whistleblower guide — The Cyprus Securities and Exchange Commission (CySEC) has introduced a new whistleblower guide, aimed at strengthening the reporting framework for breaches in the financial services sector. This initiative is designed to improve the reporting of violations of both European Union and national laws.
Released on Tuesday, the guide supports the implementation of Circular C608, which outlines the procedures for external reporting under Cyprus’ whistleblower protection framework. CySEC emphasises that the document provides practical examples and detailed guidance for individuals looking to report potential breaches under its jurisdiction.
The guide is rooted in the existing legislative framework, including the Protection of Persons who Report Breaches of Union and National Law Law of 2022, which was amended in 2024 to align with the EU Whistleblowing Directive. It also incorporates aspects of the Reporting of Actual or Potential Infringements of Regulation (EU) No. 596/2014 to the Cyprus Securities and Exchange Commission Law of 2026 and the CySEC Law of 2009.
Specifically, the guide clarifies the responsibilities of CySEC as the competent authority for receiving and addressing external reports from whistleblowers. It outlines the procedures, timelines, and necessary actions to ensure that reports are managed lawfully and efficiently.
One of the most significant aspects of the guide is its inclusive definition of who qualifies as a reporting person. This includes not only current employees in both public and private sectors but also self-employed individuals, shareholders, and members of supervisory bodies, as well as trainees and volunteers. Notably, former employees are also protected under this framework, regardless of the circumstances surrounding their departure.
CySEC has included a series of illustrative examples to demonstrate how the reporting system functions in practice. For instance, an employee at a Cyprus investment firm might discover that a senior executive is improperly sharing confidential inside information with a relative. If that relative profits from this insider information, it constitutes a breach of EU market abuse rules that could be reported to CySEC.
Another example highlights a board member at an investment firm who becomes aware of senior management submitting false capital adequacy reports. This could represent a serious violation of EU capital requirements and warrants reporting.
The guide extends its provisions to cover trainees and volunteers. For example, a trainee at a law firm may find that an application file contains falsified documents intended to mislead CySEC, a situation that would need to be reported as it could amount to fraud.
In an additional scenario, a volunteer involved in investor education might discover that an investment firm is providing misleading information about high-risk financial products, which is critical for investors’ decision-making. The guide also notes that reports can be made if products are marketed without the necessary regulatory approvals.
Former employees are recognised as potential whistleblowers as well. For instance, a former accounting staff member who uncovers that an investment firm has inaccurately reported its capital and liquidity requirements can submit a report to CySEC. Similarly, a retired risk management executive might learn that questionable practices are persisting within a firm, thereby justifying a report.
Furthermore, job applicants who notice evidence of inadequate safeguards against conflicts of interest during the recruitment process are encouraged to report such findings to CySEC, particularly if it appears that investment decisions are being made to benefit private interests at the expense of clients.
CySEC has stated that further information on whistleblower procedures and mechanisms for reporting can be accessed through their official website, ensuring that individuals understand how to navigate the new guidelines effectively.
