Conference on the Implementation of the NIS2 Directive and the National Cybersecurity System in Poland

The Polish data protection authority (UODO) organized a conference on the interactions between the GDPR, the NIS2 directive, and the national cybersecurity system (KSC).
On July 20, a conference organized by the Polish data protection authority (UODO) brought together nearly 1,500 participants to discuss the relationships between the GDPR, the NIS2 directive, and the national cybersecurity system (KSC). The vice-president of the UODO emphasized that Poland is the most targeted country by cyberattacks in Europe, with 270,000 incidents reported last year, representing a 150% increase compared to 2024. He recalled that data protection is inseparable from cybersecurity and that the NIS2 directive establishes direct responsibility for the leaders of the entities concerned.

The first debate focused on the background checks of candidates and employees. Experts noted the ambiguity of Articles 8 and 11 of the KSC law, which authorize this verification for persons performing specific tasks. It is therefore necessary for the entities concerned to precisely map these tasks and the associated personnel before collecting such data. The discussion also raised questions about the degree of involvement required to justify this verification and about the balance to be found between the GDPR, the KSC, and the labor code.

Incident management was the subject of a second panel, which highlighted the low awareness of cybersecurity obligations in the energy sector, despite the sensitivity of the data processed. It was recalled that a cybersecurity incident often constitutes a data breach within the meaning of the GDPR, and that the National Cybersecurity Incident Response Center (CSIRT NASK) encourages notifiers to assess this aspect. The importance of also reporting cyberattacks to criminal authorities was emphasized.

A third exchange dealt with cyber resilience as a collective effort. Speakers stressed that cybersecurity should not be delegated solely to IT services but must involve the entire organization, especially management. It was recommended to present cybersecurity as an investment rather than a cost, and to strengthen the human factor through training and clear, enforced procedures.

The last panel focused on the position of the data protection officer (DPO). Faced with the new regulations of the digital package, DPOs face growing challenges requiring additional resources. Participants agreed that compliance with the KSC requires interdisciplinary teams and that the DPO should not coordinate these teams to avoid any conflict of interest, with their role remaining advisory.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire