Spanish Law 2/2023, of 20 February, on the protection of persons who report regulatory breaches, transposes EU Directive 2019/1937 into Spanish law. In practice it requires many organisations to have an internal reporting channel (what everyone calls a «whistleblowing channel») and to protect the reporter against any retaliation.
The point: having the channel is not enough. The law requires deadlines, confidentiality, optional anonymity and an audit trail proving how each case was handled. This is where a channel inside Odoo makes your life easier.
Who is affected, and since when
The obligation falls, among others, on private companies with 50 or more employees, political parties, trade unions and public sector entities. Certain activities (financial services, anti-money-laundering) are obliged regardless of headcount. Companies with 50 to 249 employees had until 1 December 2023 to comply; those with 250 or more and the public sector, since June 2023.
What the law requires from the channel
- Allow written and/or verbal reports, and accept anonymous submissions.
- Guarantee confidentiality for the reporter, the person affected and any third parties.
- Send an acknowledgement of receipt within a maximum of 7 calendar days.
- Resolve the investigation within no more than 3 months.
- Appoint a system manager and keep a register of every communication.
- Process data in line with GDPR and keep it only for as long as strictly necessary.
How it works inside Odoo
The idea is simple: a public form (on the Odoo website or on a linked page) where anyone can submit a report, even anonymously. Each submission creates an internal record with a tracking code the reporter can use to check status without identifying themselves.
From there, Odoo handles the whole cycle: it assigns the case to the manager, sends the automatic acknowledgement of receipt within 7 days, tracks deadlines with alerts before the 3-month mark, restricts access to authorised people only, and logs every action in the audit trail (chatter). So when someone asks how you handled a case, you have a documented answer.
Confidentiality and data protection
The trickiest part is not technical, it is about access. A report can contain sensitive personal data and accusations not yet proven. The channel must therefore limit who sees what: only the system manager and, where applicable, the investigation team. In Odoo this is solved with security groups and record rules, so the rest of the company cannot even list the cases.
Things to watch out for
- Do not confuse the channel with a suggestion box: its purpose is to report breaches, not general feedback.
- Real anonymity requires not logging IP addresses or metadata that could identify the reporter.
- The 7-day and 3-month deadlines must be provable, not just met.
- Data retention has limits: reports must not be kept longer than necessary.
Frequently asked questions
Who is required to have a whistleblowing channel?
Companies with 50 or more employees, political parties, trade unions and public sector entities, plus companies in certain sectors (financial services, anti-money-laundering) regardless of headcount.
What deadlines does Law 2/2023 set?
Acknowledgement of receipt within a maximum of 7 calendar days, and resolution of the investigation within no more than 3 months from that acknowledgement.
Can anonymous reports be accepted?
Yes. Law 2/2023 requires the channel to allow reports to be filed anonymously and to guarantee the reporter's confidentiality in all cases.
Is a whistleblowing channel inside Odoo valid?
Yes, as long as it guarantees confidentiality, optional anonymity, access control, deadline tracking and evidence retention in line with the law and GDPR.
Want the whistleblowing channel set up inside your Odoo?
We review your specific case (size, sector and deadlines) and set up the channel in line with Law 2/2023. Book a call via Calendly or call us at +34 616 809 504.