<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data protection - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/data-protection/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 18:08:51 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 18:04:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Advertising Law]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Markets Act]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DMA]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[eu regulation]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[influencer marketing]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[new technologies]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland business law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[social commerce]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[TikTok Shop]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8857</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 24, 2026</mark></strong></p>



<figure class="wp-block-video"><video autoplay controls loop src="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4"></video></figure>



<p>You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a <em>closed-loop</em> model in which the path from watching a piece of content to completing a purchase has been cut to the bare minimum. That very immediacy is its greatest strength and, at the same time, the source of its most serious concerns.</p>



<span id="more-8857"></span>



<p id="ember53">A platform that in 2017 drew around 72 million monthly users now attracts more than 1.5 billion — and between 11 and 15 million in Poland alone. TikTok has stopped being merely a place for entertainment and has turned into a powerful advertising and sales engine, combining influencer marketing, algorithmic personalization, and the emotional purchasing impulse. For businesses, it is a new and remarkably effective retail space. For consumers, it is an environment in which it grows ever harder to tell an authentic recommendation from an ad, or a fleeting enthusiasm from a considered decision.</p>



<p id="ember54">That is precisely why TikTok Shop has landed at the center of lawmakers&#8217; attention. While its model is not unlawful, the platform&#8217;s operation intersects with an entire web of regulation: from consumer law and the ban on &#8220;dark patterns,&#8221; through the EU&#8217;s DSA and DMA, data protection and safeguards for minors, all the way to advertising, media, and electronic communications law. This article shows where the convenience of one-tap shopping ends and the protection of the buyer&#8217;s free will begins.</p>



<h2 class="wp-block-heading" id="ember55">What makes the TikTok Shop platform innovative?</h2>



<p id="ember56">Today, an effective marketing strategy is becoming an increasingly important priority for sellers. In Poland, monopolies in sales are relatively rare. Many competing companies operate in most industries. When purchasing products, consumers must choose from hundreds, or even thousands, of options offered by different brands. The scale of this phenomenon is evidenced by the fact that in the fourth quarter of 2025, over 2.9 million active businesses operated in Poland alone, the largest group of which were those associated with the retail sector. Meanwhile, buyers generally do not want to spend much time thoroughly analyzing goods available on the market. They are often guided by the opinions of other users, brand recognition, or media coverage. Therefore, in an information society based on the dynamic development of social media, tailoring advertising to current consumer needs and behaviors becomes crucial for running a business. Authentic and credible recommendations from trusted creators are becoming more important, and for many buyers, they are more persuasive than formulaic television commercials.</p>



<p id="ember57">Considering the above arguments, many companies are making changes to their advertising strategies, for example, opting for influencer marketing. Online creators typically publish aesthetically and thematically consistent content that captures the interest of users with similar preferences and tastes. A business partnering with an influencer who shares similar values gains the opportunity to reach a large group of potential consumers, made up of the influencer&#8217;s followers. TikTok has become the dominant platform enabling the implementation of the marketing model described above. In 2017, the application had approximately 72 million monthly active users, and according to data from 2026, this number has increased to approximately 1.54 billion. In Europe alone, TikTok has already reached over 200 million users, and in Poland, the number ranged from 11 to 15 million. The average time spent on the platform is 70 minutes per day, which translates to approximately 35 hours per month. These statistics also indicate the continued growth of TikTok&#8217;s popularity, confirming the future of using social media for advertising and promotional purposes.</p>



<p id="ember58">The development of influencer marketing significantly changed existing marketing practices, and its increasing prevalence led to the transformation of the TikTok app from a social media platform into an advertising system. The effective and profitable collaboration between media and advertising prompted the platform to take the next step in its development, combining these two sectors. Users were offered the opportunity to completely simplify the purchasing process. Previously, consumers only saw product advertisements, which attracted their attention and prompted them to search for sales offers. However, this pattern left them time to consider whether a purchase was truly necessary or necessary. It was also likely that, despite their interest in the product, they would eventually forget about the advertised product, and therefore their desire to purchase it.</p>



<p id="ember59">The solution to the marketing strategy described above turned out to be a new feature presented by TikTok: TikTok Shop. The innovative nature of this tool is based on a closed-loop model, meaning the purchasing process takes place within a single app. Users first encounter content promoting a specific item. They then have the option to immediately purchase it by adding the advertised item to their shopping cart in the bottom corner of the app. TikTok acts as an intermediary for payment, shipping, and the entire order process. In this way, the app has evolved not only into a profitable advertising system but also an online store, becoming a marketplace platform that mediates payment, logistics, and order fulfillment.</p>



<h2 class="wp-block-heading" id="ember60">The origins of TikTok Shop</h2>



<p id="ember61">Initially, the online shopping phenomenon developed through e-commerce. Its popularity contributed to the diversification of online sales into several business models: B2C, B2B, and C2C. The former involves a relationship between a business and an individual customer (examples include online stores such as Zalando, Zara, and IKEA). B2B refers to transactions between businesses, while C2C refers to sales between individuals, such as on platforms like Vinted, OLX, and Allegro.</p>



<p id="ember62">These e-commerce models typically control the sales process independently. Their profits largely come from consumers who shop by searching for specific products they need. Entrepreneurs compete with each other through marketing activities aimed at convincing consumers of the quality of their products and building brand recognition.</p>



<p id="ember63">In the next stage, the development of social media, and consequently influencer marketing, contributed to the emergence of a completely new type of buyer, one driven by impulse. Online creators present a specific lifestyle on their profiles in a significantly idealized form, which attracts the attention of their followers and becomes a role model. The desire to emulate the creator they follow can manifest itself both in their behavior and in the possessions they possess. The influencer thus becomes a person who inspires and encourages the purchase of a given product. Even if, from a rational perspective, the buyer doesn&#8217;t need the product, they often decide to purchase it under the influence of influencer marketing.</p>



<p id="ember64">Additionally, a new branch of e-commerce has emerged, known as discovery commerce . This model relies on the discovery and purchase of new items while actively browsing social media. Highly advanced algorithms select content for users that aligns with their tastes or interests, in order to evoke certain emotions that then transform into a strong purchasing impulse. Social media platforms, recognizing this profitable sector, have contributed to the development of social commerce, including TikTok Shop. This solution capitalizes on users&#8217; fleeting enthusiasm and allows them to complete their order without leaving the app. The entire process, from advertising content to payment and shipping, is handled by TikTok, which can limit the time available for rational purchase consideration.</p>



<h2 class="wp-block-heading" id="ember65">What exactly does the purchasing process look like on TikTok Shop?</h2>



<p id="ember66">TikTok Shop is not a separate app, but a new feature added to the TikTok platform. There&#8217;s no need to create a new account or install a new app. This solution provides access to a wide group of potential consumers, as every existing TikTok user over the age of 18 can familiarize themselves with the new feature. This solution gives businesses multiple ways to reach consumers. The platform offers a separate tab, &#8220;Shop,&#8221; where users can search for specific products using filters and categories, or browse recommended items based on their activity on the platform.</p>



<p id="ember67">Products offered by sellers using the TikTok Shop service can also be viewed on the &#8220;For You Page&#8221; tab. This is the subpage most frequently visited by users. This option is especially useful when a company decides to use influencer marketing. A creator posts a video promoting a selected product, and buyers are immediately presented with a purchase button at the bottom of the page. Consumers can also directly access the profiles of brands and creators to find the products they offer or promote.</p>



<p id="ember68">The latest feature, TikTok Live, is gaining popularity. Before the live stream begins, the seller or influencer adds products available in the TikTok Shop. During the live stream, the host can showcase products, communicate with users, and answer their questions via chat. This can increase the credibility of the product and the seller, as well as encourage consumers to make a purchase, which they can do without interrupting the stream.</p>



<p id="ember69">The very process of posting ads on TikTok Shop helps build consumer trust. Becoming a seller requires thorough verification, which the TikTok platform conducts to protect users from unreliable and fictitious businesses.</p>



<p id="ember70">The first step to becoming a seller is to log in to your TikTok Seller Center account using your email address, phone number, or existing TikTok account. You&#8217;ll also need to fill out an application form with information that proves your seller credentials, such as your company name, address, and contact information.</p>



<p id="ember71">After successful verification, the seller completes their store profile, adding a description, name, logo, seller details, addresses, customer service information, and tax information. It&#8217;s also necessary to configure payment and delivery methods, including the shipping address, available delivery methods, order processing time, and return policy. Connecting the store dashboard to a regular TikTok account is also crucial. This allows for tagging offered products in live videos, etc. The seller then has the option to publish their product, including the title, description, price, available models, and inventory. The platform also allows businesses to add listings by importing a product catalog from another sales platform.</p>



<p id="ember72">After a consumer makes a purchase, the seller receives a sale notification in the TikTok Seller Center. The seller is then responsible for packaging and shipping the item to the user, which can be done manually or using external order processing systems.</p>



<h2 class="wp-block-heading" id="ember73">Distance selling and consumer rights</h2>



<p id="ember74">The TikTok Shop platform offers the option of concluding a sale via a distance contract. This does not require the parties to be physically present at the same time, but rather requires at least one means of distance communication (Act of 30 May 2014 on consumer rights, Article 2). Therefore, when making a purchase through the TikTok Shop, consumer rights are governed by national and European Union law.</p>



<p id="ember75">In Poland, the primary legal act regulating these activities is the Act of May 30, 2014, on Consumer Rights. Article 12 requires businesses to clearly inform consumers in distance contracts, including the method and deadline for contract execution, the total price including taxes, the right to withdraw from the contract, the complaint procedure, and the seller&#8217;s identifying information. The TikTok Shop platform is therefore obligated to provide the required information to the user before finalizing the order via the app. An important regulation is also included in Article 17 of the aforementioned Act and concerns the requirement to design the interface in a way that confirms the consumer&#8217;s awareness of the obligation to pay. In the case of platforms that allow order completion via a &#8220;button,&#8221; it must be clearly marked, e.g., &#8220;I buy with an obligation to pay&#8221; or &#8220;I buy and pay.&#8221; Otherwise, the contract is not concluded. The requirements described above are referred to as &#8221; button &#8221; solution &#8221; and are intended to protect consumers from accidentally concluding paid contracts. Alternative obligations also arise from the Directive of the European Parliament and of the Council of 25 October 2011 on consumer rights.</p>



<p id="ember76">The Consumer Rights Act also implements the EU Commodity Directive (2019/771), introducing uniform standards for the conformity of goods with the contract. A trader is liable for any lack of conformity of goods with the contract upon delivery and for two years from the date the discrepancy is discovered. The Act also governs basic consumer claims in the event of non-conformity, including repair or replacement of the goods, and if this is not possible, a price reduction or withdrawal from the contract.</p>



<p id="ember77">Given that the sales strategy on the TikTok Shop platform relies on recommendation algorithms and influencer marketing, the Omnibus Directive (EU) 2019/2161 of November 27, 2019, plays a significant role in consumer empowerment. Its regulations introduce the obligation to provide information about the lowest price, disclose whether reviews were published by verified consumers, and indicate whether the seller is a business or an individual. The Omnibus Directive therefore increases consumer awareness and allows consumers to make more rational and manipulation-free purchasing decisions.</p>



<h2 class="wp-block-heading" id="ember78">Digital Services Act Regulation</h2>



<p id="ember79">Due to their global nature, online platforms reach hundreds of millions of users. Content published through them can reach a very wide audience, thus influencing social, political, and economic relations. Massive social networking sites, therefore, go beyond simply providing entertainment or communication services and digital space, and are beginning to shape the reality around us.</p>



<p id="ember80">The strong influence of individual platforms on current international relations has initiated more stringent oversight, including through the provisions of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act &#8211; DSA). Based on this regulation, TikTok was recognized by the European Commission as a Very Large Online Platform (VLOP). This status is granted to portals with monthly active users exceeding 10% of the EU population. TikTok exceeded the threshold and was classified as a VLOP in 2023.</p>



<p id="ember81">Platforms deemed globally influential are not solely responsible for removing illegal content. They are also required to counteract the negative consequences that may arise from their operation. Among the most important responsibilities of very large online platforms (VLOPs) is the identification and assessment of systemic risks and the potential implementation of proportionate mitigation measures. Impacts on fundamental rights, democratic processes, the protection of minors, public safety, and the dissemination of illegal content are particularly scrutinized. Once a specific risk is identified, measures are planned to counteract its escalation, such as modifying the user interface or changing certain advertising practices. In emergency situations, the European Commission has the authority to require VLOP providers to assess the platform&#8217;s impact on the development of the crisis, implement specific mitigation measures, and submit periodic reports on the effectiveness of these actions. Very large online platforms are also required to undergo an annual independent audit of compliance with the Digital Services Act (DSA) and regularly publish comprehensive reports on their activities. The aim of this action is to ensure transparency of the platform&#8217;s operation towards users and supervisory authorities.</p>



<p id="ember82">The DSA also regulates advertising by introducing the requirement to maintain a public ad repository. This repository should include, among other things, the ad&#8217;s content, advertiser, funding entity, broadcast time, and the number of recipients. This solution is intended to ensure transparency in advertising messages and enable social and scientific analysis of platforms&#8217; promotional activities. Restrictions have also been imposed on recommendation systems. This means that VLOPs are required to provide users with at least one way to display content that is not based on profiling, meaning it does not use user activity history or data. To monitor platforms&#8217; compliance with the EU regulation, it is also possible to impose a requirement to share data on, for example, the performance of recommendation algorithms with the European Commission, national digital service coordinators, or verified researchers.</p>



<p id="ember83">TikTok, however, is not subject only to the obligations of very large online platforms. It is subject to all regulations provided for in the Digital Services Act. According to Article 26, each advertisement must be clearly identified as promotional material and indicate the advertiser, the funding entity, and the mechanism by which it was tailored to the user. This restriction is particularly useful for the TikTok Shop platform, where sponsored content is commonly created in the manner of regular content published by creators. Limiting the phenomenon of so-called hidden advertising through the provisions described above aims to increase user awareness.</p>



<p id="ember84">One of the DSA&#8217;s key goals is also the protection of minors. When designing their services, platforms are required to consider a high level of protection for minors and their privacy. It is prohibited to display advertisements based on the profiling of minors when the platform has knowledge of the user&#8217;s minor status. The goal is to limit the use of children&#8217;s data for marketing purposes and reduce the risk of addictive use of the app.</p>



<p id="ember85">The European Commission has also become concerned about potential negative consumer behavior resulting from the increasing transformation of large social media platforms into e-commerce portals. Complex profiling algorithms, influencer marketing, and instant purchases can encourage users to make impulsive decisions or even become dependent on purchasing processes. Articles 25 and 27 of the Consumer Protection Act (DSA) mitigate this risk. Designing web interfaces that manipulate or complicate consumer decision-making &#8211; so-called dark patterns &#8211; is prohibited. Examples of unacceptable solutions include hiding options that are less favorable to the business, making it difficult to unsubscribe from services, or designing buttons that encourage a specific choice. Users should also be fully aware of how the recommendation system works; therefore, platforms are required to clearly present its main parameters and the possibility of changing the content suggestion method.</p>



<h2 class="wp-block-heading" id="ember86">Tamper protection and dark patterns</h2>



<p id="ember87">A key premise of the TikTok Shop platform is the immediacy of purchases. While this solution is very beneficial for businesses and, typically, consumers, it can lead to abuse. Sales without leaving the app, a simplified order completion process, and algorithmic personalization of recommended products seem to provide greater convenience when shopping online. However, some activities can be classified as &#8221; dark patterns&#8221;, manipulations used to mislead users and influence their decisions. Because the practices described above can lead to impulsive behavior and distort consumer will, they may be treated as unfair market practices and subject to criminal penalties.</p>



<p id="ember88">The Act of 23 August 2007 on Counteracting Unfair Market Practices defines an unfair market practice as a sale that is contrary to good practice and significantly distorts or may distort the market behavior of the average consumer before, during or after the conclusion of a product agreement , in particular a misleading market practice and an aggressive market practice (Act of 23 August 2007 on Counteracting Unfair Market Practices, Article 4). The main grounds for considering a market practice misleading include the dissemination of false information or truthful information in a potentially misleading manner. Such misleading information typically concerns the existence of a product, its type or availability, price, the method of price calculation, or the existence of a special price advantage.</p>



<p id="ember89">To encourage immediate purchases, sellers pressure buyers with messages suggesting limited availability or a limited-time promotion for a specific product. Examples of such messages include phrases like &#8220;100 people are viewing the product,&#8221; &#8220;offer ends in 2 hours,&#8221; or &#8220;only 4 items left.&#8221; This practice is not illegal and is one of the most common marketing mechanisms. Problems arise when the website or portal is programmed to continually extend promotions, the offer doesn&#8217;t actually expire after the specified date, or the counter restarts upon page refresh.</p>



<p id="ember90">Misleading practices, such as suggesting the limited nature of a permanently available offer, and aggressive practices, such as exerting time pressure, may result in legal consequences. In addition to the aforementioned Act of 23 August 2007 on Combating Unfair Commercial Practices, this issue is also regulated by Directive 2005/29/EC concerning unfair business-to-consumer commercial practices in the internal market. This directive distinguishes between misleading commercial practices and aggressive commercial practices. Together, they constitute unfair commercial practices, which include, in particular, actions that are contrary to the requirements of professional diligence and that significantly distort or are likely to significantly distort the economic behavior of the average consumer who reaches or is targeted by the practice, or the average member of a group of consumers if the commercial practice is targeted at a specific group of consumers (Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (&#8220;Unfair Commercial Practices Directive&#8221;), Chapter 2, Article 5, paragraph 2).</p>



<p id="ember91">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 (Omnibus Directive) is also intended to combat various manifestations of the &#8220;dark patterns&#8221; phenomenon. It requires sellers to disclose the lowest price for a product within the last 30 days. This is intended to prevent the practice of artificially inflating prices and then announcing sales. The practice of fake reviews has also been curbed by introducing an obligation to disclose whether and how reviews posted on sales websites are verified. The Omnibus Directive also introduced the requirement to indicate on marketplace platforms whether the seller is a private individual or a professional entrepreneur, so that consumers are aware of who they are buying from.</p>



<p id="ember92">The European Union has also introduced restrictions related to the design of digital services, contained in Regulation 2022/2065 on the Digital Single Market (DSA). As a result, online platform providers cannot design, organize, or operate their online interfaces in a way that misleads, manipulates, or otherwise interferes with or limits the ability of service users to make free and informed decisions. The regulation therefore directly addresses the fight against &#8220;dark patterns,&#8221; i.e., website design practices that deliberately use deceptive techniques, such as pre-selected consents or difficult unsubscribes.</p>



<p id="ember93">The President of the Office of Competition and Consumer Protection (UOKiK) has broad authority to protect consumers from the unfair commercial practices mentioned above. Under the Act of 16 February 2007 on Competition and Consumer Protection, one of his powers is to protect the collective interests of consumers, including through provisions counteracting unfair market practices. If necessary, the UOKiK President may initiate proceedings against a business, ordering it to cease the unfair practice, or requiring the seller to remedy the effects of the violation. Should a business fail to comply with the guidelines, he may impose a fine of up to 10% of the business&#8217;s turnover in the previous year.</p>



<p id="ember94">The number of legal acts, including EU documents, regulating unfair commercial practices reflects the considerable interest in this issue among both legislators and consumer protection authorities. TikTok Shop, as a social commerce model, is not illegal. It utilizes mechanisms combining influencer marketing, personalization, and emotional impact on the recipient, but the design of the user interface is crucial for this platform. The popularity of mass sales portals has contributed to the increasing use of &#8220;dark patterns&#8221; by businesses over the past few years. For this reason, the European Union and the Office of Competition and Consumer Protection (UOKiK) are increasingly rigorously monitoring sales tactics and issuing new legal acts to protect consumers and their free will when making purchases.</p>



<h2 class="wp-block-heading" id="ember95">Influencer Marketing and Advertising Law</h2>



<p id="ember96">The effectiveness of influencer marketing stems from combining advertising with the ability to make an immediate purchase. Affiliate links, product tags, or direct purchase buttons, such as those on the TikTok Shop platform, are displayed beneath posts, videos, or other promotional materials. This purchasing model has proven effective by significantly simplifying the ordering process, thus reducing the time consumers spend considering the rationale behind the transaction.</p>



<p id="ember97">The popularity of the marketing strategy described above stems from its perception by users, who perceive it as authentic and credible. Influencers present promoted products in a natural way, integrating them into their daily routine. However, if the material does not solely reflect the creator&#8217;s personal opinion but is created after receiving a benefit in return, it is considered commercial communication. This means it is subject to legal regulations on advertising and consumer protection. In Poland, influencers should clearly label advertising content in accordance with the Recommendations of the President of the Office of Competition and Consumer Protection. These regulations are intended to prevent misleading users.</p>



<p id="ember98">Only content regarding a product that the influencer purchased independently and for which they did not receive remuneration or other benefits can be marked as a private opinion. Such material contains genuine feelings and opinions and therefore does not constitute advertising under the law and is not subject to advertising law. This is the most credible and reliable form of review for potential consumers, as it was created by a person not under any obligation to the manufacturer.</p>



<p id="ember99">A manufacturer may enter into an agreement with an influencer to promote a product in exchange for a free product, financial benefit, or other form of remuneration. This creates legally regulated advertising. It may take the form of a post, report, or live broadcast in which the creator demonstrates how they use the product and its positive properties. Due to the natural presentation of the product as an everyday element, the recipient may have difficulty distinguishing a genuine recommendation from commercial content. The Act of August 23, 2007, on Counteracting Unfair Market Practices, classifies the act of concealing a promotional message as a misleading omission. Failure to clearly indicate the commercial nature of the material may hinder consumers&#8217; proper assessment of the message and directly influence their purchasing decisions.</p>



<p id="ember100">Another common advertising strategy is to feature a product integrated into published content without directly promoting it, for example, by placing it in the background of the material. This phenomenon is called product placement. Activities covered by advertising and consumer protection law also include, among others, affiliate and partner links, ambassador programs, and partner competitions. In Poland, these practices must contain clear, understandable to the average recipient, and visible advertising labels from the very beginning, such as &#8220;advertisement,&#8221; &#8220;paid collaboration,&#8221; or &#8220;sponsored content.&#8221; The Office of Competition and Consumer Protection (UOKiK) also recommends the use of two-level labeling, meaning that, in addition to the information contained in the content, the platform&#8217;s functionality must also be used to announce the paid collaboration. Detailed guidelines can be found in the Recommendations of the President of the UOKiK regarding the labeling of advertising content by influencers. Material is considered advertising content not only when the influencer receives monetary compensation in exchange for its creation. The same obligation applies when promoting your own business, receiving a free product or service, or obtaining a sales commission via an affiliate link or discount code (Recommendations of the President of the Office of Competition and Consumer Protection regarding the marking of advertising content by influencers).</p>



<p id="ember101">In the event of non-compliance with the Recommendations of the President of the Office of Competition and Consumer Protection regarding the labeling of advertising content by influencers, pursuant to the Act of 16 February 2007 on Competition and Consumer Protection, the Office of Competition and Consumer Protection (UOKiK) conducts proceedings against entrepreneurs using practices that violate the collective interests of consumers. Actions may be taken against advertisers, influencers, and marketing agencies. Therefore, responsibility for incorrect labeling of advertising content rests not only with the creator publishing the material but also with all entities participating in organizing the promotional campaign. One of the sanctions that the President of the UOKiK has the right to impose is a financial penalty. Incorrectly labeled promotional material can also be considered surreptitious advertising. Due to the dynamic development of influencer marketing, the proper creation of marketing content is currently widely subject to UOKiK scrutiny. Therefore, it is worth clearly and understandably labeling sponsored publications, among other things, to avoid significant financial penalties.</p>



<h2 class="wp-block-heading" id="ember102">Personal data protection</h2>



<p id="ember103">TikTok Shop, as a hybrid social network and e-commerce platform, processes a significant amount of data related to both user activity and purchasing processes. The app&#8217;s operation is based on audience profiling and matching the most relevant content. Therefore, the platform&#8217;s operations are subject to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).</p>



<p id="ember104">In addition to user data such as name, surname, contact details, shipping addresses, and payment information, media platforms also collect information that allows for behavioral analysis. Time spent browsing specific products, interactions with ads, and the history of items added to carts or wish lists allow the TikTok Shop platform to create a personalized recommendation system based on past activity. This phenomenon creates so-called behavioral advertising, a marketing strategy based on user profiling using advanced algorithms to predict future purchasing decisions. The concept of profiling refers to the automated processing of personal data, particularly for the purpose of predicting a user&#8217;s economic situation, personal preferences, interests, health, and location.</p>



<p id="ember105">According to the GDPR, profiling is permissible, but it also comes with a number of obligations. Platforms are obligated to transparently inform users about, among other things, the purposes of profiling, the legal basis for data processing, the consequences of the actions taken, and their rights, including the right to object to profiling. Data of minors is particularly protected. Due to the growing popularity of the TikTok app among young users, it was necessary to subject it to special regulations in this regard. In the area of information society services, the processing of data of children over 16 years of age is lawful. An exception is made for situations in which a person with parental authority or guardianship provides prior consent. However, EU member states may introduce a lower age limit in their laws, but it must be at least 13 years old, as is the case in Poland, for example. To ensure that platforms enforce their obligations related to the protection of minors, they should use appropriate age verification mechanisms. In practice, however, this solution requires further improvement due to the common practice of users providing false data during registration.</p>



<p id="ember106">The President of the Office of Competition and Consumer Protection (UOKiK) plays a crucial role in protecting users, especially the collective interests of consumers. He is authorized to take action against entrepreneurs who engage in unfair market practices, design manipulative interfaces, and so on. Personal data protection, however, falls primarily within the remit of the Office for Personal Data Protection (UODO), which oversees compliance with the GDPR and the secure processing of information by companies and institutions. Due to its global influence, TikTok has attracted increasing attention from EU authorities in recent years and is becoming the subject of more frequent inspections. Due to the platform&#8217;s European headquarters being located in Ireland, the relevant supervisory authority is the Irish Data Protection Commission (DPC). For example, in 2025, this institution imposed a fine of €530 million on ByteDance, the app&#8217;s owner. The fine was imposed on the transfer of user data from the European Economic Area to China in violation of the GDPR and the failure to demonstrate data protection at the level guaranteed in the EU.</p>



<p id="ember107">The GDPR is supplemented by Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), which regulates, in addition to the processing of personal data, the confidentiality of electronic communications, also known as ePrivacy. Due to the scope of its regulations, the provisions of this directive have particular relevance to the TikTok Shop application. The platform uses numerous tracking technologies, such as cookies and mobile device advertising identifiers, to monitor user activity. Information may be stored on a user&#8217;s device or accessed only after obtaining prior consent. Exceptions are made only for technologies strictly necessary to provide the service requested by the user, such as remembering a shopping cart. An additional ePrivacy regulation was also envisaged, the purpose of which was to replace the current directive and harmonize the personal data protection rules applicable in all EU Member States. The changes were to include, among other things, simplifying the rules regarding cookies. However, the project encountered legislative difficulties and was not adopted by decision of the European Commission.</p>



<h2 class="wp-block-heading" id="ember108">Abuse of Market Power and the Digital Markets Plan</h2>



<p id="ember109">The dynamic expansion of the largest digital platforms&#8217; influence has led to the need to adapt competition law to the new situation, particularly in the digital market. To this end, the European Union adopted Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act – DMA). The Act introduces the concept of a gatekeeper. This term refers to an entrepreneur with an influential position in the internal market, through which business users reach end users. A gatekeeper provides a core platform service and maintains an established market position.</p>



<p id="ember110">The dominant position of a gatekeeper is also associated with a number of obligations. Among other things, the practice of self-preferencing, which involves favoring one&#8217;s own products or services over the offers of other businesses using the platform, is prohibited. In the case of TikTok Shop, this could involve using recommendation algorithms to increase the visibility of products promoted by individual sellers, without applying objective and fair advertising criteria. This type of favoritism and limiting the reach of individual entities could lead to a distortion of fair competition between businesses using TikTok Shop for sales purposes.</p>



<p id="ember111">By decision of the European Commission, BytaDance Ltd. was granted gatekeeper status solely for the operation of the TikTok application as a social media platform. The DMA regulations governing the gatekeeper position do not apply directly to TikTok Shop, but they may impact the rules for recommending products and using entrepreneurs&#8217; data.</p>



<h2 class="wp-block-heading" id="ember112">Media law and audiovisual regulations</h2>



<p id="ember113">Audiovisual materials are the primary tool for promoting and selling products on the TikTok Shop marketplace. Therefore, the app&#8217;s operations are also subject to scrutiny for compliance with media law and regulations governing audiovisual media services. The dominant role in this regard is played by Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation, or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive – AVMSD) and the Broadcasting Act of 29 December 1992, which implements it into Polish law. As a result of the amendment to the Act of 11 August 2021, the regulations have been extended to video-sharing platforms, including the TikTok app.</p>



<p id="ember114">Video-sharing platforms are primarily obligated to implement appropriate measures to protect minors from harmful content that could negatively impact their moral, mental, or physical development. These provisions have been implemented into Polish law through Article 47e of the Broadcasting Act, which mandates, among other things, the marking of potentially inappropriate content with special graphics for young viewers. These regulations are particularly important for the TikTok Shop platform due to the constantly growing number of underage users. Posting content that spreads hatred and discrimination is also prohibited.</p>



<p id="ember115">TikTok Shop, a hybrid social media platform and e-commerce platform, is often used to publish so-called audiovisual commercial communications—images used to directly or indirectly promote goods, services, or individuals (Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services, Article 1). Article 9 of the AVMSD requires member states to ensure that such communications are easily recognizable, thus prohibiting hidden audiovisual commercial communications. The use of subliminal techniques or the inclusion of discriminatory content would also be illegal. The National Broadcasting Council (KRRiT) is responsible for ensuring compliance with audiovisual law. Its remit includes, among other things, overseeing the activities of video-sharing platform providers.</p>



<p id="ember116">The sales method used by TikTok Shop may seem analogous to teleshopping, offerings directly to consumers to deliver goods or services in exchange for payment. This modern form of interactive audiovisual commerce (live shopping) bears numerous similarities to traditional teleshopping. The mechanisms of both aforementioned sales methods involve presenting the product, its specific features, available options, and generally encouraging the recipient to purchase. However, teleshopping is targeted at a general, anonymous audience who may only be interested in the recommended product. Meanwhile, TikTok Shop relies on advanced algorithms that target promotional content to users who, based on their previous activity, have shown interest in similar content.</p>



<h2 class="wp-block-heading" id="ember117">Platform liability under e-commerce regulations</h2>



<p id="ember118">The original act regulating the legal liability of online platforms in the European Union was Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (Directive on electronic commerce). Its foundation was the so-called safe harbor principle, i.e., the principle of limited liability of online intermediaries. According to this principle, hosting service providers and online platforms were not liable for content or goods published by users, provided they had no actual knowledge of the illegal nature of the content or goods or services or, upon obtaining such knowledge, promptly removed any infringements. Furthermore, the directive did not impose a general obligation on platforms to monitor content published by users.</p>



<p id="ember119">However, the ongoing development of digital platforms has made it necessary to amend the current liability model. Regulation (EU) 2022/2065 – Digital Services Act (DSA) – came into effect on February 17, 2024. This regulation does not eliminate the principle of limited liability but significantly expands monitoring obligations, especially for very large online platforms (VLOPs). One of the key obligations introduced under the new regulations is the Know Your Business Customer (KYBC) principle. This regulation aims to increase the safety of consumers shopping online by limiting sales conducted by dishonest or anonymous traders. Before enabling sales through its platform, an online platform must collect and verify basic data identifying the seller. The required information includes, among others, the trader&#8217;s name, registered office address, contact details, registration number in the relevant register of traders, and the trader&#8217;s payment account details. In the event of refusal to provide the specified data or providing it falsely, the platform should prevent the trader from conducting sales until the situation is resolved.</p>



<p id="ember120">A problematic issue related to the TikTok Shop app is defining the platform&#8217;s responsibility for transactions conducted by sellers using it. Although TikTok Shop formally acts as an online intermediary, it can be argued that its operating mechanism goes beyond passive hosting. A recommendation system using algorithms, promoting offers, and providing marketing and analytical tools to sellers are the mechanisms TikTok Shop uses to shape consumer behavior and purchasing decisions. The platform&#8217;s influence on the visibility of offers and the order fulfillment process may support assigning it broader responsibilities in overseeing the online sales process.</p>



<h2 class="wp-block-heading" id="ember121">Regulations on electronic communications, including the European Electronic Communications Code and the Polish Electronic Communications Law</h2>



<p id="ember122">The TikTok Shop platform does not constitute an electronic communications service under European Union law, but its operations provide for various forms of electronic communication. TikTok Shop&#8217;s use of push notifications, in-app messages, and marketing communications requires the platform to comply with regulations governing electronic marketing and the protection of user privacy in electronic communications. The primary legal acts regulating these aspects are Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code (EECC) and the Act of 12 July 2024 – Electronic Communications Law.</p>



<p id="ember123">The primary function of TikTok Shop is to enable entities to sell goods through the social media platform. Article 2 of the European Electronic Communications Code defines an electronic communications service as the transmission of signal transmissions or the provision of interpersonal communications services. The mere ability to exchange messages between users or with sellers does not automatically qualify the TikTok Shop platform as a provider of electronic communications services, as this is not its core competency and does not constitute its core business. However, because electronic communications are primarily used for marketing purposes, it is obligated to comply with regulations governing direct marketing and the protection of user privacy.</p>



<p id="ember124">Push notifications, messages sent directly to users&#8217; mobile devices, are an increasingly popular marketing solution. TikTok Shop uses them to provide information about order status, discounts, time-limited campaigns, or the launch of live shopping. Transactional notifications regarding order fulfillment, shipping, or payment status are typically part of the contract and do not require marketing consent. However, notifications encouraging potential consumers to make a purchase are classified as direct marketing and, in accordance with electronic communications law, require prior user consent.</p>



<p id="ember125">The practice of using automated calling systems and electronic means of communication for advertising purposes without the user&#8217;s prior consent is also prohibited. Users should be clearly informed about the purpose of receiving marketing communications, the data controller, and the possibility of withdrawing consent, which should not result in any negative consequences. With respect to the TikTok Shop platform, the above position means that it is unlawful to send promotional content to users solely based on the fact that they have an account on the app.</p>



<p id="ember126">TikTok Shop is the clearest example of how thin the line between entertainment, advertising, and commerce has become &#8211; a one-tap purchase woven into a stream of content is now as effortless as liking a video. Yet that convenience comes at a price: the <em>closed-loop</em> model and algorithmic personalization shrink the time left for rational reflection, while responsibility for protecting the consumer shifts increasingly away from the buyer and onto the platform and the legislator. EU and national regulations &#8211; from consumer law, through the DSA and DMA, data protection and safeguards for minors, all the way to media and electronic communications law &#8211; form a web meant to counterbalance the platform&#8217;s power and restore the buyer&#8217;s awareness of their own choices. TikTok Shop thus remains a dual phenomenon: on one hand a groundbreaking innovation in digital commerce, on the other a test of whether the law can keep pace with a technology that sells faster than we can think.</p>
<p>&nbsp;</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4" length="2083444" type="video/mp4" />

			</item>
		<item>
		<title>Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:29:19 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic decision-making]]></category>
		<category><![CDATA[algorithmic transparency]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[automated moderation]]></category>
		<category><![CDATA[Central Eastern Europe legal services]]></category>
		<category><![CDATA[compliance by design]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[consumer reviews verification]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital platforms]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[e-commerce regulation]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[fake reviews]]></category>
		<category><![CDATA[fake reviews in e-commerce]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[international legal cooperation]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[marketplace regulation]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[online consumer protection]]></category>
		<category><![CDATA[online marketplaces]]></category>
		<category><![CDATA[online reputation management]]></category>
		<category><![CDATA[platform liability]]></category>
		<category><![CDATA[Poland technology law]]></category>
		<category><![CDATA[Polish e-commerce law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[review authenticity]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[unfair commercial practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8830</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 10, 2026</mark></strong></p>



<p>The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer experience, misleads the recipient, directly influencing their decision-making process. Legally, a fake review is considered not only a completely false message, but also one that, by omitting important facts or manipulating context, creates a false impression of the quality of a product or the reliability of a seller. This practice is classified as unfair commercial activity if its nature causes or is likely to cause the average consumer to make a transactional decision they would not otherwise make, thus violating the fundamental principles of fair dealing.</p>



<span id="more-8830"></span>



<p>The typology of activities considered unfair rests on several fundamental pillars, the most blatant of which is direct fabrication. This involves posting or commissioning the creation of false recommendations from specialized external entities, such as marketing agencies, which directly violates regulations on combating unfair market practices. Another mechanism is selective manipulation, in which a business intentionally manages the visibility of reviews by removing, concealing, or delaying the publication of negative reviews while favoring positive ones. Such action distorts the image of actual customer satisfaction and is considered misleading regarding the essential characteristics of a product or service. An equally significant aspect is feigned verification, i.e., declaring that reviews come from real buyers without implementing proportionate and reasonable steps to verify their authenticity, which constitutes a direct violation of the disclosure obligations imposed by the Omnibus Directive.</p>



<p>Contemporary market practices have also evolved more subtle forms of manipulation, such as astroturfing, which involves creating artificial social support through employees or store owners posing as independent consumers. These activities often involve the manipulation of user profiles, where images generated by artificial intelligence algorithms are used to authenticate fictitious accounts, creating false social proof. Each of these practices, regardless of their technological sophistication, is subject to strict scrutiny by competition and consumer protection authorities.</p>



<p><strong>The role of the President of the Office of Competition and Consumer Protection and the responsibility of management boards</strong></p>



<p>The President of the Polish Office of Competition and Consumer Protection (UOKiK) serves as a central regulator in the legal system, endowed with rigorous powers to counteract violations of collective consumer interests. The main disciplinary instrument at the authority&#8217;s disposal is an administrative fine, which can be imposed in the amount of 10% of the turnover achieved by the entrepreneur in the financial year preceding the year of issuance of the decision. The amount of the fine is not determined arbitrarily, but rather results from precisely defined criteria, which include, above all, the scale of the violation, its duration, and the degree of intentionality of the perpetrator. Importantly, this fine is intended to serve not only a repressive function but, above all, a preventive and deterrent one, discouraging other market participants from engaging in similar unfair practices involving the manipulation of reviews or misleading as to the authenticity of reviews.</p>



<p>The enforcement procedure in consumer matters is designed to ensure high effectiveness of supervisory activities. A business subject to a sanction is obligated to settle the fine within 14 days of the decision becoming final, which directly contributes to the state budget. A crucial procedural element is the prejudicial nature of the decisions of the President of the Office of Competition and Consumer Protection (UOKiK), which means that the authority&#8217;s findings regarding violations of the law are binding on common courts in compensation cases brought by injured customers. This legal structure significantly facilitates consumers in pursuing civil claims, as they do not have to prove the illegality of the store&#8217;s actions, focusing solely on demonstrating the damage suffered. The office&#8217;s activity in recent years, reflected in numerous proceedings against e-commerce leaders, confirms that protecting the transparency of reviews has become a regulatory priority, translating into real and severe financial consequences for violators.</p>



<p>The contemporary model of liability in consumer protection law departs from a concept focused solely on the business entity, shifting the burden of sanctions also to individuals who actually manage the enterprise. The President of the Office of Competition and Consumer Protection (UOKiK) has the authority to impose a personal fine of up to PLN 2,000,000 on a manager. This liability is triggered by demonstrating that the manager has intentionally allowed – through their actions or conscious omissions – the company to violate collective consumer interests. In case law, the degree of management involvement in decision-making processes regarding marketing and communications is crucial. This liability may therefore affect a management board member who approves a budget for obtaining reviews from external opinion farms or ignores the lack of implementation of verification procedures under the Omnibus Directive, despite being aware of such deficiencies.</p>



<p>It should be emphasized that the responsibility of managers is autonomous and independent of any penalty imposed directly on the entrepreneur. This is intended to provide a strong incentive for management to build internal compliance structures and actively oversee the entity&#8217;s operational ethics. In the era of digitalization of trade, where algorithms and automation of marketing processes can generate violations on a massive scale, the personal financial risk of managers is intended to compel prioritizing compliance as the foundation of business strategy. Therefore, the systemic fight against false reviews is implemented not only through sanctions against corporate structures but also by disciplining those who actually shape companies&#8217; market policies. This, according to the legislature, is intended to ensure long-term improvement in integrity standards in electronic trading.</p>



<p><strong>The Omnibus Directive and the blacklist of market practices</strong></p>



<p>The implementation of the Omnibus Directive into the Polish legal system significantly redefined transparency standards in e-commerce, introducing mechanisms that directly address the systemic manipulation of consumer reviews. A key instrument in this regard is the so-called blacklist of market practices, which constitutes a catalog of behaviors considered unfair in all circumstances, eliminating the need for supervisory authorities to conduct a case-by-case analysis of the consequences of a given action. Classifying these market torts as unfair practices aims to eliminate evidentiary difficulties, as their mere existence exaggerates the entrepreneur&#8217;s wrongdoing. This legal framework not only strengthens the consumer&#8217;s position but, above all, simplifies the evidentiary process, making the fight against e-commerce abuse more effective and predictable for market participants. The foundation of the new regulations is an absolute prohibition on manipulating the verification and authenticity of product recommendations, which imposes an active obligation on sellers to implement procedures to verify the origin of reviews.</p>



<p>Under the current wording of the regulations, it is considered an unfair market practice for a trader to claim that product reviews were posted by consumers who actually used or purchased the product, in situations where reasonable and proportionate steps were not taken to verify their authenticity. This practice violates the consumer&#8217;s right to reliable information, which is essential for making an informed decision about purchasing the product, and violating it constitutes conduct contrary to good practice. The law prohibits not only posting completely false reviews, but also commissioning third parties to create them, or transferring recommendations between products with different parameters, which is referred to as review hijacking. Other offenses listed in the catalog are treated equally severely, such as using false quality certificates without appropriate authorization or using surreptitious advertising, which involves using editorial content to promote a product without clearly identifying the paid nature of the communication. Aggressive techniques are also considered particularly burdensome, including mass spamming and forced selling, which involves demanding payment for products delivered to the consumer without their prior order.</p>



<p>The blacklist also eliminates techniques <strong>such as bait advertising and direct persuasion of children to purchase</strong>, which aims to protect the integrity of the consumer decision-making process from manipulation. This protection of minors stems from their particular vulnerability to advertising messages and their inability to critically assess the persuasive nature of commercial offers. Expanding the list to include a ban on posting or commissioning another person to post false reviews for the purpose of promoting products significantly complements the system, preventing brands from using agencies that fabricate social evidence. It is emphasized that any form of distortion of the actual image of a product&#8217;s popularity constitutes a violation of the collective interests of consumers, which entitles the President of the Office of Competition and Consumer Protection (UOKiK) to intervene under public law as soon as a threat to the interests of all market users arises.</p>



<p>A particularly significant and painful consequence of these unfair techniques for entrepreneurs is a specific civil law sanction in the form of an extended right of withdrawal from the contract. If an e-store engages in practices listed in the prohibited catalog or fails to comply with information obligations regarding review verification, the statutory return period granted to the buyers is extended from 14 days to a full 12 months. This mechanism is a direct consequence of the assumption that, in the absence of reliable information, the consumer could not have expressed a fully informed intention to purchase, which suspends the running of standard mandatory deadlines. Systematic combating of review fraud and the use of black market practices is therefore becoming not only a matter of business ethics but the foundation of legal security and stability for every entity operating in the e-commerce sector. Neglect in transparency can lead to mass claims for refunds, posing a real threat to the operational liquidity of the company.</p>



<p><strong>Manipulation Architecture and Platform Obligations under the Digital Services Act (DSA)</strong></p>



<p>The phenomenon known as dark patterns constitutes a sophisticated form of interference in the user&#8217;s decision-making process, based on the deliberate use of interface architecture to distort their autonomy of will. Manipulative design patterns are not merely a manifestation of aggressive marketing, but a systematic designer&#8217;s action aimed at inducing a specific cognitive bias in the consumer, which ultimately leads to a purchase decision they would not have made in conditions of full transparency. The psychological foundation of these actions is the use of heuristics, i.e., simplified rules of reasoning and automatic thinking, which in the fast-paced environment of e-commerce transactions make the user susceptible to subliminal suggestions. This phenomenon has evolved from simple forms of persuasion to advanced interface manipulation, where the line between inducement and fraud is deliberately blurred to maximize conversion at the expense of the interests of the weaker party in the legal relationship.</p>



<p>A particularly significant area of application of these practices is the system for <strong>presenting reviews and suggesting their authenticity</strong>, where manipulation takes the form of so-called interface interference. Businesses often employ patterns involving selective content display, which in practice means deliberately hiding negative reviews on subsequent pages of the website while simultaneously highlighting only enthusiastic reviews on the product&#8217;s home page. This practice violates the model of the average consumer, who has the right to expect that the image presented of a product&#8217;s popularity and quality is reliable and has not been subjected to arbitrary filtering. Manipulation in the sphere of social evidence also includes fabricating popularity indicators, such as false messages about the number of people viewing a given product at a given time or false offer duration counters, which create an artificial sense of scarcity in the user and pressure them to immediately close the transaction. Under the Polish Act on Combating Unfair Market Practices, these activities may be classified as misleading because they distort the actual market conditions, preventing a rational comparison of offers.</p>



<p>Another dimension of manipulation is the technique known as confirmation shaming, which in the sphere of opinion writing involves the use of evaluative and emotional language to coerce users into specific behaviors, for example, through unsubscribe buttons suggesting a lack of consumer awareness. These practices are closely related to the &#8220;<strong>roach motel model</strong>”, where the process of issuing a favorable review is simplified to the maximum extent, while editing, reporting an error, or deleting content requires navigating a complex subpage structure, which is intended to discourage users from correcting false information. In the legal context, such procedural barriers are considered burdensome impediments that violate good practice and the principle of commercial fairness. An analysis of case law and the positions of supervisory authorities indicates that an interface that deliberately hinders users from exercising their rights or changing their minds loses its neutrality and becomes a tool for harming consumer interests.</p>



<p>A fundamental change in the regulatory sphere was brought about by the entry into force of the <strong>EU Digital Services Act (DSA), which, in Article 25, explicitly prohibits online platform providers from designing, organizing, and operating interfaces in a way that misleads or manipulates service users</strong>. This regulation is overarching and complements the existing consumer protection framework by introducing a direct obligation to maintain neutrality in choice architecture and prohibiting structures that significantly impede users&#8217; ability to make free and informed decisions. Violation of this prohibition entails not only civil law risks but also severe administrative sanctions, which can amount to a significant percentage of the business&#8217;s global turnover.</p>



<p>In the sphere of law enforcement, the key role is played by the model design of the average consumer, who is observant and cautious but lacks specialized knowledge of the psychological mechanisms used in interface design. This protection is preventative and abstract in nature, meaning the President of the Office of Competition and Consumer Protection (UOKiK) can intervene in situations where the mere existence of a manipulative pattern poses a real risk of distorting market behavior, without having to wait for measurable financial damage to a specific individual. Effectively combating dark patterns requires businesses not only to comply with the law but, above all, to shift to a design model focused on reliability, where all product information, including opinions, is presented free from coercive mechanisms. Ultimately, interface transparency is becoming a prerequisite for maintaining trust in the digital economy, and the use of sophisticated forms of manipulation is perceived as highly harmful to society, subject to strict assessment in light of the principles of social coexistence.</p>



<p><strong>New obligations for marketplaces regarding moderation and transparency</strong></p>



<p>The entry into force of Regulation 2022/2065, known as the Digital Services Act (DSA), represents a fundamental shift in the liability paradigm for intermediary service providers, particularly marketplaces. This regulation shifts the emphasis from passive content hosting to active oversight of the transparency and security of the digital system, introducing rigorous operational standards aimed at eliminating illegal content while respecting users&#8217; fundamental rights. A key pillar of this reform is the formalization of moderation processes, which until now were often subject to arbitrary internal platform decisions and are now subject to strict procedural rigors contained in the notice-and-action mechanism. Under the DSA, each platform is required to provide easily accessible and user-friendly tools for identifying potentially illegal content, including fake reviews or infringing offers. The mere receipt of a report obliges the provider to promptly and objectively address it.</p>



<p>The evolution of moderation obligations is inextricably linked to the <strong>requirement for transparency in decisions</strong>, which is achieved through the justification mechanism provided for in the EU regulation. When a marketplace decides to remove content, limit its visibility, or suspend a user&#8217;s account, the user is absolutely obligated to provide clear and specific reasons for such action, which is intended to prevent abuse by blocking reliable reviews that are unfavorable to the seller. This system is complemented by a<strong> mandatory internal complaint handling system</strong>, which allows users to appeal moderation decisions free of charge within a period of at least six months. <strong>This constitutes an important procedural guarantee and allows for the correction of potential algorithmic errors</strong>. It is indicated that such a legal framework is necessary to counteract the fragmentation of consumer protection, which previously relied primarily on general national clauses that were unsuitable for the scale of operations of global digital entities.</p>



<p>A significant innovation introduced specifically for trading platforms is the &#8220;Know Your Business Customer&#8221; (KYBC) principle, regulated in the chapter on marketplace transparency. These entities are charged with collecting and verifying information about traders offering their products through their interfaces, including registration data, payment account numbers, and declarations of commitment to offer goods in compliance with EU law. This mechanism aims to eliminate the phenomenon of anonymous sellers, who often promote defective products using fabricated reviews and, after raising capital, disappear from the market, avoiding legal liability. The platform is obligated to suspend services for sellers who fail to submit the required documents, making the marketplace an active guardian of the legality of trade, rather than merely a passive intermediary in trade.</p>



<p>The scope of transparency obligations extends beyond relationships with individual users to include public reporting through the periodic publication of transparency reports. These documents must include detailed data on the number of orders received from national authorities, statistics on content moderation initiated by the platform itself, and information on the use of automated tools in verification processes. For very large online platforms, these rigors are even stricter, including the obligation to conduct annual audits and systemic risk assessments, including analysis of the interface&#8217;s vulnerability to manipulation that could negatively impact public safety or consumer protection. The systemic fight against disinformation and unfair market practices is therefore anchored in the full transparency of operational processes, which allows supervisory authorities to continuously monitor the effectiveness of implemented security measures.</p>



<p>Supervision of compliance with these obligations is based on a new institutional architecture, in which national digital services coordinators, working closely with the European Commission, play a central role. The enforcement system for the adopted regulations is based on fines of up to 6% of a provider&#8217;s global turnover, which compels compliance with specific cybersecurity standards. This control system is designed to ensure that marketplaces not only implement the required procedures but also apply them reliably and uniformly across the European Union, which is crucial for building consumer confidence in cross-border trade. The introduction of these standards ends the phase of full regulatory freedom for platforms, imposing on them real responsibility for shaping the environment in which the modern exchange of goods and services takes place.</p>



<h2 class="wp-block-heading"><strong>Technological verification mechanisms and modern operating models</strong></h2>



<p><strong>Authenticity Suggestion and Pressure Mechanisms</strong></p>



<p>The evolution of digital market oversight has led to the development of mechanisms in which traditional legal instruments are increasingly being replaced by algorithmic jurisdictions based on advanced artificial intelligence systems. The phenomenon known as AI exclusion is a modern form of sanction that, for e-commerce entities, can prove more severe than traditional financial penalties imposed by administrative bodies. The foundation of this process is the integration of data on the credibility of reviews directly with positioning parameters in ranking systems, which means that transparency is no longer merely an ethical obligation but a condition for the technical visibility of an offer. Recommendation algorithms operating within platforms such as Google and Amazon constantly analyze behavioral and linguistic patterns to identify anomalies suggesting manipulation of social evidence. These systems are currently capable of recognizing the structure of texts generated by LLM language models, which are characterized by a specific repetition of phrases and a lack of emotional details typical of authentic consumer experiences. An additional risk factor subject to automatic verification is the so-called review growth rate, where a sudden jump in the number of positive ratings without correlation with actual website traffic or sales volume is interpreted by AI as a warning signal initiating restrictive procedures.</p>



<p>The consequences of an online store being classified by AI systems as posing a high risk of manipulation are immediate and often irreversible in the short term. This mechanism, known in market practice as <strong>shadow banning or de-indexing</strong>, leads to a drastic decline in visibility in search results and the blocking of offers in advertising systems, effectively cutting the entrepreneur off from key customer acquisition channels. Under the provisions of the Digital Services Act, providers of very large online platforms are required to maintain particular transparency regarding the parameters used in recommendation systems. Article 27 of the aforementioned regulation requires platforms to clearly define in their regulations the key parameters determining information ranking, which aims to limit <strong>algorithmic arbitrage</strong> and enable entrepreneurs to understand the reasons for a potential decline in their market exposure. It is worth noting that modern risk assessment systems may be classified as high-risk systems within the meaning of the Artificial Intelligence Regulation, which imposes strict requirements on their creators regarding human oversight and the prevention of <strong>algorithmic discrimination</strong>.</p>



<p>In parallel to restrictive systems, a paradigm known as agentic commerce is developing, in which purchasing processes are carried out by autonomous AI assistants acting directly on behalf of the consumer. In this model, traditional product reviews cease to serve as persuasive texts for humans and become raw input data for machines that filter the market in search of offers with the highest level of verified trust. A key element of this new commerce architecture is the so-called trust layer, built on protocols such as the Universal Commerce Protocol promoted by Google or the Agentic Commerce Protocol developed by OpenAI. These systems are guided not only by price or availability of goods but above all by the certified credibility of the seller&#8217;s data, automatically rejecting offers from entities that lack a clear digital traceability of their recommendations. The collaboration of AI assistants with secure payment systems, such as the Agent Payments Protocol, creates a closed ecosystem in which offers at risk of manipulation are excluded at the initial algorithmic selection stage, before they are even presented to the user.</p>



<p>In the era of agent-based commerce, the role of modern shopping assistants is becoming dominant, forcing businesses to redefine their credibility-building strategies. The Context Protocol model and other open-source solutions enable the exchange of context between various AI models and commerce systems, allowing information about unfair practices by a single store to be instantly shared across the entire assistant network. The doctrine suggests that this systematic approach to eliminating abuse is a natural response to the technological ease of fabricating content online. For an e-commerce store, losing its trustworthy status in the eyes of Google or OpenAI algorithms means the modern equivalent of server shutdown, as AI assistants, protecting the interests of their users, will systematically bypass offers that generate manipulative signals. Thus, the fight for authenticity is no longer a mere compliance issue but an existential foundation in the new, automated e-commerce environment, where barriers to entry into the trust layer are becoming increasingly difficult for entities employing pressure mechanisms and suggesting false authenticity.</p>



<p><strong>Compliance as a Service and the Digital Feedback Path</strong></p>



<p>The rapid evolution of the e-commerce market and the increasing professionalization of unfair market practices have forced entrepreneurs to abandon a reactive reputation management model in favor of proactively building a digital immune system. The scale of the challenge facing modern e-commerce is illustrated by analyses of the systematic erosion of trust in the digital sector, pointing to the prevalence of fake reviews and consumer concerns about the mass implementation of generative artificial intelligence for opinion fabrication. This state of affairs creates decision paralysis, where an overabundance of unreliable information, instead of supporting the purchasing process, becomes an insurmountable barrier.</p>



<p>The economic impact of the lack of reliable content verification is directly measurable and translates into tangible operational losses for businesses. The literature emphasizes that exposure to manipulated reviews drastically reduces purchase intentions and brand trust, generating measurable financial losses. The information vacuum filled with false enthusiasm also leads to a phenomenon known as post-purchase dissonance, in which a product that fails to meet expectations is returned to the seller as a complaint or contract withdrawal. Consequently, the lack of investment in transparent review processes generates hidden logistical and operational costs that, in the long run, may outweigh the gains achieved through the temporary increase in conversions driven by manipulation.</p>



<p>In response to increasing regulatory rigor, including the Omnibus Directive, the Digital Services Act (DSA), and the AI Act framework, an operational model known as <strong>Compliance as a Service (CaaS)</strong> has emerged in market practice. It involves fully outsourcing compliance processes to specialized technology providers who take over the burden of monitoring and verifying content in accordance with current regulations. CaaS allows for the automation of data oversight, which is essential in an environment where the volume of incoming reviews precludes manual oversight without risking accusations of disproportionality. In this approach, compliance ceases to be merely an administrative cost and becomes a component of a strategy for building brand value by guaranteeing the authenticity of every customer touchpoint.</p>



<p>The foundation of the Compliance as a Service model is the maintenance of clean data and the generation of an indisputable digital trace of the review&#8217;s provenance. Every published review should be accompanied by a log containing metadata regarding the specific transaction, a unique order number, and delivery status, creating auditable proof of authenticity that can be presented during inspections by supervisory authorities such as the President of the Office of Competition and Consumer Protection. This digital reconstruction of the review process provides the most effective legal shield for businesses, eliminating the risk of allegations of unfair market practices. In the era of algorithmic jurisdiction, where ranking systems favor content supported by digital evidence, having a certified trace of data provenance is becoming a prerequisite for maintaining the market visibility of an offer.</p>



<p>Parallel to technical verification, modern review management systems integrate mediation mechanisms that allow for the amicable resolution of disputes before they are publicly expressed. Market experience suggests that implementing structured review processes allows for the amicable resolution of a significant portion of consumer disputes, effectively preventing the publication of negative reviews resulting from logistical errors. This approach aligns with the principles of reliability and good market practices, building customer relationships based on dialogue rather than solely on the one-way transmission of ratings.</p>



<p>Transaction verification is now becoming the market standard, replacing open, abuse-prone review sections with a system of unique invitations sent only after a purchase is completed. The literature emphasizes that restricting the review process to those who actually purchased the product is the simplest and most effective way to comply with the obligations imposed by the Omnibus Directive. This not only minimizes the risk of severe financial penalties, but above all, provides AI shopping assistants with reliable input data, which, in the new agent-based commerce paradigm, will determine the viability of each entity in the e-commerce ecosystem.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</title>
		<link>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:40:05 +0000</pubDate>
				<category><![CDATA[INVESTMENT LAW AND PROCESSES IN POLAND]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Governance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[Cyber Risk;]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8816</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of the European Parliament and of the Council.</p>



<p id="ember4587">The amendment to the KSC Act significantly expands the scope of the regulations and introduces new obligations in the field of cybersecurity management. The changes include, among other things, the implementation of risk management systems and expanded incident reporting requirements. The new regulations also strengthen the powers of supervisory authorities and significantly increase the maximum amount of financial penalties. It also introduces liability for the management staff (manager) of an entity. In practice, this requires certain entities to take steps to comply with the new regulations.</p>



<span id="more-8816"></span>



<p id="ember4588"><strong>The first experiences of entrepreneurs after the amendment came into force – practical conclusions</strong></p>



<p id="ember4589">The few months that the amended Act on the National Cybersecurity System has been in effect demonstrate that the biggest challenge for businesses is no longer the analysis of the new regulations, but their practical implementation. For many organizations, the adaptation process began with a seemingly simple task: determining whether a given entity is even subject to the new regulations. In practice, this step proves to be one of the most problematic.</p>



<p id="ember4590">Under the previous legal framework, many businesses awaited a formal administrative decision confirming their status as an essential service operator. This approach is no longer appropriate. The status of a key or important entity stems directly from the Act, and obligations arise regardless of whether the business has already been entered on the register. This means that the responsibility for properly assessing their own situation rests primarily with the business itself.</p>



<p id="ember4591">Practice also shows that many companies focus solely on the issue of being entered into the register of key and important entities. However, entry itself is not the purpose of the regulation. The greatest challenges remain the actual implementation of an information security management system, conducting a risk analysis, developing incident response procedures, and adequately documenting the actions taken. In the future, supervisory authorities will primarily assess an organization&#8217;s actual level of compliance with the Act, not merely the formal fulfillment of registration obligations.</p>



<p id="ember4592">Another significant change is the significant increase in management responsibility. Management can no longer treat cybersecurity as a matter solely within the purview of IT departments. The Act requires active management involvement in the organization of the cybersecurity management system, oversight of its operation, and provision of adequate organizational and financial resources. In practice, this requires regular reporting on cybersecurity issues at the management level and documentation of decisions made.</p>



<p id="ember4593">Supply chain security is also becoming increasingly important. Businesses are required not only to secure their own IT systems but also to consider the risks arising from collaboration with IT service providers, cloud computing operators, software vendors, and outsourcing providers. In practice, this means reviewing supplier contracts, verifying the security measures in place, and implementing appropriate provisions for incident management and crisis cooperation.</p>



<p id="ember4594">It&#8217;s also noticeable that a growing number of businesses are choosing to conduct internal compliance audits before the statutory deadlines expire. This approach allows for early identification of organizational and technical gaps, reducing the risk of subsequent violations and costly remedial actions.</p>



<p id="ember4595">In practice, the best solution is to treat the implementation of the Act&#8217;s requirements not as a one-time project, but rather as a process encompassing regular risk analysis, procedure updates, employee training, and ongoing oversight of the organization&#8217;s security. This approach not only increases compliance but also significantly reduces the risk of cybersecurity incidents.</p>



<p id="ember4596">It&#8217;s worth emphasizing that the current transition period should be used to calmly prepare organizations for the full application of the new regulations. Postponing implementation until the final months before the statutory deadlines expire can be risky, especially for large organizations where implementing information security management systems requires the involvement of multiple departments and adequate time to prepare procedures and documentation.</p>



<h2 class="wp-block-heading" id="ember4597">Change in the circle of entities to which the Act applies.</h2>



<p id="ember4598">Under the previous wording of the Act, an administrative decision was required to recognize an entity as an essential service operator (Article 5 of the Act before the amendment). Currently, the group of key and important entities is determined automatically (ex lege). The criteria for qualifying an entity as essential are found in Article 5, Section 1, and as an important entity in Article 5, Section 2 of the Act. It is possible that an entity meets the criteria for both key and important entities; such an entity is considered a key entity under Article 5, Section 4. When attempting to qualify entities, the Act also refers to EU regulations, particularly Regulation 651/2014/EU, which defines SMEs. Therefore, the primary criteria taken into account will be the number of employees and annual turnover. It is also necessary to refer to Annexes 1 and 2 of the Act, which precisely define the categories of entrepreneurs in specific sectors and subsectors.</p>



<p id="ember4599">The added Article 5a in paragraph 1 provides that key and important entities are subject to the obligations arising from the Act if they reside in the territory of the Republic of Poland or conduct their business in the territory of the Republic of Poland.</p>



<p id="ember4600">Articles 7 et seq. regulate matters related to the list of key and important entities. Before the amendment, the list contained only operators of essential services; now it includes key and important entities. Unlike the previous legal status, in which entry was made at the request of the authority responsible for cybersecurity (former wording of Article 7, paragraph 3 of the Act), entry is now made at the request of a key or important entity within six months of the occurrence of the conditions (Article 7c, paragraph 1 of the Act). Ex officio entry will generally only apply to existing operators of essential services, trust service providers, telecommunications companies, and public entities. This means that for entities meeting the conditions on the date the amendment comes into force, the deadline for submitting an application is October 3, 2026. Pursuant to the Announcement of the Minister of Digitization of April 8, 2026, regarding the schedule for submitting applications for entry in the register of key and important entities and for key or important entities to commence using the ICT system , self-registration on the list is possible from May 7, 2026, to October 3, 2026. The platform operating in the S46 system is available at <a href="https://wykaz-ksc.gov.pl/">https://wykaz-ksc.gov.pl/</a> . By April 3, 2027, key and important entities are required to commence using the ICT system specified in Art. 46 sec. 1 of the Act. This deadline begins depending on whether the entities were parties to agreements regarding the use of the ICT system referred to in Art. 46 sec. 1 of the Act concluded before April 3, 2026. For the former, the possibility of using the system was opened on April 8, 2026, and for the latter, this possibility will be available from June 12, 2026 (point 2 of the Communication of the Minister of Digital Affairs).</p>



<p id="ember4601">If an entity that meets the criteria for being considered a key or important entity fails to submit an application for entry, the authority responsible for cybersecurity may enter the entity on the list ex officio (Article 7j, paragraph 1 of the Act). Failure to comply with certain obligations related to the list (failure to timely complete missing data on the list or failure to correct data despite a request or failure to submit an application for entry) may result in the imposition of a substantial fine (Article 73, paragraph 1, point 1 and Article 73, paragraph 1a, point 1 of the Act). The catalogue of data to be included on the list has also been changed (expanded) (Article 7, paragraph 2).</p>



<p id="ember4602"><strong>In practice: </strong>The expansion of the scope of entities and the shift from administrative decision-making to automatic regulation mean that many entities may be subject to the Act without formal confirmation of this status. In practice, independent qualification analysis and continuous monitoring of compliance with statutory criteria become crucial. An incorrect assessment (or failure to comply) may result in exposure to sanctions (severe fines).</p>



<h2 class="wp-block-heading" id="ember4603">New responsibilities for cybersecurity management.</h2>



<h3 class="wp-block-heading" id="ember4604">Duties</h3>



<p id="ember4605">Chapter 3, which governs the obligations of key and important entities, has been expanded, and Chapters 3a and 3b have been added, addressing domain name registration service providers and public entities. Article 8 of the Act governs obligations related to the implementation of an information security management system. Compared to the previous legal framework, numerous obligations have been added. The responsibility of the manager of a key or important entity for the performance of its cybersecurity obligations has been introduced (Article 8c of the Act), and the manager&#8217;s responsibilities have also been defined (Articles 8d–8f of the Act).</p>



<p id="ember4606">The regulations regarding incident reporting have also changed. A key or important entity classifies a given incident as serious (after meeting the requirements of Article 2, Section 7 of the Act), then issues an early warning, reports the incident, and finally submits a final report on the handling of the serious incident to the CSIRT (a three-step reporting model instead of the previous one-step model – Article 11 of the Act).</p>



<h2 class="wp-block-heading" id="ember4607">Deadlines</h2>



<p id="ember4608">Pursuant to Article 15 of the Act, key entities must conduct a security audit of the information system used in the service provision process at least once every three years. For key entities that were not previously classified as key service operators, the first audit should be conducted within 24 months of the date the conditions are met (Article 16, point 2, therefore, for these entities, the deadline for conducting the audit is April 3, 2028).</p>



<p id="ember4609">The Act amending the KSC Act establishes a 12-month transition period during which key and important entities have time to fulfill the obligations specified in Chapter 3 of the Act (except for the obligation to conduct the first audit, which entities have 24 months to conduct). Therefore, with respect to obligations such as implementing an information security management system, risk assessment, implementing technical and organizational measures, reporting and managing incidents, and verifying personnel&#8217;s criminal records, the deadline for compliance with these regulations expires on April 3, 2027.</p>



<p id="ember4610"><strong>In practice: </strong>The imposed obligations require the implementation of an information security management system. Furthermore, the single-tier incident reporting system has been changed, replaced by a more complex three-tier system. Essential entities will be required to conduct audits. Importantly, entities that were not previously considered essential service operators will be required to conduct an audit within two years of the amendment&#8217;s entry into force. However, most of the new obligations will have to be implemented by April 3, 2027. Failure to comply with these obligations will result in the manager of the relevant entity being held liable.</p>



<h2 class="wp-block-heading" id="ember4611">Change in the amount and grounds for imposing fines.</h2>



<p id="ember4612">Until April 2, 2026, the maximum amount of the fine imposed on entities (only for the most serious violations) was PLN 1 million (former wording of Article 73, paragraph 5 in fine). Currently, the maximum amount of the fine is, as a rule, EUR 10 million (Article 73, paragraph 3 of the Act), and for the most serious violations, up to PLN 100 million (Article 73, paragraph 5 in fine of the Act).</p>



<p id="ember4613">With the imposition of a large number of obligations on key and important entities, the list of violations for which a fine may be imposed has also been expanded (Article 73 of the Act).</p>



<p id="ember4614">The new provisions on fines come into force only two years after the entry into force of the Act (i.e. from April 3, 2028).</p>



<p id="ember4615"><strong>In practice: </strong>Increasing the amount of fines disciplines key entities and important entities to take their cybersecurity obligations very seriously. It is worth emphasizing, however, that the amended regulations on fines will not enter into force until April 3, 2028.</p>



<h2 class="wp-block-heading" id="ember4616">Changes in the supervision and control of key and important entities.</h2>



<p id="ember4617">Chapter 11 of the Act, which deals with the supervision and control of key and important entities, has been significantly expanded. Some provisions remain unchanged (the requirement to apply the provisions of the Entrepreneurs&#8217; Law or the Act on Audit in Government Administration, the powers of the person conducting the audit, most of the obligations of audited entities, and provisions regarding audit protocols and post-audit recommendations).</p>



<h2 class="wp-block-heading" id="ember4618">Important changes</h2>



<p id="ember4619">The most important changes in the scope of supervision include a significant expansion of Article 53, which describes the powers of the authority responsible for cybersecurity regarding supervision and oversight of key entities. It empowers the competent authority to issue various types of administrative decisions aimed at enforcing the provisions of the Act. This article also contains a number of procedural provisions defining the nature of the proceedings. Generally, the regulations contained in this article apply only to key entities, but as stated in Article 53, paragraph 17, certain provisions also apply to inspections of important entities. Article 53, paragraph 3 states that supervision of key entities is both post-empty and preventive, while for important entities, supervision is only post-empty.</p>



<p id="ember4620">A new obligation for both key and important entities is the information obligation specified in Article 53c, which requires a key or important entity to provide certain data at the request of the authority responsible for cybersecurity.</p>



<p id="ember4621">A new institution is the ad hoc review added in Article 59c, which may be carried out only if the conditions specified in the cited Article are met.</p>



<p id="ember4622"><strong>In practice: </strong>Strengthening the powers of supervisory authorities and introducing ad hoc inspections means increased risk of inspections and the need to maintain constant readiness to demonstrate compliance with regulations. Entities should also prepare for more frequent requests for information from authorized bodies.</p>



<h2 class="wp-block-heading" id="ember4623">Minor changes</h2>



<p id="ember4624">Chapter 10 has been amended and Chapters 10a – 10c have been added, but they do not contain any standards addressed to entities and are therefore not relevant from a practical point of view.</p>



<p id="ember4625">Several changes concern Chapter 12 concerning the Government Plenipotentiary for Cybersecurity and the Cybersecurity Board, but these changes do not have any significant impact on the entities.</p>



<p id="ember4626">Article 12a has been added, addressing specific measures to ensure cybersecurity at the national level. It primarily contains provisions on recommendations from the Government Plenipotentiary for Cybersecurity (Article 67a), the procedure for designating a supplier as a high-risk supplier (Articles 67b–67f), and a safeguarding order in the event of a critical incident (Articles 67g–67i).</p>



<p id="ember4627">Minor changes also apply to the Cybersecurity Strategy of the Republic of Poland (Articles 68–72). The changes primarily concern the content and method of developing the strategy, as well as the frequency of strategy reviews (2.5 years instead of the previous 2 years).</p>



<p id="ember4628">The amendment to the Act on the National Emergency Response Plan creates the basis for the adoption of the National Emergency Response Plan (Articles 72a – 72f of the Act).</p>



<h2 class="wp-block-heading" id="ember4629">Recommended actions.</h2>



<p id="ember4630">In light of the amendments to the Commercial Companies Code, entities subject to the new regulations should take steps to ensure their operations are in compliance with the law. It is recommended that:</p>



<p id="ember4631">1)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Self-identification in order to determine whether a given entity qualifies as a key or important entity within the meaning of the Act.</p>



<p id="ember4632">2)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Implementation or update of an information security management system.</p>



<p id="ember4633">3)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Development of procedures for identifying and reporting incidents, taking into account the new procedure.</p>



<p id="ember4634">4)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring the involvement of management staff, e.g. the manager&#8217;s implementation of the obligations under Article 8d or 8e.</p>



<p id="ember4635">5)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Preparing the organization for potential supervisory activities, e.g. inspections.</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4637">ex officio entries carried out by the Minister of Digital Affairs (current key service operators, trust service providers, telecommunications companies and public entities)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4639">April 13 – May 6, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4641">self-registration in the list of key and important entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4643">May 7 – October 3, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4645">launching the possibility of using the S46 system for new entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4647">June 12, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4649">end of the deadline for starting to use the S46 system and implementing obligations (end of the adjustment period)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4651">April 3, 2027</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4653">the first ISMS audit (for key entities that were not key service operators) and the beginning of the application of the provisions on penalties</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4655">April 3, 2028</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PRIVACY, DATA PROTECTION, AI AND CYBERSECURITY – LAW MAP</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/privacy-data-protection-ai-and-cybersecurity-law-map/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/privacy-data-protection-ai-and-cybersecurity-law-map/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 15 Sep 2025 17:17:47 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI AND CYBERSECURITY – LAW MAP]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[PRIVACY]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8268</guid>

					<description><![CDATA[<p>Publication date: September 15, 2025 The phenomenon of dispersion of data law sources &#160;&#160; Data law is no longer just about GDPR. The European Union&#8217;s legislative trend of incorporating data law regulations into comprehensive sectoral regulations: healthcare, financial markets, corporate stock market law, the defense industry, electronic communications, and the phenomenon of fair competition in [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/privacy-data-protection-ai-and-cybersecurity-law-map/">PRIVACY, DATA PROTECTION, AI AND CYBERSECURITY – LAW MAP</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: September 15, 2025</strong></mark></p>



<h2 class="wp-block-heading"><strong>The phenomenon of dispersion of data law sources &nbsp;&nbsp;</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2025/09/20230506_201821-2.mp4"></video></figure><div class="wp-block-media-text__content">
<p>Data law is no longer just about GDPR. The European Union&#8217;s legislative trend of incorporating data law regulations into comprehensive sectoral regulations: healthcare, financial markets, corporate stock market law, the defense industry, electronic communications, and the phenomenon of fair competition in trade, is resulting in a significant fragmentation of legal sources, the core subject of which is &#8220;DATA AND DATA PROTECTION</p>
</div></div>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2025/09/ATOMIC-FORMULA-OF-LEGISLATION-HIVE.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="943" height="989" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/ATOMIC-FORMULA-OF-LEGISLATION-HIVE.png" alt="" class="wp-image-8272" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/ATOMIC-FORMULA-OF-LEGISLATION-HIVE.png 943w, https://www.kg-legal.eu/wp-content/uploads/2025/09/ATOMIC-FORMULA-OF-LEGISLATION-HIVE-286x300.png 286w, https://www.kg-legal.eu/wp-content/uploads/2025/09/ATOMIC-FORMULA-OF-LEGISLATION-HIVE-768x805.png 768w" sizes="(max-width: 943px) 100vw, 943px" /></a></figure>





<h3 class="wp-block-heading"><strong>The interpenetration and interaction of the sources of law in the shape of an atom</strong></h3>



<span id="more-8268"></span>



<p>The dispersion of legal acts at the legislative level, whether uniform for all European Union countries, or the Polish system and agencies within Polish jurisdiction, can be illustrated as a kind of legislative hive or the construction of an atom, which is focused on two axes: 1/ vertical as the law of privacy protection and generating funds on private data, and 2/ horizontal as the protection of non-private data and business processes, the financial market, the pharmaceutical and health market, and the defense sector.</p>



<h2 class="wp-block-heading"><strong>AI LAW</strong></h2>



<p>Within the atomic framework of &#8220;data, data access, and data processing&#8221;, the normative needs of cutting-edge technology, generative AI, should be highlighted. This is directly related to the legal environment of AI-based software, DEEP AND MACHINE LEARNING. The era of generative AI necessitates the creation of new regulations, as such a technological leap significantly complicates the legal relationships of economic participants. A key example is</p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-3.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="581" height="413" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-3.png" alt="" class="wp-image-8269" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-3.png 581w, https://www.kg-legal.eu/wp-content/uploads/2025/09/image-3-300x213.png 300w" sizes="(max-width: 581px) 100vw, 581px" /></a></figure>



<p>The spherical nature of data law has at its core the law created for the competences of individual agencies and consumer protection.</p>



<h2 class="wp-block-heading"><strong>The rise of cyber, defense, and data law regulations</strong></h2>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-4.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="605" height="417" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-4.png" alt="" class="wp-image-8270" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/image-4.png 605w, https://www.kg-legal.eu/wp-content/uploads/2025/09/image-4-300x207.png 300w" sizes="auto, (max-width: 605px) 100vw, 605px" /></a></figure>



<p>The year 2025 is a legislative year during the technological revolution of generative AI. It is worth noting, above all, the significant, slow, decisive, and consistent growth of personal data protection law, projecting a very clear trend of supplementing the level of legislation regarding the protection of non-personal data.</p>



<p>The forecast based on the current legislative initiative points to a very significant increase in cybersecurity law. This is a rapid and elliptical, massive expansion of cybersecurity law as part of an &#8220;offensive&#8221; of multiplying very extensive cybersecurity regulations.</p>



<p>Cybersecurity regulations are a particularly prominent legislative line within data law. Cybersecurity law shares many common points with defense industry regulations.</p>



<h2 class="wp-block-heading"><strong>CYBERSECURITY</strong></h2>



<p>This is due to the fact that cybersecurity focuses on two separate problems that required a separate legal environment:</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>1/ the first is cybercrime and data leakage area;</strong></p>



<p>The European Union, ENISA, and Polish legislation and agencies such as CSIRT Poland and the Polish Office of Electronic Communications are creating new regulations against hacker attacks and data leaks, which constitute online crimes against property. These are legal tools for the justice system, regulatory authorities, and victims of crimes such as random attacks, i.e., for ransom. This classic online crime has its own legal regulations surrounding data theft and data leaks for ransom, or crimes involving the use of specific email communications to trigger online banking transfers and the identity of bank account holders.</p>



<figure class="wp-block-table has-medium-font-size"><table class="has-white-color has-luminous-vivid-orange-to-vivid-red-gradient-background has-text-color has-background has-link-color has-fixed-layout"><tbody><tr><td class="has-text-align-center" data-align="center" colspan="3"><strong>&nbsp;</strong> <strong>Rising global cost of cybercrime</strong> <strong>1287 password attacks per second (date as of 2023)</strong> <strong>&nbsp;</strong></td></tr><tr><td class="has-text-align-center" data-align="center"><strong>$3 TRILLION</strong> <strong>&nbsp;</strong></td><td class="has-text-align-center" data-align="center"><strong>$</strong><strong>8 TRILLION</strong> <strong>&nbsp;</strong></td><td class="has-text-align-center" data-align="center"><strong>$10.5 TRILLION</strong> <strong>&nbsp;</strong></td></tr><tr><td class="has-text-align-center" data-align="center"><strong>2015</strong></td><td class="has-text-align-center" data-align="center"><strong>2023</strong></td><td class="has-text-align-center" data-align="center"><strong>2025</strong></td></tr></tbody></table></figure>



<p>&#8211; Microsoft data provided at the NDIA conference organized by ETI in Washington DC August 2023.</p>



<p>The goals of this legal community group are:</p>



<p>&#8211; computer systems that infect and secretly download data and do not interfere with the system&#8217;s functionality (an infected router with additional spyware in addition to the usual internet data transmission function &#8211; and this is a private theft patent for the purpose of stealing passwords to private content);</p>



<p>&#8211; software that interferes with the system by breaking security to destroy relevant data.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>2/ the second is the cyber battlefield and spying tools on the Internet</strong></p>



<p>Defence industry sector law, in addition to regulatory law such as the Chips Act for the creation of semiconductors, is rapidly evolving within the framework of cybersecurity law in the defence industry.</p>



<p>This is the result of changes in the needs of the defense sector, especially in the context of the Ukrainian conflict, which is neighboring Poland – the member of the EU and NATO. The conflict remains relevant because the first days of this armed conflict have already shown that, in addition to kinetic military measures concerning conventional objectives such as closing the ring around Kyiv, or through the initial drone revolution and jamming, concentrating the front line towards Odessa (southeastern Ukraine), cyberspace and data processing constitute a separate theater of war.</p>



<p>Therefore, for the Polish legal jurisdiction, in addition to the legal environment of the kinetic component (new law on drones or the issue of new technologies in cooperation with the jurisdiction of the USA, other countries of the North Atlantic Alliance, South Korea or Ukraine), it is the components of cybersecurity and network protection against disinformation (the influencer component) that are the key issues in cybersecurity law.</p>



<p>Therefore, the subject of cybersecurity law comprises three components of military cyber activity: kinetic, cyber and influence, regarding the weakening of the battlefield momentum, internal and external support and all of them concern data processing processes including:</p>



<p>&#8211; systems of destructive attacks on operational logistics systems and the transport sector;</p>



<p>&#8211; government network systems;</p>



<p>&#8211; critical infrastructure such as the functioning of public institutions, for example power plants;</p>



<p>&#8211; disruption of information and disinformation processes of media companies;</p>



<p>&#8211; destructive attacks and data infiltration.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>An additional third legal challenge is the phenomenon of OSINT (Open-Source Intelligence Services) as information tracking.</strong></p>



<p>OSINT as the analysis and tracing of analytical information is the analysis of data for the purposes of commentary in social media such as YT channels with commentary content from former military personnel when tracking armed conflicts, analysis of private stages of conflict development or the operation of new cybernetic and technological military technologies.</p>



<p>The legal environment for such OSINT encompasses the assessment of compliance with cyber law, media and press law, military and state secrets, electronic communications law, and data protection. It also addresses the protection of the interests of such online creators and influencers and freedom of content on social media. The complexity of the legality of the problem provides a new content phenomenon in Polish social media, such as comments on the Ukrainian conflict, assessments of how UV drone technology works and military methods of drone attacks (one of the first examples is the method of attacking a military ship using UV).</p>



<p>OSINT, as the acquisition of information about a debtor&#8217;s assets, is a legal field related to civil procedure to gain a procedural advantage in civil courts. It is also regulated by many telecoms’ regulatory provisions, data protection laws, and privacy laws. Modern methods of obtaining information also primarily concern the legality of the legal environment surrounding the use of OPSEC systems &#8211; that is, the anonymity of the entity collecting such information- such as the use of the TOR network on the Linux operating system, which makes it hard or even impossible to determine the location of an internet user. Another example of the subject of assessing the legality of analytical OSINT is the use of modern all-in-one investigation platforms, like Maltego, to collect data to, for example, identify participants in the crypto market.</p>



<p>Currently, NIS directives implement a number of regulations into the Polish legal system that underpin the legality of OTC securities trading platforms on the FOREX market. This is an example where the legality of implementing a financial market securities trading platform on the websites of professional brokers poses significant difficulties.</p>



<h2 class="wp-block-heading"><strong>MAIN SECTORS AND VECTORS OF THE DATA LAW MAPS</strong></h2>



<figure class="wp-block-image size-large"><a href="https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="1024" height="766" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-1024x766.png" alt="" class="wp-image-8275" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-1024x766.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-300x224.png 300w, https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-768x575.png 768w, https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-1536x1149.png 1536w, https://www.kg-legal.eu/wp-content/uploads/2025/09/KOD-100-2-1-2048x1532.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>





<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size">The main areas of sectoral regulatory law that governs cybersecurity and data protection are:</p>



<ul class="wp-block-list">
<li>HEALTH, PHARMACEUTICALS AND PHARMACEUTICAL INDUSTRY DATA (EHDS initiative);</li>



<li>GENERATIVE AI and NEW TECHNOLOGICAL PROGRESS; (AI ACT and AI procedures on sensitive data are the main basis for assessing that AI is a high-risk system);</li>



<li>FINANCIAL SECTOR and cyber resilience of the financial sector and the problem related to blocking leverage services with financial instruments that operate at the system boundary of the scope of action of the EU agency ESMA dealing with the stock exchange and the problem of the functioning of the financial instruments market;
<ul class="wp-block-list">
<li>Of particular interest to the law in this sector is software that gives an advantage to stock brokers and special regulations blocking the international freedom of these online services. This concerns legal protections for consumers against speculation in financial derivatives. It is worth mentioning the ESMA regulations and the NIS 1 and NIS 2 directives. The DORA regulation, which concerns cybersecurity of data in banks and stock exchanges, and the CER directive are key.</li>



<li>Poland has a special act on internet incidents and an act on the cybersecurity system.</li>
</ul>
</li>



<li>PERSONAL DATA PROTECTION LAW, INCLUDING SENSITIVE DATA, where, in addition to the GDPR, the Polish jurisdiction has an entire range of guidelines from the European Data Protection Board (one of the latest guidelines concerns data processing on blockchain).</li>



<li><strong>NON-PERSONAL DATA PROTECTION LAW, DATABASES AND DATA ACT</strong>.</li>
</ul>



<h1 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Data Law Map</h1>



<h2 class="wp-block-heading">Cybersecurity and Defense</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-174ad23832d97e0820e894693a757dba">Regulation (EU) 2024/2847 (Cyber Resilience Act) (23/10/2024)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2b07b06ce398c499e4683e2b94010557">Regulation (EU) 2023/1781 (Chips Act) (13/09/2023)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-31a3e402483b6d3d24d5345a81311af9">Regulation (EU) 2022/2554 (DORA) (14/12/2022)
<ul class="wp-block-list">
<li>Regulation (EU) 2025/295 supplementing DORA (24/11/2024)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-98d627fe7b901e0fc369e8a950554cf0">Regulation (EU) 2016/679 (GDPR) (27/04/2016)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-f9077fde5e05c97ceb8f04504b72667c">Directive (EU) 2022/2555 (NIS 2) (14/12/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-829af8f12049da50ccad71f75c1c3ba3">Directive (EU) 2022/2557 (CER) (14/12/2022)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-a1556da6467a93462cabddbdcd398c40">Act on the protection of personal data processed in connection with the prevention and combating of crime (14/12/2018)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-eb514d33780683a08281751e4af20a08">Act on the national cybersecurity system (05/07/2018)<ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending certain acts related to the functioning of government administration (15/05/2024)</li></ul><ul><li>Act amending certain acts regarding protective measures in connection with the spread of the SARS-CoV-2 virus (14/05/2020)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Education Law and certain other acts (16/10/2019)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-35c97e3e8888089b840bb9434bb0c3ab">Personal Data Protection Act (10/05/2018)
<ul class="wp-block-list">
<li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Health and Pharmaceutical Industry</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-dbac1ffe91341e8e94c823f38c5f0736">Regulation (EU) 2025/327 (EHDS) (11/05/2025)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2b991517465a7e9ce30f9e9e63efc4dc">Regulation (EU) 2024/1689 (AI Act) (13/06/2024)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-f446df1dc436551039fddaf0b4be1cfc">Regulation (EU) 2024/903 (Interoperable Europe Act) (13/03/2024)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-e943ba8b409dbc90475096a44737573d">Regulation (EU) 2017/745 (MDR) (05/04/2017)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-48caa074a5b20f6f8a6b5d1d91bfe0c7">Regulation (EU) 2017/746 (IVDR) (05/04/2017)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-98d627fe7b901e0fc369e8a950554cf0">Regulation (EU) 2016/679 (GDPR) (27/04/2016)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-f9077fde5e05c97ceb8f04504b72667c">Directive (EU) 2022/2555 (NIS 2) (14/12/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-829af8f12049da50ccad71f75c1c3ba3">Directive (EU) 2022/2557 (CER) (14/12/2022)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-7b4b55dea4440c1b2582520bf04abbd7">Act on clinical trials of medicinal products for human use (09/03/2023)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-eb514d33780683a08281751e4af20a08">Act on the national cybersecurity system (05/07/2018)<ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending certain acts related to the functioning of government administration (15/05/2024)</li></ul><ul><li>Act amending certain acts regarding protective measures in connection with the spread of the SARS-CoV-2 virus (14/05/2020)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Education Law and certain other acts (16/10/2019)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-1c90c3519ce0dbf1b8aad3ecfd53c0c8">Act on Medical Activity (15/04/2011)<ul><li>Act amending the Act on State Emergency Medical Services and certain other acts (24/04/2025)</li></ul><ul><li>Act amending the Act on health care services financed from public funds and certain other acts (05.12.2024)</li></ul><ul><li>Act amending the Act on the Postgraduate Medical Education Center and certain other acts (27/11/2024)</li></ul><ul><li>Act amending the Act on Patients&#8217; Rights and the Patient Ombudsman and certain other acts (26/06/2023)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (17/11/2021)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (11/08/2021)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (10/12/2020)</li></ul><ul><li>Act amending certain acts to ensure the availability of medical personnel during the period of declaration of an epidemic threat or epidemic state (27/11/2020)</li></ul><ul><li>Act amending certain acts in connection with counteracting crisis situations related to the occurrence of COVID-19 (28/10/2020)</li></ul><ul><li>Act amending certain acts to ensure the functioning of health care in connection with the COVID-19 epidemic and after its termination (14/08/2020)</li></ul><ul><li>Act amending certain acts in the field of the health care system related to the prevention, counteraction and combating of COVID-19 (31/03/2020)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (19/07/2019)</li></ul><ul><li>Act amending the Pharmaceutical Law and certain other acts (26/04/2019)</li></ul><ul><li>Act amending the Act on the principles of state property management and certain other acts (21/02/2019)</li></ul><ul><li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (05/07/2018)</li></ul><ul><li>Act amending the Act on Public-Private Partnership and certain other acts (05/07/2018)</li></ul><ul><li>Act amending the Pharmaceutical Law and certain other acts (07.06.2018)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (12/04/2018)</li></ul><ul><li>Act amending the Act on Medical Activity (25/09/2015)</li></ul><ul><li>Act amending the Act on State Emergency Medical Services, the Act on Medical Activity and the Act amending the Act on Medical Activity and certain other acts (25/09/2015)</li></ul><ul><li>Act amending the Act on the professions of nurse and midwife and certain other acts (11/09/2015)</li></ul><ul><li>Act amending the Act on medical devices and certain other acts (11/09/2015)</li></ul><ul><li>Act amending the Act on Medical Activity (24/04/2015)</li></ul><ul><li>Act amending the Act on health care services financed by public funds and certain other acts (22/07/2014)</li></ul><ul><li>Act amending the Public Procurement Law and certain other acts (14/03/2014)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Act on Medical Activity and certain other acts (14/06/2012)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-e190e5afedca81b0699bab6fc637d650">Regulation of the Minister of Health on the types of medical documentation of occupational health services, the method of maintaining and storing it, and the templates of the documents used (29/07/2010)
<ul class="wp-block-list">
<li>Regulation of the Minister of Health amending the regulation on the types of medical documentation of the labor service, the method of keeping and storing it and the templates of the documents used (28/08/2024)</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Artificial Intelligence and Technological Progress</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2b991517465a7e9ce30f9e9e63efc4dc">Regulation (EU) 2024/1689 (AI Act) (13/06/2024)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-f446df1dc436551039fddaf0b4be1cfc">Regulation (EU) 2024/903 (Interoperable Europe Act) (13/03/2024)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2b07b06ce398c499e4683e2b94010557">Regulation (EU) 2023/1781 (Chips Act) (13/09/2023)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-31a3e402483b6d3d24d5345a81311af9">Regulation (EU) 2022/2554 (DORA) (14/12/2022)
<ul class="wp-block-list">
<li>Regulation (EU) 2025/295 supplementing DORA (24/11/2024)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-7855101bbab2bdeb76412f39f390e45e">Regulation (EU) 2018/1807 (14/11/2018)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-e943ba8b409dbc90475096a44737573d">Regulation (EU) 2017/745 (MDR) (05/04/2017)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-48caa074a5b20f6f8a6b5d1d91bfe0c7">Regulation (EU) 2017/746 (IVDR) (05/04/2017)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-4c5678ae249a5b7ad2970f4d7a3ca82a">Directive (EU) 2019/1024 (20/06/2019)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-727d9190ad5f833f02cba86867f7572c">Directive (EU) 2002/58 (12/07/2002)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-91037a63606078cb02429662c9f4e7b5">Act on the national cybersecurity system (05/07/2018)<ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending certain acts related to the functioning of government administration (15/05/2024)</li></ul><ul><li>Act amending certain acts regarding protective measures in connection with the spread of the SARS-CoV-2 virus (14/05/2020)</li></ul>
<ul class="wp-block-list">
<li class="has-vivid-red-color has-text-color has-link-color wp-elements-2afd88c3c27c884d91343b35af4db997">Act amending the Education Law and certain other acts (16/10/2019)</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Finances</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-31a3e402483b6d3d24d5345a81311af9">Regulation (EU) 2022/2554 (DORA) (14/12/2022)
<ul class="wp-block-list">
<li>Regulation (EU) 2025/295 supplementing DORA (24/11/2024)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-d83f748e6377ed78f2c7fccdb03f561e">Regulation (EU) 2017/2394 (12/12/2017)<ul><li>Directive (EU) 2024/1799 amending Regulation (EU) 2017/2394, Directive (EU) 2019/771 and Directive (EU) 2020/1828 (13/06/2024)</li></ul><ul><li>Directive (EU) 2019/771 amending Regulation (EU) 2017/2394 and Directive (EU) 2009/22 and repealing Directive (EU) 1999/44 (20/05/2019)</li></ul>
<ul class="wp-block-list">
<li>Regulation (EU) 2018/302 amending Regulation (EU) 2006/2004, Regulation (EU) 2017/2394 and Directive 2009/22 (28/02/2018)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-98d627fe7b901e0fc369e8a950554cf0">Regulation (EU) 2016/679 (GDPR) (27/04/2016)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-658dac4bdb641d6a0cbadff361b46d77">Regulation (EU) 648/2012 (EMIR) (04/07/2012)<ul><li>Regulation (EU) 2021/23 amending Regulation (EU) 1095/2010, Regulation (EU) 648/2012, Regulation (EU) 600/2014, Regulation (EU) 806/2014, Regulation (EU) 2015/2365, Directive (EU) 2002/47, Directive (EU) 2004/25, Directive (EU) 2007/36, Directive (EU) 2014/59 and Directive (EU) 2017/1132 (16.12.2020)</li></ul><ul><li>Regulation (EU) 2017/2402 amending Directive (EU) 2009/65, Directive (EU) 2009/138, Directive (EU) 2011/61, Regulation (EU) 1060/2009 and Regulation (EU) 648/2012 (12/12/2017)</li></ul><ul><li>Regulation (EU) 2015/2365 amending Regulation (EU) 648/2012 (25/11/2015)</li></ul><ul><li>Regulation (EU) 600/2014 amending Regulation (EU) 648/2012 (15/05/2014)</li></ul><ul><li>Directive (EU) 2014/59 amending Directive (EU) 82/891, Directive (EU) 2001/24, Directive (EU) 2002/47, Directive (EU) 2004/25, Directive (EU) 2005/56, Directive (EU) 2007/36, Directive (EU) 2011/35, Directive (EU) 2012/30, Directive (EU) 2013/36 and Regulation (EU) 1093/2010 and Regulation (EU) 648/2012 (15/05/2014)</li></ul>
<ul class="wp-block-list">
<li>Regulation (EU) 575/2013 amending Regulation (EU) 648/2012 (26/06/2013)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-f9077fde5e05c97ceb8f04504b72667c">Directive (EU) 2022/2555 (NIS 2) (14/12/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-829af8f12049da50ccad71f75c1c3ba3">Directive (EU) 2022/2557 (CER) (14/12/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-dcf6bae6daeab52967e719e282102f0a">Directive (EU) 2020/1828 (25/11/2020)<ul><li>Directive (EU) 2024/1799 amending Regulation (EU) 2017/2394, Directive (EU) 2019/771 and Directive (EU) 2020/1828 (13/06/2024)</li></ul>
<ul class="wp-block-list">
<li>Regulation (EU) 2022/1925 amending Directive (EU) 2019/1937 and Directive (EU) 2020/1828 (14/09/2022)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-68435a403dae5634fd8252a43b900f78">Directive (EU) 2015/2366 (PSD 2) (25/11/2015)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-8d4e796fd0399d45ca40ceee0023fdba">Directive (EU) 96/9 (11/03/1996)
<ul class="wp-block-list">
<li>Directive (EU) 2019/790 amending Directive (EU) 98/9 and Directive (EU) 2001/29 (17/04/2019)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-bb403137b39f4c55086a858523bfbb3d">Act on Trading in Financial Instruments (29/07/2005)<ul><li>Act amending the Act on the Defense of the Homeland and certain other acts (25/06/2025)</li></ul><ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments (24/06/2025)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (09/05/2025)</li></ul><ul><li>Act amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Supervision and certain other acts (06.12.2024)</li></ul><ul><li>Act amending certain acts in connection with ensuring the development of the financial market and the protection of investors on this market (16/08/2023)</li></ul><ul><li>Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee System and Compulsory Restructuring and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on the handling of complaints by financial market entities and on the Financial Ombudsman and certain other acts (01.12.2022)</li></ul><ul><li>Act amending certain acts to simplify administrative procedures for citizens and entrepreneurs (07/10/2022)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (22/07/2022)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/10/2021)</li></ul><ul><li>Act amending the Act on the Capacity Market and certain other acts (23/07/2021)</li></ul><ul><li>Act amending the Act on investment funds and management of alternative investment funds and certain other acts (23/07/2021)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (21/01/2021)</li></ul><ul><li>Act amending the Act on special solutions related to the prevention, counteraction and combating of COVID-19, other infectious diseases and crisis situations caused by them, and certain other acts (31/03/2020)</li></ul><ul><li>Act amending the Act on Government Administration Departments and certain other acts (23/01/2020)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (30/08/2019)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (19/07/2019)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (15/03/2019)</li></ul><ul><li>Act amending certain acts in connection with ensuring the application of GDPR (21/02/2019)</li></ul><ul><li>Act amending certain acts in connection with strengthening supervision over the financial market and investor protection on this market (09/11/2018)</li></ul><ul><li>Act amending certain acts to introduce simplifications for entrepreneurs in tax and economic law (09/11/2018)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/03/2018)</li></ul><ul><li>Act amending the Act on certain rights of employees of the office serving the minister responsible for internal affairs and officers and employees of offices supervised by that minister, and certain other acts (09/11/2017)</li></ul><ul><li>Act amending the Penal Code and certain other acts (23/03/2017)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (10/02/2017)</li></ul><ul><li>Act amending the Act on Investment Funds and certain other acts (32/03/2016)</li></ul><ul><li>Act amending acts regulating the conditions of access to the practice of certain professions (05/08/2015)</li></ul><ul><li>Act amending the Act on Competition and Consumer Protection and certain other acts (05/08/2015)</li></ul><ul><li>Act amending the Act on Capital Market Supervision and certain other acts (12/06/2015)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (05.12.2014)</li></ul><ul><li>Act amending the Act on supplementary supervision of credit institutions, insurance companies, reinsurance companies and investment firms being part of a financial conglomerate and certain other acts (24/04/2014)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (24/10/2012)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (16/09/2011)</li></ul><ul><li>Act amending the Banking Law, the Act on Trading in Financial Instruments and the Act on Financial Market Supervision (28/04/2011)</li></ul><ul><li>Act amending the Banking Act, the Insurance Act, the Investment Funds Act, the Financial Instruments Trading Act and the Financial Market Supervision Act (25/06/2010)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments (22 January 2010)</li></ul><ul><li>Act amending the Act on toll motorways and the National Road Fund and the Act on trading in financial instruments (20/11/2009)</li></ul><ul><li>Act amending the Commercial Companies Code and the Act on Trading in Financial Instruments (05.12.2008)</li></ul>
<ul class="wp-block-list">
<li>Act amending acts to standardize IT terminology (04/09/2008)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-5c5456256f887fc5cdb5948e008e4d26">Banking law (29/08/1997)<ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending certain acts in order to deregulate economic and administrative law and improve the principles of developing economic law (21/05/2025)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (09/05/2025)</li></ul><ul><li>Act amending the Act on Development Cooperation and certain other acts (20/03/2025)</li></ul><ul><li>Act amending the Act on Goods and Services Tax, the Act on Excise Duty and certain other acts (24/01/2025)</li></ul><ul><li>Act amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Supervision and certain other acts (06.12.2024)</li></ul><ul><li>Act amending the Act on the exchange of tax information with other countries and certain other acts (23/05/2024)</li></ul><ul><li>Act amending certain acts in connection with ensuring the development of the financial market and the protection of investors on this market (16/08/2023)</li></ul><ul><li>Act amending certain acts to limit certain effects of identity theft (07/07/2023)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (26/05/2023)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee System and Compulsory Restructuring and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on the handling of complaints by financial market entities and on the Financial Ombudsman and certain other acts (01.12.2022)</li></ul><ul><li>Act amending the Excise Duty Act and certain other acts (01.12.2022)</li></ul><ul><li>Act amending acts to counteract usury (06/10/2022)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (22/07/2022)</li></ul><ul><li>Act amending the Act on Assistance to Citizens of Ukraine in Connection with the Armed Conflict on the Territory of That State and Certain Other Acts (08/04/2022)</li></ul><ul><li>Act amending certain acts in order to improve the terminological consistency of the legal system (01/10/2021)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/10/2021)</li></ul><ul><li>Act amending the Act on Tax on Goods and Services and the Act – Banking Law (11/08/2021)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund, the deposit guarantee system and compulsory restructuring and certain other acts (08/07/2021)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (27/11/2020)</li></ul><ul><li>Act amending the Act – Code of Civil Procedure and certain other acts (13/02/2020)</li></ul><ul><li>Act amending the Act on Government Administration Departments and certain other acts (23/01/2020)</li></ul><ul><li>Act amending the Act on enforcement proceedings in administration and certain other acts (11/09/2019)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (09/08/2019)</li></ul><ul><li>Act amending certain acts to reduce regulatory burdens (31/07/2019)</li></ul><ul><li>Act amending certain acts in order to reduce payment backlogs (19/07/2019)</li></ul><ul><li>Act amending the Act on support for borrowers in financial difficulties who have taken out a housing loan and certain other acts (04/07/2019)</li></ul><ul><li>Act amending the Act on Employee Capital Plans, the Act on the Organization and Operation of Pension Funds and the Banking Law (16/05/2019)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (15/03/2019)</li></ul><ul><li>Act amending certain acts in connection with ensuring the application of GDPR (21/02/2019)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund, the deposit guarantee system and compulsory restructuring and certain other acts (17/01/2019)</li></ul><ul><li>Act amending certain acts in connection with strengthening supervision over the financial market and investor protection on this market (09/11/2018)</li></ul><ul><li>Act amending the Act on the National Revenue Administration and certain other acts (November 9, 2018)</li></ul><ul><li>Act amending the Act on payment services and certain other acts (10/05/2018)</li></ul><ul><li>Act amending the Act on payment services and certain other acts (22/03/2018)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/03/2018)</li></ul><ul><li>Act amending the Act on certain rights of employees of the office serving the minister responsible for internal affairs and officers and employees of offices supervised by that minister, and certain other acts (09/11/2017)</li></ul><ul><li>Act amending the Penal Code and certain other acts (23/03/2017)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (10/02/2017)</li></ul><ul><li>Act amending the Act – Code of Civil Procedure and certain other acts (15/12/2016)</li></ul><ul><li>Act amending the Act – Family and Guardianship Code and certain other acts (10/06/2016)</li></ul><ul><li>Act amending the Act on Investment Funds and certain other acts (31/03/2016)</li></ul><ul><li>Act amending the Act on payment terms in commercial transactions, the Civil Code and certain other acts (09/10/2015)</li></ul><ul><li>Act amending the Banking Law and certain other acts (25/09/2015)</li></ul><ul><li>Act amending the Act on Competition and Consumer Protection and certain other acts (05/08/2015)</li></ul><ul><li>Act amending the Civil Code, the Code of Civil Procedure and certain other acts (10/07/2015)</li></ul><ul><li>Act amending the Act on Capital Market Supervision and certain other acts (12/06/2015)</li></ul><ul><li>Act amending the Act on supplementary supervision of credit institutions, insurance companies, reinsurance companies and investment firms being part of a financial conglomerate and certain other acts (24/04/2014)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (23/10/2013)</li></ul><ul><li>Act amending the Banking Law and the Investment Funds Act (19/04/2013)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (24/10/2012)</li></ul><ul><li>Act amending the Banking Law and the Consumer Credit Act (19/08/2011)</li></ul><ul><li>Act amending the Banking Law and certain other acts (29/07/2011)</li></ul><ul><li>Act amending the Banking Law and certain other acts (10/06/2011)</li></ul><ul><li>Act amending the Banking Law, the Act on Trading in Financial Instruments and the Act on Financial Market Supervision (28/04/2011)</li></ul><ul><li>Act amending the Banking Law, the Insurance Activity Act, the Investment Funds Act, the Financial Instruments Trading Act and the Financial Market Supervision Act (25/06/2010)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and the Banking Law (16/07/2009)</li></ul><ul><li>Act amending the Act on cooperative savings and credit unions and the Banking Law (18/06/2009)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and other acts (23/10/2008)</li></ul><ul><li>Act amending acts to standardize IT terminology (04/09/2008)</li></ul><ul><li>Act amending the Banking Law (04/09/2008)</li></ul><ul><li>Act amending the Act on bailiffs and enforcement and certain other acts (24/05/2007)</li></ul><ul><li>Act amending the Banking Law (26/01/2007)</li></ul><ul><li>Act amending the Banking Law (18/10/2006)</li></ul><ul><li>Act amending the Act on the Protection of Classified Information and certain other acts (15/04/2005)</li></ul><ul><li>Act amending and repealing certain acts in connection with the Republic of Poland&#8217;s accession to the EU (20/04/2004)</li></ul><ul><li>Act amending the Banking Law Act and other acts (01/04/2004)</li></ul><ul><li>Act amending the Act – Law on Public Trading in Securities and amending other acts (12/03/2004)</li></ul><ul><li>Act amending the Act on the National Bank of Poland and other acts (18 December 2003)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (12/12/2003)</li></ul><ul><li>Act amending the Act on the Social Insurance System and certain other acts (18 December 2002)</li></ul><ul><li>Act amending the Tax Ordinance Act and certain other acts (12/09/2002)</li></ul><ul><li>Act amending the Banking Law (27/07/2002)</li></ul><ul><li>Act amending the Act on Mortgage Bonds and Mortgage Banks and amending certain other acts (05/07/2002)</li></ul><ul><li>Act on transformations in the customs administration and on amending certain acts (20/03/2002)</li></ul><ul><li>Act on changes in the organization and functioning of central government administration bodies and their subordinate units and on amending certain acts (01.03.2002)</li></ul><ul><li>Act amending the Act on bailiffs and execution and amending certain other acts (18/09/2001)</li></ul><ul><li>Act amending the Banking Law and other acts (23/08/2001)</li></ul><ul><li>Act amending the Police Act, the Insurance Act, the Banking Law, the County Self-Government Act and the Act – Provisions introducing acts reforming public administration (27/07/2001)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and the Banking Law (15/12/2000)</li></ul><ul><li>Act amending the Penal Code, the Code of Criminal Procedure, the Act on Combating Unfair Competition, the Public Procurement Act and the Banking Law (09/09/2000)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Act on the Bank Guarantee Fund and certain other acts (09/04/1999)</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Access to Information</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-dbac1ffe91341e8e94c823f38c5f0736">Regulation (EU) 2025/327 (EHDS) (11/05/2025)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2de855a5f8eb0ee808cc78991f8039eb">Regulation (EU) 2023/2854 (Data Act) (13/12/2023)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-c1bed4787d070cc8bbbd76e16f2d6d98">Regulation (EU) 2022/868 (Data Governance Act) (30/05/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-7855101bbab2bdeb76412f39f390e45e">Regulation (EU) 2018/1807 (14/11/2018)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-9b4508cc18c3cc064289d63f140c10c8">Regulation (EU) 2018/1725 (EUDPR) (23/10/2018)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-98d627fe7b901e0fc369e8a950554cf0">Regulation (EU) 2016/679 (GDPR) (27/04/2016)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-4c5678ae249a5b7ad2970f4d7a3ca82a">Directive (EU) 2019/1024 (20/06/2019)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-4b148a2852f188a9a4a422528279c8a5">Directive (EU) 2000/31 (e-commerce directive) (08.06.2000)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-8160753715fb34433aaff99763b24c2b">Electronic Communications Law (12/07/2024)<ul><li>Act amending the Act on the Prison Service and certain other acts (09/05/2025)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Act on State Emergency Medical Services and certain other acts (24/04/2025)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-35c97e3e8888089b840bb9434bb0c3ab">Personal Data Protection Act (10/05/2018)
<ul class="wp-block-list">
<li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-e04d455af265c34854b583f30abbb36e">Detective Services Act (06/07/2011)<ul><li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li></ul><ul><li>Act amending certain acts in connection with the standardization of certain templates of documents in administrative procedures (24/04/2014)</li></ul><ul><li>Act amending the Act on detective services (26/11/2010)</li></ul>
<ul class="wp-block-list">
<li>Act amending certain acts in connection with the entry into force of the Protocol to the Agreement between the European Community and its Member States, of the one part, and the Swiss Confederation, of the other, on the free movement of persons (05.09.2008)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-d115359abcc349ecc0b5bf0b64e1a162">Act on Trading in Financial Instruments (29/07/2005)<ul><li>Act amending the Act on the Defense of the Homeland and certain other acts (25/06/2025)</li></ul><ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments (24/06/2025)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (09/05/2025)</li></ul><ul><li>Act amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Supervision and certain other acts (06.12.2024)</li></ul><ul><li>Act amending certain acts in connection with ensuring the development of the financial market and the protection of investors on this market (16/08/2023)</li></ul><ul><li>Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee System and Compulsory Restructuring and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on the handling of complaints by financial market entities and on the Financial Ombudsman and certain other acts (01.12.2022)</li></ul><ul><li>Act amending certain acts in order to simplify administrative procedures for citizens and entrepreneurs (07/10/2022)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (22/07/2022)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/10/2021)</li></ul><ul><li>Act amending the Act on the Capacity Market and certain other acts (23/07/2021)</li></ul><ul><li>Act amending the Act on investment funds and management of alternative investment funds and certain other acts (23/07/2021)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (21/01/2021)</li></ul><ul><li>Act amending the Act on special solutions related to the prevention, counteraction and combating of COVID-19, other infectious diseases and crisis situations caused by them, and certain other acts (31/03/2020)</li></ul><ul><li>Act amending the Act on Government Administration Departments and certain other acts (23/01/2020)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (30/08/2019)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (19/07/2019)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (15/03/2019)</li></ul><ul><li>Act amending certain acts in connection with ensuring the application of GDPR (21/02/2019)</li></ul><ul><li>Act amending certain acts in connection with strengthening supervision over the financial market and investor protection on this market (09/11/2018)</li></ul><ul><li>Act amending certain acts in order to introduce simplifications for entrepreneurs in tax and economic law (09/11/2018)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/03/2018)</li></ul><ul><li>Act amending the Act on certain rights of employees of the office serving the minister responsible for internal affairs and officers and employees of offices supervised by that minister, and certain other acts (09/11/2017)</li></ul><ul><li>Act amending the Penal Code and certain other acts (23/03/2017)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (10/02/2017)</li></ul><ul><li>Act amending the Act on Investment Funds and certain other acts (32/03/2016)</li></ul><ul><li>Act amending acts regulating the conditions of access to certain professions (05/08/2015)</li></ul><ul><li>Act amending the Act on Competition and Consumer Protection and certain other acts (05/08/2015)</li></ul><ul><li>Act amending the Act on Capital Market Supervision and certain other acts (12/06/2015)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (05.12.2014)</li></ul><ul><li>Act amending the Act on supplementary supervision of credit institutions, insurance companies, reinsurance companies and investment firms being part of a financial conglomerate and certain other acts (24/04/2014)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (24/10/2012)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (16/09/2011)</li></ul><ul><li>Act amending the Banking Law, the Act on Trading in Financial Instruments and the Act on Financial Market Supervision (28/04/2011)</li></ul><ul><li>Act amending the Banking Act, the Insurance Act, the Investment Funds Act, the Financial Instruments Trading Act and the Financial Market Supervision Act (25/06/2010)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments (22 January 2010)</li></ul><ul><li>Act amending the Act on toll motorways and the National Road Fund and the Act on trading in financial instruments (20/11/2009)</li></ul><ul><li>Act amending the Commercial Companies Code and the Act on Trading in Financial Instruments (05.12.2008)</li></ul>
<ul class="wp-block-list">
<li>Act amending acts to standardize IT terminology (04/09/2008)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-ed7213e8293a9a4138fd08eeb991a9ab">Banking law (29/08/1997)<ul><li>Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds (25/06/2025)</li></ul><ul><li>Act amending certain acts in order to deregulate economic and administrative law and improve the principles of developing economic law (21/05/2025)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (09/05/2025)</li></ul><ul><li>Act amending the Act on Development Cooperation and certain other acts (20/03/2025)</li></ul><ul><li>Act amending the Act on Goods and Services Tax, the Act on Excise Duty and certain other acts (24/01/2025)</li></ul><ul><li>Act amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Supervision and certain other acts (06.12.2024)</li></ul><ul><li>Act amending the Act on the exchange of tax information with other countries and certain other acts (23/05/2024)</li></ul><ul><li>Act amending certain acts in connection with ensuring the development of the financial market and the protection of investors on this market (16/08/2023)</li></ul><ul><li>Act amending certain acts to limit certain effects of identity theft (07/07/2023)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (26/05/2023)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee System and Compulsory Restructuring and certain other acts (14/04/2023)</li></ul><ul><li>Act amending the Act on the handling of complaints by financial market entities and on the Financial Ombudsman and certain other acts (01.12.2022)</li></ul><ul><li>Act amending the Excise Duty Act and certain other acts (01.12.2022)</li></ul><ul><li>Act amending acts to counteract usury (06/10/2022)</li></ul><ul><li>Act amending the Act on the Prison Service and certain other acts (22/07/2022)</li></ul><ul><li>Act amending the Act on Assistance to Citizens of Ukraine in Connection with the Armed Conflict on the Territory of That State and Certain Other Acts (08/04/2022)</li></ul><ul><li>Act amending certain acts in order to improve the terminological consistency of the legal system (01/10/2021)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/10/2021)</li></ul><ul><li>Act amending the Act on Tax on Goods and Services and the Act – Banking Law (11/08/2021)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund, the deposit guarantee system and compulsory restructuring and certain other acts (08/07/2021)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (27/11/2020)</li></ul><ul><li>Act amending the Act – Code of Civil Procedure and certain other acts (13/02/2020)</li></ul><ul><li>Act amending the Act on Government Administration Departments and certain other acts (23/01/2020)</li></ul><ul><li>Act amending the Act on enforcement proceedings in administration and certain other acts (11/09/2019)</li></ul><ul><li>Act amending the Act on Goods and Services Tax and certain other acts (09/08/2019)</li></ul><ul><li>Act amending certain acts to reduce regulatory burdens (31/07/2019)</li></ul><ul><li>Act amending certain acts in order to reduce payment backlogs (19/07/2019)</li></ul><ul><li>Act amending the Act on support for borrowers in financial difficulties who have taken out a housing loan and certain other acts (04/07/2019)</li></ul><ul><li>Act amending the Act on Employee Capital Plans, the Act on the Organization and Operation of Pension Funds and the Banking Law (16/05/2019)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (15/03/2019)</li></ul><ul><li>Act amending certain acts in connection with ensuring the application of GDPR (21/02/2019)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund, the deposit guarantee system and compulsory restructuring and certain other acts (17/01/2019)</li></ul><ul><li>Act amending certain acts in connection with strengthening supervision over the financial market and investor protection on this market (09/11/2018)</li></ul><ul><li>Act amending the Act on the National Revenue Administration and certain other acts (November 9, 2018)</li></ul><ul><li>Act amending the Act on payment services and certain other acts (10/05/2018)</li></ul><ul><li>Act amending the Act on payment services and certain other acts (22/03/2018)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (01/03/2018)</li></ul><ul><li>Act amending the Act on certain rights of employees of the office serving the minister responsible for internal affairs and officers and employees of offices supervised by that minister, and certain other acts (09/11/2017)</li></ul><ul><li>Act amending the Penal Code and certain other acts (23/03/2017)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (10/02/2017)</li></ul><ul><li>Act amending the Code of Civil Procedure and certain other acts (15/12/2016)</li></ul><ul><li>Act amending the Act – Family and Guardianship Code and certain other acts (10/06/2016)</li></ul><ul><li>Act amending the Act on Investment Funds and certain other acts (31/03/2016)</li></ul><ul><li>Act amending the Act on payment terms in commercial transactions, the Civil Code and certain other acts (09/10/2015)</li></ul><ul><li>Act amending the Banking Law and certain other acts (25/09/2015)</li></ul><ul><li>Act amending the Act on Competition and Consumer Protection and certain other acts (05/08/2015)</li></ul><ul><li>Act amending the Civil Code, the Code of Civil Procedure and certain other acts (10/07/2015)</li></ul><ul><li>Act amending the Act on Capital Market Supervision and certain other acts (12/06/2015)</li></ul><ul><li>Act amending the Act on supplementary supervision of credit institutions, insurance companies, reinsurance companies and investment firms being part of a financial conglomerate and certain other acts (24/04/2014)</li></ul><ul><li>Act amending the Act on Financial Market Supervision and certain other acts (23/10/2013)</li></ul><ul><li>Act amending the Banking Law and the Investment Funds Act (19/04/2013)</li></ul><ul><li>Act amending the Act on Trading in Financial Instruments and certain other acts (24/10/2012)</li></ul><ul><li>Act amending the Banking Law and the Consumer Credit Act (19/08/2011)</li></ul><ul><li>Act amending the Banking Law and certain other acts (29/07/2011)</li></ul><ul><li>Act amending the Banking Law and certain other acts (10/06/2011)</li></ul><ul><li>Act amending the Banking Law, the Act on Trading in Financial Instruments and the Act on Financial Market Supervision (28/04/2011)</li></ul><ul><li>Act amending the Banking Law, the Insurance Activity Act, the Investment Funds Act, the Financial Instruments Trading Act and the Financial Market Supervision Act (25/06/2010)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and the Banking Law (16/07/2009)</li></ul><ul><li>Act amending the Act on cooperative savings and credit unions and the Banking Law (18/06/2009)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and other acts (23/10/2008)</li></ul><ul><li>Act amending acts to standardize IT terminology (04/09/2008)</li></ul><ul><li>Act amending the Banking Law (04/09/2008)</li></ul><ul><li>Act amending the Act on court bailiffs and enforcement and certain other acts (24/05/2007)</li></ul><ul><li>Act amending the Banking Law (26/01/2007)</li></ul><ul><li>Act amending the Banking Law (18/10/2006)</li></ul><ul><li>Act amending the Act on the Protection of Classified Information and certain other acts (15/04/2005)</li></ul><ul><li>Act amending and repealing certain acts in connection with the Republic of Poland&#8217;s accession to the EU (20/04/2004)</li></ul><ul><li>Act amending the Banking Law Act and other acts (01/04/2004)</li></ul><ul><li>Act amending the Act – Law on Public Trading in Securities and amending other acts (12/03/2004)</li></ul><ul><li>Act amending the Act on the National Bank of Poland and other acts (18 December 2003)</li></ul><ul><li>Act amending the Commercial Companies Code and certain other acts (12/12/2003)</li></ul><ul><li>Act amending the Act on the Social Insurance System and certain other acts (18 December 2002)</li></ul><ul><li>Act amending the Tax Ordinance Act and certain other acts (12/09/2002)</li></ul><ul><li>Act amending the Banking Law (27/07/2002)</li></ul><ul><li>Act amending the Act on Mortgage Bonds and Mortgage Banks and amending certain other acts (05/07/2002)</li></ul><ul><li>Act on transformation of the customs administration and on amending certain acts (20/03/2002)</li></ul><ul><li>Act on changes in the organization and functioning of central government administration bodies and their subordinate units and on amending certain acts (01/03/2002)</li></ul><ul><li>Act amending the Act on bailiffs and execution and on amending certain other acts (18/09/2001)</li></ul><ul><li>Act amending the Banking Law and other acts (23/08/2001)</li></ul><ul><li>Act amending the Police Act, the Insurance Act, the Banking Law, the County Self-Government Act and the Act – Provisions introducing acts reforming public administration (27/07/2001)</li></ul><ul><li>Act amending the Act on the Bank Guarantee Fund and the Banking Law (15/12/2000)</li></ul><ul><li>Act amending the Penal Code, the Code of Criminal Procedure, the Act on Combating Unfair Competition, the Public Procurement Act and the Banking Law (09/09/2000)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Act on the Bank Guarantee Fund and certain other acts (09/04/1999)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-2d296c99d18748921dc17c0c610c599b">Press Law (26/01/1984)<ul><li>Act amending the Press Law (20/07/2018)</li></ul><ul><li>Act amending the Press Law (27/10/2017)</li></ul><ul><li>Act amending the Press Law (10/05/2013)</li></ul><ul><li>Act amending the Press Law (14/09/2012)</li></ul><ul><li>Act amending the Press Law (19/08/2011)</li></ul><ul><li>Act amending the Civil Code (23/08/1996)</li></ul>
<ul class="wp-block-list">
<li>Act amending the Press Law (30/05/1989)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-fd87c994c2681c3747b12445467d045f">Regulation of the Council of Ministers on the National Interoperability Framework, minimum requirements for public registers and the exchange of information in electronic form, and minimum requirements for ICT systems (21/05/2024)</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Personal Data</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-dbac1ffe91341e8e94c823f38c5f0736">Regulation (EU) 2025/327 (EHDS) (11/05/2025)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2de855a5f8eb0ee808cc78991f8039eb">Regulation (EU) 2023/2854 (Data Act) (13/12/2023)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-9b4508cc18c3cc064289d63f140c10c8">Regulation (EU) 2018/1725 (EUDPR) (23/10/2018)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-d83f748e6377ed78f2c7fccdb03f561e">Regulation (EU) 2017/2394 (12/12/2017)<ul><li>Directive (EU) 2024/1799 amending Regulation (EU) 2017/2394, Directive (EU) 2019/771 and Directive (EU) 2020/1828 (13/06/2024)</li></ul><ul><li>Directive (EU) 2019/771 amending Regulation (EU) 2017/2394 and Directive (EU) 2009/22 and repealing Directive (EU) 1999/44 (20/05/2019)</li></ul>
<ul class="wp-block-list">
<li>Regulation (EU) 2018/302 amending Regulation (EU) 2006/2004, Regulation (EU) 2017/2394 and Directive 2009/22 (28/02/2018)</li>
</ul>
</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-98d627fe7b901e0fc369e8a950554cf0">Regulation (EU) 2016/679 (GDPR) (27/04/2016)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-158e73e1ffd5e03a82b718e824a4154e">Directive (EU) 2016/680 (LED) (27/04/2016)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-a1556da6467a93462cabddbdcd398c40">Act on the protection of personal data processed in connection with the prevention and combating of crime (14/12/2018)</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-35c97e3e8888089b840bb9434bb0c3ab">Personal Data Protection Act (10/05/2018)
<ul class="wp-block-list">
<li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li>
</ul>
</li>



<li class="has-vivid-red-color has-text-color has-link-color wp-elements-64e10c01cdf18297dbb5cad0209e751c">Detective Services Act (06/07/2011)<ul><li>Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC (21/02/2019)</li></ul><ul><li>Act amending certain acts in connection with the standardization of certain templates of documents in administrative procedures (24/04/2014)</li></ul><ul><li>Act amending the Act on detective services (26/11/2010)</li></ul>
<ul class="wp-block-list">
<li>Act amending certain acts in connection with the entry into force of the Protocol to the Agreement between the European Community and its Member States, of the one part, and the Swiss Confederation, of the other, on the free movement of persons (05/09/2008)</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Non-Personal Data</h2>



<ul class="wp-block-list">
<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-2de855a5f8eb0ee808cc78991f8039eb">Regulation (EU) 2023/2854 (Data Act) (13/12/2023)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-c1bed4787d070cc8bbbd76e16f2d6d98">Regulation (EU) 2022/868 (Data Governance Act) (30/05/2022)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-4c5678ae249a5b7ad2970f4d7a3ca82a">Directive (EU) 2019/1024 (20/06/2019)</li>



<li class="has-vivid-cyan-blue-color has-text-color has-link-color wp-elements-7855101bbab2bdeb76412f39f390e45e">Regulation (EU) 2018/1807 (14/11/2018)</li>
</ul>



<h2 class="wp-block-heading">Legal Acts</h2>



<ul class="wp-block-list">
<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2016/679 (GDPR)</mark></strong><a href="http://data.europa.eu/eli/reg/2016/679/2016-05-04"> http://data.europa.eu/eli/reg/2016/679/2016-05-04</a><ul><li>The GDPR applies to the processing of personal data of European Union citizens. This covers all data-related operations, such as collection, storage, analysis, and sharing, regardless of whether they are carried out by automated means. The regulation aims to protect the privacy of individuals and ensure that their personal data is processed securely and lawfully. The GDPR covers the protection of personal data, which is any information that can identify a natural person. The regulation imposes several principles on entities processing data, such as the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. The GDPR grants data subjects a number of rights, such as the right to access, rectification, erasure (the right to be forgotten), restriction of processing, data portability, and the right to object to processing. Data processors must implement appropriate technical and organizational measures to ensure data security and compliance with the GDPR principles. The GDPR applies to all organizations that process personal data of EU citizens, regardless of their location. Violation of GDPR provisions may result in the imposition of high financial penalties.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.edpb.europa.eu/system/files/2023-06/edpb_guidelines_042022_calculationofadministrativefines_en.pdf" target="_blank" rel="noreferrer noopener">https://www.edpb.europa.eu/system/files/2023-06/edpb_guidelines_042022_calculationofadministrativefines_en.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation 2025/327 (EHDS)</mark></strong><a href="http://data.europa.eu/eli/reg/2025/327/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2025/327/oj</a><ul><li>The European Health Data Space regulates the exchange and use of health data in the European Union. The main goals of the regulation are to ensure secure access to citizens&#8217; health data across the EU, facilitate the exchange of information between healthcare providers, and promote innovation in the field of health. The regulation aims to:<ul><li>Increasing patient control over their health data:<ul><li>Citizens will have the right to access their electronic health data and control its use.</li></ul>Improving the exchange of health data between Member States:<ul><li>This will enable secure data sharing between different medical facilities in the EU, contributing to better healthcare.</li></ul>Supporting research and innovation:<ul><li>EHDS is intended to facilitate access to health data for research purposes, which is expected to accelerate the development of new therapies and improve disease prevention.</li></ul>Increase preparedness for future health crises:<ul><li>Through improved information flow, EHDS is intended to help respond to health crises more quickly and effectively.</li></ul></li></ul></li></ul>
<ul class="wp-block-list">
<li>The introduction of the EHDS requires adapting national healthcare systems to new requirements. As a member state, Poland must adapt its regulations and IT infrastructure to the new regulations to ensure full compliance with the EHDS.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2022/2554 (DORA)</mark></strong><a href="http://data.europa.eu/eli/reg/2022/2554/oj" target="_blank" rel="noreferrer noopener"> http://data.europa.eu/eli/reg/2022/2554/oj</a><ul><li>DORA governs the digital operational resilience of the EU financial sector by establishing a comprehensive framework for managing risks related to information and communication technologies (ICT). Key aspects regulated by DORA include:<ul><li>ICT Risk Management: DORA requires financial institutions to proactively and comprehensively manage all types of ICT-related risks.Incident Reporting: The Regulation specifies which ICT-related incidents are subject to mandatory reporting and sets out detailed reporting procedures.Resilience Testing: Financial institutions are required to regularly conduct digital resilience testing, including penetration testing.Third-party ICT service providers: DORA establishes a supervisory framework for key third-party ICT service providers and regulates their relationships with financial institutions.Harmonisation of standards: The Regulation aims to create a unified front for cyber resilience across the EU by harmonising security standards.</li></ul>The main goal of DORA is to ensure financial stability by strengthening the digital resilience of financial institutions to cyberattacks and other digital threats, which translates into increased trust in the financial sector.<strong>Regulation (EU) 2025/295 supplements DORA with regard to regulatory technical standards for the harmonisation of the conditions for conducting supervisory activities. </strong><a href="http://data.europa.eu/eli/reg_del/2025/295/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg_del/2025/295/oj</a></li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/2025-05/2025.04311_01_ms_v2.0_Handbook%20for%20Cyber%20Stress%20Tests_en.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/2025-05/2025.04311_01_ms_v2.0_Handbook%20for%20Cyber%20Stress%20Tests_en.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color">Regulation (EU) 2023/1781 (Chips Act )</mark></mark></strong><a href="http://data.europa.eu/eli/reg/2023/1781/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2023/1781/oj</a></li>



<li class="has-medium-font-size"><ul><li>The European Chips Act aims to strengthen the European semiconductor ecosystem, increase the European Union&#8217;s competitiveness and technological sovereignty by supporting research, production, and development of innovative technologies in this sector, and ensure the resilience of supply chains and reduce dependence on non-EU suppliers. Main objectives and provisions:</li></ul></li>



<li class="has-medium-font-size"><ul><li>Strengthening research and technological leadership: The Act aims to boost Europe&#8217;s capacity to innovate in the design, production and packaging of advanced chips;</li></ul></li>



<li class="has-medium-font-size"><ul><li>Increasing production capacity: A legal framework and investments, including support for pioneering production facilities, are provided to increase semiconductor production in the EU and double the EU&#8217;s share of the global market by 2030;</li></ul></li>



<li class="has-medium-font-size"><ul><li>Supply chain coordination and monitoring: The Regulation introduces mechanisms to monitor global supply chains, anticipate shortages and coordinate actions with Member States to ensure stability of supply;</li></ul></li>



<li class="has-medium-font-size"><ul><li>Development of skilled workforce: The activities also aim to attract new talent and address the shortage of skilled labor in the semiconductor sector;</li></ul>
<ul class="wp-block-list">
<li class="has-medium-font-size">Increasing resilience and technological sovereignty: By strengthening the European semiconductor ecosystem, the Act aims to increase Europe&#8217;s autonomy and resilience to global crises and supply disruptions.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2024/2847</mark><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color"><mark> (Cyber Resilience Act)</mark></mark></strong><a href="http://data.europa.eu/eli/reg/2024/2847/2024-11-20"> </a><a href="http://data.europa.eu/eli/reg/2024/2847/2024-11-20" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2024/2847/2024-11-20</a><ul><li>The CRA is an EU legal act establishing uniform cybersecurity requirements for all digital products introduced to the European Union market. Its main goal is to ensure that, from design and production, and throughout the product lifecycle, hardware and software are built with security in mind, minimizing security vulnerabilities and reducing the risk of attacks. The CRA addresses:<ul><li>Manufacturers: Holds them responsible for the security of their digital products throughout their lifespan;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Importers and distributors: Responsible for placing compliant products on the market;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Consumers: Influences their choices by giving access to more secure devices;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>The Regulation entered into force on December 10, 2024. Most of the CRA requirements will become mandatory from September 11, 2026, and will be fully applicable on December 11, 2027.</li></ul></li>



<li class="has-medium-font-size"><ul><li>In the event of non-compliance with the regulation, high financial penalties are foreseen.</li></ul></li>



<li class="has-medium-font-size"><ul><li>In summary, CRA is introducing security standards that will make digital products such as smartwatches, smart refrigerators and antivirus software safer for users and better protected against cyber threats.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/2024-11/Cyber%20Resilience%20Act%20Requirements%20Standards%20Mapping%20-%20final_with_identifiers_0.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/2024-11/Cyber%20Resilience%20Act%20Requirements%20Standards%20Mapping%20-%20final_with_identifiers_0.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2023/2854 (Data Act )</mark></strong><a href="http://data.europa.eu/eli/reg/2023/2854/oj"> </a><a href="http://data.europa.eu/eli/reg/2023/2854/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2023/2854/oj</a><ul><li>The Data Regulation is an EU law aimed at regulating access to, exchange, and use of data, particularly data generated by devices connected to the Internet of Things (IoT). The Data Act aims to increase competitiveness and innovation in the European market by facilitating access to data for various entities, including consumers, businesses, and public administrations. The main objectives of the Data Act are:<ul><li>Data sharing by manufacturers and service providers:<ul><li>The Data Act imposes an obligation to share data generated by IoT devices with their users, other companies (including competitors) and, in certain cases, public authorities;</li></ul>Protection of personal data:<ul><li>Sharing of personal data may only occur at the user&#8217;s request and must be in accordance with the General Data Protection Regulation (GDPR);</li></ul>Contract transparency:<ul><li>The Data Act aims to counteract unfair contractual provisions regarding access to and use of data;</li></ul>Possibility to change cloud service providers:<ul><li>The regulation aims to facilitate the switching of cloud computing service providers and improve the interoperability of data and services;</li></ul>Supporting innovation:<ul><li>Easier access to data is intended to support the creation of new products and services, especially by small and medium-sized enterprises;</li></ul>Competition and choice:<ul><li>Consumers will gain greater control over their data and a wider choice of service providers.</li></ul></li></ul>Data Act applies to:<ul><li>IoT devices (e.g. smart household appliances, cars, agricultural machinery);Service providers who process data from these devices;IoT devices (both consumers and businesses);Companies that want to use data to create new products and services;Public administration.</li></ul>The Data Act is scheduled to enter into force on September 12, 2025.The Data Act complements the GDPR by regulating access to and use of data beyond just personal data. While the GDPR continues to protect personal data, the Data Act introduces additional provisions for the sharing and use of data, including non-personal data, to promote innovation and competitiveness.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/Data%20Spaces%20Report.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/Data%20Spaces%20Report.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2022/868 (Data Governance Act) </mark></strong><a href="http://data.europa.eu/eli/reg/2022/868/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2022/868/oj</a><ul><li>Data Governance Act is a European Union regulation that establishes rules for the secure and transparent sharing and reuse of data, especially data held by the public sector. The regulation introduces mechanisms to support data exchange, including data brokerage services (aggregating and sharing data) and promoting data altruism (voluntary, free data sharing). Its goal is to support the digital economy, innovation, and better use of data for public and commercial purposes. The Act facilitates access to protected public data in a secure and controlled manner, while requiring its anonymity and compliance with personal data protection law (e.g., GDPR). It creates a framework for trusted providers who can act as intermediaries in data exchange. It promotes voluntary and free sharing of data by individuals and organizations with other entities. Improved conditions for data use are intended to foster the development of new data-driven products and services and increase the competitiveness of European businesses. Trust in data-sharing mechanisms is crucial for the development of a data-driven economy. The <strong>DGA is the EU&#8217;s first step in creating a comprehensive legal framework for data management</strong>. It is complemented by the Data Act, which focuses on regulating access to data generated by Internet of Things (IoT) devices.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/Data%20Spaces%20Report.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/Data%20Spaces%20Report.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2017/2394</mark></strong><a href="http://data.europa.eu/eli/reg/2017/2394/2025-01-19"> </a><a href="http://data.europa.eu/eli/reg/2017/2394/2025-01-19" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2017/2394/2025-01-19</a><ul><li>Regulation (EU) 2017/2394 governs cooperation between national authorities responsible for enforcing consumer protection laws. Its main objective is to ensure effective international cooperation in combating infringements of consumer rights, so as to protect the interests of consumers in the EU single market. Key aspects of the regulation include:<ul><li>Establishes a framework for cooperation between authorities such as those operating in the Consumer Protection Cooperation (CPC) network;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>It aims to guarantee a high level of consumer protection in all Member States, regardless of where they purchase or travel;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Enables coordinated action against unfair commercial practices that harm consumers across the European Union;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Enforcement authorities can require businesses to make good the damage, compensate consumers and apply effective sanctions, which can amount to up to 4% of the company&#8217;s turnover in a given EU country.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>This regulation applies to a wide range of consumer protection issues, including unfair commercial practices, product safety, personal data protection, financial services, and e-commerce. In short, Regulation 2017/2394 is a key instrument in EU consumer policy, aiming to ensure that consumers across the European Union are protected from unfair practices and can benefit from safe products and services.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Directive (EU) 2024/1799 amends Regulation (EU) 2017/2394 and Directives (EU) 2019/771 and (EU) 2020/1828 on common rules promoting the repair of goods. </strong><a href="http://data.europa.eu/eli/dir/2024/1799/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2024/1799/oj</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Directive (EU) 2019/771 amends Regulation (EU) 2017/2394 and Directive (EU) 2009/22 and repeals Directive (EU) 1999/44 on certain aspects concerning contracts for the sale of goods. </strong><a href="https://eur-lex.europa.eu/legal-content/PL/TXT/HTML/?uri=CELEX:02019L0771-20190522" target="_blank" rel="noreferrer noopener">https://eur-lex.europa.eu/legal-content/PL/TXT/HTML/?uri=CELEX:02019L0771-20190522 </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>Regulation (EU) 2018/302 amends Regulation (EU) 2006/2004 and Regulation (EU) 2017/2394 and Directive 2009/22 on unjustified geo-blocking and other forms of discrimination against customers based on their nationality, place of residence or place of establishment in the internal market.</strong> <a href="http://data.europa.eu/eli/reg/2018/302/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2018/302/oj</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color">Regulation (EU) 2024/1689 (AI Act )</mark></strong><a href="http://data.europa.eu/eli/reg/2024/1689/oj">http://data.europa.eu/eli/reg/2024/1689/oj</a><ul><li>The AI Act establishes a comprehensive legal framework for AI in the EU. It classifies AI systems based on risk levels and imposes specific obligations on AI providers and implementers. The goal is to foster trustworthy AI, ensure security, protect fundamental rights, and promote innovation. Due to the scope of the regulations, the individual elements of the AI Act are being implemented gradually. The AI Act stipulates:<ul><li>Harmonised rules for the placing on the market, putting into service and use of AI systems in the EU;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Prohibitions on certain AI practices;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Specific requirements for high-risk AI systems and obligations incumbent on operators of such systems;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Harmonized transparency rules for certain AI systems;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Harmonized rules for placing general-purpose AI models on the market;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Provisions relating to marketing monitoring, market surveillance, management and enforcement;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Measures to support innovation, with particular emphasis on SMEs, including start-ups.</li></ul>The AI Act applies to:<ul><li>Providers placing AI systems or general purpose AI models on the market in the EU, regardless of whether those providers are established or located in the EU or in a third country;Entities using AI systems that are established or located in the EU;Providers of AI systems and entities using AI systems that are established or located in a third country where the results produced by the AI system are used in the EU;Importers and distributors of AI systems;Product manufacturers who, under their own name or trademark, and together with their product, introduce an AI system into the market or put it into use;Authorised representatives of suppliers not established in the EU;People affected by AI who are located in the EU.</li></ul></li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/Artificial%20Intelligence%20and%20Cybersecurity%20Research.pdf">https://www.enisa.europa.eu/sites/default/files/publications/Artificial%20Intelligence%20and%20Cybersecurity%20Research.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2018/1725 (EUDPR)</mark></strong><a href="http://data.europa.eu/eli/reg/2018/1725/oj">http://data.europa.eu/eli/reg/2018/1725/oj</a>
<ul class="wp-block-list">
<li>Regulation (EU) 2018/1725 governs the processing of personal data by European Union institutions, bodies, and other agencies. This regulation repeals previous regulations in this area and introduces personal data protection principles similar to those contained in the GDPR. Individuals whose data is processed by EU institutions have the right to access, rectify, block, or erase their data. In case of doubts or problems, you can contact the data controller and, in the event of a dispute, the Data Protection Officer or the European Data Protection Supervisor (EDPS).</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2018/1807</mark></strong><a href="http://data.europa.eu/eli/reg/2018/1807/oj">http://data.europa.eu/eli/reg/2018/1807/oj</a>
<ul class="wp-block-list">
<li>Regulation (EU) 2018/2018 provides a framework for the free flow of non-personal data within the European Union. Its main goal is to ensure the free movement of non-personal data within the EU single market, while prohibiting Member States from imposing data localization requirements (e.g., storing them in a specific country) unless justified by public security concerns. The regulation aims to foster the development of modern technologies, such as the cloud and artificial intelligence, by facilitating the cross-border mobility of non-personal data. The regulation ensures that competent authorities have access to non-personal data for control, inspection, and audit purposes. It makes it easier for professional users to transfer data from one processing or storage service provider to another, preventing market disruptions. It entered into force on May 28, 2019.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2024/903 (Interoperable Europe Act)</mark></strong><a href="http://data.europa.eu/eli/reg/2024/903/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2024/903/oj</a><ul><li>Regulation (EU) 2024/903 establishes a framework for cooperation between Member States&#8217; public administrations to enable them to deliver public services efficiently across borders, while supporting the digital transformation and the &#8220;only once&#8221; principle. This act aims to simplify administrative processes for citizens and businesses, providing them with access to high-quality digital services regardless of their place of residence in the EU. It enables various public administrations, as well as systems and services, to exchange data and effectively interact. It ensures the efficient provision of public services (e.g., health, taxation, professional qualifications) between different Member States. The Interoperable Europe Act introduces mechanisms to support the goal of making all key public services available electronically by 2030 – including enabling citizens and businesses to share data for official purposes only once, without having to submit the same information repeatedly. An Interoperable Europe Council was established, responsible for the development and oversight of the implementation of common solutions. The act supports openness and cooperation with the private and scientific sectors. Emphasis is placed on the accessibility of digital public services for all, including the elderly, people with disabilities, and other vulnerable groups.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://interoperable-europe.ec.europa.eu/sites/default/files/document/2025-03/Local%20Policy%20Brief%20-%20Digital%20Counter.pdf" target="_blank" rel="noreferrer noopener">https://interoperable-europe.ec.europa.eu/sites/default/files/document/2025-03/Local%20Policy%20Brief%20-%20Digital%20Counter.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 648/2012 (EMIR)</mark> </strong><a href="http://data.europa.eu/eli/reg/2012/648/2025-01-17">http://data.europa.eu/eli/reg/2012/648/2025-01-17</a><ul><li>European Market Infrastructure Regulation enhances the security and transparency of the European over-the-counter (OTC) derivatives market by introducing obligations regarding transaction clearing, risk management, and reporting to trade repositories. Its purpose is to reduce systemic and operational risk, prevent future financial crises, and provide market reassurance. This regulation applies to financial contracts not concluded on regulated exchanges, such as energy, gas, foreign exchange, and interest rate contracts. EMIR requires certain transactions to be cleared through a central counterparty (CCP), which is intended to increase security. It obliges entities to report details of concluded transactions to a trade repository. It introduces requirements for managing the risks associated with derivative contracts, including the obligation to conclude transaction processing agreements. The regulation applies to various entities that conclude derivatives transactions. The main objectives of EMIR:<ul><li>Reducing systemic risk associated with the derivatives market;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Calming markets through better risk management and increased transparency;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Enabling regulators to better monitor and oversee the market.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Regulation (EU) 2021/23 amends Regulation (EU) 1095/2010, Regulation (EU) 648/2012, Regulation (EU) 600/2014, Regulation (EU) 806/2014, Regulation (EU) 2015/2365, Directive (EU) 2002/47, Directive (EU) 2004/25, Directive (EU) 2007/36, Directive (EU) 2014/59 and Directive (EU) 2017/1132 on a framework for the recovery and resolution of central counterparties. </strong><a href="http://data.europa.eu/eli/reg/2021/23/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2021/23/oj</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Regulation (EU) 2017/2402 amends Directive (EU) 2009/65, Directive (EU) 2009/138, Directive (EU) 2011/61, Regulation (EU) 1060/2009 and Regulation (EU) 648/2012 laying down a general framework for securitisation and creating a specific framework for simple, transparent and standardised securitisation. </strong><a href="http://data.europa.eu/eli/reg/2017/2402/2021-04-09">http://data.europa.eu/eli/reg/2017/2402/2021-04-09</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Regulation (EU) 2015/2365 amends Regulation (EU) 648/2012 on transparency of securities financing transactions and reuse. </strong><a href="http://data.europa.eu/eli/reg/2015/2365/2024-01-09">http://data.europa.eu/eli/reg/2015/2365/2024-01-09</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Regulation (EU) 600/2014 amends Regulation (EU) 648/2012 on markets in financial instruments. </strong><a href="http://data.europa.eu/eli/reg/2014/600/2025-01-17" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2014/600/2025-01-17</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Directive (EU) 2014/59 amends Directive (EU) 82/891, Directive (EU) 2001/24, Directive (EU) 2002/47, Directive (EU) 2004/25, Directive (EU) 2005/56, Directive (EU) 2007/36, Directive (EU) 2011/35, Directive (EU) 2012/30, Directive (EU) 2013/36, Regulation (EU) 1093/2010 and Regulation (EU) 648/2012 for the recovery and resolution of credit institutions and investment firms. </strong><a href="http://data.europa.eu/eli/dir/2014/59/2025-01-17" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2014/59/2025-01-17</a></li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Regulation (EU) 575/2013 amends Regulation (EU) 648/2012 on prudential requirements for credit institutions. </strong><a href="http://data.europa.eu/eli/reg/2013/575/2025-06-29" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2013/575/2025-06-29</a></li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.esma.europa.eu/sites/default/files/2024-03/ESMA12-2121844265-3254_Guidelines_on_position_calculation_under_EMIR_Refit.pdf" target="_blank" rel="noreferrer noopener">https://www.esma.europa.eu/sites/default/files/2024-03/ESMA12-2121844265-3254_Guidelines_on_position_calculation_under_EMIR_Refit.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2017/745 (MDR)</mark></strong><a href="http://data.europa.eu/eli/reg/2017/745/2025-01-10" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2017/745/2025-01-10</a><ul><li>The Medical Device Regulation establishes uniform and more stringent rules for the marketing, distribution, and monitoring of medical devices in the European Economic Area. The main objectives and key aspects of the MDR:<ul><li>Ensuring a robust, transparent and sustainable regulatory framework for medical devices;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>More detailed regulations regarding the classification of medical devices according to their risk;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Stricter regulations for medical device conformity assessment bodies responsible for confirming compliance with MDR requirements;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Introduction of new, extended obligations for manufacturers, importers, authorized representatives and distributors;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Requirements for the traceability of medical devices across the market, facilitating tracking and inventory management.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>The regulation became fully applicable on 26 May 2021, replacing the MDD.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.medical-device-regulation.eu/wp-content/uploads/2019/06/md_mfr_factsheet.pdf">https://www.medical-device-regulation.eu/wp-content/uploads/2019/06/md_mfr_factsheet.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Regulation (EU) 2017/746 (IVDR)</mark></strong><a href="http://data.europa.eu/eli/reg/2017/746/2025-01-10" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/reg/2017/746/2025-01-10</a><ul><li>The IVDR applies to in vitro diagnostic medical devices (IVDs). Its goal is to ensure the effectiveness, safety, and quality of these devices on the EU market. The IVDR introduces stringent requirements, a four-level classification system for devices (A, B, C, D) based on risk and increases oversight of notified bodies. The IVDR replaced the old IVDD (98/79/EC), adapting the regulations to technological and medical progress. The new regulations aim to enhance public health and patient safety. Companies must undergo additional clinical trials and tighten the technical documentation of their products. Manufacturers are required to report serious incidents, and member states are required to facilitate reporting by healthcare professionals, patients, and users. A centralized database (Eudamed) has been introduced to provide access to information about medical devices available in the EU.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://health.ec.europa.eu/document/download/12f9756a-1e0d-4aed-9783-d948553f1705_en" target="_blank" rel="noreferrer noopener">https://health.ec.europa.eu/document/download/12f9756a-1e0d-4aed-9783-d948553f1705_en</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2000/31 (e-commerce directive) </mark></strong><a href="http://data.europa.eu/eli/dir/2000/31/2024-02-17" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2000/31/2024-02-17</a>
<ul class="wp-block-list">
<li>The E-Commerce Directive establishes harmonised legal rules for information society services (including online services) across the European Union. It aims to remove barriers to cross-border online services, increase legal certainty, and regulate issues such as information requirements for providers, rules on advertising, spam, and online contracts. The Directive also introduces safe harbors. The directive introduces so-called &#8220;<strong>safe harbors</strong>&#8221; for intermediary service providers, exempting them from liability for third-party content if they meet certain conditions. The directive eliminates obstacles to cross-border services provided online. It ensures regulatory clarity for businesses and consumers using online services. It also establishes rules for advertising and other forms of commercial communication. It requires the publication of basic company data (name, address, and registration number). Recognizing online contracts as equivalent to paper contracts requires clearly defining the terms and allowing consumers to store them. The e-commerce directive limits the liability of intermediary service providers (so-called &#8220;safe harbors&#8221;) for illegal content shared by their users, provided that certain procedures are followed (e.g., notice and takedown). It also introduces provisions regarding unsolicited commercial communications.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2016/680 (LED)</mark></strong><a href="http://data.europa.eu/eli/dir/2016/680/2016-05-04" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2016/680/2016-05-04</a><ul><li>Directive (EU) 2016/680, also known as the Criminal Data Protection Directive, covers the protection of personal data processed by competent authorities for the purposes of preventing, investigating, detecting, or prosecuting criminal offences, or executing criminal penalties. It establishes a legal framework to ensure a high level of protection of the personal data of persons involved in criminal proceedings, such as witnesses, victims, and suspects. The directive aims to:<ul><li>Schengen countries, which is intended to facilitate cooperation in combating crime;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Ensuring the protection of personal data of people involved in criminal proceedings, which is intended to increase trust in the justice system and law enforcement agencies;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Establishing a comprehensive legal framework: regarding the processing of personal data in a criminal context;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>The Directive is part of the EU data protection reform package, alongside the General Data Protection Regulation (GDPR) and Regulation (EU) 2018/1725;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>In short, Directive (EU) 2016/680 regulates how personal data may be processed in a criminal context in order to protect the rights and freedoms of data subjects while at the same time enabling the effective prosecution of criminal offences.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Report%20-%20PSIRT%20Expertise%20%20And%20Capabilities%20Development%20-%20Health%20and%20Energy.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Report%20-%20PSIRT%20Expertise%20%20And%20Capabilities%20Development%20-%20Health%20and%20Energy.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color">Directive (EU) 2022/2555 (NIS 2)</mark></strong><a href="http://data.europa.eu/eli/dir/2022/2555/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2022/2555/oj</a><ul><li>NIS 2 improves cybersecurity across the European Union by establishing high, common standards for networks and information systems, particularly in key economic sectors. It introduces new, broader regulations on cybersecurity risk management and incident reporting obligations for entities across various industries, replacing the previous NIS Directive. The regulations cover a broader group of companies and institutions, including those in sectors such as manufacturing, energy, finance, and healthcare. A multi-stage cybersecurity incident reporting procedure has been established, requiring entities to provide specific information at various stages of incident handling. Management requirements have been increased through mandatory training for members of management bodies to enhance their cybersecurity awareness. More powers have been introduced for regulatory bodies to enforce compliance with the directive.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.edpb.europa.eu/system/files/2023-02/edpb_03-2022_guidelines_on_deceptive_design_patterns_in_social_media_platform_interfaces_v2_en_0.pdf" target="_blank" rel="noreferrer noopener">https://www.edpb.europa.eu/system/files/2023-02/edpb_03-2022_guidelines_on_deceptive_design_patterns_in_social_media_platform_interfaces_v2_en_0.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color">EU Directive 2022/2557 (CER)</mark></strong><a href="http://data.europa.eu/eli/dir/2022/2557/oj">http://data.europa.eu/eli/dir/2022/2557/oj</a><ul><li>Entities The Resilience Directive aims to increase the resilience of Member States and critical entities to threats such as natural disasters, terrorism, and sabotage. It creates a common EU legal framework to ensure the continuity of essential services and strengthen the physical resilience of critical infrastructure, including energy, transport, health, and public administration. The Directive takes a comprehensive approach, not just cybersecurity- related threats. Member States must develop and implement national strategies to strengthen the resilience of critical entities, including risk assessments, mitigation measures, and response plans. The Directive specifies criteria for identifying critical infrastructure entities. The CER is one element of the EU regulatory framework for cybersecurity and resilience, harmonizing its activities with NIS 2. Examples of sectors covered by the CER include:<ul><li>Energy (electricity, oil, gas);</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Transport (air, rail, water, road);</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Health (healthcare, production and distribution of medicines);</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Digital infrastructure;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Public administration;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Food production, processing and distribution.</li></ul></li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202003_healthdatascientificresearchcovid19_en.pdf" target="_blank" rel="noreferrer noopener">https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202003_healthdatascientificresearchcovid19_en.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 96/9</mark></strong><a href="http://data.europa.eu/eli/dir/1996/9/2019-06-06" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/1996/9/2019-06-06</a><ul><li>The aim of the directive is to establish a system of <strong>legal protection for databases</strong>, covering both copyright and <em>sui generis</em>, which protect the investment in the creation and collection of databases by preventing their unauthorized use.<ul><li>Copyright protects original databases as literary or artistic works.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><em>Sui </em>law<em> generis </em>(own kind) protects the investment in acquiring, verifying and presenting database content.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>The Directive protects the financial, time, and labor investment in database creation, ensuring that creators and producers can reap the benefits of these investments. It applies to databases as a whole, not just to their individual components. As a Directive, it is a legal act that European Union Member States must implement into their national law.<strong>Directive (EU) 2019/790 amends Directive (EU) 98/9 and Directive (EU) 2001/29 on copyright and related rights in the Digital Single Market</strong>. <a href="http://data.europa.eu/eli/dir/2019/790/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2019/790/oj</a></li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Cybersecurity%20guide%20for%20SMEs-online-single_page.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Cybersecurity%20guide%20for%20SMEs-online-single_page.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2002/58</mark></strong><a href="http://data.europa.eu/eli/dir/2002/58/2009-12-19" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2002/58/2009-12-19</a><ul><li>The <strong>e-Privacy Directive</strong> regulates the protection of privacy and data confidentiality in the electronic communications sector, complementing the general principles of the GDPR. It introduces specific requirements regarding the confidentiality of correspondence, <em>cookies</em>, and <strong>user metadata, such as location data</strong>. The directive establishes rules for the processing of data in electronic communications to ensure the free flow of data and services while protecting the fundamental rights and freedoms of EU citizens. It aims to harmonize national regulations to ensure the free flow of data and telecommunications services within the EU internal market.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/Technical%20Guideline%20on%20Security%20measures%20for%20Article4%20%26%20Article13a.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/Technical%20Guideline%20on%20Security%20measures%20for%20Article4%20%26%20Article13a.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2020/1828</mark></strong><a href="http://data.europa.eu/eli/dir/2020/1828/2024-12-13" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2020/1828/2024-12-13</a><ul><li>Directive (EU) 2020/1828 of the European Parliament and of the Council on representative actions, also known as the Representative Actions Directive, protects the collective interests of consumers in the European Union by harmonising rules on representative actions. This directive aims to ensure that consumers can effectively enforce their rights in the event of infringements by traders, while also introducing safeguards against abusive actions. The main objectives of the directive are:<ul><li>Unification of the rules for representative actions:<ul><li>The directive aims to approximate the rules of the Member States on representative actions so that consumers have easier access to this type of protection throughout the EU;</li></ul>Protection of the collective interests of consumers:<ul><li>The Directive applies to actions relating to infringements of EU law in various areas such as data protection, financial services, travel and tourism, energy and telecommunications;</li></ul>Prescriptive and corrective measures:<ul><li>The Directive provides for the possibility of seeking both injunctive relief and corrective measures, such as return, replacement or repair;</li></ul>Incorporation into national law:<ul><li>Member States are obliged to implement the provisions of the Directive into their national law, which means that uniform rules on representative actions will apply in each EU country;</li></ul>Entities entitled to bring actions:<ul><li>The Directive specifies which entities may represent consumers in representative actions, e.g. consumer organisations;</li></ul>Protection against abuse:<ul><li>The Directive contains provisions aimed at preventing the abuse of representative actions, for example by specifying the criteria that entities entitled to bring them must meet.</li></ul></li></ul>Directive 2020/1828 is an important step towards strengthening consumer protection in the EU and providing them with more effective access to justice in the event of infringements of their rights by traders, informs the European Commission.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>Directive (EU) 2024/1799 amends Regulation (EU) 2017/2394 and Directives (EU) 2019/771 and (EU) 2020/1828 on common rules promoting the repair of goods. </strong><a href="http://data.europa.eu/eli/dir/2024/1799/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2024/1799/oj</a></li></ul>
<ul class="wp-block-list">
<li><strong>Regulation (EU) 2022/1925 amends Directive (EU) 2019/1937 and Directive (EU) 2020/1828 on contestable and fair markets in the digital sector.</strong> <a href="http://data.europa.eu/eli/reg/2022/1925/2022-10-12">http://data.europa.eu/eli/reg/2022/1925/2022-10-12</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2015/2366 (PSD 2)</mark></strong><a href="http://data.europa.eu/eli/dir/2015/2366/2025-01-17" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2015/2366/2025-01-17</a><ul><li><strong>Payment Services Directive 2</strong> concerns payment services. Its goal is to standardize and increase the security of the electronic payments market in the EU, taking into account technological developments and new payment services. It introduces, among other things, <strong>open banking</strong>, which allows third-party companies (with the customer&#8217;s consent) to access bank account data and limits customer liability for unauthorized transactions to €50. The directive introduces more stringent transaction authentication requirements (e.g., strong customer authentication, PIN authentication for contactless transactions). Customers are better protected against fraud, and their liability for unauthorized transactions is limited. PSD 2 promotes the emergence of innovative services and providers (so-called Third Party Providers), introducing the principle of open banking – customers can use third-party applications (with their consent) to manage their accounts and make payments. It defines strong customer authentication (SCA), which requires two-factor transaction authentication, for example, using a password and an SMS code. The deadline for considering complaints regarding payment transactions has been shortened to 15 business days.</li></ul>
<ul class="wp-block-list">
<li>GUIDE <a href="https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Report%20-%20EU%20Cybersecurity%20Initiatives%20in%20the%20Finance%20Sector.pdf" target="_blank" rel="noreferrer noopener">https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Report%20-%20EU%20Cybersecurity%20Initiatives%20in%20the%20Finance%20Sector.pdf</a></li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Directive (EU) 2019/1024</mark> </strong><a href="http://data.europa.eu/eli/dir/2019/1024/oj" target="_blank" rel="noreferrer noopener">http://data.europa.eu/eli/dir/2019/1024/oj</a>
<ul class="wp-block-list">
<li>The aim of this directive is to enable citizens and businesses to <strong><u>reuse public information</u></strong>, such as documents from public authorities and public undertakings, as well as research data, for the development of the economy and society. The directive also introduces the concept of <strong>high-value datasets</strong>, which are made available under specific conditions to increase their benefits for society and the economy. Member States are required to make information available in open, machine-readable formats to enable free commercial and non-commercial use. The directive had to be implemented into the national law of the Member States. In Poland, implementation occurred through the Act of 11 August 2021 on Open Data and the Reuse of Public Sector Information. The directive aims to adapt the legal framework to technological advances, such as machine learning and artificial intelligence, in order to fully exploit the potential of public data for the European economy and society.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Personal Data Protection Act</mark> </strong><a href="https://uodo.gov.pl/en/file/754" target="_blank" rel="noreferrer noopener">https://uodo.gov.pl/en/file/754</a><ul><li>The Polish Personal Data Protection Act of 10 May 2018 governs the processing of personal data and the rights of individuals whose data is processed in datasets, in accordance with European Union law, in particular the General Data Protection Regulation (GDPR). This Act aims to ensure that personal data is processed in a lawful, fair, and transparent manner, respecting the privacy of data subjects. Specifically, the Act specifies:<ul><li>Principles of personal data processing:<ul><li>including the principles of legality, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability;</li></ul>Rights of data subjects:<ul><li>including the right to access data, the right to rectification, deletion, restriction of processing, the right to data transfer and the right to object;</li></ul>Obligations of data controllers and processors:<ul><li>including ensuring data security, maintaining processing documentation, appointing a data protection officer in certain cases;</li></ul>Sanctions for violations of regulations:<ul><li>including financial penalties and other legal consequences.</li></ul></li></ul>In short, the Act aims to protect the rights and freedoms of natural persons in relation to the processing of their personal data, while ensuring the free flow of data within the European Union.</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC introduces new rules on general provisions, the appointment of a data protection officer, requests for prior consultations before the processing of personal data, provisions on administrative fines, criminal provisions, and the prevention of inspections of compliance with personal data protection provisions. </strong><a href="https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf" target="_blank" rel="noreferrer noopener">https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf </a>[link in Polish]</li>
</ul>
</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><mark>Electronic Communications Law</mark></mark></strong><a href="https://eli.gov.pl/eli/DU/2024/1221/ogl" target="_blank" rel="noreferrer noopener">https://eli.gov.pl/eli/DU/2024/1221/ogl</a><ul><li>The EPC replaces the previous Telecommunications Law and implements EU regulations, such as the European Electronic Communications Code. The new law comprehensively regulates the telecommunications and electronic communications market in Poland, introducing changes aimed at better consumer protection, streamlining market operations, and adapting regulations to the dynamic development of the digital age. Key changes include:<ul><li><strong>Marketing consent and cookie policy</strong>;</li></ul></li></ul></li>



<li><ul><li><ul><li>Information obligations for operators;</li></ul></li></ul></li>



<li><ul><li><ul><li>New regulations on contract termination and access to services for people with disabilities.</li></ul></li></ul></li>



<li><ul><li>The Act introduces new consumer protection mechanisms, such as transparency of offers, easier comparison of services, and rules for contract amendments. The law includes new regulations regarding the management of network infrastructure, frequencies, and orbital resources. Limitations have been introduced on unilateral changes to contract terms by providers and the ability for consumers to more easily terminate contracts in the event of significant non-compliance with the contract. The Act requires the use of technical measures to protect the confidentiality of electronic communications against unauthorized disclosure.</li></ul></li>



<li><ul><li><strong>The Act amending the Prison Service Act and certain other acts introduces new provisions regarding the obligation to ensure conditions for access to and recording of data. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000820/O/D20250820.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000820/O/D20250820.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending the Act on State Emergency Medical Services and certain other acts introduces new provisions regarding the obligation to provide information on the location of the network termination point from which an emergency call was made. </strong><a href="https://orka.sejm.gov.pl/proc10.nsf/ustawy/1058_u.htm">https://orka.sejm.gov.pl/proc10.nsf/ustawy/1058_u.htm </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Act on clinical trials of medicinal products for human use</mark> </strong><a href="https://polishpharmacy.ptfarm.pl/download/?file=File%2FFarmacja+Polska%2F2023%2F12%2F05_SZ_Ustawa_o_badaniach_klinicznych_n.pdf" target="_blank" rel="noreferrer noopener">https://polishpharmacy.ptfarm.pl/download/?file=File%2FFarmacja+Polska%2F2023%2F12%2F05_SZ_Ustawa_o_badaniach_klinicznych_n.pdf</a>
<ul class="wp-block-list">
<li>The Act on Clinical Trials of Medicinal Products for Human Use establishes new rules for conducting clinical trials in Poland, harmonizing Polish law with European Union regulations (Regulation (EU) 536/2014). The Act primarily addresses the procedure for obtaining trial authorizations, the appointment of the Supreme Bioethics Committee, ethical review principles, the responsibilities of the sponsor and investigator, the Compensation Fund, and the financing of trial-related medical services. Bureaucratic and legal obstacles for the pharmaceutical industry have been reduced. Changes have been introduced, including changes to <strong>data commercialization</strong>, a b<strong>an on using data from non-commercial trials</strong> for commercial purposes, and the removal of individuals from the list of entities authorized to conduct trials. Principles and procedures for conducting clinical trial inspections have been established.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Act on the protection of personal data processed in connection with the prevention and combating of crime</mark></strong><a href="https://uodo.gov.pl/en/file/875"> </a><a href="https://uodo.gov.pl/en/file/875" target="_blank" rel="noreferrer noopener">https://uodo.gov.pl/en/file/875</a><ul><li>This Act implements Directive (EU) 2016/680 within its scope of regulation. It specifies:<ul><li>Principles and conditions for the protection of personal data processed by competent authorities for the purpose of recognizing, preventing, detecting and combating prohibited acts, including threats to public security and order, as well as the execution of temporary arrest, penalties, fines and coercive measures resulting in deprivation of liberty;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>The rights of persons whose personal data are processed by competent authorities and the legal remedies available to such persons;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>The method of supervising the protection of personal data processed by competent authorities, excluding personal data processed by the prosecutor’s office and courts;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Tasks of the supervisory body and the forms and manner of their performance;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Obligations of the controller and processor and the data protection officer and the procedure for his appointment;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>How to secure personal data;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Mode of cooperation with supervisory authorities in other European Union countries;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Criminal liability for violation of regulations.</li></ul></li></ul>
<ul class="wp-block-list">
<li>This Act applies to the processing of personal data by competent authorities in a manner<ul><li>Fully or partially automated;</li></ul>
<ul class="wp-block-list">
<li>Other than automated processing where the data is or is intended to be part of a data set.</li>
</ul>
</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Act on Medical </mark>Activity</strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111120654/U/D20110654Lj.pdf"> </a><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111120654/U/D20110654Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111120654/U/D20110654Lj.pdf </a>[link in Polish]<ul><li>The Act on Medical Activity regulates the principles of:<ul><li>Performing medical activities in Poland;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>The functioning of entities conducting it (both entrepreneurs and other entities);</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Rules for registration of medical entities in the Register of Entities Performing Medical Activities (RPWDL);</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Working time standards for medical workers;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Principles of supervision over this activity.</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>Medical activity involves providing health services, promoting health, and conducting teaching and research activities. The Act specifies which entities may conduct medical activities, including entrepreneurs, independent public health care facilities, research institutes, foundations, associations, and even churches.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on State Emergency Medical Services and certain other acts introduces new provisions regarding shift work allowances. </strong><a href="https://orka.sejm.gov.pl/proc10.nsf/ustawy/1058_u.htm" target="_blank" rel="noreferrer noopener">https://orka.sejm.gov.pl/proc10.nsf/ustawy/1058_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Healthcare Services Financed from Public Funds and Certain Other Acts introduces new provisions regarding healthcare entities and agreements on the transfer of public funds. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000129/O/D20250129.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000129/O/D20250129.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Medical Center for Postgraduate Education and certain other acts introduces new provisions regarding medical schools, the establishment of SPZOZs, property management principles, the liquidation of SPZOZs, the merger of SPZOZs, agreements between transferring entities and acquiring entities, the transformation of SPZOZs, the obligation to perform tasks, and agreements on providing access to an organizational unit to medical schools. </strong><a href="https://www.nia.org.pl/wp-content/uploads/2024/12/23.12.24-ustawa-o-CMKP.pdf" target="_blank" rel="noreferrer noopener">https://www.nia.org.pl/wp-content/uploads/2024/12/23.12.24-ustawa-o-CMKP.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Patients&#8217; Rights and the Patient Ombudsman and certain other acts introduces new provisions regarding monitoring of rooms, hospital discharge, and identification of hospital staff and patients. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001675/O/D20231675.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001675/O/D20231675.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Healthcare Services Financed from Public Funds and Certain Other Acts introduces new regulations regarding working time for employees of healthcare entities. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002120/O/D20212120.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002120/O/D20212120.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on health care services financed by public funds and certain other acts introduces new provisions regarding sources of financing, the fund of an SPZOZ facility and covering SPZOZ net losses.</strong> <strong><br></strong><a href="https://eli.gov.pl/eli/DU/2021/1773/ogl" target="_blank" rel="noreferrer noopener">https://eli.gov.pl/eli/DU/2021/1773/ogl </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Healthcare Services Financed from Public Funds and Certain Other Acts introduces new provisions regarding agreements on the transfer of public funds. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002345/O/D20202345.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002345/O/D20202345.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in order to ensure the availability of medical personnel during the period of declaration of an epidemic threat or epidemic status introduces new provisions regarding the exercise of the professions of physician, nurse and physiotherapist within the framework of medical activity.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002401/U/D20202401Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002401/U/D20202401Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with counteracting crisis situations related to the occurrence of COVID-19 introduces new provisions regarding requirements for the premises and equipment of an entity performing medical activities, principles of property management and coverage of net losses of SPZOZ.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002112/U/D20202112Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002112/U/D20202112Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts to ensure the functioning of health care in connection with the COVID-19 epidemic and after its termination introduces new provisions regarding the head of a medical entity that is not an entrepreneur, the competition procedure for certain positions in a medical entity that is not an entrepreneur and the report on the economic and financial situation of SPZOZ.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200001493/O/D20201493.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200001493/O/D20201493.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in the field of the health care system related to the prevention, counteraction, and combating of COVID-19 introduces new provisions regarding the coverage of net losses of public healthcare facilities. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000567/U/D20200567Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000567/U/D20200567Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Commercial Companies Code and certain other acts introduces new provisions on the establishment and management of healthcare entities, specific regulations regarding healthcare companies with public participation, agreements between entities establishing SPZOZs and agreements on the transfer of public funds.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001655/U/D20191655Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001655/U/D20191655Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Pharmaceutical Law and certain other acts introduces new provisions on fines for selling medicinal products in violation of the regulations.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000959/O/D20190959.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000959/O/D20190959.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the principles of state property management and certain other acts introduces new provisions concerning specific regulations regarding medical companies with public participation.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000492/T/D20190492L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000492/T/D20190492L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC introduces new rules on general provisions, the appointment of a data protection officer, requests for prior consultations before the processing of personal data, provisions on administrative fines, criminal provisions, and the prevention of inspections of compliance with personal data protection provisions. </strong><a href="https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf">https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Healthcare Services Financed by Public Funds and Certain Other Acts introduces new rules regarding general provisions and working time for employees of healthcare entities. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001532/U/D20181532Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001532/U/D20181532Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Public-Private Partnership and certain other acts introduces new provisions regarding property management principles. </strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001693/O/D20181693.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001693/O/D20181693.pdf</a>  [link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Pharmaceutical Law and certain other acts introduces new provisions regarding applications for entry into the register of entities performing medical activities, refusal of entry into the register and fines for selling medicinal products in violation of the regulations.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001375/U/D20181375Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001375/U/D20181375Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on health care services financed by public funds and certain other acts introduces new provisions regarding the agreement on the transfer of public funds.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001128/O/D20181128.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001128/O/D20181128.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on Medical Activity introduces new provisions concerning specific regulations concerning certain medical entities. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001697/O/D20151697.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001697/O/D20151697.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on State Emergency Medical Services, the Act on Medical Activity and the Act amending the Act on Medical Activity and certain other acts introduces new provisions regarding the adjustment obligations of entities performing medical activities.</strong> <a href="https://orka.sejm.gov.pl/proc7.nsf/ustawy/3864_u.htm">https://orka.sejm.gov.pl/proc7.nsf/ustawy/3864_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on the Nursing and Midwifery Professions and Certain Other Acts introduces new provisions regarding the conditions for conducting medical activities by nurses and employment standards for nurses in medical entities that are not entrepreneurs. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001640/O/D20151640.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001640/O/D20151640.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Medical Devices and certain other acts introduces new provisions regarding the conditions for conducting business activity. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001918/O/D20151918.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001918/O/D20151918.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Medical Activity introduces new provisions regarding a military unit, a medical entity that is not an entrepreneur, the founding entity, medical entities, the establishment and management of medical entities, entities providing health services other than hospitals, the admissibility of performing activities other than medical and the prohibition of advertising funeral services, medical activity as a business activity, requirements for the premises and equipment of an entity performing medical activity, temporary cessation of medical activity, special regulations regarding certain medical entities, medical entities with special regulations, the establishment, transformation and liquidation of medical budgetary units, the principles of financial management of a medical budgetary unit, the working time of employees of medical entities, specialization and the maintenance in force of implementing provisions.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150000905/O/D20150905.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150000905/O/D20150905.pdf </a>[link in Polish]<strong>The Act amending the Act on health care services financed by public funds and certain other acts introduces new provisions regarding the principles of awarding contracts for health care services and public funds transferred to entities performing medical activities.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140001138/U/D20141138Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140001138/U/D20141138Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Public Procurement Law and certain other acts introduces new provisions regarding the principles of awarding contracts for health services.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000423/O/D20140423.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000423/O/D20140423.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending the Act on Medical Activity and certain other acts introduces new rules regarding general provisions, medical entities performing medical activities such as stationary and 24-hour health services, medical entities with special regulations, medical entities that are not entrepreneurs, an independent public health care facility, a medical entity in the form of a budgetary unit, a register of entities performing medical activities, rules for the transfer of public funds to entities performing medical activities, control and supervision, and transitional provisions.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120000742/T/D20120742L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120000742/T/D20120742L.pdf </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Act on Trading in Financial Instruments </mark></strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20051831538/U/D20051538Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20051831538/U/D20051538Lj.pdf </a>[link in Polish]<ul><li>The Act regulates the principles, procedures, and conditions for undertaking and conducting business in the field of trading in financial instruments, the rights and obligations of entities participating in such trading, and the exercise of supervision in this regard. The provisions of the Act do not apply to bills of exchange and checks within the meaning of the Bills of Exchange and Checks Law. Financial instruments, as defined by the Act, are:<ul><li>Securities;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Non-securities:<ul><li>Shares in collective investment institutions;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Money market instruments;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Options, futures, swaps, forward interest rate agreements, other derivatives whose underlying instrument is a security, currency, interest rate, yield index, emission allowance or other derivative, financial index or financial index that are executed by delivery or settlement in cash;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Options, futures, swaps, forward rate agreements and other derivative instruments the underlying of which is a commodity and which are settled in cash or may be settled in cash at the option of one of the parties;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Options, futures, swaps and other derivatives whose underlying instrument is a commodity and which can be executed by delivery, provided that they are admitted to trading on a financial instruments trading venue, excluding energy products traded wholesale on an OTF, which must be executed by delivery;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Options, futures, swaps, forward contracts and other derivative instruments whose underlying instrument is a commodity and which can be executed by delivery, which are not intended for trading purposes and have the characteristics of other derivative financial instruments, not admitted to trading on a financial instruments trading venue;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Credit risk transfer derivatives;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Contracts for Difference;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Options, futures, swaps, forward interest rate agreements and other derivative instruments relating to climate change, freight rates and inflation rates or other official statistics that are settled in cash or may be settled in cash at the option of one of the parties, as well as derivative instruments and other instruments that exhibit the characteristics of other derivative financial instruments;</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li><ul><li>Emission allowances.</li></ul></li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li>The Act regulates <strong>which entities have access to which data</strong> and the ability to share this information. At the same time, it emphasizes customer and data security, including the protection of confidential information or professional secrecy.<strong>The Act amending the Act on the Defense of the Homeland and certain other acts introduces new provisions regarding securities accounts.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001014/O/D20251014.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001014/O/D20251014.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds introduces new provisions regarding Regulation (EU) 2022/2554, ICT, the acquisition or disposal of financial instruments through the use of algorithmic trading, service security, customer and data protection, and the recovery plan. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Trading in Financial Instruments introduces new provisions regarding general requirements for the regulated market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000923/O/D20250923.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000923/O/D20250923.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending the Act on the Prison Service and certain other acts introduces new provisions on the permitted disclosure of professional secrets on the capital market</strong><a><strong>.</strong></a> <a href="https://orka.sejm.gov.pl/proc10.nsf/ustawy/993_u.htm" target="_blank" rel="noreferrer noopener">https://orka.sejm.gov.pl/proc10.nsf/ustawy/993_u.htm </a>[link in Polish]</li>
</ul>
</li>
</ul>



<ul class="wp-block-list">
<li><strong>The Act amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Oversight, and certain other acts introduces new provisions concerning the inspection and supervisory powers of the Polish Financial Supervision Authority (KNF), the mandate to commission an audit firm to perform an inspection, the obligation to notify, submit documents, and provide explanations upon the KNF&#8217;s request, the permitted disclosure of professional secrecy on the capital market, and information that does not violate professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001863/U/D20241863Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001863/U/D20241863Lj.pdf </a>[link in Polish]<ul><li><strong>The Act amending certain acts in connection with ensuring the development of the financial market and investor protection on this market introduces new rules regarding the concept of financial instruments, investment certification, discretionary nature, Regulation (EU) 2022/858, DLT-based ATS, DLT-based SS, DLT-based TSS, parent entity, subsidiary entity, capital group, financial instrument operated by DLT, secondary DLT registration, DLT account, securities accounts, derivatives accounts, general provisions, deposit and dematerialization, dematerialized securities, agreement on performing the function of an agent for the issue of securities, obligations of an issue agent, information obligations towards the National Depository for Securities incumbent on issuers of securities entering into an agreement on performing the function of an agent for the issue of capital bonds or an agreement on storing capital bond documents and maintaining a register of persons entitled under capital bonds, electronic declarations of will, orders to other entities organizing the market for trading in Treasury securities, outsourcing of operational functions, taking into account the risk related to outsourcing, liability of the outsourcer and the company operating the regulated market, general requirements regarding the regulated market, the company operating the regulated market, changes in the statute of the company operating the regulated market and in the rules of the regulated market, parties to transactions on the regulated market, admission to trading on the regulated market, ineffectiveness of specific proceedings, the Organization of the National Depository, the Tasks of the National Depository, participants of the depository, settlement and clearing system, the security fund, the amount of contributions to the security fund, the rules of the security fund, the nature of the assets of the security fund, the depository and settlement system, the clearing house and the settlement house, the security fund, regulated entities, the scope of brokerage activities, exclusion of the application of regulations, a report on the best order execution systems, purchasing or selling financial instruments on own account, conducting business by investment firms, an agreement with an investment firm agent, entry in the register of investment firm agents, taking into account the risk related to outsourcing in the risk management system, liability for damages, sub-outsourcing of investment firms, application for a permit to conduct brokerage activities, qualifications of employees, general partners and partners in investment firms, service security, customer and data protection, general organizational requirements of an investment firm, risk management by an investment firm, internal audit system, internal control system, distribution strategy, limitation of the application of regulations in the case of providing selected brokerage services, examination of an application for a permit to conduct brokerage activities, refusal to grant a permit, information obligations towards the Polish Financial Supervision Authority, expiry or withdrawal of a permit, register of investment firms, register of state-owned banks conducting brokerage activities, statutory delegations, consent of the Commission to appoint the president of the management board of a brokerage house and a member of the management board of a brokerage house who will be responsible for supervising the risk management system, separation of the function of the president and the position of a member of the management board supervising the risk management system in the activities of a brokerage house, internal division of powers in the management board, significant blocks of shares of brokerage houses, deadline for delivery of the decision on the objection, indicators in recovery plans, bank&#8217;s brokerage activity permit, banks conducting brokerage activities, principles conducting business by a foreign investment firm, control powers of the Commission, custodian banks, practicing the profession of a broker or investment advisor, entry on the list of brokers or investment advisors, removal of a broker or investment advisor from the list, suspension of the right to practice the profession, grounds for removal from the list of brokers or investment advisors, compensation scheme, investor compensation scheme, obligation to participate in the compensation scheme, subjective scope of the obligation to maintain professional secrecy on the capital market, permitted disclosure of professional secrecy on the capital market, information not infringing professional secrecy on the capital market, conditions for disclosing information submitted to the PFSA as part of its supervision, exchange of information covered by professional secrecy, liability for damages, maximum amount of fees, amount of supervision fees, withdrawal of the permit to operate a regulated market, fine, withdrawal of the permit to operate an auction platform, prohibition to operate a regulated market, sanctions imposed on an entity operating a foreign regulated market, withdrawal of the permit to conduct brokerage activities, limitation of the scope of brokerage activities performed, sanctions imposed on an investment holding company, a financial holding company or a mixed-income holding company, fees, suspension of an approved publishing arrangement or an approved reporting mechanism&#8217;s authorisation to provide information disclosure services, a fine in the event of withdrawal of an approved publishing arrangement or an approved reporting mechanism&#8217;s authorisation to provide information disclosure services, infringement of regulations when providing intermediation services in concluding a structured deposit agreement, administrative sanctions for infringement of regulations, sanctions for infringement of regulations on the organisation of a regulated market or conducting brokerage activities, sanctions for infringement of regulations on the operation of an auction platform, a sanction imposed on the National Depository, a ban on performing activities, a sanction imposed on a company operating a clearing house, a sanction imposed on a company operating a settlement house, sanctions for breach of obligations related to trading in significant blocks of shares, a fine for breaching prohibitions or restrictions imposed by ESMA or EBA, unauthorised acquisition of own shares or stabilisation of prices of financial instruments, sanctions imposed on financial counterparties, sanctions imposed on non-financial counterparties, sanctions imposed on CCPs, sanctions for conducting transactions during a closed period, publication of information on decisions taken in the event of a breach of regulations, the offence of unauthorized trading in financial instruments, the offence of violating the issuer&#8217;s disclosure obligations and the offence of obstructing the control activities of the Polish Financial Supervision Authority. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001723/U/D20231723Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001723/U/D20231723Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee Scheme and Compulsory Restructuring, and certain other acts introduces new rules regarding the concept of financial instruments, Regulation (EU) 2021/33, the agreement on performing the function of an issue agent for securities, the obligations of an issue agent, general provisions, the information obligations towards the National Depository for securities issuers entering into an agreement on performing the function of an issue agent or an agreement on storing capital bond documents and maintaining a register of persons entitled under capital bonds, the depository and settlement system, significant blocks of shares in brokerage houses, specific rules for conducting business by brokerage houses and small brokerage houses, information that does not violate professional secrecy on the capital market, and administrative sanctions for violating the regulations.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000825/O/D20230825.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000825/O/D20230825.pdf </a>[link in Polish]<strong>The Act amending the Act on the handling of complaints by financial market entities and on the Financial Ombudsman and certain other acts introduces new provisions on the permitted disclosure of professional secrecy on the capital market.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002640/O/D20222640.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002640/O/D20222640.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending certain acts to simplify administrative procedures for citizens and businesses introduces new provisions regarding the obligation to notify the Polish Financial Supervision Authority (KNF), the application for a brokerage license, the obligation for investment firms to employ individuals with appropriate qualifications, and the requirement for banks to obtain brokerage licenses. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002185/O/D20222185.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002185/O/D20222185.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on the Prison Service and certain other acts introduces new provisions on the permitted disclosure of professional secrets on the capital market.</strong> <a href="https://orka.sejm.gov.pl/Druki9ka.nsf/0/31F27D27D29E1AF6C125886E004A3BBF/%24File/2384.pdf" target="_blank" rel="noreferrer noopener">https://orka.sejm.gov.pl/Druki9ka.nsf/0/31F27D27D29E1AF6C125886E004A3BBF/%24File/2384.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new provisions regarding Regulation (EU) 575/2013, Regulation (EU) 2019/2033, a brokerage house applying Regulation (EU) 575/2013, banking law provisions applied by certain brokerage houses, the receipt by the Commission of reports on infringements of regulations, the provision by a brokerage house of intermediation services in concluding a structured deposit agreement or investment advice in this respect, an application for a permit to conduct brokerage activities, security of services, customer and data protection, recommending to an investment firm to cease a specific action or not to undertake it in the future, the initial capital of a brokerage house, the amount of the initial capital, ordering an audit by an audit firm, the notification obligation, the assessment of compliance with requirements by members of the management board and supervisory board of a brokerage house, the dismissal or suspension from duties of a member of the management board of a brokerage house, members of the management board and supervisory board of a brokerage house, brokerage houses. brokerage firms, conducting business by investment firms, specific principles of conducting business by certain brokerage houses, risk management system at a brokerage house, responsibilities of the management board and supervisory board of a brokerage house, management board of a brokerage house as a management body, estimation of internal capital, recognition of a branch of a foreign investment firm as significant, entities being indirect EU parent undertakings, fulfillment of obligations by a brokerage house, consolidated supervision, actions in the event of extraordinary situations or unfavorable changes in the markets, cooperation of the Commission with other supervisory authorities in the scope of consolidated supervision, supervision of a subsidiary, provision of information to the Commission by a holding company on mixed activity, assessment of equivalence of consolidated supervision principles, documentation of systems and processes, recording of transactions by a brokerage house, examination and assessment of the brokerage house’s activities undertaken in the field of risk management, verification of compliance with the conditions regarding the method of calculating own funds used by the brokerage house, remuneration policy of the brokerage house, report on the unit’s activities, statutory delegations, supervisory measures applied in the event of infringement of the provisions by a brokerage house or the probability of their infringement, the obligation to provide the Commission with information necessary for the exercise of supervision, recovery plans and early intervention principles for certain brokerage houses, recovery plans, approval of the recovery plan by the Commission, group recovery plan, consultation on the group recovery plan, agreement on the necessity of preparing and submitting a recovery plan by the brokerage house, limitation of the scope of information in the recovery plan, change of the frequency of updating the recovery plan, agreement on providing financial support, conditions of concluding an agreement on providing financial support, conditions of providing financial support, consent of the Commission to concluding an agreement on providing financial support, conclusion of an agreement on providing financial support within a group, forwarding a copy of the agreement to other authorities, consent of the Commission to providing financial support, public disclosure of information on the conclusion of an agreement on providing financial support, early intervention measures, appointment of a curator or receivership, cooperation of the Commission with other authorities, authorisation for bank brokerage activities, the principle of a single passport, branches of foreign legal entities, provision of a service that does not constitute brokerage activities requiring a permit to conduct them, foreign entities conducting brokerage activities in the territory of the Republic of Poland, fiduciary activities of banks, claims for the return of transferred amounts, information that do not violate professional secrecy on the capital market, the maximum amount of fees, the withdrawal of a brokerage license, limitations on the scope of brokerage activities, fines, sanctions imposed on a financial holding company, notification to the supervisory authority of another Member State of an infringement of legal provisions by a foreign investment firm, a ban on conducting business by a foreign investment firm, the provision of aggregate information to the European Market and Securities Authority (ESMA) and sanctions for breaching disclosure obligations. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002140/O/D20212140.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002140/O/D20212140.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Capacity Market Act and certain other acts introduces new provisions regarding the clearing house and settlement house. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001505/O/D20211505.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001505/O/D20211505.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Investment Funds and the Management of Alternative Investment Funds and certain other acts introduces new rules regarding exemptions from the provisions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001595/O/D20211595.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001595/O/D20211595.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new provisions regarding the approved publishing entity, approved reporting mechanism, provider of information disclosure services, separated markets, official listing market, organizing an alternative trading system, operating an OTF, a company operating a regulated market, providing services in the scope of disclosing information on transactions on a regulated market, tasks of the National Depository, providing services in the scope of disclosing information on transactions on a regulated market, conducting business by investment firms, participation in trading in financial instruments, conducting business in the scope of disclosing information on transactions, submitting documents and providing explanations at the request of the Polish Financial Supervision Authority, procedures for anonymous reporting of violations of legal provisions, procedures and ethical standards in an entity providing services in the scope of disclosing information on transactions, maximum fees, amount of supervision fees, administrative sanctions for violation of regulations, withdrawal of a permit to provide services in the scope of disclosing information on transactions on a regulated market, fines, sanctions for violating regulations on organizing a regulated market or conducting brokerage activities and administrative sanctions for violating regulations. </strong><a href="https://orka.sejm.gov.pl/proc9.nsf/ustawy/868_u.htm">https://orka.sejm.gov.pl/proc9.nsf/ustawy/868_u.htm </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on special solutions related to the prevention, counteraction, and combating of COVID-19, other infectious diseases and the resulting crisis situations, and certain other acts, introduces new provisions regarding the conduct of business by investment firms</strong>. <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000568/U/D20200568Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000568/U/D20200568Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act Amending the Act on Government Administration Departments and Certain Other Acts introduces new provisions regarding information that does not violate professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000284/O/D20200284.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000284/O/D20200284.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Commercial Companies Code and certain other acts introduces new rules regarding the form of securities, general provisions, certificates of entitlement to participate in a general meeting and a list of persons authorized to participate in a general meeting of a public company, the Rules of the National Depository, the concept of professional secrecy on the capital market, and information that does not violate professional secrecy on the capital market. </strong><a href="https://eli.gov.pl/api/acts/DU/2019/1798/text/U/D20191798Lj.pdf">https://eli.gov.pl/api/acts/DU/2019/1798/text/U/D20191798Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Commercial Companies Code and certain other acts introduces new provisions regarding information that does not violate professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001655/U/D20191655Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001655/U/D20191655Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Financial Market Supervision and certain other acts introduces new provisions regarding information that does not violate professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000875/O/D20190875.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000875/O/D20190875.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending certain acts in connection with ensuring the application of the GDPR introduces new provisions regarding the GDPR, the conduct of business by investment firms, and the permitted disclosure of professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000730/O/D20190730.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000730/O/D20190730.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending certain acts in connection with strengthening financial market supervision and investor protection introduces new rules regarding the form of securities, registration with the National Depository for Securities (KDPW) based on specific provisions, general provisions, the tasks of the National Depository, broker and investment advisor examinations, information that does not violate professional secrecy on the capital market, and criminal provisions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002243/U/D20182243Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002243/U/D20182243Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending certain acts in order to introduce simplifications for entrepreneurs in tax and economic law introduces new provisions regarding the content of a deposit certificate, mandatory contributions to the compensation scheme and exclusion from participation in the scheme.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002244/O/D20182244.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002244/O/D20182244.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new rules concerning the subject of regulation, the concept of financial instruments, the form of securities, the issuance of a certificate and the blocking of securities, filing a complaint to the Commission, the taking over by the Commission of notifications of infringements of regulations, the definition of a regulated market, the powers of entities operating foreign regulated markets, separate markets, official listing markets, organizing an alternative trading system, secondary trading in financial instruments, statutory delegation &#8211; detailed principles of organization and operation of a regulated market, official listing market, auction platform, obligations of a company operating a regulated market, general requirements regarding a regulated market, suspension of admission to trading and exclusion from trading, companies operating a regulated market, organization and principles of operating a regulated market, a permit to operate a regulated market, the management board of a company operating a regulated market, foreign operations of a company operating a regulated market, refusal to issue a permit to operate a regulated market, the rules of a regulated market, the provision of services in the scope of disclosing information on transactions on a regulated market, the control and supervisory powers of the Polish Financial Supervision Authority, the tasks of the National Depository for Securities, the clearing house and settlement house, guarantee system, security fund, scope of brokerage activity, conducting business by investment firms, exclusion of application of regulations, agreement on offering financial instruments, agreement on executing orders to purchase or sell financial instruments, agreement on accepting and transmitting orders to purchase or sell financial instruments, agreement on managing a portfolio of financial instruments, investment advisory agreement, alternative trading system, agreement with an investment firm agent, entry in the register of investment firm agents, outsourcing of investment firms, liability for damages, obligation to notify the Polish Financial Supervision Authority (KNF), exclusion of application of regulations on outsourcing agreements, application for a permit to conduct brokerage activity, qualifications of employees, general partners and partners in investment firms, security of services, protection of clients and data, consideration of an application for a permit to conduct brokerage activity, refusal to grant a permit, information obligations towards the KNF, expiry of a permit, application of regulations to foreign investment firms, recommendation to an investment firm to cease a specific activity or not to undertake it in the future, statutory delegations, forms of operation of brokerage houses, opinions of supervisory authorities of other countries, the amount of the initial capital, ordering an audit by an audit firm, the notification obligation, brokerage houses, members of the management board and supervisory board of a brokerage house, cross-border provision of services, establishing branches in other Member States, installing IT systems and technical equipment in the territory of other Member States, information presented with the notification of the intention to acquire a significant block of shares, a substitute declaration, objections by the Polish Financial Supervision Authority, civil and administrative sanctions, informing the brokerage house about the acquisition of shares, specific rules for conducting business by certain brokerage houses, a brokerage house, a recovery plan, a bank&#8217;s brokerage permit, the appropriate application of regulations, the principle of a single passport, branches of foreign legal entities, foreign entities conducting brokerage activities in the territory of the Republic of Poland, rules for conducting business by a foreign investment firm, installing IT systems and technical equipment in the territory of Poland by a foreign investment firm, the division of supervisory powers, practicing the profession of broker or investment advisor, the time of making available and publishing information by an approved publishing entity, the scope of published information, the time of making available and publishing information by the consolidated information provider, the scope of published information, additional obligations incumbent on the consolidated information provider, submitting documents and providing explanations at the request of the PFSA, conducting business in the field of disclosing information on transactions, the admissibility of disclosing professional secrecy when the PFSA provides information to the minister, the maximum fees, the amount of supervision fees, fees, withdrawal of the authorisation to operate a regulated market, fines, a ban on operating a regulated market, administrative sanctions for infringement of regulations, sanctions imposed on an entity operating a foreign regulated market, withdrawal of the authorisation to conduct brokerage activities, withdrawal of the authorisation to provide services in the field of disclosing information on transactions on a regulated market, sanctions imposed on a foreign investment firm or an agent of such a firm, sanctions for violating the regulations on the organisation of a regulated market or conducting brokerage activities, providing aggregate information to the European Securities and Markets Authority (ESMA and PWM), sanctions for violating the regulations on the operation of an auction platform, unauthorized acquisition of own shares or stabilization of prices of financial instruments, criminal provisions and the offence of obstructing the inspection activities of the PFSA. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000685/O/D20180685.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000685/O/D20180685.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Certain Powers of Employees of the Office Serving the Minister of Internal Affairs and Officers and Employees of Offices Supervised by that Minister, and Certain Other Acts, introduces new provisions regarding the permitted disclosure of professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000106/U/D20180106Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000106/U/D20180106Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Penal Code and certain other acts introduces new provisions regarding the permitted disclosure of professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000768/O/D20170768.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000768/O/D20170768.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new provisions regarding Regulation (EU) 596/2014, Regulation (EU) 909/2014, organized trading platform, emission allowance market participant, central securities depository, designated entity, Alternative Investment Company manager, confidential information, acceptance by the Commission of reports of infringements of regulations, suspension of admission to trading and exclusion from trading, secondary trading in financial instruments, authorisation to operate a regulated market, rules of the regulated market, authorisation to operate an auction platform for futures contracts, principles of operating an auction platform, regulated market, application for authorisation for a brokerage house to acquire contracts at auctions organised by an auction platform, alternative trading system, application for authorisation to conduct brokerage activities, security of services, customer and data protection, amount of initial capital, prohibition on a brokerage house acquiring shares in a parent entity, credit institution, and authorisation for brokerage activities, information that does not violate professional secrecy on the capital market, confidential information, withdrawal of a license to operate an auction platform, fines, withdrawal of a license to conduct brokerage activities, administrative sanctions for violating regulations, unauthorized acquisition of own shares or stabilization of prices of financial instruments, sanctions for using confidential information, sanctions for failure to comply with disclosure obligations, delisting of securities from trading, the crime of unauthorized disclosure of confidential information regarding financial instruments, the crime of unauthorized use of confidential information regarding financial instruments, the crime of unauthorized granting of a recommendation or incitement to purchase or sell financial instruments to which confidential information relates, and the crime of manipulation of financial instruments. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000724/O/D20170724.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000724/O/D20170724.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Investment Funds and certain other acts introduces new rules concerning the management company, EU managers, general provisions, securities accounts, general requirements regarding the regulated market, shares and shareholders of a company operating a stock exchange, shares and shareholders of a company operating an over-the-counter market, assessment of conduct in order to determine accepted market practices, exclusion of the application of regulations, entry in the register of investment firm agents, application for a permit to conduct brokerage activities, qualifications of employees, general partners and partners in investment firms, information provided together with the notification of the intention to acquire a significant block of shares, information presented together with the notification of the intention to acquire a significant block of shares, formal requirements for entry on the register of brokers or the list of investment advisers, grounds for removal from the register of brokers or investment advisers, the compensation system, the subjective scope of the obligation to maintain professional secrecy on the capital market, permissible disclosure of professional secrecy on the capital market, information not infringing professional secrecy on the capital market, maximum fees, withdrawal of the permit to conduct brokerage activities and penalties. monetary.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160000615/O/D20160615.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160000615/O/D20160615.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Acts Governing the Conditions of Access to Certain Professions introduces new provisions regarding the conduct of business by investment firms, custodian banks, securities brokers and investment advisors, and professional secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001505/O/D20151505.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001505/O/D20151505.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Competition and Consumer Protection and certain other acts introduces new provisions regarding the permitted disclosure of professional secrecy on the capital market. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001634/O/D20151634.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001634/O/D20151634.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Capital Market Supervision and certain other acts introduces new provisions on professional secrecy and fees. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001260/U/D20151260Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001260/U/D20151260Lj.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new rules regarding Regulation (EU) 236/2012, Regulation (EU) 648/2012, short selling, CCPs, general provisions, the stock market, the depository and clearing system, the conduct of business by investment firms, and professional secrecy. </strong><a href="https://orka.sejm.gov.pl/proc7.nsf/ustawy/2734_u.htm">https://orka.sejm.gov.pl/proc7.nsf/ustawy/2734_u.htm </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on supplementary supervision of credit institutions, insurance companies, reinsurance companies and investment firms in a financial conglomerate and certain other acts introduces new provisions concerning brokerage houses. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000586/O/D20140586.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000586/O/D20140586.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act Amending the Act on Trading in Financial Instruments and Certain Other Acts introduces new provisions regarding secondary trading in financial instruments, accepted market practices, the conduct of business by investment firms and brokerage houses, and administrative sanctions for violations of the regulations. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001385/O/D20121385.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001385/O/D20121385.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act Amending the Act on Trading in Financial Instruments and Certain Other Acts introduces new rules regarding securities depository, equivalent state, custodian bank, general provisions, the depository and settlement system, the conduct of business by investment firms, custodian banks, securities brokers and investment advisors, the compensation system, professional secrecy, and administrative sanctions for violations of the regulations. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112341391/O/D20111391.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112341391/O/D20111391.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Banking Law, the Act on Trading in Financial Instruments and the Act on Financial Market Supervision introduces new provisions regarding the conduct of business by investment firms, brokerage houses and administrative sanctions for violation of the provisions.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111310763/O/D20110763.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111310763/O/D20110763.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Banking Act, the Insurance Act, the Investment Funds Act, the Financial Instruments Trading Act, and the Financial Market Supervision Act introduces new provisions regarding brokerage houses and confidential information. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101260853/O/D20100853.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101260853/O/D20100853.pdf </a>[link in Polish]<strong>The Act amending the Act on Trading in Financial Instruments introduces new rules regarding transitional and final provisions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20100440252/O/D20100252.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20100440252/O/D20100252.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Act on Toll Motorways and the National Road Fund and the Act on Trading in Financial Instruments introduces new regulations regarding the conduct of business by investment firms. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20092231776/O/D20091776.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20092231776/O/D20091776.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending the Commercial Companies Code and the Act on Trading in Financial Instruments introduces new rules regarding general provisions, the National Depository, and the depository and settlement system. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20090130069/O/D20090069.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20090130069/O/D20090069.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending acts to standardize IT terminology introduces new provisions regarding the terms &#8220;IT data carrier,&#8221; &#8220;IT system,&#8221; and &#8220;electronic communication means.&#8221; </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081711056/O/D20081056.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081711056/O/D20081056.pdf </a>[link in Polish]</li>
</ul>
</li>



<li><strong>Detective Services Act </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20020120110/U/D20020110Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20020120110/U/D20020110Lj.pdf</a>  [link in Polish]<ul><li>The Detective Services Act is a legal act regulating the business of detective services in Poland, defining the rights and obligations of detectives, as well as the rules and procedures for obtaining licenses to practice this profession. The act requires that this activity be entered in a register maintained by the Ministry of Internal Affairs and Administration, and detectives themselves must be licensed. The act defines detective services, meaning activities involving the acquisition, processing, and <strong>transmission of information</strong> at the client&#8217;s request. It specifies what detectives may and may not do, including the obligation to maintain professional confidentiality. Detectives are authorized to process personal data without the consent of the individuals concerned, but only to the extent necessary to conduct an investigation.<strong>The Act amending certain acts in connection with ensuring the application of the GDPR in connection with the processing of personal data and on the free movement of such data, and repealing Directive (EU) 95/46/EC introduces new rules on general provisions, the appointment of a data protection officer, requests for prior consultations before the processing of personal data, provisions on administrative fines, criminal provisions, and the prevention of inspections of compliance with personal data protection provisions. </strong><a href="https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf">https://gdpr.pl/wp-content/uploads/2019/05/Zmiana-niektorych-ustaw-21-lutego-2019_.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act amending certain acts in connection with the standardization of certain document templates in administrative procedures introduces new provisions regarding the principles of conducting business activity in the field of detective services. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000822/O/D20140822.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000822/O/D20140822.pdf </a>[link in Polish]</li></ul></li>



<li><ul><li><strong>The Act Amending the Detective Services Act introduces new provisions regarding the rights and obligations of detectives, the principles of conducting business activities in the field of detective services, the principles of conducting business activities in the field of detective services, and the qualification requirements for detectives. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20110060017/O/D20110017.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20110060017/O/D20110017.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending certain acts in connection with the entry into force of the Protocol to the Agreement between the European Community and its Member States, on the one part, and the Swiss Confederation, on the other, on the free movement of persons introduces new provisions regarding the qualification requirements for detectives. </strong><a href="https://orka.sejm.gov.pl/proc6.nsf/ustawy/552_u.htm">https://orka.sejm.gov.pl/proc6.nsf/ustawy/552_u.htm </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Banking law</mark></strong><br><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19971400939/U/D19970939Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19971400939/U/D19970939Lj.pdf </a>[link in Polish]<ul><li>This Act specifies:<ul><li>Principles of conducting banking activities, establishing and organizing banks, branches and representative offices of foreign banks, as well as branches of credit institutions;Principles of creating and functioning of the protection system;Principles of bank restructuring, liquidation and bankruptcy proceedings;Certain principles for the conduct of business by financial holding companies and mixed financial holding companies and for the organisation of these companies, as well as certain principles for the supervision of these companies;Principles of banking supervision, including consolidated supervision.</li></ul>The Act specifies the information covered by banking secrecy, while at the same time indicating the obligation to provide information covered by banking secrecy to specific entities in the specified circumstances.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds introduces new provisions regarding Regulation (EU) 2022/2554, the objectives of the risk management system and the objectives and activities of banking supervision.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf </a>[link in Polish]<strong>The Act amending certain acts in order to deregulate economic and administrative law and improve the principles of developing economic law introduces new provisions regarding joint accounts. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000769/O/D20250769.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000769/O/D20250769.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Prison Service and certain other acts introduces new provisions on the permitted disclosure of professional secrets on the capital market.</strong> <a href="https://orka.sejm.gov.pl/proc10.nsf/ustawy/993_u.htm">https://orka.sejm.gov.pl/proc10.nsf/ustawy/993_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Development Cooperation and certain other acts introduces new provisions regarding special treatment of state-owned banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000525/O/D20250525.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000525/O/D20250525.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act, the Excise Duty Act, and certain other acts introduces new rules regarding the obligation to provide information covered by banking secrecy and credit information bureaus. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000222/O/D20250222.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250000222/O/D20250222.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Accounting Act, the Act on Statutory Auditors, Audit Firms and Public Oversight, and Certain Other Acts introduces new provisions regarding outsourcing terms, notifying the Polish Financial Supervision Authority of the intention to enter into an outsourcing agreement, the obligation to provide information covered by banking secrecy, credit bureaus, auditing financial statements, re-examination of a bank&#8217;s financial situation, and the obligation to report facts indicating a crime or violation of regulations. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001863/U/D20241863Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001863/U/D20241863Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the exchange of tax information with other countries and certain other acts introduces new provisions on the obligation to provide information covered by bank secrecy and credit information offices.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000879/O/D20240879.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000879/O/D20240879.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the development of the financial market and investor protection on this market introduces new rules regarding mortgage banks, receivables funds, internal methods, extensions or significant changes in the scope of internal methods, other extensions or changes in the scope of internal methods, banking activities, advisory services in relation to structured deposits, other bank activities, scope of insourcer&#8217;s liability, outsourcing conditions, notification to the Polish Financial Supervision Authority of the intention to conclude an outsourcing agreement, general provisions, statutory delegation &#8211; conditions of functioning of the risk management system related to outsourcing, obligation of professional secrecy, decisions issued by the Polish Financial Supervision Authority, delivery of documents in restructuring proceedings, application of the Polish Financial Supervision Authority for the dismissal of a member of the governing body of a bank, financial holding company or mixed financial holding company, prohibition of exercising voting rights from shares, application for a permit to establish a bank, permit to establish a bank and to amend the statute, permit for commencement of business activity by a bank, entry of a domestic bank in the register of entrepreneurs, performance of certain forms of banking activity by a financial institution in the territory of the host country, scope of activity that can be performed by credit institution, the scope of application of Polish law to credit institutions, an explanation of the applicant&#8217;s creditworthiness assessment, structured deposits, the issuance of bank derivative rights, the transfer of receivables by the bank, the obligation to observe banking secrecy, the obligation to provide information covered by banking secrecy, the credit information bureau, entities authorized to obtain aggregate information from the central information on accounts, the obligation to publish information on outsourcers , information obligations towards the municipality related to the termination or expiration of a bank account agreement, own funds, internal capital and the financial management of banks, the objectives and activities of banking supervision, legal remedies available to the Polish Financial Supervision Authority, the imposition of a fine, the implementation of actions under the recovery plan despite failure to achieve indicator levels and criminal sanctions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001723/U/D20231723Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001723/U/D20231723Lj.pdf </a>[link in Polish]<strong>The Act amending certain acts to limit certain effects of identity theft introduces new provisions regarding the obligation to provide information covered by banking secrecy, credit information bureaus, and specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001394/O/D20231394.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230001394/O/D20231394.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act and certain other acts introduces new provisions regarding the crediting and debiting of VAT accounts. </strong><a href="https://orka.sejm.gov.pl/proc9.nsf/ustawy/3025_u.htm" target="_blank" rel="noreferrer noopener">https://orka.sejm.gov.pl/proc9.nsf/ustawy/3025_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act and certain other acts introduces new provisions regarding the obligation to provide information covered by bank secrecy and banking information bureaus. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000996/O/D20230996.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000996/O/D20230996.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Investment Funds and the Management of Alternative Investment Funds, the Act on Bonds, the Act on the Bank Guarantee Fund, the Deposit Guarantee Scheme and Compulsory Restructuring, and certain other acts introduces new provisions regarding decisions issued by the Polish Financial Supervision Authority (KNF), the acquisition of significant stakes in banks, the qualification of capital instruments and subordinated loans, equity, internal capital, and the financial management of banks, legal remedies available to the KNF, the grounds for submitting a bank&#8217;s recovery plan, and the grounds for suspending operations and declaring a bank bankrupt. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000825/O/D20230825.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20230000825/O/D20230825.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Processing of Complaints by Financial Market Entities and on the Financial Ombudsman and certain other acts introduces new provisions regarding the obligation to provide information covered by banking secrecy and credit information bureaus. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002640/O/D20222640.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002640/O/D20222640.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Excise Duty Act and Certain Other Acts introduces new rules regarding the obligation to observe banking secrecy, the obligation to provide information covered by banking secrecy, credit information bureaus, transitional provisions, changes to existing regulations, episodic provisions, and final provisions. </strong><a href="https://orka.sejm.gov.pl/proc9.nsf/ustawy/2764_u.htm" target="_blank" rel="noreferrer noopener">https://orka.sejm.gov.pl/proc9.nsf/ustawy/2764_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Acts to Combat Usury introduces new provisions regarding the scope of application of Polish law to credit institutions, credits, and loans, as well as the principles of exposure concentration, the obligation to provide information covered by banking secrecy, and credit information bureaus. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002339/U/D20222339Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220002339/U/D20222339Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Prison Service Act and certain other acts introduces new provisions regarding the obligation to provide information covered by banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220001933/T/D20221933L.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220001933/T/D20221933L.pdf</a><strong> </strong>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Assistance to Citizens of Ukraine in Connection with the Armed Conflict in the Territory of Ukraine and certain other acts introduces new provisions regarding cash benefits. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220000830/O/D20220830.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20220000830/O/D20220830.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts to improve terminological consistency within the legal system introduces new provisions regarding court jurisdiction in disputes between the National Bank of Poland and banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002052/O/D20212052.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002052/O/D20212052.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new rules concerning Directive (EU) 2013/36, Regulation (EU) 575/2013, Regulation (EU) 2019/2033, brokerage houses applying Regulation (EU) 575/2013, general provisions, the establishment and organization of banks, branches and representative offices of banks, and the organization of financial holding companies and mixed financial holding companies, banking supervision payments, the powers of the Polish Financial Supervision Authority (KNF) in the event that a financial holding company or financial holding company conducts business without the required approval or ceases to meet the conditions for conducting such business, and the list of holding companies. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002140/O/D20212140.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210002140/O/D20212140.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act and the Banking Law introduces new provisions regarding the crediting and debiting of VAT accounts, transfers using VAT accounts, and funds exempt from seizure. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001626/T/D20211626L.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001626/T/D20211626L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Bank Guarantee Fund, the Deposit Guarantee Scheme and Compulsory Restructuring, and certain other acts introduces new provisions regarding entities subject to compulsory restructuring, groups subject to compulsory restructuring, the obligation to observe banking secrecy, the processing and disclosure of information covered by banking secrecy, restrictions on the application of personal data protection regulations due to the implementation of tasks related to counteracting money laundering and terrorist financing, approval of recovery plans, supplementation or amendments to recovery plans, and the conditions for submitting a bank&#8217;s recovery program. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001598/U/D20211598Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20210001598/U/D20211598Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act and certain other acts introduces new provisions regarding the crediting and debiting of VAT accounts and the closing of VAT accounts. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002419/O/D20202419.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200002419/O/D20202419.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Code of Civil Procedure and certain other acts introduces new provisions regarding the obligation to provide information covered by banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000288/U/D20200288Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000288/U/D20200288Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on Government Administration Departments and Certain Other Acts introduces new provisions regarding the statute of a state bank and the procedure for transforming a state bank. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000284/O/D20200284.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000284/O/D20200284.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Administrative Enforcement Proceedings and certain other acts introduces new provisions regarding the Code of Civil Procedure. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190002070/U/D20192070Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190002070/U/D20192070Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Goods and Services Tax Act and certain other acts introduces new provisions regarding the crediting and debiting of VAT accounts, funds exempt from seizure, and closure of VAT accounts. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001751/U/D20191751Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001751/U/D20191751Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts to reduce regulatory burdens introduces new provisions regarding the continued operation of a deceased entrepreneur&#8217;s bank account. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001495/U/D20191495Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001495/U/D20191495Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts to reduce payment backlogs introduces new provisions regarding the obligation to provide information subject to banking and credit bureau secrecy. </strong><a href="https://orka.sejm.gov.pl/proc8.nsf/ustawy/3475_u.htm">https://orka.sejm.gov.pl/proc8.nsf/ustawy/3475_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Support for Borrowers in Financial Difficulty Who Have Taken Out a Housing Loan and Certain Other Acts introduces new provisions regarding the obligation to maintain professional secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001358/O/D20191358.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001358/O/D20191358.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Employee Capital Plans, the Act on the Organization and Operation of Pension Funds, and the Banking Law introduces new provisions regarding joint accounts. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001074/T/D20191074L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190001074/T/D20191074L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Financial Market Supervision and certain other acts introduces new provisions regarding the obligation to maintain professional secrecy and to disclose information about administrative sanctions imposed by the Polish Financial Supervision Authority. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000875/T/D20190875L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000875/T/D20190875L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the application of the GDPR introduces new rules regarding general provisions, profiling, requirements for members of bank bodies, creditworthiness, credit and monetary loans, and the principles of exposure concentration, the obligation to provide information covered by banking secrecy, credit information offices, processing and sharing information covered by banking secrecy, and the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000730/O/D20190730.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000730/O/D20190730.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Bank Guarantee Fund, the deposit guarantee scheme and compulsory restructuring and certain other acts introduces new provisions regarding the Code of Administrative Procedure, basic types of bank accounts, the status of bank accounting books, the obligation to observe banking secrecy, the obligation to provide information covered by banking secrecy, the credit information bureau, capital standards, changes to the content of the obligation of an acquired bank, the liquidation of a bank, other powers and obligations of the liquidator, and provisions applicable to agreements concluded by banks before January 1, 1998. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000326/O/D20190326.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190000326/O/D20190326.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with strengthening financial market supervision and investor protection in that market introduces new provisions regarding the objectives and activities of banking supervision, banking supervision, recovery plans and early intervention, bank liquidation and bankruptcy, grounds for suspension of operations, and bank bankruptcy and insolvency. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002243/U/D20182243Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002243/U/D20182243Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the National Revenue Administration and certain other acts introduces new provisions regarding the obligation to provide information covered by banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002354/T/D20182354L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180002354/T/D20182354L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Payment Services Act and certain other acts introduces new provisions regarding the obligation to provide information covered by banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001075/T/D20181075L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001075/T/D20181075L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new rules regarding Regulation (EU) 596/2014, Regulation (EU) 2017/565, structured deposits, retail clients, professional clients, eligible counterparties, relevant persons, durable media, banking activities, general provisions, prohibition on exercising voting rights attached to shares, banks incorporated as joint-stock companies, applications for authorization to establish a bank, authorization to establish a bank and to amend its statutes, authorization to commence business activities by a bank, capital standards, the objectives and activities of banking supervision, and legal remedies available to the Polish Financial Supervision Authority. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001355/T/D20181355L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001355/T/D20181355L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Certain Powers of Employees of the Office Serving the Minister of Internal Affairs and Officers and Employees of Offices Supervised by that Minister, and Certain Other Acts, introduces new provisions regarding the obligation to provide information covered by banking secrecy and credit bureau confidentiality. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000106/U/D20180106Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180000106/U/D20180106Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Penal Code and Certain Other Acts introduces new provisions regarding the obligation to provide information covered by banking secrecy, credit bureaus, counteracting terrorism financing and money laundering, and the obligation to notify the prosecutor. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000768/O/D20170768.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000768/O/D20170768.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new provisions regarding the objectives and activities of banking supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000724/O/D20170724.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000724/O/D20170724.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Code of Civil Procedure and certain other acts introduces new provisions regarding the obligation to provide information subject to banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000085/T/D20170085L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170000085/T/D20170085L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Family and Guardianship Code and certain other acts introduces new provisions regarding basic types of bank accounts, joint accounts, bank accounts, and the form and content of bank account agreements. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160001177/O/D20161177.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160001177/O/D20161177.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on Investment Funds and Certain Other Acts introduces new provisions regarding investment fund companies, securitization funds, subparticipation agreements, management companies, EU managers, the content of notifications of the intention to acquire a significant block of shares in a bank, supplementary information to the notification, complaint handling by financial market entities, and banking supervision payments. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160000615/O/D20160615.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20160000615/O/D20160615.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Payment Terms in Commercial Transactions, the Civil Code, and certain other acts introduces new provisions regarding the establishment and organization of banks and their branches and representative offices. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001830/O/D20151830.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001830/O/D20151830.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Banking Law and Certain Other Acts introduces new regulations regarding the commencement and conduct of business by domestic banks in the territory of the host country and by credit institutions in the territory of the Republic of Poland, credits and loans, and the principles of exposure concentration and specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001854/O/D20151854.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001854/O/D20151854.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Competition and Consumer Protection and certain other acts introduces new provisions regarding the obligation to provide information covered by banking and credit bureau secrecy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001634/O/D20151634.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001634/O/D20151634.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Civil Code, the Code of Civil Procedure, and certain other acts introduces new provisions concerning the scope of application of Polish law to credit institutions, the protection of savings deposits from enforcement, the obligation to provide information covered by banking secrecy, credit information bureaus, and the specific obligations and powers of banks. </strong><a href="https://orka.sejm.gov.pl/proc7.nsf/ustawy/2678_u.htm">https://orka.sejm.gov.pl/proc7.nsf/ustawy/2678_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on Capital Market Supervision and Certain Other Acts introduces new rules regarding general provisions, specific obligations, and powers of banks and banking supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001260/U/D20151260Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20150001260/U/D20151260Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on supplementary supervision of credit institutions, insurance undertakings, reinsurance undertakings and investment firms in a financial conglomerate and certain other acts introduces new rules regarding the parent institution in a Member State, the parent entity of a financial holding company in a Member State, general provisions, the EU parent institution, the EU parent entity of a financial holding company, the EU parent mixed financial holding company, and consolidated supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000586/O/D20140586.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20140000586/O/D20140586.pdf </a>[link in Polish]<strong>The Act amending the Act on Financial Market Supervision and certain other acts introduces new provisions regarding the specific obligations and powers of banks.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130001567/O/D20131567.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130001567/O/D20131567.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law and the Investment Funds Act introduces new provisions regarding the specific obligations and powers of banks.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130000777/O/D20130777.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130000777/O/D20130777.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Trading in Financial Instruments and certain other acts introduces new provisions concerning the procedure for establishing banks, the taking up and conducting of business by domestic banks in the territory of the host country and by credit institutions in the territory of the Republic of Poland, own funds, internal capital and financial management of banks, banking supervision, supervision over branches of credit institutions and consolidated supervision.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001385/O/D20121385.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001385/O/D20121385.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Banking Law and the Consumer Credit Act introduces new rules for entrepreneurs, general provisions, and specific obligations and powers of banks and banking supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112011181/O/D20111181.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112011181/O/D20111181.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law and certain other acts introduces new provisions on credits and loans and the principles of concentration exposure. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111650984/O/D20110984.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111650984/O/D20110984.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law and certain other acts introduces new provisions concerning banks in the form of joint-stock companies, the procedure for establishing banks and supervision over branches of credit institutions.</strong> <a href="https://eli.gov.pl/api/acts/DU/2011/781/text/O/D20110781.pdf">https://eli.gov.pl/api/acts/DU/2011/781/text/O/D20110781.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law, the Act on Trading in Financial Instruments, and the Act on Financial Market Supervision introduces new rules regarding entities linked by capital or organization, general provisions, credits and loans, and the principles of exposure concentration, specific obligations and powers of banks, affiliation, mergers, and divisions of banks, own funds, internal capital and financial management of banks, banking supervision, consolidated supervision, and recovery proceedings. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111310763/O/D20110763.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111310763/O/D20110763.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law, the Insurance Activity Act, the Investment Funds Act, the Financial Instruments Trading Act, and the Financial Market Supervision Act introduces new rules regarding management companies, general provisions, joint-stock banks, and banking supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101260853/O/D20100853.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101260853/O/D20100853.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Bank Guarantee Fund and the Act – Banking Law introduces new provisions regarding the procedure for establishing banks and the taking up and conducting of business by domestic banks in the territory of the host country and by credit institutions in the territory of the Republic of Poland.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20091441176/T/D20091176L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20091441176/T/D20091176L.pdf </a>[link in Polish]<strong>The Act amending the Act on Cooperative Savings and Credit Unions and the Banking Law introduces new provisions regarding the specific obligations and powers of banks.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20091271045/O/D20091045.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20091271045/O/D20091045.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Bank Guarantee Fund and other acts introduces new provisions regarding the procedure for establishing banks and the taking up and conducting of business by domestic banks in the territory of the host country and by credit institutions in the territory of the Republic of Poland.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20082091315/O/D20081315.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20082091315/O/D20081315.pdf </a>[link in Polish]<strong>The Act amending acts to standardize IT terminology introduces new rules regarding general provisions and monetary settlements conducted through banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081711056/O/D20081056.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081711056/O/D20081056.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Banking Law introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081921179/O/D20081179.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20081921179/O/D20081179.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Bailiffs and Enforcement and certain other acts introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20071120769/O/D20070769.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20071120769/O/D20070769.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law introduces new rules regarding a parent institution in a Member State, a parent entity in a financial holding company in a Member State, an EU parent institution, an EU parent entity in a financial holding company, general provisions, banks in the form of joint-stock companies, bank accounts, credits and loans, and the principles of concentration of exposures, specific obligations and powers of banks, own funds, internal capital and financial management of banks, funds, obligations of the bank, holding companies, banking supervision and consolidated supervision.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20070420272/O/D20070272.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20070420272/O/D20070272.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Banking Law introduces new provisions regarding the affiliation, merger, and division of banks, cooperative banks, and joint-stock banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19971400939/U/D19970939Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19971400939/U/D19970939Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Act on the Protection of Classified Information and Certain Other Acts introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20050850727/O/D20050727.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20050850727/O/D20050727.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending and repealing certain acts in connection with the Republic of Poland&#8217;s accession to the EU introduces new provisions concerning the implementation of EU directives and the taking up and conduct of business by domestic banks in the territory of the host country and by credit institutions in the territory of the Republic of Poland. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040960959/O/D20040959.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040960959/O/D20040959.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law Act and other acts introduces new rules regarding international financial institutions, financial institutions, financial holding companies, foreign bank holding companies, domestic bank holding companies, hybrid holding companies, general provisions, entrepreneurs, establishment and organization of banks and branches and representative offices of banks, state banks, cooperative banks, banks in the form of joint-stock companies, procedures for establishing banks, undertaking and conducting business by domestic banks in the territory of host countries and by credit institutions in the territory of the Republic of Poland, bank accounts, monetary settlements conducted through banks, credits and loans, as well as the principles of concentration of exposures, the sum of bank receivables, borrowers, principles of loan interest, loan security, loan to a third party, credit and loan agreements, granting loans, bank guarantees, sureties and letters of credit, issuing bank securities, specific obligations and rights of banks, association and mergers of banks, own funds and financial management of banks, banking supervision, supervision over branches of credit institutions, consolidated supervision, recovery proceedings, liquidation, bank takeover and bankruptcy.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040910870/O/D20040870.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040910870/O/D20040870.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Public Trading in Securities and other acts introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040640594/O/D20040594.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20040640594/O/D20040594.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the National Bank of Poland and other acts introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20032282260/O/D20032260.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20032282260/O/D20032260.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Commercial Companies Code and certain other acts introduces new provisions regarding banks&#8217; own funds and financial management. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20032292276/O/D20032276.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20032292276/O/D20032276.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Social Insurance System and certain other acts introduces new provisions regarding bank accounts and the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20022412074/U/D20022074Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20022412074/U/D20022074Lj.pdf </a>[link in Polish]<strong>The Act amending the Tax Ordinance Act and certain other acts introduces new provisions regarding the specific obligations and powers of banks and bank bankruptcy. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021691387/U/D20021387Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021691387/U/D20021387Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Banking Law introduces new provisions regarding banks’ own funds and financial management.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021441208/O/D20021208.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021441208/O/D20021208.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Mortgage Bonds and Mortgage Banks and amending certain other acts introduces new provisions concerning the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021261070/T/D20021070L.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20021261070/T/D20021070L.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act on Transformation of Customs Administration and Amending Certain Acts introduces new provisions regarding specific obligations and powers of banks.</strong> <a href="https://orka.sejm.gov.pl/proc4.nsf/ustawy/262_u.htm">https://orka.sejm.gov.pl/proc4.nsf/ustawy/262_u.htm </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act on Changes in the Organization and Operation of Central Government Administration Bodies and Their Subordinate Units and on Amending Certain Acts introduces new provisions regarding the specific obligations and powers of banks, banking supervision, and consolidated supervision. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20020250253/U/D20020253Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20020250253/U/D20020253Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on Bailiffs and Enforcement and certain other acts introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011301452/O/D20011452.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011301452/O/D20011452.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Banking Law and Other Acts introduces new rules regarding general provisions, the establishment and organization of banks, branches and representative offices of banks, state banks, and joint-stock banks, the procedure for establishing banks, bank accounts, monetary settlements conducted through banks, cash settlements, cashier&#8217;s checks, clearing houses, the President of the National Bank of Poland, credits and loans, and the principles of debt concentration, the issuance of bank securities, specific obligations and powers of banks, the association and merger of banks, own funds and the financial management of banks, banking supervision, consolidated supervision, rehabilitation proceedings, civil and criminal liability, and transitional provisions, changes to applicable regulations and final provisions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011111195/O/D20011195.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011111195/O/D20011195.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Police Act, the Insurance Act, the Banking Law, the County Government Act, and the Public Administration Reform Act introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011001084/O/D20011084.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011001084/O/D20011084.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Act on the Bank Guarantee Fund and the Banking Law introduces new provisions on bank accounts, specific obligations and powers of banks, restructuring proceedings and bank bankruptcy.</strong> <a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20001221316/O/D20001316.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20001221316/O/D20001316.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Penal Code, the Code of Criminal Procedure, the Act on Combating Unfair Competition, the Public Procurement Act, and the Banking Law introduces new provisions regarding the specific obligations and powers of banks. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20000931027/O/D20001027.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20000931027/O/D20001027.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending the Act on the Bank Guarantee Fund and certain other acts introduces new rules regarding general provisions, bank accounts, credits, loans, and the principles of debt concentration, specific obligations and powers of banks, recovery proceedings, bank bankruptcy, and transitional provisions, changes to existing and final provisions. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19990400399/O/D19990399.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19990400399/O/D19990399.pdf </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Press law</mark></strong></li>



<li class="has-medium-font-size"><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19840050024/U/D19840024Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19840050024/U/D19840024Lj.pdf</a>  [link in Polish]<ul><li>Press law regulates publishing and journalism. It defines the rights and obligations of journalists, the procedures for obtaining information for press materials, and the principles of maintaining journalistic confidentiality. The act guarantees freedom of speech and the right of citizens to reliable information, transparency in public life, and social scrutiny and criticism. It requires confidentiality towards informants, which is crucial for protecting information sources. The act defines the editorial office as an entity responsible for preparing materials for publication. It emphasizes the role of the press in realizing citizens&#8217; rights to reliable information, transparency in public life, and social criticism, and also ensures freedom of expression. Journalists have the right to public information, and state bodies are obligated to create conditions enabling the performance of these duties. The act contains provisions regarding the publication of corrections, which should be posted or submitted to the appropriate editorial office.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Press Law introduces new provisions regarding the right to provide information to the press, the disclosure of personal data and images of individuals subject to legal proceedings, the exemption from journalistic confidentiality, the forfeiture of press materials, and the legal protection of criticism, satire, and caricature. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001570/O/D20181570.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001570/O/D20181570.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Press Law introduces new provisions concerning the obligations of state authorities towards the press, subject-matter exclusion from the scope of press law, legal protection of criticism, satire, and caricature, journalists&#8217; obligations, authorization of statements, the obligation to obtain consent to publish certain information, the rights and obligations of journalists, the Press Council, the application for registration of a daily newspaper or magazine, the editor-in-chief, the editorial board, the editorial council, legal liability, and the application of provisions on proceedings in misdemeanor cases. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170002173/O/D20172173.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20170002173/O/D20172173.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Press Law introduces new provisions regarding legal liability and procedure in press matters. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130000771/O/D20130771.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20130000771/O/D20130771.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Press Law introduces new provisions regarding corrections, corrections of inaccurate or false information contained in press materials, publication of corrections or responses, refusal to publish corrections or responses, legal liability, and proceedings in press matters. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001136/U/D20121136Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20120001136/U/D20121136Lj.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act Amending the Press Law introduces new provisions regarding the rights and obligations of journalists. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112051204/O/D20111204.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20112051204/O/D20111204.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending the Civil Code introduces new provisions regarding legal liability. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19961140542/O/D19960542.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19961140542/O/D19960542.pdf </a>[in Polish]</li></ul></li>



<li class="has-medium-font-size"><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-green-cyan-color"><mark>Act on the National Cybersecurity </mark></mark>System</strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001560/U/D20181560Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001560/U/D20181560Lj.pdf </a>[link in Polish]<ul><li>The Act on the National Cybersecurity System establishes the National Cybersecurity System. The Act aims to ensure cybersecurity at the national level by protecting essential and digital services and the IT systems that support them. The National Cybersecurity System encompasses, among others, essential service operators (e.g., in energy, transport, and healthcare), digital service providers, and public administration. The Act&#8217;s main objectives:<ul><li>Ensuring continuity of services: Guaranteeing the uninterrupted provision of key services for the state and the economy;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>System security: Achieving a high level of security of IT systems;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Definition of tasks and responsibilities: Defining the roles and responsibilities of entities comprising the National Cybersecurity System, including essential service operators, digital service providers and public authorities;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Incident response: Creating a legal framework for detecting, preventing and minimizing the effects of cyberattacks, including the functioning of national CSIRTs.</li></ul>The Act covers, among others:<ul><li>Key service operators;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Digital service providers;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Public administration bodies.</li></ul>The Act implemented the requirements and standards of the EU directive, which constitutes minimum harmonization, but also extended its scope to the Polish administration and telecommunications sector. The Act formally strengthened the operations of existing national teams, such as CERT GOV (CSIRT GOV), CSIRT MON, and CSIRT NASK.</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts in connection with ensuring the operational digital resilience of the financial sector and issuing European green bonds introduces new provisions regarding the obligations of essential service operators and the tasks, composition, chairperson, secretary, detailed scope of activities, and procedures of the Council. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20250001069/O/D20251069.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts related to the functioning of government administration introduces new provisions regarding the tasks of the minister responsible for computerization, maximum limits of expenditure from the state budget. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000834/O/D20240834.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000834/O/D20240834.pdf </a>[link in Polish]</li></ul></li>



<li class="has-medium-font-size"><ul><li><strong>The Act amending certain acts regarding protective measures in connection with the spread of the SARS-CoV-2 virus introduces new provisions regarding the tasks of the management boards. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000875/U/D20200875Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20200000875/U/D20200875Lj.pdf </a>[link in Polish]</li></ul>
<ul class="wp-block-list">
<li><strong>The Act amending the Education Law and certain other acts introduces new provisions regarding maintenance in force of implementing regulations. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190002248/O/D20192248.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20190002248/O/D20192248.pdf </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><mark><strong>Regulation of the Council of Ministers on the National Interoperability Framework, minimum requirements for public registers and the exchange of information in electronic form, and minimum requirements for ICT systems</strong> </mark><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000773/O/D20240773.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000773/O/D20240773.pdf </a>[link in Polish]
<ul class="wp-block-list">
<li>The National Interoperability Framework Regulation regulates the principles of interoperability in public administration, including:<ul><li>National Interoperability Framework: Defines the framework and standards that ensure the proper functioning of ICT systems in public administration;</li></ul><ul><li>Minimum requirements for public records: Indicates the minimum requirements for records maintained by public entities to be consistent and compliant with the National Interoperability Framework;</li></ul><ul><li>Electronic Information Exchange: Establishes rules for the exchange of information between public entities, including standards for the security and efficiency of such exchange.</li></ul><ul><li>Minimum requirements for IT systems: Specifies the minimum requirements for IT systems used by public entities, including information security systems, so that they can cooperate with each other and exchange data;</li></ul>
<ul class="wp-block-list">
<li>This regulation is a legal act specifying what standards and principles should apply in Polish public administration in order to ensure interoperability – i.e. the ability to cooperate and exchange information between different IT systems.</li>
</ul>
</li>
</ul>
</li>



<li><strong><mark>Regulation of the Minister of Health on the types of medical documentation of occupational health services, the method of maintaining and storing it, and the templates of the documents used</mark></strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101491002/O/D20101002.pdf" target="_blank" rel="noreferrer noopener"> https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20101491002/O/D20101002.pdf </a>[link in Polish]<ul><li>Medical documentation of the occupational health service in the field of preventive health care for employees includes:<ul><li>Individual medical documentation, which is a preventive examination card;</li></ul></li></ul></li>



<li><ul><li><ul><li>Collective medical documentation.</li></ul></li></ul></li>



<li><ul><li>Medical records are stored by the occupational health service unit that maintains them. Medical records are stored in conditions that ensure the protection of the data contained therein and protect against destruction, damage, or loss, as well as against unauthorized access, while also enabling their use without undue delay. The regulation specifies the retention period for occupational health service medical records. Medical records are the property of the entities obligated to maintain them.</li></ul>
<ul class="wp-block-list">
<li><strong>The Regulation of the Minister of Health amending the Regulation on the types of medical documentation of the occupational health service, the manner of maintaining and storing it, and the templates of the documents used introduces new provisions regarding the title and period of storage of medical documentation of the occupational health service. </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001311/O/D20241311.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240001311/O/D20241311.pdf </a>[link in Polish]</li>
</ul>
</li>



<li class="has-medium-font-size"><strong>Labor Code</strong><a href="https://natlex.ilo.org/dyn/natlex2/natlex2/files/download/45181/The-Labour-Code%20consolidated%201997.pdf" target="_blank" rel="noreferrer noopener">https://natlex.ilo.org/dyn/natlex2/natlex2/files/download/45181/The-Labour-Code%20consolidated%201997.pdf</a><ul><li>The Labor Code is a set of legal provisions regulating the rights and obligations of both employees and employers in Poland. It includes rules regarding, among other things:<ul><li>Establishing and terminating employment relationships;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Wages and salaries;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Working time, holidays;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>Occupational health and safety.</li></ul></li></ul>
<ul class="wp-block-list">
<li>This is the most important legal act regulating employment relations in Poland. The Labor Code contains provisions regarding the employment of minors. It defines the principles of employee liability for damage caused to the employer and the principles for resolving disputes between employees and employers. Sanctions apply for offenses against employee rights. The Labor Code specifies the limitation periods for claims related to the employment relationship. It applies to all employees employed under an employment contract and, in some cases, also to those employed under other legal bases, to the extent not regulated by specific provisions. It is worth remembering that the Labor Code is a legal act that is subject to regular amendments.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Educational Information System Act</mark></strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111390814/U/D20110814Lj.pdf"> https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20111390814/U/D20110814Lj.pdf </a>[link in Polish]
<ul class="wp-block-list">
<li>The Education Information System introduces and defines the operational principles of the Education Information System – a Polish electronic database system used to collect and process information about schools, institutions, students, and teachers. The Education Information System is a key tool for supporting education management at various levels, data analysis, educational policy planning, and graduate career monitoring. The main goals of the Education Information System are:<ul><li>Supporting Educational Governance: Provides the data necessary for informed decision-making by policymakers at national, regional and local levels;</li></ul><ul><li>Education financing: Enables effective management of public funds allocated to education;</li></ul><ul><li>Analysis and monitoring: Allows us to examine the effectiveness of the education system and track the career paths of graduates;</li></ul>
<ul class="wp-block-list">
<li>Quality Improvement: Assists in overseeing and coordinating pedagogical supervision and improving the quality of education.</li>
</ul>
</li>
</ul>
</li>



<li><strong>Act on the Security of Mass Events </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20090620504/U/D20090504Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20090620504/U/D20090504Lj.pdf</a><ul><li>The Event Safety Act regulates the principles of ensuring safety during mass events, defining what constitutes a mass event (e.g., a concert, a sports match with a specified number of participants), the organizer&#8217;s responsibilities, the rules for issuing permits, and also provides penalties for violating regulations, such as bringing dangerous objects or disrupting the event. The Act defines a mass event as any gathering of at least 1,000 people outdoors or 300 people indoors, and which is for artistic and entertainment purposes (e.g., concerts) or sporting activities (e.g., football matches). The organizer of a mass event is primarily responsible for ensuring safety. Their responsibilities include:<ul><li>Ensuring an adequate number of security staff;</li></ul></li></ul></li>



<li><ul><li><ul><li>Maintaining public order;</li></ul></li></ul></li>



<li><ul><li><ul><li>Security of participants and property;</li></ul></li></ul>
<ul class="wp-block-list">
<li>The law provides penalties for violating its provisions. For example, anyone bringing weapons or pyrotechnics to a mass event is subject to a fine or imprisonment.</li>
</ul>
</li>



<li class="has-medium-font-size"><strong><mark>Law on Higher Education and Science</mark></strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001668/U/D20181668Lj.pdf"> https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001668/U/D20181668Lj.pdf </a>[link in Polish]<ul><li>The Law on Higher Education and Science is a key Polish legal act that regulates the operation of the higher education system and scientific activity. The act specifies, among other things:<ul><li>organization and functioning of universities;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>rights and obligations of students;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>doctoral students and research workers;</li></ul></li></ul></li>



<li class="has-medium-font-size"><ul><li><ul><li>principles of conducting scientific research and development.</li></ul></li></ul>
<ul class="wp-block-list">
<li>The Act places significant emphasis on the autonomy of the academic community and universities as such. It outlines the system&#8217;s mission to ensure the highest quality of education, shape civic attitudes, and support economic innovation. The Act guarantees freedom in teaching, creating, conducting scientific research, and publishing its results. Universities enjoy autonomy in their operations. Public authorities are responsible for creating conditions for the development of science, and universities fulfill a mission important to the state and society.</li>
</ul>
</li>



<li><strong>Act on the Military Police and Military Law Enforcement Bodies </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011231353/U/D20011353Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20011231353/U/D20011353Lj.pdf </a>[link in Polish]
<ul class="wp-block-list">
<li>The Act on the Military Police and Military Law Enforcement Bodies is a 2001 legal act that regulates the activities of the Military Police as a specialized military service and other military law enforcement bodies in Poland. The Act defines their organization, powers, responsibilities, and tasks, including ensuring military discipline, protecting public order in military areas, detecting crimes, and combating threats. The main tasks of the Military Police and military law enforcement bodies:<ul><li>Military discipline;</li></ul><ul><li>Public order;</li></ul><ul><li>Protection of life, health and property;</li></ul><ul><li>Prevention and detection of crimes;</li></ul><ul><li>Anti-terrorist operations;</li></ul><ul><li>International cooperation;</li></ul>
<ul class="wp-block-list">
<li>Combating threats.</li>
</ul>
</li>
</ul>
</li>



<li><strong>Act on the remuneration of persons managing certain legal entities </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20000260306/U/D20000306Lj.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20000260306/U/D20000306Lj.pdf</a><strong> </strong>[link in Polish]
<ul class="wp-block-list">
<li>The Act on the Remuneration of Persons Managing Certain Legal Entities, commonly known as the &#8220;Salary Cap Act,&#8221; is a set of regulations that restrict the remuneration of managerial staff in entities related to the public sector, such as state-owned enterprises, state-owned organizations, and local government units. The main goal of the act is to limit excessive remuneration for managers in these institutions, covering them under both employment contracts and civil law contracts.</li>
</ul>
</li>



<li><strong>Act on the Supreme Audit Office</strong><a href="https://www.nik.gov.pl/en/about-us/legal-regulations/act-on-the-supreme-audit-office.html">https://www.nik.gov.pl/en/about-us/legal-regulations/act-on-the-supreme-audit-office.html</a>
<ul class="wp-block-list">
<li>The Act on the Supreme Audit Office defines the scope of its authority, including the right to examine the activities of state and local government bodies in terms of legality, efficiency, purposefulness, and reliability, as well as the principles of its work and the submission of audit results. The Supreme Audit Office submits the results of its audits to the Sejm, the President of the Republic of Poland, and the Prime Minister. It also publicly discloses the results of major audits.</li>
</ul>
</li>



<li><strong>Accounting Act </strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19941210591/U/D19940591Lj.pdf">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19941210591/U/D19940591Lj.pdf</a><strong> </strong>[link in Polish]
<ul class="wp-block-list">
<li>The Act implements European Community directives in its regulations. It defines accounting principles and the rules for providing bookkeeping services. It includes data protection rules:<ul><li>When maintaining accounting books using a computer, data protection should consist in the use of threat-resistant data carriers, the selection of appropriate external protection measures, the systematic creation of reserve copies of data sets stored on IT data carriers, provided that the durability of the accounting system information recording is ensured for a period no shorter than that required for storing accounting books, and ensuring the protection of computer programs and data of the accounting IT system by using appropriate software and organizational solutions to protect against unauthorized access or destruction.</li></ul>
<ul class="wp-block-list">
<li>Unless separate provisions provide otherwise, making collections or parts thereof available to a third party:<ul><li>Inspection on the premises of the unit requires the consent of the head of the unit or a person authorized by him;</li></ul>
<ul class="wp-block-list">
<li>Outside the seat of the entity&#8217;s management board, written consent of the entity&#8217;s head is required and a certified list of the documents taken over must be left at the entity.</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>



<li><strong>Geodetic and cartographic law</strong><a href="https://www.gov.pl/attachment/95f99183-a84e-40a3-8e46-10975e5eacaf">https://www.gov.pl/attachment/95f99183-a84e-40a3-8e46-10975e5eacaf </a>[link in Polish]
<ul class="wp-block-list">
<li>Geodetic Law defines the principles of geodesy and cartography in Poland, covering, among other things, the performance of measurements, the preparation of maps, the maintenance of land and building records, the demarcation of properties, and the management of state geodetic and cartographic resources. This Act also governs the organization of the Geodetic and Cartographic Service and defines professional qualifications in this field. Surveyors are granted the right to access land and buildings to perform necessary surveying work. The scope of geodetic work includes the design and execution of geodetic measurements, control network measurements, as well as the measurement of basic gravimetric and magnetic control networks.</li>
</ul>
</li>



<li><strong>Regulation of the Minister of National Education on the manner of maintaining documentation of the teaching process, educational and care activities by public kindergartens, schools and other institutions and on the types of such documentation</strong><a href="https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000050/O/D20240050.pdf" target="_blank" rel="noreferrer noopener">https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20240000050/O/D20240050.pdf </a>[link in Polish]
<ul class="wp-block-list">
<li>The regulation regulates the types of documentation required in public preschools, schools, and educational institutions, how they should be maintained, and what each must contain, including documentation of teaching, educational, and care activities. It applies to all public preschools, schools, and educational institutions.</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Definitions</h2>



<h3 class="wp-block-heading">Data</h3>



<p>Data – collected facts, numbers, symbols, or observations describing phenomena, objects, or people that can be processed to give them meaning. Personal data is any information that allows for the identification of an individual, directly or indirectly, such as name, surname, email address, Personal Identification number, as well as physical, mental, or cultural characteristics. Non-personal data does not allow for the identification of an individual and is usually anonymized or aggregated data, such as website visitor statistics, partially masked IP addresses, or anonymous system logs.</p>



<h3 class="wp-block-heading">AI</h3>



<p>Artificial intelligence is a technology that enables machines to perform tasks traditionally requiring human intelligence through the ability to learn, reason, and solve problems. AI systems are advanced software and machines that simulate human cognitive abilities by analyzing data, learning from experience, and adapting to new situations. AI can perform tasks such as prediction, generating recommendations, and making decisions autonomously based on processed data. This definition is dynamic and evolving, and organizations such as the OECD and EU legislators are working to standardize it. The AI Act regulates the use of AI in the European Union within the limits of the competences granted to the EU by the member states. EU law does not cover AI applications beyond these competences.</p>



<h3 class="wp-block-heading">Hacker Attack</h3>



<p>A hacker attack is a deliberate, usually criminal, act aimed at gaining unauthorized access to computer systems, networks, or digital devices in order to steal, modify, or destroy data, disrupt services, or gain other benefits. These attacks can be carried out by individuals or groups of hackers, exploiting security vulnerabilities and malware such as viruses, keyloggers, or ransomware. A hacker attack compromises the integrity, confidentiality, or availability of systems and data and is treated as a cybercrime, subject to the Polish Penal Code and European Union law implementing directives on cybercrime and personal data protection. Data protection is a set of strategies and processes designed to protect confidential information from damage, security breaches, loss, or unauthorized access. A data breach occurs when a security incident compromises the confidentiality, integrity, or availability of data.</p>



<h3 class="wp-block-heading">Cybersecurity</h3>



<p>Cybersecurity is the set of activities, practices, processes, and technologies designed to protect computer systems, networks, devices, and data from digital threats, such as malware and attacks, while ensuring the confidentiality, integrity, and availability of information. It encompasses attack prevention, detection, and incident response in cyberspace. Data cybersecurity focuses on protecting personal, financial, and business information, as well as other digital assets, from cyberattacks, theft, and unauthorized access. Cybersecurity also encompasses technical and organizational measures designed to protect systems, data, and services from unauthorized access, damage, loss, or disruption.</p>



<p></p>



<figure class="wp-block-image size-large"><a href="https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200.png"><img loading="lazy" decoding="async" width="1024" height="865" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-1024x865.png" alt="" class="wp-image-8315" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-1024x865.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-300x253.png 300w, https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-768x648.png 768w, https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-1536x1297.png 1536w, https://www.kg-legal.eu/wp-content/uploads/2025/09/Kod-200-2048x1729.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>


<p class="wp-block-tag-cloud"><a href="https://www.kg-legal.eu/info/tag/ai/" class="tag-cloud-link tag-link-1251 tag-link-position-1" style="font-size: 8pt;" aria-label="AI (4 items)">AI</a>
<a href="https://www.kg-legal.eu/info/tag/ai-act/" class="tag-cloud-link tag-link-1175 tag-link-position-2" style="font-size: 10.105263157895pt;" aria-label="AI Act (7 items)">AI Act</a>
<a href="https://www.kg-legal.eu/info/tag/ai-compliance/" class="tag-cloud-link tag-link-1913 tag-link-position-3" style="font-size: 9.5789473684211pt;" aria-label="AI Compliance (6 items)">AI Compliance</a>
<a href="https://www.kg-legal.eu/info/tag/artificial-intelligence/" class="tag-cloud-link tag-link-1379 tag-link-position-4" style="font-size: 10.631578947368pt;" aria-label="Artificial intelligence (8 items)">Artificial intelligence</a>
<a href="https://www.kg-legal.eu/info/tag/att-jakub-gladkowski/" class="tag-cloud-link tag-link-126 tag-link-position-5" style="font-size: 8pt;" aria-label="Att Jakub Gładkowski (4 items)">Att Jakub Gładkowski</a>
<a href="https://www.kg-legal.eu/info/tag/biotechnology/" class="tag-cloud-link tag-link-170 tag-link-position-6" style="font-size: 8pt;" aria-label="biotechnology (4 items)">biotechnology</a>
<a href="https://www.kg-legal.eu/info/tag/business-law/" class="tag-cloud-link tag-link-2116 tag-link-position-7" style="font-size: 10.631578947368pt;" aria-label="Business Law (8 items)">Business Law</a>
<a href="https://www.kg-legal.eu/info/tag/cee/" class="tag-cloud-link tag-link-2229 tag-link-position-8" style="font-size: 8.8421052631579pt;" aria-label="CEE (5 items)">CEE</a>
<a href="https://www.kg-legal.eu/info/tag/consumer-protection/" class="tag-cloud-link tag-link-1669 tag-link-position-9" style="font-size: 11.157894736842pt;" aria-label="CONSUMER PROTECTION (9 items)">CONSUMER PROTECTION</a>
<a href="https://www.kg-legal.eu/info/tag/corporate-law/" class="tag-cloud-link tag-link-629 tag-link-position-10" style="font-size: 8.8421052631579pt;" aria-label="corporate law (5 items)">corporate law</a>
<a href="https://www.kg-legal.eu/info/tag/cross-border-business/" class="tag-cloud-link tag-link-2156 tag-link-position-11" style="font-size: 8.8421052631579pt;" aria-label="Cross Border Business (5 items)">Cross Border Business</a>
<a href="https://www.kg-legal.eu/info/tag/cross-border-cases/" class="tag-cloud-link tag-link-190 tag-link-position-12" style="font-size: 18pt;" aria-label="cross border cases (44 items)">cross border cases</a>
<a href="https://www.kg-legal.eu/info/tag/cybersecurity-en/" class="tag-cloud-link tag-link-1011 tag-link-position-13" style="font-size: 8.8421052631579pt;" aria-label="cybersecurity (5 items)">cybersecurity</a>
<a href="https://www.kg-legal.eu/info/tag/data-protection/" class="tag-cloud-link tag-link-489 tag-link-position-14" style="font-size: 9.5789473684211pt;" aria-label="data protection (6 items)">data protection</a>
<a href="https://www.kg-legal.eu/info/tag/digital-compliance/" class="tag-cloud-link tag-link-2146 tag-link-position-15" style="font-size: 8.8421052631579pt;" aria-label="Digital Compliance (5 items)">Digital Compliance</a>
<a href="https://www.kg-legal.eu/info/tag/digital-services-act/" class="tag-cloud-link tag-link-1519 tag-link-position-16" style="font-size: 9.5789473684211pt;" aria-label="Digital Services Act (6 items)">Digital Services Act</a>
<a href="https://www.kg-legal.eu/info/tag/doing-business-in-poland/" class="tag-cloud-link tag-link-176 tag-link-position-17" style="font-size: 16.315789473684pt;" aria-label="Doing business in Poland (30 items)">Doing business in Poland</a>
<a href="https://www.kg-legal.eu/info/tag/dsa/" class="tag-cloud-link tag-link-1521 tag-link-position-18" style="font-size: 9.5789473684211pt;" aria-label="DSA (6 items)">DSA</a>
<a href="https://www.kg-legal.eu/info/tag/eu-law/" class="tag-cloud-link tag-link-2222 tag-link-position-19" style="font-size: 10.105263157895pt;" aria-label="EU Law (7 items)">EU Law</a>
<a href="https://www.kg-legal.eu/info/tag/eu-regulation/" class="tag-cloud-link tag-link-653 tag-link-position-20" style="font-size: 8pt;" aria-label="eu regulation (4 items)">eu regulation</a>
<a href="https://www.kg-legal.eu/info/tag/gdpr/" class="tag-cloud-link tag-link-1385 tag-link-position-21" style="font-size: 8pt;" aria-label="gdpr (4 items)">gdpr</a>
<a href="https://www.kg-legal.eu/info/tag/healthcare-law/" class="tag-cloud-link tag-link-2140 tag-link-position-22" style="font-size: 8pt;" aria-label="Healthcare Law (4 items)">Healthcare Law</a>
<a href="https://www.kg-legal.eu/info/tag/in-house-counsel/" class="tag-cloud-link tag-link-2125 tag-link-position-23" style="font-size: 8.8421052631579pt;" aria-label="In House Counsel (5 items)">In House Counsel</a>
<a href="https://www.kg-legal.eu/info/tag/international-law/" class="tag-cloud-link tag-link-2212 tag-link-position-24" style="font-size: 9.5789473684211pt;" aria-label="International Law (6 items)">International Law</a>
<a href="https://www.kg-legal.eu/info/tag/international-trade/" class="tag-cloud-link tag-link-577 tag-link-position-25" style="font-size: 8pt;" aria-label="international trade (4 items)">international trade</a>
<a href="https://www.kg-legal.eu/info/tag/it/" class="tag-cloud-link tag-link-102 tag-link-position-26" style="font-size: 11.578947368421pt;" aria-label="IT (10 items)">IT</a>
<a href="https://www.kg-legal.eu/info/tag/kg-legal/" class="tag-cloud-link tag-link-104 tag-link-position-27" style="font-size: 21.578947368421pt;" aria-label="KG Legal (96 items)">KG Legal</a>
<a href="https://www.kg-legal.eu/info/tag/kglegal/" class="tag-cloud-link tag-link-469 tag-link-position-28" style="font-size: 10.105263157895pt;" aria-label="kglegal (7 items)">kglegal</a>
<a href="https://www.kg-legal.eu/info/tag/kieltyka-gladkowski/" class="tag-cloud-link tag-link-735 tag-link-position-29" style="font-size: 12.736842105263pt;" aria-label="kiełtyka gładkowski (13 items)">kiełtyka gładkowski</a>
<a href="https://www.kg-legal.eu/info/tag/law-firm/" class="tag-cloud-link tag-link-2084 tag-link-position-30" style="font-size: 10.105263157895pt;" aria-label="Law Firm (7 items)">Law Firm</a>
<a href="https://www.kg-legal.eu/info/tag/law-firm-in-cracow/" class="tag-cloud-link tag-link-80 tag-link-position-31" style="font-size: 12.315789473684pt;" aria-label="law firm in Cracow (12 items)">law firm in Cracow</a>
<a href="https://www.kg-legal.eu/info/tag/law-firm-in-krakow/" class="tag-cloud-link tag-link-82 tag-link-position-32" style="font-size: 12pt;" aria-label="law firm in Krakow (11 items)">law firm in Krakow</a>
<a href="https://www.kg-legal.eu/info/tag/legal-tech/" class="tag-cloud-link tag-link-2184 tag-link-position-33" style="font-size: 9.5789473684211pt;" aria-label="Legal Tech (6 items)">Legal Tech</a>
<a href="https://www.kg-legal.eu/info/tag/nis2/" class="tag-cloud-link tag-link-1171 tag-link-position-34" style="font-size: 8pt;" aria-label="NIS2 (4 items)">NIS2</a>
<a href="https://www.kg-legal.eu/info/tag/poland/" class="tag-cloud-link tag-link-112 tag-link-position-35" style="font-size: 22pt;" aria-label="Poland (105 items)">Poland</a>
<a href="https://www.kg-legal.eu/info/tag/polish-law/" class="tag-cloud-link tag-link-148 tag-link-position-36" style="font-size: 20.210526315789pt;" aria-label="Polish law (71 items)">Polish law</a>
<a href="https://www.kg-legal.eu/info/tag/polish-law-firm/" class="tag-cloud-link tag-link-106 tag-link-position-37" style="font-size: 8.8421052631579pt;" aria-label="Polish Law Firm (5 items)">Polish Law Firm</a>
<a href="https://www.kg-legal.eu/info/tag/polish-lawyer/" class="tag-cloud-link tag-link-186 tag-link-position-38" style="font-size: 8pt;" aria-label="Polish lawyer (4 items)">Polish lawyer</a>
<a href="https://www.kg-legal.eu/info/tag/polish-patent-office/" class="tag-cloud-link tag-link-342 tag-link-position-39" style="font-size: 9.5789473684211pt;" aria-label="Polish Patent Office (6 items)">Polish Patent Office</a>
<a href="https://www.kg-legal.eu/info/tag/regulatory-compliance/" class="tag-cloud-link tag-link-2128 tag-link-position-40" style="font-size: 11.578947368421pt;" aria-label="Regulatory Compliance (10 items)">Regulatory Compliance</a>
<a href="https://www.kg-legal.eu/info/tag/symposium/" class="tag-cloud-link tag-link-625 tag-link-position-41" style="font-size: 8.8421052631579pt;" aria-label="symposium (5 items)">symposium</a>
<a href="https://www.kg-legal.eu/info/tag/technology-law/" class="tag-cloud-link tag-link-2189 tag-link-position-42" style="font-size: 10.631578947368pt;" aria-label="Technology Law (8 items)">Technology Law</a>
<a href="https://www.kg-legal.eu/info/tag/uokik/" class="tag-cloud-link tag-link-503 tag-link-position-43" style="font-size: 8pt;" aria-label="uokik (4 items)">uokik</a>
<a href="https://www.kg-legal.eu/info/tag/vat/" class="tag-cloud-link tag-link-1325 tag-link-position-44" style="font-size: 8pt;" aria-label="vat (4 items)">vat</a>
<a href="https://www.kg-legal.eu/info/tag/webinar/" class="tag-cloud-link tag-link-563 tag-link-position-45" style="font-size: 9.5789473684211pt;" aria-label="webinar (6 items)">webinar</a></p><p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/privacy-data-protection-ai-and-cybersecurity-law-map/">PRIVACY, DATA PROTECTION, AI AND CYBERSECURITY – LAW MAP</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/privacy-data-protection-ai-and-cybersecurity-law-map/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2025/09/20230506_201821-2.mp4" length="20035661" type="video/mp4" />

			</item>
		<item>
		<title>Voice Cloning as a Global New Technology and its Challenges for EU and Polish Law</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/voice-cloning-as-a-global-new-technology-and-its-challenges-for-eu-and-polish-law/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/voice-cloning-as-a-global-new-technology-and-its-challenges-for-eu-and-polish-law/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 07 Jul 2017 10:56:08 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[voice cloning]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=1051</guid>

					<description><![CDATA[<p>Voice Cloning as a Global New Technology and its Challenges for EU and Polish Law</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/voice-cloning-as-a-global-new-technology-and-its-challenges-for-eu-and-polish-law/">Voice Cloning as a Global New Technology and its Challenges for EU and Polish Law</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wp-block-image">
<figure class="alignleft size-large is-resized"><img decoding="async" src="https://www.kg-legal.eu/wp-content/uploads/2016/12/pay-per-view.jpg" alt="" style="width:302px;height:auto"/></figure></div>

<p>Siri, Cortana, Google and other applications use human voice to do a variety of things, e.g. searching for information, sending emails, calling somebody. Voice-based technologies are increasingly applied in legal environment and legal services, for example in legal advice rendered online and in legal translations. At the same time, new applications of innovative technologies caused the necessity to define the approach to privacy issues anew. The cases of Edward Snowden and Julian Assange showed us how meaningful privacy and its protection is and made us realize the excessive amount of personal data processed and stored daily. This is why privacy and its protection will soon become one of the most important personal rights. The issue of voice protection comes to the fore in this context. Voice is, obviously, a personal right. What is more, voice is becoming a tool used by most applications both for mundane activities as well as more complex ones, like ROSS AI operating on IBM’s Watson, which can do legal research and is learning to understand law with every research conducted by it. What if it was possible for such applications as Watson to use the voice of a specific lawyer and, with the use of voice sample, produce speech of a different content, for example in the form of legal advice? Well, practically it is possible, since last November Adobe presented Adobe VoCo to the world, which (when having a voice sample) is able to read various content differing from the conent sampled. The present article will try to shed some light to the issue of the risk involved with voice cloning technology in legal environment and will analyse whether law can adequately protect human voice as a personal right.</p>
<p><span id="more-1051"></span></p>
<h4><strong>Background of Voice Cloning Technology</strong></h4>
<p>Voice cloning technology is based on copying and reusing of recorded speech. In the future, such software will be able to record voice samples and, afterwards, produce an infinite number of combined syllables leading to an unlimited number of sentences, without the participation of the human being that provided the voice sample. In reference to the latest developments, we may be first to witness the creation of such software for commercial use. The first project worth mentioning is Google Deep Mind&#8217;s WaveNet. It is a deep neural network for generating raw audio waveforms, including speech and music. WaveNet has outperformed other text-to-speech systems, but this product has not yet been declared to be available for consumers.<a href="#_edn1" name="_ednref1">[i]</a> From this point of view, it is of importance to mention Adobe Project VoCo, presented during the Adobe MAX 2016 Sneak Peeks. It is a software which is able to create a voice model of the speaker from an earlier given voice sample of 20 minutes duration by said speaker.<a href="#_edn2" name="_ednref2">[ii]</a> VoCo can construct new words and sentences which did not occur in the provided recordings.<a href="#_edn3" name="_ednref3">[iii]</a> Such potential of said software, with the plans to release VoCo to the consumer market, raises considerable concerns, also legal ones, in respect of data and privacy protection.</p>
<h4>Voice as a Personal Right and its Protection in Polish Jurisdiction</h4>
<p>In order to specify if the European or the Polish law can adequately protect the use of voice technology-based applications and word-building software, we need to indicate the legal status of the human voice at first. From the legal point of view, the human voice should generally be classified as a personal right and, more specific, as a non-pecuniary property of every human being connected with his individual existence, which is effective against everyone, inalienable and not inherited. Polish provisions (art. 23–24 of the  <a href="http://www.ebrd.com/downloads/legal/core/poland.pdf">Polish Civil Code</a>) include a sample and open catalogue of personal rights and their protection, irrespective of other regulations. Polish jurisprudence and the majority of law practitioners<a href="#_edn4" name="_ednref4">[iv]</a> express approval for the most essential judgement in this regard, which has been delivered by the Polish Court of Appeals in Gdańsk on 21 June 1991 (case citation: <a href="http://prawo.legeo.pl/prawo/i-acr-127-91/">I ACr 127/91, LEX</a>), where the Court acknowledged that the voice shall be regarded as a personal right (as defined in art. 23 of the Poish Civil Code)<a href="#_edn5" name="_ednref5">[v]</a> and protected pursuant to art. 24 of the Polish Civil Code.<a href="#_edn6" name="_ednref6">[vi]</a> Voice serves the same purpose as a human image, namely: identification. It is an element of appearance, given that it relates to individual voice alteration, pitch, sound and the ways someone speaks, i.e. intonation and characteristic words. The violation of this right could occur, e.g., by duplication of voice records or their modification and, what is more, by imitation of distinctive voices, if it could be demonstrated that the above mentioned use was intended to deceive listeners in regard to the identity of the person speaking.<a href="#_edn7" name="_ednref7">[vii]</a> In case of acknowledging that recognizing a person within the sphere of a sound is possible just as well as through an external image, principles related to images apply analogically to voices, provided that the voice is protected as a separate personal right.<a href="#_edn8" name="_ednref8">[viii]</a></p>
<p>In accordance with the latter provision, the one whose personal right is threatened by the activity of third party may demand this activity to cease, unless it is legitimate (art. 24 par. 1 of the Polish Civil Code). Nevertheless, there are also legal experts who intend to recognize the voice not as a separate personal right but rather as a part of human image or as «audio-image» / «sound-image» that makes it possible to identify a person by sense of hearing. If this view is adopted, then the voice is protected not only on the basis of the Polish Civil Code but also within the framework of copyright law (art. 24 par. 3 of the Polish Civil Code). </p>
<p>The protection system of the personal rights should be deeply analysed in regard to new technologies based on the use of human voice, since new ways of using (i.e. for online legal advice) or modifying it (i.e. in order to circumvent voice recognition technologies used by banks while making payment orders) could not be protected adequately enough.</p>
<p>Under the Polish Civil Code, the conditions for legal protection of the voice as a personal right are to be viewn as a breach or threat of a breach of personal rights and unlawfulness of such breach or threat. The person who provides his or her voice may therefore demand, amongst others, that the consequences of said breach are removed and that monetary compensation is paid under this title. In this context, the controversy arises, whether – given the situation that a person voluntarily and in consent provides a voice sample – the element of unlawfulness can be demonstrated when the specific software clones the voice in an unintended manner. Accordingly, the open question is whether the means mentioned above provide sufficient protection in this respect. It appears, that nowadays new technologies use subjects of personal rights (protected by given legal methods) in pioneer ways, so that the effects of those activities require new concepts, i.e. applications editing an attorney’s voice (such as VoCo by Adobe) could be used for providing unfounded legal advice and therefore we not only deal with a breach of the personal right related to the voice but also related to the image, scientific activity, freedom of conscience or other implied legal consequences. On the other hand, VoicePass technology, constructed by the Polish University of Science and Technology in Cracow, which is able to identify our voice and allows to verify our identity i.e. in banks, insurance offices or authority bodies<a href="#_edn9" name="_ednref9">[ix]</a> is not only a great invention and simplifying various official procedures but also a potential risk of violating our personal data.</p>
<h4>Voice Cloning in the Light of Penal Liability (in the Polish Copyright Law)</h4>
<p>It has to be considered that manufacturers of computer programs which allow voice cloning will provide adequate protection in the form of tags, digital watermarks or any other forms, so that it can be showed that somebody’s voice being used in bad faith has been created by the program. But what if somebody circumvents effective technical devices applied to protect the software in order to remove digital watermarks and to use somebody’s voice unlawfully? This has to be viewed as cracking and the accountable person can be treated as cracker or hacker. <a href="http://www.wipo.int/wipolex/en/text.jsp?file_id=129377">Polish Copyright Law</a> indicates penalties in its art. 118 para. 1, stating that «anyone who produces devices or components of devices for the purpose of unauthorised removal or circumvention of effective technical devices applied to protect a work or the subject matter of related rights against replaying, copying or reproduction or trades in such devices or components of such devices, or advertises their sale or rental, is liable to a fine, restriction of personal liberty or imprisonment for up to 3 years». In turn, para. 2 of said article sets forth that «anyone who owns, stores or uses devices or components of devices as referred to in paragraph 1, is liable to a fine, restriction of personal liberty or imprisonment for up to a year».</p>
<p>First of all, the term «effective technical devices» must be clarified: it means that the introduced technical security is objectively capable of fulfilling its function and – without it being removed or bypassed – replaying, copying or reproducing are impossible.<a href="#_edn10" name="_ednref10">[x]</a> The problem arising from the wording of the quoted legal provision concerns computer programs and whether this provision also applies to computer programs striving for illegal neutralization of security. It is worth pointing out that computer programs are not devices, since, according to the Polish Languages Dictionary, a device is a mechanism or a set of mechanisms performing specific actions,<a href="#_edn11" name="_ednref11">[xi]</a> meaning that devices must be material and, apart from that, computer programs constitute intangible rights. In the literature, it is proposed that computer programs may be, at most, treated as components of devices.<a href="#_edn12" name="_ednref12">[xii]</a> This is a significant issue, since the removal or circumvention of the effective technical devices applied (in this case, a voice cloning computer program) is usually performed by special computer programs and the appropriate interpretation will decide whether art. 118 para. 1 applies in this regard.</p>
<h4>Voice Cloning Software and its Risks</h4>
<p>It seems that the main anxiety in this area is connected with the use of audio recordings as an evidence in court. Obviously, audio recording could be used as a valid evidence in the course of litigation under the Polish jurisdiction.<a href="#_edn13" name="_ednref13">[xiii]</a> Some restrictions apply to recordings acquired illegally but a general rule states that such recordings are also admitted in court if they support reaching a fair ruling.<a href="#_edn14" name="_ednref14">[xiv]</a> The software enabling the creation of statements which sound, for example, like the defendant, can cause a considerable risk for the fairness of the trial. Accordingly, one of the ideas to provide protection against fake statements generated by means of voice cloning technology is adding audio watermarks to every output of such software. Digital watermarking is the process of imperceptibly embedding watermarks into digital media as a permanent sign to assure its authenticity.<a href="#_edn15" name="_ednref15">[xv]</a></p>
<h4>Data Protection in the Light of Voice Cloning</h4>
<p>Voice cloning technology requires the obtained data to be saved, therefore it is necessary to also look at this new technology from a personal data protection point of view. In the European Union, this issue is regulated by a number of directives, i.e. the Data Protection Directive (<a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:en:PDF">95/46/EC</a>), the Telecommunications Act of 16 July 2004 (unified text of 2016, item 1489 as amended) or the Electronic Communications Data Protection Directive (<a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32002L0058:en:PDF">2002/58/EC</a>). In spite of sealing personal data protection (not only internationally but also on a national level), multiple problems occur in practice, e.g., when the data controller entrusts data to countries with insufficient data protection standards. Sufficient data protection standards shall be assessed in the light of all circumstances surrounding a data transfer operation, in particular, the nature of data, its purpose and the duration of the proposed processing operation. According to the Polish Data Protection Act of 29 August 1998 (unified text Journal of Laws of 2016, item 922), the above stated doubts arise whenever personal data is transferred to a country not belonging to the European Economic Area. However, the issue of voice filing as personal data requires a more extensive description and exceeds the scope of this paper.</p>
<h4>Voice Biometrics vs Voice Cloning</h4>
<p>Voice cloning technology differs from voice biometrics technology, since the latter is a technology used to identify people by their voices. Biometrics refers to metrics related to human characteristics. Nowadays, this technology is being used increasingly, especially in matters of security (e.g., at the airport, where one can choose the facial recognition system instead of the traditional way of checking in).</p>
<p>The human voice is as unique as fingerprints. Moreover, everyone articulates sentences in an original way: one puts emphasis differently, the rate of speech and the intonation are varying. The system records and picks out all the differences while taking into consideration details such as the size and the shape of throat, mouth cavity, nasal cavity, length and tension of vocal cords. Every recorded voice print is stored as a mathematical model. To avoid mistakes during voice recording, the commands are dictated by a speech synthesizer. The verification process consists of comparing samples of recordings to previous recordings. The said systems are currently equipped with technologies removing ambient noise, and can therefore recognize voices in most cases.</p>
<p>Companies using voiceprint checks to verify their customers are at risk of voice cloning technologies, too. It is said that biometric systems would not be tricked by this, as the inspected items differ from what humans look for when identifying people.<a href="#_edn16" name="_ednref16">[xvi]</a> The authors of the VoicePIN, a new startup from Poland, claim that their product based on voice authentication is resistant to spoofing and can detect whether the sample is original or re-played.<a href="#_edn17" name="_ednref17">[xvii]</a> If such assumption is correct, it seems reasonable that the biometric system could likewise be protected from voice cloning software. The final answer will be known only after specific tests and experiments.</p>
<p>The above remarks lead to the conclusion that voice cloning technology may cause new types of legal liability, both civil and penal, of the entities applying this technology. Consequently, voice cloning, like any other new technology, will involve the need to amend and adjust the existing legal provision. Nevertheless, these should not restrict the application of this technology in areas like providing services, e.g., legal advice and legal translation. The said changes are particularly required in the area of administrative law when defining the authority and supervisory competence of entities protecting personal data. Moreover, an important postulate would be to precisely define human voice as a specific personal interest. Furthermore, an unauthorised modification of such voice by means of computer devices should be classified as a specific type of infringement of human voice as a personal interest. Nevertheless, despite the existence of potential risks, when properly safeguarded by legal provisions, voice cloning software can indeed influence the effectiveness and cost-efficiency of legal services positively.</p>
<p> </p>
<p><a href="#_ednref1" name="_edn1">[i]</a> Aaron van den Oord / Karen Simonyan / Nal Kalchbrenner / Sander Dieleman / Oriol Vinyals / Andrew Senior / Heiga Zen / Alex Graves / Koray Kavukcuoglu, WaveNet: A Generative Model for Raw Audio, 19 September 2016, <a href="http://www.arxiv.org/pdf/1609.03499.pdf">www.arxiv.org/pdf/1609.03499.pdf</a> (all internet addresses last accessed 18 April 2017).</p>
<p><a href="#_ednref2" name="_edn2">[ii]</a> Official live presentation during the Adobe MAX 2016 Sneak Peeks, co-hosted by Jordan Peele, <a href="http://www.youtube.com/watch?v=I3l4XLZ59iw">www.youtube.com/watch?v=I3l4XLZ59iw</a>.</p>
<p><a href="#_ednref3" name="_edn3">[iii]</a> Sebastian Anthony, Adobe demos «photoshop for audio,» lets you edit speech as easily as text, arsTECHNICA, 11 July 2016, <a href="http://www.arstechnica.com/information-technology/2016/11/adobe-voco-photoshop-for-audio-speech-editing">www.arstechnica.com/information-technology/2016/11/adobe-voco-photoshop-for-audio-speech-editing</a>.</p>
<p><a href="#_ednref4" name="_edn4">[iv]</a> Janusz Barta / Ryszard Markiewicz / Andrzej Matlak, Media Law, LexisNexis, Warsaw 2005; Justyna Balcarczyk, The right to image and its commercialization, Oficyna Wolter Kluwer Business, Warsaw 2009, pp. 52–54; Justyna Balcarczyk, Voice right – outline of basis issues, Zeszyty Naukowe Uniwersytetu Jagiellońskiego 2010/2/115–126, LEX; Maksymilian Pazdan, Commentary on Article 23 of the Civil Code, in: Krzysztof Pietrzkowski (ed<em>.</em>),<em> </em>Civil Code. Commentary on Articles 1–449[10]<em>,</em> Volume 1, Legalis.</p>
<p><a href="#_ednref5" name="_edn5">[v]</a> Art. 23 of the Polish Civil Code dated on 23 April 1964, Journal of Laws No 16.94 as amended.</p>
<p><a href="#_ednref6" name="_edn6">[vi]</a> Art. 24 of the Polish Civil Code dated on 23 April 1964, Journal of Laws No 16.94 as amended.</p>
<p><a href="#_ednref7" name="_edn7">[vii]</a> Małgorzata Pyziak-Szafnicka / Paweł Księżak, Civil Code – Comment. General Part. Edition II. LEX, 2014.</p>
<p><a href="#_ednref8" name="_edn8">[viii]</a> Justyna Balcarczyk,  The right to image and its commercialization, Oficyna Wolter Kluwer Business, Warsaw 2009, pp. 52–54.</p>
<p><a href="#_ednref9" name="_edn9">[ix]</a> Polish Press Agency, You know your neighbour by his voice, 31 March 2014, <a href="http://naukawpolsce.pap.pl/aktualnosci/news,399802,poznasz-blizniego-po-glosie-jego.html">http://naukawpolsce.pap.pl/aktualnosci/news,399802,poznasz-blizniego-po-glosie-jego.html</a>.</p>
<p><a href="#_ednref10" name="_edn10">[x]</a> Zbigniew Ćwiąkalski, Commentary on Article 118(1) of the Copyright Law, in: Barta Janusz / Markiewicz Ryszard (eds.), Copyright Law. Commentary, Volume 5, LEX no. 8545, 2011.</p>
<p><a href="#_ednref11" name="_edn11">[xi]</a> Polish Language Dictionary, <a href="http://sjp.pwn.pl/sjp/urzadzenie;2533403.html">http://sjp.pwn.pl/sjp/urzadzenie;2533403.html</a>.</p>
<p><a href="#_ednref12" name="_edn12">[xii]</a> Janusz Raglewski, Commentary on Article 118(1) of the Copyright Law, in: Damian Flisak (ed.), Copyright Law. Commentary, LEX no. 9083, 2015.</p>
<p><a href="#_ednref13" name="_edn13">[xiii]</a> Article 308 §1 of <a href="http://www.wipo.int/wipolex/en/details.jsp?id=3511">Polish Code of Civil Procedure</a> of 17 November 1964, Journal of Laws 2016.1822 as amended.</p>
<p><a href="#_ednref14" name="_edn14">[xiv]</a> Resolution of the Supreme Court of 22 April 2016, ref. no. II CSK 478/15.</p>
<p><a href="#_ednref15" name="_edn15">[xv]</a> Yiqing Lin / Waleed H. Abdulla, Audio Watermark: A Comprehensive Foundation Using MATLAB, Springer, 2014, ISBN: 9783319079745.</p>
<p><a href="#_ednref16" name="_edn16">[xvi]</a> British Broadcasting Corporation, Adobe VoCo «Photoshop-for-voice» causes concern, 7 November 2016, <a href="http://www.bbc.com/news/technology-37899902">www.bbc.com/news/technology-37899902</a>.</p>
<p><a href="#_ednref17" name="_edn17">[xvii]</a> Information given by CEO on VoicePIN in the interview for Business Insider, 28 March 2017, <a href="http://www.businessinsider.com.pl/technologie/nowe-technologie/voicepin-zabezpieczenia-biometryczne-thing-big-upc/l20w4f3">www.businessinsider.com.pl/technologie/nowe-technologie/voicepin-zabezpieczenia-biometryczne-thing-big-upc/l20w4f3</a>.</p>


<p></p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/voice-cloning-as-a-global-new-technology-and-its-challenges-for-eu-and-polish-law/">Voice Cloning as a Global New Technology and its Challenges for EU and Polish Law</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/voice-cloning-as-a-global-new-technology-and-its-challenges-for-eu-and-polish-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
