{"id":3475,"date":"2026-10-06T10:36:18","date_gmt":"2026-10-06T10:36:18","guid":{"rendered":"https:\/\/sawaryn.com\/?p=3475"},"modified":"2026-10-06T10:36:33","modified_gmt":"2026-10-06T10:36:33","slug":"separating-it-polish-group-company-sale-spin-off","status":"publish","type":"post","link":"https:\/\/sawaryn.com\/en\/publikacje\/separating-it-polish-group-company-sale-spin-off\/","title":{"rendered":"Separating IT When a Polish Group Company Is Sold or Spun Off"},"content":{"rendered":"<p>\u201cWe need to sell a subsidiary. How long will it take to separate the IT?&quot; \u2014 \u201cTwo weeks.&quot; \u2014 \u201cAnd how long will it really take?&quot; \u2014 \u201cThree months, if you start with the inventory you have never conducted and the data processing agreements you have never signed.&quot;<\/p>\n<p>In corporate groups, IT is not a service. It is a habit. For years, no one signs any agreements because companies within the same group \u201ctrust each other.&quot; The facts outpace the legal arrangements, and no one has a problem with that\u2014as long as the group stays together. The problem arises on the day when something that was never consciously woven together has to be untangled: the sale of a subsidiary, a spin-off, a change of ownership, or making an entity independent.<\/p>\n<p>If you run a corporate group with centralized IT, are planning a spin-off, or are preparing a company for sale, this article explains the legal, tax, and operational risks you must address when <strong>exiting intra-group IT<\/strong>. You will learn what steps to take before signing any agreement, how to secure the GDPR layer, and what to do with licenses that do not transfer automatically between companies.<\/p>\n<h2>Key concepts you need to know before starting the separation<\/h2>\n<p>Before moving on to specific steps, it is worth clarifying the terminology. Separating IT within a corporate group involves several legal regimes at once\u2014and each uses its own concepts.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Concept<\/th>\n<th style=\"text-align:left\">What it means<\/th>\n<th style=\"text-align:left\">Why it matters when separating IT<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\"><strong>Data processing agreement (Article 28 GDPR)<\/strong><\/td>\n<td style=\"text-align:left\">An agreement between a data controller and an entity that processes data on its behalf<\/td>\n<td style=\"text-align:left\">If company A administered company B\u2019s systems without such an agreement, the processing was in breach of the GDPR throughout the entire period<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Assignment of an agreement<\/strong><\/td>\n<td style=\"text-align:left\">The transfer of rights and obligations under an agreement to another entity<\/td>\n<td style=\"text-align:left\">The terms of cloud providers (Google, Microsoft) may require written consent to an assignment\u2014without it, the handover schedule becomes unrealistic<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Controlled transaction (Article 11c of the CIT Act)<\/strong><\/td>\n<td style=\"text-align:left\">A transaction between related entities whose prices must reflect market conditions<\/td>\n<td style=\"text-align:left\">A free-of-charge transfer of IT between group companies generates income from gratuitous benefits for the receiving party<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>TSA (transitional services agreement)<\/strong><\/td>\n<td style=\"text-align:left\">An agreement governing the temporary provision of services (e.g. IT) after a transaction<\/td>\n<td style=\"text-align:left\">In Polish practice, a typical TSA period ranges from several weeks to three months<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Exit strategy<\/strong><\/td>\n<td style=\"text-align:left\">A documented plan for terminating cooperation with an ICT provider<\/td>\n<td style=\"text-align:left\">Formally required for entities subject to DORA and NIS2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Why separating IT within a corporate group is a legal rather than a technical problem<\/h2>\n<p>Most management boards treat IT separation as a task for the technical department: \u201chand over the passwords, transfer the domains, carry out the migration.&quot; But a handover is not simply about providing a password. It involves changing a party to an agreement or establishing an entirely new legal relationship from scratch.<\/p>\n<h3>Four areas you need to address in parallel<\/h3>\n<ol>\n<li>\n<p><strong>Contractual matters.<\/strong> Agreements with cloud providers contain clauses restricting assignment. The Google Workspace terms prohibit the transfer or assignment of any part of the agreement without the other party\u2019s written consent\u2014except for an assignment to an affiliate that agrees in writing to comply with the terms of the agreement. The assignor remains liable for obligations arising before the assignment. Any other attempted transfer is void. It is the provider\u2014not an agreement between the companies\u2014that determines the actual schedule.<\/p>\n<\/li>\n<li>\n<p><strong>Regulatory matters.<\/strong> DORA (Regulation 2022\/2554) requires financial entities to maintain a documented and tested exit plan for every ICT agreement supporting critical functions. NIS2 (Directive 2022\/2555) introduces analogous requirements for managing risks associated with ICT providers. Check whether either party is subject to these regulations\u2014if so, ending the relationship with an ICT provider (even an intra-group one) requires a formal exit strategy.<\/p>\n<\/li>\n<li>\n<p><strong>Tax matters.<\/strong> Gratuitous IT services between related entities generate income under Article 12(1)(2) of the CIT Act for the beneficiary. The amount of income is determined based on prices charged to other customers or market prices for comparable services (Article 12(6) of the CIT Act). Questions about costs must be asked BEFORE signing, not afterward.<\/p>\n<\/li>\n<li>\n<p><strong>Data protection matters.<\/strong> Years of personal data processing by the company administering the IT without a data processing agreement (Article 28 GDPR) constitute a breach that does not disappear on the day the parties separate\u2014that is precisely when it becomes visible. A transfer of data within a group does not have a separate legal basis merely because the companies are related. <a href=\"https:\/\/sawaryn.com\/publikacje\/co-to-jest-rodo\/\">Recital 48 GDPR<\/a> (legitimate interest) is an argument, not an exemption from obligations.<\/p>\n<\/li>\n<\/ol>\n<h2>IT asset inventory\u2014what to do before signing any agreement<\/h2>\n<p>Before you sign an IT handover agreement, you need to know what you are handing over. It sounds obvious. It is not.<\/p>\n<h3>Three questions for every item<\/h3>\n<p>For every IT asset (cloud systems, email, security, hosting, domains and their registrant details, network and server equipment, licenses, hardware), answer three questions:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Question<\/th>\n<th style=\"text-align:left\">Why it matters<\/th>\n<th style=\"text-align:left\">Consequence of having no answer<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Who owns it?<\/td>\n<td style=\"text-align:left\">Company B\u2019s domains may be registered to company A. Licenses may have been purchased through company A\u2019s account.<\/td>\n<td style=\"text-align:left\">After the transaction, the buyer of company B discovers that it has no rights to the domains or software<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Who is the party to the agreement with the provider?<\/td>\n<td style=\"text-align:left\">Assignment of an agreement requires the provider\u2019s consent. The provider\u2019s procedure may take weeks.<\/td>\n<td style=\"text-align:left\">The schedule in the agreement becomes unrealistic\u2014the companies planned a handover within 2 weeks, but the provider needs 8 weeks<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Who administers it?<\/td>\n<td style=\"text-align:left\">Some access credentials exist only \u201cin the head&quot; of one IT employee or in a private password manager<\/td>\n<td style=\"text-align:left\">After the separation, no one knows the password to a critical system<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Assets that are easy to overlook<\/h3>\n<ol>\n<li>Service and shared accounts (not assigned to any individual)<\/li>\n<li>Access credentials stored in the private password managers of individual IT employees<\/li>\n<li>API tokens, SSH keys, SSL certificates<\/li>\n<li>MFA configurations linked to private phones<\/li>\n<li>Email archives<\/li>\n<li>Ticketing systems containing customer data from both companies<\/li>\n<li>Monitoring systems and security logs<\/li>\n<li>Backups (including copies held by external providers)<\/li>\n<\/ol>\n<p>Compile a list of ALL privileged accounts\u2014including unofficial ones. If the answer to the question \u201cwho has access&quot; is \u201cI don\u2019t know,&quot; that in itself is a sign that an inventory must be conducted before taking any further steps.<\/p>\n<p><a href=\"https:\/\/sawaryn.com\/en\/contact\/\">Contact us<\/a><\/p>\n<h2>The GDPR layer\u2014a breach that only comes to light upon separation<\/h2>\n<h3>Why the absence of a data processing agreement is a problem now, rather than \u201csometime in the past&quot;<\/h3>\n<p>If the answer to the question \u201cdo we have a data processing agreement with every data controller in the group&quot; is \u201cwe never thought about it,&quot; this means that the processing was in breach of Article 28 GDPR throughout the entire period of cooperation.<\/p>\n<p>A breach of Article 28 GDPR (absence of a data processing agreement) is subject to an administrative fine of up to <strong>EUR 10 million or 2% of annual turnover<\/strong> (Article 83(4) GDPR). A breach of the obligation to report a personal data breach (Articles 33\u201334 GDPR) is subject to a fine of up to <strong>EUR 10 million or 2% of turnover<\/strong>.<\/p>\n<p>Moreover, Article 82(5) GDPR provides for recourse between jointly liable entities. No <a href=\"https:\/\/sawaryn.com\/publikacje\/jak-zabezpieczyc-odpowiedzialnosc-w-umowach\/\">limitation of liability clause<\/a> can exclude this. Article 47(2)(f) GDPR also establishes the principle that a group entity with an establishment in the EU is liable for breaches of corporate rules by another group member.<\/p>\n<h3>What you need to do about GDPR before the separation<\/h3>\n<ol>\n<li>\n<p><strong>Determine the roles.<\/strong> Establish who was the controller and who was the processor throughout the entire period of shared IT. This is not a matter of declarations\u2014what counts is who actually determined the purposes and means of processing.<\/p>\n<\/li>\n<li>\n<p><strong>Enter into the missing data processing agreements.<\/strong> Do so no later than the date on which the agreement is signed, separately with each controller. A data processing agreement entered into after years of processing without one will not undo the breach\u2014but it will put matters in order going forward.<\/p>\n<\/li>\n<li>\n<p><strong>Negotiate a written statement on the status of data processing.<\/strong> Require the transferring party to provide: a list of systems and data categories, a list of sub-processors and the countries in which processing takes place, information on <a href=\"https:\/\/sawaryn.com\/publikacje\/transfer-danych-osobowych-poza-ue\/\">transfers outside the EEA<\/a>, a history of breaches and reports, and confirmation of authorizations and confidentiality obligations.<\/p>\n<\/li>\n<li>\n<p><strong>Set a deadline and define the scope for permanently deleting data after the handover is complete.<\/strong> Article 28(3)(g) GDPR requires data to be returned or deleted after processing ends. Explicitly list the locations that are easy to overlook: backups, email archives, ticketing systems, password managers, monitoring systems, and logs. Require written confirmation of deletion.<\/p>\n<\/li>\n<li>\n<p><strong>Maintain the mutual obligation to report breaches.<\/strong> Set a short notification deadline and keep this obligation in effect for a specified period after the handover is complete\u2014for events originating during the period of shared IT.<\/p>\n<\/li>\n<\/ol>\n<h2>Licenses that do not transfer automatically<\/h2>\n<p>Software licenses do not transfer automatically between companies. A transfer requires the licensor\u2019s consent or an explicit basis in the license agreement (Article 74 et seq. of the <a href=\"https:\/\/sawaryn.com\/publikacje\/prawo-autorskie-w-branzy-it-najwazniejsze-informacje\/\">Copyright Act<\/a>).<\/p>\n<p>Verify whether each license is transferable. Where a license cannot be transferred, plan and price the purchase of a new license by the receiving party <strong>before<\/strong> signing the agreement. Using software without a valid license after the separation constitutes copyright infringement.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Scenario<\/th>\n<th style=\"text-align:left\">Risk<\/th>\n<th style=\"text-align:left\">What to do<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">License purchased through company A\u2019s account and used by company B<\/td>\n<td style=\"text-align:left\">Company B loses the right to use it after the separation<\/td>\n<td style=\"text-align:left\">Check the licensor\u2019s transfer terms; if a transfer is impossible, purchase a new license<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Group license (volume licensing)<\/td>\n<td style=\"text-align:left\">Dividing the licenses requires the licensor\u2019s consent and may change the pricing terms<\/td>\n<td style=\"text-align:left\">Contact the licensor and agree the terms of the division before signing the agreement<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Software developed internally within the group<\/td>\n<td style=\"text-align:left\">The copyright may belong to company A (the employer of the creators)<\/td>\n<td style=\"text-align:left\">Determine who holds the rights and prepare a license or rights transfer agreement<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Free software (open source, freeware)<\/td>\n<td style=\"text-align:left\">As a rule, there is no income from a gratuitous benefit\u2014but an internally developed system made available exclusively to group companies may be classified differently<\/td>\n<td style=\"text-align:left\">Review the open-source license terms and internal documentation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Procedures for changing the contracting entity with cloud providers\u2014what you need to know<\/h2>\n<p>Polish law does not contain a statute specifically governing cloud computing. Whether cloud agreements may be assigned is assessed under the general provisions of the Civil Code, the GDPR, and sector-specific guidelines (KNF, CSIOZ). This means that the actual restrictions arise from the providers\u2019 terms and conditions.<\/p>\n<h3>Google Workspace<\/h3>\n<ol>\n<li>The terms prohibit assignment without written consent\u2014the exception is an assignment to an affiliate that agrees in writing to comply with the terms of the agreement<\/li>\n<li>Domain Transfer requires at least 7 days to implement retention rules in Google Vault, 48 hours to convert the primary domain into a secondary domain, and 24 hours for a test run<\/li>\n<li>The primary domain cannot be transferred while it remains the main domain\u2014it must first be converted into a secondary domain<\/li>\n<li>The administrators of both environments must expressly authorize the domain transfer team<\/li>\n<\/ol>\n<h3>Microsoft 365 \/ Azure<\/h3>\n<ol>\n<li>Transferring ownership of Azure subscription billing requires acceptance by the future owner\u2014after the transfer, role assignments must be reviewed and updated<\/li>\n<li>Changing an Azure subscription\u2019s directory requires an account with an owner role in both the current and new Microsoft Entra directories\u2014after the operation, it may take several hours for all data to become visible<\/li>\n<li>Migrating OneDrive and Exchange Online between tenants requires establishing a relationship between the administrators of both tenants\u2014the migration time depends on the number of users and the volume of data<\/li>\n<li>Microsoft\u2019s technical documentation does not require corporate documents (e.g. an extract from the National Court Register) as a condition for the operation\u2014the entire process is based on administrative permissions<\/li>\n<\/ol>\n<p>Conclusion: <strong>the schedule agreed between the companies must account for provider procedures.<\/strong> Companies planning a handover within 2 weeks may discover that the provider needs 8 weeks to change the contracting entity.<\/p>\n<h2>Phased handover\u2014how to avoid gaps and overlaps<\/h2>\n<p>A gap means an outage\u2014after the separation, no one manages critical systems, leading to operational downtime. An overlap creates a security risk\u2014both parties have full administrative permissions to the same systems, and if an incident occurs, neither can demonstrate whose actions caused it.<\/p>\n<h3>Three handover phases<\/h3>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Phase<\/th>\n<th style=\"text-align:left\">Scope<\/th>\n<th style=\"text-align:left\">Deadline<\/th>\n<th style=\"text-align:left\">Rationale<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\"><strong>Phase 1<\/strong><\/td>\n<td style=\"text-align:left\">Cloud environments and accounts (handover of administrative permissions)<\/td>\n<td style=\"text-align:left\">Firm deadline\u2014set in the agreement<\/td>\n<td style=\"text-align:left\">Technically the quickest to complete; requires only a change of credentials<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Phase 2<\/strong><\/td>\n<td style=\"text-align:left\">Equipment (physical relocation)<\/td>\n<td style=\"text-align:left\">Firm deadline\u2014set in the agreement<\/td>\n<td style=\"text-align:left\">Requires logistics, but no construction work<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Phase 3<\/strong><\/td>\n<td style=\"text-align:left\">Network layer (design, equipment purchases, physical work, possible rewiring)<\/td>\n<td style=\"text-align:left\">Reasonable timeframe\u2014without a fixed date<\/td>\n<td style=\"text-align:left\">Requires design, procurement, and physical work; the timeframe depends on the scope<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Handover mechanism for each asset<\/h3>\n<p>Design a two-stage mechanism:<\/p>\n<ol>\n<li><strong>Provision of credentials<\/strong>\u2014the transferring party provides passwords, keys, and tokens through a secure channel (password manager, one-time link, encrypted channel)<\/li>\n<li><strong>Confirmation of receipt<\/strong>\u2014the receiving party confirms receipt within a specified period; failure to respond by the deadline constitutes tacit confirmation<\/li>\n<\/ol>\n<p>Link the transfer of responsibility to the date of confirmed receipt, <strong>not<\/strong> to the date on which the agreement is signed.<\/p>\n<p>After confirming receipt of each asset, the receiving party changes the passwords, keys, tokens, certificates, and MFA configuration. The transferring party deletes its copies of the credentials. Keep an up-to-date register of the access credentials handed over\u2014including the handover date and the date of confirmed receipt for each item. It is both an operational tool and a record of evidence.<\/p>\n<h2>No-objections statement\u2014why you should not sign it blindly<\/h2>\n<p>Any general no-objections statement made on the date the agreement is signed is a statement made blindly. The receiving party confirms the quality of IT support that it had no way of verifying\u2014because it did not have administrative access to the systems.<\/p>\n<h3>How to limit the risk<\/h3>\n<p>Limit the no-objections statement to disclosed and verifiable circumstances. Exclude the following from its scope:<\/p>\n<ol>\n<li>Security configurations (e.g. whether MFA was enabled or backups were working)<\/li>\n<li>Access history (who had administrative permissions and when)<\/li>\n<li>Personal data breach events (incidents of which the receiving party is unaware)<\/li>\n<li>Compliance of data processing with the GDPR<\/li>\n<\/ol>\n<p>Supreme Court case law confirms that a waiver of future claims is permissible\u2014but only if the legal relationship from which the future claims are to arise is defined with sufficient precision (Supreme Court judgment I CSK 125\/08). A waiver of \u201cuncreated&quot; claims may be effective if the clause expressly covers claims \u201cthat may arise in the future&quot; (Supreme Court judgment II CSKP 1361\/22 of 24 April 2024)\u2014but this does not mean that you should accept such a clause without limitations.<\/p>\n<h3>What cannot be waived<\/h3>\n<p>Exclude from the waiver clause anything that cannot be waived:<\/p>\n<ol>\n<li>Claims by data subjects (individuals whose data is processed)<\/li>\n<li>Recourse under Article 82(5) GDPR<\/li>\n<li>Liability toward the Polish Data Protection Authority<\/li>\n<li>Personal data breaches predating the handover<\/li>\n<li>Breaches of the agreement itself<\/li>\n<li>Liability for damage caused intentionally (Article 473 \u00a72 of the Civil Code\u2014liability for intentional damage cannot be excluded)<\/li>\n<\/ol>\n<h2>Tax considerations\u2014the free-of-charge transfer of IT between related entities<\/h2>\n<p>A free-of-charge transfer of IT between group companies is a controlled transaction within the meaning of the transfer pricing regulations. Ignoring this aspect may result in an upward adjustment of income.<\/p>\n<h3>What the law says<\/h3>\n<p>Under Article 12(1)(2) of the CIT Act, income includes the value of items or rights received, as well as the value of other gratuitous or partially paid benefits. In resolutions FPS 9\/02 and II FPS 1\/06, the Supreme Administrative Court defined a gratuitous benefit as any economic event resulting in a benefit obtained at another entity\u2019s expense without equivalent consideration and having a specific financial value.<\/p>\n<p>As a rule, the free-of-charge provision of IT infrastructure, ERP systems, server licenses, or IT support services by a related entity generates income for the beneficiary.<\/p>\n<h3>Documentation obligations<\/h3>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Obligation<\/th>\n<th style=\"text-align:left\">Legal basis<\/th>\n<th style=\"text-align:left\">Consequence of non-compliance<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Setting transfer prices on an arm\u2019s-length basis<\/td>\n<td style=\"text-align:left\">Article 11c of the CIT Act<\/td>\n<td style=\"text-align:left\">Upward adjustment of income by the tax authority<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Preparation of local transfer pricing documentation (if the thresholds are exceeded)<\/td>\n<td style=\"text-align:left\">Articles 11k\u201311l of the CIT Act<\/td>\n<td style=\"text-align:left\">No documentation = presumption that the transaction is not at arm\u2019s length<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Submission of a statement that transfer prices are at arm\u2019s length<\/td>\n<td style=\"text-align:left\">Article 11m of the CIT Act<\/td>\n<td style=\"text-align:left\">False certification\u2014a fine of up to 720 daily rates (Article 56c of the Fiscal Penal Code)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The paradox is that the statement under Article 11m of the CIT Act declares that the terms of a transaction are at arm\u2019s length when the transaction is inherently free of charge. Have the free-of-charge nature of the transfer reviewed from a tax perspective <strong>before<\/strong> signing the agreement\u2014not afterward.<\/p>\n<h2>The transitional period\u2014using another company\u2019s network without obligations<\/h2>\n<p>During the transitional period, the receiving company often uses the transferring company\u2019s network infrastructure. The network goes down on Friday evening\u2014and no one is obliged to repair it because permission to use it did not include any service terms.<\/p>\n<h3>What to regulate in the agreement<\/h3>\n<ol>\n<li>\n<p><strong>Prohibition on accessing the content of communications.<\/strong> The confidentiality of electronic communications regulated by the Electronic Communications Law (Act of 12 July 2024, Journal of Laws of 2024, item 1221) covers traffic data and location data. The prohibition on processing applies to all persons other than the sender and recipient\u2014including internal network operators.<\/p>\n<\/li>\n<li>\n<p><strong>Restrict the processing of traffic data<\/strong> to security purposes, with a specified retention period.<\/p>\n<\/li>\n<li>\n<p><strong>Obligation to provide notice<\/strong> of requests from public authorities and of planned work or disconnection\u2014with reasonable advance notice.<\/p>\n<\/li>\n<li>\n<p><strong>Service terms<\/strong>\u2014even minimal ones: response time, contact person, and escalation rules in the event of an outage.<\/p>\n<\/li>\n<\/ol>\n<h2>Subsequent disclosure mechanism\u2014what about assets discovered after signing<\/h2>\n<p>An inventory is rarely complete on the date of signing. Therefore, include a subsequent disclosure mechanism in the agreement: an obligation to provide, free of charge, access to assets discovered after the process begins, within a specified period from signing.<\/p>\n<p>This applies in particular to:<\/p>\n<ol>\n<li>Service accounts known to only one administrator<\/li>\n<li>Backups stored in locations not included in the original inventory<\/li>\n<li>API integrations with external systems of which the receiving party was unaware<\/li>\n<li>SaaS subscriptions paid for through the transferring company\u2019s account but used by the receiving company<\/li>\n<\/ol>\n<h2>NIS2 and DORA\u2014additional requirements for regulated entities<\/h2>\n<p>If either party is subject to NIS2 (Directive 2022\/2555) or DORA (Regulation 2022\/2554), ending the relationship with an ICT provider\u2014even an intra-group one\u2014requires a formal exit strategy.<\/p>\n<p>Article 28(2) DORA requires financial entities to maintain a documented and tested exit plan for every ICT agreement supporting critical functions. The plan must address contingency scenarios, the migration schedule, and business continuity.<\/p>\n<p>NIS2 introduces analogous requirements for managing risks associated with ICT providers. The PolishCloud 2.0 and 3.0 standards specify the elements of an exit plan for the Polish market.<\/p>\n<p>An intra-group provider is subject to the same requirements as an external provider\u2014there are no separate regulations for IT services provided within a corporate group.<\/p>\n<h2>Checklist: 12 steps before signing an IT handover agreement<\/h2>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">No.<\/th>\n<th style=\"text-align:left\">Step<\/th>\n<th style=\"text-align:left\">Category<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">1<\/td>\n<td style=\"text-align:left\">Conduct a complete inventory of IT assets, answering three questions for each one (owner, party to the agreement, administrator)<\/td>\n<td style=\"text-align:left\">Audit<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2<\/td>\n<td style=\"text-align:left\">Compile a list of all privileged accounts\u2014including unofficial ones<\/td>\n<td style=\"text-align:left\">Audit<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">3<\/td>\n<td style=\"text-align:left\">Review cloud providers\u2019 terms and conditions to determine whether assignment is permitted<\/td>\n<td style=\"text-align:left\">Legal review<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">4<\/td>\n<td style=\"text-align:left\">Verify whether each software license is transferable<\/td>\n<td style=\"text-align:left\">Legal review<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">5<\/td>\n<td style=\"text-align:left\">Determine the GDPR roles and enter into the missing data processing agreements<\/td>\n<td style=\"text-align:left\">Documentation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">6<\/td>\n<td style=\"text-align:left\">Negotiate a written statement on the status of data processing<\/td>\n<td style=\"text-align:left\">Documentation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">7<\/td>\n<td style=\"text-align:left\">Design a two-stage handover mechanism with an access register<\/td>\n<td style=\"text-align:left\">Process<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">8<\/td>\n<td style=\"text-align:left\">Divide the handover into phases (cloud \u2192 equipment \u2192 network)<\/td>\n<td style=\"text-align:left\">Process<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">9<\/td>\n<td style=\"text-align:left\">Limit the no-objections statement to verifiable circumstances<\/td>\n<td style=\"text-align:left\">Legal review<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">10<\/td>\n<td style=\"text-align:left\">Review the free-of-charge nature of the transfer from a tax perspective<\/td>\n<td style=\"text-align:left\">Legal review<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">11<\/td>\n<td style=\"text-align:left\">Regulate the transitional period (network, confidentiality of communications, service terms)<\/td>\n<td style=\"text-align:left\">Documentation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">12<\/td>\n<td style=\"text-align:left\">Include a subsequent disclosure mechanism<\/td>\n<td style=\"text-align:left\">Documentation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Separating IT within a group\u2014when to start and who to involve<\/h2>\n<p>Separating IT within a corporate group is not a two-week project. It is a process that requires lawyers, the IT department, the finance department, and the management board to work in parallel. The sooner you start, the lower the risk that on the day of the transaction you will discover that your company\u2019s domains are registered to another entity, MFA was never enabled, and no one reported two security incidents to the Polish Data Protection Authority.<\/p>\n<p>We prepare agreements for transferring IT functions between companies, conduct legal inventories of IT assets within corporate groups, negotiate separation terms, and secure the GDPR layer when systems are separated. We combine IT law, data protection, contract law, and corporate law in a single model\u2014because IT separation involves all of them at once.<\/p>\n<p>Are you planning a spin-off, sale, or separation of a group company? Before you start negotiating the price, find out how much it will cost to untangle the IT. <a href=\"https:\/\/sawaryn.com\/en\/contact\/\">Contact us<\/a>.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>We have centralized IT within the group, but nothing is documented\u2014where should we start?<\/strong><br \/>\nStart with an inventory of IT assets. For each item (cloud systems, email, domains, licenses, equipment), answer three questions: who owns it, who is the party to the agreement with the provider, and who administers it. Only after completing the inventory will you know what actually needs to be transferred\u2014and how long it will take.<\/p>\n<p><strong>Can we simply hand over the system passwords and consider the matter resolved?<\/strong><br \/>\nNo. Handing over a password does not change the party to the agreement with the provider, transfer licenses, resolve GDPR issues, or protect against liability for incidents occurring during the period of shared IT. The handover requires changing the party to an agreement or establishing a new legal relationship\u2014and that requires the provider\u2019s consent and takes time.<\/p>\n<p><strong>Who is liable for a GDPR breach that occurred 2 years ago, when one company processed another company\u2019s data without a data processing agreement?<\/strong><br \/>\nLiability depends on the parties\u2019 roles under the GDPR. Article 82(5) GDPR provides for recourse between jointly liable entities. Article 47(2)(f) GDPR establishes the principle that a group entity with an establishment in the EU may be liable for breaches by another group member. Entering into a data processing agreement after the event will not undo the breach\u2014but it will put matters in order going forward.<\/p>\n<p><strong>How long does it realistically take to separate IT between companies?<\/strong><br \/>\nIn Polish practice, a typical TSA period ranges from several weeks to three months. But this applies only to the provision of transitional services. A complete separation\u2014from the inventory and assignment of provider agreements to the deletion of data from backups\u2014may take longer, especially when cloud provider procedures require a separate process on their side.<\/p>\n<p><strong>Does a free-of-charge transfer of IT between group companies have tax consequences?<\/strong><br \/>\nYes. Gratuitous IT services between related entities generate income under Article 12(1)(2) of the CIT Act for the beneficiary. The transaction requires transfer pricing documentation (if it exceeds the materiality thresholds) and submission of the statement referred to in Article 11m of the CIT Act. False certification in this statement is punishable by a fine of up to 720 daily rates (Article 56c of the Fiscal Penal Code).<\/p>\n<p><strong>Our company is subject to NIS2\u2014does ending the relationship with an internal IT provider require additional documentation?<\/strong><br \/>\nYes. NIS2 and DORA require a formal exit strategy for ICT agreements supporting critical functions. An intra-group provider is subject to the same requirements as an external provider\u2014there are no separate regulations for IT services provided within a group. The exit plan must address contingency scenarios, the migration schedule, and business continuity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn what to inventory and resolve before separating group IT in Poland, from supplier contracts and licenses to GDPR, tax, and handover terms.<\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","sip_alt_url":"","sip_en_pl_url":"","sip_pair_uuid":"b40cec06-4e62-4743-bae9-11e2fe1054ba","sip_pair_state":"verified"},"categories":[1],"tags":[1548,1446,1539,1531,1549],"specialization":[1211],"practice_area":[],"class_list":["post-3475","post","type-post","status-publish","format-standard","hentry","category-bez-kategorii","tag-due-diligence-en","tag-gdpr","tag-license","tag-personal-data-protection","tag-taxes-en","specialization-it-ai-ip-law"],"acf":[],"_links":{"self":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/comments?post=3475"}],"version-history":[{"count":2,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3475\/revisions"}],"predecessor-version":[{"id":3479,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3475\/revisions\/3479"}],"wp:attachment":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/media?parent=3475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/categories?post=3475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/tags?post=3475"},{"taxonomy":"specialization","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/specialization?post=3475"},{"taxonomy":"practice_area","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/practice_area?post=3475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}