{"id":3493,"date":"2026-10-06T13:07:12","date_gmt":"2026-10-06T13:07:12","guid":{"rendered":"https:\/\/sawaryn.com\/?p=3493"},"modified":"2026-10-06T13:07:34","modified_gmt":"2026-10-06T13:07:34","slug":"compliance-growing-tech-company-poland","status":"publish","type":"post","link":"https:\/\/sawaryn.com\/en\/publikacje\/compliance-growing-tech-company-poland\/","title":{"rendered":"Compliance for a Growing Technology Company in Poland: From Scattered Policies to a Working System"},"content":{"rendered":"<p>Imagine this situation: during due diligence, an investor asks about the AI policy, the whistleblowing procedure, and the data processing map. The CTO looks at the COO, the COO looks at HR, and HR says, \u201cI think legal has that.&quot; No one has the full picture. This is not an exception \u2014 this is what compliance looks like at most growing technology companies. And this is exactly when the transaction starts to get complicated.<\/p>\n<p>If your company employs 50\u2013200 people, processes customer data, uses AI tools, and is planning a funding round, you are now subject to at least a dozen overlapping regulatory regimes. GDPR, the Whistleblower Protection Act, the AI Act, the amendment to the National Cybersecurity System Act (NIS2), employment law, and industry-specific regulations. Each of these areas has different deadlines, different supervisory authorities, and different penalties.<\/p>\n<p>In this article, I will show you how to move from fragmented, reactive compliance to a structured system \u2014 with a map of obligations, priorities, and owners. Without legal jargon. With specific steps.<\/p>\n<h2>Key terms to know before reading<\/h2>\n<p>Before we continue, I will explain a few terms that will appear throughout the article. Each of them has a direct impact on your company\u2019s obligations.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Term<\/th>\n<th style=\"text-align:left\">What it means for your company<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\"><strong>Compliance<\/strong><\/td>\n<td style=\"text-align:left\">A set of measures ensuring that the company operates in accordance with applicable laws \u2014 not only that it has the relevant documents, but that it actually follows them<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Accountability<\/strong><\/td>\n<td style=\"text-align:left\">The principle under Article 5(2) GDPR \u2014 you must not only comply with the law but also be able to prove it (e.g. during an inspection by the Polish Data Protection Authority, UODO)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Data controller<\/strong><\/td>\n<td style=\"text-align:left\">The entity that determines the purposes and means of processing personal data \u2014 at a technology company, this is usually the company itself<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>AI literacy<\/strong><\/td>\n<td style=\"text-align:left\">An obligation under Article 4 of the AI Act \u2014 providers and deployers of AI systems must ensure that their employees have an appropriate level of AI literacy<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>AI deployer<\/strong><\/td>\n<td style=\"text-align:left\">A company that uses an AI system in its operations \u2014 it has fewer obligations than a provider, but must ensure human oversight, input data quality, and employee notification<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Due diligence<\/strong><\/td>\n<td style=\"text-align:left\">A legal and financial review of a company conducted before an investment or acquisition \u2014 increasingly, it includes a comprehensive compliance review<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Regulatory map for your technology company in 2026<\/h2>\n<p>Let us start with the rules that actually apply. Below is an overview of the regulations that typically apply to a technology or SaaS company operating in Poland.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Regulation<\/th>\n<th style=\"text-align:left\">Status<\/th>\n<th style=\"text-align:left\">Supervisory authority<\/th>\n<th style=\"text-align:left\">Maximum penalties<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">GDPR (Regulation 2016\/679)<\/td>\n<td style=\"text-align:left\">Applicable since 2018<\/td>\n<td style=\"text-align:left\">UODO<\/td>\n<td style=\"text-align:left\">Up to EUR 20 million or 4% of global turnover<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Whistleblower Protection Act (of 14 June 2024)<\/td>\n<td style=\"text-align:left\">Applicable since 25 September 2024<\/td>\n<td style=\"text-align:left\">Public prosecutors, courts<\/td>\n<td style=\"text-align:left\">A fine for failing to establish a procedure; up to 2 years\u2019 imprisonment for retaliation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">AI Act (Regulation 2024\/1689)<\/td>\n<td style=\"text-align:left\">Phased entry into force from 1 August 2024<\/td>\n<td style=\"text-align:left\">National authorities (currently being designated)<\/td>\n<td style=\"text-align:left\">Up to EUR 35 million or 7% of global turnover<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Amendment to the National Cybersecurity System Act (NIS2)<\/td>\n<td style=\"text-align:left\">Applicable since 3 April 2026<\/td>\n<td style=\"text-align:left\">Competent cybersecurity authorities<\/td>\n<td style=\"text-align:left\">Up to EUR 10 million or 2% of turnover; up to PLN 100 million (extraordinary penalty)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Labour Code (occupational health and safety, working time, and employment rules)<\/td>\n<td style=\"text-align:left\">Applicable<\/td>\n<td style=\"text-align:left\">PIP<\/td>\n<td style=\"text-align:left\">Fixed penalties, fines, and wage payment orders<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">DSA (Regulation 2022\/2065)<\/td>\n<td style=\"text-align:left\">Applicable since 17 February 2024<\/td>\n<td style=\"text-align:left\">Digital Services Coordinator<\/td>\n<td style=\"text-align:left\">Up to 6% of annual worldwide turnover<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Data Act (Regulation 2023\/2854)<\/td>\n<td style=\"text-align:left\">Phased application from 12 September 2025<\/td>\n<td style=\"text-align:left\">National authorities<\/td>\n<td style=\"text-align:left\">Determined at national level<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This is not an exhaustive list \u2014 depending on the industry, DORA (financial sector), MiCA (crypto-assets), CRA (products with digital elements), and <a href=\"https:\/\/sawaryn.com\/publikacje\/esg-co-to-jest-i-kogo-dotyczy\/\">CSRD (ESG reporting)<\/a> may also apply. But even the seven regulations listed above create dozens of separate obligations, deadlines, and documentation requirements.<\/p>\n<h3>AI Act timeline \u2014 what already applies and what takes effect in the coming months<\/h3>\n<p>The AI Act deserves a separate discussion because its obligations are being phased in, and many technology companies are not keeping track of these dates.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Date<\/th>\n<th style=\"text-align:left\">What takes effect<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">2 February 2025<\/td>\n<td style=\"text-align:left\">Prohibitions on unacceptable-risk practices (Article 5) \u2014 including emotion recognition in the workplace and social scoring. AI literacy obligation (Article 4)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2 August 2025<\/td>\n<td style=\"text-align:left\">Obligations for general-purpose AI models (Chapter V)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2 August 2026<\/td>\n<td style=\"text-align:left\">Full application as a general rule + transparency obligations (Article 50) \u2014 labelling AI-generated content and informing people that they are interacting with an AI system<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2 December 2027<\/td>\n<td style=\"text-align:left\">Obligations for stand-alone <a href=\"https:\/\/sawaryn.com\/publikacje\/systemy-wysokiego-ryzyka-wedlug-ai-act\/\">high-risk AI systems<\/a> (Annex III)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2 August 2028<\/td>\n<td style=\"text-align:left\">Obligations for AI systems embedded in products (Annex I)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>If your company uses AI tools in HR (e.g. CV screening), marketing (personalisation), or sales (chatbots, recommendations), the AI literacy obligation already applies. So do the prohibitions under Article 5. Check whether your tools violate the prohibitions on emotion recognition or subliminal manipulation.<\/p>\n<p>Moreover, a company may unknowingly shift from the role of an <a href=\"https:\/\/sawaryn.com\/publikacje\/czym-jest-system-ai-w-rozumieniu-ai-act\/\">AI deployer<\/a> to that of a provider \u2014 for example, by putting its own logo on a system, making a substantial modification to the algorithm, or changing its intended purpose. This radically increases the scope of its obligations: from human oversight and log retention to a comprehensive risk management system, technical documentation, and a conformity assessment before the system is placed on the market.<\/p>\n<h3>NIS2 in Poland \u2014 deadlines already running<\/h3>\n<p><a href=\"https:\/\/sawaryn.com\/publikacje\/dyrektywa-nis-2-nowa-era-cyberbezpieczenstwa-w-unii-europejskiej\/\">The amendment to the National Cybersecurity System Act<\/a> entered into force on <strong>3 April 2026<\/strong> \u2014 later than the EU deadline (18 October 2024). The European Commission sent Poland a reasoned opinion on 7 May 2025.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Deadline<\/th>\n<th style=\"text-align:left\">Obligation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">By 6 May 2026<\/td>\n<td style=\"text-align:left\">Ex officio registration of essential and important entities<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">7 May \u2013 3 October 2026<\/td>\n<td style=\"text-align:left\">Self-registration of entities in the register<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">By 3 April 2027<\/td>\n<td style=\"text-align:left\">Implementation of cybersecurity risk management measures<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">By 3 April 2028<\/td>\n<td style=\"text-align:left\">First audit of essential entities + full penalty regime<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Penalties: up to EUR 10 million or 2% of turnover for essential entities; up to EUR 7 million or 1.4% of turnover for important entities. Extraordinary penalty \u2014 up to PLN 100 million. Personal liability of the entity\u2019s manager: <strong>up to 600% of their monthly remuneration<\/strong>.<\/p>\n<p><a href=\"https:\/\/sawaryn.com\/en\/contact\/\">Contact us<\/a> \u2014 we will help determine whether your company is an essential or important entity under NIS2 and plan the implementation.<\/p>\n<h2>Why compliance breaks down at growing companies \u2014 and the risks this creates<\/h2>\n<h3>Each department sees only its own piece of the puzzle<\/h3>\n<p>HR knows its employment law obligations. IT knows about security controls. Legal knows about contracts. But no one combines this information into a single map. No one knows whether the whistleblowing procedure is consistent with the GDPR policy. No one checks whether the contract with an AI provider addresses the obligations under the AI Act.<\/p>\n<p>This is not a lack-of-knowledge problem. It is a lack-of-coordination problem.<\/p>\n<h3>The documents exist, but no one follows them<\/h3>\n<p>Many companies have privacy policies, internal rules, and confidentiality statements. But regulators \u2014 UODO, PIP, and cybersecurity authorities \u2014 do not ask, \u201cDo you have a document?&quot; They ask, \u201cDo you follow it, and can you prove it?&quot;<\/p>\n<p><a href=\"https:\/\/sawaryn.com\/publikacje\/co-to-jest-rodo\/\">The accountability principle<\/a> under Article 5(2) GDPR means that your company must demonstrate compliance \u2014 the authority does not have to prove the infringement. Personal data confidentiality statements should be signed before employees begin working with data, kept in personnel records, and monitored by the organisation for compliance. During a UODO inspection, these documents may serve as evidence of compliance \u2014 but only if they are actually used in practice.<\/p>\n<p>The same applies to a password policy: it must be formally approved, technically implemented by IT, monitored through audits, and updated. Responsibility for enforcing it is spread across IT, managers, the DPO, and the management board. One compliance component \u2014 four departments that must work together.<\/p>\n<h3>Inspection statistics \u2014 how many companies are affected<\/h3>\n<p>Data for 2024 shows the scale of supervisory authorities\u2019 activity:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Authority<\/th>\n<th style=\"text-align:left\">Inspections \/ decisions in 2024<\/th>\n<th style=\"text-align:left\">Financial penalties<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">UODO<\/td>\n<td style=\"text-align:left\">8,056 complaints, 14,842 data breach notifications, 1,719 administrative decisions, 22 penalty decisions<\/td>\n<td style=\"text-align:left\">McDonald&#8217;s Polska: PLN 16.9 million; ING Bank \u015al\u0105ski: PLN 18.4 million; Morele.net: PLN 3.8 million<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">PIP<\/td>\n<td style=\"text-align:left\">61,900 inspections at 49,800 entities, 6,000 wage payment orders totalling PLN 214 million<\/td>\n<td style=\"text-align:left\">PLN 23.3 million in fixed penalties (up 5.4% year on year); 15,900 employers penalised<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>In its sectoral inspection plan for 2024, UODO identified, among others, entities processing data using <strong>online web applications<\/strong> \u2014 this directly affects SaaS and e-commerce companies. Inspections of marketing entities and online delivery platforms are planned for 2026.<\/p>\n<p><a href=\"https:\/\/sawaryn.com\/publikacje\/nowe-uprawnienia-pip-w-pytaniach-i-odpowiedziach\/\">PIP conducted inspections<\/a> at entities employing a total of approximately 3.8 million people. The most common infringements were failure to keep working time records or keeping unreliable records (almost half of the entities examined), failure to record overtime, and violations of the right to daily and weekly rest.<\/p>\n<h3>Personal liability of the management board \u2014 this is not theoretical<\/h3>\n<p>The absence of a compliance system creates risks not only for the company but also personally for its management board members.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Legal basis<\/th>\n<th style=\"text-align:left\">Scope of liability<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Articles 293 and 483 of the Commercial Companies Code<\/td>\n<td style=\"text-align:left\">Civil liability of a management board member for damage caused to the company by an act or omission contrary to the law or the company\u2019s articles of association<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">2022 amendment to the Commercial Companies Code<\/td>\n<td style=\"text-align:left\">The supervisory board is required to assess compliance systems; the business judgment rule protects decisions made within the bounds of justified risk, but it does not protect the absence of a system<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 107 of the Personal Data Protection Act<\/td>\n<td style=\"text-align:left\">Criminal liability for unlawful data processing: up to 2 years\u2019 imprisonment; for special-category data \u2014 up to 3 years<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 108 of the Personal Data Protection Act<\/td>\n<td style=\"text-align:left\">Obstructing a UODO inspection: up to 2 years\u2019 imprisonment<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 58 of the Whistleblower Protection Act<\/td>\n<td style=\"text-align:left\">A fine for failing to establish an internal reporting procedure or for establishing one in material breach of the requirements<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 220 of the Criminal Code<\/td>\n<td style=\"text-align:left\">Criminal liability for violating occupational health and safety regulations<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 296 of the Criminal Code<\/td>\n<td style=\"text-align:left\">Breach of trust in business dealings<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Amendment to the National Cybersecurity System Act (NIS2)<\/td>\n<td style=\"text-align:left\">Personal liability of the manager: up to 600% of their monthly remuneration<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Article 116 of the Tax Ordinance Act<\/td>\n<td style=\"text-align:left\">Liability of a management board member for the company\u2019s tax arrears<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The 2022 amendment to the Commercial Companies Code introduced the business judgment rule \u2014 but this rule protects decisions made within the bounds of justified business risk. It does not protect a situation in which the management board has failed to implement any compliance oversight system at all. The absence of compliance may constitute an independent basis for liability.<\/p>\n<h2>What compliance costs \u2014 and what non-compliance costs<\/h2>\n<p>A comparison of the cost of building a compliance system with the cost of non-compliance over a 5-year period:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Category<\/th>\n<th style=\"text-align:left\">Option A: compliance system<\/th>\n<th style=\"text-align:left\">Option B: no system<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Personnel costs (compliance officer + support)<\/td>\n<td style=\"text-align:left\">~PLN 270,000\/year<\/td>\n<td style=\"text-align:left\">PLN 0 (until an incident occurs)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Employee training<\/td>\n<td style=\"text-align:left\">~PLN 80,000\/year<\/td>\n<td style=\"text-align:left\">PLN 0<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">IT tools and systems<\/td>\n<td style=\"text-align:left\">~PLN 70,000\/year<\/td>\n<td style=\"text-align:left\">PLN 0<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Audits and reviews<\/td>\n<td style=\"text-align:left\">~PLN 30,000\/year<\/td>\n<td style=\"text-align:left\">PLN 0<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Total (5 years)<\/strong><\/td>\n<td style=\"text-align:left\"><strong>~PLN 2.25 million<\/strong><\/td>\n<td style=\"text-align:left\"><strong>PLN 0<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">GDPR fine (single incident)<\/td>\n<td style=\"text-align:left\">Risk minimised<\/td>\n<td style=\"text-align:left\">Up to EUR 20 million or 4% of turnover<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Post-incident remediation costs<\/td>\n<td style=\"text-align:left\">Minimal<\/td>\n<td style=\"text-align:left\">PLN 2.5\u20133 million (fine + remediation + claims)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Lost investment transaction<\/td>\n<td style=\"text-align:left\">Risk minimised<\/td>\n<td style=\"text-align:left\">Impossible to estimate \u2014 but it happens<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The median monthly salary of a compliance officer in Poland is PLN 10,650 gross. The total annual cost of employment (including employer contributions) is approximately PLN 170,000\u2013190,000. This is a fraction of what a company may have to pay for a single GDPR infringement.<\/p>\n<p>The total value of UODO fines imposed on the private sector in one recent year exceeded PLN 64 million \u2014 up from approximately PLN 13 million the previous year and approximately PLN 1 million two years earlier. The trend is clear.<\/p>\n<h2>How to move from firefighting to a system \u2014 4 steps<\/h2>\n<h3>Step 1: inventory your regulatory obligations<\/h3>\n<p>Bring together information from HR, IT, legal, administration, and operations. Document:<\/p>\n<ol>\n<li>Who is currently responsible for what in the area of compliance<\/li>\n<li>The relevant legal basis (GDPR, employment law, the Whistleblower Protection Act, the AI Act, NIS2)<\/li>\n<li>What documents and procedures exist \u2014 and where they are physically stored<\/li>\n<li>Which obligations have an assigned owner and which are \u201cfalling through the cracks&quot;<\/li>\n<\/ol>\n<p>The goal is not a perfect legal analysis. The goal is to obtain a complete picture \u2014 even if imperfect \u2014 of what the company is and is not doing.<\/p>\n<h3>Step 2: prioritised risk map<\/h3>\n<p>Based on the inventory, assign each obligation to one of three categories:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Priority<\/th>\n<th style=\"text-align:left\">Description<\/th>\n<th style=\"text-align:left\">Examples<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Critical<\/td>\n<td style=\"text-align:left\">An infringement may result in a financial or criminal penalty or block a transaction<\/td>\n<td style=\"text-align:left\">No whistleblowing procedure (Article 58 of the Whistleblower Protection Act); failure to report a GDPR breach within 72 hours (Article 33 GDPR); violation of AI Act prohibitions<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Important<\/td>\n<td style=\"text-align:left\">Risk of an administrative penalty or issues during due diligence<\/td>\n<td style=\"text-align:left\">Outdated GDPR documentation; no AI literacy policy; incomplete working time records<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Forward-looking<\/td>\n<td style=\"text-align:left\">An obligation that takes effect in the future or applies to the company conditionally<\/td>\n<td style=\"text-align:left\">NIS2 obligations (if the company is not yet an essential\/important entity); CRA; CSRD<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Assign an owner within the organisation and an implementation deadline to each obligation. It does not have to be a lawyer \u2014 it may be the HR Manager, CTO, or COO. What matters is that one person knows the issue is \u201ctheirs&quot;.<\/p>\n<h3>Step 3: review existing procedures \u2014 what works and what is dead<\/h3>\n<p>Review all compliance documents by asking three questions:<\/p>\n<ol>\n<li><strong>Is the document up to date?<\/strong> \u2014 a GDPR policy from 2019 may not reflect changes in UODO case law, new IT tools, or changes in the company\u2019s structure<\/li>\n<li><strong>Does anyone follow it?<\/strong> \u2014 if employees do not know that a procedure exists, it is not a procedure \u2014 it is a file on a drive<\/li>\n<li><strong>Does it reflect the actual business model?<\/strong> \u2014 a procedure written for a 20-person company will not work at a 150-person company with three offices<\/li>\n<\/ol>\n<p>Identify documents that are dead (no one follows them), duplicated (two departments have their own versions), outdated (they do not account for new regulations), or missing (e.g. no data breach response procedure or AI use policy).<\/p>\n<h3>Step 4: coordination and periodic review<\/h3>\n<p>Designate one person or team to coordinate compliance across the organisation. Even if it is only a part-time role, someone must have the authority to bring together information from different departments.<\/p>\n<p>Prepare a simple compliance dashboard for the management board:<\/p>\n<ol>\n<li>Status of obligations (green \/ amber \/ red)<\/li>\n<li>Open risks with assigned owners<\/li>\n<li>Planned actions with deadlines<\/li>\n<li>Regulatory changes that may affect the company in the next quarter<\/li>\n<\/ol>\n<p>Update it quarterly. Schedule a recurring compliance review in the management board\u2019s calendar \u2014 at least once every six months.<\/p>\n<h2>Preparing for an inspection and due diligence \u2014 what to have ready in advance<\/h2>\n<p>Both a UODO or PIP inspection and investor due diligence may arise at short notice. The company should have a document pack ready that can be provided within 48 hours of a request.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Area<\/th>\n<th style=\"text-align:left\">What should be ready<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">GDPR<\/td>\n<td style=\"text-align:left\">Record of processing activities, privacy policy, <a href=\"https:\/\/sawaryn.com\/publikacje\/twoje-dane-w-obcych-rekach-jak-bezpiecznie-powierzac-przetwarzanie-danych\/\">data processing agreements<\/a>, data breach response procedure, confidentiality statements, DPIA results (if required)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Whistleblowing<\/td>\n<td style=\"text-align:left\">Internal reporting procedure, report register, evidence that the procedure was communicated to employees<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Employment law<\/td>\n<td style=\"text-align:left\">Working time records, personnel records, workplace regulations, contracts (employment, B2B), occupational health and safety documentation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">AI<\/td>\n<td style=\"text-align:left\">List of AI tools used in the organisation, risk assessment, AI literacy policy, AI system logs (at least 6 months)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Cybersecurity<\/td>\n<td style=\"text-align:left\">Information security policy, incident response procedure, audit results, business continuity plan<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Contracts<\/td>\n<td style=\"text-align:left\">Contract templates for business partners, contract register, contractual risk analysis<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Contractual risk management \u2014 particularly in IT contracts \u2014 should be integrated with the compliance system. Decisions on liability caps, exclusions, and financial safeguards should be based on risk analysis, and material deviations from contracting standards should be formally approved at management level.<\/p>\n<h2>We can help you with this<\/h2>\n<p>Building a compliance system at a growing technology company requires expertise across several areas of law \u2014 GDPR, employment law, AI, cybersecurity, contract law, and corporate law. We do not divide these into separate projects. We combine them into a single operating model tailored to your organisation\u2019s structure, scale, and pace of growth.<\/p>\n<p>Our support includes:<\/p>\n<ol>\n<li><strong>Inventory of obligations<\/strong> \u2014 we gather information from all departments and create a complete map of the regulations that apply to your company<\/li>\n<li><strong>Prioritised risk map<\/strong> \u2014 we identify what is critical, important, and forward-looking, and assign owners and deadlines<\/li>\n<li><strong>Document review and updates<\/strong> \u2014 we identify gaps, eliminate dead procedures, and prepare missing documents<\/li>\n<li><strong>Preparation for inspections and due diligence<\/strong> \u2014 we build a document pack that can be provided within 48 hours<\/li>\n<li><strong>Training for the management board and team<\/strong> \u2014 not on the legislation itself, but on practical obligations: what you must do, what you must not do, and whom to contact<\/li>\n<li><strong>Ongoing monitoring<\/strong> \u2014 we inform you about regulatory changes and update the map of obligations<\/li>\n<\/ol>\n<p>We do not create documents \u201cjust in case.&quot; We design rules where risks actually arise \u2014 and tailor them to how your company operates day to day.<\/p>\n<h2>Compliance does not have to slow your company down \u2014 a lack of compliance does<\/h2>\n<p>A growing technology company faces an increasing number of regulatory obligations. GDPR, whistleblowing, the AI Act, NIS2, employment law \u2014 each of these regulations imposes separate requirements and has different deadlines and penalties. Without a single system, the management board loses control of risks that may jeopardise an investment, a contract, or the company\u2019s reputation.<\/p>\n<p>Moving from firefighting to a system requires four things: an inventory of obligations, a prioritised risk map, a review of existing procedures, and the appointment of a coordinator authorised to bring together information from different departments.<\/p>\n<p>If you want to establish where your company stands on compliance today and what should be put in order first \u2014 <a href=\"https:\/\/sawaryn.com\/en\/contact\/\">contact us<\/a>. We will have a no-obligation conversation, without legal jargon, and end with specific conclusions.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>What compliance obligations apply to my technology company, and how can I find out?<\/strong><\/p>\n<p>The scope of your obligations depends on several factors: the number of employees (the threshold of 50 people under the Whistleblower Protection Act), the type of data processed (GDPR), the use of AI (AI Act), whether you operate in a sector covered by NIS2, and your sales model (DSA, Data Act). There is no single register that will display a list of your obligations \u2014 that is why the first step is an inventory carried out with the involvement of all departments: HR, IT, legal, and operations. This provides the basis for a map of obligations with assigned owners and deadlines.<\/p>\n<p><strong>As a CEO or founder, can I be held personally liable for compliance gaps?<\/strong><\/p>\n<p>Yes. Articles 293 and 483 of the Commercial Companies Code provide for the civil liability of a management board member for damage caused to the company. Article 107 of the Personal Data Protection Act makes unlawful data processing punishable by up to 2 years\u2019 imprisonment. Article 58 of the Whistleblower Protection Act provides for a fine if no reporting procedure has been established. The amendment to the National Cybersecurity System Act (NIS2) introduces personal liability of the manager of up to 600% of their monthly remuneration. The business judgment rule introduced by the 2022 amendment to the Commercial Companies Code protects decisions made within the bounds of justified risk \u2014 but it does not protect the absence of an oversight system.<\/p>\n<p><strong>Where should I start organising compliance if the company has grown quickly and no one has been managing it?<\/strong><\/p>\n<p>Start with an inventory. Gather information from every department: who is responsible for what, what documents exist, where they are stored, and whether anyone follows them. Then create a risk map with three priorities (critical, important, and forward-looking) and assign owners. Do not try to fix everything at once \u2014 start with obligations whose violation may result in a financial or criminal penalty (no whistleblowing procedure, failure to report a GDPR breach within 72 hours, violation of AI Act prohibitions).<\/p>\n<p><strong>How can I reconcile AI implementation with regulatory obligations?<\/strong><\/p>\n<p>Start by mapping where AI tools are used in the organisation \u2014 HR, marketing, sales, and customer service. Check what data they process and who is responsible for compliance with the AI Act and GDPR. The AI literacy obligation (Article 4 of the AI Act) has applied since 2 February 2025 \u2014 your employees must have the appropriate competencies. The prohibitions under Article 5 (e.g. emotion recognition in the workplace) also already apply. An AI deployer is required to retain logs for at least 6 months and inform employees about the use of AI. Be aware of the risk of a change in role \u2014 if you modify the algorithm or put your own logo on the system, you may become a provider under the AI Act, which radically increases the scope of your obligations.<\/p>\n<p><strong>Do I need a dedicated compliance officer?<\/strong><\/p>\n<p>There is no statutory obligation for a technology company to employ a compliance officer (unlike, for example, <a href=\"https:\/\/sawaryn.com\/publikacje\/audyt-rodo-gdpr-outsourcing-iod\/\">a DPO required under GDPR<\/a> in certain cases). But someone in the organisation must coordinate information from different departments and report to the management board. This may be a part-time role \u2014 for example, the COO, Head of Operations, or an external adviser. What matters is that this person has the authority to gather information from HR, IT, legal, and operations and has access to the management board.<\/p>\n<p><strong>What does an investor review during compliance due diligence?<\/strong><\/p>\n<p>Increasingly, due diligence includes a comprehensive compliance review, not just finances and intellectual property. Typical areas include GDPR documentation (record of processing activities, data processing agreements, data breach response procedure), employment status (risk of B2B contracts being reclassified), the whistleblowing procedure, the AI use policy, regulatory licences and permits, and contracts with business partners. A company should have a document pack ready that can be provided within 48 hours of an investor\u2019s request \u2014 the absence of such a pack is itself a red flag.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how to map GDPR, AI Act, NIS2 and other obligations, assign owners, review procedures and prepare your Polish tech company for due diligence.<\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","sip_alt_url":"","sip_en_pl_url":"","sip_pair_uuid":"6614c9fb-997f-487d-b589-347e0932477a","sip_pair_state":"verified"},"categories":[1],"tags":[1545,1446,1540,1546,1532],"specialization":[1207],"practice_area":[],"class_list":["post-3493","post","type-post","status-publish","format-standard","hentry","category-bez-kategorii","tag-ai-act-en","tag-gdpr","tag-internal-procedure","tag-risk-assessment","tag-whistleblowers","specialization-compliance"],"acf":[],"_links":{"self":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/comments?post=3493"}],"version-history":[{"count":2,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3493\/revisions"}],"predecessor-version":[{"id":3496,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3493\/revisions\/3496"}],"wp:attachment":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/media?parent=3493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/categories?post=3493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/tags?post=3493"},{"taxonomy":"specialization","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/specialization?post=3493"},{"taxonomy":"practice_area","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/practice_area?post=3493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}