The Whistleblower Protection Directive (Directive 2019/1937)
The Whistleblower Protection Directive, formally Directive (EU) 2019/1937, establishes minimum standards for the protection of persons reporting breaches of EU law across the European Union. Adopted on 23 October 2019 with a transposition deadline of 17 December 2021, the Directive requires Member States to create comprehensive legal frameworks for internal and external reporting channels, personal scope of protection, safeguards against retaliation, and measures of support for whistleblowers. The Directive represents the culmination of a legislative process that began with the European Parliament’s resolution of 2017 calling for stronger EU-wide whistleblower protections following the Panama Papers, LuxLeaks, and Cambridge Analytica revelations.
Scope: Protected Reports and Persons
The Directive applies to reports of breaches of EU law in a defined set of policy areas: public procurement, financial services, money laundering and terrorist financing, product safety, transport safety, environmental protection, radiation protection and nuclear safety, food and feed safety, animal health and welfare, public health, consumer protection, privacy and personal data protection, network and information systems security, and breaches affecting the financial interests of the Union and the internal market. Member States may extend protection to breaches of national law outside the EU law scope.
Protected persons include workers in the private and public sectors, self-employed persons, shareholders and persons belonging to administrative, management, or supervisory bodies of undertakings, volunteers, unpaid trainees, and any persons whose working relationship has ended or has not yet begun. The personal scope is broad, covering anyone who obtained information about a breach in a work-related context. Persons facilitating reports — those who assist a reporting person in a confidential context — are also protected.
Internal and External Reporting Channels
The Directive establishes a three-tier reporting framework. The first tier requires legal entities in the private sector with 50 or more employees (and all public sector entities, regardless of size) to establish internal reporting channels and procedures. Internal channels must enable reporting in writing, orally, or in person, and must allow for both named and anonymous reporting, though Member States may choose not to require legal entities to accept anonymous reports. The entity must acknowledge receipt of the report within seven days, designate an impartial person or department to follow up, maintain confidentiality, and provide feedback within three months.
The second tier requires Member States to designate competent authorities to receive, follow up, and provide feedback on external reports. External reporting channels must be independent, autonomous, and separate from the internal channels of the entities concerned. Competent authorities must designate procedures for handling external reports, including acknowledgment within seven days and diligent follow-up.
The third tier provides for public disclosure — making information publicly available through press, social media, or other channels — but only in defined circumstances: where the reporting person has reasonable grounds to believe that internal or external reporting would not be effective (because the breach may be imminent or because there is a risk of evidence destruction), where a competent authority has not provided feedback within the prescribed timeframe, or where there is a risk of retaliation due to the particular circumstances.
Protection Against Retaliation
The Directive prohibits retaliation against reporting persons, defined broadly to include any direct or indirect act or omission occurring in a work-related context that causes unjustified detriment. The Directive provides a non-exhaustive list of prohibited retaliatory measures, including suspension, dismissal, demotion, withholding of promotion, change of working hours or location, reduction of pay, negative performance assessments, disciplinary measures, coercion, intimidation, harassment, discrimination, blacklisting, and early termination of public contracts. The burden of proof is reversed: where a reporting person suffers detriment following a report, it is presumed to be retaliation, and the person who subjected the reporting person to the detriment must prove that the action was based on duly justified grounds unrelated to the report.
Safeguards and Remedies
Reporting persons are protected only if they had reasonable grounds to believe that the information reported was true at the time of reporting and that it fell within the scope of the Directive. Persons who knowingly report false information are not protected and may be subject to sanctions. Member States must provide remedial measures for persons suffering retaliation, including interim relief pending resolution of proceedings, full compensation for material and non-material damage, legal aid, and psychological support. Trade unions and civil society organisations may support reporting persons in proceedings.
Transposition and Implementation
The Directive’s transposition deadline of 17 December 2021 was missed by a majority of Member States. The Commission initiated infringement proceedings against multiple Member States, including Germany, Estonia, Greece, Spain, Hungary, Italy, Poland, Portugal, and others, for failure to transpose or for incomplete transposition. By mid-2025, most Member States had adopted transposition legislation, though the quality and completeness of transposition varies significantly, particularly regarding the scope of material breaches covered, the definition of protected persons, and the specific safeguards against retaliation.