Poland
Poland's Whistleblower Protection Act: Complete Implementation Guide
How Polish employers must design internal reporting procedures, protect whistleblowers and maintain the mandatory register.
Act on the Protection of Whistleblowers — overview
Poland transposed Directive (EU) 2019/1937 through the Act on the Protection of Whistleblowers (in force since September 2024 for larger entities, with phased thresholds for smaller employers). The Act defines reporting procedures, confidentiality obligations and sanctions for obstruction or retaliation.
Scope of application
- Employers with 50 or more employees (phased thresholds apply for smaller entities)
- Public sector bodies
- Entities in financial services, AML, transport and other regulated areas
Internal reporting requirements
- Written and oral internal reporting channels
- Possibility of anonymous reporting where technically feasible
- Acknowledgement within 7 days of receipt
- Feedback within 3 months (up to 6 months for complex cases)
- Documentation in an internal register
- Designated person or organisational unit to handle reports
Data protection and GDPR
Whistleblowing systems process special categories of data in some cases. Polish employers must conduct a DPIA where required, limit data collection to what is necessary, define retention periods and ensure processors (including SaaS vendors) provide adequate guarantees under Article 28 GDPR.
Sanctions and enforcement
The Act provides for administrative fines for failure to establish channels, obstruction of reporting or retaliation against whistleblowers. Beyond fines, reputational damage and labour court claims pose significant additional risk.
Deploying QReportly in Poland
QReportly offers Polish UI, EU-only hosting, automatic register, deadline tracking and templates aligned with EU/Polish requirements. Implementation takes minutes without IT projects.