Whistleblower report retention periods in EU
Whistleblower report retention periods across the EU run from three months to ten years. Cyprus deletes a report three months after a case closes. Spain lets a company keep one for ten years. Eleven member states set no period at all. The numbers come from our 2026 report on the EU Whistleblower Directive, which compares all 27 national laws. Here is how long you have to keep a report in each country, and what to do where the law says nothing.
Key facts
- Retention runs from 3 months in Cyprus to 10 years in Spain.
- Eleven member states set no fixed period, so the GDPR decides.
- Five years is the most common fixed term, chosen by eight states.
- The clock can start on receipt, at closure, or at a point the law never names.
- The directive itself sets no retention period.
How long must you keep a whistleblower report?
The EU Whistleblower Directive fixes no retention period. It says only that you keep personal data no longer than you need it. So each country filled the gap its own way. Fifteen states picked one clear number. Belgium set several, one per region. The other eleven set none.
Spain sits at the top with a ten-year ceiling. Where no investigation follows, it deletes the report after three months instead. Eight states chose five years: Austria, Czechia, Finland, Italy, Lithuania, Portugal, Romania and Slovenia. Four chose three years: Germany, Estonia, Poland and Slovakia. Sweden keeps a report two years. Cyprus is the shortest, deleting three months after a case closes.
Source: WeMoral, 2026 Report on Whistleblower Directive Transposition Across the EU, p. 20.
The table below gives every fixed period and the moment its clock starts. The eleven states with no set period come after it.
| Country | Retention period | Clock starts |
|---|---|---|
| 5 years | Last processing step | |
| 3 months | After closure, 1 year after any proceedings | |
| 5 years | On receipt | |
| 3 years | After feedback | |
| 5 years | On arrival | |
| 3 years | Case closure, extendable | |
| 5 years | Final outcome | |
| 5 years, a minimum | Last decision | |
| 3 years | Year-end after follow-up | |
| 5 years, a minimum | Not defined, plus pending proceedings | |
| 5 years | On registration | |
| 3 years | On delivery | |
| 5 years | End of the procedure | |
| 10 years, a ceiling | Not stated, 3 months if no investigation | |
| 2 years | On closure |
Source: WeMoral, 2026 Report on Whistleblower Directive Transposition Across the EU, p. 20.
"The directive fixes no retention period. It asks only that personal data be kept no longer than necessary and proportionate, and eleven member states left it exactly there."
WeMoral, 2026 Report on Whistleblower Directive Transposition Across the EU, p. 19
Where no retention period is set, the GDPR takes over
Eleven states name no number: Bulgaria, Croatia, Denmark, France, Greece, Hungary, Ireland, Latvia, Luxembourg, Malta and the Netherlands. Belgium is a twelfth case of its own, with a different rule in each region. No fixed period does not mean keep forever. It hands the decision to the GDPR.
The GDPR's storage limitation rule says you keep personal data only as long as the purpose needs. For a report, that purpose is handling the case and defending against any claim that follows. So in Denmark, France, Ireland and Luxembourg you set your own period and justify it. Bulgaria points to a data-protection ordinance. Croatia falls back on its general archiving law. Greece keeps the file until proceedings end. This is where a written retention policy earns its place. Our guides on responding to a report and what to do with a report cover the handling steps that decide when the clock can stop.
| Country | What applies instead |
|---|---|
| Varies by instrument, from the length of the working relationship to 10 years | |
| Set by a data-protection authority ordinance | |
| General archiving law applies | |
| Only what is necessary and proportionate | |
| Only what is necessary and proportionate | |
| Kept until proceedings end | |
| 5 years, but only in the ombudsman's system | |
| Only what is necessary and proportionate | |
| No period or clock in the act | |
| Secure storage and data minimisation only | |
| No clock start given | |
| Register duty only |
Source: WeMoral, 2026 Report on Whistleblower Directive Transposition Across the EU, p. 19.
When does the retention clock start?
The number of years is only half the answer. The same five years can mean very different storage, depending on when the clock starts. Four states start it when the report arrives: Czechia, Finland, Romania and Slovakia. The period runs before anyone has looked at the case. Nine states start it once the case is handled, at closure, the final outcome, or the last decision. Two states never say clearly.
Source: WeMoral, 2026 Report on Whistleblower Directive Transposition Across the EU, p. 20.
This is the trap for a company in more than one country. Two five-year rules are not the same rule. Austria runs its clock from the last time you touch the file, so opening a case again can push the delete date back. Poland counts from the end of the year in which follow-up ended. Spain ties deletion to whether an investigation follows, and Portugal leaves the start undefined and adds any pending proceedings on top. If you hold one archive for every country, you have to meet the earliest start and the latest end at once.
Build one retention policy for every country
Most companies want a single rule, not 27. To get there, you design for the strictest state on your map. That means the longest floor and the shortest ceiling at the same time. Portugal and Lithuania set their five years as a minimum, so you cannot go lower. Spain's ten years is a ceiling, so you cannot go higher there. Cyprus wants deletion after three months. A company in both Spain and Cyprus needs two separate policies for the same kind of record.
How 27 member states transposed Directive 2019/1937, and where their laws still disagree on fines, anonymity, deadlines and protection.
Get full report for free nowWrite the period down, tie it to the case file, and record why you chose it. That is what the GDPR asks for, and it is what an auditor will look for. The country-law posts for Spain, Sweden and Germany give the exact wording at the two extremes and in the middle.
Set the retention clock once, then let it run
Retention is the quiet part of a whistleblowing programme. It rarely comes up until an audit or a data request, and then it comes up fast. A report kept a year too long is a GDPR problem. A report deleted a year too early is an evidence problem. The safe path is to fix the period per country, attach it to each case, and delete on schedule without anyone having to remember. WeMoral applies each country's rule to each report and clears it when the time is up, so the archive stays lawful on its own. Check your countries' rows before you set a single number for all of them.
Compliance specialist focused on policy roll-out and internal information flow. Writes on EU rule-making, landmark cases, and implementing reporting software.