Non-EEA IT vendors – growing challenges in the face of geopolitical change

10 June 2025 | Knowledge, News, The Right Focus

The global political landscape is changing rapidly, and the directions of these changes can often be surprising. This has been clearly demonstrated by the recent, hard-to-understand decisions of the US administration, and is one of the reasons why the question of cooperation with IT service providers from outside the European Economic Area is becoming an issue of strategic importance. It is thus worth taking a closer look at the implications of such cooperation, especially in critical infrastructure sectors, including banking.

Global challenges in IT supply chains

International unrest is calling into question the stability of global supply chains, particularly in the technology services sector. Analysts at Reuters Events (October 2024), point out that while supply-related processes have always been subject to uncertainty, recent years have seen disruptions on an unprecedented scale.

American technology companies dominate the global market in this area, providing key solutions such as:

  • cloud infrastructure
  • analytical tools
  • data management systems
  • cybersecurity solutions
  • other technologies essential for modern financial institutions

It should be noted that the activities of these companies are subject to strong political influence, in particular, decisions taken by the US authorities.

Legal regulations and their implications

An example of a regulation that affects IT service providers is the US Cloud Act, which allows the US government to access electronically stored communications data on the basis of a court order.

“Entities from the European Union may be subject to the Cloud Act if they use services related to the US or provided by companies based in the US,” says Natalia Kotłowska-Wochna.

It should also be noted that data transfers between the EU and the US are currently governed by the Data Privacy Framework, which was established in response to the CJEU ruling in the Schrems II case. However, when adopting this framework, the United States did not repeal Section 702 of the FISA Amendments Act, which grants intelligence services powers over non-US persons located outside the United States. This creates a risk that the validity of the Data Privacy Framework could be challenged by the CJEU.

The EU Data Act is another piece of legislation impacting the IT services industry. From 12 January 2027, it will prohibit cloud service providers from charging for the transfer of customer data to another provider, regardless of the company’s location. This provision may have contributed to the decision by some global providers to waive data transfer fees (so-called egress fees).

Risk mitigation strategies

As geopolitical tensions rise, critical infrastructure organisations will undoubtedly focus on mitigating the risks associated with using IT services from non-EEA providers.

One way to achieve this goal will be to diversify providers, which will minimise the risks arising from potential political decisions or regulatory changes. As part of such a strategy, it is possible to switch to European providers whose solutions not only comply with EU standards, but are also adapted to local risks and their latest updates, which results in a higher level of security.

“The DORA Regulation, which introduces a comprehensive framework for managing the risks associated with ICT third-party service providers, is proving to be a significant support for banks,” says Natalia Kotłowska-Wochna.

DORA requires financial institutions to develop a policy for managing the risks associated with ICT third-party service providers. This policy should be implemented in accordance with the principle of proportionality, taking into account the nature, scale and complexity of the technological reliance and the criticality of the service to ensuring the continuity of financial operations.

The Regulation also requires a preliminary assessment of ICT concentration risk and a periodic review of ICT service risks, taking into account the organisation’s risk profile and the complexity of its services.

Non-EEA IT vendors –  our recommendations for banks

In summary, as geopolitical tensions rise, critical infrastructure organisations should implement risk mitigation measures such as:

  • Diversifying IT service providers
  • Investing in local solutions
  • Conducting regular regulatory compliance audits
  • Strengthening cyber security controls
  • Developing advanced business continuity plans
  • Implementing backup solutions
  • Giving priority to recovery actions
  • Implementing comprehensive training schemes
  • Monitoring of risks
  • Regularly updating plans to reflect changing market and geopolitical conditions

 Any questions? Get in touch with us

Natalia Kotłowska-Wochna

Latest Knowledge

Announcement of Income Tax Reform

On 19 August, during a press conference, the Prime Minister announced a package of tax changes planned for next year. According to the announcement, the reform is intended, on the one hand, to ease the burden on the middle class and, on the other, to shift a greater fiscal burden onto the wealthiest individuals and the largest companies. We take a look at the proposals included in the announced package and explain what they might mean for taxpayers.

Family foundations and the tax authorities: what draft bill UD447 proposes and why this is not the end of the troubles

Family foundations were intended to provide entrepreneurs with a stable framework for intergenerational wealth management. Yet not even four years have passed since the first such foundations were established, and the rules governing their taxation are set to be changed once again. This is because the scale of interest and the practical problems uncovered have overwhelmed the drafters of the legislation, as best illustrated by the figures – 927 applications for individual tax rulings and 77 opinions issued from the Head of the National Revenue Administration. This does not, however, mean that family foundations are being used on a massive scale for aggressive tax optimisation. A significant proportion of the queries concerned simply how to correctly apply the complex regulations.

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

Contact us:

Natalia Kotłowska-Wochna

Natalia Kotłowska-Wochna

Attorney-at-Law / Partner/ New Tech, IP, Trade & Logistics Practice Group / Head of New Tech M&A

+48 606 689 185

n.kotlowska@kochanski.pl