Back to Frameworks

EU Whistleblower Protection Directive (2019/1937)

European Union
v2019/1937
4 domains
16 controls

Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law (Whistleblower Protection Directive). Establishes minimum standards for protecting whistleblowers reporting breaches of EU law in areas including public procurement, financial services, product safety, environmental protection, food safety, public health, consumer protection, data protection, and more.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Chapter II — Internal Reporting

5 controls

Requirements for internal reporting channels within organisations

Controls in the Chapter II — Internal Reporting domain of EU Whistleblower Protection Directive (2019/1937)5 controls
CodeTitle
WPD-INT-01Internal Reporting Channel Obligation
WPD-INT-02Channel Design Requirements
WPD-INT-03Acknowledgement and Follow-up
WPD-INT-04Confidentiality of Identity
WPD-INT-05Record-Keeping

Chapter III — External Reporting

3 controls

Requirements for external reporting channels operated by competent authorities

Controls in the Chapter III — External Reporting domain of EU Whistleblower Protection Directive (2019/1937)3 controls
CodeTitle
WPD-EXT-01External Reporting Channel Establishment
WPD-EXT-02External Channel Procedures
WPD-EXT-03Information Published by Authorities

Chapter IV — Public Disclosure

2 controls

Conditions under which public disclosure is protected

Controls in the Chapter IV — Public Disclosure domain of EU Whistleblower Protection Directive (2019/1937)2 controls
CodeTitle
WPD-PUB-01Conditions for Protected Public Disclosure
WPD-PUB-02Media Protection

Chapter V-VI — Protection Measures and Penalties

6 controls

Whistleblower protection measures and penalty provisions

Controls in the Chapter V-VI — Protection Measures and Penalties domain of EU Whistleblower Protection Directive (2019/1937)6 controls
CodeTitle
WPD-PEN-01Penalties for Retaliation
WPD-PEN-02Penalties for Malicious Reporting
WPD-PROT-01Prohibition of Retaliation
WPD-PROT-02Support Measures
WPD-PROT-03Protection Against Retaliation
WPD-PROT-04Reversal of Burden of Proof

Maps to 76 other frameworks

16 total controls
SEC Cybersecurity Disclosure Rules
2 source controls mapped|1 target controls covered
13%
EU Digital Services Act
2 source controls mapped|2 target controls covered
13%
Singapore Payment Services Act (PSA) — Digital Payment Token Regulation
2 source controls mapped|1 target controls covered
13%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
2 source controls mapped|2 target controls covered
13%
UK Online Safety Act 2023
2 source controls mapped|3 target controls covered
13%
NIST SP 1800-32
2 source controls mapped|1 target controls covered
13%
IAIS Insurance Core Principles (ICPs)
2 source controls mapped|1 target controls covered
13%
BIMCO Cyber Security
2 source controls mapped|1 target controls covered
13%
Voluntary Principles on Security and Human Rights (VPs)
2 source controls mapped|1 target controls covered
13%
EU Better Internet for Kids (BIK+) Strategy
2 source controls mapped|1 target controls covered
13%
Notifiable Data Breaches Scheme (Australia)
2 source controls mapped|2 target controls covered
13%
EU Digital Markets Act
2 source controls mapped|2 target controls covered
13%
FTC Health Breach Notification Rule
2 source controls mapped|2 target controls covered
13%
UK Product Security and Telecommunications Infrastructure Act (PSTI)
2 source controls mapped|2 target controls covered
13%
EAR — Export Administration Regulations
2 source controls mapped|3 target controls covered
13%
European Accessibility Act (Directive (EU) 2019/882)
2 source controls mapped|2 target controls covered
13%
EU Deforestation-Free Products Regulation (EUDR)
2 source controls mapped|2 target controls covered
13%
US ITAR and EAR — Export Control and Data Security
2 source controls mapped|2 target controls covered
13%
US SEC Digital Assets and Crypto Regulatory Framework
2 source controls mapped|2 target controls covered
13%
Australia Consumer Data Right — Banking (CDR)
2 source controls mapped|2 target controls covered
13%
Australia eSafety Commissioner — Online Safety Expectations for Industry
2 source controls mapped|3 target controls covered
13%
NIS2 Directive
2 source controls mapped|1 target controls covered
13%
IEC 62443
2 source controls mapped|1 target controls covered
13%
NERC CIP
2 source controls mapped|1 target controls covered
13%
DO-326A
2 source controls mapped|1 target controls covered
13%
Tonga Communications Act (2015) — Privacy & Data Protection
2 source controls mapped|1 target controls covered
13%
IEEE 1686
2 source controls mapped|1 target controls covered
13%
NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
2 source controls mapped|1 target controls covered
13%
Barbados Data Protection Act 2019
2 source controls mapped|1 target controls covered
13%
Online Safety Act 2021 (Australia)
2 source controls mapped|1 target controls covered
13%
German Supply Chain Due Diligence Act (LkSG)
2 source controls mapped|2 target controls covered
13%
MiFID II / MiFIR
2 source controls mapped|1 target controls covered
13%
TSA Pipeline Security
2 source controls mapped|1 target controls covered
13%
API 1164
2 source controls mapped|1 target controls covered
13%
Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
2 source controls mapped|1 target controls covered
13%
Australia My Health Records Act 2012
2 source controls mapped|1 target controls covered
13%
ISO 27019
2 source controls mapped|1 target controls covered
13%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
2 source controls mapped|1 target controls covered
13%
Modern Slavery Act 2018 (Australia)
2 source controls mapped|1 target controls covered
13%
AML/CTF Act 2006 (Australia)
2 source controls mapped|1 target controls covered
13%
ICH E6(R3) — Good Clinical Practice
2 source controls mapped|1 target controls covered
13%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|1 target controls covered
13%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|1 target controls covered
13%
Lloyd's Minimum Standards — Cyber Security
2 source controls mapped|1 target controls covered
13%
FTC Safeguards Rule (16 CFR Part 314)
2 source controls mapped|1 target controls covered
13%
EU Audiovisual Media Services Directive (AVMSD, Directive 2018/1808)
2 source controls mapped|1 target controls covered
13%
EU Carbon Border Adjustment Mechanism (CBAM)
2 source controls mapped|1 target controls covered
13%
EU Machinery Regulation (Regulation (EU) 2023/1230)
2 source controls mapped|1 target controls covered
13%
EU General Product Safety Regulation (GPSR, Regulation 2023/988)
2 source controls mapped|1 target controls covered
13%
EU Network Code on Cybersecurity for the Electricity Sector
2 source controls mapped|1 target controls covered
13%
African Union Malabo Convention
2 source controls mapped|1 target controls covered
13%
Myanmar Cybersecurity Law (2023)
2 source controls mapped|1 target controls covered
13%
Morocco Data Protection Law (09-08)
2 source controls mapped|1 target controls covered
13%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
2 source controls mapped|1 target controls covered
13%
Chile Personal Data Protection Law (Law No. 21.719)
2 source controls mapped|1 target controls covered
13%
Peru Personal Data Protection Law (Law No. 29733)
2 source controls mapped|1 target controls covered
13%
Turkey Personal Data Protection Law (KVKK — Law No. 6698)
2 source controls mapped|1 target controls covered
13%
Ukraine Law on Personal Data Protection (Law No. 2297-VI)
2 source controls mapped|1 target controls covered
13%
Uzbekistan Law on Personal Data (No. ZRU-547)
2 source controls mapped|1 target controls covered
13%
Montenegro Law on Personal Data Protection (2023)
2 source controls mapped|1 target controls covered
13%
North Macedonia Law on Personal Data Protection (2020)
2 source controls mapped|1 target controls covered
13%
13%
Serbia Law on Personal Data Protection (2018)
2 source controls mapped|1 target controls covered
13%
Lithuania Law on Legal Protection of Personal Data (2018)
2 source controls mapped|1 target controls covered
13%
Malta Data Protection Act (Cap. 586, 2018)
2 source controls mapped|1 target controls covered
13%
Netherlands GDPR Implementation Act (UAVG — Uitvoeringswet AVG, 2018)
2 source controls mapped|1 target controls covered
13%
Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
2 source controls mapped|1 target controls covered
13%
South Korea Personal Information Protection Act (PIPA)
2 source controls mapped|1 target controls covered
13%
SASB Standards (ISSB Integrated)
2 source controls mapped|1 target controls covered
13%
SASB Standards
2 source controls mapped|1 target controls covered
13%
Kids Online Safety Act (KOSA)
2 source controls mapped|1 target controls covered
13%
C2M2
2 source controls mapped|1 target controls covered
13%
UK Modern Slavery Act 2015
2 source controls mapped|1 target controls covered
13%

Frequently Asked Questions

What is EU Whistleblower Protection Directive (2019/1937)?

EU Whistleblower Protection Directive (2019/1937) is a compliance framework from European Union with 4 domains and 16 controls. Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law (Whistleblower Protection Directive). Establishes minimum standards for protecting whistleblowers reporting breaches of EU law in areas including public procurement, financial services, product safety, environmental protection, food safety, public health, consumer protection, data protection, and more. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does EU Whistleblower Protection Directive (2019/1937) have?

EU Whistleblower Protection Directive (2019/1937) has 16 controls organised across 4 domains. The largest domains are Chapter V-VI — Protection Measures and Penalties (6 controls), Chapter II — Internal Reporting (5 controls), Chapter III — External Reporting (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does EU Whistleblower Protection Directive (2019/1937) map to?

EU Whistleblower Protection Directive (2019/1937) maps to 76 other compliance frameworks. The top mapping partners are SEC Cybersecurity Disclosure Rules (13% coverage), EU Digital Services Act (13% coverage), Singapore Payment Services Act (PSA) — Digital Payment Token Regulation (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with EU Whistleblower Protection Directive (2019/1937) compliance?

Start your EU Whistleblower Protection Directive (2019/1937) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Whistleblower Protection Directive (2019/1937) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 16 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.

Get Started Free →

Free forever — no credit card required