<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EU Law - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/eu-law/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/eu-law/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 17:55:16 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Kiełtyka Gładkowski KG Legal has published an expert contribution in Infor, devoted to loot boxes in video games</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/kieltyka-gladkowski-kg-legal-has-published-an-expert-contribution-in-infor-devoted-to-loot-boxes-in-video-games/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/kieltyka-gladkowski-kg-legal-has-published-an-expert-contribution-in-infor-devoted-to-loot-boxes-in-video-games/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 15:45:33 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[behavioral design]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[consumer rights]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data-driven design]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[digital services]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[FinTech law]]></category>
		<category><![CDATA[gambling law]]></category>
		<category><![CDATA[game monetization]]></category>
		<category><![CDATA[gaming industry]]></category>
		<category><![CDATA[gaming law]]></category>
		<category><![CDATA[interactive entertainment]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[KIELTYKA GLADKOWSKI KG LEGAL participates in the 10th European Cybersecurity Standardization Conference - ENISA 2026]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Loot boxes]]></category>
		<category><![CDATA[microtransactions]]></category>
		<category><![CDATA[online gaming]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Regulatory Law]]></category>
		<category><![CDATA[tech law]]></category>
		<category><![CDATA[video game law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8843</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 We are pleased to share that Kiełtyka Gładkowski KG Legal has published an expert contribution in Infor, one of Poland’s leading legal and financial publications, devoted to one of the most intriguing regulatory phenomena of the digital economy: loot boxes in video games. “Loot boxes in video games: between gambling [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/kieltyka-gladkowski-kg-legal-has-published-an-expert-contribution-in-infor-devoted-to-loot-boxes-in-video-games/">Kiełtyka Gładkowski KG Legal has published an expert contribution in Infor, devoted to loot boxes in video games</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 24, 2026</mark></strong></p>



<figure class="wp-block-video"><video autoplay controls loop src="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-1.mp4"></video></figure>



<p>We are pleased to share that Kiełtyka Gładkowski KG Legal has published an expert contribution in Infor, one of Poland’s leading legal and financial publications, devoted to one of the most intriguing regulatory phenomena of the digital economy: loot boxes in video games.</p>



<span id="more-8843"></span>



<p id="ember1220"> “Loot boxes in video games: between gambling law and consumer protection – a regulatory analysis under Polish and European Union law”</p>



<p id="ember1221">The article goes far beyond the classic “are loot boxes gambling?” debate. By analysing the actual monetisation models used in modern games — particularly microtransactions involving paid acquisition of virtual packages with randomised content — we examine how these mechanisms interact with:</p>



<ul class="wp-block-list">
<li>Polish gambling law and the statutory definition of a game of chance,</li>



<li>EU consumer protection rules,</li>



<li>digital services regulation,</li>



<li>taxation and compliance considerations,</li>



<li>and emerging concerns related to behavioural design and dark patterns.</li>
</ul>



<p id="ember1223">One of the key conclusions is that the regulatory importance of loot boxes stems not only from their possible resemblance to gambling mechanisms, but also from the fact that such systems are frequently used by inexperienced consumers, including minors, who may be especially susceptible to manipulative design techniques aimed at increasing engagement and spending.</p>



<p id="ember1224">This is precisely the type of cross-sector regulatory issue in which our team has extensive experience — combining expertise in technology law, highly regulated industries, digital services, compliance, consumer protection and EU regulatory frameworks. We are proud that this experience is reflected in publications appearing in professional journals such as Infor.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-large-font-size">Read the article here: Infor – <a href="https://www.infor.pl/prawo/nowosci-prawne/7623813,lootboxy-w-grach-komputerowych-miedzy-prawem-hazardowym-a-ochrona-konsumentow-analiza-regulacyjna-na-tle-prawa-polskiego-i-unii-europejskiej.html" target="_blank" rel="noreferrer noopener">Loot boxes in video games: between gambling law and consumer protection</a></p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/kieltyka-gladkowski-kg-legal-has-published-an-expert-contribution-in-infor-devoted-to-loot-boxes-in-video-games/">Kiełtyka Gładkowski KG Legal has published an expert contribution in Infor, devoted to loot boxes in video games</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/kieltyka-gladkowski-kg-legal-has-published-an-expert-contribution-in-infor-devoted-to-loot-boxes-in-video-games/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-1.mp4" length="2524522" type="video/mp4" />

			</item>
		<item>
		<title>Summer holidays? Not for our litigation team. We are preparing a dispute before the EU General Court</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/summer-holidays-not-for-our-litigation-team-we-are-preparing-a-dispute-before-the-eu-general-court/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/summer-holidays-not-for-our-litigation-team-we-are-preparing-a-dispute-before-the-eu-general-court/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 14:43:22 +0000</pubDate>
				<category><![CDATA[CROSS BORDER CASES]]></category>
		<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[co-counsel]]></category>
		<category><![CDATA[Commercial Litigation]]></category>
		<category><![CDATA[Court of Justice of the European Union]]></category>
		<category><![CDATA[cross-border litigation]]></category>
		<category><![CDATA[Dispute Resolution]]></category>
		<category><![CDATA[EISMEA]]></category>
		<category><![CDATA[EU funding]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[foreign lawyers]]></category>
		<category><![CDATA[General Court]]></category>
		<category><![CDATA[grant agreements]]></category>
		<category><![CDATA[Horizon 2020]]></category>
		<category><![CDATA[Horizon Europe]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[International Litigation]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[legal services]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[referral network]]></category>
		<category><![CDATA[Regulatory Law]]></category>
		<category><![CDATA[research and innovation]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8832</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 The holiday season is in full swing, but our litigation team remains fully alert — and fully engaged. The best proof: ongoing preparations for proceedings before the General Court of the European Union in Luxembourg in one of the most complex categories of disputes — EU grant litigation. What is [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/summer-holidays-not-for-our-litigation-team-we-are-preparing-a-dispute-before-the-eu-general-court/">Summer holidays? Not for our litigation team. We are preparing a dispute before the EU General Court</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 24, 2026</strong></mark></p>



<p>The holiday season is in full swing, but our litigation team remains fully alert — and fully engaged. The best proof: ongoing preparations for proceedings before the General Court of the European Union in Luxembourg in one of the most complex categories of disputes — EU grant litigation.</p>



<span id="more-8832"></span>



<h2 class="wp-block-heading" id="ember53"><strong>What is the dispute about?</strong></h2>



<p id="ember54">We represent a client — a beneficiary of a grant awarded under an EU framework programme — in a dispute with the European Innovation Council and SMEs Executive Agency (EISMEA). At the heart of the dispute lies the allegation of so-called technology abandonment (departure from the technology) — the EU agency&#8217;s claim that, in the course of the project, the beneficiary departed from the technology on which the funding decision was based, which, in the Agency&#8217;s view, justifies a demand for repayment of the funds.</p>



<p id="ember55">This is one of the most difficult and most judgment-laden categories of allegations in grant disputes. The line between impermissible &#8220;abandonment&#8221; of a technology and the natural — indeed expected — evolution of a solution in a research and innovation project is fluid, and where that line is drawn determines the fate of the entire funding. Disputes of this kind require navigating simultaneously the grant agreement regime, European Union law and the technological specifics of the project.</p>



<h2 class="wp-block-heading" id="ember56">A direct action before the EU General Court</h2>



<p id="ember57">The dispute will be brought before the General Court of the European Union by way of a direct action based on the arbitration clause contained in the grant agreement (Article 272 TFEU). As part of the preparations, our attorneys-at-law have set up individual representative accounts in e-Curia — the mandatory electronic filing system of the EU courts — and stand ready to represent the client at every stage of the proceedings in Luxembourg.</p>



<h2 class="wp-block-heading" id="ember58">What does this mean for you?</h2>



<p id="ember59">If your company is implementing, or has implemented, an EU-funded project (Horizon 2020, Horizon Europe, EIC Accelerator and others) and you have received a letter from an EU institution questioning the implementation of the project, an audit notification, a debit note or a repayment demand — you are not without recourse. Decisions and demands of EU executive agencies are subject to review, and beneficiaries have real legal remedies at their disposal, including judicial proceedings before the EU General Court.</p>



<p id="ember60">Our litigation team combines experience in civil and commercial disputes with hands-on knowledge of EU law, the EU grant regime and the procedure before the EU courts.</p>



<p id="ember61">Feel free to reach out — holiday season included. We are not slowing down.</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/summer-holidays-not-for-our-litigation-team-we-are-preparing-a-dispute-before-the-eu-general-court/">Summer holidays? Not for our litigation team. We are preparing a dispute before the EU General Court</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/summer-holidays-not-for-our-litigation-team-we-are-preparing-a-dispute-before-the-eu-general-court/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations &#124; May 2026</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 11:04:24 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Advertising Law]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Central and Eastern Europe]]></category>
		<category><![CDATA[Client Alert]]></category>
		<category><![CDATA[Commercial Law]]></category>
		<category><![CDATA[Compliance Management]]></category>
		<category><![CDATA[Consumer Health]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[Corporate Compliance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross-Border Business]]></category>
		<category><![CDATA[Dietary Supplements]]></category>
		<category><![CDATA[Distributors]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[e-Sanepid]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Regulatory Law]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[Food and Nutrition Safety Act]]></category>
		<category><![CDATA[Food Business]]></category>
		<category><![CDATA[food industry]]></category>
		<category><![CDATA[Food Law]]></category>
		<category><![CDATA[Food Regulation]]></category>
		<category><![CDATA[Food Safety]]></category>
		<category><![CDATA[Food Supplements]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[GIS]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Importers]]></category>
		<category><![CDATA[In-House Counsel]]></category>
		<category><![CDATA[International Business]]></category>
		<category><![CDATA[International Lawyers]]></category>
		<category><![CDATA[international trade]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Compliance]]></category>
		<category><![CDATA[Legal Insights]]></category>
		<category><![CDATA[Legal Risk]]></category>
		<category><![CDATA[Legal Update]]></category>
		<category><![CDATA[Life Sciences]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Market Entry]]></category>
		<category><![CDATA[Nutraceuticals]]></category>
		<category><![CDATA[Online Retail]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Poland Food Law]]></category>
		<category><![CDATA[Polish Food Law]]></category>
		<category><![CDATA[Product Compliance]]></category>
		<category><![CDATA[Product Safety]]></category>
		<category><![CDATA[Regulatory Affairs]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Regulatory Law]]></category>
		<category><![CDATA[Risk Management]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8825</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The draft Act of April 13, 2026, amending the Act on Food and Nutrition Safety will enter into force six months after its publication. The new regulations primarily impact producers, importers, distributors, and sellers of dietary supplements &#8211; both in traditional and online channels. Below, we present the real changes [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/">CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations | May 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><em>The draft Act of April 13, 2026, amending the Act on Food and Nutrition Safety will enter into force six months after its publication. The new regulations primarily impact producers, importers, distributors, and sellers of dietary supplements &#8211; both in traditional and online channels. Below, we present the real changes to your business.</em></td></tr></tbody></table></figure>



<span id="more-8825"></span>



<h1 class="wp-block-heading">1. Reports only via e-Sanepid</h1>



<p>Every dietary supplement introduced to the market for the first time must be reported to the Chief Sanitary Inspector (GIS). Until now, various forms were acceptable &#8211; paper or electronic, with a handwritten or electronic signature. After the amendment comes into effect, the only acceptable method will be the e-Sanepid platform.</p>



<p>What does this mean in practice?</p>



<ul class="wp-block-list">
<li>It is necessary for each person submitting notifications to have a qualified electronic signature or a trusted profile.</li>



<li>All communication with sanitary inspection bodies &#8211; letters, decisions, and confirmations &#8211; will be handled through the platform account. The moment of notification submission will be clearly confirmed with an official receipt, eliminating disputes over the deadline.</li>



<li>Companies that have previously used paper forms or traditional correspondence must immediately switch to the new channel and ensure appropriate employee training.</li>
</ul>



<p>The change also concerns the timing of the notification obligation: the previous option to notify the Chief Sanitary Inspectorate (GIS) at the stage of intended product introduction is no longer available. The obligation now arises at the time of actual introduction to the market.</p>



<h1 class="wp-block-heading">2. Strict deadlines and automatic presumption of irregularities</h1>



<p>The amendment introduces a completely new mechanism for conducting investigations. This change has the greatest potential to surprise companies without effective internal compliance procedures.</p>



<h2 class="wp-block-heading">How does the new mechanism work?</h2>



<p>If the Chief Sanitary Inspectorate initiates an investigation and requests the entity to submit a scientific opinion, the company has exactly 14 days to submit an application to an accredited scientific unit – at the same time forwarding a copy of it to the Chief Sanitary Inspectorate.</p>



<figure class="wp-block-table"><table class="has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color has-fixed-layout"><tbody><tr><td><strong>Step</strong></td><td><strong>What&#8217;s going on</strong></td></tr><tr><td><strong>14 days</strong></td><td>Deadline for submitting an application for a scientific opinion to a scientific unit (from the date of delivery of the request by GIS)</td></tr><tr><td><strong>6 months</strong></td><td>Maximum time for a scientific unit to issue an opinion</td></tr><tr><td><strong>Up to 12 months</strong></td><td>Possible extension of the deadline by the entity if the case is complex</td></tr><tr><td><strong>Failure to meet 14 days</strong></td><td>Automatic presumption that the product is incorrectly classified and does not meet the requirements &#8211; GIS ends the proceedings to the detriment of the entity</td></tr></tbody></table></figure>



<p>The mechanism for presuming irregularities is a significant innovation. Previously, a company&#8217;s inaction during the proceedings did not automatically result in any legal consequences &#8211; the proceedings could drag on for years. Following the amendment, any failure to meet the 14-day deadline will lead to direct negative consequences, regardless of whether the product is safe.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>The ban on re-registration – an important trap</strong></td></tr><tr><td>Once the investigation is complete, the entity cannot submit a new notification for a product with the same qualitative and quantitative composition. If the company withdraws its notification during the investigation, this prohibition is indefinite. In such cases, changing the composition may be the only way to return to the market.</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">3. Advertising without reporting? A fine of nearly one million zlotys</h1>



<p>This change directly impacts brands engaging in active digital marketing. Previously, advertising or presenting a dietary supplement without prior notification to the Chief Sanitary Inspectorate (GIS) was punishable by a fine (a misdemeanor). Following the amendment, this becomes grounds for imposing an administrative fine &#8211; with new, significantly higher penalties.</p>



<h2 class="wp-block-heading">What exactly is prohibited?</h2>



<p>The amendment penalizes not only the sale of a supplement without reporting it to the Chief Sanitary Inspectorate (GIS), but also the mere advertising or presentation of it if the notification has not been effectively submitted. In other words:</p>



<ul class="wp-block-list">
<li>Sponsored post on Instagram or Facebook promoting a new supplement before notification = grounds for an administrative penalty.</li>



<li>Product page in the online store visible to the public before successful reporting to GIS = risk of infringement.</li>



<li>Promotional materials sent to wholesalers or distributors before GIS is notified = potential infringement.</li>



<li>Influencer marketing initiated before the date of effective notification = liability on the part of the entity commissioning the campaign.</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Key: What is a &#8220;successful report&#8221;?</strong></td></tr><tr><td>The notification is effectively submitted when the company receives official confirmation of receipt from the e-Sanepid platform. Simply submitting the form isn&#8217;t enough &#8211; confirmation is what counts. These dates can differ by several days or more. Every marketing campaign should be planned with this time buffer in mind.</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Prohibition on suggesting medicinal properties &#8211; wider scope</h2>



<p>The amendment expands liability for violations of advertising requirements from labeling to the entire marketing message. Previously, sanctions primarily covered incorrect packaging labeling. Following the amendment, a company is responsible for every communication channel &#8211; online advertising, point-of-sale materials, newsletters, or YouTube videos &#8211; if the message suggests that a varied diet does not provide sufficient nutrients, or if a supplement is presented as a medicinal product.</p>



<h1 class="wp-block-heading">4. Public register &#8211; the company&#8217;s reputation under public scrutiny</h1>



<p>The Chief Sanitary Inspectorate (GIS) has maintained a register of dietary supplements before, but the amendment will significantly expand its scope and availability. The data will be published on the e-Sanepid platform and will include:</p>



<ul class="wp-block-list">
<li>the name of the product and its qualitative composition (without quantitative data &#8211; the recipe remains protected),</li>



<li>product qualification proposed by the entity,</li>



<li>information about the initiation or ongoing investigation,</li>



<li>data on the detection of a prohibited ingredient.</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Reputational risk before final decision</strong></td></tr><tr><td>Information about the initiation of an investigation will appear in the public register immediately &#8211; not after the proceedings have concluded. Consumers and competitors will have access to this information before the Chief Sanitary Inspectorate issues any ruling. Even if the proceedings end favorably for the company, the registry record could impact brand perception.</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">5. Fines &#8211; increase by over 330%</h1>



<p>The maximum administrative fine for violating food safety regulations is increasing from 30 to 100 times the average monthly salary. At the current salary level, this means:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td>&nbsp;</td><td><strong>Before the amendment</strong></td><td><strong>After the amendment</strong></td></tr><tr><td><strong>Multiplier</strong></td><td>30×</td><td><strong>100×</strong></td></tr><tr><td><strong>Maximum penalty</strong></td><td>approx. PLN 245,000</td><td><strong>approx. PLN 818,000</strong></td></tr></tbody></table></figure>



<p>The new penalties are imposed administratively (not as fiscal or misdemeanor offenses), which means faster proceedings and no need to prove intentional guilt. A mere finding of a violation is sufficient. The increased level of sanctions has a real deterrent effect, especially for companies with turnover in the tens of millions of zlotys.</p>



<h1 class="wp-block-heading">The biggest risks &#8211; a practical overview</h1>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Risk area</strong></td><td><strong>Triggering situation</strong></td><td><strong>Consequence</strong></td></tr><tr><td><strong>Advertising before submission</strong></td><td>Launch of the campaign on social media before the official confirmation of receipt of the notification by the Chief Sanitary Inspectorate</td><td>Fine up to approximately PLN 818,000</td></tr><tr><td><strong>Exceeding the 14-day deadline</strong></td><td>No application submitted to the scientific unit within 14 days of the request by the Chief Sanitary Inspectorate</td><td>Automatic presumption of product irregularity; termination of proceedings to the detriment of the entity</td></tr><tr><td><strong>Errors in the product description on the website</strong></td><td>Content suggesting medicinal properties or claiming that a diet without a supplement is insufficient</td><td>Fine of up to approximately PLN 818,000; risk of product recall</td></tr><tr><td><strong>Publicity of the proceedings</strong></td><td>Initiation of explanatory proceedings by GIS</td><td>Immediate publication of information in the public register &#8211; reputational damage before resolution</td></tr><tr><td><strong>Sale without notification</strong></td><td>Distribution to wholesalers or stores before effective notification of the Chief Sanitary Inspectorate</td><td>A fine of up to approximately PLN 818,000; possible ban on further trading</td></tr><tr><td><strong>No trusted profile/signature</strong></td><td>The employees responsible for reporting do not have the required qualifications</td><td>Notification submitted ineffectively &#8211; risk of sanctions as for failure to notify</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>What is worth doing before the regulations come into force?</strong></td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>1. Register on the e-Sanepid platform</strong></td></tr><tr><td>Ensure that at least two people in your company have a qualified electronic signature or an active trusted profile. Register a company account on e-Sanepid before the law comes into effect and complete a test application. A lack of technical readiness on the date the regulations come into effect could prevent you from legally introducing new products to the market.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>2. Audit current submissions and the new product calendar</strong></td></tr><tr><td>Check that all products in your offer have successfully submitted notifications to the Chief Sanitary Inspectorate. For products planned for launch in the coming months, submit notifications well in advance of the planned sale date or marketing campaign. Take into account the waiting time for official confirmation of receipt.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>3. Implement a procedure for monitoring deadlines in explanatory proceedings</strong></td></tr><tr><td>Designate a person responsible for receiving correspondence from the e-Sanepid platform and immediately forwarding documents to legal or compliance services. The 14-day deadline for submitting a request for a scientific opinion is short—missing it automatically creates a presumption of irregularities. It&#8217;s worth identifying accredited scientific institutions now with which the company could quickly establish cooperation if proceedings are initiated.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>4. Verify all marketing materials – websites, social media, product descriptions</strong></td></tr><tr><td>Analyze the content on your website, online store, social media profiles and sales materials for:</td></tr><tr><td>suggestions for medicinal or therapeutic properties of supplements,</td></tr><tr><td>information suggesting that a normal diet does not provide adequate nutrients,</td></tr><tr><td>promoting products for which the GIS notification has not yet been successfully submitted.</td></tr><tr><td>Influencer marketing campaigns deserve special attention – messages created by third parties still place the responsibility on the company commissioning the campaign.</td></tr></tbody></table></figure>



<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>5. Monitor the GIS register and respond to information about proceedings</strong></td>
</tr>
<tr>
<td>Once the expanded SEPIS register is launched, regularly check the status of your products. If you receive information about the initiation of an investigation, act immediately. Inaction at this stage can lead to automatic assumptions of irregularities and reputational damage that will be publicly visible throughout the proceedings.</td>
</tr>
</tbody>
</table>
</figure>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/">CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations | May 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</title>
		<link>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:40:05 +0000</pubDate>
				<category><![CDATA[INVESTMENT LAW AND PROCESSES IN POLAND]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Governance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[Cyber Risk;]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8816</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of the European Parliament and of the Council.</p>



<p id="ember4587">The amendment to the KSC Act significantly expands the scope of the regulations and introduces new obligations in the field of cybersecurity management. The changes include, among other things, the implementation of risk management systems and expanded incident reporting requirements. The new regulations also strengthen the powers of supervisory authorities and significantly increase the maximum amount of financial penalties. It also introduces liability for the management staff (manager) of an entity. In practice, this requires certain entities to take steps to comply with the new regulations.</p>



<span id="more-8816"></span>



<p id="ember4588"><strong>The first experiences of entrepreneurs after the amendment came into force – practical conclusions</strong></p>



<p id="ember4589">The few months that the amended Act on the National Cybersecurity System has been in effect demonstrate that the biggest challenge for businesses is no longer the analysis of the new regulations, but their practical implementation. For many organizations, the adaptation process began with a seemingly simple task: determining whether a given entity is even subject to the new regulations. In practice, this step proves to be one of the most problematic.</p>



<p id="ember4590">Under the previous legal framework, many businesses awaited a formal administrative decision confirming their status as an essential service operator. This approach is no longer appropriate. The status of a key or important entity stems directly from the Act, and obligations arise regardless of whether the business has already been entered on the register. This means that the responsibility for properly assessing their own situation rests primarily with the business itself.</p>



<p id="ember4591">Practice also shows that many companies focus solely on the issue of being entered into the register of key and important entities. However, entry itself is not the purpose of the regulation. The greatest challenges remain the actual implementation of an information security management system, conducting a risk analysis, developing incident response procedures, and adequately documenting the actions taken. In the future, supervisory authorities will primarily assess an organization&#8217;s actual level of compliance with the Act, not merely the formal fulfillment of registration obligations.</p>



<p id="ember4592">Another significant change is the significant increase in management responsibility. Management can no longer treat cybersecurity as a matter solely within the purview of IT departments. The Act requires active management involvement in the organization of the cybersecurity management system, oversight of its operation, and provision of adequate organizational and financial resources. In practice, this requires regular reporting on cybersecurity issues at the management level and documentation of decisions made.</p>



<p id="ember4593">Supply chain security is also becoming increasingly important. Businesses are required not only to secure their own IT systems but also to consider the risks arising from collaboration with IT service providers, cloud computing operators, software vendors, and outsourcing providers. In practice, this means reviewing supplier contracts, verifying the security measures in place, and implementing appropriate provisions for incident management and crisis cooperation.</p>



<p id="ember4594">It&#8217;s also noticeable that a growing number of businesses are choosing to conduct internal compliance audits before the statutory deadlines expire. This approach allows for early identification of organizational and technical gaps, reducing the risk of subsequent violations and costly remedial actions.</p>



<p id="ember4595">In practice, the best solution is to treat the implementation of the Act&#8217;s requirements not as a one-time project, but rather as a process encompassing regular risk analysis, procedure updates, employee training, and ongoing oversight of the organization&#8217;s security. This approach not only increases compliance but also significantly reduces the risk of cybersecurity incidents.</p>



<p id="ember4596">It&#8217;s worth emphasizing that the current transition period should be used to calmly prepare organizations for the full application of the new regulations. Postponing implementation until the final months before the statutory deadlines expire can be risky, especially for large organizations where implementing information security management systems requires the involvement of multiple departments and adequate time to prepare procedures and documentation.</p>



<h2 class="wp-block-heading" id="ember4597">Change in the circle of entities to which the Act applies.</h2>



<p id="ember4598">Under the previous wording of the Act, an administrative decision was required to recognize an entity as an essential service operator (Article 5 of the Act before the amendment). Currently, the group of key and important entities is determined automatically (ex lege). The criteria for qualifying an entity as essential are found in Article 5, Section 1, and as an important entity in Article 5, Section 2 of the Act. It is possible that an entity meets the criteria for both key and important entities; such an entity is considered a key entity under Article 5, Section 4. When attempting to qualify entities, the Act also refers to EU regulations, particularly Regulation 651/2014/EU, which defines SMEs. Therefore, the primary criteria taken into account will be the number of employees and annual turnover. It is also necessary to refer to Annexes 1 and 2 of the Act, which precisely define the categories of entrepreneurs in specific sectors and subsectors.</p>



<p id="ember4599">The added Article 5a in paragraph 1 provides that key and important entities are subject to the obligations arising from the Act if they reside in the territory of the Republic of Poland or conduct their business in the territory of the Republic of Poland.</p>



<p id="ember4600">Articles 7 et seq. regulate matters related to the list of key and important entities. Before the amendment, the list contained only operators of essential services; now it includes key and important entities. Unlike the previous legal status, in which entry was made at the request of the authority responsible for cybersecurity (former wording of Article 7, paragraph 3 of the Act), entry is now made at the request of a key or important entity within six months of the occurrence of the conditions (Article 7c, paragraph 1 of the Act). Ex officio entry will generally only apply to existing operators of essential services, trust service providers, telecommunications companies, and public entities. This means that for entities meeting the conditions on the date the amendment comes into force, the deadline for submitting an application is October 3, 2026. Pursuant to the Announcement of the Minister of Digitization of April 8, 2026, regarding the schedule for submitting applications for entry in the register of key and important entities and for key or important entities to commence using the ICT system , self-registration on the list is possible from May 7, 2026, to October 3, 2026. The platform operating in the S46 system is available at <a href="https://wykaz-ksc.gov.pl/">https://wykaz-ksc.gov.pl/</a> . By April 3, 2027, key and important entities are required to commence using the ICT system specified in Art. 46 sec. 1 of the Act. This deadline begins depending on whether the entities were parties to agreements regarding the use of the ICT system referred to in Art. 46 sec. 1 of the Act concluded before April 3, 2026. For the former, the possibility of using the system was opened on April 8, 2026, and for the latter, this possibility will be available from June 12, 2026 (point 2 of the Communication of the Minister of Digital Affairs).</p>



<p id="ember4601">If an entity that meets the criteria for being considered a key or important entity fails to submit an application for entry, the authority responsible for cybersecurity may enter the entity on the list ex officio (Article 7j, paragraph 1 of the Act). Failure to comply with certain obligations related to the list (failure to timely complete missing data on the list or failure to correct data despite a request or failure to submit an application for entry) may result in the imposition of a substantial fine (Article 73, paragraph 1, point 1 and Article 73, paragraph 1a, point 1 of the Act). The catalogue of data to be included on the list has also been changed (expanded) (Article 7, paragraph 2).</p>



<p id="ember4602"><strong>In practice: </strong>The expansion of the scope of entities and the shift from administrative decision-making to automatic regulation mean that many entities may be subject to the Act without formal confirmation of this status. In practice, independent qualification analysis and continuous monitoring of compliance with statutory criteria become crucial. An incorrect assessment (or failure to comply) may result in exposure to sanctions (severe fines).</p>



<h2 class="wp-block-heading" id="ember4603">New responsibilities for cybersecurity management.</h2>



<h3 class="wp-block-heading" id="ember4604">Duties</h3>



<p id="ember4605">Chapter 3, which governs the obligations of key and important entities, has been expanded, and Chapters 3a and 3b have been added, addressing domain name registration service providers and public entities. Article 8 of the Act governs obligations related to the implementation of an information security management system. Compared to the previous legal framework, numerous obligations have been added. The responsibility of the manager of a key or important entity for the performance of its cybersecurity obligations has been introduced (Article 8c of the Act), and the manager&#8217;s responsibilities have also been defined (Articles 8d–8f of the Act).</p>



<p id="ember4606">The regulations regarding incident reporting have also changed. A key or important entity classifies a given incident as serious (after meeting the requirements of Article 2, Section 7 of the Act), then issues an early warning, reports the incident, and finally submits a final report on the handling of the serious incident to the CSIRT (a three-step reporting model instead of the previous one-step model – Article 11 of the Act).</p>



<h2 class="wp-block-heading" id="ember4607">Deadlines</h2>



<p id="ember4608">Pursuant to Article 15 of the Act, key entities must conduct a security audit of the information system used in the service provision process at least once every three years. For key entities that were not previously classified as key service operators, the first audit should be conducted within 24 months of the date the conditions are met (Article 16, point 2, therefore, for these entities, the deadline for conducting the audit is April 3, 2028).</p>



<p id="ember4609">The Act amending the KSC Act establishes a 12-month transition period during which key and important entities have time to fulfill the obligations specified in Chapter 3 of the Act (except for the obligation to conduct the first audit, which entities have 24 months to conduct). Therefore, with respect to obligations such as implementing an information security management system, risk assessment, implementing technical and organizational measures, reporting and managing incidents, and verifying personnel&#8217;s criminal records, the deadline for compliance with these regulations expires on April 3, 2027.</p>



<p id="ember4610"><strong>In practice: </strong>The imposed obligations require the implementation of an information security management system. Furthermore, the single-tier incident reporting system has been changed, replaced by a more complex three-tier system. Essential entities will be required to conduct audits. Importantly, entities that were not previously considered essential service operators will be required to conduct an audit within two years of the amendment&#8217;s entry into force. However, most of the new obligations will have to be implemented by April 3, 2027. Failure to comply with these obligations will result in the manager of the relevant entity being held liable.</p>



<h2 class="wp-block-heading" id="ember4611">Change in the amount and grounds for imposing fines.</h2>



<p id="ember4612">Until April 2, 2026, the maximum amount of the fine imposed on entities (only for the most serious violations) was PLN 1 million (former wording of Article 73, paragraph 5 in fine). Currently, the maximum amount of the fine is, as a rule, EUR 10 million (Article 73, paragraph 3 of the Act), and for the most serious violations, up to PLN 100 million (Article 73, paragraph 5 in fine of the Act).</p>



<p id="ember4613">With the imposition of a large number of obligations on key and important entities, the list of violations for which a fine may be imposed has also been expanded (Article 73 of the Act).</p>



<p id="ember4614">The new provisions on fines come into force only two years after the entry into force of the Act (i.e. from April 3, 2028).</p>



<p id="ember4615"><strong>In practice: </strong>Increasing the amount of fines disciplines key entities and important entities to take their cybersecurity obligations very seriously. It is worth emphasizing, however, that the amended regulations on fines will not enter into force until April 3, 2028.</p>



<h2 class="wp-block-heading" id="ember4616">Changes in the supervision and control of key and important entities.</h2>



<p id="ember4617">Chapter 11 of the Act, which deals with the supervision and control of key and important entities, has been significantly expanded. Some provisions remain unchanged (the requirement to apply the provisions of the Entrepreneurs&#8217; Law or the Act on Audit in Government Administration, the powers of the person conducting the audit, most of the obligations of audited entities, and provisions regarding audit protocols and post-audit recommendations).</p>



<h2 class="wp-block-heading" id="ember4618">Important changes</h2>



<p id="ember4619">The most important changes in the scope of supervision include a significant expansion of Article 53, which describes the powers of the authority responsible for cybersecurity regarding supervision and oversight of key entities. It empowers the competent authority to issue various types of administrative decisions aimed at enforcing the provisions of the Act. This article also contains a number of procedural provisions defining the nature of the proceedings. Generally, the regulations contained in this article apply only to key entities, but as stated in Article 53, paragraph 17, certain provisions also apply to inspections of important entities. Article 53, paragraph 3 states that supervision of key entities is both post-empty and preventive, while for important entities, supervision is only post-empty.</p>



<p id="ember4620">A new obligation for both key and important entities is the information obligation specified in Article 53c, which requires a key or important entity to provide certain data at the request of the authority responsible for cybersecurity.</p>



<p id="ember4621">A new institution is the ad hoc review added in Article 59c, which may be carried out only if the conditions specified in the cited Article are met.</p>



<p id="ember4622"><strong>In practice: </strong>Strengthening the powers of supervisory authorities and introducing ad hoc inspections means increased risk of inspections and the need to maintain constant readiness to demonstrate compliance with regulations. Entities should also prepare for more frequent requests for information from authorized bodies.</p>



<h2 class="wp-block-heading" id="ember4623">Minor changes</h2>



<p id="ember4624">Chapter 10 has been amended and Chapters 10a – 10c have been added, but they do not contain any standards addressed to entities and are therefore not relevant from a practical point of view.</p>



<p id="ember4625">Several changes concern Chapter 12 concerning the Government Plenipotentiary for Cybersecurity and the Cybersecurity Board, but these changes do not have any significant impact on the entities.</p>



<p id="ember4626">Article 12a has been added, addressing specific measures to ensure cybersecurity at the national level. It primarily contains provisions on recommendations from the Government Plenipotentiary for Cybersecurity (Article 67a), the procedure for designating a supplier as a high-risk supplier (Articles 67b–67f), and a safeguarding order in the event of a critical incident (Articles 67g–67i).</p>



<p id="ember4627">Minor changes also apply to the Cybersecurity Strategy of the Republic of Poland (Articles 68–72). The changes primarily concern the content and method of developing the strategy, as well as the frequency of strategy reviews (2.5 years instead of the previous 2 years).</p>



<p id="ember4628">The amendment to the Act on the National Emergency Response Plan creates the basis for the adoption of the National Emergency Response Plan (Articles 72a – 72f of the Act).</p>



<h2 class="wp-block-heading" id="ember4629">Recommended actions.</h2>



<p id="ember4630">In light of the amendments to the Commercial Companies Code, entities subject to the new regulations should take steps to ensure their operations are in compliance with the law. It is recommended that:</p>



<p id="ember4631">1)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Self-identification in order to determine whether a given entity qualifies as a key or important entity within the meaning of the Act.</p>



<p id="ember4632">2)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Implementation or update of an information security management system.</p>



<p id="ember4633">3)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Development of procedures for identifying and reporting incidents, taking into account the new procedure.</p>



<p id="ember4634">4)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring the involvement of management staff, e.g. the manager&#8217;s implementation of the obligations under Article 8d or 8e.</p>



<p id="ember4635">5)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Preparing the organization for potential supervisory activities, e.g. inspections.</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4637">ex officio entries carried out by the Minister of Digital Affairs (current key service operators, trust service providers, telecommunications companies and public entities)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4639">April 13 – May 6, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4641">self-registration in the list of key and important entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4643">May 7 – October 3, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4645">launching the possibility of using the S46 system for new entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4647">June 12, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4649">end of the deadline for starting to use the S46 system and implementing obligations (end of the adjustment period)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4651">April 3, 2027</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4653">the first ISMS audit (for key entities that were not key service operators) and the beginning of the application of the provisions on penalties</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4655">April 3, 2028</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:33:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy;]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign Investment]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Marketplace]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Online Retail]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8813</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in assessing store credibility, force businesses to consider their platforms much more broadly. It is no longer just about regulatory compliance, but also about building digital trust, which influences a store&#8217;s visibility, legal security, and customer purchasing decisions. Below, we present a practical checklist of the most important actions to implement to reduce the risk of sanctions and increase the credibility of an online store.</p>



<span id="more-8813"></span>



<h2 class="wp-block-heading" id="ember4228">Practical guidelines for online store owners</h2>



<h2 class="wp-block-heading" id="ember4229">I.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Avoiding UOKiK fines and compliance with the Omnibus Directive</h2>



<p id="ember4230">a. <strong>Implement transactional verification</strong>: You should configure your feedback system so that each review you post is technically linked to the unique order number and email address of the customer who actually completed the purchase.</p>



<p id="ember4231">b. <strong>Updating the content of the regulations</strong>: In the &#8220;Rules for publishing opinions&#8221; section, the verification procedure should be described in detail, whether all opinions (including critical ones) are published and how the average product rating is calculated.</p>



<p id="ember4232">c. <strong>Transparent labeling</strong>: Each review should have a clear status indication (e.g., &#8220;Purchase confirmed&#8221;). If a benefit is provided in exchange for reviews (e.g., a discount code), this information must be clearly and prominently displayed within the review text.</p>



<p id="ember4233">d. <strong>Lowest price mechanism</strong>: In accordance with the requirements of price transparency, each discount must display the lowest price of the product that was valid in the 30 days prior to the introduction of the discount.</p>



<p id="ember4234"><strong>Legal basis</strong>: Act of 30 May 2014 on consumer rights ( Journal of Laws of 2024, item 1796, as amended); Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ EU L 328 of 2019, No. 328, p. 7, as amended); Act of 23 August 2007 on counteracting unfair market practices ( i.e. Journal of Laws of 2023, item 845).</p>



<h2 class="wp-block-heading" id="ember4235">II.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring compliance with the Digital Services Act (DSA)</h2>



<p id="ember4236">a. <strong>Implementing a &#8220;report content&#8221; mechanism</strong>: Every review or user-generated content must have an easily accessible button to report suspected illegality or manipulation of the content.</p>



<p id="ember4237">b. <strong>Procedure for justifying decisions</strong>: In the event of deletion of an opinion or blocking of a user account, the platform is obliged to send the author a detailed justification indicating a specific violation of the regulations or legal provisions.</p>



<p id="ember4238">c. <strong>Internal Complaints Process</strong>: Users must be able to appeal moderation decisions for a period of at least 6 months from the date the platform takes action.</p>



<p id="ember4239">d. <strong>Designation of a contact point</strong>: The entrepreneur must designate an electronic contact point for supervisory authorities and users, enabling efficient communication on matters relating to digital security.</p>



<p id="ember4240"><strong>Legal basis:</strong> Regulation<strong> </strong>(EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended), in particular Articles 16, 17 and 20.</p>



<h2 class="wp-block-heading" id="ember4241">III.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reducing the risk of “algorithmic exclusion”</h2>



<p id="ember4242">a. <strong>Design Patterns (UX) Audit</strong>: Eliminate so-called dark patterns, such as asymmetric selector buttons, hard-to-close pop-ups, or mechanisms that make it difficult to unsubscribe. Supervisory algorithms treat such practices as signals of poor interface quality.</p>



<p id="ember4243">b. <strong>Data Certification for AI</strong>: Ensure structured review data is provided, allowing shopping assistants and crawlers to properly verify the “digital provenance” of the data.</p>



<p id="ember4244">c. <strong>Filtering synthetically generated content</strong>: It is worth implementing tools that monitor review language for bot-like patterns (unnatural correctness, lack of detail) to avoid indexing false enthusiasm that results in lower trust rankings.</p>



<p id="ember4245"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, p. 1, as amended) – Article 25 (prohibition of deceptive interfaces)</p>



<h2 class="wp-block-heading" id="ember4246">IV.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Proper management of data and opinions (CaaS model)</h2>



<p id="ember4247">a. <strong>Digital</strong> <strong>Audit</strong> <strong>Trail</strong>: It is recommended to store logs containing transaction metadata related to opinions for a period enabling verification of data reliability (e.g. 12-24 months).</p>



<p id="ember4248">b. <strong>Active mediation systems</strong>: Instead of deleting negative feedback, use complaint management systems that document the process of resolving customer disputes. Resolving a problem is treated by ranking systems as evidence of high-quality service.</p>



<p id="ember4249"><strong>c.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; “Know Your Business Customer” principle</strong>: When running a marketplace model, it is essential to verify the identity of sellers before allowing them to offer goods, collecting registration numbers and contact details.</p>



<p id="ember4250"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L of 2022, No. 277, p. 1, as amended) – Article 30; Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L of 2016, No. 119, p. 1, as amended).</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</title>
		<link>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/</link>
					<comments>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:20:43 +0000</pubDate>
				<category><![CDATA[CROSS BORDER CASES]]></category>
		<category><![CDATA[Administrative Law]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[Corporate Counsel;]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign direct investment]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Investigations]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8811</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass and automated identification of unfair market practices. With the Digital Services Act (DSA) and the Omnibus Directive in force, traditional control methods are giving way to algorithmic interface analysis aimed at eliminating so-called dark patterns and price manipulation. However, the use of &#8220;digital controllers&#8221; raises fundamental questions for legal science and business practice about the limits of automated decision-making processes in public administration. Although AI agents significantly improve the effectiveness of detecting violations, their legal status as a source of evidence remains the subject of heated debate. The main thesis is that while AI can be a powerful auxiliary tool for regulatory bodies, the ultimate responsibility for determining the facts and assessing the legitimate interests of a party must rest with humans, which is the foundation of a fair procedure in a state governed by the rule of law.</p>



<span id="more-8811"></span>



<h2 class="wp-block-heading" id="ember3873">Dark Patterns: Legal and Ethical Aspects of Prohibiting Manipulation in Digital Interfaces</h2>



<p id="ember3874">A key obligation of internet platform providers in light of modern regulations is to design interfaces in a transparent and ethical manner. The prohibition of manipulation, formulated, among others, in the Digital Services Act (Article 25), directly affects the structure of so-called deceptive interfaces (dark patterns). Websites and applications cannot be designed in a way that limits the recipient&#8217;s cognitive autonomy, interferes with their ability to rationally assess the situation, or forces them to make a purchasing decision that they would not have made under other circumstances.</p>



<p id="ember3875">One of the most glaring examples of such violations is the asymmetry in the contract conclusion and termination process, <strong>particularly evident in subscription models</strong>. This mechanism relies on extreme simplification of the purchase path while simultaneously mounting procedural barriers when attempting to cancel the service. Visual techniques are used here, among other things: payment activation buttons are highlighted with bright colors and a central location, while contract termination options are deliberately hidden at the bottom of the page, written in small font or masked with colors that blend with the background. Furthermore, canceling a subscription on online platforms often requires multiple selections or confirmation of the desire to cancel, despite the consumer&#8217;s prior explicit choice. Artificial intelligence algorithms, analyzing the page structure and visual hierarchy of elements, can pinpoint these disparities with mathematical precision, creating a list of violations that serves as hard evidence.</p>



<p id="ember3876">In the context of the Omnibus Directive, the obligation to disclose the lowest price 30 days before the discount has become a market standard, but its implementation is open to abuse. The practice of &#8220;empty promotions&#8221; involves artificially inflating the base price just before a planned discount or providing a false reference amount. In this area, AI agents demonstrate particular effectiveness, acting as real-time monitoring systems; they can archive the price history of each product, creating an independent database. Comparing this information with the entrepreneur&#8217;s declaration visible on the website allows for immediate detection of manipulation of the promotional algorithm.</p>



<p id="ember3877">An equally important area of control is the phenomenon of drip pricing , or hiding the real costs of a transaction until the final stage of the shopping cart. Businesses often employ a &#8220;decoy&#8221; strategy, presenting an attractive unit price, which, at the time of order finalization, is increased by mandatory, previously undisclosed costs, such as service fees, packaging costs, or payment processing fees. Pursuant to Article 12 of the Consumer Rights Act, businesses are obligated to clearly and understandably inform consumers about, among other things, the total price for the proposed service. Automated control systems are capable of conducting a full simulation of the purchasing process, from product selection to the payment gateway. Any discrepancy between the price presented in the product list and the amount required to complete the contract is reported by AI as an attempt to circumvent disclosure obligations and a direct violation of the collective interests of consumers.</p>



<p id="ember3878">According to Article 5 of the Act on Combating Unfair Market Practices, the key criterion for assessing a trader&#8217;s behavior is the impact of their actions on the recipient&#8217;s decision-making process. A <strong>market practice is considered misleading</strong> if &#8220;this action in any way causes or is likely to cause the average consumer to make a transactional decision that they would not otherwise have made&#8221;. The legislator specifies that both &#8220;spreading false information&#8221; and &#8220;spreading true information in a manner that is likely to be misleading&#8221; can constitute an infringement. In the digital environment, these manipulations most often focus on the &#8220;existence of a product, its type, or availability.&#8221; A common method of exerting unjustified pressure on consumers is the use of social proof mechanisms and an artificial sense of scarcity. This manifests itself in messages such as: &#8220;this product is now being viewed by x people,&#8221; &#8220;x items have already been purchased today,&#8221; or displaying timers indicating that &#8220;only 30 minutes left until the end of the promotion.&#8221; Particularly problematic from the perspective of trade ethics is the use of so-called false advertising. Timers – clocks counting down to the finale of a supposedly unique price opportunity. In reality, these are fake mechanisms, as after the specified deadline, the offer remains active and the product price remains unchanged or becomes even more favorable. This type of activity, a classic example of dark patterns, is designed to induce fear of missing out (FOMO) in customers and induce them to rush into a transaction. Using AI agents allows regulators to serially monitor such counters and prove their cyclical recurrence, providing direct evidence of deceptive practices.</p>



<h2 class="wp-block-heading" id="ember3879">The algorithm as a controller</h2>



<p id="ember3880">With millions of transactions taking place across the country in just a few minutes or hours, standard order verification procedures prove insufficient to effectively fulfill the statutory responsibilities of supervisory authorities. Technological advancements in the form of AI algorithms come to the rescue. These algorithms can automatically monitor numerous commercial transactions simultaneously, generating preliminary opinions that are ultimately subject to human review. Such systems not only save significant processing time but, above all, enable oversight of a much broader range of businesses and their online platforms. The AI multi-agents used in this process are virtual &#8220;consumer robots&#8221; capable of mass-auditing e-commerce websites, simulating the natural behavior of online users to detect irregularities that a human controller would be unable to detect on such a large scale.</p>



<p id="ember3881">To conduct reliable and effective inspections, Polish law already offers supervisory authorities a toolkit in the form of the &#8220;mystery shopper&#8221; institution. Traditionally, this involves a person unrelated to the inspected company or the inspecting authority making a purchase and then completing a survey regarding specific activities they observe during standard shopping. The implementation of AI technology by the Office of Competition and Consumer Protection (UOKiK) aims to entrust AI multi-agents with the role of such digital &#8220;mystery shoppers.&#8221; Their task is to interact with the website interface, add a product to the cart, and complete the entire purchasing process without disclosing that this activity is being performed by an algorithm or that it is part of an official inspection procedure. This approach allows for direct verification of whether the entrepreneur is not using prohibited manipulative practices, known as dark patterns. However, it should be emphasized that <strong>the activity of AI multi-agents is strictly regulated by legal procedures and cannot be arbitrary</strong>. The algorithm operates under the strict supervision of the President of the Office of Competition and Consumer Protection, who, pursuant to Article 105ia of the Act on Competition and Consumer Protection, must always obtain prior consent from the Court of Competition and Consumer Protection. This mechanism serves as a key safeguard against abuse of power. Furthermore, after completing the inspection, the office is obligated to immediately provide the entrepreneur with an official ID and authorization for the inspection. In the age of digital administration, this obligation can be fulfilled electronically immediately after the AI multi-agents withdraw from the sales platform.</p>



<p id="ember3882">The key legal framework for the operation of algorithms commissioned by the regulator is provided by the EU AI Act. According to its provisions, AI systems used by public authorities for control and supervisory purposes should be considered high-risk AI systems. This entails a strict requirement to design them with appropriate transparency, which allows both the controlling and the controlled entities to properly interpret the system&#8217;s results and use them fairly. In practice, this means that algorithms must be built in an &#8220;explainable&#8221; model. A business subject to allegations based on an algorithmic audit has the statutory right to request full insight into the operation of AI tools. This transparency is essential for the controlled entity to understand the basis and criteria on which the authority deemed its online platform unfair or infringing on the collective interests of consumers (Article 24). This balance between the effectiveness of digital supervision and the right to defense is the foundation of a modern rule of law in the age of algorithms.</p>



<h2 class="wp-block-heading" id="ember3883">The opinion of AI multi-agents as evidence in the case</h2>



<p id="ember3884">After completing the inspection activities on the entrepreneur&#8217;s online platform, the AI algorithm&#8217;s role evolves towards an analytical function, consisting of preparing an opinion indicating detected violations. In the context of potential proceedings against an entity employing unfair market practices, the admissibility of using such an analysis as valid evidence becomes a key issue. Pursuant to Article 7 of the Code of Administrative Procedure (hereinafter referred to as the Code of Administrative Procedure), which establishes the principle of objective truth, a public administration body is obligated to take all steps necessary to thoroughly clarify the factual circumstances. This obligation is consistent with Article 75 § 1 of the Code of Administrative Procedure, which introduces an open catalog of evidence, allowing as evidence anything that may contribute to the clarification of the case, provided it is not contrary to the law.</p>



<p id="ember3885">Under these regulations, the results of AI multi-agent work &#8211; taking the form of reports, opinions, or analyses generated after conducting an audit with court approval &#8211; fully fall within the statutory definition of evidence. However, it should be clearly stated that an AI opinion cannot be equated with an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure. This stems from the fact that an algorithm does not possess the status of a natural person equipped with specialized knowledge, which is a statutory requirement for appointing an expert. Instead, documentation generated by an AI agent should be classified as a private document or so-called &#8220;unnamed evidence.&#8221;</p>



<p id="ember3886">Practical justification for this position can be found in the case law concerning digital evidence. The judgment of the Court of Appeal in Szczecin of September 19, 2016, I ACa 364/15, LEX no. 2147337 aptly describes this issue, pointing out that evidence in a case may include official and private documents, but also means other than those listed in Articles 305-308 of the Code of Civil Procedure. Electronic evidence, currently increasingly used in civil proceedings, is not explicitly listed in the catalog of means of evidence. However, the Code of Civil Procedure does not contain a closed list of evidence sources; anything relevant to the case may constitute evidence. Although the above ruling was issued in the context of civil procedure, due to the identical approach to the openness of the evidence system, it remains fully applicable to administrative proceedings conducted by the President of the Office of Competition and Consumer Protection.</p>



<p id="ember3887">The key element of algorithmic evidence remains the human factor, which serves as a primary safeguard over the autonomous operation of technology. It&#8217;s important to note that AI multi-agents, despite their high sophistication, operate based on statistical probability models, which carries the risk of misinterpreting dynamic website elements. For example, the system may incorrectly classify a standard technical error as intentional dark web activity. patterns or misinterpret the interface&#8217;s intentions in a specific cultural or linguistic context. Therefore, opinions generated by AI agents cannot constitute a standalone and final basis for a decision, but should be subjected to thorough, critical review by an official. Only such a comparison of the &#8220;raw&#8221; algorithmic result with human knowledge and experience allows for avoiding errors that could lead to unjustified penalties. This approach is directly supported by Article 80 of the Code of Administrative Procedure, according to which a public administration body assesses whether a given circumstance has been proven based on the entirety of the evidence. In this process, the &#8220;AI opinion&#8221; is only one of many components that must be weighed against other evidence and evaluated through the prism of principles of logic and life experience, ultimately guaranteeing the implementation of the principle of objective truth and protecting the entrepreneur from the automaticity of decisions made by the algorithm.</p>



<h2 class="wp-block-heading" id="ember3888">Summary</h2>



<p id="ember3889">Multi-agent system implemented by the Office of Competition and Consumer Protection for automatic control of the e-commerce sector poses a significant challenge for entrepreneurs, forcing strict compliance with regulations regarding dark patterns, price transparency (Omnibus Directive, Art. 6a) and information obligations (Consumer Rights Act, Art. 12). These tools are used to mass detect manipulative practices such as drip pricing, fake timers or making it difficult to unsubscribe. Although AI agents perform a function similar to &#8220;mystery shoppers,&#8221; their activity must meet the rigors of Article 105ia of the Act on Competition and Consumer Protection, including the requirement to obtain court consent for a controlled purchase. What is crucial from a procedural perspective is that the findings made by the algorithm do not have the status of an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure (lack of the status of a natural person with specialist knowledge), but constitute only a private document or &#8220;other evidence&#8221; subject to the authority&#8217;s free assessment (Article 80 of the Code of Administrative Procedure).</p>



<p id="ember3890">Consequently, the official is required to subject AI reports to thorough human review to eliminate the risk of misclassification resulting from so-called &#8220;AI hallucinations&#8221; or technical errors in the interpretation of the website&#8217;s code. The entrepreneur has full rights of defense based on the principle of active participation of the party (Article 10 of the Code of Administrative Procedure) and the principle of objective truth (Article 7 of the Code of Administrative Procedure), which means the right to question the bot&#8217;s logic and to access the instructions and parameters of the AI system, in accordance with the &#8220;explainability&#8221; requirement enshrined in the AI Act (Article 13). Any decision based solely on the automated generation of conclusions, without providing the party with an opportunity to comment on the evidence (Article 81 of the Code of Administrative Procedure), constitutes a gross violation of administrative procedure and may constitute an effective basis for challenging the authority&#8217;s decision.</p>



<h2 class="wp-block-heading" id="ember3891">Sources:</h2>



<p id="ember3892">Regulation 2022/2065 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended).</p>



<p id="ember3893">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ L 328, 2019, p. 7, as amended).</p>



<p id="ember3894">Act of 30 May 2014 on consumer rights (consolidated text: Journal of Laws of 2024, item 1796, as amended).</p>



<p id="ember3895">Act of 23 August 2007 on counteracting unfair market practices (consolidated text: Journal of Laws of 2023, item 845).</p>



<p id="ember3896">Act of 16 February 2007 on competition and consumer protection (consolidated text: Journal of Laws of 2025, item 1714).</p>



<p id="ember3897">Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) Text with EEA relevance (OJ L 1689, 2024).</p>



<p id="ember3898">Act of 14 June 1960, the Code of Administrative Procedure (consolidated text: Journal of Laws of 2025, item 1691).</p>



<p id="ember3899">Judgment of the Court of Appeal in Szczecin of 19 September 2016, I ACa 364/15, LEX no. 2147337.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
