<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gdpr - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/gdpr/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/gdpr/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 18:08:51 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 18:04:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Advertising Law]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Markets Act]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DMA]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[eu regulation]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[influencer marketing]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[new technologies]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland business law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[social commerce]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[TikTok Shop]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8857</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 24, 2026</mark></strong></p>



<figure class="wp-block-video"><video autoplay controls loop src="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4"></video></figure>



<p>You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a <em>closed-loop</em> model in which the path from watching a piece of content to completing a purchase has been cut to the bare minimum. That very immediacy is its greatest strength and, at the same time, the source of its most serious concerns.</p>



<span id="more-8857"></span>



<p id="ember53">A platform that in 2017 drew around 72 million monthly users now attracts more than 1.5 billion — and between 11 and 15 million in Poland alone. TikTok has stopped being merely a place for entertainment and has turned into a powerful advertising and sales engine, combining influencer marketing, algorithmic personalization, and the emotional purchasing impulse. For businesses, it is a new and remarkably effective retail space. For consumers, it is an environment in which it grows ever harder to tell an authentic recommendation from an ad, or a fleeting enthusiasm from a considered decision.</p>



<p id="ember54">That is precisely why TikTok Shop has landed at the center of lawmakers&#8217; attention. While its model is not unlawful, the platform&#8217;s operation intersects with an entire web of regulation: from consumer law and the ban on &#8220;dark patterns,&#8221; through the EU&#8217;s DSA and DMA, data protection and safeguards for minors, all the way to advertising, media, and electronic communications law. This article shows where the convenience of one-tap shopping ends and the protection of the buyer&#8217;s free will begins.</p>



<h2 class="wp-block-heading" id="ember55">What makes the TikTok Shop platform innovative?</h2>



<p id="ember56">Today, an effective marketing strategy is becoming an increasingly important priority for sellers. In Poland, monopolies in sales are relatively rare. Many competing companies operate in most industries. When purchasing products, consumers must choose from hundreds, or even thousands, of options offered by different brands. The scale of this phenomenon is evidenced by the fact that in the fourth quarter of 2025, over 2.9 million active businesses operated in Poland alone, the largest group of which were those associated with the retail sector. Meanwhile, buyers generally do not want to spend much time thoroughly analyzing goods available on the market. They are often guided by the opinions of other users, brand recognition, or media coverage. Therefore, in an information society based on the dynamic development of social media, tailoring advertising to current consumer needs and behaviors becomes crucial for running a business. Authentic and credible recommendations from trusted creators are becoming more important, and for many buyers, they are more persuasive than formulaic television commercials.</p>



<p id="ember57">Considering the above arguments, many companies are making changes to their advertising strategies, for example, opting for influencer marketing. Online creators typically publish aesthetically and thematically consistent content that captures the interest of users with similar preferences and tastes. A business partnering with an influencer who shares similar values gains the opportunity to reach a large group of potential consumers, made up of the influencer&#8217;s followers. TikTok has become the dominant platform enabling the implementation of the marketing model described above. In 2017, the application had approximately 72 million monthly active users, and according to data from 2026, this number has increased to approximately 1.54 billion. In Europe alone, TikTok has already reached over 200 million users, and in Poland, the number ranged from 11 to 15 million. The average time spent on the platform is 70 minutes per day, which translates to approximately 35 hours per month. These statistics also indicate the continued growth of TikTok&#8217;s popularity, confirming the future of using social media for advertising and promotional purposes.</p>



<p id="ember58">The development of influencer marketing significantly changed existing marketing practices, and its increasing prevalence led to the transformation of the TikTok app from a social media platform into an advertising system. The effective and profitable collaboration between media and advertising prompted the platform to take the next step in its development, combining these two sectors. Users were offered the opportunity to completely simplify the purchasing process. Previously, consumers only saw product advertisements, which attracted their attention and prompted them to search for sales offers. However, this pattern left them time to consider whether a purchase was truly necessary or necessary. It was also likely that, despite their interest in the product, they would eventually forget about the advertised product, and therefore their desire to purchase it.</p>



<p id="ember59">The solution to the marketing strategy described above turned out to be a new feature presented by TikTok: TikTok Shop. The innovative nature of this tool is based on a closed-loop model, meaning the purchasing process takes place within a single app. Users first encounter content promoting a specific item. They then have the option to immediately purchase it by adding the advertised item to their shopping cart in the bottom corner of the app. TikTok acts as an intermediary for payment, shipping, and the entire order process. In this way, the app has evolved not only into a profitable advertising system but also an online store, becoming a marketplace platform that mediates payment, logistics, and order fulfillment.</p>



<h2 class="wp-block-heading" id="ember60">The origins of TikTok Shop</h2>



<p id="ember61">Initially, the online shopping phenomenon developed through e-commerce. Its popularity contributed to the diversification of online sales into several business models: B2C, B2B, and C2C. The former involves a relationship between a business and an individual customer (examples include online stores such as Zalando, Zara, and IKEA). B2B refers to transactions between businesses, while C2C refers to sales between individuals, such as on platforms like Vinted, OLX, and Allegro.</p>



<p id="ember62">These e-commerce models typically control the sales process independently. Their profits largely come from consumers who shop by searching for specific products they need. Entrepreneurs compete with each other through marketing activities aimed at convincing consumers of the quality of their products and building brand recognition.</p>



<p id="ember63">In the next stage, the development of social media, and consequently influencer marketing, contributed to the emergence of a completely new type of buyer, one driven by impulse. Online creators present a specific lifestyle on their profiles in a significantly idealized form, which attracts the attention of their followers and becomes a role model. The desire to emulate the creator they follow can manifest itself both in their behavior and in the possessions they possess. The influencer thus becomes a person who inspires and encourages the purchase of a given product. Even if, from a rational perspective, the buyer doesn&#8217;t need the product, they often decide to purchase it under the influence of influencer marketing.</p>



<p id="ember64">Additionally, a new branch of e-commerce has emerged, known as discovery commerce . This model relies on the discovery and purchase of new items while actively browsing social media. Highly advanced algorithms select content for users that aligns with their tastes or interests, in order to evoke certain emotions that then transform into a strong purchasing impulse. Social media platforms, recognizing this profitable sector, have contributed to the development of social commerce, including TikTok Shop. This solution capitalizes on users&#8217; fleeting enthusiasm and allows them to complete their order without leaving the app. The entire process, from advertising content to payment and shipping, is handled by TikTok, which can limit the time available for rational purchase consideration.</p>



<h2 class="wp-block-heading" id="ember65">What exactly does the purchasing process look like on TikTok Shop?</h2>



<p id="ember66">TikTok Shop is not a separate app, but a new feature added to the TikTok platform. There&#8217;s no need to create a new account or install a new app. This solution provides access to a wide group of potential consumers, as every existing TikTok user over the age of 18 can familiarize themselves with the new feature. This solution gives businesses multiple ways to reach consumers. The platform offers a separate tab, &#8220;Shop,&#8221; where users can search for specific products using filters and categories, or browse recommended items based on their activity on the platform.</p>



<p id="ember67">Products offered by sellers using the TikTok Shop service can also be viewed on the &#8220;For You Page&#8221; tab. This is the subpage most frequently visited by users. This option is especially useful when a company decides to use influencer marketing. A creator posts a video promoting a selected product, and buyers are immediately presented with a purchase button at the bottom of the page. Consumers can also directly access the profiles of brands and creators to find the products they offer or promote.</p>



<p id="ember68">The latest feature, TikTok Live, is gaining popularity. Before the live stream begins, the seller or influencer adds products available in the TikTok Shop. During the live stream, the host can showcase products, communicate with users, and answer their questions via chat. This can increase the credibility of the product and the seller, as well as encourage consumers to make a purchase, which they can do without interrupting the stream.</p>



<p id="ember69">The very process of posting ads on TikTok Shop helps build consumer trust. Becoming a seller requires thorough verification, which the TikTok platform conducts to protect users from unreliable and fictitious businesses.</p>



<p id="ember70">The first step to becoming a seller is to log in to your TikTok Seller Center account using your email address, phone number, or existing TikTok account. You&#8217;ll also need to fill out an application form with information that proves your seller credentials, such as your company name, address, and contact information.</p>



<p id="ember71">After successful verification, the seller completes their store profile, adding a description, name, logo, seller details, addresses, customer service information, and tax information. It&#8217;s also necessary to configure payment and delivery methods, including the shipping address, available delivery methods, order processing time, and return policy. Connecting the store dashboard to a regular TikTok account is also crucial. This allows for tagging offered products in live videos, etc. The seller then has the option to publish their product, including the title, description, price, available models, and inventory. The platform also allows businesses to add listings by importing a product catalog from another sales platform.</p>



<p id="ember72">After a consumer makes a purchase, the seller receives a sale notification in the TikTok Seller Center. The seller is then responsible for packaging and shipping the item to the user, which can be done manually or using external order processing systems.</p>



<h2 class="wp-block-heading" id="ember73">Distance selling and consumer rights</h2>



<p id="ember74">The TikTok Shop platform offers the option of concluding a sale via a distance contract. This does not require the parties to be physically present at the same time, but rather requires at least one means of distance communication (Act of 30 May 2014 on consumer rights, Article 2). Therefore, when making a purchase through the TikTok Shop, consumer rights are governed by national and European Union law.</p>



<p id="ember75">In Poland, the primary legal act regulating these activities is the Act of May 30, 2014, on Consumer Rights. Article 12 requires businesses to clearly inform consumers in distance contracts, including the method and deadline for contract execution, the total price including taxes, the right to withdraw from the contract, the complaint procedure, and the seller&#8217;s identifying information. The TikTok Shop platform is therefore obligated to provide the required information to the user before finalizing the order via the app. An important regulation is also included in Article 17 of the aforementioned Act and concerns the requirement to design the interface in a way that confirms the consumer&#8217;s awareness of the obligation to pay. In the case of platforms that allow order completion via a &#8220;button,&#8221; it must be clearly marked, e.g., &#8220;I buy with an obligation to pay&#8221; or &#8220;I buy and pay.&#8221; Otherwise, the contract is not concluded. The requirements described above are referred to as &#8221; button &#8221; solution &#8221; and are intended to protect consumers from accidentally concluding paid contracts. Alternative obligations also arise from the Directive of the European Parliament and of the Council of 25 October 2011 on consumer rights.</p>



<p id="ember76">The Consumer Rights Act also implements the EU Commodity Directive (2019/771), introducing uniform standards for the conformity of goods with the contract. A trader is liable for any lack of conformity of goods with the contract upon delivery and for two years from the date the discrepancy is discovered. The Act also governs basic consumer claims in the event of non-conformity, including repair or replacement of the goods, and if this is not possible, a price reduction or withdrawal from the contract.</p>



<p id="ember77">Given that the sales strategy on the TikTok Shop platform relies on recommendation algorithms and influencer marketing, the Omnibus Directive (EU) 2019/2161 of November 27, 2019, plays a significant role in consumer empowerment. Its regulations introduce the obligation to provide information about the lowest price, disclose whether reviews were published by verified consumers, and indicate whether the seller is a business or an individual. The Omnibus Directive therefore increases consumer awareness and allows consumers to make more rational and manipulation-free purchasing decisions.</p>



<h2 class="wp-block-heading" id="ember78">Digital Services Act Regulation</h2>



<p id="ember79">Due to their global nature, online platforms reach hundreds of millions of users. Content published through them can reach a very wide audience, thus influencing social, political, and economic relations. Massive social networking sites, therefore, go beyond simply providing entertainment or communication services and digital space, and are beginning to shape the reality around us.</p>



<p id="ember80">The strong influence of individual platforms on current international relations has initiated more stringent oversight, including through the provisions of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act &#8211; DSA). Based on this regulation, TikTok was recognized by the European Commission as a Very Large Online Platform (VLOP). This status is granted to portals with monthly active users exceeding 10% of the EU population. TikTok exceeded the threshold and was classified as a VLOP in 2023.</p>



<p id="ember81">Platforms deemed globally influential are not solely responsible for removing illegal content. They are also required to counteract the negative consequences that may arise from their operation. Among the most important responsibilities of very large online platforms (VLOPs) is the identification and assessment of systemic risks and the potential implementation of proportionate mitigation measures. Impacts on fundamental rights, democratic processes, the protection of minors, public safety, and the dissemination of illegal content are particularly scrutinized. Once a specific risk is identified, measures are planned to counteract its escalation, such as modifying the user interface or changing certain advertising practices. In emergency situations, the European Commission has the authority to require VLOP providers to assess the platform&#8217;s impact on the development of the crisis, implement specific mitigation measures, and submit periodic reports on the effectiveness of these actions. Very large online platforms are also required to undergo an annual independent audit of compliance with the Digital Services Act (DSA) and regularly publish comprehensive reports on their activities. The aim of this action is to ensure transparency of the platform&#8217;s operation towards users and supervisory authorities.</p>



<p id="ember82">The DSA also regulates advertising by introducing the requirement to maintain a public ad repository. This repository should include, among other things, the ad&#8217;s content, advertiser, funding entity, broadcast time, and the number of recipients. This solution is intended to ensure transparency in advertising messages and enable social and scientific analysis of platforms&#8217; promotional activities. Restrictions have also been imposed on recommendation systems. This means that VLOPs are required to provide users with at least one way to display content that is not based on profiling, meaning it does not use user activity history or data. To monitor platforms&#8217; compliance with the EU regulation, it is also possible to impose a requirement to share data on, for example, the performance of recommendation algorithms with the European Commission, national digital service coordinators, or verified researchers.</p>



<p id="ember83">TikTok, however, is not subject only to the obligations of very large online platforms. It is subject to all regulations provided for in the Digital Services Act. According to Article 26, each advertisement must be clearly identified as promotional material and indicate the advertiser, the funding entity, and the mechanism by which it was tailored to the user. This restriction is particularly useful for the TikTok Shop platform, where sponsored content is commonly created in the manner of regular content published by creators. Limiting the phenomenon of so-called hidden advertising through the provisions described above aims to increase user awareness.</p>



<p id="ember84">One of the DSA&#8217;s key goals is also the protection of minors. When designing their services, platforms are required to consider a high level of protection for minors and their privacy. It is prohibited to display advertisements based on the profiling of minors when the platform has knowledge of the user&#8217;s minor status. The goal is to limit the use of children&#8217;s data for marketing purposes and reduce the risk of addictive use of the app.</p>



<p id="ember85">The European Commission has also become concerned about potential negative consumer behavior resulting from the increasing transformation of large social media platforms into e-commerce portals. Complex profiling algorithms, influencer marketing, and instant purchases can encourage users to make impulsive decisions or even become dependent on purchasing processes. Articles 25 and 27 of the Consumer Protection Act (DSA) mitigate this risk. Designing web interfaces that manipulate or complicate consumer decision-making &#8211; so-called dark patterns &#8211; is prohibited. Examples of unacceptable solutions include hiding options that are less favorable to the business, making it difficult to unsubscribe from services, or designing buttons that encourage a specific choice. Users should also be fully aware of how the recommendation system works; therefore, platforms are required to clearly present its main parameters and the possibility of changing the content suggestion method.</p>



<h2 class="wp-block-heading" id="ember86">Tamper protection and dark patterns</h2>



<p id="ember87">A key premise of the TikTok Shop platform is the immediacy of purchases. While this solution is very beneficial for businesses and, typically, consumers, it can lead to abuse. Sales without leaving the app, a simplified order completion process, and algorithmic personalization of recommended products seem to provide greater convenience when shopping online. However, some activities can be classified as &#8221; dark patterns&#8221;, manipulations used to mislead users and influence their decisions. Because the practices described above can lead to impulsive behavior and distort consumer will, they may be treated as unfair market practices and subject to criminal penalties.</p>



<p id="ember88">The Act of 23 August 2007 on Counteracting Unfair Market Practices defines an unfair market practice as a sale that is contrary to good practice and significantly distorts or may distort the market behavior of the average consumer before, during or after the conclusion of a product agreement , in particular a misleading market practice and an aggressive market practice (Act of 23 August 2007 on Counteracting Unfair Market Practices, Article 4). The main grounds for considering a market practice misleading include the dissemination of false information or truthful information in a potentially misleading manner. Such misleading information typically concerns the existence of a product, its type or availability, price, the method of price calculation, or the existence of a special price advantage.</p>



<p id="ember89">To encourage immediate purchases, sellers pressure buyers with messages suggesting limited availability or a limited-time promotion for a specific product. Examples of such messages include phrases like &#8220;100 people are viewing the product,&#8221; &#8220;offer ends in 2 hours,&#8221; or &#8220;only 4 items left.&#8221; This practice is not illegal and is one of the most common marketing mechanisms. Problems arise when the website or portal is programmed to continually extend promotions, the offer doesn&#8217;t actually expire after the specified date, or the counter restarts upon page refresh.</p>



<p id="ember90">Misleading practices, such as suggesting the limited nature of a permanently available offer, and aggressive practices, such as exerting time pressure, may result in legal consequences. In addition to the aforementioned Act of 23 August 2007 on Combating Unfair Commercial Practices, this issue is also regulated by Directive 2005/29/EC concerning unfair business-to-consumer commercial practices in the internal market. This directive distinguishes between misleading commercial practices and aggressive commercial practices. Together, they constitute unfair commercial practices, which include, in particular, actions that are contrary to the requirements of professional diligence and that significantly distort or are likely to significantly distort the economic behavior of the average consumer who reaches or is targeted by the practice, or the average member of a group of consumers if the commercial practice is targeted at a specific group of consumers (Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (&#8220;Unfair Commercial Practices Directive&#8221;), Chapter 2, Article 5, paragraph 2).</p>



<p id="ember91">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 (Omnibus Directive) is also intended to combat various manifestations of the &#8220;dark patterns&#8221; phenomenon. It requires sellers to disclose the lowest price for a product within the last 30 days. This is intended to prevent the practice of artificially inflating prices and then announcing sales. The practice of fake reviews has also been curbed by introducing an obligation to disclose whether and how reviews posted on sales websites are verified. The Omnibus Directive also introduced the requirement to indicate on marketplace platforms whether the seller is a private individual or a professional entrepreneur, so that consumers are aware of who they are buying from.</p>



<p id="ember92">The European Union has also introduced restrictions related to the design of digital services, contained in Regulation 2022/2065 on the Digital Single Market (DSA). As a result, online platform providers cannot design, organize, or operate their online interfaces in a way that misleads, manipulates, or otherwise interferes with or limits the ability of service users to make free and informed decisions. The regulation therefore directly addresses the fight against &#8220;dark patterns,&#8221; i.e., website design practices that deliberately use deceptive techniques, such as pre-selected consents or difficult unsubscribes.</p>



<p id="ember93">The President of the Office of Competition and Consumer Protection (UOKiK) has broad authority to protect consumers from the unfair commercial practices mentioned above. Under the Act of 16 February 2007 on Competition and Consumer Protection, one of his powers is to protect the collective interests of consumers, including through provisions counteracting unfair market practices. If necessary, the UOKiK President may initiate proceedings against a business, ordering it to cease the unfair practice, or requiring the seller to remedy the effects of the violation. Should a business fail to comply with the guidelines, he may impose a fine of up to 10% of the business&#8217;s turnover in the previous year.</p>



<p id="ember94">The number of legal acts, including EU documents, regulating unfair commercial practices reflects the considerable interest in this issue among both legislators and consumer protection authorities. TikTok Shop, as a social commerce model, is not illegal. It utilizes mechanisms combining influencer marketing, personalization, and emotional impact on the recipient, but the design of the user interface is crucial for this platform. The popularity of mass sales portals has contributed to the increasing use of &#8220;dark patterns&#8221; by businesses over the past few years. For this reason, the European Union and the Office of Competition and Consumer Protection (UOKiK) are increasingly rigorously monitoring sales tactics and issuing new legal acts to protect consumers and their free will when making purchases.</p>



<h2 class="wp-block-heading" id="ember95">Influencer Marketing and Advertising Law</h2>



<p id="ember96">The effectiveness of influencer marketing stems from combining advertising with the ability to make an immediate purchase. Affiliate links, product tags, or direct purchase buttons, such as those on the TikTok Shop platform, are displayed beneath posts, videos, or other promotional materials. This purchasing model has proven effective by significantly simplifying the ordering process, thus reducing the time consumers spend considering the rationale behind the transaction.</p>



<p id="ember97">The popularity of the marketing strategy described above stems from its perception by users, who perceive it as authentic and credible. Influencers present promoted products in a natural way, integrating them into their daily routine. However, if the material does not solely reflect the creator&#8217;s personal opinion but is created after receiving a benefit in return, it is considered commercial communication. This means it is subject to legal regulations on advertising and consumer protection. In Poland, influencers should clearly label advertising content in accordance with the Recommendations of the President of the Office of Competition and Consumer Protection. These regulations are intended to prevent misleading users.</p>



<p id="ember98">Only content regarding a product that the influencer purchased independently and for which they did not receive remuneration or other benefits can be marked as a private opinion. Such material contains genuine feelings and opinions and therefore does not constitute advertising under the law and is not subject to advertising law. This is the most credible and reliable form of review for potential consumers, as it was created by a person not under any obligation to the manufacturer.</p>



<p id="ember99">A manufacturer may enter into an agreement with an influencer to promote a product in exchange for a free product, financial benefit, or other form of remuneration. This creates legally regulated advertising. It may take the form of a post, report, or live broadcast in which the creator demonstrates how they use the product and its positive properties. Due to the natural presentation of the product as an everyday element, the recipient may have difficulty distinguishing a genuine recommendation from commercial content. The Act of August 23, 2007, on Counteracting Unfair Market Practices, classifies the act of concealing a promotional message as a misleading omission. Failure to clearly indicate the commercial nature of the material may hinder consumers&#8217; proper assessment of the message and directly influence their purchasing decisions.</p>



<p id="ember100">Another common advertising strategy is to feature a product integrated into published content without directly promoting it, for example, by placing it in the background of the material. This phenomenon is called product placement. Activities covered by advertising and consumer protection law also include, among others, affiliate and partner links, ambassador programs, and partner competitions. In Poland, these practices must contain clear, understandable to the average recipient, and visible advertising labels from the very beginning, such as &#8220;advertisement,&#8221; &#8220;paid collaboration,&#8221; or &#8220;sponsored content.&#8221; The Office of Competition and Consumer Protection (UOKiK) also recommends the use of two-level labeling, meaning that, in addition to the information contained in the content, the platform&#8217;s functionality must also be used to announce the paid collaboration. Detailed guidelines can be found in the Recommendations of the President of the UOKiK regarding the labeling of advertising content by influencers. Material is considered advertising content not only when the influencer receives monetary compensation in exchange for its creation. The same obligation applies when promoting your own business, receiving a free product or service, or obtaining a sales commission via an affiliate link or discount code (Recommendations of the President of the Office of Competition and Consumer Protection regarding the marking of advertising content by influencers).</p>



<p id="ember101">In the event of non-compliance with the Recommendations of the President of the Office of Competition and Consumer Protection regarding the labeling of advertising content by influencers, pursuant to the Act of 16 February 2007 on Competition and Consumer Protection, the Office of Competition and Consumer Protection (UOKiK) conducts proceedings against entrepreneurs using practices that violate the collective interests of consumers. Actions may be taken against advertisers, influencers, and marketing agencies. Therefore, responsibility for incorrect labeling of advertising content rests not only with the creator publishing the material but also with all entities participating in organizing the promotional campaign. One of the sanctions that the President of the UOKiK has the right to impose is a financial penalty. Incorrectly labeled promotional material can also be considered surreptitious advertising. Due to the dynamic development of influencer marketing, the proper creation of marketing content is currently widely subject to UOKiK scrutiny. Therefore, it is worth clearly and understandably labeling sponsored publications, among other things, to avoid significant financial penalties.</p>



<h2 class="wp-block-heading" id="ember102">Personal data protection</h2>



<p id="ember103">TikTok Shop, as a hybrid social network and e-commerce platform, processes a significant amount of data related to both user activity and purchasing processes. The app&#8217;s operation is based on audience profiling and matching the most relevant content. Therefore, the platform&#8217;s operations are subject to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).</p>



<p id="ember104">In addition to user data such as name, surname, contact details, shipping addresses, and payment information, media platforms also collect information that allows for behavioral analysis. Time spent browsing specific products, interactions with ads, and the history of items added to carts or wish lists allow the TikTok Shop platform to create a personalized recommendation system based on past activity. This phenomenon creates so-called behavioral advertising, a marketing strategy based on user profiling using advanced algorithms to predict future purchasing decisions. The concept of profiling refers to the automated processing of personal data, particularly for the purpose of predicting a user&#8217;s economic situation, personal preferences, interests, health, and location.</p>



<p id="ember105">According to the GDPR, profiling is permissible, but it also comes with a number of obligations. Platforms are obligated to transparently inform users about, among other things, the purposes of profiling, the legal basis for data processing, the consequences of the actions taken, and their rights, including the right to object to profiling. Data of minors is particularly protected. Due to the growing popularity of the TikTok app among young users, it was necessary to subject it to special regulations in this regard. In the area of information society services, the processing of data of children over 16 years of age is lawful. An exception is made for situations in which a person with parental authority or guardianship provides prior consent. However, EU member states may introduce a lower age limit in their laws, but it must be at least 13 years old, as is the case in Poland, for example. To ensure that platforms enforce their obligations related to the protection of minors, they should use appropriate age verification mechanisms. In practice, however, this solution requires further improvement due to the common practice of users providing false data during registration.</p>



<p id="ember106">The President of the Office of Competition and Consumer Protection (UOKiK) plays a crucial role in protecting users, especially the collective interests of consumers. He is authorized to take action against entrepreneurs who engage in unfair market practices, design manipulative interfaces, and so on. Personal data protection, however, falls primarily within the remit of the Office for Personal Data Protection (UODO), which oversees compliance with the GDPR and the secure processing of information by companies and institutions. Due to its global influence, TikTok has attracted increasing attention from EU authorities in recent years and is becoming the subject of more frequent inspections. Due to the platform&#8217;s European headquarters being located in Ireland, the relevant supervisory authority is the Irish Data Protection Commission (DPC). For example, in 2025, this institution imposed a fine of €530 million on ByteDance, the app&#8217;s owner. The fine was imposed on the transfer of user data from the European Economic Area to China in violation of the GDPR and the failure to demonstrate data protection at the level guaranteed in the EU.</p>



<p id="ember107">The GDPR is supplemented by Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), which regulates, in addition to the processing of personal data, the confidentiality of electronic communications, also known as ePrivacy. Due to the scope of its regulations, the provisions of this directive have particular relevance to the TikTok Shop application. The platform uses numerous tracking technologies, such as cookies and mobile device advertising identifiers, to monitor user activity. Information may be stored on a user&#8217;s device or accessed only after obtaining prior consent. Exceptions are made only for technologies strictly necessary to provide the service requested by the user, such as remembering a shopping cart. An additional ePrivacy regulation was also envisaged, the purpose of which was to replace the current directive and harmonize the personal data protection rules applicable in all EU Member States. The changes were to include, among other things, simplifying the rules regarding cookies. However, the project encountered legislative difficulties and was not adopted by decision of the European Commission.</p>



<h2 class="wp-block-heading" id="ember108">Abuse of Market Power and the Digital Markets Plan</h2>



<p id="ember109">The dynamic expansion of the largest digital platforms&#8217; influence has led to the need to adapt competition law to the new situation, particularly in the digital market. To this end, the European Union adopted Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act – DMA). The Act introduces the concept of a gatekeeper. This term refers to an entrepreneur with an influential position in the internal market, through which business users reach end users. A gatekeeper provides a core platform service and maintains an established market position.</p>



<p id="ember110">The dominant position of a gatekeeper is also associated with a number of obligations. Among other things, the practice of self-preferencing, which involves favoring one&#8217;s own products or services over the offers of other businesses using the platform, is prohibited. In the case of TikTok Shop, this could involve using recommendation algorithms to increase the visibility of products promoted by individual sellers, without applying objective and fair advertising criteria. This type of favoritism and limiting the reach of individual entities could lead to a distortion of fair competition between businesses using TikTok Shop for sales purposes.</p>



<p id="ember111">By decision of the European Commission, BytaDance Ltd. was granted gatekeeper status solely for the operation of the TikTok application as a social media platform. The DMA regulations governing the gatekeeper position do not apply directly to TikTok Shop, but they may impact the rules for recommending products and using entrepreneurs&#8217; data.</p>



<h2 class="wp-block-heading" id="ember112">Media law and audiovisual regulations</h2>



<p id="ember113">Audiovisual materials are the primary tool for promoting and selling products on the TikTok Shop marketplace. Therefore, the app&#8217;s operations are also subject to scrutiny for compliance with media law and regulations governing audiovisual media services. The dominant role in this regard is played by Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation, or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive – AVMSD) and the Broadcasting Act of 29 December 1992, which implements it into Polish law. As a result of the amendment to the Act of 11 August 2021, the regulations have been extended to video-sharing platforms, including the TikTok app.</p>



<p id="ember114">Video-sharing platforms are primarily obligated to implement appropriate measures to protect minors from harmful content that could negatively impact their moral, mental, or physical development. These provisions have been implemented into Polish law through Article 47e of the Broadcasting Act, which mandates, among other things, the marking of potentially inappropriate content with special graphics for young viewers. These regulations are particularly important for the TikTok Shop platform due to the constantly growing number of underage users. Posting content that spreads hatred and discrimination is also prohibited.</p>



<p id="ember115">TikTok Shop, a hybrid social media platform and e-commerce platform, is often used to publish so-called audiovisual commercial communications—images used to directly or indirectly promote goods, services, or individuals (Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services, Article 1). Article 9 of the AVMSD requires member states to ensure that such communications are easily recognizable, thus prohibiting hidden audiovisual commercial communications. The use of subliminal techniques or the inclusion of discriminatory content would also be illegal. The National Broadcasting Council (KRRiT) is responsible for ensuring compliance with audiovisual law. Its remit includes, among other things, overseeing the activities of video-sharing platform providers.</p>



<p id="ember116">The sales method used by TikTok Shop may seem analogous to teleshopping, offerings directly to consumers to deliver goods or services in exchange for payment. This modern form of interactive audiovisual commerce (live shopping) bears numerous similarities to traditional teleshopping. The mechanisms of both aforementioned sales methods involve presenting the product, its specific features, available options, and generally encouraging the recipient to purchase. However, teleshopping is targeted at a general, anonymous audience who may only be interested in the recommended product. Meanwhile, TikTok Shop relies on advanced algorithms that target promotional content to users who, based on their previous activity, have shown interest in similar content.</p>



<h2 class="wp-block-heading" id="ember117">Platform liability under e-commerce regulations</h2>



<p id="ember118">The original act regulating the legal liability of online platforms in the European Union was Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (Directive on electronic commerce). Its foundation was the so-called safe harbor principle, i.e., the principle of limited liability of online intermediaries. According to this principle, hosting service providers and online platforms were not liable for content or goods published by users, provided they had no actual knowledge of the illegal nature of the content or goods or services or, upon obtaining such knowledge, promptly removed any infringements. Furthermore, the directive did not impose a general obligation on platforms to monitor content published by users.</p>



<p id="ember119">However, the ongoing development of digital platforms has made it necessary to amend the current liability model. Regulation (EU) 2022/2065 – Digital Services Act (DSA) – came into effect on February 17, 2024. This regulation does not eliminate the principle of limited liability but significantly expands monitoring obligations, especially for very large online platforms (VLOPs). One of the key obligations introduced under the new regulations is the Know Your Business Customer (KYBC) principle. This regulation aims to increase the safety of consumers shopping online by limiting sales conducted by dishonest or anonymous traders. Before enabling sales through its platform, an online platform must collect and verify basic data identifying the seller. The required information includes, among others, the trader&#8217;s name, registered office address, contact details, registration number in the relevant register of traders, and the trader&#8217;s payment account details. In the event of refusal to provide the specified data or providing it falsely, the platform should prevent the trader from conducting sales until the situation is resolved.</p>



<p id="ember120">A problematic issue related to the TikTok Shop app is defining the platform&#8217;s responsibility for transactions conducted by sellers using it. Although TikTok Shop formally acts as an online intermediary, it can be argued that its operating mechanism goes beyond passive hosting. A recommendation system using algorithms, promoting offers, and providing marketing and analytical tools to sellers are the mechanisms TikTok Shop uses to shape consumer behavior and purchasing decisions. The platform&#8217;s influence on the visibility of offers and the order fulfillment process may support assigning it broader responsibilities in overseeing the online sales process.</p>



<h2 class="wp-block-heading" id="ember121">Regulations on electronic communications, including the European Electronic Communications Code and the Polish Electronic Communications Law</h2>



<p id="ember122">The TikTok Shop platform does not constitute an electronic communications service under European Union law, but its operations provide for various forms of electronic communication. TikTok Shop&#8217;s use of push notifications, in-app messages, and marketing communications requires the platform to comply with regulations governing electronic marketing and the protection of user privacy in electronic communications. The primary legal acts regulating these aspects are Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code (EECC) and the Act of 12 July 2024 – Electronic Communications Law.</p>



<p id="ember123">The primary function of TikTok Shop is to enable entities to sell goods through the social media platform. Article 2 of the European Electronic Communications Code defines an electronic communications service as the transmission of signal transmissions or the provision of interpersonal communications services. The mere ability to exchange messages between users or with sellers does not automatically qualify the TikTok Shop platform as a provider of electronic communications services, as this is not its core competency and does not constitute its core business. However, because electronic communications are primarily used for marketing purposes, it is obligated to comply with regulations governing direct marketing and the protection of user privacy.</p>



<p id="ember124">Push notifications, messages sent directly to users&#8217; mobile devices, are an increasingly popular marketing solution. TikTok Shop uses them to provide information about order status, discounts, time-limited campaigns, or the launch of live shopping. Transactional notifications regarding order fulfillment, shipping, or payment status are typically part of the contract and do not require marketing consent. However, notifications encouraging potential consumers to make a purchase are classified as direct marketing and, in accordance with electronic communications law, require prior user consent.</p>



<p id="ember125">The practice of using automated calling systems and electronic means of communication for advertising purposes without the user&#8217;s prior consent is also prohibited. Users should be clearly informed about the purpose of receiving marketing communications, the data controller, and the possibility of withdrawing consent, which should not result in any negative consequences. With respect to the TikTok Shop platform, the above position means that it is unlawful to send promotional content to users solely based on the fact that they have an account on the app.</p>



<p id="ember126">TikTok Shop is the clearest example of how thin the line between entertainment, advertising, and commerce has become &#8211; a one-tap purchase woven into a stream of content is now as effortless as liking a video. Yet that convenience comes at a price: the <em>closed-loop</em> model and algorithmic personalization shrink the time left for rational reflection, while responsibility for protecting the consumer shifts increasingly away from the buyer and onto the platform and the legislator. EU and national regulations &#8211; from consumer law, through the DSA and DMA, data protection and safeguards for minors, all the way to media and electronic communications law &#8211; form a web meant to counterbalance the platform&#8217;s power and restore the buyer&#8217;s awareness of their own choices. TikTok Shop thus remains a dual phenomenon: on one hand a groundbreaking innovation in digital commerce, on the other a test of whether the law can keep pace with a technology that sells faster than we can think.</p>
<p>&nbsp;</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4" length="2083444" type="video/mp4" />

			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 13 May 2026 10:56:58 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DataAct]]></category>
		<category><![CDATA[DataGovernance]]></category>
		<category><![CDATA[DataPrivacy]]></category>
		<category><![CDATA[EUDataAct]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[RegTech]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8769</guid>

					<description><![CDATA[<p>Publication date: May 13, 2026 The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: May 13, 2026</strong></mark></p>



<p>The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act introduces a new legal regime designed to improve access to and use of data generated by connected products and related digital services.</p>



<span id="more-8769"></span>



<p>For businesses operating in the European Union, the key challenge is not understanding each regulation in isolation, but determining how they interact in practice. Many organizations already have mature GDPR compliance frameworks, but the Data Act creates additional obligations that require them to share data with users and third parties. Where those datasets contain personal data, compliance with the Data Act must be reconciled with the GDPR.</p>



<p>This article explains the relationship between the Data Act and the GDPR in practical terms. It highlights the main legal issues and outlines the steps businesses should take to prepare.</p>



<p><strong>What Is the Data Act?</strong></p>



<p>The Data Act, Regulation (EU) 2023/2854, is part of the European Union&#8217;s broader strategy to build a single market for data. Its purpose is to ensure that users of connected products and related services can access the data they generate and, in certain circumstances, require that such data be shared with third parties.</p>



<p>The regulation is intended to rebalance the relationship between manufacturers, service providers and users. In many industries, companies that design connected products control large volumes of data generated through use of those products. The Data Act seeks to ensure that users are able to benefit from this data rather than being locked into a single ecosystem.</p>



<p>The regulation applies to both personal and non-personal data, which is one of the key differences from the GDPR.</p>



<p>Examples of products and services covered by the Data Act include smart watches, connected vehicles, industrial machinery, medical devices, smart home appliances, agricultural equipment and software applications that process the data generated by such products.</p>



<p><strong>What Is the GDPR?</strong></p>



<p>The GDPR governs the processing of personal data relating to identified or identifiable natural persons. Its objective is to protect privacy and ensure that personal data is processed lawfully, fairly and transparently.</p>



<p>The GDPR applies whenever data relates to an individual and a controller or processor carries out an operation such as collecting, storing, sharing or analyzing that data.</p>



<p>Unlike the Data Act, the GDPR does not grant a broad right of access to all data generated by products. It focuses solely on personal data and establishes rights such as access, rectification, erasure and portability.</p>



<p><strong>The Relationship Between the Data Act and the GDPR</strong></p>



<p>The Data Act expressly states that it is without prejudice to EU and national laws on personal data protection, privacy and confidentiality of communications. In practical terms, this means that the Data Act does not override the GDPR. If a company is required to provide data under the Data Act and the dataset contains personal data, the GDPR continues to apply in full.</p>



<p>This principle has several important consequences.</p>



<p>First, the Data Act does not create a new legal basis for processing personal data. A company cannot rely on the Data Act alone to justify collecting, disclosing or otherwise processing personal data.</p>



<p>Second, organizations must continue to comply with all GDPR principles, including purpose limitation, data minimization, storage limitation and security.</p>



<p>Third, where there is a conflict between the two regulations, the GDPR prevails in relation to personal data.</p>



<p><strong>Why This Matters in Practice</strong></p>



<p>Most data generated by connected products is not purely personal or purely non-personal. Instead, businesses often deal with mixed datasets.</p>



<p>A connected vehicle, for example, may generate information on speed, fuel consumption, component performance, geolocation and driver behavior. Some of this information clearly relates to an identifiable person and therefore qualifies as personal data. Other elements may be technical or operational in nature.</p>



<p>Where personal and non-personal data are inextricably linked, organizations should assume that the GDPR applies to the dataset as a whole unless the data can be effectively separated.</p>



<p>This means that compliance with the Data Act often requires a GDPR analysis before any disclosure can take place.</p>



<p><strong>Practical Example: Smart Watch Data</strong></p>



<p>A consumer uses a smart watch that collects heart rate, sleep patterns, exercise metrics and location information. The consumer wishes to transfer the data to a third-party health application.</p>



<p>Under the Data Act, the user may request access to the data generated by the device and ask the manufacturer to transmit the data to another provider.</p>



<p>Because the dataset contains information relating to an identifiable person, the GDPR applies.</p>



<p>In this scenario, the manufacturer must verify that the request is valid, ensure the transmission is secure and process the data in accordance with the GDPR. The Data Act creates the obligation to provide the data, but the GDPR determines how the transfer must be carried out.</p>



<p><strong>Practical Example: Industrial Equipment</strong></p>



<p>A manufacturing company leases connected machinery that generates data concerning temperature, output, wear and maintenance cycles. The company wants to share this data with an independent maintenance provider.</p>



<p>The Data Act allows the user to request access to the data and to require the data holder to share it with a third party.</p>



<p>If the dataset contains no personal data, the GDPR may not apply.</p>



<p>However, if the data includes operator IDs or logs that can identify employees, GDPR considerations arise. The data holder must assess whether a lawful basis exists for sharing those elements.</p>



<p><strong>Key Roles Under the Data Act and the GDPR</strong></p>



<p>The terminology used by the two regulations differs, but the concepts often overlap. Under the Data Act, the principal roles are the data holder, the user and the data recipient. Under the GDPR, the key roles are the controller and processor. In practice, a data holder will often act as a controller because it determines the purposes and means of processing personal data. A business user receiving data may also become a controller if it decides how the data will be used.</p>



<p>This distinction is important because the recipient of data under the Data Act may inherit independent GDPR obligations.</p>



<p><strong>Data Portability: How the Data Act Expands Existing Rights</strong></p>



<p>The GDPR grants individuals a right to data portability, but this right is limited to personal data provided by the data subject and processed on the basis of consent or contract. The Data Act significantly broadens this concept.</p>



<p>It applies to data generated through the use of connected products and related services, regardless of whether the data is personal or non-personal.</p>



<p>For businesses, this means that existing GDPR portability procedures will usually not be sufficient. Organizations may need entirely new technical and contractual frameworks to handle Data Act requests.</p>



<p><strong>Trade Secrets and Confidential Information</strong></p>



<p>One of the most common concerns raised by businesses is the protection of proprietary information. The Data Act recognizes that data may contain trade secrets and allows data holders to implement safeguards such as confidentiality agreements, access controls and contractual restrictions. However, trade secret protection is not an automatic ground for refusing access. A refusal is permitted only in exceptional circumstances where disclosure would likely cause serious economic harm and where protective measures are insufficient.</p>



<p>In practice, businesses should assume that most requests will need to be fulfilled, subject to appropriate safeguards.</p>



<p><strong>Smart Contracts</strong></p>



<p>The Data Act introduces specific requirements for smart contracts used to automate data sharing.</p>



<p>Where businesses use blockchain-based or automated systems to execute data-sharing arrangements, those systems must meet standards relating to security, integrity and the ability to terminate or interrupt execution where necessary. Although this aspect of the regulation may not affect all organizations, it is highly relevant to businesses deploying decentralized or automated contractual technologies.</p>



<p><strong>Cloud Switching and Digital Assets</strong></p>



<p>The Data Act also addresses switching between providers of data processing services, including cloud providers. Customers must be able to move digital assets such as applications, configuration files, metadata and access credentials to another provider more easily. Organizations that offer cloud or platform services should review their contractual and technical arrangements to ensure that customers can migrate without undue barriers.</p>



<p><strong>Legal Basis for Processing Personal Data</strong></p>



<p>A recurring misconception is that the Data Act itself authorizes disclosure of personal data. This is incorrect. Whenever personal data is involved, a valid legal basis under the GDPR remains necessary. The applicable legal basis will depend on the circumstances. In some cases, processing may be necessary for the performance of a contract. In others, consent or legitimate interests may be relevant. Where the user requesting the data is a business rather than the individual to whom the data relates, the requesting party may need to demonstrate that it has an independent lawful basis for processing the personal data.</p>



<p><strong>What Businesses Should Do</strong></p>



<p>Organizations should begin by identifying whether they fall within the scope of the Data Act. Businesses that manufacture connected products, provide related services, control access to product-generated data or offer cloud services are the most likely to be affected. The next step is to map the data generated by products and services. This exercise should identify what data is collected, whether it includes personal data, who controls it and with whom it may be shared.</p>



<p>Once the data landscape is understood, businesses should review the legal bases for processing any personal data contained in those datasets.</p>



<p>Policies and procedures should then be updated to address Data Act requests. Existing GDPR processes will rarely be sufficient because they are designed primarily for requests from individuals, not business-to-business data sharing.</p>



<p>Contracts with customers, partners and recipients should be revised to address data use restrictions, confidentiality obligations, trade secret protections and security measures.</p>



<p>Technical teams should ensure that systems can provide data in accessible formats, authenticate requesters, record disclosures and protect sensitive information.</p>



<p>Finally, legal, compliance, IT and customer support teams should be trained so that they understand how to manage requests consistently.</p>



<p><strong>Common Pitfalls</strong></p>



<p>Businesses preparing for the Data Act frequently make several mistakes. The first is assuming that the Data Act overrides the GDPR. In reality, the GDPR remains fully applicable whenever personal data is involved. The second is underestimating the complexity of mixed datasets. The third is relying too heavily on trade secret arguments to resist disclosure. The fourth is failing to update contracts and operational procedures.</p>



<p>The fifth is treating compliance as a purely legal issue rather than a multidisciplinary project involving legal, IT, security and commercial teams.</p>



<p><strong>Enforcement and Business Risk</strong></p>



<p>Failure to comply with the Data Act may result in regulatory investigations, disputes with customers and partners, and reputational damage. Where personal data is mishandled, GDPR enforcement risks also arise, including potentially significant administrative fines. For this reason, businesses should approach the Data Act as a strategic compliance project rather than a narrow contractual exercise.</p>



<p><strong>Conclusion</strong></p>



<p>The Data Act and the GDPR are complementary regulations that pursue different objectives. The GDPR protects individuals and their personal data. The Data Act promotes broader access to data generated by connected products and services. When those datasets contain personal data, organizations must apply both regimes simultaneously. The Data Act creates the obligation to make data available, while the GDPR determines the conditions under which personal data may be processed and shared.</p>



<p>Businesses that rely on connected products, IoT ecosystems, industrial data or cloud services should begin preparing well in advance.</p>



<p>Organizations that invest now in data mapping, contractual updates, technical controls and internal governance will be best positioned to comply with the new rules and to leverage data as a strategic asset.</p>



<p><strong>Client Alert</strong></p>



<p><strong>EU Data Act Applies from 12 September 2025: Is Your Business Ready?</strong></p>



<p>The EU Data Act introduces a new framework governing access to data generated by connected products and related services. It applies from 12 September 2025 and will affect manufacturers, software providers, cloud providers and businesses that rely on connected technologies.</p>



<p>The regulation grants users the right to access data generated by products they use and to request that such data be shared with third parties.</p>



<p>Where the data includes personal data, the GDPR remains fully applicable.</p>



<p>For many organizations, the Data Act will require updates to contracts, technical systems and operational procedures.</p>



<p>Businesses should begin by identifying whether they control product-generated data, determining whether datasets include personal data, and assessing whether existing systems can support secure and compliant data sharing.</p>



<p>Organizations should also review trade secret protections and update agreements with customers and business partners.</p>



<p>Companies that prepare early will be better positioned to meet legal obligations and capitalize on new opportunities arising from increased data portability.</p>



<p><strong>Data Act Implementation Checklist</strong></p>



<p>An effective implementation project should begin with a governance assessment to determine which internal teams will be responsible for legal analysis, technical implementation and operational oversight.</p>



<p>The organization should then conduct a comprehensive data mapping exercise covering all connected products, related services and cloud environments. This exercise should distinguish between personal data, non-personal data and mixed datasets.</p>



<p>A legal review should be undertaken to confirm the GDPR legal bases for processing personal data and to identify any restrictions arising from confidentiality obligations or trade secret protections.</p>



<p>Customer terms, data-sharing agreements, cloud contracts and internal policies should be revised to reflect Data Act requirements.</p>



<p>Technical teams should ensure that systems are capable of exporting data in usable formats, authenticating requesters, logging disclosures and protecting confidential information.</p>



<p>Operational procedures should be established for receiving, reviewing and responding to requests.</p>



<p>Training should be delivered to legal, compliance, IT, security and customer-facing teams.</p>
<p> </p>



<p><strong>The EU Data Act Meets the GDPR: What Businesses Need to Know</strong></p>



<p>With the EU Data Act becoming applicable from <strong>12 September 2025</strong>, we’re entering a new era of data regulation in Europe — one that doesn’t replace the GDPR, but fundamentally reshapes how it operates in practice.</p>



<p>For many organizations, the challenge is no longer <em>GDPR vs. Data Act</em>, but how both frameworks work together when data is shared, accessed, and reused.</p>



<p>The key reality?<br>Most data generated by connected products is <strong>mixed — personal and non-personal at the same time</strong>. And that changes everything.</p>



<h3 class="wp-block-heading">Key takeaway:</h3>



<p>The Data Act creates obligations to <strong>share data</strong>, but the GDPR still governs <strong>how personal data can be processed and transferred</strong>. The Data Act never overrides GDPR requirements.</p>



<h3 class="wp-block-heading">What this means in practice:</h3>



<ul class="wp-block-list">
<li>No new legal basis for processing personal data under the Data Act</li>



<li>GDPR principles (minimization, purpose limitation, security) still fully apply</li>



<li>Trade secrets don’t automatically block access requests</li>



<li>Data portability rights are significantly expanded beyond GDPR scope</li>



<li>Cloud and IoT ecosystems will need major technical and contractual updates</li>
</ul>



<h3 class="wp-block-heading">The real challenge for businesses</h3>



<p>Compliance is no longer just legal — it’s operational and technical.</p>



<p>Organizations will need to:<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Map all product-generated data<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Identify where personal data is involved<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Update contracts and data-sharing frameworks<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Build secure, auditable data access systems<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Align legal, IT, and compliance teams</p>



<h3 class="wp-block-heading">Bottom line:</h3>



<p>The Data Act doesn’t replace the GDPR — it adds a new layer of complexity on top of it. Companies that prepare early will not only reduce compliance risk but also gain a competitive advantage in the emerging EU data economy.</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>National Healthcare and the processing of personal data by means of AI</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 12 Nov 2025 10:22:53 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[National Health Fund]]></category>
		<category><![CDATA[National Healthcare]]></category>
		<category><![CDATA[nfz]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[processing of personal data]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8478</guid>

					<description><![CDATA[<p>Publication date: November 12, 2025 Artificial intelligence (AI) is currently finding widespread use in healthcare. A prime example is the Polish National Health Fund (NFZ) initiative, which utilizes AI to analyze patient data stored in the Fund&#8217;s databases. This data is then analyzed with the support of machine learning tools to make strategic decisions regarding [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/">National Healthcare and the processing of personal data by means of AI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: November 12, 2025</mark></strong></p>



<p>Artificial intelligence (AI) is currently finding widespread use in healthcare. A prime example is the Polish National Health Fund (NFZ) initiative, which utilizes AI to analyze patient data stored in the Fund&#8217;s databases. This data is then analyzed with the support of machine learning tools to make strategic decisions regarding the health of Poles. This approach will certainly simplify the work of doctors by searching for and analyzing the desired information, undoubtedly reducing their workload. However, such a solution may raise several issues and legal requirements related to regulations regarding the protection and processing of personal data.</p>



<span id="more-8478"></span>



<h2 class="wp-block-heading"><strong>What is personal data?</strong></h2>



<p>The most common definition of personal data is contained in the EU Regulation 2016/679 (GDPR), according to which personal data is any information about an identified or identifiable natural person. This includes direct identification (e.g., name and surname) or certain factors allowing indirect identification (e.g., job description or nationality). This concept is expanded by the Polish Act on the Protection of Personal Data Processed in Connection with the Prevention and Combating of Crime of December 14, 2018, by applying it directly to health. Health data here means personal data relating to the physical or mental health of an individual, including data on the use of healthcare services that reveal information about their health.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Patients&#8217; rights</strong></p>



<p>A number of patient rights are listed in the EU Regulation 2025/327 (Regulation on the European Health Data Space). The fundamental right is the right of individuals to access their electronically collected data (especially &#8220;priority data,&#8221; e.g., electronic prescriptions or imaging test results), which should be granted immediately after data is registered in the system. Individuals can also add their own information to their data already visible in the system and correct it. Furthermore, patients can grant access or request the transfer of their data to another provider. Access to healthcare professionals can also be restricted (however, in such cases, the patient should also be informed of the potential impact of such action on the quality of care provided). In this case, institutions collecting patient data should be aware of these rights, because if they are not respected, the patient could file a complaint (provided, however, that the rights or interests of the individual are adversely affected) and demand appropriate compensation.</p>



<p>The EU GDPR also provides similar rights, which additionally provides for one crucial privilege: the right to object. According to this regulation, an individual may object at any time to the processing of their data, including in connection with the performance of healthcare tasks, for reasons relating to their particular situation. In such a case, the data may no longer be processed unless the controller demonstrates compelling and legitimate grounds for further processing. Under the regulation, a patient could also request the deletion of their personal data if, for example, they are no longer necessary for the purpose for which they were collected or if they were processed unlawfully. Furthermore, the regulation also provides for the possibility of imposing an administrative fine of up to €20 million for a controller&#8217;s violation of guaranteed rights. Furthermore, Article 79 of the GDPR grants the right to an effective judicial remedy if the individual (patient) believes that the processing of their personal data violated the law.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Obligations of entities storing and processing data</strong></p>



<p>Pursuant to Article 24 of the GDPR, the data controller is obligated to implement appropriate technical and organizational measures to ensure data processing is carried out in compliance with legal provisions and the rights and freedoms of others. The controller must also review and update these measures as necessary. In the case of <strong><u>AI-based patient data processing</u></strong>, the obligation specified in this article to design the measures described above is also crucial, ensuring that only information necessary to protect the patient&#8217;s life and health is processed by default. In the event of a personal data breach, the controller should (within 72 hours of becoming aware of the breach) notify the relevant supervisory authority of the personal data breach. However, the controller is not obligated to do so if the likelihood of a breach affecting the rights and freedoms of natural persons is low. If the risk of a breach is high, the controller should also notify the affected individual. Furthermore, before processing begins, even using new technologies (including AI), if it may result in a high future risk to the rights and freedoms of natural persons, it will be necessary to assess the impact of the planned processing on personal data protection. If such an assessment indeed reveals a high risk, and if the controller fails to implement any measures to mitigate it, the controller must contact the relevant supervisory authority (in Poland, the President of the Personal Data Protection Office [President of the UODO]), which then provides the controller with a written recommendation and may also temporarily restrict or prohibit processing or issue a warning to the controller. General obligations, according to which personal data must be processed lawfully and fairly, in a transparent manner, and limited to what is necessary for the purposes for which they are processed, are also important.</p>



<p>In this situation, Regulation 2024/1689 (&#8220;AI Act&#8221;) also provides an interesting requirement. According to Article 4 thereof, healthcare entities using AI systems to make strategic decisions about patients are responsible for maintaining an appropriate level of AI competence among their staff, taking into account the purpose of using the system and the persons for whom the systems are to be used.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Requirements for the AI systems themselves</strong></p>



<p>The basic requirements that AI systems used for data processing would have to meet are set out in the aforementioned AI Act. This document explicitly classifies AI systems as &#8220;high-risk systems&#8221;, and therefore, the requirements set out in the act apply to them. Primarily, this requires maintaining appropriate documentation for the system: technical documentation regarding the quality management system (including data acquisition, collection, analysis, and labeling) and an EU declaration of conformity confirming the system&#8217;s compliance with the requirements set out in the regulation. Furthermore, this documentation should be kept at the disposal of the competent national authorities for 10 years after the system&#8217;s commissioning. Such systems should also meet transparency requirements, meaning they should be designed to facilitate proper use and interpretation of their actions (they should also have clear operating instructions). They must also have an appropriate oversight system that allows for human oversight of the AI if necessary, especially if its operation were to get out of control and harm others. Finally, AI systems are also subject to certain formal requirements, such as undergoing a pre-market conformity assessment and registering in a dedicated EU database for high-risk AI systems. It is also important to remember that high-risk AI systems are subject to general CE marking regulations. Once placed on the market, suppliers are required to establish a post-market monitoring system for AI systems to ensure their legal compliance.</p>



<p><strong><u>The issue of non-personal data</u></strong></p>



<p>It is also worth raising the issue of non-personal data, for example, in the context of a situation where a hospital, in order to decide on the appropriate medication for a patient, requests information about certain medications from a pharmacy. A public sector body may request such information only to the extent that the lack of this data would prevent it from performing its public interest tasks or when the body has no other available means of obtaining such data. A request for this purpose should be submitted (specifying, in particular, the purpose for which the information is requested). However, the data subject who received it may refuse to provide it if they have no control over the requested information or if a similar request for the same purpose has already been submitted by another public sector body. Once the requested information is in the possession of the requester, they must not use it in a manner inconsistent with the purpose for which the data was provided. They must ensure measures to protect its confidentiality or integrity, and they must delete the data as soon as it is no longer needed for the specified purpose. They are also prohibited from using the information obtained to improve a competitive product or from disclosing any information in this regard to third parties. It is also important to bear in mind the right of a public sector body to share the data received with individuals or organisations for the purposes of scientific research or analyses consistent with the purpose for which the data was requested, or with national statistical offices (e.g. the Central Statistical Office). It is important here that these organisations do not have a commercial nature or are not related to entities that do.</p>



<p><strong><u>The status in Poland</u></strong></p>



<p>As mentioned above, Poland has established a special supervisory authority for personal data protection, the President of the Personal Data Protection Office (UODO), acting with the assistance of the Office for Personal Data Protection. Among other things, this authority is responsible for consultations on data processing that poses a significant risk of violating the rights of others. It also conducts proceedings in cases of violations of personal data protection regulations and establishes a plan for monitoring compliance with these regulations.</p>



<p>It is also worth remembering the regulations of the Polish Act on Patients&#8217; Rights and the Patient Ombudsman. It stipulates that patients have the right to access medical records concerning their health and the services provided to them. The entity storing this documentation is obligated to disclose the data contained therein only to the patient themselves or an authorized person (or, for example, to a university or research institute for scientific purposes, but without any data allowing for the identification of the individual). Furthermore, the entity providing services is obligated to retain medical records only for a specified period (generally 20 years), after which they should be destroyed in a way that prevents the identification of the patient to whom they pertained. The Act on the Healthcare Information System also limits access to these records to medical professionals and physicians.</p>



<p>Also important are the provisions of the Act on the computerization of the activities of entities carrying out public activities, under which an entity maintaining a public register (i.e. any type of records used to carry out public tasks based on the relevant provisions) should provide another public entity with access to the data in its possession to the extent necessary to carry out public tasks.</p>



<p>It is also important to remember the Polish Code of Medical Ethics, which, in Article 14, requires physicians to inform patients about the benefits and risks associated with proposed diagnostic procedures and, where appropriate, about the possibility of using other methods. Furthermore, according to Article 12, the use of AI in treatment may only occur after the following conditions are met: informing the patient that artificial intelligence will be used in the diagnosis or therapeutic process; obtaining the patient&#8217;s informed consent to the use of artificial intelligence in the diagnostic or therapeutic process; and using AI algorithms that are approved for medical use and have the appropriate certifications. However, the final decision always rests with the physician.</p>



<p>A government draft legislation is currently being prepared, which will be designed to adapt the national legal system to the requirements imposed by the AI Act. The government&#8217;s proposals primarily envisage the establishment of the Artificial Intelligence Development and Security Commission, which will oversee the AI market within the scope specified in Article 2 of Regulation 2024/1689. The second main body will be the President of the Personal Data Protection Office (UODO) that will oversee high-risk AI systems, including those related to healthcare.</p>



<p><strong><u>Summary</u></strong></p>



<p>Processing personal data for healthcare purposes, additionally supported by artificial intelligence, is undoubtedly a convenient and practical solution, but it is associated with a number of legal obligations intended to ensure the security of the data used (e.g., using the acquired data only for a strictly defined purpose), the security of patients themselves (e.g., the obligation to inform the patient of the intention to use artificial intelligence in the treatment process), or simply related to formalities (e.g., the requirement to register the artificial intelligence system in an EU database). Currently, EU regulations are much more detailed in this matter.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/">National Healthcare and the processing of personal data by means of AI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
