Blog

Whistleblower training under EU Directive 2019/1937 in 2026

EU Directive 2019/1937 requires internal channels and training at 50+ employees. Module content, fines up to EUR 40k, and two SMB rollout examples.

·6 min read·Mentor Team

The EU Whistleblower Directive (2019/1937) has been in force across the Union since 2019, with national transposition rolled out by most Member States by 2023. Every private employer with 50 or more employees must run an internal reporting channel and train the staff handling it. The 250+ employee deadline hit on 17 December 2021; the 50–249 band followed on 17 December 2023.

A channel without training does not qualify. If a report lands and no one knows what to do, two things happen. The report escapes the internal route and lands with the supervisory authority or the media. Or the reporter's identity leaks by accident. Either outcome triggers administrative fines and, in most Member States, personal liability for the responsible officer. Slovenia's ZZPri, for one, sets fines of EUR 4,000 to 40,000 on medium and large legal entities for the most serious breaches, plus EUR 400 to 4,000 on the responsible person.

This article covers three things. What the directive specifically demands from a training program. What a working module looks like. And two worked examples for teams of 60 and 120 employees.

What the directive requires

Article 12 of Directive 2019/1937 asks Member States to ensure that staff handling reports receive "specific training". National laws add the teeth. Two audit anchors show up in every transposition.

  • The case handler and a backup must be trained in report intake, GDPR processing, and retaliation avoidance.
  • Every employee must know the channel exists, who is protected, and how to escalate.

Article 9 hard-codes timing.

  • The report must be acknowledged within 7 days of receipt.
  • The reporter must receive feedback within 3 months.
  • Missed deadlines let the reporter go straight to the external channel or the public.

Article 2 lists the material scope: public procurement, financial services, product and transport safety, environmental protection, public health, consumer protection, data protection, network and information security, and the financial interests of the Union. National laws often widen the scope. Slovenia's ZZPri, for instance, adds all suspected criminal offences.

Companies under the 50-employee threshold are out of scope. Supplier-security questionnaires and ISO 37002 (whistleblowing management systems) still expect an equivalent program from any tender-active SMB.

What a working module covers

A generic 60-minute video sees completion below 55 %. A module that actually trains behavior needs seven components.

  • Definition of a breach by scope — three concrete examples per department (procurement, finance, operations).
  • Who is protected — employees, candidates, self-employed contractors, volunteers, business partners, and former staff.
  • Where to file — internal form, case-handler email, postal address, and an in-person meeting option.
  • What retaliation looks like — dismissal, demotion, negative review, project reassignment. Article 19 also bans the threat of these acts.
  • Anonymity vs confidentiality — the directive does not force acceptance of anonymous reports; confidentiality is mandatory either way.
  • What a reporter risks by lying — knowingly false reports lose protection and can trigger civil and criminal liability.
  • What happens next — 7-day acknowledgment, 3-month feedback, external escalation options.

A 5–8 question quiz at the end is non-negotiable. Without an evidence trail, a supervisory authority does not accept "everyone read the intranet page".

Two concrete programs

Program 1: manufacturing SMB, 60 employees

The company just crossed the 50-employee threshold after a warehouse hiring round. No case handler is appointed and the current channel is a generic hr@ inbox. Year-one program:

  • Kick-off workshop for leadership (60 min) — legal duty, personal liability, how to select a handler without conflict of interest. Delivered by outside counsel or an HR consultant.
  • Case handler training (4 hours) — legal framework, intake practice, document handling, five-year retention, GDPR basics.
  • All-hands module (20 min e-learning) — three worked examples: an unreported workplace injury, a tax anomaly at a subcontractor, a harassment suspicion.
  • Annual 10-min refresher — this year: expanded reading of "retaliation" in recent labour-court case law and any new supervisory-authority guidance.

Cost: about EUR 1,800 per year for a platform with tracking and quizzes, plus a one-off EUR 900 for the legal workshop. That works out to EUR 45 per employee in year one and EUR 30 after.

Program 2: IT services company, 120 employees

The company sells to public-sector buyers and already runs a channel — but it is a static HTML page. A recent internal survey shows 30 % of employees do not know who the case handler is. Program:

  • Baseline for all (25 min) — what to report, how, what happens next. Signed acknowledgment.
  • Deep-dive for team leads (45 min) — retaliation in practice, how to avoid an unconscious reprisal (e.g. a "project reassignment" right after a report).
  • Case handler and backup training (8 hours over two days) — intake, triage, communication with the reporter, cooperation with the supervisory authority, handling a press call.
  • Annual simulation — HR sends a test report and measures response time. Target: acknowledgment within 24 hours, not 7 days.
  • Quarterly 5-min refresher by role — team leads see different content from admin staff.

Cost: about EUR 4,200 per year for a multi-role platform with reporting, plus EUR 1,500 for handler training. Roughly EUR 47 per employee in year one.

Three mistakes we keep seeing

  • "The CEO is the case handler." Conflict of interest. A report about senior management cannot land in the same office. The handler must be independent — internal audit, an HR partner with no line authority over the reporter, or an external provider.
  • "Email is enough." The directive requires written, oral, and in-person options. Without an oral option, the reporter can bypass the internal channel and go straight to the supervisory authority.
  • "No reports means we don't need training." Zero reports at an inspection is a red flag, not proof of compliance. It signals the channel is unknown or inaccessible.

For the wider view on data-handling training see GDPR training for HR teams.

Where to start this week

If no program is in place, four steps take about 10 working days.

  • Confirm employee count against the average of the previous calendar year. At 50+ the obligation applies.
  • Appoint a case handler and backup. Sign a mandate that spells out independence from the reporter's line management.
  • Draft or refresh the internal act, structured around Articles 8–12 of the directive.
  • Push the e-learning module to everyone and log attendance.

What consolidation actually solves

A supervisory audit is not a policy-paper review — it is an evidence check. Who completed the module, when, with what quiz result. An LMS such as Mentor centralises those records, triggers the annual refresher automatically, and exports the report a regulator asks for in under 30 minutes. A technically sound channel without evidence does not survive inspection.

Ready to try Mentor?

14-day free trial, no card. Set-up in under 5 minutes.

Start trial