{"id":2753,"date":"2026-10-09T08:18:24","date_gmt":"2026-10-09T08:18:24","guid":{"rendered":"https:\/\/sawaryn.com\/us\/?p=2753"},"modified":"2026-10-09T08:18:42","modified_gmt":"2026-10-09T08:18:42","slug":"company-incident-first-72-hours-poland","status":"publish","type":"post","link":"https:\/\/sawaryn.com\/us\/company-incident-first-72-hours-poland\/","title":{"rendered":"The First 72 Hours After an Incident at a Company in Poland"},"content":{"rendered":"<h1>The First 72 Hours After an Incident at a Company in Poland<\/h1>\n<p>Monday morning. The CEO has three messages: HR reports a conflict in the development team; the data protection officer flags a possible customer data leak; and a report has arrived through the anonymous whistleblowing channel. All three concern the same person.<\/p>\n<p>Where should the CEO start? Is there a 72-hour deadline, a seven-day deadline, or an obligation to act \u201cwithout delay\u201d? The decisions made between discovering an event and establishing what happened can determine whether the company manages the incident\u2014or incurs greater costs through a disorganized response.<\/p>\n<p>For a technology company, SaaS business, or scale-up operating in Poland, this is a practical concern. In 2024, CERT Polska recorded more than <strong>100,000 confirmed security incidents<\/strong>, up 29% year over year. KPMG research indicates that <strong>83% of companies<\/strong> recorded attempted attacks, yet only <strong>18% of small businesses<\/strong> have an incident response plan.<\/p>\n<p>This is an operational guide to the first 72 hours: how to classify an event, whom to involve, what to preserve, what to avoid, and how to document decisions so the company and its management board can account for their response.<\/p>\n<h2>First, distinguish a vulnerability from an incident<\/h2>\n<p>Companies sometimes treat every warning as a reportable incident\u2014or overlook an event that needs a formal response. These working distinctions help identify the next step:<\/p>\n<table>\n<thead>\n<tr>\n<th>Term<\/th>\n<th>Meaning<\/th>\n<th>Example<\/th>\n<th>Typical response<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Vulnerability<\/strong><\/td>\n<td>A weakness in a system, network, or software that could be exploited<\/td>\n<td>An outdated software library in an application<\/td>\n<td>Remediate it; the vulnerability itself does not require notification<\/td>\n<\/tr>\n<tr>\n<td><strong>Potential event<\/strong><\/td>\n<td>An attempted exploitation that did not compromise the confidentiality, integrity, or availability of data<\/td>\n<td>A blocked phishing attempt<\/td>\n<td>Documenting it is worthwhile; formal notification is generally not required<\/td>\n<\/tr>\n<tr>\n<td><strong>Incident<\/strong><\/td>\n<td>An event that has caused adverse consequences, such as a data leak, loss of availability, or harm to individuals<\/td>\n<td>A customer database sent to an unauthorized recipient<\/td>\n<td>Assess and initiate applicable notification and documentation procedures<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The classification affects the clock. A personal data breach may require notification to the <strong>President of the Personal Data Protection Office (UODO)<\/strong> within <strong>72 hours<\/strong> under the GDPR; see our guide to <a href=\"https:\/\/sawaryn.com\/publikacje\/zgloszenie-naruszenia-rodo-wyciek-danych-osobowych\/\">reporting a personal data breach in Poland<\/a>. A whistleblower report brings a <strong>seven-day<\/strong> period for acknowledging receipt and a <strong>three-month<\/strong> period for feedback. An occupational health and safety issue calls for an immediate response.<\/p>\n<p>Misclassification can mean using the wrong procedure, omitting a required action, or missing a statutory deadline. Each can create a separate liability risk.<\/p>\n<h2>Why a disorganized response can cost more than the event<\/h2>\n<p>A data leak, workplace conflict, or whistleblower report is serious in itself. A late, contradictory, or undocumented response can add legal and operational costs.<\/p>\n<h3>One event can engage several Polish legal regimes<\/h3>\n<p>An incident may simultaneously involve the GDPR, Poland\u2019s Whistleblower Protection Act, the Labor Code, and the Commercial Companies Code. Criminal Code provisions may also be relevant. The following examples show the separate exposures described in the approved source:<\/p>\n<table>\n<thead>\n<tr>\n<th>Legal regime<\/th>\n<th>Typical failure<\/th>\n<th>Stated consequence<\/th>\n<th>Legal basis<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>GDPR<\/td>\n<td>Failure to notify UODO of a breach within 72 hours<\/td>\n<td>Up to EUR 10 million or 2% of turnover<\/td>\n<td>Articles 33\u201334 and 83(4) GDPR<\/td>\n<\/tr>\n<tr>\n<td>GDPR<\/td>\n<td>Failure to notify affected individuals where there is a high risk<\/td>\n<td>Up to EUR 10 million or 2% of turnover<\/td>\n<td>Articles 34 and 83(4) GDPR<\/td>\n<\/tr>\n<tr>\n<td>Whistleblower Protection Act<\/td>\n<td>Obstructing a report<\/td>\n<td>Up to one year\u2019s imprisonment; up to three years where threats or violence are used<\/td>\n<td>Article 58 of the Whistleblower Protection Act<\/td>\n<\/tr>\n<tr>\n<td>Whistleblower Protection Act<\/td>\n<td>Retaliation against a whistleblower<\/td>\n<td>Up to two years\u2019 imprisonment; up to three years if persistent<\/td>\n<td>Article 58 of the Whistleblower Protection Act<\/td>\n<\/tr>\n<tr>\n<td>Labor Code<\/td>\n<td>Violating employee rights concerning, for example, occupational health and safety or pay<\/td>\n<td>Fine of PLN 1,000\u201330,000<\/td>\n<td>Articles 281\u2013283 of the Labor Code<\/td>\n<\/tr>\n<tr>\n<td>Criminal Code<\/td>\n<td>Malicious or persistent violation of employee rights<\/td>\n<td>Up to two years\u2019 imprisonment<\/td>\n<td>Article 218 \u00a7 1a of the Criminal Code<\/td>\n<\/tr>\n<tr>\n<td>Commercial Companies Code<\/td>\n<td>Damage to the company caused by a management board member\u2019s action or omission through fault<\/td>\n<td>Liability for damages<\/td>\n<td>Article 293 \u00a7 1 of the Commercial Companies Code<\/td>\n<\/tr>\n<tr>\n<td>Criminal Code<\/td>\n<td>Breach of trust through failure to perform duties resulting in substantial damage<\/td>\n<td>Criminal liability<\/td>\n<td>Article 296 of the Criminal Code<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Failure to make a required GDPR notification is a separate infringement from the underlying leak. As examples, UODO fined Link4 <strong>PLN 103,752<\/strong> for failing to notify a breach on time, rather than for the incident itself. A court enforcement officer paid approximately <strong>PLN 21,000<\/strong> in total: PLN 7,700 for failing to notify the authority and PLN 13,200 for failing to inform the affected person.<\/p>\n<p>Regulatory penalties are only part of the potential cost. A disorganized response can also lead to:<\/p>\n<ol>\n<li><strong>Data recovery and infrastructure replacement costs<\/strong> if production systems are affected.<\/li>\n<li><strong>Personnel costs<\/strong>, including overtime for IT, HR, and legal teams or the need for additional staff.<\/li>\n<li><strong>Customer and business-partner claims<\/strong>, particularly where confidentiality or data processing agreements are involved.<\/li>\n<li><strong>Lost revenue<\/strong> from downtime, customer departures, or paused projects.<\/li>\n<li><strong>Crisis advisory costs<\/strong> for legal, IT forensics, and communications support engaged after the event.<\/li>\n<li><strong>Employee claims<\/strong> concerning leave, overtime, or workplace bullying if reports were not addressed.<\/li>\n<li><strong>Reputational damage<\/strong> among employees, customers, and investors.<\/li>\n<\/ol>\n<p>An early, coordinated response is generally less costly than trying to repair the consequences of improvisation.<\/p>\n<h2>The first 72 hours: an operational sequence<\/h2>\n<p>Start these actions as soon as the event is identified. Several workstreams may need to run at once, but they should be coordinated.<\/p>\n<h3>Step 1: Preserve evidence<\/h3>\n<p>Before reaching conclusions, secure material that may establish what happened:<\/p>\n<ul>\n<li><strong>Correspondence:<\/strong> email, Slack, Teams, and other messages.<\/li>\n<li><strong>System logs:<\/strong> access, logins, permission changes, and file transfers.<\/li>\n<li><strong>Documents:<\/strong> agreements, notes, screenshots, and reports.<\/li>\n<li><strong>Recordings:<\/strong> where the company uses video surveillance or records calls.<\/li>\n<li><strong>HR-system records:<\/strong> working-time records, requests, and evaluations.<\/li>\n<\/ul>\n<p>The initial rule is: <strong>do not delete, alter, or move potentially relevant material<\/strong>, even if it appears unrelated or uncomfortable for the company. Delay in preserving evidence weakens the company\u2019s position in matters ranging from GDPR compliance to employment disputes.<\/p>\n<h3>Step 2: Classify the event and open every relevant workstream<\/h3>\n<p>Do not treat the matter as solely an HR issue, solely a data leak, or solely an IT failure without checking the other possibilities.<\/p>\n<table>\n<thead>\n<tr>\n<th>Screening question<\/th>\n<th>If yes, examine this workstream<\/th>\n<th>Deadline or response stated in the source<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Were personal data lost, disclosed, or accessed without authorization?<\/td>\n<td>GDPR; assess notification to UODO<\/td>\n<td>72 hours<\/td>\n<\/tr>\n<tr>\n<td>Did a report arrive through the whistleblowing channel, or does it concern a breach of law?<\/td>\n<td>Whistleblower Protection Act; internal follow-up<\/td>\n<td>Seven days to acknowledge receipt; three months for feedback<\/td>\n<\/tr>\n<tr>\n<td>Does it concern an employment relationship, workplace bullying, discrimination, or occupational health and safety?<\/td>\n<td>Labor Code; employer response<\/td>\n<td>Without delay<\/td>\n<\/tr>\n<tr>\n<td>Does it threaten the continuity of IT systems?<\/td>\n<td>Cybersecurity incident procedure<\/td>\n<td>24 hours for a serious incident under the <a href=\"https:\/\/sawaryn.com\/publikacje\/dyrektywa-nis-2-nowa-era-cyberbezpieczenstwa-w-unii-europejskiej\/\">Act on the National Cybersecurity System (KSC)<\/a><\/td>\n<\/tr>\n<tr>\n<td>Could it create management board liability toward the company?<\/td>\n<td>Commercial Companies Code; document decisions<\/td>\n<td>No statutory deadline stated here, but delay weakens the position<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>More than one \u201cyes\u201d means the response needs shared coordination\u2014not disconnected teams pursuing separate plans.<\/p>\n<h3>Step 3: Appoint an incident owner<\/h3>\n<p>When responsibility is dispersed, HR may wait for IT, IT may wait for legal advice, and legal advisers may wait for facts from HR. Name one person, or a two-person team, to:<\/p>\n<ol>\n<li>Coordinate the response across workstreams.<\/li>\n<li>Collect information from HR, IT, compliance, and legal advisers.<\/li>\n<li>Report directly to the management board.<\/li>\n<li>Track statutory deadlines.<\/li>\n<li>Set operational priorities and the order of actions.<\/li>\n<\/ol>\n<p>The incident owner need not be the subject-matter expert on every issue. The essential skill is knowing whom to involve, when, and how to bring the information together for decisions.<\/p>\n<h3>Step 4: Avoid making matters worse in the first 24 hours<\/h3>\n<p>Until the event has been properly assessed:<\/p>\n<ul>\n<li><strong>Do not dismiss anyone hastily.<\/strong> Terminating the contract of a person involved in a whistleblower matter may be regarded as retaliation, for which the source identifies a penalty of up to two years\u2019 imprisonment.<\/li>\n<li><strong>Do not issue broad internal or external announcements<\/strong> before establishing the facts and agreeing on an accurate message.<\/li>\n<li><strong>Do not delete correspondence or logs<\/strong>, even if they appear damaging.<\/li>\n<li><strong>Do not make premature written or oral statements<\/strong> that may later be used against the company.<\/li>\n<li><strong>Do not wait for the entire investigation before checking deadlines.<\/strong> The GDPR\u2019s 72-hour notification period runs from becoming aware of the breach, not from completing every factual inquiry.<\/li>\n<\/ul>\n<p>Recital 87 GDPR states that assessing whether notification was made \u201cwithout undue delay\u201d takes account of the breach\u2019s nature, gravity, and consequences. A documented decision-making process may assist the company where there is a minor delay; an undocumented one will not.<\/p>\n<h3>Step 5: Record decisions as they are made<\/h3>\n<p>For each material decision, record:<\/p>\n<ol>\n<li><strong>Date and time.<\/strong><\/li>\n<li><strong>Who made it.<\/strong><\/li>\n<li><strong>The reasons and information available at the time.<\/strong><\/li>\n<li><strong>The alternatives considered.<\/strong><\/li>\n<\/ol>\n<p>An email, dated note, or incident-management entry can serve this purpose. What matters is a reliable record of the decision and its basis.<\/p>\n<p>This serves two distinct purposes. First, <strong>Article 33(5) GDPR<\/strong> requires <a href=\"https:\/\/sawaryn.com\/publikacje\/jak-dokumentowac-i-zglaszac-naruszenia-danych-osobowych\/\">documentation of all personal data breaches<\/a>, including breaches the company decides not to notify to UODO. Record the reasons for a decision not to notify.<\/p>\n<p>Second, <strong>Article 293 \u00a7 3 of the Polish Commercial Companies Code<\/strong>\u2014the business judgment rule\u2014may protect management board members against liability for damage to the company when its conditions are met. Records help show what information and analysis supported their actions.<\/p>\n<h2>When procedures overlap: two examples<\/h2>\n<h3>A departing CTO takes a code repository<\/h3>\n<p>Suppose a CTO leaves and takes the company\u2019s code repository. The same facts may raise:<\/p>\n<ol>\n<li><strong>Intellectual property issues<\/strong> concerning rights to the source code.<\/li>\n<li><strong>GDPR issues<\/strong> if the code or systems contained customers\u2019 personal data.<\/li>\n<li><strong>Confidentiality issues<\/strong> if the code contained material covered by agreements with business partners.<\/li>\n<li><strong>Employment issues<\/strong> if the CTO was employed under a Polish employment contract and subject to confidentiality or non-compete obligations.<\/li>\n<li><strong>Cybersecurity issues<\/strong> if production systems were accessed without authorization.<\/li>\n<\/ol>\n<p>Legal may prepare a formal demand, HR may arrange a discussion, and IT may block access. Those actions should not proceed without someone also checking whether a personal data breach must be notified to UODO within 72 hours.<\/p>\n<h3>A whistleblower reports a personal data leak<\/h3>\n<p>The <a href=\"https:\/\/sawaryn.com\/publikacje\/sygnalista-w-firmie-jak-wdrozyc-dyrektywe-o-sygnalistach\/\">Polish Whistleblower Protection Act<\/a> and the GDPR have different procedures, but both may apply to one report. In the scenario described by the source, the company must manage these parallel tasks:<\/p>\n<ol>\n<li>Acknowledge receipt of the whistleblower report within <strong>seven days<\/strong>.<\/li>\n<li>Notify UODO of the personal data breach within <strong>72 hours<\/strong>.<\/li>\n<li>Investigate under the whistleblowing procedure and provide <a href=\"https:\/\/sawaryn.com\/publikacje\/jakie-obowiazki-ma-pracodawca-w-zwiazku-z-ochrona-sygnalistow\/\">feedback to the whistleblower<\/a> within <strong>three months<\/strong>.<\/li>\n<li>Protect the whistleblower\u2019s identity. The source states that Article 8 of the Whistleblower Protection Act excludes the obligation to tell the person named in the report the source of the data referred to in Article 14(2)(f) GDPR.<\/li>\n<\/ol>\n<p>These tracks must run concurrently without obstructing one another. The person conducting the whistleblowing investigation should not also decide whether to notify UODO: keep the decisions on independent tracks, with one coordination point.<\/p>\n<h2>Documenting management board decisions under Polish law<\/h2>\n<p>A company operating in Poland acts through its management board. Board members should therefore be able to explain not just <em>what<\/em> they decided during an incident, but <em>how<\/em> they reached that decision.<\/p>\n<p>An amendment to the Commercial Companies Code dated <strong>February 9, 2022<\/strong>, which entered into force on <strong>October 13, 2022<\/strong>, introduced the <a href=\"https:\/\/sawaryn.com\/en\/publikacje\/prawo-holdingowe-nowe-przepisy-dla-spolek\/\">business judgment rule<\/a> into Article 293 \u00a7 3. In the source\u2019s summary, a board member is not liable for damage caused to the company if they acted loyally and within reasonable business risk, including on the basis of information, analyses, and opinions that should have been considered in the circumstances.<\/p>\n<table>\n<thead>\n<tr>\n<th>Condition<\/th>\n<th>What to establish during an incident<\/th>\n<th>Useful record<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Loyalty to the company<\/strong><\/td>\n<td>The decision served the company\u2019s interests, not the decision-maker\u2019s or a third party\u2019s<\/td>\n<td>A decision note stating the purpose of the action<\/td>\n<\/tr>\n<tr>\n<td><strong>Reasonable business risk<\/strong><\/td>\n<td>The response was proportionate to the circumstances<\/td>\n<td>Alternatives considered and reasons for the chosen course<\/td>\n<\/tr>\n<tr>\n<td><strong>Appropriate information and analysis<\/strong><\/td>\n<td>The board gathered the available facts before deciding<\/td>\n<td>Incident classification, legal advice, and risk analysis<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>There is a limit:<\/strong> the business judgment rule does not protect a board member from liability for breaching mandatory law. The source\u2019s example is a board that knows of a GDPR breach and deliberately fails to make a required notification within 72 hours.<\/p>\n<h2>Prepare before an incident: a readiness checklist<\/h2>\n<p>Written policies are of little operational use if the people who must apply them cannot find or follow them.<\/p>\n<h3>Priority actions: implement immediately<\/h3>\n<ol>\n<li><strong>Check for a written incident response procedure.<\/strong> It should set out who acts, in what order, which deadlines matter, and who decides\u2014not merely state general security principles.<\/li>\n<li><strong>Prepare a one-page initial response card.<\/strong> List the first ten actions, including whom to contact, what to preserve, what to avoid, and which deadlines to check. Give it to the board, HR, IT, and compliance lead.<\/li>\n<li><strong>Create a classification matrix.<\/strong> Make it easy to identify GDPR, HR, whistleblowing, cybersecurity, and management risks in the same event.<\/li>\n<li><strong>Appoint an incident owner<\/strong> to coordinate responses regardless of the incident type.<\/li>\n<li><strong>Require real-time decision records<\/strong>, even if initially kept as dated emails or notes.<\/li>\n<\/ol>\n<h3>Recommended actions: implement within one month<\/h3>\n<ol start=\"6\">\n<li><strong>Train the board and managers<\/strong> on the \u201cdo no harm in the first 24 hours\u201d principle: avoid premature communications, deletion, and staffing decisions before proper classification.<\/li>\n<li><strong>Build an accessible crisis contact list<\/strong> covering external legal counsel, a GDPR specialist, IT forensics, and crisis communications support.<\/li>\n<li><strong>Have a lawyer review existing procedures together<\/strong>\u2014including workplace rules, GDPR policies, whistleblowing procedures, and IT security policies\u2014for conflicting responsibilities or deadlines.<\/li>\n<li><strong>Review incident-response clauses in <a href=\"https:\/\/sawaryn.com\/publikacje\/twoje-dane-w-obcych-rekach-jak-bezpiecznie-powierzac-przetwarzanie-danych\/\">IT provider agreements<\/a>.<\/strong> They should allocate tasks, timelines, and responsibilities between the company and provider.<\/li>\n<\/ol>\n<h3>Additional actions: implement within one quarter<\/h3>\n<ol start=\"10\">\n<li><strong>Run a tabletop exercise.<\/strong> Simulate, for example, a customer data leak reported through the whistleblowing channel. Test whether the team knows what to do and who decides.<\/li>\n<li><strong>Hold a 30-minute lessons-learned meeting after each incident<\/strong>, even a minor one. Identify what worked, what did not, and how the response card or procedure should change.<\/li>\n<\/ol>\n<h2>How we support companies dealing with incidents in Poland<\/h2>\n<p>A technology-company incident can require coordinated advice on GDPR, Polish employment law, whistleblower protection, corporate duties, and cybersecurity. We support companies and scale-ups through:<\/p>\n<ol>\n<li><strong>Incident readiness audits:<\/strong> reviewing procedures, consistency, staff awareness, and statutory deadlines, then reporting practical gaps and recommendations.<\/li>\n<li><strong>Support during an incident:<\/strong> helping classify the event, coordinate the legal response, track notifications, and document management board decisions.<\/li>\n<li><strong>Procedures and training:<\/strong> preparing response cards, classification matrices, and breach procedures, and training board members and managers.<\/li>\n<\/ol>\n<p>Our team brings employment, data protection, IT, and corporate law together because a single incident rarely stays within one specialty.<\/p>\n<h2>Close the incident\u2014and improve the next response<\/h2>\n<p>No procedure prevents every incident. A structured response can, however, limit financial loss, improve the board\u2019s ability to account for its decisions, and help the company resume normal operations.<\/p>\n<p>Three useful actions now are to <strong>check whether your response procedure is written and understood<\/strong>, <strong>appoint an incident owner<\/strong>, and <strong>prepare a response card and crisis contact list<\/strong>. If you need help auditing readiness, building procedures, or training your management board, <a href=\"https:\/\/sawaryn.com\/kontakt\/\">contact us<\/a>.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>We do not know whether an incident is \u201cserious.\u201d How quickly should we assess it?<\/h3>\n<p>Start with three questions. Were personal data lost, disclosed, or accessed without authorization? If so, assess whether UODO notification is required against the <strong>72-hour<\/strong> deadline. Did a report arrive through the whistleblowing channel? If so, track the <strong>seven-day<\/strong> acknowledgment deadline. Does the matter involve employee safety? If so, respond immediately. More than one \u201cyes\u201d calls for a coordinated, multidisciplinary response.<\/p>\n<h3>Who should make decisions: the board, HR, legal, or compliance?<\/h3>\n<p>The management board makes strategic decisions, such as authority notifications, external communications, and staffing decisions. An appointed incident owner coordinates operations: collecting information from HR, IT, compliance, and legal advisers; tracking deadlines; and reporting to the board.<\/p>\n<h3>Can board members be personally liable for a slow or poor response?<\/h3>\n<p>Yes. Under <strong>Article 293 \u00a7 1 of the Commercial Companies Code<\/strong>, a board member may be liable for damage caused to the company by an unlawful action or omission. The <strong>Article 293 \u00a7 3 business judgment rule<\/strong> may provide protection where the member acted loyally, within reasonable business risk, and on appropriate information. Documenting that process matters. The rule does not protect a deliberate breach of mandatory requirements, such as knowingly missing a required GDPR notification deadline.<\/p>\n<h3>We have procedures, but employees do not know them. Is that enough?<\/h3>\n<p>No. A procedure that is not known or used does not satisfy the source\u2019s account of the GDPR accountability requirement under <strong>Article 5(2)<\/strong> or the need for appropriate organizational measures. During a UODO or Polish National Labor Inspectorate inspection, or in proceedings, the company should be able to show that procedures were implemented, understood, and followed\u2014not merely written. Training and tabletop exercises help provide that evidence.<\/p>\n<h3>The immediate problem has passed. What is needed to close the matter?<\/h3>\n<p>Complete the applicable records and follow-up: document any personal data breach in the breach register, including the reasons for not notifying UODO if that was the decision; provide whistleblower feedback within <strong>three months<\/strong> where relevant; prepare a closing note covering actions, findings, and recommendations; and update procedures based on lessons learned. The records should be usable if a regulator, employee, business partner, auditor, or court asks questions months later.<\/p>\n<h3>How should we communicate internally without causing panic?<\/h3>\n<p>Communicate established facts rather than speculation, and appoint one person to coordinate internal messaging. Tell employees what happened at an appropriate level of detail, what the company is doing, and whom to contact with questions. Avoid both \u201cnothing happened\u201d assurances that may later prove false and alarmist statements that interfere with the investigation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For companies operating in Poland: learn how to preserve evidence, assess GDPR and whistleblower deadlines, coordinate teams and record board decisions.<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":"","sip_alt_url":"https:\/\/sawaryn.com\/publikacje\/pierwsze-72-godziny-incydent\/","sip_en_pl_url":"https:\/\/sawaryn.com\/en\/publikacje\/first-72-hours-company-incident-poland\/","sip_pair_uuid":"9f9ad173-8839-47ad-ae20-ffe25f1b0c47","sip_pair_state":"verified"},"categories":[1],"tags":[116,1239,1206,1235,1238],"specialization":[1134],"practice_area":[],"class_list":["post-2753","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-corporate-governance","tag-data-breach","tag-gdpr","tag-labor-law","tag-whistleblowers","specialization-compliance-risk"],"acf":[],"_links":{"self":[{"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/posts\/2753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/comments?post=2753"}],"version-history":[{"count":1,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/posts\/2753\/revisions"}],"predecessor-version":[{"id":2754,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/posts\/2753\/revisions\/2754"}],"wp:attachment":[{"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/media?parent=2753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/categories?post=2753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/tags?post=2753"},{"taxonomy":"specialization","embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/specialization?post=2753"},{"taxonomy":"practice_area","embeddable":true,"href":"https:\/\/sawaryn.com\/us\/wp-json\/wp\/v2\/practice_area?post=2753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}