Where to report externally as a whistleblower in the EU

Where to report externally as a whistleblower in the EU

Where to report externally as a whistleblower in the EU depends on the country. Each of the 27 member states named its own authority to take reports. Some run one national office. Others send you to a sector regulator, or to the data-protection body. External reporting is one of three routes the EU Whistleblowing Directive gives a worker, next to reporting inside the company and, in some cases, going public. This guide names the authority for each state, with the form, email, or phone to reach it.

List of external whistleblower reporting authorities in the European Union

The table gives the external reporting authority for each member state, the channel to use, and the official website. The country name links to that country's own whistleblower law, so you can read the rules before you report. Every entry was checked against the authority's own site.

Country External reporting body How to report Official website
Austria Bureau for anti-corruption (BAK) online or BMI-III-BAK-SPOC@bak.gv.at bak.gv.at
Belgium Federal Ombudsman online or integrity@federalombudsman.be federaalombudsman.be
Bulgaria Commission for Personal Data Protection written report or kzld@cpdp.bg cpdp.bg
Croatia Ombudswoman of the Republic of Croatia info@ombudsman.hr or phone 01 4851 855 ombudsman.hr
Cyprus Sector competent authority (no single office) report to the sector authority openly or anonymously
Czechia Ministry of Justice online or oznamovatel@msp.justice.cz oznamovatel.justice.cz
Denmark Data Protection Agency scheme online or wb@datatilsynet.dk whistleblower.dk
Estonia Sector competent authority (no single office) report to the sector authority for the breach justdigi.ee
Finland Office of the Chancellor of Justice ilmoittajansuojelu@gov.fi or phone 02951 62600 oikeuskansleri.fi
France Defender of Rights (Defenseur des droits) online defenseurdesdroits.fr
Germany Federal Office of Justice online bundesjustizamt.de
Greece National Transparency Authority written form by post or in person or phone 213 212 9870 aead.gr
Hungary Commissioner for Fundamental Rights (Ombudsman) online ajbh.hu
Ireland Protected Disclosures Commissioner disclosures@opdc-ireland.ie opdc.ie
Italy Anti-corruption authority (ANAC) online anticorruzione.it
Latvia State Chancellery online or trauksmescelejs@knab.gov.lv trauksmescelejs.lv
Lithuania Prosecutor General's Office praneseju.apsauga@prokuraturos.lt prokuraturos.lt
Luxembourg Office of Reports (Office des signalements) online or info@osig.lu mj.gouvernement.lu
Malta Parliamentary Ombudsman online ombudsman.org.mt
Netherlands House for Whistleblowers online or contact@huisvoorklokkenluiders.nl huisvoorklokkenluiders.nl
Poland Commissioner for Human Rights (RPO) online or phone 800 676 676 bip.brpo.gov.pl
Portugal National Anti-Corruption Mechanism (MENAC) online or phone 210 540 950 mec-anticorrupcao.pt
Romania National Integrity Agency (ANI) online integritate.eu
Slovakia Whistleblower Protection Office online or phone 0800 221 213 oznamovatelia.sk
Slovenia Commission for the Prevention of Corruption (KPK) online or anti.korupcija@kpk-rs.si kpk-rs.si
Spain Regional anti-fraud agencies (national body rolling out) Valencia online or Catalonia online antifraucv.es
Sweden Privacy Protection Authority (IMY) by sealed post or phone 08-657 61 53 (email is not allowed) imy.se

How external reporting works under the EU directive

External reporting means taking a concern to a national authority. You do this instead of, or after, reporting inside your own workplace. Every member state had to name at least one competent authority for these reports. That body must run a secure channel, keep your identity secret, and follow each report up.

You do not have to report inside your company first. The directive lets you go straight to the authority. Your protection does not depend on trying the internal channel before it. The three tiers, and how the order affects your protection, sit in our post on external and public reporting. Which route is wiser is a separate question. We cover it below.

Which breaches you can report externally

External reporting covers breaches of EU law, not every workplace gripe. The directive lists the areas it protects: money laundering, tax fraud, and financial services; product safety, transport safety, and food safety; the environment, public health, consumer rights, and data privacy. A report about one of these stays protected across the EU.

Many countries went wider than the directive asks. Poland's law reaches domestic corruption and some constitutional rights. France kept stricter rules from its earlier Sapin II law. So a concern that counts in one country may not count in another. Check your own country's law, linked in the table, before you rely on the protection. If you are not sure you qualify at all, our guide on who is a whistleblower sets out the limits.

A simple test helps. Ask if the wrongdoing harms the public, not just you. A bank hiding dirty money fits, and so does a factory dumping waste or a firm selling unsafe toys. A pay dispute or a rude boss does not. Those are real problems, but other laws deal with them. The whistleblower rules are for breaches that put other people at risk.

The patterns behind the 27 channels

The countries fall into a few groups. Some built a new office just for whistleblowers. Slovakia's Whistleblower Protection Office and Ireland's Protected Disclosures Commissioner are the clearest cases. Others handed the job to a body that already existed. France uses the Defender of Rights, an ombudsman-style watchdog. Italy and Romania use their anti-corruption agencies. Poland uses its human-rights commissioner.

A third group leaned on the data-protection regulator. That office already guards sensitive personal data with care. Bulgaria, Denmark, and Sweden all took this path. Cyprus and Estonia stand apart with no single office at all. Each sends you to the authority for the sector, so the right body depends on what the breach is about.

WeMoral - whistleblowing software

An anonymous, encrypted whistleblower reporting channel for your employees, suppliers and customers, with case management, the 7-day and 3-month deadlines, and audit logs. Be compliant with the whistleblowing laws that apply to you, in minutes.

How to reach each authority, and what to expect

Most authorities take reports three ways. You can use an online form, an email address, or a phone line. The form is usually the safest. It runs on a secure system built for the job. A few countries allow only the form. Italy and Sweden both refuse email for whistleblower reports. They judge ordinary email too easy to read in transit.

Many authorities accept a report with no name. Whether an anonymous report keeps full protection still varies, as our post on anonymous reporting rules across the EU explains. Once you report, the authority owes you two things on a clock. It must confirm your report within 7 days. It must tell you what it did, or plans to do, within 3 months. Those deadlines come from the directive. They apply in every country in the table.

A clear report helps the authority act fast. Say what happened, where, and when. Name the organisation and the people involved if you can. Attach any proof you hold, such as emails or documents. But do not break into systems or take papers you have no right to hold. The law protects the report, not the theft of evidence. Keep a copy of what you send and the reply you get. If you want whistleblower status, some countries ask you to say so plainly, and Lithuania is one of them.

What happens next is set by law. The authority reads your report and decides if it falls under the rules. It may look into the matter itself. Or it may pass it to the right body and tell you where it went. You can ask how the case is going. If the authority sits on your report and does nothing, you may then go public and keep your protection. That is the third tier, and it is a last resort.

What protection you get when you report

Reporting to an authority puts you under the directive's shield. Your employer cannot dismiss you for it, demote you, cut your hours, or deny you training. Nor can they move you to worse duties or hold back a reference. All of these count as retaliation, and all are banned. The protection reaches not just the reporter, but colleagues and helpers who are tied to the report.

The law also shifts the burden of proof. If your employer punishes you soon after you report, they must show the two are not linked. You do not have to prove they hit back. A clause in a contract or an NDA cannot sign this right away either. An honest report that later proves wrong stays protected too. Only a knowingly false report falls outside the shield. For most workers, in most countries, an honest concern is safe to raise.

Support does not stop at your job. If an employer breaks these rules, you can seek redress. A court can order your job back or award damages. Some countries also offer free legal advice. Groups like Transparency International run advice lines in many states. You do not have to face it alone.

Internal or external, which route is wiser

Going straight to the authority is your right. But internal reporting is often the faster fix. A concern raised inside the company can be sorted in days. An authority handles many cases and takes longer. Many workers report inside first. They turn to the authority only if nothing happens, or if they fear the company will bury the problem or hit back. Either order keeps your protection.

The choice should turn on which route is safer for your case. If the wrongdoing reaches senior management, or an earlier internal report went nowhere, the external authority is the stronger move. If the problem is contained and the company runs a trusted channel, raising it inside is usually quicker for everyone.

One more thing to know. You can use more than one route over time. Start inside the company, and move to the authority later if you must. You keep your protection at each step. The law gives you options rather than trapping you in one channel. Pick the route that fits the risk in front of you.

A trusted internal channel is what makes the company route work. WeMoral provides a directive-compliant whistleblowing software with one-day setup. It lets your people report inside the company safely, and tracks each report to a close; see how WeMoral whistleblowing software works.

Reporting outside the EU

The directive covers only the 27 member states. Nearby countries run their own systems on different rules. The United Kingdom left the EU and keeps its older regime built around protected disclosures, set out in our post on UK whistleblower law. The United States uses a patchwork of federal and state laws with agency-run reward programmes, covered in our post on US whistleblower law. A cross-border case can involve more than one national authority at once. If a concern crosses a border, check which country's authority has the reach before you report.

External reporting is a real right, but it is rarely the first door to knock on. A concern handled well inside the company is faster for the reporter and cheaper for everyone. Find your country in the table above, read its law, and keep the authority's details close in case the internal route falls short.

Updated at
Damian Sawicki

Legal advisor specializing in business, commercial and IP law. Writes on whistleblower legislation, the EU Directive, and implementing reporting procedures.

Launch your whistleblower reporting channel in less than 5 minutes!

A ready-made reporting page compliant with the EU Whistleblower Protection Directive. Deploy it without a developer.