Back to the blog

The First 72 Hours After an Incident at a Company in Poland

For companies operating in Poland: learn how to preserve evidence, assess GDPR and whistleblower deadlines, coordinate teams and record board decisions.

The First 72 Hours After an Incident at a Company in Poland

Monday morning. The CEO has three messages: HR reports a conflict in the development team; the data protection officer flags a possible customer data leak; and a report has arrived through the anonymous whistleblowing channel. All three concern the same person.

Where should the CEO start? Is there a 72-hour deadline, a seven-day deadline, or an obligation to act “without delay”? The decisions made between discovering an event and establishing what happened can determine whether the company manages the incident—or incurs greater costs through a disorganized response.

For a technology company, SaaS business, or scale-up operating in Poland, this is a practical concern. In 2024, CERT Polska recorded more than 100,000 confirmed security incidents, up 29% year over year. KPMG research indicates that 83% of companies recorded attempted attacks, yet only 18% of small businesses have an incident response plan.

This is an operational guide to the first 72 hours: how to classify an event, whom to involve, what to preserve, what to avoid, and how to document decisions so the company and its management board can account for their response.

First, distinguish a vulnerability from an incident

Companies sometimes treat every warning as a reportable incident—or overlook an event that needs a formal response. These working distinctions help identify the next step:

Term Meaning Example Typical response
Vulnerability A weakness in a system, network, or software that could be exploited An outdated software library in an application Remediate it; the vulnerability itself does not require notification
Potential event An attempted exploitation that did not compromise the confidentiality, integrity, or availability of data A blocked phishing attempt Documenting it is worthwhile; formal notification is generally not required
Incident An event that has caused adverse consequences, such as a data leak, loss of availability, or harm to individuals A customer database sent to an unauthorized recipient Assess and initiate applicable notification and documentation procedures

The classification affects the clock. A personal data breach may require notification to the President of the Personal Data Protection Office (UODO) within 72 hours under the GDPR; see our guide to reporting a personal data breach in Poland. A whistleblower report brings a seven-day period for acknowledging receipt and a three-month period for feedback. An occupational health and safety issue calls for an immediate response.

Misclassification can mean using the wrong procedure, omitting a required action, or missing a statutory deadline. Each can create a separate liability risk.

Why a disorganized response can cost more than the event

A data leak, workplace conflict, or whistleblower report is serious in itself. A late, contradictory, or undocumented response can add legal and operational costs.

One event can engage several Polish legal regimes

An incident may simultaneously involve the GDPR, Poland’s Whistleblower Protection Act, the Labor Code, and the Commercial Companies Code. Criminal Code provisions may also be relevant. The following examples show the separate exposures described in the approved source:

Legal regime Typical failure Stated consequence Legal basis
GDPR Failure to notify UODO of a breach within 72 hours Up to EUR 10 million or 2% of turnover Articles 33–34 and 83(4) GDPR
GDPR Failure to notify affected individuals where there is a high risk Up to EUR 10 million or 2% of turnover Articles 34 and 83(4) GDPR
Whistleblower Protection Act Obstructing a report Up to one year’s imprisonment; up to three years where threats or violence are used Article 58 of the Whistleblower Protection Act
Whistleblower Protection Act Retaliation against a whistleblower Up to two years’ imprisonment; up to three years if persistent Article 58 of the Whistleblower Protection Act
Labor Code Violating employee rights concerning, for example, occupational health and safety or pay Fine of PLN 1,000–30,000 Articles 281–283 of the Labor Code
Criminal Code Malicious or persistent violation of employee rights Up to two years’ imprisonment Article 218 § 1a of the Criminal Code
Commercial Companies Code Damage to the company caused by a management board member’s action or omission through fault Liability for damages Article 293 § 1 of the Commercial Companies Code
Criminal Code Breach of trust through failure to perform duties resulting in substantial damage Criminal liability Article 296 of the Criminal Code

Failure to make a required GDPR notification is a separate infringement from the underlying leak. As examples, UODO fined Link4 PLN 103,752 for failing to notify a breach on time, rather than for the incident itself. A court enforcement officer paid approximately PLN 21,000 in total: PLN 7,700 for failing to notify the authority and PLN 13,200 for failing to inform the affected person.

Regulatory penalties are only part of the potential cost. A disorganized response can also lead to:

  1. Data recovery and infrastructure replacement costs if production systems are affected.
  2. Personnel costs, including overtime for IT, HR, and legal teams or the need for additional staff.
  3. Customer and business-partner claims, particularly where confidentiality or data processing agreements are involved.
  4. Lost revenue from downtime, customer departures, or paused projects.
  5. Crisis advisory costs for legal, IT forensics, and communications support engaged after the event.
  6. Employee claims concerning leave, overtime, or workplace bullying if reports were not addressed.
  7. Reputational damage among employees, customers, and investors.

An early, coordinated response is generally less costly than trying to repair the consequences of improvisation.

The first 72 hours: an operational sequence

Start these actions as soon as the event is identified. Several workstreams may need to run at once, but they should be coordinated.

Step 1: Preserve evidence

Before reaching conclusions, secure material that may establish what happened:

  • Correspondence: email, Slack, Teams, and other messages.
  • System logs: access, logins, permission changes, and file transfers.
  • Documents: agreements, notes, screenshots, and reports.
  • Recordings: where the company uses video surveillance or records calls.
  • HR-system records: working-time records, requests, and evaluations.

The initial rule is: do not delete, alter, or move potentially relevant material, even if it appears unrelated or uncomfortable for the company. Delay in preserving evidence weakens the company’s position in matters ranging from GDPR compliance to employment disputes.

Step 2: Classify the event and open every relevant workstream

Do not treat the matter as solely an HR issue, solely a data leak, or solely an IT failure without checking the other possibilities.

Screening question If yes, examine this workstream Deadline or response stated in the source
Were personal data lost, disclosed, or accessed without authorization? GDPR; assess notification to UODO 72 hours
Did a report arrive through the whistleblowing channel, or does it concern a breach of law? Whistleblower Protection Act; internal follow-up Seven days to acknowledge receipt; three months for feedback
Does it concern an employment relationship, workplace bullying, discrimination, or occupational health and safety? Labor Code; employer response Without delay
Does it threaten the continuity of IT systems? Cybersecurity incident procedure 24 hours for a serious incident under the Act on the National Cybersecurity System (KSC)
Could it create management board liability toward the company? Commercial Companies Code; document decisions No statutory deadline stated here, but delay weakens the position

More than one “yes” means the response needs shared coordination—not disconnected teams pursuing separate plans.

Step 3: Appoint an incident owner

When responsibility is dispersed, HR may wait for IT, IT may wait for legal advice, and legal advisers may wait for facts from HR. Name one person, or a two-person team, to:

  1. Coordinate the response across workstreams.
  2. Collect information from HR, IT, compliance, and legal advisers.
  3. Report directly to the management board.
  4. Track statutory deadlines.
  5. Set operational priorities and the order of actions.

The incident owner need not be the subject-matter expert on every issue. The essential skill is knowing whom to involve, when, and how to bring the information together for decisions.

Step 4: Avoid making matters worse in the first 24 hours

Until the event has been properly assessed:

  • Do not dismiss anyone hastily. Terminating the contract of a person involved in a whistleblower matter may be regarded as retaliation, for which the source identifies a penalty of up to two years’ imprisonment.
  • Do not issue broad internal or external announcements before establishing the facts and agreeing on an accurate message.
  • Do not delete correspondence or logs, even if they appear damaging.
  • Do not make premature written or oral statements that may later be used against the company.
  • Do not wait for the entire investigation before checking deadlines. The GDPR’s 72-hour notification period runs from becoming aware of the breach, not from completing every factual inquiry.

Recital 87 GDPR states that assessing whether notification was made “without undue delay” takes account of the breach’s nature, gravity, and consequences. A documented decision-making process may assist the company where there is a minor delay; an undocumented one will not.

Step 5: Record decisions as they are made

For each material decision, record:

  1. Date and time.
  2. Who made it.
  3. The reasons and information available at the time.
  4. The alternatives considered.

An email, dated note, or incident-management entry can serve this purpose. What matters is a reliable record of the decision and its basis.

This serves two distinct purposes. First, Article 33(5) GDPR requires documentation of all personal data breaches, including breaches the company decides not to notify to UODO. Record the reasons for a decision not to notify.

Second, Article 293 § 3 of the Polish Commercial Companies Code—the business judgment rule—may protect management board members against liability for damage to the company when its conditions are met. Records help show what information and analysis supported their actions.

When procedures overlap: two examples

A departing CTO takes a code repository

Suppose a CTO leaves and takes the company’s code repository. The same facts may raise:

  1. Intellectual property issues concerning rights to the source code.
  2. GDPR issues if the code or systems contained customers’ personal data.
  3. Confidentiality issues if the code contained material covered by agreements with business partners.
  4. Employment issues if the CTO was employed under a Polish employment contract and subject to confidentiality or non-compete obligations.
  5. Cybersecurity issues if production systems were accessed without authorization.

Legal may prepare a formal demand, HR may arrange a discussion, and IT may block access. Those actions should not proceed without someone also checking whether a personal data breach must be notified to UODO within 72 hours.

A whistleblower reports a personal data leak

The Polish Whistleblower Protection Act and the GDPR have different procedures, but both may apply to one report. In the scenario described by the source, the company must manage these parallel tasks:

  1. Acknowledge receipt of the whistleblower report within seven days.
  2. Notify UODO of the personal data breach within 72 hours.
  3. Investigate under the whistleblowing procedure and provide feedback to the whistleblower within three months.
  4. Protect the whistleblower’s identity. The source states that Article 8 of the Whistleblower Protection Act excludes the obligation to tell the person named in the report the source of the data referred to in Article 14(2)(f) GDPR.

These tracks must run concurrently without obstructing one another. The person conducting the whistleblowing investigation should not also decide whether to notify UODO: keep the decisions on independent tracks, with one coordination point.

Documenting management board decisions under Polish law

A company operating in Poland acts through its management board. Board members should therefore be able to explain not just what they decided during an incident, but how they reached that decision.

An amendment to the Commercial Companies Code dated February 9, 2022, which entered into force on October 13, 2022, introduced the business judgment rule into Article 293 § 3. In the source’s summary, a board member is not liable for damage caused to the company if they acted loyally and within reasonable business risk, including on the basis of information, analyses, and opinions that should have been considered in the circumstances.

Condition What to establish during an incident Useful record
Loyalty to the company The decision served the company’s interests, not the decision-maker’s or a third party’s A decision note stating the purpose of the action
Reasonable business risk The response was proportionate to the circumstances Alternatives considered and reasons for the chosen course
Appropriate information and analysis The board gathered the available facts before deciding Incident classification, legal advice, and risk analysis

There is a limit: the business judgment rule does not protect a board member from liability for breaching mandatory law. The source’s example is a board that knows of a GDPR breach and deliberately fails to make a required notification within 72 hours.

Prepare before an incident: a readiness checklist

Written policies are of little operational use if the people who must apply them cannot find or follow them.

Priority actions: implement immediately

  1. Check for a written incident response procedure. It should set out who acts, in what order, which deadlines matter, and who decides—not merely state general security principles.
  2. Prepare a one-page initial response card. List the first ten actions, including whom to contact, what to preserve, what to avoid, and which deadlines to check. Give it to the board, HR, IT, and compliance lead.
  3. Create a classification matrix. Make it easy to identify GDPR, HR, whistleblowing, cybersecurity, and management risks in the same event.
  4. Appoint an incident owner to coordinate responses regardless of the incident type.
  5. Require real-time decision records, even if initially kept as dated emails or notes.

Recommended actions: implement within one month

  1. Train the board and managers on the “do no harm in the first 24 hours” principle: avoid premature communications, deletion, and staffing decisions before proper classification.
  2. Build an accessible crisis contact list covering external legal counsel, a GDPR specialist, IT forensics, and crisis communications support.
  3. Have a lawyer review existing procedures together—including workplace rules, GDPR policies, whistleblowing procedures, and IT security policies—for conflicting responsibilities or deadlines.
  4. Review incident-response clauses in IT provider agreements. They should allocate tasks, timelines, and responsibilities between the company and provider.

Additional actions: implement within one quarter

  1. Run a tabletop exercise. Simulate, for example, a customer data leak reported through the whistleblowing channel. Test whether the team knows what to do and who decides.
  2. Hold a 30-minute lessons-learned meeting after each incident, even a minor one. Identify what worked, what did not, and how the response card or procedure should change.

How we support companies dealing with incidents in Poland

A technology-company incident can require coordinated advice on GDPR, Polish employment law, whistleblower protection, corporate duties, and cybersecurity. We support companies and scale-ups through:

  1. Incident readiness audits: reviewing procedures, consistency, staff awareness, and statutory deadlines, then reporting practical gaps and recommendations.
  2. Support during an incident: helping classify the event, coordinate the legal response, track notifications, and document management board decisions.
  3. Procedures and training: preparing response cards, classification matrices, and breach procedures, and training board members and managers.

Our team brings employment, data protection, IT, and corporate law together because a single incident rarely stays within one specialty.

Close the incident—and improve the next response

No procedure prevents every incident. A structured response can, however, limit financial loss, improve the board’s ability to account for its decisions, and help the company resume normal operations.

Three useful actions now are to check whether your response procedure is written and understood, appoint an incident owner, and prepare a response card and crisis contact list. If you need help auditing readiness, building procedures, or training your management board, contact us.

Frequently asked questions

We do not know whether an incident is “serious.” How quickly should we assess it?

Start with three questions. Were personal data lost, disclosed, or accessed without authorization? If so, assess whether UODO notification is required against the 72-hour deadline. Did a report arrive through the whistleblowing channel? If so, track the seven-day acknowledgment deadline. Does the matter involve employee safety? If so, respond immediately. More than one “yes” calls for a coordinated, multidisciplinary response.

Who should make decisions: the board, HR, legal, or compliance?

The management board makes strategic decisions, such as authority notifications, external communications, and staffing decisions. An appointed incident owner coordinates operations: collecting information from HR, IT, compliance, and legal advisers; tracking deadlines; and reporting to the board.

Can board members be personally liable for a slow or poor response?

Yes. Under Article 293 § 1 of the Commercial Companies Code, a board member may be liable for damage caused to the company by an unlawful action or omission. The Article 293 § 3 business judgment rule may provide protection where the member acted loyally, within reasonable business risk, and on appropriate information. Documenting that process matters. The rule does not protect a deliberate breach of mandatory requirements, such as knowingly missing a required GDPR notification deadline.

We have procedures, but employees do not know them. Is that enough?

No. A procedure that is not known or used does not satisfy the source’s account of the GDPR accountability requirement under Article 5(2) or the need for appropriate organizational measures. During a UODO or Polish National Labor Inspectorate inspection, or in proceedings, the company should be able to show that procedures were implemented, understood, and followed—not merely written. Training and tabletop exercises help provide that evidence.

The immediate problem has passed. What is needed to close the matter?

Complete the applicable records and follow-up: document any personal data breach in the breach register, including the reasons for not notifying UODO if that was the decision; provide whistleblower feedback within three months where relevant; prepare a closing note covering actions, findings, and recommendations; and update procedures based on lessons learned. The records should be usable if a regulator, employee, business partner, auditor, or court asks questions months later.

How should we communicate internally without causing panic?

Communicate established facts rather than speculation, and appoint one person to coordinate internal messaging. Tell employees what happened at an appropriate level of detail, what the company is doing, and whom to contact with questions. Avoid both “nothing happened” assurances that may later prove false and alarmist statements that interfere with the investigation.

RECOMMENDED

this could be interesting to you

Real work, real outcomes - compliance, technology, transactions, and the everyday legal support businesses run on.