Whistleblowing Channel: Law 2/2023 Compliance Made Simple
Implementation of internal whistleblowing channels under Spanish Law 2/2023 transposing EU Directive 2019/1937. Full Internal Information System design, investigation protocols, and confidentiality guarantees.
Does this apply to your business?
Does your company have more than 50 employees and still lacks a formally implemented whistleblowing channel with a designated responsible person?
Has your existing channel ever received a complaint and processed it within the statutory 7-day acknowledgement and 3-month response deadlines?
Has your company conducted the GDPR Data Protection Impact Assessment specifically required for whistleblowing systems?
Do your managers understand the reversed burden of proof that applies if a whistleblower is dismissed or disadvantaged after making a report?
0 of 4 questions answered
Our whistleblowing channel implementation process
System design & organisational analysis
We assess your company's size, group structure, and risk profile to design the optimal channel model: internally managed by the designated responsible person, or outsourced to an independent third party for greater perceived impartiality.
Technical implementation & documentation
We configure the technical channel with encryption and anonymity options, draft the corporate whistleblowing policy, the operating rules, and the acknowledgement and follow-up procedures within the statutory deadlines (7 days for acknowledgement, 3 months for response).
Responsible person designation & training
We advise on the appointment of the System Responsible Person, provide training on investigation protocols, confidentiality obligations, and whistleblower protection measures against retaliation.
GDPR coordination & ongoing maintenance
We coordinate with the DPO to ensure GDPR compliance in the processing of personal data in complaints, conduct the required Data Protection Impact Assessment, and maintain the system updated as regulations and supervisory authority guidance evolve.
The challenge
Law 2/2023 requires companies with 50 or more employees to implement an Internal Information System with real confidentiality guarantees, a designated responsible person, legal deadlines for processing, and effective anti-retaliation protections. Most companies that believe they have complied have installed a contact form — not a compliant system. A non-functional channel can generate greater liability than having none at all.
Our solution
We design and implement the complete Internal Information System (SII): technical channel with confidentiality and anonymity options, corporate whistleblowing policy, responsible person designation, investigation protocol with statutory deadlines, staff training, and GDPR coordination. A fully audited and documented system that meets every requirement of the EU Directive and Spanish Law 2/2023.
Spain's whistleblowing framework is established by Law 2/2023 of 20 February on the Protection of Persons who Report Regulatory Infringements and the Fight against Corruption, which transposed EU Directive 2019/1937 on whistleblower protection. Law 2/2023 requires private companies with 50 or more employees, public entities, and all companies operating in financial services regardless of size to implement an Internal Information System (Sistema Interno de Información, SII) with specific requirements: a confidential and optionally anonymous reporting channel, a designated responsible person (Responsable del Sistema), acknowledgement within 7 days, a substantive response within 3 months, anti-retaliation protections for reporters, and coordination with GDPR obligations for personal data processed through the channel. Non-compliant organisations face sanctions of up to EUR 1 million for serious infringements.
Our team combines expertise in regulatory compliance, employment law, and data protection to implement whistleblowing systems that function in practice — not only on paper.
The Gap Between Having a Channel and Being Compliant
Law 2/2023, transposing EU Directive 2019/1937 into Spanish law, establishes a comprehensive framework for whistleblower protection that extends far beyond enabling a contact form. The law requires a structured Internal Information System with a formally designated responsible person, statutory processing deadlines, genuine confidentiality guarantees, and effective protection against retaliation. Organisations that have installed a generic inbox or a third-party whistleblowing tool without structuring the system around it are technically non-compliant — and potentially exposed to sanctions reaching EUR 1 million.
Designing a System That Works Under Pressure
The first step in any implementation is system design. A 60-employee manufacturing company and a 5,000-employee financial services group require fundamentally different architectures. We analyse the organisational structure, risk profile, and corporate culture to recommend whether the channel should be managed internally by the designated responsible person or outsourced to an independent third party. Outsourcing typically provides greater perceived credibility for potential whistleblowers — a critical factor in whether employees actually use the system — and removes the conflict-of-interest concerns that arise when the channel is managed internally.
Integration with Criminal Compliance
The relationship between a whistleblowing channel and a criminal compliance programme is direct and legally significant. Spanish courts have confirmed that a functional internal reporting system is one of the elements they examine when assessing whether a legal entity’s compliance programme should have exculpatory effects on criminal liability. A channel that exists on paper but generates no investigations and no corrective measures will not satisfy this standard. We design the investigation protocol to produce the documented evidence trail that compliance programmes require.
GDPR Considerations Specific to Whistleblowing
The processing of personal data in whistleblowing systems presents specific challenges that require close coordination with the Data Protection Officer. The AEPD has issued specific guidance on impact assessments for these systems, retention periods for data relating to both whistleblowers and reported individuals, and the limits of the reported person’s right to information when it could compromise the investigation. We integrate all of these requirements from day one, avoiding the retroactive GDPR remediation that many organisations face after deploying their channels without adequate data protection planning.
Real results in whistleblowing channel compliance
We had a form on our intranet that we called a whistleblowing channel. BMC showed us it was missing almost everything the law requires. They built us a complete system in six weeks — designated responsible person, trained, DPIA completed, and the first real complaint handled within 48 hours. The difference is night and day.
Experienced team with local insight and international reach
What our whistleblowing channel service includes
Internal Information System (SII) Design
Organisational analysis, channel model selection (internal or outsourced), drafting of the corporate whistleblowing policy and operating rules covering all elements required by Law 2/2023 and the EU Directive.
Technical Channel with Confidentiality Guarantees
Configuration of the complaint-receipt platform with encryption, anonymous communication options, whistleblower follow-up tracking, and a full audit trail of all actions taken on each case.
Investigation Protocol & Deadline Management
Documented procedure for opening, investigating, and closing complaint files, with statutory deadlines integrated (7-day acknowledgement, 3-month response) and escalation paths to governance bodies where required.
Training & Internal Communication
Training for the Responsible Person and key management on investigation obligations and anti-retaliation rules; company-wide communication on the channel's existence and operation; whistleblower protection awareness materials.
GDPR Coordination & DPIA
Data Protection Impact Assessment specific to the whistleblowing system, DPO coordination, and establishment of data retention and deletion policies for personal data of whistleblowers and reported persons.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Analysis and perspectives
Frequently asked questions about whistleblowing channels in Spain
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Whistleblowing Channel (EU Directive)
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Anti-Money Laundering (AML)
AML/CFT compliance programme for entities subject to Spain's Law 10/2010: policies, procedures, training, and SEPBLAC liaison.
Saber másCriminal Compliance
Corporate criminal compliance programmes to exempt or mitigate the criminal liability of legal entities under Article 31 bis of the Spanish Criminal Code.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másEmployment Compliance
Comprehensive employment compliance programme: working-time registration, equality plans, pay transparency, harassment protocols, remote work agreements, and labour inspection defence.
Saber más