<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GDPR Compliance - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/gdpr-compliance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/gdpr-compliance/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 15:15:26 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:29:19 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic decision-making]]></category>
		<category><![CDATA[algorithmic transparency]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[automated moderation]]></category>
		<category><![CDATA[Central Eastern Europe legal services]]></category>
		<category><![CDATA[compliance by design]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[consumer reviews verification]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital platforms]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[e-commerce regulation]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[fake reviews]]></category>
		<category><![CDATA[fake reviews in e-commerce]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[international legal cooperation]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[marketplace regulation]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[online consumer protection]]></category>
		<category><![CDATA[online marketplaces]]></category>
		<category><![CDATA[online reputation management]]></category>
		<category><![CDATA[platform liability]]></category>
		<category><![CDATA[Poland technology law]]></category>
		<category><![CDATA[Polish e-commerce law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[review authenticity]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[unfair commercial practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8830</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 10, 2026</mark></strong></p>



<p>The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer experience, misleads the recipient, directly influencing their decision-making process. Legally, a fake review is considered not only a completely false message, but also one that, by omitting important facts or manipulating context, creates a false impression of the quality of a product or the reliability of a seller. This practice is classified as unfair commercial activity if its nature causes or is likely to cause the average consumer to make a transactional decision they would not otherwise make, thus violating the fundamental principles of fair dealing.</p>



<span id="more-8830"></span>



<p>The typology of activities considered unfair rests on several fundamental pillars, the most blatant of which is direct fabrication. This involves posting or commissioning the creation of false recommendations from specialized external entities, such as marketing agencies, which directly violates regulations on combating unfair market practices. Another mechanism is selective manipulation, in which a business intentionally manages the visibility of reviews by removing, concealing, or delaying the publication of negative reviews while favoring positive ones. Such action distorts the image of actual customer satisfaction and is considered misleading regarding the essential characteristics of a product or service. An equally significant aspect is feigned verification, i.e., declaring that reviews come from real buyers without implementing proportionate and reasonable steps to verify their authenticity, which constitutes a direct violation of the disclosure obligations imposed by the Omnibus Directive.</p>



<p>Contemporary market practices have also evolved more subtle forms of manipulation, such as astroturfing, which involves creating artificial social support through employees or store owners posing as independent consumers. These activities often involve the manipulation of user profiles, where images generated by artificial intelligence algorithms are used to authenticate fictitious accounts, creating false social proof. Each of these practices, regardless of their technological sophistication, is subject to strict scrutiny by competition and consumer protection authorities.</p>



<p><strong>The role of the President of the Office of Competition and Consumer Protection and the responsibility of management boards</strong></p>



<p>The President of the Polish Office of Competition and Consumer Protection (UOKiK) serves as a central regulator in the legal system, endowed with rigorous powers to counteract violations of collective consumer interests. The main disciplinary instrument at the authority&#8217;s disposal is an administrative fine, which can be imposed in the amount of 10% of the turnover achieved by the entrepreneur in the financial year preceding the year of issuance of the decision. The amount of the fine is not determined arbitrarily, but rather results from precisely defined criteria, which include, above all, the scale of the violation, its duration, and the degree of intentionality of the perpetrator. Importantly, this fine is intended to serve not only a repressive function but, above all, a preventive and deterrent one, discouraging other market participants from engaging in similar unfair practices involving the manipulation of reviews or misleading as to the authenticity of reviews.</p>



<p>The enforcement procedure in consumer matters is designed to ensure high effectiveness of supervisory activities. A business subject to a sanction is obligated to settle the fine within 14 days of the decision becoming final, which directly contributes to the state budget. A crucial procedural element is the prejudicial nature of the decisions of the President of the Office of Competition and Consumer Protection (UOKiK), which means that the authority&#8217;s findings regarding violations of the law are binding on common courts in compensation cases brought by injured customers. This legal structure significantly facilitates consumers in pursuing civil claims, as they do not have to prove the illegality of the store&#8217;s actions, focusing solely on demonstrating the damage suffered. The office&#8217;s activity in recent years, reflected in numerous proceedings against e-commerce leaders, confirms that protecting the transparency of reviews has become a regulatory priority, translating into real and severe financial consequences for violators.</p>



<p>The contemporary model of liability in consumer protection law departs from a concept focused solely on the business entity, shifting the burden of sanctions also to individuals who actually manage the enterprise. The President of the Office of Competition and Consumer Protection (UOKiK) has the authority to impose a personal fine of up to PLN 2,000,000 on a manager. This liability is triggered by demonstrating that the manager has intentionally allowed – through their actions or conscious omissions – the company to violate collective consumer interests. In case law, the degree of management involvement in decision-making processes regarding marketing and communications is crucial. This liability may therefore affect a management board member who approves a budget for obtaining reviews from external opinion farms or ignores the lack of implementation of verification procedures under the Omnibus Directive, despite being aware of such deficiencies.</p>



<p>It should be emphasized that the responsibility of managers is autonomous and independent of any penalty imposed directly on the entrepreneur. This is intended to provide a strong incentive for management to build internal compliance structures and actively oversee the entity&#8217;s operational ethics. In the era of digitalization of trade, where algorithms and automation of marketing processes can generate violations on a massive scale, the personal financial risk of managers is intended to compel prioritizing compliance as the foundation of business strategy. Therefore, the systemic fight against false reviews is implemented not only through sanctions against corporate structures but also by disciplining those who actually shape companies&#8217; market policies. This, according to the legislature, is intended to ensure long-term improvement in integrity standards in electronic trading.</p>



<p><strong>The Omnibus Directive and the blacklist of market practices</strong></p>



<p>The implementation of the Omnibus Directive into the Polish legal system significantly redefined transparency standards in e-commerce, introducing mechanisms that directly address the systemic manipulation of consumer reviews. A key instrument in this regard is the so-called blacklist of market practices, which constitutes a catalog of behaviors considered unfair in all circumstances, eliminating the need for supervisory authorities to conduct a case-by-case analysis of the consequences of a given action. Classifying these market torts as unfair practices aims to eliminate evidentiary difficulties, as their mere existence exaggerates the entrepreneur&#8217;s wrongdoing. This legal framework not only strengthens the consumer&#8217;s position but, above all, simplifies the evidentiary process, making the fight against e-commerce abuse more effective and predictable for market participants. The foundation of the new regulations is an absolute prohibition on manipulating the verification and authenticity of product recommendations, which imposes an active obligation on sellers to implement procedures to verify the origin of reviews.</p>



<p>Under the current wording of the regulations, it is considered an unfair market practice for a trader to claim that product reviews were posted by consumers who actually used or purchased the product, in situations where reasonable and proportionate steps were not taken to verify their authenticity. This practice violates the consumer&#8217;s right to reliable information, which is essential for making an informed decision about purchasing the product, and violating it constitutes conduct contrary to good practice. The law prohibits not only posting completely false reviews, but also commissioning third parties to create them, or transferring recommendations between products with different parameters, which is referred to as review hijacking. Other offenses listed in the catalog are treated equally severely, such as using false quality certificates without appropriate authorization or using surreptitious advertising, which involves using editorial content to promote a product without clearly identifying the paid nature of the communication. Aggressive techniques are also considered particularly burdensome, including mass spamming and forced selling, which involves demanding payment for products delivered to the consumer without their prior order.</p>



<p>The blacklist also eliminates techniques <strong>such as bait advertising and direct persuasion of children to purchase</strong>, which aims to protect the integrity of the consumer decision-making process from manipulation. This protection of minors stems from their particular vulnerability to advertising messages and their inability to critically assess the persuasive nature of commercial offers. Expanding the list to include a ban on posting or commissioning another person to post false reviews for the purpose of promoting products significantly complements the system, preventing brands from using agencies that fabricate social evidence. It is emphasized that any form of distortion of the actual image of a product&#8217;s popularity constitutes a violation of the collective interests of consumers, which entitles the President of the Office of Competition and Consumer Protection (UOKiK) to intervene under public law as soon as a threat to the interests of all market users arises.</p>



<p>A particularly significant and painful consequence of these unfair techniques for entrepreneurs is a specific civil law sanction in the form of an extended right of withdrawal from the contract. If an e-store engages in practices listed in the prohibited catalog or fails to comply with information obligations regarding review verification, the statutory return period granted to the buyers is extended from 14 days to a full 12 months. This mechanism is a direct consequence of the assumption that, in the absence of reliable information, the consumer could not have expressed a fully informed intention to purchase, which suspends the running of standard mandatory deadlines. Systematic combating of review fraud and the use of black market practices is therefore becoming not only a matter of business ethics but the foundation of legal security and stability for every entity operating in the e-commerce sector. Neglect in transparency can lead to mass claims for refunds, posing a real threat to the operational liquidity of the company.</p>



<p><strong>Manipulation Architecture and Platform Obligations under the Digital Services Act (DSA)</strong></p>



<p>The phenomenon known as dark patterns constitutes a sophisticated form of interference in the user&#8217;s decision-making process, based on the deliberate use of interface architecture to distort their autonomy of will. Manipulative design patterns are not merely a manifestation of aggressive marketing, but a systematic designer&#8217;s action aimed at inducing a specific cognitive bias in the consumer, which ultimately leads to a purchase decision they would not have made in conditions of full transparency. The psychological foundation of these actions is the use of heuristics, i.e., simplified rules of reasoning and automatic thinking, which in the fast-paced environment of e-commerce transactions make the user susceptible to subliminal suggestions. This phenomenon has evolved from simple forms of persuasion to advanced interface manipulation, where the line between inducement and fraud is deliberately blurred to maximize conversion at the expense of the interests of the weaker party in the legal relationship.</p>



<p>A particularly significant area of application of these practices is the system for <strong>presenting reviews and suggesting their authenticity</strong>, where manipulation takes the form of so-called interface interference. Businesses often employ patterns involving selective content display, which in practice means deliberately hiding negative reviews on subsequent pages of the website while simultaneously highlighting only enthusiastic reviews on the product&#8217;s home page. This practice violates the model of the average consumer, who has the right to expect that the image presented of a product&#8217;s popularity and quality is reliable and has not been subjected to arbitrary filtering. Manipulation in the sphere of social evidence also includes fabricating popularity indicators, such as false messages about the number of people viewing a given product at a given time or false offer duration counters, which create an artificial sense of scarcity in the user and pressure them to immediately close the transaction. Under the Polish Act on Combating Unfair Market Practices, these activities may be classified as misleading because they distort the actual market conditions, preventing a rational comparison of offers.</p>



<p>Another dimension of manipulation is the technique known as confirmation shaming, which in the sphere of opinion writing involves the use of evaluative and emotional language to coerce users into specific behaviors, for example, through unsubscribe buttons suggesting a lack of consumer awareness. These practices are closely related to the &#8220;<strong>roach motel model</strong>”, where the process of issuing a favorable review is simplified to the maximum extent, while editing, reporting an error, or deleting content requires navigating a complex subpage structure, which is intended to discourage users from correcting false information. In the legal context, such procedural barriers are considered burdensome impediments that violate good practice and the principle of commercial fairness. An analysis of case law and the positions of supervisory authorities indicates that an interface that deliberately hinders users from exercising their rights or changing their minds loses its neutrality and becomes a tool for harming consumer interests.</p>



<p>A fundamental change in the regulatory sphere was brought about by the entry into force of the <strong>EU Digital Services Act (DSA), which, in Article 25, explicitly prohibits online platform providers from designing, organizing, and operating interfaces in a way that misleads or manipulates service users</strong>. This regulation is overarching and complements the existing consumer protection framework by introducing a direct obligation to maintain neutrality in choice architecture and prohibiting structures that significantly impede users&#8217; ability to make free and informed decisions. Violation of this prohibition entails not only civil law risks but also severe administrative sanctions, which can amount to a significant percentage of the business&#8217;s global turnover.</p>



<p>In the sphere of law enforcement, the key role is played by the model design of the average consumer, who is observant and cautious but lacks specialized knowledge of the psychological mechanisms used in interface design. This protection is preventative and abstract in nature, meaning the President of the Office of Competition and Consumer Protection (UOKiK) can intervene in situations where the mere existence of a manipulative pattern poses a real risk of distorting market behavior, without having to wait for measurable financial damage to a specific individual. Effectively combating dark patterns requires businesses not only to comply with the law but, above all, to shift to a design model focused on reliability, where all product information, including opinions, is presented free from coercive mechanisms. Ultimately, interface transparency is becoming a prerequisite for maintaining trust in the digital economy, and the use of sophisticated forms of manipulation is perceived as highly harmful to society, subject to strict assessment in light of the principles of social coexistence.</p>



<p><strong>New obligations for marketplaces regarding moderation and transparency</strong></p>



<p>The entry into force of Regulation 2022/2065, known as the Digital Services Act (DSA), represents a fundamental shift in the liability paradigm for intermediary service providers, particularly marketplaces. This regulation shifts the emphasis from passive content hosting to active oversight of the transparency and security of the digital system, introducing rigorous operational standards aimed at eliminating illegal content while respecting users&#8217; fundamental rights. A key pillar of this reform is the formalization of moderation processes, which until now were often subject to arbitrary internal platform decisions and are now subject to strict procedural rigors contained in the notice-and-action mechanism. Under the DSA, each platform is required to provide easily accessible and user-friendly tools for identifying potentially illegal content, including fake reviews or infringing offers. The mere receipt of a report obliges the provider to promptly and objectively address it.</p>



<p>The evolution of moderation obligations is inextricably linked to the <strong>requirement for transparency in decisions</strong>, which is achieved through the justification mechanism provided for in the EU regulation. When a marketplace decides to remove content, limit its visibility, or suspend a user&#8217;s account, the user is absolutely obligated to provide clear and specific reasons for such action, which is intended to prevent abuse by blocking reliable reviews that are unfavorable to the seller. This system is complemented by a<strong> mandatory internal complaint handling system</strong>, which allows users to appeal moderation decisions free of charge within a period of at least six months. <strong>This constitutes an important procedural guarantee and allows for the correction of potential algorithmic errors</strong>. It is indicated that such a legal framework is necessary to counteract the fragmentation of consumer protection, which previously relied primarily on general national clauses that were unsuitable for the scale of operations of global digital entities.</p>



<p>A significant innovation introduced specifically for trading platforms is the &#8220;Know Your Business Customer&#8221; (KYBC) principle, regulated in the chapter on marketplace transparency. These entities are charged with collecting and verifying information about traders offering their products through their interfaces, including registration data, payment account numbers, and declarations of commitment to offer goods in compliance with EU law. This mechanism aims to eliminate the phenomenon of anonymous sellers, who often promote defective products using fabricated reviews and, after raising capital, disappear from the market, avoiding legal liability. The platform is obligated to suspend services for sellers who fail to submit the required documents, making the marketplace an active guardian of the legality of trade, rather than merely a passive intermediary in trade.</p>



<p>The scope of transparency obligations extends beyond relationships with individual users to include public reporting through the periodic publication of transparency reports. These documents must include detailed data on the number of orders received from national authorities, statistics on content moderation initiated by the platform itself, and information on the use of automated tools in verification processes. For very large online platforms, these rigors are even stricter, including the obligation to conduct annual audits and systemic risk assessments, including analysis of the interface&#8217;s vulnerability to manipulation that could negatively impact public safety or consumer protection. The systemic fight against disinformation and unfair market practices is therefore anchored in the full transparency of operational processes, which allows supervisory authorities to continuously monitor the effectiveness of implemented security measures.</p>



<p>Supervision of compliance with these obligations is based on a new institutional architecture, in which national digital services coordinators, working closely with the European Commission, play a central role. The enforcement system for the adopted regulations is based on fines of up to 6% of a provider&#8217;s global turnover, which compels compliance with specific cybersecurity standards. This control system is designed to ensure that marketplaces not only implement the required procedures but also apply them reliably and uniformly across the European Union, which is crucial for building consumer confidence in cross-border trade. The introduction of these standards ends the phase of full regulatory freedom for platforms, imposing on them real responsibility for shaping the environment in which the modern exchange of goods and services takes place.</p>



<h2 class="wp-block-heading"><strong>Technological verification mechanisms and modern operating models</strong></h2>



<p><strong>Authenticity Suggestion and Pressure Mechanisms</strong></p>



<p>The evolution of digital market oversight has led to the development of mechanisms in which traditional legal instruments are increasingly being replaced by algorithmic jurisdictions based on advanced artificial intelligence systems. The phenomenon known as AI exclusion is a modern form of sanction that, for e-commerce entities, can prove more severe than traditional financial penalties imposed by administrative bodies. The foundation of this process is the integration of data on the credibility of reviews directly with positioning parameters in ranking systems, which means that transparency is no longer merely an ethical obligation but a condition for the technical visibility of an offer. Recommendation algorithms operating within platforms such as Google and Amazon constantly analyze behavioral and linguistic patterns to identify anomalies suggesting manipulation of social evidence. These systems are currently capable of recognizing the structure of texts generated by LLM language models, which are characterized by a specific repetition of phrases and a lack of emotional details typical of authentic consumer experiences. An additional risk factor subject to automatic verification is the so-called review growth rate, where a sudden jump in the number of positive ratings without correlation with actual website traffic or sales volume is interpreted by AI as a warning signal initiating restrictive procedures.</p>



<p>The consequences of an online store being classified by AI systems as posing a high risk of manipulation are immediate and often irreversible in the short term. This mechanism, known in market practice as <strong>shadow banning or de-indexing</strong>, leads to a drastic decline in visibility in search results and the blocking of offers in advertising systems, effectively cutting the entrepreneur off from key customer acquisition channels. Under the provisions of the Digital Services Act, providers of very large online platforms are required to maintain particular transparency regarding the parameters used in recommendation systems. Article 27 of the aforementioned regulation requires platforms to clearly define in their regulations the key parameters determining information ranking, which aims to limit <strong>algorithmic arbitrage</strong> and enable entrepreneurs to understand the reasons for a potential decline in their market exposure. It is worth noting that modern risk assessment systems may be classified as high-risk systems within the meaning of the Artificial Intelligence Regulation, which imposes strict requirements on their creators regarding human oversight and the prevention of <strong>algorithmic discrimination</strong>.</p>



<p>In parallel to restrictive systems, a paradigm known as agentic commerce is developing, in which purchasing processes are carried out by autonomous AI assistants acting directly on behalf of the consumer. In this model, traditional product reviews cease to serve as persuasive texts for humans and become raw input data for machines that filter the market in search of offers with the highest level of verified trust. A key element of this new commerce architecture is the so-called trust layer, built on protocols such as the Universal Commerce Protocol promoted by Google or the Agentic Commerce Protocol developed by OpenAI. These systems are guided not only by price or availability of goods but above all by the certified credibility of the seller&#8217;s data, automatically rejecting offers from entities that lack a clear digital traceability of their recommendations. The collaboration of AI assistants with secure payment systems, such as the Agent Payments Protocol, creates a closed ecosystem in which offers at risk of manipulation are excluded at the initial algorithmic selection stage, before they are even presented to the user.</p>



<p>In the era of agent-based commerce, the role of modern shopping assistants is becoming dominant, forcing businesses to redefine their credibility-building strategies. The Context Protocol model and other open-source solutions enable the exchange of context between various AI models and commerce systems, allowing information about unfair practices by a single store to be instantly shared across the entire assistant network. The doctrine suggests that this systematic approach to eliminating abuse is a natural response to the technological ease of fabricating content online. For an e-commerce store, losing its trustworthy status in the eyes of Google or OpenAI algorithms means the modern equivalent of server shutdown, as AI assistants, protecting the interests of their users, will systematically bypass offers that generate manipulative signals. Thus, the fight for authenticity is no longer a mere compliance issue but an existential foundation in the new, automated e-commerce environment, where barriers to entry into the trust layer are becoming increasingly difficult for entities employing pressure mechanisms and suggesting false authenticity.</p>



<p><strong>Compliance as a Service and the Digital Feedback Path</strong></p>



<p>The rapid evolution of the e-commerce market and the increasing professionalization of unfair market practices have forced entrepreneurs to abandon a reactive reputation management model in favor of proactively building a digital immune system. The scale of the challenge facing modern e-commerce is illustrated by analyses of the systematic erosion of trust in the digital sector, pointing to the prevalence of fake reviews and consumer concerns about the mass implementation of generative artificial intelligence for opinion fabrication. This state of affairs creates decision paralysis, where an overabundance of unreliable information, instead of supporting the purchasing process, becomes an insurmountable barrier.</p>



<p>The economic impact of the lack of reliable content verification is directly measurable and translates into tangible operational losses for businesses. The literature emphasizes that exposure to manipulated reviews drastically reduces purchase intentions and brand trust, generating measurable financial losses. The information vacuum filled with false enthusiasm also leads to a phenomenon known as post-purchase dissonance, in which a product that fails to meet expectations is returned to the seller as a complaint or contract withdrawal. Consequently, the lack of investment in transparent review processes generates hidden logistical and operational costs that, in the long run, may outweigh the gains achieved through the temporary increase in conversions driven by manipulation.</p>



<p>In response to increasing regulatory rigor, including the Omnibus Directive, the Digital Services Act (DSA), and the AI Act framework, an operational model known as <strong>Compliance as a Service (CaaS)</strong> has emerged in market practice. It involves fully outsourcing compliance processes to specialized technology providers who take over the burden of monitoring and verifying content in accordance with current regulations. CaaS allows for the automation of data oversight, which is essential in an environment where the volume of incoming reviews precludes manual oversight without risking accusations of disproportionality. In this approach, compliance ceases to be merely an administrative cost and becomes a component of a strategy for building brand value by guaranteeing the authenticity of every customer touchpoint.</p>



<p>The foundation of the Compliance as a Service model is the maintenance of clean data and the generation of an indisputable digital trace of the review&#8217;s provenance. Every published review should be accompanied by a log containing metadata regarding the specific transaction, a unique order number, and delivery status, creating auditable proof of authenticity that can be presented during inspections by supervisory authorities such as the President of the Office of Competition and Consumer Protection. This digital reconstruction of the review process provides the most effective legal shield for businesses, eliminating the risk of allegations of unfair market practices. In the era of algorithmic jurisdiction, where ranking systems favor content supported by digital evidence, having a certified trace of data provenance is becoming a prerequisite for maintaining the market visibility of an offer.</p>



<p>Parallel to technical verification, modern review management systems integrate mediation mechanisms that allow for the amicable resolution of disputes before they are publicly expressed. Market experience suggests that implementing structured review processes allows for the amicable resolution of a significant portion of consumer disputes, effectively preventing the publication of negative reviews resulting from logistical errors. This approach aligns with the principles of reliability and good market practices, building customer relationships based on dialogue rather than solely on the one-way transmission of ratings.</p>



<p>Transaction verification is now becoming the market standard, replacing open, abuse-prone review sections with a system of unique invitations sent only after a purchase is completed. The literature emphasizes that restricting the review process to those who actually purchased the product is the simplest and most effective way to comply with the obligations imposed by the Omnibus Directive. This not only minimizes the risk of severe financial penalties, but above all, provides AI shopping assistants with reliable input data, which, in the new agent-based commerce paradigm, will determine the viability of each entity in the e-commerce ecosystem.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 10:31:49 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Lawyer Europe]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[CADA]]></category>
		<category><![CDATA[Cloud and AI Development Act]]></category>
		<category><![CDATA[Cloud Compliance]]></category>
		<category><![CDATA[Cloud Computing Law]]></category>
		<category><![CDATA[Cloud Computing Lawyer]]></category>
		<category><![CDATA[Cross-Border Legal Services]]></category>
		<category><![CDATA[Cybersecurity Law]]></category>
		<category><![CDATA[Data Act]]></category>
		<category><![CDATA[Data Governance Act]]></category>
		<category><![CDATA[Data Protection Law]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Sovereignty]]></category>
		<category><![CDATA[EU Cloud Regulation]]></category>
		<category><![CDATA[EU Regulatory Law]]></category>
		<category><![CDATA[EU Technology Law]]></category>
		<category><![CDATA[European Tech Regulation]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[Kiełtyka Gładkowski KG Legal]]></category>
		<category><![CDATA[public procurement law]]></category>
		<category><![CDATA[Sovereign Cloud]]></category>
		<category><![CDATA[Technology Law Firm]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8827</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 I. Introduction On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 10, 2026</strong></mark></p>



<h2 class="wp-block-heading">I. Introduction</h2>



<p>On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards governing public procurement, the certification of cloud computing providers, and artificial intelligence infrastructure.</p>



<span id="more-8827"></span>



<p>CADA focuses on 3 goals:</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 1 &#8211; Research and Innovation: Support for next-generation technologies, frontier, industrial and physical AI; introduction of &#8220;grand challenges&#8221;; implementation of Experience and Acceleration Centres for AI.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 2 &#8211; Capacity: target to triple EU data centre capacity within 5-7 years; simplify and speed up construction permitting.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 3 &#8211; autonomy (core of regulation): a single EU framework for assessing cloud and AI sovereignty, a public sector adoption mechanism; an open source-first principle; and a common public procurement framework.</p>



<p>CADA fits into the broader EU digital policy framework, which includes the AI Act, Data Act, Data Governance Act, Digital Markets Act (DMA) and Digital Services Act (DSA), as well as soft law initiatives such as Gaia-X and the 2020 European Data Strategy. CADA takes a coordinated “ecosystem approach” as it combines supply-side actions to strengthen national capabilities, demand-side actions to drive deployment, and enablers for innovation and investment in cloud computing and AI.</p>



<p>“This initiative will connect networks, cloud, artificial intelligence, and software into cohesive ecosystems to address the following:</p>



<p>(1) future challenges related to energy-efficient computing infrastructure;</p>



<p>(2) autonomy across the entire cloud stack;</p>



<p>(3) advanced EU capabilities in advanced AI technologies, such as frontier AI, physical AI and industrial AI;</p>



<p>(4) implementing cloud and artificial intelligence in the public and private sectors.”</p>



<h1 class="wp-block-heading">II. The concept of digital sovereignty and the &#8220;sovereign cloud&#8221; in EU documents</h1>



<h2 class="wp-block-heading">1. Origin of the concept</h2>



<p>The concept of digital sovereignty (technological sovereignty) entered the vocabulary of the European Commission and the Council of the EU around 2020-2021 as a reaction to three phenomena: (1) the ongoing consolidation of the global cloud market in the hands of hyperscalers from the United States. à&#8221;The current situation in the cloud computing and artificial intelligence sector is characterized by a clear dependence on a limited group of third-country providers. Although the EU cloud computing market is growing significantly, the share of EU providers fell from 29% in 2017 to 15% in 2022 and has remained unchanged since then. Currently, three non-EU cloud computing providers control over 70% of the European cloud computing market&#8230; This dependency also exposes European users to the risk of disruptions, especially in situations where unilateral decisions by third-country entities could disrupt service provision.”</p>



<p>(2) legal risks related to the extraterritorial application of the US CLOUD Act of 2018, which allows US authorities to access data stored by US-based companies regardless of the location of the servers, and</p>



<p>(3) the CJEU judgments in Schrems I (2015) and Schrems II (2020), questioning the legal basis for transatlantic transfers of personal data. The Court of Justice of the EU (CJEU) invalidated the <em>Privacy Shield Agreement</em>, finding that US regulations did not guarantee EU citizens adequate protection of their personal data against surveillance. This forced the processing of sensitive data in Europe.</p>



<p>The Gaia-X initiative, launched in 2019 by Germany and France, was the first attempt to operationalize cloud sovereignty. The project&#8217;s main goals are:</p>



<ul class="wp-block-list">
<li>reducing Europe&#8217;s dependence on American and Chinese cloud providers (such as AWS, Google Cloud, Azure, Alibaba)</li>



<li>Gaia-X does not build its own cloud, but creates rules, standards and trust mechanisms that allow different providers (small and large) to offer interoperable, compatible services.</li>



<li>companies and institutions must maintain control over where and how their data is stored and processed, in accordance with European regulations (e.g. GDPR)</li>



<li>common certification rules, trust labels (&#8220;Gaia-X Trust Framework&#8221;) and open API</li>
</ul>



<p>However, the project was criticized for its slow pace and the influence of large American technology companies, which raised doubts about the sovereign nature of the undertaking.</p>



<h2 class="wp-block-heading">&nbsp;</h2>



<h2 class="wp-block-heading">2. Components of digital sovereignty according to the CADA project</h2>



<p>The CADA project does not have a single, closed dictionary definition of &#8220;cloud/digital sovereignty.&#8221; Instead, the project develops the concept through a system of levels and assessment criteria.</p>



<p><strong>Recital 51 of the Preamble</strong><strong>à</strong><strong> </strong>&#8220;it is necessary to establish a Union cloud computing sovereignty framework determining criteria for trusted cloud computing services. To cater for the <strong>nuanced and layered nature of sovereignty</strong>, the framework should provide for four different levels of trusted offers (&#8216;Union assurance levels&#8217;).&#8221;</p>



<p><strong>Recital 50 of the Preamble</strong><strong>à</strong><strong> </strong>“The Union and Member States being critically dependent on a limited number of cloud computing service providers subject to the control of a third country or a legal entity established in a third-country may lead to risks such as misuse (ie manipulation, remote access and control, sabotage, weaponization), access to information (ie access to sensitive information, unauthorized communication, technology leakage, data manipulation or exfiltration, espionage) and dependency vulnerabilities (ie political and/or economic coercion, for example by using vendor or technology lock-ins, embargos or sanctions, monopoly pricing damaging the financial interest of the Union and Member States).” – risks to sovereignty</p>



<p><strong>Article 16</strong><strong>à</strong><strong> </strong>&#8220;This Chapter establishes a Union cloud computing sovereignty framework comprising four Union assurance levels, the criteria for which are set out in Annex II, that cloud computing service providers shall meet in order to provide their cloud computing services to Union entities and public sector bodies&#8221;</p>



<p><strong>Annex II</strong><strong>à</strong><strong> </strong>contains four cumulative sets of technical, legal and organisational criteria. &#8220;Software&#8221; within the meaning of the Annex includes Regulation 2024/2847 (Cyber Resilience Act). CADA in Annex II defines sovereignty in the field of cloud computing and artificial intelligence, comprising four levels of guarantees that public sector bodies will benefit from based on their risk assessments. Cloud service providers can be recognised by Member States under this framework after passing an audit. The Commission retains the competence to issue implementing acts identifying third countries whose providers would be subject to audits under the above system.</p>



<p>Level 1 (Basic) &#8211; &nbsp;pt. 1</p>



<p>The lowest threshold, covering all public sector services:</p>



<ul class="wp-block-list">
<li>supplier&#8217;s registered office in the EU; infrastructure and assets in the EU (unless the customer expressly agrees otherwise);</li>



<li>customer data (including metadata, telemetry) remains exclusively within the EU, unless a public authority decides otherwise;</li>



<li>when outsourcing technical support outside the EU, the requirement of traceability and safeguards that do not undermine operational autonomy;</li>



<li>compliance with current cybersecurity standards;</li>



<li>full transparency regarding subcontractors;</li>



<li>if the supplier is controlled by an entity from a third country – a guarantee of no obligation to report security vulnerabilities to the authorities of that country before their disclosure.</li>
</ul>



<p>Level 2 (Standard) &#8211; point 2</p>



<p>It requires an audit (not just a declaration) and adds:</p>



<ul class="wp-block-list">
<li>mandatory location of infrastructure, assets and personnel in the EU;</li>



<li>the possibility of requesting EU citizenship of staff (at the client&#8217;s request);</li>



<li>cybersecurity certificate of at least &#8220;substantial&#8221; level (EUCS or national equivalent);</li>



<li>prohibition on using customer data to train AI models operated by a third-country entity;</li>



<li>if the supplier is subject to third-country control – requirement to demonstrate safeguards against: limiting the ability to provide the service, access to data, disruption of service continuity, enforcement of sanctions/embargoes;</li>



<li>technical support only from the EU;</li>



<li>transparency of the software supply chain (SBOM &#8211; Software Bill of Materials), control of components from third-country suppliers, source code audit;</li>



<li>legal and technical separation between the EU parent company and the subsidiary in a third country.</li>
</ul>



<p>Level 3 (Enhanced) &#8211; point 3</p>



<p>Adds important refinements:</p>



<ul class="wp-block-list">
<li>staff must be EU citizens and, when handling classified information, have a national security clearance;</li>



<li>&#8220;substantial&#8221; cybersecurity certificate;</li>



<li>as a rule, a ban on control by a third-country entity – except where the Commission issues an implementing act under Article 19 authorising such a supplier (in which case additional safeguards apply, including &#8220;reasonable access to the code&#8221;);</li>



<li>technical support provided exclusively by EU residents and entities not subject to third-country control.</li>
</ul>



<p>Level 4 (Sovereign) &#8211; point 4</p>



<p>Highest, most restrictive threshold:</p>



<ul class="wp-block-list">
<li>complete lack of control by a third country entity (without any exception authorised by the Commission, as opposed to Level 3);</li>



<li>cybersecurity certificate at least &#8220;high&#8221;;</li>



<li>staff – EU citizens with appropriate security clearances;</li>



<li>for software components: requirement of effective control over design, development and maintenance &#8211; no third-country entity may have the ability to materially influence the technical development, maintenance priorities or continuity of the component</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Key criterion</strong></td><td><strong>Accessibility for non-EU entities</strong></td></tr></thead><tbody><tr><td>1</td><td>Basic Date of residency</td><td>Data localization in the EU, GDPR</td><td>Accessible &#8211; meeting basic data protection requirements</td></tr><tr><td>2</td><td>Standard Supply-chain independence</td><td>EUCS certification, operational independence</td><td>Conditionally available &#8211; requires ENISA/EUCS certification</td></tr><tr><td>3</td><td>Enhanced EU ownership &amp; control</td><td>Supply chain control, no non-EU law</td><td>Limited &#8211; Commission recognition required; US CLOUD Act disqualifies</td></tr><tr><td>4</td><td>Sovereign Defence-grade</td><td>Full transparency, technical autonomy, EU ownership</td><td>Essentially unavailable to non-EU hyperscalers without restructuring</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">III. EU Cloud Sovereignty Framework</h2>



<p>The EU Cloud Sovereignty Framework is also a key document defining the &#8220;sovereign cloud.&#8221; This document <strong>is not part of the CADA regulation itself</strong>, but a separate DG DIGIT methodological tool used in specific procurement procedures. Compared to the four-level <strong>Union Assurance Levels scale </strong>in CADA Annex II (levels 1–4, based on cumulative binary criteria—pass/fail), the SEAL framework is more detailed. According to it, digital sovereignty consists of eight elements.</p>



<p><strong>Eight Components of Digital Sovereignty (SOV-1 to SOV-8)</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>#</strong></td><td><strong>Component</strong></td><td></td></tr></thead><tbody><tr><td><strong>SOV-1</strong></td><td><strong>Strategic sovereignty</strong></td><td>The supplier&#8217;s embeddedness in the EU legal, financial and industrial ecosystem – ownership stability, influence on governance, compliance with EU strategic priorities</td></tr><tr><td><strong>SOV-2</strong></td><td><strong>Legal and jurisdictional sovereignty</strong></td><td>The legal environment of the service, exposure to foreign authorities, the possibility of pursuing rights in EU jurisdiction – including resistance to extraterritorial acts such as <strong>the US CLOUD Act </strong>or the Chinese cybersecurity law</td></tr><tr><td><strong>SOV-3</strong></td><td><strong>Data Sovereignty and AI</strong></td><td>Protection, control, and independence of data resources and AI services – where data is processed and what degree of autonomy the customer retains over AI capabilities</td></tr><tr><td><strong>SOV-4</strong></td><td><strong>Operational sovereignty</strong></td><td>Practical ability of EU entities to independently conduct, support and develop technologies without dependence on foreign control &#8211; business continuity, availability of competences</td></tr><tr><td><strong>SOV-5</strong></td><td><strong>Supply chain sovereignty</strong></td><td>Geographical origin, transparency and resilience of the technology supply chain – the extent to which key components remain under EU control</td></tr><tr><td><strong>SOV-6</strong></td><td><strong>Technological sovereignty</strong></td><td>The degree of openness, transparency and independence of the technology stack – the ability to interoperate, audit and develop solutions without dependence on closed systems from third-party vendors</td></tr><tr><td><strong>SOV-7</strong></td><td><strong>Security and Compliance Sovereignty</strong></td><td>The extent to which security operations, compliance obligations and resilience activities remain controlled within the EU – independence from foreign jurisdictions</td></tr><tr><td><strong>SOV-8</strong></td><td><strong>Environmental sustainability</strong></td><td>Long-term autonomy and resilience of cloud services in the context of energy consumption, resource dependencies, and material scarcity</td></tr></tbody></table></figure>



<p><strong>Rating scale: Sovereignty Effectiveness Assurance Levels (SEAL)</strong></p>



<p>Independently of the eight components, the document introduces <strong>a five-level maturity scale </strong>(SEAL-0 to SEAL-4) used to assess each of the eight objectives separately:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Description</strong></td></tr></thead><tbody><tr><td><strong>SEAL-0</strong></td><td>Lack of sovereignty</td><td>A service entirely controlled by a non-EU entity, managed in a foreign jurisdiction</td></tr><tr><td><strong>SEAL-1</strong></td><td>Jurisdictional sovereignty</td><td>EU law formally applies but has limited enforceability; exclusive control by a non-EU entity</td></tr><tr><td><strong>SEAL-2</strong></td><td>Data sovereignty</td><td>EU law is in force and enforceable, but significant dependencies on non-EU entities remain; indirect control</td></tr><tr><td><strong>SEAL-3</strong></td><td>Digital resilience</td><td>EU law fully enforceable, EU entities have significant but limited influence; non-EU entities have marginal control</td></tr><tr><td><strong>SEAL-4</strong></td><td>Full digital sovereignty</td><td>Technology and operations entirely under EU control, subject only to EU law, with no critical dependencies from outside the EU</td></tr></tbody></table></figure>



<p><strong>Sovereignty Score</strong></p>



<p>The document also introduces <strong>percentage weightings </strong>for each of the eight components when calculating the aggregate sovereignty score in the tender process:</p>



<ul class="wp-block-list">
<li><strong>Supply Chain (SOV-5): 20% </strong>&#8211; Highest Weight</li>



<li><strong>Strategic sovereignty (SOV-1) and operational sovereignty (SOV-4): 15% each</strong></li>



<li><strong>Technological Sovereignty (SOV-6): 15%</strong></li>



<li><strong>Legal/Jurisdictional (SOV-2), Data/AI (SOV-3), Security (SOV-7): 10% each</strong></li>



<li><strong>Environmental Sustainability (SOV-8): 5% </strong>&#8211; Lowest Weight</li>
</ul>



<p>The lower weights for SOV-2 and SOV-7 were justified by the fact that these areas are already covered by separate procedural safeguards in the procurement procedure itself.</p>



<h2 class="wp-block-heading">IV. Impact of the CADA project on public procurement</h2>



<p>One of the central mechanisms of CADA is the common EU-level procurement framework.</p>



<p><strong>Recital 64 of the Preamble</strong><strong>à</strong><strong> </strong>The free flow of data within the EU is a prerequisite for the functioning of the internal market – data cannot be artificially limited to the territory of a single Member State. The EU pledges, in principle, open, non-discriminatory market access in accordance with the TFEU and international obligations (including the WTO GPA on Government Procurement).</p>



<p>However, the EU invokes Article III:2(a) of the WTO GPA, which allows for measures necessary to protect public order, public morality, or security. This justifies proportionate restrictions on access to public procurement based on the risk of critical dependencies, unauthorized access to EU data, technology leakage, sabotage, and espionage by third-country entities. Contracting entities whose activities are identified as relevant to public order are required to procure cloud services <strong>only at levels 2-4</strong>. At the same time, <strong>level 1 becomes the mandatory minimum for the entire </strong>EU public sector, providing a consistent baseline level of security.</p>



<p><strong>Motif 65</strong><strong>à</strong><strong> </strong>To reduce vendor dependency, EU entities and Member States should consider a multi-vendor/multi-cloud strategy in their procurement processes, based on a contextual risk assessment that takes into account operational, regulatory and resilience circumstances.</p>



<p><strong>Motif 66</strong><strong>à</strong><strong> </strong>Public procurement is treated as a directional signal for the entire market – requirements imposed on the public sector regarding levels of assurance tend to be imitated by the private sector in regulated industries. Article 31 allows private entities from sectors covered by Annex I of the NIS2 Directive to carry out similar assessments.</p>



<p><strong>Article 29 </strong><strong>à</strong>Member States and EU entities are required (annually or biannually) to carry out risk assessments that:</p>



<ul class="wp-block-list">
<li>identify public sector activities using cloud services in areas covered by Annexes I/II of the NIS2 Directive and in the spheres of national security, defence, justice and law enforcement;</li>



<li>determine which <strong>assurance level (Union assurance level 2, 3 or 4) </strong>is appropriate for a given activity.</li>
</ul>



<p>The Commission has the power to impose the methodology for this assessment by means of implementing acts and, if it considers the Member State&#8217;s assessment to be inadequate, to determine the required level itself (Article 29(5)).</p>



<p><strong>Article 30</strong><strong>à</strong><strong></strong></p>



<p><strong>Paragraph 2: </strong>entities whose activities are <strong>not </strong>classified as important for public order must use at least <strong>level 1 cloud services</strong>.</p>



<p><strong>Paragraph 3: </strong>contracting entities whose activities <strong>have been </strong>so qualified (NIS2, national security, defence, justice sectors) <strong>may only procure </strong>cloud services classified as <strong>level 2, 3 or 4 </strong>.</p>



<p><strong>Paragraph 4: </strong>allows for derogations in exceptional, justified cases (lack of available services on the market, lack of offers in the previous procedure, grossly disproportionate cost).</p>



<p><strong>Art. 32 </strong><strong>à</strong>In procurement procedures for innovative cloud services and AI systems, contracting authorities must take into account <strong>non-price criteria for the evaluation of offers </strong>, including:</p>



<ul class="wp-block-list">
<li>the contractor&#8217;s contribution to strengthening the EU digital technology supply chain,</li>



<li>the use of technologies developed in the EU (including the results of EU R&amp;D programmes),</li>



<li>providing the service using hardware components designed/manufactured in the EU.</li>
</ul>



<p><strong>Recital 67 </strong>clarifies that this criterion <strong>cannot be decisive </strong>and suggests an indicative maximum weighting of <strong>15 points out of 120 </strong>in the tender evaluation methodology – it is intended to be subsidiary to the technical and financial criteria.</p>



<p><strong>Article 33</strong><strong>à</strong><strong> </strong>Member States are to aim to ensure that at least 25% of procurement for cloud services and AI systems goes to innovative SMEs, and report annual data on SME participation in procurement to the Commission.</p>



<h1 class="wp-block-heading">V. Relationship of the CADA project with existing EU legal acts</h1>



<h2 class="wp-block-heading">1. AI Act (Regulation 2024/1689)</h2>



<p>The AI Act governs the security and fundamental rights of AI systems; the CADA governs the sovereignty of the infrastructure that supports these systems.</p>



<p>Art. 2 point 3 of CADA <strong>does not create its own definition </strong>of an AI system, but refers directly to the AI Act à&#8221;&#8216;AI system&#8217; means an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689&#8243;</p>



<p><strong>Explanatory memorandum</strong><strong>à</strong><strong> </strong>&#8220;The proposal also reinforces key objectives of the AI Act. The AI Act harmonises rules for AI systems and general-purpose AI models to be placed on the EU market, improving the functioning of the internal market and promoting the uptake of human-centric and trustworthy AI along the value chain. The AI Act ensures a high level of protection of health, safety and fundamental rights. It does not cover aspects of sovereignty.&#8221; &#8211; The Commission <strong>explicitly states that the AI Act does not cover the issue of sovereignty </strong>&#8211; this is the very gap that CADA aims to fill.</p>



<p>CADA entrusts the AI Board (the body established under the AI Act) with a coordinating role beyond its original mandate:</p>



<ul class="wp-block-list">
<li><strong>Motif 33</strong><strong>à</strong> <em>&#8220;As cloud computing underpins and enables AI, the AI Board should serve as a platform to facilitate cooperation and coordination of AI adoption-related activities between the Union and the Member States.&#8221;</em></li>



<li><strong>Article 7(6) </strong>gives the AI Board a specific operational responsibility: to advise and support Member States in coordinating national cloud and AI strategies required by CADA, and to facilitate the exchange of good practices between Member States.</li>
</ul>



<p>This is an important institutional arrangement: CADA does not create a new, parallel body for AI issues, but extends the remit of the existing body from the AI Act to a new area (cloud as an infrastructure supporting AI).</p>



<h2 class="wp-block-heading">2. Data Act (Regulation 2023/2854)</h2>



<p>The Data Act, effective from September 2025, imposes obligations on cloud service providers to facilitate data portability and switching. CADA builds on this foundation by adding a dimension of sovereignty: it&#8217;s no longer just about data portability, but also about ensuring that data remains under the sole jurisdiction of the EU throughout its time in the cloud. The two acts create a complementary layer of protection: the Data Act allows for switching providers, and CADA establishes criteria for which alternative cloud services are considered sufficiently sovereign. Without CADA, the Data Act&#8217;s switching mechanism would be &#8220;blind&#8221; to the quality or sovereignty of the target provider.</p>



<p>&#8220;&#8221;The proposal is consistent with the rules on switching between data processing services introduced by the Data Act. By enabling switching and removing key sources of vendor lock-in, the Data Act seeks to ensure that cloud computing service providers in the EU compete on quality, innovation, and price. It seeks to enable cloud users to freely choose the provider that best meets their needs and combine offers of different providers in a multi-cloud approach.&#8221;</p>



<p><em>&#8220;However, the Data Act does not contain elements to shape up a more competitive offer of European cloud computing services or encourage the entry into the market of a more diverse set of cloud computing service providers.&#8221;</em></p>



<p><em>&#8220;The Data Act opens the path towards a possible reduction of dependencies on non-EU providers but does not build the road towards a more sovereign and trusted EU cloud computing sector. [&#8230;] <strong>The Data Act is thus an enabler for the proposal.</strong>&#8220;</em></p>



<h2 class="wp-block-heading">3. Data Governance Act (Regulation 2022/868)</h2>



<p>The Data Governance Act, effective from September 2023, establishes a framework for neutral data intermediaries and the reuse of public sector data. The CADA does not explicitly address the DGA in its text. However, it imposes sovereign certification requirements on the infrastructure storing this data, which in practice limits the range of providers deemed suitable for handling data covered by the DGA.</p>



<h2 class="wp-block-heading">4. Digital Markets Act</h2>



<p>The DMA, effective from May 2023, imposes obligations on gatekeepers, including interoperability requirements and prohibition of self-preferential services. CADA and DMA operate under different logics: DMA regulates market behavior ex ante, while CADA creates positive eligibility criteria for the public sector. There is a risk of conflict between the interoperability obligations with the DMA and the closed architectures required by the highest levels of CADA sovereignty.</p>



<h2 class="wp-block-heading">5. Digital Services Act and the general regulatory context</h2>



<p>The DSA, fully applicable since February 2024, governs the liability of online intermediaries. Although it does not directly address cloud infrastructure, it contributes to a regulatory climate characterized by high levels of EU intervention in the digital market and increasing assertiveness towards global technology providers.</p>



<p>&#8220;While certain providers of cloud computing services could be regulated under both this proposal and the DMA, <strong>the DMA has different objectives and does not contain measures that would actively promote the uptake of sovereign cloud computing services </strong>. The DMA only aims at maintaining and promoting a fair and contestable cloud market in the Union, regulating specific behaviors of companies designated as gatekeepers and <strong>thus intervenes at a different level than the proposal</strong>, which focuses on the uptake and use of the services provided.&#8221;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td>Dimension</td><td>DMA</td><td>CADA</td></tr></thead><tbody><tr><td>The Logic of Intervention</td><td>Ex post / behavioral — corrects the market behavior of already dominated entities (gatekeepers)</td><td>Ex ante/structural &#8211; shapes demand and supply towards trusted/sovereign services</td></tr><tr><td>Subject of regulation</td><td>Fairness and contestability of the market</td><td>Uptake and utilization of sovereign services</td></tr><tr><td>Recipients</td><td>Only entities formally designated as gatekeepers</td><td>All cloud providers seeking certification at levels 1-4</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">VI. Arguments in favor of introducing CADA regulations</h1>



<ul class="wp-block-list">
<li><strong>Security and strategic independence: </strong>AWS, Microsoft Azure, and Google Cloud control approximately 70-80% of the EU cloud computing market. This concentration means that key EU administrative, banking, and healthcare systems are de jure accessible to US authorities under the US CLOUD Act (the CLOUD Act gives <strong>US law enforcement and intelligence agencies </strong>the right to demand access to data from US service providers (including cloud computing providers) <strong>&nbsp;&#8211; regardless of the physical location of the servers </strong>on which that data is stored.) &#8211; which EU authorities classify as a security risk. CADA will help mitigate this risk by introducing a complex system of vendor evaluation criteria.</li>



<li><strong>Risk of service interruption</strong><strong>à</strong><strong> </strong>&#8220;This dependence also exposes European users to the risks related to operational discontinuity, particularly in scenarios where unilateral decisions by third-country actors could disrupt service provision.&#8221;</li>



<li><strong>Critical loss of market position for European providers &#8211; </strong>&#8220;While the EU market for cloud computing services is growing significantly, the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.&#8221; CADA will help them regain their strategic position.</li>



<li><strong>Industrial and investment goal: </strong>The project assumes tripling the capacity of data centers in the EU within 5–7 years, which will significantly improve the efficiency and functionality of the AI system in the EU àtoday: &#8220;The EU&#8217;s limited data center capacity poses a significant threat to its ability to benefit from the digital transformation and adopt AI-driven solutions, notably those requiring low-latency compute capacity.&#8221; The lack of appropriate infrastructure also hinders the EU&#8217;s economic growth: &#8220;the lack of data center capacity in the EU forces European enterprises to route critical workloads through foreign hyperscaler infrastructure. This makes <strong>the EU a less attractive destination for tech investment </strong>than regions with more abundant, lower-cost compute resources.&#8221;</li>



<li><strong>Enabling the use of the EU&#8217;s own potential &#8211; </strong>&#8220;Europe has world-class research and development capabilities, vibrant open-source communities and a strong industrial base in cloud and AI, <strong>which however remain largely untapped.</strong>&#8220;</li>
</ul>



<h1 class="wp-block-heading">VII. Tensions with Single Market Principles and Competition Law</h1>



<p>The CADA project, whose legal basis is <strong>Article 114 and Article 173(3) TFEU </strong>(harmonisation of the internal market and strengthening of the EU’s industrial competitiveness), is consciously constructed by the Commission as a means of removing internal market barriers – the argument justifying the intervention is precisely the divergence of national sovereignty criteria and procurement practices, which hinders suppliers from operating freely between Member States.</p>



<p>Despite this declared harmonisation logic, the practical effect of the sovereignty criteria at levels 3-4 (complete lack of control by a third-country entity, EU citizenship of staff, location of the entire infrastructure in the EU) may in fact restrict the freedom to provide services by non-EU suppliers in the EU internal market. However, the Act itself does not explicitly address this potential tension with Article 56 TFEU – the Commission locates the justification for procurement restrictions not in primary EU law, but in the <strong>public policy exception in Article III:2(a) of the WTO GPA </strong>(recital 64), consistently using the category of &#8220;<strong>public order</strong>&#8221; as the substantive basis for the restrictions (recitals 49-53).</p>



<p>The question whether the criteria thus constructed – despite their declared technological neutrality – in fact constitute a measure having an effect equivalent to a quantitative restriction or infringe the principle of proportionality required for derogations from the internal market freedoms remains open and not determined by the text of the act itself – this would require an assessment by the Court of Justice of the EU in a possible preliminary ruling procedure or an action for annulment.</p>



<p><strong>Application</strong></p>



<p>It is believed that despite the weaknesses identified earlier, the CADA project offers more benefits than threats – especially in the context of growing cyber warfare, where information, not just physical critical infrastructure, becomes the primary weapon.</p>



<p>Data collected by healthcare providers, the banking sector, and digital service providers is strategic in nature &#8211; its confidentiality and integrity today determine the security of citizens to a degree comparable to energy or military security. As the Schrems II case demonstrated, no contractual safeguards effectively protect against a situation in which an infrastructure provider is legally obligated to disclose data to third-party authorities &#8211; regardless of the physical location of the servers. CADA addresses precisely this gap: it no longer regulates only <em>the method </em>of data processing, but also <em>the structure of control </em>over the entity that manages it. This seems to me a necessary step, not an unnecessary one.</p>



<p>The complete dependence of the European digital economy on external infrastructure providers would limit its ability to fully develop &#8211; particularly in the field of artificial intelligence, where control over training data and computing infrastructure is becoming a key factor in competitiveness. The European Union possesses significant research and development resources, which currently remain largely untapped due to the lack of coherent institutional and regulatory support to fully develop their potential. CADA, by combining infrastructure investments with preferential procurement criteria, is attempting to fill this gap.</p>



<p>A mechanism to level the playing field for smaller European providers is also crucial. Automatic recognition of compliance for SMEs at the basic assurance level and the goal of at least a quarter of cloud and AI service contracts going to innovative SMEs create a real stimulus for development—not just a barrier for large entities. Such a competitive boost could, in the long run, motivate European providers to continually improve the quality and innovation of their services, rather than remain permanently in the shadow of foreign hyperscalers.</p>



<p>Finally, the planned tripling of data centre capacity in the EU over the next 5-7 years is an investment not only in sovereignty, but also in the security of the data itself – a distributed, redundant infrastructure located within the EU reduces the risk of systemic failures, service interruptions or abuses resulting from unilateral decisions by foreign entities.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
