Contents
Compliance Management

The EU Whistleblower Directive and resulting requirements for companies

Picture of Dr. Thomas Altenbach
Dr. Thomas Altenbach

Updated version – as of July 2026

What is the content of the whistleblower policy?

Directive (EU) 2019/1937 has been implemented in Germany through the Whistleblower Protection Act (HinSchG). The HinSchG came into force on 2 July 2023. For German companies, therefore, it is no longer a future draft law but the current version of the HinSchG that is decisive.

The central content of the whistleblower policy is the creation of an internal company Infrastructure for reporting legal violations. The infringements can affect different areas such as these:

Whistleblowers should be given the opportunity to report infringements of the law and violations of internal company policies to report anonymously

What does the Whistleblower Directive mean for German companies?

  • Businesses with 50 to 249 employees:These companies must also provide their employees with a reporting channel, although the deadline for this was 17 December 2023.

  • Public sector organisations, or municipalities and cities with over 10,000 inhabitants are also affected by the law.

  • The reporting systems must allow for both written or oral as well as for personal reporting of incidents.

  • A notification must be processed or confirmed by the internal reporting office within 7 days.

  • Whistleblowers must be informed of the measures taken no later than 3 months after reporting.

  • The application areas of the Whistleblower Protection Act relate to EU law and national law.

  • The whistleblowing system must comply with the GDPR and protect the identity of the whistleblower. Whilst the option to submit reports anonymously has been recommended up to now, it will become mandatory in 2025. This means that internal reporting bodies must take the necessary steps to receive and process anonymous reports.

  • When laws are broken, companies can face fines of up to €50,000.

Who does the Whistleblower Policy protect?

The main objective of the Whistleblower Directive is the Protection of so-called whistleblowers. This refers to the people who use the whistleblowing systems and report incidents. The HinSchG contains a confidentiality obligation and a Prohibition of reprisals. However, protection is not equivalent to a guarantee of permanent anonymity. The law provides for exceptions to the duty of confidentiality and requires the preconditions of § 33 HinSchG to be met for the protection of the whistleblower. The individuals to be protected within a company include not only employees but also others. Stakeholder like suppliers, partners, or external supervisory bodies

What sanctions can be expected for non-compliance with the whistleblower directive?

The whistleblower policy intents sanctions for non-complying companies. How these consequences will be structured is left to the respective countries.

For German companies, the penalty provisions of § 40 of the HinSchG are decisive. The potential consequences depend on the specific violation, such as obstructing a report, retaliation, a breach of confidentiality, or the failure to establish an internal reporting office.

Fairy
Whistleblower Software from LegalTegrity
Learn in 5 minutes

Before you book a live demo appointment with LegalTegrity, you can get to know our software in just 5 minutes. Request our demo video to get an overview of all the system's important features and customisation options. You will receive the demo video via email.

Whistleblowing systems as a consequence of the new EU directive

Whistleblowing schemes are the digital response to the Whistleblower Protection Act. Employees can report breaches at any time. Those entrusted with the duties of an internal reporting office must be independent in their work and possess the necessary expertise. A legal qualification is not generally required. Documentation that complies with data protection regulations and appropriate follow-up measures must be ensured through the specific organisation and implementation of the procedure.

This is how a Whistleblower System:

  1. Observation of the incident

  2. Message in the system

  3. Review by independent experts

  4. Consequence of the breach

  5. Follow-up

Procedure in the whistleblowing system for an incident or report

Whistleblower Policy – An Expert's Assessment

All companies must adapt their compliance management!

„I firmly assume that all companies will have to adapt parts of their compliance management [...],“ says Dr. Thomas Altenbach In an interview with IT-Daily on the impact of the EU Whistleblower Directive on existing compliance management in companies.

The LegalTegrity-CEO answered exciting questions like these in an interview with IT Daily:

A whistleblower system as a core element

The Conclusion of the compliance expert: At the end of this process, a well-functioning, anonymised whistleblower system should be a core element of a company's compliance measures.„

How can companies prepare for a whistleblower directive law?

Companies should check whether they are obliged to set up an internal reporting office under the applicable Whistleblower Protection Act and whether their organisational and technical implementation meets the statutory requirements. A digital solution can facilitate confidential reporting channels, anonymous communication and the structured processing support. However, compliance with the law also depends on responsibilities, processes, expertise and how reports are actually handled.

(The male form used refers to all persons, regardless of gender.)

About the author
More topics at a glance
Compliance Management
Compliance Management