01

Which businesses are required to implement the procedure?

The general rule applies when at least 50 people perform paid work for the relevant legal entity. Employees are counted as full-time equivalents. The calculation also includes people providing paid work on another legal basis if they do not employ other people to carry out that type of work.

As a result, a Polish business using employees, mandate contracts and individual B2B contractors may cross the threshold even if it has fewer than 50 employees. The calculation is made as at 1 January and 1 July. The company should assign responsibility for the calculation and retain a clear record of how each category was treated.

The threshold does not apply to certain entities operating in regulated fields identified by the Polish Act and the EU instruments to which it refers. These include parts of the financial services, anti-money laundering, transport safety and environmental sectors. Their position must be assessed by reference to the activity carried out, not merely the company's registered business codes.

An entity below the threshold may introduce a procedure voluntarily. This may be sensible for a corporate group, before an investment, to meet a customer requirement or to provide one controlled route for serious compliance concerns.

02

What types of report should the procedure cover?

The Act covers specified areas of law, including corruption, public procurement, AML, product safety, environmental protection, consumer protection, privacy and personal data, information-system security and the financial interests of Poland and the European Union.

The procedure may also cover breaches of internal rules or ethical standards that have a legal basis and comply with generally applicable law. The company should nevertheless distinguish statutory whistleblowing from ordinary employee grievances, complaints, interpersonal conflicts and anti-harassment reports handled under other procedures.

A report outside the statutory scope should not simply be discarded. It may need to be redirected, but the reporting person should not automatically be told that every internal complaint attracts statutory whistleblower status.

03

What must the internal procedure regulate?

The procedure must identify the internal team, individual or external provider authorised to receive reports. It must also designate an impartial team or person responsible for verification, communication and follow-up. The same function may perform both roles if impartiality can be maintained.

The document must address reporting methods, anonymous reports, acknowledgement, follow-up, feedback, external reporting information and data protection. A robust procedure should also deal with conflicts of interest, substitute case handlers, initial classification, preservation of evidence and management reporting that does not disclose unnecessary identities.

The design must match the organisation. A template naming a non-existent compliance department or a mailbox accessible to the whole HR team may fail to create a workable system and may breach confidentiality requirements.

04

Which reporting channels should be available?

Reports may be written or oral. A written channel may be paper-based or electronic. Oral reports may be submitted by telephone or another voice communication system and, at the whistleblower's request, during an in-person meeting arranged within the statutory period.

The company may choose to process anonymous reports, but this is not mandatory. It should not create a system that accepts anonymous messages only and refuses a report from a person who provides their identity. If anonymity is offered, the company should verify whether the technology protects metadata and still permits secure follow-up communication.

The route should be available beyond the current employee population. Statutory protection may extend to contractors, applicants, former workers, shareholders, board members, commercial proxies, trainees and people working under the supervision of a supplier or subcontractor.

05

How is the procedure consulted and brought into effect?

The draft is consulted with the workplace trade union or, if none operates, with representatives of the people performing work selected under the organisation's usual process. Consultation lasts no less than 5 and no more than 10 days from presentation of the draft.

The final procedure takes effect 7 days after it is communicated in the manner normally used by the business. Information about the procedure must also be provided to candidates when recruitment or pre-contract negotiations begin.

Implementation requires more than publication. Case handlers need written authorisations, operating instructions, secure access and preparation for fact-finding. The work should be coordinated with a broader GDPR audit, because the reporting register and case files contain particularly sensitive workplace and allegation data.

06

What happens after a report is received?

If the whistleblower provides a contact address, receipt should be acknowledged within 7 days. An impartial case handler then assesses scope, conflicts, evidence and proportionate follow-up measures.

Feedback must be provided within no more than 3 months, calculated under the statutory rules. It need not reveal protected information or the full investigation file, but it should genuinely explain the actions planned or taken and the reasons for them.

Each report is entered in a separate statutory register containing only the required fields. The register information is retained for 3 years after the end of the calendar year in which follow-up or proceedings triggered by that follow-up were completed.

07

Confidentiality, personal data and retaliation

Only people holding written authorisations may access and process report information. Protection extends beyond the whistleblower's name to information that could identify them indirectly. Confidentiality also protects the person concerned by the allegation and third parties mentioned in the report.

Irrelevant personal data should not be collected and inadvertently collected data must be deleted within the statutory period. The business needs privacy notices, retention rules, procedures for data-subject rights and safeguards for files and messages. An unauthorised disclosure may also require an assessment under the process described in the article on the first 72 hours after a personal data breach.

Protection begins when a report is made, provided the reporting person had reasonable grounds to believe that the information was true and concerned a breach of law. The company should not wait for the investigation to end before addressing retaliation risks. Retaliation, attempted retaliation and threats are prohibited and may also affect helpers and people connected with the whistleblower.

PRACTICE

How the issue appears in practice

Example

Hypothetical example: a mixed workforce crosses the threshold

A Polish company has 44 employees measured as full-time equivalents and works continuously with 12 individual contractors who personally provide services and do not employ others for that work. Management assumes that no procedure is required because the employee list remains below 50. The 1 July review shows that the qualifying contractors must also be included. The company has no draft, workforce representatives, secure channel or trained case handler. The correct response is not to copy a generic policy. It should document the calculation, consult the draft, appoint impartial handlers, issue authorisations, implement the channels and register, and train those responsible for follow-up.

Working checklist

Matters to determine or verify before proceeding

  • How many people perform paid work for the entity on 1 January and 1 July after applying the statutory rules to employees and contractors?
  • Does the business operate in a regulated sector to which the 50-person threshold does not apply?
  • Which reports fall within statutory whistleblowing and which should follow another route?
  • Who receives reports, who conducts follow-up and how are conflicts of interest managed?
  • Do the written and oral channels protect content, identity and metadata?
  • Will anonymous reports be processed and how will secure communication be maintained?
  • How will acknowledgement, feedback, the register, retention, authorisations and applicant information be managed?
  • How will the organisation identify and document retaliation risks?

Key issues at a glance

IssueKey information
ThresholdAt least 50 people performing paid work as at 1 January or 1 July; the test is wider than employee headcount.
Sector exceptionsCertain regulated businesses are covered irrespective of the number of people.
ConsultationBetween 5 and 10 days with the union or workforce representatives.
Effective dateSeven days after the procedure is communicated.
AcknowledgementGenerally within 7 days if a contact address is provided.
FeedbackNo later than 3 months under the statutory calculation.
Register and retentionA separate register; retention for 3 years after the end of the relevant calendar year.
OutsourcingExternal receipt is possible, but the entity remains responsible.
LEGAL BASIS

Legal basis

  • Polish Act of 14 June 2024 on the Protection of Whistleblowers, in particular Articles 3–8, 11–22 and 23–29.
  • Regulation (EU) 2016/679 (GDPR).
  • Directive (EU) 2019/1937 of 23 October 2019 on the protection of persons who report breaches of Union law.
Explore this areaBusiness in Poland

This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.

Summary

An effective whistleblowing procedure is an operating process, not a policy alone. The organisation must determine whether it is covered, consult the document, provide confidential channels, issue authorisations and ensure timely, impartial follow-up. The system should protect the whistleblower while also respecting the rights and data of the person concerned and other participants. Button: Implement a whistleblowing procedure Link: /en/#contact ---