The entities subject to this regulation are:
(i) All entities forming part of the public sector.
(ii) Private-sector entities:
a. Those with 50 or more employees.
b. Those falling within the scope of European Union acts relating to services, products and financial markets, prevention of money laundering or terrorist financing, transport safety and environmental protection, regardless of the number of employees they have.
This also includes entities which, although not domiciled in Spain, carry out activities in Spain through branches or agents, or by providing services without a permanent establishment.
c. Political parties, trade unions, business organisations and foundations created by any of them, provided that they receive or manage public funds.
In addition, any private-sector legal entity may voluntarily establish its own whistleblowing channel.
Reports may be submitted in relation to acts that infringe either European Union law or national law, including serious or very serious criminal or administrative offences.
With regard to European Union law, reports may concern acts that:
(i) Fall within the scope of European Union acts, such as public procurement, financial products, consumer protection, privacy and data protection, among others;
(ii) Affect the financial interests of the European Union; or
(iii) Affect the internal market, including competition, corporate tax, fraud involving public aid, and similar matters.
The internal reporting system must be designed, established and managed securely, ensuring the confidentiality of the identity of the reporting person and of any third party mentioned in the report, as well as the confidentiality of the actions carried out in the management and processing of the report. It must also ensure data protection and prevent access by unauthorised personnel.
The internal reporting channel must also allow anonymous reports to be submitted and subsequently processed.
Fines for failure to comply with the obligations established in the Law range from €100,000 to €1,000,000 for legal entities and from €1,000 to €300,000 for natural persons, depending on the seriousness of the infringement.
At DATAX, we offer an Internal Reporting System designed to ensure transparency, prevention of irregularities and regulatory compliance, protecting both employees and the organisation.
Our platform, Report2Box, ensures compliance with both Law 2/2023 and the General Data Protection Regulation, as well as the Spanish Organic Law on Data Protection and Guarantee of Digital Rights. It is also certified under ISO 27001 for Information Security Management Systems.
In addition to the platform, we provide the Internal Reporting System Management Policy, carry out the mandatory notification of the Person Responsible for the System to the Independent Authority for Whistleblower Protection, and provide training to the System Manager and employees.





