Poland's Privacy Regulator Says Cybersecurity & Data Protection Can No Longer Be Treated Separately
Key Takeaways
- Cybersecurity and Data Protection Are Now Inseparable: Poland's Personal Data Protection Office said organizations can no longer treat GDPR compliance and cybersecurity as separate disciplines, arguing that effective protection of personal data depends on resilient cyber defenses.
- NIS2 Expands Executive Accountability: Regulators emphasized that NIS2 introduces direct management liability for organizations subject to the directive, elevating cybersecurity from an IT function to a board-level governance responsibility.
- Compliance Requires Balancing Multiple Legal Frameworks: Experts said organizations designated as key or important entities must reconcile obligations under the GDPR, Poland's National Cybersecurity System Act (KSC), and the Labor Code, particularly when conducting employee background checks and managing critical functions.
- Cyber Incidents Often Trigger Multiple Reporting Obligations: Panelists stressed that many cybersecurity incidents also constitute personal data breaches and may even require criminal reporting, underscoring the need for organizations to assess incidents across privacy, cybersecurity, and criminal law simultaneously.
- Data Protection Officers Should Advise, Not Lead Cybersecurity: As digital regulations expand, participants argued that DPOs should remain independent advisors within multidisciplinary governance teams rather than assume operational responsibility for cybersecurity programs.
Deep Dive
Poland recorded roughly 270,000 cybersecurity incidents last year, according to the country's Personal Data Protection Office. That was a 150% increase over 2024. The agency says it is seeing the same trajectory in reports of personal data breaches.
Those numbers framed nearly every conversation at the Personal Data Protection Office's "NIS2 and KSC in Practice" conference on July 20, where regulators, prosecutors, academics, cybersecurity specialists, and industry leaders spent the day wrestling with a problem that sounds straightforward until it reaches an organization's legal department: where does cybersecurity end and data protection begin? According to the regulator, it doesn't.
"Personal data cannot be effectively protected without ensuring cybersecurity. They are interconnected," Deputy President Konrad Komornicki told attendees. "I am pleased that the private and public sectors are exchanging views; the voices of practitioners are important to us."
Nearly 1,500 people attended the conference, either in person or online. Across four panel discussions, the focus remained remarkably consistent. The GDPR, the NIS2 Directive, and Poland's National Cybersecurity System (KSC) are often discussed as separate compliance exercises. In practice, speakers argued, organizations will struggle if they continue to treat them that way.
Komornicki also said the Personal Data Protection Office has been integrated into Poland's S46 cybersecurity incident reporting system, allowing it to participate not only as a user but also as a supervisory authority. He reminded attendees that NIS2 introduces direct management liability for organizations required to comply with the directive, making cybersecurity a board-level responsibility rather than solely a technical one.
The Background Check Problem
One of the day's more practical debates concerned criminal background checks for employees and job candidates working in organizations designated as key or important entities under Poland's cybersecurity legislation. The question sounds administrative. It quickly became legal.
Panelists agreed that the relevant provisions governing criminal record verification leave considerable room for interpretation. Before collecting criminal history information, they said, organizations first need to identify which specific functions fall within the National Cybersecurity System Act and which individuals actually perform those functions. That assessment extends beyond traditional employees and may also include contractors working under civil law agreements.
Where consensus began to fade was over proximity to those critical functions. Should criminal record checks apply only to people making operational decisions? What about those supporting the process without exercising authority, such as personnel responsible for transporting or handling storage media? At what point does support become participation?
Another unresolved issue was whether organizations should collect criminal history information directly or require candidates and employees to obtain official certificates themselves. By the end of the discussion, no one claimed the legislation answered every question. Instead, participants described compliance as an exercise in balancing three separate legal frameworks simultaneously: the GDPR, the National Cybersecurity System Act, and Poland's Labor Code. Which framework carries the greatest weight depends on the facts of the individual case.
Most Cyber Incidents Are Privacy Incidents Too
The second panel exposed another divide that regulators appear increasingly eager to erase. Organizations often report cybersecurity incidents without considering whether they also constitute personal data breaches. According to Maciej Siciarek, Director of the CSIRT Division at NASK PIB, that distinction frequently exists only in the minds of the reporting organizations.
A cybersecurity incident will often involve compromised personal data as well, he said, which is why CSIRT NASK encourages organizations to examine incidents through the GDPR lens and notify the Personal Data Protection Office whenever reporting obligations are triggered.
Małgorzata Kozak, Director of the Department of Market Development and Consumer Affairs at Poland's Energy Regulatory Office, argued that awareness has not kept pace with the growth of the energy sector. Electricity consumption data combined with location information, she noted, can reveal intimate patterns about people's lives. In some respects, she suggested, energy providers may know more about individuals than banks do.
For Agnieszka Gryszczyńska, Director of the Department of Cybercrime and Informatization at the National Prosecutor's Office, another blind spot remains. Organizations tend to think first about regulatory notifications while overlooking criminal reporting obligations.
She reminded attendees that public officials who fail to report criminal offenses may themselves face consequences for neglecting official duties. She also pushed back against the popular image of ransomware attacks beginning with encrypted files and ransom notes. By the time ransomware appears, she said, attackers have often already spent considerable time inside a victim's systems using spyware to identify valuable information and determine how to profit from it.
Cybersecurity Is Not an IT Department
The third panel returned repeatedly to a familiar organizational habit: assigning cybersecurity almost exclusively to technical teams. Participants argued that approach has outlived its usefulness.
Boards and senior management must become active participants rather than distant sponsors, they said. Just as importantly, organizations need to stop presenting cybersecurity as another unavoidable compliance expense. If executives see only cost, investment becomes defensive. If they understand cybersecurity as something that strengthens public trust, protects essential services, and improves institutional resilience, the conversation changes.
Several speakers described employees as both the weakest point in any security system and its greatest asset. Technology alone cannot compensate for poorly trained staff, unclear responsibilities, or response procedures that exist only on paper.
Building competence, repeatedly practicing incident response, and making procedures understandable to the people expected to follow them were presented as equally important parts of cyber resilience.
The Expanding Role of the Data Protection Officer
The conference concluded with a discussion that reflected a broader shift occurring across European regulation. Each new digital law adds responsibilities somewhere inside an organization. Increasingly, those responsibilities intersect with the work of the data protection officer. Panelists agreed that this does not mean the DPO should become the organization's cybersecurity manager.
Instead, they argued that compliance with the National Cybersecurity System framework requires multidisciplinary teams bringing together legal, privacy, cybersecurity, and operational expertise. Someone must coordinate those efforts and make operational decisions, but participants maintained that the DPO's value lies in preserving independence, advising the organization, and providing oversight without assuming responsibility for the operational choices they may later be required to assess.
The discussion reflected a broader reality emerging across Europe's digital regulatory landscape. As privacy, cybersecurity, and operational resilience become increasingly intertwined, organizations may continue assigning them to different departments. Regulators, however, are beginning to speak as though they are parts of the same system.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

