On 14 July 2026, the Cyprus Securities and Exchange Commission (“CySEC”) announced the publication of a Practical Guide to facilitate the application of Circular C608 and the Protection of Persons who Report Breaches of Union and National Law of 2022 (Law 6(I)/2022), as amended.
The Guide provides practical guidance on the external reporting of breaches of Union law within the financial sector and is intended to facilitate the effective implementation of Cyprus’ whistleblowing framework.
The publication provides greater clarity on how the external reporting framework operates in practice, including the reporting process, the categories of reportable breaches and the protections available to reporting persons.
What is the Purpose of the Practical Guide?
The Guide explains CySEC’s role as the competent external reporting authority for financial services matters and sets out the procedures for receiving, assessing and following up on reports of breaches falling within its supervisory remit.
It also sets out the applicable timelines, responsibilities and procedures designed to ensure that reports are handled lawfully and efficiently.
Who Can Submit a Report?
The Guide confirms that the external reporting framework applies to a broad range of individuals who obtain information on breaches in a work-related context. Subject to the requirements of the Law, this includes:
- employees;
- members of Boards of Directors;
- shareholders;
- volunteers;
- trainees;
- contractors and subcontractors;
- former employees; and
- prospective employees who become aware of potential breaches during the recruitment process.
The Guide confirms that eligibility to submit an external report extends beyond current employees and applies to a broad range of individuals connected with an organisation in a work-related context.
What Types of Breaches Fall Within CySEC’s Competence?
A particularly valuable feature of the Practical Guide is the extensive collection of practical examples illustrating the types of breaches that may be reported.
CySEC explains how the framework applies in real-world situations across numerous areas of financial regulation.
Examples include potential breaches relating to:
- MiFID II / MiFIR;
- Market Abuse Regulation (MAR);
- AIFMD;
- EMIR;
- Short Selling Regulation;
- Benchmark Regulation;
- Transparency Directive;
- Takeover Bids;
- Shareholder Rights;
- Recovery and Resolution of Investment Firms;
- Investor Compensation Fund requirements; and
- other breaches of EU law within CySEC’s supervisory responsibilities.
The practical examples may also assist regulated entities in better understanding the types of regulatory breaches that could give rise to external reports.
Protection of Reporting Persons
The Guide also explains the key protections available to reporting persons, including:
- confidentiality of the reporting process;
- protection of personal data and
- protection against retaliation.
Practical Considerations for Regulated Entities
Although the Guide is primarily intended for potential reporting persons, it is also relevant for Cyprus Investment Firms and other regulated entities. The Guide contains numerous practical examples involving investment firms and clarifies the types of regulatory breaches that may be reported to CySEC, the categories of persons who may submit reports and the procedures followed by CySEC in handling external reports. As such, it provides regulated entities with greater transparency regarding the operation of CySEC’s external reporting framework.
Key Takeaway
The publication of the Practical Guide complements Circular C608 by providing practical clarification on the operation of CySEC’s external reporting framework. Although it does not introduce new legal or regulatory obligations, it serves as a useful reference for understanding the external whistleblowing process, the categories of reportable breaches and the protections available to reporting persons.
