Law 2/2023 of 20 February (Ley 2/2023), on the protection of persons who report regulatory breaches and on the fight against corruption, transposes the EU Whistleblowing Directive into Spanish law. Since it came into force, companies and public authorities have been required to set up an internal whistleblowing channel that meets the law’s technical and organisational requirements. Failure to comply has significant financial consequences.

Who Law 2/2023 applies to

The obligation to set up an internal whistleblowing channel applies to:

Private sector:

  • Companies with 50 or more employees (in any sector)
  • Political parties, trade unions, employers’ organisations and foundations that receive public funding (regardless of the number of employees)
  • Companies in the financial sector (regardless of size): banking, insurance, investment services, securities markets and payment institutions

Public sector:

  • All public authorities: central government (Administración General del Estado, AGE), the autonomous communities (regions) and local authorities
  • Public bodies and public-law entities
  • Companies that are majority publicly owned

Important: until 1 December 2023, companies with between 50 and 249 employees were allowed to set up a channel shared between several companies. Since that date, the obligation has applied to each company individually.

What the whistleblowing channel must include under the law

Law 2/2023 lays down specific requirements that the whistleblowing channel must meet. An email form or a physical complaints box is not enough.

Mandatory technical requirements

Guaranteed confidentiality: the system must ensure that the whistleblower’s identity is known only to the manager of the internal reporting system and is not accessible to any other employee or executive of the organisation. This means that the channel cannot be run by HR, by the in-house legal department or by anyone who reports to a person who might be the subject of a report.

Anonymous reporting option: the channel must allow reports to be submitted anonymously. This is new compared with earlier legislation: the company cannot reject anonymous reports.

Acknowledgement of receipt within 7 days: the system must send the whistleblower confirmation of receipt within a maximum of 7 calendar days of the report being made.

Response within 3 months: the company or public authority must inform the whistleblower of the action taken or planned within a maximum of 3 months of receipt (extendable to 6 months in complex cases).

Independence of the system manager: the person responsible for the system must be independent in carrying out investigations and have direct access to the governing body. In many cases, this role is outsourced to an external lawyer or an independent compliance officer.

Record-keeping: every report must be recorded with its date, its content and the action taken. The records must be kept for at least 3 years.

Which breaches the channel must allow people to report

The channel must cover, as a minimum:

  • Breaches of European Union law
  • Breaches of Spanish law (criminal, administrative and employment law)
  • Breaches of the organisation’s internal rules
  • Acts or omissions that may constitute corruption

The law is deliberately broad: the company cannot restrict the scope of the channel to only some categories of breach.

The penalties for failing to comply with Law 2/2023

The penalty regime is one of the strictest in the field of compliance in Spain:

InfringementClassificationMaximum penalty
Not having a whistleblowing channel when one is mandatoryVery serious€1,000,000 (companies) / €500,000 (individuals)
A channel that does not meet the technical requirementsSerious€300,000 (companies) / €100,000 (individuals)
Retaliation against the whistleblowerVery serious€1,000,000 + compensation for the whistleblower
Breach of confidentialityVery serious€1,000,000
Failure to resolve a report within the deadlineSerious€300,000

The power to impose penalties lies with the Independent Whistleblower Protection Authority (Autoridad Independiente de Protección del Informante, A.A.I.), a body created by the law itself.

Technical security requirements: why the ENS matters here

A whistleblowing channel handles particularly sensitive information: whistleblowers’ identities, details of alleged breaches and data about people under investigation. Law 2/2023 does not explicitly mention the National Security Framework (Esquema Nacional de Seguridad, ENS), but it does require the system to guarantee the confidentiality and integrity of the information.

For public authorities, the ENS is mandatory for the whistleblowing channel too, since it is an information system that handles the personal data of citizens or public employees. The system is usually categorised as medium, which requires third-party certification.

For private companies, the ENS is not required by law, but using a supplier with ENS and/or ISO 27001 certification is the most robust way of demonstrating that appropriate technical measures have been taken to guarantee the confidentiality the law requires. In the event of litigation or an investigation by the A.A.I., that certification is an important line of defence.

Exactly what it means for a supplier to be certified – the issuing body, scope and validity of its ENS and ISO 27001 certification – is set out on CEDESA’s certifications page, which serves as a benchmark for what is worth asking for in writing.

How to set up the whistleblowing channel: practical steps

Step 1: Determine whether the obligation applies

Check the number of employees, the sector of activity and any public ownership. If you are in doubt, consult a lawyer who specialises in compliance, or the software supplier, before starting the project.

Step 2: Decide between in-house and outsourced management

In-house management: the channel manager is an employee or executive of the company, usually the compliance officer or the head of legal. This is valid if the person appointed is genuinely independent and has access to the board of directors. The risk: a conflict of interest if senior management itself has to be investigated.

Outsourced management: the channel manager is an external law firm or another specialist company. This removes the conflict of interest and lends credibility in the eyes of whistleblowers. It is recommended for companies without a compliance officer of their own.

Step 3: Select and implement the technology platform

The platform must provide:

  • An anonymous reporting form available 24/7
  • Encryption of communications in transit and at rest
  • An anonymised two-way communication channel (for putting questions to the whistleblower without revealing their identity)
  • A case management workflow: logging, assignment, deadline tracking and resolution
  • An immutable log of every action (for audit purposes)
  • Role-based access control with segregation of duties

If no off-the-shelf platform fits the organisation’s internal workflow (integration with case files, the HR system or the document registry), the channel can be built as a custom development: CEDESA handles this through its custom software service, with the ENS and ISO 27001 as the foundation of the architecture.

Step 4: Communicate the existence of the channel

The law requires all employees to be informed of the existence of the channel, its scope and the protection it gives whistleblowers. This communication must be documented.

Step 5: Train the channel manager

The channel manager must receive specific training on the investigation procedure, the statutory deadlines, the processing of personal data and the safeguards for whistleblowers.

Frequently asked questions about the whistleblowing channel

Does a company with 30 employees have to set up a whistleblowing channel?

No, provided it is not in a regulated financial sector and has no public ownership. For the private sector in general, the obligation starts at 50 employees. Below that threshold, having a channel is good compliance practice but not a legal obligation.

Can the HR channel or the director’s email address be used as the whistleblowing channel?

It would not meet the requirements of the law. The channel must guarantee the independence of its manager and the confidentiality of the whistleblower’s identity. A corporate email account managed by HR meets neither requirement.

Does the GDPR affect the whistleblowing channel?

Yes. The channel processes personal data (of the whistleblower, the person under investigation and witnesses) and must comply with the GDPR. That means a legal basis for the processing, information for the data subject (to the extent that it does not compromise the investigation), retention periods and appropriate security measures. The data controller is the company, not the software supplier.

Can whistleblowers be required to identify themselves before their report is processed?

No. The law prohibits the rejection of anonymous reports. The company may allocate fewer resources to investigating anonymous reports than identified ones, but it cannot ignore them or close them without first investigating.

How long does a company have to set up the channel if it does not yet have one?

The obligation is already in force. If your company has more than 50 employees and no whistleblowing channel, it has been in breach since 1 June 2023 (companies with more than 249 employees) or since 1 December 2023 (companies with 50 to 249 employees). Implementation at short notice is possible: with a specialist supplier, the channel can be up and running in 2–4 weeks.