
The German Whistleblower Protection Act
Explore the Whistleblower Protection Act (Hinweisgeberschutzgesetz / HinSchG) including compliance requirements, scope and how to support and protect reporting in your organization.

Explore the Whistleblower Protection Act (Hinweisgeberschutzgesetz / HinSchG) including compliance requirements, scope and how to support and protect reporting in your organization.

Germany enacted amendments to the country’s existing whistleblower protection laws in May 2023. The amendments transposed the EU Whistleblower Protection Directive’s requirements into German law, and expanded the scope of the directive as well. The new law protects not just reports of breaches of Union law, but also breaches of German national law and other “administrative” offenses of German regulations. Breaches of a company’s own policies and procedures are not protected under the law.
The Whistleblower Protection Act covers all organizations with at least 50 employees (including both full- and part-time employees), as well as government agencies and private organizations that receive public funding, such as those operating in healthcare, education or transportation. However, there are exceptions for entities with fewer than 50 employees; for detailed information on these exceptions, visit this webpage.
The law requires employers to establish internal reporting channels and to provide training to employees on the protection of whistleblowers. Employers must also appoint a person or department responsible for receiving and processing reports of wrongdoing. The law protects whistleblowers and those assisting them from retaliation for submitting a report, and allows them to report their concerns to external state authorities as well.

The Act adopts the minimum standards for whistleblower protection outlined in the EU Whistleblower Protection Directive. These requirements include:
The Whistleblower Protection Act (known in German as Hinweisgeberschutzgesetz, or abbreviated as “HinSchG,”) covers all German organizations with at least 50 employees; or any financial services business at all, regardless of the number of employees. Multinational companies can operate one enterprise-wide reporting system, so long as that system complies with the EU Whistleblower Directive.

The Act requires all covered businesses to:
Large companies (those with 250 or more employees) must have implemented their whistleblower systems by 30 June 2023. Smaller companies must have complied by 17 Dec. 2023.

The whistleblower protections include confidentiality, a prohibition against retaliation and no liability for disclosing necessary information to the report. The person who receives internal reports can be either a direct employee of the company, such as an HR or compliance officer; or an outside third party such as a service provider. In all cases, the person must protect the whistleblower’s identity and other personal information at all times.

On January 1, 2025, Germany made it a mandatory requirement for both internal and external reporting channels to support anonymous reporting and secure two-way communication.
Key operational requirements include:

In the event of a violation as the result of retaliation the perpetrator is obliged to compensate the Whistleblower. Companies or people found to be in violation of the whistleblower protection law can be subject to fines as high as €50,000.
10 Jun 2026 Matt Kelly
Why do employees wait days or weeks before making an internal report? Explore the emotions, fears and motivations that shape speak-up behavior and reporting decisions.
Read more
Webinars Upcoming
UK organisations report just 0.69 cases per 100 employees, compared to the global benchmark of 1.65, while 66% of reports are submitted anonymously. So, what do these figures really mean?
Join NatWest, M&G and NAVEX as they explore what the latest UK benchmark data reveals about reporting behaviour, employee confidence and speak-up culture and share practical strategies for strengthening trust, encouraging employees to speak up and improving programme effectiveness.
Save your seat!
19 May 2026 Carrie Penman
Learn the difference between incident management and case management, how the workflows connect and what to look for when evaluating software and program structure.
Read more
11 May 2026 NAVEX Editorial Team
UK whistleblowing law changes in 2026 bring sexual harassment under protected disclosures. Learn what this means for employers, compliance risk, and speak-up culture.
Read more
Use Cases
Expand your incident management program to capture data from external stakeholders with NAVEX One Whistleblowing & Incident Management.
Get the use case
Guides
Explore the state of workplace conduct issue reports, learn what the data really says about culture, risk and trust, and determine how to best approach your speak-up program in 2026 and beyond.
Get the guide
16 Apr 2026 NAVEX Editorial Team
Closing the loop on internal investigations turns findings into corrective action. Learn how remediation, accountability, and governance visibility strengthen compliance programs.
Read more
Guides
Benchmark your internal reporting against 15 years of global data. See how Reports per 100 Employees have changed over time and what this data reveals about your speak-up culture.
Get the guide
26 Mar 2026 Carrie Penman
This article, from the 2026 Top 10 Trends in Risk & Compliance, discusses how past benchmarking is useful context for what’s to come in R&C.
Read more
Customer Stories
Read how Aderco implemented a centralized, secure, and confidential reporting process backed by effective case management and tracking.
See their story
19 Mar 2026 Matt Kelly
Compliance officers need to speak the language of the business and communicate in terms that the board, management, and other leaders will understand.
Read more
18 Mar 2026 NAVEX Editorial Team
Speak-up culture is revealed through patterns, not promises. Learn which signals matter most for oversight and trust.
Read more
Germany’s regulatory environment is complex and constantly evolving. Get the insights you need to strengthen your compliance program, reduce risk, and build a culture of transparency.