Luxembourg’s Whistleblower Law Builds a Network of Reporting Authorities
Luxembourg’s whistleblower law combines internal reporting duties with 23 competent external authorities and a central Office for Whistleblowers. The practical challenge is routing a report without losing confidentiality or momentum.
The Law of 16 May 2023 transposed the EU Whistleblower Directive and created a framework for reports concerning breaches of national law and directly applicable EU law in a professional context. It requires covered private and public entities to establish internal channels and designates authorities to receive external reports.
Private-sector entities with more than 50 employees on average generally need an internal channel, subject to sector-specific obligations that can apply at lower thresholds. The regime also covers public entities under its own thresholds and rules.
A secure channel needs a safe case path
The internal channel must protect the confidentiality of the people involved, prevent access by unauthorised staff or management and comply with data-protection law. It can be managed internally or by a third party, but outsourcing does not remove the statutory safeguards.
The procedure must include acknowledgement within seven days, an impartial person or service for follow-up and feedback within three months. Those requirements turn the channel into a case-management process.
An organisation should know where a report goes after intake, who can see identity, how evidence is stored, how deadlines are calculated and what happens when the normal handler is implicated. A general-purpose ticketing platform can expose allegations through search, notifications or administrator access even if the front-end form uses encryption.
External reporting is distributed by subject
Luxembourg designated 23 competent authorities within their respective mandates. A competition matter, financial-services issue or workplace concern may therefore have a different external destination. Authorities can transfer a report securely when it belongs elsewhere and must protect identity during that cooperation.
The Office for Whistleblowers, OSIG, supports the framework by informing, advising and assisting people, raising awareness and monitoring compliance with the law. It also receives information about failures to establish internal channels.
For organisations, the network creates a routing question. The internal case team should identify potential external authorities and preservation duties without telling reporters that they must diagnose the legal category themselves. A report can span several domains and may require coordinated rather than sequential handling.
Confidentiality needs selective disclosure
Case access should be based on function. The person acknowledging a report does not necessarily need access to every investigation document. A subject-matter expert may need the allegation and evidence without the reporter’s identity. Senior management may need a risk summary rather than the raw file.
Systems should record disclosures and transfers, but the audit trail must not repeat sensitive narratives in broadly visible logs. Notifications should use neutral references. Attachments should be protected against malware and uncontrolled metadata while their evidential integrity is preserved.
Data retention should follow the law and the purpose of the case. Keeping every report indefinitely “just in case” increases exposure and conflicts with data-minimisation principles. Deletion decisions need holds for litigation, investigation and protection claims where applicable.
Enforcement reaches channel design
The competent authorities can verify whether private entities within their remit established compliant internal channels and can request information. The law provides for administrative penalties for conduct including obstructing reports, breaching confidentiality, failing to remedy identified non-compliance and omitting required channels and procedures.
That means an organisation should be able to demonstrate operation, not only point to a policy. Evidence can include channel availability, access roles, training, acknowledgement and feedback records, conflict routing, privacy configuration and periodic testing.
Test a multi-authority case
A useful tabletop scenario should include a report that alleges procurement fraud, misuse of personal data and retaliation by a manager. The team should test:
- whether the reporter can communicate safely;
- which internal handlers can access each part;
- whether several external authorities may be relevant;
- how transfer or referral is documented;
- how the reporter is updated; and
- how retaliation concerns are escalated immediately.
Luxembourg’s framework recognises that whistleblower protection is an ecosystem. The organisation, its provider, OSIG and competent authorities may all touch the process. Compliance depends on ensuring that every hand-off preserves confidentiality, ownership and the ability to act.
Official sources
- Luxembourg Office for Whistleblowers: remit and the Law of 16 May 2023
- Luxembourg Office for Whistleblowers: internal-channel obligations
- Guichet.lu: internal reporting under the Law of 16 May 2023
Continue the series
- Next in Luxembourg: Luxembourg’s DSA Law Gives Platform Oversight Enforcement Teeth
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



