Mandatory whistleblowing channel for companies under Spain Law 2/2023.

The mandatory whistleblowing channel for companies operating in Spain — what Law 2/2023 calls the internal information system — stopped being a future prospect some time ago. The deadlines expired in 2023, the authority that supervises compliance has been operating since September 2025, and in April 2026 it opened its first major enforcement file. This guide brings together who is covered, what the law actually requires and what is going wrong.

Who must have a whistleblowing channel

Article 10 of Law 2/2023 requires an internal information system from:

  • Private legal entities with 50 or more employees.
  • Regardless of headcount, entities falling within the scope of EU acts on financial services and products, prevention of money laundering and terrorist financing, transport safety and environmental protection.
  • Political parties, trade unions, employers’ organisations and the foundations they create, where they receive or manage public funds.

Article 13 extends the obligation to the entire public sector: territorial administrations, public bodies, public universities, public-law corporations, commercial companies with majority public ownership and public sector foundations.

The second bullet is the one most often missed. An entity covered by anti-money-laundering rules must have a channel even with five employees. The fifty-employee threshold does not apply to it.

The deadlines have passed — and so has one more

The law allowed three months from its entry into force, placing the general deadline at 13 June 2023. For private entities with fewer than 250 employees and for municipalities under 10,000 inhabitants it extended this to 1 December 2023.

No implementation deadline remains open. An organisation without a channel has been in breach for more than two and a half years.

There is also a later deadline many organisations did not notice: on 10 February 2026 the Independent Whistleblower Protection Authority opened the form for notifying the appointment of the System Manager, setting 10 April 2026 as the cut-off for outstanding appointments. Having the channel in place but never notifying who runs it is itself a breach today.

What the system must contain, article by article

This is where most implementations fall short. The law does not ask for an inbox: it asks for a system.

  • Article 5. Implementation falls to the administrative or governing body, after consulting the workers’ representatives. The system must have a System policy formally approved by that body. A decision taken by the HR department does not qualify.
  • Article 7. Reports must be capable of being submitted in writing, orally or both, including an in-person meeting at the reporting person’s request; oral reports are documented by recording or transcript. Paragraph 3 is categorical: the channels shall allow anonymous reports to be submitted and processed. Anonymity is not a design option: it is a requirement.
  • Article 9. Acknowledgement of receipt within seven calendar days. A maximum investigation and response period of three months, extendable by a further three in particularly complex cases. And immediate referral to the Public Prosecutor where the facts may constitute a criminal offence.
  • Article 26. A register of reports received, showing receipt data, subject matter and status. It is not public, but it must exist.

The System Manager: where organisations are failing

Article 8 requires the appointment of a System Manager, who may be an individual or a collegiate body, and who must perform the role independently and autonomously, free from instructions. Appointment and removal must be notified to the Authority within ten working days.

That independence requirement is not rhetorical. In the first major file opened by the Authority, one of the objections is precisely that the person appointed as Manager could not, given their position, exercise the role autonomously.

Outsourcing the channel: what may be delegated and what may not

Article 6 allows management of the channel to be entrusted to a third party, provided it offers adequate guarantees of independence, confidentiality, data protection and secrecy of communications. It is formalised in an agreement, and that third party acts as a processor.

Two points matter here. First, liability remains with the entity. Outsourcing the management does not outsource the breach. Second — and this is the criterion the Authority has set in its first file — the third party may not take on the investigation function, which is reserved to the System Manager. A provider offering to “investigate on your behalf” is selling something the law does not allow you to buy.

Sharing the system between entities

Article 12 allows private entities with between fifty and two hundred and forty-nine employees to share the system and its resources. Article 14 allows municipalities under 10,000 inhabitants to share it with other administrations in their region. Article 11 governs groups of companies.

It is the sensible route for a mid-sized company that does not want to build an entire structure for three reports a year.

How it interacts with the GDPR

Title VI of the law governs data processing, and it pays to be clear here, because this is where the other authority comes in.

  • Legal basis: compliance with a legal obligation where the system is mandatory; performance of a task in the public interest where it is voluntary. Never the reporting person’s consent.
  • Retention (Article 32): data is kept only for as long as strictly necessary. Where three months pass from receipt without investigation having been opened, the data must be deleted, and may be kept in anonymised form to evidence the functioning of the system. It is the most breached rule of all, because nobody deletes anything.
  • Confidentiality of the reporting person: their identity is confidential and is not disclosed to the person concerned by the facts. Disclosure is possible only to the judicial authority, the Public Prosecutor or the competent administrative authority.
  • The person reported on: against their right to object, compelling legitimate grounds to continue the processing are presumed, unless proven otherwise.
  • Special categories: processing rests on substantial public interest, and any special category data received inadvertently must be deleted immediately.

One detail that catches out anyone who set up their channel before 2023: Article 24 of the Spanish Data Protection Act is no longer the reference rule. A final provision of Law 2/2023 reconfigured it and referred the regime to the law itself. If your documentation cites Article 24 as its basis, it is out of date.

The Authority is now operating

For almost three years the law existed without a supervisor. That is over. Royal Decree 1101/2024 approved the Statute of the Independent Whistleblower Protection Authority, and a ministerial order set its start of operations for 1 September 2025. It has been chaired by Manuel Villoria Mendieta since May 2025.

Appearing before the Spanish Parliament in May 2026, the Authority reported more than 600 reports received in nine months, 32 people under protection and five enforcement actions initiated. No penalty had been finalised at that date.

Its first major file targets the Port Authority of Valencia: the verification phase closed on 14 April 2026 and the matter moved to enforcement proceedings, with exposure of between 600,001 and one million euros. The two objections are the ones set out above: a System Manager without real independence, and investigation functions assigned to the external provider.

What getting it wrong costs

Article 65 sets the following fines:

  • Minor infringements: 1,001 to 10,000 euros for individuals; up to 100,000 euros for legal entities.
  • Serious infringements: 10,001 to 30,000 euros for individuals; 100,001 to 600,000 euros for legal entities.
  • Very serious infringements: 30,001 to 300,000 euros for individuals; 600,001 to 1,000,000 euros for legal entities.

Very serious conduct includes retaliating against the reporting person, disclosing their identity in breach of confidentiality, destroying or altering evidence, deliberately obstructing the investigation and not having an internal system while under an obligation to do so.

Ancillary penalties may be added: public reprimand, a ban on obtaining subsidies or tax benefits for up to four years, and a ban on contracting with the public sector for up to three. For many companies, that second part weighs more than the fine.

The eight recurring mistakes

From the Authority’s Recommendation 1/2026 on the design and implementation of the system, and from what is seen in practice, the same ones come up:

  1. Channels that do not accept anonymous reports, despite Article 7(3).
  2. A generic email inbox instead of a secure platform with traceability and encryption.
  3. No System policy formally approved by the governing body.
  4. A System Manager with a conflict of interests or without real autonomy.
  5. Delegating the investigation to the external provider.
  6. Missing deadlines: acknowledgements beyond seven days, files closed after three months.
  7. No register of reports.
  8. Not notifying the Authority of the System Manager’s appointment.

All eight have something in common: none of them is visible from the company’s website. They surface when the first report arrives and has to be handled, or when the Authority asks.

What to do if your company is covered

The order is this: establish whether you are covered and on what basis; approve the System policy at board level, after consulting workers’ representatives; implement a channel that accepts anonymous reports and leaves an audit trail; appoint the System Manager and notify the Authority; open the register; and set down in writing the handling procedure with its deadlines and its three-month deletion rule.

At Auratech Legal we implement the system and take on its direction as external whistleblowing channel manager, with expert certification in Internal Information Systems from Spain’s UNED and with the split of functions the law requires: channel management outside, and the decision on each report where the law places it.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *