Whistleblowing Channel: Law 2/2023 Compliance Made Simple
Implementation of internal whistleblowing channels under Spanish Law 2/2023 transposing EU Directive 2019/1937. Full Internal Information System design, investigation protocols, and confidentiality guarantees.
Why a contact form is not a compliant whistleblowing channel under Law 2/2023
Does this apply to your business?
Does your company have more than 50 employees and still lacks a formally implemented whistleblowing channel with a designated responsible person?
Has your existing channel ever received a complaint and processed it within the statutory 7-day acknowledgement and 3-month response deadlines?
Has your company conducted the GDPR Data Protection Impact Assessment specifically required for whistleblowing systems?
Do your managers understand the reversed burden of proof that applies if a whistleblower is dismissed or disadvantaged after making a report?
0 of 4 questions answered
Our whistleblowing channel implementation process
System design & organisational analysis
We assess your company's size, group structure, and risk profile to design the optimal channel model: internally managed by the designated responsible person, or outsourced to an independent third party for greater perceived impartiality.
Technical implementation & documentation
We configure the technical channel with encryption and anonymity options, draft the corporate whistleblowing policy, the operating rules, and the acknowledgement and follow-up procedures within the statutory deadlines (7 days for acknowledgement, 3 months for response).
Responsible person designation & training
We advise on the appointment of the System Responsible Person, provide training on investigation protocols, confidentiality obligations, and whistleblower protection measures against retaliation.
GDPR coordination & ongoing maintenance
We coordinate with the DPO to ensure GDPR compliance in the processing of personal data in complaints, conduct the required Data Protection Impact Assessment, and maintain the system updated as regulations and supervisory authority guidance evolve.
The challenge
Law 2/2023 requires companies with 50 or more employees to implement an Internal Information System with real confidentiality guarantees, a designated responsible person, legal deadlines for processing, and effective anti-retaliation protections. Most companies that believe they have complied have installed a contact form — not a compliant system. A non-functional channel can generate greater liability than having none at all.
Our solution
We design and implement the complete Internal Information System (SII): technical channel with confidentiality and anonymity options, corporate whistleblowing policy, responsible person designation, investigation protocol with statutory deadlines, staff training, and GDPR coordination. A fully audited and documented system that meets every requirement of the EU Directive and Spanish Law 2/2023.
Spain's whistleblowing framework is established by Law 2/2023 of 20 February on the Protection of Persons who Report Regulatory Infringements and the Fight against Corruption, which transposed EU Directive 2019/1937 on whistleblower protection. Law 2/2023 requires private companies with 50 or more employees, public entities, and all companies operating in financial services regardless of size to implement an Internal Information System (Sistema Interno de Información, SII) with specific requirements: a confidential and optionally anonymous reporting channel, a designated responsible person (Responsable del Sistema), acknowledgement within 7 days, a substantive response within 3 months, anti-retaliation protections for reporters, and coordination with GDPR obligations for personal data processed through the channel. Non-compliant organisations face sanctions of up to EUR 1 million for serious infringements.
Our team combines expertise in regulatory compliance, employment law, and data protection to implement whistleblowing systems that function in practice — not only on paper.
The Gap Between Having a Channel and Being Compliant
Law 2/2023, transposing EU Directive 2019/1937 into Spanish law, establishes a comprehensive framework for whistleblower protection that extends far beyond enabling a contact form. The law requires a structured Internal Information System with a formally designated responsible person, statutory processing deadlines, genuine confidentiality guarantees, and effective protection against retaliation. Organisations that have installed a generic inbox or a third-party whistleblowing tool without structuring the system around it are technically non-compliant — and potentially exposed to sanctions reaching EUR 1 million.
Designing a System That Works Under Pressure
The first step in any implementation is system design. A 60-employee manufacturing company and a 5,000-employee financial services group require fundamentally different architectures. We analyse the organisational structure, risk profile, and corporate culture to recommend whether the channel should be managed internally by the designated responsible person or outsourced to an independent third party. Outsourcing typically provides greater perceived credibility for potential whistleblowers — a critical factor in whether employees actually use the system — and removes the conflict-of-interest concerns that arise when the channel is managed internally.
Integration with Criminal Compliance
The relationship between a whistleblowing channel and a criminal compliance programme is direct and legally significant. Spanish courts have confirmed that a functional internal reporting system is one of the elements they examine when assessing whether a legal entity’s compliance programme should have exculpatory effects on criminal liability. A channel that exists on paper but generates no investigations and no corrective measures will not satisfy this standard. We design the investigation protocol to produce the documented evidence trail that compliance programmes require.
GDPR Considerations Specific to Whistleblowing
The processing of personal data in whistleblowing systems presents specific challenges that require close coordination with the Data Protection Officer. The AEPD has issued specific guidance on impact assessments for these systems, retention periods for data relating to both whistleblowers and reported individuals, and the limits of the reported person’s right to information when it could compromise the investigation. We integrate all of these requirements from day one, avoiding the retroactive GDPR remediation that many organisations face after deploying their channels without adequate data protection planning.
The Internal Investigation Protocol
A whistleblowing channel is only as effective as the investigation process that follows a report. Law 2/2023 requires the designated responsible person to acknowledge receipt of a report within seven days and to communicate the outcome of the investigation within three months. These deadlines are not aspirational — they are legal obligations with sanction exposure attached. We design investigation protocols that specify who conducts the investigation for different categories of reported conduct, what evidence-gathering steps are required, how potential conflicts of interest are managed, and how the outcome is communicated to the reporter.
The Responsible Person: Appointment and Training
The designation of the responsible person (Responsable del Sistema) is a formal appointment that must be documented. Law 2/2023 requires the responsible person to have the authority to conduct investigations, access relevant information, and recommend corrective measures. Where the responsible person role is outsourced, our team manages the complete lifecycle: report receipt, acknowledgement, investigation coordination, outcome communication, and compliance documentation. The integration with the criminal compliance programme ensures that reports alleging criminal conduct are handled with the procedural rigour that a potential criminal proceeding requires.
Interaction with the Anti-Retaliation Framework
Law 2/2023 establishes comprehensive protections for reporters against retaliation: dismissal, demotion, salary reduction, change of duties, coercion, discrimination, and negative performance assessment are all forms of prohibited retaliation. The law creates a reversal of the burden of proof in employment proceedings. Our employment law team advises on how to handle situations where a report is received and an employment decision affecting the reporter is subsequently required — ensuring the decision is legally defensible and demonstrably independent of the report.
Multinational Groups and Multi-Jurisdiction Channels
For multinational groups with operations in multiple EU member states, Law 2/2023 allows a centralised internal channel at group level as long as the channel is genuinely accessible to employees in all jurisdictions. We design group-level whistleblowing systems that comply with the requirements of the EU Directive as transposed in each operating jurisdiction, manage the cross-border data flows in compliance with GDPR international transfer rules, and ensure that the local law variations across member states are reflected in the system’s operational procedures.
Sectors Most Affected
Financial services: all companies in the financial sector are subject to Law 2/2023 regardless of employee count, due to the sector-wide applicability of the EU Directive. Financial sector entities also have overlapping whistleblowing-adjacent obligations under DORA, Solvency II, and MiFID II that require coordination.
Large companies (50+ employees): the primary obligated category. The focus for established programmes is quality assurance — whether the system is genuinely trusted, whether investigations produce documented outcomes, and whether the governing body receives meaningful reporting on channel activity.
Public sector and public contract recipients: public entities and companies that receive public grants or contracts above EUR 15 million in the prior year are in scope regardless of employee count.
Professional services: professional secrecy creates specific complications for whistleblowing channels. The investigation protocol must be designed to respect client privilege while achieving the objectives of the Law.
Company Size Segmentation
SMEs (10–49 employees): not currently obligated for the internal channel, though external reporting to the AIAI (Autoridad Independiente de Protección del Informante) is available for employees of any-size organisation. SMEs preparing for growth to 50+ employees should implement proactively.
Companies with 50–249 employees: obligated since 1 December 2023. Can share an internal channel within a group structure, subject to conditions. The channel must be accessible to employees, former employees, shareholders, suppliers, and subcontractors.
Companies with 250+ employees: obligated since June 2023. Full implementation required including dedicated responsible person appointment, investigation protocol, and annual activity report to the governing body.
Worked Example: Channel Implementation for a Manufacturing Group
A Spanish manufacturing group (180 employees across three entities) implemented Law 2/2023 compliance. BMC’s approach: group-level shared channel covering all three entities. Outsourced management model recommended due to ownership concentration. External Responsable del Sistema appointed through BMC’s compliance team. Third-party anonymous reporting platform deployed at all facilities. Investigation protocol designed for three categories (labour disputes, regulatory infringements, criminal conduct). DPIA completed and retention policy established. All managers trained on anti-retaliation obligations. Full implementation: 8 weeks.
Common Mistakes We Fix
-
Deploying a technology platform without building the governance structure around it. A reporting tool is not a compliant system. The law requires a designated responsible person, a documented investigation procedure, GDPR-compliant data architecture, and anti-retaliation protocols.
-
Managing the channel internally without addressing conflict-of-interest risk. Where the responsible person reports to executives who could be the subject of reports, whistleblowers are unlikely to use the channel. External management provides the perceived independence that encourages actual use.
-
Not integrating with the criminal compliance programme. Reports alleging criminal conduct must be handled with the evidentiary rigour that criminal proceedings require. A standard HR investigation does not meet this standard.
-
Missing the GDPR requirements. Whistleblowing channels process sensitive personal data. A system without a DPIA, without a retention policy, and without a procedure for the reported individual’s rights is simultaneously non-compliant with Law 2/2023 and GDPR.
-
Not training line managers on anti-retaliation obligations. The most common retaliation is not dramatic — it is the negative performance review or exclusion from meetings applied to an employee who filed a report. The burden-of-proof reversal means the employer must prove the adverse treatment was unconnected to the report.
Regulatory Framework: Law 2/2023 and EU Directive 2019/1937
Law 2/2023 of 20 February on the Protection of Persons who Report Regulatory Infringements transposes EU Directive 2019/1937. Key provisions:
Art. 7 Law 2/2023: internal reporting channel obligation for private entities with 50+ employees, public entities, and all financial-sector entities regardless of size. The channel must be designed to guarantee the confidentiality of the reporter’s identity.
Art. 9 Law 2/2023: the Responsable del Sistema must acknowledge receipt within 7 days and communicate the outcome of the investigation within 3 months (extendable to 6 months for complex cases).
Art. 14 Law 2/2023: comprehensive anti-retaliation protections. Retaliation includes dismissal, salary reduction, change of duties, negative references, denial of training, exclusion from promotion, and psychological pressure.
Art. 16 Law 2/2023: reversal of burden of proof in employment proceedings where retaliation is alleged. The employer must prove that adverse treatment was not connected to the report.
Arts. 20-21 Law 2/2023: sanctions regime. Failure to implement the required system: sanctions of up to EUR 300,000 (serious) or EUR 1,000,000 (very serious). Retaliation against reporters: up to EUR 1,000,000.
How We Work
Phase 1 — Assessment (1 week): review of governance structure, employee population, regulatory obligations, and risk profile. Recommendation on internal vs external management model.
Phase 2 — Implementation (4–6 weeks): responsible person designation, investigation protocol design, GDPR data architecture, technology deployment, employee and manager training.
Phase 3 — Ongoing management: where we act as external Responsable del Sistema, we manage the complete channel lifecycle — report receipt, 7-day acknowledgement, investigation coordination, 3-month outcome communication, and annual governing body report.
Fixed-fee implementation packages are available for all size categories.
The External Reporting Channel and the AIAI
Law 2/2023 established the AIAI (Autoridad Independiente de Protección del Informante), the national external reporting body to which any person can report infringements of EU law directly, bypassing the internal company channel. The AIAI has investigative powers and coordinates with the Ministerio de Hacienda, AEAT, AEPD, and other regulatory bodies.
For companies, a functional, trustworthy internal channel reduces the probability of employees going directly to the AIAI — which generates a regulatory investigation with external publicity. If the internal channel fails to investigate credibly, employees will use the AIAI, and the company faces the consequences of an external investigation it does not control.
ESG and Supply Chain Dimension
The Corporate Sustainability Due Diligence Directive (CSDDD) requires affected persons — including supply-chain workers — to be able to report human rights and environmental concerns. The CSRD (ESRS G1) requires disclosure of how many reports were received, their categories, outcomes, and any remediation measures taken. A channel that generates no reports (because it is not trusted) or produces reports but no documented outcomes is a CSRD disclosure problem as well as a Law 2/2023 compliance failure.
Geographic Coverage
Our whistleblowing practice covers all of Spain. For Madrid-headquartered companies, our local presence enables rapid response to AIAI investigation notifications and direct engagement with the authority. For multinational groups with Spanish operations, we advise on the Spanish-specific compliance requirements that must be layered onto group-level programmes — including anti-retaliation protections, Spanish-language accessibility requirements, and the formal Responsable del Sistema appointment process. For cross-border investigations, we coordinate with correspondent law firms across the EU to manage multi-jurisdiction evidence gathering and data protection compliance. Our whistleblowing practice is available to companies across all Spanish provinces, with in-person meetings in Madrid and Málaga and remote service for all other locations. Initial consultations to assess compliance status and the recommended implementation approach are provided at no charge.
The External Reporting Channel and the AIAI
Law 2/2023 also established the AIAI (Autoridad Independiente de Protección del Informante), the independent external reporting authority to which any person can report infringements of EU law directly, bypassing the internal company channel. The AIAI has investigative powers and can coordinate with the Ministerio de Hacienda, the AEAT, the AEPD, and other regulatory bodies.
For companies, the existence of the AIAI creates both an incentive and a risk. The incentive: a functional, trustworthy internal channel reduces the probability of employees going directly to the AIAI — which generates a regulatory investigation with external publicity. The risk: if the internal channel fails to investigate credibly, employees will use the AIAI, and the company will face the consequences of an external investigation rather than an internal one it controls.
Well-designed internal channels — managed by an independent, trusted responsible person — are the most effective tool for keeping whistleblowing internal, managing it appropriately, and demonstrating compliance. Channels that exist on paper but produce no investigations generate the worst of both worlds: regulatory sanction for non-compliance and employee distrust that leads to external reporting.
ESG and Supply Chain Dimension
Whistleblowing channels are increasingly relevant beyond the strict employment and criminal compliance dimensions. The Corporate Sustainability Due Diligence Directive (CSDDD), which will require large EU companies to monitor their supply chains for human rights and environmental abuses, includes a requirement for affected persons (including supply-chain workers) to be able to report concerns. The CSRD (Corporate Sustainability Reporting Directive) requires disclosure of the governance of the internal reporting system and the outcomes of investigations under ESRS G1.
For companies subject to CSRD, the whistleblowing channel is part of the ESG governance infrastructure that must be disclosed — how many reports were received, what categories, what outcomes, what remediation measures were taken. A channel that generates no reports (because it is not trusted) or that produces reports but no documented outcomes (because investigations are poorly managed) is a CSRD disclosure problem as well as a Law 2/2023 problem.
Geographic Coverage
Our whistleblowing compliance practice covers all of Spain, with particular experience in:
Madrid: the AIAI and the Ministerio de Justicia (which oversees Law 2/2023 enforcement in the private sector) are based in Madrid. For companies headquartered in Madrid, our local presence enables rapid response to AIAI investigation notifications and direct engagement with the authority.
Multinational groups with Spanish operations: Law 2/2023 requires that the channel be accessible and functional for all employees in Spain — even if the group’s global whistleblowing programme is managed from another jurisdiction. We advise on the Spanish-specific compliance requirements that must be layered onto group-level programmes, including the specific anti-retaliation protections, the Spanish-language accessibility requirements, and the Responsable del Sistema appointment.
Cross-border investigations: where a report made through the Spanish channel concerns conduct in another jurisdiction, the investigation protocol must address how evidence is gathered across borders, how local employment law in each relevant jurisdiction affects the investigation, and how findings are communicated across jurisdictions without breaching data protection requirements. Our network of correspondent law firms across the EU covers the most common multi-jurisdiction investigation scenarios.
Real results in whistleblowing channel compliance
We had a form on our intranet that we called a whistleblowing channel. BMC showed us it was missing almost everything the law requires. They built us a complete system in six weeks — designated responsible person, trained, DPIA completed, and the first real complaint handled within 48 hours. The difference is night and day.
Experienced team with local insight and international reach
What our whistleblowing channel service includes
Internal Information System (SII) Design
Organisational analysis, channel model selection (internal or outsourced), drafting of the corporate whistleblowing policy and operating rules covering all elements required by Law 2/2023 and the EU Directive.
Technical Channel with Confidentiality Guarantees
Configuration of the complaint-receipt platform with encryption, anonymous communication options, whistleblower follow-up tracking, and a full audit trail of all actions taken on each case.
Investigation Protocol & Deadline Management
Documented procedure for opening, investigating, and closing complaint files, with statutory deadlines integrated (7-day acknowledgement, 3-month response) and escalation paths to governance bodies where required.
Training & Internal Communication
Training for the Responsible Person and key management on investigation obligations and anti-retaliation rules; company-wide communication on the channel's existence and operation; whistleblower protection awareness materials.
GDPR Coordination & DPIA
Data Protection Impact Assessment specific to the whistleblowing system, DPO coordination, and establishment of data retention and deletion policies for personal data of whistleblowers and reported persons.
Results that speak for themselves
Criminal Compliance Spain: Construction Group Case | BMC
Criminal compliance program implemented in 6 months, whistleblower channel operational, AENOR certification obtained, and prosecution risk effectively mitigated.
GDPR Healthcare Spain: Compliance Case Study | BMC
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
AML compliance program for a real estate development group
SEPBLAC inspection passed with minor observations only, zero sanctions. Full AML program operational within 90 days.
Reference guides
Post-Brexit: your British company operating in Spain with the right structure
post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.
View guideAML compliance in Spain 2026: what your business must know about anti-money laundering regulation
Spain AML compliance 2026: SEPBLAC obligations, risk-based approach, PBC manual, UBO verification, and suspicious transaction reporting. Expert service from BMC.
View guideComprehensive legal services for businesses
Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.
View guideBuy property in Spain with confidence — and without the horror stories
Buying property in Spain 2026: NIE, conveyancing, ITP tax, mortgage advice, and due diligence for foreign buyers. Step-by-step guide from BMC property lawyers.
View guideThe collective agreement that governs your workforce: understand it and negotiate from strength
Spain collective bargaining guide: union negotiation obligations, ERE/ERTE triggers, works council rights, agreement registration, and how BMC protects employer interests.
View guideYour commercial lease agreement: get the clauses right before you sign
Spain commercial lease guide: LAU legal framework, rent review clauses, break options, guarantee structures, and key negotiation points for tenants and landlords.
View guideAnalysis and perspectives
Frequently asked questions about whistleblowing channels in Spain
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Whistleblowing Channel (EU Directive)
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Anti-Money Laundering (AML)
AML/CFT compliance programme for entities subject to Spain's Law 10/2010: policies, procedures, training, and SEPBLAC liaison.
Saber másCriminal Compliance
Corporate criminal compliance programmes to exempt or mitigate the criminal liability of legal entities under Article 31 bis of the Spanish Criminal Code.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másEmployment Compliance
Comprehensive employment compliance programme: working-time registration, equality plans, pay transparency, harassment protocols, remote work agreements, and labour inspection defence.
Saber másKey terms
CSRD (Corporate Sustainability Reporting Directive)
EU directive requiring large companies and listed SMEs to report on sustainability matters using the…
Read definitionData Protection Impact Assessment (DPIA)
A Data Protection Impact Assessment (DPIA) is a structured risk analysis process required by GDPR…
Read definitionData Protection Officer (DPO)
A Data Protection Officer (DPO) is a designated individual responsible for overseeing an…
Read definitionDue Diligence
Due diligence is the structured investigation and analysis of a target company or asset before a…
Read definitionWhistleblowing Channel
A whistleblowing channel is a secure reporting mechanism allowing employees, contractors, suppliers,…
Read definitionTalk to the partner in charge
Response within 24 business hours. First meeting free.