There is no effective personal data protection without cybersecurity
On July 20, the Personal Data Protection Office hosted a conference titled "NIS2 and the National Cybersecurity System (KSC) in practice." More than a dozen experts shared their insights during the event, which was attended by nearly 1,500 participants, both in person and online. Across four panel discussions, speakers explored the relationship between the GDPR, the NIS2 Directive, the National Cybersecurity System (KSC), the proper division of roles in building a cybersecurity system, as well as the position of data protection officers within that system.
The opening address was delivered by Konrad Komornicki, Deputy President of the Personal Data Protection Office. He noted that Poland is the country experiencing the highest number of cyberattacks in all of Europe. Last year, 270,000 cybersecurity incidents were reported in the country - a 150% increase compared to 2024. The Personal Data Protection Office has recorded similarly steep rises in breach notifications.
"Effective personal data protection is impossible without ensuring cybersecurity. The two are closely interconnected. I am glad the private and public sectors are exchanging views - the voice of practitioners matters to us," said Konrad Komornicki.
The Deputy President added that the Office is part of the S46 system, which allows for reporting cybersecurity incidents - not only as a user but also as a supervisory authority. He also emphasized that NIS2 introduces a new form of accountability for obligated entities: the direct liability of those entities' management.
When and who may be subject to criminal record verification under the National Cybersecurity System?
The first panel addressed the verification of job candidates' criminal records in the context of risk management. The moderator was Piotr Drobek, Director of the Department of Innovation and Data Management at the Personal Data Protection Office. Speakers included Sławomir Chmielewski, Chief Security Officer at Orange Polska, along with members of the Social Team of Experts to the President of the Personal Data Protection Office: Marlena Sakowska–Baryła, PhD, Professor at the University of Łódź; Dominika Dörre-Kolasa PhD; Arwid Mednis PhD, Professor at the University of Warsaw; and Paweł Litwiński, PhD.
The discussion focused on whether current regulations leave room for interpretation regarding the scope of data an employer that is a key or important entity may collect. Panellists agreed that Articles 8 and 11 of the National Cybersecurity System - which provide for the right and obligation to verify the criminal record of employees and job candidates - are not unambiguous. They also stressed that these provisions apply to individuals performing tasks specified in the law. There is no doubt, then, that in order to lawfully collect data on such individuals (not only employees but also those engaged under civil-law contracts), an organization subject to the National Cybersecurity System must first properly identify the tasks being performed and the personnel responsible for them.
More controversial was the question of the degree to which a given person must be involved in carrying out these tasks - whether the decisive factor should be their influence over decision-making within a given process, and to what extent supporting roles (e.g., those handling data carriers) should be included. Disputes also arose over the point at which data on these individuals may begin to be collected, and whether the management of a key or important entity may do so on its own initiative or may only require the employee/candidate to provide the relevant certificates. An interesting conclusion from the discussion was that entities carrying out such strategic activities must operate within a triangle defined by GDPR, the National Cybersecurity System, and the Labour Code. Depending on the circumstances, interpretation should lean toward one of these three corners.
How to handle data protection and cybersecurity incidents
The second panel addressed incidents as understood under GDPR and NIS2. The moderator was Mirosław Gumularz PhD, Chair of the Social Team of Experts to the President of the Personal Data Protection Office. Participants included Małgorzata Kozak, Director of the Department of Market Development and Consumer Affairs at the Energy Regulatory Office; Agnieszka Gryszczyńska PhD, Professor at Cardinal Stefan Wyszyński University and Director of the Department for Cybercrime and Digitalization at the National Prosecutor's Office; Maciej Siciarek, Director of the CSIRT Division at NASK PIB; Marcin Wysocki, Deputy Director of the Cybersecurity Department at the Ministry of Digital Affairs; and two members of the Social Team of Experts: Rafał Tomasz Prabucki PhD (Łukasiewicz AI) and Tomasz Izydorczyk.
Małgorzata Kozak noted that although more and more entities are emerging in the energy sector, awareness of cybersecurity and information protection obligations among them remains low. Meanwhile, data on electricity consumption or geolocation means the energy sector knows more about us than the banking sector does. Maciej Siciarek, in turn, emphasized that a cybersecurity incident often also constitutes a data breach, though many people reporting incidents are unaware of this. That is why CSIRT NASK advises them to also check the incident from a GDPR perspective and, if applicable, report it to the Personal Data Protection Office.
Agnieszka Gryszczyńska pointed out that, in addition to the National Cybersecurity System and GDPR regimes, one should also not forget the Criminal Code and the obligation to report cyberattacks as crimes. While for an ordinary citizen this is merely a social obligation, in the case of a public official, failure to report may be considered a dereliction of duty. She also noted that ransomware is usually not the first type of software hackers install in an organization's systems - they first use spyware to determine what data to steal and how to profit from it. The remaining panellists focused on defining the concept of an "incident" itself, as well as its various types.
How should roles in cybersecurity be properly divided?
The moderator of the third panel, titled "Cyber resilience as a team sport - division of roles and security procedures," was Artur Klepacki, Director of the Department of IT and Cybersecurity at the Personal Data Protection Office. Participants included Grzegorz Nowak, Director of the Cybersecurity and Data Protection Center in Władysławowo; Tomasz Turba, Cybersecurity Consultant at Sekurak.pl; Grzegorz Abgarowicz, Head of the Audit and Implementation Team at NASK S.A.; Dariusz Jędryczek, Director of the Department of Digitalization and Cybersecurity at the Ministry of State Assets; Adam Tatarowski, Chair of the Sectoral Competence Council for Property and Personal Protection and Security; and Colonel Dariusz Chmielewski from the Ministry of National Defense.
The panel focused above all on the fact that too many organizations delegate cybersecurity solely to IT departments. However, for it to be effective, all members of an organization must be involved - especially leadership. It is important to change the way we talk about cybersecurity by focusing on its benefits, so that decision-makers begin to treat it as an investment rather than merely a cost. The idea is to frame cybersecurity differently, emphasizing the advantages of securing IT systems in terms of the security of individuals, and consequently building a positive image of an organization that citizens trust and are therefore willing to use - rather than treating the need for security as simply a matter of spending money without financial benefit (or even as a financial loss) for the organization.
It was also noted that people are both the weakest and the most important part of the cybersecurity system. That is why it is worth investing in building and training staff with the appropriate competencies. Beyond individual employee knowledge, clear and understandable procedures for responding to cyberattacks and subsequently enforcing compliance with them, are also important.
The position of the DPO in the cybersecurity system
The fourth panel focused on the role of Data Protection Officers (DPOs) in organizational governance and avoiding conflicts of interest. The moderator was Krzysztof Król, Deputy Director of the Department of International Cooperation at the Personal Data Protection Office. Speakers included Beata Konieczna-Drzewiecka PhD, Data Protection Officer at the Ministry of Interior and Administration; Attorney Monika Susałko, Managing Partner at Lubasz i Wspólnicy; Milena Rygiel-Soćko, Vice President of Women Go Cyber; Mariola Więckowska of the Social Team of Experts to the President of the Personal Data Protection Office; Mateusz Jakubik, President of SABI (the Polish Association of Data Protection Officers); and Piotr Czubaty, Project Director and Member of the Program Council at ISSA Poland.
During the discussion, it was noted that as further regulations under the so-called digital package come into force, DPOs face an increasing array of new challenges. This naturally requires an expansion of the resources allocated to them. It was also emphasized that the National Cybersecurity System regulations require an interdisciplinary approach involving a team that brings together experts from various specializations. The question of who should coordinate the work of such a team, make decisions, and bear responsibility for them remains open. According to panel participants, the DPO should not take on this role, and should instead be limited to serving as an advisory body.