<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LegalTech - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/legaltech/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/legaltech/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 10 Jul 2026 11:29:20 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:29:19 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic decision-making]]></category>
		<category><![CDATA[algorithmic transparency]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[automated moderation]]></category>
		<category><![CDATA[Central Eastern Europe legal services]]></category>
		<category><![CDATA[compliance by design]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[consumer reviews verification]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital platforms]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[e-commerce regulation]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[fake reviews]]></category>
		<category><![CDATA[fake reviews in e-commerce]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[international legal cooperation]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[marketplace regulation]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[online consumer protection]]></category>
		<category><![CDATA[online marketplaces]]></category>
		<category><![CDATA[online reputation management]]></category>
		<category><![CDATA[platform liability]]></category>
		<category><![CDATA[Poland technology law]]></category>
		<category><![CDATA[Polish e-commerce law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[review authenticity]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[unfair commercial practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8830</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 10, 2026</mark></strong></p>



<p>The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer experience, misleads the recipient, directly influencing their decision-making process. Legally, a fake review is considered not only a completely false message, but also one that, by omitting important facts or manipulating context, creates a false impression of the quality of a product or the reliability of a seller. This practice is classified as unfair commercial activity if its nature causes or is likely to cause the average consumer to make a transactional decision they would not otherwise make, thus violating the fundamental principles of fair dealing.</p>



<span id="more-8830"></span>



<p>The typology of activities considered unfair rests on several fundamental pillars, the most blatant of which is direct fabrication. This involves posting or commissioning the creation of false recommendations from specialized external entities, such as marketing agencies, which directly violates regulations on combating unfair market practices. Another mechanism is selective manipulation, in which a business intentionally manages the visibility of reviews by removing, concealing, or delaying the publication of negative reviews while favoring positive ones. Such action distorts the image of actual customer satisfaction and is considered misleading regarding the essential characteristics of a product or service. An equally significant aspect is feigned verification, i.e., declaring that reviews come from real buyers without implementing proportionate and reasonable steps to verify their authenticity, which constitutes a direct violation of the disclosure obligations imposed by the Omnibus Directive.</p>



<p>Contemporary market practices have also evolved more subtle forms of manipulation, such as astroturfing, which involves creating artificial social support through employees or store owners posing as independent consumers. These activities often involve the manipulation of user profiles, where images generated by artificial intelligence algorithms are used to authenticate fictitious accounts, creating false social proof. Each of these practices, regardless of their technological sophistication, is subject to strict scrutiny by competition and consumer protection authorities.</p>



<p><strong>The role of the President of the Office of Competition and Consumer Protection and the responsibility of management boards</strong></p>



<p>The President of the Polish Office of Competition and Consumer Protection (UOKiK) serves as a central regulator in the legal system, endowed with rigorous powers to counteract violations of collective consumer interests. The main disciplinary instrument at the authority&#8217;s disposal is an administrative fine, which can be imposed in the amount of 10% of the turnover achieved by the entrepreneur in the financial year preceding the year of issuance of the decision. The amount of the fine is not determined arbitrarily, but rather results from precisely defined criteria, which include, above all, the scale of the violation, its duration, and the degree of intentionality of the perpetrator. Importantly, this fine is intended to serve not only a repressive function but, above all, a preventive and deterrent one, discouraging other market participants from engaging in similar unfair practices involving the manipulation of reviews or misleading as to the authenticity of reviews.</p>



<p>The enforcement procedure in consumer matters is designed to ensure high effectiveness of supervisory activities. A business subject to a sanction is obligated to settle the fine within 14 days of the decision becoming final, which directly contributes to the state budget. A crucial procedural element is the prejudicial nature of the decisions of the President of the Office of Competition and Consumer Protection (UOKiK), which means that the authority&#8217;s findings regarding violations of the law are binding on common courts in compensation cases brought by injured customers. This legal structure significantly facilitates consumers in pursuing civil claims, as they do not have to prove the illegality of the store&#8217;s actions, focusing solely on demonstrating the damage suffered. The office&#8217;s activity in recent years, reflected in numerous proceedings against e-commerce leaders, confirms that protecting the transparency of reviews has become a regulatory priority, translating into real and severe financial consequences for violators.</p>



<p>The contemporary model of liability in consumer protection law departs from a concept focused solely on the business entity, shifting the burden of sanctions also to individuals who actually manage the enterprise. The President of the Office of Competition and Consumer Protection (UOKiK) has the authority to impose a personal fine of up to PLN 2,000,000 on a manager. This liability is triggered by demonstrating that the manager has intentionally allowed – through their actions or conscious omissions – the company to violate collective consumer interests. In case law, the degree of management involvement in decision-making processes regarding marketing and communications is crucial. This liability may therefore affect a management board member who approves a budget for obtaining reviews from external opinion farms or ignores the lack of implementation of verification procedures under the Omnibus Directive, despite being aware of such deficiencies.</p>



<p>It should be emphasized that the responsibility of managers is autonomous and independent of any penalty imposed directly on the entrepreneur. This is intended to provide a strong incentive for management to build internal compliance structures and actively oversee the entity&#8217;s operational ethics. In the era of digitalization of trade, where algorithms and automation of marketing processes can generate violations on a massive scale, the personal financial risk of managers is intended to compel prioritizing compliance as the foundation of business strategy. Therefore, the systemic fight against false reviews is implemented not only through sanctions against corporate structures but also by disciplining those who actually shape companies&#8217; market policies. This, according to the legislature, is intended to ensure long-term improvement in integrity standards in electronic trading.</p>



<p><strong>The Omnibus Directive and the blacklist of market practices</strong></p>



<p>The implementation of the Omnibus Directive into the Polish legal system significantly redefined transparency standards in e-commerce, introducing mechanisms that directly address the systemic manipulation of consumer reviews. A key instrument in this regard is the so-called blacklist of market practices, which constitutes a catalog of behaviors considered unfair in all circumstances, eliminating the need for supervisory authorities to conduct a case-by-case analysis of the consequences of a given action. Classifying these market torts as unfair practices aims to eliminate evidentiary difficulties, as their mere existence exaggerates the entrepreneur&#8217;s wrongdoing. This legal framework not only strengthens the consumer&#8217;s position but, above all, simplifies the evidentiary process, making the fight against e-commerce abuse more effective and predictable for market participants. The foundation of the new regulations is an absolute prohibition on manipulating the verification and authenticity of product recommendations, which imposes an active obligation on sellers to implement procedures to verify the origin of reviews.</p>



<p>Under the current wording of the regulations, it is considered an unfair market practice for a trader to claim that product reviews were posted by consumers who actually used or purchased the product, in situations where reasonable and proportionate steps were not taken to verify their authenticity. This practice violates the consumer&#8217;s right to reliable information, which is essential for making an informed decision about purchasing the product, and violating it constitutes conduct contrary to good practice. The law prohibits not only posting completely false reviews, but also commissioning third parties to create them, or transferring recommendations between products with different parameters, which is referred to as review hijacking. Other offenses listed in the catalog are treated equally severely, such as using false quality certificates without appropriate authorization or using surreptitious advertising, which involves using editorial content to promote a product without clearly identifying the paid nature of the communication. Aggressive techniques are also considered particularly burdensome, including mass spamming and forced selling, which involves demanding payment for products delivered to the consumer without their prior order.</p>



<p>The blacklist also eliminates techniques <strong>such as bait advertising and direct persuasion of children to purchase</strong>, which aims to protect the integrity of the consumer decision-making process from manipulation. This protection of minors stems from their particular vulnerability to advertising messages and their inability to critically assess the persuasive nature of commercial offers. Expanding the list to include a ban on posting or commissioning another person to post false reviews for the purpose of promoting products significantly complements the system, preventing brands from using agencies that fabricate social evidence. It is emphasized that any form of distortion of the actual image of a product&#8217;s popularity constitutes a violation of the collective interests of consumers, which entitles the President of the Office of Competition and Consumer Protection (UOKiK) to intervene under public law as soon as a threat to the interests of all market users arises.</p>



<p>A particularly significant and painful consequence of these unfair techniques for entrepreneurs is a specific civil law sanction in the form of an extended right of withdrawal from the contract. If an e-store engages in practices listed in the prohibited catalog or fails to comply with information obligations regarding review verification, the statutory return period granted to the buyers is extended from 14 days to a full 12 months. This mechanism is a direct consequence of the assumption that, in the absence of reliable information, the consumer could not have expressed a fully informed intention to purchase, which suspends the running of standard mandatory deadlines. Systematic combating of review fraud and the use of black market practices is therefore becoming not only a matter of business ethics but the foundation of legal security and stability for every entity operating in the e-commerce sector. Neglect in transparency can lead to mass claims for refunds, posing a real threat to the operational liquidity of the company.</p>



<p><strong>Manipulation Architecture and Platform Obligations under the Digital Services Act (DSA)</strong></p>



<p>The phenomenon known as dark patterns constitutes a sophisticated form of interference in the user&#8217;s decision-making process, based on the deliberate use of interface architecture to distort their autonomy of will. Manipulative design patterns are not merely a manifestation of aggressive marketing, but a systematic designer&#8217;s action aimed at inducing a specific cognitive bias in the consumer, which ultimately leads to a purchase decision they would not have made in conditions of full transparency. The psychological foundation of these actions is the use of heuristics, i.e., simplified rules of reasoning and automatic thinking, which in the fast-paced environment of e-commerce transactions make the user susceptible to subliminal suggestions. This phenomenon has evolved from simple forms of persuasion to advanced interface manipulation, where the line between inducement and fraud is deliberately blurred to maximize conversion at the expense of the interests of the weaker party in the legal relationship.</p>



<p>A particularly significant area of application of these practices is the system for <strong>presenting reviews and suggesting their authenticity</strong>, where manipulation takes the form of so-called interface interference. Businesses often employ patterns involving selective content display, which in practice means deliberately hiding negative reviews on subsequent pages of the website while simultaneously highlighting only enthusiastic reviews on the product&#8217;s home page. This practice violates the model of the average consumer, who has the right to expect that the image presented of a product&#8217;s popularity and quality is reliable and has not been subjected to arbitrary filtering. Manipulation in the sphere of social evidence also includes fabricating popularity indicators, such as false messages about the number of people viewing a given product at a given time or false offer duration counters, which create an artificial sense of scarcity in the user and pressure them to immediately close the transaction. Under the Polish Act on Combating Unfair Market Practices, these activities may be classified as misleading because they distort the actual market conditions, preventing a rational comparison of offers.</p>



<p>Another dimension of manipulation is the technique known as confirmation shaming, which in the sphere of opinion writing involves the use of evaluative and emotional language to coerce users into specific behaviors, for example, through unsubscribe buttons suggesting a lack of consumer awareness. These practices are closely related to the &#8220;<strong>roach motel model</strong>”, where the process of issuing a favorable review is simplified to the maximum extent, while editing, reporting an error, or deleting content requires navigating a complex subpage structure, which is intended to discourage users from correcting false information. In the legal context, such procedural barriers are considered burdensome impediments that violate good practice and the principle of commercial fairness. An analysis of case law and the positions of supervisory authorities indicates that an interface that deliberately hinders users from exercising their rights or changing their minds loses its neutrality and becomes a tool for harming consumer interests.</p>



<p>A fundamental change in the regulatory sphere was brought about by the entry into force of the <strong>EU Digital Services Act (DSA), which, in Article 25, explicitly prohibits online platform providers from designing, organizing, and operating interfaces in a way that misleads or manipulates service users</strong>. This regulation is overarching and complements the existing consumer protection framework by introducing a direct obligation to maintain neutrality in choice architecture and prohibiting structures that significantly impede users&#8217; ability to make free and informed decisions. Violation of this prohibition entails not only civil law risks but also severe administrative sanctions, which can amount to a significant percentage of the business&#8217;s global turnover.</p>



<p>In the sphere of law enforcement, the key role is played by the model design of the average consumer, who is observant and cautious but lacks specialized knowledge of the psychological mechanisms used in interface design. This protection is preventative and abstract in nature, meaning the President of the Office of Competition and Consumer Protection (UOKiK) can intervene in situations where the mere existence of a manipulative pattern poses a real risk of distorting market behavior, without having to wait for measurable financial damage to a specific individual. Effectively combating dark patterns requires businesses not only to comply with the law but, above all, to shift to a design model focused on reliability, where all product information, including opinions, is presented free from coercive mechanisms. Ultimately, interface transparency is becoming a prerequisite for maintaining trust in the digital economy, and the use of sophisticated forms of manipulation is perceived as highly harmful to society, subject to strict assessment in light of the principles of social coexistence.</p>



<p><strong>New obligations for marketplaces regarding moderation and transparency</strong></p>



<p>The entry into force of Regulation 2022/2065, known as the Digital Services Act (DSA), represents a fundamental shift in the liability paradigm for intermediary service providers, particularly marketplaces. This regulation shifts the emphasis from passive content hosting to active oversight of the transparency and security of the digital system, introducing rigorous operational standards aimed at eliminating illegal content while respecting users&#8217; fundamental rights. A key pillar of this reform is the formalization of moderation processes, which until now were often subject to arbitrary internal platform decisions and are now subject to strict procedural rigors contained in the notice-and-action mechanism. Under the DSA, each platform is required to provide easily accessible and user-friendly tools for identifying potentially illegal content, including fake reviews or infringing offers. The mere receipt of a report obliges the provider to promptly and objectively address it.</p>



<p>The evolution of moderation obligations is inextricably linked to the <strong>requirement for transparency in decisions</strong>, which is achieved through the justification mechanism provided for in the EU regulation. When a marketplace decides to remove content, limit its visibility, or suspend a user&#8217;s account, the user is absolutely obligated to provide clear and specific reasons for such action, which is intended to prevent abuse by blocking reliable reviews that are unfavorable to the seller. This system is complemented by a<strong> mandatory internal complaint handling system</strong>, which allows users to appeal moderation decisions free of charge within a period of at least six months. <strong>This constitutes an important procedural guarantee and allows for the correction of potential algorithmic errors</strong>. It is indicated that such a legal framework is necessary to counteract the fragmentation of consumer protection, which previously relied primarily on general national clauses that were unsuitable for the scale of operations of global digital entities.</p>



<p>A significant innovation introduced specifically for trading platforms is the &#8220;Know Your Business Customer&#8221; (KYBC) principle, regulated in the chapter on marketplace transparency. These entities are charged with collecting and verifying information about traders offering their products through their interfaces, including registration data, payment account numbers, and declarations of commitment to offer goods in compliance with EU law. This mechanism aims to eliminate the phenomenon of anonymous sellers, who often promote defective products using fabricated reviews and, after raising capital, disappear from the market, avoiding legal liability. The platform is obligated to suspend services for sellers who fail to submit the required documents, making the marketplace an active guardian of the legality of trade, rather than merely a passive intermediary in trade.</p>



<p>The scope of transparency obligations extends beyond relationships with individual users to include public reporting through the periodic publication of transparency reports. These documents must include detailed data on the number of orders received from national authorities, statistics on content moderation initiated by the platform itself, and information on the use of automated tools in verification processes. For very large online platforms, these rigors are even stricter, including the obligation to conduct annual audits and systemic risk assessments, including analysis of the interface&#8217;s vulnerability to manipulation that could negatively impact public safety or consumer protection. The systemic fight against disinformation and unfair market practices is therefore anchored in the full transparency of operational processes, which allows supervisory authorities to continuously monitor the effectiveness of implemented security measures.</p>



<p>Supervision of compliance with these obligations is based on a new institutional architecture, in which national digital services coordinators, working closely with the European Commission, play a central role. The enforcement system for the adopted regulations is based on fines of up to 6% of a provider&#8217;s global turnover, which compels compliance with specific cybersecurity standards. This control system is designed to ensure that marketplaces not only implement the required procedures but also apply them reliably and uniformly across the European Union, which is crucial for building consumer confidence in cross-border trade. The introduction of these standards ends the phase of full regulatory freedom for platforms, imposing on them real responsibility for shaping the environment in which the modern exchange of goods and services takes place.</p>



<h2 class="wp-block-heading"><strong>Technological verification mechanisms and modern operating models</strong></h2>



<p><strong>Authenticity Suggestion and Pressure Mechanisms</strong></p>



<p>The evolution of digital market oversight has led to the development of mechanisms in which traditional legal instruments are increasingly being replaced by algorithmic jurisdictions based on advanced artificial intelligence systems. The phenomenon known as AI exclusion is a modern form of sanction that, for e-commerce entities, can prove more severe than traditional financial penalties imposed by administrative bodies. The foundation of this process is the integration of data on the credibility of reviews directly with positioning parameters in ranking systems, which means that transparency is no longer merely an ethical obligation but a condition for the technical visibility of an offer. Recommendation algorithms operating within platforms such as Google and Amazon constantly analyze behavioral and linguistic patterns to identify anomalies suggesting manipulation of social evidence. These systems are currently capable of recognizing the structure of texts generated by LLM language models, which are characterized by a specific repetition of phrases and a lack of emotional details typical of authentic consumer experiences. An additional risk factor subject to automatic verification is the so-called review growth rate, where a sudden jump in the number of positive ratings without correlation with actual website traffic or sales volume is interpreted by AI as a warning signal initiating restrictive procedures.</p>



<p>The consequences of an online store being classified by AI systems as posing a high risk of manipulation are immediate and often irreversible in the short term. This mechanism, known in market practice as <strong>shadow banning or de-indexing</strong>, leads to a drastic decline in visibility in search results and the blocking of offers in advertising systems, effectively cutting the entrepreneur off from key customer acquisition channels. Under the provisions of the Digital Services Act, providers of very large online platforms are required to maintain particular transparency regarding the parameters used in recommendation systems. Article 27 of the aforementioned regulation requires platforms to clearly define in their regulations the key parameters determining information ranking, which aims to limit <strong>algorithmic arbitrage</strong> and enable entrepreneurs to understand the reasons for a potential decline in their market exposure. It is worth noting that modern risk assessment systems may be classified as high-risk systems within the meaning of the Artificial Intelligence Regulation, which imposes strict requirements on their creators regarding human oversight and the prevention of <strong>algorithmic discrimination</strong>.</p>



<p>In parallel to restrictive systems, a paradigm known as agentic commerce is developing, in which purchasing processes are carried out by autonomous AI assistants acting directly on behalf of the consumer. In this model, traditional product reviews cease to serve as persuasive texts for humans and become raw input data for machines that filter the market in search of offers with the highest level of verified trust. A key element of this new commerce architecture is the so-called trust layer, built on protocols such as the Universal Commerce Protocol promoted by Google or the Agentic Commerce Protocol developed by OpenAI. These systems are guided not only by price or availability of goods but above all by the certified credibility of the seller&#8217;s data, automatically rejecting offers from entities that lack a clear digital traceability of their recommendations. The collaboration of AI assistants with secure payment systems, such as the Agent Payments Protocol, creates a closed ecosystem in which offers at risk of manipulation are excluded at the initial algorithmic selection stage, before they are even presented to the user.</p>



<p>In the era of agent-based commerce, the role of modern shopping assistants is becoming dominant, forcing businesses to redefine their credibility-building strategies. The Context Protocol model and other open-source solutions enable the exchange of context between various AI models and commerce systems, allowing information about unfair practices by a single store to be instantly shared across the entire assistant network. The doctrine suggests that this systematic approach to eliminating abuse is a natural response to the technological ease of fabricating content online. For an e-commerce store, losing its trustworthy status in the eyes of Google or OpenAI algorithms means the modern equivalent of server shutdown, as AI assistants, protecting the interests of their users, will systematically bypass offers that generate manipulative signals. Thus, the fight for authenticity is no longer a mere compliance issue but an existential foundation in the new, automated e-commerce environment, where barriers to entry into the trust layer are becoming increasingly difficult for entities employing pressure mechanisms and suggesting false authenticity.</p>



<p><strong>Compliance as a Service and the Digital Feedback Path</strong></p>



<p>The rapid evolution of the e-commerce market and the increasing professionalization of unfair market practices have forced entrepreneurs to abandon a reactive reputation management model in favor of proactively building a digital immune system. The scale of the challenge facing modern e-commerce is illustrated by analyses of the systematic erosion of trust in the digital sector, pointing to the prevalence of fake reviews and consumer concerns about the mass implementation of generative artificial intelligence for opinion fabrication. This state of affairs creates decision paralysis, where an overabundance of unreliable information, instead of supporting the purchasing process, becomes an insurmountable barrier.</p>



<p>The economic impact of the lack of reliable content verification is directly measurable and translates into tangible operational losses for businesses. The literature emphasizes that exposure to manipulated reviews drastically reduces purchase intentions and brand trust, generating measurable financial losses. The information vacuum filled with false enthusiasm also leads to a phenomenon known as post-purchase dissonance, in which a product that fails to meet expectations is returned to the seller as a complaint or contract withdrawal. Consequently, the lack of investment in transparent review processes generates hidden logistical and operational costs that, in the long run, may outweigh the gains achieved through the temporary increase in conversions driven by manipulation.</p>



<p>In response to increasing regulatory rigor, including the Omnibus Directive, the Digital Services Act (DSA), and the AI Act framework, an operational model known as <strong>Compliance as a Service (CaaS)</strong> has emerged in market practice. It involves fully outsourcing compliance processes to specialized technology providers who take over the burden of monitoring and verifying content in accordance with current regulations. CaaS allows for the automation of data oversight, which is essential in an environment where the volume of incoming reviews precludes manual oversight without risking accusations of disproportionality. In this approach, compliance ceases to be merely an administrative cost and becomes a component of a strategy for building brand value by guaranteeing the authenticity of every customer touchpoint.</p>



<p>The foundation of the Compliance as a Service model is the maintenance of clean data and the generation of an indisputable digital trace of the review&#8217;s provenance. Every published review should be accompanied by a log containing metadata regarding the specific transaction, a unique order number, and delivery status, creating auditable proof of authenticity that can be presented during inspections by supervisory authorities such as the President of the Office of Competition and Consumer Protection. This digital reconstruction of the review process provides the most effective legal shield for businesses, eliminating the risk of allegations of unfair market practices. In the era of algorithmic jurisdiction, where ranking systems favor content supported by digital evidence, having a certified trace of data provenance is becoming a prerequisite for maintaining the market visibility of an offer.</p>



<p>Parallel to technical verification, modern review management systems integrate mediation mechanisms that allow for the amicable resolution of disputes before they are publicly expressed. Market experience suggests that implementing structured review processes allows for the amicable resolution of a significant portion of consumer disputes, effectively preventing the publication of negative reviews resulting from logistical errors. This approach aligns with the principles of reliability and good market practices, building customer relationships based on dialogue rather than solely on the one-way transmission of ratings.</p>



<p>Transaction verification is now becoming the market standard, replacing open, abuse-prone review sections with a system of unique invitations sent only after a purchase is completed. The literature emphasizes that restricting the review process to those who actually purchased the product is the simplest and most effective way to comply with the obligations imposed by the Omnibus Directive. This not only minimizes the risk of severe financial penalties, but above all, provides AI shopping assistants with reliable input data, which, in the new agent-based commerce paradigm, will determine the viability of each entity in the e-commerce ecosystem.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 17:54:28 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[3D Scanning]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in Defence]]></category>
		<category><![CDATA[Armed Forces]]></category>
		<category><![CDATA[Arms Trade]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[ASAP]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[B2G]]></category>
		<category><![CDATA[Civil Defence]]></category>
		<category><![CDATA[Classified Information]]></category>
		<category><![CDATA[Crisis Preparedness]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Defence Conference]]></category>
		<category><![CDATA[Defence Expo]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[Defence IP]]></category>
		<category><![CDATA[Defence Procurement]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Defense Expo]]></category>
		<category><![CDATA[Defense Industry]]></category>
		<category><![CDATA[Defense Tech]]></category>
		<category><![CDATA[Drones]]></category>
		<category><![CDATA[Dual Use Technology]]></category>
		<category><![CDATA[EDF]]></category>
		<category><![CDATA[Emergency Preparedness]]></category>
		<category><![CDATA[European Defence Fund]]></category>
		<category><![CDATA[EXPO XXI]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[Firearms Law]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[Infrastructure Protection]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[Military Innovation]]></category>
		<category><![CDATA[Military Modernization]]></category>
		<category><![CDATA[Military Technology]]></category>
		<category><![CDATA[Mini MSPO]]></category>
		<category><![CDATA[MON RP]]></category>
		<category><![CDATA[MSWiA]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Personal Protective Equipment]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish Armed Forces]]></category>
		<category><![CDATA[Polish Defence Industry]]></category>
		<category><![CDATA[Public Procurement]]></category>
		<category><![CDATA[Range Safety]]></category>
		<category><![CDATA[Resilience]]></category>
		<category><![CDATA[Security Conference]]></category>
		<category><![CDATA[Shooting Sports]]></category>
		<category><![CDATA[Sport Shooting]]></category>
		<category><![CDATA[State Resilience]]></category>
		<category><![CDATA[Tactical Communications]]></category>
		<category><![CDATA[Territorial Defence]]></category>
		<category><![CDATA[UAV]]></category>
		<category><![CDATA[Unmanned Systems]]></category>
		<category><![CDATA[WARSAW]]></category>
		<category><![CDATA[Warsaw Defence Expo]]></category>
		<category><![CDATA[Warszawa]]></category>
		<category><![CDATA[Warszawskie Targi Obronne]]></category>
		<category><![CDATA[Weapons Permits]]></category>
		<category><![CDATA[WOT]]></category>
		<category><![CDATA[WTO2026]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8803</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 – the first edition of a new nationwide event dedicated to the defence, security and resilience of the state On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-1 wp-block-group-is-layout-flex">
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>


</div>



<h3 class="wp-block-heading">– the first edition of a new nationwide event dedicated to the defence, security and resilience of the state</h3>



<p id="ember53">On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. This is the first edition of a completely new trade fair and conference event, created in response to the growing importance of the defense sector, national security, and technologies supporting Poland&#8217;s institutional, economic, and social resilience. The fair is held under the honorary patronage of the Ministry of Interior and Administration and the Minister of National Defense. The event is informally referred to as a &#8220;mini-MSPO in Warsaw&#8221; – a capital city-based, intimate alternative to the September International Defense Industry Fair in Kielce, open not only to professionals but also – on the second day – to the general public.</p>



<span id="more-8803"></span>



<p id="ember54">The goal of the Warsaw Defense Fair is to integrate key groups responsible for national security and to create a space for dialogue, collaboration, and exchange of experiences between public administration, the military, uniformed services, the defense industry, the technology sector, the investor community, and military universities. The event combines exhibition, conference, and networking elements , creating a platform for showcasing modern technologies, exchanging expert knowledge, and building business relationships in one of the fastest-growing sectors of the Polish economy.</p>



<p id="ember55">The trade fair program is divided into two complementary days, representing one of the most distinctive solutions adopted by the organizers. Friday, June 19, 2026, will be an industry day (B2B/B2G), intended exclusively for companies, institutions, and business partners. Industry registration is required. This day will be a platform for meetings and discussions between individuals and entities interested in establishing cooperation in the defense and security sector, including representatives of public administration and local governments, soldiers and uniformed services, representatives of companies in the defense and technology sectors, investors, industry advisors, and representatives of military universities. The program focuses on key challenges facing the defense and national security sectors, including conferences, panel discussions, and business and institutional meetings concerning the development of the Polish defense industry, modernization of the Armed Forces, public procurement in the defense sector, and cross-sectoral cooperation.</p>



<p id="ember56">Saturday, June 20, 2026, will be an open day (B2B/B2G/B2C), also open to the public interested in security, defense, and shooting. The second day significantly complements the industry portion and expands the event to include the general public, as well as educational and outreach communities. It will feature demonstrations of equipment and technologies in near-operational settings, demonstration zones by exhibitors and manufacturers, presentations of solutions in cybersecurity, drones, communications, and critical infrastructure protection, as well as numerous lectures for enthusiasts. Topics covered include firearms licenses – myths and legal realities, training and shooting sports, hearing and eye protection, safety and ergonomics at the shooting range, and civic preparedness for crisis situations.</p>



<h2 class="wp-block-heading" id="ember57">Exhibitors and thematic scope</h2>



<p id="ember58">Over 100 exhibitors will be present at the fair, representing a full cross-section of entities active in the Polish defense and security sector. Exhibitors include military units such as the 1st Warsaw Armored Brigade and the 18th Capital Territorial Defense Brigade, international technology companies, including 3M Poland, which presents personal protection solutions for the defense sector, and Artec 3D with 3D scanners used in military applications. The shooting and equipment segment will be strongly represented, with companies such as House of Guns , Hubertus Pro Hunting , Kaliber, 4HUNTING, Kolba, 4SHOOTER, Son of Gun , Jammas , and Wolfer. Group and Works11. The event is also partnered by the Legia Warsaw Central Military Sports Club – Shooting Section.</p>



<p id="ember59">The exhibition covers cutting-edge weapons, equipment, facilities and technologies used in the defense and security sector: unmanned systems and drones, cybersecurity solutions, tactical communications and communication technologies, critical infrastructure protection, personal protective equipment, 3D scanning and simulation technologies, individual soldier equipment, as well as solutions in the area of civil defense and population protection.</p>



<h2 class="wp-block-heading" id="ember60">Three conference stages and a substantive agenda</h2>



<p id="ember61">The WTO 2026 program will unfold simultaneously across three conference stages. The industry day will be dedicated to the most important strategic challenges facing the defense sector – the technical modernization of the Polish Armed Forces, the development of the domestic arms industry, cooperation with foreign partners, public procurement in the defense sector, new dual-use technologies , and the role of the private sector in building national resilience. The second day, open to the public, will feature lectures and discussions covering a much broader range of topics – from legal issues concerning access to weapons and individual security, through shooting sports and defense training, to preparing society for crisis situations and disseminating knowledge about modern defense technologies.</p>



<p id="ember62">The significance of the event from a legal perspective</p>



<p id="ember63">The establishment of the Warsaw Defense Fair is part of the broader context of the dynamic development of the Polish defense sector, which in recent years has become one of the most important areas of public and private investment, generating significant demand for legal services. From the firm&#8217;s perspective, issues related to public procurement in the defense sector, regulations regarding trade in arms and dual-use technologies, export controls, protection of classified information, cybersecurity in the context of the NIS2 directive, intellectual property rights in defense technology projects, and financing of projects from European funds (including the European Defense Fund and ASAP), as well as the development of regulations regarding artificial intelligence in military applications in light of the European AI Act . The participation of representatives of the KG LEGAL KIEŁTYKA GŁADKOWSKI law firm in this event is a natural element of tracking the development of one of the fastest-growing sectors of the Polish economy and building competences in the area of law related to new defense technologies.</p>



<p id="ember64">The Warsaw Defense Fair 2026 demonstrates that security and defense are no longer the exclusive domain of the military and state administration. They have become an area of broad cross-sectoral cooperation, with technology companies, investors, academia, non-governmental organizations, and informed citizens playing key roles. The development of this sector today requires not only advanced technological competencies but also an appropriate legal, regulatory, and institutional environment.</p>



<p id="ember65">Link to the event: <a href="https://wto26.exposupport.pl/program">https://wto26.exposupport.pl/program</a></p>



<p id="ember66">#WarsawDefenceExpo #WTO2026 #WarszawskieTargiObronne #DefenceIndustry #DefenseIndustry #DefenceExpo #DefenseExpo #PolishDefenceIndustry #PolishArmedForces #NationalSecurity #StateResilience #CivilDefence #HomelandSecurity #DefenceTechnology #DefenseTech #MilitaryTechnology #MilitaryInnovation #DualUseTechnology #DefenceProcurement #PublicProcurement #ArmsTrade #ExportControl #ClassifiedInformation #CyberSecurity #NIS2 #CriticalInfrastructure #InfrastructureProtection #UnmannedSystems #Drones #UAV #TacticalCommunications #PersonalProtectiveEquipment #3DScanning #AIinDefence #AIAct #ArtificialIntelligence #EuropeanDefenceFund #EDF #ASAP #IntellectualProperty #DefenceIP #TerritorialDefence #WOT #ArmedForces #MilitaryModernization #SportShooting #FirearmsLaw #WeaponsPermits #ShootingSports #RangeSafety #CrisisPreparedness #EmergencyPreparedness #Resilience #B2B #B2G #EXPOXXI #Warsaw #Warszawa #Poland #MONRP #MSWiA #MiniMSPO #DefenceConference #SecurityConference #LegalTech #LawFirm #KGLegal #KieltykaGladkowski</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 13 May 2026 10:56:58 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DataAct]]></category>
		<category><![CDATA[DataGovernance]]></category>
		<category><![CDATA[DataPrivacy]]></category>
		<category><![CDATA[EUDataAct]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[RegTech]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8769</guid>

					<description><![CDATA[<p>Publication date: May 13, 2026 The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: May 13, 2026</strong></mark></p>



<p>The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act introduces a new legal regime designed to improve access to and use of data generated by connected products and related digital services.</p>



<span id="more-8769"></span>



<p>For businesses operating in the European Union, the key challenge is not understanding each regulation in isolation, but determining how they interact in practice. Many organizations already have mature GDPR compliance frameworks, but the Data Act creates additional obligations that require them to share data with users and third parties. Where those datasets contain personal data, compliance with the Data Act must be reconciled with the GDPR.</p>



<p>This article explains the relationship between the Data Act and the GDPR in practical terms. It highlights the main legal issues and outlines the steps businesses should take to prepare.</p>



<p><strong>What Is the Data Act?</strong></p>



<p>The Data Act, Regulation (EU) 2023/2854, is part of the European Union&#8217;s broader strategy to build a single market for data. Its purpose is to ensure that users of connected products and related services can access the data they generate and, in certain circumstances, require that such data be shared with third parties.</p>



<p>The regulation is intended to rebalance the relationship between manufacturers, service providers and users. In many industries, companies that design connected products control large volumes of data generated through use of those products. The Data Act seeks to ensure that users are able to benefit from this data rather than being locked into a single ecosystem.</p>



<p>The regulation applies to both personal and non-personal data, which is one of the key differences from the GDPR.</p>



<p>Examples of products and services covered by the Data Act include smart watches, connected vehicles, industrial machinery, medical devices, smart home appliances, agricultural equipment and software applications that process the data generated by such products.</p>



<p><strong>What Is the GDPR?</strong></p>



<p>The GDPR governs the processing of personal data relating to identified or identifiable natural persons. Its objective is to protect privacy and ensure that personal data is processed lawfully, fairly and transparently.</p>



<p>The GDPR applies whenever data relates to an individual and a controller or processor carries out an operation such as collecting, storing, sharing or analyzing that data.</p>



<p>Unlike the Data Act, the GDPR does not grant a broad right of access to all data generated by products. It focuses solely on personal data and establishes rights such as access, rectification, erasure and portability.</p>



<p><strong>The Relationship Between the Data Act and the GDPR</strong></p>



<p>The Data Act expressly states that it is without prejudice to EU and national laws on personal data protection, privacy and confidentiality of communications. In practical terms, this means that the Data Act does not override the GDPR. If a company is required to provide data under the Data Act and the dataset contains personal data, the GDPR continues to apply in full.</p>



<p>This principle has several important consequences.</p>



<p>First, the Data Act does not create a new legal basis for processing personal data. A company cannot rely on the Data Act alone to justify collecting, disclosing or otherwise processing personal data.</p>



<p>Second, organizations must continue to comply with all GDPR principles, including purpose limitation, data minimization, storage limitation and security.</p>



<p>Third, where there is a conflict between the two regulations, the GDPR prevails in relation to personal data.</p>



<p><strong>Why This Matters in Practice</strong></p>



<p>Most data generated by connected products is not purely personal or purely non-personal. Instead, businesses often deal with mixed datasets.</p>



<p>A connected vehicle, for example, may generate information on speed, fuel consumption, component performance, geolocation and driver behavior. Some of this information clearly relates to an identifiable person and therefore qualifies as personal data. Other elements may be technical or operational in nature.</p>



<p>Where personal and non-personal data are inextricably linked, organizations should assume that the GDPR applies to the dataset as a whole unless the data can be effectively separated.</p>



<p>This means that compliance with the Data Act often requires a GDPR analysis before any disclosure can take place.</p>



<p><strong>Practical Example: Smart Watch Data</strong></p>



<p>A consumer uses a smart watch that collects heart rate, sleep patterns, exercise metrics and location information. The consumer wishes to transfer the data to a third-party health application.</p>



<p>Under the Data Act, the user may request access to the data generated by the device and ask the manufacturer to transmit the data to another provider.</p>



<p>Because the dataset contains information relating to an identifiable person, the GDPR applies.</p>



<p>In this scenario, the manufacturer must verify that the request is valid, ensure the transmission is secure and process the data in accordance with the GDPR. The Data Act creates the obligation to provide the data, but the GDPR determines how the transfer must be carried out.</p>



<p><strong>Practical Example: Industrial Equipment</strong></p>



<p>A manufacturing company leases connected machinery that generates data concerning temperature, output, wear and maintenance cycles. The company wants to share this data with an independent maintenance provider.</p>



<p>The Data Act allows the user to request access to the data and to require the data holder to share it with a third party.</p>



<p>If the dataset contains no personal data, the GDPR may not apply.</p>



<p>However, if the data includes operator IDs or logs that can identify employees, GDPR considerations arise. The data holder must assess whether a lawful basis exists for sharing those elements.</p>



<p><strong>Key Roles Under the Data Act and the GDPR</strong></p>



<p>The terminology used by the two regulations differs, but the concepts often overlap. Under the Data Act, the principal roles are the data holder, the user and the data recipient. Under the GDPR, the key roles are the controller and processor. In practice, a data holder will often act as a controller because it determines the purposes and means of processing personal data. A business user receiving data may also become a controller if it decides how the data will be used.</p>



<p>This distinction is important because the recipient of data under the Data Act may inherit independent GDPR obligations.</p>



<p><strong>Data Portability: How the Data Act Expands Existing Rights</strong></p>



<p>The GDPR grants individuals a right to data portability, but this right is limited to personal data provided by the data subject and processed on the basis of consent or contract. The Data Act significantly broadens this concept.</p>



<p>It applies to data generated through the use of connected products and related services, regardless of whether the data is personal or non-personal.</p>



<p>For businesses, this means that existing GDPR portability procedures will usually not be sufficient. Organizations may need entirely new technical and contractual frameworks to handle Data Act requests.</p>



<p><strong>Trade Secrets and Confidential Information</strong></p>



<p>One of the most common concerns raised by businesses is the protection of proprietary information. The Data Act recognizes that data may contain trade secrets and allows data holders to implement safeguards such as confidentiality agreements, access controls and contractual restrictions. However, trade secret protection is not an automatic ground for refusing access. A refusal is permitted only in exceptional circumstances where disclosure would likely cause serious economic harm and where protective measures are insufficient.</p>



<p>In practice, businesses should assume that most requests will need to be fulfilled, subject to appropriate safeguards.</p>



<p><strong>Smart Contracts</strong></p>



<p>The Data Act introduces specific requirements for smart contracts used to automate data sharing.</p>



<p>Where businesses use blockchain-based or automated systems to execute data-sharing arrangements, those systems must meet standards relating to security, integrity and the ability to terminate or interrupt execution where necessary. Although this aspect of the regulation may not affect all organizations, it is highly relevant to businesses deploying decentralized or automated contractual technologies.</p>



<p><strong>Cloud Switching and Digital Assets</strong></p>



<p>The Data Act also addresses switching between providers of data processing services, including cloud providers. Customers must be able to move digital assets such as applications, configuration files, metadata and access credentials to another provider more easily. Organizations that offer cloud or platform services should review their contractual and technical arrangements to ensure that customers can migrate without undue barriers.</p>



<p><strong>Legal Basis for Processing Personal Data</strong></p>



<p>A recurring misconception is that the Data Act itself authorizes disclosure of personal data. This is incorrect. Whenever personal data is involved, a valid legal basis under the GDPR remains necessary. The applicable legal basis will depend on the circumstances. In some cases, processing may be necessary for the performance of a contract. In others, consent or legitimate interests may be relevant. Where the user requesting the data is a business rather than the individual to whom the data relates, the requesting party may need to demonstrate that it has an independent lawful basis for processing the personal data.</p>



<p><strong>What Businesses Should Do</strong></p>



<p>Organizations should begin by identifying whether they fall within the scope of the Data Act. Businesses that manufacture connected products, provide related services, control access to product-generated data or offer cloud services are the most likely to be affected. The next step is to map the data generated by products and services. This exercise should identify what data is collected, whether it includes personal data, who controls it and with whom it may be shared.</p>



<p>Once the data landscape is understood, businesses should review the legal bases for processing any personal data contained in those datasets.</p>



<p>Policies and procedures should then be updated to address Data Act requests. Existing GDPR processes will rarely be sufficient because they are designed primarily for requests from individuals, not business-to-business data sharing.</p>



<p>Contracts with customers, partners and recipients should be revised to address data use restrictions, confidentiality obligations, trade secret protections and security measures.</p>



<p>Technical teams should ensure that systems can provide data in accessible formats, authenticate requesters, record disclosures and protect sensitive information.</p>



<p>Finally, legal, compliance, IT and customer support teams should be trained so that they understand how to manage requests consistently.</p>



<p><strong>Common Pitfalls</strong></p>



<p>Businesses preparing for the Data Act frequently make several mistakes. The first is assuming that the Data Act overrides the GDPR. In reality, the GDPR remains fully applicable whenever personal data is involved. The second is underestimating the complexity of mixed datasets. The third is relying too heavily on trade secret arguments to resist disclosure. The fourth is failing to update contracts and operational procedures.</p>



<p>The fifth is treating compliance as a purely legal issue rather than a multidisciplinary project involving legal, IT, security and commercial teams.</p>



<p><strong>Enforcement and Business Risk</strong></p>



<p>Failure to comply with the Data Act may result in regulatory investigations, disputes with customers and partners, and reputational damage. Where personal data is mishandled, GDPR enforcement risks also arise, including potentially significant administrative fines. For this reason, businesses should approach the Data Act as a strategic compliance project rather than a narrow contractual exercise.</p>



<p><strong>Conclusion</strong></p>



<p>The Data Act and the GDPR are complementary regulations that pursue different objectives. The GDPR protects individuals and their personal data. The Data Act promotes broader access to data generated by connected products and services. When those datasets contain personal data, organizations must apply both regimes simultaneously. The Data Act creates the obligation to make data available, while the GDPR determines the conditions under which personal data may be processed and shared.</p>



<p>Businesses that rely on connected products, IoT ecosystems, industrial data or cloud services should begin preparing well in advance.</p>



<p>Organizations that invest now in data mapping, contractual updates, technical controls and internal governance will be best positioned to comply with the new rules and to leverage data as a strategic asset.</p>



<p><strong>Client Alert</strong></p>



<p><strong>EU Data Act Applies from 12 September 2025: Is Your Business Ready?</strong></p>



<p>The EU Data Act introduces a new framework governing access to data generated by connected products and related services. It applies from 12 September 2025 and will affect manufacturers, software providers, cloud providers and businesses that rely on connected technologies.</p>



<p>The regulation grants users the right to access data generated by products they use and to request that such data be shared with third parties.</p>



<p>Where the data includes personal data, the GDPR remains fully applicable.</p>



<p>For many organizations, the Data Act will require updates to contracts, technical systems and operational procedures.</p>



<p>Businesses should begin by identifying whether they control product-generated data, determining whether datasets include personal data, and assessing whether existing systems can support secure and compliant data sharing.</p>



<p>Organizations should also review trade secret protections and update agreements with customers and business partners.</p>



<p>Companies that prepare early will be better positioned to meet legal obligations and capitalize on new opportunities arising from increased data portability.</p>



<p><strong>Data Act Implementation Checklist</strong></p>



<p>An effective implementation project should begin with a governance assessment to determine which internal teams will be responsible for legal analysis, technical implementation and operational oversight.</p>



<p>The organization should then conduct a comprehensive data mapping exercise covering all connected products, related services and cloud environments. This exercise should distinguish between personal data, non-personal data and mixed datasets.</p>



<p>A legal review should be undertaken to confirm the GDPR legal bases for processing personal data and to identify any restrictions arising from confidentiality obligations or trade secret protections.</p>



<p>Customer terms, data-sharing agreements, cloud contracts and internal policies should be revised to reflect Data Act requirements.</p>



<p>Technical teams should ensure that systems are capable of exporting data in usable formats, authenticating requesters, logging disclosures and protecting confidential information.</p>



<p>Operational procedures should be established for receiving, reviewing and responding to requests.</p>



<p>Training should be delivered to legal, compliance, IT, security and customer-facing teams.</p>
<p> </p>



<p><strong>The EU Data Act Meets the GDPR: What Businesses Need to Know</strong></p>



<p>With the EU Data Act becoming applicable from <strong>12 September 2025</strong>, we’re entering a new era of data regulation in Europe — one that doesn’t replace the GDPR, but fundamentally reshapes how it operates in practice.</p>



<p>For many organizations, the challenge is no longer <em>GDPR vs. Data Act</em>, but how both frameworks work together when data is shared, accessed, and reused.</p>



<p>The key reality?<br>Most data generated by connected products is <strong>mixed — personal and non-personal at the same time</strong>. And that changes everything.</p>



<h3 class="wp-block-heading">Key takeaway:</h3>



<p>The Data Act creates obligations to <strong>share data</strong>, but the GDPR still governs <strong>how personal data can be processed and transferred</strong>. The Data Act never overrides GDPR requirements.</p>



<h3 class="wp-block-heading">What this means in practice:</h3>



<ul class="wp-block-list">
<li>No new legal basis for processing personal data under the Data Act</li>



<li>GDPR principles (minimization, purpose limitation, security) still fully apply</li>



<li>Trade secrets don’t automatically block access requests</li>



<li>Data portability rights are significantly expanded beyond GDPR scope</li>



<li>Cloud and IoT ecosystems will need major technical and contractual updates</li>
</ul>



<h3 class="wp-block-heading">The real challenge for businesses</h3>



<p>Compliance is no longer just legal — it’s operational and technical.</p>



<p>Organizations will need to:<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Map all product-generated data<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Identify where personal data is involved<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Update contracts and data-sharing frameworks<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Build secure, auditable data access systems<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Align legal, IT, and compliance teams</p>



<h3 class="wp-block-heading">Bottom line:</h3>



<p>The Data Act doesn’t replace the GDPR — it adds a new layer of complexity on top of it. Companies that prepare early will not only reduce compliance risk but also gain a competitive advantage in the emerging EU data economy.</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
