<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/risk-management/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/risk-management/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 07 Sep 2026 20:31:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations &#124; May 2026</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 11:04:24 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Advertising Law]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Central and Eastern Europe]]></category>
		<category><![CDATA[Client Alert]]></category>
		<category><![CDATA[Commercial Law]]></category>
		<category><![CDATA[Compliance Management]]></category>
		<category><![CDATA[Consumer Health]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[Corporate Compliance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross-Border Business]]></category>
		<category><![CDATA[Dietary Supplements]]></category>
		<category><![CDATA[Distributors]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[e-Sanepid]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Regulatory Law]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[Food and Nutrition Safety Act]]></category>
		<category><![CDATA[Food Business]]></category>
		<category><![CDATA[food industry]]></category>
		<category><![CDATA[Food Law]]></category>
		<category><![CDATA[Food Regulation]]></category>
		<category><![CDATA[Food Safety]]></category>
		<category><![CDATA[Food Supplements]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[GIS]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Importers]]></category>
		<category><![CDATA[In-House Counsel]]></category>
		<category><![CDATA[International Business]]></category>
		<category><![CDATA[International Lawyers]]></category>
		<category><![CDATA[international trade]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Compliance]]></category>
		<category><![CDATA[Legal Insights]]></category>
		<category><![CDATA[Legal Risk]]></category>
		<category><![CDATA[Legal Update]]></category>
		<category><![CDATA[Life Sciences]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Market Entry]]></category>
		<category><![CDATA[Nutraceuticals]]></category>
		<category><![CDATA[Online Retail]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Poland Food Law]]></category>
		<category><![CDATA[Polish Food Law]]></category>
		<category><![CDATA[Product Compliance]]></category>
		<category><![CDATA[Product Safety]]></category>
		<category><![CDATA[Regulatory Affairs]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Regulatory Law]]></category>
		<category><![CDATA[Risk Management]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8825</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The draft Act of April 13, 2026, amending the Act on Food and Nutrition Safety will enter into force six months after its publication. The new regulations primarily impact producers, importers, distributors, and sellers of dietary supplements &#8211; both in traditional and online channels. Below, we present the real changes [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/">CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations | May 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><em>The draft Act of April 13, 2026, amending the Act on Food and Nutrition Safety will enter into force six months after its publication. The new regulations primarily impact producers, importers, distributors, and sellers of dietary supplements &#8211; both in traditional and online channels. Below, we present the real changes to your business.</em></td></tr></tbody></table></figure>



<span id="more-8825"></span>



<h1 class="wp-block-heading">1. Reports only via e-Sanepid</h1>



<p>Every dietary supplement introduced to the market for the first time must be reported to the Chief Sanitary Inspector (GIS). Until now, various forms were acceptable &#8211; paper or electronic, with a handwritten or electronic signature. After the amendment comes into effect, the only acceptable method will be the e-Sanepid platform.</p>



<p>What does this mean in practice?</p>



<ul class="wp-block-list">
<li>It is necessary for each person submitting notifications to have a qualified electronic signature or a trusted profile.</li>



<li>All communication with sanitary inspection bodies &#8211; letters, decisions, and confirmations &#8211; will be handled through the platform account. The moment of notification submission will be clearly confirmed with an official receipt, eliminating disputes over the deadline.</li>



<li>Companies that have previously used paper forms or traditional correspondence must immediately switch to the new channel and ensure appropriate employee training.</li>
</ul>



<p>The change also concerns the timing of the notification obligation: the previous option to notify the Chief Sanitary Inspectorate (GIS) at the stage of intended product introduction is no longer available. The obligation now arises at the time of actual introduction to the market.</p>



<h1 class="wp-block-heading">2. Strict deadlines and automatic presumption of irregularities</h1>



<p>The amendment introduces a completely new mechanism for conducting investigations. This change has the greatest potential to surprise companies without effective internal compliance procedures.</p>



<h2 class="wp-block-heading">How does the new mechanism work?</h2>



<p>If the Chief Sanitary Inspectorate initiates an investigation and requests the entity to submit a scientific opinion, the company has exactly 14 days to submit an application to an accredited scientific unit – at the same time forwarding a copy of it to the Chief Sanitary Inspectorate.</p>



<figure class="wp-block-table"><table class="has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color has-fixed-layout"><tbody><tr><td><strong>Step</strong></td><td><strong>What&#8217;s going on</strong></td></tr><tr><td><strong>14 days</strong></td><td>Deadline for submitting an application for a scientific opinion to a scientific unit (from the date of delivery of the request by GIS)</td></tr><tr><td><strong>6 months</strong></td><td>Maximum time for a scientific unit to issue an opinion</td></tr><tr><td><strong>Up to 12 months</strong></td><td>Possible extension of the deadline by the entity if the case is complex</td></tr><tr><td><strong>Failure to meet 14 days</strong></td><td>Automatic presumption that the product is incorrectly classified and does not meet the requirements &#8211; GIS ends the proceedings to the detriment of the entity</td></tr></tbody></table></figure>



<p>The mechanism for presuming irregularities is a significant innovation. Previously, a company&#8217;s inaction during the proceedings did not automatically result in any legal consequences &#8211; the proceedings could drag on for years. Following the amendment, any failure to meet the 14-day deadline will lead to direct negative consequences, regardless of whether the product is safe.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>The ban on re-registration – an important trap</strong></td></tr><tr><td>Once the investigation is complete, the entity cannot submit a new notification for a product with the same qualitative and quantitative composition. If the company withdraws its notification during the investigation, this prohibition is indefinite. In such cases, changing the composition may be the only way to return to the market.</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">3. Advertising without reporting? A fine of nearly one million zlotys</h1>



<p>This change directly impacts brands engaging in active digital marketing. Previously, advertising or presenting a dietary supplement without prior notification to the Chief Sanitary Inspectorate (GIS) was punishable by a fine (a misdemeanor). Following the amendment, this becomes grounds for imposing an administrative fine &#8211; with new, significantly higher penalties.</p>



<h2 class="wp-block-heading">What exactly is prohibited?</h2>



<p>The amendment penalizes not only the sale of a supplement without reporting it to the Chief Sanitary Inspectorate (GIS), but also the mere advertising or presentation of it if the notification has not been effectively submitted. In other words:</p>



<ul class="wp-block-list">
<li>Sponsored post on Instagram or Facebook promoting a new supplement before notification = grounds for an administrative penalty.</li>



<li>Product page in the online store visible to the public before successful reporting to GIS = risk of infringement.</li>



<li>Promotional materials sent to wholesalers or distributors before GIS is notified = potential infringement.</li>



<li>Influencer marketing initiated before the date of effective notification = liability on the part of the entity commissioning the campaign.</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Key: What is a &#8220;successful report&#8221;?</strong></td></tr><tr><td>The notification is effectively submitted when the company receives official confirmation of receipt from the e-Sanepid platform. Simply submitting the form isn&#8217;t enough &#8211; confirmation is what counts. These dates can differ by several days or more. Every marketing campaign should be planned with this time buffer in mind.</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Prohibition on suggesting medicinal properties &#8211; wider scope</h2>



<p>The amendment expands liability for violations of advertising requirements from labeling to the entire marketing message. Previously, sanctions primarily covered incorrect packaging labeling. Following the amendment, a company is responsible for every communication channel &#8211; online advertising, point-of-sale materials, newsletters, or YouTube videos &#8211; if the message suggests that a varied diet does not provide sufficient nutrients, or if a supplement is presented as a medicinal product.</p>



<h1 class="wp-block-heading">4. Public register &#8211; the company&#8217;s reputation under public scrutiny</h1>



<p>The Chief Sanitary Inspectorate (GIS) has maintained a register of dietary supplements before, but the amendment will significantly expand its scope and availability. The data will be published on the e-Sanepid platform and will include:</p>



<ul class="wp-block-list">
<li>the name of the product and its qualitative composition (without quantitative data &#8211; the recipe remains protected),</li>



<li>product qualification proposed by the entity,</li>



<li>information about the initiation or ongoing investigation,</li>



<li>data on the detection of a prohibited ingredient.</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Reputational risk before final decision</strong></td></tr><tr><td>Information about the initiation of an investigation will appear in the public register immediately &#8211; not after the proceedings have concluded. Consumers and competitors will have access to this information before the Chief Sanitary Inspectorate issues any ruling. Even if the proceedings end favorably for the company, the registry record could impact brand perception.</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">5. Fines &#8211; increase by over 330%</h1>



<p>The maximum administrative fine for violating food safety regulations is increasing from 30 to 100 times the average monthly salary. At the current salary level, this means:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td>&nbsp;</td><td><strong>Before the amendment</strong></td><td><strong>After the amendment</strong></td></tr><tr><td><strong>Multiplier</strong></td><td>30×</td><td><strong>100×</strong></td></tr><tr><td><strong>Maximum penalty</strong></td><td>approx. PLN 245,000</td><td><strong>approx. PLN 818,000</strong></td></tr></tbody></table></figure>



<p>The new penalties are imposed administratively (not as fiscal or misdemeanor offenses), which means faster proceedings and no need to prove intentional guilt. A mere finding of a violation is sufficient. The increased level of sanctions has a real deterrent effect, especially for companies with turnover in the tens of millions of zlotys.</p>



<h1 class="wp-block-heading">The biggest risks &#8211; a practical overview</h1>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Risk area</strong></td><td><strong>Triggering situation</strong></td><td><strong>Consequence</strong></td></tr><tr><td><strong>Advertising before submission</strong></td><td>Launch of the campaign on social media before the official confirmation of receipt of the notification by the Chief Sanitary Inspectorate</td><td>Fine up to approximately PLN 818,000</td></tr><tr><td><strong>Exceeding the 14-day deadline</strong></td><td>No application submitted to the scientific unit within 14 days of the request by the Chief Sanitary Inspectorate</td><td>Automatic presumption of product irregularity; termination of proceedings to the detriment of the entity</td></tr><tr><td><strong>Errors in the product description on the website</strong></td><td>Content suggesting medicinal properties or claiming that a diet without a supplement is insufficient</td><td>Fine of up to approximately PLN 818,000; risk of product recall</td></tr><tr><td><strong>Publicity of the proceedings</strong></td><td>Initiation of explanatory proceedings by GIS</td><td>Immediate publication of information in the public register &#8211; reputational damage before resolution</td></tr><tr><td><strong>Sale without notification</strong></td><td>Distribution to wholesalers or stores before effective notification of the Chief Sanitary Inspectorate</td><td>A fine of up to approximately PLN 818,000; possible ban on further trading</td></tr><tr><td><strong>No trusted profile/signature</strong></td><td>The employees responsible for reporting do not have the required qualifications</td><td>Notification submitted ineffectively &#8211; risk of sanctions as for failure to notify</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>What is worth doing before the regulations come into force?</strong></td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>1. Register on the e-Sanepid platform</strong></td></tr><tr><td>Ensure that at least two people in your company have a qualified electronic signature or an active trusted profile. Register a company account on e-Sanepid before the law comes into effect and complete a test application. A lack of technical readiness on the date the regulations come into effect could prevent you from legally introducing new products to the market.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>2. Audit current submissions and the new product calendar</strong></td></tr><tr><td>Check that all products in your offer have successfully submitted notifications to the Chief Sanitary Inspectorate. For products planned for launch in the coming months, submit notifications well in advance of the planned sale date or marketing campaign. Take into account the waiting time for official confirmation of receipt.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>3. Implement a procedure for monitoring deadlines in explanatory proceedings</strong></td></tr><tr><td>Designate a person responsible for receiving correspondence from the e-Sanepid platform and immediately forwarding documents to legal or compliance services. The 14-day deadline for submitting a request for a scientific opinion is short—missing it automatically creates a presumption of irregularities. It&#8217;s worth identifying accredited scientific institutions now with which the company could quickly establish cooperation if proceedings are initiated.</td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>4. Verify all marketing materials – websites, social media, product descriptions</strong></td></tr><tr><td>Analyze the content on your website, online store, social media profiles and sales materials for:</td></tr><tr><td>suggestions for medicinal or therapeutic properties of supplements,</td></tr><tr><td>information suggesting that a normal diet does not provide adequate nutrients,</td></tr><tr><td>promoting products for which the GIS notification has not yet been successfully submitted.</td></tr><tr><td>Influencer marketing campaigns deserve special attention – messages created by third parties still place the responsibility on the company commissioning the campaign.</td></tr></tbody></table></figure>



<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>5. Monitor the GIS register and respond to information about proceedings</strong></td>
</tr>
<tr>
<td>Once the expanded SEPIS register is launched, regularly check the status of your products. If you receive information about the initiation of an investigation, act immediately. Inaction at this stage can lead to automatic assumptions of irregularities and reputational damage that will be publicly visible throughout the proceedings.</td>
</tr>
</tbody>
</table>
</figure>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/">CLIENT ALERT Dietary supplements market in Poland Amendments to food safety regulations | May 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/client-alert-dietary-supplements-market-in-polandamendments-to-food-safety-regulations-may-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</title>
		<link>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:40:05 +0000</pubDate>
				<category><![CDATA[INVESTMENT LAW AND PROCESSES IN POLAND]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Governance]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[Cyber Risk;]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8816</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The Act amending the Act on the National Cybersecurity System aims to implement Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS Directive 2) and the partial application of Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 of the European Parliament and of the Council.</p>



<p id="ember4587">The amendment to the KSC Act significantly expands the scope of the regulations and introduces new obligations in the field of cybersecurity management. The changes include, among other things, the implementation of risk management systems and expanded incident reporting requirements. The new regulations also strengthen the powers of supervisory authorities and significantly increase the maximum amount of financial penalties. It also introduces liability for the management staff (manager) of an entity. In practice, this requires certain entities to take steps to comply with the new regulations.</p>



<span id="more-8816"></span>



<p id="ember4588"><strong>The first experiences of entrepreneurs after the amendment came into force – practical conclusions</strong></p>



<p id="ember4589">The few months that the amended Act on the National Cybersecurity System has been in effect demonstrate that the biggest challenge for businesses is no longer the analysis of the new regulations, but their practical implementation. For many organizations, the adaptation process began with a seemingly simple task: determining whether a given entity is even subject to the new regulations. In practice, this step proves to be one of the most problematic.</p>



<p id="ember4590">Under the previous legal framework, many businesses awaited a formal administrative decision confirming their status as an essential service operator. This approach is no longer appropriate. The status of a key or important entity stems directly from the Act, and obligations arise regardless of whether the business has already been entered on the register. This means that the responsibility for properly assessing their own situation rests primarily with the business itself.</p>



<p id="ember4591">Practice also shows that many companies focus solely on the issue of being entered into the register of key and important entities. However, entry itself is not the purpose of the regulation. The greatest challenges remain the actual implementation of an information security management system, conducting a risk analysis, developing incident response procedures, and adequately documenting the actions taken. In the future, supervisory authorities will primarily assess an organization&#8217;s actual level of compliance with the Act, not merely the formal fulfillment of registration obligations.</p>



<p id="ember4592">Another significant change is the significant increase in management responsibility. Management can no longer treat cybersecurity as a matter solely within the purview of IT departments. The Act requires active management involvement in the organization of the cybersecurity management system, oversight of its operation, and provision of adequate organizational and financial resources. In practice, this requires regular reporting on cybersecurity issues at the management level and documentation of decisions made.</p>



<p id="ember4593">Supply chain security is also becoming increasingly important. Businesses are required not only to secure their own IT systems but also to consider the risks arising from collaboration with IT service providers, cloud computing operators, software vendors, and outsourcing providers. In practice, this means reviewing supplier contracts, verifying the security measures in place, and implementing appropriate provisions for incident management and crisis cooperation.</p>



<p id="ember4594">It&#8217;s also noticeable that a growing number of businesses are choosing to conduct internal compliance audits before the statutory deadlines expire. This approach allows for early identification of organizational and technical gaps, reducing the risk of subsequent violations and costly remedial actions.</p>



<p id="ember4595">In practice, the best solution is to treat the implementation of the Act&#8217;s requirements not as a one-time project, but rather as a process encompassing regular risk analysis, procedure updates, employee training, and ongoing oversight of the organization&#8217;s security. This approach not only increases compliance but also significantly reduces the risk of cybersecurity incidents.</p>



<p id="ember4596">It&#8217;s worth emphasizing that the current transition period should be used to calmly prepare organizations for the full application of the new regulations. Postponing implementation until the final months before the statutory deadlines expire can be risky, especially for large organizations where implementing information security management systems requires the involvement of multiple departments and adequate time to prepare procedures and documentation.</p>



<h2 class="wp-block-heading" id="ember4597">Change in the circle of entities to which the Act applies.</h2>



<p id="ember4598">Under the previous wording of the Act, an administrative decision was required to recognize an entity as an essential service operator (Article 5 of the Act before the amendment). Currently, the group of key and important entities is determined automatically (ex lege). The criteria for qualifying an entity as essential are found in Article 5, Section 1, and as an important entity in Article 5, Section 2 of the Act. It is possible that an entity meets the criteria for both key and important entities; such an entity is considered a key entity under Article 5, Section 4. When attempting to qualify entities, the Act also refers to EU regulations, particularly Regulation 651/2014/EU, which defines SMEs. Therefore, the primary criteria taken into account will be the number of employees and annual turnover. It is also necessary to refer to Annexes 1 and 2 of the Act, which precisely define the categories of entrepreneurs in specific sectors and subsectors.</p>



<p id="ember4599">The added Article 5a in paragraph 1 provides that key and important entities are subject to the obligations arising from the Act if they reside in the territory of the Republic of Poland or conduct their business in the territory of the Republic of Poland.</p>



<p id="ember4600">Articles 7 et seq. regulate matters related to the list of key and important entities. Before the amendment, the list contained only operators of essential services; now it includes key and important entities. Unlike the previous legal status, in which entry was made at the request of the authority responsible for cybersecurity (former wording of Article 7, paragraph 3 of the Act), entry is now made at the request of a key or important entity within six months of the occurrence of the conditions (Article 7c, paragraph 1 of the Act). Ex officio entry will generally only apply to existing operators of essential services, trust service providers, telecommunications companies, and public entities. This means that for entities meeting the conditions on the date the amendment comes into force, the deadline for submitting an application is October 3, 2026. Pursuant to the Announcement of the Minister of Digitization of April 8, 2026, regarding the schedule for submitting applications for entry in the register of key and important entities and for key or important entities to commence using the ICT system , self-registration on the list is possible from May 7, 2026, to October 3, 2026. The platform operating in the S46 system is available at <a href="https://wykaz-ksc.gov.pl/">https://wykaz-ksc.gov.pl/</a> . By April 3, 2027, key and important entities are required to commence using the ICT system specified in Art. 46 sec. 1 of the Act. This deadline begins depending on whether the entities were parties to agreements regarding the use of the ICT system referred to in Art. 46 sec. 1 of the Act concluded before April 3, 2026. For the former, the possibility of using the system was opened on April 8, 2026, and for the latter, this possibility will be available from June 12, 2026 (point 2 of the Communication of the Minister of Digital Affairs).</p>



<p id="ember4601">If an entity that meets the criteria for being considered a key or important entity fails to submit an application for entry, the authority responsible for cybersecurity may enter the entity on the list ex officio (Article 7j, paragraph 1 of the Act). Failure to comply with certain obligations related to the list (failure to timely complete missing data on the list or failure to correct data despite a request or failure to submit an application for entry) may result in the imposition of a substantial fine (Article 73, paragraph 1, point 1 and Article 73, paragraph 1a, point 1 of the Act). The catalogue of data to be included on the list has also been changed (expanded) (Article 7, paragraph 2).</p>



<p id="ember4602"><strong>In practice: </strong>The expansion of the scope of entities and the shift from administrative decision-making to automatic regulation mean that many entities may be subject to the Act without formal confirmation of this status. In practice, independent qualification analysis and continuous monitoring of compliance with statutory criteria become crucial. An incorrect assessment (or failure to comply) may result in exposure to sanctions (severe fines).</p>



<h2 class="wp-block-heading" id="ember4603">New responsibilities for cybersecurity management.</h2>



<h3 class="wp-block-heading" id="ember4604">Duties</h3>



<p id="ember4605">Chapter 3, which governs the obligations of key and important entities, has been expanded, and Chapters 3a and 3b have been added, addressing domain name registration service providers and public entities. Article 8 of the Act governs obligations related to the implementation of an information security management system. Compared to the previous legal framework, numerous obligations have been added. The responsibility of the manager of a key or important entity for the performance of its cybersecurity obligations has been introduced (Article 8c of the Act), and the manager&#8217;s responsibilities have also been defined (Articles 8d–8f of the Act).</p>



<p id="ember4606">The regulations regarding incident reporting have also changed. A key or important entity classifies a given incident as serious (after meeting the requirements of Article 2, Section 7 of the Act), then issues an early warning, reports the incident, and finally submits a final report on the handling of the serious incident to the CSIRT (a three-step reporting model instead of the previous one-step model – Article 11 of the Act).</p>



<h2 class="wp-block-heading" id="ember4607">Deadlines</h2>



<p id="ember4608">Pursuant to Article 15 of the Act, key entities must conduct a security audit of the information system used in the service provision process at least once every three years. For key entities that were not previously classified as key service operators, the first audit should be conducted within 24 months of the date the conditions are met (Article 16, point 2, therefore, for these entities, the deadline for conducting the audit is April 3, 2028).</p>



<p id="ember4609">The Act amending the KSC Act establishes a 12-month transition period during which key and important entities have time to fulfill the obligations specified in Chapter 3 of the Act (except for the obligation to conduct the first audit, which entities have 24 months to conduct). Therefore, with respect to obligations such as implementing an information security management system, risk assessment, implementing technical and organizational measures, reporting and managing incidents, and verifying personnel&#8217;s criminal records, the deadline for compliance with these regulations expires on April 3, 2027.</p>



<p id="ember4610"><strong>In practice: </strong>The imposed obligations require the implementation of an information security management system. Furthermore, the single-tier incident reporting system has been changed, replaced by a more complex three-tier system. Essential entities will be required to conduct audits. Importantly, entities that were not previously considered essential service operators will be required to conduct an audit within two years of the amendment&#8217;s entry into force. However, most of the new obligations will have to be implemented by April 3, 2027. Failure to comply with these obligations will result in the manager of the relevant entity being held liable.</p>



<h2 class="wp-block-heading" id="ember4611">Change in the amount and grounds for imposing fines.</h2>



<p id="ember4612">Until April 2, 2026, the maximum amount of the fine imposed on entities (only for the most serious violations) was PLN 1 million (former wording of Article 73, paragraph 5 in fine). Currently, the maximum amount of the fine is, as a rule, EUR 10 million (Article 73, paragraph 3 of the Act), and for the most serious violations, up to PLN 100 million (Article 73, paragraph 5 in fine of the Act).</p>



<p id="ember4613">With the imposition of a large number of obligations on key and important entities, the list of violations for which a fine may be imposed has also been expanded (Article 73 of the Act).</p>



<p id="ember4614">The new provisions on fines come into force only two years after the entry into force of the Act (i.e. from April 3, 2028).</p>



<p id="ember4615"><strong>In practice: </strong>Increasing the amount of fines disciplines key entities and important entities to take their cybersecurity obligations very seriously. It is worth emphasizing, however, that the amended regulations on fines will not enter into force until April 3, 2028.</p>



<h2 class="wp-block-heading" id="ember4616">Changes in the supervision and control of key and important entities.</h2>



<p id="ember4617">Chapter 11 of the Act, which deals with the supervision and control of key and important entities, has been significantly expanded. Some provisions remain unchanged (the requirement to apply the provisions of the Entrepreneurs&#8217; Law or the Act on Audit in Government Administration, the powers of the person conducting the audit, most of the obligations of audited entities, and provisions regarding audit protocols and post-audit recommendations).</p>



<h2 class="wp-block-heading" id="ember4618">Important changes</h2>



<p id="ember4619">The most important changes in the scope of supervision include a significant expansion of Article 53, which describes the powers of the authority responsible for cybersecurity regarding supervision and oversight of key entities. It empowers the competent authority to issue various types of administrative decisions aimed at enforcing the provisions of the Act. This article also contains a number of procedural provisions defining the nature of the proceedings. Generally, the regulations contained in this article apply only to key entities, but as stated in Article 53, paragraph 17, certain provisions also apply to inspections of important entities. Article 53, paragraph 3 states that supervision of key entities is both post-empty and preventive, while for important entities, supervision is only post-empty.</p>



<p id="ember4620">A new obligation for both key and important entities is the information obligation specified in Article 53c, which requires a key or important entity to provide certain data at the request of the authority responsible for cybersecurity.</p>



<p id="ember4621">A new institution is the ad hoc review added in Article 59c, which may be carried out only if the conditions specified in the cited Article are met.</p>



<p id="ember4622"><strong>In practice: </strong>Strengthening the powers of supervisory authorities and introducing ad hoc inspections means increased risk of inspections and the need to maintain constant readiness to demonstrate compliance with regulations. Entities should also prepare for more frequent requests for information from authorized bodies.</p>



<h2 class="wp-block-heading" id="ember4623">Minor changes</h2>



<p id="ember4624">Chapter 10 has been amended and Chapters 10a – 10c have been added, but they do not contain any standards addressed to entities and are therefore not relevant from a practical point of view.</p>



<p id="ember4625">Several changes concern Chapter 12 concerning the Government Plenipotentiary for Cybersecurity and the Cybersecurity Board, but these changes do not have any significant impact on the entities.</p>



<p id="ember4626">Article 12a has been added, addressing specific measures to ensure cybersecurity at the national level. It primarily contains provisions on recommendations from the Government Plenipotentiary for Cybersecurity (Article 67a), the procedure for designating a supplier as a high-risk supplier (Articles 67b–67f), and a safeguarding order in the event of a critical incident (Articles 67g–67i).</p>



<p id="ember4627">Minor changes also apply to the Cybersecurity Strategy of the Republic of Poland (Articles 68–72). The changes primarily concern the content and method of developing the strategy, as well as the frequency of strategy reviews (2.5 years instead of the previous 2 years).</p>



<p id="ember4628">The amendment to the Act on the National Emergency Response Plan creates the basis for the adoption of the National Emergency Response Plan (Articles 72a – 72f of the Act).</p>



<h2 class="wp-block-heading" id="ember4629">Recommended actions.</h2>



<p id="ember4630">In light of the amendments to the Commercial Companies Code, entities subject to the new regulations should take steps to ensure their operations are in compliance with the law. It is recommended that:</p>



<p id="ember4631">1)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Self-identification in order to determine whether a given entity qualifies as a key or important entity within the meaning of the Act.</p>



<p id="ember4632">2)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Implementation or update of an information security management system.</p>



<p id="ember4633">3)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Development of procedures for identifying and reporting incidents, taking into account the new procedure.</p>



<p id="ember4634">4)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring the involvement of management staff, e.g. the manager&#8217;s implementation of the obligations under Article 8d or 8e.</p>



<p id="ember4635">5)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Preparing the organization for potential supervisory activities, e.g. inspections.</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4637">ex officio entries carried out by the Minister of Digital Affairs (current key service operators, trust service providers, telecommunications companies and public entities)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4639">April 13 – May 6, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4641">self-registration in the list of key and important entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4643">May 7 – October 3, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4645">launching the possibility of using the S46 system for new entities</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4647">June 12, 2026</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4649">end of the deadline for starting to use the S46 system and implementing obligations (end of the adjustment period)</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4651">April 3, 2027</p>



<ul class="wp-block-list">
<li><em>Action:</em></li>
</ul>



<p id="ember4653">the first ISMS audit (for key entities that were not key service operators) and the beginning of the application of the provisions on penalties</p>



<ul class="wp-block-list">
<li><em>Deadline:</em></li>
</ul>



<p id="ember4655">April 3, 2028</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/">NIS2 in Poland: Practical Implications of the New Cybersecurity Framework for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/nis2-in-poland-practical-implications-of-the-new-cybersecurity-framework-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
