
17 Forms of Whistleblower Retaliation: What CySEC's Guide Means for Cyprus Firms
A new practical guide sets out the external reporting channel for breaches of Union law in financial services. The reporting mechanics are straightforward. The retaliation table at the back is where the real exposure sits.
A whistleblowing policy that prohibits retaliation is a starting point, not a control. The more demanding question is whether a firm's actual practice, the way leave is cancelled, appraisals are written and training places are allocated, would survive scrutiny once someone has made a report.
The CySEC guide gives that question a concrete reference point: a numbered list of what counts as retaliation, and who is protected.
1. What the guide is, and what it is not
The Practical Guide on Reporting Breaches of Union Law sets out the role of the supervisor as the external reporting channel under Law No. 6(I)/2022, which transposes Directive 2019/1937/EU into Cyprus law. It covers who may report, what may be reported, how reports are handled, how personal data is treated, and how reporting persons are protected against retaliation.
The guide does not itself introduce a new regulatory return or filing deadline for supervised firms. It explains CySEC's external reporting function and the protections associated with reporting under the existing legal framework.
Read from the firm's side of the desk, the guide is a statement of what the regulator will accept a report about, who is entitled to make one, and what the firm may not do afterwards. That makes it a map of exposure rather than a piece of administration.
Practical point: The guide is most useful when read alongside HR policies, the appraisal framework and the leave approval process, rather than filed with the reporting procedure and left there.
2. The seventeen forms of retaliation
The guide sets out seventeen numbered categories of retaliation, each with a worked example drawn from financial services. The list is expressly indicative and does not limit the scope of the law, which covers all forms of retaliation. Seventeen is a floor, not a ceiling.
- Suspension, dismissal or equivalent measures
- Demotion
- Withholding of promotion
- Transfer of duties, change of workplace, reduction in wages or change in working hours
- Withholding of training
- Negative performance assessment or employment reference
- A disciplinary measure, reprimand or other penalty, including a financial penalty
- Coercion, intimidation, harassment or ostracism
- Discrimination, disadvantageous or unfair treatment
- Failure to convert a temporary contract into a permanent one, where there was a legitimate expectation of permanent employment
- Failure to renew, or early termination of, a temporary employment contract
- Reputational or financial harm, including harm on social media, loss of business or loss of income
- Blacklisting under an informal or formal sector- or industry-wide arrangement
- Early termination or cancellation of a contract for goods or services
- Cancellation of leave or approval
- Psychiatric or medical referrals
- Unilateral detrimental change of working conditions
The first categories are those most readily associated with whistleblower retaliation: someone speaks up, and loses their job or their rank. That case is well understood, and it is the one a reporting procedure is most likely to have in mind.
Other categories overlap more closely with day-to-day HR and management processes, which is where the harder judgements arise. A separate group, including harassment, blacklisting and reputational attacks, is more overt and less likely to be mistaken for a routine decision.
3. Where routine decisions meet the list
It is worth looking closely at the categories that overlap with day-to-day management.
Withholding of training. In the guide's example, an analyst reports a breach and is then told verbally that his place on a professional development programme has been revoked and the cost will no longer be covered. There is no written reason, and colleagues at a similar level continue to be told about new courses as usual.
Negative performance assessment. Here the example is an employee whose annual appraisal cites general "difficulties in cooperation", with no specific incidents, no documentation and no prior warning. He is given no opportunity to respond, and the rating affects his bonus and progression.
Cancellation of leave. The example is an employee whose summer leave had been provisionally approved months earlier under the department's annual schedule. Days before it was due to start, management cancels it, citing "operational needs", without documenting any emergency or need for cover, while colleagues with similar duties take their leave as normal.
Psychiatric or medical referrals. This one is less routine. The example is an employee asked to undergo a psychiatric evaluation on the basis of "unusual behaviour" and "signs of stress", with no prior report from a superior or occupational physician, no written documentation and no consent, accompanied by a suspension of duties "for security reasons". The guide describes the particular measure in this example as an attempt to undermine the reporting person's credibility and place them under psychological pressure.
Not every action falling within these categories is automatically retaliatory. A firm may, for example, alter a training budget, issue a critical appraisal or cancel leave for legitimate reasons. Other conduct may also be unlawful on separate grounds. For whistleblowing purposes, the central question is whether the action was prompted by the report or public disclosure and caused, or could cause, unjustified detriment in a work-related context.
If the decision is later disputed, the firm's position will depend in part on the evidence showing why it was taken. A leave cancellation supported by a documented operational need and applied consistently may be easier to justify. Documentation does not determine the legal result by itself, but it can materially affect the firm's ability to establish its reasons.
Practical conclusion: The evidential trail carries real weight. Undocumented appraisals, informal training decisions and verbal leave cancellations are the weak points, because they leave the firm unable to show why a decision was made if it is later questioned.
4. How the burden of proof actually works
The burden-of-proof rule comes from Law 6(I)/2022 rather than from the CySEC guide itself. The reporting person must establish that they made a report or public disclosure protected by the law and suffered harm. The harm is then presumed to have resulted from retaliation unless the person who took the measure demonstrates that it was based on duly justified grounds.
The sequence is not "report made, therefore every later decision is presumed unlawful". A protected report or public disclosure, together with harm, gives rise to the statutory presumption. The person who took the measure must then demonstrate that it was based on duly justified grounds. Contemporaneous records can help establish those grounds, but documentation is evidence rather than the legal test itself.
5. Protection reaches beyond the person who reported
Protection does not attach only to the reporting person. It can also reach:
- Facilitators, meaning a person who provided support to the reporting person during the reporting process, which can include an external legal adviser or compliance specialist who guided them.
- Connected third persons who could suffer retaliation in a work-related context. The guide expressly names colleagues and relatives, by blood or affinity, up to the fourth degree.
- Legal entities that the reporting person owns, works for, or is otherwise connected with in a work-related context.
Fourth degree is a wide net, reaching well beyond the immediate family.
The guide illustrates the point with an example worth pausing on. An employee at an investment firm reports failures in the handling of client orders and non-compliance with best execution. Some weeks later, the firm transfers the reporting person's wife, an administrative employee at the same firm, from Nicosia to a branch in another city. She had not asked for the transfer. She is stripped of her administrative responsibilities, moved to afternoon shifts, and has her salary reduced on grounds of "organisational restructuring". She had no negative appraisals and there had been no prior indication of any such change. The guide treats this as retaliation against the person who reported, carried out through a relative.
The guide gives two separate facilitator examples. In one, a facilitator helps an employee document and submit a report; afterwards the company excludes the facilitator from new client lists, stops assigning work, and no longer invites the facilitator to professional meetings or product presentations. In the other, a facilitator who owns a financial-advisory sole proprietorship reports a breach, and the company then spreads negative and false comments about the business on social media and terminates the commercial relationship, causing reputational and financial harm. The two illustrate different points, protection of a supporter and protection of a connected legal entity, and are not the same scenario.
Practical point: Once a report is made, the firm's exposure is not limited to how it treats the reporter. The firm's review should also consider adverse action involving identifiable facilitators, protected connected third persons and legal entities that fall within the statutory connection to the reporting person.
6. Who is entitled to report
The personal scope includes several categories that should be considered in the firm's procedure:
- Employees in the public and private sectors, in salaried and non-salaried work
- Shareholders, and persons belonging to the administrative, management or supervisory body of an undertaking, including non-executive members
- Volunteers
- Paid and unpaid trainees
- Employees under the supervision of contractors, subcontractors and suppliers
- Former employees, regardless of how the working relationship ended, including those who were dismissed and those who have retired
- Prospective employees
Three categories have particularly broad practical implications.
Non-executive directors. The guide's example is a board member who identifies that senior management is systematically failing to submit accurate capital adequacy reports and is concealing material information. He may report externally.
Former employees. The example includes a retiree who learns from former colleagues that practices under internal investigation during his tenure are still running and still unaddressed. He no longer works there, and he may still report.
Prospective employees. Here the example is a candidate in a recruitment process at an asset management company who discovers, through internal documents or conversations, that the firm has inadequate measures to prevent conflicts of interest. He does not work there and may never do so, and he may report. A second recruitment example is sharper: during an interview for a compliance role at an AIFM, the candidate is told that the firm avoids reporting certain conflicts of interest to the regulator, and that this is "standard practice in the industry". The candidate may report.
Practical point: The recruitment process is part of the reporting risk surface. What is said in interviews, and what candidates see in documents shared during a process, can be reported externally by someone who never joins the firm.
7. The twenty-two breach categories
The guide also sets out, in one place, every category of breach that falls within the supervisor's competence as an external reporting channel. There are twenty-two, each with a description of the applicable obligations and worked examples of what a reportable breach looks like. They span:
- Alternative investment fund managers (AIFMD)
- Short selling and credit default swaps (Regulation 236/2012)
- European venture capital funds (EuVECA, Regulation 345/2013)
- European social entrepreneurship funds (EuSEF, Regulation 346/2013)
- Markets in financial instruments (MiFIR, Regulation 600/2014)
- Public takeover bids (Directive 2004/25/EC)
- Shareholder rights in listed companies (Directive 2007/36/EC)
- Transparency obligations for issuers (Directive 2004/109/EC)
- OTC derivatives, central counterparties and trade repositories (EMIR)
- Benchmarks (Regulation 2016/1011)
- Recovery and resolution (BRRD)
- Investor compensation schemes
- Prudential requirements (CRR, Regulation 575/2013)
- Crowdfunding service providers (Regulation 2020/1503)
- UCITS (Directive 2009/65/EC)
- Market abuse (MAR, Regulation 596/2014)
- Access to the activity of credit institutions (CRD IV)
- Markets in financial instruments (MiFID II, Directive 2014/65/EU)
- Securities settlement and central securities depositories (CSDR)
- Key information documents (PRIIPs, Regulation 1286/2014)
- Transparency of securities financing transactions (Regulation 2015/2365)
- Prospectus requirements (Regulation 2017/1129)
The worked examples are the practical part. Under MiFID II, the guide describes sales managers pressuring investment advisers to market high-risk products without carrying out the required suitability assessment. Under MiFIR, a trainee notices that certain OTC derivatives are being left out of daily transaction reports on an informal instruction to "omit small-volume transactions for convenience". Under MAR, an employee observes that transaction order details are being modified without adequate documentation, and that subcontractors have access to confidential information without confidentiality commitments.
These are indicative examples rather than identified enforcement cases. Their value is that they translate broad legal categories into recognisable conduct.
Practical point: Cross the twenty-two categories against the firm's own regulated activities and read the worked examples for the ones that apply. This is a useful checklist of the matters falling within CySEC's competence as an external reporting channel. The guide does not state that the categories or their ordering represent current supervisory priorities.
8. The procedural timelines
The handling process is defined and time-bound.
There is no specific deadline for reporting. A report may be made at any time after the person becomes aware of the breach, provided that, at the time of reporting, the person had reasonable grounds to believe that the information was true and fell within the law's scope. A report may be made by name or anonymously, and submitted by telephone, by email, by post marked confidential, or by an arranged personal meeting.
Once a report is received, the supervisor normally confirms receipt within seven days and informs the reporting person of the timeframe in which they will receive information on the outcome. Confirmation is not sent where the reporting person has asked for something different, or where sending it might jeopardise the protection of their identity.
The follow-up process may not exceed three months, extended to six months in specially justified cases. During that period the supervisor may refer the report to another competent authority, request further information, or take corrective measures and impose sanctions.
On personal data, the reporting person's identity is kept confidential and is not disclosed without consent, subject to two exceptions: where disclosure is required by a mandatory provision of law or judicial procedure, or where disclosure is necessary for the investigation, in which case CySEC informs the reporting person in a timely manner unless doing so would conflict with the public interest or adversely affect the investigation. Personal data is normally deleted within three months after the procedure is completed. Where judicial or disciplinary proceedings have begun, the data is retained throughout those proceedings, including any appeal or objection, and is deleted one year after their completion.
One limit is worth noting. Acting as an external reporting channel, the supervisor states that it has no authority to remedy damage suffered as a result of retaliation. On request from a competent administrative or judicial authority, it will provide evidence and documents, but the remedy itself is pursued elsewhere.
9. What a compliance officer can do with this
The compliance officer does not run HR. You do not approve leave, write appraisals, or decide who is sent on a course, whose temporary contract is renewed, or who is moved between offices. Yet once a report is made, each of those decisions can become a regulatory exposure that eventually lands with compliance.
Several practical steps follow from the guide. These are risk-management recommendations rather than measures expressly prescribed by CySEC.
Map the seventeen categories against actual HR practice, not just against the policy wording. What matters is whether leave cancellations, withdrawn training places and appraisal ratings are documented well enough that the reason for each could be explained a year later.
Put a trigger in place. When an internal report is received, or when the firm learns that an external report has been made, adverse HR actions affecting the reporting person or another identifiable protected person are worth routing through a documented review. The aim is not to freeze ordinary decisions, but to record why they were taken.
Review the policy to determine whether it covers facilitators, connected third persons and protected legal entities. Where those categories are in scope under the law, the policy should reflect them.
Bring recruitment into the picture. If prospective employees are protected reporting persons, then what is said in interviews and what candidates see in documents shared during a process are both part of the exposure. That is a conversation worth having with whoever runs hiring.
Practical conclusion: A compliant policy is necessary, but it is not sufficient. The firm's ordinary management and HR processes must also produce a reliable record showing why potentially adverse decisions were made.
10. In short
Whistleblowing frameworks are often approached primarily as reporting procedures: where a report goes, who receives it and how quickly it must be acknowledged. The guide answers those questions clearly.
Its retaliation section extends the analysis into employment, management and commercial decision-making. The seventeen categories show how decisions involving training, appraisal, leave, contracts, reputation and connected persons may fall within the protection framework when they are prompted by reporting and cause, or may cause, unjustified detriment.
Know what supervisors are looking for. Our seminars are built around what supervisors actually examine and what enforcement decisions actually say, not just what the legislation states on paper.
Explore seminars at cpds.academy
Source: Practical Guide on Reporting Breaches of Union Law, Cyprus Securities and Exchange Commission. The burden-of-proof explanation is based on section 23 of Law 6(I)/2022. The guide describes its worked scenarios as indicative examples rather than identified enforcement cases.
This article is provided for educational purposes and does not constitute legal advice. Firms should assess their own obligations against the applicable legal framework and take professional advice where required.

Article by Nikolas Demetriades
Published 16 Jul 2026