Whistleblowing in France: Employer Compliance Guide

Whistleblowing France guide covering Sapin II, CNIL, GDPR, reporting channels, whistleblower protection, investigations, and employer compliance.

Whistleblowing in France employer compliance guide covering confidential reporting, legal duties, and whistleblower protection.

Whistleblowing in France is now a significant employer compliance issue involving employment law, corporate governance, anti-corruption controls, investigations, and data protection. Organizations that treat a reporting channel as nothing more than an ethics mailbox risk missing strict procedural, confidentiality, anti-retaliation, and GDPR requirements.

Whistleblowing in France is the protected reporting or disclosure, by a natural person acting in good faith and without direct financial consideration, of qualifying unlawful conduct, violations, threats, or harm to the public interest.

The French framework combines Sapin II, the Waserman reforms, the EU Whistleblower Protection Directive, implementing rules, CNIL requirements, and specific anti-corruption obligations. Employers must know who can report, how reports should be received, when feedback must be provided, how investigations should be conducted, and how whistleblowers and other affected individuals must be protected.

Employers reviewing their current reporting arrangements should act before a serious case exposes weaknesses in the system. The French Compliance Institute's Whistleblowing & Ethics Reporting Systems training provides structured guidance on reporting channels, confidentiality, investigations, and ethical reporting governance.

What Is Whistleblowing in France?

French whistleblower protection is broader than reporting corruption or financial fraud. A qualifying alert may concern a crime, an offense, a threat or harm to the public interest, or a violation or attempted concealment of a violation of applicable law, including certain French, European Union, and international rules.

The reporter must be a natural person, act in good faith, and receive no direct financial consideration for making the report. When information is obtained outside a professional context, the whistleblower must generally have personal knowledge of it. When the information arises through professional activities, the framework is broader and does not apply the same personal-knowledge condition.

Whistleblowing can therefore arise from many areas of an employer's operations. Reports might concern suspected bribery, corruption, fraud, accounting manipulation, procurement misconduct, harassment, discrimination, health and safety violations, environmental wrongdoing, data-protection failures, regulatory breaches, conflicts of interest, or attempts to conceal unlawful conduct.

The categories of people who may use an organization's internal procedure can also extend beyond current employees. Depending on the circumstances, former employees, applicants, shareholders, members of corporate bodies, external collaborators, contractors, subcontractors, and people working under their supervision may be able to submit reports concerning information obtained through their professional relationship with the organization.

This broader scope has practical implications. A reporting process placed exclusively on an employee-only intranet may not be sufficiently accessible to every person entitled to use it. Organizations should determine who needs access and make their reporting procedure permanently available through appropriate channels.

Employers should also distinguish statutory whistleblowing from ordinary workplace complaints. A grievance about scheduling or a disagreement with a manager does not automatically qualify as protected whistleblowing. However, the same reporting platform can potentially receive multiple categories of concern if the organization has clear triage rules for determining which legal and internal procedures apply.

Whistleblowing Laws and Regulations in France

France's whistleblower framework is built from several connected legal instruments rather than one standalone "whistleblower law."

Sapin II Law

The central French statute is Law No. 2016-1691 of 9 December 2016, commonly known as Sapin II. It established a general whistleblower protection framework and introduced major corporate anti-corruption obligations.

For employers, Sapin II is important in two separate but related ways. First, its whistleblower provisions regulate who can qualify for protection and how internal, external, and public reporting operate. Second, Article 17 imposes anti-corruption compliance requirements on certain large companies, including an internal alert mechanism for reporting conduct contrary to the organization's anti-corruption code of conduct.

Waserman Law

France strengthened the system through the Law of 21 March 2022 aimed at improving whistleblower protection, often referred to as the Waserman Law.

The reforms broadened protections and significantly changed reporting routes. One particularly important change for employers is that a whistleblower no longer generally needs to report internally before making a protected external report. A person can approach an appropriate external authority directly.

The reforms also strengthened protection for facilitators and other people connected with whistleblowers who may themselves face retaliation.

EU Whistleblower Protection Directive

France's reforms also implement the requirements of the EU Whistleblower Protection Directive, Directive (EU) 2019/1937. The Directive establishes minimum standards across the EU for internal and external reporting channels, confidentiality, follow-up, feedback, record keeping, and protection from retaliation.

For multinational groups, this European dimension matters because a France-based system may form part of a wider EU whistleblowing program while still needing to comply with French implementation rules.

Decree No. 2022-1284

Operational requirements are further detailed in Decree No. 2022-1284 of 3 October 2022. The decree addresses internal reporting procedures, oral and written reporting, acknowledgment deadlines, confidentiality, processing responsibilities, feedback, external authorities, and the handling of anonymous reports.

Together, these instruments mean employers should view whistleblowing as a formal compliance process rather than an informal HR practice.

Which Employers Must Have a Whistleblowing System?

Private companies employing at least 50 employees are generally required to establish an internal procedure for collecting and processing qualifying whistleblowing reports. Before establishing the procedure, the employer must consult the CSE where applicable and communicate the procedure to employees through appropriate means. The official French government guidance on whistleblowers in companies confirms these threshold and procedural requirements.

The obligation should not be interpreted as merely creating a contact address. The procedure must explain how reports can be submitted, who receives and handles them, how confidentiality is protected, what follow-up occurs, and how individuals can access information about external reporting routes.

Companies with fewer than 50 employees are not necessarily outside the whistleblowing framework. Where no formal internal reporting procedure exists, a qualifying internal report can be made to a direct or indirect supervisor, the employer, or a designated contact. Those employers still need to recognize protected reports and avoid retaliation.

Certain entities may also be subject to sector-specific reporting rules under EU or French legislation regardless of how the general threshold applies.

Another distinction concerns the anti-corruption obligations of Sapin II Article 17. The general corporate threshold covers companies or qualifying corporate groups with at least 500 employees and turnover or consolidated turnover exceeding €100 million. Covered organizations must implement a broader anti-corruption compliance program, including an internal reporting mechanism related to conduct contrary to the anti-corruption code of conduct.

Key Employer Requirements

Compliance Area

Main Requirement

Formal internal reporting procedure

Generally required from 50 employees

CSE consultation

Required where applicable before establishing the procedure

Acknowledgment

Within 7 working days

Feedback

Normally within a maximum of 3 months

Shared system

Qualifying companies with fewer than 250 employees may pool reporting resources

Accessibility

Procedure should be permanently accessible to eligible reporters

Article 17 anti-corruption program

Applies to qualifying companies meeting the statutory employee and turnover criteria

External reporting

Can be used directly without first exhausting the internal procedure

The 50-employee threshold is therefore an important compliance trigger, but it should not become the organization's only decision point. Smaller businesses can still receive protected reports, while large companies may face additional anti-corruption requirements.

How a Compliant Whistleblowing Procedure Should Work

A compliant whistleblowing procedure needs defined governance before the first report arrives. The employer should establish who is responsible for receiving reports, assessing their scope, requesting additional information, conducting investigations, approving corrective actions, communicating with reporters, and closing cases.

Internal Reporting Channels

The internal channel should provide a secure means for eligible people to communicate concerns and supporting evidence. The French implementing rules permit written or oral reporting according to the procedure adopted by the organization. Where oral reporting is available, it may include telephone or voice messaging and, upon request, a video conference or physical meeting. The relevant meeting must be organized within the applicable statutory timeframe.

The organization may operate the system internally or use an external service provider. Outsourcing the technical or administrative channel does not remove the employer's responsibility to ensure confidentiality and compliant processing.

Acknowledgment and Feedback Deadlines

For the statutory internal procedure, the reporter must be informed in writing that the report has been received within seven working days.

The employer must then provide written information about measures envisaged or taken to assess the allegations and, where appropriate, remedy the reported issue. This feedback must be given within a reasonable period that cannot normally exceed three months from acknowledgment. If no acknowledgment was provided, the three-month period is calculated from the end of the seven-working-day acknowledgment period.

Feedback does not mean disclosing confidential witness information, privileged legal advice, disciplinary details, or every investigative document. It means keeping the reporter appropriately informed about the handling of the concern.

Internal vs External Reporting

France does not require a whistleblower to exhaust the internal process before going externally. A qualifying reporter may contact an appropriate external authority directly, after an internal report, or use other channels recognized by the law.

Employers should therefore avoid policies stating that employees "must" report internally before contacting regulators. Instead, organizations should make the internal system credible enough that people feel comfortable using it.

Public Disclosure

Public disclosure can attract statutory protection in specified circumstances. These may include situations where appropriate action has not followed an external report within the relevant timeframe, where there is serious and imminent danger, or where external reporting may expose the person to retaliation or be ineffective because evidence could be concealed or destroyed.

A reliable internal system can reduce escalation risk by demonstrating that credible concerns are taken seriously and investigated promptly.

CNIL and GDPR Requirements for Whistleblowing Systems

A whistleblowing case can contain extensive personal information about the reporter, accused person, witnesses, managers, suppliers, customers, investigators, and other third parties. Employers must therefore integrate GDPR compliance into the design and operation of their reporting system.

The CNIL Professional Alerts Reference Framework was updated in 2023 to reflect the Waserman reforms and the 2022 implementing decree. It covers data-protection issues associated with professional whistleblowing systems, including purposes, legal bases, outsourcing, retention, security, and information requirements.

Legal Basis and Purpose

The organization should document why personal data is being processed and identify the appropriate GDPR legal basis. Where processing is necessary to operate a reporting procedure required by law, compliance with a legal obligation may be relevant. Voluntary ethics reporting systems extending beyond statutory requirements may require a different analysis, including legitimate interests where applicable.

Organizations using one channel for several purposes should not assume that every purpose automatically relies on the same legal basis.

Data Minimization

Whistleblowing systems should encourage reporters to provide factual information that is necessary and relevant to the allegation. Reports can otherwise contain excessive personal details, opinions, rumors, or sensitive information that is not needed to investigate the concern.

The investigation team should apply the same principle when collecting additional evidence. The existence of an allegation does not justify unrestricted access to an employee's entire personal or professional history.

Access and Confidentiality

Access should be limited to people who need the information to receive, assess, investigate, or resolve the report. Sensitive cases involving executives, HR leaders, compliance personnel, or board members may require alternative escalation arrangements.

Technical controls should support these restrictions. Shared mailboxes accessible to broad teams, uncontrolled spreadsheets, ordinary chat applications, and open network folders can undermine confidentiality.

Retention

Identifiable information should not be stored indefinitely simply because it originated in a whistleblowing system. Retention periods should reflect the status of the case, legal requirements, possible proceedings, protection of affected persons, and any legitimate need for archiving.

Where information is irreversibly anonymized, longer-term statistical use may be possible because it no longer identifies individuals.

Third-Party Providers and Transfers

Employers using hotline vendors, investigation providers, cloud platforms, or group-level systems need to identify data-processing roles and ensure appropriate contractual safeguards. International transfers must also be reviewed where information is accessed or hosted outside the European Economic Area.

The DPO should be involved where appropriate, and the reporting process should be reflected in the organization's data-processing documentation. Depending on the circumstances and level of risk, a data-protection impact assessment may also need to be considered.

Whistleblower Protection, Confidentiality, and Retaliation

A reporting channel cannot function effectively if workers believe using it will damage their careers.

French law protects qualifying whistleblowers against a broad range of retaliatory measures. These can include dismissal, suspension, demotion, refusal of promotion, transfer, salary reduction, disciplinary action, coercion, intimidation, discrimination, reputational harm, and other adverse treatment connected with a protected report or disclosure.

Protection can also extend beyond the individual reporter. Facilitators and certain natural or legal persons connected to a whistleblower may receive protection where they risk retaliatory measures because of that relationship.

Employers therefore need to think beyond obvious retaliation such as termination. A sudden negative appraisal, exclusion from meetings, removal of responsibilities, stalled promotion, disadvantageous transfer, or non-renewal following a report may create serious compliance concerns.

Confidentiality

The reporting process must protect the integrity and confidentiality of information collected, particularly the identity of the reporter, people targeted by the allegations, and third parties mentioned in the report. Access must be restricted to authorized personnel.

Confidentiality should not be confused with anonymity. A person may identify themselves to the reporting team while remaining confidential from managers or colleagues who do not need that information. An anonymous report does not reveal the reporter's identity to the organization.

Employers should establish how anonymous cases will be processed and whether their technical system allows investigators to communicate securely with anonymous reporters.

The practical need for protection remains significant. In its 2024-2025 report on whistleblower protection, published in May 2026, the Défenseur des droits reported continued problems with retaliation and noted that external authorities received more than 10,000 reports in 2025, compared with 2,000 in 2023. It also observed that internal reporting mechanisms remain insufficiently known and underused in many organizations.

This makes awareness, managerial conduct, and trust as important as the technical reporting platform.

Whistleblowing, Anti-Corruption, and Internal Investigations

Whistleblowing plays a particularly important role in French anti-corruption compliance. An internal report may be the first indication that bribery, influence peddling, procurement manipulation, accounting misconduct, gifts and hospitality abuses, or third-party corruption risks exist within an organization.

For organizations subject to Article 17 of Sapin II, internal alerts form part of a broader anti-corruption system alongside the code of conduct, corruption risk mapping, third-party assessment procedures, accounting controls, training, disciplinary measures, and internal evaluation.

In July 2026, the French Anti-Corruption Agency published a new practical guide dedicated to internal reporting systems. The AFA guidance on implementing internal alert mechanisms and building an ethical reporting culture focuses on practical implementation and day-to-day processing of reports.

Investigation Governance

A report should be investigated by people with appropriate competence, authority, independence, and resources. The French implementing rules specifically require safeguards supporting impartial handling of reports.

Conflict-of-interest procedures are essential. If a report concerns the compliance director, HR director, CEO, CFO, or another person who would normally supervise the investigation, the case should be redirected through an alternative escalation route.

For serious matters, involvement from legal, compliance, internal audit, HR, the DPO, executive management, or the board may be appropriate depending on the allegation. External investigators or counsel may also be necessary in particularly sensitive cases.

Evidence and Documentation

Evidence may include contracts, invoices, accounting records, emails, access records, HR information, policies, meeting records, communications, third-party documentation, or witness interviews.

Collection should remain proportionate. Investigators should preserve potentially relevant evidence while respecting employment, privacy, confidentiality, and legal requirements.

The organization should maintain a defensible record showing how the allegation was assessed, what investigative steps were taken, what findings were reached, what corrective action was approved, and how the reporter was informed.

Corrective action may extend beyond disciplining an individual. A credible investigation might reveal weaknesses in approval limits, third-party due diligence, procurement controls, management oversight, training, policy design, or reporting processes that require systemic remediation.

How Should Employers Handle a Whistleblowing Report?

Once an alert arrives, the employer needs a structured process that protects evidence, people, and procedural integrity. The following sequence can be adapted according to the seriousness and complexity of the case.

Step 1: Receive and Secure the Report

The report should immediately enter a controlled case-management process. Access should be limited to authorized personnel, and supporting documents should be preserved securely.

If a manager receives a whistleblowing report outside the official channel, the manager should know how to transmit it promptly to the authorized function without unnecessarily circulating the information.

Step 2: Acknowledge Receipt

Where the statutory internal procedure applies, acknowledgment should be provided within seven working days. The organization should use case-management controls so this deadline is not dependent on an individual employee remembering it.

Step 3: Assess Whether the Report Falls Within Scope

The receiving team should assess whether the report appears to meet the relevant whistleblower criteria and whether it concerns the organization.

A case falling outside the statutory whistleblower scope should not simply disappear. The policy should specify whether it will be redirected to HR, grievance management, security, data protection, ethics, or another appropriate process.

Step 4: Conduct an Initial Risk Assessment

Before beginning a full investigation, the organization should assess urgency and exposure.

A report involving ongoing bribery payments, imminent environmental damage, risk to personal safety, destruction of evidence, retaliation, or significant regulatory exposure may require immediate protective action.

The assessment should also determine whether evidence needs to be preserved before potentially implicated individuals learn of the investigation.

Step 5: Appoint an Independent Investigator

The investigator should have the expertise and independence necessary for the allegations.

An HR team may be appropriate for certain employment matters, while suspected corruption may require compliance, legal, forensic accounting, internal audit, or external support.

Potential conflicts must be identified before access to sensitive allegations is granted.

Step 6: Gather and Preserve Evidence

The investigation plan should identify relevant systems, documents, people, and time periods.

Evidence should be collected in a controlled and proportionate manner. Investigators should consider privacy, confidentiality, employment rules, legal privilege where applicable, and the integrity of the evidence.

Step 7: Interview Relevant Individuals

Interviews can help establish chronology, corroborate documents, explain inconsistencies, and identify further evidence.

Investigators should avoid assuming the allegation is either true or false before the evidence has been assessed. The whistleblower deserves protection, while the person accused is also entitled to fair treatment.

Step 8: Reach and Document Findings

Findings should be based on the available evidence and the applicable standard used by the organization.

The final record should distinguish facts, supporting evidence, unresolved issues, and conclusions. Sensitive investigative records should not be distributed more widely than necessary.

Step 9: Implement Corrective Action

Where concerns are substantiated, action should address both individual conduct and underlying control weaknesses.

Possible responses can include disciplinary processes, control enhancements, policy updates, additional training, third-party remediation, management changes, financial recovery, or escalation to competent authorities where required or appropriate.

Step 10: Provide Feedback and Close the Case

The reporter should receive the feedback required within the applicable timeframe. The communication should explain that the report was assessed and indicate appropriate measures envisaged or taken without compromising confidentiality or the rights of other people.

The case should then be formally closed or moved into a monitored remediation phase. Closure records should show the decision, follow-up action, communication, and applicable retention arrangements.

Whistleblowing Compliance Checklist for French Employers

Employers can use the following checklist when reviewing the design and operation of a whistleblowing program.

Compliance Check

Employer Action

Threshold assessment

Confirm whether the organization is required to maintain a formal internal procedure

CSE consultation

Verify consultation occurred where legally required

Written procedure

Maintain an accessible and current whistleblowing policy

Eligible reporters

Ensure the system can be accessed by relevant employees and external populations

Written reporting

Provide a secure method for submitting written reports

Oral reporting

Define available oral reporting procedures where provided

Acknowledgment

Track the 7-working-day deadline

Feedback

Track the maximum applicable 3-month internal feedback period

External routes

Provide clear information about external reporting options

Confidentiality

Restrict case information to authorized personnel

Anonymous reports

Define how anonymous reports will be received and processed

Investigator independence

Establish conflict-of-interest and alternative escalation arrangements

Anti-retaliation

Monitor adverse employment decisions affecting protected individuals

GDPR

Document purposes, legal bases, access, retention, security, and transparency

Third parties

Review hotline vendors, investigators, processors, and data transfers

Evidence

Maintain controlled preservation and investigation procedures

Remediation

Track corrective actions until completion

Training

Train employees, managers, HR, compliance, and report handlers appropriately

Governance

Periodically review reporting trends, response times, and program effectiveness

A checklist should not become a substitute for testing. Employers should periodically simulate the lifecycle of a report to determine whether the organization can actually acknowledge, investigate, escalate, protect, remediate, and close a case in accordance with its documented process.

Conclusion

Whistleblowing in France requires employers to combine legal compliance with credible governance. Sapin II, the Waserman reforms, EU rules, CNIL expectations, anti-corruption requirements, confidentiality, and anti-retaliation safeguards all influence how a reporting system should operate.

A compliant organization needs more than a hotline. It needs accessible reporting routes, trained decision-makers, independent investigations, controlled personal-data processing, clear deadlines, evidence preservation, remediation, and protection for people who raise concerns in good faith.

Employers should therefore review the complete reporting lifecycle rather than assessing the platform alone. French Compliance Institute training can help compliance, HR, DPO, risk, and governance teams strengthen the knowledge required to operate ethical reporting systems consistently and responsibly.

Frequently Asked Questions

For private companies with at least 50 employees, an internal procedure for receiving and processing qualifying whistleblowing reports is generally mandatory. Employers below the threshold can still receive protected reports and must handle them appropriately.

No. A qualifying whistleblower can make an external report directly to an appropriate authority without first using the employer's internal reporting procedure. Internal reporting can still be encouraged when it can address the concern effectively and safely.

Where the statutory internal procedure applies, the reporter should be informed in writing of receipt within seven working days.

French rules do not simply impose one universal deadline for completing every internal investigation. However, the employer must provide appropriate written feedback within a reasonable period that normally cannot exceed three months from acknowledgment, or from the end of the seven-working-day period if no acknowledgment was issued.

Yes, internal procedures can provide for the handling of anonymous reports. Organizations should establish how those reports are assessed and, where possible, provide a secure method for communicating with the anonymous reporter without requiring identification.