<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NIS2 - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/nis2/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/nis2/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Tue, 07 Jul 2026 19:32:02 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</title>
		<link>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:40:05 +0000</pubDate>
				<category><![CDATA[INVESTMENT LAW AND PROCESSES IN POLAND]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Governance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[Cyber Risk;]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8816</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of the European Parliament and of the Council.</p>



<p id="ember4587">The amendment to the KSC Act significantly expands the scope of the regulations and introduces new obligations in the field of cybersecurity management. The changes include, among other things, the implementation of risk management systems and expanded incident reporting requirements. The new regulations also strengthen the powers of supervisory authorities and significantly increase the maximum amount of financial penalties. It also introduces liability for the management staff (manager) of an entity. In practice, this requires certain entities to take steps to comply with the new regulations.</p>



<span id="more-8816"></span>



<p id="ember4588"><strong>The first experiences of entrepreneurs after the amendment came into force – practical conclusions</strong></p>



<p id="ember4589">The few months that the amended Act on the National Cybersecurity System has been in effect demonstrate that the biggest challenge for businesses is no longer the analysis of the new regulations, but their practical implementation. For many organizations, the adaptation process began with a seemingly simple task: determining whether a given entity is even subject to the new regulations. In practice, this step proves to be one of the most problematic.</p>



<p id="ember4590">Under the previous legal framework, many businesses awaited a formal administrative decision confirming their status as an essential service operator. This approach is no longer appropriate. The status of a key or important entity stems directly from the Act, and obligations arise regardless of whether the business has already been entered on the register. This means that the responsibility for properly assessing their own situation rests primarily with the business itself.</p>



<p id="ember4591">Practice also shows that many companies focus solely on the issue of being entered into the register of key and important entities. However, entry itself is not the purpose of the regulation. The greatest challenges remain the actual implementation of an information security management system, conducting a risk analysis, developing incident response procedures, and adequately documenting the actions taken. In the future, supervisory authorities will primarily assess an organization&#8217;s actual level of compliance with the Act, not merely the formal fulfillment of registration obligations.</p>



<p id="ember4592">Another significant change is the significant increase in management responsibility. Management can no longer treat cybersecurity as a matter solely within the purview of IT departments. The Act requires active management involvement in the organization of the cybersecurity management system, oversight of its operation, and provision of adequate organizational and financial resources. In practice, this requires regular reporting on cybersecurity issues at the management level and documentation of decisions made.</p>



<p id="ember4593">Supply chain security is also becoming increasingly important. Businesses are required not only to secure their own IT systems but also to consider the risks arising from collaboration with IT service providers, cloud computing operators, software vendors, and outsourcing providers. In practice, this means reviewing supplier contracts, verifying the security measures in place, and implementing appropriate provisions for incident management and crisis cooperation.</p>



<p id="ember4594">It&#8217;s also noticeable that a growing number of businesses are choosing to conduct internal compliance audits before the statutory deadlines expire. This approach allows for early identification of organizational and technical gaps, reducing the risk of subsequent violations and costly remedial actions.</p>



<p id="ember4595">In practice, the best solution is to treat the implementation of the Act&#8217;s requirements not as a one-time project, but rather as a process encompassing regular risk analysis, procedure updates, employee training, and ongoing oversight of the organization&#8217;s security. This approach not only increases compliance but also significantly reduces the risk of cybersecurity incidents.</p>



<p id="ember4596">It&#8217;s worth emphasizing that the current transition period should be used to calmly prepare organizations for the full application of the new regulations. Postponing implementation until the final months before the statutory deadlines expire can be risky, especially for large organizations where implementing information security management systems requires the involvement of multiple departments and adequate time to prepare procedures and documentation.</p>



<h2 class="wp-block-heading" id="ember4597">Change in the circle of entities to which the Act applies.</h2>



<p id="ember4598">Under the previous wording of the Act, an administrative decision was required to recognize an entity as an essential service operator (Article 5 of the Act before the amendment). Currently, the group of key and important entities is determined automatically (ex lege). The criteria for qualifying an entity as essential are found in Article 5, Section 1, and as an important entity in Article 5, Section 2 of the Act. It is possible that an entity meets the criteria for both key and important entities; such an entity is considered a key entity under Article 5, Section 4. When attempting to qualify entities, the Act also refers to EU regulations, particularly Regulation 651/2014/EU, which defines SMEs. Therefore, the primary criteria taken into account will be the number of employees and annual turnover. It is also necessary to refer to Annexes 1 and 2 of the Act, which precisely define the categories of entrepreneurs in specific sectors and subsectors.</p>



<p id="ember4599">The added Article 5a in paragraph 1 provides that key and important entities are subject to the obligations arising from the Act if they reside in the territory of the Republic of Poland or conduct their business in the territory of the Republic of Poland.</p>



<p id="ember4600">Articles 7 et seq. regulate matters related to the list of key and important entities. Before the amendment, the list contained only operators of essential services; now it includes key and important entities. Unlike the previous legal status, in which entry was made at the request of the authority responsible for cybersecurity (former wording of Article 7, paragraph 3 of the Act), entry is now made at the request of a key or important entity within six months of the occurrence of the conditions (Article 7c, paragraph 1 of the Act). Ex officio entry will generally only apply to existing operators of essential services, trust service providers, telecommunications companies, and public entities. This means that for entities meeting the conditions on the date the amendment comes into force, the deadline for submitting an application is October 3, 2026. Pursuant to the Announcement of the Minister of Digitization of April 8, 2026, regarding the schedule for submitting applications for entry in the register of key and important entities and for key or important entities to commence using the ICT system , self-registration on the list is possible from May 7, 2026, to October 3, 2026. The platform operating in the S46 system is available at <a href="https://wykaz-ksc.gov.pl/">https://wykaz-ksc.gov.pl/</a> . By April 3, 2027, key and important entities are required to commence using the ICT system specified in Art. 46 sec. 1 of the Act. This deadline begins depending on whether the entities were parties to agreements regarding the use of the ICT system referred to in Art. 46 sec. 1 of the Act concluded before April 3, 2026. For the former, the possibility of using the system was opened on April 8, 2026, and for the latter, this possibility will be available from June 12, 2026 (point 2 of the Communication of the Minister of Digital Affairs).</p>



<p id="ember4601">If an entity that meets the criteria for being considered a key or important entity fails to submit an application for entry, the authority responsible for cybersecurity may enter the entity on the list ex officio (Article 7j, paragraph 1 of the Act). Failure to comply with certain obligations related to the list (failure to timely complete missing data on the list or failure to correct data despite a request or failure to submit an application for entry) may result in the imposition of a substantial fine (Article 73, paragraph 1, point 1 and Article 73, paragraph 1a, point 1 of the Act). The catalogue of data to be included on the list has also been changed (expanded) (Article 7, paragraph 2).</p>



<p id="ember4602"><strong>In practice: </strong>The expansion of the scope of entities and the shift from administrative decision-making to automatic regulation mean that many entities may be subject to the Act without formal confirmation of this status. In practice, independent qualification analysis and continuous monitoring of compliance with statutory criteria become crucial. An incorrect assessment (or failure to comply) may result in exposure to sanctions (severe fines).</p>



<h2 class="wp-block-heading" id="ember4603">New responsibilities for cybersecurity management.</h2>



<h3 class="wp-block-heading" id="ember4604">Duties</h3>



<p id="ember4605">Chapter 3, which governs the obligations of key and important entities, has been expanded, and Chapters 3a and 3b have been added, addressing domain name registration service providers and public entities. Article 8 of the Act governs obligations related to the implementation of an information security management system. Compared to the previous legal framework, numerous obligations have been added. The responsibility of the manager of a key or important entity for the performance of its cybersecurity obligations has been introduced (Article 8c of the Act), and the manager&#8217;s responsibilities have also been defined (Articles 8d–8f of the Act).</p>



<p id="ember4606">The regulations regarding incident reporting have also changed. A key or important entity classifies a given incident as serious (after meeting the requirements of Article 2, Section 7 of the Act), then issues an early warning, reports the incident, and finally submits a final report on the handling of the serious incident to the CSIRT (a three-step reporting model instead of the previous one-step model – Article 11 of the Act).</p>



<h2 class="wp-block-heading" id="ember4607">Deadlines</h2>



<p id="ember4608">Pursuant to Article 15 of the Act, key entities must conduct a security audit of the information system used in the service provision process at least once every three years. For key entities that were not previously classified as key service operators, the first audit should be conducted within 24 months of the date the conditions are met (Article 16, point 2, therefore, for these entities, the deadline for conducting the audit is April 3, 2028).</p>



<p id="ember4609">The Act amending the KSC Act establishes a 12-month transition period during which key and important entities have time to fulfill the obligations specified in Chapter 3 of the Act (except for the obligation to conduct the first audit, which entities have 24 months to conduct). Therefore, with respect to obligations such as implementing an information security management system, risk assessment, implementing technical and organizational measures, reporting and managing incidents, and verifying personnel&#8217;s criminal records, the deadline for compliance with these regulations expires on April 3, 2027.</p>



<p id="ember4610"><strong>In practice: </strong>The imposed obligations require the implementation of an information security management system. Furthermore, the single-tier incident reporting system has been changed, replaced by a more complex three-tier system. Essential entities will be required to conduct audits. Importantly, entities that were not previously considered essential service operators will be required to conduct an audit within two years of the amendment&#8217;s entry into force. However, most of the new obligations will have to be implemented by April 3, 2027. Failure to comply with these obligations will result in the manager of the relevant entity being held liable.</p>



<h2 class="wp-block-heading" id="ember4611">Change in the amount and grounds for imposing fines.</h2>



<p id="ember4612">Until April 2, 2026, the maximum amount of the fine imposed on entities (only for the most serious violations) was PLN 1 million (former wording of Article 73, paragraph 5 in fine). Currently, the maximum amount of the fine is, as a rule, EUR 10 million (Article 73, paragraph 3 of the Act), and for the most serious violations, up to PLN 100 million (Article 73, paragraph 5 in fine of the Act).</p>



<p id="ember4613">With the imposition of a large number of obligations on key and important entities, the list of violations for which a fine may be imposed has also been expanded (Article 73 of the Act).</p>



<p id="ember4614">The new provisions on fines come into force only two years after the entry into force of the Act (i.e. from April 3, 2028).</p>



<p id="ember4615"><strong>In practice: </strong>Increasing the amount of fines disciplines key entities and important entities to take their cybersecurity obligations very seriously. It is worth emphasizing, however, that the amended regulations on fines will not enter into force until April 3, 2028.</p>



<h2 class="wp-block-heading" id="ember4616">Changes in the supervision and control of key and important entities.</h2>



<p id="ember4617">Chapter 11 of the Act, which deals with the supervision and control of key and important entities, has been significantly expanded. Some provisions remain unchanged (the requirement to apply the provisions of the Entrepreneurs&#8217; Law or the Act on Audit in Government Administration, the powers of the person conducting the audit, most of the obligations of audited entities, and provisions regarding audit protocols and post-audit recommendations).</p>



<h2 class="wp-block-heading" id="ember4618">Important changes</h2>



<p id="ember4619">The most important changes in the scope of supervision include a significant expansion of Article 53, which describes the powers of the authority responsible for cybersecurity regarding supervision and oversight of key entities. It empowers the competent authority to issue various types of administrative decisions aimed at enforcing the provisions of the Act. This article also contains a number of procedural provisions defining the nature of the proceedings. Generally, the regulations contained in this article apply only to key entities, but as stated in Article 53, paragraph 17, certain provisions also apply to inspections of important entities. Article 53, paragraph 3 states that supervision of key entities is both post-empty and preventive, while for important entities, supervision is only post-empty.</p>



<p id="ember4620">A new obligation for both key and important entities is the information obligation specified in Article 53c, which requires a key or important entity to provide certain data at the request of the authority responsible for cybersecurity.</p>



<p id="ember4621">A new institution is the ad hoc review added in Article 59c, which may be carried out only if the conditions specified in the cited Article are met.</p>



<p id="ember4622"><strong>In practice: </strong>Strengthening the powers of supervisory authorities and introducing ad hoc inspections means increased risk of inspections and the need to maintain constant readiness to demonstrate compliance with regulations. Entities should also prepare for more frequent requests for information from authorized bodies.</p>



<h2 class="wp-block-heading" id="ember4623">Minor changes</h2>



<p id="ember4624">Chapter 10 has been amended and Chapters 10a – 10c have been added, but they do not contain any standards addressed to entities and are therefore not relevant from a practical point of view.</p>



<p id="ember4625">Several changes concern Chapter 12 concerning the Government Plenipotentiary for Cybersecurity and the Cybersecurity Board, but these changes do not have any significant impact on the entities.</p>



<p id="ember4626">Article 12a has been added, addressing specific measures to ensure cybersecurity at the national level. It primarily contains provisions on recommendations from the Government Plenipotentiary for Cybersecurity (Article 67a), the procedure for designating a supplier as a high-risk supplier (Articles 67b–67f), and a safeguarding order in the event of a critical incident (Articles 67g–67i).</p>



<p id="ember4627">Minor changes also apply to the Cybersecurity Strategy of the Republic of Poland (Articles 68–72). The changes primarily concern the content and method of developing the strategy, as well as the frequency of strategy reviews (2.5 years instead of the previous 2 years).</p>



<p id="ember4628">The amendment to the Act on the National Emergency Response Plan creates the basis for the adoption of the National Emergency Response Plan (Articles 72a – 72f of the Act).</p>



<h2 class="wp-block-heading" id="ember4629">Recommended actions.</h2>



<p id="ember4630">In light of the amendments to the Commercial Companies Code, entities subject to the new regulations should take steps to ensure their operations are in compliance with the law. It is recommended that:</p>



<p id="ember4631">1)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Self-identification in order to determine whether a given entity qualifies as a key or important entity within the meaning of the Act.</p>



<p id="ember4632">2)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Implementation or update of an information security management system.</p>



<p id="ember4633">3)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Development of procedures for identifying and reporting incidents, taking into account the new procedure.</p>



<p id="ember4634">4)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring the involvement of management staff, e.g. the manager&#8217;s implementation of the obligations under Article 8d or 8e.</p>



<p id="ember4635">5)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Preparing the organization for potential supervisory activities, e.g. inspections.</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4637">ex officio entries carried out by the Minister of Digital Affairs (current key service operators, trust service providers, telecommunications companies and public entities)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4639">April 13 – May 6, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4641">self-registration in the list of key and important entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4643">May 7 – October 3, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4645">launching the possibility of using the S46 system for new entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4647">June 12, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4649">end of the deadline for starting to use the S46 system and implementing obligations (end of the adjustment period)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4651">April 3, 2027</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4653">the first ISMS audit (for key entities that were not key service operators) and the beginning of the application of the provisions on penalties</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4655">April 3, 2028</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 17:54:28 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[3D Scanning]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in Defence]]></category>
		<category><![CDATA[Armed Forces]]></category>
		<category><![CDATA[Arms Trade]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[ASAP]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[B2G]]></category>
		<category><![CDATA[Civil Defence]]></category>
		<category><![CDATA[Classified Information]]></category>
		<category><![CDATA[Crisis Preparedness]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Defence Conference]]></category>
		<category><![CDATA[Defence Expo]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[Defence IP]]></category>
		<category><![CDATA[Defence Procurement]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Defense Expo]]></category>
		<category><![CDATA[Defense Industry]]></category>
		<category><![CDATA[Defense Tech]]></category>
		<category><![CDATA[Drones]]></category>
		<category><![CDATA[Dual Use Technology]]></category>
		<category><![CDATA[EDF]]></category>
		<category><![CDATA[Emergency Preparedness]]></category>
		<category><![CDATA[European Defence Fund]]></category>
		<category><![CDATA[EXPO XXI]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[Firearms Law]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[Infrastructure Protection]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[Military Innovation]]></category>
		<category><![CDATA[Military Modernization]]></category>
		<category><![CDATA[Military Technology]]></category>
		<category><![CDATA[Mini MSPO]]></category>
		<category><![CDATA[MON RP]]></category>
		<category><![CDATA[MSWiA]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Personal Protective Equipment]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish Armed Forces]]></category>
		<category><![CDATA[Polish Defence Industry]]></category>
		<category><![CDATA[Public Procurement]]></category>
		<category><![CDATA[Range Safety]]></category>
		<category><![CDATA[Resilience]]></category>
		<category><![CDATA[Security Conference]]></category>
		<category><![CDATA[Shooting Sports]]></category>
		<category><![CDATA[Sport Shooting]]></category>
		<category><![CDATA[State Resilience]]></category>
		<category><![CDATA[Tactical Communications]]></category>
		<category><![CDATA[Territorial Defence]]></category>
		<category><![CDATA[UAV]]></category>
		<category><![CDATA[Unmanned Systems]]></category>
		<category><![CDATA[WARSAW]]></category>
		<category><![CDATA[Warsaw Defence Expo]]></category>
		<category><![CDATA[Warszawa]]></category>
		<category><![CDATA[Warszawskie Targi Obronne]]></category>
		<category><![CDATA[Weapons Permits]]></category>
		<category><![CDATA[WOT]]></category>
		<category><![CDATA[WTO2026]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8803</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 – the first edition of a new nationwide event dedicated to the defence, security and resilience of the state On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-1 wp-block-group-is-layout-flex">
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>


</div>



<h3 class="wp-block-heading">– the first edition of a new nationwide event dedicated to the defence, security and resilience of the state</h3>



<p id="ember53">On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. This is the first edition of a completely new trade fair and conference event, created in response to the growing importance of the defense sector, national security, and technologies supporting Poland&#8217;s institutional, economic, and social resilience. The fair is held under the honorary patronage of the Ministry of Interior and Administration and the Minister of National Defense. The event is informally referred to as a &#8220;mini-MSPO in Warsaw&#8221; – a capital city-based, intimate alternative to the September International Defense Industry Fair in Kielce, open not only to professionals but also – on the second day – to the general public.</p>



<span id="more-8803"></span>



<p id="ember54">The goal of the Warsaw Defense Fair is to integrate key groups responsible for national security and to create a space for dialogue, collaboration, and exchange of experiences between public administration, the military, uniformed services, the defense industry, the technology sector, the investor community, and military universities. The event combines exhibition, conference, and networking elements , creating a platform for showcasing modern technologies, exchanging expert knowledge, and building business relationships in one of the fastest-growing sectors of the Polish economy.</p>



<p id="ember55">The trade fair program is divided into two complementary days, representing one of the most distinctive solutions adopted by the organizers. Friday, June 19, 2026, will be an industry day (B2B/B2G), intended exclusively for companies, institutions, and business partners. Industry registration is required. This day will be a platform for meetings and discussions between individuals and entities interested in establishing cooperation in the defense and security sector, including representatives of public administration and local governments, soldiers and uniformed services, representatives of companies in the defense and technology sectors, investors, industry advisors, and representatives of military universities. The program focuses on key challenges facing the defense and national security sectors, including conferences, panel discussions, and business and institutional meetings concerning the development of the Polish defense industry, modernization of the Armed Forces, public procurement in the defense sector, and cross-sectoral cooperation.</p>



<p id="ember56">Saturday, June 20, 2026, will be an open day (B2B/B2G/B2C), also open to the public interested in security, defense, and shooting. The second day significantly complements the industry portion and expands the event to include the general public, as well as educational and outreach communities. It will feature demonstrations of equipment and technologies in near-operational settings, demonstration zones by exhibitors and manufacturers, presentations of solutions in cybersecurity, drones, communications, and critical infrastructure protection, as well as numerous lectures for enthusiasts. Topics covered include firearms licenses – myths and legal realities, training and shooting sports, hearing and eye protection, safety and ergonomics at the shooting range, and civic preparedness for crisis situations.</p>



<h2 class="wp-block-heading" id="ember57">Exhibitors and thematic scope</h2>



<p id="ember58">Over 100 exhibitors will be present at the fair, representing a full cross-section of entities active in the Polish defense and security sector. Exhibitors include military units such as the 1st Warsaw Armored Brigade and the 18th Capital Territorial Defense Brigade, international technology companies, including 3M Poland, which presents personal protection solutions for the defense sector, and Artec 3D with 3D scanners used in military applications. The shooting and equipment segment will be strongly represented, with companies such as House of Guns , Hubertus Pro Hunting , Kaliber, 4HUNTING, Kolba, 4SHOOTER, Son of Gun , Jammas , and Wolfer. Group and Works11. The event is also partnered by the Legia Warsaw Central Military Sports Club – Shooting Section.</p>



<p id="ember59">The exhibition covers cutting-edge weapons, equipment, facilities and technologies used in the defense and security sector: unmanned systems and drones, cybersecurity solutions, tactical communications and communication technologies, critical infrastructure protection, personal protective equipment, 3D scanning and simulation technologies, individual soldier equipment, as well as solutions in the area of civil defense and population protection.</p>



<h2 class="wp-block-heading" id="ember60">Three conference stages and a substantive agenda</h2>



<p id="ember61">The WTO 2026 program will unfold simultaneously across three conference stages. The industry day will be dedicated to the most important strategic challenges facing the defense sector – the technical modernization of the Polish Armed Forces, the development of the domestic arms industry, cooperation with foreign partners, public procurement in the defense sector, new dual-use technologies , and the role of the private sector in building national resilience. The second day, open to the public, will feature lectures and discussions covering a much broader range of topics – from legal issues concerning access to weapons and individual security, through shooting sports and defense training, to preparing society for crisis situations and disseminating knowledge about modern defense technologies.</p>



<p id="ember62">The significance of the event from a legal perspective</p>



<p id="ember63">The establishment of the Warsaw Defense Fair is part of the broader context of the dynamic development of the Polish defense sector, which in recent years has become one of the most important areas of public and private investment, generating significant demand for legal services. From the firm&#8217;s perspective, issues related to public procurement in the defense sector, regulations regarding trade in arms and dual-use technologies, export controls, protection of classified information, cybersecurity in the context of the NIS2 directive, intellectual property rights in defense technology projects, and financing of projects from European funds (including the European Defense Fund and ASAP), as well as the development of regulations regarding artificial intelligence in military applications in light of the European AI Act . The participation of representatives of the KG LEGAL KIEŁTYKA GŁADKOWSKI law firm in this event is a natural element of tracking the development of one of the fastest-growing sectors of the Polish economy and building competences in the area of law related to new defense technologies.</p>



<p id="ember64">The Warsaw Defense Fair 2026 demonstrates that security and defense are no longer the exclusive domain of the military and state administration. They have become an area of broad cross-sectoral cooperation, with technology companies, investors, academia, non-governmental organizations, and informed citizens playing key roles. The development of this sector today requires not only advanced technological competencies but also an appropriate legal, regulatory, and institutional environment.</p>



<p id="ember65">Link to the event: <a href="https://wto26.exposupport.pl/program">https://wto26.exposupport.pl/program</a></p>



<p id="ember66">#WarsawDefenceExpo #WTO2026 #WarszawskieTargiObronne #DefenceIndustry #DefenseIndustry #DefenceExpo #DefenseExpo #PolishDefenceIndustry #PolishArmedForces #NationalSecurity #StateResilience #CivilDefence #HomelandSecurity #DefenceTechnology #DefenseTech #MilitaryTechnology #MilitaryInnovation #DualUseTechnology #DefenceProcurement #PublicProcurement #ArmsTrade #ExportControl #ClassifiedInformation #CyberSecurity #NIS2 #CriticalInfrastructure #InfrastructureProtection #UnmannedSystems #Drones #UAV #TacticalCommunications #PersonalProtectiveEquipment #3DScanning #AIinDefence #AIAct #ArtificialIntelligence #EuropeanDefenceFund #EDF #ASAP #IntellectualProperty #DefenceIP #TerritorialDefence #WOT #ArmedForces #MilitaryModernization #SportShooting #FirearmsLaw #WeaponsPermits #ShootingSports #RangeSafety #CrisisPreparedness #EmergencyPreparedness #Resilience #B2B #B2G #EXPOXXI #Warsaw #Warszawa #Poland #MONRP #MSWiA #MiniMSPO #DefenceConference #SecurityConference #LegalTech #LawFirm #KGLegal #KieltykaGladkowski</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybersecurity and GDPR Compliance in 2025</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 20 Aug 2025 16:11:16 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[CRA]]></category>
		<category><![CDATA[eIDAS]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8192</guid>

					<description><![CDATA[<p>Publication date: August 20, 2025 In an era of dynamic digital technology development and a growing number of cyberthreats, cybersecurity and personal data protection are becoming key aspects of how organizations operate in the European Union. New regulations, such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the current GDPR, create a [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/">Cybersecurity and GDPR Compliance in 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: August 20, 2025</mark></strong></p>



<p>In an era of dynamic digital technology development and a growing number of cyberthreats, cybersecurity and personal data protection are becoming key aspects of how organizations operate in the European Union. New regulations, such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the current GDPR, create a comprehensive security system aimed at raising protection standards and ensuring greater transparency in data processing.</p>



<span id="more-8192"></span>



<p><strong>NIS2 and GDPR: Strengthening Data Protection and Incident Response</strong></p>



<p>The Network and Information Security Directive (NIS2) is another step towards increasing the cyber resilience of entities operating in key economic sectors. In 2025, its implementation will require organizations to take a number of actions, including:</p>



<ul class="wp-block-list">
<li>Expanding security measures against cyberattacks,</li>



<li>Introducing more rigorous incident reporting procedures,</li>



<li>Strengthening cooperation between supervisory authorities and the private sector.</li>
</ul>



<p>NIS2, in conjunction with GDPR (Regulation 2016/679), means that businesses will not only have to protect personal data more effectively, but also implement new procedures for risk management and auditing of IT security activities.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>5 Things You Need to Know About NIS2</strong></p>



<p><strong>01 </strong>– Fines up to <strong>€10 million or 2% of total annual global turnover</strong></p>



<p><strong>02 </strong>– <strong>Expanded scope </strong>compared to NIS1, changing the way companies are classified and requiring more of them to comply with the directives</p>



<p><strong>03 </strong>– Management staff <strong>is liable for violations </strong>and the authorities may <strong>suspend activities or functions</strong></p>



<p><strong>04 </strong>– Broad <strong>security risk management measures </strong>and shift to a risk-based approach</p>



<p><strong>05 </strong>– Initial reporting <strong>of security incidents within 24 hours</strong>, further action within <strong>72 hours</strong>, and final summary <strong>within 1 month</strong></p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>DORA: Cyber Resilience and Personal Data Security in Finance</strong></p>



<p>DORA is the Regulation of the European Parliament and of the Council (EU) of 14 December 2022 on the digital operational resilience of the financial sector. This is another of many recent regulations concerning cybersecurity and the broadly defined security of information technology.</p>



<p>The Digital Operational Resilience Act (DORA) focuses on the financial sector, which is particularly vulnerable to cyberattacks. Key requirements imposed by DORA include:</p>



<ul class="wp-block-list">
<li>Testing the operational resilience of IT systems,</li>



<li>Implementing risk management strategies based on threat analysis,</li>



<li>Obligation to monitor and report digital incidents.</li>
</ul>



<p>DORA applies to:</p>



<ol style="list-style-type:lower-alpha" class="wp-block-list">
<li>credit institutions;</li>



<li>payment institutions, including payment institutions exempted under <a href="https://sip-1lex-1pl-18l00itm9016d.extranet.rajska.info/#/document/68589670?cm=DOCUMENT">Directive </a>(EU) 2015/2366;</li>



<li>providers of account information access services;</li>



<li>electronic money institutions, including electronic money institutions exempted under <a href="https://sip-1lex-1pl-18l00itm9016d.extranet.rajska.info/#/document/67903621?cm=DOCUMENT">Directive </a>2009/110/EC;</li>



<li>investment companies;</li>



<li>crypto-asset service providers,</li>



<li>central securities depositories;</li>



<li>central counterparties;</li>



<li>trading systems;</li>



<li>transaction repositories;</li>



<li>alternative investment fund managers;</li>



<li>management companies;</li>



<li>information sharing service providers;</li>



<li>insurance and reinsurance undertakings;</li>



<li>insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries;</li>



<li>institutions of occupational pension programs;</li>



<li>rating agencies;</li>



<li>administrators of critical benchmarks;</li>



<li>crowdfunding service providers;</li>



<li>securitization repositories;</li>



<li>external ICT service providers.</li>
</ol>



<p>In the context of GDPR compliance, financial institutions must ensure adequate security measures to protect customer data against unauthorized access and information leakage. GDPR also mandates cooperation with cloud service providers and external IT operators, which requires thorough verification of their security standards.</p>



<p>Article 33 of the DORA Directive requires personal data breaches to be reported without undue delay, and within 72 hours where possible. In the event of a delay, an explanation of the reason for the delay must be included.</p>



<p class="has-vivid-cyan-blue-background-color has-background has-medium-font-size"><strong><mark>AI Act and GDPR: Managing Artificial Intelligence and Data Protection</mark></strong></p>



<p>The AI Act regulations classify AI systems according to risk level and impose obligations on entities that implement them. In the context of data protection, the AI Act requires:</p>



<ul class="wp-block-list">
<li>Transparency of artificial intelligence algorithms and mechanisms,</li>



<li>Possibilities of controlling and auditing decisions made by AI,</li>



<li>Compliance with the principles of data minimization and limitation of the processing purpose.</li>
</ul>



<p>Companies that use AI to process personal data will have to meet stringent GDPR requirements, giving users greater control over their information and minimizing the risk of abuse.</p>



<p><strong>CRA: Cyber Resilience Act – Security of Digital Products</strong></p>



<p>The Cyber Resilience Act (CRA) introduces obligations related to the security of digital software and hardware. Its key requirements include:</p>



<ul class="wp-block-list">
<li>Designing secure digital products,</li>



<li>Monitoring vulnerabilities and updating them regularly,</li>



<li>Manufacturers&#8217; responsibility to ensure continued safety throughout the product life cycle.</li>
</ul>



<p>CRA aims to increase cybersecurity across the entire digital ecosystem, minimizing the risk of attacks based on device and application vulnerabilities.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>eIDAS 2.0: Strengthening digital identification</strong></p>



<p>The amendment to the eIDAS (electronic IDentification, Authentication and trust Services) regulation – known as eIDAS 2.0 – introduces a European digital identity wallet that:</p>



<ul class="wp-block-list">
<li>Allows citizens to securely store and share their identity data,</li>



<li>It enables public and private institutions to provide secure online services,</li>



<li>Strengthens authentication standards in digital transactions.</li>
</ul>



<p>In conjunction with GDPR, eIDAS 2.0 improves users&#8217; control over their identity data and increases the security of online transactions.</p>



<p><strong>Challenges and benefits of new regulations</strong></p>



<p>Adapting to new regulations poses numerous challenges for companies, including:</p>



<ul class="wp-block-list">
<li>The need to invest in modern security systems,</li>



<li>Employee training in cybersecurity and data protection,</li>



<li>Implementation of effective incident monitoring and reporting mechanisms.</li>
</ul>



<p>However, the new regulations also bring numerous benefits, such as:</p>



<ul class="wp-block-list">
<li>Better protection of customer data and greater trust in the organization,</li>



<li>Increased resistance to cyber attacks,</li>



<li>Possibility to avoid high fines for violating data protection regulations.</li>
</ul>



<p><strong>The impact of new regulations on small and medium-sized enterprises (SMEs)</strong></p>



<p>New regulations such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0 can pose challenges for small and medium-sized enterprises (SMEs). Implementing these regulations requires investment in modern security systems and employee training in cybersecurity and data protection. SMEs may face challenges related to limited financial and human resources, which can make it difficult to fully comply with the new requirements.</p>



<p>However, compliance with these regulations also brings benefits, such as better protection of customer data, increased trust in the organization, and the ability to avoid significant fines for violating data protection regulations. Therefore, it is worthwhile for SMEs to consider partnering with external IT service providers and cybersecurity specialists to effectively implement the required security measures.</p>



<p><strong>The future of cybersecurity in the EU</strong></p>



<p>In the coming years, we can expect further development of regulations regarding cybersecurity and personal data protection. The European Union will continue to work on strengthening the legal framework to address growing cyber threats and ensure a high level of data protection. Organizations will need to be prepared to continuously adapt to new requirements and invest in modern security technologies and procedures.</p>



<p><strong>Summary</strong></p>



<p>In 2025, organizations will have to comply with a range of regulations regarding cybersecurity and personal data protection. NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the GDPR, create a modern legal framework aimed at improving data protection and increasing resilience to cyber threats across various economic sectors. Implementing these regulations will be a challenge, but also an opportunity, to build a more secure and digitally resilient business environment in the EU.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/">Cybersecurity and GDPR Compliance in 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
