Whistleblowing – A Guide to Compliance: Part 4
Client Alert | 2 min read | 07.14.21
Crowell & Moring LLP’s 2021 series of client alerts: Whistleblowing – A Guide to Compliance is intended to provide companies with a practical guide to help them comply with their obligations under the EU Whistleblower Directive. Via a monthly alert, Crowell & Moring LLP will explain the different steps that companies need to take for compliance and emphasize various points for consideration. Step #4: Check the steps you should already be taking to ensure your company’s compliance with the EU Whistleblower Directive and the national laws that implement it.
1. Summary of the different steps and action points that can already be undertaken for compliance with the EU Whistleblower Directive
In our previous Alerts in this series, we have drawn attention to some of the steps and action points that companies can already undertake with a view to compliance:
- Action point #1: Analyze the company’s obligation to establish internal reporting channels and procedures (see Whistleblowing – A Guide to Compliance: Part 1)
- Action point #2: Understand the importance of setting up an effective internal whistleblowing system and organize an Internal Survey or listening sessions that will give you an insight into how your company’s employees view your internal communications (see Whistleblowing – A Guide to Compliance: Part 2)
- Action point #3: Understand the obligations of companies with operations in various EU member states and start implementing internal reporting channels, based on the provisions of the EU Whistleblower Directive (see Whistleblowing – A Guide to Compliance: Part 3 and Part 3b)
2. Current status of the implementation of the EU Whistleblower Directive in the various EU member states
Conclusion:
From the overview set out above, it can be seen that although some major EU member states are already well advanced in the transposition of the EU Whistleblower Directive (the Netherlands, Sweden), most countries are lagging behind. As a result, there is a definite risk that these countries will not meet the deadline for transposition of the Directive of December 17, 2021. The coming months will be crucial in determining whether the deadline of December 17, 2021 is realistic and whether the European Commission might agree to an extension of this deadline.
- Action point #4: Monitor the different EU member states’ national implementation of the EU Whistleblower Directive to identify specific national requirements.
Contacts
Insights
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen.
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach
Client Alert | 7 min read | 08.12.26
Developments in Canadian Investment Treaty Practice: New FIPA Between Canada and UAE in Force

