{"id":3568,"date":"2026-10-09T08:18:31","date_gmt":"2026-10-09T08:18:31","guid":{"rendered":"https:\/\/sawaryn.com\/?p=3568"},"modified":"2026-10-09T08:18:51","modified_gmt":"2026-10-09T08:18:51","slug":"first-72-hours-company-incident-poland","status":"publish","type":"post","link":"https:\/\/sawaryn.com\/en\/publikacje\/first-72-hours-company-incident-poland\/","title":{"rendered":"The First 72 Hours After an Incident at a Company in Poland"},"content":{"rendered":"<p>Monday morning. Three messages in the CEO\u2019s inbox: HR reports a conflict in the development team, the DPO flags a possible leak of customer data, and a report has been submitted through the anonymous whistleblowing channel. All three concern the same person. The CEO does not know where to start \u2014 whether the deadline is 72 hours, 7 days, or whether action should be taken \u201cwithout delay&quot;. And it is precisely this moment \u2014 between the event and the first decision \u2014 that determines whether the company emerges from the incident in a controlled manner or pays more for the chaos than for the problem itself.<\/p>\n<p>If you run a technology company, SaaS business or scale-up, this scenario is not abstract. In 2024, CERT Polska recorded more than <strong>100,000 confirmed security incidents<\/strong> \u2014 a 29% increase year on year. KPMG research indicates that <strong>83% of companies<\/strong> recorded attempted attacks. And yet only <strong>18% of small businesses<\/strong> have an incident response plan.<\/p>\n<p>This article is a guide to the first 72 hours after an incident at a company. It is not a legal analysis, but an operational manual: how to classify the event, whom to notify, what to preserve, what not to do \u2014 and how to document the response in a way that protects the management board.<\/p>\n<h2>Key terms to understand before taking action<\/h2>\n<p>Before we move on to the steps, it is worth clarifying the terminology. Companies often confuse three different situations, which leads them to initiate the wrong procedure or \u2014 worse still \u2014 take no action at all.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Term<\/th>\n<th style=\"text-align:left\">Meaning<\/th>\n<th style=\"text-align:left\">Example<\/th>\n<th style=\"text-align:left\">Does it require a formal response?<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\"><strong>Vulnerability<\/strong><\/td>\n<td style=\"text-align:left\">A weakness in a system, network or software that may be exploited<\/td>\n<td style=\"text-align:left\">An outdated version of a library in an application<\/td>\n<td style=\"text-align:left\">Does not require notification, but does require remediation<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Potential event<\/strong><\/td>\n<td style=\"text-align:left\">An attempt to exploit a vulnerability that did not compromise the confidentiality, integrity or availability of data<\/td>\n<td style=\"text-align:left\">A blocked phishing attempt<\/td>\n<td style=\"text-align:left\">Worth documenting; as a rule, formal notification is not required<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\"><strong>Incident<\/strong><\/td>\n<td style=\"text-align:left\">An event that has actually caused adverse consequences \u2014 a data leak, loss of availability or harm to individuals<\/td>\n<td style=\"text-align:left\">Sending a customer database to an unauthorised recipient<\/td>\n<td style=\"text-align:left\">Yes \u2014 it triggers notification and documentation obligations<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This distinction has a direct bearing on your obligations. If the event constitutes an incident within the meaning of the GDPR, you have <strong>72 hours<\/strong> to <a href=\"https:\/\/sawaryn.com\/publikacje\/zgloszenie-naruszenia-rodo-wyciek-danych-osobowych\/\">notify the President of the UODO<\/a>. If it is a whistleblower report \u2014 <strong>7 days<\/strong> to acknowledge receipt and <strong>3 months<\/strong> to provide feedback. If it is an occupational health and safety violation \u2014 the response should be immediate.<\/p>\n<p>Misclassifying the event at the outset means that the company initiates the wrong procedure, omits mandatory actions or misses statutory deadlines. Each of these situations gives rise to separate liability.<\/p>\n<h2>Why post-incident chaos costs more than the event itself<\/h2>\n<p>The greatest risk is not the data leak itself, the team conflict or the whistleblower report. The risk is a <strong>chaotic, delayed or undocumented response<\/strong>. Here is why.<\/p>\n<h3>Concurrent liability under four legal regimes<\/h3>\n<p>A company incident rarely falls into a single category. A single event may trigger obligations under the GDPR, the Whistleblower Protection Act, the Labour Code and the Commercial Companies Code \u2014 all at the same time. And each of these regimes provides for separate penalties.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Legal regime<\/th>\n<th style=\"text-align:left\">Typical failure<\/th>\n<th style=\"text-align:left\">Penalty<\/th>\n<th style=\"text-align:left\">Legal basis<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">GDPR<\/td>\n<td style=\"text-align:left\">Failure to notify the UODO of a breach within 72 hours<\/td>\n<td style=\"text-align:left\">Up to EUR 10 million or 2% of turnover<\/td>\n<td style=\"text-align:left\">Articles 33\u201334 and Article 83(4) GDPR<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">GDPR<\/td>\n<td style=\"text-align:left\">Failure to notify individuals where there is a high risk<\/td>\n<td style=\"text-align:left\">Up to EUR 10 million or 2% of turnover<\/td>\n<td style=\"text-align:left\">Article 34 and Article 83(4) GDPR<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Whistleblower Protection Act<\/td>\n<td style=\"text-align:left\">Obstructing a report<\/td>\n<td style=\"text-align:left\">Up to one year\u2019s imprisonment (up to 3 years where threats or violence are used)<\/td>\n<td style=\"text-align:left\">Article 58 of the Whistleblower Protection Act<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Whistleblower Protection Act<\/td>\n<td style=\"text-align:left\">Retaliation against a whistleblower<\/td>\n<td style=\"text-align:left\">Up to 2 years\u2019 imprisonment (up to 3 years if persistent)<\/td>\n<td style=\"text-align:left\">Article 58 of the Whistleblower Protection Act<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Labour Code<\/td>\n<td style=\"text-align:left\">Violations of employee rights (occupational health and safety, pay)<\/td>\n<td style=\"text-align:left\">Fine of PLN 1,000\u201330,000<\/td>\n<td style=\"text-align:left\">Articles 281\u2013283 of the Labour Code<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Criminal Code<\/td>\n<td style=\"text-align:left\">Malicious or persistent violation of employee rights<\/td>\n<td style=\"text-align:left\">Up to 2 years\u2019 imprisonment<\/td>\n<td style=\"text-align:left\">Article 218 \u00a7 1a of the Criminal Code<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Commercial Companies Code<\/td>\n<td style=\"text-align:left\">Damage to the company caused by the management board\u2019s fault (through action or omission)<\/td>\n<td style=\"text-align:left\">Liability for damages<\/td>\n<td style=\"text-align:left\">Article 293 \u00a7 1 of the Commercial Companies Code<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Criminal Code<\/td>\n<td style=\"text-align:left\">Breach of trust \u2014 failure to fulfil duties resulting in substantial damage<\/td>\n<td style=\"text-align:left\">Criminal liability<\/td>\n<td style=\"text-align:left\">Article 296 of the Criminal Code<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Note that the penalty for the <strong>mere failure to notify<\/strong> a GDPR breach within 72 hours concerns a separate infringement carrying a separate penalty \u2014 regardless of how serious the leak itself was. The President of the UODO imposed a fine of <strong>PLN 103,752<\/strong> on Link4 specifically for failing to notify the breach on time, not for the incident itself. A court enforcement officer paid a total of approximately <strong>PLN 21,000<\/strong> \u2014 PLN 7,700 for failing to notify the breach and PLN 13,200 for failing to inform the person whose data was affected.<\/p>\n<h3>Costs extend far beyond administrative fines<\/h3>\n<p>UODO penalties or fines imposed by the National Labour Inspectorate are only the tip of the iceberg. The full cost of a chaotic response includes:<\/p>\n<ol>\n<li><strong>Data recovery and infrastructure replacement costs<\/strong> \u2014 if the incident affected production systems<\/li>\n<li><strong>Personnel costs<\/strong> \u2014 overtime for IT, HR and legal teams; sometimes additional staff must be hired<\/li>\n<li><strong>Compensation for customers and contractors<\/strong> \u2014 particularly where NDAs or data processing agreements have been breached<\/li>\n<li><strong>Lost revenue<\/strong> \u2014 downtime, customer churn and suspended projects<\/li>\n<li><strong>Crisis advisory costs<\/strong> \u2014 lawyers, IT forensics specialists and crisis PR advisers engaged \u201cafter the fact&quot; cost many times more than prevention<\/li>\n<li><strong>Employee claims<\/strong> \u2014 leave, overtime and compensation for workplace bullying if the company failed to respond to a report<\/li>\n<li><strong>Reputational costs<\/strong> \u2014 loss of trust among the team, customers and investors<\/li>\n<\/ol>\n<p>An early, structured response is many times less expensive than repairing the damage caused by improvisation.<\/p>\n<p><a href=\"https:\/\/sawaryn.com\/en\/contact\/\">Contact us<\/a><\/p>\n<h2>The first 72 hours after an incident \u2014 what to do step by step<\/h2>\n<p>Below is the sequence of actions your company should initiate as soon as an incident is identified. The order matters.<\/p>\n<h3>Step 1: preserve evidence \u2014 before anything else<\/h3>\n<p>Before you begin analysing, classifying and making decisions \u2014 preserve the evidence. This includes:<\/p>\n<ol>\n<li><strong>Correspondence<\/strong> \u2014 emails and messages on Slack, Teams and other messaging platforms<\/li>\n<li><strong>System logs<\/strong> \u2014 access records, logins, changes to permissions and file transfers<\/li>\n<li><strong>Documents<\/strong> \u2014 agreements, notes, screenshots and reports<\/li>\n<li><strong>Recordings<\/strong> \u2014 if the company uses video surveillance or records calls<\/li>\n<li><strong>Data from HR systems<\/strong> \u2014 working time records, requests and appraisals<\/li>\n<\/ol>\n<p>The rule is: <strong>do not delete, modify or move anything<\/strong>. Even if you believe a particular file is unrelated to the case. Delaying the preservation of evidence weakens the company\u2019s position under every legal regime \u2014 from the GDPR to employment disputes.<\/p>\n<h3>Step 2: classify the event \u2014 initiate the correct procedure<\/h3>\n<p>This is the most common mistake: the company responds to an incident as though it were solely an HR problem, solely a data leak or solely an IT failure. In reality, a single event may require concurrent action across several areas.<\/p>\n<p>Use the matrix below for rapid classification:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Question<\/th>\n<th style=\"text-align:left\">If YES \u2192 area<\/th>\n<th style=\"text-align:left\">Statutory deadline<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Have personal data been lost, disclosed or accessed without authorisation?<\/td>\n<td style=\"text-align:left\">GDPR \u2014 notification to the UODO<\/td>\n<td style=\"text-align:left\">72 hours<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Was the report submitted through a whistleblowing channel, or does it concern a breach of law?<\/td>\n<td style=\"text-align:left\">Whistleblower Protection Act \u2014 internal investigation<\/td>\n<td style=\"text-align:left\">7 days (acknowledgement), 3 months (feedback)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Does the event concern an employment relationship \u2014 workplace bullying, discrimination or an occupational health and safety violation?<\/td>\n<td style=\"text-align:left\">Labour Code \u2014 employer response<\/td>\n<td style=\"text-align:left\">Without delay<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Does the event threaten the continuity of IT systems?<\/td>\n<td style=\"text-align:left\">Cybersecurity \u2014 incident response procedure<\/td>\n<td style=\"text-align:left\">24 hours (serious incident, <a href=\"https:\/\/sawaryn.com\/publikacje\/dyrektywa-nis-2-nowa-era-cyberbezpieczenstwa-w-unii-europejskiej\/\">National Cybersecurity System Act<\/a>)<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Could the event give rise to management board liability towards the company?<\/td>\n<td style=\"text-align:left\">Commercial Companies Code \u2014 decision documentation<\/td>\n<td style=\"text-align:left\">No statutory deadline, but delay weakens the company\u2019s position<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>If the answer is \u201cYES&quot; in more than one row, you are dealing with a multidisciplinary incident. You need coordination, not separate, unconnected courses of action.<\/p>\n<h3>Step 3: appoint an \u201cincident owner&quot;<\/h3>\n<p>Fragmented responsibility is the second most common mistake. HR thinks it is an IT matter. IT thinks it is a matter for the lawyer. The lawyer waits for information from HR. No one makes a decision.<\/p>\n<p>Appoint one person (or a two-person team) who:<\/p>\n<ol>\n<li>Coordinates all post-incident activities \u2014 regardless of the type of incident<\/li>\n<li>Collects information from HR, IT, compliance and legal<\/li>\n<li>Reports directly to the management board<\/li>\n<li>Monitors statutory deadlines<\/li>\n<li>Decides on the order and priority of actions<\/li>\n<\/ol>\n<p>The \u201cincident owner&quot; does not need to be an expert in every area. They need to know whom to involve and in what order.<\/p>\n<h3>Step 4: do no harm during the first 24 hours<\/h3>\n<p>Until the incident has been fully classified, the rule is \u201cdo not make the situation worse&quot;. Here is what <strong>not to do<\/strong>:<\/p>\n<ol>\n<li><strong>Do not dismiss anyone<\/strong> \u2014 hastily terminating the contract of a person involved in a whistleblower report may be regarded as retaliation (punishable by up to 2 years\u2019 imprisonment)<\/li>\n<li><strong>Do not communicate publicly<\/strong> \u2014 either internally or externally, until you know the facts and have agreed on the narrative<\/li>\n<li><strong>Do not delete correspondence or logs<\/strong> \u2014 even if they appear incriminating<\/li>\n<li><strong>Do not make statements<\/strong> \u2014 written or oral \u2014 that may later be used against the company<\/li>\n<li><strong>Do not ignore deadlines<\/strong> \u2014 the 72-hour deadline for notifying a GDPR breach runs from the moment the breach is <strong>identified<\/strong>, not from the moment it has been \u201cfully investigated&quot;<\/li>\n<\/ol>\n<p>Recital 87 of the GDPR expressly states that the assessment of whether notification was made \u201cwithout undue delay&quot; should take into account the nature and gravity of the breach and its consequences. A documented decision-making process may protect the company even in the event of a minor delay. A lack of documentation will not.<\/p>\n<h3>Step 5: document every decision in real time<\/h3>\n<p>Every decision made during an incident should be recorded together with:<\/p>\n<ol>\n<li><strong>The date and time<\/strong> it was made<\/li>\n<li><strong>The decision-maker<\/strong> \u2014 who made the decision<\/li>\n<li><strong>The rationale<\/strong> \u2014 why the decision was made and what information it was based on<\/li>\n<li><strong>The alternatives<\/strong> \u2014 what other options were considered<\/li>\n<\/ol>\n<p>The format does not need to be formal. An email to yourself, a note in a document or an entry in an incident management tool \u2014 they all count, provided they include a date and content.<\/p>\n<p>Why is this so important? For two reasons.<\/p>\n<p>First, <strong>Article 33(5) GDPR<\/strong> requires <a href=\"https:\/\/sawaryn.com\/publikacje\/jak-dokumentowac-i-zglaszac-naruszenia-danych-osobowych\/\">the documentation of <strong>all<\/strong> personal data breaches<\/a> \u2014 including those that the company has decided not to notify to the UODO. You must have a written justification for that decision.<\/p>\n<p>Second, <strong>Article 293 \u00a7 3 of the Commercial Companies Code<\/strong> (the business judgement rule) may protect the management board against liability for damages \u2014 but only if the board demonstrates that it acted loyally towards the company, within the limits of reasonable risk and on the basis of <strong>adequate information and analysis<\/strong>. Without documentation, there is nothing to demonstrate.<\/p>\n<h2>When an incident does not fit into a single category \u2014 conflicting procedures<\/h2>\n<p>At technology companies, incidents rarely concern just one area. A typical scenario is that the CTO leaves the company and takes the code repository. This simultaneously constitutes:<\/p>\n<ol>\n<li><strong>An IP issue<\/strong> \u2014 infringement of rights to the source code<\/li>\n<li><strong>A GDPR breach<\/strong> \u2014 if the code or systems contained customers\u2019 personal data<\/li>\n<li><strong>An NDA breach<\/strong> \u2014 if the code contained solutions covered by confidentiality agreements with contractors<\/li>\n<li><strong>An HR issue<\/strong> \u2014 if the person was employed under an employment contract and is subject to a non-compete obligation or confidentiality clause<\/li>\n<li><strong>A cybersecurity incident<\/strong> \u2014 if production systems were accessed without authorisation<\/li>\n<\/ol>\n<p>Each of these areas has a different response deadline, supervisory authority and procedure. Without coordination, the company risks taking contradictory actions: the legal department sends a formal demand, HR conducts an investigatory interview, IT blocks access \u2014 while no one has checked whether the breach must be notified to the UODO within 72 hours.<\/p>\n<h3>A particular conflict: a whistleblower report and a GDPR breach<\/h3>\n<p>The <a href=\"https:\/\/sawaryn.com\/publikacje\/sygnalista-w-firmie-jak-wdrozyc-dyrektywe-o-sygnalistach\/\">Whistleblower Protection Act<\/a> and the GDPR have different deadlines and procedures, but may apply to the same event. If a whistleblower reports a personal data leak, the company must simultaneously:<\/p>\n<ol>\n<li>Acknowledge receipt of the whistleblower report within <strong>7 days<\/strong><\/li>\n<li>Notify the UODO of the personal data breach within <strong>72 hours<\/strong><\/li>\n<li>Conduct an internal investigation under the whistleblowing procedure and provide <a href=\"https:\/\/sawaryn.com\/publikacje\/jakie-obowiazki-ma-pracodawca-w-zwiazku-z-ochrona-sygnalistow\/\">feedback to the whistleblower<\/a> within <strong>3 months<\/strong><\/li>\n<li>Protect the whistleblower\u2019s identity (Article 8 of the Whistleblower Protection Act excludes the obligation to inform the person concerned by the report about the source of the data \u2014 Article 14(2)(f) GDPR)<\/li>\n<\/ol>\n<p>These procedures must run concurrently, but they must not obstruct one another. The person conducting the internal investigation under the whistleblowing procedure should not also decide whether to notify the UODO \u2014 these should be independent tracks with a single coordination point.<\/p>\n<h2>How to protect the management board \u2014 the business judgement rule following the amendment to the Commercial Companies Code<\/h2>\n<p>The amendment to the Commercial Companies Code of 9 February 2022 (which entered into force on 13 October 2022) introduced the <a href=\"https:\/\/sawaryn.com\/publikacje\/prawo-holdingowe-nowe-przepisy-dla-spolek\/\">business judgement rule<\/a> into Article 293 \u00a7 3. In simple terms, a management board member is not liable for damage caused to the company if they acted loyally and within the limits of reasonable business risk \u2014 including on the basis of information, analyses and opinions that should have been taken into account in the circumstances.<\/p>\n<p>For incident response, this means specific requirements:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align:left\">Condition for protection<\/th>\n<th style=\"text-align:left\">What this means during an incident<\/th>\n<th style=\"text-align:left\">How to document it<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align:left\">Loyalty towards the company<\/td>\n<td style=\"text-align:left\">The management board acted in the company\u2019s interests, not in its own interests or those of third parties<\/td>\n<td style=\"text-align:left\">A decision note indicating that the actions were intended to protect the company<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Reasonable business risk<\/td>\n<td style=\"text-align:left\">The decision was proportionate to the situation \u2014 neither overly cautious nor excessively risky<\/td>\n<td style=\"text-align:left\">A description of the alternatives considered and the reasons for selecting the chosen option<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align:left\">Adequate information and analysis<\/td>\n<td style=\"text-align:left\">The management board collected the available data before making its decision \u2014 it did not act \u201cblindly&quot;<\/td>\n<td style=\"text-align:left\">Incident classification report, legal opinion and risk analysis<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Limit of protection:<\/strong> the business judgement rule does not protect against liability for breaching mandatory legal provisions. If the management board knew about a GDPR breach and deliberately failed to notify it within 72 hours, the business judgement rule will not help.<\/p>\n<h2>Prepare your company before an incident occurs \u2014 readiness checklist<\/h2>\n<p>Companies often have policies, regulations and procedures on paper but do not know how to apply them in a crisis. Below are the measures worth implementing <strong>before<\/strong> an incident occurs.<\/p>\n<h3>Priority measures (implement immediately)<\/h3>\n<ol>\n<li>\n<p><strong>Check whether you have a written incident response procedure.<\/strong> Not a general security policy, but a specific sequence: who responds, in what order, what deadlines apply and who makes the decisions. If a procedure exists but no one knows it \u2014 it may as well not exist.<\/p>\n<\/li>\n<li>\n<p><strong>Prepare an initial response card<\/strong> \u2014 a one-page document containing a checklist of the first 10 actions following an incident: whom to notify, what to preserve, what not to do and what deadlines are running. Distribute it to the management board, HR, IT and the person responsible for compliance.<\/p>\n<\/li>\n<li>\n<p><strong>Establish an incident classification matrix<\/strong> \u2014 a table (like the one above in this article) that allows you to quickly determine whether an event is an HR issue, a GDPR breach, a whistleblower report, a cyber incident or a management risk.<\/p>\n<\/li>\n<li>\n<p><strong>Appoint an incident owner<\/strong> \u2014 one person to coordinate the response, regardless of the type of incident.<\/p>\n<\/li>\n<li>\n<p><strong>Introduce the practice of documenting decisions in real time<\/strong> \u2014 even in the form of an email containing the date, the decision and its rationale.<\/p>\n<\/li>\n<\/ol>\n<h3>Recommended measures (implement within one month)<\/h3>\n<ol start=\"6\">\n<li>\n<p><strong>Train the management board and managers<\/strong> in the principle of \u201cdoing no harm during the first 24 hours&quot; \u2014 what not to communicate, what not to delete and whom not to dismiss before the event has been fully classified.<\/p>\n<\/li>\n<li>\n<p><strong>Compile a crisis contact list<\/strong> \u2014 external lawyer, GDPR specialist, IT forensics company and crisis PR adviser. Keep it somewhere accessible before it is needed. Looking for support during a crisis costs hours you do not have.<\/p>\n<\/li>\n<li>\n<p><strong>Ask a lawyer to review the existing procedures<\/strong> (workplace regulations, GDPR policy, whistleblowing procedure and IT security policy) for consistency \u2014 to check whether they contain conflicting provisions on who should respond and within what timeframe.<\/p>\n<\/li>\n<li>\n<p><strong>Review the incident response clauses in your <a href=\"https:\/\/sawaryn.com\/publikacje\/twoje-dane-w-obcych-rekach-jak-bezpiecznie-powierzac-przetwarzanie-danych\/\">agreements with IT providers<\/a>.<\/strong> If there are none, it is unclear who \u2014 the company or the provider \u2014 is responsible for which actions when an incident occurs. Properly drafted clauses allocate tasks to the parties, specify deadlines and divide responsibility.<\/p>\n<\/li>\n<\/ol>\n<h3>Additional measures (implement within one quarter)<\/h3>\n<ol start=\"10\">\n<li>\n<p><strong>Conduct a tabletop exercise<\/strong> \u2014 simulate an incident scenario (e.g. a customer data leak and a whistleblower report occurring at the same time) and check whether the team knows what to do. You will identify procedural gaps before a real problem arises.<\/p>\n<\/li>\n<li>\n<p><strong>After every incident \u2014 even a minor one \u2014 hold a 30-minute \u201clessons learned&quot; meeting<\/strong> with the team. What worked, what did not and what should be changed in the procedure. Update the initial response card.<\/p>\n<\/li>\n<\/ol>\n<h2>We can help you<\/h2>\n<p>Incident response requires coordination across many areas of law \u2014 the GDPR, employment law, the Whistleblower Protection Act, corporate law and cybersecurity. A single lawyer specialising in one area will not be enough if an event extends beyond one category.<\/p>\n<p>We support technology companies and scale-ups under three models:<\/p>\n<ol>\n<li>\n<p><strong>Incident readiness audit<\/strong> \u2014 we check whether your company has procedures, whether they are consistent, whether the team knows them and whether statutory deadlines have been taken into account. You receive a report identifying specific gaps and recommendations.<\/p>\n<\/li>\n<li>\n<p><strong>Support during an incident<\/strong> \u2014 we coordinate the legal response, help classify the event, monitor notification deadlines and prepare documentation that protects the management board. We act as an external coordination point so that you can focus on running the company.<\/p>\n<\/li>\n<li>\n<p><strong>Procedure implementation and training<\/strong> \u2014 we prepare an initial response card, classification matrix and breach management procedure, and train the management board and managers in incident response principles.<\/p>\n<\/li>\n<\/ol>\n<p>We bring together employment law, the GDPR, IT law and corporate law within a single team \u2014 because incidents at technology companies rarely fit neatly into one category.<\/p>\n<h2>A structured response protects the company better than the absence of an incident<\/h2>\n<p>No procedure will prevent every incident. But a structured response \u2014 rapid classification, preservation of evidence, documentation of decisions and coordination of actions \u2014 can limit financial losses, protect the management board from personal liability and allow the company to resume normal operations sooner.<\/p>\n<p>Three things to do after reading this article:<\/p>\n<ol>\n<li>Check whether your company has a written incident response procedure \u2014 and whether anyone knows it.<\/li>\n<li>Appoint a person responsible for coordinating incident response.<\/li>\n<li>Prepare an initial response card and a crisis contact list.<\/li>\n<\/ol>\n<p>If you need support with an incident readiness audit, preparing procedures or training the management board \u2014 <a href=\"https:\/\/sawaryn.com\/en\/contact\/\">contact us<\/a>.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>We have an incident, but we do not know whether it is \u201cserious&quot; \u2014 how can we quickly assess whether a formal response is required?<\/strong><\/p>\n<p>Use three screening questions: (1) Have personal data been lost, disclosed or accessed without authorisation? If so, you have 72 hours to assess the incident and potentially notify the UODO. (2) Was the report submitted through a whistleblowing channel? If so, you have 7 days to acknowledge receipt. (3) Does the event concern employee safety? If so, the response should be immediate. If the answer is \u201cyes&quot; to more than one question, you are dealing with a multidisciplinary incident and need coordination.<\/p>\n<p><strong>Who in the company should make decisions following an incident \u2014 the management board, HR, a lawyer or the compliance officer?<\/strong><\/p>\n<p>Strategic decisions (notification to a supervisory authority, external communications and staffing decisions) belong to the management board. Operational coordination should be handled by an appointed \u201cincident owner&quot; \u2014 a person who gathers information from HR, IT, compliance and legal, monitors deadlines and reports to the management board. They do not need to be an expert in every area, but they must know whom to involve and in what order.<\/p>\n<p><strong>Is the management board personally liable if the company responded to an incident too slowly or incorrectly?<\/strong><\/p>\n<p>Yes \u2014 under Article 293 \u00a7 1 of the Commercial Companies Code, a management board member is liable for damage caused to the company by an action or omission contrary to the law. The 2022 amendment to the Commercial Companies Code introduced the business judgement rule (Article 293 \u00a7 3), which may protect the management board \u2014 but subject to three conditions: loyalty towards the company, acting within the limits of reasonable risk and basing decisions on adequate information. Without a documented decision-making process, there is nothing to demonstrate. Moreover, this rule does not protect against liability for breaching mandatory legal provisions \u2014 for example, knowingly missing the 72-hour deadline for notifying a GDPR breach.<\/p>\n<p><strong>We have procedures on paper, but no one knows them \u2014 does this protect us or count against us during an inspection?<\/strong><\/p>\n<p>It counts against you. A procedure that the team does not know or follow does not satisfy the accountability requirement (Article 5(2) GDPR) or the obligation to implement appropriate organisational measures. During an inspection by the UODO or the National Labour Inspectorate, or in court proceedings, the company must demonstrate that the procedures were implemented, known and followed \u2014 not merely written down. This is why regular training and tabletop exercises are just as important as the document itself.<\/p>\n<p><strong>Everything has settled down after the incident \u2014 do I still need to do anything to close the matter formally?<\/strong><\/p>\n<p>Yes. Closing the matter requires: (1) an entry in the breach register (the GDPR requires all breaches to be documented, including those not notified to the UODO, together with the reasons for the decision not to notify), (2) feedback to the whistleblower within 3 months (if the event concerned a whistleblower report), (3) a closing note describing the actions taken, conclusions and recommendations, and (4) updates to procedures based on lessons learned from the incident. The aim is to prepare the company for questions from a regulator, employee, contractor, auditor or court \u2014 even if they arise several months later.<\/p>\n<p><strong>How should an incident be communicated internally without causing panic or concealing the problem?<\/strong><\/p>\n<p>Communicate facts, not speculation. Appoint one person responsible for internal communications. Provide the team with three pieces of information: (1) what happened (without details that could prejudice the investigation), (2) what the company is doing in response, and (3) whom to contact with questions. Avoid messages such as \u201cnothing happened&quot; \u2014 if the incident later proves serious, the company will lose credibility. Also avoid excessive alarmism \u2014 it makes it more difficult to conduct a calm internal investigation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how to preserve evidence, classify overlapping incidents, track Polish notification deadlines and document management board decisions in the first 72 hours.<\/p>\n","protected":false},"author":13,"featured_media":3605,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","sip_alt_url":"","sip_en_pl_url":"","sip_pair_uuid":"9f9ad173-8839-47ad-ae20-ffe25f1b0c47","sip_pair_state":"verified"},"categories":[],"tags":[1555,1533,1446,1546,1534,1532],"specialization":[1215],"practice_area":[],"class_list":["post-3568","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-corporate-governance-en","tag-data-breach","tag-gdpr","tag-risk-assessment","tag-uodo-en","tag-whistleblowers","specialization-gdpr"],"acf":[],"_links":{"self":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3568","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/comments?post=3568"}],"version-history":[{"count":2,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3568\/revisions"}],"predecessor-version":[{"id":3571,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/posts\/3568\/revisions\/3571"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/media\/3605"}],"wp:attachment":[{"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/media?parent=3568"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/categories?post=3568"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/tags?post=3568"},{"taxonomy":"specialization","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/specialization?post=3568"},{"taxonomy":"practice_area","embeddable":true,"href":"https:\/\/sawaryn.com\/en\/wp-json\/wp\/v2\/practice_area?post=3568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}