All articles Article

The Polish Whistleblower Protection Act: who it applies to and from when

The obligation does not apply to "companies with more than 50 employees". It applies to entities for which at least 50 persons perform paid work on one of two days in the year, and in several sectors to every entity, regardless of size. The difference matters, because it determines whether you need a procedure at all.

min read
7 min read
Updated
Legal status as of
In this article 8
  1. Where the obligation comes from
  2. The 50-person threshold: how to count
  3. No threshold: sectors covered regardless of size
  4. Exemptions: small municipalities and counties
  5. Who can be a whistleblower
  6. Which breaches the Act covers
  7. What the Act does not cover
  8. What this means for the reporting channel

Where the obligation comes from

The Polish Act of 14 June 2024 on the Protection of Whistleblowers (Journal of Laws 2024, item 928) implements Directive (EU) 2019/1937 of the European Parliament and of the Council. It entered into force on 25 September 2024, except for the provisions on external reports to the Commissioner for Human Rights (RPO) and public authorities, which took effect on 25 December 2024. Poland implemented the directive almost three years late, so there was practically no transition period for companies: anyone covered by the Act on the day it entered into force should have had a procedure in place that day.

At the heart of the Act are two obligations of the legal entity: establishing an internal reporting procedure and protecting the reporting person from retaliation. This article addresses the first question every board and every head of a public body asks: does this apply to us at all.

The 50-person threshold: how to count

An internal reporting procedure must be established by a legal entity for which at least 50 persons perform paid work as at 1 January or 1 July of a given year (Article 23(1)). Three elements of this definition regularly come as a surprise:

  1. Persons count, not full-time positions under employment law. The number includes employees calculated as full-time equivalents and persons performing work for remuneration on a basis other than an employment relationship, provided they do not employ other persons for that kind of work (Article 23(2)). Contracts of mandate, contracts for specific work and sole traders invoicing the company all count. A company with 38 employees and 15 B2B contractors exceeds the threshold.
  2. Two measurement dates a year. The headcount is checked on 1 January and 1 July. It is enough for the threshold to be reached on one of those dates. A seasonal organisation that grows to 60 people in summer and drops to 40 in winter is covered by the Act.
  3. The threshold applies to the legal entity, not the group. Three companies with 30 people each do not add up to a single obligation, but each of them may separately exceed the threshold at a different time. Conversely, a parent company does not "take care of" its subsidiaries' obligation with a single channel unless each of them formally establishes a procedure and designates a common unit to receive reports. The Act permits a shared procedure for private entities with 50 to 249 workers, subject to an agreement between them (Article 28).

In practice: count persons on 1 January and 1 July, including contractors and B2B, for each company separately. If any of those numbers is 50 or more, that company needs a procedure.

No threshold: sectors covered regardless of size

The 50-person threshold does not apply to entities operating in the areas of financial services, products and markets, prevention of money laundering and terrorist financing, transport safety and environmental protection, covered by the legal acts listed in the annexes to the directive (Article 23(3)). This includes, among others, banks, credit unions (SKOK), investment firms, insurers, accounting firms and law firms to the extent that they are obliged institutions within the meaning of the Anti-Money Laundering Act, as well as some carriers and waste management entities. A five-person accounting firm that applies AML procedures as an obliged institution needs an internal reporting procedure just as a bank does.

Exemptions: small municipalities and counties

The provisions on internal reports do not apply to organisational units of a municipality or county with fewer than 10,000 inhabitants (Article 23(4)). Note the word "units": the exemption covers the municipal office and its organisational units (schools, social welfare centres, municipal utilities), but only in municipalities below the population threshold. A municipality with 12,000 inhabitants is fully covered by the Act, even if the office itself employs 30 people, because for public bodies the deciding factor is the number of inhabitants, not the number of workers.

Who can be a whistleblower

The Act defines a whistleblower broadly (Article 4). It is a natural person who reports or publicly discloses information about a breach of law obtained in a work-related context. The list includes an employee, a temporary agency worker, a person performing work on a basis other than an employment relationship (including under a civil-law contract), an entrepreneur, a commercial proxy (prokurent), a shareholder or partner, a member of a governing body of a legal person, a person performing work under the supervision of a contractor, subcontractor or supplier, a trainee, a volunteer, an intern, an officer of the uniformed services and a soldier.

Protection also extends to persons who are only applying for work (information obtained during recruitment) and persons whose legal relationship has already ended. A former employee who reports what they learned during their employment is therefore also a whistleblower, as is a candidate who heard about an irregularity during an interview. The reporting channel must be accessible to these persons, which means it cannot operate solely on the intranet or require a company account.

Protection also covers persons who assist in making a report and persons connected with the whistleblower, for example a colleague or a family member, if they may suffer retaliation (Articles 21 and 22).

Which breaches the Act covers

A breach of law within the meaning of the Act is an act or omission that is unlawful or intended to circumvent the law in the areas listed in Article 3(1). The list is closed and covers:

  • corruption,
  • public procurement,
  • financial services, products and markets,
  • prevention of money laundering and terrorist financing,
  • product safety and compliance,
  • transport safety,
  • environmental protection,
  • radiation protection and nuclear safety,
  • food and feed safety, animal health and welfare,
  • public health,
  • consumer protection,
  • protection of privacy and personal data,
  • security of network and information systems,
  • the financial interests of the State Treasury, local government units and the European Union,
  • the internal market of the Union, including the rules on competition, State aid and corporate taxation,
  • constitutional freedoms and rights of persons and citizens in relations with public authorities.

Two things are worth remembering. First, during the legislative process labour law was removed from the list. Mobbing, discrimination or irregularities in pay are not breaches of law within the meaning of the Act, so a person who reports them does not benefit from statutory protection unless the matter falls into another category (for example personal data protection, or constitutional rights in a public body). Second, the legal entity may extend the procedure to reports of breaches of internal regulations or ethical standards (Article 3(2)). Most organisations do this, because a channel that rejects a mobbing report as "not covered by the Act" loses trust after the first such case. It should simply be remembered that a report in a category added by the employer protects the whistleblower under the procedure and labour law, not under the Act.

What the Act does not cover

The Act does not apply to information covered by the professional secrecy of the medical and legal professions, the secrecy of judicial deliberations, the secrecy of criminal proceedings, or to classified information (Article 5). Nor does it cover procurement in the fields of defence and security to the extent specified in the Act. An attorney-at-law who learns of a breach while serving a client cannot report it invoking whistleblower protection if the information is covered by professional secrecy.

What this means for the reporting channel

The definition of a whistleblower and the list of breaches translate directly into requirements for the system:

  • the channel must be accessible from outside the organisation and without a company account, because a former employee, a candidate, a subcontractor or a partner may be a whistleblower;
  • the form should allow a report outside the statutory list if the procedure extends it, and state clearly which reports benefit from statutory protection;
  • the register of internal reports must exist from the first day on which the entity exceeded the threshold, because the first measurement date after exceeding it is also the day from which the obligation runs.

How to write and implement the procedure itself is described in a separate article on the internal reporting procedure. The deadlines that start running from that point are covered in the article on statutory deadlines.

This text is for information only and describes the legal position on the stated date. It does not replace legal advice in a specific case.

A procedure is a document. A channel is the system that carries it out.

sygnadesk counts the deadlines, keeps the register and protects the reporter’s identity the way the knowledge base describes. See how it would look in your organisation.