
The Spanish Whistleblower Protection Law
Explore the Spanish Whistleblower Protection Law, including compliance requirements, scope, and how to support and protect reporting in your organization

Explore the Spanish Whistleblower Protection Law, including compliance requirements, scope, and how to support and protect reporting in your organization

Law 2/2023 outlines the protection of persons who report breaches of law and seek to combat corruption. Published in the Official State Journal on 21st February 2023 and entering into force on March 13th, 2023, this law marks Spain as the eighteenth country in the EU to adopt legislation implementing the EU Whistleblower Protection Directive.
Before the implementation of Law 2/2023, Spanish law lacked a unified approach to whistleblower protection. Though a patchwork of laws and regulations was in place at a national and regional level, which provided some protection for whistleblowers, they varied widely in scope, coverage and effectiveness. For example, these existing laws covered the financial sector around the prevention of money laundering and terrorist financing and in violations of law around handling personal data, but they did not provide comprehensive protection for whistleblowers in all sectors or meet all EU Whistleblower Protection Directive requirements.
As of March 13th, 2023, Law 2/2023 is the first national legislation protecting whistleblowers across all private organizations employing more than 50 employees within Spain. Public sector entities with any number of employees fall into the scope of the Law, as well as other entities, including political parties, trade unions, employers’ organizations and foundations receiving or managing public funds. Private companies with fewer than 50 employees are not obligated to meet the requirements of Law 2/2023 by December 1st. However, those operating within certain sectors must still abide by existing EU and national reporting channel regulations specific to those sectors1.
Law 2/2023 aims to protect people who report offenses in a professional or work-related context where the offense could constitute an infringement of EU law and/or serious or very serious criminal or administrative offenses within Spain. Reported issues that obligate protections for the whistleblower include:

The Spanish Whistleblower Protection Law adopts the minimum standards for whistleblower protection outlined in the EU Whistleblower Protection Directive. These requirements include:

The Law 2/2023 broadens the scope of the “Reporting System Officer” position – the private-sector company’s designated role responsible for managing the internal reporting system. The Senate amended the original Bill to allow existing compliance or ethics officers to serve in this role if they meet requirements.

An organization can manage its own internal information system outlined as a requirement or contract the service to a specialized external third party – as long as it can also ensure independence, confidentiality and adherence to data protection and sharing requirements. Outsourcing the management of this internal reporting system must also not release the Reporting System Officer from liability.
The law also outlines the penalties for entity-level or individual actions that limit the rights of whistleblowers or amount to retaliation against the reporter.

For entities, infringements of the law result in penalties that start at €100,000 for minor offenses to upwards of €1 million for serious offenses. Additional sanctions for serious offenses will allow the Independent Authority for the Protection of Informants to impose public reprimand, a ban on obtaining subsidies or tax benefits for up to four years, and/or a ban on contracting with the public sector for up to three years. Fines for individuals start at €1000 for minor offenses to €300,000 for serious offenses

The sanctions for non-compliance include a leniency system in the cases of reporters involved in the reported offense if they fully cooperate with the investigation proceedings. Failure to implement an internal reporting system in compliance with the law qualifies as a very serious breach and can result in a penalty of between €600,001 and €1,000,000.
Datasheets
Discover how NAVEX supports global whistleblowing and incident reporting programs through trusted telephony providers, broad geographic coverage and reliable caller access.
Get the datasheet
Webinars Upcoming
Discover how risk and compliance teams are using AI today to improve investigations, policy management, reporting, and oversight – and what’s next for AI-powered compliance.
Save your seat!
12 Jun 2026 NAVEX Editorial Team
A strong speak-up culture starts with trust. Learn how reporting practices, leadership behavior and program performance influence whether employees raise concerns.
Read more
10 Jun 2026 Matt Kelly
Why do employees wait days or weeks before making an internal report? Explore the emotions, fears and motivations that shape speak-up behavior and reporting decisions.
Read more
Webinars Upcoming
Across continental Europe, organisations report 0.85 whistleblowing cases per 100 employees, and 58% of reports are submitted anonymously. In the UK, reporting rates are even lower at 0.69 cases per 100 employees, while anonymity levels are higher at 66%. Both figures sit in contrast to the global benchmark of 1.65 cases per 100 employees. What can these benchmarks tell us about the health of speak-up cultures across Europe, and what can organisations do to strengthen employee trust and reporting confidence?
Join NatWest, M&G and NAVEX as they explore the latest UK whistleblowing benchmark findings and compare them with trends across continental Europe. Discover what reporting volumes, anonymity rates and investigation outcomes reveal about programme effectiveness, and gain practical strategies to build trust, encourage employees to speak up and strengthen your whistleblowing programme.
Save your seat!
19 May 2026 Carrie Penman
Learn the difference between incident management and case management, how the workflows connect and what to look for when evaluating software and program structure.
Read more
12 May 2026 Matt Kelly
The EU Anti-Corruption Directive introduces stricter penalties, broader accountability, and greater expectations for compliance programs operating across Europe.
Read more
11 May 2026 NAVEX Editorial Team
UK whistleblowing law changes in 2026 bring sexual harassment under protected disclosures. Learn what this means for employers, compliance risk, and speak-up culture.
Read more
Use Cases
Expand your incident management program to capture data from external stakeholders with NAVEX One Whistleblowing & Incident Management.
Get the use case
Guides
Explore the state of workplace conduct issue reports, learn what the data really says about culture, risk and trust, and determine how to best approach your speak-up program in 2026 and beyond.
Get the guide
16 Apr 2026 NAVEX Editorial Team
Speak-up culture is revealed through patterns, not promises. Learn which signals matter most for oversight and trust.
Read more
8 Apr 2026 Matt Kelly
Compliance officers need to speak the language of the business and communicate in terms that the board, management, and other leaders will understand.
Read more
A strong incident management system is critical to meeting Spanish whistleblowing laws, building trust, and protecting your organization.