In recent days, the topic of whistleblower protection has gained prominence, becoming a vital aspect of corporate risk management. On June 14, 2024, Poland implemented national legislation based on a European Union directive, introducing regulations aimed at protecting individuals who report legal violations—commonly referred to as whistleblowers. A central provision of these regulations is the obligation for companies to implement internal whistleblower reporting procedures by September 25. Failure to comply may result in criminal sanctions.
Whistleblower Protection in EU and Polish Law
The obligation to implement whistleblower reporting procedures stems primarily from the transposition of Directive (EU) 2019/1937 into Polish law. This directive requires member states to establish legal frameworks that protect individuals reporting violations in both the public and private sectors. Poland’s response is the Act of June 14, 2024 on Whistleblower Protection. This law imposes a duty on businesses—particularly large and medium-sized companies and financial institutions—to establish internal procedures that enable the reporting of unlawful conduct.
The purpose of these procedures is not only to shield whistleblowers from retaliation by employers but also to help companies manage risk effectively and prevent misconduct.
Who Is Required to Implement a Procedure?
The obligation applies primarily to companies employing at least 50 individuals, financial institutions, and entities operating in high-risk sectors, such as managers of alternative investment companies (ZASI – Zarządzający Alternatywnymi Spółkami Inwestycyjnymi).
Although smaller firms are not legally required to implement such procedures, it is increasingly recommended that they do so. By adopting appropriate mechanisms, businesses can foster a culture of transparency and accountability, which in turn builds trust among clients, business partners, and employees.
What Should a Whistleblower Procedure Include?
An internal reporting procedure should be comprehensive and tailored to the specific nature of the company. Key elements include:
- Reporting channels: The procedure should specify how whistleblowers can submit reports—e.g., via dedicated email addresses, online forms, or telephone hotlines. At least one channel must allow for anonymous reporting.
- Designation of responsible personnel: The company must appoint individuals responsible for receiving and verifying reports, as well as initiating follow-up actions when violations are confirmed.
- Personal data protection: Both whistleblowers and individuals named in reports must be protected in accordance with the General Data Protection Regulation (GDPR – RODO). The company should include appropriate information clauses regarding data processing.
- Impartiality: Those handling reports must be impartial and free from conflicts of interest in the cases they review.
- Detailed procedures: The company should clearly outline the steps taken after receiving a report, including verification methods and potential sanctions against those found to have committed violations.
- Whistleblower protection measures: The procedure must specify the protections afforded to whistleblowers, including confidentiality of identity and safeguards against retaliation.
Benefits of Implementing a Whistleblower Procedure
Introducing a whistleblower reporting procedure offers numerous advantages. It enables early detection and prevention of irregularities before they escalate into serious financial or reputational damage. Companies with effective procedures often enjoy greater trust from employees, clients, and contractors. Transparency and responsible governance are increasingly valued by investors.
Moreover, legal compliance with whistleblower protection regulations helps companies avoid potential penalties.
Consequences of Failing to Implement a Procedure
Failure to implement a whistleblower reporting procedure can lead to serious consequences. Companies that do not adopt appropriate measures may face fines, and their management teams may be held legally accountable. Additionally, the absence of a procedure may allow legal violations to go undetected, ultimately harming the company’s reputation and financial performance.
Types of Penalties and Liabilities
Financial penalties The law provides for fines against companies that fail to meet the obligation to implement whistleblower procedures. These penalties can be substantial, depending on the company’s size, the severity of violations, and other factors. Fines may reach several hundred thousand złoty, posing a significant financial burden.
Management liability Responsibility for non-compliance may rest not only with the company but also with board members or other individuals in management roles. In practice, this means that failure to comply may result in fines or, in extreme cases, criminal liability.
Management may also be held accountable if the lack of a procedure leads to serious violations—such as money laundering, labor law breaches, or other illegal activities that could have been prevented through proper reporting.
Administrative sanctions In addition to fines, companies may face administrative penalties imposed by supervisory authorities such as the National Labour Inspectorate (Państwowa Inspekcja Pracy) or other institutions responsible for enforcing labor law and whistleblower protection. These sanctions may include mandatory implementation of procedures, suspension of operations, or revocation of operating licenses (e.g., in the financial sector).
Reputational damage Failure to implement whistleblower procedures can result in significant reputational harm. Whistleblowers who lack internal reporting channels may turn to mainstream media, leading to public exposure of violations. Such disclosures can damage a company’s prestige and deter investors, business partners, or customers from engaging with the firm.
Civil liability The law also provides for civil liability in cases where whistleblowers suffer harm—such as dismissal, retaliation, or harassment—due to the absence of proper procedures. Companies may be sued for damages, and if found liable, may be required to pay substantial compensation.
Criminal penalties In cases of particularly serious violations, the law allows for criminal prosecution of individuals who knowingly failed to implement reporting procedures, resulting in significant harm to whistleblowers or enabling continued illegal activity. This may include concealing instances of money laundering, corruption, or other serious crimes.
The Whistleblower Protection Act provides for penalties of restriction of liberty or imprisonment for up to one year.
Contact us to receive expert support!

