Skip to content

Whistleblowing Channel: Law 2/2023 Compliance Made Simple

Implementation of internal whistleblowing channels under Spanish Law 2/2023 transposing EU Directive 2019/1937. Full Internal Information System design, investigation protocols, and confidentiality guarantees.

50+
Employees: threshold for mandatory channel under Law 2/2023
7 days
Maximum acknowledgement deadline — we manage the entire process
EUR 1M
Maximum fine for absence of channel or retaliatory measures
4.8/5 on Google · 50+ reviews 25+ years experience 5 offices in Spain 500+ clients
Deadline 1 December 2023

Mandatory Whistleblowing Channel

Companies with 50+ employees must have a compliant Internal Information System under Law 2/2023 — fines up to €1M for non-compliance

Quick assessment

Does this apply to your business?

Does your company have more than 50 employees and still lacks a formally implemented whistleblowing channel with a designated responsible person?

Has your existing channel ever received a complaint and processed it within the statutory 7-day acknowledgement and 3-month response deadlines?

Has your company conducted the GDPR Data Protection Impact Assessment specifically required for whistleblowing systems?

Do your managers understand the reversed burden of proof that applies if a whistleblower is dismissed or disadvantaged after making a report?

0 of 4 questions answered

Our approach

Our whistleblowing channel implementation process

01

System design & organisational analysis

We assess your company's size, group structure, and risk profile to design the optimal channel model: internally managed by the designated responsible person, or outsourced to an independent third party for greater perceived impartiality.

02

Technical implementation & documentation

We configure the technical channel with encryption and anonymity options, draft the corporate whistleblowing policy, the operating rules, and the acknowledgement and follow-up procedures within the statutory deadlines (7 days for acknowledgement, 3 months for response).

03

Responsible person designation & training

We advise on the appointment of the System Responsible Person, provide training on investigation protocols, confidentiality obligations, and whistleblower protection measures against retaliation.

04

GDPR coordination & ongoing maintenance

We coordinate with the DPO to ensure GDPR compliance in the processing of personal data in complaints, conduct the required Data Protection Impact Assessment, and maintain the system updated as regulations and supervisory authority guidance evolve.

The challenge

Law 2/2023 requires companies with 50 or more employees to implement an Internal Information System with real confidentiality guarantees, a designated responsible person, legal deadlines for processing, and effective anti-retaliation protections. Most companies that believe they have complied have installed a contact form — not a compliant system. A non-functional channel can generate greater liability than having none at all.

Our solution

We design and implement the complete Internal Information System (SII): technical channel with confidentiality and anonymity options, corporate whistleblowing policy, responsible person designation, investigation protocol with statutory deadlines, staff training, and GDPR coordination. A fully audited and documented system that meets every requirement of the EU Directive and Spanish Law 2/2023.

Spain's whistleblowing framework is established by Law 2/2023 of 20 February on the Protection of Persons who Report Regulatory Infringements and the Fight against Corruption, which transposed EU Directive 2019/1937 on whistleblower protection. Law 2/2023 requires private companies with 50 or more employees, public entities, and all companies operating in financial services regardless of size to implement an Internal Information System (Sistema Interno de Información, SII) with specific requirements: a confidential and optionally anonymous reporting channel, a designated responsible person (Responsable del Sistema), acknowledgement within 7 days, a substantive response within 3 months, anti-retaliation protections for reporters, and coordination with GDPR obligations for personal data processed through the channel. Non-compliant organisations face sanctions of up to EUR 1 million for serious infringements.

Our team combines expertise in regulatory compliance, employment law, and data protection to implement whistleblowing systems that function in practice — not only on paper.

The Gap Between Having a Channel and Being Compliant

Law 2/2023, transposing EU Directive 2019/1937 into Spanish law, establishes a comprehensive framework for whistleblower protection that extends far beyond enabling a contact form. The law requires a structured Internal Information System with a formally designated responsible person, statutory processing deadlines, genuine confidentiality guarantees, and effective protection against retaliation. Organisations that have installed a generic inbox or a third-party whistleblowing tool without structuring the system around it are technically non-compliant — and potentially exposed to sanctions reaching EUR 1 million.

Designing a System That Works Under Pressure

The first step in any implementation is system design. A 60-employee manufacturing company and a 5,000-employee financial services group require fundamentally different architectures. We analyse the organisational structure, risk profile, and corporate culture to recommend whether the channel should be managed internally by the designated responsible person or outsourced to an independent third party. Outsourcing typically provides greater perceived credibility for potential whistleblowers — a critical factor in whether employees actually use the system — and removes the conflict-of-interest concerns that arise when the channel is managed internally.

Integration with Criminal Compliance

The relationship between a whistleblowing channel and a criminal compliance programme is direct and legally significant. Spanish courts have confirmed that a functional internal reporting system is one of the elements they examine when assessing whether a legal entity’s compliance programme should have exculpatory effects on criminal liability. A channel that exists on paper but generates no investigations and no corrective measures will not satisfy this standard. We design the investigation protocol to produce the documented evidence trail that compliance programmes require.

GDPR Considerations Specific to Whistleblowing

The processing of personal data in whistleblowing systems presents specific challenges that require close coordination with the Data Protection Officer. The AEPD has issued specific guidance on impact assessments for these systems, retention periods for data relating to both whistleblowers and reported individuals, and the limits of the reported person’s right to information when it could compromise the investigation. We integrate all of these requirements from day one, avoiding the retroactive GDPR remediation that many organisations face after deploying their channels without adequate data protection planning.

The Internal Investigation Protocol

A whistleblowing channel is only as effective as the investigation process that follows a report. Law 2/2023 requires the designated responsible person to acknowledge receipt of a report within seven days and to communicate the outcome of the investigation within three months. These deadlines are not aspirational — they are legal obligations with sanction exposure attached. We design investigation protocols that specify who conducts the investigation for different categories of reported conduct, what evidence-gathering steps are required, how potential conflicts of interest are managed, and how the outcome is communicated to the reporter.

The Responsible Person: Appointment and Training

The designation of the responsible person (Responsable del Sistema) is a formal appointment that must be documented. Law 2/2023 requires the responsible person to have the authority to conduct investigations, access relevant information, and recommend corrective measures. Where the responsible person role is outsourced, our team manages the complete lifecycle: report receipt, acknowledgement, investigation coordination, outcome communication, and compliance documentation. The integration with the criminal compliance programme ensures that reports alleging criminal conduct are handled with the procedural rigour that a potential criminal proceeding requires.

Interaction with the Anti-Retaliation Framework

Law 2/2023 establishes comprehensive protections for reporters against retaliation: dismissal, demotion, salary reduction, change of duties, coercion, discrimination, and negative performance assessment are all forms of prohibited retaliation. The law creates a reversal of the burden of proof in employment proceedings. Our employment law team advises on how to handle situations where a report is received and an employment decision affecting the reporter is subsequently required — ensuring the decision is legally defensible and demonstrably independent of the report.

Multinational Groups and Multi-Jurisdiction Channels

For multinational groups with operations in multiple EU member states, Law 2/2023 allows a centralised internal channel at group level as long as the channel is genuinely accessible to employees in all jurisdictions. We design group-level whistleblowing systems that comply with the requirements of the EU Directive as transposed in each operating jurisdiction, manage the cross-border data flows in compliance with GDPR international transfer rules, and ensure that the local law variations across member states are reflected in the system’s operational procedures.

The Internal Investigation Protocol

A whistleblowing channel is only as effective as the investigation process that follows a report. Law 2/2023 requires the designated responsible person to acknowledge receipt of a report within seven days and to communicate the outcome of the investigation within three months. These deadlines are not aspirational — they are legal obligations with sanction exposure attached. We design investigation protocols that specify who conducts the investigation for different categories of reported conduct, what evidence-gathering steps are required, how potential conflicts of interest are managed, and how the outcome is communicated to the reporter.

The Responsible Person: Appointment and Training

The designation of the responsible person (Responsable del Sistema) is a formal appointment that must be documented. Law 2/2023 requires the responsible person to have the authority to conduct investigations, access relevant information, and recommend corrective measures. Where the responsible person role is outsourced, our team manages the complete lifecycle: report receipt, acknowledgement, investigation coordination, outcome communication, and compliance documentation. The integration with the criminal compliance programme ensures that reports alleging criminal conduct are handled with the procedural rigour that a potential criminal proceeding requires.

Interaction with the Anti-Retaliation Framework

Law 2/2023 establishes comprehensive protections for reporters against retaliation: dismissal, demotion, salary reduction, change of duties, coercion, discrimination, and negative performance assessment are all forms of prohibited retaliation. The law creates a reversal of the burden of proof in employment proceedings. Our employment law team advises on how to handle situations where a report is received and an employment decision affecting the reporter is subsequently required — ensuring the decision is legally defensible and demonstrably independent of the report.

Multinational Groups and Multi-Jurisdiction Channels

For multinational groups with operations in multiple EU member states, Law 2/2023 allows a centralised internal channel at group level as long as the channel is genuinely accessible to employees in all jurisdictions. We design group-level whistleblowing systems that comply with the requirements of the EU Directive as transposed in each operating jurisdiction, manage the cross-border data flows in compliance with GDPR international transfer rules, and ensure that the local law variations across member states are reflected in the system’s operational procedures.

Track record

Real results in whistleblowing channel compliance

We had a form on our intranet that we called a whistleblowing channel. BMC showed us it was missing almost everything the law requires. They built us a complete system in six weeks — designated responsible person, trained, DPIA completed, and the first real complaint handled within 48 hours. The difference is night and day.

Hartmann Iberia Manufacturing S.A.
Chief Compliance Officer

Experienced team with local insight and international reach

What you get

What our whistleblowing channel service includes

Internal Information System (SII) Design

Organisational analysis, channel model selection (internal or outsourced), drafting of the corporate whistleblowing policy and operating rules covering all elements required by Law 2/2023 and the EU Directive.

Technical Channel with Confidentiality Guarantees

Configuration of the complaint-receipt platform with encryption, anonymous communication options, whistleblower follow-up tracking, and a full audit trail of all actions taken on each case.

Investigation Protocol & Deadline Management

Documented procedure for opening, investigating, and closing complaint files, with statutory deadlines integrated (7-day acknowledgement, 3-month response) and escalation paths to governance bodies where required.

Training & Internal Communication

Training for the Responsible Person and key management on investigation obligations and anti-retaliation rules; company-wide communication on the channel's existence and operation; whistleblower protection awareness materials.

GDPR Coordination & DPIA

Data Protection Impact Assessment specific to the whistleblowing system, DPO coordination, and establishment of data retention and deletion policies for personal data of whistleblowers and reported persons.

Guides

Reference guides

Post-Brexit: your British company operating in Spain with the right structure

post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.

View guide

Comprehensive legal services for businesses

Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.

View guide

Buy property in Spain with confidence — and without the horror stories

Buying property in Spain as a non-resident involves legal checks, tax obligations, and title risks that many buyers discover too late. BMC protects your investment from offer to deed.

View guide

The collective agreement that governs your workforce: understand it and negotiate from strength

How collective agreements work in Spain: hierarchy of agreements, company-level vs sector agreements, ultra-actividad, inaplicacion (opt-out), and negotiation strategy for employers after the 2021 labour reform.

View guide

Your commercial lease agreement: get the clauses right before you sign

Expert legal guidance on commercial lease agreements in Spain under the LAU: key clauses, rent reviews, subleasing, termination rights, VAT implications and tenant and landlord protections.

View guide

Corporate lawyer for construction: protect your contracts and your rights

Corporate legal advisory for construction companies and developers in Spain: construction contracts, UTEs, joint ventures, interim valuation disputes, claims for defects, and debt recovery.

View guide
FAQ

Frequently asked questions about whistleblowing channels in Spain

Law 2/2023 requires all private sector entities with 50 or more employees to implement an Internal Information System. Companies with between 50 and 249 employees may share a channel with other entities in the same group. For public sector entities the obligation is general, regardless of size. Certain regulated sectors (financial services, insurance, transport) are subject to the obligation irrespective of headcount.
Yes. The law requires the channel to accept anonymous communications. The responsible person must guarantee the confidentiality of the whistleblower's identity in all cases — including where the report is made non-anonymously. The system must be designed so that only the responsible person can link a report to an identified individual.
The responsible person must acknowledge receipt of the complaint within 7 calendar days. The deadline to inform the whistleblower of the actions taken is 3 months, extendable to 6 months in complex cases. These deadlines are mandatory and non-compliance is itself an infringement under the law.
Law 2/2023 expressly prohibits any retaliatory measure against a whistleblower: dismissal, demotion, change of working conditions, harassment, or any other detrimental measure. The burden of proof is reversed: if a whistleblower suffers a detrimental measure after making a report, it is presumed to be retaliation unless the employer proves otherwise. Retaliation is classified as a very serious infringement carrying fines of up to EUR 1 million.
Yes. The law expressly permits outsourcing channel management to an independent third party, which typically provides greater credibility to potential whistleblowers and reduces the administrative burden on the company. BMC offers an outsourced channel service, acting as the independent receiver and preliminary investigator of complaints.
The processing of personal data in a whistleblowing system is subject to the full GDPR framework. A Data Protection Impact Assessment (DPIA) is required before deployment. Data relating to persons mentioned in a complaint may only be retained for the time necessary for the investigation (maximum 3 months if no follow-up action is taken, or throughout proceedings if action continues). The reported person has a right to be informed of the processing, unless notification would compromise the investigation.
A functional whistleblowing channel is a central element of any effective [criminal compliance](/en/legal/criminal-compliance) programme. Spanish courts require evidence of real investigations, documented actions, and corrective measures for a compliance programme to have exculpatory effects on the legal entity's criminal liability. A channel that receives no complaints and triggers no investigations will not satisfy this standard.
Law 2/2023 classifies the absence of a whistleblowing channel for obligated companies as a very serious infringement, with fines of up to EUR 1 million for legal entities. Retaliation against whistleblowers, obstruction of investigations, and breach of confidentiality obligations are also classified as very serious infringements carrying equivalent penalties.
First step

Start with a free diagnostic

Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.

Whistleblowing Channel (EU Directive)

Legal

First step

Start with a free diagnostic

Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.

25+
years experience
5
offices in Spain
500+
clients served

Request your diagnostic

We respond within 4 business hours

Or call us directly: +34 910 917 811

Call Contact