Where to report externally as a whistleblower in the EU
Where to report externally as a whistleblower in the EU depends on the country. Each of the 27 member states named its own authority to take reports. Some run one national office. Others send you to a sector regulator, or to the data-protection body. External reporting is one of three routes the EU Whistleblowing Directive gives a worker, next to reporting inside the company and, in some cases, going public. This guide names the authority for each state, with the form, email, or phone to reach it.
List of external whistleblower reporting authorities in the European Union
The table gives the external reporting authority for each member state, the channel to use, and the official website. The country name links to that country's own whistleblower law, so you can read the rules before you report. Every entry was checked against the authority's own site.
| Country | External reporting body | How to report | Official website |
|---|---|---|---|
| Bureau for anti-corruption (BAK) | online or BMI-III-BAK-SPOC@bak.gv.at | bak.gv.at | |
| Federal Ombudsman | online or integrity@federalombudsman.be | federaalombudsman.be | |
| Commission for Personal Data Protection | written report or kzld@cpdp.bg | cpdp.bg | |
| Ombudswoman of the Republic of Croatia | info@ombudsman.hr or phone 01 4851 855 | ombudsman.hr | |
| Sector competent authority (no single office) | report to the sector authority openly or anonymously | ||
| Ministry of Justice | online or oznamovatel@msp.justice.cz | oznamovatel.justice.cz | |
| Data Protection Agency scheme | online or wb@datatilsynet.dk | whistleblower.dk | |
| Sector competent authority (no single office) | report to the sector authority for the breach | justdigi.ee | |
| Office of the Chancellor of Justice | ilmoittajansuojelu@gov.fi or phone 02951 62600 | oikeuskansleri.fi | |
| Defender of Rights (Defenseur des droits) | online | defenseurdesdroits.fr | |
| Federal Office of Justice | online | bundesjustizamt.de | |
| National Transparency Authority | written form by post or in person or phone 213 212 9870 | aead.gr | |
| Commissioner for Fundamental Rights (Ombudsman) | online | ajbh.hu | |
| Protected Disclosures Commissioner | disclosures@opdc-ireland.ie | opdc.ie | |
| Anti-corruption authority (ANAC) | online | anticorruzione.it | |
| State Chancellery | online or trauksmescelejs@knab.gov.lv | trauksmescelejs.lv | |
| Prosecutor General's Office | praneseju.apsauga@prokuraturos.lt | prokuraturos.lt | |
| Office of Reports (Office des signalements) | online or info@osig.lu | mj.gouvernement.lu | |
| Parliamentary Ombudsman | online | ombudsman.org.mt | |
| House for Whistleblowers | online or contact@huisvoorklokkenluiders.nl | huisvoorklokkenluiders.nl | |
| Commissioner for Human Rights (RPO) | online or phone 800 676 676 | bip.brpo.gov.pl | |
| National Anti-Corruption Mechanism (MENAC) | online or phone 210 540 950 | mec-anticorrupcao.pt | |
| National Integrity Agency (ANI) | online | integritate.eu | |
| Whistleblower Protection Office | online or phone 0800 221 213 | oznamovatelia.sk | |
| Commission for the Prevention of Corruption (KPK) | online or anti.korupcija@kpk-rs.si | kpk-rs.si | |
| Regional anti-fraud agencies (national body rolling out) | Valencia online or Catalonia online | antifraucv.es | |
| Privacy Protection Authority (IMY) | by sealed post or phone 08-657 61 53 (email is not allowed) | imy.se |
How external reporting works under the EU directive
External reporting means taking a concern to a national authority. You do this instead of, or after, reporting inside your own workplace. Every member state had to name at least one competent authority for these reports. That body must run a secure channel, keep your identity secret, and follow each report up.
You do not have to report inside your company first. The directive lets you go straight to the authority. Your protection does not depend on trying the internal channel before it. The three tiers, and how the order affects your protection, sit in our post on external and public reporting. Which route is wiser is a separate question. We cover it below.
Which breaches you can report externally
External reporting covers breaches of EU law, not every workplace gripe. The directive lists the areas it protects: money laundering, tax fraud, and financial services; product safety, transport safety, and food safety; the environment, public health, consumer rights, and data privacy. A report about one of these stays protected across the EU.
Many countries went wider than the directive asks. Poland's law reaches domestic corruption and some constitutional rights. France kept stricter rules from its earlier Sapin II law. So a concern that counts in one country may not count in another. Check your own country's law, linked in the table, before you rely on the protection. If you are not sure you qualify at all, our guide on who is a whistleblower sets out the limits.
A simple test helps. Ask if the wrongdoing harms the public, not just you. A bank hiding dirty money fits, and so does a factory dumping waste or a firm selling unsafe toys. A pay dispute or a rude boss does not. Those are real problems, but other laws deal with them. The whistleblower rules are for breaches that put other people at risk.
The patterns behind the 27 channels
The countries fall into a few groups. Some built a new office just for whistleblowers. Slovakia's Whistleblower Protection Office and Ireland's Protected Disclosures Commissioner are the clearest cases. Others handed the job to a body that already existed. France uses the Defender of Rights, an ombudsman-style watchdog. Italy and Romania use their anti-corruption agencies. Poland uses its human-rights commissioner.
A third group leaned on the data-protection regulator. That office already guards sensitive personal data with care. Bulgaria, Denmark, and Sweden all took this path. Cyprus and Estonia stand apart with no single office at all. Each sends you to the authority for the sector, so the right body depends on what the breach is about.
An anonymous, encrypted whistleblower reporting channel for your employees, suppliers and customers, with case management, the 7-day and 3-month deadlines, and audit logs. Be compliant with the whistleblowing laws that apply to you, in minutes.
How to reach each authority, and what to expect
Most authorities take reports three ways. You can use an online form, an email address, or a phone line. The form is usually the safest. It runs on a secure system built for the job. A few countries allow only the form. Italy and Sweden both refuse email for whistleblower reports. They judge ordinary email too easy to read in transit.
Many authorities accept a report with no name. Whether an anonymous report keeps full protection still varies, as our post on anonymous reporting rules across the EU explains. Once you report, the authority owes you two things on a clock. It must confirm your report within 7 days. It must tell you what it did, or plans to do, within 3 months. Those deadlines come from the directive. They apply in every country in the table.
A clear report helps the authority act fast. Say what happened, where, and when. Name the organisation and the people involved if you can. Attach any proof you hold, such as emails or documents. But do not break into systems or take papers you have no right to hold. The law protects the report, not the theft of evidence. Keep a copy of what you send and the reply you get. If you want whistleblower status, some countries ask you to say so plainly, and Lithuania is one of them.
What happens next is set by law. The authority reads your report and decides if it falls under the rules. It may look into the matter itself. Or it may pass it to the right body and tell you where it went. You can ask how the case is going. If the authority sits on your report and does nothing, you may then go public and keep your protection. That is the third tier, and it is a last resort.
What protection you get when you report
Reporting to an authority puts you under the directive's shield. Your employer cannot dismiss you for it, demote you, cut your hours, or deny you training. Nor can they move you to worse duties or hold back a reference. All of these count as retaliation, and all are banned. The protection reaches not just the reporter, but colleagues and helpers who are tied to the report.
The law also shifts the burden of proof. If your employer punishes you soon after you report, they must show the two are not linked. You do not have to prove they hit back. A clause in a contract or an NDA cannot sign this right away either. An honest report that later proves wrong stays protected too. Only a knowingly false report falls outside the shield. For most workers, in most countries, an honest concern is safe to raise.
Support does not stop at your job. If an employer breaks these rules, you can seek redress. A court can order your job back or award damages. Some countries also offer free legal advice. Groups like Transparency International run advice lines in many states. You do not have to face it alone.
Internal or external, which route is wiser
Going straight to the authority is your right. But internal reporting is often the faster fix. A concern raised inside the company can be sorted in days. An authority handles many cases and takes longer. Many workers report inside first. They turn to the authority only if nothing happens, or if they fear the company will bury the problem or hit back. Either order keeps your protection.
The choice should turn on which route is safer for your case. If the wrongdoing reaches senior management, or an earlier internal report went nowhere, the external authority is the stronger move. If the problem is contained and the company runs a trusted channel, raising it inside is usually quicker for everyone.
One more thing to know. You can use more than one route over time. Start inside the company, and move to the authority later if you must. You keep your protection at each step. The law gives you options rather than trapping you in one channel. Pick the route that fits the risk in front of you.
A trusted internal channel is what makes the company route work. WeMoral provides a directive-compliant whistleblowing software with one-day setup. It lets your people report inside the company safely, and tracks each report to a close; see how WeMoral whistleblowing software works.
Reporting outside the EU
The directive covers only the 27 member states. Nearby countries run their own systems on different rules. The United Kingdom left the EU and keeps its older regime built around protected disclosures, set out in our post on UK whistleblower law. The United States uses a patchwork of federal and state laws with agency-run reward programmes, covered in our post on US whistleblower law. A cross-border case can involve more than one national authority at once. If a concern crosses a border, check which country's authority has the reach before you report.
External reporting is a real right, but it is rarely the first door to knock on. A concern handled well inside the company is faster for the reporter and cheaper for everyone. Find your country in the table above, read its law, and keep the authority's details close in case the internal route falls short.
Legal advisor specializing in business, commercial and IP law. Writes on whistleblower legislation, the EU Directive, and implementing reporting procedures.