Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Whistleblowing: Confidentiality, Data Protection and Record-Keeping
The identity of the reporting person shall not be disclosed, without their explicit consent, to anyone beyond the authorised staff competent to receive or follow up on reports, except where this is a necessary and proportionate obligation under Union or national law in the context of investigations or judicial proceedings (with prior information to the reporting person where possible).
- Controls ensuring reporter identity is disclosed only to authorised staff or as legally required
- Process for informing the reporter before any required disclosure
- Reporter identity accessible beyond authorised staff
- Disclosure without the legal-obligation basis
Any processing of personal data carried out pursuant to the Directive, including the exchange or transmission of personal data, shall be carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Directive (EU) 2016/680; personal data manifestly not relevant to a specific report shall not be collected or, if accidentally collected, deleted without undue delay.
- Records-of-processing and lawful-basis assessment for whistleblowing data
- Data-minimisation controls deleting irrelevant data
- Processing whistleblowing data without a GDPR basis
- Retaining manifestly irrelevant personal data
Entities and competent authorities shall keep records of every report received, in compliance with confidentiality requirements, retained no longer than necessary and proportionate; where a recorded telephone line or voicemail is used, the report may be documented by recording (with consent) or by a complete and accurate transcript.
- A record-keeping procedure with retention limits and confidentiality
- Documentation method for oral/telephone reports
- No records of reports
- Indefinite retention of whistleblowing records
Whistleblowing: External Reporting Channels
Reporting persons may report to competent authorities through external channels, either after first reporting internally or directly.
- Information made available on external reporting options to competent authorities
- Suppressing or penalising recourse to external channels
Member States shall designate competent authorities to establish independent and autonomous external reporting channels, acknowledge receipt within seven days, diligently follow up, provide feedback within a reasonable timeframe (not exceeding three months, or six in duly justified cases), and communicate the final outcome.
- Designated competent authority external channels with 7-day acknowledgement and 3-month feedback
- No independent external channel
- Feedback exceeding the prescribed timeframe
External reporting channels shall be designed, established and operated to ensure completeness, integrity and confidentiality of information, prevent unauthorised access, and allow durable storage of information for further investigation.
- Design specification for the external channel ensuring confidentiality, integrity and durable storage
- External channel without integrity/confidentiality safeguards
Competent authorities shall publish on their websites, in a separate, easily identifiable and accessible section, clear and easily accessible information on the conditions, procedures and protections for external reporting.
- Published, accessible information on external reporting conditions and procedures
- External-reporting information not published or hard to find
Competent authorities shall review their procedures for receiving reports and following up on them at least once every three years.
- Records of the at-least-three-yearly review of external reporting procedures
- No periodic review of procedures
Whistleblowing: Internal Reporting Channels
Member States shall encourage reporting through internal channels before external reporting where the breach can be addressed effectively internally and the reporting person considers there is no risk of retaliation; entities shall provide information on the use of internal channels.
- Information provided to staff encouraging and explaining internal reporting
- No guidance steering reporters to internal channels first
Legal entities in the private sector with 50 or more workers, and public sector entities, shall establish channels and procedures for internal reporting and follow-up, designed and operated securely to protect the confidentiality of the identity of the reporting person and any third party mentioned, and preventing access by non-authorised staff.
- Established internal reporting channel(s) (e.g. hotline, portal, in-person)
- Confidentiality controls restricting access to authorised staff
- No internal channel despite 50+ workers
- Channel that exposes reporter identity to unauthorised staff
Internal reporting procedures shall include: secure channels protecting confidentiality; acknowledgement of receipt within seven days; designation of an impartial person or department competent for following up; diligent follow-up; feedback to the reporting person within a reasonable timeframe not exceeding three months; and clear, easily accessible information on external reporting.
- Documented internal procedure with 7-day acknowledgement and 3-month feedback timelines
- A designated impartial follow-up person/department
- No acknowledgement within 7 days
- No feedback within 3 months
- No designated impartial handler
Whistleblowing: Penalties and Remedies
Member States shall provide effective, proportionate and dissuasive penalties applicable to persons who hinder or attempt to hinder reporting, retaliate, bring vexatious proceedings, or breach the duty of confidentiality; and penalties for reporting persons who knowingly reported or publicly disclosed false information.
- A penalties regime covering obstruction, retaliation, breach of confidentiality, and knowingly false reports
- No sanction for retaliation or confidentiality breaches
The rights and remedies provided for under the Directive cannot be waived or limited by any agreement, policy, form or condition of employment, including a pre-dispute arbitration agreement.
- Confirmation that contracts/policies do not waive whistleblower rights
- Employment terms or NDAs purporting to waive reporting rights
Member States may introduce or retain provisions more favourable to reporting persons than those in the Directive, and implementation shall not constitute grounds for reducing the level of protection already afforded.
- Confirmation that national/organisational measures do not lower pre-existing protection
- Using transposition to reduce existing whistleblower protections
Whistleblowing: Protection Measures
Member States shall prohibit any form of retaliation against protected reporting persons, including threats and attempts of retaliation (e.g. suspension, dismissal, demotion, withholding of training, negative performance assessment, disciplinary measures, coercion, intimidation, discrimination, blacklisting, early termination of contracts).
- A policy prohibiting the enumerated forms of retaliation
- Records showing no detriment imposed on reporters
- Detrimental treatment of a reporter
- No anti-retaliation policy
Reporting persons shall have access to support measures, including comprehensive and independent information and advice on available procedures and remedies (free of charge), effective assistance from competent authorities, and legal aid in proceedings.
- Access to free information/advice and assistance for reporters
- No support or advice route for reporters
Protected persons shall not be considered to have breached restrictions on disclosure and shall not incur liability for reporting or public disclosure made in accordance with the Directive; in proceedings concerning detriment suffered, where the reporter shows they reported and suffered a detriment, it shall be presumed the detriment was retaliation and the burden shifts to the person who took the measure to prove it was based on duly justified grounds.
- Process implementing the reversal of the burden of proof and liability exemptions
- Placing the burden of proof on the reporter
- Treating protected disclosures as a breach of confidentiality
Persons concerned (those referred to in a report) shall fully enjoy the right to an effective remedy and to a fair trial, the presumption of innocence and rights of defence, including the right to be heard and to access their file; their identity shall be protected while investigations are ongoing.
- Procedures protecting the rights of persons concerned (defence, identity protection during investigation)
- No safeguards for the rights of persons named in a report
Whistleblowing: Public Disclosures
A person who makes a public disclosure qualifies for protection where they first reported internally and externally (or directly externally) without appropriate action being taken within the prescribed timeframe, or where they have reasonable grounds to believe the breach may present an imminent or manifest danger to the public interest, or that external reporting risks retaliation or is unlikely to be effectively addressed.
- Policy describing the conditions under which public disclosure attracts protection
- Denying protection to public disclosures that meet the Article 15 conditions
Whistleblowing: Scope and Conditions for Protection
The Directive applies to reporting persons working in the private or public sector who acquired information on breaches in a work-related context, including workers, self-employed persons, shareholders, members of administrative/management bodies, volunteers, paid/unpaid trainees, and persons working under the supervision of contractors, subcontractors and suppliers; it also covers facilitators, third persons connected to the reporting person, and legal entities the reporting person is connected with.
- Mapping of categories of persons eligible for protection in the organisation's whistleblowing policy
- Policy limiting protection to direct employees only
Defines the key terms (breaches, information on breaches, report, internal/external reporting, public disclosure, reporting person, facilitator, work-related context, person concerned, retaliation, follow-up, feedback, competent authority).
- Consistent use of the directive definitions in the whistleblowing policy and procedures
- Ambiguous or absent definitions of report, retaliation, follow-up
Reporting persons qualify for protection where they had reasonable grounds to believe the information reported was true at the time of reporting and fell within the scope of the Directive, and they reported internally/externally or made a public disclosure in accordance with the Directive.
- Criteria in the policy for when a reporter qualifies for protection (reasonable-grounds and scope test)
- Conditioning protection on the report being ultimately proven correct
- Requiring proof of motive
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.