Our Expert in Spain
No results available
Quick answer: A whistle blowing channel is a secure, confidential mechanism through which employees, contractors and other stakeholders can report breaches of law or serious misconduct within an organisation. In Spain, Ley 2/2023, de 20 de febrero, the country’s transposition of EU Directive 2019/1937, makes these channels mandatory for every private-sector entity with 50 or more workers, for all public bodies, and for organisations in regulated sectors regardless of headcount.
Understanding what is a whistle blowing channel has moved from a theoretical governance question to a front-line compliance priority for companies operating in Spain. Law 2/2023 not only requires organisations to stand up an internal information system (sistema interno de información, or SII), it also prescribes how reports must be received, triaged, investigated and stored, all within strict timelines. With Spain’s Autoridad Independiente de Protección del Informante (AAI) now fully operational and conducting inspections, the window for passive compliance has closed. This guide walks in-house counsel, compliance officers and HR leads through every obligation, from channel design and data-protection safeguards to the administrative penalties that can reach up to EUR 1 000 000 for the most serious infractions.
Law 2/2023 casts a wide net. Title II of the statute sets out the entities that must establish an internal information system, and it groups them into three broad categories: private-sector companies above a defined headcount, public-sector bodies, and entities operating in specified regulated sectors. The size thresholds and deadlines were phased in to give smaller organisations additional preparation time.
Under Article 10 of Law 2/2023, every legal person in the private sector with 50 or more employees must provide a functioning internal reporting channel. Companies with 250 or more employees were required to comply by 13 June 2023, three months after the law’s publication in the Boletín Oficial del Estado (BOE) on 21 February 2023. Companies with between 50 and 249 employees received an extended deadline of 1 December 2023 under the Ninth Transitional Provision of the statute.
All public-sector entities, including municipalities, autonomous communities, state agencies and publicly controlled foundations, must maintain an internal information system. Municipalities with fewer than 10 000 inhabitants may share resources or outsource channel management to supra-municipal bodies, provided the system still meets every procedural guarantee laid down in the law.
Regardless of employee count, companies in spain must implement a whistleblowing channel if they operate in financial services, money-laundering-sensitive activities, transport safety, environmental protection or other sectors listed in Part II of the Annex to Directive (EU) 2019/1937. Political parties, trade unions and foundations that receive or manage public funds are also covered.
Article 12 of Law 2/2023 permits corporate groups to operate a single, centralised internal reporting channel at parent-company level, provided each subsidiary with 50 or more employees also maintains its own channel or has clear, documented access to the group system. The law requires that the group policy explicitly describe escalation paths, data-segregation measures and the roles of each entity’s compliance officer. Where the parent company is headquartered outside Spain, the Spanish subsidiary remains individually liable for compliance.
| Entity Type | Channel Requirement (Law 2/2023) | Deadline / Note |
|---|---|---|
| Private companies, 250+ employees | Mandatory internal information system (SII) | 13 June 2023 |
| Private companies, 50–249 employees | Mandatory SII | 1 December 2023 (Ninth Transitional Provision) |
| Public bodies & municipalities | Mandatory SII; municipalities < 10 000 may share resources | 13 June 2023 (general public-sector deadline) |
| Regulated-sector entities (any size) | Mandatory SII regardless of headcount | Sector-specific; no later than 13 June 2023 for larger entities |
| Political parties, unions, foundations receiving public funds | Mandatory SII | As specified in Titles II–III of Law 2/2023 |
Law 2/2023, following the architecture of Directive (EU) 2019/1937, establishes a three-tier reporting framework. Each tier serves a different purpose, and whistleblower protection attaches regardless of which route the informant chooses, a point that many compliance teams still overlook.
Industry observers expect the internal channel to remain the dominant route in practice, because early detection gives employers the strongest position to mitigate regulatory exposure and reputational harm. However, the law deliberately removes any hierarchy that would penalise a whistleblower for going directly to the AAI or another external authority.
Establishing an internal reporting channel that satisfies the internal reporting channel Spain requirements set out in Law 2/2023 involves more than activating a software tool. The statute prescribes governance structures, procedural safeguards and technical standards that together define a compliant system. Below is a practical implementation checklist based on the requirements in Articles 5–9 and Articles 11–13 of the law.
Article 8 of Law 2/2023 requires every entity to designate a person or collegiate body as the system manager. This individual must have sufficient seniority, operational independence and the authority to initiate and conclude investigations. In companies with a compliance officer or compliance committee, that function is typically assigned to the same structure, but the law does not mandate this. What it does mandate is that the responsable del sistema cannot be overruled or sanctioned for decisions taken in good faith within the scope of their role.
The whistleblower channel must accept reports in writing (electronic form, postal mail or both) and, upon the informant’s request, verbally, either by telephone, voice-messaging system or in-person meeting. The key operational requirement is that every modality preserves confidentiality, records the report in a tamper-proof manner, and generates an automatic or manual acknowledgement of receipt.
Upon receiving a report the system manager must send a written acknowledgement within seven calendar days (Article 9). The acknowledgement should confirm that the report has been received, outline the next steps and remind the informant of their right to confidentiality. At triage stage the manager decides whether the report falls within the material scope of Law 2/2023, whether it should be investigated internally or referred to an external authority, and whether interim protective measures are needed.
Law 2/2023 sets a maximum period of three months from the date of acknowledgement for the system manager to communicate the outcome of the investigation, or, at a minimum, to provide a substantive status update. This mirrors the timeline in Article 9(1)(f) of Directive (EU) 2019/1937. The investigation itself should follow a documented protocol covering evidence collection, witness interviews, legal privilege and conflict-of-interest screening.
Articles 36–39 of Law 2/2023 prohibit any form of retaliation against informants. Companies in Spain must implement a whistleblowing channel policy that expressly forbids dismissal, demotion, reassignment, harassment, disciplinary action or any other detrimental measure taken because a person has filed a report. The prohibition extends to facilitators, colleagues and relatives of the informant. Embedding non-retaliation clauses into employment contracts, staff handbooks and supplier codes of conduct is now considered baseline compliance.
A channel that employees do not know about, or do not trust, is a channel that fails the purpose test. Best practice, consistent with OECD guidance on whistleblower protection, is to conduct initial training at roll-out and annual refresher sessions thereafter. Training should cover how to submit a report, the protections available, the role of the system manager, and the consequences of submitting a report in bad faith.
Article 9 requires the system manager to report periodically to the governing body (the board of directors or equivalent) on the volume, nature and outcome of reports received. This governance loop serves a dual purpose: it keeps senior leadership informed and creates a documented audit trail that regulators can inspect. Recommended key performance indicators include the number of reports received per quarter, average time to acknowledgement, average investigation duration and the ratio of substantiated to unsubstantiated cases.
The external channel under Law 2/2023 functions as both an alternative and a safeguard. An informant in Spain may file a report directly with the AAI or with a sector-specific regulator at any time, there is no legal obligation to exhaust the internal route first. However, the practical effect of reporting externally is that investigation control shifts to the public authority, which may impose its own timelines, request documentation from the entity and, where warranted, initiate sanctioning proceedings.
The law anticipates situations in which the internal channel cannot offer adequate protection. These include scenarios where the alleged breach involves senior management, where the informant has reasonable grounds to fear retaliation, where the entity has no functioning internal system, or where a prior internal report went unanswered within the three-month investigation window. In any of these cases the informant may report directly to the AAI without prejudice to their protection status.
For cross-border matters, where the reported breach involves EU-level regulation or affects more than one Member State, informants may also report to EU institutions or bodies, retaining the protections afforded by Directive (EU) 2019/1937. Early indications suggest that Spanish regulators are coordinating with their European counterparts through the European Commission’s whistleblower-protection network to streamline cross-border intake procedures.
Every whistleblower channel processes personal data: the informant’s identity, the identity of the person reported and, often, the identities of witnesses. This makes the whistleblowing channel a data-processing activity governed simultaneously by Law 2/2023 and by Spain’s Organic Law 3/2018 (LOPDGDD), which supplements the EU General Data Protection Regulation.
Article 32 of Law 2/2023 establishes that the identity of the informant may not be disclosed to the person reported or to any third party without the informant’s explicit consent, except where disclosure is required by a judicial authority in the context of criminal proceedings. The system manager and any persons who participate in the investigation are bound by a duty of confidentiality, breach of which is itself a sanctionable offence under the law.
Law 2/2023 does not require entities to accept anonymous reports, but it does require them to process and investigate any anonymous report that is received, provided the report contains sufficient detail to warrant action. AEPD guidance recommends that organisations accepting anonymous reports implement technical controls, such as end-to-end encryption and anonymisation of metadata, to ensure that anonymity cannot be inadvertently compromised through system logs or network records.
From a GDPR perspective, the lawful basis for processing personal data within the whistleblowing channel is typically Article 6(1)(c) of the GDPR, compliance with a legal obligation, reinforced by the specific mandate of Law 2/2023. Data retention is limited: Article 32 of the law requires that personal data not relevant to the investigation be deleted without undue delay, and that all data be erased once the investigation concludes and any follow-up actions are completed, subject to a maximum retention period that should not normally exceed ten years for records linked to proven regulatory breaches.
Compliance teams should map the whistle blowing channel investigation process against the statutory milestones set out in Law 2/2023. The table below consolidates the key deadlines and the evidence each milestone should generate.
| Milestone | Statutory / Recommended Deadline | Evidence Required |
|---|---|---|
| Receipt of report | Immediate, log date and time stamp | Intake record with unique case reference, channel used, category of alleged breach |
| Acknowledgement to informant | 7 calendar days from receipt (Article 9) | Written acknowledgement (copy retained in case file) |
| Triage and admissibility decision | Within 7–14 days (recommended best practice) | Triage assessment note: scope, admissibility, conflict-of-interest check |
| Substantive investigation | Ongoing, must conclude within 3 months of acknowledgement | Investigation plan, interview records, documentary evidence, legal analysis |
| Outcome communication to informant | 3 months from acknowledgement (Article 9) | Written summary of findings and any remedial actions taken or planned |
| Periodic board reporting | Quarterly or as prescribed by internal policy | Aggregate statistics and anonymised case summaries |
| Data retention / deletion | Delete non-relevant data promptly; retain investigation files per legal limits | Deletion logs, retention-schedule documentation |
Robust recordkeeping is both a compliance obligation and a defence mechanism. In the event of an AAI inspection, the entity must be able to demonstrate that every report was logged, acknowledged, investigated and resolved within the statutory framework. Missing or incomplete records are treated as evidence of systemic non-compliance.
Title IX of Law 2/2023 classifies infractions into three tiers, minor, serious and very serious, each carrying progressively steeper sanctions. Understanding the penalties in Spain for not implementing a whistleblowing channel is critical because the fines apply to both the organisation and, in certain cases, to individuals who obstruct or prevent reporting.
Beyond monetary penalties, very serious infractions may trigger a public reprimand and a prohibition on obtaining public subsidies for up to four years. The likely practical effect of these sanctions is that non-compliance now carries both a direct financial cost and a significant reputational risk, particularly for companies that rely on public-sector contracts or EU funding.
With the AAI now conducting supervisory activities and receiving external reports, industry observers expect enforcement volume to increase through 2026 and 2027. Compliance teams should conduct an annual internal audit of their whistle blowing channel, update their risk registers accordingly, and maintain a corrective-action log that documents any remediation steps taken following each audit cycle.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 6 minutes ago
posted 10 minutes ago
posted 17 minutes ago
posted 32 minutes ago
posted 45 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message