Data audit & mapping
We check what data you process, on what basis and where, and where the compliance gaps and risks are.

Virtually every operating company processes personal data — of clients, employees, contractors and users. The GDPR has applied in Poland since 2018, but the risk landscape in 2026 looks different than it did a few years ago: fines imposed by the President of the Polish DPA (UODO) have risen sharply, cybersecurity has become a duty for the management of entities covered by the National Cybersecurity System Act (the NIS2 implementation), and the use of artificial intelligence has added another layer of obligations to personal data.
At the foundation of the GDPR are principles that must be met whatever the industry: lawful bases for processing, data minimisation, correct retention periods, security (Art. 32) and accountability — the ability to demonstrate compliance. So GDPR compliance is not a one-off "paper" project but a state you have to maintain: up-to-date registers and documentation, correct data-processing agreements, real procedures for a breach and for data-subject requests. Gaps usually surface at the worst moment — during an inspection, a data leak or a transaction in which a buyer examines compliance.
We guide companies through this whole area: from an audit and implementation, through ongoing advice and outsourcing of the data protection officer (DPO) function, to representation before the President of the UODO. Rather than leaving you with a bare statement that "this is what the rule says", we implement the specific documents and procedures that genuinely work in your organisation.
We check what data you process, on what basis and where, and where the compliance gaps and risks are.
A complete rollout: lawful bases, policies, procedures and documentation tailored to the company.
The record of processing activities (RoPA), a data-retention and deletion policy, a data-protection policy and internal procedures.
Data-processing agreements (Art. 28 GDPR), assessment of IT and cloud providers and controller–processor relations.
Privacy notices, consents and lawful bases — correct, clear and demonstrable.
Handling access, rectification, erasure ("right to be forgotten") and objection requests, within GDPR deadlines.
Assessing a breach, notifying the President of the UODO within 72 hours and informing the data subjects.
A data protection impact assessment where processing may result in high risk (Art. 35 GDPR).
Acting as, or supporting, your data protection officer — independently and without a conflict of interest.
Lawful transfers to the US and other countries: the DPF, standard contractual clauses (SCC) and transfer impact assessments.
Monitoring, email review and biometrics in line with the Labour Code and the proportionality principle.
Data in AI systems, marketing and profiling, and cookie consent — at the crossroads of GDPR, the AI Act and telecoms law.
Your matter is handled by lawyers for whom data protection is daily practice, not a side topic.

Marta Solarska-Kaleńczuk
Partner, COO,
Data Protection Officer
Implements and audits GDPR programmes, handles breaches and acts as data protection officer; works at the crossroads of data protection, new technologies and competition law.

Oliwia Koper
Associate, Advocate
An advocate advising businesses on data protection: data-processing agreements, information duties, e-commerce and new technologies, and representation in disputes.
We start with what genuinely protects the company — not with a stack of documents "for the drawer".
We establish what data and processes you have, where the gaps are and which risks are most pressing.
We prioritise the work and present a plan with scope, cost and a timeline.
We prepare policies, registers, data-processing agreements and procedures — ready to use.
We run ongoing compliance, updates and support during breaches and inspections.
In practice, yes — the GDPR applies to any entity that processes personal data, regardless of size. If you have clients, employees, collaborators, website or newsletter users, then you process personal data and are subject to the GDPR. There is no company-size threshold and no "we are small" exemption — the obligations differ in scale, but not in whether they apply.
The scope of the obligations depends on what data you process and for what purpose. It looks different for a sole trader running a newsletter, different for a company that employs staff and uses monitoring, and different again where special categories of data (for example health data) are processed or large-scale profiling is carried out. Some obligations — such as the record of processing or appointing a DPO — depend precisely on those circumstances.
We help establish which obligations genuinely apply to you and implement them in a sensible scope — without over-regulating a small company and without gaps in a larger one. The starting point is usually a short audit, after which you know what is urgent and what can wait.
The GDPR provides for administrative fines of up to EUR 20 million or — for an undertaking — up to 4% of total worldwide annual turnover, whichever is higher. These are the upper ceilings for the most serious infringements; in practice the amount depends on factors such as the nature of the breach, the number of people affected, the degree of fault and cooperation with the authority.
In Poland, 2025 was a record year: the President of the UODO imposed fines totalling over PLN 64 million, including some of the highest in the country's history — among them Bank ING (about PLN 18.4 million, in connection with the unlawful processing of identity-document data) and McDonald's Poland (about PLN 16.9 million, after employee data were exposed through, among other things, failures in risk analysis, security and oversight of a processor). These are amounts imposed — not necessarily final or collected: the largest (PLN 27.1 million, national-ID data, Poczta Polska) was annulled by the court, but that judgment is non-final and contested by the UODO. The clear trend, though, is towards higher, deterrence-oriented fines for systemic infringements, and the financial and reputational risk is real.
Beyond the fine itself come further costs: handling the incident, notifications, claims by those affected and loss of client trust. That is why it pays to invest in compliance before a problem arises. We help reduce the risk on the organisational and documentation side and, if proceedings begin, represent the company before the President of the UODO.
NIS2 is an EU cybersecurity directive that Poland implemented by amending the National Cybersecurity System Act (KSC). The amendment entered into force on 3 April 2026, but the obligations phase in: covered entities should implement the requirements (among others an information-security management system, risk assessment and incident reporting and handling) by 3 April 2027, and mandatory audits and real penalties begin from 3 April 2028. The catalogue of covered entities expanded from about 400 to roughly 38,000 (most of them public-sector bodies).
NIS2 covers "essential" and "important" entities in listed sectors (among others energy, transport, healthcare, digital infrastructure, manufacturing and ICT service providers) — often including medium-sized companies that previously had no obligations here. For covered entities, cybersecurity has ceased to be solely an IT matter: it has become a duty of the entity's manager, with requirements on risk management, supply-chain security and incident reporting. Penalties vary by entity category and, in the most serious cases, can reach as high as PLN 100 million.
Data protection and cybersecurity overlap heavily here — the same incident is often at once a personal-data breach (GDPR) and an incident reportable under the KSC/NIS2, though the two regimes have different thresholds, deadlines and recipients. We help establish whether and to what extent NIS2 applies to your company, and implement the requirements coherently with the GDPR and — where relevant — with DORA. You can read more about the compliance area on our compliance and ESG page.
Appointing a data protection officer is mandatory in three cases: where the processing is carried out by a public authority or body (except courts acting in their judicial capacity); where the core activity consists of regular and systematic monitoring of individuals on a large scale; and where the core activity consists of large-scale processing of special categories of data (for example health data) or data on convictions. The tests are assessed separately for a controller and for a processor. Outside those cases, appointing a DPO is voluntary — but often worth considering nonetheless.
A DPO must have expert knowledge, act independently and free of a conflict of interest, and report directly to the highest level of management. In practice it is hard to combine this role with a function that decides on the purposes and means of processing (for example a board member or the head of IT), as that would amount to "checking oneself".
That is why many companies outsource the role. We offer outsourcing of the data protection officer or support for your in-house DPO — combining independence, experience and availability without the cost of another full-time hire. We also handle the formalities: a DPO is a specific natural person, and their contact details are published and notified to the President of the UODO electronically within 14 days of appointment (and on any change or dismissal). And we help assess whether, in your case, appointing a DPO is mandatory or merely advisable.
A data protection impact assessment (DPIA) is a risk analysis that must be carried out before starting processing that is likely to result in a high risk to people's rights and freedoms (Art. 35 GDPR). It answers the questions: what data do we process and why, what are the threats and how do we reduce them to an acceptable level.
A DPIA is mandatory in cases such as systematic profiling with legal effects, large-scale processing of special categories of data, and systematic monitoring of publicly accessible areas. The President of the UODO also publishes a list of operations for which an assessment is required. If, despite the measures applied, the risk remains high, a prior consultation with the supervisory authority may be necessary before the processing begins.
Increasingly, a DPIA is combined with the fundamental-rights impact assessment (FRIA) required under the AI Act — where the high risk relates to the use of an artificial-intelligence system. We help carry out the assessment, choose risk-mitigating measures and document the whole process so that it can be demonstrated during an inspection.
The first hours matter most. A breach that may pose a risk to the rights or freedoms of individuals (where such a risk is "not unlikely") must be reported to the President of the UODO without undue delay, and no later than 72 hours after becoming aware of it; for cross-border processing you must also identify the lead authority. If the risk to individuals is high, the affected data subjects must additionally be informed — unless one of the Art. 34 exceptions applies (for example the data were encrypted, or a public communication is used instead of individual notices). Every breach — even one that is not reported — must be recorded in an internal register.
In practice, prior preparation is what counts: a response procedure, a clear division of roles and knowing how to assess the severity of a breach. Under time pressure it is easy to slip up — a late or unnecessary report, missing documentation, chaotic communication with clients. The same incident may at the same time be an event reportable under NIS2/KSC, so it is worth keeping the procedures aligned.
We support companies both before an incident (procedures, tests, training) and during one: we help assess whether and what to report, prepare the report and notifications and manage communication. When a matter turns into proceedings, we represent the company before the President of the UODO.
Transferring data outside the European Economic Area is permitted only on one of the bases provided for in the GDPR. The simplest situation is a country covered by a European Commission adequacy decision. For the US, that basis is the EU–US Data Privacy Framework — but only a recipient certified under the programme can rely on it.
The status of the transatlantic framework is, however, uncertain. In September 2025 the EU General Court upheld the DPF adequacy decision, but the ruling has been appealed to the Court of Justice of the EU (the Latombe case, C-703/25 P, pending), and privacy organisations have announced further challenges. The DPF, moreover, covers only recipients currently certified under the programme. The DPF currently applies, but it is prudent to have a "plan B" in case it is struck down — as happened with the earlier mechanisms (Safe Harbour, Privacy Shield).
Where a recipient does not rely on an adequacy decision, the main tool is the standard contractual clauses (SCC) — which, however, are not enough on their own: they require a documented transfer impact assessment (TIA), often additional safeguards and ongoing monitoring. We help choose the right basis, prepare the SCC and the transfer assessment and put in order data flows to cloud providers and tools based outside the EU.
The two regimes apply in parallel and complement each other. If an artificial-intelligence system processes personal data, GDPR obligations (a lawful basis, information duties, data-subject rights — including the Art. 22 rules on decisions taken solely by automated means — and a DPIA) apply regardless of the AI Act. The AI Act deadlines for high-risk systems have, however, been postponed by an amendment (the so-called Omnibus): obligations for stand-alone Annex III systems apply from 2 December 2027, and for AI embedded in Annex I products from 2 August 2028. From 2 August 2026 only the transparency requirements (Art. 50) begin to apply — for example telling users they are dealing with AI or AI-generated content.
The scope of your obligations depends on your role (provider or deployer of the system) and on the risk level of the particular use. A fundamental-rights impact assessment (FRIA) under the AI Act is not a general obligation — it applies to specific actors (among others public bodies and private providers of public services, and certain uses such as creditworthiness assessment or life and health insurance) and complements, rather than replaces, the DPIA required by the GDPR.
The European Data Protection Board stresses that a model's anonymity cannot be assumed up front — it requires a case-by-case assessment of the risk of identifying individuals and of extracting data from the model. We help arrange the use of AI in line with both regimes: establishing roles and risk, preparing lawful bases, assessing automated decisions (Art. 22), carrying out the DPIA (and a FRIA where required) and setting out rules for employees' use of AI tools — so as to adopt AI safely rather than give it up out of fear of the rules.
Yes, but within the limits of the law and the proportionality principle. The Labour Code permits monitoring (video, email and other forms) only for specific purposes — such as ensuring safety, protecting property or checking the organisation of work — and only after informing employees in advance and introducing the rules into internal documentation. Monitoring may not infringe dignity or personal rights, nor cover areas where that would be excessive.
Biometric data are a special category of data when they are processed for the purpose of uniquely identifying a person (for example a fingerprint or facial geometry used for recognition) — an ordinary employee photo is not automatically "biometric data". The Labour Code allows an employer to collect biometric data from an employee only in a narrow scope — as a rule, where it is necessary to control access to particularly important information or premises. For special-category data the consent must, as a rule, come from the employee and carry no detriment on refusal, and in a relationship of subordination it may be ineffective — so "fingerprint entry for everyone" is most often excessive.
We help design monitoring and any biometrics so that they achieve the purpose with the least intrusion: choosing the measure, the legal basis, privacy notices, provisions in workplace rules and retention periods. That way you reduce the risk of disputes with employees and objections from the President of the UODO.
Consent must be freely given, specific, informed and unambiguous — and the company must be able to demonstrate that it obtained it. In practice this means separate, non-pre-ticked boxes, a clear description of the purpose and the ability to withdraw consent as easily as it was given. "Forced" consents (for example access to content only after accepting marketing) are usually defective.
Cookies and similar technologies are an additional layer: alongside the GDPR, the rules of the Polish Electronic Communications Law (PKE) apply here, and authorities expect a genuine choice — "accept" and "reject" on equal terms, with no hidden consents. The rules may change: the Digital Omnibus package (a European Commission proposal of 19 November 2025 — separate from the already-adopted amendment to the AI Act itself, and still not adopted) proposed, among other things, moving the cookie rules into the GDPR and a minimum period during which consent may not be re-requested after refusal. Until it is adopted, the existing rules apply.
We put consents and cookies in order from both the legal and the implementation side: the wording of consents and notices, configuring the banner and cookie categories, recording consents and consistency with privacy policies. That way marketing works, and the company is able to demonstrate compliance during an inspection.
A controller is the entity that decides on the purposes and means of processing (for example your company in relation to its own clients' and employees' data). A processor processes data on behalf of, and on the instructions of, the controller — most often service providers: hosting, cloud, HR systems, marketing or accounting. The same company may be a controller in some processes and a processor in others.
Which agreement is needed depends on the provider's role — so we establish it first. If the provider acts as a processor (on your instructions), the GDPR requires a data-processing agreement (Art. 28) setting out, among other things, the scope, purpose, duration and manner of processing and the processor's obligations on security and sub-processing. If instead the provider decides on the purposes of processing itself, it is a separate or joint controller — and then different arrangements apply (for example a joint-controllership agreement). The "terms of service" alone are usually not enough, and mis-classifying the role is one of the more common gaps caught during audits.
We help correctly classify the roles in each process, prepare and negotiate data-processing agreements and assess providers for security and data location. This is especially important when using cloud tools and providers outside the EU, where it ties in with the question of transfers.
We start with a short audit: we establish what data and processes you handle, on what basis, to whom you entrust data and where the biggest gaps and risks are. The result is a clear map of your compliance status together with priorities — what is urgent (for example missing processing agreements, defective consents, no breach procedure) and what can be spread out over time.
On that basis we propose a plan with scope, cost and a timeline, and then move to implementation: policies and procedures, registers, privacy notices, data-processing agreements, a breach-response procedure and, where needed, a DPIA. We can also take over the data protection officer function or support your DPO on an ongoing basis.
We match the cooperation model to the scale of the company: from a one-off implementation, through ongoing advice, to a full outsourcing of the DPO function. You can book a first conversation and an initial assessment through our contact form. If you are looking for broader legal support for your company, see also outsourcing of legal services.
Legal position: July 2026. Data protection law is changing rapidly — among other things, work is under way on the so-called Digital Omnibus (a proposal to amend the GDPR, cookie rules and the Data Act, announced by the European Commission on 19 November 2025 and not yet adopted). The President of the UODO has also announced a 2026 sectoral inspection plan (among others marketing entities and delivery platforms), and inspections are not limited to that plan. This information is general in nature and does not constitute legal advice on an individual matter.
Book a short call — afterwards you will know where the biggest risks are and where to start your GDPR implementation.