Reconectando con el servidor

Mantén esta pestaña abierta: tu trabajo no se ha perdido.

No hemos podido reconectar

Recarga la página para continuar donde lo dejaste.

La sesión ha caducado

Vuelve a cargar la página para iniciar sesión de nuevo.

Spain's authority is now operating and tick-box channels are under review. Would yours hold up?Act now →
España · Practical guide

Ley 2/2023: the whistleblowing channel Spain's authority requires, explained

Ley 2/2023 of 20 February, on the protection of persons who report breaches (Spain) · Updated: julio de 2026

What is it, and what does it require of you?

Ley 2/2023 requires every Spanish company with 50 or more employees (and the whole public sector) to run an internal reporting channel that guarantees confidentiality and anonymity, acknowledges receipt within 7 days and answers within 3 months at most. With Spain's whistleblower protection authority now operational, fines reach €1,000,000.

Who does it apply to?

Companies with 50 or more employees, all political parties, unions and employers' associations, and the whole public sector (with nuances for small municipalities). Companies over 250 have been covered since June 2023; those with 50–249 since December 2023. A group may share resources, but each covered entity answers for its own compliance.

Key dates

13 mar 2023 Ley 2/2023 enters into force.
13 jun 2023 Channel mandatory for companies over 250 employees and the public sector.
1 dic 2023 Channel mandatory for companies with 50 to 249 employees.
sep 2025 Spain's whistleblower authority begins operating as national supervisor.
2026 First enforcement cases for missing or defective channels.

See also the Spain–Latin America compliance calendar.

Penalties

Very serious infringements (no channel, retaliation against the reporter…) De 600.001 € a 1.000.000 €
Serious infringements Hasta 600.000 €
Additional Prohibición de obtener subvenciones y de contratar con el sector público hasta 4 años

Compliance checklist

  1. Check your channel takes verbal, written and ANONYMOUS reports — an ethics@ mailbox doesn't qualify.
  2. Guarantee acknowledgement within 7 calendar days, with a record that proves it.
  3. Watch the 3-month response deadline (extendable to 6 in complex cases, with reasons).
  4. Appoint and document the officer responsible for the internal reporting system.
  5. Protect the reporter's identity: encryption, restricted access, access logging.
  6. Keep evidence of every step: the authority doesn't ask whether you have a channel — it asks whether it works.
How DSA Compliance solves it
  • A complete whistleblowing channel: reports by web, app, phone or QR with real technical anonymity.
  • Statutory deadlines watched automatically: the 7-day acknowledgement and the 3-month resolution don't depend on anyone remembering.
  • Secure dialogue between handler and reporter, preserving anonymity.
  • A single file with dated evidence, ready to show the authority.
Free one-hour assessment → See the program See the campaign

Frequently asked questions

Which companies must have a whistleblowing channel?

All those with 50 or more employees, plus the public sector, political parties, unions and employers' associations. The duty has applied since June 2023 (250+) and December 2023 (50–249).

What are the fines under Ley 2/2023?

Very serious infringements carry fines of €600,001 to €1,000,000, plus a possible ban on grants and public contracting for up to four years.

What is Spain's whistleblower authority?

The Autoridad Independiente de Protección del Informante (AIPI), the national body that supervises compliance with Ley 2/2023, handles external reports and exercises enforcement powers. It is operational and already reviewing internal channels.

Will an email inbox do as a whistleblowing channel?

No. The channel must guarantee confidentiality, allow anonymity, record the deadlines (7-day acknowledgement, 3-month answer) and protect the data under GDPR. An ethics@company.com mailbox can evidence none of that.

Can group subsidiaries share a channel?

Resources can be shared in certain cases, but each covered entity keeps its own responsibility: the files, deadlines and evidence of ITS channel must be individually identifiable and defensible.

DS
Reviewed by David Soler, founder of DSA Nexus · Updated: julio de 2026
For information only — this is not legal advice. Check dates and thresholds with your adviser.
How it is implemented

This obligation is organised with an international management system standard. If your group is already certified, you have half the road done — and the same holds in the other countries where you operate.

ISO 37301 · Compliance management systems
Other guides:AI ActPPWR (Envases · UE 2025/40)Lei 12.846/2013 (Brazil Anti-Corruption Act)Ley 2195 de 2022 (PTEE Colombia)Ley 30424 (Responsabilidad de la empresa · Perú)Ley 20.393 / 21.595 (Delitos económicos Chile)Ley 21.719 (Chile's data protection law)EUDR (Deforestation)Ley Karin (21.643, Chile)