After the Report: What the EU Whistleblowing Directive Asks Firms to Prove

This informal CPD article, ‘After the Report: What the EU Whistleblowing Directive Asks Firms to Prove’, was provided by Nikolas Demetriades, CFA, who holds the CySEC Advanced and AML certifications. He is the founder of CPDs.Academy, a CPD training platform delivering compliance education for professionals in EU-regulated financial services.

Most regulated firms will by now be familiar with whistleblowing policies and internal reporting arrangements. The harder question is what happens after somebody reports. Directive (EU) 2019/1937 sets minimum standards protecting people who report specified breaches of Union law within its scope, provided the conditions for protection are met. Member States were required to transpose the Directive by 17 December 2021. Private legal entities employing between 50 and 249 workers had until 17 December 2023 for one particular obligation: establishing internal reporting channels under Article 8(3) (1).

The more demanding point for a compliance function is what happens to the evidential position after a protected report and an alleged detriment. On that question, the Directive does something worth understanding precisely. In defined proceedings, it reverses the burden of proof.

A list that is not a list

Article 19 requires Member States to prohibit any form of retaliation against persons protected by the Directive, including threats and attempted retaliation. It then gives fifteen lettered examples. Some are obvious: dismissal and demotion. Others can look like ordinary management decisions, including withholding training, a negative performance assessment, changes to duties or working hours, and failure to renew a temporary contract. Others are overtly hostile, such as harassment, blacklisting and psychiatric or medical referrals (1).

The way the provision is constructed matters more than the number of examples. Article 19 prohibits any form of retaliation and then identifies particular forms it may take. The list is therefore not exhaustive. The fact that a management measure does not appear expressly in Article 19 does not put it outside the prohibition if it otherwise amounts to retaliation (1).

The provision that shifts the burden

Article 21(5) changes the practical calculation. In proceedings before a court or other authority concerning detriment suffered by a reporting person, once that person establishes that they reported or made a public disclosure and suffered a detriment, the detriment is presumed to have been retaliatory. The person who imposed the detrimental measure must then show that duly justified grounds lay behind it (1).

That mechanism matters for two reasons. The reporting person does not first have to prove retaliatory motive or establish a prima facie causal link between the report and the measure. The Commission's 2024 transposition report criticised national rules that imposed just such an additional requirement (2).

The argument then shifts to the reason for the decision. For a firm, that is likely to be heavily documentary in practice. A decision may have been entirely legitimate, but if its basis was never recorded the organisation may later have to reconstruct its reasoning in proceedings where the statutory presumption is already operating. A contemporaneous record showing the grounds for the decision and how comparable cases were treated puts it in a materially better position. The Directive does not say that documentary records determine the outcome. It does create circumstances in which the reason for a detrimental measure may have to be proved.

Who is protected, and it is wider than the payroll

Article 4 has a broad personal scope. It covers workers, including civil servants, the self-employed, shareholders and members of administrative, management or supervisory bodies, including non-executive members, as well as volunteers and paid and unpaid trainees. It also covers people working under the supervision and direction of contractors, subcontractors and suppliers (1).

The protection reaches both backwards and forwards in time. It applies where the work-based relationship has ended and where it has not yet begun, if the relevant information was acquired during recruitment or other pre-contractual negotiations (1).

Chapter VI protection also extends, where relevant, beyond the reporting person. It covers facilitators, connected third persons such as colleagues or relatives exposed to retaliation through their own work, and legal entities in which the reporter holds an ownership, employment or comparable connection (1). The practical consequence is that the population to consider after a report may be wider than the person who submitted it.

The channel, the clock, and the threshold that does not apply

Article 8 generally requires private legal entities with 50 or more workers to establish internal reporting channels. The 50-worker threshold does not apply to entities falling within the scope of the Union acts listed in Parts I.B and II of the Annex. Those provisions include substantial parts of the financial-services, investment-funds, payment-services and anti-money-laundering framework. A firm within the scope of those acts cannot rely simply on being below the ordinary 50-worker threshold (1).

Sector-specific whistleblowing rules also pre-dated the Directive and were deliberately preserved. The market-abuse regime is one example: Regulation (EU) No 596/2014 and Commission Implementing Directive (EU) 2015/2392 already contained specific whistleblower provisions (3).

Article 9 sets the procedural timetable for internal reporting. Receipt must be acknowledged within seven days. Feedback must be provided within a reasonable period not exceeding three months from the acknowledgement, or from expiry of the seven-day period if no acknowledgement was sent (1).

cpd-CPDs.Academy-Article-15(1)(a)-protects-a-public-disclosure
Article 15(1)(a) protects a public disclosure

Internal reporting channels may enable reporting in writing, orally, or both. Where oral reporting is available, the Directive provides for reporting by telephone or another voice-messaging system and, at the reporting person's request, a physical meeting within a reasonable period (1). Article 16 separately protects not only the person's name but also information from which their identity could be directly or indirectly deduced (1).

The three-month internal deadline matters, but not in quite the way it is sometimes described. Missing it does not by itself give the reporting person an automatic protected route straight to public disclosure.

Article 15(1)(a) protects a public disclosure where the person first reported internally and externally, or reported directly externally, and no appropriate action was taken within the applicable statutory timeframe. For an external report, the competent authority normally has up to three months to provide feedback, extendable to six months in duly justified cases (1).

There is also a separate route to protected public disclosure without that prior sequence. Article 15(1)(b) applies where the person has reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest, or, in the case of external reporting, that there is a risk of retaliation or a low prospect of the breach being effectively addressed because of the particular circumstances (1).

For a firm, missing the internal timetable is therefore serious because it weakens confidence in the internal process and can push a reporting person towards external escalation. It is not, by itself, the legal event that makes public disclosure protected.

What cannot be signed away

Article 24 is short and direct. Rights and remedies under the Directive cannot be waived or limited by an agreement, policy, form or condition of employment, including a pre-dispute arbitration agreement (1). Contractual confidentiality provisions or settlement terms cannot therefore be used to contract out of protected reporting rights.

Article 21 approaches the same problem from the liability side. A person who reports or publicly discloses information in accordance with the Directive is not treated as having breached a restriction on disclosure, and incurs no liability in respect of the report or disclosure, provided they had reasonable grounds to believe that it was necessary to reveal a breach (1).

Article 21(7) also protects persons covered by Article 4 in legal proceedings including those for defamation, breach of copyright, breach of secrecy, breach of data-protection rules and disclosure of trade secrets, subject to the Directive's conditions (1).

The protection is not one-sided. Article 22 preserves the rights of the person concerned to an effective remedy and fair trial, the presumption of innocence and the rights of defence, including the right to be heard and to access their file. Article 23 requires effective, proportionate and dissuasive penalties for conduct including hindering reporting, retaliation and vexatious proceedings, and also requires penalties where a reporting person knowingly reports or publicly discloses false information (1).

What it means for firms

The Directive sets minimum standards rather than a complete uniform code. Article 25 allows Member States to introduce or retain provisions more favourable to reporting persons and prohibits implementation of the Directive from being used to reduce existing protection. A group operating in several Member States therefore cannot assume that compliance with the rules of one jurisdiction resolves the position elsewhere (1).

The Commission's report of 3 July 2024 concluded that all Member States had transposed the Directive's main provisions, while also identifying shortcomings in key areas including material scope, conditions for protection and measures against retaliation. It also noted the significant delays with which transposition had occurred (2).

Article 27(3) required the Commission to submit a further report by 17 December 2025 assessing the impact of national transposing legislation and considering whether additional measures or amendments were needed. The Commission's subsequent evaluation roadmap identifies Q4 2026 as the planned completion date for that evaluation (4). The implementation framework is therefore still being assessed at EU level.

The burden-of-proof rule also reaches decisions that compliance does not ordinarily take itself. Leave decisions, appraisal ratings, training allocations, renewals and reassignments are usually controlled by managers and human-resources teams. If one of those decisions is alleged to constitute detriment after a protected report, Article 21(5) can become relevant in subsequent proceedings.

That makes record-keeping outside the compliance function important. The practical control is not simply whether the whistleblowing policy prohibits retaliation, but whether the organisation can later show why a challenged decision was taken and whether the stated reason is supported by the record.

The internal timetable matters for a different reason. Seven-day acknowledgement and timely feedback are straightforward procedural controls that help keep the reporting process credible. Missing them does not automatically authorise a protected public disclosure, but it can contribute to escalation towards external reporting and, eventually, public disclosure where the conditions in Article 15 are satisfied.

Closing thoughts

A whistleblowing framework is often assessed primarily as a reporting mechanism: whether a channel exists, whether confidentiality is protected and whether retaliation is prohibited. Directive (EU) 2019/1937 also changes the evidential position after a report.

In proceedings concerning an alleged detriment, once the reporting person establishes the report or public disclosure and the detriment, Article 21(5) places the burden on the person who took the detrimental measure to prove that it rested on duly justified grounds (1).

That is why the quality of the decision record matters. A policy can be drafted quickly. The ability to explain, months later and with evidence, why a particular decision was taken has to be built into the organisation before the dispute arises.

We hope this article was helpful. For more information from CPDs.Academy, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.

References

(1) Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law, OJ L 305, 26.11.2019, p. 17, including Articles 2 and 6 on material scope and conditions for protection, Article 4 on personal scope, Articles 8 and 9 on internal reporting channels and procedures, Articles 10 and 11 on external reporting, Article 15 on public disclosures, Article 16 on confidentiality, Article 19 on retaliation, Article 21 on protection against retaliation, Articles 22 to 24, Article 25 on more favourable treatment and non-regression, Article 26 on transposition, Article 27 on reporting, evaluation and review, and Parts I.B and II of the Annex.

(2) European Commission, Report to the European Parliament and the Council on the implementation and application of Directive (EU) 2019/1937, COM(2024) 269 final, 3 July 2024.

(3) Regulation (EU) No 596/2014 of the European Parliament and of the Council of 16 April 2014 on market abuse, and Commission Implementing Directive (EU) 2015/2392 of 17 December 2015, which recital 20 of Directive (EU) 2019/1937 identifies as examples of existing sector-specific whistleblower rules.

(4) European Commission, Call for Evidence for the Evaluation of Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law, identifying Q4 2026 as the indicative completion date for the evaluation under Article 27(3).