Implementation status and background to the directive
Why was the EU WBD introduced?
Prior to the introduction of the WBD, protection of whistleblowers in the EU was fragmented, with some countries having no prior legislation in place. The WBD is intended to address the lack of uniform protection of whistleblowers in the EU, by requiring effective, confidential and secure reporting channels and effectively protecting whistleblowers against retaliation.
The WBD therefore requires member states to establish a framework to protect persons who report breaches of EU Law from retaliation. Member states can gold plate the WBD's material scope so that it covers, for example, breaches of national law. Notwithstanding the laudable objective of the WBD to protect whistleblowers, the "framework" for doing so has resulted in prescriptive procedural requirements which focus on companies establishing local, entity level, internal reporting and investigation processes.
Current implementation status?
*Updated chart as of 29 March 2023
What key issues are we working with our clients on to address?
Internal reporting channels
Article 8(3) of the WBD prescribes that each legal entity in the private sector with 50 or more workers is required to establish channels and procedures for internal reporting. In the expert group minutes, the European Commission explains that there is no exception from this rule for group companies who have historically relied on central reporting channels operated by group functions.
This requirement poses two key challenges to global employers. The first one being, how this requirement can sit alongside a centralized group level reporting system (e.g., through a global "hotline"). Although it is clear that the requirement to establish internal reporting channels doesn't prevent employers from maintaining and encouraging the use of their central reporting hotline, the requirement remains that a local, entity level, channel must be established for entities with more than 50 workers. This means employers who meet the threshold will need to establish local entity level reporting systems alongside existing global channels.
The second key challenge is, where companies have multiple entities in one jurisdiction, whether one internal reporting channel can be established at a country level or whether the channel must be established in each entity. The implementing legislation in some countries is unclear on this point but, where the requirement is for entity level channels, this raises challenges for companies which have multiple entities within a jurisdiction but only one HR or Legal function which operates across multiple entities.
Confidentiality and sharing group resources
Article 8(6) of the WBD explains that legal entities with 50 to 249 workers may share resources as regards the receipt of reports and any investigation to be carried out.
Article 16 of the WBD requires that the identity of the reporting person is not disclosed to anyone beyond the authorized staff members competent to receive or follow up on reports, without the explicit consent of the reporter. In some of the countries that have implemented the WBD to date, e.g., France, the confidentiality of the accused is also protected.
Whilst the WBD doesn't explicitly say that companies with 250 or more employees ("large employers") cannot use group resources for investigating reports, when Articles 8(6) and 16(1) are read together, the implication is that large employers must investigate reports at a local legal entity level (where the report has been filed locally). One reason for this is that the group investigations/compliance function for large employers is not considered "authorized" to receive and investigate reports - only the local entity channel is authorized. This creates risks of complaints of breach of confidentiality by the reporter (if consent is not obtained to escalate to group) and the accused (whose consent will often not be possible or practical to get). The confidentiality requirements of the WBD and the accompanying implementing legislation is generally the area which appears to theoretically attract the most severe sanctions, including criminal sanctions. Until regulators publish guidance or a pattern of enforcement emerges companies will have to pay strict attention to the requirements around confidentiality when implementing a reporting system in compliance with the WBD.
Differences with existing whistleblowing laws
Whilst many global employers will already have established advanced reporting and investigation programs which encourage a culture of "speaking up", it is unlikely that these will be compliant with the requirements of the WBD. Some of the procedural elements will be relatively easy to build into existing programs - such as acknowledging receipt of a report within seven days and providing feedback to the reporter within three months, but the WBD requirements to establish a local internal reporting channel (and the related confidentiality requirements) go beyond requirements of similar legislation which already exists in the US or the UK. Employers will therefore need to consider whether they want to maintain a global approach to managing reports, which would put in place more onerous obligations in countries outside the EU than required by local laws or, alternatively, deviate from their global practices where necessary at an EU level.
How we can help
We have deep expertise in advising employers across the globe on key employment, privacy and compliance issues that arise when implementing whistleblowing policies, rolling out whistleblowing hotline systems, and handling whistleblowing-related complaints. We provide globally coordinated on-the-ground support, and we can help you benchmark your approach based on our combined experience of working with a wide variety of organizations in implementing whistleblowing regimes. Our support includes the following:
- Revising your internal compliance programs (The EU WBD will enhance the culture of crime prevention and detection within companies.)
- Implementing of whistleblowing hotlines and global HR databases
- Assessing privacy issues arising from the EU WBD
- Building or enhancing your investigations protocols
- Assisting your internal investigations, ensuring evidence is collected lawfully
- Conducting independent and thorough investigations for serious allegations
- Providing advice on potential disciplinary measures needed
- Training your managers and personnel on handling investigations
- Litigation support
We can provide your company with a multijurisdictional analysis matrix covering five key areas of WBD compliance at a local level, to help you get started in planning your organization's whistleblowing regime. For a fixed fee per jurisdiction, we offer jurisdiction-specific data sheets that provide answers to questions about the Directive's scope and implementation requirements for internal procedures, protection of whistleblowers, and data privacy issues. Our experienced team of lawyers can then assist you with implementing the changes, as well as with training, communications and more.
For further information please send an email to EMEAEUWhistleblowingDirective@bakermckenzie.com
Click here to subscribe to our EU Whistleblowing Directive mailing list for more updates.