Back to the blog

The First 72 Hours After an Incident at a Company in Poland

Learn how to preserve evidence, classify overlapping incidents, track Polish notification deadlines and document management board decisions in the first 72 hours.

Monday morning. Three messages in the CEO’s inbox: HR reports a conflict in the development team, the DPO flags a possible leak of customer data, and a report has been submitted through the anonymous whistleblowing channel. All three concern the same person. The CEO does not know where to start — whether the deadline is 72 hours, 7 days, or whether action should be taken “without delay". And it is precisely this moment — between the event and the first decision — that determines whether the company emerges from the incident in a controlled manner or pays more for the chaos than for the problem itself.

If you run a technology company, SaaS business or scale-up, this scenario is not abstract. In 2024, CERT Polska recorded more than 100,000 confirmed security incidents — a 29% increase year on year. KPMG research indicates that 83% of companies recorded attempted attacks. And yet only 18% of small businesses have an incident response plan.

This article is a guide to the first 72 hours after an incident at a company. It is not a legal analysis, but an operational manual: how to classify the event, whom to notify, what to preserve, what not to do — and how to document the response in a way that protects the management board.

Key terms to understand before taking action

Before we move on to the steps, it is worth clarifying the terminology. Companies often confuse three different situations, which leads them to initiate the wrong procedure or — worse still — take no action at all.

Term Meaning Example Does it require a formal response?
Vulnerability A weakness in a system, network or software that may be exploited An outdated version of a library in an application Does not require notification, but does require remediation
Potential event An attempt to exploit a vulnerability that did not compromise the confidentiality, integrity or availability of data A blocked phishing attempt Worth documenting; as a rule, formal notification is not required
Incident An event that has actually caused adverse consequences — a data leak, loss of availability or harm to individuals Sending a customer database to an unauthorised recipient Yes — it triggers notification and documentation obligations

This distinction has a direct bearing on your obligations. If the event constitutes an incident within the meaning of the GDPR, you have 72 hours to notify the President of the UODO. If it is a whistleblower report — 7 days to acknowledge receipt and 3 months to provide feedback. If it is an occupational health and safety violation — the response should be immediate.

Misclassifying the event at the outset means that the company initiates the wrong procedure, omits mandatory actions or misses statutory deadlines. Each of these situations gives rise to separate liability.

Why post-incident chaos costs more than the event itself

The greatest risk is not the data leak itself, the team conflict or the whistleblower report. The risk is a chaotic, delayed or undocumented response. Here is why.

Concurrent liability under four legal regimes

A company incident rarely falls into a single category. A single event may trigger obligations under the GDPR, the Whistleblower Protection Act, the Labour Code and the Commercial Companies Code — all at the same time. And each of these regimes provides for separate penalties.

Legal regime Typical failure Penalty Legal basis
GDPR Failure to notify the UODO of a breach within 72 hours Up to EUR 10 million or 2% of turnover Articles 33–34 and Article 83(4) GDPR
GDPR Failure to notify individuals where there is a high risk Up to EUR 10 million or 2% of turnover Article 34 and Article 83(4) GDPR
Whistleblower Protection Act Obstructing a report Up to one year’s imprisonment (up to 3 years where threats or violence are used) Article 58 of the Whistleblower Protection Act
Whistleblower Protection Act Retaliation against a whistleblower Up to 2 years’ imprisonment (up to 3 years if persistent) Article 58 of the Whistleblower Protection Act
Labour Code Violations of employee rights (occupational health and safety, pay) Fine of PLN 1,000–30,000 Articles 281–283 of the Labour Code
Criminal Code Malicious or persistent violation of employee rights Up to 2 years’ imprisonment Article 218 § 1a of the Criminal Code
Commercial Companies Code Damage to the company caused by the management board’s fault (through action or omission) Liability for damages Article 293 § 1 of the Commercial Companies Code
Criminal Code Breach of trust — failure to fulfil duties resulting in substantial damage Criminal liability Article 296 of the Criminal Code

Note that the penalty for the mere failure to notify a GDPR breach within 72 hours concerns a separate infringement carrying a separate penalty — regardless of how serious the leak itself was. The President of the UODO imposed a fine of PLN 103,752 on Link4 specifically for failing to notify the breach on time, not for the incident itself. A court enforcement officer paid a total of approximately PLN 21,000 — PLN 7,700 for failing to notify the breach and PLN 13,200 for failing to inform the person whose data was affected.

Costs extend far beyond administrative fines

UODO penalties or fines imposed by the National Labour Inspectorate are only the tip of the iceberg. The full cost of a chaotic response includes:

  1. Data recovery and infrastructure replacement costs — if the incident affected production systems
  2. Personnel costs — overtime for IT, HR and legal teams; sometimes additional staff must be hired
  3. Compensation for customers and contractors — particularly where NDAs or data processing agreements have been breached
  4. Lost revenue — downtime, customer churn and suspended projects
  5. Crisis advisory costs — lawyers, IT forensics specialists and crisis PR advisers engaged “after the fact" cost many times more than prevention
  6. Employee claims — leave, overtime and compensation for workplace bullying if the company failed to respond to a report
  7. Reputational costs — loss of trust among the team, customers and investors

An early, structured response is many times less expensive than repairing the damage caused by improvisation.

Contact us

The first 72 hours after an incident — what to do step by step

Below is the sequence of actions your company should initiate as soon as an incident is identified. The order matters.

Step 1: preserve evidence — before anything else

Before you begin analysing, classifying and making decisions — preserve the evidence. This includes:

  1. Correspondence — emails and messages on Slack, Teams and other messaging platforms
  2. System logs — access records, logins, changes to permissions and file transfers
  3. Documents — agreements, notes, screenshots and reports
  4. Recordings — if the company uses video surveillance or records calls
  5. Data from HR systems — working time records, requests and appraisals

The rule is: do not delete, modify or move anything. Even if you believe a particular file is unrelated to the case. Delaying the preservation of evidence weakens the company’s position under every legal regime — from the GDPR to employment disputes.

Step 2: classify the event — initiate the correct procedure

This is the most common mistake: the company responds to an incident as though it were solely an HR problem, solely a data leak or solely an IT failure. In reality, a single event may require concurrent action across several areas.

Use the matrix below for rapid classification:

Question If YES → area Statutory deadline
Have personal data been lost, disclosed or accessed without authorisation? GDPR — notification to the UODO 72 hours
Was the report submitted through a whistleblowing channel, or does it concern a breach of law? Whistleblower Protection Act — internal investigation 7 days (acknowledgement), 3 months (feedback)
Does the event concern an employment relationship — workplace bullying, discrimination or an occupational health and safety violation? Labour Code — employer response Without delay
Does the event threaten the continuity of IT systems? Cybersecurity — incident response procedure 24 hours (serious incident, National Cybersecurity System Act)
Could the event give rise to management board liability towards the company? Commercial Companies Code — decision documentation No statutory deadline, but delay weakens the company’s position

If the answer is “YES" in more than one row, you are dealing with a multidisciplinary incident. You need coordination, not separate, unconnected courses of action.

Step 3: appoint an “incident owner"

Fragmented responsibility is the second most common mistake. HR thinks it is an IT matter. IT thinks it is a matter for the lawyer. The lawyer waits for information from HR. No one makes a decision.

Appoint one person (or a two-person team) who:

  1. Coordinates all post-incident activities — regardless of the type of incident
  2. Collects information from HR, IT, compliance and legal
  3. Reports directly to the management board
  4. Monitors statutory deadlines
  5. Decides on the order and priority of actions

The “incident owner" does not need to be an expert in every area. They need to know whom to involve and in what order.

Step 4: do no harm during the first 24 hours

Until the incident has been fully classified, the rule is “do not make the situation worse". Here is what not to do:

  1. Do not dismiss anyone — hastily terminating the contract of a person involved in a whistleblower report may be regarded as retaliation (punishable by up to 2 years’ imprisonment)
  2. Do not communicate publicly — either internally or externally, until you know the facts and have agreed on the narrative
  3. Do not delete correspondence or logs — even if they appear incriminating
  4. Do not make statements — written or oral — that may later be used against the company
  5. Do not ignore deadlines — the 72-hour deadline for notifying a GDPR breach runs from the moment the breach is identified, not from the moment it has been “fully investigated"

Recital 87 of the GDPR expressly states that the assessment of whether notification was made “without undue delay" should take into account the nature and gravity of the breach and its consequences. A documented decision-making process may protect the company even in the event of a minor delay. A lack of documentation will not.

Step 5: document every decision in real time

Every decision made during an incident should be recorded together with:

  1. The date and time it was made
  2. The decision-maker — who made the decision
  3. The rationale — why the decision was made and what information it was based on
  4. The alternatives — what other options were considered

The format does not need to be formal. An email to yourself, a note in a document or an entry in an incident management tool — they all count, provided they include a date and content.

Why is this so important? For two reasons.

First, Article 33(5) GDPR requires the documentation of all personal data breaches — including those that the company has decided not to notify to the UODO. You must have a written justification for that decision.

Second, Article 293 § 3 of the Commercial Companies Code (the business judgement rule) may protect the management board against liability for damages — but only if the board demonstrates that it acted loyally towards the company, within the limits of reasonable risk and on the basis of adequate information and analysis. Without documentation, there is nothing to demonstrate.

When an incident does not fit into a single category — conflicting procedures

At technology companies, incidents rarely concern just one area. A typical scenario is that the CTO leaves the company and takes the code repository. This simultaneously constitutes:

  1. An IP issue — infringement of rights to the source code
  2. A GDPR breach — if the code or systems contained customers’ personal data
  3. An NDA breach — if the code contained solutions covered by confidentiality agreements with contractors
  4. An HR issue — if the person was employed under an employment contract and is subject to a non-compete obligation or confidentiality clause
  5. A cybersecurity incident — if production systems were accessed without authorisation

Each of these areas has a different response deadline, supervisory authority and procedure. Without coordination, the company risks taking contradictory actions: the legal department sends a formal demand, HR conducts an investigatory interview, IT blocks access — while no one has checked whether the breach must be notified to the UODO within 72 hours.

A particular conflict: a whistleblower report and a GDPR breach

The Whistleblower Protection Act and the GDPR have different deadlines and procedures, but may apply to the same event. If a whistleblower reports a personal data leak, the company must simultaneously:

  1. Acknowledge receipt of the whistleblower report within 7 days
  2. Notify the UODO of the personal data breach within 72 hours
  3. Conduct an internal investigation under the whistleblowing procedure and provide feedback to the whistleblower within 3 months
  4. Protect the whistleblower’s identity (Article 8 of the Whistleblower Protection Act excludes the obligation to inform the person concerned by the report about the source of the data — Article 14(2)(f) GDPR)

These procedures must run concurrently, but they must not obstruct one another. The person conducting the internal investigation under the whistleblowing procedure should not also decide whether to notify the UODO — these should be independent tracks with a single coordination point.

How to protect the management board — the business judgement rule following the amendment to the Commercial Companies Code

The amendment to the Commercial Companies Code of 9 February 2022 (which entered into force on 13 October 2022) introduced the business judgement rule into Article 293 § 3. In simple terms, a management board member is not liable for damage caused to the company if they acted loyally and within the limits of reasonable business risk — including on the basis of information, analyses and opinions that should have been taken into account in the circumstances.

For incident response, this means specific requirements:

Condition for protection What this means during an incident How to document it
Loyalty towards the company The management board acted in the company’s interests, not in its own interests or those of third parties A decision note indicating that the actions were intended to protect the company
Reasonable business risk The decision was proportionate to the situation — neither overly cautious nor excessively risky A description of the alternatives considered and the reasons for selecting the chosen option
Adequate information and analysis The management board collected the available data before making its decision — it did not act “blindly" Incident classification report, legal opinion and risk analysis

Limit of protection: the business judgement rule does not protect against liability for breaching mandatory legal provisions. If the management board knew about a GDPR breach and deliberately failed to notify it within 72 hours, the business judgement rule will not help.

Prepare your company before an incident occurs — readiness checklist

Companies often have policies, regulations and procedures on paper but do not know how to apply them in a crisis. Below are the measures worth implementing before an incident occurs.

Priority measures (implement immediately)

  1. Check whether you have a written incident response procedure. Not a general security policy, but a specific sequence: who responds, in what order, what deadlines apply and who makes the decisions. If a procedure exists but no one knows it — it may as well not exist.

  2. Prepare an initial response card — a one-page document containing a checklist of the first 10 actions following an incident: whom to notify, what to preserve, what not to do and what deadlines are running. Distribute it to the management board, HR, IT and the person responsible for compliance.

  3. Establish an incident classification matrix — a table (like the one above in this article) that allows you to quickly determine whether an event is an HR issue, a GDPR breach, a whistleblower report, a cyber incident or a management risk.

  4. Appoint an incident owner — one person to coordinate the response, regardless of the type of incident.

  5. Introduce the practice of documenting decisions in real time — even in the form of an email containing the date, the decision and its rationale.

Recommended measures (implement within one month)

  1. Train the management board and managers in the principle of “doing no harm during the first 24 hours" — what not to communicate, what not to delete and whom not to dismiss before the event has been fully classified.

  2. Compile a crisis contact list — external lawyer, GDPR specialist, IT forensics company and crisis PR adviser. Keep it somewhere accessible before it is needed. Looking for support during a crisis costs hours you do not have.

  3. Ask a lawyer to review the existing procedures (workplace regulations, GDPR policy, whistleblowing procedure and IT security policy) for consistency — to check whether they contain conflicting provisions on who should respond and within what timeframe.

  4. Review the incident response clauses in your agreements with IT providers. If there are none, it is unclear who — the company or the provider — is responsible for which actions when an incident occurs. Properly drafted clauses allocate tasks to the parties, specify deadlines and divide responsibility.

Additional measures (implement within one quarter)

  1. Conduct a tabletop exercise — simulate an incident scenario (e.g. a customer data leak and a whistleblower report occurring at the same time) and check whether the team knows what to do. You will identify procedural gaps before a real problem arises.

  2. After every incident — even a minor one — hold a 30-minute “lessons learned" meeting with the team. What worked, what did not and what should be changed in the procedure. Update the initial response card.

We can help you

Incident response requires coordination across many areas of law — the GDPR, employment law, the Whistleblower Protection Act, corporate law and cybersecurity. A single lawyer specialising in one area will not be enough if an event extends beyond one category.

We support technology companies and scale-ups under three models:

  1. Incident readiness audit — we check whether your company has procedures, whether they are consistent, whether the team knows them and whether statutory deadlines have been taken into account. You receive a report identifying specific gaps and recommendations.

  2. Support during an incident — we coordinate the legal response, help classify the event, monitor notification deadlines and prepare documentation that protects the management board. We act as an external coordination point so that you can focus on running the company.

  3. Procedure implementation and training — we prepare an initial response card, classification matrix and breach management procedure, and train the management board and managers in incident response principles.

We bring together employment law, the GDPR, IT law and corporate law within a single team — because incidents at technology companies rarely fit neatly into one category.

A structured response protects the company better than the absence of an incident

No procedure will prevent every incident. But a structured response — rapid classification, preservation of evidence, documentation of decisions and coordination of actions — can limit financial losses, protect the management board from personal liability and allow the company to resume normal operations sooner.

Three things to do after reading this article:

  1. Check whether your company has a written incident response procedure — and whether anyone knows it.
  2. Appoint a person responsible for coordinating incident response.
  3. Prepare an initial response card and a crisis contact list.

If you need support with an incident readiness audit, preparing procedures or training the management board — contact us.

Frequently asked questions

We have an incident, but we do not know whether it is “serious" — how can we quickly assess whether a formal response is required?

Use three screening questions: (1) Have personal data been lost, disclosed or accessed without authorisation? If so, you have 72 hours to assess the incident and potentially notify the UODO. (2) Was the report submitted through a whistleblowing channel? If so, you have 7 days to acknowledge receipt. (3) Does the event concern employee safety? If so, the response should be immediate. If the answer is “yes" to more than one question, you are dealing with a multidisciplinary incident and need coordination.

Who in the company should make decisions following an incident — the management board, HR, a lawyer or the compliance officer?

Strategic decisions (notification to a supervisory authority, external communications and staffing decisions) belong to the management board. Operational coordination should be handled by an appointed “incident owner" — a person who gathers information from HR, IT, compliance and legal, monitors deadlines and reports to the management board. They do not need to be an expert in every area, but they must know whom to involve and in what order.

Is the management board personally liable if the company responded to an incident too slowly or incorrectly?

Yes — under Article 293 § 1 of the Commercial Companies Code, a management board member is liable for damage caused to the company by an action or omission contrary to the law. The 2022 amendment to the Commercial Companies Code introduced the business judgement rule (Article 293 § 3), which may protect the management board — but subject to three conditions: loyalty towards the company, acting within the limits of reasonable risk and basing decisions on adequate information. Without a documented decision-making process, there is nothing to demonstrate. Moreover, this rule does not protect against liability for breaching mandatory legal provisions — for example, knowingly missing the 72-hour deadline for notifying a GDPR breach.

We have procedures on paper, but no one knows them — does this protect us or count against us during an inspection?

It counts against you. A procedure that the team does not know or follow does not satisfy the accountability requirement (Article 5(2) GDPR) or the obligation to implement appropriate organisational measures. During an inspection by the UODO or the National Labour Inspectorate, or in court proceedings, the company must demonstrate that the procedures were implemented, known and followed — not merely written down. This is why regular training and tabletop exercises are just as important as the document itself.

Everything has settled down after the incident — do I still need to do anything to close the matter formally?

Yes. Closing the matter requires: (1) an entry in the breach register (the GDPR requires all breaches to be documented, including those not notified to the UODO, together with the reasons for the decision not to notify), (2) feedback to the whistleblower within 3 months (if the event concerned a whistleblower report), (3) a closing note describing the actions taken, conclusions and recommendations, and (4) updates to procedures based on lessons learned from the incident. The aim is to prepare the company for questions from a regulator, employee, contractor, auditor or court — even if they arise several months later.

How should an incident be communicated internally without causing panic or concealing the problem?

Communicate facts, not speculation. Appoint one person responsible for internal communications. Provide the team with three pieces of information: (1) what happened (without details that could prejudice the investigation), (2) what the company is doing in response, and (3) whom to contact with questions. Avoid messages such as “nothing happened" — if the incident later proves serious, the company will lose credibility. Also avoid excessive alarmism — it makes it more difficult to conduct a calm internal investigation.

POLECANE

mogą Cię zaciekawić

Wybrane przykłady projektów, w których wspieraliśmy firmy w sprawach prawnych - od doradztwa regulacyjnego i compliance, przez projekty technologiczne, po transakcje i bieżącą obsługę biznesu.