# Whistleblower Protection — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/reporting-person-protection-whistleblower
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is essential because the content explicitly addresses the protection of reporting persons, including safeguards against retaliation, confidentiality measures, and legal protections, which constitute a critical and distinct regulatory framework within the AI Act.

## Overview

## Legal Framework

The protection of reporting persons is governed primarily by Directive (EU) 2019/1937, which mandates secure reporting channels and robust safeguards against retaliation. In the Netherlands, this is implemented through the Wet bescherming klokkenluiders (WBK). A cornerstone of the WBK is Article 17e, which establishes a strict prohibition against detriment (benadelingsverbod) for reporters during and after the handling of a report. Processing personal data within these frameworks requires strict compliance with the GDPR, relying on Article 6(1)(f) for legitimate interests while carefully managing any special categories of data under Article 9. Additionally, Article 1a of the General Equal Treatment Act (AWBG) provides complementary anti-retaliation protections.

## Key Developments

Recent jurisprudence clarifies the evidentiary standards for retaliation claims. In a June 2026 ruling, the Rechtbank Amsterdam addressed Article 17e WBK, confirming that when a recognized whistleblower suffers detriment, a reversed burden of proof applies. The detriment is presumed to be a consequence of the report, shifting the evidentiary burden to the entity accused of retaliation. Furthermore, the Rechtbank Den Haag in January 2026 examined the intersection of whistleblower protections and post-employment confidentiality agreements. The court addressed whether strict confidentiality obligations persist after employment termination, highlighting the friction between protecting reporting persons and enforcing contractual secrecy. 

Regulatory enforcement underscores the data protection risks inherent in handling whistleblower data. The Croatian Data Protection Authority (AZOP) imposed a €4.5 million fine on a telecommunications operator for multiple GDPR violations, signaling aggressive oversight of data handling in regulated sectors. Similarly, the Italian DPA (Garante) fined FT Solutions €5,000 for direct marketing violations, reflecting strict enforcement of data processing boundaries. The EDPB Guidelines 3/2019 on video equipment further establish that monitoring mechanisms must not compromise the confidentiality of reporting channels.

## Practical Guidance

- Establish internal reporting channels that guarantee end-to-end confidentiality for both the whistleblower and the accused, strictly adhering to Directive (EU) 2019/1937 and WBK requirements.
- Implement protocols to prevent detriment against reporting persons. Under the reversed burden of proof established in Article 17e WBK, any adverse action taken against a recognized whistleblower will be presumed retaliatory unless proven otherwise.
- Audit post-employment confidentiality clauses to ensure they do not unlawfully override statutory whistleblower protections, mitigating risks highlighted in recent Hague District Court proceedings.
- Conduct Data Protection Impact Assessments (DPIAs) for whistleblower systems, particularly when processing special categories of data under Article 9 GDPR, to preempt regulatory scrutiny similar to the AZOP and Garante enforcement actions.
- Restrict access to whistleblower data on a strict need-to-know basis, ensuring that surveillance mechanisms, such as video monitoring addressed in EDPB Guidelines 3/2019, do not inadvertently expose reporter identities.

## Legislation (full text of key provisions)

### Recital 172 — whistleblower protection under Union law

*Source: AI Act, aiact-rec-172-en, 2024-06-12 — https://overview.legal/posts/94026*

Persons acting as whistleblowers on the infringements of this Regulation should be protected under the Union law. Directive (EU) 2019/1937 of the European Parliament and of the Council (54) should therefore apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.

## Guidance

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

## Recent developments

### De AI-wet is niet voldoende: we moeten de gevaarlijke hiaten dichten die misbruik mogelijk maken en de rechten van mensen schenden.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/51727*

Hoewel de AI-wetgeving van de EU tot doel heeft om AI-systemen met een hoog risico te reguleren, wordt deze ondermijnd door belangrijke uitzonderingen die hun ongecontroleerde toepassing mogelijk maken in de context van nationale veiligheid en handhaving van de wet. Deze uitzonderingen riskeren onder meer het mogelijk maken van grootschalige surveillance van protesten en discriminerende migratiepraktijken. Om dit te voorkomen, heeft de EDRi-partner Danes je nov dan aanbevelingen gepubliceerd voor Slovenië om strengere nationale beschermingsmaatregelen en transparante toezichtsmechanismen in te voeren. De post "De AI-wetgeving is niet..."

## Related topics

- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Privacy by Design & Default** — https://overview.legal/topics/data-protection-by-design-default-article-25
  This topic is essential as it specifically addresses Article 25 GDPR requirements for implementing data protection principles through design and default setting
- **Authority Powers for Fundamental Rights Protection** — https://overview.legal/topics/authority-powers-fundamental-rights-protection
  This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Accuracy** — https://overview.legal/topics/accuracy
  Principle that personal data must be accurate and up to date

---
Generated by overview.legal · https://overview.legal/topics/reporting-person-protection-whistleblower · 2026-08-22
