27. Sep 2021

Important information summarized for you

Whistleblower guideline for private companies and public bodies

In October 2019, the EU passed a directive ((EU) 2019/1937) on the protection of whistleblowers, which must be implemented as minimum standards of the national whistleblower directive in all EU member states by December 2021 in order to protect whistleblowers from reprisals.

The qualityaustria experts Eckehard Bauer, MSc, Executive Vice President Business Development Safety Management, Business Continuity, Risk, Security, Compliance and Transport and Martin Fridl, Network partner, Product Expert Compliance and Anti-bribery management systems have summarized all important information for you in a compact article!


  • General implementation of the EU directive into national law by December 17th, 2021 (currently open).
  • The Austrian legislature still has to determine which authority (s) will be responsible for such reports in Austria.
  • Graduation of the entry into force according to company size:
    • > 249 employees: December 17, 2021 Mandatory compliance with internal whistleblowing channels
    • 50-249 employees: mandatory compliance for organizations from December 17, 2023

Area of application:

Any report of a breach or potential breach of EU law. That means:

  • The provisions of the directive only apply to reports of legal violations in certain areas of Union law. The following are recorded, for example:
    • Violations related to public procurement (procurement procedures), financial services, public health,
    • The protection of privacy and data protection or internal market rules (free movement of workers)
    • Misconduct in other areas / on other topics - such as in anti-discrimination law (but that will be the largest proportion!) - are not covered by the directive. The Austrian legislature could extend these rights and obligations to other areas, but nothing of this is included in the government program.

Procedure – three-stage reporting system:

  1. internal reporting channels;
  2. external reporting channels and
  3. a disclosure (as part of which information is made publicly available).

The basic rule is that whistleblowers must first exhaust the internal reporting channels before they continue to report. Under certain conditions, the whistleblower may contact the responsible authorities directly (external reporting channels). For example, if no “suitable measures” are taken after an internal report or there is no internal reporting system at all. If these reporting systems do not (also) work or if the whistleblower has, for example, “sufficient reason” from the outset to assume that a violation could directly or obviously jeopardize the “public interest”, he may even make information about a violation directly publicly available (e.g. go to the media). According to the directive, making information publicly available should only be permitted in exceptional cases, but it only describes the requirements for this in a general way (possibly too complicated questions of interpretation in practice).

Legally important for the system and the handling of whistleblower information is:

  • Safely designed, set up and operated (Art. 9.1.a)
  • Confirmation of receipt of the report within seven days (Art. 9.1.b)
  • Designation of a person or department (Art. 9.1.c) Attention: independence
  • Proper follow-up on anonymous and non-anonymous reports (Art. 9.1.d-e)
  • Prompt response, within three months (Art. 9.1.f)
  • Guarantee of confidentiality (Art. 16)
  • Conformity with the GDPR (Art. 17)
  • Documentation of reports (Art. 18)

Normative support is provided by the following management system standards ISO 37001 (Management Systems) and ONR 192050 "Compliance Management Systems (CMS) - Requirements and Instructions for Use" and in parts ISO 37301 (Compliance Management Systems).

You would like to have more information? Contact us here – we look forward to your inquiries and contact!

Contact person


quadratisches Portraitbild von Claudia Kerpe

Ms. Claudia Kerpe, MSc

Head of HR, Business Development Risk, Business Continuity, Compliance and Anti-bribery

News & Events

The basis for long-term success!

18. Jun 2024

QMD Services: First in-vitro diagnostics certificate achieved in record time

IVDR certificate for test kits for the identification of infectious diseases

Learn more
27. May 2024

New accreditation for SCC VAZ 2021 A and SHE Personal VAZ 2021

News regarding SCC

Learn more
22. May 2024

With QMD Services, Austria has its own national Notified Body for medical devices since mid-May

National Notified Body for medical devices

Learn more
06. May 2024

QMD Services: Florian Heffeter (43) new second Managing Director

Management expanded

Learn more
30. Apr 2024

5 hints on how companies can get a grip on their reporting requirements

Building on existing systems:

Learn more
23. Apr 2024

Climate change becomes the focus of management system standards

New ISO requirements:

Learn more
18. Apr 2024

Above-average high recommendation rate for Quality Austria

Achieving top performance together

Learn more
28. Mar 2024

ISO 14001 is being revised – what can we expect?

New revision planned

Learn more
22. Mar 2024

Into the future with a system

New qualityaustria Overview of Services 2024 published

Learn more
08. Jan 2024

Current information on the ISO 450xx series

New publication EN ISO 45001:2023

Learn more
13. Mar 2024

Event: 29. qualityaustria Forum

21. Dec 2023

ISO 9001 Revision: What you need to know now!

The first board meeting has taken place

Learn more
+43 732 34 23 22