Reconectando con el servidor
Mantén esta pestaña abierta: tu trabajo no se ha perdido.
No hemos podido reconectar
Recarga la página para continuar donde lo dejaste.
La sesión ha caducado
Vuelve a cargar la página para iniciar sesión de nuevo.
Ley 2/2023 of 20 February, on the protection of persons who report breaches (Spain) · Updated: julio de 2026
Ley 2/2023 requires every Spanish company with 50 or more employees (and the whole public sector) to run an internal reporting channel that guarantees confidentiality and anonymity, acknowledges receipt within 7 days and answers within 3 months at most. With Spain's whistleblower protection authority now operational, fines reach €1,000,000.
Companies with 50 or more employees, all political parties, unions and employers' associations, and the whole public sector (with nuances for small municipalities). Companies over 250 have been covered since June 2023; those with 50–249 since December 2023. A group may share resources, but each covered entity answers for its own compliance.
See also the Spain–Latin America compliance calendar.
All those with 50 or more employees, plus the public sector, political parties, unions and employers' associations. The duty has applied since June 2023 (250+) and December 2023 (50–249).
Very serious infringements carry fines of €600,001 to €1,000,000, plus a possible ban on grants and public contracting for up to four years.
The Autoridad Independiente de Protección del Informante (AIPI), the national body that supervises compliance with Ley 2/2023, handles external reports and exercises enforcement powers. It is operational and already reviewing internal channels.
No. The channel must guarantee confidentiality, allow anonymity, record the deadlines (7-day acknowledgement, 3-month answer) and protect the data under GDPR. An ethics@company.com mailbox can evidence none of that.
Resources can be shared in certain cases, but each covered entity keeps its own responsibility: the files, deadlines and evidence of ITS channel must be individually identifiable and defensible.
This obligation is organised with an international management system standard. If your group is already certified, you have half the road done — and the same holds in the other countries where you operate.