Hungary’s Whistleblower Law Turns Follow-Up Into a Timed Process
Hungary’s 2023 whistleblower act combines employer channels with public-interest reporting and puts clocks around receipt, investigation and feedback. A mailbox without case orchestration is not enough.
Act XXV of 2023 on complaints, public-interest disclosures and rules concerning whistleblowing took effect on 24 July 2023. It replaced the previous general complaints statute and implemented the EU Whistleblower Directive while retaining a Hungarian public-interest disclosure structure.
Employers with at least 50 workers generally need an internal whistleblowing system, with special entities covered under sector rules and phased treatment for some smaller employers. The Act identifies a wider professional group that can report, including employees and other people connected with the organisation’s activities.
The law contains several reporting routes
The Act addresses ordinary complaints and public-interest disclosures to public bodies as well as internal employer systems and separate reporting channels operated by designated state bodies. These routes have different recipients and purposes.
An employer should not force every concern into the EU-directive categories at the front door. The person reporting may know the facts but not whether they amount to a public-interest disclosure, employment grievance, criminal allegation or regulated breach. The intake process should classify the matter after receipt and explain any transfer or different procedure.
Mixed cases need parallel handling. An allegation about manipulation of customer records could trigger whistleblower protection, an internal fraud investigation and a personal-data breach assessment. One classification should not hide the other duties.
Thirty days requires active case control
Public complaints and disclosures are generally to be handled within 30 days, with information to the reporting person if a longer investigation is expected and an overall limit in the extended case. Employer systems also operate with statutory acknowledgement and feedback periods under the whistleblower framework.
The practical requirement is a timer tied to the correct route. The system should record receipt, acknowledgement, initial scope, investigator, extension reasoning, communications and outcome. It should cover weekends, holidays, transfer between entities and absence of the normal case owner.
Automatically closing a case when a timer expires is dangerous. A deadline is a control for action and communication, not a substitute for a reasoned conclusion.
Confidentiality must include the subject of the report
The reporting person’s personal data may be transferred only as authorised for the procedure and generally may not be disclosed without consent. Information about the person accused and other individuals also requires controlled handling.
Access should therefore be selective. Identity can be separated from allegations; investigators can receive the minimum information needed; and management can receive risk summaries rather than a complete case file. The platform’s administrators and external provider also belong in the access analysis.
An anonymous or unidentified report may be left unexamined in some circumstances, but serious harm can justify investigation. Systems should support protected two-way contact so handlers can assess credibility without requiring identity.
Anti-retaliation needs a monitoring owner
The Act protects qualifying reporters against detrimental measures. Retaliation may appear as dismissal, schedule changes, withheld promotion, intimidation or supplier consequences rather than an explicit statement.
Once a protected report is identified, the organisation should establish who monitors subsequent decisions concerning the person and for how long. That monitor must preserve confidentiality; alerting every manager that an employee is a whistleblower defeats the protection.
The case record should connect alleged retaliation to the original protected activity while keeping both matters independently reviewable.
Test the route, not only the form
Employers should run a scenario and ask:
- Can eligible people outside the workforce find and use the system?
- Can written, oral and protected follow-up be supported?
- Does triage recognise public-interest, employment, criminal and privacy dimensions?
- Are the correct deadlines applied after a transfer?
- Can a conflict involving senior management be routed independently?
- Is identity shielded from unnecessary technical and managerial access?
- Who watches for retaliation after the investigation begins?
Hungary’s Act treats follow-up as a public and organisational responsibility. The visible channel matters, but the real compliance system is the timed, confidential path that turns a report into assessment, protection and a reasoned response.
Official sources
- Hungarian National Legislation Database: Act XXV of 2023
- Hungarian National Legislation Database: official explanatory memorandum
Continue the series
- Also in Hungary: Hungary’s Cybersecurity Act Starts With Registration and Audit
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



