Bookkeeping

Accounting

Whistleblower protection in the Netherlands: what the Wbk requires

Does the Wet Bescherming Klokkenluiders apply to your BV? See the real threshold, the seven meldprocedure rules, and the 2026 enforcement gap.

•

15 mins

Whistleblower Protection in the Netherlands

Intro

All organisations in the Netherlands with 50 or more employees must have an internal reporting channel under the Wet Bescherming Klokkenluiders, the Wbk. Most Dutch employers sitting near that headcount already know this. What they do not always know is that 50 is measured on the regular average number of employees, not a snapshot on any single payroll date, and that several categories of employer are subject to the law regardless of size at all.

More Employers Are Subject Than They Realise

The financial sector exception catches the most people off guard. Organisations in the financial sector with fewer than 50 employees must also have an internal reporting channel from 18 February 2023, with no headcount exemption whatsoever. A payment provider with 12 staff, a small investment manager with 8 people, or a CASP with 20 employees is subject to the full Wbk meldprocedure requirement, and the 50-employee threshold simply does not apply to any of them.

The transition dates matter for understanding how long this obligation has actually been running. The Wbk entered into force on 18 February 2023, and employers with 250 or more employees were subject from that exact date. Private sector employers with 50 to 249 workers only needed to comply from 17 December 2023, under the transitional provision in article 21c. For most mid-sized Dutch businesses, that means the obligation has now been active for almost three years, not a few months.

The headcount itself deserves a closer look than most employers give it. The count includes every employee on payroll, permanent, temporary, and on-call staff working regular hours. ZZP contractors are generally not counted. Crucially, the figure is based on the employer's regular average across the year, not a single year-end snapshot. A BV that regularly employs 48 people but spikes to 60 during a busy season is very likely at the threshold year-round, if the average across the full year genuinely reaches 50, regardless of what the headcount happens to read on any one date.

Key takeaway: Employers with 50 or more employees have been required to have an internal reporting procedure meeting the Wbk's requirements since December 2023. Three years in, a meaningful number of Dutch employers in this category still have not implemented a compliant procedure. The practical consequence is not yet a fine. It is a civil law liability that grows with every month a meldprocedure stays absent.

Getting the underlying employer obligations right from the very first hire is what this whole framework ultimately builds on top of; hiring staff as a sole proprietor covers that starting point.

What the Meldprocedure Must Contain

The Wbk specifies exactly what an internal meldprocedure must contain, and there is no discretion on the essential elements. An employer can add more detail than the law strictly requires, but cannot omit any of the seven mandatory components without the procedure itself becoming legally deficient.

Requirement

What the law requires

What this means in practice

Common failure

1. Meldkanaal

A channel allowing both written and oral reporting

Secure email or web form, plus a phone line or in-person option

Only email exists; no oral reporting route is offered at all

2. Ontvangstbevestiging within 7 days

Acknowledge receipt within 7 calendar days

An automated or manual confirmation sent to the melder

No response for weeks; the 7-day clock is treated as flexible when it is not

3. Feedback within 3 months

Inform the melder of action taken within 3 months of acknowledgement

A substantive update, not necessarily a final conclusion

No feedback at all; the report is quietly closed without ever informing the melder

4. Designated meldpunt

An independent person or department handles reports

A compliance officer, internal audit, or an external whistleblowing service

No designated person; the report lands with the line manager of the person being reported

5. Information about external channels

Employees must know they can report externally without using the internal channel first

Details of the Huis voor Klokkenluiders and relevant bevoegde autoriteiten included in the procedure

Internal-only procedures that never mention any external option exists

6. Confidentiality safeguards

The melder's identity cannot be disclosed without consent; AVG compliance required

Access restrictions, data minimisation, set retention periods, a DPIA assessment

No access controls; report data is visible to the very person being reported

7. Benadelingsverbod statement

The retaliation prohibition must be explicitly stated in the procedure

A clear clause confirming no employee will be disadvantaged for reporting

It is not stated at all; the employer assumes the legal prohibition speaks for itself

Where this most commonly goes wrong in practice is the privacy side. The meldkanaal itself is a processing of personal data, often genuinely sensitive data, and it therefore has to comply with the AVG on top of the Wbk's own procedural requirements. A compliant meldprocedure is really a double compliance exercise: the Wbk governs the procedure itself, and the AVG governs how the resulting data actually gets handled once a report comes in.

Watch out: If your organisation has an ondernemingsraad, the meldprocedure must be submitted for the OR's instemmingsrecht, its right of consent, under the Wet op de Ondernemingsraden before it is implemented. A meldprocedure introduced without OR consultation is not validly established, and for an employer with 50 or more employees, an OR is mandatory too. Both obligations land at exactly the same threshold, which is precisely why they are so often overlooked together.

Where the OR's involvement in this kind of policy sits alongside broader collective labour obligations is worth understanding on its own terms; CAO Netherlands employer covers that wider context.

Who Is Protected, and How Broadly

The protection the Wbk provides is significantly broader than most Dutch employers assume when they picture a "klokkenluider." The benadelingsverbod, the retaliation prohibition, covers not just the employee who made the report but a genuinely wide circle of people, and it attaches to the act of reporting regardless of whether the reported misstand ultimately turns out to be correct.

The primary circle covers any employee who reports, or who is merely suspected of having reported, a vermoeden van een misstand, a suspicion of wrongdoing. This includes employees on every contract type, former employees, and job applicants whose applications were rejected in connection with whistleblowing activity. The extended circle reaches further still: freelancers and ZZP contractors working for the organisation, interns and volunteers, directors, including a DGA even where they are the company's only director, and anyone who assists the melder, colleagues who corroborate the report, witnesses, or anyone else who helped the reporting process along.

What actually triggers the protection is deliberately generous: a vermoeden van een misstand, a suspicion based on reasonable grounds. The employee does not need to prove the misstand actually occurred. A good-faith report based on reasonable grounds is enough, and an employer cannot defeat the protection later by demonstrating the report turned out to be unfounded. Dutch courts have been consistently expansive in interpreting what counts as benadeling, retaliation, in practice. Dismissal is the obvious case, but demotion, negative performance reviews, removal of responsibilities, hostile treatment, and any measure capable of discouraging future reporting all fall within the prohibition. The Hof Den Bosch confirmed that an employee reporting suspected serious wrongdoing in the care sector retains Wbk protection even where they violated privacy rules while gathering evidence for that report; the protection is not contingent on the melder having behaved perfectly throughout.

The courts have kept applying this actively through 2026. The Huis voor Klokkenluiders' own tenth-anniversary review, published in July 2026, found that more than 80% of people who contacted the Huis for support had experienced some form of retaliation, despite the statutory protection already in place. Separately, in a 15 June 2026 ruling, the Gerechtshof Arnhem-Leeuwarden confirmed that an employer's dismissal of an employee who had made a report was unlawful under the benadelingsverbod. The civil law liability that follows a wrongful dismissal in a whistleblowing context can include reinstatement, back pay, and damages, a genuinely material exposure regardless of the formal regulatory landscape sitting behind it. Where dismissal and severance obligations intersect with this kind of protected status is worth understanding in more depth; transitievergoeding Netherlands covers that separate but closely related exposure.

The Enforcement Reality, and What Is Changing

The Wbk carries real obligations and growing civil law consequences, but it currently lacks the one element that would make it more immediately enforceable in the ordinary administrative sense. The Huis voor Klokkenluiders, the authority established to oversee whistleblower protection, does not yet have any formal handhavings- or sanctiebevoegdheid over employers. The Netherlands has not fully implemented the obligation in article 23 of the underlying EU Directive, which calls for effective, proportionate, and dissuasive sanctions against employers who violate the law.

Civil law is, today, the primary enforcement mechanism in practice. An employee who is retaliated against can bring a claim before the kantonrechter, and the burden of proof is reversed: the employer must demonstrate that any adverse measure was genuinely unrelated to the report, rather than the employee having to prove retaliation occurred. This omgekeerde bewijslast is a significant practical exposure on its own; an employer who dismisses someone shortly after they made a Wbk report has to prove the dismissal had an entirely unconnected cause, which is often a difficult burden to meet convincingly.

The Huis itself can investigate complaints and produce recommendations, but those recommendations carry no binding force today. An employer can, in the narrow technical sense, ignore a Huis recommendation without facing any immediate administrative sanction as a direct result. Reputational risk fills part of that gap in practice: where the Huis investigates and its findings become public, which they typically do, a Dutch employer of 80 or 150 people faces the genuine reputational consequence of being publicly identified as an organisation that retaliated against a whistleblower, in a labour market where talent retention at growing BVs is already a real, ongoing concern.

That gap is genuinely closing, though not quite as completely as some coverage suggests. The government confirmed in mid-2025 that the Huis will receive formal toezichts- and handhavingstaken on two specific fronts: the mandatory meldregeling and information duty for larger organisations, and the protection of a melder's identity, with the expectation the Huis can begin exercising these new powers around the end of 2026 or early 2027. A legal review by Pro Facto found that a third element originally proposed, giving the Huis power to sanction employers who simply ignore its own recommendations, was not legally sustainable, and that specific piece has been dropped from the current plan. What this means concretely: once the change lands, an employer with no meldprocedure at all, or one that breaches a melder's confidentiality, faces a genuinely new administrative enforcement risk. Sanctioning an actual act of retaliation under the benadelingsverbod, however, is expected to remain a civil law matter even after this upgrade takes effect, since that specific enforcement route was the one found legally unworkable. Employers who have not yet implemented a compliant meldprocedure are, right now, operating without one during exactly the window in which this enforcement framework is being actively rebuilt. Since compliance investigations and documentation standards elsewhere in Dutch business regulation offer a useful preview of what this kind of oversight typically looks like once it does land, boekenonderzoek Belastingdienst covers that broader pattern.

Building a Compliant Meldprocedure

For a Dutch employer who does not yet have a compliant meldprocedure, the implementation path is genuinely well defined. It requires four components in sequence, and none of them is technically complex, though all four are necessary for the result to actually hold up.

The written meldregeling document comes first: a clear, written procedure containing all seven required elements, typically running three to five pages, written in plain language rather than legal terminology. It needs to describe the meldkanaal, the acknowledgement and feedback timelines, the designated meldpunt, the external reporting options, the confidentiality commitments, and the benadelingsverbod explicitly, and it should be written in the language employees actually use day to day, Dutch for most Dutch employers, English where an international workforce genuinely operates in English.

The meldkanaal infrastructure comes next: a secure channel supporting both written and oral reports. For many Dutch SMEs, this is simply a dedicated email address managed only by the designated meldpunt, paired with a phone number or a standing in-person appointment option. Specialist whistleblowing software, platforms such as TrueSpeak or Disclosurely among others, provides a more robust and often simpler route, handling the confidentiality and data retention requirements largely automatically, typically for somewhere between 50 and 200 euros a month depending on organisation size and feature set.

The designated meldpunt itself needs to be a specific person or small team, genuinely independent from the subject of any likely report. For a BV where the DGA is the only senior figure in the business, an external compliance consultant or lawyer can reasonably serve as the meldpunt instead, and the designation itself should be documented rather than left informal.

The OR consultation and distribution round out the sequence. Where an ondernemingsraad exists, the draft meldprocedure needs to go through its instemmingsrecht before implementation. Once approved, the procedure needs to actually reach every employee, through an updated handbook, a direct communication, intranet publication, and inclusion in onboarding for new hires; passively leaving it on an internal page nobody visits does not satisfy the requirement to actually bring it to employees' attention. Getting this kind of compliance work genuinely right, rather than treating it as a document to file away once written, is exactly where professional guidance tends to earn its cost; accountant or bookkeeper covers where that kind of support typically fits into a growing Dutch BV's compliance work more broadly.

FAQs

What is the Wet Bescherming Klokkenluiders?

The Wbk is Dutch legislation, in force since 18 February 2023, implementing EU Directive 2019/1937 on whistleblower protection. It requires qualifying employers to run a compliant internal reporting procedure and prohibits retaliation against anyone who reports a suspected misstand.

Does the Wbk apply to my business?

Yes, if your organisation has 50 or more employees on a regular average basis, or if you operate in the financial sector regardless of headcount, or if you are a public sector employer of any size. Private sector employers with 50 to 249 employees have been required to comply since 17 December 2023.

What counts as an employee for the 50-person threshold?

All employees on payroll, permanent, temporary, and structurally working on-call staff, counted as a regular average across the year rather than a single snapshot date. ZZP contractors are generally not counted toward this threshold.

What must my internal meldprocedure contain?

Seven mandatory elements: a channel supporting both written and oral reports, an acknowledgement within 7 days, substantive feedback within 3 months, a designated independent meldpunt, information about external reporting options, confidentiality safeguards compliant with the AVG, and an explicit statement of the benadelingsverbod.

Does a financial services company with fewer than 50 employees need a meldprocedure?

Yes. The financial sector has no headcount exemption at all under the Wbk. A payment provider, investment firm, insurer, or CASP with even a handful of employees is fully subject to the internal reporting requirement from 18 February 2023.

What is a "misstand" under the Wbk?

A suspicion, based on reasonable grounds, of wrongdoing that carries a genuine public interest dimension, or a breach or threatened breach of EU law. Purely personal workplace grievances without any wider public interest element generally do not qualify as a reportable misstand.

Who is protected by the benadelingsverbod?

A wide circle: employees of every contract type, former employees, rejected job applicants connected to reporting activity, freelancers and ZZP contractors working for the organisation, interns, volunteers, directors including a DGA, and anyone who assists a melder in making their report.

Can the Huis voor Klokkenluiders impose fines on my company?

Not yet. The Huis currently has no formal sanctiebevoegdheid. From around the end of 2026 or early 2027, it is expected to gain enforcement powers specifically over the mandatory meldregeling and melder identity protection, though sanctioning actual retaliation is expected to remain a civil law matter even after that change.

What happens if I retaliate against a whistleblower?

The employee can bring a civil claim with the burden of proof reversed onto the employer, who must prove any adverse action was genuinely unrelated to the report. Dutch courts have consistently ruled against employers in these cases, and remedies can include reinstatement, back pay, and damages.

Does my works council need to approve the meldprocedure?

Yes, if your organisation has an ondernemingsraad. The OR holds instemmingsrecht over the meldprocedure under the Wet op de Ondernemingsraden, and a procedure introduced without that consultation is not validly established.

Portrait of Nick
Portrait of Nick

Written by

Nick Knuppe

CEO & Founder

We take care of admin. You take care of business.

We take care of admin. You take care of business.

We take care of admin. You take care of business.