Whistleblower law in Spain #
Spain implemented Directive (EU) 2019/1937 through Ley 2/2023, de 20 de febrero. The Spanish framework combines the standard 50-worker private-sector trigger with a broad public-sector obligation and a meaningful regional-authority layer.
Applicable law #
Who must establish an internal channel #
- Private-sector entities with 50 or more workers must maintain an internal information system (Sistema interno de información).
- All public-sector entities.
- Financial / AML, environmental, and transport-safety entities — regardless of headcount.
Phased deadlines: 13 June 2023 for 250+ employees, 1 December 2023 for 50-249. Municipalities below 10,000 inhabitants may share means; 50-249 entities may share resources.
Which breaches are covered #
The Act protects people who report (art. 2):
- breaches of EU law within the annex to Directive (EU) 2019/1937, affecting the EU’s financial interests (art. 325 TFEU) or concerning the internal market (art. 26(2) TFEU), including competition, State aid and corporate-tax avoidance practices;
- acts or omissions that may constitute a criminal offence or a serious or very serious administrative infringement.
The second limb goes beyond the Directive’s minimum: in Spain the system covers any criminal offence or serious/very serious administrative infringement, not only the annex subject matters.
Who is protected #
Article 3 covers anyone who obtains the information in a work or professional context: public employees and employees, the self-employed, shareholders and partners, members of the administrative, management or supervisory body — including non-executives — and anyone working for contractors, subcontractors and suppliers.
It extends to relationships that have already ended, volunteers, trainees, people in training whether paid or not, and people who have not yet started work, where the information was obtained during recruitment or pre-contractual negotiation.
What the internal reporting system must do #
Responsibility for implementing it sits with the administrative or governing body, after consulting the workers’ legal representatives (art. 5(1)). The system must (art. 5(2)):
- let everyone covered by art. 3 report;
- be designed, established and managed securely, guaranteeing the confidentiality of the reporting person’s identity and of any third party mentioned, and preventing access by unauthorised staff;
- allow reports in writing, orally, or both;
- integrate any separate internal channels the entity operates;
- ensure reports can be handled effectively inside the entity, so that the organisation itself is the first to learn of the possible irregularity.
Anonymous reports. Article 7(3) is explicit: internal channels shall permit the submission and subsequent processing of anonymous reports. It is not a recommendation. Germany, by contrast, imposes no equivalent duty.
Channel and formats (art. 7(2)). In writing — by post or electronic means — or orally, by telephone or voice messaging. At the reporting person’s request, an in-person meeting within a maximum of seven days. Oral reports are documented, with consent, either by a recording in a secure and durable format or by a complete transcript, and the reporting person is offered the chance to check, correct and sign it.
Third-party management (art. 6). The system may be run in-house or by an external third party, “management” meaning the receipt of reports. The third party must offer adequate guarantees of independence, confidentiality, data protection and secrecy of communications.
System Officer (art. 8). The administrative body appoints the natural person responsible for running the system. Where a collegiate body is chosen, it must delegate to one of its members. A point frequently missed: both the appointment and the removal must be notified to the AIPI, or to the competent regional authority (art. 8(3)).
Procedural deadlines (art. 9(2)). Acknowledgment within seven calendar days, unless that would endanger confidentiality. A response within a maximum of three months from receipt — or from the expiry of the seven days where no acknowledgment was sent — extendable by up to three further months in especially complex cases.
Register (art. 26). Every obliged entity must keep a register of the reports received and the internal investigations they led to. It is not public: access is only possible on a reasoned request from the competent judicial authority, by court order and within judicial proceedings. The data may not be kept for more than ten years.
Penalties and enforcement #
Spain has the harshest no-channel penalty in the EU. Failing to have an internal information system is a muy grave (very serious) infraction under Art. 63.1.g — verbatim, “Incumplimiento de la obligación de disponer de un Sistema interno de información en los términos exigidos en esta ley.”
| Infraction tier (Art. 65) | Legal persons | Natural persons |
|---|---|---|
| Leve | up to €100,000 | €1,001–10,000 |
| Grave | €100,001–600,000 | €10,001–30,000 |
| Muy grave (incl. no internal system, retaliation, breach of confidentiality, obstruction) | €600,001–1,000,000 | €30,001–300,000 |
For muy grave infractions the authority may add (Art. 65.2): public reprimand, a ban on subsidies / tax benefits for up to 4 years, and a ban on public-sector contracting for up to 3 years.
An honest assessment of enforcement. Two things make Spain different from the rest of the region. First, the headline is real: up to €1,000,000 for simply not having a compliant system. Second, enforcement is actually switching on: the national authority (AIPI) only began operating on 1 September 2025 and activated channel supervision around February 2026, and in December 2025 it made its first public move — referring a channel-mismanagement matter (the PSOE/Salazar case) to its Monitoring & Sanctions Department. That is a referral, not yet a completed fine — no company has been fined to date — but Spain is the clearest “enforcement is arriving” signal of any market we track.
External reporting authority #
The national external channel is run by the Autoridad Independiente de Protección del Informante (AIPI) — its competence, the statutory deadlines and how a report is filed. Autonomous community authorities may handle regional and local matters within their territory unless a convention assigns them to the national authority.
Data protection authority #
For GDPR complaints and privacy guidance, the competent authority is the Agencia Española de Protección de Datos (AEPD) .
Key compliance points #
- Spain’s public-sector obligation is broader than the simple private-sector 50-worker rule.
- The national external system expressly supports written and verbal submissions.
- The regional-authority layer matters in practice, especially for local or single-region cases.
Official sources #
- Ley 2/2023 — official BOE text
- AIPI — external information channel
- AIPI — who we are
- AIPI — sanctioning procedure
- Oficina Antifrau de Catalunya — whistleblower authority
- AEPD