All articles Article

Penalties for not having an internal reporting procedure and for retaliation

The criminal provisions of the Whistleblower Protection Act are short, but aimed at specific individuals, not at the company. Liability falls on whoever failed to establish the procedure, whoever obstructed a report and whoever retaliated. Beyond the Criminal Code there are also costs that have no article number.

min read
5 min read
Updated
Legal status as of
In this article 8
  1. Catalogue of prohibited acts
  2. No procedure: a fine, but not only
  3. Obstructing a report: also through the design of the channel
  4. Retaliation: a criminal sanction alongside compensation
  5. Breach of confidentiality: a year for one sentence
  6. False report: a safeguard, not a weapon
  7. Costs that have no article number
  8. What minimises the risk

Catalogue of prohibited acts

Chapter 6 of the Polish Act of 14 June 2024 on the Protection of Whistleblowers (Journal of Laws 2024, item 928) contains five criminal provisions. They are addressed to natural persons: a board member, the head of a unit, a manager, an employee who had access to the report.

ActSanctionBasis
Preventing or materially obstructing the making of a reportfine, restriction of liberty or imprisonment for up to one year; with the use of violence, threat or deceit, up to 3 yearsArticle 54
Retaliation against a whistleblower, a facilitator or a connected personfine, restriction of liberty or imprisonment for up to 2 years; persistent conduct, up to 3 yearsArticle 55
Disclosing the identity of a whistleblower, a facilitator or a connected person contrary to the Actfine, restriction of liberty or imprisonment for up to one yearArticle 56
Making a report or public disclosure knowing that no breach occurredfine, restriction of liberty or imprisonment for up to 2 yearsArticle 57
Failing to establish an internal reporting procedure, or establishing one in material breach of the requirements of the Act, when obliged to do sofineArticle 58

No procedure: a fine, but not only

Article 58 concerns the person responsible for establishing the procedure, which in a company is usually the management board and in a public body its head. "Material breach of the requirements of the Act" is a vague concept, but several situations are hard to assess otherwise: a procedure that does not designate the persons receiving reports, has no deadlines for acknowledgement of receipt and feedback, no information on external reporting, was introduced without consultation with employee representatives or was never announced. An email address given in the workplace regulations is not a procedure within the meaning of Article 25.

The fine is imposed in daily rates under the Criminal Code, so its amount depends on the offender's income. The criminal sanction, however, is the smaller problem. The bigger one is that in a retaliation dispute an organisation without a procedure has nothing on which to base its defence: it cannot show that the report was received, who handled it, or that the personnel decision was taken without knowledge of the report.

Obstructing a report: also through the design of the channel

Article 54 penalises preventing and materially obstructing a report. In practice this concerns intimidation and pressure, but the provision is not limited to conduct towards a specific person. A channel that requires identification contrary to a procedure that declares anonymity, a form available only from a company account for employees who have no such account, a reporter page that is "accidentally" not working: each of these may be assessed as material obstruction if intent can be shown.

Retaliation: a criminal sanction alongside compensation

Article 55 provides for criminal liability for retaliation independently of civil liability: the whistleblower is entitled to compensation of not less than the average monthly wage (Article 14), and the perpetrator of the retaliation, for example a manager who dismissed an employee after a report, is personally liable. Persistence, meaning repeated actions against the same person, raises the upper limit to 3 years.

Breach of confidentiality: a year for one sentence

Article 56 concerns disclosure of the whistleblower's identity contrary to the provisions of the Act. The perpetrator may be anyone who learned the identity: a committee member, an HR employee, an IT administrator with access to the mailbox. Saying in the corridor "it was Kowalski who reported it" satisfies the elements of the offence. This provision is the strongest argument for limiting access to the identity to a minimum and for a log that shows who had that access: it makes it possible to rule out those who did not.

False report: a safeguard, not a weapon

Article 57 protects against abuse of the channel, but requires awareness that no breach occurred. A report based on a mistaken assessment, exaggerated or emotional, is not false within the meaning of this provision. An organisation that responds to an inconvenient report by notifying the authorities of an offence under Article 57 should expect a court to treat this as retaliation under Article 55.

Costs that have no article number

Criminal sanctions are rarely what really hurts. Four consequences of not having a working channel are more costly:

  1. An external report instead of an internal one. A whistleblower who does not trust the internal channel or did not receive a reply on time goes to the Commissioner for Human Rights (RPO), to a supervisory authority or to the press. The organisation loses the opportunity to clarify the matter in-house.
  2. A retaliation dispute with a reversed burden of proof. Without a register, a log and separation of identity from content, the employer has no evidence that the personnel decision was independent of the report.
  3. An inspection by the National Labour Inspectorate (PIP) or a supervisory authority. The inspection asks about the procedure, authorisations, the register, deadlines and consultations. Every gap is noted, and together they add up to a "material breach" under Article 58.
  4. Liability for a personal data breach. Reports are high-risk data. A leak from an unsecured mailbox is a GDPR breach with a separate administrative fine of up to 4% of turnover.

What minimises the risk

  • A procedure compliant with Article 25, consulted and announced with proof of the date.
  • A channel accessible to all whistleblowers, including anonymously, if the procedure so provides.
  • Deadlines tracked by the system, not by one person's memory.
  • The whistleblower's identity separated from the content, with access on request and a log of who learned it.
  • Written authorisations for every person with access.
  • A register and audit log that cannot be altered, because they are the evidence before an inspection and a court.

sygnadesk is built around this list: the implementation wizard guides you through the requirements of the procedure, the system counts the deadlines, identity is protected by a request approved by a second person, and the register and audit log are immutable and available for export for an inspection.

This text is for information only and describes the legal position on the stated date. It does not replace legal advice in a specific case.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.