Skip to main content
EU Whistleblower Directory

Whistleblower reporting tools for EU compliance

Verifiable facts about platforms that meet the requirements of EU Directive 2019/1937. Vendors headquartered outside the European Union are flagged for data-sovereignty risk. Every entry is sourced from vendor-published materials and dated at last verification.

Or read the scored country rankings or the 2026 market research.

What most vendors won't tell you

Counted across all 126 platforms still on sale, not a shortlist. Each figure is what vendors publish on their own pages — where a vendor publishes nothing, that is recorded as its own answer rather than dropped.

53 / 126
publish no entry price
46 / 126
do not say where report data is hosted
89 / 126
publish no security certification
3 / 126
cover all 24 official EU languages

Read the 2026 research →

Shortlist by requirement

Most shortlists start from one non-negotiable requirement. Each page applies exactly one and shows how many of the listed platforms survive it.

Shortlist by country

Which platforms cover each member state, and the national law a channel there has to satisfy.

How this directory works

Four things worth knowing before you rely on anything here.

What a vendor says, and what we checked

A profile records what a vendor publishes, with the source link and the date we read it. A ranking is our own assessment against a rubric written before any product was scored. The two are kept apart.

Read the methodology

Entries go stale, and we show it

Every vendor page we cite is re-fetched on a schedule. When one changes, the entry that relies on it is flagged for re-checking instead of quietly ageing.

How we keep it current

Nobody can buy a place here

No vendor pays for a listing, a position, or a score, and there is no affiliate revenue. Vendors can correct any fact or dispute any score, and every correction is dated on the entry.

Correct an entry

Take the data and check it

The whole catalogue is published as JSON, no authentication, under CC BY 4.0. Recompute any number on this site, or reuse it with attribution.

Developer documentation

Last updated:

Frequently asked questions

Buyer questions that recur across procurement and compliance reviews. All answers reference the Directive's text or vendor-published facts.

What is the EU Whistleblower Directive?
Directive (EU) 2019/1937 sets minimum EU-wide standards for protecting persons who report breaches of Union law. It requires covered organisations to operate secure internal reporting channels, prohibits retaliation against reporters, and obliges member states to transpose it into national law.
Which organisations must have a whistleblower reporting channel?
Private-sector organisations with 50 or more employees, all public-sector entities, and all financial-sector entities regardless of size. Some national transpositions extend the scope further — verify the obligation in each jurisdiction where your organisation operates.
What counts as a compliant reporting channel?
A secure, confidential channel that accepts reports in writing and orally, protects the reporter's identity, tracks acknowledgement within 7 days, and delivers follow-up feedback within 3 months. Most organisations deploy a digital platform backed by a designated handler; telephone hotlines and in-person meetings also qualify.
Does whistleblower software have to be hosted in the EU?
Directive 2019/1937 does not mandate EU hosting. The GDPR governs transfers of personal data outside the EU and most procurement teams treat EU-hosted processing as the default. This directory records each vendor's published hosting region.
Can whistleblower reports be anonymous?
The Directive leaves anonymous reporting to national discretion, but a reporter who is later identified still receives the full protections. Germany (HinSchG), France (Loi Waserman / Sapin II), and Italy (D.Lgs. 24/2023) explicitly accept anonymous reports.
What deadlines apply once a report is received?
Acknowledgement of receipt within 7 days, follow-up feedback to the reporter within 3 months, and retention of records under GDPR. Platforms in this directory vary in how they enforce and surface these deadlines.
How much does whistleblower software cost?
Published entry prices in this directory start around €40 per month for flat-rate EU SME plans. Per-employee tiered pricing reaches several hundred euros per month above 1,000 employees. Several enterprise vendors publish no price and require sales engagement.
What are the penalties for non-compliance?
Penalties are set in national transposition laws. Germany's HinSchG sets fines up to €50,000 for failing to establish a channel and up to €100,000 for retaliation against a reporter. Other member states publish similar ranges.

Read the full guide to Directive 2019/1937 →