> Spain's Ley 2/2023: the private-sector threshold, public-sector scope, regional authority nuance, and the official Spanish reporting authorities.

Source: https://ethicsportal.eu/nl/whistleblower-laws/spain/
Updated: 2026-06-10

---

# Whistleblower law in Spain

Spain implemented Directive (EU) 2019/1937 through **Ley 2/2023, de 20 de febrero**. The Spanish framework combines the standard **50-worker** private-sector trigger with a broad public-sector obligation and a meaningful regional-authority layer.

## Applicable law

- [Ley 2/2023 — official BOE text](https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513)
- [AIPI — external information channel](https://www.proteccioninformante.gob.es/nuestro-trabajo/investigacion)

## Who must establish an internal channel

- **Private-sector entities with 50 or more workers** must maintain an internal information system (*Sistema interno de información*).
- **All public-sector entities.**
- **Financial / AML, environmental, and transport-safety entities** — regardless of headcount.

Phased deadlines: **13 June 2023** for 250+ employees, **1 December 2023** for 50-249. Municipalities below 10,000 inhabitants may share means; 50-249 entities may share resources.

## Which breaches are covered

The Act protects people who report (art. 2):

- breaches of **EU law** within the annex to Directive (EU) 2019/1937, affecting the EU's financial interests (art. 325 TFEU) or concerning the internal market (art. 26(2) TFEU), including competition, State aid and corporate-tax avoidance practices;
- acts or omissions that may constitute a **criminal offence or a serious or very serious administrative infringement**.

The second limb goes beyond the Directive's minimum: in Spain the system covers any criminal offence or serious/very serious administrative infringement, not only the annex subject matters.

## Who is protected

Article 3 covers anyone who obtains the information in a work or professional context: public employees and employees, **the self-employed**, **shareholders and partners**, members of the administrative, management or supervisory body — including **non-executives** — and anyone working for contractors, subcontractors and suppliers.

It extends to **relationships that have already ended**, volunteers, trainees, people in training whether paid or not, and people who **have not yet started work**, where the information was obtained during recruitment or pre-contractual negotiation.

## What the internal reporting system must do

Responsibility for implementing it sits with the **administrative or governing body**, after consulting the workers' legal representatives (art. 5(1)). The system must (art. 5(2)):

- let everyone covered by art. 3 report;
- be designed, established and managed **securely**, guaranteeing the confidentiality of the reporting person's identity and of any third party mentioned, and preventing access by unauthorised staff;
- allow reports **in writing, orally, or both**;
- **integrate** any separate internal channels the entity operates;
- ensure reports can be handled effectively inside the entity, so that the organisation itself is the first to learn of the possible irregularity.

**Anonymous reports.** Article 7(3) is explicit: internal channels *shall permit the submission and subsequent processing of anonymous reports*. It is not a recommendation. Germany, by contrast, imposes no equivalent duty.

**Channel and formats** (art. 7(2)). In writing — by post or electronic means — or orally, by telephone or voice messaging. At the reporting person's request, an **in-person meeting within a maximum of seven days**. Oral reports are documented, with consent, either by a recording in a secure and durable format or by a complete transcript, and the reporting person is offered the chance to check, correct and sign it.

**Third-party management** (art. 6). The system may be run in-house or by an external third party, "management" meaning the receipt of reports. The third party must offer adequate guarantees of independence, confidentiality, data protection and secrecy of communications.

**System Officer** (art. 8). The administrative body appoints the natural person responsible for running the system. Where a collegiate body is chosen, it must delegate to one of its members. A point frequently missed: **both the appointment and the removal must be notified to the AIPI**, or to the competent regional authority (art. 8(3)).

**Procedural deadlines** (art. 9(2)). Acknowledgment within **seven calendar days**, unless that would endanger confidentiality. A response within a maximum of **three months** from receipt — or from the expiry of the seven days where no acknowledgment was sent — **extendable by up to three further months** in especially complex cases.

**Register** (art. 26). Every obliged entity must keep a register of the reports received and the internal investigations they led to. It is not public: access is only possible on a reasoned request from the competent judicial authority, by court order and within judicial proceedings. The data may not be kept for more than **ten years**.

## Penalties and enforcement

Spain has the **harshest no-channel penalty in the EU**. Failing to have an internal information system is a *muy grave* (very serious) infraction under **Art. 63.1.g** — verbatim, *"Incumplimiento de la obligación de disponer de un Sistema interno de información en los términos exigidos en esta ley."*

| Infraction tier (Art. 65) | Legal persons | Natural persons |
| --- | --- | --- |
| Leve | up to €100,000 | €1,001–10,000 |
| Grave | €100,001–600,000 | €10,001–30,000 |
| **Muy grave** (incl. **no internal system**, retaliation, breach of confidentiality, obstruction) | **€600,001–1,000,000** | €30,001–300,000 |

For *muy grave* infractions the authority may add (Art. 65.2): **public reprimand**, a ban on subsidies / tax benefits for up to 4 years, and a ban on public-sector contracting for up to 3 years.

**An honest assessment of enforcement.** Two things make Spain different from the rest of the region. First, the headline is real: **up to €1,000,000** for simply not having a compliant system. Second, **enforcement is actually switching on**: the national authority (**AIPI**) only began operating on **1 September 2025** and activated channel supervision around February 2026, and in December 2025 it made its first public move — referring a channel-mismanagement matter (the PSOE/Salazar case) to its Monitoring & Sanctions Department. That is a *referral*, not yet a completed fine — no company has been fined to date — but Spain is the clearest "enforcement is arriving" signal of any market we track.

## External reporting authority

The national external channel is run by the [Autoridad Independiente de Protección del Informante (AIPI)](/authorities/spain-aipi/) — its competence, the statutory deadlines and how a report is filed. Autonomous community authorities may handle regional and local matters within their territory unless a convention assigns them to the national authority.

## Data protection authority

For GDPR complaints and privacy guidance, the competent authority is the [Agencia Española de Protección de Datos (AEPD)](https://www.aepd.es/).

## Key compliance points

- Spain's public-sector obligation is broader than the simple private-sector 50-worker rule.
- The national external system expressly supports written and verbal submissions.
- The regional-authority layer matters in practice, especially for local or single-region cases.

## Official sources

- [Ley 2/2023 — official BOE text](https://www.boe.es/buscar/act.php?id=BOE-A-2023-4513)
- [AIPI — external information channel](https://www.proteccioninformante.gob.es/nuestro-trabajo/investigacion)
- [AIPI — who we are](https://www.proteccioninformante.gob.es/AIPI/que-es)
- [AIPI — sanctioning procedure](https://www.proteccioninformante.gob.es/nuestro-trabajo/potestad-sancionadora/procedimiento)
- [Oficina Antifrau de Catalunya — whistleblower authority](https://www.antifrau.cat/en/who-is-independent-whistleblower-protection-authority-catalonia)
- [AEPD](https://www.aepd.es/)

---

[Deploy your reporting channel →](/pricing/)
