Skip to main content
EU Whistleblower Directory

Whistleblowing failures on the record: regulator and court decisions

Every case where a regulator or court found that a whistleblowing channel, or the people running it, failed to protect a reporter. Fines, what went wrong, and a link to the primary decision for each.

Whistleblowing law rests on one promise: the person who reports can do so without being identified against their will. This register collects the decisions where a regulator or court found that promise broken, and the decisions where states were fined for not making it in the first place.

Each entry links to the primary document: the regulator’s order, the court’s judgment, or the supervisor’s press release. Where press coverage and the primary source disagree, the entry follows the primary source and notes the difference.

Inclusion rule: a published decision by a regulator, supervisory authority or court. Allegations, lawsuits without a ruling, and vendor marketing are left out.

Summary

DateAuthorityWhoSanctionWhat failed
Dec 2025Oficina Antifrau de Catalunya (Spain)Nora, S.A.€600,000 and public reprimandEmployee suspended about a month after reporting irregularities
6 Mar 2025Court of Justice of the EUGermany, Czechia, Hungary, Estonia, Luxembourg€39m combinedDirective transposed late or not at all
Mar 2025AEPD (Spain)Servicios Especiales, S.A. (Servisa)€200,000 (paid €120,000)Closure resolutions naming all complainants and accused emailed to the works council and all parties
25 Apr 2024Court of Justice of the EUPoland€7m lump sum + €40,000/dayDirective not transposed
7 Apr 2022Garante (Italy)Azienda Ospedaliera di Perugia€40,000Firewall logged the IP address and username of everyone opening the whistleblowing app
7 Apr 2022Garante (Italy)ISWEB S.p.A. (the app’s vendor)€40,000Hosted the app with an unauthorised sub-processor, no written contract
18 Dec 2018NYDFS (New York)Barclays Bank PLC and New York branch$15,000,000Governance and controls failed to stop the CEO’s attempt to unmask the writer
11 May 2018FCA and PRA (UK)Jes Staley, CEO of Barclays£642,430CEO directed internal security to identify an anonymous letter writer
3 Apr 2017OSHA (US)Wells Fargo~$5.4 million, reinstatementBranch manager forced out after reporting suspected fraud to superiors
12 Nov 2014US Court of Appeals, Fifth CircuitHalliburtonRuling for the whistleblowerGeneral counsel named the whistleblower in a document-hold email to colleagues

Channel and confidentiality failures

Azienda Ospedaliera di Perugia: the logs around the app identified reporters

Garante per la protezione dei dati personali, order of 7 April 2022. Fine: €40,000.

The hospital ran a web-based whistleblowing application. The application itself was not the problem. Access to it went through the hospital’s firewall, and the firewall recorded browsing operations in log files, including the IP address of the device and the username of the person connecting. The logs were kept until the file reached 150 GB before being overwritten. Anyone with access to those logs could see who had opened the whistleblowing application, and when.

The Garante also found that the hospital had given staff no privacy notice for the channel, had carried out no data protection impact assessment, had not listed the processing in its record of processing activities, and had left the credentials of a department head who resigned in May 2019 active for two months afterwards.

Provisions breached: GDPR Articles 5(1)(a) and (f), 13, 14, 25, 30, 32 and 35.

Lesson for buyers: encryption inside the application does not help if the network in front of it records who connected. Confidentiality has to cover the full request path, including proxies, firewalls and CDNs.

Primary source: Garante order against Azienda Ospedaliera di Perugia (docweb 9768363)

ISWEB S.p.A.: the vendor’s undisclosed hosting provider

Garante per la protezione dei dati personali, order of 7 April 2022. Fine: €40,000.

ISWEB supplied the hospital’s whistleblowing application. According to the order, the application used HTTPS and encrypted the content of reports. The Garante fined ISWEB anyway: it had hosted the system with Seeweb S.r.l. without the hospital’s prior written authorisation as controller, and without a data processing agreement governing Seeweb’s role. The hospital did not know its whistleblowing data sat with a third party.

Provision breached: GDPR Article 28. ISWEB was given thirty days to regularise the hosting relationship.

Lesson for buyers: ask for the complete sub-processor list for the whistleblowing service specifically, and make sure the contract requires your written authorisation before a new one is added.

Primary source: Garante order against ISWEB S.p.A. (docweb 9768387)

Barclays: the CEO who tried to find the letter writer

FCA and PRA (UK), final notices of 11 May 2018. Fine: £642,430 against Jes Staley personally. NYDFS (New York), 18 December 2018. Fine: $15 million against Barclays.

In June 2016 Barclays board members received anonymous letters raising concerns about a senior executive Staley had recruited. On 28 June 2016 Staley instructed Group Security to try to identify the author of the first letter. The bank’s whistleblowing team told Group Security that tracing an anonymous author was not acceptable. Staley then instructed Group Security to resume.

The UK regulators found a breach of Individual Conduct Rule 2 (due skill, care and diligence), not of the integrity rule. It was the first case brought by the FCA and PRA under the Senior Managers Regime. Barclays separately reduced Staley’s bonus by £500,000, and now has to report annually to both regulators on its whistleblowing cases, with its whistleblowers’ champion attesting personally to the soundness of the bank’s whistleblowing systems and controls.

New York’s Department of Financial Services fined the bank itself. Its consent order says Staley “personally directed the head of Barclays’ Group Security to attempt to identify the author(s) of two whistleblowing letters,” despite advice against it from the Group Chief Compliance Officer and the General Counsel.

Note on the sources: the FCA notice says Staley pursued only the first letter, and left the second alone because it purported to come from an employee and so fell within the whistleblowing policy. NYDFS refers to two letters. Both are cited here as published.

Primary sources: FCA final notice · Bank of England / PRA announcement · NYDFS press release

US Court of Appeals for the Fifth Circuit, Halliburton, Inc. v. Administrative Review Board, No. 13-60323, 12 November 2014.

Anthony Menendez, a director in Halliburton’s accounting function, raised revenue-recognition concerns internally and filed a confidential complaint with the SEC. His internal complaint was sent from his company email address, under his name, and was forwarded to the general counsel.

When the SEC notified Halliburton of an investigation and directed it to preserve documents, the general counsel inferred that Menendez was the source. He emailed Menendez’s manager and others to preserve documents because “the SEC has opened an inquiry into the allegations of Mr. Menendez.” The manager forwarded the email to fifteen members of Menendez’s work group. According to the opinion, colleagues then began “generally refusing to work and associate with him.”

The court upheld the Department of Labor’s finding that disclosing a whistleblower’s identity was an adverse action under the Sarbanes-Oxley Act’s anti-retaliation provision.

Lesson for buyers: a report submitted from a named work account is identified the moment it is forwarded. The channel has to keep the reporter’s identity separate from the case file that investigators circulate.

Primary source: Fifth Circuit opinion, No. 13-60323

Servisa: closure letters that named every complainant

Agencia Española de Protección de Datos, procedure PS/00505/2024, resolution of March 2025. Fine: €200,000, reduced to €120,000 paid.

This case concerns an internal harassment procedure rather than a Directive reporting channel. It is included because the failure is the one a reporting channel most often suffers: identity leaking as the case file circulates.

In May 2024 Servisa, a funeral services company in the Ocaso group, opened a harassment procedure with five complainants and ten accused. On 31 July 2024 it emailed the works council the closure resolution for each complainant. Each resolution named every complainant and every accused person, with their job positions. The same resolutions went to all fifteen people involved. One accused person then posted “Gracias por la denuncia” (“thanks for the complaint”) in a work WhatsApp group, and a complainant went on sick leave after an anxiety attack. The company’s own rules had promised confidentiality.

The AEPD found a very serious breach of the confidentiality principle in GDPR Article 5(1)(f). The fine was reduced by 40% for acknowledgement of responsibility and voluntary payment.

Primary source: AEPD resolution PS/00505/2024 · Corroboration: elDiario.es

Nora, S.A.: Catalonia’s first retaliation fine under Ley 2/2023

Oficina Antifrau de Catalunya, sanction reported December 2025, confirmed final in its 2025 annual report. Fine: €600,000 plus public reprimand.

According to press reports, an employee of Nora, S.A., the public waste company of the Consell Comarcal de la Selva and the town of Blanes, requested internal information on irregularities in hiring, bonuses and time recording, and reported to the Oficina Antifrau in 2023. About a month later the company suspended her without pay for six days. The Girona social court annulled the suspension as retaliation and awarded her €7,500. It is the first sanction the Oficina Antifrau has imposed for retaliation under Spain’s whistleblower protection law.

Note on the sources: the Oficina Antifrau’s annual report confirms a final sanction for retaliation against a whistleblower but does not name the company, and the sanction resolution is not published. The company name and amount come from Catalan press.

Primary source: Oficina Antifrau 2025 annual report press release, p. 9 · Corroboration: Nació Digital, 3Cat

Wells Fargo: OSHA’s largest individual whistleblower award

US Occupational Safety and Health Administration, order of 3 April 2017. About $5.4 million, plus reinstatement.

OSHA found that a branch manager in Los Angeles was abruptly forced out in 2010 after telling superiors he suspected two subordinates of bank, mail and wire fraud, and that the report was a contributing factor in his termination. OSHA ordered reinstatement and about $5.4 million in back pay, compensatory damages and attorneys’ fees, the largest individual award in its whistleblower programme at the time. Wells Fargo said it would contest the order.

This case concerns retaliation after an internal report to management. It is separate from the sales-practices scandal of 2016, in which former employees told CNNMoney they were fired after calling the bank’s ethics line. That reporting did not result in a regulator decision on the ethics line and is not listed here as a case.

Primary source: US Department of Labor news release, 3 April 2017 · Corroboration: NPR

State-level enforcement of Directive (EU) 2019/1937

The Directive set a transposition deadline of 17 December 2021. The European Commission took several member states to the Court of Justice for missing it.

CaseMember stateJudgmentLump sumDaily penalty
C-147/23Poland25 Apr 2024€7,000,000€40,000 until transposition
C-149/23Germany6 Mar 2025€34,000,000none
C-152/23Czechia6 Mar 2025€2,300,000none
C-155/23Hungary6 Mar 2025€1,750,000none
C-154/23Estonia6 Mar 2025€500,000€1,500 until transposition
C-150/23Luxembourg6 Mar 2025€375,000none

Germany argued that the 2021 federal election and the conciliation procedure between its two chambers had delayed the law. The Court rejected this: a member state cannot rely on its domestic legislative process to justify failing to meet an EU obligation.

Primary sources: C-147/23 Commission v Poland (EUR-Lex) · C-149/23 Commission v Germany (EUR-Lex) · Summary of all five 2025 judgments: eucrim

Regulator guidance that follows from these cases

Email is not an adequate channel (Italy, 2025). In its opinion of 9 October 2025 on the national anti-corruption authority’s draft guidelines for internal reporting channels, the Garante stated that using email, ordinary or certified (PEC), is “di per sé non adeguato” (inadequate in itself) to guarantee the confidentiality of the reporting person’s identity. Mail systems generate and keep transmission logs that can identify the sender, especially on employer-provided accounts. Garante opinion, docweb 10184673

What the cases have in common

None of the failures above involved an attacker. Each came from an ordinary part of the organisation or its supply chain: a firewall doing its job, a hosting arrangement nobody wrote down, a security team following the CEO’s instruction, a legal hold email forwarded to the team, closure letters sent to every party. Confidentiality depends on everything a report passes through, on its way in and as the case moves around the organisation.

For the questions these cases suggest asking a vendor, see the what the enforcement cases teach buyers checklist.

Corrections and additions

This register is updated as new decisions are published. To propose a case, email the link to the primary decision to contact [at] whistleblowertools [dot] eu. Cases are added only once the primary document has been read.