saves the access code.&amp;lt;/strong&amp;gt; This is their key to the case.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The case handler reviews the report&amp;lt;/strong&amp;gt; and can post follow-up questions or status updates to the case.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;The reporter returns to the portal&amp;lt;/strong&amp;gt;, enters the access code, and sees any messages from the handler. They can reply, provide additional documents, or answer questions &amp;amp;mdash; all without revealing who they are.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;This approach satisfies the Directive&amp;amp;rsquo;s two-way communication requirement while preserving anonymity. The handler gets the information they need for the investigation; the reporter stays protected.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The access code model also supports the seven-day acknowledgment and three-month feedback requirements, because the reporter can check the portal at any time to see if acknowledgment or feedback has been provided.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-offering-both-options-is-the-right-approach&amp;#34;&amp;gt;
Why offering both options is the right approach
&amp;lt;a href=&amp;#34;#why-offering-both-options-is-the-right-approach&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The strongest reporting channels give reporters the choice: submit anonymously, or provide your identity with the assurance of confidentiality.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Here is why:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Different situations call for different approaches.&amp;lt;/strong&amp;gt; A junior employee reporting a senior executive&amp;amp;rsquo;s fraud may choose anonymity. A department head flagging a safety issue may prefer to identify themselves so the investigation can move faster.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Choice builds trust.&amp;lt;/strong&amp;gt; When reporters see that anonymity is genuinely available, they trust the channel more &amp;amp;mdash; even the ones who ultimately choose to identify themselves.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Legal coverage.&amp;lt;/strong&amp;gt; In member states that require anonymous reporting, you are compliant. In those that do not, you exceed the minimum standard.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Better reporting rates.&amp;lt;/strong&amp;gt; The &amp;lt;a href=&amp;#34;https://www.acfe.com/report-to-the-nations/2024/&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;ACFE Report to the Nations (2024)&amp;lt;/a&amp;gt;
found that tips are the most common fraud detection method (43% of cases), and anonymous hotlines significantly increase tip volume.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The EU Directive&amp;amp;rsquo;s own recitals acknowledge this: allowing anonymous reporting &amp;lt;em&amp;gt;encourages&amp;lt;/em&amp;gt; reporting and makes channels more effective.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;how-ethicsportal-handles-this&amp;#34;&amp;gt;
How EthicsPortal handles this
&amp;lt;a href=&amp;#34;#how-ethicsportal-handles-this&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal supports both anonymous and confidential reporting:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anonymous by default.&amp;lt;/strong&amp;gt; Reporters are never required to provide their identity. No name, no email, no account.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Optional identity disclosure.&amp;lt;/strong&amp;gt; Reporters can choose to share their name or contact information if they want to. This is entirely voluntary.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Access code messaging.&amp;lt;/strong&amp;gt; Every report generates a unique access code. The reporter uses it to check for updates and communicate with the case handler, without revealing who they are.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality enforced.&amp;lt;/strong&amp;gt; When a reporter does share their identity, access controls ensure only designated case handlers can see it.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;This gives reporters full control over their level of exposure, while giving case handlers the tools they need to investigate effectively.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-bottom-line&amp;#34;&amp;gt;
The bottom line
&amp;lt;a href=&amp;#34;#the-bottom-line&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Anonymous means the handler does not know who you are. Confidential means the handler knows but is legally bound not to tell anyone else. Both serve the goal of protecting reporters, but they do so differently.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The EU Directive mandates confidentiality. It leaves anonymous reporting to member states, most of which now require or recommend it. The safest approach &amp;amp;mdash; for your reporters and your compliance posture &amp;amp;mdash; is to offer both.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>How to deploy an internal reporting channel</title><link>https://ethicsportal.eu/blog/how-to-implement-whistleblower-channel/</link><pubDate>Sun, 01 Feb 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/how-to-implement-whistleblower-channel/</guid><description>A step-by-step guide to deploying a compliant internal reporting channel without adopting a broad enterprise GRC suite.</description><content:encoded>&amp;lt;h1 id=&amp;#34;how-to-deploy-an-internal-reporting-channel&amp;#34;&amp;gt;
How to deploy an internal reporting channel
&amp;lt;a href=&amp;#34;#how-to-deploy-an-internal-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;Every EU member state now requires organizations with 50 or more employees to operate an internal reporting channel &amp;amp;mdash; through national laws like &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland), all transposing EU Directive 2019/1937. The requirement is clear, but most implementations take far longer than they should.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This guide explains what the law actually requires from the channel itself, why broad enterprise tools can slow deployment, and what a compliant channel needs before it is put into operation.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-directive-requires&amp;#34;&amp;gt;
What the Directive requires
&amp;lt;a href=&amp;#34;#what-the-directive-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Article 8 and Article 9 specify what an internal reporting channel must do:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Accept reports in writing or orally&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Allow anonymous reporting (required in some member states, strongly recommended everywhere)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Enable two-way communication with the reporter, even if they are anonymous&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Ensure only authorized persons can access reports&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Acknowledge receipt within seven calendar days&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Provide feedback within three months&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;That is the legal minimum. No specific technology is mandated &amp;amp;mdash; the Directive is technology-neutral. A web portal, a phone line, or even a locked physical mailbox can qualify, as long as the requirements above are met.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;why-most-implementations-take-weeks&amp;#34;&amp;gt;
Why most implementations take weeks
&amp;lt;a href=&amp;#34;#why-most-implementations-take-weeks&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Enterprise whistleblower platforms are designed for large organizations with complex procurement processes. A typical implementation looks like this:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Request a vendor presentation&amp;lt;/strong&amp;gt; &amp;amp;mdash; fill out a form and wait for a sales representative to call back&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attend the presentation&amp;lt;/strong&amp;gt; &amp;amp;mdash; a 30&amp;amp;ndash;60 minute call where the vendor walks through features you may not need&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Receive a proposal&amp;lt;/strong&amp;gt; &amp;amp;mdash; custom pricing based on employee count, modules, and add-ons&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Negotiate the contract&amp;lt;/strong&amp;gt; &amp;amp;mdash; legal review, DPA signing, procurement approval&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Onboarding kickoff&amp;lt;/strong&amp;gt; &amp;amp;mdash; a project manager is assigned, another call is scheduled&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Configuration&amp;lt;/strong&amp;gt; &amp;amp;mdash; the vendor configures your reporting channel, categories, and branding (or trains you to do it)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Testing and launch&amp;lt;/strong&amp;gt; &amp;amp;mdash; review, approve, and go live&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;For a 100-person company that just needs a compliant channel, this process is weeks of elapsed time and hours of meetings. It is designed for enterprises where a six-week procurement cycle is normal. For an SME, it is friction that delays compliance.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;operational-in-minutes-with-ethicsportal&amp;#34;&amp;gt;
Operational in minutes with EthicsPortal
&amp;lt;a href=&amp;#34;#operational-in-minutes-with-ethicsportal&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;EthicsPortal is built for a narrower scenario: your organization needs a compliant Directive channel without a broader GRC implementation.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-1-activate-the-reporting-channel&amp;#34;&amp;gt;
Step 1: Activate the reporting channel
&amp;lt;a href=&amp;#34;#step-1-activate-the-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Go to &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;ethicsportal.eu&amp;lt;/a&amp;gt;
, create the organization account, choose a plan, and enter the portal administration area.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-2-configure-your-reporting-channel&amp;#34;&amp;gt;
Step 2: Configure your reporting channel
&amp;lt;a href=&amp;#34;#step-2-configure-your-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;From the dashboard, set up your reporting channel:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Organization name&amp;lt;/strong&amp;gt; &amp;amp;mdash; appears on the portal so reporters know they are in the right place&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Report categories&amp;lt;/strong&amp;gt; &amp;amp;mdash; define what types of issues can be reported (fraud, harassment, safety violations, etc.). Sensible defaults are provided.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Welcome text&amp;lt;/strong&amp;gt; &amp;amp;mdash; the message reporters see when they land on the portal. A clear, reassuring default is pre-filled.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Logo&amp;lt;/strong&amp;gt; &amp;amp;mdash; match your organization&amp;amp;rsquo;s visual identity&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Language&amp;lt;/strong&amp;gt; &amp;amp;mdash; choose the portal language for your reporters&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;The portal has a unique URL as soon as you save the configuration.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;step-3-share-the-reporting-channel-with-employees&amp;#34;&amp;gt;
Step 3: Share the reporting channel with employees
&amp;lt;a href=&amp;#34;#step-3-share-the-reporting-channel-with-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Every reporting channel gets a shareable link and a QR code. You can:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Email the link to all employees&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Print the QR code and post it in break rooms, offices, or common areas&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Add the link to your intranet or employee handbook&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Include it in your written whistleblower policy&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h3 id=&amp;#34;step-4-start-receiving-and-managing-reports&amp;#34;&amp;gt;
Step 4: Start receiving and managing reports
&amp;lt;a href=&amp;#34;#step-4-start-receiving-and-managing-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;When someone submits a report through the portal, you receive a notification. From the dashboard, you can:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Read the report&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Communicate with the reporter via secure two-way messaging (even if they are anonymous &amp;amp;mdash; they use an access code)&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Track the seven-day acknowledgment deadline&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Track the three-month feedback deadline&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Update the case status and add internal notes&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Close the case with a documented outcome&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;At this point, the internal reporting channel is configured and ready to receive reports.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;what-to-do-after-setup&amp;#34;&amp;gt;
What to do after setup
&amp;lt;a href=&amp;#34;#what-to-do-after-setup&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;An internal reporting channel is the technical foundation, but compliance requires organizational steps too:&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;designate-a-case-handler&amp;#34;&amp;gt;
Designate a case handler
&amp;lt;a href=&amp;#34;#designate-a-case-handler&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Appoint one or more persons to receive and investigate reports. This person should be impartial and not likely to be the subject of reports. A compliance officer, legal counsel, or senior HR person typically fills this role. For small organizations, the managing director can serve as handler.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;train-your-handlers&amp;#34;&amp;gt;
Train your handlers
&amp;lt;a href=&amp;#34;#train-your-handlers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Case handlers need to understand: how to use the platform, confidentiality obligations, the seven-day and three-month deadlines, basics of conducting an internal investigation, and anti-retaliation rules.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;write-a-whistleblower-policy&amp;#34;&amp;gt;
Write a whistleblower policy
&amp;lt;a href=&amp;#34;#write-a-whistleblower-policy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Document how your organization handles reports. Cover scope, who can report, confidentiality, anti-retaliation, and the investigation process. See our &amp;lt;a href=&amp;#34;/blog/whistleblower-policy-template/&amp;#34;&amp;gt;free policy template&amp;lt;/a&amp;gt;
for a ready-to-use document.&amp;lt;/p&amp;gt;
&amp;lt;h3 id=&amp;#34;inform-employees&amp;#34;&amp;gt;
Inform employees
&amp;lt;a href=&amp;#34;#inform-employees&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The Directive requires you to proactively tell employees about the channel. Send an email, post on the intranet, mention it in team meetings, and include it in onboarding. The QR code makes this easy &amp;amp;mdash; print it and put it where people will see it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;common-mistakes-to-avoid&amp;#34;&amp;gt;
Common mistakes to avoid
&amp;lt;a href=&amp;#34;#common-mistakes-to-avoid&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Using a generic email address.&amp;lt;/strong&amp;gt; An email like &amp;lt;a href=&amp;#34;mailto:compliance@company.com&amp;#34;&amp;gt;compliance@company.com&amp;lt;/a&amp;gt;
does not meet the Directive&amp;amp;rsquo;s requirements in most cases. Email lacks encryption, does not support anonymous reporting, and does not provide two-way communication with anonymous reporters.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Requiring reporters to identify themselves.&amp;lt;/strong&amp;gt; While the Directive does not uniformly require anonymous reporting, several national laws do (e.g., &amp;lt;a href=&amp;#34;/whistleblower-laws/belgium/&amp;#34;&amp;gt;Belgium&amp;lt;/a&amp;gt;
mandates anonymous reporting for companies with 250+ employees). Making identification mandatory discourages reporting. Allow anonymity by default.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Forgetting the deadlines.&amp;lt;/strong&amp;gt; Seven days for acknowledgment, three months for feedback. These are not suggestions &amp;amp;mdash; they are legal requirements. Missing them is a compliance failure. Use a system that tracks these deadlines automatically.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Not designating a handler.&amp;lt;/strong&amp;gt; The channel is a mailbox. Someone needs to open it, read the reports, and act on them. If no one is designated, reports go unanswered and deadlines pass.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Over-engineering the setup.&amp;lt;/strong&amp;gt; You do not need a full GRC suite, custom integrations, or a six-month rollout to comply. A working channel with anonymous reporting, two-way communication, and deadline tracking covers the legal requirements. Start simple, add complexity only if you need it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;deploy-the-channel&amp;#34;&amp;gt;
Deploy the channel
&amp;lt;a href=&amp;#34;#deploy-the-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
is €41.67/month billed annually with no per-employee pricing. Deploy the internal reporting channel, assign handlers, publish the link, and keep the focus on protecting the people who speak up.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>EU whistleblower directive compliance checklist for companies</title><link>https://ethicsportal.eu/blog/compliance-checklist/</link><pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/compliance-checklist/</guid><description>A practical 12-step checklist to comply with EU Directive 2019/1937 and national transposition laws, with article references, tips, and implementation guidance.</description><content:encoded>&amp;lt;h1 id=&amp;#34;eu-whistleblower-directive-compliance-checklist-for-companies&amp;#34;&amp;gt;
EU whistleblower directive compliance checklist for companies
&amp;lt;a href=&amp;#34;#eu-whistleblower-directive-compliance-checklist-for-companies&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;All 27 EU member states have transposed EU Directive 2019/1937 into national law &amp;amp;mdash; including &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;Loi Waserman&amp;lt;/a&amp;gt;
(France), &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;HinSchG&amp;lt;/a&amp;gt;
(Germany), &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Ley 2/2023&amp;lt;/a&amp;gt;
(Spain), &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;D.Lgs. 24/2023&amp;lt;/a&amp;gt;
(Italy), and the &amp;lt;a href=&amp;#34;/whistleblower-laws/poland/&amp;#34;&amp;gt;Act of 14 June 2024&amp;lt;/a&amp;gt;
(Poland). Your organization must comply with the national law in your country of operation, and enforcement is active.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This checklist walks you through the twelve steps to full compliance. For each item, we cite the relevant Directive article, share practical tips, and note where tooling can help. See our &amp;lt;a href=&amp;#34;/whistleblower-laws/&amp;#34;&amp;gt;whistleblower laws by country&amp;lt;/a&amp;gt;
reference for your country&amp;amp;rsquo;s specific requirements.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;the-checklist&amp;#34;&amp;gt;
The checklist
&amp;lt;a href=&amp;#34;#the-checklist&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;h3 id=&amp;#34;1-determine-if-your-organization-is-in-scope&amp;#34;&amp;gt;
1. Determine if your organization is in scope
&amp;lt;a href=&amp;#34;#1-determine-if-your-organization-is-in-scope&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 8(3&amp;amp;ndash;4)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;All legal entities in the private sector with 50 or more workers must establish internal reporting channels. &amp;lt;a href=&amp;#34;/industries/public-sector/&amp;#34;&amp;gt;Public sector&amp;lt;/a&amp;gt;
entities, municipalities, and entities in certain regulated sectors (&amp;lt;a href=&amp;#34;/industries/financial-services/&amp;#34;&amp;gt;financial services&amp;lt;/a&amp;gt;
, aviation safety, maritime, etc.) are in scope regardless of size.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Count all workers, not just full-time employees. Part-time staff, contractors working on-site, and temporary agency workers may count toward the threshold depending on your national law. Some countries go further &amp;amp;mdash; &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
requires a channel for all companies with a Model 231 compliance program regardless of size, and &amp;lt;a href=&amp;#34;/whistleblower-laws/spain/&amp;#34;&amp;gt;Spain&amp;lt;/a&amp;gt;
covers all public entities.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;2-establish-an-internal-reporting-channel&amp;#34;&amp;gt;
2. Establish an internal reporting channel
&amp;lt;a href=&amp;#34;#2-establish-an-internal-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 8(1), Article 9(1)(a)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The channel must allow reporting in writing (online form, email, postal) or orally (phone, voice messaging system), or both. On request, it must also allow in-person meetings within a reasonable timeframe.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; A web-based portal is the most practical option &amp;amp;mdash; it is accessible 24/7, creates an automatic record, and supports anonymous two-way communication. Avoid using generic email addresses; they lack encryption, anonymity, and audit trails.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Provides a branded web portal with encrypted anonymous reporting and two-way messaging.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;3-designate-an-impartial-person-or-department-to-handle-reports&amp;#34;&amp;gt;
3. Designate an impartial person or department to handle reports
&amp;lt;a href=&amp;#34;#3-designate-an-impartial-person-or-department-to-handle-reports&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(c)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must designate a person or department competent to follow up on reports. This person must be impartial &amp;amp;mdash; they should not have a conflict of interest with the subject matter of reports.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Common choices include a compliance officer, a legal counsel, an HR director, or an external ombudsperson. For smaller organizations, the managing director can serve this role if they are not likely to be the subject of reports. Consider designating a backup handler.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;4-set-up-the-acknowledgment-process-7-day-deadline&amp;#34;&amp;gt;
4. Set up the acknowledgment process (7-day deadline)
&amp;lt;a href=&amp;#34;#4-set-up-the-acknowledgment-process-7-day-deadline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(b)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must acknowledge receipt of a report within seven calendar days. This applies to all reports, including anonymous ones.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Automate this. A manual process risks missing the seven-day window during holidays or absences.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Tracks the acknowledgment deadline for each report and shows case handlers which reports need attention.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;5-define-the-feedback-process-3-month-deadline&amp;#34;&amp;gt;
5. Define the feedback process (3-month deadline)
&amp;lt;a href=&amp;#34;#5-define-the-feedback-process-3-month-deadline&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(f)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must provide feedback to the reporting person within three months of the acknowledgment. Feedback includes: whether the report is being assessed, is under investigation, or has been closed, and the outcome of any investigation.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; &amp;amp;ldquo;Feedback&amp;amp;rdquo; does not require disclosing the full investigation outcome. Informing the reporter that the matter was investigated and appropriate action was taken is sufficient. For anonymous reporters, feedback must be available through the reporting channel (for example, via an access code).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Tracks the three-month feedback deadline per case and supports two-way messaging with anonymous reporters via access codes.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;6-implement-confidentiality-measures&amp;#34;&amp;gt;
6. Implement confidentiality measures
&amp;lt;a href=&amp;#34;#6-implement-confidentiality-measures&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 16&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The identity of the reporting person must not be disclosed to anyone beyond authorized case handlers without the reporter&amp;amp;rsquo;s explicit consent. This also covers information from which the reporter&amp;amp;rsquo;s identity could be indirectly deduced.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Limit access to reports strictly. Do not share report details in meetings where unauthorized persons are present. When referring cases internally, redact identifying information about the reporter. Ensure your IT systems enforce access controls.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Role-based access ensures only designated case handlers can view reports. Reporter identity is never exposed unless the reporter voluntarily shares it.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;7-establish-anti-retaliation-protections&amp;#34;&amp;gt;
7. Establish anti-retaliation protections
&amp;lt;a href=&amp;#34;#7-establish-anti-retaliation-protections&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Articles 19, 20, 21&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Reporting persons, facilitators, and connected third parties must be protected from retaliation. The Directive defines retaliation broadly: dismissal, demotion, intimidation, blacklisting, and more. The burden of proof is reversed &amp;amp;mdash; if a reporter suffers a detriment after reporting, the employer must prove the detriment was unrelated to the report.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Document this protection in your whistleblower policy. Train managers on what constitutes retaliation. Track personnel actions involving anyone who has made a report, so you can demonstrate that decisions were made on legitimate grounds.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;8-train-case-handlers&amp;#34;&amp;gt;
8. Train case handlers
&amp;lt;a href=&amp;#34;#8-train-case-handlers&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(c&amp;amp;ndash;f) (implied)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Directive does not prescribe specific training, but case handlers must be competent to fulfill the obligations it creates: maintaining confidentiality, providing acknowledgment within seven days, conducting diligent follow-up, and providing feedback within three months.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; At a minimum, train case handlers on: how to use the reporting channel, confidentiality obligations, investigation basics, anti-retaliation rules, and data protection. Document the training. Refresh annually.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;9-inform-employees-about-the-reporting-channel&amp;#34;&amp;gt;
9. Inform employees about the reporting channel
&amp;lt;a href=&amp;#34;#9-inform-employees-about-the-reporting-channel&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 9(1)(g)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;You must provide clear and easily accessible information about how to use the internal reporting channel. You must also inform employees about their right to report externally to competent authorities.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Publish the information on your intranet, include it in onboarding materials, and display it in common areas. A QR code linking to the reporting channel is an effective way to make the channel discoverable.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;How EthicsPortal helps:&amp;lt;/strong&amp;gt; Generates a QR code and shareable link for your portal that you can print and distribute.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;10-set-up-data-retention-and-deletion&amp;#34;&amp;gt;
10. Set up data retention and deletion
&amp;lt;a href=&amp;#34;#10-set-up-data-retention-and-deletion&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 17(1&amp;amp;ndash;3)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Personal data in reports must not be kept longer than necessary. Data that is manifestly not relevant must be deleted promptly. Specific retention periods depend on your member state&amp;amp;rsquo;s law, but the principle is: retain as long as needed for the investigation and any resulting proceedings, then delete.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Define a retention period in your policy. National laws vary &amp;amp;mdash; for example, &amp;lt;a href=&amp;#34;/whistleblower-laws/france/&amp;#34;&amp;gt;France&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000046357368&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 5 years&amp;lt;/a&amp;gt;
, &amp;lt;a href=&amp;#34;/whistleblower-laws/germany/&amp;#34;&amp;gt;Germany&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.gesetze-im-internet.de/englisch_hinschg/englisch_hinschg.html&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 3 years&amp;lt;/a&amp;gt;
(HinSchG §11), and &amp;lt;a href=&amp;#34;/whistleblower-laws/italy/&amp;#34;&amp;gt;Italy&amp;lt;/a&amp;gt;
&amp;lt;a href=&amp;#34;https://www.gazzettaufficiale.it/eli/id/2023/03/15/23G00032/sg&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;requires 5 years&amp;lt;/a&amp;gt;
(D.Lgs. 24/2023). See our &amp;lt;a href=&amp;#34;/blog/gdpr-and-whistleblower-reporting/&amp;#34;&amp;gt;GDPR and whistleblower reporting guide&amp;lt;/a&amp;gt;
for a full comparison. Set calendar reminders to review and delete closed cases.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;11-prepare-a-written-whistleblower-policy&amp;#34;&amp;gt;
11. Prepare a written whistleblower policy
&amp;lt;a href=&amp;#34;#11-prepare-a-written-whistleblower-policy&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Articles 8, 9 (implied), plus most national transposition laws&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;While the Directive does not explicitly mandate a standalone policy document, most national transposition laws do, and it is practically necessary to fulfill the information obligations in Article 9(1)(g).&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Your policy should cover: scope, who can report, what can be reported, how to report, confidentiality, anti-retaliation, investigation process, feedback timelines, and data protection. See our &amp;lt;a href=&amp;#34;/blog/whistleblower-policy-template/&amp;#34;&amp;gt;free whistleblower policy template&amp;lt;/a&amp;gt;
for a ready-to-use document.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h3 id=&amp;#34;12-document-compliance-for-regulatory-review&amp;#34;&amp;gt;
12. Document compliance for regulatory review
&amp;lt;a href=&amp;#34;#12-document-compliance-for-regulatory-review&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Directive reference:&amp;lt;/strong&amp;gt; Article 11(2) (external channels), national transposition laws (internal)&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Several member states require organizations to document that they have fulfilled their obligations and to make this documentation available to regulators on request.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Practical tip:&amp;lt;/strong&amp;gt; Keep records of: when the reporting channel was established, who the designated case handlers are, training records, the whistleblower policy (with version history), and aggregate statistics on reports received and handled. Do not store individual case details longer than your retention period allows.&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;next-steps&amp;#34;&amp;gt;
Next steps
&amp;lt;a href=&amp;#34;#next-steps&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you have checked every box above, your organization is compliant with the core requirements of the Directive and its national transposition. Compliance is not a one-time event &amp;amp;mdash; review your setup annually, retrain handlers, and update your policy as national law evolves. Check our &amp;lt;a href=&amp;#34;/whistleblower-laws/&amp;#34;&amp;gt;whistleblower laws by country&amp;lt;/a&amp;gt;
reference for country-specific requirements that may go beyond the Directive&amp;amp;rsquo;s baseline.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Need a reporting channel? &amp;lt;a href=&amp;#34;/&amp;#34;&amp;gt;EthicsPortal&amp;lt;/a&amp;gt;
provides a compliant anonymous reporting channel at €41.67/month billed annually, with no per-employee pricing. &amp;lt;a href=&amp;#34;/pricing/&amp;#34;&amp;gt;Deploy your reporting channel&amp;lt;/a&amp;gt;
.&amp;lt;/p&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item><item><title>EU Directive 2019/1937 on whistleblower protection adopted</title><link>https://ethicsportal.eu/blog/eu-whistleblower-directive-2019-1937-adopted/</link><pubDate>Wed, 23 Oct 2019 00:00:00 +0000</pubDate><guid>https://ethicsportal.eu/blog/eu-whistleblower-directive-2019-1937-adopted/</guid><description>The European Parliament and the Council formally adopt Directive (EU) 2019/1937, establishing EU-wide protection for persons who report breaches of Union law.</description><content:encoded>&amp;lt;h1 id=&amp;#34;eu-directive-20191937-on-whistleblower-protection-adopted&amp;#34;&amp;gt;
EU Directive 2019/1937 on whistleblower protection adopted
&amp;lt;a href=&amp;#34;#eu-directive-20191937-on-whistleblower-protection-adopted&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h1&amp;gt;
&amp;lt;p&amp;gt;On 23 October 2019, the European Parliament and the Council formally adopted &amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/eli/dir/2019/1937/oj/eng&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Directive (EU) 2019/1937&amp;lt;/a&amp;gt;
on the protection of persons who report breaches of Union law. The plenary vote passed with 591 votes in favour, 29 against, and 33 abstentions.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The Directive requires every organization with 50 or more employees to establish secure internal reporting channels, protect reporters from retaliation, and provide feedback within three months. Member states had until 17 December 2021 to transpose it into national law.&amp;lt;/p&amp;gt;
&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/video/protecting-democracy-by-protecting-whistleblowers_N01-PUB-190408-BLOW&amp;#34; style=&amp;#34;display: block; padding: 1.5rem; border: 1px solid #ddd; border-radius: 0.5rem; text-decoration: none; color: inherit; margin: 2rem 0;&amp;#34;&amp;gt;
&amp;lt;strong&amp;gt;&amp;amp;#9654; Watch: Protecting democracy by protecting whistleblowers&amp;lt;/strong&amp;gt;&amp;lt;br&amp;gt;
&amp;lt;span style=&amp;#34;color: #666; font-size: 0.875rem;&amp;#34;&amp;gt;European Parliament Multimedia Centre · 1:28&amp;lt;/span&amp;gt;
&amp;lt;/a&amp;gt;
&amp;lt;h2 id=&amp;#34;what-the-directive-requires&amp;#34;&amp;gt;
What the directive requires
&amp;lt;a href=&amp;#34;#what-the-directive-requires&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Internal reporting channels&amp;lt;/strong&amp;gt; (Art. 8) &amp;amp;mdash; secure, confidential channels accessible to all workers, including contractors and suppliers&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;7-day acknowledgment&amp;lt;/strong&amp;gt; (Art. 9) &amp;amp;mdash; organizations must confirm receipt of a report within seven calendar days&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;3-month feedback deadline&amp;lt;/strong&amp;gt; (Art. 9) &amp;amp;mdash; reporters must receive feedback on actions taken within three months&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anti-retaliation protection&amp;lt;/strong&amp;gt; (Art. 19&amp;amp;ndash;21) &amp;amp;mdash; dismissal, demotion, intimidation, and other forms of retaliation are prohibited&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reversed burden of proof&amp;lt;/strong&amp;gt; (Art. 21(5)) &amp;amp;mdash; once a reporter shows they made a report and suffered a detriment, the employer must prove the measure was unrelated&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;External and public reporting&amp;lt;/strong&amp;gt; (Art. 10, 15) &amp;amp;mdash; reporters retain protection when reporting to competent authorities or, as a last resort, making public disclosures&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;plenary-debate&amp;#34;&amp;gt;
Plenary debate
&amp;lt;a href=&amp;#34;#plenary-debate&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The European Parliament debated the directive during its plenary session in Strasbourg. Extracts from the debate are available on the European Parliament Multimedia Centre:&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/video/protection-of-whistle-blowers-extracts-from-the-debate_I123987&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Watch the plenary debate on whistleblower protection&amp;lt;/a&amp;gt;
&amp;lt;/p&amp;gt;
&amp;lt;hr&amp;gt;
&amp;lt;h2 id=&amp;#34;official-resources&amp;#34;&amp;gt;
Official resources
&amp;lt;a href=&amp;#34;#official-resources&amp;#34; class=&amp;#34;ml-1 text-base-content/30 hover:text-base-content/60 no-underline&amp;#34; aria-label=&amp;#34;Link to this section&amp;#34;&amp;gt;#&amp;lt;/a&amp;gt;
&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://eur-lex.europa.eu/eli/dir/2019/1937/oj/eng&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Full text of Directive (EU) 2019/1937&amp;lt;/a&amp;gt;
&amp;amp;mdash; EUR-Lex&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://commission.europa.eu/aid-development-cooperation-fundamental-rights/your-fundamental-rights-eu/protection-whistleblowers_en&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Protection for whistleblowers&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Commission&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.europarl.europa.eu/news/en/press-room/20190410IPR37529/protecting-whistle-blowers-new-eu-wide-rules-approved&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;New EU-wide rules approved&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament press release&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://multimedia.europarl.europa.eu/en/topic/protection-of-whistleblowers-8th-parliamentary-term_9901&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;All whistleblower protection multimedia&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament Multimedia Centre&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.europarl.europa.eu/legislative-train/theme-area-of-justice-and-fundamental-rights/file-whistle-blower-protection-proposal&amp;#34; rel=&amp;#34;nofollow&amp;#34;&amp;gt;Legislative train schedule&amp;lt;/a&amp;gt;
&amp;amp;mdash; European Parliament&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;</content:encoded><author>support@ethicsportal.eu (EthicsPortal)</author></item></channel></rss>