Most companies meet the whistleblowing rules at the worst possible moment. A customer's security review asks whether you have an internal reporting channel, or a worker raises a serious concern and finds there's nowhere safe to send it. Either way the scramble is expensive, because a compliant channel isn't something you stand up overnight.
The EU Whistleblower Directive and its national versions, like the Swedish visselblåsarlag, turned internal reporting from a nice-to-have into a legal obligation. It comes with employee thresholds, strict deadlines, confidentiality rules, and record-keeping you have to prove. This guide covers what the rules actually ask of a Nordic company and how to run the channel as a living program instead of a form nobody trusts.
Who needs a reporting channel
The headline threshold is 50. If you have 50 or more workers, you're required to set up an internal reporting channel. The directive phased this in by size: organizations with 250 or more workers had to comply first, and those with 50 to 249 got a later deadline that has now passed across the Nordics. Public sector bodies are covered too, often regardless of size, though smaller municipalities can get exemptions.
"Workers" is broader than your payroll. The rules protect employees, but also job applicants, contractors, interns, volunteers, shareholders, and people whose relationship has ended. When you size your obligation, count the people who could reasonably report, not just the ones with an employment contract. If you operate in several Nordic countries, check each national law, because thresholds, sanctions, and the list of covered breaches vary between Sweden, Denmark, Norway, and Finland even though they share the same directive.
What a compliant channel looks like
A reporting channel isn't a shared inbox that three managers can read. The directive sets real requirements for how it works.
- Confidential by design. The identity of the reporter, and anyone mentioned in the report, must be protected. Only the people authorized to handle cases can see who reported.
- Secure. The channel has to prevent unauthorized access. That rules out a personal email address or a spreadsheet on a shared drive.
- Multiple formats. Workers can report in writing, orally, or both. If someone asks for a meeting, you have to offer one within a reasonable time.
- An impartial handler. You have to designate a person or team to receive reports and follow up diligently. They need to be independent enough to act on what they find.
You also have to give workers clear information about how to report, both internally and to the relevant external authority, so they can make an informed choice.
The deadlines you have to hit
Two clocks start the moment a report lands, and missing either one is a compliance failure you can't paper over later.
- Acknowledgment within 7 days. You have to confirm to the reporter that you received the report within seven days of it arriving.
- Feedback within 3 months. Within three months you have to tell the reporter what you're doing about it: the action planned or taken, and the reasoning. If a case runs longer, you keep them informed.
These deadlines are exactly why an ad hoc process fails. If a report sits in someone's inbox while they're on leave, the seven days pass and you're already non-compliant, no matter how well you investigate afterward.
Protection against retaliation
The core promise of the law is that reporting in good faith shouldn't cost someone their job or their standing. Retaliation is defined broadly: dismissal, demotion, a withheld promotion, a pay cut, negative references, exclusion, or any other detriment tied to the report.
The burden of proof shifts to the employer. If a worker who reported suffers a detriment, you have to show it wasn't retaliation. That reversal is a big deal, and it's the reason your case records matter so much. Clean, timestamped documentation of what you decided and why is often the only thing standing between you and a costly claim.
Record-keeping and the GDPR interplay
You're required to keep records of every report and how you handled it, and to retain them for as long as necessary and proportionate. Those records are your evidence that the channel works, but they're also full of personal data, which puts you squarely in GDPR territory.
Every report involves at least the reporter, and usually the person the report is about and any witnesses. That data needs a lawful basis, which is typically your legal obligation to operate the channel. It needs to be minimized, so you collect what's relevant to the case and nothing more. It needs a retention limit, so cases don't live forever in a system nobody reviews. And it can trigger tension between two rules, because the accused person has GDPR access rights, but the reporter's identity has to stay confidential. You have to be able to honor both.
Decide retention before you launch
Set a clear retention period for whistleblowing cases and enforce it. Keeping reports longer than you can justify turns a compliance asset into a GDPR liability, and it's one of the first things a data protection review will probe.
The stakes
The legal exposure is real. National laws attach fines for failing to establish a channel, for obstructing reports, or for retaliating, and the retaliation claims themselves can be expensive once the burden of proof sits with you.
The reputational stakes are bigger. A whistleblowing case that leaks, or a reporter who goes public because they didn't trust the internal channel, does far more damage than any fine. Enterprise buyers increasingly ask about your reporting channel in security reviews, and a credible answer signals a mature governance culture. A missing or improvised one signals the opposite.
Turn case handling into evidence
This is where a program beats a form. In the OptiTech Console, your reporting channel, your case handling, and your records live in one connected system instead of scattered across inboxes and drives.
Each report becomes a case with the acknowledgment and feedback deadlines tracked automatically, so the seven-day and three-month clocks are visible instead of forgotten. Access is limited to the people authorized to handle cases, which is how you keep confidentiality real rather than aspirational. Every action is logged with a timestamp, so if a retaliation claim ever arrives, you have the contemporaneous record the reversed burden of proof demands. Retention rules run on schedule, so cases close out when they should and your GDPR posture stays clean. Because OptiTech keeps EU-only data residency in Stockholm and Frankfurt, sensitive reports never leave the region.
Because the whole thing sits inside your wider compliance program, the channel isn't an island. The same evidence that proves the channel works can be surfaced in your trust center, alongside your frameworks and controls, so a buyer's security review starts to answer itself.
Getting started
You don't have to solve everything at once. A realistic first pass looks like this:
- Confirm your obligation. Count all your workers, not just employees, and check the national law in each country you operate in.
- Stand up a secure, confidential channel with an impartial handler named and trained before you announce it.
- Wire in the deadlines. Make the 7-day acknowledgment and 3-month feedback clocks impossible to miss.
- Set retention and access rules so the channel is a GDPR asset, not a liability.
- Connect it to your program so case records become evidence you can show.
Whistleblowing compliance rewards the companies that treat it as an operating habit rather than a checkbox. Build the channel properly once, keep the records current, and both your workers and your buyers get the same clear answer: this is a place where concerns are handled seriously. For more on the wider picture, see the rest of our writing on the blog.
Ready to run a whistleblowing channel that holds up as evidence? Book a demo and see how OptiTech connects your reporting channels, case handling, and records.
