After months of uncertainty upon learning of the Draft Law and several modifications in the Senate, the Law on the complaints channel has been published in the Official State Gazette of February 21, 2023 as the Law 2/2023 of February 20, regulating the protection of people who report regulatory infractions and the fight against corruption. Thus, it is finally transposed into the Spanish legal system. Directive 2019/1937 on the protection of persons who report infringements of Union law, also commonly known as Directive Whistleblowing.
This Law, which comes into force 20 days after its publication in the BOE, provides for the correct implementation of a complaints system - or, in the terms of the Law, an internal information system - as an essential instrument for the companies can provide adequate protection to informants. These systems, by their very nature, involve processing personal data that presents certain particularities that must be taken into account, which is why the Law dedicates its entire Title VI to the protection of personal data.
Through this publication, we analyze the most significant legislative developments in relation to data protection in whistleblowing systems after the publication in the BOE of this Law:
- Data adjusted to the purposes pursued: Personal data that is not relevant to the purposes of investigating the complaint within the scope of this law should not be collected and, if collected by accident, should be deleted without undue delay.
- Legality in data processing: Data processing that is necessary to comply with this Law is presumed lawful. The appropriate bases of legitimation will be legal obligation and public interest. For these purposes, special category data may be processed in the complaints system, as necessary for the purposes of the corresponding investigation and in accordance with art. 9.2.g) of the RGPD: because it is necessary for reasons of essential public interest, and provided that the processing of the data is proportional to the objective pursued, essentially respects the right to data protection and appropriate and appropriate measures have been adopted. specific to protect the interests and fundamental rights of the interested party.
- Duty of information: The interested parties (both employees of the organization and third parties) must be provided with information regarding the processing of their data in accordance with the provisions of the RGPD, but confidentiality must be maintained regarding the data of the complainant, whose identity must be reserved and in no case may it be revealed to the accused. The identity of the informant, when it is available because he or she has not made his or her complaint anonymously, may only be communicated to the judicial authority, the Public Prosecutor's Office or the competent administrative authority within the framework of a criminal, disciplinary or sanctioning investigation.
- Exercise of rights: The people whose data is processed in the complaints system have all the rights provided for in the RGPD with the only particularity that if the person reported exercises the right to object, it is presumed, unless proven otherwise, that there are compelling legitimate reasons. that legitimize the processing of your data, so your request may be rejected.
- Access to personal data: Only the following people will be able to access personal data in the complaints system:
- The person responsible for the system itself and whoever manages it directly.
- The person responsible for human resources or the competent body when disciplinary measures could be taken against a worker.
- The person responsible for legal services when the adoption of legal measures is appropriate.
- Those in charge of treatment who require it to provide their service.
- The Data Protection Officer.
In addition, the information may be shared with other people or third parties when this is necessary for the adoption of corrective measures in the entity or the processing of appropriate sanctioning or criminal procedures.
- Data retention period in the complaints system: The general rule is that the personal data contained in the complaints system are kept there exclusively for the time necessary to decide whether to open an investigation. In any case, if three months pass without an investigation having been initiated, the data must be deleted within the complaints system, unless it is anonymized or the purpose of the conservation is to leave evidence of the operation of the system.
- Delegate of Data Protection: Despite the previous provisions of the Draft Law, it is confirmed that the obligation to designate this figure to those companies that were obliged to implement an internal information system only by virtue of being subject to this obligation has finally been eliminated. without prejudice to the fact that they will have to name it if it is applicable to them in accordance with the provisions of the General Data Protection Regulation and/or the Organic Law on Data Protection and guarantee of digital rights.
- Joint responsibility for treatment. In those cases in which there is co-responsibility in the management of a complaints system (for example, because a group of companies share a single system that they manage jointly), the Law expressly mentions the obligation to sign a co-responsibility agreement in accordance with the provided for in art. 26 GDPR.
- Security measures: Obviously every reporting channel must have the application of robust security measures that guarantee, in the greatest possible way, above all the confidentiality of the data, and also its integrity and availability.
Eduardo Oliveros Caballero, lawyer in ELZABURU.


