Saltar para o conteúdo principal
Exigido pela legislação da UE para organizações com 50 ou mais trabalhadores
Esta página está disponível apenas em inglês.

Whistleblower law in Spain #

Spain implemented Directive (EU) 2019/1937 through Ley 2/2023, de 20 de febrero. The Spanish framework combines the standard 50-worker private-sector trigger with a broad public-sector obligation and a meaningful regional-authority layer.

Applicable law #

Who must establish an internal channel #

Phased deadlines: 13 June 2023 for 250+ employees, 1 December 2023 for 50-249. Municipalities below 10,000 inhabitants may share means; 50-249 entities may share resources.

Which breaches are covered #

The Act protects people who report (art. 2):

The second limb goes beyond the Directive’s minimum: in Spain the system covers any criminal offence or serious/very serious administrative infringement, not only the annex subject matters.

Who is protected #

Article 3 covers anyone who obtains the information in a work or professional context: public employees and employees, the self-employed, shareholders and partners, members of the administrative, management or supervisory body — including non-executives — and anyone working for contractors, subcontractors and suppliers.

It extends to relationships that have already ended, volunteers, trainees, people in training whether paid or not, and people who have not yet started work, where the information was obtained during recruitment or pre-contractual negotiation.

What the internal reporting system must do #

Responsibility for implementing it sits with the administrative or governing body, after consulting the workers’ legal representatives (art. 5(1)). The system must (art. 5(2)):

Anonymous reports. Article 7(3) is explicit: internal channels shall permit the submission and subsequent processing of anonymous reports. It is not a recommendation. Germany, by contrast, imposes no equivalent duty.

Channel and formats (art. 7(2)). In writing — by post or electronic means — or orally, by telephone or voice messaging. At the reporting person’s request, an in-person meeting within a maximum of seven days. Oral reports are documented, with consent, either by a recording in a secure and durable format or by a complete transcript, and the reporting person is offered the chance to check, correct and sign it.

Third-party management (art. 6). The system may be run in-house or by an external third party, “management” meaning the receipt of reports. The third party must offer adequate guarantees of independence, confidentiality, data protection and secrecy of communications.

System Officer (art. 8). The administrative body appoints the natural person responsible for running the system. Where a collegiate body is chosen, it must delegate to one of its members. A point frequently missed: both the appointment and the removal must be notified to the AIPI, or to the competent regional authority (art. 8(3)).

Procedural deadlines (art. 9(2)). Acknowledgment within seven calendar days, unless that would endanger confidentiality. A response within a maximum of three months from receipt — or from the expiry of the seven days where no acknowledgment was sent — extendable by up to three further months in especially complex cases.

Register (art. 26). Every obliged entity must keep a register of the reports received and the internal investigations they led to. It is not public: access is only possible on a reasoned request from the competent judicial authority, by court order and within judicial proceedings. The data may not be kept for more than ten years.

Penalties and enforcement #

Spain has the harshest no-channel penalty in the EU. Failing to have an internal information system is a muy grave (very serious) infraction under Art. 63.1.g — verbatim, “Incumplimiento de la obligación de disponer de un Sistema interno de información en los términos exigidos en esta ley.”

Infraction tier (Art. 65)Legal personsNatural persons
Leveup to €100,000€1,001–10,000
Grave€100,001–600,000€10,001–30,000
Muy grave (incl. no internal system, retaliation, breach of confidentiality, obstruction)€600,001–1,000,000€30,001–300,000

For muy grave infractions the authority may add (Art. 65.2): public reprimand, a ban on subsidies / tax benefits for up to 4 years, and a ban on public-sector contracting for up to 3 years.

An honest assessment of enforcement. Two things make Spain different from the rest of the region. First, the headline is real: up to €1,000,000 for simply not having a compliant system. Second, enforcement is actually switching on: the national authority (AIPI) only began operating on 1 September 2025 and activated channel supervision around February 2026, and in December 2025 it made its first public move — referring a channel-mismanagement matter (the PSOE/Salazar case) to its Monitoring & Sanctions Department. That is a referral, not yet a completed fine — no company has been fined to date — but Spain is the clearest “enforcement is arriving” signal of any market we track.

External reporting authority #

The national external channel is run by the Autoridad Independiente de Protección del Informante (AIPI) — its competence, the statutory deadlines and how a report is filed. Autonomous community authorities may handle regional and local matters within their territory unless a convention assigns them to the national authority.

Data protection authority #

For GDPR complaints and privacy guidance, the competent authority is the Agencia Española de Protección de Datos (AEPD) .

Key compliance points #

Official sources #


Deploy your reporting channel →