EU frameworkGDPRNIS 2DORAAI ActWhistleblowing
Recital 14

Recital 14

Directive on the protection of persons who report breaches of Union law · UE 2019/1937

(14)

Respect for privacy and protection of personal data, which are enshrined as fundamental rights in Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (the ‘Charter’), are other areas in which whistleblowers can help to disclose breaches, which can harm the public interest. Whistleblowers can also help disclose breaches of Directive (EU) 2016/1148 of the European Parliament and of the Council (19) on the security of network and information systems, which introduces a requirement to provide notification of incidents, including those that do not compromise personal data, and security requirements for entities providing essential services across many sectors, for example energy, health, transport and banking, for providers of key digital services, for example cloud computing services, and for suppliers of basic utilities, such as water, electricity and gas. Whistleblowers' reporting in this area is particularly valuable for the prevention of security incidents that would affect key economic and social activities and widely used digital services, as well as for the prevention of any infringement of Union data protection rules. Such reporting helps ensure the continuity of services that are essential for the functioning of the internal market and the wellbeing of society.

Luxembourg specificity
loi luxembourgeoise du 16 mai 2023 relative a la protection des lanceurs d'alerte

In Luxembourg, the law of 16 May 2023 on whistleblower protection explicitly transposes the areas covered by recital 14 and designates the OFRS as the cross-sectoral external authority, with sectoral routing to the CNPD (GDPR), ILR (NIS 2, digital services) and CSSF (finance). The internal channel obligation threshold is 50 employees for private entities, with no threshold for public bodies. Retaliation triggers criminal fines of 1,250 to 25,000 EUR, doubled in case of recidivism, on top of civil damages.

Luxgap practice: configure parallel OFRS plus CNPD plus ILR routing in your internal channel from day one, and log every qualification decision, because the OFRS audits the consistency of triage, not merely the existence of the channel.