Ga naar de hoofdinhoud
Wettelijk verplicht in de EU voor organisaties met 50 of meer werknemers
Deze pagina is alleen beschikbaar in het Engels.

Whistleblower law in Slovenia #

Slovenia implemented Directive (EU) 2019/1937 through the Zakon o zaščiti prijaviteljev (ZZPri), Uradni list RS no. 16/23, in force since 22 February 2023. Slovenia gives a visible role to the Commission for the Prevention of Corruption (KPK) for protection and reporting oversight.

Two features make Slovenia unusual. The person who receives internal reports — the zaupnik — must be appointed from among the employer’s own employees. And every obliged employer files an annual return to the KPK by 1 March.

Applicable law #

Who must establish an internal channel #

Article 9(2) ZZPri: public and private sector entities with 50 or more employees.

Article 9(3) lowers the threshold to 10 employees for entities whose principal registered activity is healthcare, or the collection, treatment and distribution of water, sewerage, or waste collection and management. This is a lower threshold, not an exemption from headcount — the Directive’s own Article 8(4) carve-out for regulated financial and AML entities applies separately and does remove the headcount test for those entities.

Article 9(4) covers listed public sector bodies regardless of size.

The zaupnik #

The employer appoints a zaupnik (confidential officer) from among its employees. The role cannot be outsourced, which is the first structural question for any organization procuring a reporting channel here: the software is the system of record and the audit trail, but the statutory recipient is an internal person.

The zaupnik runs a 7-day preliminary admissibility test on each report — whether the reporter qualifies, whether the matter is a breach within scope, whether it is manifestly unfounded, and whether the breach is ongoing or ended less than two years ago. Substantive feedback follows within three months.

Annual return to the KPK #

Article 9(16): by 1 March each year, for the preceding year, every obliged employer reports to the KPK via an electronic form — the number of reports received, how many were anonymous, how many were well-founded, the number of retaliation cases handled, and the identity of the zaupnik.

This is a recurring dated obligation most EU transpositions do not impose, and it is the practical reason a mailbox is not enough: the figures have to be countable at year end.

Retention #

Article 7(4): unless another act provides otherwise, data in the register of reports is retained for five years after the end of the procedure.

Penalties #

Fine bands turn on the size of the offender as well as the offence.

OffenceMedium/large companiesOther legal entitiesSole tradersResponsible person
No internal channel; channel not described in the internal act; missed 1 March return€3,000–6,000€2,000–4,000€1,000–2,000€300–2,000
Trying to establish the reporter’s identity; threatening or attempting retaliation€3,000–6,000€2,000–4,000€1,000–2,000€300–2,000
Carrying out a retaliatory measure€10,000–60,000€5,000–20,000€3,000–15,000€500–2,500

Disclosing the identity of a reporter, facilitator or connected person is fined €300–2,500. A reporter who deliberately reports or publicly discloses information they know to be untrue is fined €400–1,200; that offence is prosecuted by the external reporting authority that handled the report, not the KPK.

External reporting authority #

ZZPri designates around two dozen sectoral external reporting authorities. The Commission for the Prevention of Corruption (KPK) is the catch-all where no specialised regulator has jurisdiction, and it is the body that issues the certificate of eligibility for protection.

Data protection authority #

For GDPR complaints about whistleblower data handling, the relevant authority is the Information Commissioner of the Republic of Slovenia and its complaint filing page .

Support measures beyond the Directive #

Official sources #


Deploy your reporting channel →