Our Expert in Spain
No results available
Understanding what is a whistleblower channel is now a front-line compliance priority for every organisation operating in Spain. Ley 2/2023, de 20 de febrero, reguladora de la protección de las personas que informen sobre infracciones normativas y de lucha contra la corrupción, published in the Boletín Oficial del Estado on 21 February 2023, transposed EU Directive 2019/1937 into Spanish law and created binding obligations for both private and public entities. With enforcement activity maturing through 2025 and into 2026, regulators are scrutinising whether obligated organisations have established compliant internal reporting systems, protective confidentiality protocols, and functioning investigation workflows. This guide provides a practical, step-by-step breakdown of employer duties, channel design requirements, data-protection intersections, penalty exposure, and a ready-to-use implementation roadmap.
A whistleblower channel is a secure, confidential mechanism through which individuals can report breaches of law, ethical violations, or corruption within or connected to an organisation. In Spanish law, Law 2/2023 uses the term sistema interno de información (internal information system) and requires it to guarantee the identity protection of reporters, the integrity of evidence, and structured follow-up procedures.
In simple terms, whistleblowing is the act of alerting an organisation or a public authority to wrongdoing, fraud, bribery, health-and-safety failures, environmental breaches, or other regulatory violations, so that corrective action can be taken before harm escalates.
There are three main types of whistleblowing channels recognised under Law 2/2023 and EU Directive 2019/1937:
Law 2/2023 applies broadly. All private-sector entities with 50 or more employees must operate a compliant internal whistleblower channel. The same obligation extends to all public-sector bodies regardless of headcount, including local authorities, state-owned enterprises, and constitutional bodies. Political parties, trade unions, and employer associations receiving or managing public funds are also caught within the scope of the law.
Persons protected under the statute include employees, civil servants, self-employed workers, shareholders, members of governing bodies, trainees, volunteers, and even job applicants, provided the reported information was obtained in a work-related context.
EU Directive 2019/1937, adopted on 23 October 2019, set minimum standards for whistleblower protection and reporting channels in Spain and across all Member States. Spain’s transposition via Law 2/2023 went beyond the Directive’s minimum thresholds in several respects: it extended protected subject matter to any serious criminal or administrative infraction (not solely breaches of EU law), and it mandated that internal channels accept anonymous reports, a feature encouraged but not required by the Directive. The European Commission continues to monitor transposition quality and enforcement across the EU, making robust compliance a matter of cross-border regulatory expectation as well as domestic obligation.
The internal channel is the cornerstone of the compliance framework. Organisations must design a system that allows reports to be submitted in writing (via web portal, secure email, or postal submission) and orally (telephone hotline or in-person meeting). The channel must be accessible to all persons within the scope of protection and must guarantee acknowledgement of receipt within seven calendar days. Industry observers expect that well-implemented internal channels will handle the vast majority of reports, reducing the need for external escalation and the reputational exposure that accompanies it.
Law 2/2023 establishes the Autoridad Independiente de Protección del Informante (A.A.I.) as the principal external channel at national level, complemented by equivalent bodies that autonomous communities may create. Reporters may also submit information directly to the CNMV for matters falling within securities regulation, to the AEPD for data-protection infringements, or to the Fiscalía (Public Prosecutor’s Office) for criminal conduct. A reporter is free to use the external channel without first exhausting the internal route, Law 2/2023 does not impose a hierarchy between the two.
Public disclosure, reporting to the press, social media, or civil-society organisations, carries protection under Law 2/2023 only where the reporter has first used an internal or external channel without obtaining an adequate response, where there is an imminent or manifest danger to the public interest, or where using other channels would be ineffective or would expose the reporter to retaliation. Outside those narrow conditions, a public disclosure may forfeit the statutory protections and expose the reporter to defamation or confidentiality claims. Practical advice: treat the media route as a last resort and document every prior attempt to report through formal channels.
Every report received through the whistleblower channel must be logged, risk-rated, and triaged within a structured timeline:
| Step | Deadline / SLA | Owner |
|---|---|---|
| Acknowledge receipt to the reporter | Within 7 calendar days | Channel manager / responsible person |
| Preliminary admissibility assessment | Within 10 business days (recommended) | Responsible person |
| Substantive investigation and response | Maximum 3 months from acknowledgement | Investigation team / external advisers |
| Communicate outcome to the reporter | At the close of the 3-month period | Responsible person |
Once a report is admitted, the responsible person must ensure a fair, confidential investigation. Key obligations include preserving evidence, offering the accused person a right to be heard before final conclusions, and recommending corrective or disciplinary measures to the competent governance body. Where investigation findings reveal potential criminal conduct, the organisation must refer the matter to the Fiscalía without delay.
Law 2/2023 requires that records relating to reports and investigations be retained for the minimum period necessary and in any event no longer than ten years from receipt of the report. The AEPD has emphasised that personal data collected through whistleblower channels must comply with GDPR data-minimisation principles, meaning organisations should periodically review stored records and delete data that is no longer necessary for the stated purpose. A robust retention schedule, mapping data categories, lawful bases, and deletion triggers, is essential.
A compliant internal whistleblower channel must offer multiple reporting routes to accommodate different user needs and risk profiles. At minimum, organisations should provide:
Access to the channel’s back-end, where reports, evidence, and identities are stored, must be restricted to authorised personnel through role-based access controls, multi-factor authentication, and encrypted storage. Audit logs should capture every access event to support oversight and regulatory review.
Effective channel governance typically requires a clear role matrix:
Measuring channel effectiveness is a regulatory expectation and a governance best practice. The following table sets out minimum KPIs that compliance teams should track:
| KPI | Target | Measurement frequency |
|---|---|---|
| Acknowledgement within 7 days | 100 % | Per report |
| Investigation closed within 3 months | ≥ 90 % | Quarterly |
| Reporter satisfaction (anonymous survey) | ≥ 70 % positive | Annually |
| Substantiation rate | Tracked (no fixed target) | Quarterly |
| Retaliation incidents reported | Zero tolerance | Quarterly |
Whistleblower channels inevitably process sensitive personal data, the reporter’s identity, the accused’s identity, witness statements, and supporting evidence. Under the GDPR and Spain’s Ley Orgánica 3/2018 (LOPDGDD), this processing requires a lawful basis. Law 2/2023 itself provides the legal obligation basis for processing data received through internal channels. However, the AEPD has stressed that organisations must collect only the data strictly necessary to assess and investigate the report, avoid processing data that is clearly irrelevant, and delete personal data that proves unnecessary within a maximum period aligned with the ten-year retention cap.
Organisations already required to appoint a DPO under the GDPR (public bodies, entities conducting large-scale systematic monitoring, or those processing special-category data) must involve the DPO in the design and operation of the whistleblower channel. Recommended steps include:
Law 2/2023 classifies infractions into three tiers, minor, serious, and very serious, each carrying escalating fines:
Beyond administrative penalties, failure to maintain a functioning whistleblower channel weakens an organisation’s ability to rely on a compliance programme (programa de cumplimiento normativo) as a mitigating factor under Spain’s corporate criminal liability framework (Código Penal, art. 31 bis). Early indications suggest that regulators are looking at channel operability, not just paper policies, when assessing compliance programme effectiveness.
The A.A.I. became formally operational after Law 2/2023 entered into force, and its supervisory and sanctioning functions have been progressively activated. Industry observers expect enforcement actions to intensify through 2026 and 2027 as the authority completes its initial organisational build-out and begins systematic inspections, particularly targeting entities that have failed to establish any internal channel at all.
Reporters, and compliance teams advising them, should assess the nature of the alleged breach to identify the most appropriate external route. The following table maps common matter types to recommended authorities:
| Matter type | Recommended external authority |
|---|---|
| General regulatory or administrative breaches | Autoridad Independiente de Protección del Informante (A.A.I.) |
| Securities and financial-market infractions | Comisión Nacional del Mercado de Valores (CNMV) |
| Data-protection violations | Agencia Española de Protección de Datos (AEPD) |
| Criminal conduct | Fiscalía General del Estado (Public Prosecutor’s Office) |
| Workplace safety breaches | Inspección de Trabajo y Seguridad Social |
Where an infraction has a cross-border dimension, for example, conduct affecting other EU Member States or breaches of directly applicable EU regulations, reporters may also submit information to relevant EU-level bodies (e.g., OLAF for fraud involving EU funds, or the European Securities and Markets Authority for systemic market-integrity issues). Law 2/2023 and Directive 2019/1937 both protect reporters who use these channels, provided the report falls within the material scope of protection.
| Entity type | Channel obligation under Law 2/2023 | Practical notes (thresholds / timelines) |
|---|---|---|
| Public bodies | Mandatory internal channels, must accept reports from public employees and certain third parties | Immediate acknowledgement; public bodies may have specific additional rules set by autonomous communities |
| Private companies ≥ 50 employees | Mandatory internal channels; obligations to process reports, protect reporter confidentiality, and prevent retaliation | Set SLAs for acknowledgement (7 days) and investigation closure (3 months); maintain records up to 10 years |
| SMEs < 50 employees | Not always mandatory under national thresholds, check delegated rules and sectoral regulations | Best practice: adopt a basic channel; consider outsourced provider or collective schemes shared among small entities |
Understanding what is a whistleblower channel, and building one that meets Spain’s Law 2/2023 requirements, is no longer optional for organisations above the fifty-employee threshold or operating in the public sector. The obligations span channel design, governance, confidentiality, data protection, investigation timelines, and record-keeping, all backed by significant administrative sanctions. Organisations that have not yet implemented a compliant internal channel should treat the matter as urgent and seek specialist compliance guidance to close any remaining gaps before enforcement scrutiny intensifies.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 35 seconds ago
posted 21 minutes ago
posted 25 minutes ago
posted 46 minutes ago
posted 51 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message