Data and information security after 5 years of the GDPR

5 June 2023 | Knowledge, News, The Right Focus

The last few years have seen significant changes in the data protection landscape with this year marking the 5th anniversary of the General Data Protection Regulation, commonly referred to as the GDPR. It’s a good time to take stock and analyse what has changed, and what we can expect in the near future.

What has the GDPR brought us

First and foremost, there has been a significant increase in data subjects’ awareness of their rights and the obligations of data processors. This can be seen, for example, in the high number of complaints filed with the supervisory authority.

The need to ensure “GDPR compliance” has also had a significant impact on business operations. Businesses have started to place much greater emphasis on the implementation and practical application of data protection systems, which have become a core area of ensuring business security. This is undoubtedly influenced by the fines for non-compliance with these data protection regulations.

Thanks to the principles of privacy by design and privacy by default, there has been a huge shift in the approach to data protection, which is now taken into account from the very beginning of data processing, especially where modern technology is used.

With the GDPR, data protection has become a process rather than a single one-off activity, which is very important for the improving of data security, and also in the context of changing technology. This can be seen with the recent unprecedented development of artificial intelligence systems, in particular generative artificial intelligence where the issue of data protection is a key element in the development and implementation of AI systems, including the learning of algorithms and the building of models related to the processing of large amounts of data.

The importance of cyber security

With the rapid development of technology, cyber security is a key issue. Digital threats are increasingly affecting businesses and are closely linked to the issue of data protection, making it one of the biggest challenges facing organisations today. As an example, we are seeing a significant increase in the use of malware, particularly ransomware.

This has also not escaped the attention of EU regulators, who have addressed the issue of cyber security in legislation such as DORA, the Regulation on digital operational resilience for the financial sector[1], or NIS II, the Directive on measures for a high common level of cybersecurity across the Union[2].

DORA

The objective of DORA is to upgrade and consolidate the requirements for managing the operational digital resilience of financial services market participants at a pan-European level.

Upgrading is understood as complementing the traditional quantitative approach consisting in setting capital requirements to cover ICT risks, with a qualitative approach focusing on defining targeted qualitative requirements for the protection, detection and containment of security incidents and the building of operational resilience testing capabilities.

As regards consolidation, DORA focuses on several issues:

  • Requirements for the management of financial entities in terms of digital resilience and requirements for the management of ICT-related risk
  • Requirements for the management, including monitoring, classification and logging, of ICT-related incidents;
  • Requirements for testing the digital resilience of financial entities
  • Requirements for the management of ICT third-party risk

The proposed regulation covers 20 categories of entity, with financial entities obliged to comply with the regulation expanded to include a new generation of financial market participants, such as crypto-asset and crowdfunding service providers, in addition to the traditional financial institutions such as credit institutions, payment institutions, and investment firms.

In accordance with the principle of proportionality, the DORA requirements vary depending on financial entities’ business profile, size and scale of operation. Financial entities identified as microenterprises are therefore exempt from a significant part of the DORA requirements, whilst those identified as significant are required, among other things, to conduct TLPTs. Importantly, the list of financial entities also includes ICT service providers, which represents another departure from previous sectoral regulations.

Entities covered by DORA must apply the resulting requirements from 18 October 2024.

NIS II

NIS II, which repeals the existing NIS Directive, was adopted by the European Parliament on 10 November 2022.

NIS II introduces a distinction between essential entities and important entities, rather than between operators of essential services and digital service providers, significantly expanding the existing list.

It also clarifies cyber security risk management obligations by making certain solutions mandatory, including but not limited to:

  • Risk analysis and IT system security policies
  • Incident management policies
  • Business continuity plans
  • Ensuring supply chain security

In addition, the Directive introduces the possibility of imposing fines on entities failing to comply with their obligations. The amount of these fines will depend on the type of entity and will be up to the greater of EUR 10 million or 2% of the total worldwide annual turnover in the preceding year for essential entities, and EUR 7 million or 1.4% of the total worldwide annual turnover in the preceding year for important entities.

The main objective of NIS II is to further improve digital security in the European Union and the incident response capabilities of both public and private sector entities. In addition, it aims to harmonise across the Union precisely who will be affected by cyber security obligations.

The NIS II regulations must be applied in all EU Member States from 18 October 2024, so we can expect changes to the National Cyber Security System Act in this area as well.

Summary

The above regulations herald the fact that we can expect even more guidelines, recommendations, good practices and opinions to be issued at both European and national levels in the coming years.

These regulations will inevitably relate to practices in specific market sectors and will provide specific, individual solutions that businesses will need to comply with, and hence directly impact the need for businesses to proactively respond and adapt their business practices and procedures. Some of these changes may have implications for business strategies. It is clear that there will be a need to focus on technical safeguards and assess their adequacy with a view to avoiding possible fines from the supervisory authority.

Any questions? Contact us

Monika Maćkowska-Morytz

Maciej Kuranc

[1] Regulation of the European Parliament and of the Council on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014 and (EU) No 909/2014

[2] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148)

Latest Knowledge

Those who have data have power. The Data Act redistributes this power

The EU Data Act, which came into force in September 2025, represents a breakthrough in the regulation of data access and use. Data generated by devices, ranging from agricultural tractors and industrial machinery to solar panels and transport fleets, is no longer the sole property of manufacturers. Other market participants now have the opportunity to access and use this data to develop new, innovative products and services. The Data Act marks a departure from business models based on data monopolisation, to one requiring data to be shared in accordance with its rules. We are therefore entering a completely new reality.

KSeF and transfer pricing: a new era of transparency and operational challenges

The introduction of the National e-Invoice System (KSeF) represents one of the most significant challenges for group companies in recent years. Although the KSeF is intended to simplify the invoicing process and reduce tax abuse, it also has a significant impact on transfer pricing, particularly with regard to the documentation and settlement of TP adjustments.

Contributing assets to a family foundation – what to keep in mind

A family foundation is a legal entity whose purpose is to manage wealth effectively and ensure its succession without the risk of dispersing assets accumulated over generations. Therefore, a key issue related to the activities of such an organisation is the contribution of this wealth to the foundation in the form of various types of assets that will work for the beneficiaries. Let’s take a look at what this process involves in practice.

Cloud migration after the Data Act: new rights, lower costs and greater freedom

The Data Act requires a significant change in approach to cloud services. Companies should review their contracts and start planning updates immediately. It is crucial to introduce appropriate switching provisions and remove or renegotiate exit fees. Companies must also prepare their infrastructure, both technically and organisationally, for interoperability and migration in accordance with the new regulations.

A decade of sustainable development

Ten years ago, the international community adopted the 2030 Agenda for Sustainable Development with 17 Sustainable Development Goals (SDGs). As a signatory, Poland committed itself to implementing measures in the areas of economy, society and the environment. A decade on, and it is a good time to summarise our achievements and the key ESG regulations that have shaped the legal landscape in Poland and throughout the European Union.

Banking sector overview | Banking today and tomorrow | October 2025

According to estimates by the Polish Bank Association (ZBP), the last four months of 2025 may bring banks operating in Poland another PLN 10 billion in profits. This would set a new record, probably marking the last such good year. Forecasts for 2026 suggest that bank profits will decline to PLN 35 billion.

New tax limits for company cars

From 1 January 2026, new limits will come into force regarding the inclusion of depreciation charges and lease payments for passenger cars in tax-deductible costs.

Foreign investments in companies from strategic sectors under state protection

On 24 July 2025, amendments to the Act on the control of certain investments came into force, including the removal of the time limitation of the provisions relating to the control of certain investments prior to foreign acquisition. These regulations were introduced during the COVID-19 pandemic and were valid for a specific period.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / Head of the Personal Data Protection and Cyber Security Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl