Vai al contenuto principale
Richiesto dal diritto UE per le organizzazioni con oltre 50 dipendenti
Questa pagina è disponibile solo in inglese.

Whistleblower compliance for e-money and payment institutions #

The 50-employee threshold does not apply to you. A licensed e-money institution or payment institution with 18 staff carries the same internal reporting channel obligation as a bank with 18,000. Headcount is not the trigger — your licence is.

This is the single most misread point in the Directive. Most guidance leads with “50 or more employees”, which is correct for ordinary private-sector companies and wrong for regulated financial entities.

Why headcount does not apply #

The obligation runs through three steps:

  1. Your licence places you within the scope of a Union financial-services act — the E-Money Directive (2009/110/EC) for EMIs, the Payment Services Directive (PSD2, (EU) 2015/2366) for payment institutions.
  2. Part I.B of the Annex to Directive 2019/1937 enumerates the Union acts governing financial services, products and markets, and the prevention of money laundering and terrorist financing. The E-Money Directive is point (i) on that list; PSD2 is point (ix).
  3. Art. 8(4) provides that the threshold in Art. 8(3) “shall not apply to the entities falling within the scope of Union acts referred to in Parts I.B and II of the Annex”. Article 8(3) is what sets the 50-worker trigger for private-sector entities generally.

Part II of the Annex is a different list — the sector-specific acts that lay down their own reporting rules, which take precedence over this Directive under Art. 3(1) . Several financial-services acts sit there, so a licensed firm may be answering to sector rules and this Directive at once, with the Directive filling whatever the sector act does not mandate.

The practical result: there is no size at which a licensed EMI or payment institution is out of scope. A newly authorised firm is in scope from the day it holds the licence.

PSD3 and the PSR do not remove this. The agreed texts were published in April 2026 and will in time repeal and replace both PSD2 and the E-Money Directive, merging the payment-institution and e-money-institution regimes into a single framework. Application is not expected before late 2027. Until then PSD2 and EMD2 remain the operative acts and the analysis above is unchanged. How the Annex to Directive 2019/1937 comes to reference the successor acts is a point to watch — not a reason to defer, because the obligation applies now.

Member states transpose this in their own drafting. Romania, for example, places financial services, anti-money-laundering and insurance entities in Annex 3 to Legea nr. 361/2022 and applies the obligation to them regardless of employee count. Confirm your own national transposition — the mechanism is uniform, the drafting is not.

Who supervises this #

Whistleblowing obligations for licensed firms are enforced by your prudential or conduct regulator, independently of the national whistleblower authority. Both can act on the same failure.

CountryRegulator for EMIs / PIs
LithuaniaBank of Lithuania
IrelandCentral Bank of Ireland
MaltaMFSA
LuxembourgCSSF
NetherlandsDNB
GermanyBaFin
FranceACPR
PolandKNF
RomaniaBNR

What the obligation actually requires #

Small licensed firms usually fail on the same point: the person who would receive a report is also the person a report is most likely to concern. Article 9 requires the channel to prevent exactly that conflict, which is difficult to satisfy with a shared mailbox.

What DORA adds at procurement #

Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. It does not create a whistleblowing obligation — but it governs how you buy the software that satisfies one. Whistleblowing software is an ICT service, so the engagement runs through your ICT third-party risk process rather than as an ordinary software purchase: an entry in your Register of Information, and the baseline contractual provisions in Article 30(2), including access, inspection and audit rights.

A second, heavier tier — the extended provisions in Article 30(3), and the documented exit strategy required by Article 28(8) — applies where the service supports a critical or important function. The financial entity makes that regulatory classification, but the classification does not unilaterally amend the supplier contract. See procurement under DORA for the framing, the DORA ICT third-party map for provider-side evidence, and the non-binding DORA contracting template . Customer-specific DORA commitments require an order signed by both parties.

Reviewing EthicsPortal #

The documentation a licensed firm’s third-party assessment asks for is published rather than released on request: security architecture , subprocessors , business continuity plan , incident register , DPA , and the ISO/IEC 27001:2022 control map . A pre-filled DPIA template is available for you to adapt and sign as controller.


Deploy your reporting channel →