
The German Whistleblower Protection Act
Explore the Whistleblower Protection Act (Hinweisgeberschutzgesetz / HinSchG) including compliance requirements, scope and how to support and protect reporting in your organization.

Explore the Whistleblower Protection Act (Hinweisgeberschutzgesetz / HinSchG) including compliance requirements, scope and how to support and protect reporting in your organization.

Germany enacted amendments to the country’s existing whistleblower protection laws in May 2023. The amendments transposed the EU Whistleblower Protection Directive’s requirements into German law, and expanded the scope of the directive as well. The new law protects not just reports of breaches of Union law, but also breaches of German national law and other “administrative” offenses of German regulations. Breaches of a company’s own policies and procedures are not protected under the law.
The Whistleblower Protection Act covers all organizations with at least 50 employees (including both full- and part-time employees), as well as government agencies and private organizations that receive public funding, such as those operating in healthcare, education or transportation. However, there are exceptions for entities with fewer than 50 employees; for detailed information on these exceptions, visit this webpage.
The law requires employers to establish internal reporting channels and to provide training to employees on the protection of whistleblowers. Employers must also appoint a person or department responsible for receiving and processing reports of wrongdoing. The law protects whistleblowers and those assisting them from retaliation for submitting a report, and allows them to report their concerns to external state authorities as well.

The Act adopts the minimum standards for whistleblower protection outlined in the EU Whistleblower Protection Directive. These requirements include:
The Whistleblower Protection Act (known in German as Hinweisgeberschutzgesetz, or abbreviated as “HinSchG,”) covers all German organizations with at least 50 employees; or any financial services business at all, regardless of the number of employees. Multinational companies can operate one enterprise-wide reporting system, so long as that system complies with the EU Whistleblower Directive.

The Act requires all covered businesses to:
Large companies (those with 250 or more employees) must have implemented their whistleblower systems by 30 June 2023. Smaller companies must have complied by 17 Dec. 2023.

The whistleblower protections include confidentiality, a prohibition against retaliation and no liability for disclosing necessary information to the report. The person who receives internal reports can be either a direct employee of the company, such as an HR or compliance officer; or an outside third party such as a service provider. In all cases, the person must protect the whistleblower’s identity and other personal information at all times.

On January 1, 2025, Germany made it a mandatory requirement for both internal and external reporting channels to support anonymous reporting and secure two-way communication.
Key operational requirements include:

In the event of a violation as the result of retaliation the perpetrator is obliged to compensate the Whistleblower. Companies or people found to be in violation of the whistleblower protection law can be subject to fines as high as €50,000.
16 Jul 2026 NAVEX Editorial Team
The NAVEX article covers what you need to know about anonymous reporting.
Read more
Customer Stories
As reporting volumes increased and regulatory complexity grew, Currys needed a way to manage compliance without expanding resources. By connecting incident management, risk workflows and regulatory intelligence in a single platform, the team gained the visibility and control needed to scale their program with confidence.
See their story
29 Jun 2026 Sarah Jo Loveday
This article, from the 2026 Top 10 Trends in Risk & Compliance eBook, discusses the signals pointing to an erosion of workplace culture.
Read more
Webinars Upcoming
Employees won’t use a speak-up program they don’t know about—or trust. Join NAVEX to learn eight proven strategies for increasing employee speak-up awareness, building confidence in reporting channels and encouraging a stronger speak-up culture across your organization.
Save your seat!
Guides
France’s regulatory environment is one of the most complex in Europe. Understanding French compliance regulations is critical for organizations operating in or connected to the market. This definitive guide helps you understand compliance obligations in France and build a resilient, trusted compliance program.
Get the guide
23 Jun 2026 NAVEX Editorial Team
In this blog, we explore retaliation, early warning signs and how to protect reporters.
Read more
22 Jun 2026 WhistleB by NAVEX
Learn what makes a whistleblowing system secure: anonymity protections, encryption standards, GDPR compliance, and how to evaluate build vs. outsource options.
Read more
Datasheets
Discover how NAVEX supports global whistleblowing and incident reporting programs through trusted telephony providers, broad geographic coverage and reliable caller access.
Get the datasheet
Datasheets
See how WhistleB supports secure reporting, case management and whistleblowing compliance with intuitive workflows built for organizations operating in Europe.
Get the datasheet
Datasheets
Explore WhistleB’s secure reporting, case management and GDPR-first capabilities designed to simplify whistleblowing compliance across Europe.
Get the datasheet
White Papers
This white paper explores how organizations can better support whistleblowers and create a culture in which reporting is seen as an act of integrity, not disloyalty.
Get the white paper
10 Jun 2026 Matt Kelly
Why do employees wait days or weeks before making an internal report? Explore the emotions, fears and motivations that shape speak-up behavior and reporting decisions.
Read more
Germany’s regulatory environment is complex and constantly evolving. Get the insights you need to strengthen your compliance program, reduce risk, and build a culture of transparency.