A whistleblowing policy that only describes how to report is missing the two things the EU Whistleblower Directive actually enforces: a pair of deadlines, and a reversal of the burden of proof that changes how every subsequent employment decision has to be documented.
The second one is the reason this belongs on a board agenda rather than in an HR folder.
Who has to have a whistleblowing policy

Article 8(3) applies the obligation to legal entities in the private sector with 50 or more workers. Below that, Article 8(7) lets Member States extend it after a risk assessment — so the national threshold can be lower than the Directive’s.
The exception matters more than the threshold. Article 8(4) states that the 50-worker threshold does not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex — financial services, transport safety and environmental protection instruments. A small firm in scope of those rules needs channels regardless of headcount.
Two practical allowances sit alongside it. Channels may be operated internally or provided externally by a third party, with the Article 9(1) safeguards applying to that third party too. And entities with 50 to 249 workers may share resources for receiving reports and investigating — without diluting their own duties on confidentiality, feedback and addressing the breach.
The two clocks a whistleblowing policy must state
Article 9(1) sets deadlines that most whistleblowing policy documents either omit or state loosely.
- Seven days to acknowledge receipt of the report to the reporting person.
- Three months to provide feedback, measured from the acknowledgement — or, where no acknowledgement was sent, from the expiry of the seven-day period.
Read the second one carefully. Missing the acknowledgement does not pause the feedback clock; it starts it anyway. An organisation that lets a report sit unacknowledged has already spent a week of a three-month budget and has no record that the clock began.
The Directive also requires clear and easily accessible information about reporting externally to competent authorities. A whistleblowing policy that discourages external reporting, or simply omits it, is non-compliant on its face — and in practice the omission is what pushes reporters straight to a regulator.
What a whistleblowing policy channel has to do
Article 9(1)(a) requires channels designed, established and operated in a secure manner ensuring the confidentiality of the identity of the reporting person and any third party mentioned in the report, and preventing access by non-authorised staff.
Note “any third party mentioned”. Protection extends to people named in a report, not only the person making it — which rules out routing reports through a shared mailbox that a team can read.
Article 9(1)(c) requires an impartial person or department to follow up; it may be the same one that receives reports. Article 9(2) requires channels enabling reporting in writing or orally, or both — oral meaning telephone or voice messaging, and on request, a physical meeting within a reasonable timeframe.
That last clause quietly rules out a web-form-only implementation. If someone asks to meet, you have to meet.
The provision that changes how you write the whistleblowing policy
Article 19 prohibits retaliation in any form, and lists it exhaustively enough to be useful: suspension and dismissal, demotion or withheld promotion, transfer of duties or changed hours, withholding of training, a negative performance assessment or employment reference, discipline, coercion, intimidation, harassment or ostracism, and failure to convert a temporary contract where there were legitimate expectations.
Then Article 21(5) reverses the burden of proof. In proceedings relating to a detriment suffered by a reporting person — once that person establishes that they reported and suffered a detriment — it shall be presumed that the detriment was made in retaliation. It is then for the person who took the measure to prove that it was based on duly justified grounds.
The operational consequence is large and rarely drawn out. Any adverse decision affecting someone who has reported — a performance rating, a restructuring, a declined promotion — must be independently evidenced and contemporaneously documented, because you will be defending it, not them. Managers who do not know a report exists cannot protect the organisation, and managers who do know cannot be told why the paperwork suddenly matters. That tension is what a good policy has to resolve.
Dates, and why your obligation is national
The Directive had to be transposed by 17 December 2021, with a derogation letting Member States take until 17 December 2023 for private entities with 50 to 249 workers. Both dates have passed, so the practical question is no longer whether the obligation applies but which national law it applies through — and national implementations vary on thresholds, sanctions and anonymous reporting.
Check the transposing act in each country you employ people in. A group-wide whistleblowing policy written to the Directive alone will be wrong somewhere.
How the whistleblowing policy connects
| Area | Connection |
|---|---|
| ISO 37001 | Requires a reporting mechanism and protection for reporters — the same channel usually serves both |
| ISO 37301 | The compliance management system that gives the policy owners, training and review |
| Records of processing | A reporting channel processes personal data about identified individuals, and needs an entry |
| Coordinated vulnerability disclosure | The security equivalent, with its own confidentiality and follow-up duties |
Where to start
- Confirm your threshold nationally, and check Annex Parts I.B and II in case headcount is irrelevant to you.
- Put both clocks in the whistleblowing policy, and make the seven-day acknowledgement automatic.
- Offer a meeting, since a form-only channel does not satisfy Article 9(2).
- Protect people named in reports, not only reporters.
- Document adverse decisions properly for anyone who has reported, because the presumption runs against you.
- Signpost external reporting clearly rather than burying it.
This guide reflects Directive (EU) 2019/1937 as published on EUR-Lex, read at 16 August 2026. The Directive is transposed nationally — your obligations, thresholds and penalties come from the implementing law in each Member State.
The ISO 37001 Anti-Bribery Toolkit provides 55 editable templates covering the reporting and investigation procedures, the non-retaliation commitments and the case records a whistleblowing policy has to produce.